Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X MediaPath Root.exe"Added by the GRUEL WORM!"
X MediaPipe P2P Loader mpp2pl.exe"MediaPipe peer-to-peer file swapping program also reported as a hijacker"
X mediaplayer.exe mediaplayer.exe"Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
X mediaplayer.exe mediaplayer.exe"Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
X MediaPlayeS MediaPlayer_update.exe"Added by the STARTER-K TROJAN!"
X mediapluscash.exe mediapluscash.exe"MediaGateway adware"
N MediaRing Talk mrtalk.exe"Media Ring Talk
? MediaSync MediaSync.exe"Found on Acer laptops
X MediaXPServicePack mxpsp.exe"Added by the SDBOT.CDT WORM!"
X media_manager mediaman.exe"Mini-Player
X media_stub stub.exe"Mini-Player
U MEDIC sprtcmd.exe /P MEDIC"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
X Medichi medichi.exe"Added by the VIRANTIX.B TROJAN!"
X Medichi2 medichi2.exe"Added by the VIRANTIX.B TROJAN!"
U medicsp2 sprtcmd.exe /P medicsp2"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
? MedionVFD MdionLCM.exe"Related to Medion Display Information. What does it do and is it required?"
X Meeting Connection comsutil.exe"Added by the PPDOOR-E TROJAN!"
X Meeting Connection wowdache.exe"Added by the PPDOOR-D TROJAN!"
X Meeting Connection hgakdl32.exe"Looks like a variant of the PPDOOR-E TROJAN!"
U MegaPanel HSTrans.exe"Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
X MegaVirusKit pgs.exe"MegaVirusKit rogue security software - not recommended. A member of the AVSystemCare family"
? meidntpa vqgdpfrs.exe"??"
X melg34 mdmd.exe"Added by an unidentified WORM or TROJAN - see here"
X melg3445 mdmdd.exe"Added by a variant of the RBOT WORM!"
X mem32 mem32.exe"Added by the AGENT-FWF WORM!"
X Members area ******.exe [* = random digit]Premium rate adult content dialer
X MemConfig SetupIE.com"Added by the TAPLAK WORM!"
N Memento Memento.exe"Memento - simple app to keep text notes on your desktop"
U MemMonster memmnstr.exe"MemMonster - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
U MemoKit MK.EXE"Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
X memory outlookrem.exe"Added by the NOPIR.C WORM!"
X Memory Allocation Host cihost.exe"Detected by Avast as a variant of the IRCBOT-CHZ WORM!"
X Memory Allocation Server ciserv.exeAdded by an unidentified malware
X Memory Allocation Services cisrv.exe"Added by the IRCBOT.FC BACKDOOR!"
X Memory Check memore.exe"Added by the KILLAV.C TROJAN!"
X Memory manager himem32.exe"Added by the MANCSYN TROJAN!"
X Memory Manager memorymanager.pif"Added by the DELF-JJ TROJAN!"
X Memory relocation service reloc32.exe"Added by the RELFEERWORM!"
X Memory Service freememory.exeAdded by the RBOT.GEN WORM!
N Memory Stick Monitor MSTAT.exe"Used with the Sony floppy disk adapter for memory sticks
U Memory Stick Monitor MSstat.exeSony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
X Memory Watcher MemoryWatcher.exe"MemoryWatcher spyware"
U Memory+ tfimemsr.exe"Memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
U MemoryBoost MemoryBoost.exe"MemoryBoost - memory optimizing program made by Tenebril Inc. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/ME. See this article and make up your own mind"
U MemoryCardManager MemCard.exe"Memory Card Manager - for removable memory cards found on Dell or Lexmark photo printers"
X MemoryManager [random name].dllVirtumondo adware related
X MemoryMeter MemoryMeter.exe"MemoryMeter - bundled with TVMedia adware"
U MemoryZipperPlus memzip.exe"Memory Zipper Plus - ""optimizes the memory management of your system and boost-up its performance amazingly!"""
X memreader.exe memreader.exe"Added by the AGOBOT-TY WORM!"
X MEMreaload MEMreaload.exe"Added by the LAZAR TROJAN!"
