Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 10/8/7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 31st January, 2017
50984 listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

309 results found for Q

Startup Item or Name Status Command or Data Description Tested
Mozilla Firefox Check 8.0.1Xq09nufv.exeDetected by Sophos as Mal/DotNet-C and by Malwarebytes as Backdoor.WPM. The file is located in %AllUsersProfile%No
Mozilla Firefox Check 8.0.1Xq1joskv.exeDetected by Dr.Web as Trojan.DownLoader5.34509 and by Malwarebytes as Backdoor.WPMNo
uiijegXq3qen9s.exeAdded by the VB-FHC TROJAN!No
Microsoft Server ApplacationsXQ8See.exeAdded by a variant of Backdoor:Win32/RbotNo
Windows HosterXq93jq9j3.exeDetected by Malwarebytes as Backdoor.Agent.E. The file is located in %CommonAppData%No
LoadXq93jq9j3.exeDetected by Malwarebytes as Backdoor.Bot.MSIL. The file is located in %CommonAppData%No
qaa##.exeXqaa##.exeDetected by Malwarebytes as Backdoor.Agent.E - where # represents a digit. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see an example hereNo
Uniblue Quick AccessUqaccess.exeQuick Access application from UniBlue Systems Ltd - "helps you account for all processes on your computer by providing an additional plug-in for the Windows task manager"No
QAGENTNqagent.exeQuicken program is controlled by a separate utility program called the Quicken Download Manager (also known as Qagent). When Quicken Download Manager option is enabled, background downloading takes advantage of unused bandwidth to download current financial information anytime your computer is connected to the InternetNo
qakosmacocsiXqakosmacocsi.exeDetected by Intel Security/McAfee as PWSZbot-FLN!1E4563A9BEF1 and by Malwarebytes as Trojan.Agent.USNo
qappsrvc32.exeXqappsrvc32.exeDetected by Kaspersky as the WEBBER.M TROJAN!No
qasoxvidukehXqasoxvidukeh.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
qasutbeqhisgXqasutbeqhisg.exeDetected by Intel Security/McAfee as RDN/Downloader.a!ms and by Malwarebytes as Trojan.Agent.USNo
XSZDECXQASXDE.exeDetected by Malwarebytes as Spyware.Password. The file is located in %AppData%\QASCXDE - see hereNo
XSZQWAXQASXDE.exeDetected by Malwarebytes as Spyware.Password. The file is located in %AppData%\QASCXDE - see hereNo
PorcnsmXqavbap.exeDetected by Sophos as Troj/Ranck-CBNo
XWXWXXQAWWWW.exeDetected by Intel Security/McAfee as RDN/Generic.bfr!fs and by Malwarebytes as Backdoor.Agent.ENo
WXQQXQAWWWW.exeDetected by Intel Security/McAfee as RDN/Generic.bfr!fs and by Malwarebytes as Backdoor.Agent.ENo
qazxswedcvfrtgb.exeXqazxswedcvfrtgb.exeDetected by Intel Security/McAfee as Generic Downloader.x and by Malwarebytes as Trojan.Banker.IDF. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
QuickBooks Delivery AgentNQBDAgent.exeAs for QAGENT but for QuickBooks. Can also have the version number in the nameNo
qBittorrentNqbittorrent.exeqBittorrent Bittorrent client. As with any peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloadsYes
QBReminderFlashNQBReminder.exeUpgrade reminder for Intuit's QuickBooksNo
qBrowse?qbrowse.exeThe file is located in %ProgramFiles%\uniwill\qbrowse or %Windir%No
QuickBooks Database Server ManagerUQBServerUtilityMgr.exePart of QuickBooks Pro/Premier from Intuit - "QuickBooks Database Server Manager is a utility that allows you to configure the QuickBooks Server for multi-user access." See here for further informationNo
Quickbooks Update AgentNqbupdate.exeAssociated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or notNo
QualityCheckerUQC.exeDetected by Malwarebytes as PUP.Optional.QualityChecker. The file is located in %ProgramFiles%\QualityChecker. If bundled with another installer or not installed by choice then remove itNo
VFCCR8M6QVXqc81okL.exe.lnkDetected by Intel Security/McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
ypEOwvXQCdzMa.exeDetected by Intel Security/McAfee as RDN/Generic BackDoor!tz and by Malwarebytes as Backdoor.Agent.DCENo
Qchex Tray IconUQchex.exeRelated to G7 Productivity Systems Check SoftwareNo
QCTrayUQCTray.exeSystem Tray access to IBM Access Connections - forerunner to the current ThinkVantage version. Connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically"Yes
QcvaqtHXQcvaqtH.exeDetected by Malwarebytes as Trojan.Banker. The file is located in %Root%\Arquivos de programas\FvkymuL\MxeyryWNo
QCWLICONUQCWLICON.EXEPart of IBM Access Connections - forerunner to the current ThinkVantage verison. Connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically." This is the System Tray icon giving notifications of and access to the Wireless Connection StatusYes
QD FastAndSafeNQDCSFS.exeAutomatically runs the "Fast & Safe Cleanup" option from the now discontinued Norton Cleansweep (was Quarterdeck CleanSweep) uninstaller/file cleaning utility. Deletes safe to remove files such as Temporary Internet Files (cache) at startup. It's recommended you run it manually on a regular basisYes
QDCSFSNQDCSFS.exeAutomatically runs the "Fast & Safe Cleanup" option from the now discontinued Norton Cleansweep (was Quarterdeck CleanSweep) uninstaller/file cleaning utility. Deletes safe to remove files such as Temporary Internet Files (cache) at startup. It's recommended you run it manually on a regular basisYes
