| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
255 results found for X
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| XSC SIP Client | U | X-Lite.exe | "CounterPath's X-Lite 3.0 is the market's leading free SIP based softphone available for download". For VOIP and broadband users | No |
| XSC SIP Client | N | X-PRO-Vonage.exe | Vonage SoftPhone X-PRO - allows you to use your computer as a phone by adding a fully functioning telephone interface to your PC | No |
| HKLM | X | x.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDir | No |
| X Server | U | X.exe | "XoftWare for Windows" enables you to run network-based UNIX programs ("X programs" or "clients") side-by-side with Windows applications on your personal computer. You can also share programs and computing resources with host computers connected to your PC over a network | No |
| X1 | U | X1.exe | Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine | No |
| X10 Device Network Service | U | x10nets.exe | Belongs to X10 video streaming device(s) | No |
| X1FileMonitor.exe | U | X1FileMonitor.exe | Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine | No |
| X1 System Tray | U | X1Systray.exe | Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine | No |
| Application Layer Gateway Service | X | x32.exe | Added by the POISON-AG TROJAN! | No |
| x3watch | U | x3watch.exe | "X3watch is a free accountability software program helping with online integrity. Whenever you access a website that contains inappropriate or pornographic material, the program will record the website, time, and date the site was visited. A person of your choice (an accountability partner) will receive an email containing a list of all the inappropriate sites you have visited that week" | No |
| Excite Private Messenger Pipe | ? | x8impipe.exe | ?? | No |
| ASDPLUGIN | X | Xadult1.exe | AsdPlug premium rate adult content dialer | No |
| xagvosyzuqem | X | xagvosyzuqem.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| Windo Servic Agent 32 | X | xagw.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Micrsft Updese | X | xagwxz.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Microsoft Locals466 | X | xagwxzy.exe | Added by the SPYBOT.EL WORM! | No |
| Microsoft Update Machine | X | xagwxzy.exe | Added by the RBOT.S WORM! | No |
| Xanadu | N | Xanadu.exe | Xanadu - free language and translation wizard from Foreignword | No |
| avp | X | xar6000v7.exe | Detected by Kaspersky as the ALPHABET.B TROJAN! | No |
| userinit | X | xaveqx.exe | Detected by McAfee as Generic PWS.y!1c3 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| winupdate | X | xayfcgdc.exe | Detected by Malwarebytes Anti-Malware as Spyware.Passwords. The file is located in %CommonAppData% | No |
| Iamnacho On Irc.MusIrc.com Is a Homosexual! | X | XBox64.exe | Added by the RANDEX.Y WORM! | No |
| XboxStat | U | XboxStat.exe | Accessory status indicator program installed with the drivers for Xbox 360 hardware for Windows. It displays a dialog if you press the central Xbox button on the controller and lets you keep track of wireless controller battery levels and the number of Xbox devices connected | No |
| Msword | X | Xcalibre.exe | Detected by Trend Micro as WORM_SPYBOT.NB | No |
| t | X | xclean.exe | FlashEnhancer adware | No |
| X-Cleaner Freeware | U | XCleaner_free.exe | X-Cleaner privacy and anti-spy application from Xblock - no longer supported, see here | No |
| X-Cleaner Deluxe | U | XCleaner_full.exe | X-Cleaner privacy and anti-spy application from Xblock - no longer supported, see here | No |
| X-Cleaner Deluxe | U | XCLEAN~1.EXE | X-Cleaner privacy and anti-spy application from Xblock - no longer supported, see here | No |
| X-Cleaner Freeware | U | XCLEAN~1.EXE | X-Cleaner privacy and anti-spy application from Xblock - no longer supported, see here | No |
| zmmclr | X | xcllsx.exe | Added by the LETHIC TROJAN! | No |
| avx communicator | Y | xcommsur.exe | Anti-virus part of BitDefender virus scanner/firewall | No |
