Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft Update Control Ms64.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Debugger wincfg32.exe"Added by the SPYBOT.ZC WORM!"
X Microsoft Update Device flolo.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Update Device Drivers wuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
X Microsoft Update DLL rxxhost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Drivers explorers.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Update Emulator kern-mxe.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Emulator wuaddsff.exe"Added by the RBOT-GX WORM!"
X Microsoft Update Event svnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
X Microsoft Update Loader [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft Update Loaders 2005 winusers.exe"Added by the RBOT-AIQ WORM!"
X Microsoft Update Loaders 2006 winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Update Machine expl0rer.exe"Added by the SDBOT.OK WORM!"
X Microsoft Update Machine rxhost.exe"Added by the RBOT.FC WORM!"
X Microsoft Update Machine servicz.exe"Added by the RBOT-HU WORM!"
X Microsoft Update Machine SP2.exe"Added by the SPYBOT.FP WORM!"
X Microsoft Update Machine winini.exe"Added by the RBOT-KV WORM!"
X Microsoft Update Machine xvshost.exe"Added by the RBOT.QP WORM!"
X Microsoft Update Machine memstat.exe"Added by the RBOT-OM WORM!"
X Microsoft Update Machine ntce.exe"Added by the RBOT-FA WORM!"
X Microsoft Update Machine system03.exe"Added by the RBOT-NM WORM!"
X Microsoft Update Machine wuawx.exe"Added by the RBOT-CE WORM!"
X Microsoft Update Machine zonealarm.exe"Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
X Microsoft Update Machine systemll.exe"Added by the RBOT-JT WORM!"
X Microsoft Update Machine winupdt.exe"Added by the RBOT-FP WORM!"
X Microsoft Update Machine svshost.exe"Added by the RBOT.AK WORM!"
X Microsoft Update Machine wuamgd.exe"Added by the SDBOT.HQ WORM!"
X Microsoft Update Machine wupdt32x.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Update Machine [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine linux.exe"Added by the RBOT-IM WORM!"
X Microsoft Update Machine lmrss.exe"Added by the RBOT-DY WORM!"
X Microsoft Update Machine windowsu.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine wininigo.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine winmgr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine Winmsixp32.exe"Added by the RBOT.DN WORM!"
X Microsoft Update Machine Winregs32.exe"Added by the RBOT.DN WORM!"
X Microsoft Update Machine winxpini.exe"Added by the RBOT-OB WORM!"
X Microsoft Update Machine wuamgrd.exe"Added by the RBOT-HE WORM!"
X Microsoft Update Machine wuagrd.exe"Added by the RBOT-GF WORM!"
X Microsoft Update Machine LANWAKE.EXE"Added by the RBOT-QZ WORM!"
X Microsoft Update Machine scvhost.exe"Added by the RBOT-GS WORM!"
X Microsoft Update Machine winhost.exe"Added by the RBOT-GK WORM!"
X Microsoft Update Machine winss.exe"Added by the RBOT.JU WORM!"
X Microsoft Update Machine WUAMGRDXS.EXE"Added by the RBOT-GL WORM!"
X Microsoft Update Machine crss32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine lsasse.exe"Added by the RBOT-DI WORM!"
X Microsoft Update Machine qwerty.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine rxxhost.exe"Added by the RBOT.EP WORM!"
X Microsoft Update Machine servicez.exe"Added by the SPYBOT.BI WORM!"
X Microsoft Update Machine spoolserv.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine Systemnt.exe"Added by the RBOT.DA WORM!"
X Microsoft Update Machine systemse.exe"Added by the RBOT-BD WORM!"
X Microsoft Update Machine taskmngrs.exe"Added by the RBOT-CR WORM!"
X Microsoft Update Machine windowsup.exe"Added by the RBOT-FV WORM!"
X Microsoft Update Machine wuamgard.exe"Added by the SPYBOT.CS WORM!"
X Microsoft Update Machine wupdate32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine system.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine TMEMSER.EXE"Added by the RBOT-NQ WORM!"
X Microsoft Update Machine winnie.exe"Added by the RBOT-ACD WORM!"
