Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X MSN User Service! msnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X MSN User Services msnuserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X MSN User Svc msnusnsvc.exe"Added by the IRCBOT.AVV BACKDOOR!"
U MSN Video Enhanced MSNVE.exe"""MSN Video Enhanced can play videos that have dramatically improved video quality and sound. It can play the latest high-quality videos at the best possible quality."" No longer appears to exist"
N MSN Webcam Recorder ml20gui.exe"""MSN Webcam Recorder is a tool that allows you to record video streamed to and from your computer by MSN Messenger's Webcam Feature"""
X msn.exe son.exe"Added by the STARTPA-GS TROJAN!"
X MSN32 X Service MSN32x.EXEAdded by an unidentified WORM!
X MSN6.1 Auto-Updater v6msn.exe"Added by the AUTORUN-MM WORM!"
X MSN8m Startup msn8m.exe"Added by a variant of the RBOT WORM!"
X msnager32 svchostt.exe"Added by the WOMANIZ.E TROJAN!"
N msnappau msnappau.exe"Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to ""update"" the toolbar"
X Msnarrator msnarrator.exe"Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware"
X MSNavWH MSWkwrH.exe"Added by the ANAV-A WORM!"
X msndrvsys msndrvsys.exe"Added by the BROGGER-D TROJAN!"
X MSNET msnet.exe"Added by the BOA WORM!"
X MsnExplorer winagent.exe"Added by the BDOOR-EQ BACKDOOR!"
X MsnExplorer MSEXPLOREN.EXE"Added by the BDOOR-EB BACKDOOR!"
X MsnExplorer SHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
X MsnExplorer SVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
X MsnExplorer msnexploren.exe"Added by the TACTSLAY.B TROJAN!"
X MsnExplorer sdhch.exe"Added by the TACTSLAY.B TROJAN!"
? MsnFixer msnfixjs.js"Located in the HPbinmsnfix directory of a HP PC"
X MSNGrabber MSNgrabber.exe"Added by the ENVID.A WORM!"
X msngta32 msngta32.exe"Added by a variant of the RBOT WORM!"
N MSNIA MSNIASVC.EXEAdded with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG
X msnload32.exe msnload32.exe"Added by the BANCOS.M TROJAN!"
X MSNMESENGER Main.exe"Added by the PRORAT TROJAN!"
X msnmessenger msnmessenger.exe"Added by the BANCBAN-KJ TROJAN!"
X MsnMessengerSvc msnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
X msnmgnr msnmgnr.exe"Added by the KOLAB.TC WORM!"
X msnmgr msnmgr.exe"Added by the BIFROSE-K WORM!"
U MsnMonitor MsnMonitor.exe"MSN Messenger Monitor Sniffer surveillance software for the MSN instant messenger. Uninstall this software unless you put it there yourself"
X msnmsg asgag.exe"CoolWebSearch parasite variant"
X msnmsg TBC.exeAdded by an unidentified TROJAN!
X msnmsg msnmsg.exe"Added by the BANKER-CLX TROJAN!"
X msnmsg.exe mscmd32.exeAdded by a variant of the AGENT.AH TROJAN!
X msnmsg.exe msnmsg.exe"Added by the BANCBAN-KN TROJAN!"
X msnmsgq32 msnmsgq.exe"Added by the TACTSLAY.H TROJAN!"
X msnmsgq32 msnmsgq32.exe"Added by the TACTSLAY.F TROJAN!"
X msnmsgq32 sssasasb32.exe"Added by the TACTSLAY.F TROJAN!"
N msnmsgr msnmsgr.exe"Windows Live Messenger or the older MSN Messenger utility - available via the Start menu. For Windows Live Messenger
X MsnMsgr MsnMsgrs.exe"Added by the NETSKY.AD WORM!"
X MsnMsgr msnmsgr.exe"Added by the ANNEW-FAM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
X Msnmsgr.exe lsass.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
X msnmsgr32-.exe msnmsgr-.exe"Added by a variant of the SPYBOT WORM!"
X MSNMSGR5 MSNMSGR5.exe"Added by the RBOT.PQ WORM!"
X MSNMSGRE swef.batIRC backdoor TROJAN or WORM!
X MSNMSGRR swin.batIRC backdoor TROJAN or WORM!
X MSNMSGRS swe.batIRC worm or backdoor trojan!