| BitDefender Communicator | Y | xcommsvr.exe | Part of older versions of BitDefender anti-malware products. Runs as a service on Windows XP and later | No |
| BullGuard XComm | Y | XCOMMSVR.EXE | Part of Bullguard antivirus | No |
| EasySync Pro | U | XCPCMenu.exe | "IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems" | No |
| XTNDConnect PC | U | XCPCMenu.exe | XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications" | No |
| Xcpy1 | X | Xcpy1.exe | FlashEnhancer adware | No |
| Notification BranchCache Panel | X | xcxllmdue.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.NBP. The file is located in %AppData%\obqkqdetyl - see here | No |
| fqfewn | X | xcze.exe | Added by the SDBOT-CJ WORM! | No |
| Home | X | xd.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %AppData% | No |
| Home | X | xd.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ransom.Ran. The file is located in %AppData% | No |
| microsoft xdaemon 2.0 | X | xdaemon.exe | Added by the DELF.D TROJAN! | No |
| Start Upping | X | xdcc.exe | Added by the SPYBOT.OY WORM! | No |
| WINDOWS SYSTEM UPDATE | X | xDcc.exe | Added by the MYOTB-EH WORM! | No |
| XDeskCal | U | XDeskCal.exe | "XDeskCal is a fully customizable Desktop calendar that will allows users to display 'to do' list, appointments,and holidays on the screen . It is a lightweight application that doesn't use much system resources or take much space on your desktop" | No |
| CIBA2001 | N | xdict.exe | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| Kingsoft PowerWord 2006 | N | XDict.exe | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| PowerWord 2002 | N | XDICT.EXE | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| Powerword 2003 | N | XDICT.EXE | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| Powerword 2005 | N | XDICT.EXE | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| Powerword 2006 | N | XDICT.EXE | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| powerword 2007 | N | xdict.exe | Old version of the PowerWord Chinese and English two way translation software/e-dictionary from Kingsoft | No |
| xdmouw | X | xdmouw.exe | Detected by Dr.Web as Trojan.DownLoader7.32785 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| XdriveTrayIcon | N | XdriveTray.exe | System Tray access and notifications for the now defunct Xdrive Desktop client which integrated Windows Explorer with the user's Xdrive online storage account | No |
| xeaxenbewear | X | xeaxenbewear.exe | Detected by Sophos as Troj/Zbot-EOA and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| SystemUpdate | X | Xeyu.exe | Added by the CULLER-D WORM! | No |
| XFastUsb | U | XFastUsb.exe | ASRock XFast USB - USB accelaration driver on for supported motherboards which "can boost the performance of USB 3.0 up to 5X faster" | No |
| svcroot | X | xffanl.exe | Added by the AGENT-BMF BACKDOOR! | No |
| MSConfig | X | xfhz.exe | Detected by McAfee as PWS-FAGF!29FEB17C1B44 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| XFilesDialog | U | XFilesDialog.EXE | "XFilesDialog is designed to improve all the (more or less standard) Windows file dialogs (Open / Load / Save)" | No |
| XFILTER | Y | xfilter.exe | Filseclab Personal Firewall Professional Edition | No |
| Xfire | N | Xfire.exe | Terratec DMXFire 1024 soundcard control panel | No |
| Xfire Music | U | xfiremusic.exe | XfirePlus Music plugin is a program written to display your currently playing music into your Xfire Status. Currently the program supports 10 different music players and is packed with features to make it work just for you | No |
| xflash | X | xflash.exe | Detected by Sophos as Troj/LdPinch-BW | No |
| Intel File Transfer | U | xfr.exe | Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients | No |
| Depassx | X | Xfsa.exe | Added by the SDBOT-SK WORM! | No |
| xftpGraber | X | Xftpgraber.exe | Added by the ENVID.C WORM! | No |