QDMUQdmStart.exeQDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etcNo
QDMStartUQdmStart.exeQDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etcNo
qdqewedaxzzxcsda.exeXqdqewedaxzzxcsda.exeDetected by Dr.Web as Trojan.DownLoader12.16702 and by Malwarebytes as Trojan.Banker.IDF. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
QdrModule10XQdrModule10.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule11XQdrModule11.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule12XQdrModule12.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule13XQdrModule13.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule15XQdrModule15.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule16XQdrModule16.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule17XQdrModule17.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrModule9XQdrModule9.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrModuleNo
QdrPack10XQdrPack10.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack11XQdrPack11.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack12XQdrPack12.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack13XQdrPack13.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack14XQdrPack14.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack15XQdrPack15.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack16XQdrPack16.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack17XQdrPack17.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
QdrPack9XQdrPack9.exeAdware.ISMonitor/Adware.Adsponsor variant - detected by Malwarebytes as Adware.ISM. The file is located in %ProgramFiles%\QdrPack - see hereNo
Telephony Backup Accounts EncryptionXqdugq4fg.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%\wotfqpx2i2j3 - see hereNo
yoinkXqdwwdtx.exeAdded by the SDBOT.BGF WORM!No
disgxXqdwwdtx.exeAdded by the SDBOT.BGF WORM!No
SwdaswdwXqdwwdtx.exeAdded by the SDBOT.BGF WORM!No
qefiklixubibXqefiklixubib.exeDetected by Intel Security/McAfee as PWS-Zbot-FAHU!880343AE561C and by Malwarebytes as Trojan.Agent.USNo
3Ew1qOFs2oXqefuh.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %CommonAppData%No
sZ1qIDNc9kXqefuh.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %CommonAppData%No
qegigaztugpeXqegigaztugpe.exeDetected by Malwarebytes as Trojan.Inject. The file is located in %UserProfile%No
QexVW.exeXQexVW.exeDetected by Malwarebytes as Trojan.Zapchast. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
qezgohibgeqeXqezgohibgeqe.exeDetected by Intel Security/McAfee as RDN/Generic Dropper!vh and by Malwarebytes as Trojan.Agent.USNo
qezmupuocoqeXqezmupuocoqe.exeDetected by Dr.Web as Trojan.DownLoad3.34015 and by Malwarebytes as Trojan.Agent.USNo
QFan Help?QFanHelp.exePart of the AI Suite system management utility included with some performance ASUS motherboards. "Asus Fan Xpert (aka QFan3) intelligently allows you to adjust bot the CPU and chassis fan speeds according to different ambient temperatures caused by different climate conditions in different geographic regions and your PC's system loading". Can user's with a supported motherboard (such as the Maximus II Formula and P7P55D-E Premium) confirm whether this is required for correct operation?Yes
QFanHelp?QFanHelp.exePart of the AI Suite system management utility included with some performance ASUS motherboards. "Asus Fan Xpert (aka QFan3) intelligently allows you to adjust bot the CPU and chassis fan speeds according to different ambient temperatures caused by different climate conditions in different geographic regions and your PC's system loading". Can user's with a supported motherboard (such as the Maximus II Formula and P7P55D-E Premium) confirm whether this is required for correct operation?Yes
QFanHelp.exe?QFanHelp.exePart of the AI Suite system management utility included with some performance ASUS motherboards. "Asus Fan Xpert (aka QFan3) intelligently allows you to adjust bot the CPU and chassis fan speeds according to different ambient temperatures caused by different climate conditions in different geographic regions and your PC's system loading". Can user's with a supported motherboard (such as the Maximus II Formula and P7P55D-E Premium) confirm whether this is required for correct operation?Yes
QuickFinder SchedulerNQFSCHD100.exeUsed in Corel WordPerfect Office 2002 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD110.EXEUsed in Corel WordPerfect Office 11 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD130.EXEUsed in Corel WordPerfect Office X3 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD140.EXEUsed in Corel WordPerfect Office X4 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD150.EXEUsed in Corel WordPerfect Office X5 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD160.EXEUsed in Corel WordPerfect Office X6 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD170.EXEUsed in Corel WordPerfect Office X7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSCHD80.EXEUsed in Corel Office Suite 8 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
QuickFinder SchedulerNQFSched.exeUsed in Corel Office Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)No
PJ8L04EUDQXqfslmbkr.exeDetected by Malwarebytes as Trojan.Agent.RND. The file is located in %CommonAppData%\qhinudgtNo
