Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(Default)fada.exe"Added by the VB.HEI TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X1KHATRA.exe"Added by the AUTOIT-BP WORM!"
X180sa180sa.exe"180Search adware"
U1cla1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
U1cla.exe1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
X5-1-61-96members-area.exeAdult content dialler
X666Ska.exe"Added by the PIPES TROJAN!"
Xaa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
Xaaaaaa.exe"Added by the POISON.PG BACKDOOR!"
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
Uacaaca.exe"Access Controller - ""a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection
Uaca.exeaca.exe"Access Controller - ""a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
Xadirkaadirka.exe"Added by the TIBS-QT TROJAN!"
?Aeiwlsta.exeAeiwlsta.exe"IBM High Rate Wireless LAN Adapter driver. Is it required?"
XAicatuaa.exe"PurityScan adware"
Ualaala.exe"Access Lock - ""an easy-to-use system-tray security utility you can use to secure your desktop when you are away from your computer. Just configure the program
Uala.exeala.exe"Access Lock - ""an easy-to-use system-tray security utility you can use to secure your desktop when you are away from your computer. Just configure the program
NAlexaalexa.exe"Related to Alexa. Note - collects and stores information about the web pages you view
XAlphaAntalpha.exe"Alpha Antivirus rogue security software - not recommended
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAritimaaritima.exe"Added by the ARITIM WORM!"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XAsicfcicfca.exe"Added by the AGENT.AAJE WORM!"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
UATKMEDIADMEDIA.EXE"Driver for the media buttons on the front of some Asus laptops
NAtomicaatomica.exe"Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
XAuto Updatedma.exe"Added by the RBOT-AVO WORM!"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
?AVWLPSTAAVWLPSTA.exe"PRISM Status Tray Applet - but what is it for and is it required?"
XAwolaAwola.exe"Awola rogue spyware remover - not recommended"
?AWUSGSTAAWUSGSTA.exe"Reportedly related to a USB Wifi Adapter - is it required at startup?"
UBACPI10bacpi10a.exe"Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
Ubcabca.exe"BeClean Agent - registry
?Belsta.exeBelsta.exe"Configuration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed?"
UBioniXWallpaperBionix Wallpaper 5beta.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
NBitTorrent DNAbtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
Xbolenjabolenja.exe"Added by the WANTVI.BF TROJAN!"
UBrmfRmPABrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
Nbtdnabtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Nbtdna.exebtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
NCanadaCanada.exe"Known to be a dialler - but is it maliscous or clean?"
XCashFiestaCashfiesta.exe"CASHFIESTA.A pay-per-surf adware"
XCassandracassandra.exe"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
Ucmacma.exe"DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center"""
XCMFibulaCMFibula.exe"CASClient adware"
YCnwiDeviceAgentcnwida.exe"Part of the Canon imagePROGRAF W8400 printer management software"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
UConnect KasambaKasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
Xcouponicacouponica.exe"Adware - see here"
Ucsvdeacsvdea.exe"SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself"
Xctfmonactfmona.exe"Added by the DLOADR-BME TROJAN!"
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
XDepassxXfsa.exe"Added by the SDBOT-SK WORM!"
UDesksite CMAcma.exe"DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center"""
Xdisnisadisnisa.exe"Added by the DORF-AE WORM!"
Xdlucadluca.exe"Added by the DLUCA.C TROJAN!"
NDNAbtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
XDrvStartHPMedia.exe"Added by the BANCBAN-QE TROJAN!"
XdS35DLLffqca.exe"Added by the SDBOT-KV WORM!"
