Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
X$sys$cmp$sys$xp.exe"Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X456655explorer.exe"Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAgent Explorer[random filename]Unidentified adware
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
XAntispyware PRO XPasproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
XAtxBrwIexplor.exe"""Pop Marketing"" adware"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAXPDefenderAXPDefender.exe"Advanced XP Defender rogue security software - not recommended
XAXPFixerAXPFixer.exe"AdvancedXPFixer rogue security software - not recommended
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
Xbxproxybxproxy.exe"Added by the BXPROXY TROJAN!"
Xbxproxy[random].dll"SoftStop rogue security software - not recommended"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
XccApprexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
Xccregexplorer.exe"Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
NCIJxP2PSERVERCIJxP2PS.EXE"Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model
?Client Access Express Welcomecwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XCOM++ Systemexploier.exe"Added by the LOVGATE.Z WORM!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XCPU Idlecpuidlexp.exe"Added by the AGOBOT-BW WORM!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
Ucryptoexpertcexpert.exe"CryptoExpert from SecureAction Research. Advanced on the fly encryption system"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
NCursorXPCursorXP.exe"CursorXP from Stardock - tool for creating mouse cursors"
XDebuggerexplorer32dbg.exe"Added by the CWS-M TROJAN!"
XDebuggeriexplore_dbg.exe"Added by the CWS-M TROJAN!"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
XDELXP Protocoldelxp.exe"Added by a variant of the SDBOT WORM!"
XdirectxSqlexploit.exe"Added by the SDBOT.D TROJAN!"
XDivX PlayerDivXPlayer.exe"Added by a variant of the RBOT WORM!"
XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
Xdllhostxp.exedllhostxp.exeBrowser hijacker and adware downloader
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
Xexp1orer.exeexp1orer.exe"Added by the DLOAD-FG TROJAN! Notice the digit ""1"" used in both the startup entry and filename
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
XexplerUpdadv.exe"Added by the QQPASS-N TROJAN!"
XExplkwexpup.exeKeywords hijacker
Xexplord.exeexplord.exe"Added by the DLOADR-AYW TROJAN!"
Xexploreexplore.exe"Added by any number of VIRUSES
XExploreExplorer.exe"Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XExploreexplore.exeAdult content dialler
XExplorePLORE.EXE"Added by the FORBOT-P WORM!"
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplore.exeExplore.exe"Added by the GRAYBIRD.G TROJAN!"
Xexploreff.exeexploreff.exe"Added by the FINFANSE TROJAN!"
Xexplorep.exeexplorep.exe"Added by the LINEAG-I TROJAN!"
Uexplorerexplorer.exe"Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorershellexpl.exe"Added by the SHELDOR TROJAN!"
Xexplorerexpl32.exe"Added by the RATSOU TROJAN!"
XExplorer[path to worm]"Added by the AUTEX WORM!"
XExplorershellexp.exe"Added by the AGENT-ZY TROJAN!"
XEXPLOREREXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
XEXPLORERsys.exe"Added by the SILLYFDC-A TROJAN!"
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorerdrv.exe"Added by the SMALL-FD TROJAN!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
Xexplorerexplorer.exe"Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
XEXPLOREREXPLORER.exe"Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
Xexplorerexplorer.exe"Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
XExplorerTXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
XExplorermsrstart.exe"Added by the SOPICLICK TROJAN!"
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
XExplorer Loaderexplr32.exe"Added by the AGOBOT.N WORM!"
XExplorer Loaderexplorerl.exe"Added by the SDBOT-ADI WORM!"
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer softexplorer.pif"Added by the RBOT-APK WORM!"
XExplorer softexplorer.com"Added by the RBOT-ARM WORM!"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
XExplorer32Expl32.exe"Added by the HACKTACK.B TROJAN!"
XExplorer32explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
XExplorer6.1.EXEExplorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
Xexplorerf.exeexplorerf.exe"Added by the AGENT-GDZ TROJAN!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
XExplorerTaskexplorer.exe"Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
UExpress ClickYesClickYes.exe"""Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
XFirefox Plugin Managerfirefoxpgm.exeAdded by the MSNPHOTO.E WORM!
UFirefox PreloaderFirefoxPreloader.exe"Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
UFreeRAM XPFreeRAM XP Pro *.exe"FreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UFreeRAM XPFreeRAM XP Pro.exe"FreeRAM XP Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
XHelpExp.exeHelpExp.exe"Attune HelpExpress - spyware. Disable and uninstall - see here"
Uhfxphfxp.exe"Hide Folders XP - hide your folders so only you can view them"
NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHLL Data Parameterhllcxpa.exe"Added by the RBOT.AFG WORM!"
NHP Info Express??"On HP PCs
Xhriiexpl0re.exe"Added by the DLOADER.MAQ TROJAN! Note the number ""0"" in the filename"
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XIECheckxpssl.exe"Added by the TIRBOT-E WORM!"
XIEDriverxplore.exe"IeDriver adware variant"
XIEexplorer AUpdateIEexplore32.exe"Added by the RBOT-GRE WORM!"
XIELoader32iexplore32.exe"Added by the SPEX or SPEX.B WORMS!"
XIESetIExplorer.dll"Added by the PWS-BLUEDIT TROJAN!"
Xiestartiexp1orer.exe"Added by the NEMOG.C TROJAN!"
