Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
X2020Downloadermssvr.exe"2020Search Toolbar"
X@sysload.exe"Added by the DELF-EL TROJAN!"
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
UAct! PreloaderAct8.exe"Sage Software's ACT! ""enables individuals and small business customers to instantly access key contact and customer information
XADM Library Loaderadmlib32.exe"Added by a variant of the SDBOT TROJAN!"
UAdobe Gamma LoaderAdobe Gamma Loader.exe"Adjusts monitor colours across all programs
UAdobe Gamma Loader.exeAdobe Gamma Loader.exe"Adjusts monitor colours across all programs
NAdobe Photo Downloaderapdproxy.exe"Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)"
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
Xautoloadcftmon.exe"Added by the SOCKS-E WORM!"
Xautoloadspooll.exe"Added by the SILLYFDC WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
Xautoloadspool.exe"Added by the AGENT-GSG TROJAN!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
Xauto__hloader__keyhloader_exe.exe"Added by the BAGLE.AB TROJAN!"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
Ublsloaderblsloader.exe"BellSouth ISP Internet Tools"
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
NBrowserWebCheckloadwc.exeChecks to make sure that IE is still your default browser
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
Ycdloadercdloader2.exe"From MagicJack - ""A softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge"""
UCDLoadersb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
XClickTheButtoncd_load.exe"Added by the DOWNLOADER-MY TROJAN!"
XClrSchLoader[path to file]"ClearSearch adware"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
NCorel Photo DownloaderMediaDetect.exe"Related to Corel Photo Album"
NCryptLoadRouterClient.exe"CryptLoad download manager"
XCSRSS Loadercsrsss.exe"Added by the AGOBOT.TX WORM!"
XCTF Device Loaderctfmond.exe"Added by the AGOBOT-FO WORM!"
XCyDoorCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
XCydoorUpdateCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
XDealHelperDowndownload.exe"DealHelper adware"
XDelayLoadmsprint.exe"Added by a variant of the Win32.Agent.ryo malware - see here"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDllLoaderlssas.exe"Added by the BDOOR-JE BACKDOOR!"
XDlloadkiller.exe"Added by the KILLAV-FK TROJAN!"
NdlmMgrAdobeDownloadManager.exe"Adobe Download Manager - ""can prevent you from having to start from the beginning should your download process be interrupted
UDMHotKeyDMLoader.exeHotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
Xdmloaderdmloader.exe"Added by a variant of the RBOT WORM!"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
NDownload Accelerator Manager Free Editiondam.exe"Download Accelerator Manager Free Edition from Tensons Corp"
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownload PlusDownloadPlus.exe"DownloadPlus adware"
NDownload WonderDownloadWonder.exe"Download Wonder from Forty Software. Download manager for resuming downloads
NDownloadAcceleratorDAP.EXE"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadWaredw.exe"DownloadWare adware"
XDownloadWare EngineDwe.exe"DownloadWare adware"
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDxLoadDX3DRndr.exe"Added by the GIBE.B WORM!"
XDynamic Link Library loaderLoader32.exe"Added by the KOL TROJAN!"
XEac Downloaddownload.exe"Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
NeBotDownloadWizard.exe"eBot from Digital River - ""helps ensure your computer always has the latest technology
UeDataSecurity LoadereDSloader.exe"Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons
NEDLoaderDTLoader.exeEffective Desktop from MiniStars Software - desktop management software no longer being supported
XExplorer Loaderexplr32.exe"Added by the AGOBOT.N WORM!"
XExplorer Loaderexplorerl.exe"Added by the SDBOT-ADI WORM!"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
UFirefox PreloaderFirefoxPreloader.exe"Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
XFlashget Download ManagerFlashget.exe"Added by the RBOT-AGZ WORM!"
XFontsLoaderldfnt32.htaUnidentified malware
YFP Loaderloadfp.exe"FoolProof Security - PC security software from SmartStuff"
NFree Download Managerfdm.exe"""Free Download Manager"" - see here"
?Free Downloads Monitorfdcmon.exe"??"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
XFXieloader.exeAdded by the SMALL.RR TROJAN!
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
XGo!Zilla Monster DownloadsGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
XGraphic Loaderntvdm32.exe"Added by a variant of the RBOT WORM!"