X Microsoft Update Machine winortho.exe"Added by the RBOT-NW WORM!"
X Microsoft Update Machine wins32.exe"Added by the RBOT.EZ WORM!"
X Microsoft Update Machine serviz.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine TASKMAN4.EXE"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine wftestb.exe"Added by the RBOT-AFZ WORM!"
X Microsoft Update Machine Win32.exe"Added by the SDBOT.UV WORM!"
X Microsoft Update Machine windns.exe"Added by the RBOT.EF WORM!"
X Microsoft Update Machine MSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
X Microsoft Update Machine WINSVC32.EXE"Added by the RBOT.CU WORM!"
X Microsoft Update Machine ntsystem.exe"Added by the RBOT.GF WORM!"
X Microsoft Update Machine winupdte.exe"Added by the RBOT-GKL WORM!"
X Microsoft Update Machine jkfrnz.exe"Added by the RBOT-GOZ WORM!"
X Microsoft Update Machine wlimyc.exe"Added by the RBOT-GQN WORM!"
X Microsoft Update Machine xagwxzy.exe"Added by the RBOT.S WORM!"
X Microsoft Update Machine jkydxg.exe"Added by the RBOT.AEA BACKDOOR!"
X Microsoft Update Machine opmmve.exe"Added by the KOLABC.DES WORM!"
X Microsoft Update Machine paxrxo.exe"Added by the PUSHBOT.A WORM!"
X Microsoft Update Machine psmszw.exe"Added by the KOLABC.CC WORM!"
X Microsoft Update Machine syadpo.exe"Added by the CIADOOR.GN BACKDOOR!"
X Microsoft Update Machine systemi.exe"Added by the BUZUS.JKU TROJAN!"
X Microsoft Update Machine thvfyq.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Machine ubthec.exe"Added by the AGENT.AWZ TROJAN!"
X Microsoft Update Machine winmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
X Microsoft Update Machine gbhglj.exe"Added by the IRCBOT-ZJ TROJAN!"
X Microsoft Update Machine wuamgdr.exe"Added by the RBOT-IO BACKDOOR!"
X Microsoft Update Manager WINRLS.EXE"Added by the RBOT-AF WORM!"
X Microsoft Update Manager svshost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Manager scvhost.exe"Added by the AGOBOT.AXJ WORM!"
X Microsoft Update Manager scvideo.exe"Added by the SDBOT-CVP TROJAN!"
X Microsoft Update Mechene Updatez.exe"Added by the RBOT-GI WORM!"
X Microsoft Update Module rundll24.exe"Added by the RBOT-PS WORM!"
X Microsoft Update Process wmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
X Microsoft Update Security Patch mssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
X Microsoft Update Server mssrv.exe"Added by an unidentified VIRUS
X Microsoft Update Service csrss32.exe"Added by the AGOBOT-HC WORM!"
X Microsoft Update Service mswin32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft update service systemm.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Update SERVICE phqghum.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Service msupdate.pif"Added by the RBOT-AQB WORM!"
X Microsoft Update Service wmiprvre.exe"Added by the AGOBOT-NN WORM!"
X Microsoft Update Services wcsnfty.exe"Added by the RBOT-AGK WORM!"
X Microsoft Update Services wsnfty.exe"Added by the RBOT-AFU WORM!"
X Microsoft Update Time wuam.exe"Added by the RBOT-M WORM!"
X Microsoft Update USB2 wuammgrd32.exe"Added by the RBOT-ADT WORM!"
X Microsoft Update v2.6 lxxex.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Win32a winupdate32a.exe"Added by the RBOT-LO WORM!"
X Microsoft Update Win32x winupdate32x.exe"Added by the RBOT-AJN WORM!"
X Microsoft Update32 wuamgrd32.exe"Added by the RBOT-PU WORM!"
X Microsoft Updater winsys32.exe"Added by the RBOT.RL WORM!"
X Microsoft Updater msconsole.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Updater svhost.exe"Added by the AGENT.CDF TROJAN!"
X Microsoft Updater vbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Updater wuamgrds.exe"Added by the RBOT.A WORM!"
X Microsoft Updater winupdate.exe"Added by the AGENT-KIR TROJAN!"