XIEXPL0RERIEXPL0RER.EXE"Added by the AGOBOT-QL WORM!
Xiexploiexplor.exe"Added by the SIDEA TROJAN!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
XIexploitIexploit.html"Added by the INKER.B WORM!"
Xiexplor.exeiexplor.exe"Added by an unidentified WORM or TROJAN! See here"
XIexploreiexplore.exe"Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIEXPLOREiexplore.exe"Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIExploreIEXPLORE.EXE"Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
XIEXPLOREIEXPLORE.EXE"Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XiExplore Iniie4uini.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XIEXPLORE.EXEgoot.exe"Added by the BIFROSE-C TROJAN!"
XIExplorerIexplor32.exe"Added by the BDOOR-BY BACKDOOR!"
XIExplorerIExplorer.EXE"Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
XIexplorerexplorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xiexplorer lptt01iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiexplorer ml097eiexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIexplorer.exeIexplorer.exe"Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XIexplorerr.exeIexplorerr.exe"Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
XIexplorerr.exeIexplorerr.exe"Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
XiExpresseriexpresser.exe"Added by the SLENFBOT.AP WORM!"
Uigfxpersigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
XInternet Application DriverexpIorer.exe"Added by the IRCBOT-WK TROJAN!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Exploreriexplorer.exe"Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet ExplorerIExplorer.exe"Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorerhttp.exe"Added as part of a new potential CWS infection
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet ExplorerIEPLORE32.EXE"Added by the AGOBOT-CU WORM!"
XInternet Explorertwain.exe"Added by the AGENT.BEA TROJAN!"
XInternet Explorer Agentiexplorer.exe"Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XInternet Explorer Updaterlexbac.exe"Added by the DOWNLOAD TROJAN!"
XInternet Explorer Updateriexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetExplorer32iexplore32.exe"Added by the RBOT-GRA WORM!"
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XInternet_Explorer.exeInternet_Explorer.exe"Added by the BANKER-END TROJAN!"
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
UIomega ImIconXPimiconxp.exe"Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system
Xirwftpiexplorer.exe"Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xixploreixplore.exe"Added by the SDBOT-CY TROJAN!"
Xixploresixplores.exe"Added by the SDBOT-CE WORM!"
Xixproxy[path to trojan]"Added by the XORPIX-A TROJAN!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
XJufualtwinxp2.exe"Added by the SDBOT-AAB WORM!"
Xkernel32sys.dllIEXPLORER.exe"Added by the RBOT-MK WORM!"
XKernellAppslexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Xkeysysxp.exe"Added by the BEAGLE.AB WORM!"
Xkeysys_xp.exe"Added by the BEAGLE.AC WORM!"
Xkeywinxp.exe"Added by the BEAGLE.AG WORM!"
Uklpexplorer.exe"ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself!"
YKPDrv4XPKPDrv4XP.exeMediaKey USB Keypad Driver
Xl44sys**iexplore"Added by the VBS.LIDO WORM - where ** is a number between 65 and 76"
Xlexplorelexplore.exe"Added by the BROPIA WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Nlexppslexpps.exe"For Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC
?LifeCamLifeExp.exe"Related to Microsoft's LifeCam series of webcams. What does it do and is it required?"
?LifeExpLifeExp.exe"Related to Microsoft's LifeCam series of webcams. What does it do and is it required?"
XLimpetexplorer16.exe"Added by the RBOT-AJD WORM!"
Xlnternet ExplorerAMSNDMGR.EXE"Added by the KWBOT.R WORM! Note that the ""l"" is a lower case ""L"" and not an upper case ""I"""
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Xloadexplorer.exe"Added by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
XLoadab1explorer.exe"Added by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMecq0explorer.exe"Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMect1explorer.exe"Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XLSA Shell (Export Version)LSASS.exe"Added by the AHKER.K WORM and variants. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMacromedia DriveIexplor32.exe"Added by a variant of the RBOT WORM!"
XMedia Player Updatexpsp1mfh.exe"Added by a variant of the RBOT WORM!"
XMedia-XP-Service-Pack3msnzx.exe"Added by the SDBOT-ACW WORM!"
UMediafour XPlay Tray Notification IconXptryicn.exe"Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod"
UMediafour XPlay Tray Notification IconXptryicn.exe"Xplay 2 from Mediafour Corporation - ""expands what you can do with any iPod
XMediaXPServicePackmxpsp.exe"Added by the SDBOT.CDT WORM!"
XMessenger Explorerm41n.exe"Added by the SDBOT-SA BACKDOOR!"
XMicrcoft Exploererspoolsal.exe"Added by the RBOT-AKK WORM!"
XMicrcoft Exploerersvchose.exe"Added by the RBOT-ASL WORM!"
XMicroCQ0explorer.exe"Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XMicroft Exploererspoolsac.exe"Added by the RBOT-AMD WORM!"
XMicromedia Flash Updatexptxt.exe"Added by the RBOT-GAB WORM!"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoftExplorerr.exe"Added by the IRCBOT-WG TROJAN!"
XMicrosoftExplorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft ALGXP Protocolalg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Automatic UpdaterExplorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft CPXP Protocolcpxp.exe"Added by the RBOT.ATP WORM!"
XMicrosoft Deviexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Directx pushdirectxpushup.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Explorerexplorer.pif"Added by the SDBOT-ACX WORM!"