Xdsadsa.exeHomepage hijacker - redirecting to downseek.com
Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
Xdxdiag diagnosemsidxdia.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns Binarydynitora.exe"Added by the RBOT-WT WORM!"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
NEMA.exeEMA.EXETime management system which helps you to manage your time and appointments
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
XErocaEroca.exe"Insider.i adware"
UEudoraEudora.exe"Eudora from Qualcomm allows you to receive and send Internet e-mails"
UEVOLOSTAEVOLOSTA.EXE"Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID
YEZ Firewallca.exe"eTrust EZ Armor Internet Security"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
UFLMBROWSERMOUSEmouse32A.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMK08KBKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMLABTECMOUSEmouse32A.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMMEDIONMOUSEmouse32a.exeMouse utility for a Medion branded Fellowes mouse
UFLMOFFICE4DMOUSEmouse32a.exeMouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMTRUSTKBKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMTRUSTMOUSEmouse32a.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
Yfsaafsaa.exe"F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers"
XFSHsvcnva.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
Xgabougoolnounina.exe"Added by the AGENT-JVX TROJAN!"
UGammaHotKeyssetgamma.exe"Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop"
Xgangstagangsta.exe"Added by the RIMA.A BACKDOOR!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
YGetcaInfoMyCa.exe"Monitor for a Belkin USB Wireless adapter"
XGo!Zillagozilla.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
NGRAgra.exe"Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up
Xgtydfiisca.exe"Added by the CLAGGER-BB TROJAN!"
Xgtydfiscca.exe"Added by the DWNLDR-GTK TROJAN!"
XHDAudiohda.exe"Added by the TACTSLAY.U TROJAN!"
XHELPERcanada.exe"AsdPlug premium rate adult content dialer variant"
XHLL Data Parameterhllcxpa.exe"Added by the RBOT.AFG WORM!"
XHotbarSAHotbarSA.exe"Hotbar adware"
?HP Network Registry Agenthpnra.exe"??"
NHP ScanPicturehpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
?hpjsiroutehpjsira.exe"Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2""
Nhpodbliahpodblia.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
YhppptaHPPPTA.exeHP parallel port driver for certain hardware
?IDAIDA.EXE"Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?"
XIE Java Updateiejava.exe"Added by the AGENT-HD TROJAN!"
XIEACCESSsurfya.exe"
Xigamatuatecaca.exe"Added by the IRCBOT.R WORM!"
UInstallBuddyIbtna.exe"InstallBuddy - automatically translates and installs your desktop documents
XInternalSystrayKazza.exe"Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable
UInternet Download Acceleratorida.exe"Internet Download Accelerator download manager"
XInternet Firewall Layertsqla.exe"Added by a variant of the SPYBOT WORM!"
NIntroducing Media ManagerSPLASHA.EXE"MS Media Manager tour. Not required"
YISLP2STAISLP2STA.EXEA process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers
Xisxaisxa.exe"Added by the SMALL-EIV TROJAN!"
XiTunesAgentita.exe"Added by the TACTSLAY.U TROJAN!"
XJava Runtime Valuerunjava.exe"Added by the RBOT-DDJ WORM!"
XJavaVMjava.exe"Added by the MYDOOM.M WORM and variants! Note - not to be confused with the valid Windows ""java.exe"" which is located in %System% as this is located in %Windir%"
Xjavawsa.exejavawsa.exe"Added by the BANK-Y TROJAN!"
NKAZAAkazaa.exe"KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it"
XKazaa lptt01kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
XKazaa ml097ekazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
Xlcvgalcvga.exe"Added by the HOSTOL-A TROJAN!"
XLisaLisa.exe"Added by the SCOM-D premium rate adult content dialler"
XloadKHATRA.exe"Added by the ORBINA-A WORM!"
XLOAD32Lorena.exe"Added by the MAPSON.C WORM!"
Xload321111a.exe"Added by the DUMARU.AH WORM!"
Xload32netda.exe"Added by the NIBU.E TROJAN!"
Xload32winldra.exe"Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
XLoginlala.exe"Added by the BUGSPR-A TROJAN!"
XLoveHebeAvistaAA.exe"Added by the LOZAVITA TROJAN!"
XLSAlsa.exe"Added by the SDBOT-YV WORM!"
