Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Config TaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
X Config Loadation iEEexplore.exe"Added by the SDBOT.H TROJAN!"
X Config Loadatiorin I3Explorer.exe"Added by the SDBOT.H TROJAN!"
X Config Loader svchosl.exe"Added by the GAOBOT.P WORM!"
X Config Loader sysldr32.exe"Added by the GAOBOT WORM!"
X Config Loader scvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
X Config Loader svhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Config Loader svchost2.exe"Added by the AGOBOT.XE WORM!"
X Config Loader [worm filename]"Added by the AGOBOT-AE WORM!"
X Config Loader SYSMGR.EXE"Added by the AGOBOT.C WORM!"
X Config Loader wincrt32.exe"Added by the AGOBOT-AW WORM!"
X Config Loader for Microsoft Windows mwincfg32.exe"Added by the AGOBOT.BD WORM!"
X Config Loader2 explores.exe"Added by the GAOBOT.BT WORM!"
X Config Loadr winsys32.exe"Added by the AGOBOT-HN WORM!"
X Config33.exe Config33.exe"Added by the SDBOT.T TROJAN!"
X ConfiggLoader cart322.exe"Added by the GAOBOT.DJ WORM!"
U ConfigSafe CFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
U ConfigSafe AUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
N ConfigServices Config.exePart of initial setup on a Compaq PC
X configsetup configsetup32.exe"Added by the AGOBOT-AFP WORM!"
X Configuration explorer32.exe"Added by the SDBOT-ML WORM!"
X configuration apphost.exe"Added by the SDBOT-VP WORM!"
X Configuration ntsys32.exe"Added by the SDBOT-LN WORM!"
X Configuration msgfixs.exe"Added by the SDBOT-NN WORM!"
X Configuration Default Wuxat.exe"Added by the SPYBOT-CA WORM!"
X Configuration Driver scghost.exe"Added by the SDBOT-DLA WORM!"
X Configuration File Winset32.exeAdded by the FLUX.101 TROJAN!
X Configuration Loaded wupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
X Configuration Loaded lssas.exe"Added by a variant of the SDBOT WORM!"
X Configuration Loaded iexploree.exe"Added by the SDBOT-KC WORM!"
X Configuration Loader aim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader cmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader syscfg32.exe"Added by the SDBOT.B BACKDOOR!"
X Configuration Loader service5.exe"Added by the GAOBOT.AF WORM!"
X Configuration Loader lfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader sycfg34.exe"Added by the GAOBOT.AN WORM!"
X Configuration Loader wincrt32.exe"Added by the GAOBOT.BF WORM!"
X Configuration Loader windex.exe"Added by the GAOBOT.BZ WORM!"
X Configuration Loader dosrun32.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader Service.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader Servicess.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader sw32.exe"Added by the AGOBOT.BQ WORM!"
X Configuration Loader System.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader Winreg.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader sysinfo.exe"Added by the GAOBOT.FQ WORM!"
X Configuration Loader microsoft.exe"Added by the GAOBOT.JB WORM!"
X Configuration Loader confgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
X configuration loader winicfg32.exe"Added by the GAOBOT.RQ WORM!"
X Configuration Loader svhst.exe"Added by the GAOBOT.YC WORM!"
X Configuration Loader msgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
X Configuration Loader msnss.exe"Added by the GAOBOT.AUS WORM!"
X Configuration Loader IEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
X Configuration Loader loadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
X Configuration Loader MSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader systemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader ccSort.exe"Added by the AGOBOT.SR WORM!"
X Configuration Loader smss32.exe"Added by the AGOBOT.MB WORM!"
X Configuration Loader wincffg.exe"Added by the AGOBOT.A3 WORM!"
X Configuration Loader seru32.exe"Added by the SDBOT-VR WORM!"
X Configuration Loader botss.exe"Added by the SDBOT-XS WORM!"
X Configuration Loader ldasp.exe"Added by the AGOBOT.BH WORM!"
X Configuration Loader msgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader smsai.exe"Added by the SDBOT-YE WORM!"
X Configuration Loader svupdate.exe"Added by the RANDEX.DXP WORM!"
X Configuration Loader crcss.exe"Added by the AGOBOT.ADG WORM!"
X Configuration Loader lexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
X Configuration Loader scvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
X Configuration Loader svchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X Configuration Loader svchost2.exe"Added by the AGOBOT.JR WORM!"
X Configuration Loader dezi.exe"Added by the SDBOT-OB WORM!"
X Configuration Loader mouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader msg.exe"Added by the SDBOT.BT WORM!"
X Configuration Loader WinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader extrac.exe"Added by the SDBOT-AFP WORM!"
X Configuration Loader DVD-Player.exe"Added by a variant of the SDBOT WORM!"
X Configuration Loader IEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Configuration Loader wincore.exe"Added by the SDBOT.BHE WORM!"
X Configuration Loader configldr.exe"Added by the AGOBOT-PP TROJAN!"