XMicrosoft Explorerexplorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Explorer(64)explorer64.exe"Added by the SPYBOT-R WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft Explorer2nome.exe"Added by the RANDEX.AA WORM!"
XMicrosoft Explorer2bitchbot.exe"Added by the SDBOT.EV WORM!"
XMicrosoft EXPLOREXP Protocolexplorexp.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Inc.iexplorer.exe"Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Inc.iexplorer.exe..."Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Inet Xp..teekids.exe"Added by the BLASTER.C WORM!"
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internet Expiiexplorer.exe"Added by the RBOT-KX WORM!"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplorer.exe"Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorermccagent.exe"Added by the DLOADER-UD TROJAN!"
XMicrosoft Internet Explorersysini.exe"Added by the DELF-LN TROJAN!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Intrenet Explorergoaw.pif"Added by the RBOT-API WORM!"
XMicrosoft Intrenet ExplorerSoundsyst.exe"Added by the RBOT-AQU WORM!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft LAN32 ProtocollanXp.exe"Added by the RBOT-SS WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft Neser Experiencenese.exe"Added by the RBOT-YH WORM!"
XMicrosoft OfficeXPofficeXP.exe"Added by the KILLAV.MA WORM!"
XMicrosoft Outlook Express Protocolsvchst.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Synchronization Managerexplorer.exe"Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
XMicrosoft Uwuamkopxp.exe"Added by the RBOT-AHC WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft Updateexplorer.exe"Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update 32explore32.exe"Added by the SPYBOT.CYM WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32explorer.exe"Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Windowsexplorar.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows Communicator for NT/XPwincomm.exe"Added by the RBOT.ATH WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Expresswebsploit.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft XPSP Protocolxp386.exe"Added by a variant of the RBOT WORM!"
XMicrosoft xpsp2Networksystem.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft xpsp2xpsp2.exe"Added by the SDBOT-YQ WORM!"
XMicrosofts Updatezexploirez.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftXP Service Pack 2servicepack2.exe"Added by the RBOT.EMC WORM!"
XMicrosoft©iexplore.exe"Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
XMicsoft-Published-Softwareexplrer.exe"Added by the RBOT-GFL WORM!"
UMini-XPMini-XP.exe"Minimizer-XP from Totalidea Software - adds an additional button in the top right-corner of any application window to allow you to quickly minimize it to the System Tray. No longer available from the author but still available from download sites such as Download.com"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMMB2explorer.exeAdded by an unidentified WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Xmmxp2passion.exemmxp2passion.exe"MediaMotor adware"
NMoney Expressmoneyexpress.exePart of MS Money. Available via Start -> Programs
NMoneyAgentmoney express.exePart of MS Money. Available via Start -> Programs
NMoneyAgentmnyexpr.exeMicrosoft Money
XMonitorexplor.exe"Added by the AGOBOT-EF BACKDOOR!"
Nmozilla_cleanupxpicleanup.exe"Firefox Mozilla cleans up after installation. It is invoked on a restart after installation
NMPXTraympxptray.exe"Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause
XMS Explorermexplore.exe"Added by the YAHA.AE WORM!"
XMS Internet ExploreMSIEx.exe"Added by a variant of the RBOT WORM!"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS MSN Menssenger 7.0MSEXPORT.exe"Added by a variant of the SDBOT WORM!"
XMS Unix Binaryoutlookexpressupdate.exe"Added by the RBOT-YU WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMSAgentXPMSAgentXP.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN!
XMsAudioexplorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMSDN for Windows NT & WinXPmsdnxp.exe"Added by the IRCBOT-PE WORM!"
Xmsjava servicexpcd.exe"Added by the SDBOT.VM WORM!"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMSN Explorermsnexplorer.exe"Added by the AGENT-CAX TROJAN!"
XMSN Explorerexplorer..exe"Dropper for the Ciadoor.cb TROJAN!"
XMsn MessengeIExplorer.exe"Added by the DELF-LL TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMSN MessengerIExplorer.exe"Added by the BANKER-EU TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMSN Messengerexplorer..exe"Dropper for the Ciadoor.cb TROJAN!"
XMSN Messengermsnmsxp.exe"Added by the AGOBOT-O WORM!"
XMsnExplorerwinagent.exe"Added by the BDOOR-EQ BACKDOOR!"
XMsnExplorerMSEXPLOREN.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorerSHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorerSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XMsnExplorersdhch.exe"Added by the TACTSLAY.B TROJAN!"
XMSNS PLUS XP2msdupd.exe"Added by the RBOT-BCE WORM!"
Umspwrpupxpman.exe"Related to Ashampoo's PowerUp XP"
UmspwrPuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
XMSSQL for Windows NT & XPmssqlsnt.exe"Added by a variant of the SDBOT WORM!"
XMSStartOptimizerIexpres.exe"Added by the DASMIN-E TROJAN!"
XmssysintIexplore .exe"Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XMsupdateexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
Xms_anti_spywarebxpmwfirebpx.exe"Added by the SURILA-D TROJAN!"
Xms_anti_spywarebxpmwfibpx.exe"Added by the SURILA-J TROJAN!"
XmyMh2iexpl0re.exe"Added by the AGENT.HWE TROJAN! Note the number ""0"" in the filename"
Xmysoftwinexplor.exe"Browser hijacker
XNameIexplorer0.exe"Added by the THREADSYS TROJAN!"