X MemScanner MemScanner.exe"Part of Enigma SpyHunter - not recommended
U MemTurbo memturbo.exe"MemTurbo memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
X MenaceFighter GDC.exe"MenaceFighter rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
X MenaceSecure pgs.exe"MenaceSecure rogue security software - not recommended. A member of the AVSystemCare family"
N MenuSnap MenuSnap.exe"MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe"
N Mercora MercoraClient.exe"Mercora MusicSearch ""Search
N Message Center Plus MCPLaunch.exe"Launcher for Message Center Plus ""which alerts you when conditions arise on your computer that require your attention"" on IBM/Lenovo ThinkCentre desktops
X Message Queuing msmqs.exe"Added by the FREEFORS TROJAN!"
N MessagerStarter Freeserve StartMessager.exeFreeserve Messenger
U Message_Blocker messageblock.exe"Message Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation
X Messanger trillian.exe"Added by the RBOT.CKI WORM!"
X Messanger deamon.exe"Added by the TACTSLAY.C TROJAN!"
X Messanger msgaol.exe"Added by the TACTSLAY.C TROJAN!"
X Messanger s_menu.exe"Added by the TACTSLAY.C TROJAN!"
X Messanger browse.exe"Added by the TACTSLAY.C TROJAN!"
X Messenger messenger.exe"Added by the KUTEX TROJAN!"
X Messenger ntsubsys.exe"Added by the SDBOT.BGE WORM!"
X Messenger Wmsngr.exe"Added by a variant of the RBOT WORM!"
Y Messenger SCANMSG.EXE"AntiVirus Quick Heal - virus protection"
N Messenger MsnMsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → General → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 8.*"
N Messenger msmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
X Messenger msnmsgrr.exe"Added by the RBOT-GYK WORM!"
N Messenger (Yahoo!) YahooMessenger.exe"System Tray access to the Yahoo! Messenger instant messenger"
X Messenger Block msngrblock.exe"Added by the PATOO WORM!"
X Messenger Explorer m41n.exe"Added by the SDBOT-SA BACKDOOR!"
X Messenger Gateway msmgs.exe"Added by the AGENT-IGK TROJAN!"
X Messenger Protocol netsender.exe"Added by the SDBOT-ACC WORM!"
X Messenger Service msmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
X Messenger Service nvhost.exe"Added by the JLOK-A WORM!"
X Messenger Service Updater svshost.exe"Added by the MYTOB.GC WORM!"
X Messenger Sharing Control mnwsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Messenger start-up Msgran.exe"Added by the GRAMOS WORM!"
X Messenger6 command.pif"Added by the INZAE.B WORM!"
X Messenger91 messengersystem.exe"Added by the RBOT-FPF WORM!"
U MessengerDiscovery MessengerDiscovery.exe"MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features. Now superseded by MessengerDiscovery Live - with support added for Windows Live"
N MessengerPlus MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
N MessengerPlus2 MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
N MessengerPlus3 MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
X messengerskinner MessengerSkinner.exe"Messenger Skinner malware - uses a rootkit to hide executable files"
X messnger [worm filename]"Added by the DELODER WORM!"
X messnger Dvldr32.exe"Added by the DELODER.A WORM!"
N Metacafe MetacafeAgent.exe"Metacafe - video sharing on the web. Note - if you subscribe make sure you read the Privacy Policy"
X MeTaLRoCk (irc.musirc.com) has sex with printers metalrock-is-gay.exe"Added by the RANDEX.Q WORM!"
X MeuPrograma accwizz.exe"Added by the RULAND.A WORM!"
X Mfc**.exe [* = random char] Mfc**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X Mfc**32.exe [* = random char] Mfc**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
? mfgboot ??"??"
X mfhsornwnduy regsvr32.exe gisyflngpshcvuakv.dll"Pro AntiSpyware 2009 rogue spyware remover - not recommended
X mFilter MNeck.exe"Added by the CLICKER-AG TROJAN!"
X mfin32 mfin32.exeMyFreeInternetUpdate - adware downloader
Y mfp mfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
U MFP PanelMgr SSMMgr.exe"Monitors ink levels
Y MFP Server Agent MFPAgent.exe"Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520"
U MFP1815_S2P Scan2pc.exeScan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer
X Mfqneqfeb vdddwq.exe"Added by the RANDEX.AP WORM!"
? MGA Hook Mgahook.exe"MATROX Graphics card related. What does it do and is it required?"