ULWBKEYBOARDKbdAp32A.exeKeyboard utility for a Labtec brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
ULWBMOUSEMOUSE32A.EXEMouse utility for a Lenovo brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
XMachineTestCMagesta.exe"Added by the SDBOT-NE WORM!"
NMadExeLaunchRA.exe"Part of Dell Resolution Assistant - ""a diagnostic program that allows you to contact Dell. When factory-installed by Dell
XMapiyashaMapiyasha.exe"Added by the SILLYFDC-DM WORM!"
NMECAMeca.exe"Meca cross-platform communications technology
XMedia Playermedia.exe"Added by the FLDMEDIA-A TROJAN!"
XMicrosoftwinampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftsymtea.exe"Added by the SPYBOT.AMTE WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Datalog Applicationmsdata.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLLfumeta.exe"Added by the RBOT-AUG WORM!"
XMicrosoft Hyptertext Helpermshtha.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Machineupdata.exe"Added by the RBOT-DJ WORM!"
XMicrosoft Nvidia Videonvidia.exe"Added by a variant of the SDBOT WORM!"
NMicrosoft Officeosa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Office quick launchOSA.exe"Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
NMicrosoft Office Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft quick launchOSA.exe"Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
XMicroSoft ssas3s1SADASDA.exe"Added by the RBOT.URF WORM!"
XMicrosoft Synchronization Managerjava.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Synchronization Managerwmedia.exe"Added by the SDBOT.BFC WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft Telecoma Centertellcoma.exe"Added by the RBOT-AWX WORM!"
XMicrosoft Updatephqghumea.exe"Added by the SDBOT.AFO WORM!"
XMicrosoft Updateimchemaoa.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Update 32neta.exe"Added by the RBOT-AMI WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
Xmmxrunmsosa.exeAdded by an unidentified TROJAN or WORM!
Xmonitor1amonitor1a.exe"Added by the MSNAGEN-A TROJAN!"
UMouse 32AMouse32A.exeMouse utility. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
XMozilamozila.exe"Added by the DELBOT-AJ WORM!"
NMozilla Quick LaunchMozilla.exeNetscape 6 and Mozilla browsers
XMp3 LoaderSysdata.EXE"Added by the AVETTE-A VIRUS!"
XMr_CoolFace_GameEmma.exe"Added by the ROMARIO-A WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMS LARISSAMS_LARISSA.exe"Added by the ASSIRAL.B WORM!"
XMS32DLLffqca.exe"Added by the SDBOT-YD WORM!"
Xmsfindosa.exemsfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
XMS_LARISSAMS_LARISSA.exe"Added by the ASSIRAL WORM!"
XMy Kazaa GoldMyGoldKazaa.exe"My Kazaa Gold - regarded as a scam by McAfee SiteAdvisor as you're paying for something which available for free elsewhere"
XNcaoosoa.exe"PurityScan adware"
XNeroUpdate Checkmsjava.exe"Added by the AGOBOT.AMH WORM!"
XNeroUpdater6.8winjava.exe"Added by the AGOBOT.AMK WORM!"
UNetManageImportnmcpdata.exe"NetManage business software related"
XNetropa Internet ReceiverNetropa.exeNetropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
XNeuroMedia(IESpeaker)NeuroMedia.exe"Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available"
Xnisdisanisdisa.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
UNliaClientNetpia.exe"Netpia NLIA System - ""In the existing Internet address system
XNordBullmsa.exe"Added by the DLOADR-CSV TROJAN!"
XNorton Auto Protectnava.exeAdded by an unidentified WORM or TROJAN!
XNorton Updaterlsa.exe"Added by a variant of the RBOT WORM!"
XNotnwtta.exe"PurityScan adware"
Xnovsvida.exenovsvida.exe"GlobalAccess dialer"
Xnsdluansdlua.exeAll-In-One Telcom - adult content dialler
XNTSF MICROSOFT SYSTEMmarya.exe"Added by the RBOT-AXY WORM!"
XnwizKHATRA.exe"Added by the ORBINA-A WORM!"
