Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
UAbsolute Shielddseraser.exe"Absolute Shield Evidence Eliminator - internet history eraser"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans
YActiveShieldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
XAntiSpyGoldenAntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGolden 5.1AntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
Xantispysoldierantispysoldier.exe"AntiSpyware Soldier rogue spyware remover - not recommended
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield rogue security software - not recommended
XAntiviralGoldenAntiviralGolden.exe"AntiviralGolden rogue security software - not recommended
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
NAOLDialerAOLDial.exeAOL ISP software dialer - can be activated through a desktop shortcut
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
YArovax ShieldArovaxShield.exe"Part of Arovax Shield from Arovax
YArovaxShieldArovaxShield.exe"Part of Arovax Shield from Arovax
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
Xasr64_ldm.exeasr64_ldm.exe"Added by the Dr. Guard rogue security software - not recommended
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Nbldbubgbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
UBTopenworldDialBTYahoo.exeBT Yahoo! internet connection manager
NBuildBUbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XBuildLabslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
XCiaBackdoormsldr.comAdded by a VIRUS!
UCMGShieldUICMGShieldUI.exe"UI for CMG (CREDANT Mobile Guardian) Shield from Credant Technologies. ""The CMG Shield resides on devices and external media to enforce security policies even if the device is disconnected from the network."" Used to protect sensitive corporate on laptops
XColdlife -icmpSystray.exe"Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XCorelDraw ToolboxCorelDraw.exe"Added by the SDBOT-VZ WORM!"
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
UCPLDFL10CPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttons
Xcqlygworld_cup_.bat"Added by the WCUP.A WORM!"
Xcximddlldfrmmd.exe"Added by the BUZUS.CQMU TROJAN!"
?DellDMIdelldmi.exe"Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
Udevldr16devldr16.exeAssociated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Udevldr16.exedevldr16.exe"Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
XDivx4 codecdevldr32.exe"Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
Xdlderdlder.exe"Dlder spyware. Also creates a fake ""explorer.exe"" file and can be installed via versions of Grokster
XDlDir1caKe"Added by the CAKE WORM!"
Udldtamondldtamon.exeDell AIO Printer V305 device monitor
Udldtmondldtmon.exeDell AIO Printer V305 device monitor
Udldtmon.exedldtmon.exeDell AIO Printer V305 device monitor
Xdlldmtdlldmt.exe"Added by a variant of the CRYPTER.C TROJAN!"
NDMILDRdmildr.exe"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
Xdrvsyskithldrrr.exe"Added by the BAGLE.QU TROJAN!"
NDulux WeatherShield WeatherDeskweather.exe"Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
UEFI Hot Foldershffw.exe"""EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select
?Executedelfolders.exe"??"
YezShieldProtector for PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
UFolder Viewfolderview.exe"Folder View enhances the Windows file Explorer by making all folders you need available in a single click"
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
XFolderRaper[path to worm]"Added by the VB.GOZ WORM!"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
NFolding@homeWINFAH.EXE"Folding@Home is a distributed computing project which studies protein folding
XFontsLoaderldfnt32.htaUnidentified malware
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
YfsprFolderShield.exe"Folder Shield - hide personal files and folders"
UGazelDisplaygsyno.exe"BT Digital Access USB - Gazel ISDN installation System Tray icon"
XGoldenAntiSpypgs.exe"GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
Xhelloworldnb32ext2.exe"Added by the MYDOOM.BV WORM!"
Xhelloworldnb32ext3.exe"Added by the MYTOB.JT WORM!"
Xhelloworld3nb32ext4.exe"Added by the RITDOOR.A WORM!"
Xhldrrrhldrrr.exe"Added by the BAGLE-KF WORM!"
NHPAIO_PrintFolderMgrhpoopm07.exe"Directly from HP: "This process has one purpose - detects if the device moves to a different port
Xhttp://www.lienvandekelder.beLienVandeKelder.exe"Added by the MYTOB-AZ WORM!"
