Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

255 results found for X

Startup Item or Name Status Command or Data Description Tested
XSC SIP ClientUX-Lite.exe"CounterPath's X-Lite 3.0 is the market's leading free SIP based softphone available for download". For VOIP and broadband usersNo
XSC SIP ClientNX-PRO-Vonage.exeVonage SoftPhone X-PRO - allows you to use your computer as a phone by adding a fully functioning telephone interface to your PCNo
HKLMXx.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDirNo
X ServerUX.exe"XoftWare for Windows" enables you to run network-based UNIX programs ("X programs" or "clients") side-by-side with Windows applications on your personal computer. You can also share programs and computing resources with host computers connected to your PC over a networkNo
X1UX1.exePart of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engineNo
X10 Device Network ServiceUx10nets.exeBelongs to X10 video streaming device(s)No
X1FileMonitor.exeUX1FileMonitor.exePart of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engineNo
X1 System TrayUX1Systray.exePart of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engineNo
Application Layer Gateway ServiceXx32.exeAdded by the POISON-AG TROJAN!No
x3watchUx3watch.exe"X3watch is a free accountability software program helping with online integrity. Whenever you access a website that contains inappropriate or pornographic material, the program will record the website, time, and date the site was visited. A person of your choice (an accountability partner) will receive an email containing a list of all the inappropriate sites you have visited that week"No
Excite Private Messenger Pipe?x8impipe.exe??No
ASDPLUGINXXadult1.exeAsdPlug premium rate adult content dialerNo
xagvosyzuqemXxagvosyzuqem.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
Windo Servic Agent 32Xxagw.exeAdded by a variant of the IRCBOT BACKDOOR!No
Micrsft UpdeseXxagwxz.exeAdded by a variant of the IRCBOT BACKDOOR!No
Microsoft Locals466Xxagwxzy.exeAdded by the SPYBOT.EL WORM!No
Microsoft Update MachineXxagwxzy.exeAdded by the RBOT.S WORM!No
XanaduNXanadu.exeXanadu - free language and translation wizard from ForeignwordNo
avpXxar6000v7.exeDetected by Kaspersky as the ALPHABET.B TROJAN!No
userinitXxaveqx.exeDetected by McAfee as Generic PWS.y!1c3 and by Malwarebytes Anti-Malware as Trojan.AgentNo
winupdateXxayfcgdc.exeDetected by Malwarebytes Anti-Malware as Spyware.Passwords. The file is located in %CommonAppData%No
Iamnacho On Irc.MusIrc.com Is a Homosexual!XXBox64.exeAdded by the RANDEX.Y WORM!No
XboxStatUXboxStat.exeAccessory status indicator program installed with the drivers for Xbox 360 hardware for Windows. It displays a dialog if you press the central Xbox button on the controller and lets you keep track of wireless controller battery levels and the number of Xbox devices connectedNo
MswordXXcalibre.exeDetected by Trend Micro as WORM_SPYBOT.NBNo
tXxclean.exeFlashEnhancer adwareNo
X-Cleaner FreewareUXCleaner_free.exeX-Cleaner privacy and anti-spy application from Xblock - no longer supported, see hereNo
X-Cleaner DeluxeUXCleaner_full.exeX-Cleaner privacy and anti-spy application from Xblock - no longer supported, see hereNo
X-Cleaner DeluxeUXCLEAN~1.EXEX-Cleaner privacy and anti-spy application from Xblock - no longer supported, see hereNo
X-Cleaner FreewareUXCLEAN~1.EXEX-Cleaner privacy and anti-spy application from Xblock - no longer supported, see hereNo
zmmclrXxcllsx.exeAdded by the LETHIC TROJAN!No
avx communicatorYxcommsur.exeAnti-virus part of BitDefender virus scanner/firewallNo
BitDefender CommunicatorYxcommsvr.exePart of older versions of BitDefender anti-malware products. Runs as a service on Windows XP and laterNo
BullGuard XCommYXCOMMSVR.EXEPart of Bullguard antivirusNo
EasySync ProUXCPCMenu.exe"IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"No
XTNDConnect PCUXCPCMenu.exeXTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications"No
Xcpy1XXcpy1.exeFlashEnhancer adwareNo