X MSNMSGRS swiss.batIRC worm or backdoor trojan!
X MSNMSGRS1 swed.batIRC backdoor TROJAN or WORM!
X msnmsgs.exe msnmsgs.exe"Added by the BANKER-HK TROJAN! Note - not to be confused with msmsgs.exe
X msnmsgsgs msnmsgsgs.exe"Added by the ""Catal"" alias Spy.Delitall.B backdoor TROJAN!"
X msnmsgy [path to file]"Added by the BANKER-EQ TROJAN!"
X msnnt winampb.exe"Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!"
X msnnt winampf.exeAdded by the SMALL.DTS TROJAN!
X MSNPluginSrIvcs n3vasap23.exe"Added by a variant of the RBOT WORM!"
X MSNPluginSrvcs p6.exe"Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
X MSNPluginSrvcs sagate.exe"Added by the SDBOT.AKJ WORM!"
X MSNPlus msnplus.exe"Added by the BANKER-DAN TROJAN!"
X MSNS PLUS XP2 msdupd.exe"Added by the RBOT-BCE WORM!"
X msnsched2 msnsched2.exe"Added by the SPYBOT.NNT WORM!"
X msnscr.exe msnscr.exe"Added by the CERTIF-P TROJAN!"
X MSNService MSNService.exe"Added by the CARPET.C WORM!"
X msnsgs msnsgs.exe"Added by the CHEUKO-B TROJAN!"
X msnshed msnshed.exe"Added by the RBOT-YN WORM!"
X msnsmgr MsnMsr.exe"Added by the LOONY-N TROJAN!"
N msnsyslog msnappm.exe"Related to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying"
X MSNSysRestore pc32.exeAdded by a variant of the MASTAK VIRUS!
X msnToolbaar msnmsgesc.exe"Added by the RBOT.BMF WORM!"
X msnupdt kolie.exe"Added by a variant of the RBOT WORM!"
X MsnWin messagewin.exe"Added by the BANCBAN-D TROJAN!"
N MSNŽ Toolbar mswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
X MSObject32 MSObject32.js"Added by the PUN TROJAN!"
X Msoffice msoffice.htaHijacker - redirecting to Searchdot.net
X MSOffice services.exe"Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
X msoffice msoffice.exe"Added by the LIKASIMAL WORM!"
X MSOffice32 msjcf.exe"Added by the RAKER-A TROJAN!"
X MSOfficeCfg msocfg.exePremium rate adult content dialer
X MSOfficeCfg navchk.exePremium rate adult content dialer
X MSOfficeCfg qservice.exePremium rate adult content dialer
X MSOfficeCfg shman.exePremium rate adult content dialer
X MSOfficeCfg ssvr.exePremium rate adult content dialer
X msoffwz msoffwz.EXE"Added by the BANCBAN-HQ TROJAN!"
X msoft-updater23 mssysstems.exe"Added by the RBOT-ATU WORM!"
X msoft-updater23 slssystem.exe"Added by the RBOT-ASR WORM!"
X MSOleath32 winss.exe"Added by the KATHER TROJAN!"
X MSOOBD MSOOBD.EXE"Added by the MAGISTR.A VIRUS!"
X msoupdater msoupdater.exe"Added by the DLOADER.GBD TROJAN!"
X mspaint.exe check32.exe"Added by the AGENT.AH TROJAN!"
X Mspatch69 [path to trojan]"Added by the MPROX TROJAN!"
X Mspatch89 cnqmax.exe"Added by the RANDEX.P WORM!"
X MSPetServ PET32.EXE"Added by the IRCBOT-VE WORM!"
X msping msping.exe"Added by the FLOODBLACK TROJAN!"
X msping.exe msping.exe"Added by the BDOOR-MZ BACKDOOR!"
X MSPluginSrvc p3.exe"Added by the RBOT-WV WORM!"
X MSPLUS msplus32.exe"Added by the MYTOB-AM or MYTOB-CL WORMS!"
X MSPP System Update 64 wiaadmgr.exe"Detected by Kaspersky as the RANKY.GEN TROJAN!"
X MSPQFile MSA****.TMP [* = random char]Homepage hijacker
X MsPrint32D MsPrint32D.exe"Added by the WINKO.AO WORM!"
X MSPRO32 [path to worm]"Added by the IBERIO WORM!"