| XGDMonitor | Y | XGDMonitor.exe | Related to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security features | No |
| XeroxEndeavorBackgroundTask | ? | xGKOHbgnd.exe | Associated with a Xerox multifunction and/or scanner. What does it do and is it required? | No |
| XGSensor | Y | XGSensor.exe | Related to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security features | No |
| XGUpdateClient | Y | XGUpdaterClient.exe | Related to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security features | No |
| XHFHGEBDbadw | X | XHFHGEBDbadw.exe | Added by the AGENT-NHN TROJAN! | No |
| xhi | X | xhi.exe | Added by the SCLOG-A TROJAN! | No |
| xhrmy | X | Xhrmy.exe | Detected by Trend Micro as ADW_HYPLINKER.A | No |
| Windows Insecure | X | xhxugzoy.exe | Added by the RBOT.AEU BACKDOOR! | No |
| loopsos | X | xiaosos.exe | Added by the GENOME.ANTS TROJAN! | No |
| xicon | ? | xicon.exe | Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required? | No |
| visla | X | xihikhaxnnrluyama.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.VS. The file is located in %Temp% - see here | No |
| xikahexowuxr | X | xikahexowuxr.exe | Detected by Sophos as Troj/Pushd-Fam and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| Win32SysV | X | xin.exe | Added by the FORBOT-EO WORM! | No |
| JMB36X IDE Setup | U | xInsIDE.exe | JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool | No |
| xInsIDE | U | xInsIDE.exe | JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool | No |
| xInsIDE | X | xInsIDE.exe | Added by the ADLOAD.BH TROJAN! Note - this should not be confused with the valid IDE configuration utility from JMicron Technology which is normally located in %Windir%\RaidTool and uses the same filename. This one is located in %ProgramFiles%\xInsIDE | No |
| XIR Start | X | XIR.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ardamax. The file is located in %System%\HMXBKT | No |
| xitami | U | Xiwin32.exe | Xitami Multiplatform Open Source web server | No |
| XtreamLok License Manager | U | xl.exe | License manager for xLok (XtreamLok) - prevents software being reverse engineered | No |
| xMain | U | xlaunch.exe | Xming is the leading X Window Server for Microsoft XP/2008/Windows7. It is a fully featured X Server and is lean, fast, current, simple to install and because it is standalone native Microsoft Windows, easily made portable (not needing a machine-specific installation)" | No |
| Xlaunchpad | U | XLaunchPad.exe | Xlaunchpad by XWidget Software - "gives you instant access to all your shortcuts. Arrange apps in XLaunchpad any way you like by dragging icons to different locations or by grouping apps in folders. Simply drag one icon over another to create a folder. you can name the folder whatever you like when you open the folder" | No |
| xlb | X | xlb.cpl | Added by the BANCOS.VO TROJAN! | No |
| xln | X | xln.cpl | Added by the BANCOS.VO TROJAN! | No |
| xloadnet | X | xloadnet.exe | Added by the VB.NCK TROJAN! | No |
| xlr | X | xlr.exe | Added by the BANCOS.VO TROJAN! | No |
| xlr2 | X | xlr2.exe | Added by the BANCOS.VO TROJAN! | No |
| XLliveUp | X | XLUpdate.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %CommonFiles% | No |
| winzSystam | X | xly.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| startkey | X | XMCHAI.EXE | Added by the BIFROSE-AO TROJAN! | No |
| stratas | X | xmconfig.exe | Added by the RBOT-AHR WORM! | No |
| Windows Networking Monitorin | X | xmdmx.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| xmguy | X | xmguy.exe | Added by the VB-FOZ TROJAN! | No |
| ifperx | X | xmliwvug.exe | Added by the SLAPER.U TROJAN! | No |
| imcssl | X | xmliwvug.exe | Added by the SLAPER.U TROJAN! | No |
| xNeat Clipboard Manager | N | xNeatClipMngr.exe | "Windows clipboard has the disadvantage that you can only copy once before pasting, xNeat Clipboard Manager solves such problem by keeping track of all your copied items and giving you quick access to them" | No |