qvqeXqgebv.exeAdded by the AGOBOT-OJ WORM!No
QGY StartXQGY.exeDetected by Malwarebytes as Spyware.Keylogger.H. The file is located in %System%\UCJNNVNo
qhfwYqhfw.exeSystem Tray access to, and notifications for an older version of Quick Heal Firewall. Based upon the Outpost Firewall by Agnitum LtdYes
Quick Heal Firewall ProYqhfw.exeSystem Tray access to, and notifications for an older version of Quick Heal Firewall. Based upon the Outpost Firewall by Agnitum LtdYes
Quick Heal MessengerUQHM32.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal"No
Quick Heal Startup ScanYQHSTRT32.EXEPart of Quick Heal Antivirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malwareNo
Quick Hide WindowsUqhw.exeQuick Hide Windows from CronoSoft - "provides a quick and easy way for home and office PC users to quickly get sensitive materials off the screen without closing programs or losing documents"No
qiaroiXqiaroi.exeDetected by Malwarebytes as Worm.SFDC. The file is located in %UserProfile%No
qifuajanmoqiXqifuajanmoqi.exeDetected by Intel Security/McAfee as RDN/Generic Downloader.x!lg and by Malwarebytes as Trojan.Agent.USNo
qigelofaqiXqigelofaqi.exeDetected by Sophos as Troj/Upatre-DQ and by Malwarebytes as Trojan.Agent.USNo
QinLiangXQinLiang.exeDetected by Intel Security/McAfee as RDN/Generic BackDoor!ng and by Malwarebytes as Trojan.Agent.ENo
qioupoXqioupo.exeDetected by Microsoft as Worm:Win32/Vobfus.S and by Malwarebytes as Worm.SFDC. The file is located in %UserProfile%No
InfiumNqip.exeQIP (Quiet Internet Pager) Infium multiprotocol instant messaging clientNo
QIP Internet GuardianUQipGuard.exeStart page guard related to the QIP (Quiet Internet Pager) Infium multiprotocol instant messaging client. Translate this Russian page if you want to know moreNo
qiqinqysxutyXqiqinqysxuty.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
xdeqbbdfXqivsvccg.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %LocalAppData%No
qjbqbwsqah.exeXqjbqbwsqah.exeDetected by Malwarebytes as Trojan.Agent.DF. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
qjoarovaXqjoarova.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %System%No
qjoarovaXqjoarova.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %UserProfile%No
qjoarovaXqjoarova.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile%No
LVILUJA471F0XQJPW1FZJ.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %AppData%No
qjybkgwgvkmehmdXqjybkgwg.exeDetected by Malwarebytes as Trojan.Ransomer.WO. The file is located in %Windir%No
QuikShieldNqkshield.exeQuikShield popup blocker - reportedly stealth installed, see hereNo
qktierXqktier.exeDetected by Kaspersky as Worm.Win32.VBNA.isu and by Malwarebytes as Worm.SFDC. The file is located in %UserProfile%No
Quicklink IIINQL.EXEFax program by Smith Micro Software, Inc. bundled with HP products. Only needs to be in the start-up group if you allow your phone to automatically answer your phone in fax mode, that is, to receive faxes after a certain number of rings. Available via Start → ProgramsNo
U4Q7WMJ6WVZB8XQL64NPHF8JC.exeDetected by Intel Security/McAfee as Generic.tfr!c and by Malwarebytes as Trojan.AgentNo
QLBControllerUQLBController.exeHP Quick Launch Buttons control center on their laptopsNo
QlbCtrlUQlbCtrl.exeHP Quick Launch Buttons control center on their laptopsNo
Windows DefenderXQLJJMXM17Q.exeDetected by Sophos as Troj~VBDwnLdr-C and by Malwarebytes as Trojan.Agent.GenNo
qlockUqlock.exeQlock System Tray clock by Vitei Inc. - "designed for both business or home use, Qlock takes the world clock to a new level with more features, more settings and more control"No
QMusic?QMAgent.exeStarts BenQ Qmusic when a BenQ mobile phone or a Joybee MP3 Player is connected to the computer. Installed by default in BenQ Joybook computers and laptopsNo
Winamp MediaXqmedia.exeDetected by Sophos as Troj/Diazom-A and by Malwarebytes as Trojan.AgentNo
QQ[Chinese characters]Xqnetsvr.exeDetected by Ikarus as Trojan-Downloader.Win32.Delf and by Malwarebytes as Trojan.ChinAd. THe file is located in %ProgramFiles%\qnetsvrNo
QnextUqnext.exe"Qnext is the world's most advanced communication and sharing suite"No
QNPlusNQNPlus.exeQuick Notes Plus by Conceptworld - sticky notes toolNo
QnXXqnx.exeAdded by the ACKANTTA WORM!No
QO8fH.exeXQO8fH.exeDetected by Malwarebytes as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
qOCDM.exeXqOCDM.exeDetected by Malwarebytes as Trojan.Dropper. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
HOT FIXXQOching.exeAdded by a variant of W32.IRCBot. The file is located in %System%No
Windows Service NetworkXqodvzpmdiaj.exeAdded by the RBOT-GUV WORM!No
qoecuyXqoecuy.exeDetected by Sophos as Troj/VB-ERVNo
QOELOADERUQOELoader.exeInstalled with older versions of CA anti-spam tools - both as a stand-alone product or as part of a security suite. Scans and filters your E-mail for spam. Now incorporated into CA Internet Security Suite Plus. Formerly Qurb until their acquisition by CAYes
QOELoader ApplicationUQOELoader.exeInstalled with older versions of CA anti-spam tools - both as a stand-alone product or as part of a security suite. Scans and filters your E-mail for spam. Now incorporated into CA Internet Security Suite Plus. Formerly Qurb until their acquisition by CAYes