X Microsoft Updater Resources WinFixd32.exe"Added by the SPYBOT.CA WORM!"
X Microsoft Updater v2 [path to worm]"Added by the AUTORUN-BCI WORM!"
X Microsoft UPDATER32 lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
X Microsoft UPDATER32 LSASS32.EXE"Added by the RANDEX.AR WORM!"
X Microsoft Updaters tskmgr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updaters sysconfigs.exe"Added by the RBOT-DF TROJAN!"
X Microsoft Updaters Pros WINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
X Microsoft Updates systemc32.exe"Added by the RBOT-GR WORM!"
X Microsoft Updates wkssvr.exe"Added by the RBOT.R WORM!"
X Microsoft Updates wkssvrs.exe"Added by the RBOT-EB WORM!"
X Microsoft Updates wuamgrd.exe"Added by the RBOT-CO WORM!"
X Microsoft Updates wtemp32.exe"Added by the RBOT-AHQ WORM!"
X Microsoft Updates svehost.exe"Added by the RBOT-GRW WORM!"
X Microsoft Updates svshost.exe"Added by the AGOBOT-AIW WORM!"
X Microsoft Updates svdhost.exe"Added by the RBOT-GVH WORM!"
X Microsoft Updates service.exe"Added by the POISON.HPT BACKDOOR!"
X Microsoft Updates [worm filename]"Added by the AGOBOT-AIZ WORM!"
X Microsoft Updates wgcptsud.exe"Added by the RBOT-GTF WORM!"
X Microsoft Updates winit.exe"Added by the SDBOT-CSB WORM!"
X Microsoft Updates 2 USB wgafixer.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updates 5 USB sp3fixer.exe"Added by the RBOT-ADS WORM!"
X Microsoft UpdateS Machine wgrd.exe"Added by the RBOT-FI WORM!"
X Microsoft Updates Resources WinFixIDs.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updating navguard.exe"Added by the RBOT.HW WORM!"
X Microsoft Updating syswr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updating wuamguards.exe"Added by the RBOT-BY WORM!"
X Microsoft Updating Client websvc.exe"Added by the RBOT.AQ WORM!"
X Microsoft Updating Machine sysc0de.exe"Added by the RBOT.RB WORM!"
X Microsoft Updatting miroupdate.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updote [random filename]"Added by the RBOT-ARC WORM!"
X Microsoft UpMachine doezs.exe"Added by the RBOT.BCT WORM!"
X Microsoft upnp Update msie.exe"Added by the RBOT-LQ WORM!"
X Microsoft uptime Service sysuptime.exe"Added by the RBOT-ACG WORM!"
X Microsoft uptime Service sycuptime.exe"Added by the RBOT-AHY WORM!"
X Microsoft UpToDate Driver (32-bits) [random filename].exe"Added by the SPYBOT.LXJ WORM!"
X Microsoft Urlmon urlmon.exe"Added by the AGENT-GOO TROJAN!"
X Microsoft USA Plug usaplug.exe"Added by the RBOT-DVC WORM!"
X Microsoft USB Windows2 Driver usbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
X Microsoft USB2 Driver crmss.exe"Added by the RBOT-VK WORM!"
X Microsoft usnsvc Service usnsvc.exe"Added by a variant of the KOBOT-C WORM!"
N Microsoft Utility Startup OSA9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
X Microsoft Values igfkishc.exe"Added by the RBOT-GLO WORM!"
X Microsoft Vertupdate MSvert32.exe"Added by the MYTOB-CY WORM!"
X Microsoft Video Capture Controls MSsrvs32.exe"Added by the SDBOT-AAK WORM!"
X Microsoft Video Controls tskmsgr.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Video Driver videodrv.exe"Added by the SDBOT-AGP WORM!"
X Microsoft Viewer Monitor Manager viewmon.exe"Added by the XPAK.A TROJAN!"
X Microsoft Virtual Service Manager vservice32.exe"Added by the MSNWORM.T WORM!"
X Microsoft Virual Machine sms.exe"Added by the RBOT-SP WORM!"