| Xnet2 | U | xnet2.exe | Green Dam Youth Escort content control software. Internet filtering software that the Chinese government requires to be installed on all new computers sold in China after July 1, 2009. According to some reports this has now been either delayed or cancelled | No |
| XobniService | X | XobniService.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %AppData%\XobniService | No |
| XoftSpy | Y | XoftSpy.exe | XoftSpy antispyware software by Pareto Logic | No |
| xonzeajoqtir | X | xonzeajoqtir.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| WinOpin | X | xopin2.exe | Added by the SDBOT-DA BACKDOOR! | No |
| XP-078F2E4E | X | XP-078F2E4E.EXE | Added by the AUTORUN-SW WORM! | No |
| XP-C300C3AC | X | XP-C300C3AC.EXE | Added by the AUTORUN.EHW WORM! | No |
| XPGuard | X | XP-Guard.exe | XP-Guard rogue security software - not recommended, removal instructions here | No |
| XPShield | X | XP-Shield.exe | XP-Shield rogue security software - not recommended, removal instructions here | No |
| Microsoft XPSP Protocol | X | xp386.exe | Added by a variant of the RBOT WORM! | No |
| [32 random numbers] | X | xpa.exe | XP Antivirus rogue security software - not recommended | No |
| Antivirus | X | xpa.exe | Xpert Antivirus Enterprise rogue security software - not recommended, removal instructions here | No |
| OneMoreKey | X | xpa.exe | XP Antivirus rogue security software - not recommended | No |
| XP Antivirus | X | xpa.exe | XP Antivirus rogue security software - not recommended | No |
| Xpadder | N | Xpadder.exe | "Xpadder simulates the keyboard and mouse using your gamepad" | No |
| XPAgent | X | XPAgent.exe | Detected by Panda as the CLICKER.LE TROJAN! Do not confuse this with the IBM/XPoint Rapid Restore file which is normally located in %ProgramFiles%\XPOINT\AGENT folder. This one is found in %System% | No |
| XPAgent | ? | XPAgent.exe | Part of the IBM/XPoint Rapid Restore utility - normally located in %ProgramFiles%\XPOINT\AGENT folder. Runs as a service on an NT based OS (such as Windows 7/Vista/XP). What does it do and is it required? | No |
| XP Antivirus | X | xpantivirus.exe | XPAntivirus rogue security software - not recommended, removal instructions here | No |
| XPAntivirus | X | XPAntivirus.exe | XPAntivirus rogue security software - not recommended, removal instructions here | No |
| XP Cleaner | X | xpc.exe | XP Cleaner rogue cleaning utility - not recommended, removal instructions here | No |
| msjava service | X | xpcd.exe | Added by the SDBOT.VM WORM! | No |
| xpcfg | ? | xpcfg.exe | ?? | No |
| Xpclient | ? | xpclient.exe | Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required? | No |
| XPCMonitor | U | XPCMonitor.exe | XPC Monitor Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| XPCPHOST Settings | X | xpcphost.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| XPDecrees | X | XPDecrees.exe | Detected by Dr.Web as Trojan.MulDrop4.31371 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| XPdefender | X | XPdefender.exe | XPdefender rogue spyware remover - not recommended, removal instructions here | No |
| xpprotect | X | xpdeluxe.exe | XP Protector Deluxe rogue security software - not recommended, removal instructions here | No |
| XPeria.exe | X | XPeria.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and here | No |
| Microsoft Telecoms Center | X | xpfilesys.exe | Added by the RBOT.BCJ TROJAN! | No |
| Windows Service XP | X | XpFirewall.exe | Added by the MYTOB.AM WORM! | No |
| [original filename] | X | xphost.scr | Detected by Sophos as Troj/Bancban-HM | No |
| mozilla_cleanup | N | xpicleanup.exe | Firefox Mozilla cleans up after installation. It is invoked on a restart after installation, to remove the bits and pieces resulting from the installation | No |
| xpiupdate | X | xpiupdate.exe | Added by the RBOT-AAB WORM! | No |
| MS Java for Windows NT, XP & ME | X | xpjavams.exe | Added by the KASSBOT-V WORM! | No |