UGravis Appawareloaderdbserver.exe"Looks like it's associated with Gravis game controllers and the Keyset Manager
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
XIDE LoaderIDElibr32.exe"Added by the XILON TROJAN! Related to the game ""Diablo II"""
XIELoader32iexplore32.exe"Added by the SPEX or SPEX.B WORMS!"
XIMAPIload.exe"Added by the DOWNDEL-A TROJAN!"
UInternet Download Acceleratorida.exe"Internet Download Accelerator download manager"
XInternet download manager serviceidman.exe"Added by the RBOT-BMS WORM!"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIomega_loaderIomega_loader.exe"Added by the ANTINNY.F WORM!"
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XKernel Loaderntkrnl.exe"Added by the CERVIVEC.A WORM!"
YKeyboard Preload CheckPreload.exeMillenium Multi-Function Keyboard driver
UKK Loaderloadkk.exe"KeyKey XP Professional from "Monitor Instant Messages
NKodak Picture Easy *.* Batch TransferPezDownload.exe"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
XKTAX Auto Loaderktax.exe"Added by the SDBOT-MZ WORM!"
ULightning DownloadLightning.exe"Lightning Download from Headlight Software - shareware download manager for resuming downloads. Start it manually unless you want to intercept download links from your browser"
?live rdrloadloud.exe"??"
Xloadmdm.exe"Added by the BINGHE TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
Xloadmsgsr32.exe"Added by the SDBOT-QR WORM!"
Xload[path to worm]"Added by the KELVIR.AI WORM!"
XLoadMyGame.exe"Added by the LAMEYEAR-A WORM!"
Xload_Kerne1.exe"Added by the LINEAGE-AN TROJAN!"
XloadInternat.exe"Added by the WOWCRAFT TROJAN!"
Xloadrundll32.exe"Added by the WOWCRAFT TROJAN!"
Xloadsvhost32.exe"Added by the WOWCRAFT TROJAN!"
Xloadsvchsot.exe"Added by the GWGHOST-O TROJAN!"
Xloadexplorer.exe"Added by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XloadKerne121.exe"Added by the LINEAGE-ON TROJAN!"
XloadKerne1211.exe"Added by the LINEAGE-DY TROJAN!"
Xloadrundl132.exe"Added by the LOOKED-CK WORM!"
Xloadctftpscr32.exe"Added by the AGENT-FPN TROJAN!"
XLoadwin32.exe"Added by the RUBBLE-A WORM!"
XloadQQ.exe"Added by the QUADRULE.A WORM! Note - this is not the Tencent QQ Asian instant messanger program which is located in %Windir%"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
XloadSystemfile.dll.vbs"Added by an unidentified WORM or TROJAN! See here"
XloadKHATRA.exe"Added by the ORBINA-A WORM!"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
ULOAD WBLOADWB.EXE"Part of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
XLOAD32Lorena.exe"Added by the MAPSON.C WORM!"
Xload32load32.exe"Added by the NIBU
Xload32l32x.exe"Added by the DUMARU.Z or DUMARU.Y or DUMARU.AD WORM!"
Xload321111a.exe"Added by the DUMARU.AH WORM!"
Xload32swchost.exe"Added by the TURTA.A WORM!"
Xload32netda.exe"Added by the NIBU.E TROJAN!"
Xload32winldra.exe"Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
Nload=adw30.exeAfter Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Uload=asistat.exeStatus monitor for an NEC SuperScript printer
Uload=esspk.exe"Speakerphone capability through a soundcard for an ESS modem"
Yload=hotkey.exeSolo 5300 display driver for Win2K on some Gateway laptops
Nload=HPWHRC.EXELoads the Status Window software for the HP Laserjet printers
?load=WPSLOAD.EXE"Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk"
Nload=vi_grm.exeMonitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
Yload=wpshrc.exeRequired to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others)
Yload=Bfrecv.exeBitware modem driver
Xload=msater.exe"Added by the RETSAM TROJAN!"
Xload=shambl3r.exe"Added by the REMABL WORM!"
Xload=Spoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
?Load=wtfeat.exe"Associated with the Wintab Digitizer"
Yload=AICLIENT.EXE"Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system"
Xload=hint.exe"Added by the ATAK WORM!"
Xload=win32exec.exe"Added by the BITTER WORM!"
Xload=a1g.exe"Added by the ATAK.B WORM!"
Xload=dapdll.exe"Added by the ATAK.E WORM!"
Xload=svhost32.exe"Added by the LINEAGE-AB TROJAN!"