X MSPRO32 pnp.exe"Added by the ZOTOB.O WORM!"
X MSprotect.exe MSprotect.exe"Added by the DABYREV.A VIRUS!"
U mspwr pupstman.exe"""Transparent icon background"" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)"
U mspwr pupxpman.exe"Related to Ashampoo's PowerUp XP"
U mspwr pwrupst.exe"Ashampoo's PowerUp XP is a ""tool for fine-tuning your Windows NT4
U mspwr PuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
U MSPY2002 ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
X msqssr msqssr.exe"Detected by Kaspersky as the DLUCA.GEN TROJAN!"
X MSR msr.exe"Added by the AGOBOT.RT WORM!"
X Msrc Msrc.exeAdded by the KRYPTONIC GHOST TROJAN!
X msrdc msrdc.exe"Added by the SDBOT-CXO WORM!"
X msreg.exe msrege.exe"Added by the ZINX TROJAN!"
X msReg32 Loader msreg32.exe"Added by the AGOBOT.IU WORM!"
X MSREGIT Msgp.exe"Added by the KRYPGHOS.13 TROJAN!"
U MSRegScan SGP.exe"SpyGator surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan SSDemo.exe"SupremeSpy surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan ETNKL.exe"ComKeylogger surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan KSPDemo.exe"KeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan DDSSDemo.exe"SystemSleuth surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan ESP+.exe"ESP surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan ESPDemo.exe"Eye Spy Pro surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan SBPDemo.exe"SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan YEKPND.exe"EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself"
U MSRegScan YKPND.exe"YKPMD surveillance software. Uninstall this software unless you put it there yourself"
X MSRegSvc regsvc32.exeHomepage hijacker that changes your homepage to an adult content site
X msresear [path to trojan]"Added by the WEASYW-B TROJAN!"
X msresearch msresearch.exe"TROJAN! - 180SearchAssistant adware related"
X msresearch tool3.exe"Spy Sheriff/SpywareNO malware
X msrundll msrund1l32.exe"Added by the BINGHE TROJAN!"
X msrunocx32 msrunocx32.exe"Added by the SKUS WORM!"
X Mss Serv msssrv.exe"Added by the SLENFBOT.AA WORM!"
X Mss VC mssvc.exe"Added by the OPANKI.AB WORM!"
X mssaru mssaru.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
X msscan.exe msscan.exe"Microsoft Security Adviser rogue security software - not recommended"
U MSSCDL MSSCDLL.exe"SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!"
X mssdbsrv msupdtck.exeAdded by a variant of a password stealing TROJAN!
Y MSSE msseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
Y msseces msseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
X msserrv32 msserrv32.exe"Added by the STRATION.DW WORM!"
X msserv msserv.exe"Added by the BLACKLOG-A TROJAN!"
X msserv lvsrev.exe"Added by the BROWMON-B TROJAN!"
X msserv32 msserv32.exe"Added by the RBOT-ACK WORM!"
X MsServer msfun80.exe"Added by the VB-CYG WORM!"
X MSServer "Rundll32.exe [random].dll#1"
X MsServer msfir80.exe"Added by the VB-CYJ TROJAN!"
X msservice msserv.exe"Added by the HYD WORM!"
X MSService_v1.0 realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
X MSService_v1.0 vfp02.exe"NewWeb adware"
X mssfos sfool.exe"Added by the RANDEX.EUS WORM!"
X MSSGisg [path to file]"Added by the RANKY.N TROJAN!"
X Msshield.exe Msshield.exe"Added by a variant of the IRCBOT TROJAN!"
X MSShow MSShow.exe"Added by the QQROB-M TROJAN!"
X MSSHVC MSSHVC.exe"Added by the NUFFY.A WORM!"
X mssonfig winupdate.exe"Added by a variant of the SDBOT WORM!"
X mssoul msmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
X mssoul msmscc.exe"Added by the BANCOS.HKT TROJAN!"
X mssp3 mssp22.exe"Added by the IBANK-D TROJAN!"
X MSSQL Mssql.exe"Added by the SDBOT TROJAN!"
X MSSQL for Windows NT & XP mssqlsnt.exe"Added by a variant of the SDBOT WORM!"
X MSSQL Manager mssqlmgr.exe"Added by the RBOT-BWU WORM!"