| xPlanetControl | U | xPlanetControl.exe | Tool that displays a globe with current day/night zones and clouds on users desktop. | No |
| {914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29} | U | XPlay.exe | Xplay 3 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and iTouch, and a Windows computer." If not used regularily start manually before connecting the iPod/iTouch | No |
| Xplay | U | XPlay.exe | Xplay 3 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and iTouch, and a Windows computer." If not used regularily start manually before connecting the iPod/iTouch | No |
| XPlay.exe | U | XPlay.exe | Xplay 3 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and iTouch, and a Windows computer." If not used regularily start manually before connecting the iPod/iTouch | No |
| Windows Update | X | XPLoogNT.exe | Detected by Sophos as Troj/Bancd-B and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| IEDriver | X | xplore.exe | IeDriver adware variant | No |
| MSPY2002 | X | Xplorer.exe | Detected by Sophos as W32/Autoit-BP | No |
| NvCplDaemon | X | Xplorer.exe | Added by the ORBINA-A WORM! | No |
| VBoxTray | X | Xplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir% | No |
| VMware Tools | X | Xplorer.exe | Added by the AUTOIT.K TROJAN! | No |
| VMware User Process | X | Xplorer.exe | Detected by Sophos as W32/Autoit-BP | No |
| xplorer | X | xplorer.exe | Detected by McAfee as Generic VB.jh and by Malwarebytes Anti-Malware as Worm.AutoIT | No |
| Xplorer | X | Xplorer.exe | Detected by Sophos as W32/Autoit-BP | No |
| Symantec Antivirus professional | X | xplrer.exe | Added by a variant of the FORBOT WORM! | No |
| Win32 NDIS Driver | X | xpndis.exe | Added by a variant of Win32/Rbot | No |
| PoliceAV | X | xppolice.exe | XP Police Antivirus rogue security software - not recommended, removal instructions here | No |
| XP Protection Center | X | XPProtectionCenter.exe | XP Protection Center rogue security software - not recommended, removal instructions here | No |
| xprotectS | X | xprotectU.exe | XProtect rogue security software - not recommended. One of the OneScan family of rogue scanner programs | No |
| Widnows Xp Web scan | X | xpscan.exe | Added by a variant of W32/Sdbot.worm | No |
| XP SecurityCenter | X | XPSecurityCenter.exe | XPSecurityCenter rogue security software - not recommended, removal instructions here | No |
| XP Service Pack | X | xpservicepack.exe | Added by the SDBOT.AQA WORM! | No |
| Media Player Update | X | xpsp1mfh.exe | Added by a variant of the RBOT WORM! | No |
| Microsoft xpsp2 | X | xpsp2.exe | Added by the SDBOT-YQ WORM! | No |
| xp service pack 2 | X | xpsp2.exe | Added by the RBOT-KW WORM! | No |
| XPSP2 Firewall | X | xpsp2fw.exe | Detected by Sophos as Troj/Small-RN and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| xpsp2install | X | xpsp2Update.exe | Added by the AGENT-DPK BACKDOOR! | No |
| xpsp2Update | X | xpsp2Update.exe | Added by the AGENT-DPK BACKDOOR! | No |
| ChromeUpdate | X | xpspntl.exe | Detected by Dr.Web as Trojan.Siggen.65182 | No |
| Windows-XP-Service-Pack | X | xpspz.exe | Added by the SDBOT-AAC WORM! | No |
| IECheck | X | xpssl.exe | Added by the TIRBOT-E WORM! | No |
| XPsys | X | XPsys.exe | Added by the DELF-KQ TROJAN! | No |
| Windows DLL Verifier | X | xptl.exe | Added by a variant of the RBOT WORM! | No |
| XP Tools | U | xptools.exe | XPTools - "integrated suite of powerful PC Utilities to fix, speed up, maintain and protect your computer" | No |
| Mediafour XPlay Tray Notification Icon | U | Xptryicn.exe | Xplay 2 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and touch, and a Windows computer." No longer supported | No |
| Micromedia Flash Update | X | xptxt.exe | Added by the RBOT-GAB WORM! | No |
| Microsoft Update | X | xpupdate.exe | Added by the RBOT-QE WORM! | No |
| WINDOWS SYSTEM | X | xpupdate.exe | Added by the ZOTOB-G WORM! | No |