Yload=01comm32.exe"Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions
Xload=inetinfo.exe"Added by the PROXY-GG TROJAN!"
Xload=Kerne14.exe"Added by the LINEAGE-BA TROJAN!"
XLoadab1explorer.exe"Added by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
YLoadBlackDblackd.exe"""Intrusion detection system"" of the BlackICE PC Protection (was Defender) firewall which loads independently of the ""user interface"" (BlackICE Utility). BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
ULoadBtnHndBtnHnd.exeFujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock input
XLoadDBackUpBcTool.exe"Added by the GIBE WORM!"
Xloaddllloaddll.exe"Winvest spyware"
Xloaddr[path to trojan]"Added by the AGENT-DIY TROJAN!"
YLoadDvpApi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
Xloaderloader.exe"Homepage hijacker
XloaderWMPLAYER.EXEUnknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
Xloader32sys*****.exe [***** = random digit]"Added by the DOMCOM TROJAN!"
Xloader32Loader32.exeAdded by an unidentified TROJAN!
XLoadersHeIp.exe"Added by the SDBOT-ADB WORM!"
Xloadfaxloadfax.exe"Added by the WINFLUX-C TROJAN!"
XLoadFontsLoadFonts.vbsHomepage hijacker that changes your homepage to an adult content site
XLoadFontsTahoma.vbsHomepage hijacker that changes your homepage to an adult content site
ULoadFujitsuQuickTouchQuickTouch.exeMaps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions foistware - stealth installed!
XLoadhgrundll32.exe"Added by the LINEAG-ABX TROJAN!"
XLoadHTML"rundll32.exe regsvr32.exeMShtmpre"
XLoadingAgentZipLoader32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
XLoadingAgentmsload32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
XLoadManagermsload.exe"Added by the OPASERV.T WORM!"
XloadMecq0explorer.exe"Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMecq3rundll32.exe"Added by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process
XloadMect1explorer.exe"Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMefsrundll32.exe"Added by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process
XloadMefssmss32.exe"Added by the FLOOD-EL TROJAN!"
NLoadMSvcmmmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
ULoadout Managernost_LM.exe"Manager for the Belkin Nostromo n50 SpeedPad game controller - see here"
XLoadPFWwmimgr.exe"Added by the QEDS-B WORM!"
XLoadPowerProfileASDAPI.EXE"Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
ULoadPowerProfileRundll32.exe powrprof.dll"Power management specifics such as monitor shut-off
XLoadPowerProfileRundll.exe powerprof.dll"Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
XLoadPowerProfilerundl.exe"Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
XLoadPowerProfileRundll32.exe"Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
ULoadQMloadqm.exe"Installed with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the ""users choice"" recommendation. If you have problems leave it
Xloads.exeloads.exe"MediaMotor adware"
Xloads.exemedload.exe"Medload adware"
Xloads.exesuploads.exe"Added by the AGENT-BZ TROJAN!"
XLoadServiceRest In Peace"Added by the KANGAROO-A WORM!"
XLoadService"Maaf tempatmu bukan di sin"
XLoadServiceVirus"Added by the CAGER.A WORM!"
XLoadSIPS"rundll32.exe SIPSPI32.dll SIPSPI32"
?LoadWatcherTest.exe"Reportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct?"
XLoadWatcherwatcher.exe"Watcher spyware"
Xloadwinwinset.exe"Added by the QQPASS-I TROJAN!"
Xloadwinwinsys.exe"Added by the QQPASS-J TROJAN!"
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
ULogon LoaderLogonLoader.exe"Logon Loader - customize boot & login screens"
ULogon Loader RandomLogonLoader.exe"Logon Loader - customize boot & login screens"
XMainDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
XMedia Loadmsn32.exeAdded by a unidentified WORM or TROJAN!
XMediaLoadsdw.exe"Medialoads adware"
XMediaLoads Installerdw.exe"Medialoads adware"
XMediaPipe P2P Loadermpp2pl.exe"MediaPipe peer-to-peer file swapping program also reported as a hijacker"
XMEMrealoadMEMreaload.exe"Added by the LAZAR TROJAN!"
NmicroAttuneDownloadatmdlusr.exe"Application Launcher
XMicroLoad[random filename]"Added by the DARBY WORM!"
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
UMicrosoft CTF Loaderctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Loaderwloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoftvirussysoverload.exe"Added by the FORBOT-AL WORM!"
