Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft Windows DLL Services Configuration windir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
X Microsoft Windows DLL Services Configuration windll32.exe"Added by the SDBOT.BHD WORM!"
X Microsoft Windows DLL Services Configuration winDSL.exe"Added by the SDBOT-ZG WORM!"
X Microsoft Windows DLL Services Configuration dllmanager32.exe"Added by the SDBOT-BTU WORM!"
X Microsoft Windows DLLHandler bitpaint.exe"Added by the SDBOT.AHG WORM!"
X Microsoft Windows Drivers windrv.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows DVR windvr.exe"Added by the RBOT-AXD WORM!"
X Microsoft Windows Expl0rer expl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Windows Explorer iexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Microsoft Windows Explorer explorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
X Microsoft Windows Express Microsoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Windows Express websploit.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Windows Express windowslogonb.exe"Added by the SDBOT.ABOO WORM!"
X Microsoft Windows Files Loader cgy32win.exe"Added by the RBOT-AXR WORM!"
X Microsoft Windows Game Updater msgame32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows GUI Windowz.exe"Added by the RANDEX.AEV WORM!"
X Microsoft Windows GUI msmonk32.exe"Added by the SDBOT-PE WORM!"
X Microsoft Windows Kernel Services winkrnl386.exe"Added by the ZEBROXY TROJAN!"
X Microsoft Windows Keyboard service keyboard.exe"Added by the RBOT-CRF WORM!"
X Microsoft Windows Loader wloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Windows Logon Process winlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Microsoft Windows Media Player mediaplayer.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Media Player wimp.exe"Added by the RBOT-FN WORM!"
U Microsoft Windows Media Player Network Sharing Service Configuration Application WMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
X Microsoft Windows Registry Service wregistry.exe"Added by the AGOBOT.AKG WORM!"
N Microsoft Windows Search System Tray WindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
X Microsoft Windows Secure windocs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Secure windocs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Secure Server rpcxWindows.exe"Added by the RBOT-LL WORM!"
X Microsoft Windows Secure Update rpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
X Microsoft Windows Securety wurguar.exe"Added by the RBOT-KY WORM!"
X Microsoft Windows Security spvsper.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Security wscndrives.exe"Added by the RBOT-AJK WORM!"
X Microsoft Windows Service winsys.exe"Added by the RBOT-ADP WORM!"
X Microsoft Windows Service Pack winspkn.exe"Added by the RBOT-AYD WORM!"
X Microsoft Windows Services msw32.exe"Added by the RBOT-FWQ WORM!"
X Microsoft Windows Services Sersices.exe"Added by the SDBOT-NO WORM!"
X Microsoft Windows Services Edt ssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
X Microsoft Windows Services Edt dllrun32.exe"Added by the RBOT-GAF WORM!"
X Microsoft Windows Session Manager Subsystem smss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
U Microsoft Windows Sidebar Sidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
X Microsoft Windows Socketx32 Services winsockx32.exe"Added by the RBOT-FWT WORM!"
X Microsoft Windows Sound svghost.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Windows Sound svshost.exe"Added by the RBOT.RNE BACKDOOR!"
X Microsoft Windows Sound svuhost.exe"Added by the KOLAB.XC WORM!"
X Microsoft Windows Sound Drivers sounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
X Microsoft Windows Storage Machine Service winms.exe"Added by the RBOT-AHK WORM!"
X Microsoft Windows SVCHOST SVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X Microsoft Windows System srwhost.exe"Added by the RBOT-AWU WORM!"
X Microsoft Windows System syshost.exe"Added by the RBOT-ASW WORM!"
X Microsoft Windows System System.exe"Added by the VB.KV WORM!"
X Microsoft Windows System Kernel kernel32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Windows System Service Manager winsvc.exe"Added by the SPYBOT.LR WORM!"
X Microsoft Windows Task Management mstasks.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Task Manger Mstosk.exe"Added by the SDBOT-WW WORM!"
X Microsoft Windows Tasks Management taskmng.exe"Added by the RBOT-FXK WORM!"
X Microsoft Windows Updata scvhost.exe"Added by the RBOT.CEM BACKDOOR!"
X Microsoft Windows Updata windows.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Updata [5 random letters].exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Update rundlls.exe"Added by the HABRACK WORM!"
X Microsoft Windows Update msoffice2.exe"Added by the RBOT-GB WORM!"