XNavegateiiexplorer.exe"Added by the BANCBAN-OP TROJAN!"
XNDIS Adapterservenxpp.exe"Added by the FORBOT-GP WORM!"
XNDIS AdapterServenxp.exe"Added by the SPYBOT.LY WORM!"
XNetwork Security XPnvsvc86.exe"Added by the RBOT-GUI WORM!"
Xnternet Exploreriexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xntxp2ntxp2.exe"Added by the VB-API TROJAN!"
XNvCplDaemonXplorer.exe"Added by the ORBINA-A WORM!"
XNvXplDeamonxstyles.exeAdded by the SMALL.AJ VIRUS!
Unxpclientsprtcmd.exe /P nxpclient"NetExpert - ""India's first ever automated Broadband care technology."" Identifies and automatically fixes typical problems that may occur with your high-speed internet service"
XOffica Monitor Secura Systemewinxp_sp3.exe"Added by a variant of the RBOT WORM!"
XOffice StartupExploer.exe"Added by the GAOBOT.BV WORM! Note the different filename to the valid MS Office entries"
XOfficeAgentexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XOFFICEXPOFFICEXP.exe"Added by the WOOTBOT.HE WORM!"
XOneMoreKeyxpa.exe"XP Antivirus rogue security software - not recommended"
XOPTIMIZERiexplore.exe"Added by the EVEVINC BACKDOORNote - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOPTIMIZERiexplore.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOutlook Expressmsinm.exe"Added by a variant of the RBOT WORM!"
XOutlook Express Config*****.exe [* = random char]"Added by a variant of the RBOT WORM!"
XOutlook Express Protocollook.exe"Added by the RBOT-ACS WORM!"
XOutlook Mail Servicesexpress.exe"Added by the RBOT.CJN WORM!"
Xpccexplcrer.exe"Added by the AGENT-FW BACKDOOR!"
XPcEXPLODEspecialfile.exe"Added by the RBOT.RH WORM!"
NpdexploPDEXPLO.EXE"PowerDesk Pro by PowerDesk Pro by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs"
UPersistenceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
NPhoto Express Calendar Checker SECALCHECK.EXE"If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper
UPhotoExplosionCalCheckcalcheck.exe"Calendar management feature of Nova Development's Photo Explosion"
UPhraseExpressphrase.exe"""PhraseExpress organizes your frequently used text phrases and allows pasting them into any application"""
XPoliceAVxppolice.exe"XP Police Antivirus rogue security software - not recommended
UPower2GoExpressPower2GoExpress.exe"Power2GoExpress - all media disc burning software"
YPrevxProSAGUI.exe"PrevX Home intrusion prevention software"
Xprint sharing[path] hidden32.exe [path] explorer.exe"Added by the ZCREW.B BACKDOOR! Note - the legitimate Windows Explorer (explorer.exe) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XProgram in WindowsIEXPLORE.exe"Added by the LOVGATE.AB WORM!"
XProtectionIExplore .exe"Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
UPuXpMan2PuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
UPwrUpManagerPuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
UPwrupTweakMePUPXPTWK.EXE"Ashampoo's PowerUp XP is a ""tool for fine-tuning your Windows NT4
?QexploQexplo.exe"??"
URAM Idle ProfessionalRAM_XP.exe"RAM Idle LE - ""A smart memory management program that will keep your computer running better
Xravshellexpl0rer.exe"Added by the DLOADER.MAR TROJAN!"
XRavshellexplore3.exe"Added by the PAKES.HZ TROJAN!"
XRavshellIEXPLORER.EXE"Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xravshell1explore.exe"Added by the DLOADER.MJF TROJAN!"
Xravshelliexpl0re.exe"Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
Xravtaskiexpl0re.exe"Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
XRavTimerexplores.exe"Added by the HOMEY-A TROJAN!"
XRavTimeXP[worm filename]"Added by the WULLIK.B WORM!"
XRavTimeXPVirus"Added by the CAGER.A WORM!"
XRavTimXP[worm filename]"Added by the WULLIK.B WORM!"
XRBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Serverglossary.exe"Added by the VANEBOT-J WORM!"
XRealDownload Expressnpnzdad.exeAdvertising spyware
URegClean Expert SchedulerRCHelper.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
URegClean Expert SchedulerRCScheduler.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
Xregdiitwinxp.exe"Added by the RUNAUTO.F WORM!"
XRegistry Value Namesyswinxp.exe"Added by the RBOT.BTZWORM!"
XRegistry Value Nameenzxp.exe"Added by the RBOT-BAJ WORM!"
XRegistryMonitor1igfxpers.exe"Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename"
XRegMutexlexplore_.exe"Added by the MSNOPT-A TROJAN!"
NReminderRemind_XP.exeHP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
NRemind_XPRemind_XP.exeHP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
URetroExpressRetroExpress.exe"EMC (was Dantz) Retrospect Express - backup software for external hardware storage devices"
XrforceEXP1ORER.EXE"Added by the DROPPER.KN TROJAN! Note the number ""1"" in the filename rather than letter ""L"". It also drops another file named DEVICEMAP.SYS which is the ROOTKIT.O TROJAN!"
XRpcLocatorexplorer.exe"Added by the RBOT-GSA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xrxexplore.exe"Added by the ZHENGTU-A TROJAN!"
