Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xregedit.exe /s appboost.reg"Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
YABRegmonABregmon.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
XATI VIDEO REGKEYati2vid.exe"Added by the SDBOT.UR WORM!"
NAUTOPROPREGPROP.EXE WMPADDIN.DLL"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently
YAVG_RegCleanerAVGREGCL.exe"Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
NBatchreg1N/A"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation
UBDRegionbrs.exe"Part of Cyberlink's PowerDVD version 8 - removes the Blu-ray region on a DVD"
YBDWizRegbdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
XBregbcre.exe"BroadcastPC adware variant"
XBregbptre.exe"BroadcastPC adware variant"
XBregbreg.exe"BroadcastPC adware"
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
XCcaoregedit.exe"Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This version resides in a ""mduu"" subfolder
Xccregexplorer.exe"Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
YccRegVfyccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYoutIook.exe"Added by the TACTSLAY.A TROJAN!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
UCertRegcertreg.exe"Related to Gemplus Card Reader"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
?CleanRegPathCleanReg.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
YCommon ClientccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorel RegistrationRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel Registration ReminderRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
XData789Regedit.exe ....data789.tmpHomepage hijacker
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDHCP Serverregsvr.exe"Added by the RBOT-PR WORM!"
NDJRegFixregedit /s c:hpdjregfix.reg"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
Xdllregdllreg.exe"Added by the CRYPTER.A TROJAN!"
NDNS7reminderEreg.exe Ereg.ini"Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
?dregfixph_finder.exe"??"
NDXDllRegExedxdllreg.exe"Created when you select ""Yes"" to check the ""WHQL Digital signatures"" in the DirectX9 files at the first time you open it"
NE-Color RegistrationSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
NEregreg32.exe"EReg is a software registration tool incorporated on products such as those by Broderbund
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
Xhotdlllvmmreg32.exe"BANKER.DX spyware"
?HP Network Registry Agenthpnra.exe"??"
UHREF.OCXregsvr32.exe ....HREF.OCX"HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller"
?ILO_Office_ManagerIntEdReg.exe /OFFMAN"Intense Educational Ltd - Language Office Software. Is it required?"
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XInternalregedit.exe /s c[month number]"Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir%
NIntroduction-Registration??"For Compaq PC's. Should only run first time
Xipregipreg.exe"Added by the ZAGABAN-H TROJAN!"
UIr41_32.axregsvr32.exe Ir41_32.ax"Intel® Indeo® video 4.4 Decompression Filter related. The ""Ir41_32.ax"" file is located in %System%"
XJregJreg2b.exe"FlashEnhancer adware"
XKavSvc******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
Xkvern16.dllregsvr32.exe kvern16.dll"DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""kvern16.dll"" file is found in %System%"
XLoadHTML"rundll32.exe regsvr32.exeMShtmpre"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
NLogitech . Product RegistrationeReg.exe"Registration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice
YLogitechRegisterVideoApplicationsInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software
NMass storage check registry"rundll32.exe MSDServ.dll check registry"
UMaxtorRegAUTOREG.EXEPart of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
NMcRegWizmcregwiz.exeProduct registration wizard for McAfee's range of internet security tools
Xmfhsornwnduyregsvr32.exe gisyflngpshcvuakv.dll"Pro AntiSpyware 2009 rogue spyware remover - not recommended
XMicrosoft Regestry Edit Managerregedit.exe"Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
XMicrosoft Regestry Managerregedit32.exe"Added by a variant of the IRCBOT.ARD WORM!"
XMicrosoft Regestry Managerregistry32.exe"Added by the IRCBOT.ARD WORM!"
XMicrosoft Registrosvchostt.exe"Added by the BANCOS-DH TROJAN!"
XMicrosoft Registrycsrse.exe"Added by the RBOT-PC WORM!"
XMicrosoft Scanregmicrosoftscanreg.exe"Added by the FRANRIV.A WORM!"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
XMicrosoftCorpregtray.exe"Added by the POISON.AHNW BACKDOOR!"
XMicrosoftNAPCregtray.exe"Added by the POISON.AHNW BACKDOOR!"
XMicrozoft_OfizKdzEregli.exe"Added by the AMUS.A WORM!"
XMircrosoft Technic HelpRegKey.exe"Added by a variant of the SPYBOT WORM! See here"
XModule Call initialize"RUNDLL32.EXE reg.dll ondll_reg"
XMS Registry ServiceMSRMS32.exe"Added by the RBOT-AKP WORM!"
