Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft svhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft winampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft winline.exe"Added by the AGENT.KT TROJAN!"
X Microsoft system32.exe"Added by the IRCBOT-ZZ WORM!"
X Microsoft winsys32.exe"Added by the RBOT-GSQ WORM!"
X Microsoft winnn.exe"Added by the RANDEX.GGP WORM!"
X Microsoft symtea.exe"Added by the SPYBOT.AMTE WORM!"
X Microsoft MicrosoftCorporation.exe"Added by the KILLFILES.AED TROJAN!"
X Microsoft firefox.exe"Added by the RBOT-GVJ TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
X Microsoft (C) HTML Application host [random filename]"Added by the RBOT-YB WORM!"
X Microsoft (R) Windows Configuration Backup Service svchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
X Microsoft (R) Windows DLL Loader rundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
X Microsoft (R) Windows Network Latency Controller 1.tmp"Added by a generic password stealer TROJAN - see here"
X Microsoft (R) Windows Network Latency Controller nlc.exe"Added by a generic password stealer TROJAN - see here"
X Microsoft (R) Windows Network Latency Controller sp2vc.exe"Added by a generic password stealer TROJAN - see here"
X Microsoft (R) Windows Network Security Management Service nsms.exe"Added by the RANKY.LC TROJAN!"
X Microsoft (R) Windows Protected Content Restoration Service services.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
X Microsoft (R) Windows Protocol Deployment Manager [random].tmpAdded by an unidentified WORM or TROJAN!
X Microsoft (R) Windows TCP/IP Socket Driver [path to trojan]"Added by the PROXY-DD TROJAN!"
X Microsoft (R) Windows TCP/IP Socket Layer services.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
X Microsoft (R) Windows Update Service wuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
X Microsoft (R) Windows Vista/NT Runtime Compatibility Service nrcs.exe"Added by the RANKY.X TROJAN!"
X Microsoft .NET Confingurator msnconf.exe"Added by an unidentified VIRUS
X Microsoft 16Bit Update wuapdate16.exe"Added by the RBOT.CZ WORM!"
X Microsoft 64 Bit Runtime Updater wupdt64.exe"Added by a variant of the RBOT WORM!"
U Microsoft ActiveSync WCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
X Microsoft ActiveX Debugger NT [path to trojan]"Added by the BANCOS-DO TROJAN!"
X Microsoft Admin Protocal MSADNIN.exe"Added by a variant of the RBOT WORM!"
X Microsoft ADservice [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft Agent mdss32.exe"Added by the KEYLOG-AG TROJAN!"
X Microsoft Agent svch0st.exe"Added by the VB-DRO WORM!"
X Microsoft ALG32 Protocol alg32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft ALGXP Protocol alg32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft all mmall.exeWopla.ac malware variant
N Microsoft Announcement Listener Annclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X Microsoft Ansti Update msie.exe"Added by the RBOT-LE WORM!"
X Microsoft Anti Virus Controller msavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Anti Virus Controller msavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
X Microsoft Anti-Spy [random filename]"Added by a variant of the SDBOT WORM!"
X Microsoft AntiSpyware Bazzi.exe"Added by the AHKER.J WORM!"
X Microsoft AntiSpyware KT06.pif"Added by the IRCBOT.GEN WORM!"
X Microsoft AOL Instant Messenger MSAOL32.exe"Added by the RBOT-AAI WORM!"
X Microsoft AOL32 Protocol aol32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Application Center mappc.exe"Added by a variant of the RBOT WORM!"
X Microsoft Application Manager msapl32.exe"Added by the BROPIA-AE TROJAN!"
X Microsoft AUT Update MSlti32.exe"Added by the RBOT-X WORM!"
X Microsoft AUT Update MSlti16.exe"Added by the RBOT.EB WORM!"
X Microsoft Authority Service lsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
X Microsoft auto update winupdate.exe"Added by the BMBOT TROJAN!"
X Microsoft Auto Update WINHLP16.EXE"Added by the RBOT.GY WORM!"
X Microsoft auto update wuauclt.exe"Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process
X Microsoft Automatic Update Serivce msautou.exe"Added by the RBOT-AOB WORM!"
X Microsoft Automatic Updater Explorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft AutoUpdater svhost.exe"Added by the RBOT.QG WORM!"