X Configuration Loader ahnhst.exe"Added by the AGOBOT.MX WORM!"
X Configuration Loader ntdm.exe"Added by the AGOBOT.RV WORM!"
X Configuration Loader msnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
X Configuration Loader svschost.exe"Added by the SDBOT-NS WORM!"
X Configuration Loader wump.exe"Added by the AGOBOT-BU BACKDOOR!"
X Configuration Loader WinSys32ys.exe"Added by the SDBOT.BCS WORM!"
X Configuration Loader cvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
X Configuration Loader asnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
X Configuration Loader soundconf.exe"Added by the AGOBOT-MH WORM!"
X Configuration Loader win32exec.exe"Added by the SDBOT-LA WORM!"
X Configuration Loader mservs.exe"Added by the SDBOT-NM WORM!"
X Configuration Loader update.exe"Added by the SDBOT-OS WORM!"
X Configuration Loader FILENAME.EXE"Added by the AGOBOT-DQ WORM!"
X Configuration Loader explore.exe"Added by the GAOBOT.GW WORM!"
X Configuration Loader msgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
X Configuration Loader winfix.exe"Added by the SDBOT-MA WORM!"
X Configuration Loader scvh0st.exe"Added by the AGOBOT-AX WORM!"
X Configuration Loader msrun.exe"Added by the AGOBOT-Y WORM!"
X Configuration Loader 2 confuldr.exe"Added by the AGOBOT-FC WORM!"
X Configuration Loader Service Winsys32.exe"Added by the RBOT-YV WORM!"
X Configuration Loader Service devl32.exe"Added by the SDBOT-XY WORM!"
X Configuration Loader10 ip7.exe"Added by the AGOBOT-ANZ WORM!"
X Configuration Loading svchos1.exe"Added by the GAOBOT.DK WORM!"
X Configuration Loading configldr.exe"Added by the AGOBOT-EC WORM!"
X Configuration Loading Service wscel.exe"Added by the SDBOT-WJ WORM!"
X Configuration Loadr iexplore.exeeAdded by an unidentified WORM or TROJAN!
X Configuration Manager CNFGLD32.EXE"Added by the SDBOT TROJAN!"
X Configuration Manager Cnfgldr.exe"Added by the SDBOT TROJAN!"
X Configuration Manager cfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
X Configuration Servecie sewins.exe"Added by the SDBOT-COH WORM!"
X Configuration Service suchost.exe"Added by the TREB TROJAN!"
X Configuration Services mswords.exe"Added by the SDBOT-YM WORM!"
X Configuration Update UPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
N Configuration Utility CONFIG.EXEControls linksys wireless connection. Available from the Desktop
U Configuration Utility wlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
X Configuration Wizard Cfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
X Configuration32 Loader32 winamp32.exe"Added by the SDBOT-BIC WORM!"
X Configurations Asclt asclt.exe"Added by the SDBOT-MX WORM!"
X CONFIGUREv antivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
U ConfigUtility ConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies
X ConfigVir services.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
X ConfLoader sysconf16.exe"Added by the SDBOT-FB TROJAN!"
X conime.exe conime.exe"Added by the AVENDOG WORM! Note - this is not the legitimate Console IME process of the same filename which is located in %System%"
N Conmgr conmgr.exeStarts Winfax pro at startup
U ConMgr.exe conmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
X conmswf conrnbne.exe"Added by the SDBOT-DEX WORM!"
U Connect Kasamba Kasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
X Connect2Party connect2party.exeAdult content dialler
N CONNECTAuto Update CONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
N CONNECTAUTrayApp CONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
U Connection Keeper ConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle
N Connection Manager CManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
X Connectivity Tool [path to trojan]"Added by the LITEBOT-E TROJAN!"
X Connector SYS.EXE"Nunci premium rate dialer"
X Connector sms.EXE"Added by the ExDial-B premium rate adult content dialer"
N CONNECTScheduler CONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
X Cons consol32.exe"Hijacker - redirects to an adult content portal
X conscorr conscorr.exe"VX2.Transponder parasite updater/installer related"
X Console de Gerenciamento Microsoft csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
X Console de Gerenciamento Microsoft csrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
U Consumer Input ConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
? Contacte contacte.exe"Some kind of driver?"
X Content connector [random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
X Content List Management Subsystem clmss.exe"Added by the SPYBOT-EL WORM!"
X Content Service winserv[LETTER].exe"PurityScan adware"
X ContentDownload "rundll32.exe MSA64CHK.dllDllMostrar"
X ContentEraser GDC.exe"ContentEraser rogue privacy tool - not recommended
X ContentService winservn.exe"PurityScan adware - see here"
U ContentTransferWMDetector.exe ContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
X ContinueInstall bpsinstall.exe"BrowserAid/BrowserPal foistware"
X Contraviro Contraviro.exe"Contraviro rogue security software - not recommended
X ContraVirus ContraVirusPro.exe"ContraVirus rogue security software - not recommended
X ContraVirus ContraVirus.exe"ContraVirus rogue security software - not recommended
X Control "rundll32.exe ctrlpan.dll Restore ControlPanel"
U Control Center Center.exe"Associated with Hawking Technologies
X Control handler ***********.exe [* = random char]"CoolWebSearch parasite variant"
X Control handler ahjinst.exe"CoolWebSearch parasite variant"
X Control handler [10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
N control panel smctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
X Control Panel System.exe"Added by the DANI TROJAN!"
