Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(*)Runwin32API.exe"Homepage hijacker
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
Xautowin32.exe"Added by an unidentified TROJAN! See here"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XLoadwin32.exe"Added by the RUBBLE-A WORM!"
Xload=win32exec.exe"Added by the BITTER WORM!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XmcafeeWin32.dll.vbs"Added by the CATCHER-B WORM!"
XMicrosoftwin32.exe"Added by the DARKMOON TROJAN!"
XMicrosoft Network Daemon for Win32Netd32.exe"Added by the SDBOT.R TROJAN!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Standard Executions Librarywin32lib.exe"Added by the RBOT-AUK WORM!"
XMicrosoft Updatewin32.exe"Added by a variant of the SDBOT WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Update Win32xwinupdate32x.exe"Added by the RBOT-AJN WORM!"
XMicrosoft WIN32 DOSMSdos32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WIN32 SecurityMSsec32.exe"Added by the RBOT-DOQ TROJAN!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft32win32sys.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftkeysdsystemwin32s.exe"Added by the WOOTBOT.CO WORM!"
XMicrosoftNetwork Daemon for Win32NETD32.EXE"Added by the RANDEX.F WORM!"
XMismowin32x.exe"Added by the RBOT-JP WORM!"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMS Unix Binarywin32ttb.exe"Added by the SPYBOT.OQ WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
XMS_NETD_WIN32netd32.EXE"Added by the RANDEX.F WORM!"
XNod32 ServiceAutoUpdateWin32.exe"Added by the SDBOT-DJG WORM!"
Xnvc Win32nvcvc.exe"Added by the RBOT-ADD WORM!"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XRandomWin32mgnwin32.exe"Added by the SDBOT-DV WORM!"
XRegistry oidetwin32.exe"Added by the RBOT.BMT WORM!"
Xrpc Win32shost32.exe"Added by the RBOT-ABL WORM!"
Xrpc Win32spoolscv.exe"Added by a variant of the RBOT WORM!"
Xrpcda Win32rpcda.exe"Added by the RBOT-AEE WORM!"
Xrunwin32runwin32.exe"Added by the ESEARCH-A TROJAN!"
XRUNWIN32runwin32.exe"Added by the VB-AET TROJAN!"
XServices32 Startupwin32dll.exe"Added by the SDBOT-XO WORM!"
XShellWin32.dll.exe"Added by the VB.BTX TROJAN!"
NSM56 Helper Win32 Utilitysm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSMSERIALSTARTERwin32st.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
Xstartkeywin32i.exe"Added by the BIFROSE-R TROJAN!"
Xsvwin32unninst32.exe"Added by the AGOBOT-NF WORM!"
XSygate Personal FirewallWin32x.exe"Added by the RBOT-KZ WORM!"
XSysctrlswin32dll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsyswin32syswin32.exe"Added by a variant of the SPYBOT WORM!"
XTask Manager Win32taskmngr32.exe"Added by the RANCK-EX BACKDOOR!"
XUSB Devicewin32usb.exe"Added by the FORBOT-BQ WORM!"
XVIEW POINT DRIVERS FOR WIN32phqghu.exe"Added by a variant of the RBOT WORM!"
YVshwin32EXEVSHWIN32.EXEFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
XWEB DRIVERS FOR WIN32phqgh.exe"Added by a variant of the RBOT WORM!"
XWIN32WIN32.EXE"Added by the RATEGA TROJAN!"
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
Xwin32Setup_32.exe"Added by the EVILBOT.B TROJAN!"
XWin32Win32.exe"Added by the ISRAZ.A WORM!"
Xwin32winsrv32.exe"Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites"
Xwin32WinSetup.exe"Added by the EVILBOT.B TROJAN!"
XWin32system32.vbs"Added by the SWERUN VIRUS!"
XWin32Game.exe.vbs"Added by the SCAFENE WORM!"
XWin32arsetup.exeAdded by the SPAZBOX.A TROJAN!
Xwin32winhost.exe"Added by the BROPIA.J WORM!"
XWin32winnnit.exe"Added by a variant of the SDBOT WORM!"
XWin32msnsrv.exe"Added by a variant of the SDBOT WORM!"
XWin32sysmon.exe"Added by the MYTOB-HQ TROJAN!"
XWin32zaq.exe"Added by the RBOT-GCE WORM!"
XWin32 BiosWinbios.exe"Added by the SEMAPI-A WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 Configurationvideosd32.exe"Added by the SDBOT.TT WORM!"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 Configurationmplayer.exe"Added by the FORBOT-BZ WORM!"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWin32 Critical FileWin32.exe"Added by the RBOT-GUB WORM!"
XWIN32 DDOSSERdos.exe"Added by the KELVIR.F WORM!"
XWin32 Debug ManagerWin32Debug.exe"Added by a variant of the WOOTBOT WORM!"
XWin32 Debug Managermicrosoftupd.exe"Added by the RBOT-GRJ WORM!"