Xs9201av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended
Xs9201as2008xp.exe"AntiSpyware XP 2008 rogue spyware remover - not recommended
Xs9201asproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
Nscscrubxp.exe"ScrubXP - utility that deletes safe to remove files
XScheduIrmsexploren.exe"Added by a variant of the SDBOT WORM!"
XSchedulerexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
XSecureExpertCleanersec.exe"Secure Expert Cleaner rogue privacy program - not recommended
XSecurity Antivirus Xp 1inetfor.exe"Added by the SDBOT.BAV WORM!"
XService Monitorwinxpser.exe"Added by the RBOT-BDF WORM!"
XService SystemwindowsXP.exe"Added by the BANCOS-EL TROJAN!"
XServicesiexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XServicesiexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XServicesiexploler.exe"Added by the RANCK-LT TROJAN!"
XServicesiexpolere.exe"Added by the RANCK.LU TROJAN!"
XSetup experationsvchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShellExplorer.exe sound_drive16.exe"Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""sound_drive16.exe"" file is located in %System%"
XShell"Explorer.exe msmsgs.exe"
XShellExplorer.exe svchost.exe"Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xshellexplorer.exe"Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XShellExplorer.exe iexplore.exe"Added by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft"
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
XShellExplorer.exe [path] ibm[RANDOM 5 DIGIT NUMBER].exe"Added by the ANSERIN TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files"
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
XShellexplorer.exe msbnc.exe"Added by the AGENT-PL BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""msbnc.exe"" file is located in %System%"
XShellExplorer.exe kbdsys.exe"Added by the DAPROSY WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""kbdsys.exe"" file is located in %AppData%\Microsoft\Keyboard"
XShellExplorer.exe init32m.exe"Added by the DLSW-B TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""init32m.exe"" file is located in %System%"
XShellExplorer.exe smssnt.exe"Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""smssnt.exe"" file is located in %System%"
XShell32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XShell32explorer.exe"Added by the SDBOT-NF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XShellRunlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XShellRun32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Nshicoxpshicoxp.exeInstalled with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
XslideIexplore.exe"Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
NSmartBarXPSmartBarXP.exe"SmartBarXP is a bar that runs down the side of your screen
XsmsysExplorer.exe"Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a ""Template"" subfolder"
USoundMAXPnPSMax4PNP.exe"Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones
Xsp2fwxpsp2fwxp.exeAdded by the SMALL.ABW TROJAN!
XSpam Blocker for Outlook ExpressSBInst.exe"Hotbar adware"
USpeedswitchXPSpeedswitchXP.exe"SpeedswitchXP is a CPU frequency control for notebooks running Windows XP"
XStart Uppingiexplorerupdt.exe"Added by the RBOT-RR WORM!"
XStart Xp Setupmsxp.exe"Added by the RBOT.AKK WORM!"
Xstarteriexplore.exe"Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xstartkeyexplore32.exe"Added by the BDOOR-MT BACKDOOR!"
Xstartkeyexplorer.exe"Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XstartkeywinampXP.exe"Added by the BIFROSE-OY TROJAN!"
UStyleXPStyleXP.exe"StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
XSustemexplorer.exe"Added by an unidentified VIRUS
XSustemUpdateexplorer.exe"Added by an unidentified VIRUS
Xsvcexpseny.exe"Added by the PWS-ANG TROJAN!"
XSvcH0stmsexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
XSvcH0stmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
Xsvchost[path to explorer.exe]"Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XsvcsharewinampXP.exe"Added by the FUJACKS-J VIRUS!"
?Sxplogsxpstub.exe"Part of CA Unicenter Software Delivery - manage software across various systems
XSygate Personal Firewallwinxpstat.exe"Added by a variant of the RBOT WORM!"
XSymantec Antivirus professionalxplrer.exe"Added by a variant of the FORBOT WORM!"
XSYS1explorar.exe"Added by the SILLYFDC.BDJ WORM!"
Xsyscheckiexplorer.exeAdded by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Xsysconfigiexplorer.exe"Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XsysMett1explorer.exe"Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XSysMonXPSysMonXP.exe"Added by the NETSKY.Q WORM!"
XSysResIExpIore .exe"Added by the ELITPER.E WORM!"
XSystam13exp.exe"Added by the RBOT.ESD BACKDOOR!"
XsystemExplorer.exe"Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSystemIEXPL0RE.EXE"Added by the VB.KS WORM! Note the number ""0"" in the filename"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Information Manageriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Serviceexp0lrer.exe"Added by a variant of the RBOT WORM!"
XSystem Servicemsnxpexe.exe"Added by the RBOT-AUA WORM!"
XSystem Update2explorer.exe"Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xsystem xpacdsee demo.exe"Added by the SALGA.A WORM!"
XSystem-ServiceEXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
XSystemDrivemaxpaynow1.exe"Added by the TIBS.BKU TROJAN!"
XSystemExplorerexplore.exe"Homepage hijacker - file located in the ""Services"" folder in Common Files"
XSystrayw32explorer.exe"Added by the RBOT-AJY WORM!"
XSystrayServicesMsxpw.exe"Added by the CITOR WORM!"
Xsys_Runtt1explorer.exe"Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XSyzmy3exp1orer.exe"Added by the LINEAG-AIO TROJAN! Note the number ""1"" in the filename"
XSyztMyexpiorer.exe"Added by the LINEAG-AIN TROJAN!"
Xtaskmgrexplorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
UTaskSwitchXPTaskSwitchXP.exe"""TaskSwitchXP from NTWind Software. Advanced task management utility that picks up where the standard Windows Alt Tab switcher leaves off. It provides the same functionality
XTCPXP Updatetcpxp.exe"Added by the RBOT-UL WORM!"
XTelephony ProviderIexplore.exe"Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XThe Service Pack Loaderspxp.exe"Added by the RBOT-BYM WORM!"
UTurboExplorerTE.exe"Web accelerator - ""TurboExplorer 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer 4/5 to achieve a faster and more effective approach to the internet"". Only needed if you find it improves web browsing"
XTURXP Protocolsps32.exe"Added by a variant of the SDBOT WORM!"
UTweak-xpTweak-xp.exe"Main program for Tweak-XP - a WinXP tweaking utility"
XTwunk_32exp.exeTwunk_32exp.exe"Added by the FAKEAV-BDZ TROJAN!"
UUCmore XP - The Search Accelerator"rundll32.exe UCMTSAIE.dll DllShowTB"
NUlead Photo Express Calendar Checkercalcheck.exe"If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper
NUlead Photo Express x.0 Calendarcalcheck.exe"Ulead Calendar Checker - part of Ulead Photo Express
XUpdate Exploreriexploreupd.exe"Added by a variant of the RBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdateXpSpMS045-XP2.exe"Added by the IRCBOT.NY TROJAN!"
XUSB 2.0 DriverupdateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
XUSB 2.0 DriverupdateXP.exe"Added by the AGOBOT-QP WORM!"
XUSB 2.0 DriverUpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
XUSB Driver4UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
YVade Retro Outlook ExpressVaderetro_oe.exe"Vade Retro anti-spam software for Outlook Express from GOTO software products"
XVideoexplored.exe"Added by the GAOBOT.RF WORM!"
XVideo Servicesexplore.exe"Added by the GAOBOT.GL WORM!"
UVirtualExpanderVirtualExpander.exe"Micro Vault Virtual Expander from Sony for their range of USB memory sticks. This software will compress your data to virtually store about 3 times as much data"
XVMware ToolsXplorer.exe"Added by the AUTOIT.K TROJAN!"
XVsamplewinxpsock.exe"Added by the SDBOT.BLK WORM!"
Xwhxpin servicessvsol.exe"Added by a variant of the SDBOT WORM!"
XWidnows Xp Web scanxpscan.exe"Added by a variant of the SDBOT WORM!"
Xwin-xpnvsc32.exe"Added by the BROPIA.N WORM!"
Xwin-xpwinis.exe"Added by the BROPIA.N WORM!"
XWin32 ExplorerExplorer32.exe"StartPa-MN homepage hijacker"
XWin32 NDIS Driverxpndis.exe"Added by a variant of the RBOT WORM!"
XWin32 USB Driverwinxpinit.exe"Added by the SDBOT.AA TROJAN!"
XWin32.Exploit.mzHmzrun.exe"Added by the PAINTER TROJAN!"
XWinAmpAgentMsexploren.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XWindowexplore.exe"Added by the GAOBOT.ADW WORM!"
XWindowsexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwindowsiexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Communicator for NT/XPosndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows DLL Verifierxptl.exe"Added by a variant of the RBOT WORM!"
XWindows Driverwinxpdriver.exe"Added by the WOOTBOT.EE WORM!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows ExplorerLsas.exe"Added by the GAOBOT.AO WORM!"
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows ExplorerEEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
XWindows Explorerexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorerexplorer.pif"Added by the RBOT-AID WORM!"
XWindows Explorersystem32.exe"Added by the RBOT-AJH WORM!"
XWindows Explorerexplorer32.exe"Added by a variant of the SDBOT WORM!"
XWindows ExplorerWindows Explorer.EXE"Added by the VB-EBA WORM!"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows Explorer Keyexplorer.exe"Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Explorer ShellWinexec32.exe"Added by the REDIST.B WORM!"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Explorer-3212WINRE16.EXE"Added by the HARDOC WORM!"
XWindows Explorer.exeExplorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Expresspci32b.exe"Added by the BUZUS.C TROJAN!"
XWindows File XP Managerwfdmgr.exe"Added by the SDBOT.XD TROJAN!"
XWindows Internet Explorer 6firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Loginexplored.exe"Added by the GAOBOT.SY WORM!"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
XWindows Network ControllerWinxPupd.exe"Added by the FORBOT-DK WORM!"
XWindows Registry Express Loaderregexpress.exe"Added by the FORBOT-CJ WORM!"
XWindows Registry XPwinxptdl.exe"Added by the IRCBOT.AUN WORM!"
XWindows serviceiexpl0rer.exe"Added by the SDBOT.RO WORM!"
XWindows Service XPXpFirewall.exe"Added by the MYTOB.AM WORM!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWINDOWS SYSTEMwinxpserv.exe"Added by the MYTOB-BQ WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMexpI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows System Filecmxp.exe"Added by the SPYBOT.KHO WORM!"
XWindows System32explorer.exe"Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
XWindows Taskmanageriexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Taskmanagertaskxphost.exe"Added by the PUSHBOT.BI WORM!"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
XWindows UpdateXPLoogNT.exe"Added by the BANCD-B TROJAN!"
