Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Inc.""Machine WorksXaecces.exe
X(*)API MachinewinSOCKS.exe"Homepage hijacker
U24Online ClientCyberoamClient.exe"Related to Cyberroam from Elitecore Technologies Ltd"
Y@OnlineArmor GUIoaui.exe"System Tray access to and main user interface for the Online Armor range of security tools from Tall Emu Pty Ltd. The free version incorporates a firewall
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
?Ad Online Guideadonlineguide.exe"??"
NAmerica Onlineaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAmerica Online *.* Tray Iconaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
XAttuneClientEngineattune_ce.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAvengineAvengine.com"Added by the DELF.LJ TROJAN!"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
UBrowser SentinelBrowserSentinel.exe"Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer
?ChangeLineschngline.exe"??"
UChineseStarcstar.exeChinese language support software
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
Xcosinecosine.exe"Added by the RBOT-SW WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
Xctfmon.exectfmon.exe eminem.exe"Added by the BHARAT.A WORM!"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
NDigital Line DetectDLG.exeDetects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
XDownloadWare EngineDwe.exe"DownloadWare adware"
UeMachines eBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
Uenginecs2enginecs2.exe"Cyber Sentinel - internet filtering software"
NESPN BottomLinebline.exe"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop
YezPS_PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
XFCEngineFCEngine.exe"CASClient adware"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
NFromine WinPopupwinpopup.exeInstant Messenger program
NHard Disk SentinelHDSentinel.exe"Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find
XIEengineIEeng.exe"STARTPAG.AI hijacker"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XINETinetsync.exe"Meplex adware"
XInet DataBaseInetdbs.exe"Added by the QEDS WORM!"
XInet Deliveryinetdl.exe"Inet Delivery adware"
XInet Deliveryinetdl_2.exe"Inet Delivery adware"
XInetapiNetapi.exe"Added by the NETDEVIL.14 TROJAN!"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
Uinetcntrlinetcntrl.exeBsafe Online - internet filter
?InetConfinetconf.exe"??"
UInetdINETD32.EXE"Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation"
Uinetinfo.exeinetinfo.exe"Executable used by MS Internet Information Server (IIS). If it's running
Xinetinfomon managerinetinfomon.exe"Added by the DONBOMB.A TROJAN!"
Xinetmgrinetmgr.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XInetMSNmsnet.exe"Added by a variant of the SDBOT TROJAN!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
XInstant Accesslinewsrv.exe"InstantAccess premium rate adult content dialer variant"
XIntel Physical Routine 1.2Astnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
UInternet Answering MachineIAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
NIntervideo Win Cinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
XISSinet.exe"Meplex adware"
XJava Virtual Machinejavaw.exe"Added by a variant of the RBOT WORM!"
Xl44sys**winmine"Added by the VBS.LIDO WORM - where ** is a number between 33 and 44"
NLine Speed Meter V3.0LineSpeedMeter.exe"LineSpeedMeter - detect the download and upload speed of your internet connection"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
Xload=inetinfo.exe"Added by the PROXY-GG TROJAN!"
NLogitech QuickCamManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
NLogitechSoftwareUpdateManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
XMabochine Deybug Malnagerkdm.exe"Added by the SDBOT-SD WORM!"
UMachine Debug ManagerMDM.EXE"Used by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to ""hang"" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the ""RunServices"" key in Me (located in C:\WINDOWS\SYSTEM). It also loads a service in XP/Vista (located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug)"
XMachine Debug Managermsdn.exe"Added by a variant of the RBOT WORM!"
XMachine Debug Managermdm.exe"Added by the SDBOT-APE WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
XMachine Debug Managermdms.exe"Added by the SDBOT-CH WORM!"
XMachine Update Softwusas.exeAdded by an unidfentified WORM!
Xmachine-debuggerWMIPRVSW.exe"Added by the AGOBOT.WW WORM!"
Xmachine-debuggermdmsv.exe"Added by the AGOBOT-BR WORM!"
XMachineTestCMagesta.exe"Added by the SDBOT-NE WORM!"
NManifestEngineManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
UMcAfee Online BackupMOBKstat.exe"System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Online Backup StatusMOBKstat.exe"System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
XMcAfee Online virus Scanneravp.exe"Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XMcAfee Online Virus Scannernzm.exe"Added by the IRCBOT.XV WORM!"