Notification BranchCache PanelXxcxllmdue.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.NBP. The file is located in %AppData%\obqkqdetyl - see hereNo
fqfewnXxcze.exeAdded by the SDBOT-CJ WORM!No
HomeXxd.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %AppData%No
HomeXxd.exeDetected by Malwarebytes Anti-Malware as Trojan.Ransom.Ran. The file is located in %AppData%No
microsoft xdaemon 2.0Xxdaemon.exeAdded by the DELF.D TROJAN!No
Start UppingXxdcc.exeAdded by the SPYBOT.OY WORM!No
WINDOWS SYSTEM UPDATEXxDcc.exeAdded by the MYOTB-EH WORM!No
XDeskCalUXDeskCal.exe"XDeskCal is a fully customizable Desktop calendar that will allows users to display 'to do' list, appointments,and holidays on the screen . It is a lightweight application that doesn't use much system resources or take much space on your desktop"No
CIBA2001Nxdict.exeOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
Kingsoft PowerWord 2006NXDict.exeOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
PowerWord 2002NXDICT.EXEOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
Powerword 2003NXDICT.EXEOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
Powerword 2005NXDICT.EXEOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
Powerword 2006NXDICT.EXEOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
powerword 2007Nxdict.exeOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
xdmouwXxdmouw.exeDetected by Dr.Web as Trojan.DownLoader7.32785 and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
XdriveTrayIconNXdriveTray.exeSystem Tray access and notifications for the now defunct Xdrive Desktop client which integrated Windows Explorer with the user's Xdrive online storage accountNo
xeaxenbewearXxeaxenbewear.exeDetected by Sophos as Troj/Zbot-EOA and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
SystemUpdateXXeyu.exeAdded by the CULLER-D WORM!No
XFastUsbUXFastUsb.exeASRock XFast USB - USB accelaration driver on for supported motherboards which "can boost the performance of USB 3.0 up to 5X faster"No
svcrootXxffanl.exeAdded by the AGENT-BMF BACKDOOR!No
MSConfigXxfhz.exeDetected by McAfee as PWS-FAGF!29FEB17C1B44 and by Malwarebytes Anti-Malware as Trojan.AgentNo
XFilesDialogUXFilesDialog.EXE"XFilesDialog is designed to improve all the (more or less standard) Windows file dialogs (Open / Load / Save)"No
XFILTERYxfilter.exeFilseclab Personal Firewall Professional EditionNo
XfireNXfire.exeTerratec DMXFire 1024 soundcard control panelNo
Xfire MusicUxfiremusic.exeXfirePlus Music plugin is a program written to display your currently playing music into your Xfire Status. Currently the program supports 10 different music players and is packed with features to make it work just for youNo
xflashXxflash.exeDetected by Sophos as Troj/LdPinch-BWNo
Intel File TransferUxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clientsNo
DepassxXXfsa.exeAdded by the SDBOT-SK WORM!No
xftpGraberXXftpgraber.exeAdded by the ENVID.C WORM!No
XGDMonitorYXGDMonitor.exeRelated to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security featuresNo
XeroxEndeavorBackgroundTask?xGKOHbgnd.exeAssociated with a Xerox multifunction and/or scanner. What does it do and is it required?No
XGSensorYXGSensor.exeRelated to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security featuresNo
XGUpdateClientYXGUpdaterClient.exeRelated to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security featuresNo
XHFHGEBDbadwXXHFHGEBDbadw.exeAdded by the AGENT-NHN TROJAN!No
xhiXxhi.exeAdded by the SCLOG-A TROJAN!No
xhrmyXXhrmy.exeDetected by Trend Micro as ADW_HYPLINKER.ANo
Windows InsecureXxhxugzoy.exeAdded by the RBOT.AEU BACKDOOR!No
loopsosXxiaosos.exeAdded by the GENOME.ANTS TROJAN!No
xicon?xicon.exePart of the IBM/XPoint Rapid Restore utility. What does it do and is it required?No
vislaXxihikhaxnnrluyama.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.VS. The file is located in %Temp% - see hereNo
xikahexowuxrXxikahexowuxr.exeDetected by Sophos as Troj/Pushd-Fam and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
Win32SysVXxin.exeAdded by the FORBOT-EO WORM!No
