Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Internet Mail and News [path to trojan]"Added by the SMUTSRCH-A TROJAN!"
X Internet Mail and News msqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
X Internet Optimizer optimize.exe"Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants"
X Internet Protocol Configuration Loader ipcl32.exe"Added by the SDBOT TROJAN!"
X Internet Security 2010 IS2010.exe"Internet Security 2010 rogue security software - not recommended
X Internet Security Service msq32.exe"Added by the RBOT-GFP WORM!"
X Internet Security Service msq23.exe"Added by the RBOT-GQL WORM!"
X Internet Security Service msql23.exe"Added by the RBOT-GML WORM!"
X Internet Security Service mysqlwin32.exe"Added by the RBOT.UX TROJAN!"
X Internet Security Service expllorer.exe"Added by the REFROSO.AFF TROJAN!"
X Internet Send More log.exeUnidentfied adware
X Internet Server inetsrv.exe"Added by the STARTPA-EM TROJAN!"
X Internet Service intersvc.exe"Added by the SPYBOT-DE WORM!"
X internet service syscfg32.exe"Added by the RBOT-QS WORM!"
X internet service ssvhost.exe"Added by a variant of the RBOT WORM!"
X internet service svho0st98.exe"Added by the RBOT.EAT WORM!"
X Internet Services systemdev.exe"Added by the SDBOT-PW WORM!"
X Internet Services internet.exe"Added by the MYTOB.BT WORM!"
X Internet Services interserv.exe"Added by the RBOT.BNT WORM!"
X Internet Services Netsvc.exe"Added by the MYTOB.MN WORM!"
X INTERNET SERVISES winz32.exe"Added by the KWBOT.Z WORM!"
Y Internet Sharing Server iss_srvr.exe"Intel AnyPoint internet sharing software. Now discontinued"
X Internet Suspention story.exe"Added by the WOOTBOT.HV WORM!"
N Internet Sweeper Sweeper.exe"Internet Sweeper - removes unnecessart left over files after browsing the internet"
U Internet Timer ITIMER.exe"Shareware dial-up connection call cost calculator from Ratsoft"
X Internet Washer Pro iw.exe"Internet Washer manages temporary browser files
X Internet.exe Internet.exe"Added by the MAGICCALL VIRUS!"
X internet.exe yinyin3345.vbs"Added by the YINI MACRO!"
X Internet2 Optimizer wkfix.exe"Added by a variant of the RBOT WORM!"
N InternetCalls InternetCalls.exe"InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
X InternetExplorer2 windows.exe"Added by the SDBOT-CZP WORM!"
X InternetExplorer32 iexplore32.exe"Added by the RBOT-GRA WORM!"
X InternetGetConnectedState winupdate.exe"Added by the SDBOT-JN WORM!"
X InternetGetConnectedStateEx winupdate.exe"Added by the SDBOT-JN WORM!"
X InternetShield INTERN~1.EXE"InternetShield rogue security software - not recommended
X InternetShield InternetShield.exe"InternetShield rogue security software - not recommended
U InternetSpy InternetSpy.exe"Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
X InternetWasherPro iw.exe"Internet Washer manages temporary browser files
X Internet_Explorer microsoft.exe"Added by the BANKER-EUQ TROJAN!"
X Internet_Explorer.exe Internet_Explorer.exe"Added by the BANKER-END TROJAN!"
X INTERNET_SERVISES winz32.exe"Added by the SDBOT.Q TROJAN!"
U InternodeUsage mum.exeAustralian ISP's free monthly download meter
X Internt Internt.exe"Added by the PEEPER or CARUFAX.A TROJANS!"
X Inters Configuration Loader RCL0ADERS.exe"Added by the SDBOT-KX WORM!"
X Intersoft Msngr intersoftmsngr.exe"Added by the AGOBOT-NW WORM!"
N InterTrust Quick Start it_cpq~1.exe"InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
X InterU WINDRV.EXE"Added by the IRCINTER.A TROJAN!"