X Microsoft Bool Value MV2.exe"Added by a variant of the RBOT WORM!"
X Microsoft boot system cfg32 actboost.exe"Added by the BROPIA.R WORM!"
U Microsoft Broadband Networking MSBNTray.exeMicrosoft Broadband Networking Tray Application
X Microsoft Browser Services Brwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Browser Services Brwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Buffer App msbuffer.exe"Added by the SLINBOT.NQ BACKDOOR!"
X Microsoft Cab Manager exec.exe"Affilred adware"
X Microsoft Cab Manager cab.exe"Added by the DELF-JJ TROJAN!"
X Microsoft Calculator calc.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft checker MsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Client mshost.exe"Added by the RBOT-AND WORM!"
X Microsoft Client msclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Client Pc spoolsrv.exe"Added by the RBOT-AQM WORM!"
X Microsoft Client/Server Runtime Server Subsystem csrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Client/Server Runtime Server Subsystem csrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Com Port Manager svdhost.exe"Added by the SDBOT-NI WORM!"
X Microsoft Command C sshost.exe"Added by the RBOT-CMK WORM!"
X Microsoft Command C winhost32.exe"Added by the SDBOT-BBA WORM!"
X Microsoft Command Line wincmd.exe"Added by a variant of the RBOT WORM!"
X Microsoft Conf Ldr sysconf.exe"Added by a variant of the SDBOT TROJAN!"
X Microsoft ConfgKeys wurmgrd32.exe"Added by the RBOT-ARX WORM!"
X Microsoft Config msconf.exe"Added by the RBOT.PV WORM!"
X Microsoft Config MSCONF.EXE"Added by the RBOT-LG WORM!"
X Microsoft Config 32 msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
X Microsoft Config 32bit mscnfg32.exe"Added by the RBOT-Z WORM!"
X Microsoft Config File config.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
X Microsoft Config Loader msconfig32.exe"Added by the AGOBOT.XX WORM!"
X Microsoft Config Loader msrun32.exe"Added by the AGOBOT-DY WORM!"
X Microsoft Config Loader msconf32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Configoration Service msconfigs.exe"Added by the RBOT-ETT WORM!"
X Microsoft Configs 32 msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Configuewe msconfiguwe.exe"Added by the SDBOT-BPK WORM!"
X Microsoft Configuration msconfig32.exe"Added by the SDBOT.MQ WORM!"
X Microsoft Configuration 35 microsot1.exe"Added by an unidentified TROJAN!"
X Microsoft Configuration Wizard taskmrg.exe"Added by the SDBOT-MX TROJAN!"
X Microsoft Configure 32 msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Connection Manager Monitor cmmon.pif"Added by the RBOT-AKV WORM!"
X Microsoft Control Center crtl.exe"Added by the RBOT-VX WORM!"
X Microsoft Core Support MSxUP32.exe"Added by the RBOT-ANR WORM!"
X Microsoft Core Support [random filename]"Added by a variant of the RBOT TROJAN!"
X Microsoft Corp svchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Microsoft Corp SQL Certificates sqlcer.exe"Added by the ZYBOT-C WORM!"
X Microsoft Corp SSL Certificates windowz.exe"Added by the RBOT-GCZ WORM!"
X Microsoft Corp TLS Certificates msauth.exe"Added by the RBOT-GAC WORM!"
X Microsoft Corp Updates wupdates.exe"Added by the RBOT-AUU WORM!"
X Microsoft Corp. Host Services svchosl.exe"Added by the RBOT-FMZ WORM!"
X Microsoft Corporaticn SQL Handler sqlhandler.exe"Added by a variant of the RBOT WORM!"
X Microsoft Corporation [random filename]"Added by various VIRUSES
X Microsoft Corporation jview.exe"Added by the RBOT-AOD WORM!"
X Microsoft Corporation Svchost Service mssvc.exe"Added by a variant of the SDBOT WORM! See here"
X Microsoft Corporation Svchost Service mswsc.exeAdded by the AGENT.MAB TROJAN!
X Microsoft Corporation SYM monitor mssym.exe"Added by the RBOT-GDB WORM!"
X Microsoft CP Web Manager webcp.exe"Added by the IRCBOT.HP TROJAN!"