X Microsoft Windows Update spools.exe"Added by the SDBOT.TD WORM!"
X Microsoft Windows Update svchos.exe"Added by the SDBOT.AC WORM!"
X Microsoft Windows Update svcshost.exe"Added by the FORBOT-CF WORM!"
X Microsoft Windows Update svmhost.exe"Added by the FORBOT-CH WORM!"
X Microsoft Windows Update svshost.exe"Added by the WOOTBOT.CJ WORM!"
X Microsoft Windows Update msnmessenger.exe"Added by the SDBOT.AJ WORM!"
X Microsoft Windows Update msnwun.exe"Added by the SDBOT-RM WORM!"
X Microsoft Windows Update scvvhost.exe"Added by the FORBOT-DH WORM!"
X Microsoft Windows Update swwhost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Update MSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
X Microsoft Windows Update svzhost.exe"Added by the FORBOT-EV WORM!"
X Microsoft Windows Update sccvhost.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Update scrhost.exe"Added by the RBOT-AOW WORM!"
X Microsoft Windows Update mnswinsx.exe"Added by the RBOT-AWH WORM!"
X MICROSOFT Windows update pdate.exe"Added by the RBOT.BZT WORM!"
X Microsoft Windows Update srshost.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Update rhost32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Windows Update windowsupdate.exe"Added by the AGOBOT.ON WORM!"
X Microsoft Windows Update servcs.exe"Added by the SDBOT.AL BACKDOOR!"
X Microsoft Windows Update syssinfos.exe"Added by the RBOT-FWR WORM!"
X Microsoft Windows Update Application wuap.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Update Client csrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
X Microsoft Windows Update Client services.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Microsoft Windows Update Logon win-logon.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Update Service wupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
X Microsoft Windows Update Service msnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Windows Update x86 [various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
X Microsoft Windows Update XP64 ********.exe [* = random char]"Added by a variant of the RBOT WORM!"
X Microsoft Windows Update XP64 updatexp64.exe"Added by the SDBOT-AIM WORM!"
X Microsoft Windows Update XP64 Lcuninst.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Update XP64 mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Updater winupdgm.exe"Added by the GAOBOT.BI WORM!"
X Microsoft Windows Updater WINIUPDATES.EXE"Added by the RBOT-KK WORM!"
X Microsoft Windows Updater WINUPDATE.EXE"Added by the RBOT-LI WORM!"
X Microsoft Windows Updater TMNTSrv.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Updater win32upd.exe"Added by the RBOT-EC WORM!"
X Microsoft Windows Updater msnupdateit.exe"Added by the AGOBOT-RL WORM!"
X Microsoft Windows Updater windates.exe"Added by the SDBOT.TE WORM!"
X Microsoft Windows Updater spoolvs.exe"Added by the RBOT.ACQ WORM!"
X Microsoft Windows Updater suvhost.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Updater winfix.exe"Added by the RBOT-CM WORM!"
X Microsoft Windows updaterD log32zx.exe"Added by the MYDOOM.W WORM!"
X Microsoft Windows Updates explorer32.exe"Added by the SDBOT.VQ WORM!"
X Microsoft Windows Updates wsap32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Updating System msresource.exe"Added by the RBOT-EAM WORM!"
X Microsoft Windows Visual V2.0 msiutil.exe"Added by the DELF.JPH TROJAN!"
X Microsoft Windows W32 Services mssw32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Windows WinSaSS Management winsass.exe"Added by the RBOT-APW WORM!"
X Microsoft Windows WKS Service gt.exe"Added by the SDBOT.IR BACKDOOR!"
X Microsoft Windows WKS Service mstask0.exe"Added by the SDBOT.FV WORM!"
X Microsoft Windows Workstation devcode.exe"Added by the RBOT-AWL WORM!"
X Microsoft Windows XP Configuration Loader m32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
X Microsoft Windows XP/2K Explorer winexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Winedows startup WinKey.exe"Added by a variant of the SDBOT WORM! See here"
X Microsoft Winedows Updateing NinKey.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Winedows WinServ iPodFix.exe"Added by a variant of the RBOT WORM!"
X Microsoft WINGS32 Protocol WinSGR32.exe"Added by the RBOT-APU WORM!"
X Microsoft WinRaR winrar.exe"Added by the RBOT-AEC WORM!"