?MsmqIntCertregsvr32 /s mqrt.dll"Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?"
XMsn Messsengerregsvr.exe"Added by the AGENT-GXM TROJAN!"
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
Xmsreg.exemsrege.exe"Added by the ZINX TROJAN!"
XmsReg32 Loadermsreg32.exe"Added by the AGOBOT.IU WORM!"
XMSREGITMsgp.exe"Added by the KRYPGHOS.13 TROJAN!"
UMSRegScanSGP.exe"SpyGator surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSSDemo.exe"SupremeSpy surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanETNKL.exe"ComKeylogger surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanKSPDemo.exe"KeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanDDSSDemo.exe"SystemSleuth surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESP+.exe"ESP surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESPDemo.exe"Eye Spy Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSBPDemo.exe"SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYEKPND.exe"EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYKPND.exe"YKPMD surveillance software. Uninstall this software unless you put it there yourself"
XMSRegSvcregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
UMyRegistryCleanerMyRegistryCleaner.exe"MyRegistryCleaner from PCSecurityShield - who's reputation is poor"
XNeroCheckregedit.exe"Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD/DVD burning program. Also
XNetWINREG.EXE"Added by the ASSASIN.D TROJAN!"
XNOD32 FiXregedt32.exe"NodFix is a is a potentially unwanted application. This application is given an (X) status because we does not and will not support Cracks or Warez. Do not delete the regedt32.exe as it is the legitimate Windows application. NodFix interferes with the default settings of the NOD32 AV application allowing to bypass its free using period as well as changes the default update server to that eval signatures thus allowing to update NOD32 without password. Note - to avoid interfering with the NOD32 application original settings no full cleanup can be provided"
XNod32 Runtimesysregi.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NNuance OmniPage 17-reminderEreg.exe Ereg.ini"Registration reminder for Ominpage version 17 from Nuance"
NNuance PDF Create! 5-reminderEreg.exe Ereg.ini"Registration reminder for PDF Create version 5 from Nuance"
NNuance PDF Professional 6-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 6 from Nuance"
NNuance PDF Professional5-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 5 from Nuance"
YNvRegisterMCTray"RUNDLL32.EXE NVMCTRAY.DLLNvMCRegisterApp NvCpl.dll"
YNvRegisterMCTrayNview"RUNDLL32.EXE NVMCTRAY.DLLNvMCRegisterApp nView.dll"
YOfficeGuard RegCheckerogrc.exe"Kaspersky Labs anti-virus"
NOP12 ReminderEreg.exe ereg.ini"Registration reminder for OmniPage from Nuance (was ScanSoft)"
NOperations Typhoon Rising RegistrationNOVG.EXE"Joint Operations registration reminder"
XOPQFileregedit.exe /s ...rad03FA6.tmpUnsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
NOPSE reminderEreg.exe ereg.ini"Registration reminder for OmniPage from Nuance (was ScanSoft)"
XOptim1regdtopt.exe"Added by the RAMVICRYPE TROJAN!"
XOptim2regdtopt.exe"Added by the RAMVICRYPE TROJAN!"
XOptim3regdtopt.exe"Added by the RAMVICRYPE TROJAN!"
XOptim4regdtopt.exe"Added by the RAMVICRYPE TROJAN!"
NpalmOne Registrationregister.exe"Registration reminder for Palm products"
NPCPitstop Registration ReminderReminder.exe"Registration reminder for the Exterminate antimalware package from PC Pitstop"
XPCShieldregsvr32 sfg_****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
?PDF Converter Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 2 from Scansoft (now Nuance). what does it do and is it required?"
?PDF4 Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 4 from Scansoft (now Nuance). what does it do and is it required?"
?PDF5 Registry ControllerRegistryController.exe"Part of PDF Converter Professional and PDF Create (both version 5) - from Nuance. what does it do and is it required?"
?PDF6 Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 6 from Nuance. what does it do and is it required?"