| Windows update loader | X | xpupdate.exe | Malware installed by different rogue security software including SpyKillerPro. Also detected by Sophos as Troj/Brave-A and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| xp32win | X | xpupdater02.exe | Added by the MOSUCK-A TROJAN! | No |
| Windows Updater Servc | X | xpuupdate.exe | ContraVirus rogue security software - not recommended, removal instructions here | No |
| XpyBurner | X | XpyBurner.exe | XpyBurner rogue spyware remover - not recommended, removal instructions here | No |
| XP Antispyware 2009 | X | XP_AntiSpyware.exe | XP AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions here | No |
| MSConfig | X | xqmvnvb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| Windows Servicer | X | xqobypik.exe | Added by the SDBOT-DFB WORM! | No |
| Windows USB Printer | X | xqteby.exe | Added by a variant of the SPYBOT WORM! See here | No |
| 36X Raid Configurer | Y | xRaidSetup.exe | JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers | No |
| star3 | X | Xred1.exe | Detected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| xrt_Shell | X | xrt_brel.exe | Detected by Trend Micro as BKDR_AGENT.AJAT | No |
| xrt_Shell | X | xrt_vijr.exe | Added by the GOZI-GEN TROJAN! | No |
| XeroxScannerDaemon | U | XrxFTPLt.exe | Xerox Scanner Daemon - driver for Xerox Scanner model fu621d | No |
| XeroxScanUtility | ? | xrxzipui.exe | Associated with a Xerox multifunction and/or scanner. What does it do and is it required? | No |
| xSafe | X | xSafe.exe | Added by the SILLYFDC.BAY WORM! | No |
| XSECVA | X | xsecva.exe | Detected by Sophos as Troj/Scar-BS and by Malwarebytes Anti-Malware as Backdoor.Bot.H | No |
| [various names] | X | xsetup.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| System | X | Xsfr.exe | Added by the CULLER-D WORM! | No |
| XStop95 | U | XStop95.exe | XStop - internet filter | No |
| NvXplDeamon | X | xstyles.exe | Added by the SMALL.AJ VIRUS! | No |
| xswin | N | xswin.exe | Installed with a Xerox Work Centre Pro 555. Unchecking it removes an "out of system memory" error | No |
| M1cr0s0ftf DDEs C0ntr01 | X | Xsyn.pif | Detected by Trend Micro as WORM_RBOT.DDN and by Malwarebytes Anti-Malware as Backdoor.RBot | No |
| WinRun32 | X | xSystem32x.exe | Detected by Dr.Web as Trojan.DownLoader6.19723 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| XupiterCfgLoader | X | XTCfgLoader.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
| XTCsgloader | ? | XTCsgloader.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
| [various names] | X | XTermInit.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Operator | U | xtmop.exe | Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported | No |
| Xtray | X | xtray_link.exe | Detected by Trend Micro as TROJ_VB.JL | No |
| (Default) | X | xtreme.exe | Added by the DROPR-CZ TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| HKCU | X | xtremeserver.exe | Detected by Microsoft as Backdoor:Win32/Xtrat.A and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| HKLM | X | xtremeserver.exe | Detected by Microsoft as Backdoor:Win32/Xtrat.A and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| XTServiceUpdate | X | XTServiceUpdate.exe | hahame.net adware downloader | No |
| XtTb.exe | X | XtTb.exe | Top-banners.com adware | No |
| jidifedig | X | xudexoli.exe | Added by the SDBOT-UW WORM! | No |
| xuio.exe | ? | xuio.exe | ?? | No |
| xmstart | X | xuming.exe | Added by the GMIN-A WORM! | No |
| Xupiter Startup | X | XupiterStartup.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
| xupiterstartup2003 | X | xupiterstartup2003.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
| XupiterToolbarLoader | X | XupiterToolbarLoader.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
| xusklerj.exe | X | xusklerj.exe | Detected by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %System% | No |
| [random characters] | X | xvassdf.exe | Detected by Sophos as W32/AutoRun-BAD | No |
| 54dfsger | X | xvassdf.exe | Detected by Trend Micro as WORM_ONLINEG.KXL. The file is located in %System% | No |