N MGA Quickdesk MGAQDESK.EXEFor Matrox video cards. Quick access to tweak your card to your liking
U Mgabg Mgabg.exe"Matrox BIOS Guard - monitors a Matrox card's BIOS
Y mgavctrl mgavrtcl.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
Y mgavrtclexe mgavrtcl.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
Y mgavrtclexe mgavrte.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
N MGA_CD_Install mgasetup.exeMatrox Millennium video driver. Not required once drivers installed
X mgmtapi mgmtapi.exeUnidentified malware
X Mgsgi service wkzfn.exe"Added by the AGOBOT-AHL WORM!"
U MGSysCtrl MGSysCtrlPart of the System Control Manager for MSI notebooks - displays animations for hot key commands (such as turning the wirelss card on/off)
X MHDOGStart mhdogst.EXE"Added by an unidentified VIRUS
N MHINIT MHINIT.EXEPart of the Cybermedia Clean Sweep package
X mhs3 mhs3.exe"Added by the PWS-ALZ TROJAN!"
X Mi7sft sdce b0yz.exe"Added by the RBOT.CWG WORM!"
X Mi7sft sdce MNSQ.exe"Added by the RBOT.DMU WORM!"
X Mi7sft sdce scorti.exe"Added by the RBOT.ELC WORM!"
X Mickey Mouse Cereal [random filename].exe"Added by the RANKY.Q TROJAN!"
X Micosoft Data Core runservice.exe"Added by the IRCBOT.BK WORM!"
X Micosoft Data Core stuff svshosts.exe"Added by the RBOT.FZA WORM!"
X Micosoft Startup syscall.exe"Added by the SDBOT-JI WORM!"
X Micosoft Startup systall.exe"Added by the SDBOT-GM BACKDOOR!"
X Micr Update soundblaster.exe"Added by the SDBOT.NP WORM!"
X Micr Update System upwin.exe"Added by the SDBOT.YS WORM!"
X Micr0s0ft Ms D0s msdx.exe"Added by the RBOT-AON WORM!"
X Micr0s0ft Upd4t4z svchost32.exe"Added by the RBOT.ALF WORM!"
X Micrcoft Exploerer spoolsal.exe"Added by the RBOT-AKK WORM!"
X Micrcoft Exploerer svchose.exe"Added by the RBOT-ASL WORM!"
X Micrcoft Updat spoolsae.exe"Added by the RBOT-AIB WORM!"
X Micrcoft Updat spoolsaex.exe"Added by the RBOT-AJM WORM!"
X Micrcoft Updat Internet.exe"Added by the RBOT-ANA WORM!"
X Micrcsoft Certificate Services cflmon.exe"Added by the RBOT-FWV WORM!"
X Micro CRC Protocol scrc32.exe"Added by a variant of the SDBOT WORM!"
X Micro Office [path to trojan]"Added by the BANCBAN-QC TROJAN!"
X Micro Process appconf.exeAdded by an unidentified WORM or TROJAN!
X Micro Update dailin.exe"Added by the RBOT-ER WORM!"
N Microangelo Desktop Muamgr.exe"Using MicroAngelo On Display
N microAttuneDownload atmdlusr.exe"Application Launcher
U MicroBrew MicroBrew2.exe"Related to Bluebeam PDF printer support. Prints AutoCAD .dwgs to PDF's"
X MicroCQ0 explorer.exe"Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
U MicroDialler atdialler1.exe"Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered"
X MicroedSoft Toolbar Smoked.exe"Added by the RBOT-ALN WORM!"
X Microfinder lptt01 mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Microfinder ml097e mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Microfot Update winldx32.exe"Added by a variant of the RBOT WORM!"
X Microft Exploerer spoolsac.exe"Added by the RBOT-AMD WORM!"
X Microft Update 32 winssx.exe"Added by the RBOT-AQS WORM!"
X MicroLoad [random filename]"Added by the DARBY WORM!"
X Micromedia Flash Update wdfmrg.exe"Added by a variant of the SDBOT WORM!"
X Micromedia Flash Update xptxt.exe"Added by the RBOT-GAB WORM!"
X MicroMix32 WinCon.exe"Added by the VB-ECC TROJAN!"
X Microoft Timing pupdate.exe"Added by a variant of the RBOT WORM!"
X MICROSFT ANTIVIRUS UPDATE SUPPORT [random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
X MICROSFT ANTIVIRUS UPDATE SUPPORT MSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
X Microsft Conf 32 msaconf.exe"Added by the RBOT.EYA WORM!"
X Microsft Confige 32 msaconfigurez.exe"Added by the RBOT.CLC WORM!"