Xhttp://www.lienvandekelder.beLien Van de Kelder.exe"Added by the MYTOB-AP WORM and variants!"
Xhttp://www.lienvandekelder.beLien Vande Kelder.exe"Added by the MYTOB-AQ WORM!"
Xhttp://www.lienvandekelder.beLien vd Kelder.exe"Added by the MYTOB-M WORM!"
Xhttp://www.lienvandekelder.beLien.exe"Added by the MYTOB-CZ WORM!"
Xhttp://www.lienvandekelder.beLientjeuh.exe"Added by the MYTOB-P WORM!"
Xhttp://www.lienvandekelder.beLienVdK.exe"Added by the MYTOB-U WORM!"
Xhttp://www.lienvandekelder.beVan de Kelder Lien.exe"Added by the MYTOB-BF WORM!"
Xhttp://www.lienvandekelder.beWe Love Lien Van de Kelder.exe"Added by the MYTOB-CV WORM!"
Xhttp://www.lienvandekelder.comLien Van de Kelder.exe"Added by the MYTOB-EQ WORM!"
Xhttp://www.lienvandekelder.com/LienVandeKelder.exe"Added by the MYTOB-EO WORM!"
NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
XInternetShieldINTERN~1.EXE"InternetShield rogue security software - not recommended
XInternetShieldInternetShield.exe"InternetShield rogue security software - not recommended
UInventory ScanLDISCN32.EXE"LANDesk® Management Suite software component"
UiShieldiShield.exe"""GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser"""
XJava Runtime Environmentjbuild.exe"Added by the DELBOT-J WORM!"
XJnskdfmf9eldfdcsrssc.exe"Added by the AGENT.EBC TROJAN!"
Xkeymgrldr"rundll32 setupapi InstallHinfSection... keymgr3.inf"
ULANDeskInventoryClientLDIScn32.exe"LANDesk® Management Suite software component"
XLAsIAf32RePEAtLD.exe"Added by the REPEATLD WORM!"
Xlayersldmhostplsrvc.exe"Added by a variant of the SDBOT WORM!"
Xldld.exe"CoolWebSearch Tooncomics parasite affiliate variant - redirects to fastwebfinder.com"
NLDMbackweb-8876480.exe"Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products
NLDMLogitechDesktopMessenger.exe"Installed with the software for Logitech products. Automatically checks for software upgrades and new products
Xldriverldriver.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
Xli-rcash00001vldial.exe"Added by the Vl TROJAN!"
Xload32winldra.exe"Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
NLogitech Desktop Messengerldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
NLogitech Desktop Messenger Agentldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
XMacfee Security PatchMpfsheild.exe"Added by the RBOT-NP WORM!"
XMcafee Auto Protectmcafeshield.exe"Added by the RBOT-UH WORM!"
YMcAfee VirusScanmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
XMCAFFE FLD LOADERMCAFFEFLD.EXE"Added by the RBOT-PY WORM!"
XMcaffeemcsheild.exe"Added by the RBOT-FDP WORM!"
YMcShld9xmcshld9x.exe"Window 9x/Me on-access scanner for older McAfee's internet security products such as VirusScan and VirusScan Online which scans files in real-time for malware as you access
Ymcvsshldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
XmessngerDvldr32.exe"Added by the DELODER.A WORM!"
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Conf Ldrsysconf.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Installshieldnundll32.exe"Added by the AGOBOT-AHZ WORM!"
XMicrosoft Synchronization Managerdevldr32.exe"Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file"
XMicrosoft Time Managerdveldr.exe"Added by the RBOT-HQ WORM!"
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoftUpdateRBuilder.exe"Added by the DLOADR-BMV TROJAN!"