JMB36X IDE SetupUxInsIDE.exeJMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidToolNo
xInsIDEUxInsIDE.exeJMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidToolNo
xInsIDEXxInsIDE.exeAdded by the ADLOAD.BH TROJAN! Note - this should not be confused with the valid IDE configuration utility from JMicron Technology which is normally located in %Windir%\RaidTool and uses the same filename. This one is located in %ProgramFiles%\xInsIDENo
XIR StartXXIR.exeDetected by Malwarebytes Anti-Malware as Trojan.Ardamax. The file is located in %System%\HMXBKTNo
xitamiUXiwin32.exeXitami Multiplatform Open Source web serverNo
XtreamLok License ManagerUxl.exeLicense manager for xLok (XtreamLok) - prevents software being reverse engineeredNo
xMainUxlaunch.exeXming is the leading X Window Server for Microsoft XP/2008/Windows7. It is a fully featured X Server and is lean, fast, current, simple to install and because it is standalone native Microsoft Windows, easily made portable (not needing a machine-specific installation)"No
XlaunchpadUXLaunchPad.exeXlaunchpad by XWidget Software - "gives you instant access to all your shortcuts. Arrange apps in XLaunchpad any way you like by dragging icons to different locations or by grouping apps in folders. Simply drag one icon over another to create a folder. you can name the folder whatever you like when you open the folder"No
xlbXxlb.cplAdded by the BANCOS.VO TROJAN!No
xlnXxln.cplAdded by the BANCOS.VO TROJAN!No
xloadnetXxloadnet.exeAdded by the VB.NCK TROJAN!No
xlrXxlr.exeAdded by the BANCOS.VO TROJAN!No
xlr2Xxlr2.exeAdded by the BANCOS.VO TROJAN!No
XLliveUpXXLUpdate.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %CommonFiles%No
winzSystamXxly.exeAdded by a variant of the SDBOT BACKDOOR!No
startkeyXXMCHAI.EXEAdded by the BIFROSE-AO TROJAN!No
stratasXxmconfig.exeAdded by the RBOT-AHR WORM!No
Windows Networking MonitorinXxmdmx.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
xmguyXxmguy.exeAdded by the VB-FOZ TROJAN!No
ifperxXxmliwvug.exeAdded by the SLAPER.U TROJAN!No
imcsslXxmliwvug.exeAdded by the SLAPER.U TROJAN!No
xNeat Clipboard ManagerNxNeatClipMngr.exe"Windows clipboard has the disadvantage that you can only copy once before pasting, xNeat Clipboard Manager solves such problem by keeping track of all your copied items and giving you quick access to them"No
Xnet2Uxnet2.exeGreen Dam Youth Escort content control software. Internet filtering software that the Chinese government requires to be installed on all new computers sold in China after July 1, 2009. According to some reports this has now been either delayed or cancelledNo
XobniServiceXXobniService.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %AppData%\XobniServiceNo
XoftSpyYXoftSpy.exeXoftSpy antispyware software by Pareto LogicNo
xonzeajoqtirXxonzeajoqtir.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
WinOpinXxopin2.exeAdded by the SDBOT-DA BACKDOOR!No
XP-078F2E4EXXP-078F2E4E.EXEAdded by the AUTORUN-SW WORM!No
XP-C300C3ACXXP-C300C3AC.EXEAdded by the AUTORUN.EHW WORM!No
XPGuardXXP-Guard.exeXP-Guard rogue security software - not recommended, removal instructions hereNo
XPShieldXXP-Shield.exeXP-Shield rogue security software - not recommended, removal instructions hereNo
Microsoft XPSP ProtocolXxp386.exeAdded by a variant of the RBOT WORM!No
[32 random numbers]Xxpa.exeXP Antivirus rogue security software - not recommendedNo
AntivirusXxpa.exeXpert Antivirus Enterprise rogue security software - not recommended, removal instructions hereNo
OneMoreKeyXxpa.exeXP Antivirus rogue security software - not recommendedNo
XP AntivirusXxpa.exeXP Antivirus rogue security software - not recommendedNo
XpadderNXpadder.exe"Xpadder simulates the keyboard and mouse using your gamepad"No
XPAgentXXPAgent.exeDetected by Panda as the CLICKER.LE TROJAN! Do not confuse this with the IBM/XPoint Rapid Restore file which is normally located in %ProgramFiles%\XPOINT\AGENT folder. This one is found in %System%No