X Microsft Corporation Version 2001.12.4414 comrel.exe"Added by a variant of the SDBOT TROJAN!"
X Microsft Corporation Version 2002.12.2414 comserv.exe"Added by a variant of the SLAPER TROJAN!"
X MICROSFT MX UPDATE SUPPORT taskmngrs.exe"Added by the RBOT-AUZ WORM!"
X MICROSFT MX UPDATE SUPPORT winmx32.EXE"Added by the IRCBOT-FD WORM!"
X MICROSFT RAMA UPDATE SUPPORT [random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
X MICROSFT RAMA UPDATE SUPPORT MSN32.EXE"Added by the RBOT-AWJ WORM!"
X MICROSFT RAMA UPDATE SUPPORT mtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
X MICROSFT RAMA UPDATE SUPPORT MSGUPDAT32.EXE"Added by the RBOT-BBB WORM!"
X Microsft Remote Procedure Daemon msrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsft Security Monitor Process cmh.exe"Added by the EGGDROP.V WORM!"
X Microsft Security Monitor Process mssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsft Security Monitor Process mssmpp.exe"Added by the SDBOT-DJW WORM!"
X Microsft Updtes sarvice.exe"Added by a variant of the SDBOT WORM!"
X Microsft Upgraed [random filename].exe"Added by a variant of the SDBOT WORM!"
X Microsft Windows Adapter 5.1.3013 [random filename]"Added by the SMALL.HIT TROJAN!"
X microsft windows updates mwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
X Microsof Value nmatt.exe"Added by a variant of the RBOT WORM!"
X Microsof Windows Host svhost32.exe"Added by the RBOT.ADY WORM!"
X Microsof Winlog Host wilogon32.exe"Added by the RBOT.XC WORM!"
X Microsofot x386 System Monitor system32.exe"Added by the WOOTBOT.M WORM!"
X microsoft svchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X microsoft microsoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X Microsoft win32.exe"Added by the DARKMOON TROJAN!"
X Microsoft iexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Microsoft svchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Microsoft wuauclt.exe"Added by the QQROB-AAQ TROJAN! Note - this is not the legitimate wuauclt.exe process
X Microsoft guard.exe"Added by a variant of the SDBOT WORM!"
X Microsoft wcsntfy.exe"Added by the AGOBOT-AHT WORM!"
X Microsoft ssmss.exe"Added by the RBOT-FZF WORM!"
X Microsoft lsass.ppf"Added by the RBOT-GAA WORM!"
X Microsoft msvchost.exe"Added by the RBOT-GAW WORM!"
X Microsoft mixers.exe"Added by the AGOBOT-AHU WORM!"
X Microsoft msmsger.exe"Added by a variant of the SDBOT WORM!"
X Microsoft MSUPDATE.exeAdded by an unidentified WORM or TROJAN!
X Microsoft radnom.exe"Added by the RBOT-GHO WORM!"
X Microsoft rtvcscan.exe"Added by the RBOT-GGU WORM!"
X Microsoft taskbar.exe"Added by a variant of the RBOT WORM!"
X Microsoft updater.exe"Added by the RBOT-GHP WORM!"
X Microsoft windl32.exe"Added by the SDBOT-DCZ WORM!"
X Microsoft aim.exe"Added by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility"
X Microsoft Explorerr.exe"Added by the IRCBOT-WG TROJAN!"
X Microsoft kasperskyLive32.exe"Added by the RBOT-GRT WORM!"
X Microsoft msngerf.exe"Added by the RBOT-GLW WORM!"
X Microsoft netsrv.exe"Added by the RBOT-GOS WORM!"
X Microsoft rundll.exe"Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X Microsoft WinSecUp.exe"Added by the RBOT-GPL WORM!"
X Microsoft wsim32.exe"Added by the RBOT-GTL WORM!"
X Microsoft wplayer.exe"Added by the IRCBOT-ABP TROJAN!"
X Microsoft mdms.exe"Added by the AGENT-GHY TROJAN!"
X Microsoft Explorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft install.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft internetdat.exe"Added by the RBOT.ETY BACKDOOR!"
X Microsoft ntsvr.exe"Added by a variant of the RBOT WORM!"
X Microsoft schost.exe"Added by the RBOT.FEH BACKDOOR!"
X Microsoft soundvol32.exe"Added by the RBOT.CIJ BACKDOOR!"
X Microsoft sqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list