Xmloadlxmstart.exe"Added by an unidentified VIRUS
XMp3 LoaderSysdata.EXE"Added by the AVETTE-A VIRUS!"
XMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMS Autoloader 32MSAuto32.exe"Added by the SPYBOT.BD WORM!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMs Valud LoaderSvhots.exe"Added by the AGOBOT-SP WORM!"
XMsn Configuration Loadermsngms.exe"Added by the KELVIR.T WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN Message Background loader[path to worm]"Added by the RBOT-AIE WORM!"
XMSN Messenger Inbox Loadermsninbox.exe"Added by the SLENFBOT.YG WORM!"
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
Xmsnload32.exemsnload32.exe"Added by the BANCOS.M TROJAN!"
XmsReg32 Loadermsreg32.exe"Added by the AGOBOT.IU WORM!"
Xmsvccc66dload.exe"Added by a variant of the RBOT WORM!"
Xmsvload32msvload32.exe"Added by the RBOT-ACI WORM!"
Xmswsplvnmispoisn downloader.exeSearchBarCash adware variant
UMXO Auto LoaderMXOaldr.exeMaxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
NNavLoadNAVBrowser.exeRegistration reminder for CorelDRAW 10
XNBInstallMBDownloader_876919.exe"Added by the MIRAR_D TROJAN!"
XNeroLoaderNeroLoader.exe"Added by the BANCBAN-EJ TROJAN!"
XNetzip Smart Downloadernpnzdad.exeAdvertising spyware
XNewDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNiceDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
?Norton AV PreloadPremend.exe"Norton Antivirus related. What does it do and is it required"
NNorton Navigator Loadernnloader.exe"An older Norton utility for file management under Windows 95. More information here"
Xnotepad"rundll32.exe ntload.dll_IWMPEvents@0"
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XNTmessageSystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
Xnviload32nviload32.exe"Added by the SDBOT-VT WORM!"
XOeloaderOeloader.exe"Xupiter OrbitExplorer toolbar related. Drive-by foistware. Use Spybot S&D
XOleLoaderole32.exeAdded by the DELF.BR TROJAN!
XOS Boot Loadbootload.exe"Added by a variant of the IRCBOT TROJAN!"
UPassword Door LoaderPDMonitor.exe"Password Door - password protection software"
NPhoto Loader supervisoryPlauto.exe"Casio's Photo Loader software. Hook up your camera to the USB port
?PLoaderumsd.exe"USB Mass Storage Disk related tray icon. Is it required?"
UPraize MessengeritLoad.exe"Praize IM Christian chat instant messenger"
YPreloadPreload.exeMillenium Multi-Function Keyboard driver
NpreloadRUNXMLPL.exeSoftware found on Acer computers from Wistron. Information suggests it maps keyboard buttons to operating system functions
?PreloadApphphprld.exe"HP PhotoSmart printers related. What does it do and is it required?"
NProdikeysAutorunProdload.exe"Creative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured
Xpsaload32psaload32.exe"Added by the RBOT-ADL WORM!"
UQoeloaderQoeloader.exe"Qurb 2.0 anti-spam tool for Outlook/Outlook Express. Required when supporting OE but not for Outlook. Shortcut available via Start -> Programs"
Xrawload[path to trojan]"Added by the DARKIRC.QZ TROJAN!"
NRealDownloadRealPlay.exeDownload manager. Available via Start -> Programs
XRealDownload Expressnpnzdad.exeAdvertising spyware
XRegistry Loaderregloadr.exe"Added by the GAOBOT.AO WORM!"
XRegistry Loaderwinhlpp32.exe"Added by the GAOBOT.AO WORM!"
Xreg_keyloader_name.exe"Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!"
Xreloadreload.vbs"Added by the LOVELETTER.AS VIRUS!"
XReloadreload.exe"Added by the LAZAR TROJAN!"
XRUNLOADl0ad.exe"PurityScan/Clickspring adware"
?RUSBHOLoader"rundll32.exe RUSBHOLoader.dll AutoRegister"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
Xsearchbarvnmispoisn downloader.exeSearchBarCash adware variant
XServices DLL Loadersrvdll.exe"Added by the SLENFBOT.ZS WORM!"
XServicesLoadlsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsloadsload.exe"Win SynchroAd adware
Xsloadsload32.exe"Added by the SDBOT-OY WORM!"