UMDSA Sentinel Xsmss.exe"SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
XMicrosoftwinline.exe"Added by the AGENT.KT TROJAN!"
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Data Machinecsdata32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Event EngineEvtEngn.exe"Added by the RBOT-XV WORM!"
XMicrosoft Genuine Logonmsnmsg.exe"Added by the IRCBOT-XH WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Inet Xp..teekids.exe"Added by the BLASTER.C WORM!"
XMicrosoft Internet Dumping Protocolinetdump.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Internet Syncinginetsync.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Java Virtual Machinemsjvm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Java Virtual Machinejavavm.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft machineblah.exe"Added by a variant of the RBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft Machineupdata.exe"Added by the RBOT-DJ WORM!"
XMicrosoft Machinetemp.exe"Added by the RBOT-FSQ WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft machinearcpack.scr.exe"Added by the RBOT.ADF BACKDOOR!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update Machinerxhost.exe"Added by the RBOT.FC WORM!"
XMicrosoft Update Machineservicz.exe"Added by the RBOT-HU WORM!"
XMicrosoft Update MachineSP2.exe"Added by the SPYBOT.FP WORM!"
XMicrosoft Update Machinewinini.exe"Added by the RBOT-KV WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinememstat.exe"Added by the RBOT-OM WORM!"
XMicrosoft Update Machinentce.exe"Added by the RBOT-FA WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Update Machinewuawx.exe"Added by the RBOT-CE WORM!"
XMicrosoft Update Machinezonealarm.exe"Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
XMicrosoft Update Machinesystemll.exe"Added by the RBOT-JT WORM!"
XMicrosoft Update Machinewinupdt.exe"Added by the RBOT-FP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinewuamgd.exe"Added by the SDBOT.HQ WORM!"
XMicrosoft Update Machinewupdt32x.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelinux.exe"Added by the RBOT-IM WORM!"
XMicrosoft Update Machinelmrss.exe"Added by the RBOT-DY WORM!"
XMicrosoft Update Machinewindowsu.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewininigo.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewinmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Update Machinewuamgrd.exe"Added by the RBOT-HE WORM!"
XMicrosoft Update Machinewuagrd.exe"Added by the RBOT-GF WORM!"
XMicrosoft Update MachineLANWAKE.EXE"Added by the RBOT-QZ WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update MachineWUAMGRDXS.EXE"Added by the RBOT-GL WORM!"
XMicrosoft Update Machinecrss32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelsasse.exe"Added by the RBOT-DI WORM!"
XMicrosoft Update Machineqwerty.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinerxxhost.exe"Added by the RBOT.EP WORM!"
XMicrosoft Update Machineservicez.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Update Machinespoolserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineSystemnt.exe"Added by the RBOT.DA WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update Machinetaskmngrs.exe"Added by the RBOT-CR WORM!"
XMicrosoft Update Machinewindowsup.exe"Added by the RBOT-FV WORM!"
XMicrosoft Update Machinewuamgard.exe"Added by the SPYBOT.CS WORM!"
XMicrosoft Update Machinewupdate32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinesystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTMEMSER.EXE"Added by the RBOT-NQ WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinortho.exe"Added by the RBOT-NW WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update Machineserviz.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTASKMAN4.EXE"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewftestb.exe"Added by the RBOT-AFZ WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machinejkfrnz.exe"Added by the RBOT-GOZ WORM!"
XMicrosoft Update Machinewlimyc.exe"Added by the RBOT-GQN WORM!"
XMicrosoft Update Machinexagwxzy.exe"Added by the RBOT.S WORM!"
XMicrosoft Update Machinejkydxg.exe"Added by the RBOT.AEA BACKDOOR!"
XMicrosoft Update Machineopmmve.exe"Added by the KOLABC.DES WORM!"
XMicrosoft Update Machinepaxrxo.exe"Added by the PUSHBOT.A WORM!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Update Machinesyadpo.exe"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Update Machinesystemi.exe"Added by the BUZUS.JKU TROJAN!"
XMicrosoft Update Machinethvfyq.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machineubthec.exe"Added by the AGENT.AWZ TROJAN!"
XMicrosoft Update Machinewinmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
XMicrosoft Update Machinegbhglj.exe"Added by the IRCBOT-ZJ TROJAN!"
XMicrosoft Update Machinewuamgdr.exe"Added by the RBOT-IO BACKDOOR!"