X Microsoft Winsock mswinsck.exe"Added by the RBOT-ANK WORM!"
X Microsoft Winsock Service msusvc.exe"Added by the RBOT-ANS WORM!"
X Microsoft Winsock Wrapper ws2_32s.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Winsock32 System winsock32.exe"Added by the SPYBOT.AKKC WORM!"
X Microsoft WinSound [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft winsupdater WINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
X Microsoft WinUpdate mntcgf032.exe"Added by the RBOT-PF WORM!"
X Microsoft WinUpdate svh0st.exe"Added by the SPYBOT.DL WORM!"
X Microsoft WinUpdate syslx32.exe"Added by an unidentified VIRUS
X Microsoft WinUpdate syswin32.exe"Added by the RBOT-HO WORM!"
X Microsoft WinUpdate spfix.exe"Added by a variant of the RBOT WORM!"
X Microsoft WinUpdate Winamp61.exe"Added by a variant of the RBOT WORM!"
X Microsoft WinUpdate Winupd32.exe"Added by the RBOT.MQ WORM!"
X Microsoft WinUpdate WinNTinit32.exe"Added by the RBOT.VS WORM!"
X Microsoft WinUpdate msupdte.exe"Added by an unidentified TROJAN! See examples here & here"
X Microsoft WinUpdates serm32.exe"Added by the RBOT.GE WORM!"
X Microsoft WM mswm32.exe"Added by the BCKDR-AM BACKDOOR!"
X Microsoft Word BootSector.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Word Profissional csrss.exe"Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""s1613"" subfolder"
X Microsoft Word Profissional Java Plug In close.exe"Added by the BANKER-EL TROJAN!"
X Microsoft Word Profissional csrss.exe"Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""protect"" subfolder"
X Microsoft Word Profissional csrss.exe"Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaVM"" subfolder"
N Microsoft Works Calendar Reminders wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
N Microsoft Works Portfolio WksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file. Can be prevented from starting from a setting within Portfolio
N Microsoft Works Update Detection wkdetect.exeChecks for updates to MS Works
X Microsoft World Service winworld.exeAdded by an unidentified IRC worm with backdoor capability!
X Microsoft WPCEmail [path to trojan]"Added by the SNIFFER-N TROJAN!"
X Microsoft WWW [path to trojan]"Added by the AGENT-DRI TROJAN!"
X Microsoft Wxdate Syswu32.exe"Added by the SPYBOT.HZ WORM!"
X Microsoft X Update wuamkoppnp.exe"Added by the RBOT-ANI WORM!"
X microsoft xdaemon 2.0 xdaemon.exe"Added by the DELF.D TROJAN!"
X Microsoft XML Service msxmlx.exe"Added by the RBOT.KS WORM!"
X Microsoft Xp Systems loader winsystem32xp.exe"Added by the KELVIR.W WORM!"
X Microsoft Xp Systems loaders win32xpsys.exe"Added by the SPYBOT.NYT WORM!"
X Microsoft XPSP Protocol xp386.exe"Added by a variant of the RBOT WORM!"
X Microsoft xpsp2 Networksystem.exe"Added by a variant of the SDBOT WORM!"
X Microsoft xpsp2 xpsp2.exe"Added by the SDBOT-YQ WORM!"
X Microsoft's System Module Sysmodule.exe"Added by the BDOOR-FJ BACKDOOR!"
X Microsoft(R) System Manager sysmgr.exe"Added by the AGENT.QTR TROJAN!"
X Microsoft--Updates sxvhost.exe"Added by the RBOT-FH WORM!"
X Microsoft-software ****.exe [* = random char]"Added by a variant of the RBOT WORM!"
X Microsoft-Update wngard.exe"Added by the RBOT-JV WORM!"
X Microsoft-Updates svxhost.exe"Added by the RBOT-CT WORM!"
X Microsoft.exe [random].exe"Added by a variant of the IRCBOT TROJAN!"
X microsoft.exe microsoft.exe"Added by the GOLDUN-GB TROJAN!"
X Microsoft32 win32sys.exeAdded by an unidentified WORM or TROJAN!
X microsoft420 microsoft420.exe"Added by the MENACE.B WORM!"
X Microsoft64 antiv.exe"Added by the SOBER WORM!"