NMicrosoft® Windows® Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
UMilShieldSlaveShieldWorker.exe"Mil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities"
UMirrorFolderShellmrfshl.exe"MirrorFolder backup software"
UModemOnHoldMOH.EXE"NetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more information"
UModemOnHoldnetWaiting.exe"NetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more information"
XMooNlightMySqld-nt.cmd"Added by the BOBANDY-A WORM!"
XMs BuildersWupated.exe"Added by the AGOBOT-SS WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS Windows Local DirectoryMSWLD32.exe"Added by a variant of the RBOT WORM!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
XMSN File & Folder Sharing Appmsnfileshare.exe"Added by an unidentified WORM or TROJAN! See here"
XMsshield.exeMsshield.exe"Added by a variant of the IRCBOT TROJAN!"
XMSWorldmsworld.exe"Added by the AGENT.DED TROJAN!"
Ymurphy shieldlmgui.exe"Firewall part of BitDefender virus scanner/firewall"
UMXO Auto LoaderMXOaldr.exeMaxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
UMXOBGMXOALDR.EXEMaxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
XMy Kazaa GoldMyGoldKazaa.exe"My Kazaa Gold - regarded as a scam by McAfee SiteAdvisor as you're paying for something which available for free elsewhere"
XNdpldaemon[path to trojan]"Added by the RPCSDBOT-A TROJAN!"
XNDplDeamonnstask32.exe"Added by the RANDEX.E WORM!"
XNDplDeamonwinlogin.exe"Added by the RANDEX.E WORM!"
UNetOnHoldFTNOHMgr.EXE"""FaxTalk NetOnHold 1.5 works with the Modem-On-Hold capabilities found in V.92 modems to provide the ability to place an Internet connection ""on hold"" and receive incoming calls or place outgoing calls"""
NNetZIPFoldersnzfprop.exe"
XNeuerSchildpgs.exe"NeuerSchild
Xntldrntldr.exe"Browser hijacker re-directing to search-control.com. In addition to the registry changes found by HijackThis it also creates the following system files: %System%\ntldr.exe
XNvCplDm2gr32.exe"""Switch"" premium rate adult content dialler variant"
XNvCplDntcpl.exe"""Switch"" premium rate adult content dialler variant"
UNvCplDaemon"RUNDLL32.EXE NvQTwkNvCplDaemon"
UNvCplDaemon"RUNDLL32.EXE NvCpl.dllNvStartup"
XNvCplDaemonmsmsgrs.exe"Added by the DLOADER-YI TROJAN!"
XNvCplDaemonXplorer.exe"Added by the ORBINA-A WORM!"
XNvCplDaemon32anvshell32.exe"Added by the VB-XU TROJAN!"
XNvCplDeamonnvdisp.exe"Added by the PEEPVIE-I TROJAN!"
XNvCplDmnNAVSVC.EXE"Added by an unidentified VIRUS
XNvXplDeamonxstyles.exeAdded by the SMALL.AJ VIRUS!
Xoddworldz.exeoddworldz.exe"Added by the MULTIDR-EG TROJAN!"
XOpenGL Drivers0penGLD.exe"Added by the YIMP-A WORM!"
XPCShieldregsvr32 sfg_****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPCTotalDefenderpgs.exe"PCTotalDefender rogue security software - not recommended. A member of the AVSystemCare family"
?PreloadApphphprld.exe"HP PhotoSmart printers related. What does it do and is it required?"
XProtectSoldierProtectSoldier.exe"ProtectSoldier rogue security software - not recommended
XProtocolDiskChkssrms.exe"Added by the BDOOR-ML BACKDOOR!"
XProtocolDiskChksvcvlw32.exe"Added by the STINX-Y TROJAN!"
NQuikShieldqkshield.exe"QuikShield popup blocker - reportedly stealth installed
NRealDownloadRealPlay.exeDownload manager. Available via Start -> Programs
XRealDownload Expressnpnzdad.exeAdvertising spyware
XRNBc Testbvldv32.exe"Added by the RBOT-AJF WORM!"