XPopup Blocker Updaterregsvr32 veev****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPopup Defence Updaterregsvr32 pdfupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
NPowerRegeReg.exe"Registration reminder from Leader Technologies for software from Logitech
NPowerReg SchedulerPowerReg Scheduler.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerPowerReg Scheduler V3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg Scheduler V3PowerReg Scheduler V3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerV2PowerReg SchedulerV2.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerV3PowerReg SchedulerV3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
?PowerSetRegedit.exe /s ...PowerSet_8100_CU.REG"Appears to be Toshiba power management related"
NPPort10reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 10 from Scansoft (now Nuance)"
NPPort11reminderEreg.exe Ereg.ini"Registration reminder for PaperPort version 11 from Scansoft (now Nuance)"
NPPort12reminderEreg.exe Ereg.ini"Registration reminder for PaperPort version 12 from Nuance"
NPPort9reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 9 from Scansoft (now Nuance)"
?Printer UpdateCFGREG.EXE"Maybe a registration reminder or automatically updates drivers or application software for a printer?"
XPromoReg[path to worm]"Added by the WALEDAC.C WORM!"
XPromoRegalt.exe.exeAdded by a variant of the AGENT.DOM TROJAN!
XProtected StorageRUNDLL32.EXE MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRecycleSTRmsreg32.exe"Added by the RBOT-TC WORM!"
XRegReg.hta"Passon homepage hi-jacker"
?Reg Checklpt.exe"Related to Supanet ISP software - what does it do and is it required?"
Xreg runSysten.exe"Added by the BANCOS-BS TROJAN!"
XReg Servicewinsy.exe"Added by a variant of the SPYBOT WORM!"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XReg Serviceipcfg.exe"Added by the AGOBOT-SO WORM!"
XReg ServiceREGSRV32.EXE"Added by the RBOT.ZW WORM!"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XReg ServiceNT32.exe"Added by the AGOBOT.G TROJAN!"
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
Xreg1.regvuamgard.exe"Added by a variant of the IRCBOT TROJAN!"
Ureg2.0SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
XReg32Reg32.exeHijacker - redirecting to only-virgins.com
Xreg32reg32.exe"Added by the NOUPDATE.B TROJAN!"
XReg32reg33.exe"CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!"
XRegcheck~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
Xregcheck[path to file]"Added by the SERVPAM TROJAN!"
URegClean Expert SchedulerRCHelper.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
URegClean Expert SchedulerRCScheduler.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
XRegCleanerSYSio32.exe"Added by an unidentified VIRUS
XRegCompresRegcpm32.exe"Added by the POLDO.B TROJAN!"
XRegCompresREGCPM32.EXE"Added by the DASMIN-E TROJAN!"
XRegcxdinafREGCXDINAF.EXE"Added by the BANCOS-BW TROJAN!"
XRegcxmarqREGCXMARQ.EXE"Added by the BANCOS.DK TROJAN! Note that the filename has a leading space
XRegcxnRegcxn.exe"Added by the COIBOA-D TROJAN!"
Uregdefendregdefend.exe"""RegDefend is a configurable
Xregdiitwinxp.exe"Added by the RUNAUTO.F WORM!"
Xregdiitwin.exe"Added by the VBSAUTO-A WORM!"
XRegDoneservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XRegDonewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XRegDone Excsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XRegDoneExlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xregeditregedit.exe"Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in %Windir$ and will not figure in Msconfig/Startup! This version resides in %System%"
XREGEDITRegsrv32.com"Added by the SOUTHGHOST WORM!"
Xregeditautoexe.exe"Added by a variant of the RBOT WORM!"
Xregeditsvchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename"
Xregeditregedit.exe"Added by the GANBATE.A WORM! Note that the legitimate Windows registry editor (regedit.exe) is located %Windir% and will not figure in Msconfig/Startup! This one is located in %Windir%\security\Database"
XRegeditregedits.exe"Added by the BANCBAN-QV TROJAN!"
XRegEdit32RegEdit32.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
XRegedit32regedit.exeAdded by an unidentified WORM or TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%
XRegexitrunlli32.exe"Added by the QQPASS-U TROJAN!"
XRegexitUpdadv.exe"Added by the QQPASS-N TROJAN!"
XRegFreezeregfreeze.exe"RegFreeze rogue spyware remover - not recommended
Xreggsdgspoolserv.exe"Added by the SDBOT-MS WORM!"
Xreggsdgspoolsrv.exe"Added by the SDBOT-DI WORM!"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
Xreghostreghost.exe"SpyPal surveillance software. Uninstall this software unless you put it there yourself"
?reginfo32reginfo32.exe"??"