XMicrosoft UpdateS Machinewgrd.exe"Added by the RBOT-FI WORM!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicrosoft UpMachinedoezs.exe"Added by the RBOT.BCT WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Winedows startupWinKey.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Winedows UpdateingNinKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMMicrosoft Security Managementinetforn.exe"Added by the RBOT.AFZ WORM!"
XMS Java virtual machinejavavm.exe"Added by the RBOT.ABG WORM!"
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
XMsinetMsinet.exe"Added by the RBOT-AOA WORM!"
NMSN Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
NMSNŽ Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
Nmswinextmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMy Security EngineMS[random characters].exe"My Security Engine rogue security software - not recommended
Xmysoftwinexplor.exe"Browser hijacker
NNetline Usernetchk.exe"Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game
XNetMeterNielsenOnline.exe"NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited
UNsengineNsengine.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
XNT Virtual Machine[path to file]"Added by the SCAERBOT-A WORM!"
UOfflineFileSyncOfflineFileSyn.exe"Offline synchronization part of ZANTAZ EAS (Enterprise Archive Solution) - which ""is a secure
YOnline Armor Firewalloaui.exe"System Tray access to and main user interface for the Online Armor range of security tools from Tall Emu Pty Ltd. The free version incorporates a firewall
?online cdromActive acid.exe"??"
XOnline Servicesvchost.exe"Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XOnline Servicestwain.exe"Added by the AGENT.BEA TROJAN!"
YOnlineArmor GUIoaui.exe"System Tray access to and main user interface for the Online Armor range of security tools from Tall Emu Pty Ltd. The free version incorporates a firewall
XOnlineGuardOnlineGuard.exe"OnlineGuard rogue security software - not recommended
XOnlineHelpmateGDC.exe"OnlineHelpmate rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UOnlinePCfix SmoothSurferSS.exe"Smooth-Surfer - blocks banners
NOnlineTimeonlinetime.exe"OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs"
Xonline_partyonline_party.exeAdult content dialler
XOptimum OnlineNetsurf.exeOptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity
XPandaAVEnginePandaAVEngine.exe"Added by the NETSKY.R WORM!"
UPDEnginePDEngine.exe"PerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot"
UpdfMachine dispatchermapisnd.exe"pdfMachine Windows print driver"
UPervasive.SQL Workgroup EngineW3dbsmgr.exeDatabase Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
?PFW_CfgEnginePFWCFG~1.EXE"Personal Firewall related?"
YQuick Heal On-Line ProtectionCateye.exe"Quick Heal - virus scanner"
URealtime Audio Enginemmrtkrnl.exe"Associated with ALCATech BPM Studio"
NRedline Taskbartaskbar.exeTaskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
XRoot_Machine[path to trojan]"Added by the BANCBAN-DI TROJAN!"
XROOT_Machinewinlogon.exe"Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
?Roxio EngineMSMNGR32.EXE"Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!"
YRoxio Engine Compatibility WizardEngUtil.exe"Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine
YRoxioEngineUtilityEngUtil.exe"Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine
XRpcxWindows Extensionsrpcxwinex.exe"Added by the RBOT.ACP WORM!"
Xruninetinfo.exe"Added by the BINGHE TROJAN!"
Xrun=Celine.scr"Added by the CELINE-A TROJAN!"
XRundll32_8"rundll32.exe inetp60.dll DllRunServer"
NScotia OnLine Recoveryetdirrcv.exe"Scotia OnLine Security Software provided by Entrust for
NScotia OnLine Security v*.* Recoveryetdirrcv.exe"Scotia OnLine Security Software provided by Entrust for
USecureOnlineAccountNumbersSOAN.exe"Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions"
XSecurity Antivirus Xp 1inetfor.exe"Added by the SDBOT.BAV WORM!"
XShineShine.exe"Added by the HAPPYLOW (or NISHE-A) VIRUS!"
NShockmachineReminderSmReminder.exe"""Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline"". Could be a registration reminder for the trial version"
XsInErA.exe"Added by the SILLYFDC-AB WORM!"
USmarthruengineQS.exe"Samsung smarthru software
USolidWorks Task Scheduler EngineswBOEngine.exe"Task scheduler for SolidWorks 3D CAD software"
Xssgrate.exewinerdir.exe"Added by the MITGLIEDER.O TROJAN!"