MicrosoftXqolKQa.vbsDetected by Sophos as Troj/AutoIt-AXT and by Malwarebytes as Trojan.Agent.MSGenNo
qoq9wsa2e2Xqoq9wsa2e2.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %UserProfile%No
WindowsUpdateXQPHBO.exe QYIMY.APFDetected by Malwarebytes as Backdoor.IRCBot.Gen. Both files are located in %AppData%\NFPGXNo
BT24Xqpqpdndnn.exeDetected by Malwarebytes as Trojan.Agent.EDHE. The file is located in %CommonAppData%\binNo
mutexXqpqpdndnn.exeDetected by Malwarebytes as Misused.Legit. The file is located in %CommonAppData%\mutex32No
InstallShield Update ServiceXQPService.exeDetected by Intel Security/McAfee as RDN/Generic.tfr!dm and by Malwarebytes as Backdoor.AgentNo
QPServiceUQPService.exeHP QuickPlay - "brings your favorite music and movies to life with the touch of a button"No
WDrvr32SSLXqpws32.exeAdded by the SDBOT.AQO WORM!No
QQ.exeXQQ.exeDetected by Symantec as W32.Quadrule.A. Note - this is not the Tencent QQ Asian instant messanger program which is located in %Windir%. This version is located in %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
QQ.exeXQQ.exeDetected by Malwarebytes as Spyware.Password. Note - this is not the Tencent QQ Asian instant messenger program and is located in %UserProfile%\DesktopNo
QQ.exeXQQ.exeDetected by Intel Security/McAfee as PWS-Banker!hbr. Note - this is not the Tencent QQ Asian instant messenger program and is located in %Windir%No
QQ.exeXQQ.exeDetected by Intel Security/McAfee as Downloader.a!zi. Note - this is not the Tencent QQ Asian instant messenger program and is located in %Windir%\systemNo
QQServerXQQ.exeDetected by Sophos as Troj/DownLdr-ANNo
loadXQQ.exeDetected by Symantec as W32.Quadrule.A. Note - this is not the Tencent QQ Asian instant messanger program which is located in %Windir%. This version is located in %System%No
Tencent QQNQQ.exeTencent QQ Asian instant messanger programNo
NRESmart WorkstationXQQBrowserUpdateService.exeDetected by Trend Micro as TROJ_XKILL.A and by Malwarebytes as Trojan.Agent. Note - do not confuse with the updater for the legitimate Tencent QQ Asian instant messenger program which runs as a service (QQBrowser Software Updater) with the same filename but is normally located in %ProgramFiles%\Tencent\QQBrowser. This one is located in %UserTemp%No
[Chinese characters]Xqqceec.exeDetected by Malwarebytes as Trojan.ChinAd. The file is located in %ProgramFiles%\qqceecNo
QQ[Chinese characters]Xqqcenot.exeDetected by Malwarebytes as Trojan.ChinAd. The file is located in %ProgramFiles%\qqcenotNo
[Chinese characters]Xqqcorb.exeDetected by Malwarebytes as Trojan.ChinAd. The file is located in %ProgramFiles%\qqcorbNo
QQ[Chinese characters]Xqqcore.exeDetected by Malwarebytes as Trojan.StartPage. The file is located in %ProgramFiles%\qqcoreNo
SysDesktopXQQDAO.exeDetected by Sophos as Troj/QQPass-ANNo
QQ[Chinese characters]Xqqdonet.exeDetected by Malwarebytes as Trojan.ChinAd. The file is located in %ProgramFiles%\qqdonetNo
QQExternal.exeXQQExternal.exeDetected by Malwarebytes as Trojan.Agent.QQ. The file is located in %System%No
QQExtrenalXQQExtrenal.exeDetected by Dr.Web as Trojan.KillProc.11344 and by Malwarebytes as Trojan.QQPassNo
SysDeskqqfxXqqfx.exeDetected by Symantec as Trojan.PWS.QQPass.HNo
system32XQQGame.exeDetected by Sophos as Troj/QQPass-AC and by Malwarebytes as Trojan.AgentNo
IDO PortXQQGamedl.exeDetected by Intel Security/McAfee as RDN/Generic PWS.y!yz and by Malwarebytes as Trojan.Downloader.IDNo
X8TWLAUG4B796UXQQM9NZ4DT.exeAdded by the AGENT-RPT TROJAN!No
qqmallXqqmall.exeDetected by Dr.Web as Trojan.Siggen5.9777No
QQMinXQQMin.exeDetected by Dr.Web as Trojan.DownLoader10.6751 and by Malwarebytes as Spyware.OnlineGamesNo
QQvbXQQMs4w.exeDetected by Malwarebytes as Trojan.Agent.QQ.Generic. The file is located in %CommonFiles%\SystemNo
QQNewsXQQNews.exeDetected by Dr.Web as Trojan.DownLoader6.14063 and by Malwarebytes as Trojan.Agent.QQNNo
[Chinese characters]Xqqntde.exeDetected by Malwarebytes as Trojan.ChinAd. The file is located in %ProgramFiles%\qqntdeNo
QQSBXQQSB.exeDetected by Intel Security/McAfee as Generic.ca and by Malwarebytes as Trojan.Agent.QQNo
360saftXQQSKT.EXEDetected by Malwarebytes as Trojan.Dropper. The file is located in %ProgramFiles%No
HKLMXqqsr.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDirNo
[foreign characters]Xqqsrnet.exeDetected by Malwarebytes as Trojan.Clicker. The file is located in %ProgramFiles%\qqsrnetNo
QQ[Chinese characters]Xqqtodet.exeDetected by Malwarebytes as Trojan.ChinAd. The file is located in %ProgramFiles%\qqtodetNo
(Default)XQQUpdate.exeDetected by Symantec as W32.Quadrule.A. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
WiniDowsXQQ[14 digits].exeDetected by Malwarebytes as Worm.AutoRun.WD. The file is located in %Temp% - see examples here and hereNo
YdaloEXQRbkfJ.exeDetected by Intel Security/McAfee as Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
SmarthruengineUQS.exeSamsung smarthru software, used with Lexmark Z82 or Samsung multifunction printersNo
QscanXQScan.exeQscan rogue security software - not recommended, removal instructions hereNo
WCYJMCXqsCMHj.exeDetected by Intel Security/McAfee as RDN/Generic.dx and by Malwarebytes as Backdoor.Agent.ENo