Y MicrosoftAntiSpywareCleaner gcASCleaner.exe"Microsoft Antipsyware - now superseded by Microsoft's Windows Defender"
X MicrosoftCorp flashsplayer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X MicrosoftCorp javaw.exe"Added by the BUZUS.BULO TROJAN!"
X MicrosoftCorp msnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X MicrosoftCorp regtray.exe"Added by the POISON.AHNW BACKDOOR!"
X MicrosoftCorp securebind.exe"Added by the INJECT TROJAN!"
X MicrosoftCorp sysdiag64.exe"Added by a the AUTOINF-AB WORM!"
X MicrosoftCorp traymgr.exe"Added by a variant of the IRCBOT BACKDOOR!"
X MicrosoftCorp update.exe"Added by the AUTORUN-ASG WORM!"
X MicrosoftCorp wupdate.exe"Added by the AGENT-LAY TROJAN!"
X MicrosoftDriverService32 drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
X Microsoftf DDEs ContDLL rune.pif"Added by the RBOT-AGF WORM!"
X Microsoftf DDEs ContrDL runm.pif"Added by the RBOT-AFQ WORM!"
X Microsoftf DDEs Control lxes.exe"Added by the RBOT.BOF WORM!"
X Microsoftf DDEs Control wees.exe"Added by a variant of the RBOT WORM!"
X Microsoftf DDEs Control soff.pif"Added by the RBOT-AKH WORM!"
X Microsoftf DDEs Control why-.exe"Added by the RBOT-AMV WORM!"
X Microsoftf DDEs Control msnn.exe"Added by the RBOT-AXT WORM!"
X Microsoftf DDEs Control FEnR.exe"Added by the RBOT-AIM WORM!"
X Microsoftf DDEs Control w33s.exe"Added by a variant of the RBOT WORM!"
X Microsoftf DDEs Control waes.exe"Added by a variant of the RBOT WORM!"
X Microsoftkeysd systemproc.exe"Added by the FORBOT-BI WORM!"
X Microsoftkeysd systemwin32s.exe"Added by the WOOTBOT.CO WORM!"
X Microsoftkeysds lass32.exe"Added by a variant of the RBOT WORM!"
X MicrosoftKs Drivers.bat"Added by the SHUTDOWN-F TROJAN!"
X microsoftm eegs cuntrol loor.pif"Added by a variant of the RBOT WORM!"
X MicrosoftMessenger msnserv.exe"Added by the DARKER.M WORM!"
X Microsoftmsn32.exe microsoftmsn32.exe"Added by the CERTIF-C TROJAN!"
X MicrosoftMultimediaTask Mmtask.exeAdware downloader - not the valid MusicMatch Jukebox which shares the same filename
X MicrosoftNAPC flashsplayer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X MicrosoftNAPC javaw.exe"Added by the BUZUS.BULO TROJAN!"
X MicrosoftNAPC msnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X MicrosoftNAPC regtray.exe"Added by the POISON.AHNW BACKDOOR!"
X MicrosoftNAPC securebind.exe"Added by the INJECT TROJAN!"
X MicrosoftNAPC sysdiag64.exe"Added by a the AUTOINF-AB WORM!"
X MicrosoftNAPC traymgr.exe"Added by a variant of the IRCBOT BACKDOOR!"
X MicrosoftNAPC update.exe"Added by the AUTORUN-ASG WORM!"
X MicrosoftNAPC wupdate.exe"Added by the AGENT-LAY TROJAN!"
X MicrosoftNetwork Daemon for Win32 NETD32.EXE"Added by the RANDEX.F WORM!"
X MicrosoftOEM smvss.exe"Added by the DEDLER-G TROJAN!"
X MicrosoftPersonalFirewall spoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
X MicrosoftROMDriverService cdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
X MicroSoftRun MSCOMM.dll"Added by the AGENT-DJG TROJAN!"
X Microsofts Help Services msnmngr.exe"Added by the SDBOT-PJ WORM!"
X Microsofts media winmplayd.exeAdded by an undidentified WORM or TROJAN!
X Microsofts media wingtp.exe"Added by the RBOT-VO WORM!"
X Microsofts MediaScope winmep.exe"Added by the RBOT-WB WORM!"
X Microsofts MediaScope winmedplay.exe"Added by a variant of the RBOT WORM!"
X Microsofts Security Manager ****.exe [**** = random char]"Added by the RBOT-WH TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list