Xrun=fntldr.exe"CoolWebSearch Tapicfg parasite variant"
USafeworldFreedom.exeSafeWorld Internet Security - now no longer available
XSaveSoldierSaveSoldier.exe"SaveSoldier rogue security software - not recommended
XScrSvrOld[worm filename]"Added by the OPASERV WORM!"
XSecuritySoldierSecuritySoldier.exe"SecuritySoldier rogue security software - not recommended
Nsetuphphprld.exe ....setup.exeHP DeskJet Setup - printers function normally without it
Xshell32ntldrt.exe"Added by the JLOK-A WORM!"
XShelldaemonShelldaemon.exeAdded by a variant of the AGENT.ALN TROJAN!
XShield Securityshield.exe"Added by the RIZO.A TROJAN!"
XShield32 Securityshield32.exe"Added by the RIZO.A TROJAN!"
XShieldSafenessShieldSafeness.exe"ShieldSafeness rogue security software - not recommended
XSoftSoldierSoftSoldier.exe"SoftSoldier rogue security software - not recommended
XSoftStrongholdSoftStronghold.exe"SoftStronghold rogue security software - not recommended
USpeaking Clock DeluxeSpClDlx.exe"Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date
Xspysoldierspysoldier.exe"SpySoldier rogue spyware remover - not recommended
USpyWare ShieldShield.exe"Acronis Privacy Expert Spyware Shield prevents spyware and other suspicious programs from being installed on PCs"
YSpywareTerminatorSpywareTerminatorShield.exe"Spyware Terminator's real-time protection. Initially not recommended due to false positives but the later versions have since improved - see here"
XSrv32Old[worm filename].PIF"Added by the OPASERV.J WORM!"
XSSLDynSSLDyn.exE"FRETHOG.MM spyware"
NStreamload DownloaderSlDB.exe"Downloader for MediaMax (was Streamload) - ""gives you a private and secure place to upload
Xsyncmanwuaucldt.exe"Added by the NAMSYS-A TROJAN!"
Xsysclxntldrt.exe"Added by the JLOK-A WORM!"
Xsysldtrayld02.exe"Added by the KOOBFACE.BG WORM!"
Xsysldtrayld03.exe"Added by the KOOBFACE.CA WORM!"
Xsysldtrayld11.exe"Added by the KOOBFACE.JG WORM!"
XsysLDtrayld08.exe"Added by the AGENT-JSV TROJAN!"
Xsysldtrayld09.exe"Added by the AGENT-KFI TROJAN!"
Xsysldtrayld10.exe"Added by the FAKEAV-UD TROJAN!"
Xsysldtrayld12.exe"Added by the KOOBFACE.V WORM!"
Xsysldtrayld01.exe"Added by the KOOBFACE.I WORM!"
Xsysldtrayld15.exe"Added by the AGENT-LNH TROJAN!"
Xsysldtrayld04.exe"Added by the KOOBFACE WORM!"
Xsysldtrayld06.exe"Added by the KOOBFACE WORM!"
Xsysldtrayld07.exe"Added by the KOOBFACE WORM!"
Xsysldtrayld14.exe"Added by the VIRUT.CE VIRUS!"
Xsysldtrayld16.exe"Added by the AGENT-MMO TROJAN!"
XSystemLoadersysldr32.exe"Added by the DOWNLDR-NS TROJAN!"
UTPP Auto LoaderTppaldr.exe"Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD
UTray FolderTray Folder.exe"Tray Folder by Titlebar Software - creates a hidden folder that is only normally accessible by double-clicking on a System Tray icon that shows the current date. You can also hide files and other folders in that hidden folder. The originator's website is no longer available but you can still download it here"
UTrayFolderTray Folder.exe"Tray Folder by Titlebar Software - creates a hidden folder that is only normally accessible by double-clicking on a System Tray icon that shows the current date. You can also hide files and other folders in that hidden folder. The originator's website is no longer available but you can still download it here"
XTrojan Guarder Gold VersionTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
UTrojanShieldInit.exe"TrojanShield"
UTrojanShield ProtectorPort.exe"TrojanShield anti-hacker/anti-trojan software"
XTrustSoldierTrustSoldier.exe"TrustSoldier rogue security software - not recommended
Xttoolessldev.exe"Added by the AGENT-LWB TROJAN!"