Quantifier SecurityXqsecue.exeAdded by the SPYBOT.UOL WORM!No
QuickenSEMessageNQsemsg.exeRelated to QuickenNo
qservicesXqservice.exeDetected by Sophos as Troj/Progent-A and by Malwarebytes as Backdoor.ProRatNo
SystemServiceXqservice.exePremium rate adult content diallerNo
MSOfficeCfgXqservice.exePremium rate adult content dialerNo
CONNECTION PC CONFIGURATIONXqsfodrsxr.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %System%No
QuickShelf 2000Nqshelf2k.exeSystem tray for launching Microsoft Bookshelf 2000No
QshelfNqshelf98.exeSystem tray for launching Microsoft Bookshelf 98No
QshelfNqshelf99.exeSystem tray for launching Microsoft Bookshelf 2.0 (99)No
Encarta Dictionary QuickshelfNQSHLFED.EXEProvides quick access to Encarta's Dictionary features?No
userinitXqsjtmw.exeDetected by Intel Security/McAfee as Generic.bfr and by Malwarebytes as Trojan.AgentNo
QSort2000NQSORT.EXEUtility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name"No
zcprooXqssstiej.exePossible homepage hijacker installing a toolbar: http://tdko.com/ ,Lop.com in disguiseNo
vdsoarsvXqstviuhsjmo.exeAntivirus .NET rogue security software - not recommendedNo
LManagerUQtaET2S.EXEAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating stateNo
Windows UpdateXqtask.exeDetected by Sophos as W32/Rbot-AKU. Note - do not confuse with the Quicken file of the same nameNo
QTaskStartupUqtask.exeFeature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly, it is only required for the Desktop Alerts featureNo
MicrosoftXqtask.exeDetected by Sophos as W32/Rbot-GCA and by Malwarebytes as Trojan.Agent.MSGenNo
60xu9Xqtfcyyp.exeDetected by Intel Security/McAfee as Generic BackDoor!dkaNo
Quick Time UpdaterXqtime8_32.exeDetected by Sophos as Troj/DwnLdr-IIZNo
HKLMXqtitune.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %UserTemp%\qtiituneNo
HKCUXqtitune.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %UserTemp%\qtiituneNo
RegistryMonitor1Xqtplugin.exeDetected by Sophos as Troj/Delf-EZY and by Malwarebytes as Trojan.AgentNo
[various filenames]Xqtsks.exeAdded by the WEBDOR.Y TROJANNo
runNQtstub.exePart of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders. Note - this entry loads via "run" section of WIN.INI on operating systems prior to Windows NTNo
QuickTime TaskNQTTask.exeSystem Tray access to Apple's QuickTime Player media player from version 5 onwards. Disabling this entry via the programs preferences leaves the entry in place but it no longer runsYes
QuickTime TaskXqttask.exeTrojan that is typically bundled with rogue security programs (such as Virus Trigger and AntivirusTrigger) and fake codecs. Note - this is not the legitimate Apple "Quick Time" viewer that has the same startup name and filename and is normally located in %ProgramFiles%\QuickTime. This one is located in %ProgramFiles%\WebMediaViewerNo
QTTaskNQTTask.exeSystem Tray access to Apple's QuickTime Player media player from version 5 onwards. Disabling this entry via the programs preferences leaves the entry in place but it no longer runsYes
qttask.exeXqttask.exeDetected by Malwarebytes as Trojan.Agent.AI. Note - this is not the legitimate Apple "Quick Time" viewer that is normally located in %ProgramFiles%\QuickTime. This one is located in %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
Quick Time TaskNqttask.exeSystem Tray access to Apple's QuickTime Player media player from version 5 onwards. Disabling this entry via the programs preferences leaves the entry in place but it no longer runsNo
QuickTimeXqttask.exeAdded by the AGENT-ENG TROJAN! Note - this is not the legitimate Apple "Quick Time" viewer that has the same startup name and filename and is normally located in %ProgramFiles%\QuickTime. This one is located in %System%No
QuickTimeNQTTask.exeSystem Tray access to Apple's QuickTime Player media player from version 5 onwards. Disabling this entry via the programs preferences leaves the entry in place but it no longer runsYes
QuickTime TaskXqttasks.exeCoolWebSearch parasite variantNo
SheduIerXqttasks.exeAdded by a variant of Troj/Bdoor-EBNo
QuicktimeXqttasks.exeDetected by Sophos as Troj/AdClick-AKNo
qtvtcpXqtvcr.exeDetected by Intel Security/McAfee as RDN/Generic.tfr!ea and by Malwarebytes as Trojan.Proxy.AGNo
QtVprMtxUQTVPRMTX.EXEMultimedia keyboard driver from Dritek System IncNo
RegistryWmXqtwm.exeDetected by Microsoft as Backdoor:Win32/Wombot.A and by Malwarebytes as Trojan.AgentNo
LManagerUQtZgAcer.EXEAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating stateYes
QtZgAcerUQtZgAcer.EXEAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating stateYes
Launch ManagerUQtZgAcer.EXEAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating stateYes
LManagerUQtZpAcer.exeAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating stateNo
QtZpAcerUQtZpAcer.exeAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating stateNo
Mozilla Firefox Check 8.0.1Xqu5eukv.exeDetected by Malwarebytes as Backdoor.WPM. The file is located in %CommonAppData%No
qualcommXqualcomm.exeDetected by Malwarebytes as Trojan.FakeMS. The file is located in %AppData%\qualcomm - see hereNo
QualityCheckerUQualityChecker.exeDetected by Malwarebytes as PUP.Optional.QualityChecker. The file is located in %UserTemp%. If bundled with another installer or not installed by choice then remove itNo