NOffice Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
UOFFICEKBkbdap32a.EXE"Keyboard utility for a Micro Innovations brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard"
XOneMoreKeyxpa.exe"XP Antivirus rogue security software - not recommended"
Xp2snetiscomippwa.exe"Added by the SPAMTOO-AL TROJAN!"
Upamela.exepamela.exe"Pamela is a plug-in or add-on that adds features to Skype peer to peer voice service"
XPanterapantera.exe"Added by the SDBOT.AYN WORM!"
XPC-Config32corona.exe"Added by the CORONEX.A WORM!"
UPCRecSAPCRecSA.exe"Part of the IBM/XPoint Rapid Restore backup utility. If you choose
UpdfFactory Dispatcher v1fppdis1a.exe"FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UpdfFactory Dispatcher v2fppdis2a.exe"FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 2.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UpdfFactory Pro Dispatcher v3fppdis3a.exe"FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory Pro printer. Version 3.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
Xpointmaniapointmania.exe"PointMania adware. File located in %Program Files%\pointmania"
XPopup Blocker System326a MonitoringPopUpBlocker6a.exe"Added by the RBOT.AUH WORM!"
UPP Gammappgamma.exe"Profile Prism software that allows monitor calibration and can generate ICC profiles for digital cameras"
?PrimstaPrimsta.exe"Linksys Wireless CompactFlash Card driver related. Is it required?"
UPRISMSTA.EXEPRISMSTA.EXECreates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
XPurgatoryPurga.exe"Added by the PURGORY-B WORM!"
?QueenslaQueensla.exe"??"
XRcshweaa.exe"PurityScan adware"
XRegistry Checkup System326a MonitorWinregs326a.exe"Added by a variant of the SDBOT WORM!"
XRegistry Value Name StartMsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
Xrestorer32_arestorer32_a.exe"Added by the AGENT.CQQB TROJAN!"
Xrestorer64_arestorer64_a.exe"Added by the DLDR-BY TROJAN!"
XRosTikaRosTika.exe"Added by the BRONTOK-BU WORM!"
Xrpcda Win32rpcda.exe"Added by the RBOT-AEE WORM!"
Xrunmexica.exe"Added by the AUTORUN.AEV WORM!"
Nrun=fmedia.exeFMedia FaxWorks related - can be run manually
Xrunner1tsitra.exe"Added by the AGENT.ABFQ TROJAN!"
XSakoraSakora.exe"Added by the GOWELES.A TROJAN!"
Xsecure socket layerwins32a.exe"Added by an IRCBOT TROJAN!"
XSeekmoSASeekmoSA.exe"180Solutions.Seekmo adware variant - also see here"
USensivaSensiva.exe"Symbol Commander makes the use of your PC
XServices Controllerlsassa.exeAdded by the CIADOOR.122 VIRUS!
XSession Manager Subsystemsmssa.exe"Added by the RBOT-AGS WORM!"
Xsfitasfita.exe"Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware"
NShareazaShareaza.exe"Shareaza P2P client"
UShareazabindata.exe"Shareaza P2P client related"
XShellNisca.exe"Added by the IBILL.Z TROJAN!"
USIAPRO6sia.exe"Steganos Internet Anonym privacy software"
NSigmatelSysTrayAppstsystra.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
NSimplify MediaSimplifyMedia.exe"Simplify Media media manager - ""enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online"""
XSkraSkra.exeIdentified as a variant of the TrojanDownloader.Matcash malware
Usmasma.exe"SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
NSmart Type Assistantsta.exe"Smart Type Assistant - a complex typing automation tool
?Smcsta.exeSmcsta.exe"SMC Networks wireless PCI card driver. Is it required?"
XSocial Security Agencyrpcxsocsa.exe"Added by a variant of the RBOT WORM!"
?Sootrcea.exe"??"
NSpellex Anywheresa.exe"Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used"
?SprintPortSprintPortA.exe"Novatel wireless modem related. What does it do and is it required?"