NSMSI LoaderSMLoader.exe"Smith Micro HotFax - fax software"
XSMSSS Loadersmsss.exe"Added by the AGOBOT.MQ WORM!"
XSound Loadersndloader.exe"Added by the AGOBOT-BV WORM!"
XSpool Loaderspool.exe"Added by a variant of the RBOT WORM!"
XSpool LoadKItspoolv.exe"Added by a variant of the RBOT WORM!"
Xstart uploadingsmsss.exe"Added by a variant of the SDBOT WORM!"
Xstart uploadingcrsss.exe"Added by the RBOT-SZ WORM!"
XStartReplySystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
XStartupOptionloadsysdisk.exe"Added by the HIDAGENT-B WORM!"
Xstatloadspgjd83sa.exe"Added by the SDBOT-UM WORM!"
Xstcloaderstcloader.exe"SecondThought adware"
NStreamload DownloaderSlDB.exe"Downloader for MediaMax (was Streamload) - ""gives you a private and secure place to upload
NStreamload UploaderStreamMgr.exe"Uploader for MediaMax (was Streamload) - ""gives you a private and secure place to upload
XSvhost Loadersvshost.exe"Added by the AGOBOT.G WORM!"
Xsviload32sviload32.exe"Added by the RBOT-AAS WORM!"
Xsvnloadersvnload32.exe"Added by the RBOT-ACU WORM!"
XSvost Loadersvost.exe"Added by the SDBOT.G BACKDOOR!"
YSweep95ICLOAD95.EXE"Part of Sophos ant-virus sofware"
XSymantec Configuration LoaderccApp32.exe"Added by the AGOBOT-EE WORM!"
XSystem Boot Checksysload3.exe"Added by the FUBALCA WORM!"
XSystem Boot Loadersysboot32.exe"Added by the SDBOT.PG WORM!"
XSystem Configsysloadcnf.exe"Added by a variant of the SDBOT WORM! See here"
XSystem Download ManagerSysMgr.exe"Added by the RBOT.CIG WORM!"
XSystem Initializationpayload.dat"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem Loadersystems.exe"Added by the AGOGBOT-FI WORM!"
XSystem Loadersyscfg.exe"Added by the AGOBOT-BS BACKDOOR!"
XSystem Loaderapsyst19b.exe"Added by the AGOBOT-AT BACKDOOR!"
XSystemDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemLoad32sysload32.exe"Added by the MIMAIL.E WORM!"
XSystemLoadersysldr32.exe"Added by the DOWNLDR-NS TROJAN!"
XSystemTasksloaded.exeAdult content dialler
XTask Loader{rdprM@Y_VO^"Added by the AGOBOT.CB WORM!"
XTaskManager Load ModuleTSKMNGR32.EXE"Added by the SPYBOT.I WORM!"
XThe Service Pack Loaderspxp.exe"Added by the RBOT-BYM WORM!"
UTPP Auto LoaderTppaldr.exe"Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD
NTurbine Download Manager Tray IconTurbineDownloadManagerIcon.exe"Turbine Download Manager (TDM) - download manager associated with the game ""The Lord of the Rings Online™"""
?UpdateFWfwdload.exe"Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module?"
Xupdater32winload32.exe"Added by the CULT.M WORM!"
NUVS10 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
NUVS11 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
NUVS12 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
XVital Load ProcessSpoolsvr.exe"Added by the RBOT.AIF WORM!"
Xvnmispoisn downloadervnmispoisn downloader.exeSearchBarCash adware variant
XW32Load[random filename].scr"Added by the CASPID WORM!"
XW32PluginsDownloaderXMLHTTPSelfClearing7520wiper.exe"Added by the PROXYSER-M TROJAN!"
NWaveTop Upload ManagerN/A"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
XWifi Loaderwifiload.exe"Added by the IRCBOT.XEL BACKDOOR!"
XWifi Loader!wifiloader.exe"Added by the IRCBOT.XES BACKDOOR!"
XWin TaskLoadermsgmr.exe"Added by the MYTOB.L WORM!"
XWin32 Device LoaderWin32ldr.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 Rundll LoaderRundll32.exe"Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
Xwin32servvload.exe"iSearch adware"
XWin64 Compatibility Checkload win64.drv"CoolWebSearch parasite variant"
XWindow LoaderDos32.exe"Added by the GAOBOT.AO WORM!"