auto repair systemXqualityx.exeAdded by unidentified malware. The file is located in %System%No
service updaerXqualityz.exeAdded by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variantNo
quartzXquartz.exeMalware installed by different rogue security software including SpyKillerProNo
qucgopogkadeXqucgopogkade.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile%No
DefencerGBAXquebra.exeDetected by Intel Security/McAfee as Generic Downloader.x!glh and by Malwarebytes as Spyware.BankerNo
kingstonreleaseXqueensetmon.exeDetected by Malwarebytes as Trojan.Banker.BLT. The file is located in %LocalAppData%\queenteenstar - see hereNo
Queensla?Queensla.exeThe file is located in %Windir%\OPTIONS\CABS\OLS\AOLNo
TRUSTSECXqueijo.exeDetected by Intel Security/McAfee as RDN/PWS-Banker and by Malwarebytes as Trojan.Banker.ENo
Quest CalendarUQuest Calendar.exeCalendar gadget included with the Quest theme for MyColors from Stardock CorporationNo
Quest ClockUQuest Clock.exeClock gadget included with the Quest theme for MyColors from Stardock CorporationNo
quetipinXquetipin.exeDetected by Intel Security/McAfee as RDN/Generic.tfr!eb and by Malwarebytes as Trojan.Banker.ENo
R45T6Z7U8XQuick-Config.exeDetected by Intel Security/McAfee as Generic.dx and by Malwarebytes as Backdoor.Agent.UXNo
QuickXQuick-Config.exeDetected by Intel Security/McAfee as Generic.dx and by Malwarebytes as Backdoor.Agent.UXNo
Corel Desktop Application DirectorNQUICK.EXEThe Desktop Application Director (DAD) gives you easy access to all Corel applicationsNo
StartYQuick95.exeFor a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left aloneNo
QBRSRXQuickBrowser.exetop-banners.com adwareNo
LogitechQuickCamRibbonNQuickcam.exeLoads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled, System Tray access is also available to the main user interface "ribbon" - otherwise you'll have to use the desktop shortcut or Start menu to display it. Run it manually when required unless you use it all the timeYes
QuickcamNQuickcam.exeLoads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled, System Tray access is also available to the main user interface "ribbon" - otherwise you'll have to use the desktop shortcut or Start menu to display it. Run it manually when required unless you use it all the timeYes
Quickcam.exeNQuickcam.exeLoads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled, System Tray access is also available to the main user interface "ribbon" - otherwise you'll have to use the desktop shortcut or Start menu to display it. Run it manually when required unless you use it all the timeYes
LogitechQuickCamRibbonNQuickCam10.exeLoads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled, System Tray access is also available to the main user interface "ribbon" - otherwise you'll have to use the desktop shortcut or Start menu to display it. Run it manually when required unless you use it all the timeYes
QuickCam10NQuickCam10.exeLoads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled, System Tray access is also available to the main user interface "ribbon" - otherwise you'll have to use the desktop shortcut or Start menu to display it. Run it manually when required unless you use it all the timeYes
QuickCam10.exeNQuickCam10.exeLoads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled, System Tray access is also available to the main user interface "ribbon" - otherwise you'll have to use the desktop shortcut or Start menu to display it. Run it manually when required unless you use it all the timeYes
Exif LauncherUQuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularlyNo
QuickDVBTUQuickDVB-T.exeRelated to AVerTV DVB-T TV tuners from AVerMediaNo
quickenXquicken.exeCoolWebSearch Therealsearch parasite variantNo
QuickHealCleanerXQuickHealCleaner.exeQuickHealCleaner rogue spyware remover - not recommended, removal instructions here. A member of the WiniGuard familyNo
QuickInstallPackXQuickInstallPack.exeInstalled and used by rogue security products such as Cleaner2009, AntiMalwareSuite, SecureExpertCleaner and System Guard CenterNo
QuickLaunchErYQuickLaunchEr.ExeQuickLaunchEr - allows you to quickly launch programs from an icon in the system trayNo
PhotoWise QuickLinkNquicklnk.exeAgfa PhotoWise QuickLink by Sierra Imaging "lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more"No
QuicknoteNquicknote.exeJC&MB Quicknote Virtual ScrapbookNo
Frix QuickResNquickres.exeFrix QuickRes "is a handy tool that allows you to quickly switch between 2 desktop resolutions by simply double-clicking on the system tray icon. When shifting resolution it will remember the position of your desktop icons." No longer supportedNo
QuickResNQUICKRES.EXEUtility to quickly change desktop resolution - left over from Win95 Power Toys. In Win98 and above incorporated via Control Panel → Display. Not required unless you have to change resolutions on a regular basisNo
Dell QuickSetUquickset.exeDell utility which provides the user with easy access to configure settings such as power management, icon and font size and displays System Tray and on-screen notifications when function keys are pressed - for volume, brightness, Num-Lock and Wi-Fi on/off for exampleNo