X control panel software service cprs.exe"Added by the RBOT-FPI WORM!"
X Controladores [path to trojan]"Added by the TELEFO-A TROJAN!"
Y ControlCenter ctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
N ControlCenter2.0 brctrcen.exeBrother scanner 'Control Center' application - can be started manually
N ControlCentreTray XWCTray.exe"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers
X Controlled Resource System Service crss.exe"Added by the AGOBOT.GH WORM!"
N Controller WFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
X ControlPanel "rundll32 internat.dll LoadKeyboardProfile"
X ControlPanel "host32.exe internat.dll LoadKeyboardProfile"
X ControlPanel "cmd32.exe internat.dllLoadKeyboardProfile"
X ControlPanel "systemctrl.exe internet.dll LoadNetworkProfile"
X ControlPanel "[path to executable] internat.dllLoadKeyboardProfile"
X ControlPanel "popcorn.exe internat.dll LoadKeyboardProfile"
X ControlPanel "popcorn64.exe rundll.dll LoadMouseProfile"
X ControlPanel "popcorn72.exe rundll.dll LoadMouseProfile"
X ControlPanel "svcc.exe internat.dllLoadKeyboardProfile"
X ControlPanel "popcorn320.exe rundll.dll LoadMouseProfile"
X ControlPanel "private.exe internat.dllLoadMouseCarpetProfile"
X ControlPanel "twink64.exe internat.dllLoadKeyboardProfile"
X ControlServiceMgr csmsv.exe"Added by the AGENT-XC TROJAN!"
U Cookie Cop 2 CookieCop.exe"
U Cookie Pal CPBRWTCH.EXE"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
U CookieJar Cookiejar.exe"Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return. No longer being actively supported"
U CookiePatrol CookiePatrol.exe"CookiePatrol - cookie interceptor stopping spyware cookies that used to be part of PestPatrol before CA's aquisition"
U CookieWall cookie.exe"CookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return"
X cookw cookw.exe"Part of the ErrClean rogue system error and cleaning utility - not recommended. See here"
U Cool Desk cdesk.exe"Cool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you"
X CoolDownloads "rundll32.exe MSA64CHK.dllDllMostrar"
U CoolMon CoolMon.exe"""CoolMon monitors vital system stats and almost anything else you wish to display on the desktop"""
X CoolMP3 "rundll32.exe MSA64CHK.dllDllMostrar"
U CoolSwitch taskswitch.exeALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
N Coolwallpaper cwm_tray.exe"Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers"
X coolwebprogram clrssn.exe"CoolWebSearch Smartsearch parasite variant"
N Copernic Desktop Search DesktopSearch.exe"Copernic Desktop Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file
U Copernic Desktop Search 2 DesktopSearchService.exe"Copernic Desktop Search - search agent"
U CopernicPerUserTaskMgr CopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
U Copperhead razerhid.exe"Razer Copperhead gaming mouse driver - required if you use the additional features and programmed keys/macros"
U Copy handler Copy Handler.exe"Copy Handler lets you copy between hard disks
N Copyright mwcpyrt.exeDisplays copyright information on IBM ThinkPads
X Core Process Aplication ccapl.exe"Added by the QHOSTS.G TROJAN!"
X Core Process Aplication x16 ccapl16.exe"Added by the SPYBOT.AFT WORM!"
X Core Process Aplication x32 ccapl32.exe"Added by the SRAMLER.E TROJAN!"
X Core System Hardware syscorehd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
U CoreCenter CoreCenter.exe"MSI Core Center - motherboard utility for monitoring CPU speed
U CoreCenter CORECE~1.EXE"MSI Core Center - motherboard utility for monitoring CPU speed
X Coreguard Antivirus 2009 Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
N Corel Colleagues & Contacts Reminders cffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
N Corel Desktop Application Director dadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
N Corel Family & Friends reminders CFFREM.EXE"Corel Family & Friends - all-in-one calender
N Corel Photo Downloader MediaDetect.exe"Related to Corel Photo Album"
N Corel Registration Remind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
N Corel Registration Reminder Remind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
N Corel Reminder NAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
N Corel Reminder NAVBrowser.exeRegistration reminder for CorelDRAW 10
N CorelCENTRAL 10 I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
X CorelDraw Toolbox CorelDraw.exe"Added by the SDBOT-VZ WORM!"
N CorelMedia FoldersIndexer8 MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
N CorelMedia FoldersIndexer8 MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list