XWindows Updateexplored.exe"Added by the GAOBOT.MF WORM!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows Updateriexplorerrs.exe"Added by the RBOT-TN WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Vista Corparation Agent Serviceswinxp_sp3.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindows Xpnortonguard.exe"Added by the MYTOB-DZ WORM!"
XWindows xpWins.exe"Added by the RBOT.VH BACKDOOR!"
XWindows XP Automatic UpdatewXPupdate.exe"Added by the RBOT-AFC WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows XP SP2 KeyGenWindows XP SP2 KeyGen.exe"Added by the TIBICK-C WORM!"
XWindows-XP-Service-Packxpspz.exe"Added by the SDBOT-AAC WORM!"
XWindowsExplorercsrss.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsExplorersvchost.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsRegKey update XPwindexv1.exe"Added by the RBOT-ABM WORM!"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsXP ModuleDirectX3D.exe"Malware
XWindowsXp Securityspool.exe"Added by the RBOT-GRK WORM!"
XWindowsXP Updatewindowsxpupdate.exe"Added by the RBOT-PB WORM!"
XWindowsXPservsvcnxp32.exe"Addee by the NANINF-A TROJAN!"
XWindowz Update V2.0Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
XWinExlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
Uwinmatrix.exeWinMatrixXP.exe"WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop"
Xwinnt DNS identiexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xwinnt DNS identwindowxp.exe"Added by a variant of the RBOT WORM!"
YWinPatrol ExplorerWinPatrolEx.exe"Part of WinPatrol"
Xwinprofileiexpiore.exeAdded by a variant of the MONCHER WORM!
XWinProfileiexpIore.exe"Added by the CHUM-C TROJAN!"
XWinReg32 serviceholqdnoxpmeu.exe"Added by a variant of the SDBOT WORM!"
XWinSigNetXP.exe"Added by the BANKER-FN TROJAN!"
XWinsock2 driverIEXPLORE .EXE"Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
Xwinsockdriveriexplor.exe"Added by the BLATIC.A WORM!"
XWinStarIEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
XWINTASKmsmgrxp.exe"Added by the MYTOB.AQ WORM!"
XWINTASKiexplorer.exe"Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWINTASKSwinxpro.exe"Added by the MYTOB.EZ WORM!"
NWintime WtxploadWxpload.exe Wintime"Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet
XWinUPD32explorer.exe"Added by an unidentified VIRUS
XWinupdate Servicewinxp.exe"Added by the SPYBOT.IR WORM!"
Xwinupdateconn_Explorer.EXE"Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWinVNCiexplorer.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XwinXP33.exe"Added by the ANPES WORM!"
XWinXPplugin1.exeAdded by the Downloader-JW TROJAN!
XWinXPcsrss.exe"Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools"
Xwinxpwinxp.exe"Added by the BRONTOK-DN WORM!"
XWinXP fix[path to file]"Added by the RANKY.P TROJAN!"
XWinXP Processor Generator v1.2intspnsr32.exe"Added by the SDBOT.LP WORM!"
XWinxp updateCappp.exe"Added by the RBOT.DKO WORM!"
XWinXp Updaterwinxp32.exe"Added by the RBOT-HG WORM!"
XWinXP-98CSRSS.exe"Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools"
Xwinxpdll32.exewinxpdll32.exeAdded by a variant of the SMALL downloader TROJAN!
XWinXPHomeplugin2.exe"Added by the malicious INOR.T SCRIPT!"
UWinXPLoad"Rundll32 LoadDll LoadExe WinXPLoad.exe"
XWinXProtectorWinXProtector.exe"WinXProtector rogue security software - not recommended
XWinXPServicelsass.exe"Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
XWinXPServicetaksmgr.exeIdentified as a variant of the IRC/Flood.tool malware
XWinXPServiceTskdbg.exe"Added by the MDROP-BPQ TROJAN!"
XWinXPServicectfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""ctf"" sub-folder"
XWinXPServicemirc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWinXPServicenero.exe"Added by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in the root directory
XWinXPServicewacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %Windir%\Fonts"
XWinXPServicewacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%\mnut"
XWinXpUpdate32WinXpUpdate32.exe"Added by the AGENT.YWL WORM!"
Xwinxpusbdwinxp64.exe"Added by a variant of the RBOT WORM!"
XWksSVCEXPLORER.exe"Added by the MYTOB-BW WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwnxpupdatespvspool.exe"Added by the DABORA.B WORM!"
Xwnxupdateupdatexp.exe"Added by the COMBRA-G WORM!"
XWxp4Norton Update.exe"Added by the ERKEZ.D WORM!"
NWXProcMgr ModuleWXprocMgr.exe"TVTonic from Wavexpress - ""enjoy 3 full-screen
Xxpwinis.exe"Added by the RBOT-WO WORM!"
XXpp2pnetworking.exe"Added by the SDBOT.XA WORM!"
XXP Antispyware 2009XP_AntiSpyware.exe"XP AntiSpyware 2009 rogue spyware remover - not recommended
XXP Antivirusxpantivirus.exe"XPAntivirus rogue security software - not recommended
XXP Antivirusxpa.exe"XP Antivirus rogue security software - not recommended"
XXP Cleanerxpc.exe"XP Cleaner rogue cleaning utility - not recommended
XXP HOT FISkbx.exe"Added by the FORBOT-GS WORM!"