QuickSetUQuickSet.exeDell utility which provides the user with easy access to configure settings such as power management, icon and font size and displays System Tray and on-screen notifications when function keys are pressed - for volume, brightness, Num-Lock and Wi-Fi on/off for exampleYes
Browser Infrastructure HelperUQuickShare.exeQuickShare ad-supported browser enhancement by Linkury. Detected by Malwarebytes as PUP.Optional.SmartBar. The file is located in %LocalAppData%\Smartbar\Application. If bundled with another installer or not installed by choice then remove itNo
OpenOffice.org [version]Nquickstart.exeDisplays OpenOffice quick start applet in the System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Will automatically be started when any OpenOffice component is startedNo
SyncablesNQuickSync.exeHP QuickSync by Syncables - gives "you a quick and easy way to sync your photos, music, videos, documents, e-mail and more from your digital devices"No
HPNquicksync.exeHP QuickSync by Syncables - gives "you a quick and easy way to sync your photos, music, videos, documents, e-mail and more from your digital devices"No
OpenOffice.org [version]NQUICKS~1.EXEDisplays OpenOffice quick start applet in the System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Will automatically be started when any OpenOffice component is startedNo
QuickTime PlayerXQuickTime Player.exeDetected by Intel Security/McAfee as RDN/Generic BackDoor and by Malwarebytes as Trojan.MSILNo
QuickTimeXQuickTime.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %LocalAppData%No
QuickTimeXQuickTime.exeDetected by Kaspersky as Trojan.Win32.Scar.cdww. The file is located in %ProgramFiles%\QuickTimeNo
QuickTimeXQuickTime.exeDetected by Dr.Web as Trojan.DownLoader5.43248. The file is located in %System%No
QuicktimeMngrXQuicktimeMngr.exeDetected by Trend Micro as WORM_WOOTBOT.BANo
Quick Time file managerXquicktimeprom.exeDetected by Symantec as Backdoor.SdbotNo
QuickTime Update Completion #Nquicktimeupdatehelper.exeDifferent numbers caused by number of launches - where # represents the number. So if 3 updates are made separately, 3 would appear (in theory). The file is located in %System%\QuickTime or %ProgramFiles%\QuickTime\QTSystemNo
LoadFujitsuQuickTouchUQuickTouch.exeMaps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functionsNo
QuickTourNQuickTour.exeRuns the QuickTour on the first reboot after installing Logitech's SetPoint software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). The tour is designed to help you get the most out of the device - you can learn about the default settings of your device and how to customize it for the way you workYes
QuickTVUQuickTV.exeInfra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote controlNo
QuickTimeUpdateXQuickUpdate.exeDetected by Sophos as Troj/Bifrose-CWNo
QuickyTranslatorUQuicky Translator.exeDetected by Malwarebytes as PUP.Optional.QuickyTranslator.PrxySvrRST. The file is located in %Windir%\Quicky Translator\Quicky Translator. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
quicuirixpipXquicuirixpip.exeDetected by Intel Security/McAfee as RDN/Generic Dropper!va and by Malwarebytes as Trojan.Agent.USNo
Animated WallpaperUQuiet Thunderstorm.exeQuiet Thunderstorm animated desktop wallpaper from Desktop AnimatedNo
QuikSyncNQUIKSYNC.EXEIomega (now LenovoEMC) QuikSync - tool to copy or backup data to a sync location on an external drive. No longer supportedNo
Iomega QuikSyncUQuikSync.exeIomega (now LenovoEMC) QuikSync - tool to copy or backup data to a sync location on an external drive. No longer supportedNo
Iomega QuikSync 3Uquiksync3.exeIomega (now LenovoEMC) QuikSync - tool to copy or backup data to a sync location on an external drive. No longer supportedNo
quinewipqezqXquinewipqezq.exeDetected by Intel Security/McAfee as RDN/Generic Dropper!va and by Malwarebytes as Trojan.Agent.USNo
QuitCounterNQuitCounter.exeQuit Counter by Xarka Software - a utility to help quit smoking which "keeps track of various statistics, friends and also congratulates the user with many different graphics on reaching various milestones"Yes
QuitCounter.exeNQuitCounter.exeQuit Counter by Xarka Software - a utility to help quit smoking which "keeps track of various statistics, friends and also congratulates the user with many different graphics on reaching various milestones"Yes
7xzbpXquosbnkp.exeDetected by Malwarebytes as Trojan.VBAgent. The file is located in %System%No
Quote on Table 3NQuote3.exeQuote on Table from Badevlad Company - displays automatically changing quotes and citations on your desktop. Start manually when requiredYes
Quote3NQuote3.exeQuote on Table from Badevlad Company - displays automatically changing quotes and citations on your desktop. Start manually when requiredYes
Quote3.exeNQuote3.exeQuote on Table from Badevlad Company - displays automatically changing quotes and citations on your desktop. Start manually when requiredYes
quqothibcequXquqothibcequ.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
qursumarlydfXqursumarlydf.exeDetected by Intel Security/McAfee as Downloader.a!cvx and by Malwarebytes as Malware.PackerNo
QuwergyXQuwergy.exeDetected by Dr.Web as Trojan.DownLoader10.58512 and by Malwarebytes as Trojan.BankerNo