N Intervideo Win Cinema Manager WinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
N Intervideo Win Cinema Manager WINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
N Intervideo WinCinema Manager WinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
N Intervideo WinCinema Manager WINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
N Intervideo WinScheduler WinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
N Intervideo WinScheduler SchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
N InterVoip InterVoip.exe"InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
U InterWARN interwarn.exe"InterWARN by Storm Alert Inc. Provides customized
X Intespention IEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Intmgr Intmgr.exe"Added by the GEMA TROJAN!"
X intranet SYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
X Intranet intranet.exe"Added by the CHIMOZ.AC TROJAN!"
X Intranet schost.exe"Added by the RBOT.SV BACKDOOR!"
X Intranet Explorer [random filename]"Added by the POEBOT.DK BACKDOOR!"
X Intrenat Intrenat.exe"Added by the LEMIR.E TROJAN!"
N Introducing Media Manager SPLASHA.EXE"MS Media Manager tour. Not required"
N Introduction-Registration ??"For Compaq PC's. Should only run first time
X IntruderAlert ia99.exe"Intruder Alert '99 from Bonzi - spyware"
X IntSys1 [path to trojan]"Added by the BANLOA-ASE TROJAN!"
Y Intuit SyncManager IntuitSyncManager.exe"Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync
U Inventory Scan LDISCN32.EXE"LANDesk® Management Suite software component"
X Ioadqm Media Player.exe"Added by the HAWAWI WORM!"
N iobi iobiClient.exe"iobi Home - a mail/voice service by Verizon"
Y iolo AntiVirus ioloAV.exe"iolo AntiVirus"
Y iolo Personal Firewall ioloFW.exe"iolo Personal Firewall"
U Iolo Task Agent Task_Agent.exe"Iolo System Mechanic Task Agent. Scheduled maintenance"
N iolo Utility Bar SMUtilityBar.exe"Iolo System Mechanic Utility Bar - can be launched manually"
U ioloDelayModule delay.exe"Part of Iolo System Mechanic. Used to delay the start of an application which loads automatically as Windows loads"
U Iomega Automatic Backup ibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
U Iomega Automatic Backup 1.0.1 ibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
N Iomega Backup Scheduler dtiom98.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
U Iomega Disk Icons IMGICON.EXE"Displays Iomega icons in Explorer/My Computer
U Iomega Drive Icons IMGICON.EXE"Displays Iomega icons in Explorer/My Computer
U Iomega ImIconXP imiconxp.exe"Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system
? Iomega QuickSync Quicksync.exe"??"
N Iomega Startup Options IMGSTART.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
N Iomega Watch IOWATCH.EXEUsed by Iomega drives. Available via Start -> Programs
N IomegaWare COMMANDER.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
X Iomega_loader Iomega_loader.exe"Added by the ANTINNY.F WORM!"
U Iomon98.exe Iomon98.exePC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
X ioroxxo microsoft sux system32.exe"Added by a variant of the RBOT WORM!"
X IP IP.EXE"Added by the AGOBOT-QO WORM!"
U IP Changer 2.0 IPChanger.exe"IP Changer 2.0 from Plustech Inc - network configuration management tool"
X IP Packet Redirect Service ipredirect.exe"Added by the FORBOT.SM WORM!"
X IP Stack ipstack.exe"Added by the AGOBOT.CW WORM!"
X IP**.exe [* = random char] IP**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X IP**32.exe [* = random char] IP**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
N iPalm mon.exe"Installed with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded"
X IPC Connection ipcconn.exe"Added by the RBOT-AEG WORM!"
X IPC Spool Manager wnmgre.exe"Added by the SDBOT-ZC WORM!"
X IPC Spool Manager winspec.exe"Added by the SDBOT-BLU WORM!"
X ipcfg.exe ipcfg.exe"Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!"
X IPConfig svcxnv32.exe"Added by the HACARMY.E TROJAN!"
X IPConfig svcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
X IPConfig ipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
X IpCtrl ipcon32.exe"Added by an unidentified VIRUS
X IPFW ipwf.exe"Added by the DLOADER-YF TROJAN!"
? IPHSend IPHSend.exe"AOL related. What does it do and is it required?"