XXP Loaderloaderxp.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XXP Protection CenterXPProtectionCenter.exe"XP Protection Center rogue security software - not recommended
XXP SecurityCenterXPSecurityCenter.exe"XPSecurityCenter rogue security software - not recommended
XXP Service Packxpservicepack.exe"Added by the SDBOT.AQA WORM!"
Xxp service pack 2xpsp2.exe"Added by the RBOT-KW WORM!"
XXP Systemsystemxp.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UXP Toolsxptools.exe"XPTools - ""integrated suite of powerful PC Utilities to fix
XXP-C300C3ACXP-C300C3AC.EXE"Added by the AUTORUN.EHW WORM!"
Xxp32winxpupdater02.exe"Added by the MOSUCK-A TROJAN!"
NXpadderXpadder.exe"""Xpadder simulates the keyboard and mouse using your gamepad"""
?XPAgentXPAgent.exe"Part of the IBM/XPoint Rapid Restore utility - normally located in %ProgramFiles%\XPOINT\AGENT folder. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98. What does it do and is it required?"
XXPAgentXPAgent.exe"Detected by Panda as the CLICKER.LE TROJAN! Do not confuse this with the IBM/XPoint Rapid Restore file which is normally located in %ProgramFiles%\XPOINT\AGENT folder. This one is found in %System%"
XXPAntivirusXPAntivirus.exe"XPAntivirus rogue security software - not recommended
XXpAspy[path to trojan]"Added by the DELF-WH BACKDOOR!"
?xpcfgxpcfg.exe"??"
?Xpclientxpclient.exe"Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required?"
UXPCMonitorXPCMonitor.exe"XPC Monitor Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XXPCPHOST Settingsxpcphost.exe"Added by a variant of the RBOT WORM!"
XXPdefenderXPdefender.exe"XPdefender rogue spyware remover - not recommended
XXPGuardXP-Guard.exe"XP-Guard rogue security software - not recommended
Xxpiupdatexpiupdate.exe"Added by the RBOT-AAB WORM!"
UxPlanetControlxPlanetControl.exe"Tool that displays a globe with current day/night zones and clouds on users desktop."
UXplayXPlay.exe"Xplay 3 from Mediafour Corporation - ""expands what you can do with any iPod
UXPlay.exeXPlay.exe"Xplay 3 from Mediafour Corporation - ""expands what you can do with any iPod
XXplorerXplorer.exe"Added by the AUTOIT-BP WORM!"
XXplorerKHATRA.exe"Added by the AUTOIT.K TROJAN!"
XXpnetNetXp.exe"Added by the BANCBAN-AT TROJAN!"
Xxpprotectxpdeluxe.exe"XP Protector Deluxe rogue security software - not recommended
XXPShieldXP-Shield.exe"XP-Shield rogue security software - not recommended
XXPSoftCVDAsDW.exe"Added by the SDBOT-SY WORM!"
XXPSP2 Firewallxpsp2fw.exe"Added by the SMALL-RN TROJAN!"
Xxpsp2installxpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpsp2Updatexpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpstartwini.exe"Added by the PICRATE.A WORM!"
Xxpstatwinlogins.exe"Added by the RBOT-AAR WORM!"
XXPsysXPsys.exe"Added by the DELF-KQ TROJAN!"
Xxpsystemy.exe"CoolWebSearch parasite variant"
XXpsystemSERVICES.EXE"Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\SERVICES"
Xxpsystemservices.exe"CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process
XxpsystemMSXMIDI.EXE"CoolWebSearch parasite variant
Xxpupdateupdates.exe"Added by the BROPIA.L WORM!"
XXpyBurnerXpyBurner.exe"XpyBurner rogue spyware remover - not recommended
Xxp_system[filename]"Added by the BOOKMARKER.J TROJAN! The file is located in %Windir%\inet20004"
Xxp_systemwinlogon.exe"Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe
Xxp_systemservices.exe"Added by the KREPPER-N TROJAN and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The one is located in a %Windir%\inet***** - where ***** varies dependent upon the variant
XYahoo MessenggerIEXPLORERS.exe"Added by the AUTOIT.DH TROJAN!"
UZero PoPup Killer XPzpk_xp.exe"Intelligent anti-pop-up software product by Ax-Soft"
XZonealarmiexplore.exe"Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X[32 random numbers]xpa.exe"XP Antivirus rogue security software - not recommended"
X[original filename]xphost.scr"Added by the BANCBAN-HM TROJAN!"
X[random name]??xplore.exe"PurityScan adware"
X[random name]d?xplore.exe"PurityScan adware"
X[random name]iexpl0ra.exe"Added by the ULPM.BD TROJAN!"
X[random name]explore3.exe"Added by the DELF.FAN TROJAN!"
X[random number]explorer.exe"Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
X[various names]expoler.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_Cat3msmsgrxp.exe"Added by a variant of the SMALL-DT downloader TROJAN"
X_explore manager_explore.exe"Added by the SPEXTA-C TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sxpgknrwva.exe"Added by the FAKEALERT-AM TROJAN!"
U{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}XPlay.exe"Xplay 3 from Mediafour Corporation - ""expands what you can do with any iPod
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sxpjbwvahn.exe"Added by the FAKEALERT-AM TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.