XSpywareKillaSpywareKilla.exe"SpywareKilla spyware remover - not recommended
XstartkeyMysia.exeAdded by the CEP TROJAN!
Xstatloadspgjd83sa.exe"Added by the SDBOT-UM WORM!"
UStayAlivesa.exe"StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen
USTOPzillaStopzilla.exe"StopZilla! - pop-up killer"
NSurveysasurveysa.exe"Found on Sony laptops
Xsvcdata.exesvcdata.exe"Added by the SPYBOT.ZIF WORM!"
Xsvchostasvchosta.exe"Added by the SNIFFER-I TROJAN!"
Xswitpswitpa.exe"OfferAgent adware"
XSygate Peral FirewallSyga.exe"Added by the RBOT-AQK WORM!"
XSygate Personal FirewallSyga.exe"Added by the RBOT-AQD WORM!"
USymKeepAliveCKA.exe"Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive"
XSynchronization Agentmobsynca.exe"Added by the RANDEX-E WORM!"
XSysqqweiba.exe"Added by the DELF-CFX TROJAN!"
XSystemAtira.exe"Added by the KOTIRA VIRUS!"
XSystem Database administrationsystemDA.exe"Added by the DERDERO.B WORM!"
NSystem DLFcpqdiaga.exeCompaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
XSystem Servicessvcsenes32a.exe"Added by the RBOT-AFG WORM!"
Xsystem updataupdata.exe"Added by the LINEAGE-C TROJAN!"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystemMgrIr32_a.exe"Added by the MAGANIA-OU TROJAN!"
XSystemMigrationWinMedia.exe"Added by the KELVIR.EI WORM!"
XSystemtraSystra.exe"Added by the LOVGATE-W WORM!"
XSystesjrdtifkkxbbsa.exe"Added by the RBOT-ADC WORM!"
USysW8csta.exe"Clean Space internet evidence eliminator"
XT2WMemoria.exe"Added by the DROPPER.CYG TROJAN!"
UTapiTNATapiTNA.exe"Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys"
XTaskmanKHATRA.exe"Added by the AUTORUN-AKR WORM!"
XTaskmon driverwinampa.exe"Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
Ytcactivetca.exe"Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage"
XTdrbompa.exe"PurityScan adware"
?TeslaTESLA.EXE"??"
XTrustNinjaTrustNinja.exe"TrustNinja rogue security software - not recommended
Xttaatata.exe"Added by the LINEAGE-T TROJAN!"
Xtwhewbta.exe"PurityScan adware"
Yumxldraumxldra.exe"User mode executive module DLL loader - part of Tiny Personal Firewall V4"
XUpDatawupdata.exe"Added by the IRCBOT-AA TROJAN!"
XUpdateMediaUpdateMedia.exe"MediaUpdate foistware"
UUpromise UpdateUpromiseUa.exe"Updater for the Upromise college savings program"
XUSAusa.exe"USAntiSpy rogue security software - not recommended
YUSRpdAUSRmlnkA.exeModem driver files from US Robotics
?USRSTAUSRSTA.exe"Wireless Card controller. What does it do and is it required?"
?USRSTA.EXEUSRSTA.EXE"Wireless Card controller. What does it do and is it required?"
XUssirwsa.exe"PurityScan adware"
Xvbwg cuteaaa.exe"Added by the VB-DZG TROJAN!"
XVdat Updatelalaa.exe"Added by a variant of the RBOT WORM!"
UVGAUtilG-VGA.exe"Gigabyte VGA Utility - access card options (application needs to be run at startup
NVidaliaVidalia.exe"Vidalia is a cross-platform GUI controller for the Tor anonymityn package. Using Vidalia
YVideoraVideora.exe"Video Holding personal video downloading program"
UVirtuele KatjaVKatja.exe"Virtuele Katja - have an attractive moviestar parade on your Desktop and help you search the Dutch ""Gouden Gids"" business directory too..."
XVirus Scanvirscana.exe"Added by an unidentified VIRUS
XVMware User ProcessKHATRA.exe"Added by the AUTOIT.K TROJAN!"