N IPInSightLAN 01 IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
N IPInSightMonitor 01 IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
Y IPinst N/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
X IPLog Security iplogsec.exe"Added by the IRCBOT.GP BACKDOOR!"
? iPlusAgent2 iAgent2.exe"Related to iriver portable media products. What does it do and is it required?"
X ipmon.exe ipmon.exe"Added by the RECERV or R3C.B TROJANS!"
X IpNetwork ipnetwork.exeMaxifiles adware
X Ipnuker Ipnuker.vbs"Added by the INKER.B WORM!"
N IPO3 IP Operator 2005.exe"
X Ipod Help [9 random letters].exe"Added by a variant of the RBOT WORM!"
X iPOD USB Driver IPODUSB.EXE"Added by a variant of the RBOT WORM!"
X iPod USB Service iPODService.exe"Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service
N iPodder iPodder.exe"iPodder (now known as Juice) - a free utility that ""allows you to select and download audio files from anywhere on the Internet to your desktop"". This entry is present if you choose the option to add it to the startup group during installation"
U iPodManager iPodManager.exe"Apple iPod® management software for the iPod® player - updates
? iPodWatcher iPodWatcher.exe"Associated with Apple's iPod® player. Detects when the iPod® is connected?"
U ipoint ipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
X IPOT Service Drivers compaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
X IPOT USB Service DRIVER hpsebc087.exe"Added by the SDBOT-WA WORM!"
X IPOT USB Service DRV32 hpsebc08.exe"Added by the SDBOT-WH WORM!"
N IPPDetect IPP4Detect.exe"Part of Presto! Mr.Photo - ""an ideal program for creating
X ipreg ipreg.exe"Added by the ZAGABAN-H TROJAN!"
? iPrint LPT Redirector nipplpte.exe"Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
N iPrint Tray iprntctl.exe"Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net"
U iProtectYou ip.exe"iProtectYou - internet filtering/parental control and network monitoring software"
X iprun iPY.exe"iProtectYou spyware"
X IPSEC Configuration wsupdate.exe"Added by the AGOBOT-IQ WORM!"
X iPSec7 ipsec7.exe"Added by the AGENT.AHVR TROJAN!"
U ipsecdialer IPSECD~1.EXE"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
U ipsecdialer ipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
Y IPSecMon IPSecMon.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
X IPTable Configuration Winipcfgs.exe"Added by a variant of the RBOT WORM!"
N iptray iptray.exe"System Tray access to Intel Desktop Utilities - ""provides you with the means to monitor system temperatures
X IPv6 Helper Driver csass.exe"Added by the AGOBOT.TC WORM!"
X IPv6 STUN Service netstun.exe"Added by a variant of the SDBOT WORM!"
N IPW IPW.exe"Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to ""make and receive free Internet calls on your regular phone"" whilst ""at the same time
N ipw usbipw.exe"Related to Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to ""make and receive free Internet calls on your regular phone"" whilst ""at the same time
X ipwf ipwf.exe"Added by the SCHOEBERL TROJAN!"
X IpWins ipwins.exe"IPWins adware"
X ipxwshel ipxwshel.exe"Added by the WAREZOV.DG WORM!"
X ipyjy woniz.exe"Added by the SDBOT.BQD WORM!"
? IQES.exe iqes.exe"??"
X iqmanager.exe iqmanager.exe"IQ-Manager ransomware copyright scanner - not recommended
U Ir41_32.ax regsvr32.exe Ir41_32.ax"Intel® Indeo® video 4.4 Decompression Filter related. The ""Ir41_32.ax"" file is located in %System%"
X irassync irasyncd.exe"IRASSync adware"
X irc session sessionmgr.exe"Added by the SDBOT-ACE WORM!"
Y IREIKE IreIKE.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
N iRis Active Monitor winmon32.exe"Iris Antivirus - discontinued
N iRiS AntiVirus Active Monitor WIMMUN32.exe"Iris Antivirus - discontinued
U IRIS_S2P Scan2pc.exeScan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer
U IRIS_XRX_S2P Scan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer
U iRiver AutoDB MLService.exe"Associated with the iRiver Music Manager"
N iRiver Updater Updater.exe"Updates for the iRiver Music Manager - used with their digital music players"
U IrMon IRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
? IRPMonitor itcnmon.exe"??"
