Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
UAbyssWebServerabyssws.exe"Abyss web server"
?AeXSWDUsrAeXSWDUsr.exe"Altiris Express NS Client Manager software. Is it required?"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool
NASUSWebStorageASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NAsusWSDashBoardASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NASWDPASWDP.exe"MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market"
XASWnkaswnk.exeAdult content dialler
UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
NAutoSpell 5ASWATC32.EXE"AutoSpell - spell checker"
UBackgroundSwitcherbgswitch.exe"Originally included with Microsoft's XP PowerToys (but now withdrawn - see here
UBackgroundSwitcherBackgroundSwitcher.exe"John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
UBayswapbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
Xbdfgergggasw.exe"Added by the SDBOT-RT WORM!"
YBDSwitchAgentbdswitch.exe"Bitdefender 8 antivirus and firewall"
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
UBiomenumenusw.exe"Related to Sony VAIO - passwords
XBONZI Task SwitcherTaskswitch.exe"Added by the SPYBOT.DTR WORM!"
Xbuohxqtfswbgcjydr.exe"Added by the AGENT-NRC TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Xcleansweep.execleansweep.exe"Added by the AGENT-NEU TROJAN!"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
UCoolSwitchtaskswitch.exeALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
XCSRSSWCSRSSW.EXE"Added by the CWS-F TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
UDialgo SDKPhoneAnswer.exe"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID
NDigitalWizardISWizard.exe"InstallShield's DigitalWizard - free
Ydlatfswctrl.exe"Drive letter access to a UDF packet writer for CD-RW - from HP
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
Xemsw.exeemsw.exe"Attune HelpExpress - spyware. Disable and uninstall - see here"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFlyswatDesktopflydesk.exeAdvertising spyware
YFoolProofSweep??"Part of FoolProof Security PC security software from SmartStuff"
XFSWFSW.exe"FreeScratchAndWin parasite"
UFSWebServerfsws.exe"Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XHDriveSweeperHDriveSweeper.exe"HDriveSweeper rogue privacy program - not recommended
XHELPERsweden.exe"AsdPlug premium rate adult content dialer variant"
YIBM Password Managerpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
?IBMUltraBayHotSwapSoundIBMBAYSN.EXE"Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
UInternet Answering MachineIAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
NInternet SweeperSweeper.exe"Internet Sweeper - removes unnecessart left over files after browsing the internet"
UISW.exeISW.exe"Related to Internet Security Wizard from AT&T (formerly BellSouth Premium Internet Security) alerts users about any potential security threats. It should not be uninstalled unless the user wants to completely remove all traces of AT&T Internet Security Suite"
Xload32swchost.exe"Added by the TURTA.A WORM!"
Xmachine-debuggerWMIPRVSW.exe"Added by the AGOBOT.WW WORM!"
UMalware SweeperMalSwep.exe"Malware Sweeper - ""Protects the user from malicious malware and monitors the sanity of the running programs"""
XMalwaresWipedsMalwareWipeds.exe"MalwareWipe rogue security software variant - not recommended
NMania Win RestoreRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
XMasterBoot Switchpopupkill.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft Security Monitor Processmsword.exe"Added by the VIRUT.P VIRUS!"
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
XMicrosoft Updat3mswkst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatingsyswr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft WMmswm32.exe"Added by the BCKDR-AM BACKDOOR!"
XMicrosoft WxdateSyswu32.exe"Added by the SPYBOT.HZ WORM!"
Xmmxrunmswinindex.exe"TwoSeven spyware"
Xmobiswing[random].exe"Mobis adware"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Domain Name SystemMSWDNS32.exe"Added by the RBOT-GKY WORM!"
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
XMS Sys Securitymswin.pif"Added by the RBOT-APJ WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMS Windows Local DirectoryMSWLD32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS Winsockmsws2_32.exe"Added by the AKBOT-A TROJAN!"
?MSLIB32mswatch32.exe"??"
NMSN Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSNavWHMSWkwrH.exe"Added by the ANAV-A WORM!"
XMSNMSGREswef.batIRC backdoor TROJAN or WORM!
XMSNMSGRRswin.batIRC backdoor TROJAN or WORM!
XMSNMSGRSswe.batIRC worm or backdoor trojan!
XMSNMSGRSswiss.batIRC worm or backdoor trojan!
XMSNMSGRS1swed.batIRC backdoor TROJAN or WORM!
NMSN® Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
Xmswavemswave.exe"Added by the CRYPTER.A TROJAN!"
XMswavedllmswavedll.exe"Added by the CRYPTER-C TROJAN!"