Yumxldraumxldra.exe"User mode executive module DLL loader - part of Tiny Personal Firewall V4"
YUMXLDRWUMXLDRW.exe"Tiny Personal Firewall (pre V4)"
Xunldr16unldr16.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xunldr32unldr32.exe"Added by a variant of the CRYPTER.C TROJAN!"
UV.92 Modem On HoldLtmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
UVirtual DimensionVirtualDimension.exe"Virtual Dimension by Typz - ""a free
UVirtualDimension.exeVirtualDimension.exe"Virtual Dimension by Typz - ""a free
NVirtualDriveVDTask.exe"VirtualDrive from Farstone - virtual CD/DVD drive emulator. Available via Start → Programs"
XVirus Shield 2009VShield.exe"Virus Shield 2009 rogue security software - not recommended
YVirusScan Onlinemcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
NvTPassvtpassld.exe"Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs
UWashAndGo - Cleanup of old Backupfileschecker.exe"WashAndGo - temp file cleaner"
NWebCallDirectWebCallDirect.exe"WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
NWebposition Gold 2wpsche~1.exe"Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines"
XWebSpyShieldWebSpyShield.exe"WebSpyShield rogue security software - not recommended"
XWildFlicsWildFlics.exe"Direct-B premium rate adult content dialler"
?WildTangent CDA"RUNDLL32.exe cdaEngine0400.dll cdaEngineMain"
UWildTangent Web Driver updaterwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
NWildwire MonitorWWMon.exeThis places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
XWin Patchntldr.exe"Added by the SDBOT-GS WORM!"
XWin32 Device LoaderWin32ldr.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWinDLL (dlfksdld.exe)"rundll32.exe dlfksdld.exestart"
XWinDLL (wchshield.exe)"rundll32.exe wchshield.exestart"
XWindowfdgfds DLL fgfdg VerifierWindowsdldfglcheckkk.exe"Added by the RBOT.CSP WORM!"
XWindows applications serverSysShield.exe"Added by the unregistered version of Personal Anti Malware rogue security software - not recommended
XWindows Automatic Updatesdvldr.exe"Added by the RBOT.MF WORM!"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Login Folderwinzep.exe"Added by the AGOBOT-TZ WORM!"
XWINDOWSflashbrgsqldata1.exe"Added by a variant of the AGENT-IC TROJAN!"
NWindowsWelcomeCenter"rundll32.exe oobefldr.dllShowWelcomeCenter"
XWiniShieldWiniShield.exe"WiniShield rogue security software - not recommended
Xwinldr[path to file]"Added by the VIDLO-P TROJAN!"
XwinldrRechnung.pdf.exe"Added by the ACS TROJAN!"
XWorldAntiSpyworldantispy.exe"WorldAntiSpy rogue spyware remover - not recommended
UWorldTime.exeWorldTime.exe"Part of AnyTime Organizer Deluxe from Individual Software Inc - ""Check the time anywhere in the world and know when to communicate. Place up to twelve clocks on your desktop"""
XWsecurityldanw32.exe"Added by the AGENT-BUC TROJAN!"
UWSEP Status+ConfigurationcontroldGUI.exe"User interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from Watchguard"
Uxbtlbootldr.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XXPShieldXP-Shield.exe"XP-Shield rogue security software - not recommended
X[Randomly chosen existing folder name]_autorun.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_cfg.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_config.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_env.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_loader.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_login.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_setup.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_start.exe"Added by the ANTINNY-L WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.