XRegister ManagerRegistryManage.exe"Added by the SDBOT.AYH WORM!"
NRegister MediaRing Talkregister.exeIf you don't want to register MediaRing and be reminded about it every bootup disable it
?Register SeqChkregsvr32.exe ..csseqchk.dll"??"
URegisterDropHandlerREGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
XRegistration Servicetoker.exe"Added by the SDBOT-BB WORM!"
XRegistration Servicemsvdm6.exe"Added by the SDBOT-HE TROJAN!"
NRegistration-Studio 8RegTool.exe"Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems"
XRegistrywscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in %Windir%"
URegistryclass0117[random].exe"Blackbox captures emails and chat logs
XRegistry CheckerRegrun.exe"Added by the SDBOT TROJAN!"
XRegistry Checkupwinreg.exeAdded by an unidentified WORM or TROJAN!
XRegistry Checkup System326a MonitorWinregs326a.exe"Added by a variant of the SDBOT WORM!"
XRegistry CleanerRegclean.exe"Registry Cleaner misleading security software - not recommended
XRegistry Integrity Checkerregintmon.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XRegistry IntegritycheckWCPDT.EXE"Added by the AGOBOT-RF WORM!"
XRegistry Loaderregloadr.exe"Added by the GAOBOT.AO WORM!"
XRegistry Loaderwinhlpp32.exe"Added by the GAOBOT.AO WORM!"
URegistry MechanicRegMech.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
URegistry Mechanic Vista TrayRMTray.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
XRegistry Monitorregmon.exe"Added by the BCKDR-QKH BACKDOOR!"
XRegistry oidetwin32.exe"Added by the RBOT.BMT WORM!"
XRegistry Protectorregprotect.exe"Added by the ARIVER.A WORM!"
XRegistry Scannerregscanr.exe"Added by a variant of the OPTIX TROJAN!"
XRegistry Servregsvr.exe"Added by the WEBMONEY-G TROJAN!"
XRegistry Serverregsrv32.exe"Added by the RBOT-GM WORM!"
XRegistry Serverregserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRegistry ServiceREGSRV32.EXE"Added by a variant of the RBOT WORM!"
XRegistry Serviceresvs.exe"Added by the DELBOT-I WORM!"
XRegistry Serviceregsvc.exe"Added by the IRCBOT-ZM BACKDOOR!"
XRegistry ServicesRegistry.exe"Added by the CILE TROJAN!"
XRegistry Startup Checkcheckreg.exe"Added by the REMLOAD-A or DANMEC-B TROJANS!"
XRegistry SystemRegsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRegistry System16 Checkup MonitorSystemReg16.exe"Added by a variant of the RBOT WORM!"
XRegistry System166 Checkup MonitorSystemReg166.exe"Added by a variant of the RBOT WORM!"
XRegistry Value Nameroses.exe"Added by the RBOT-AFT WORM!"
XRegistry Value Nameservice.exe"Added by the RBOT-AHT WORM!"
XRegistry Value Namewinapi32.exe"Added by a variant of the RBOT WORM!"
XRegistry Value Namesyswinxp.exe"Added by the RBOT.BTZWORM!"
XRegistry Value Nameenzxp.exe"Added by the RBOT-BAJ WORM!"
XRegistry Value Name StartMsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
NRegistryBoosterRegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
XRegistryCheck"rundll32.exe chkreg.dll CheckRegistry"
XRegistryChkwinbackup.exe"Added by the MERTIAN WORM!"
XRegistryCleanFixMFCregistrycleanfix.exe"RegistryCleanFix rogue registry cleaner - not recommended"
XRegistryConfigrundll.exe"Added by the AGOBOT-KN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XRegistryDoctor2008registrydoctor.exe"RegistryDoctor2008 rogue registry cleaner - not recommended
XRegistryFix.exeregistryfix.exe"RegistryFix rogue registry cleaner - not recommended
XRegistryGreat.exeRegistryGreat.exe"Registry Great rogue registry cleaner - not recommended"
URegistryMechanicRegMech.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
URegistryMechanicRMTray.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
XRegistryMonitorregistry.pif"Affilred adware"
XRegistryMonitorsysfade.exe"Added by the SYSFADE TROJAN!"
XRegistryMonitor1mljul1.exe"Added by the SPAMBOT TROJAN!"
XRegistryMonitor1qtplugin.exe"Added by the DELF-EZY TROJAN!"
XRegistryMonitor1igfxpers.exe"Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename"
XRegistryMonitor1incognito.exe"Added by the BUZUS.DAHY TROJAN!"
UREGIST~1REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
URegKillTrayRegKillTray.exe"DVD region killer part of CloneDVD from Elaborate Bytes AG. Copies the main movie
URegMechRegMech.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
XRegmonitorregmaping.exe"Added by the BEAGLE.DO WORM!"
XREGMSYS[path to file]"Added by the LOWZONE-AX TROJAN!"
XRegMutexlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XRegPowerCleanRegPowerClean.exe"Registry Power Cleaner rogue registry cleaner - not recommended"
YRegProtRegprot.exe"RegistryProt from Diamond Computer Systems - protects the system registry against changes"
XRegptmensREGPTMENS.EXE"Added by the BANCOS-ED TROJAN!"
XRegrorundll132.exe"Added by the OKARAG TROJAN!"
XRegRunmActiveX.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUN[path to trojan]"Added by the LOWZONE-AH TROJAN!"
XREGRUNregeditt.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUNsory.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUNdialer.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
URegRun WinBaitwinbait.exe"Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.."
YRegrun2WatchDog.exe"Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's
XREGRUNMautoprotect.exeAdded by an unidentified WORM or TROJAN!
XRegrxrundll32.exe"Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process
XRegscanregscanr.exe"Added by the OPTIX-SE TROJAN!"
XRegScanDLLSRV32.EXE"Added by the AGOBOT.AEW WORM!"
XRegScanRegscan.exe"Added by the TALEX TROJAN!"
?RegServerregserve.exe"Related to XGI Technology's Volari graphics cards - what does it do and is it required?"
Xregservices.exeregservices.exe"Added by an unidentified VIRUS
NRegShaveregshave.exe"Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers
Xregsrvregsrv.exe"Added by the OPTIXPRO.11 TROJAN!"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
XRegSrv64DRegSrv64D.exE"Added by the WINKO.AO WORM!"
Xregsrvcregsrvc.exe"Added by the STOPED-A TROJAN!"
XRegsvregsv.exeSearch hijacker - redirecting to scheo.com
XRegsvcregsv.exeAdded by an unidentified TROJAN!
Xregsvcsysd"Sys Detective+ spyware"
Xregsvc32regsvc32.exeHomepage hijacker that changes your homepage to an adult content site
Xregsvrregsvr.exe"Added by the WEBMONEY-G TROJAN!"
UREGSVR32regsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
XRegSvr32msmsgs.exe"Added by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
Xregsyncregsync.exe"SafeSurfing adware"
?regtmlpN/A"??"
URegTweakRegTwk.exe"Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options
URegUpdatesb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XRegVerREGVER.EXE"Added by the LATINUS.16 TROJAN!"
XRegVfy32Regverif32.exe"Added by the SYGYP.A WORM!"
XRegWritecsrss.exe"Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
YRegx10EXEATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
Xreg_keyFUKULAMER.exe"Added by the BEAGLE.AH WORM!"
Xreg_keyloader_name.exe"Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!"
XReg_WFTRegsysw.com"Added by the WILSEF VIRUS!"
XReg_WFTscanreg32.com"Added by the SENNASPY-F TROJAN!"
XReg_WFTRegsysw.exe"Added by the WILSEF.A WORM!"
Nreminder-ScanSoft Product Registrationremind32.exeRegistration reminder for ScanSoft products such as PaperPort
XRemote Procedure Call LocatorRUNDLL32.EXE reg678.dll ondll_reg"Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Urmoc3260.dll OCXregsvr32.exe rmoc3260.dll"A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The ""rmoc3260.dll"" file is found in %System%"
URun Nintendo Wi-Fi USB Connector Registration ToolNintendoWFCReg.exe"Related to Wi-Fi USB Connector from Nintendo"
Xrun=RegistryReminder.exe"Added by the APSTROJAN.OB TROJAN!"
Xrun=dllreg.exe"Added by the DUMARU-L TROJAN!"
NSAClientRegCon.exe"AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected
XSafeGuard Popup Blocker Updaterregsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Blocker Updater (required)regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XScan Registerssms.exe"Added by the RBOT-AT WORM!"
XScanreg[filename]"Added by the QQPASS.E TROJAN!"