| 54dfsger | X | xvassdf.exe | Detected by Trend Micro as WORM_TATERF.DL and by Malwarebytes Anti-Malware as Worm.Magania. The file is located in %UserTemp% | No |
| Xvid Codec | X | Xvid.exe | Detected by Malwarebytes Anti-Malware as Spyware.BlackshadesNET. The file is located in %Temp% | No |
| Microsoft Update Machine | X | xvshost.exe | Added by the RBOT.QP WORM! | No |
| xware | X | xware.exe | Malware downloader from xxsware.com, causes adult content popups | No |
| XGIWatchDog | ? | XWatDog.exe | Related to XGI Technology's Volari graphics cards - what does it do and is it required? | No |
| ControlCentreTray | N | XWCTray.exe | System Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc | No |
| asdx | X | xwinrpc32.exe | Detected by Trend Micro as WORM_AGOBOT.VO | No |
| xDRam rar procx | X | xwinupdaterarx.exe | Added by the RILER-W TROJAN! | No |
| win | X | xwinxrpc.exe | Detected by Sophos as W32/Agobot-MV | No |
| win | X | xwinxrpc32.exe | Detected by Sophos as W32/Agobot-MV and by Malwarebytes Anti-Malware as Trojan.Sdbot | No |
| ISP Life | U | xwISPLife.exe | ISP Life - Korean secure payment service from VP Inc | No |
| [various names] | X | xwiz.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| XWMSUSBAPI | ? | XWMSAPI.EXE | Part of the installation of a Xerox WorkCentre printer/scanner. Is it required? | No |
| MSConfig | X | xwpwqf.exe | Added by the AGENT-NEW TROJAN! | No |
| x32x | X | xwrm.exe | Detected by Dr.Web as Trojan.MulDrop4.31134 and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| xXjsKiNbkvU | X | xXjsKiNbkvU.exe | Added by the FAKEAV-DVL TROJAN! | No |
| XXqMLit | X | XXqMLit.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot.WPM. The file is located in %AppData%\XXqMLit - see here | No |
| CirebonPunya | X | XXrocks.exe | Added by the BHARAT.A WORM! | No |
| xxsrSrv32 | X | xxsrsrv.exe | Added by the BANCSDE-E TROJAN! | No |
| [various names] | X | xxtoolbar.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| mark the service | X | xxtra32.exe | Added by the SDBOT.APP WORM! | No |
| CMD | X | xxx.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
| Microsoft Synchronization Manager | X | xXx.exe | Added by the SDBOT-KZ WORM! | No |
| MICROSOFT UPDATER7 | X | xxx.exe | Detected by McAfee as RDN/Generic Downloader.x!cn and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| WINDOWS SYSTEM | X | xxx.exe | Added by the MYTOB.CZ WORM! | No |
| xxx.exe | X | xxx.exe | Detected by Dr.Web as Trojan.DownLoader4.19359 | No |
| xxxcxcxcx | X | xxxcxcxcx.exe | Added by the DWNLDR-IUR TROJAN! | No |
| XxXEwaKALMUmlh.exe | X | XxXEwaKALMUmlh.exe | Detected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %AppData% | No |
| XXXmpeg | X | XXXmpeg.exe | Adult content dialler | No |
| xxxvideo | X | xxxvideo.exe | AccessPlugin premium rate adult content dialler | No |
| xxxxxxx | X | xxxxxxx.exe | Detected by Dr.Web as Trojan.DownLoader6.6878. The file is located in %AppData% | No |
| XXXXXXXX | X | XXXXXXX.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.XST. The file is located in %System% - see here | No |
| xydjifcimeqa | X | xydjifcimeqa.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| xydyswylmylh | X | xydyswylmylh.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| xyftafimbyrn | X | xyftafimbyrn.exe | Detected by Sophos as Troj/Cutwail-AL and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| xygeruxycwyb | X | xygeruxycwyb.exe | Detected by McAfee as PWS-Zbot.gen.ari and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| 0_AVD32 | X | xzboot.exe | Detected by Sophos as Troj/Agent-IWI | No |
| Microsoft | X | XzG38N.exe | Detected by McAfee as PWS-Zbot.gen.aqs and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| x[Number from 1 to 7] | X | x[Number from 1 to 7].exe | Added by the DADOBRA-A TROJAN! | No |
| x~{{dybel | X | x~{{dy8%nsn | Detected by Trend Micro as WORM_AGOBOT.DQ | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |