Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X MS Windows Executor Process MSEXECP32.exe"Added by a variant of the RBOT WORM!"
X MS Windows Local Directory MSWLD32.exe"Added by a variant of the RBOT WORM!"
X MS Windows procces 32 msprocces.exe"Added by the RBOT-AEZ WORM!"
X MS Windows Process Class MSPRCSS32.exe"Added by the RBOT-YQ WORM!"
X MS Windows Process Init MSWPI32.exe"Added by the RBOT-ASQ WORM!"
X MS Windows Security Updater updater.pif"Added by the RBOT-AKY WORM!"
X MS Windows System Alert MSWSA32.exe"Added by the RBOT-BFN WORM!"
X MS Windows TASK Service MSWTASK32.exe"Added by a variant of the RBOT WORM!"
X MS Windows Update scguard.exe"Added by the RBOT-YZ WORM!"
X MS WINS Binary ign32.pif"Added by the RBOT-ASB WORM!"
X MS Winsock msws2_32.exe"Added by the AKBOT-A TROJAN!"
X ms************* [* = random digit] ms*************.exe [* = random digit]"WINBO adware"
X Ms**.exe [* = random char] Ms**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X Ms**32.exe [* = random char] Ms**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X MS-Connect arr.exe"Adult content dialler - see here"
X MS-Connect cdm.exe"Adult content dialler - see here"
X MS-Connect game.exe"Adult content dialler - see here"
X MS-Connect msite18.exe"Adult content dialler - see here"
X MS-Connect web.exe"Adult content dialler - see here"
X MS-DOS Boot Service Boot32.pif"Added by the RBOT-AMF WORM!"
X MS-DOS Security Service ms-dos.pif"Added by the RBOT-AMR WORM!"
X MS-DOS Service MS-DOS.pif"Added by the RBOT-AII WORM!"
X MS-DOS Windows Service MS-DOS.PIF"Added by the RBOT-AJW WORM!"
X MS-HTML [random filename]"Added by the LATINUS.15 TROJAN!"
X MS-patch msconfig32.exe"Added by the RBOT-AUF WORM!"
X MS-patch mspatch32.exe"Added by the RBOT-AWF TROJAN!"
X MS-RunKey arr.exeMS-Connect dialler/hijacker
X ms2src ms2src.exe"Added by a TROJAN - see here"
X MS32DLL achi.dll.vbs"Added by the ACHI-A TROJAN!"
X MS32DLL Bha.dll.vbs"Added by the BUTSUR-A WORM!"
X MS32DLL MS32DLL.dll.vbs"Added by the ZODGILA WORM!"
X MS32DLL ffqca.exe"Added by the SDBOT-YD WORM!"
X MS7531 ms7531.exeHomepage hijacker
X MSACM msacm.exe"Added by the OPASERV-O WORM!"
X msadcheck msadcheck32.exe"Browser hijacker
X MSAdmin jdbgmrg.exe"Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
X MSAgent mshtm.exeBrowser hijacker - redirecting to buldog-search.com
X MSAgent hhnt.exe"AGENT.JI spyware"
X MSAgentXP MSAgentXP.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN!
U msaim msaolim.exe"MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X msappts32 msappts32.exe"Added by the ELBURRO-A TROJAN!"
Y MSASCui MSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
X MsAudio explorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X MsAudio "MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
X msavsc.exe msavsc.exe"Added by the AGENT.ANQ TROJAN!"
X MSbackups backups.exe"Added by the BANLOAD-TL TROJAN!"
X msbb msbb.exe"180Search adware"
X Msbb.exe Msbb.exe"Added by the SDBOT.QJ WORM!"
X msbcs msbcs.exe"Added by the DADOBRA-G TROJAN!"
X MsBootMgr.exe MsBootMgr.exe"Added by the VERIFY TROJAN!"
X msbsc [path to trojan]"Added by the BANKER-DF TROJAN!"
X msc msc.exe"MaCatte Antivirus 2009 rogue security software - not recommended
X msccrt msccrt.exe"Added by the PWS-ALA TROJAN!"
X mscheck rundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
X mschkdf.exe mschkdf.exe"Added by a variant of the SDBOT WORM!"
X MSChoExE suge.exe"Added by a variant of the RBOT WORM!"
? msci mcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
X msclac msclac.exe"Added by the SDBOT-JM WORM!"
X msclean msvchost.exe"Added by the OPANKI-Q WORM!"
X mscman mscman.exe"ClientMan parasite variant"
X mscms mscms.exe"Added by the AGENT-MS TROJAN!"
U mscn mscn.exePart of the SafeChildNet internet filtering program - required if you use it
X Mscnt mscnt.exe"Added by the DLUCA-C TROJAN!"
X Mscolour mscolour.exe"Added by the GEMA TROJAN!"
X MSCommX mscommx.exe"Added by a variant of the RBOT WORM!"
X Msconf32 Msconf32.exe"Added by the AGOBOT-NR WORM!"
X MSCONFG32.EXE MSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
N MSConfig msconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
X MSConfig MSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
X msconfig msconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
X msconfig msconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
X msconfig wins.exe"Added by the RBOT.PF WORM!"
X MSConfig MSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
X msconfig scvhost.exe"Added by the AGENT-DSF TROJAN!"
X msconfig winlog.exe"Added by the IRCBOT-TJ TROJAN!"
X Msconfig icpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
X msconfig msconfig.com"Added by the IRCBOT-SM WORM!"
X msconfig msconfig.bat"Added by the PAHATIA.B WORM!"
X MSConfig lssas.exe"Added by the AUTORUN.CEY WORM!"
X MSConfig xwpwqf.exe"Added by the AGENT-NEW TROJAN!"
X Msconfig lptt01 msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X MSConfig Manager msupdate.exe"CoolWebSearch parasite variant"
X Msconfig ml097e msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X msconfig service MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
X msconfig. msconf.exe"Added by the BUZUS-AY WORM!"
X msconfig.exe proxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X msconfig.exe uline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X msconfig38 mssvcc.exe"Added by the RBOT-BJV WORM!"
X MSConfig45 MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
X MSConfigr jdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
N MSConfigReminder msconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
X MsConfigs MsConfigs.exe"Added by the ALCAN.A WORM!"
X MSConfigs RUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
X msconfigurator ctfsdk.exe"Added by the DELF-ALS TROJAN!"
X MSControl28 crsss.exe"Added by the SPYBOT.AJX WORM!"
X MSControl31 winnsyst.exe"Added by the RBOT.CFY WORM!"
X MSControl3d1 isasse.exe"Added by the RBOT.CGU WORM!"
X MSCORE syscnfg.exe"Added by an unidentified VIRUS
? MSCRMStartup Microsoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
X Mscsgs MSCSGS.EXE"Added by the ZEZER WORM!"
X Mscsgs32 MSCSGS32.EXE"Added by the ZEZER WORM!"
X mscsvc.exe mscsvc.exe"Added by the BANCOS.T TROJAN!"
X msctfg32 msctfg32.exe"Added by the RBOT-TJ WORM!"
X msctrl.exe msctrl.exe"Microsoft Security Adviser rogue security software - not recommended"
X Msctrl32 Msctrl32.scr"Added by the REDIST WORM!"
X MSCVT MSCVT.exe"Added by the SLIDESHOW WORM!"
X MSDatabla vadasq.exe"Added by the LIOTEN.IK WORM!"
X msdbgm.exe msdbgm.exe"Added by the CIMUZ-CQ TROJAN!"
X MSDcom MSDcom.exe"Added by a variant of the SDBOT WORM!"
X msdefender msdefender.exe"Identified as a variant of the PAKES.CMD TROJAN! See here for an example"
X msdefender.exe msdefender.exe"Added by the PAKES.ZL TROJAN!"
X msdev msdev.exe"Added by the FORBOT-CR WORM!"
X msdev msconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
X msdev control msdevctrl.exe"Added by the SPYBOT.N BACKDOOR!"
X msdir32 msdir32.bat"Added by the ROOKIE-A TROJAN!"
X msdirect.exe msdirect.exe"Added by the CERTIF-L TROJAN!"
X MSDLL syscnfg.exe"Added by an unidentified VIRUS
X Msdmxm msdmxm.exe"Added by the DLUCA-DC TROJAN!"
X MSDN nese.exeAdded by the SDBOT.AHY WORM!
X MSDN for Windows NT msdn.exe"Added by a variant of the RBOT WORM!"
X MSDN for Windows NT & WinXP msdnxp.exe"Added by the IRCBOT-PE WORM!"
X MSDN for Windows with NT's msdn-nt.exe"Added by the RBOT-EWD WORM!"
X MSDN HELP msdn.exe"Added by the AGOBOT.AIB WORM!"
X MSDNMess [path to trojan]"Added by the RANKY.BA TROJAN!"
X MSDNN help.exe"Added by the AGENT-GBK TROJAN!"
X MSDOS Security Service msdos.pif"Added by the RBOT-AMP WORM!"
X MSDOS Service MSDOS.PIF"Added by the RBOT-AIY WORM!"
X MSDOS Windows Service MSDOS.PIF"Added by the RBOT-AKF WORM!"
X Msdos32 Msdos32.pif"Added by the RECORY WORM!"
X msdos423 msdos423.exe"Added by the MENACE.A WORM!"
X MSDosdrv msdosdrv.exe"Added by the BACROS WORM!"
X MSDrive rundll32.exe drvkoc.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
X MSDrive rundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
X MSDrive rundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
X MSDRV NetFilter.exe"Added by the INTERRUPDATE TROJAN!"
X msdrvctrl msdrvctrl.exe"Added by the VIDCACH-A TROJAN!"
N MSDTC msdtc.exeMS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
X Msemu32 Msemu32.exeUnidentified spyware/adware/hijacker
X msennger l4m3r.exe"Added by the PROGENT-AF TROJAN!"
X msennger ournik.com"Added by the IRCFLOOD.AL BACKDOOR!"
X mserv seres.exe"Added by the AGENT-LIL WORM!"
X mservices.exe mservices.exe"Added by the SDBOT.WJ WORM!"
X mset svchost.exe"Added by the BIZEX-F TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""mset"" sub-directory"
X Msfind Msfind.exe"CoolWebSearch parasite variant"
X MSFind32 msfind32.exe"Added by the CAYAM WORM!"
X msfindosa.exe msfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
X MSFTP Service Config r3grun.exe"Added by a variant of the SDBOT WORM!"
X msfw.exe msfw.exe"Microsoft Security Adviser rogue security software - not recommended"
X MSFWAVTSM FTPDev.exe"Added by the RBOT-ACF WORM!"
X Msg Fixage msgfixed.exe"Added by the SDBOT.ZD WORM!"
X MsgApi [path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
X msgb1 msgb1.exeAdded by the DLUCA.GEN TROJAN!
N MsgCenterExe RealOneMessageCenter.exe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
X msgex32 msgex32.exe"Added by the APPFLET-A WORM!"
X msgina wuauclt2.exe"Added by the IYUS-H TROJAN!"
X Msgmgr [path to worm]"Added by the BABYBEAR WORM!"
X msgmsgs peremption.exe"Added by the SDBOT-KU WORM!"
X msgserv_ Syss.exe"Added by the FANTA TROJAN!"
X msgsm32 msgsm32.exe"Added by the RBOT-ASG WORM!"
X Msgsrv16 Msgsrv16.exe"Added by the DELF family of TROJANS!"
Y MSGSRV32.exe msgsrv32.exe"Windows 32-bit VxD Message Server. For more information on its function and why it's needed
X Msgsvc32 [worm filename]"Added by the NAUTICAL-A WORM!"
X MsgSvcMgr32 cmdzxdll.exe"Added by the RBOT-AEK WORM!"
X msgsvr32 msgsvr32.exe"Added by the DEADHAT.B WORM! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
U MSGTAG MSGTAG.exe"MSGTAG is an application that tells you when your emails have been received and opened"
X Msgtray sys16.exeAdded by an unknown VIRUS!
X Mshelp32 mshelp32.exe"CoolWebSearch parasite variant"
X mshmail mshmail.exe"Added by the INJECT.JDT TROJAN!"
X Mshosts Mshosts.exe"Added by the STARTPAG.CF TROJAN!"
X MSHT@ MSHT@.EXE"Added by the MAGISTR.A VIRUS!"
X mshtmll mshtmll.dll"Added by the DELF.BAS TROJAN!"
X MSI Configuration msiconf.exe"Added by the AGENT.AKSZ TROJAN!"
X msiconf.exe msiconf.exeAdded by a variant of the FAKEALERT TROJAN!
X msidle msidle.exe"Added by the OPASERV-O WORM!"
X MsIdle32.exe MsIdle32.exe"Added by the VERIFY TROJAN!"
X MSIdll winmp.exe"Added by a variant of the RBOT WORM!"
X MSIE Parsers MSIE32ab.exe"Added by the SDBOT.MV WORM!"
X msiemon.exe msiemon.exe"Microsoft Security Adviser rogue security software - not recommended"
X msiew mseiw.exe"Added by the LITTLOG TROJAN!"
X MSIEXEC MSIEXEC32.exe"Added by the AINESEY.A WORM!"
X MSIEXEC MSIEXEC.EXE"Added by the YOSENIO-A VIRUS!"
X msiexecs msiexecs.exe"Added by the SILLYFDC.BBB WORM!"
X msiexecs.exe msiexecs.exe"Added by a variant of the SDBOT WORM!"
X msig disk10.exe"Added by the BANBRA-KF TROJAN!"
X MsIMMs32 MsIMMs32.exe"ONLINEG.GDJ spyware"
X msimn msimn.exe"Added by the AGOBOT.JL WORM!"
X MSIMN32 MSIMN32.EXE"Added by the CWS-M TROJAN!"
? MSIN MSin.exe"??"
X Msinet Msinet.exe"Added by the RBOT-AOA WORM!"
X MSInfo msinfo.exe"Added by the ALADINZ.M TROJAN!"
X MSInfo AVBgle.exe"Added by the NETSKY.O WORM!"
X MSInstall smvss.exe"Added by the DEDLER-G TROJAN!"
X msjava service xpcd.exe"Added by the SDBOT.VM WORM!"
X msjdqs fddwqt.exe"Added by the SDBOT-PO WORM!"
U MskAgent MskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
U MskAgentexe MskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
X MSKCES32 [random filename]"Added by the CLONER TROJAN!"
U MSKDetectorExe MSKDetct.exe"Part of McAfee Spamkiller"
X MSKernel32 MSKernel32.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
X MSkernel32 System.exe 4820"Added by the TUXDER BACKDOOR!"
U MSKExe spamkiller.exe"McAfee Spamkiller"
X mskj mskj.exe"Added by the KAEMON TROJAN!"
X mskrider maskrider.dll.vbs"Added by the SOLOW-F WORM!"
U MSKServerExe MSKSrvr.exe"Part of McAfee Spamkiller"
X mslagent mslagent.exe"Added by the WINTRIM-F TROJAN!"
X MSLARISSA MSLARISSA.pif"Added by the ASSIRAL.B WORM!"
? MSLIB32 mswatch32.exe"??"
X msliveupdate msliveupdate.exe"Added by the AGOBOT.ALT WORM!"
X MSLog MicrosoftLog.exe"Added by a variant of the SDBOT WORM!"
X Mslogon lptt01 mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Mslogon ml097e mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X msm msm.scr"Added by the BANKER-EHJ TROJAN!"
X msmacro32 msmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!
X msmacro32 msmacro64.exe"Added by a variant of the BACKDOOR-DOQ TROJAN!"
X MsManager msmgr32.exe"Added by the YAHA.AF WORM!"
X msmanager32 msmngr32.exe"Added by the RANDON-R (or WOMANIZ.A) WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list