Xvptraya analyzingvptraya.exe"Added by the RIZO.A TROJAN!"
XWebSUpdaterwupda.exe"Added by the STARTPAGE.C TROJAN!"
XWin l5oahderwinampa.exe"Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
XWin Server Updtpxckdla.exe"IEPlugin adware"
XWin32 LSA Driverlsa.exe"Added by the FORBOT-FJ WORM!"
XWin32 nvcnvcva.exe"Added by the RBOT-ABF WORM!"
XWinamp Mediaqmedia.exe"Added by the DIAZMON-A TROJAN!"
XWinamp media playerwinapa.exe"Added by an unidentified VIRUS
UWinampaWINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinampawinampa.exe"Added by the AGOBOT-GS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
XWinampa AgentWINAMPA.EXE"Added by the SPYBOT-BR WORM! Note - this is NOT the popular Winamp media player which is normally located in %ProgramFiles%\Winamp. This one is found in %System%"
UWinampAgentWINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinDLL (asdfsa.exe)"rundll32.exe asdfsa.exestart"
XWindows Default Serverwinampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
XWindows Gamma Displaywingamma.exe"Antivirus 2010 rogue security software - not recommended
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
XWindows Media Playermsa.exe"Added by the RBOT-SI WORM!"
XWindows Media Playermpupdata.exe"Added by the SDBOT.BBG WORM!"
XWindows Media Player Servicewmedia.exe"Added by the RBOT.213504 WORM!"
XWindows Registry Scanwinmedia.exe"Added by the SPYBOT.GK WORM!"
XWindows Relay Serviceirfnga.exe"Added by the DROPPER.ACO TROJAN!"
XWindows Service Agentywgma.exe"Added by the RBOT.DZT BACKDOOR!"
XWindows svchostserviceaaa.exe"Added by the PUSHBOT.ER WORM!"
XWINDOWS SYSTEMbeta.exe"Added by the MYTOB.DF WORM!"
XWINDOWS SYSTEMgothica.exe"Added by the MYTOB.HU WORM!"
XWindows Update CenterW32RSA.exeAdded by an unidentified WORM or TROJAN!
XWindows Workstationmsup32a.exe"Added by a variant of the SDBOT WORM!"
XWindoxs Update CenterW32RfSA.exe"Added by a variant of the SDBOT WORM!"
Xwinlawinla.exe"Added by the DLOADR-AQL TROJAN!"
XWinToolsWToolsA.exe"Wintools adware"
NWLAN Status Tray AppletWLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
NWLANSTA.EXEWLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
XWNSIrwsa.exe"PurityScan adware"
YWU713STA.EXEWU713STA.EXEBlitzz Technology wireless NIC adapter driver
Xxdxqadewa.exe"Added by the SDBOT-YB WORM!"
XXP Antivirusxpa.exe"XP Antivirus rogue security software - not recommended"
XXplorerKHATRA.exe"Added by the AUTOIT.K TROJAN!"
UYou've Got Pictures Screensaverygpsstra.exeAOL You've Got Pictures Screensaver
XZangoSAZangoSA.exe"Zango Search Assistant adware"
Xzupacha.exezupacha.exe"Added by the DROPPER-QL TROJAN!"
X[32 random numbers]xpa.exe"XP Antivirus rogue security software - not recommended"
X[random name]iexpl0ra.exe"Added by the ULPM.BD TROJAN!"
X[random name]rundl13a.exe"Added by the GAMPASS-L TROJAN!"
X[various names]corrida.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]pizda.exe"Wareout - malware masquerading as a spyware and dialer remover"
X{29123221-3AF8-488c-85DE-6B3EC59E8074}netmedia.exe"NetMedia adware"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sxpgknrwva.exe"Added by the FAKEALERT-AM TROJAN!"
X{42562052-EE17-4197-82C7-91CB2E4B0666}sysrswva.exe"Added by the FAKEALERT-AH TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.