XPAgent?XPAgent.exePart of the IBM/XPoint Rapid Restore utility - normally located in %ProgramFiles%\XPOINT\AGENT folder. Runs as a service on an NT based OS (such as Windows 7/Vista/XP). What does it do and is it required?No
XP AntivirusXxpantivirus.exeXPAntivirus rogue security software - not recommended, removal instructions hereNo
XPAntivirusXXPAntivirus.exeXPAntivirus rogue security software - not recommended, removal instructions hereNo
XP CleanerXxpc.exeXP Cleaner rogue cleaning utility - not recommended, removal instructions hereNo
msjava serviceXxpcd.exeAdded by the SDBOT.VM WORM!No
xpcfg?xpcfg.exe??No
Xpclient?xpclient.exePart of the IBM/XPoint Rapid Restore utility. What does it do and is it required?No
XPCMonitorUXPCMonitor.exeXPC Monitor Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!No
XPCPHOST SettingsXxpcphost.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
XPDecreesXXPDecrees.exeDetected by Dr.Web as Trojan.MulDrop4.31371 and by Malwarebytes Anti-Malware as Trojan.AgentNo
XPdefenderXXPdefender.exeXPdefender rogue spyware remover - not recommended, removal instructions hereNo
xpprotectXxpdeluxe.exeXP Protector Deluxe rogue security software - not recommended, removal instructions hereNo
XPeria.exeXXPeria.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and hereNo
Microsoft Telecoms CenterXxpfilesys.exeAdded by the RBOT.BCJ TROJAN!No
Windows Service XPXXpFirewall.exeAdded by the MYTOB.AM WORM!No
[original filename]Xxphost.scrDetected by Sophos as Troj/Bancban-HMNo
mozilla_cleanupNxpicleanup.exeFirefox Mozilla cleans up after installation. It is invoked on a restart after installation, to remove the bits and pieces resulting from the installationNo
xpiupdateXxpiupdate.exeAdded by the RBOT-AAB WORM!No
MS Java for Windows NT, XP & MEXxpjavams.exeAdded by the KASSBOT-V WORM!No
xPlanetControlUxPlanetControl.exeTool that displays a globe with current day/night zones and clouds on users desktop.No
{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}UXPlay.exeXplay 3 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and iTouch, and a Windows computer." If not used regularily start manually before connecting the iPod/iTouchNo
XplayUXPlay.exeXplay 3 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and iTouch, and a Windows computer." If not used regularily start manually before connecting the iPod/iTouchNo
XPlay.exeUXPlay.exeXplay 3 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and iTouch, and a Windows computer." If not used regularily start manually before connecting the iPod/iTouchNo
Windows UpdateXXPLoogNT.exeDetected by Sophos as Troj/Bancd-B and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
IEDriverXxplore.exeIeDriver adware variantNo
MSPY2002XXplorer.exeDetected by Sophos as W32/Autoit-BPNo
NvCplDaemonXXplorer.exeAdded by the ORBINA-A WORM!No
VBoxTrayXXplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%No
VMware ToolsXXplorer.exeAdded by the AUTOIT.K TROJAN!No
VMware User ProcessXXplorer.exeDetected by Sophos as W32/Autoit-BPNo
xplorerXxplorer.exeDetected by McAfee as Generic VB.jh and by Malwarebytes Anti-Malware as Worm.AutoITNo
XplorerXXplorer.exeDetected by Sophos as W32/Autoit-BPNo
Symantec Antivirus professionalXxplrer.exeAdded by a variant of the FORBOT WORM!No
Win32 NDIS DriverXxpndis.exeAdded by a variant of Win32/RbotNo
PoliceAVXxppolice.exeXP Police Antivirus rogue security software - not recommended, removal instructions hereNo
XP Protection CenterXXPProtectionCenter.exeXP Protection Center rogue security software - not recommended, removal instructions hereNo
xprotectSXxprotectU.exeXProtect rogue security software - not recommended. One of the OneScan family of rogue scanner programsNo
Widnows Xp Web scanXxpscan.exeAdded by a variant of W32/Sdbot.wormNo
XP SecurityCenterXXPSecurityCenter.exeXPSecurityCenter rogue security software - not recommended, removal instructions hereNo
XP Service PackXxpservicepack.exeAdded by the SDBOT.AQA WORM!No
Media Player UpdateXxpsp1mfh.exeAdded by a variant of the RBOT WORM!No
Microsoft xpsp2Xxpsp2.exeAdded by the SDBOT-YQ WORM!No