UMSwheelmswheel.exeMicrosoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Xmswiiz32mswiiz32.exe"Added by the STRATION.DH WORM!"
Xmswiizz32mswiizz32.exe"Added by the STRATION.DL WORM!"
XMSWinmswin.exe"Added by the BANKER-CU TROJAN!"
XMswincfgMswincfg32.exe"Added by the CYBRSPY.D TROJAN!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMSWindows Syspgmspg32.exe"Added by the RBOT-TB WORM!"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
Nmswinextmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSWinlogonSynCor.exe"Added by the AGENT-FZL TROJAN!"
XMSWinlogonwinlogon.exe"Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMswinpid32mswinpid32.exeAdded by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
XMSWinupdwinupd.exe"Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMsWinVgrmsvgr.exe"Added by the MYTOB.LE WORM!"
Xmswiz32mswiz32.exe"Added by the STRATIO-BG WORM!"
Xmswkork Servicemsework.exe"Added by a variant of the RBOT WORM!"
Xmswordmsword.exe"Added by the RBOT-ADR WORM!"
Xmsworddocx.exe"Added by the CODOX-A WORM!"
Xmsword98msword98.exe"Added by the AGENT-KUO TROJAN!"
XMSWorldmsworld.exe"Added by the AGENT.DED TROJAN!"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
Xmswsplsearchbarcash.exeSearchBarCash adware
Xmswsplvnmispoisn downloader.exeSearchBarCash adware variant
Xmswsplplugin1.exe"Added by the SMALL.IQ TROJAN!"
XMSWTL32MSATL32.exe"Added by an unidentified WORM or TROJAN! See here"
XMSWUpdate[path to worm]"Added by the SILLYFD-V WORM! The most common filename is lsass.exe but it not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xmvsyswinaacsysiom.exe"Added by a variant of the SDBOT WORM!"
Umynswwntsrv.exe"Net Screen Watcher surveillance software. Uninstall this software unless you put it there yourself"
XName Servermswins.exe"Added by a variant of the SDBOT WORM!"
YNCSW ServerNcsW.exe"LockLink access control management software. LockLink 7.0 lets users seamlessly manage both offline and online access control solutions available from IR Security & Safety"
UNet4SwitchNet4Switch.exe"ASUS Net4Switch utility as provided on their range of notebooks - which ""helps users to quickly configure the notebook PC's network settings and easily switch between different network environments. A wizard guides users to create and edit configuration settings as well as diagnose problems in the settings for timely connection"""
UNetWork Device SwitchNetDevSW.exeToshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
XNorton SpySweeper AutoUpdatenavsw.exe"Added by the FORBOT-AS WORM!"
XNvClipRsvswchost.exe"Added by the DUMARU-AK WORM!"
Xorder_Shellorder_glsw.exe"Added by the DLOADR-KO TROJAN!"
XOS Securitymswind32.pif"Added by the RBOT-ASU WORM!"
UPassword Door LoaderPDMonitor.exe"Password Door - password protection software"
UPassword Tracker DeluxePwTrkr.exe"""Password Tracker Deluxe stores passwords and usernames neatly and securely (encrypted) on your computer"""
Xpestsweeperpestsweeper.exe"PestSweeper rogue security software - not recommended
NpictureBUZZTrayswtray.exe"System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually"
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
UPowerUp SwitchDeskSwitchDesk.exe"PowerUp SwitchDesk - virtual desktop manager which allows ""you have the possibility to launch games
UPSwitchProxySwitcher.exe"""Proxy Switcher offers full featured connection management solution"" as different internet connections often require completely different proxy server settings and it's a real pain to change them manually"
UPwrUpSwDeskSwitchDesk.exe"PowerUp SwitchDesk - virtual desktop manager which allows ""you have the possibility to launch games
Xqaswwwjdsuml.exe"Added by the BUZUS.CQMU TROJAN!"
YQCDriverInstallerLqdsw.exe"Launches the camera driver setup wizard on the first reboot after installing Logitech's ClickSmart
UQT4StBtnSwiftBtn.EXE"SwiftBtn - installed alongside the system drivers on Fujitsu Siemens notebooks and allows extra keyboard support"
UQuickPasswordagquickp.exeSmart card-based authentication and digital signature client software
URed Swoosh EDN ClientRSEDNClient.exe"Red_Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other
XRegistry Value Namesyswinxp.exe"Added by the RBOT.BTZWORM!"
XReg_WFTRegsysw.com"Added by the WILSEF VIRUS!"
XReg_WFTRegsysw.exe"Added by the WILSEF.A WORM!"