N mssSort msssort.exe"Maxtor (now Seagate) ""Drag and Sort"" for their external storage - ""Just drag documents onto the Shared Storage II icon and Maxtor's Drag and Sort organizes your files
X Msstart msstart.exe"Added by the LIVUP.C TROJAN!"
X MSStartOptimizer Iexpres.exe"Added by the DASMIN-E TROJAN!"
X MSStartOptimizer WINUPD.EXE"Added by the DASMIN-E TROJAN!"
X MSStartOptimizer SCVHOST.EXE"Added by the DASMIN-E TROJAN!"
X msstask msstask.exe"Added by the MYPARTY WORM!"
X mssurfer lptt01 mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X mssurfer ml097e mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X mssvc [path to trojan]"Added by the PSK TROJAN!"
X MSSVC svcsys.exe"Added by the FATOOS-C TROJAN!"
Y MSSVC.EXE MSSVC.EXE"StealthDisk - hides folders
X mssvc32 mssvc32.exe"Added by the AGOBOT-ME WORM!"
X mssync20 mssync20.exe"Added by the LDPINC-QC TROJAN!"
X mssys mssys.exe"Added by the MYSS.B TROJAN!"
X mssysint Iexplore .exe"Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
X mssysint comime.exe"Added by the NETSNAKE-I TROJAN!"
X mssyslanhelper msmsgri32.exe"Added by the RANDEX.D WORM!"
X MsSystem msdos.exe"Adult content downloader - see here"
X MsSystem mssys.exe"Added by the VANTA.A TROJAN!"
X MSSYSTEM svcsys.exe"Added by the FATOOS-C TROJAN!"
U Mstapi Mstapi.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
X Mstask mstask.exe"Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in %Windir%"
X mstask mstask.exe"Browser hijacker - redirecting to find-more.net. Note - this is not the legitimate mstask.exe system file"
X MSTask run dll.exe"Yuupsearch adware"
X MStask svchost.exe"Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X MsTask wstask32.exe"Added by the MYTOB-FE WORM!"
X Mstask kernel32.exe"Added by the STAP-C WORM!"
X Mstask MSDTC.exe"Added by the STAP-D WORM!"
X MSTask Monitor mstaskmon.exe"Added by the SDBOT-LU WORM!"
X Mstask32driver Mstask32.exe"Added by the LOONY-D TROJAN!"
X MSTaskbar 32 tbsvc32.exe"Added by the RBOT.BQZ WORM!"
X mstasks mstasks.exe"Added by the MULTIDR-AY TROJAN!"
? Mstcgww MSTCGWW.EXE"??"
X mstds.exe mstds.exe"Added by the IPTABLES TROJAN!"
X mstg32.exe mstg32.exeAdded by the AGENT.BI TROJAN!
N MSTMON_N MSTMON_N.EXEGenerates an error message on startup if a Konica Minolta printer is not turned on and ready
N MSTMON_Q MSTMON_Q.exeGenerates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready
X Mstng32 MSTng32.exe"Added by the TANG WORM!"
X MSTray rundll.exe"Added by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
X mstsdsc.exe mstsdsc.exe"Added by the CIMUZ-CD TROJAN!"
X msupd msupd.exe"Added by the IEACCESS DIALER!"
X MSUpdate wupd.exe"Added by the ALADINZ.M TROJAN!"
X MSUpdate svchosthlp.exe"Added by the BLASTER.T WORM!"
X msupdate msupdate.exe"Added by the RBOT-MZ WORM!"
X MSUpdate criticalUpdate.exe"Affilred adware"
X msupdate update.exe"Added by a variant of the SDBOT WORM!"
X Msupdate expIorer.exe"Added by the TACTSLAY.A TROJAN!"
X Msupdate outIook.exe"Added by the TACTSLAY.A TROJAN!"
X Msupdate svchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
X Msupdate svcrhost.exe"Added by the TACTSLAY.A TROJAN!"
X Msupdate svcshost.exe"Added by the TACTSLAY.A TROJAN!"
X MSupdate.exe N/A"CoolWebSearch parasite variant - resets home page to an adult content site"
X MSUpdateDevKit axfd.exe"Added by the SDBOT-ZD WORM!"
X msupdater msupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
X MsUpdater System udpsys32.exe"Added by the RBOT.AAA WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list