X irssyncd irssyncd.exe"SafeSurfing adware variant"
X Irwftp [path to trojan]"Added by the BANCOS-AP TROJAN!"
X irwftp iexplorer.exe"Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X irwftp ftpmon.exe"Added by the BANCBAN-BO TROJAN!"
U IrXfer IrXfer.exeMicrosoft Infrared Transfer application
X ir_ftp ir_ftp.exe"Added by the IRFTP TROJAN!"
X ir_ftp irwftp.exe"Added by the BANCOS.H TROJAN!"
N IS CfgWiz cfgwiz.exeNorton Internet Security configuration wizard
X iSafeAV iSafeAV.exe"iSafe AntiVirus rogue security software - not recommended
X isamini.exe isamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X isamonitor.exe isamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X Isass Isass.exe"Added by the FUTRO TROJAN!"
X IsassRenascimento Issas.exe"Added by the BANKER.GAX TROJAN!"
U ISBMgr.exe ISBMgr.exeRelated to Sony ISB Utility
X iscch iscch.exe"Added by the LCPRANK-A WORM!"
N isdbdc isdbdc.exeFor Compaq PC's. May install properties in dial-up networking when you register with an ISP
U isDeleteMe isDel.batUsed by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product
N ISDN Monitor Linksts.exe"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards
U ISDNwatch IWatch.exe"FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"""
X iSecurity applet "rundll32.exe iSecurity.cplSecurityMonitor"
X ish-b.exe ish-b.exe"Added by the IRCBOT-ACZ TROJAN!"
U ISHelp help.exe"ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it"
U iShield iShield.exe"""GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser"""
X ishost.exe ishost.exe"Added by the DLOADR-XJ TROJAN!"
Y ISLP2STA ISLP2STA.EXEA process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers
X ISMModule ISMModule.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule2 ISMModule2.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule3 ISMModule3.exe"Internet Speed Monitor C adware"
X ISMModule4 ISMModule4.exe"Internet Speed Monitor A adware related"
X ISMModule6 ISMModule6.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule7 ISMModule7.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule8 ISMModule8.exe"Internet Speed Monitor C adware related"
X ISMPack5 ISMPack5.exe"Internet Speed Monitor C adware related - see example here"
X ISMPack6 ISMPack6.exe"Internet Speed Monitor C adware related - see example here"
X ISMPack7 ISMPack7.exe"Internet Speed Monitor C adware"
X ISMPack8 ISMPack8.exe"Internet Speed Monitor C adware related - see example here"
Y ISP.COM High Speed slipgui.exe"User interface for Slipstream - internet acceleration through compression/decompression techniques
X ISPSERVICE psycho.exe"Added by the IRCFLOOD-O TROJAN!"
X ISPSERVICE wintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
U iSpyNOW ispynow.exe"iSpyNOW - remote monitoring and surveillance software"
X Israfel Israfel.vbs"Added by the GAGGLE.D or GAGGLE.E WORMS!"
N IsReminder ISPopup.exe"Related to GuardWare iShield - this is the registration reminder for the trial version
X ISS inet.exe"Meplex adware"
N issch issch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
X issearch.exe issearch.exe"Added by the ZLOB-QF TROJAN!"
X issEnc32Svr issEnc32.exe"Added by a variant of the RBOT WORM!"
N ISSI EZUpdate Service issimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
U ISStart ISStart.exe"Installed with Logitech's QuickSmart
Y ISSVC ISSVC.exePart of Norton Internet Security Suite
Y ISS_Certtool certtool.exe"Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk)
X IST Service istsvc.exe"ISTBar adware"
X ist service uninstall [random filename]"ISTBar adware related"
X istinstall zazzer.exe istinstall zazzer.exeUnidentified adware downloader/installer
Y ISTray pctsTray.exe"System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
N ISUSPM ISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
N ISUSPM Startup ISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
N ISUSScheduler issch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list