X Microsoft CPU Over Heat Manager CPU.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft CPXP Protocol cpxp.exe"Added by the RBOT.ATP WORM!"
X Microsoft Critical Services svhhost.exe"Added by the AGOBOT-AJA WORM!"
X Microsoft Crs Fix Serv wincrs.exe"Added by the SDBOT.BWF WORM!"
X Microsoft CRT Monitor Manager crtmon.exe"Added by the ROBOTON.A WORM!"
X Microsoft CSRSS Service nsmscrs.exe"Added by the RBOT-BPT WORM!"
X Microsoft CSRSS32 Protocol csrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft CSRSS386 Protocol csrss386.exe"Added by a variant of the SPYBOT WORM!"
U Microsoft CTF Loader ctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
X Microsoft Cvrt mscvrt32.exe"Added by an unidentified VIRUS
X Microsoft Data Helper cihost.exe"Malware
X Microsoft Data Machine csdata32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Database Handler mssql32.exe"Added by the RANDEX.AX WORM!"
X Microsoft Datalog Application msdata.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DDE Control wupades.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DDEs Control Erun.pif"Added by the RBOT-AMU WORM!"
X Microsoft Debug Manager Console mdm32.exe"Added by the AGOBOT-AQ WORM!"
X Microsoft Debug Service dbgbgr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Decryption Technology Msfenoe.exe"Added by the SPYBOT-DG WORM!"
U Microsoft Default Manager DefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
X Microsoft Desktop Manager msdesk32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Dev iexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Development Debugger msdev.exe"Added by a variant of the RBOT WORM!"
X Microsoft Development Services msdevelop.exe"Added by the RBOT-FWS WORM!"
X Microsoft Device Manager msdevmgr32.exe"Added by the LATEDA.B TROJAN!"
X Microsoft Device Manager mscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
X Microsoft Device Manager svcswin.exe"Added by the IRCBOT-YH TROJAN!"
X Microsoft Diagnostic [random filename]"Added by the ACEBOT TROJAN!"
X Microsoft Diagnostic msdiag32.exe"Added by the RBOT-UC WORM!"
X Microsoft Digital Clock msclock.exe"Added by the NACKBOT-D WORM!"
X Microsoft Digital Cryptors mdigits.exe"Added by the SDBOT.LM WORM!"
X Microsoft DirectX Spoolserv.exe"Added by the DINFOR WORM!"
X Microsoft DirectX rasmngr.exe"Added by a variant of the RBOT WORM!"
X Microsoft DirectX PDSched.exe"Added by the SDBOT.CN WORM!"
X Microsoft DirectX wuamgrd.exe"Added by the SDBOT.MY WORM!"
X Microsoft DirectX time123.exe"Added by the SDBOT.MD WORM!"
X Microsoft Directx directxat.exe"Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
X Microsoft DirectX wupdate.exe"Added by the RBOT-L WORM!"
X Microsoft Directx click directxclick.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft Directx clicks directxclickers.exe"Added by the RBOT-GHT WORM!"
X Microsoft Directx push directxpushup.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft Directxsp directxbt.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft Directxspnew directxnew.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft DirktorWin [random filename]"Added by the SPYBOT.GEN3 TROJAN!"
X Microsoft Disk Scanner scansdisk.exe"Added by the WOOTBOT.DT WORM!"
X Microsoft DLL fumeta.exe"Added by the RBOT-AUG WORM!"
X Microsoft Dll runapidll.exe"Added by the RBOT-GRG WORM!"
X Microsoft DLL Authentification dllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Extensions SystemDll.exe"Added by the RBOT-ADV WORM!"
X Microsoft dll Host Service wkssr.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DLL Host Service dllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Host Service svcdllhst.exe"Added by the AGENT.EAK TROJAN!"
X Microsoft dll Host Service svchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Microsoft DLL Library winlib32.exe"Added by the ATNAS.A WORM!"
X Microsoft Dll Management windll.exe"Added by the RBOT-MT WORM!"
X Microsoft Dll Manager microsoft32dll.exe"Added by the SHEUR.LH TROJAN!"
X Microsoft DLL Manager dllmgr.exe"Added by the SDBOT-KJ WORM!"