xp service pack 2Xxpsp2.exeAdded by the RBOT-KW WORM!No
XPSP2 FirewallXxpsp2fw.exeDetected by Sophos as Troj/Small-RN and by Malwarebytes Anti-Malware as Trojan.AgentNo
xpsp2installXxpsp2Update.exeAdded by the AGENT-DPK BACKDOOR!No
xpsp2UpdateXxpsp2Update.exeAdded by the AGENT-DPK BACKDOOR!No
ChromeUpdateXxpspntl.exeDetected by Dr.Web as Trojan.Siggen.65182No
Windows-XP-Service-PackXxpspz.exeAdded by the SDBOT-AAC WORM!No
IECheckXxpssl.exeAdded by the TIRBOT-E WORM!No
XPsysXXPsys.exeAdded by the DELF-KQ TROJAN!No
Windows DLL VerifierXxptl.exeAdded by a variant of the RBOT WORM!No
XP ToolsUxptools.exeXPTools - "integrated suite of powerful PC Utilities to fix, speed up, maintain and protect your computer"No
Mediafour XPlay Tray Notification IconUXptryicn.exeXplay 2 from Mediafour Corporation - "expands what you can do with any iPod, including the iPhone and touch, and a Windows computer." No longer supportedNo
Micromedia Flash UpdateXxptxt.exeAdded by the RBOT-GAB WORM!No
Microsoft UpdateXxpupdate.exeAdded by the RBOT-QE WORM!No
WINDOWS SYSTEMXxpupdate.exeAdded by the ZOTOB-G WORM!No
Windows update loaderXxpupdate.exeMalware installed by different rogue security software including SpyKillerPro. Also detected by Sophos as Troj/Brave-A and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
xp32winXxpupdater02.exeAdded by the MOSUCK-A TROJAN!No
Windows Updater ServcXxpuupdate.exeContraVirus rogue security software - not recommended, removal instructions hereNo
XpyBurnerXXpyBurner.exeXpyBurner rogue spyware remover - not recommended, removal instructions hereNo
XP Antispyware 2009XXP_AntiSpyware.exeXP AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions hereNo
MSConfigXxqmvnvb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
Windows ServicerXxqobypik.exeAdded by the SDBOT-DFB WORM!No
Windows USB PrinterXxqteby.exeAdded by a variant of the SPYBOT WORM! See hereNo
36X Raid ConfigurerYxRaidSetup.exeJMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host ControllersNo
star3XXred1.exeDetected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.BankerNo
xrt_ShellXxrt_brel.exeDetected by Trend Micro as BKDR_AGENT.AJATNo
xrt_ShellXxrt_vijr.exeAdded by the GOZI-GEN TROJAN!No
XeroxScannerDaemonUXrxFTPLt.exeXerox Scanner Daemon - driver for Xerox Scanner model fu621dNo
XeroxScanUtility?xrxzipui.exeAssociated with a Xerox multifunction and/or scanner. What does it do and is it required?No
xSafeXxSafe.exeAdded by the SILLYFDC.BAY WORM!No
XSECVAXxsecva.exeDetected by Sophos as Troj/Scar-BS and by Malwarebytes Anti-Malware as Backdoor.Bot.HNo
[various names]Xxsetup.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
SystemXXsfr.exeAdded by the CULLER-D WORM!No
XStop95UXStop95.exeXStop - internet filterNo
NvXplDeamonXxstyles.exeAdded by the SMALL.AJ VIRUS!No
xswinNxswin.exeInstalled with a Xerox Work Centre Pro 555. Unchecking it removes an "out of system memory" errorNo
M1cr0s0ftf DDEs C0ntr01XXsyn.pifDetected by Trend Micro as WORM_RBOT.DDN and by Malwarebytes Anti-Malware as Backdoor.RBotNo
WinRun32XxSystem32x.exeDetected by Dr.Web as Trojan.DownLoader6.19723 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
XupiterCfgLoaderXXTCfgLoader.exeXupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
XTCsgloader?XTCsgloader.exeXupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
[various names]XXTermInit.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
OperatorUxtmop.exeFax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supportedNo
XtrayXxtray_link.exeDetected by Trend Micro as TROJ_VB.JLNo
(Default)Xxtreme.exeAdded by the DROPR-CZ TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
HKCUXxtremeserver.exeDetected by Microsoft as Backdoor:Win32/Xtrat.A and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXxtremeserver.exeDetected by Microsoft as Backdoor:Win32/Xtrat.A and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
XTServiceUpdateXXTServiceUpdate.exehahame.net adware downloaderNo
XtTb.exeXXtTb.exeTop-banners.com adwareNo
jidifedigXxudexoli.exeAdded by the SDBOT-UW WORM!No