XRemote Access Domainrswsvc.exe"Added by the IRCBOT.BFA TROJAN!"
XRemote Procedure Callsmswinrpc.exe"Added by the RBOT.KJ WORM!"
XRemote Procedure Callsmswinc.exe"Added by the RBOT-IT WORM!"
XRsWinlsass.exe"Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""12053"" subfolder"
XRsWinlsass.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""4350"" subfolder"
Xrtkernsw[random filename]"Added by a variant of the SLAPER TROJAN!"
Yrun=wswpd.exe"Used with some models of Panasonic
URupsw32Rupsw32.exe"MegaTec Rups
XsetFTPBackcreatesw.exe"Added by the FTP_BMAIL TROJAN!"
XSettingsysweb.exe"Added by the SDBOT.GEN TROJAN!"
NShockwave InitSWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
NSideWinderTrayV4SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
USiSSWLEDsisswled.exeSystem Tray utility for SiS 900 network cards
USolidWorks Task Scheduler EngineswBOEngine.exe"Task scheduler for SolidWorks 3D CAD software"
USpeedswitchXPSpeedswitchXP.exe"SpeedswitchXP is a CPU frequency control for notebooks running Windows XP"
USpySweeperSpySweeper.exe"Spy Sweeper - detects and removes spyware"
USpySweeperSpySweeperUI.exe"Spy Sweeper - detects and removes spyware"
USpySweeperEnterpriseSpySweeperUI.exe"User interface for Spy Sweeper Enterprise edition - ""a centrally managed
YSpyware Doctorswdoctor.exe"Older version of Spyware Doctor antispyware from PC Tools"
USpyware Nukerswn2.exe"Spyware remover by TrekBlue. Previously not recommended but the latest version was delisted here"
XSpyware SweeperSpywareSweeper.exe"SpywareSweeper rogue spyware remover - not recommended"
XSpywareSweeperSpywareSweeper.exe"SpywareSweeper rogue spyware remover - not recommended"
XSpywareSweeperProMFCSpyware Sweeper Pro.exe"Spyware Sweeper Pro rogue security software - not recommended
XSSWPlaunchercomet.exe"Comet Cursor adware"
Xsussehpsw.exe"LinkMaker adware"
Xsvchost.exeswchost.exe"Added by the SADELPHI-A TROJAN!"
XSWSpyOnThis.exe"SpyOnThis rogue spyware remover - not recommended"
USW20sw20.exe"Related to MSI's Dynamic Overclocking Technology"
USW24sw24.exe"Related to MSI's Dynamic Overclocking Technology"
YswAgentexeSWAGENT.EXEPart of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses
NSwap Nutjavaw.exe"javaw.exe can be loaded by other programs at startup but in this instance it's SwapNut
XSWCallerSWcaller.exe"Swporta homepage hijacker"
XSWCallerSwcaller2.exe"Swporta homepage hijacker"
XSwchostSwhost.exe"Added by the BDOOR-MP BACKDOOR!"
USWClientswsys.exe"ActivMonAgent keyboard logger/monitoring program - remove unless you installed it yourself"
USWClientswclient.exe"Stealth Watcher surveillance software. Uninstall this software unless you put it there yourself"
Xswcrootswcroot.exe"Added by the SOLENO-A TROJAN!"
USWdwinwd.exe"PC Security™ from Tropical Software - ""is the ultimate in computer security
YSweep95ICLOAD95.EXE"Part of Sophos ant-virus sofware"
NSweetIMSweetIM.exe"vSweetIM - send fancier smiley-faces and IM graphics to friends who are using MSN Messenger. They are only able to see these advanced smiley-faces if they also have SweetIM installed"
XSwf32AVupdate.exe"Added by the MERKUR.E WORM!"
XSwf32_backup.exe"Added by the SYMTEN WORM!"
UswgGoogleToolbarNotifier.exe"Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
XSwiftCleanerSwiftCleanerScanner.exe"SwiftCleaner rogue cleaning utility - not recommended
XSwimSuitNetworkSwimSuitNetwork.exeAdvertising spyware
XswingsysSWINGSYS.EXE"Added by the BANCOS-CX TROJAN!"