XScanRegistrynsrvnt.exe"Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe"
XScanRegistryscanregv.exe"Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe"
YScanRegistryScanregw.exeScans the Win98/Me system registry and makes back-ups at start-up - important should the registry become corrupt. Located in %windir%
XScanRegistryScanregw.exe"Added by the STATOR WORM! Note - this is not legitimate ScanRegistry entry - which is a vital Windows file. The executable ""Scanregw.exe"" is located in %System%. Runs from the registry RunServices key as opposed to the Run key"
XScanRegistryN/A"Added by the DINOXI or DINOXI.B WORMS!"
XScanRegistryscanregw.exe"Added by the NYXEM-D WORM! Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in %System%"
XScanRegistryupdate.exe"Added by the DWNLDR-FZY TROJAN!"
NScanSoft OmniPage SE 4.0-reminderEreg.exe ereg.ini"Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance)"
NScanSoft PaperPort 7 Registration ReminderNAVBrowser.EXE"Registration reminder for PaperPort 7 from Scansoft (now Nuance)"
NScanSoft PDF Professional 4-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 4 from Scansoft (now Nuance)"
XSecure64Regedit32.com StartUp"Added by the BRONTOK-CJ WORM!"
NSecureClean4RegManagerscregmanager4.exe"WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data
XServer Registryregscr32.exe"Added by the BIFROSE-ZB TROJAN!"
XServer Registryregsrv32.exe"Added by the VB-EJD TROJAN!"
XService Registry NT Savejdbgmgrnt.exe"Added by the BANCOS-CG TROJAN!"
XService Registry NT Savetaskmgrnt.exe"Added by the BANCOS-BY TROJAN!"
XService Registry NT Saveregeditnt.exe"Added by the BANCOS-BM TROJAN!"
Xsetupuserregedit.exe setupuser.log"Regfile in disguise - another CoolWebSearch parasite variant"
XSolutionRegSysRep.exe"SolutionReg rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
NSonnRegSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
XSOProc_RegSoAlertWxLiteNnAj"rundll32 shell32.dll ShellExec_RunDLL [path] soproc.exe"
NSourcePathgwreg.exeUsed to update Gateway registry settings for System Restoration Kit and Web update programs
Xspsp.regIE search hijacker - changes the default search to http://www.gocybersearch.com/
Xspregedit-s .... sp.dll"Malicious javascript annoyance that changes the default search engine in IE to one of many including ""topsearcher"". See here for more and a fix"
NSpeed racerCTSRReg.exeSoftware for a Creative sound card
Xsppregedit -s spp.reg"IE search hijacker - changes the default search to h**p://www.hotsearchbox.com/ie/. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""spp.reg"" is located in the root folder (ie
USpyware Guard Control Panelspywareguardcp.exe"""SpywareGuard provides a real-time protection solution against spyware"""
YSpywareGuardsgmain.exe"""SpywareGuard provides a real-time protection solution against spyware"""
XSpywareGuardwinproc32.exe"Startpage adware Trojan"
XSpywareGuarddeinst_qfe001.exe"Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
Xspywareguardspywareguard.exe"Spyware Guard 2008 rogue spyware remover - not recommended
XSpywareguard lptt01Spywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareguard ml097eSpywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareGuardPluswinmm64.exeStartPage.ht homepage hijacker
Xsupdate2.dllregsvr32.exe /s supdate2.dll"Added by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""supdate2.dll"" file is found in %System%"
XSvcsys Registry Managersvcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
XSymantec Antivirus professionalregedit.exe"Added by a variant of the FORBOT WORM! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
Xsysregedit /s sys.reg"Raxmus adware. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
Xsysregedit sysdllwm.reg"CoolWebSearch parasite variant - also detected as the FEMAD-L TROJAN!"
XSysRegSysReg.exe"Added by the CHEKIN TROJAN!"
XSysRegSysReg.exe"SearchSeekFind textual marketing foistware"
XSysSearchRegedit.exe -s pcsearch.reg"Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""pcsearch.reg"" file is located in %Windir%"
XSysSearchRegedit.exe -s sysreg.reg"Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""sysreg.reg"" file is located in %Windir%"
Xsystemregedit -s system.dllHomepage hijacker
NSystem Mechanic Professional Update [Incinerator.dll]SysMech4.exe /REREG: [path] Incinerator.dll"Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
XSystem ProfileRegsrv.exe"Added by a variant of the OPTIX TROJAN!"