xuio.exe?xuio.exe??No
xmstartXxuming.exeAdded by the GMIN-A WORM!No
Xupiter StartupXXupiterStartup.exeXupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
xupiterstartup2003Xxupiterstartup2003.exeXupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
XupiterToolbarLoaderXXupiterToolbarLoader.exeXupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
xusklerj.exeXxusklerj.exeDetected by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %System%No
[random characters]Xxvassdf.exeDetected by Sophos as W32/AutoRun-BADNo
54dfsgerXxvassdf.exeDetected by Trend Micro as WORM_ONLINEG.KXL. The file is located in %System%No
54dfsgerXxvassdf.exeDetected by Trend Micro as WORM_TATERF.DL and by Malwarebytes Anti-Malware as Worm.Magania. The file is located in %UserTemp%No
Xvid CodecXXvid.exeDetected by Malwarebytes Anti-Malware as Spyware.BlackshadesNET. The file is located in %Temp%No
Microsoft Update MachineXxvshost.exeAdded by the RBOT.QP WORM!No
xwareXxware.exeMalware downloader from xxsware.com, causes adult content popupsNo
XGIWatchDog?XWatDog.exeRelated to XGI Technology's Volari graphics cards - what does it do and is it required?No
ControlCentreTrayNXWCTray.exeSystem Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etcNo
asdxXxwinrpc32.exeDetected by Trend Micro as WORM_AGOBOT.VONo
xDRam rar procxXxwinupdaterarx.exeAdded by the RILER-W TROJAN!No
winXxwinxrpc.exeDetected by Sophos as W32/Agobot-MVNo
winXxwinxrpc32.exeDetected by Sophos as W32/Agobot-MV and by Malwarebytes Anti-Malware as Trojan.SdbotNo
ISP LifeUxwISPLife.exeISP Life - Korean secure payment service from VP IncNo
[various names]Xxwiz.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
XWMSUSBAPI?XWMSAPI.EXEPart of the installation of a Xerox WorkCentre printer/scanner. Is it required?No
MSConfigXxwpwqf.exeAdded by the AGENT-NEW TROJAN!No
x32xXxwrm.exeDetected by Dr.Web as Trojan.MulDrop4.31134 and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
xXjsKiNbkvUXxXjsKiNbkvU.exeAdded by the FAKEAV-DVL TROJAN!No
XXqMLitXXXqMLit.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot.WPM. The file is located in %AppData%\XXqMLit - see hereNo
CirebonPunyaXXXrocks.exeAdded by the BHARAT.A WORM!No
xxsrSrv32Xxxsrsrv.exeAdded by the BANCSDE-E TROJAN!No
[various names]Xxxtoolbar.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
mark the serviceXxxtra32.exeAdded by the SDBOT.APP WORM!No
CMDXxxx.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%No
Microsoft Synchronization ManagerXxXx.exeAdded by the SDBOT-KZ WORM!No
MICROSOFT UPDATER7Xxxx.exeDetected by McAfee as RDN/Generic Downloader.x!cn and by Malwarebytes Anti-Malware as Backdoor.BotNo
WINDOWS SYSTEMXxxx.exeAdded by the MYTOB.CZ WORM!No
xxx.exeXxxx.exeDetected by Dr.Web as Trojan.DownLoader4.19359No
xxxcxcxcxXxxxcxcxcx.exeAdded by the DWNLDR-IUR TROJAN!No
XxXEwaKALMUmlh.exeXXxXEwaKALMUmlh.exeDetected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %AppData%No
XXXmpegXXXXmpeg.exeAdult content diallerNo
xxxvideoXxxxvideo.exeAccessPlugin premium rate adult content diallerNo
xxxxxxxXxxxxxxx.exeDetected by Dr.Web as Trojan.DownLoader6.6878. The file is located in %AppData%No
XXXXXXXXXXXXXXXX.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.XST. The file is located in %System% - see hereNo
xydjifcimeqaXxydjifcimeqa.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
xydyswylmylhXxydyswylmylh.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
xyftafimbyrnXxyftafimbyrn.exeDetected by Sophos as Troj/Cutwail-AL and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
xygeruxycwybXxygeruxycwyb.exeDetected by McAfee as PWS-Zbot.gen.ari and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
0_AVD32Xxzboot.exeDetected by Sophos as Troj/Agent-IWINo
MicrosoftXXzG38N.exeDetected by McAfee as PWS-Zbot.gen.aqs and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
x[Number from 1 to 7]Xx[Number from 1 to 7].exeAdded by the DADOBRA-A TROJAN!No
x~{{dybelXx~{{dy8%nsnDetected by Trend Micro as WORM_AGOBOT.DQNo

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home