XWin32 Device LoaderWin32ldr.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Driversysmls.exe"Added by the MYTOB.JH WORM!"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWin32 DRK Driverwdrk32.exe"Added by the WOOTBOT.CY WORM!"
XWin32 exe filewinstr32.exe"Added by a variant of the SPYBOT WORM!"
XWin32 ExplorerExplorer32.exe"StartPa-MN homepage hijacker"
XWin32 Firewall Driverwinfw.exe"Added by a variant of the RBOT WORM!"
XWin32 Firewall Driverswinfirewall.exe"Added by the WOOTBOT.GX WORM!"
XWin32 FireWire DriverCTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
XWin32 FRT Drivermsfr32.exe"Added by the WOOTBOT.EJ WORM!"
XWin32 Help32 Servicewin32help.exe"Added by the DELBOT-U WORM!"
XWin32 Infowindowsnfo.exe"Added by a variant of the IRCBOT TROJAN!"
XWin32 Information Servicecrsrs.exe"Added by the RINBOT.Y WORM!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 Kernel core componentKernel32.pif"Added by the MOKS VIRUS!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 LSA Driverlsa.exe"Added by the FORBOT-FJ WORM!"
XWin32 Ms Auto UpdaterAutomsUPD.exe"Added by a variant of the RBOT WORM!"
XWin32 NDISNdiswin.exe"Added by the RBOT.AMG WORM!"
XWin32 NDIS Driverxpndis.exe"Added by a variant of the RBOT WORM!"
XWin32 NDIS DriverNdistcp.exe"Added by the WOOTBOT.EU WORM!"
XWin32 Network Drivercrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 NT Adv Servicestaskmngr.exe"Added by the RBOT-ADE WORM!"
XWin32 nvcnvcva.exe"Added by the RBOT-ABF WORM!"
XWin32 NVIDIA DriverMSPMSPSU.EXE"Added by a variant of the WOOTBOT.Y WORM!"
Xwin32 regeditmsn32.exeAdded by an unidentified WORM or TROJAN!
XWin32 Rundll LoaderRundll32.exe"Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Security Protocolsecure32.exe"Added by the RBOT-ETI WORM!"
XWin32 Security Servicecrsss.exe"Added by the DELBOT-O WORM!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWin32 Servicebazzi.exe"Added by the AHKER.E WORM!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32 Servicesodbc32.exe"Added by the SPYBOT-EK WORM!"
XWin32 Serviceswuamngr.exe"Added by the SDBOT-N WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWin32 Services1wuamngr1.exe"Added by the SDBOT-PV WORM!"
XWin32 Src Servicewin32src.exe"Added by the RBOT-SX WORM!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWin32 System Spoolspoolsvc.exe"Added by the SDBOT.UK WORM!"
XWin32 Testbleatest.exe"Added by a variant of the RBOT WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWin32 Updatedl32.exeAdded by an unidentified WORM or TROJAN!
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB Driverwinxpinit.exe"Added by the SDBOT.AA TROJAN!"
XWin32 USB Drivermvsecn.exe"Added by the FORBOT-BK WORM!"
XWin32 Usb Driversvhosint32.exe"Added by the FORBOT-BE or FORBOT-J WORMS!"
XWin32 Usb Driverusb32.exe"Added by the SDBOT-OV WORM!"
XWin32 Usb DriverAvpG.exe"Added by the FORBOT-BX WORM!"
XWin32 USB Driverrundll.exe"Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWin32 USB2wins32.exe"Added by a variant of the RBOT WORM!"
XWin32 USB2 Driverwin32usb.exe"Added by the SPYBOT.DHV WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWin32 USB2 Driversys32.exe"Added by the WOOTBOT.X WORM!"
XWin32 USB2 Driversys32snd.exe"Added by the FORBOT-AN WORM!"
XWin32 USB2 Driverwind32.exe"Added by the FORBOT-AH WORM!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
XWin32 USB2 Driverupdatemgr.exe"Added by a variant of the FORBOT WORM!"
XWin32 USB2 Driverwinsnd32.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Drivermsn.exe"Added by the FORBOT-EX WORM!"
XWin32 USB2 Driversyscfg32.exe"Added by the FORBOT-R WORM!"
XWin32 USB2 Driveralgg.exe"Added by the TIBS.BF WORM!"
XWin32 USB2 Driverusb2.exe"Added by the FORBOT-Y WORM!"
XWin32 USB2 Driverwinusb32.exe"Added by the FORBOT-M WORM!"
XWin32 USB2.0 Driver386.exe"Added by the IRCBOT.D WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32 USB2.0 Driverw32usb2.exe"Added by the SPYBOT.DN WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
XWin32 USB3 Driverwin32tool.exe"Added by a variant of the RBOT WORM!"
XWin32 Wmls Driverwinitr32.exe"Added by the WOOTBOT.B WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
Xwin32.exewin32.exe"Added by the STARTPAGE TROJAN!"
XWin32.exeWin32.exe"Added by the AWQ.A TROJAN!"