XSystem Registry Managersysrgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
?SystemRegPROCES.EXE"??"
XSystemRegsvchost.exe"Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemRegWINREG.EXE"Added by the DEWIN.A TROJAN!"
XSystemSearchregedit.exe -s ie.reg"Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""ie.reg"" is located in the root folder (ie
XSystemSearchregedit.exe -s sys.reg"Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
XTask Commanderregsvc32.exe"Added by the AGOBOT-RX WORM!"
XTaskReg[random filename]"Added by the CBLAD WORM!"
?TExBUtil RegistryTExBUtil.exe"??"
XThe Registry SentinelThe Registry Sentinel.exe"The Registry Sentinel rogue security software - not recommended
NToshiba RegistrationToshibaRegistration.exeToshiba Registration - available via Start -> Programs
Ntourregedit ..tour.regEdits registry values to keep the WinMe tour in Task Scheduler
Ntourpathregedit /s [path] tour.reg"Edits registry values to keep the Win 2000 ""tour"" in Task Scheduler"
Xtsxregedlt.exe"Added by the SDBOT-KA BACKDOOR! Note the lower case ""L"" in place of the lower case ""I"" in the command"
?TypeRegCheckerTypeRegChecker.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
NUniblue Registry BoosterRegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
NUniblue RegistryBooster 2RegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
NUniblue RegistryBooster 2009RegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
Xuninstalregsvr32 image.dll"CoolWebSearch parasite variant. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""image.dll"" file is found in %System%"
NUpdRegUpdreg.exeReminder to register Creative Labs SoundBlaster Live! cards
NUsrobotics Online Registration??Pop-up reminding customers to register their products online at US Robotics
NUSSShRegUSSSHREG.EXERegistration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
Xvern16.dllregsvr32.exe vernn16.dll"DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""vernn16.dll"" file is found in %System%"
XVFW Encoder/Decoder SettingsRUNDLL32.exe MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XVideo DriverMsregdrv32.exe"Added by the SPIGOT BACKDOOR!"
YVOBRegCheckVOBRegCheck.exe"Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
Xvuaaareg.exe"Added by a variant of the RBOT WORM!"
NWarReg_PopUpWarReg_PopUp.exeAcer warranty registration popup
Xwinregedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
Xwin32 regeditmsn32.exeAdded by an unidentified WORM or TROJAN!
XWindowRegKey updatewins.exe"Added by the SPYBOT.I WORM!"
XWindows Media Playervmmreg32.exe"Added by the AGENT.AQO TROJAN!"
XWindows Reg Servicesffservice.exe"Added by the DLOADER-PL or DLOADER-XM TROJANS!"
XWindows Reg Servicesdservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesfservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesssservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Serviceslncom.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceslservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceswservice.exe"Added by the PRORAT-O TROJAN!"
XWINDOWS REGISTER EDITregistr32.exeAdded by an unidentified WORM or TROJAN!
XWindows Register Settingssvmhost.exe"Added by a variant of the FORBOT WORM!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Registrymsnmsg.exe"Added by a variant of the RBOT WORM!"
XWindows Registrywinhost.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Cleanerwinclean.exe"Added by a variant of the SPYBOT WORM!"
XWindows Registry Controlwinreg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Registry DLLwinregdll.exe"Added by the IRCBOT.FB BACKDOOR!"
XWindows Registry Express Loaderregexpress.exe"Added by the FORBOT-CJ WORM!"
XWindows Registry Managertasksmanagers.exe"Added by the MYTOB.ER WORM!"
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Registry Namewinses.exe"Added by the RBOT-ADB WORM!"
UWindows Registry Repair ProRegistryRepairPro.exe"Registry Repair Pro. ""Scans the Windows Registry for invalid or obsolete information in the registry"""
XWindows Registry Scanregscan32.exe"Added by the RBOT.KE WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Registry Scansvcdll.exe"Added by the RBOT-TP WORM!"
XWindows Registry Scanregscan23.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Scanregscan.exe"Added by the RBOT-HA WORM!"
XWindows Registry Scanwinmedia.exe"Added by the SPYBOT.GK WORM!"
XWindows Registry Securitycrss.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Registry Servicesregserv.exe"Added by the SLENFBOT.BB WORM!"
XWindows Registry Startupwind32.exe"Added by the AGOBOT-BZ WORM!"