Xsvchostinetinfo.scr"Added by the ODELUD WORM!"
XSymantec Security Routine Addonnavpaw.exe"Added by the AGOBOT-ES BACKDOOR!"
XSymantec Security Routine Addon for Microsoft Windowsnavpxaw32.exe"Added by the AGOBOT-GJ TROJAN!"
XSysteminetinfo.exe"Added by the PARDROP-A TROJAN!"
NSystem Mechanic Professional Update [Incinerator.dll]SysMech4.exe /REREG: [path] Incinerator.dll"Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updater Machinecrhwss.exe"Added by the CIADOOR-DQ TROJAN!"
XSystem Updater Machinesystem.exe"Added by the CIADOOR.GN BACKDOOR!"
XSystem64inet.exe"Added by the DENGLE-A TROJAN!"
XTask Scheduler Engineschedsvc32.exe"Added by the RBOT-ASJ WORM!"
XThe Registry SentinelThe Registry Sentinel.exe"The Registry Sentinel rogue security software - not recommended
XThe Web SentinelThe Web Sentinel.exe"The Web Sentinel rogue security software - not recommended
XTigerShine.exe"Added by the HAPPYLOW (or NISHE-A) VIRUS!"
NTimeOnlineTIMEONLINE.EXELightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
NTurbine Download Manager Tray IconTurbineDownloadManagerIcon.exe"Turbine Download Manager (TDM) - download manager associated with the game ""The Lord of the Rings Online™"""
XUndefinedwinter.exe"Added by the KILLAV.LW TROJAN!"
NUsrobotics Online Registration??Pop-up reminding customers to register their products online at US Robotics
XVagiconlinevadaSq.exe"Added by the SDBOT-TD WORM!"
UVerizon Online Support Centermatcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xvirtual-machinesvchosts.exe"Added by the RBOT-US WORM!"
Xvirtual-machinewinlogin.exe"Added by the RBOT-VU WORM!"
Xvirtual-machinewini.exe"Added by the RBOT-WR WORM!"
YVirusScan Onlinemcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
?WildTangent CDA"RUNDLL32.exe cdaEngine0400.dll cdaEngineMain"
NWINCINEMAMGRWINCIN~1.EXE"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NWinCinemaMgrWinCinemaMgr.exe"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
UWINCINEMAMGRWinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
XWindowEnhancerWinex.exe"SCBar foistware variant"
XWindows Explorer ShellWinexec32.exe"Added by the REDIST.B WORM!"
XWindows Genuinesvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
XWindows Online Updaterdllman.exe"Added by the RBOT-TE WORM!"
XWindows Updateinetinf.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Updater Onlinewinupdatexx.exe"Added by a variant of the RBOT WORM!"
Xwinenvwinenv.exe"Added by a variant of the SDBOT WORM!"
XWinEssentialKeyhost.exeHijacker - hailing from jraun.com
XWinEssentialkeyword.exe"Jraun adware"
XWineWorkWineWork.exe"Added by the BANCOS.AB TROJAN!"
XWinExlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XWinExecWinexec.exe.vbs"Added by the AINESEY.A WORM!"
XWinExecWinExec.exe"Added by the FALUS-A WORM!"
XWinExecLsass.exe"Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinExec32WinExec32.exe"Added by the KAZWIN WORM!"
XWinexec32windhelp32.exe"Added by the AGENT-HKU TROJAN!"
Xwinexecswinexecs.exe"Added by the SILLYFDC.BBB WORM!"
UWinGate Engine Monitorwgengmon.exe"WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine
XWinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
Xwininetwininet.exe"Added by the STUBBOT-C WORM!"
Xwininet.dllregperf.exe"Added by the ZLOB TROJAN and variants!"
Xwininet32wininet32.exe"Added by the RAZNEW-A TROJAN!"
Xwininetdwininetd.exe"Added by the WINET TROJAN!"
XWinMineD4NG3.vbs"Added by the BISCUIT.A WORM!"
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
XWins32 Onlinecfgpwnz.exe"Added by the BROPIA.R WORM!"
XWinupdate Enginewupeng.exe"MalwareCrush rogue security software - not recommended
UYahoo! Widget EngineYahooWidgetEngine.exe"Yahoo! Widget Engine lets you run little files called Widgets that can do pretty much whatever you want them to"
X_WinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus"
X_WinMainwinexec.exe"Added by the DLOADER-XX TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.