UWindowBlindswbload.exe"WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
UWindowFXwfxload.exe"Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
XWindows Autostart Loadernotepad32.exe"Added by a variant of the RBOT WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows DDE Loaderwindde32.exe"Added by the SDBOT-UZ WORM!"
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL Loaderdefragfat32z.exe"Added by the LINKBOT.A WORM!"
XWindows DLL Loaderrundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
XWindows DLL Loaderdefragfat32pi.exe"Added by the RBOT-QQ WORM!"
XWindows DLL Loaderdefragfat39.exe"Added by the POEBOT-C WORM!"
XWindows DLL Loaderdefragfatz.exe"Added by the LINKBOT.H WORM!"
XWindows DLL Loaderdefragfat32.exe"Added by the SDBOT-SS WORM!"
XWindows DLL Loaderdefragfat32abc.exe"Added by the RBOT-RG WORM!"
XWindows DLL Loaderwdevice.exe"Added by a variant of the SDBOT WORM!"
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows DLL LoaderWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows DLL Loaderdefragfatx.exe"Added by the POEBOT-F WORM!"
XWindows Download Managerwindlmngr.exeAdded by an unidentified TROJAN!
XWindows Dynamic Loading HeaderwinDLL32.exe"Added by a variant of the SDBOT WORM!"
XWindows Graphics Loaderswingraphics.exe"Added by the SPYBOT.JG WORM!"
XWindows Loaderwstart32.exe"Added by the GAOBOT.CA WORM!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
Xwindows LoadxmWin_.exe"Added by the FODDER-A TROJAN!"
XWindows Media Loaderwmloader.exe"Added by a variant of the GAOBOT WORM!"
XWindows Registry Express Loaderregexpress.exe"Added by the FORBOT-CJ WORM!"
XWindows Secure Updateload.exe"Added by the FORBOT-GU WORM!"
XWindows Service LoaderWindow.exe"Added by the RBOT-XO WORM!"
XWindows Shell Library Loaderload shell.dll"CoolWebSearch parasite variant"
XWindows SP2 Version Loadwuauclt32.exe"Added by the GAOBOT.CX WORM!"
XWindows Subsyswinload.exe"Added by the NETSPREE.C WORM!"
XWINDOWS SYSTEM FILEwinload.exe"Added by the MYTOB.DK WORM!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWindows UpdateWinload.exe"Added by the DEDMIR-A WORM!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
XWindowsFZzloader3.exe"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
UWinfast2KLoadDefault"rundll32.exe wf2kcpl.dllDllLoadDefaultSettings"
UWinLoadWinload.exe"PCTattletale is a surveillance software program that monitors user activity
Xwinloadwinload.exe"Added by the AGENT-GNY TROJAN! Note - the file is located in %ProgramFiles%\Internet Explorer"
XWinLoader[random filename]"Added by variants of the SUBSEVEN TROJAN!"
Xwinnloadwinnload.COM"Added by the DOWNLD-ABG TROJAN!"
XWins Loader5Gadu-Gadu.exe"Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu"
XWinsk system Loaderwinsk.exe"Added by the AGOBOT-IZ WORM!"
XWinsock2 LoaderWICONF.EXE"Added by the SDBOT-LA WORM!"
NWintime WtxploadWxpload.exe Wintime"Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet
XWinUpdate Loadermsnnm.exe"Added by the REVCUSS.C TROJAN!"
UWinXPLoad"Rundll32 LoadDll LoadExe WinXPLoad.exe"
Xxload[path to trojan]"Added by the VB-AGP TROJAN!"
Xxload32netdd.exe"Added by the NETSPY TROJAN!"
Xxloadnetxloadnet.exeAdded by the VB.NCK TROJAN!
XXP Loaderloaderxp.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
?XTCsgloaderXTCsgloader.exe"Another Xupiter toolbar variant??"
XXupiterCfgLoaderXTCfgLoader.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
XXupiterCfgLoaderBWCfgLoader.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
XXupiterToolbarLoaderXupiterToolbarLoader.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
XZip Driver LoaderZipLoader32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
XZip Driver Loadermsload32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
X[random characters]securewinload32x.exe"Added by the OPTIXP-N TROJAN!"
X[random name]CXTPLS_LOADER.EXE"AproposMedia adware"
X[Randomly chosen existing folder name]_loader.exe"Added by the ANTINNY-L WORM!"
X[various names]runload32.exe"Wareout - malware masquerading as a spyware and dialer remover"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.