XWindows Registry XPwinxptdl.exe"Added by the IRCBOT.AUN WORM!"
XWindows Services Agantregs32.exe"Added by the SDBOT-DIK WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey upd4te2d4te*********.exe [* = random char]"Added by the RBOT.XQ WORM!"
XWindowsRegKey updatewinupdate.exe"Added by the RBOT-QJ WORM!"
XWindowsRegKey updatewindns.exe"Added by the RBOT.IE WORM!"
XWindowsRegKey updatewinupdatexx.exe"Added by the RBOT.LW WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsRegKey updatesvchostc.exe"Added by the RBOT.IF WORM!"
XWindowsRegKey updatewdnupdate.exe"Added by the SDBOT.QX WORM!"
XWindowsRegKey updateWindowsup.exe"Added by the SDBOT.PU WORM!"
XWindowsRegKey updateWINUPDATES.EXE"Added by the RBOT-MM WORM!"
XWindowsRegKey updaterkbuouoxfl.exe"Added by the RBOT-OO WORM!"
XWindowsRegKey updatewinsys.exe"Added by the RBOT-JY WORM!"
XWindowsRegKey updatewinupdat32.exe"Added by the RBOT-AGW WORM!"
XWindowsRegKey update XPwindexv1.exe"Added by the RBOT-ABM WORM!"
XWindowsRegKey%$ updatemsi332.exe"Added by the RBOT-IX WORM!"
XWindowsRegKey%updateethernet32m.exe"Added by the RBOT-EN WORM!"
XWindowsRegKeys updatewinsysi.exe"Added by the SDBOT.WE WORM!"
XWindowsUpdateRregserv.exe"Added by the COBFINN_B TROJAN!"
XWindows_Protectwinregal.exe"Added by a variant of the RBOT WORM!"
Xwininet.dllregperf.exe"Added by the ZLOB TROJAN and variants!"
Xwinlogonmsreg32.exe"Added by the SDBOT.EO WORM!"
XwinRegwinReg.exe"Added by the YAHA.H or YAHA.J WORMS!"
XWinRegournik.com"Added by the IRCFLOOD.AL BACKDOOR!"
XWinReg32 serviceholqdnoxpmeu.exe"Added by a variant of the SDBOT WORM!"
Xwinregsrvwinregsrv.exe"Added by the SYNRG TROJAN!"
Xwinreg_32svchosst.exe"Added by the BANCOS-CE TROJAN!"
Xwinreg_32[path to trojan]"Added by the BANKER-DB TROJAN!"
Xwinreg_32sysdll.exe"Added by the DLOADER-IJ TROJAN!"
Xwinreg_32Vc030405.exe"Added by the BANCOS-CT TROJAN!"
XWinSP[path] REGEDIT.EXE -s [path] sysreg.reg"Added by the STARTPA-ME TROJAN!"
Xwinsync******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
Xwinupdate.regwinupdate.exe"Added by the SPYBOT.EAS WORM!"
NWMC_RebootCheckunregmp2.exe"Corrects problems with installations of Windows Media Player from version 9 onwards - see here and search for ""unregmp2.exe"""
NWordPerfect Office 1215Registration.exe"Corel WordPerfect Office 12 registration wizard"
?WregBioswregbios.exe"Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?"
?WUx_RegSvrRegSvr32.exe"x is any number??"
NXeroxRegistationEReg.exeRegistration reminder from Leader Technologies for software from Xerox
XYahoo Messenggerregsvr.exe"Added by the IMAUT.CN WORM!"
XZstartcxdxregt.exe"ZenoSearch adware"
X[executed file name]Regsrv32.com"Added by the SOUTHGHOST WORM!"
X[random name]??anregw.exe"PurityScan adware"
X[random name]scanregw.exe"PurityScan adware. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines"
X[random name]regedit.exe"PurityScan adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup!"
X{**-**-**-**-**}mrdsregp.exe"Zenosearch adware
X{1C-CC-C5-54-ZN}dwdsregt.exe"ZenoSearch adware"
X{2F-FF-F4-4C-ZN}omdsregk.exe"ZenoSearch adware"
X{8C-C4-4A-A4-ZN}dwdsregt.exe"ZenoSearch adware"
X{B7-7D-D0-08-ZN}dwdsregt.exe"Added by the AGENT-GBC TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.