USwitch Offswoff.exe"Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer
NSwitchboard.com ToolbarAtHoc.exe"Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com"
USwitchDeskSwitchDesk.exe"PowerUp SwitchDesk - virtual desktop manager which allows ""you have the possibility to launch games
USwitcherSwitcher.exe"""On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN
Xswitpswitpa.exe"OfferAgent adware"
USWLrundll32.exe [path] SWL.dll rdl"StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
USWN2swnxt.exe"Spyware remover by TrekBlue. Previously not recommended but the latest version was delisted here"
Xsws.exe[random filename]"Haldex type adult content dialler"
Xsws.exegd-dial.exe"Globaldialer adult content premium rate dialer"
NSwTraySWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
NSWTrayV4SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
USwyxIt!SwyxIt!.exe"PC Based soft phone from Swyx - see here for more details"
XSysDesktopfswanQQ.exe"Added by the QQSEND-A TROJAN!"
XSysStartsyswin.exe 1"Added by the AUTORUN-EY WORM!"
XSystem Updater Processwmiprvsw.exe"Added by the AGOBOT-IL WORM!"
XSystem Updater Servicewmiprvsw.exe"Added by the GAOBOT.AFC WORM!"
USysW8csta.exe"Clean Space internet evidence eliminator"
USYSWB6SYSWB6.exe"Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content
XSysWinSysWin.exe"Added by the IRCCONTACT TROJAN!"
Xsyswinv6.exe"Added by the AGENT-ECM TROJAN!"
Xsyswin.txt[3 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
Xsyswin32syswin32.exe"Added by a variant of the SPYBOT WORM!"
XSyswindowSyswindow.exe"Added by the COW TROJAN!"
XSysWyrundll32.exe"Added by the LINEAGE-JH TROJAN! Note - this is not the legitimate rundll32.exe process
Utaskswitchtaskswitch.exeALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
UTaskSwitchXPTaskSwitchXP.exe"""TaskSwitchXP from NTWind Software. Advanced task management utility that picks up where the standard Windows Alt Tab switcher leaves off. It provides the same functionality
Ytfswctrltfswctrl.exe"Drive letter access to a UDF packet writer for CD-RW - from HP
Ytfswctrl.exetfswctrl.exe"Drive letter access to a UDF packet writer for CD-RW - from HP
Xtracesweepertracesweeper.exe"Trace Sweeper rogue privacy tool - not recommended"
?Update for WorksMSWkstz.exe"Maybe related to later versions of MS Works?"
XUpdate Run MSwordLOGON.EXE"Added by the RBOT.TY WORM!"
XUpdate ver 1.0Swap.exe"Added by the SWAP-C WORM!"
Xusrgtway.exesyswrun4x.exe"Added by the MITGLIEDER.E TROJAN!"
XVirus SweeperVSweep.exe"Virus Sweeper rogue security software - not recommended
?WFXSwtchWFXSWTCH.exe"Related to WinFax. What does it do and is it required?"
XWin Securitymsw32.pif"Added by the RBOT-AQT WORM!"
XWin32 NDISNdiswin.exe"Added by the RBOT.AMG WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
XWinbinswchost.exe"Added by the RBOT.CLS WORM!"
XWind Securitymswi32.pif"Added by the RBOT-ARH WORM!"
XWindows DOSdosw.exe"Added by the SALAY-A WORM!"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
XWindows reportswchost.exe"Added by the SMALL-BD TROJAN!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWINDOWS SYSTEMmswins.exe"Added by the MYTOB.DP WORM!"
XWindows System Trayswhost.exe"Added by an unidentified VIRUS
XWindows UDP Control Centermswinudpmgr32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindowsFYbsw.exe"Added by a variant of the DESKTOPHIJACK TROJAN! For removal see here"
NWindowsWelcomeCenter"rundll32.exe oobefldr.dllShowWelcomeCenter"
XWinFix servicersswjzgp.exe"Added by the RBOT-FAE WORM!"
XWinSysW371662L.exe"Added by the WINKO.AO WORM!"
UWireless Switching Setting UtilitySwitcher.exe"On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN
XWorking System Analyzersyswork.exe"Added by the FORBOT-FZ WORM!"
Ywswpdwswpd.exe"Used with some models of Panasonic
Xws_dssws32.exe"Added by the DELF-GZ TROJAN!"
NX-Grabbersswizard.exe"ScreenShot Wizard"
Xxswdmse[8 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
Nxswinxswin.exe"Installed with a Xerox Work Centre Pro 555. Unchecking it removes an ""out of system memory"" error"
YZENworks Imaging ServiceZISWin.exe"Imaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management""
XZtgServerSwitchserver.vbsZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware
X[various names]PasswdMon.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]ssweeper.exe"Wareout - malware masquerading as a spyware and dialer remover"
X{42562052-EE17-4197-82C7-91CB2E4B0666}sysrswva.exe"Added by the FAKEALERT-AH TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.