X Microsoft Vista Upgrade Validation Service cfmon.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Visual Application vpcrtf.exe"Added by the IRCBOT-XJ TROJAN!"
X Microsoft Visual Debuger mdm.exe"Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
X Microsoft Visual SourceSafe services.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X Microsoft Visual SourceSafe winlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X MicroSoft Visual SP igxdfdfds.com"Added by the SDBOT.GAV WORM!"
X MicroSoft Visual SP2 igfxsrvc32.exe"Added by the SDBOT.GAV WORM!"
X Microsoft Visual Studio plscdksxg.exe"Added by the RBOT-AWV WORM!"
X Microsoft Visual Studio VSA varpc32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Web CP Manager webcp32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Web Device wdevice.exe"Added by a variant of the SDBOT WORM!"
X Microsoft web update webmsn.exe"Added by the RBOT-EMQ WORM!"
U Microsoft Webserver svctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
X Microsoft Win Corp TLS Verification mswintls.exe"Added by the RBOT-GCT WORM!"
X Microsoft Win Update WinUP.exe"Added by the RBOT-BPR WORM!"
X Microsoft WIN32 DOS MSdos32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft WIN32 Security MSsec32.exe"Added by the RBOT-DOQ TROJAN!"
X MicroSoft Wind0ws Updater winsupdater.exe"Added by a variant of the RBOT WORM!"
X MicroSoft Window Updater winsupdater.exe"Added by the RBOT-ZZ WORM!"
X Microsoft Windows mstask0.exe"Added by the SDBOT.FQ WORM!"
X Microsoft Windows atup"Added by a variant of the RBOT WORM!"
X Microsoft Windows Microsoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X Microsoft Windows explorar.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows [path to file]"Added by the BDOOR-LI BACKDOOR!"
X Microsoft Windows bootini.exe"Added by the VANEBOT-K WORM!"
X Microsoft Windows Kernel.exe"Added by the EDIBARA-A VIRUS!"
X Microsoft Windows Kernel.vbs"Added by the EDIBARA-A VIRUS!"
X Microsoft Windows pwjbvphi.exe"Added by the RBOT-GQK WORM!"
X Microsoft Windows windets.com"Added by the FLOOD-EQ TROJAN!"
X Microsoft Windows (D) iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
X Microsoft Windows 128bit Subsystem system12.exe"Added by the RANCK-CZ TROJAN!"
X Microsoft Windows 16Bit mswinn16.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Windows 2000 Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
X Microsoft Windows 32 Update win32update.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Windows 32Bit mswinn32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows 64 Bit mswin32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Adapter 5.1.3214 [worm filename].exe"Added by the STRAT.GEN-3 WORM!"
X Microsoft Windows Autowxckn autowxckn.exe"Added by the RBOT.DYZ BACKDOOR!"
X Microsoft Windows Client Firewall msclt.exe"Added by the VANEBOT-F WORM!"
X Microsoft Windows Communicator for NT/XP wincomm.exe"Added by the RBOT.ATH WORM!"
X Microsoft Windows Config 32 win32conf.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Control mswctl32.exe"Added by the RBOT.JP WORM!"
X Microsoft Windows CSRSS csrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
N Microsoft Windows Desktop Search System Tray WindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
N Microsoft Windows Desktop Search Tool Tray Admin WindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
X Microsoft Windows DHCP ___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
X Microsoft Windows DLL 32-BIT msncheck32.exe"Added by the SDBOT-XX WORM!"
X Microsoft Windows DLL Services mwindll.exe"Added by the SDBOT-VX WORM!"
X Microsoft Windows DLL Services Configuration newdll.exe"Added by the SDBOT-ZR WORM!"
X Microsoft Windows DLL Services Configuration newdll2.exe"Added by the SDBOT-ABD WORM!"
X Microsoft Windows DLL Services Configuration poker.exe"Added by the SDBOT-ZY WORM!"
X Microsoft Windows DLL Services Configuration poker3.exe"Added by the SDBOT-AAH WORM!"
X Microsoft Windows DLL Services Configuration proxy.exe"Added by the SDBOT-ZL WORM!"
X Microsoft Windows DLL Services Configuration windir32.exe"Added by the SDBOT.BHF WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list