XWin32.Exploit.mzHmzrun.exe"Added by the PAINTER TROJAN!"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
Xwin3208022-1336687win3208022-1336687.exe"Added by the VB-CFG TROJAN!"
XWin32BaseServiceMODWintask.exe"Added by the NAVIDAD WORM!"
Xwin32betawin32sys4.exe"Added by the BANKER-DA TROJAN!"
Xwin32clfwin32clf.exe"Added by an unidentified VIRUS
Xwin32debugwin32debug.exe"Added by the GUDEB WORM!"
XWin32DLLWin32DLL.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
XWin32dllWin32dll.exe"Added by the BANPAES TROJAN!"
XWIN32DSclienttimer.exe"Eziin adware"
XWin32GKernel32.com"Added by the ESTRELLA TROJAN!"
XWin32GScandisk.com"Added by the ESTRELLA TROJAN!"
Xwin32gbwin32gb.exe"Added by the DLUCA-F TROJAN!"
XWin32Host Processwebemir.exe"Added by the TURGEN -A TROJAN!"
Xwin32infowin32info.exeAdult content dialler
Xwin32inisystroy.exe"Added by the IRC.ALADINZ.C TROJAN!"
XWIN32ioclienttimer.exe"Eziin adware"
Xwin32Kernelfindx.exe"Added by the BANLOA-EY TROJAN!"
XWin32KernelStartmicrosoft.exe"Added by the DELF-EWZ TROJAN!"
XWin32RServer.com"Added by the ESTRELLA TROJAN!"
XWIn32S Java DLLkavsvx.exe"Added by the AGOBOT-RZ WORM!"
Xwin32servdevicer.exe"Added by the CHECKOUT WORM!"
Xwin32servservicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
Xwin32servsystemdevices.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
Xwin32servvload.exe"iSearch adware"
Xwin32servvms1.exe"iSearch adware"
YWIN32SLWin32sl.exe"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
XWIN32SNDSbanc.exeAdded by an unidentified WORM or TROJAN!
XWin32system[random filename]"Added by the DDV.B WORM!"
XWin32Systemwin32s.exe"Added by the MYDOOM.V WORM!"
XWin32SystemMonitor***.exe [* = random char]Browser hijacker
XWin32SysVxin.exe"Added by the FORBOT-EO WORM!"
Xwin32updatewin32update.exe"Added by the GENOME.AQUV TROJAN!"
XWin32UpdaterKERNAL32.EXE"Added by the SPYBOT-OK WORM!"
Xwin32uswin32us.exeAll-In-One-Telcom (adult content dialler) variant
Xwin32usbdssrs.exe"Added by the RBOT-RA WORM!"
XWin32UsrWinCab.exe"Added by the DEDMIR-A WORM!"
XWIN32WNsystem_wc.exe"Eziin adware"
Xwin32_i lptt01win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin32_i ml097ewin32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwinbin32win32exe.exe"Added by the RBOT-ZL WORM!"
XwindefWin32sp.vbs"Added by the ANPES WORM!"
Xwindhost.exeosrwin32.exe"Added by the BANKER-CB TROJAN!"
XWinDll32_WIN32.EXE"Added by the LEGMIR.AQ TROJAN!"
XWindosupdate managerrunwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
XWindows 32 EditorWin32edit.exe"Added by the WOOTBOT.GQ WORM!"
XWindows 32 Rescuewin32resc.exe"Added by the FORBOT-EU WORM!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows Extensions for Win32winprgs32.exe"Added by the SDBOT.AFA WORM!"
XWindows Logon Applicationwin32help.exe"Added by the DELBOT-X WORM!"
XWindows Runtime Helpwin32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWINDOWS SYSTEMWin32IMAPSVR.exe"Added by the MYTOB-FQ or MYTOB-FU WORMS!"
XWindows System 32-Bat Servicewin32bat.exe"Added by the MYTOB.FI WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows Update IPv6 LayerWIN32IPV6.EXE"Added by the RBOT.DUD WORM!"
Xwinkernel32wWin32.com"Added by the BANSAP TROJAN!"
Xwinloginwin32x.exe"Browser hijacker
XWinnupwin32nls.exe"Added by a variant of the SPYBOT WORM!"
Xwinprotectwin32.exe"Added by the MUGLY.E WORM!"
XWinsock32driverwin32server.scr"Added by the HACARMY TROJAN!"
XWinsock32driverwin32server.exe"Added by the BACKDOOR-AZV TROJAN!"
XWinsock32driverwin32server.exe"Added by the HACARMY.F TROJAN!"
XWSAConfigurationwin32upd.exe"Added by a variant of the RBOT WORM!"
Xwupdwin32.exe"Added by the ORSE-C TROJAN!"
UxitamiXiwin32.exe"Xitami Multiplatform Open Source web server"
X[unknown]WIN32OP.EXE"Added by the SDBOT-U WORM!"
X[various names]win32snd.exe"Added by the RBOT-DQ WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.