X Microsoft DLL Monitor dllmon32.exe"Added by the AGENT.WP WORM!"
X Microsoft DLL Monitor dllmon64.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Monitor dllmonitor.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Dll Printer Manager dllpt.exe"Added by the SDBOT.BIH WORM!"
X Microsoft DLL Service servicedll.exe"Added by the IRCBOT.OX BACKDOOR!"
X Microsoft DLL Service svcdll.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft DLL Source dllsrc.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Verifier file.exe"Added by the RBOT-AED WORM!"
X Microsoft DLL Verifier chkfile.exe"Added by the RBOT-AOC WORM!"
X Microsoft DLL Verifier csrssv.exe"Added by the RBOT-ATK WORM!"
X Microsoft DLL Verifier mscon.exe"Added by the SDBOT.EAH WORM!"
X Microsoft DLL Verifier winavguard.exeAdded by the SDBOT.AAD WORM!
X Microsoft DLL Verifier wns.exe"Added by the SPYBOT-LA WORM!"
X Microsoft DLLSet32 dllset32.exe"Added by the RBOT.OZ WORM!"
X Microsoft DNS Host Resolution hostres.exe"Added by the AGOBOT-MK BACKDOOR!"
X Microsoft DNS Query msdns.exe"Added by the AGENT-BS TROJAN!"
X Microsoft DNSx mdnex.exe"Added by the DELBOT-AI WORM!"
X Microsoft Document krisp.exe"Added by the SDBOT-RQ WORM!"
X Microsoft Domain Controller mstc.exe"Added by the NUGACHE.A WORM!"
X Microsoft Driver faet.exe"Added by a variant of the RBOT WORM!"
X Microsoft Driver Control windrv.exe"Added by the SDBOT.FW WORM!"
X Microsoft Driver Manager mswindrv.exe"Added by the FORBOT-EZ WORM!"
X Microsoft Driver Setup msddrv42.exe"Added by the PALEVO WORM!"
X Microsoft Driver Setup Jwrb.exe"Added by the AUTORUN-AOB WORM!"
X Microsoft Driver Setup dllhost.exe"Added by the AUTORUN-AOZ WORM!"
X Microsoft Driver Setup sysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
X Microsoft Driver Setup w7services.exe"Added by the AUTORUN-ARJ WORM!"
X Microsoft Driver Setup mslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
X Microsoft Driver Setup ccdrive32.exe"Added by the AGENT-LYL TROJAN!"
X Microsoft Driver Setup cidrive32.exe"Added by the AGENT-NES TROJAN!"
X Microsoft driver update Mshome.exeAdded by the SDBOT.BL WORM!
X Microsoft Drivers WSconf.exe"Added by a variant of the SDBOT WORM!"
X Microsoft ErgoPack wserb32.exe"Added by the RBOT-RI WORM!"
X Microsoft EV32 Service MSev32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Event Engine EvtEngn.exe"Added by the RBOT-XV WORM!"
X Microsoft Excel msexcel.exe"Added by the RBOT-TQ WORM!"
X Microsoft Excele msmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
X Microsoft Excell wuamngr32.exe"Added by the RBOT-QH WORM!"
X Microsoft Executing microsoft.exe"Added by the AGOBOT.UV WORM!"
X Microsoft Explorer svapache.exe"Added by the RBOT-VR WORM!"
X Microsoft Explorer explorer.scr"Added by the RBOT-ADH WORM!"
X Microsoft Explorer explorer.pif"Added by the SDBOT-ACX WORM!"
X Microsoft Explorer explorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft Explorer Service msexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
X Microsoft explorer Update internal.exeAdded by an unidentified WORM or TROJAN!
X Microsoft Explorer(64) explorer64.exe"Added by the SPYBOT-R WORM!"
X Microsoft Explorer2 system.exe"Added by the IRCBOT.BS TROJAN!"
X Microsoft Explorer2 nome.exe"Added by the RANDEX.AA WORM!"
X Microsoft Explorer2 bitchbot.exe"Added by the SDBOT.EV WORM!"
X Microsoft EXPLOREXP Protocol explorexp.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Features ms32cfg.exe"Added by the RBOT.HO WORM!"
X Microsoft Features msie.exe"Added by a variant of the RBOT WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list