quyxgauqegx.exeXquyxgauqegx.exeDetected by Dr.Web as Trojan.DownLoader12.18627 and by Malwarebytes as Trojan.Banker.IDF. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
qv7AQ7B6jXQ.exeXqv7AQ7B6jXQ.exeDetected by Intel Security/McAfee as RDN/Generic PWS.y and by Malwarebytes as Trojan.Agent.RND. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
GuffinsIE Browser Plugin LoaderUqvbrmon.exeGuffins toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\GuffinsIE\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itNo
QuickView Plus (Vers. 10.0.0) [View a File...]Nqvp32.exeQuick View Plus multiple file type viewer by Avantstar (was Inso Corporation) - "lets you view virtually any file or email attachment you need instantly, without purchasing numerous software programs"No
Qvp32.exeNQVP32.EXEQuick View Plus multiple file type viewer by Avantstar (was Inso Corporation) - "lets you view virtually any file or email attachment you need instantly, without purchasing numerous software programs"No
Quick View PlusNqvp32.exeQuick View Plus multiple file type viewer by Avantstar (was Inso Corporation) - "lets you view virtually any file or email attachment you need instantly, without purchasing numerous software programs"No
MicroUpdateXqw.exeDetected by Malwarebytes as Backdoor.Agent.DC. The file is located in %ProgramFiles%\QW22No
qw2jd.exeXqw2jd.exeDetected by Dr.Web as Trojan.Winlock.8854 and by Malwarebytes as Trojan.Winlock. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Quicken StartupNQWDLLS.EXEQuicken option to load DLLs at startupNo
qweXqwe.exeDetected by Sophos as Troj/Lineage-FNo
[various names]Xqwe.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
qwerty.exeXqwerty.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.15111 and by Malwarebytes as Worm.AutoRunNo
Microsoft Update MachineXqwerty.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %System%No
qwertybot.exeXqwertybot.exeDetected by ThreatTrack Security as Backdoor.Win32.Agent.alf. The file is located in %System%No
qwertyujhgfdXqwertyujhgfd.exeDetected by Dr.Web as Trojan.DownLoader6.51249 and by Malwarebytes as Trojan.DownloaderNo
werqewrqwerXqwerwqerq.exeDetected by Malwarebytes as Trojan.MSIL.ED. The file is located in %LocalAppData%\werqwerNo
Windows Spooler Control ServiceXqwidh.exeAdded by a variant of the SPYBOT WORM! See hereNo
Class Net.TCP Removal DiscoveryXqwnbwxvs.exeDetected by Malwarebytes as Trojan.QHost. The file is located in %System%No
WINUPDATERCLIENTSXqwrtaw5.exeDetected by Intel Security/McAfee as W32/Sdbot.worm!lw and by Malwarebytes as Backdoor.IRCBotNo
JUpdate 1.1.0Xqwrtaw5.exeDetected by Intel Security/McAfee as Generic.tfr!bf and by Malwarebytes as Backdoor.IRCBotNo
Micosoft LoggenXqxaw.exeAdded by the SDBOT-ID WORM!No
iJPIeNgnXqxjpfBXY.exeDetected by Malwarebytes as Trojan.Agent.FKS. The file is located in %AppData%\MozillaNo
QXrs0tB0Sgm09qoGuBvhqEIAAMXQXrs0tB0Sgm09qoGuBvhqEIAAM.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%No
qycvonvawamxXqycvonvawamx.exeDetected by Intel Security/McAfee as RDN/Generic BackDoor!sd and by Malwarebytes as Trojan.Agent.USNo
qyftegoblariXqyftegoblari.exeDetected by Intel Security/McAfee as Downloader.a!dbd and by Malwarebytes as Trojan.Agent.USNo
qygronhazepiXqygronhazepi.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %UserProfile%No
HCDNClientUQyKernel.exeDetected by Malwarebytes as PUP.Optional.IQIYI. The file is located in %ProgramFiles%\IQIYI Video\Common. If bundled with another installer or not installed by choice then remove itNo
qyprusotemusXqyprusotemus.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
66qiwXqz81l2.exeDetected by Kaspersky as Virus.Win32.Virut.ce. The file is located in %WinTemp%No
QZNewVerXqznewver.exeDetected by Dr.Web as Trojan.DownLoader5.57283No
loadXQzOuRq1|Û#@.exeDetected by Kaspersky as Hoax.Win32.Agent.jz. Note - this entry adds an illegal HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" entry which loads the file "QzOuRq1|Û#@.exe" (which is located in %System%)No
QuickZoneUDXQZUpdate.exeDetected by Dr.Web as Trojan.DownLoader5.57283No

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a list of tasks/processes taken from the Task Manager (CTRL+SHIFT+ESC) "Processes" tab. This displays some startup programs AND other background tasks and "Services". These pages are concerned with startup programs from the common startup locations shown above ONLY. Please do not submit entries collected from this method as they will not be used. For a list of tasks/processes you should try the list at PC Pitstop, the Process Library from Uniblue or one of the many others now available.

Therefore, before ending a task/process via CTRL+SHIFT+ESC just because it has an "X" recommendation, please check whether it's in the registry or common startup locations first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+SHIFT+ESC. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 25K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entries listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program.

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the Windows 8/7/Vista/XP/2K/NT operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2017 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home