Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Rundll32_8 "rundll32.exe inetp60.dll DllRunServer"
X Rundll32_8 "rundll32.exe 1.dll DllRunServer"
X RunDLL34 syscnfg.exe"Added by an unidentified VIRUS
X rundll64 [path to worm]"Added by the AUTEX WORM!"
X RundllSvr Rundll.exe"Added by the HUAYU WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X Rundllsystem32 Rundllsystem32.exe"Added by the NETDEVIL.B TROJAN!"
X Rundnm Rundnm.exe"Added by the DELF-HA TROJAN!"
X RUNGogoTools LaunchAdware.exe"GoGoTools adware"
X RUNGogoTools GoGoLaunch.exe"GoGoTools adware"
X RUNHYPER hyperx.exe"PurityScan/Clickspring adware"
X runing win.exe"Added by the DELF-LC TROJAN!"
X RUNLOAD l0ad.exe"PurityScan/Clickspring adware"
X RUNLOUD loud.exe"PurityScan/Clickspring adware"
U Runmarc8mManager marc8m95.exe"MARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settings"
U RunNarrator Narrator.exeAssociated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech
X Runner lsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Runner csrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Runner lsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Runner svchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X runner1 updater.exeAdded by the CRYPT.ULPM.GEN TROJAN!
X runner1 retadpu.exe"Added by the AGENT.SLZ TROJAN!"
X runner1 mrofinu.exe"Added by the AGENT.CZC TROJAN!"
X runner1 retadpu[random digits].exe"Added by the SMALL.CTV TROJAN!"
X runner1 tsitra.exe"Added by the AGENT.ABFQ TROJAN!"
X runner1 faceback.exe"Added by the DLOADR-BSX TROJAN!"
U RunOnce RUNONCE.EXEPart of MS Data Access Components - only required if you use these
X Runonce runouce.exe"Added by the CHIR-B WORM!"
X RunOnce [path to trojan]"Added by the BANCBAN-P TROJAN!"
X RunOnce [path to mstask32.exe]"Added by the DELF-IA TROJAN!"
X RunOnce2Upd [path to trojan]"Added by the MURLO.FI TROJAN!"
X RunOnceEx sms.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
X RunProg Server.exe"Added by the OPTIX.04.A TROJAN!"
X RunProg wini.exe"Added by the OPTIX.04.D TROJAN!"
X runreper viewer.exe"Added by the REPER.A VIRUS!"
X runs run.exe"Added by the RBOT-BWF WORM!"
X RunSearvices tread.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
X RunServices runsvc32.exe"Added by the AGOBOT.QJ WORM!"
X runservices services.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X runsql runsql.exe"Added by the DELF.ZWK TROJAN!"
X runSubvalues [path to file]"Added by the DLOADER-QY TROJAN!"
X runsvc runsvc.exe"Added by the SMALL-CF TROJAN!"
U RunSysd32 RunSysd32.exeDesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
X Runtime Process Csrss.exe"Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Runtime Server Subsystem csrss.exe"Added by the IRCBOT-XV WORM!"
X runtime.exe runtime.exeAdded by a variant of the Tibs malware
X Runtt1 Internat.exe"Added by the LINEAGE-R TROJAN!"
X Runtt1 Internet.exe"Added by the LINEAGE-Q TROJAN!"
X RunWin [path to file]"Added by the BANKER-ES TROJAN!"
X runwin32 runwin32.exe"Added by the ESEARCH-A TROJAN!"
X RUNWIN32 runwin32.exe"Added by the VB-AET TROJAN!"
X RunWindowsUpdate uptodate.exe"BrowserAid/BrowserPal foistware"
X runwinlogon winlogon.exe"Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process
X Run_cd Run_cd.exe"Added by the GHOST.23 TROJAN!"
Y run_pbnext PBNext.exe"PBNext is virtual phone system which offers the same functionality as expensive PBX hardware"
U Rupsw32 Rupsw32.exe"MegaTec Rups
? RUSBHOLoader "rundll32.exe RUSBHOLoader.dll AutoRegister"
X RVC6Player tskdbg.exe"Added by the ZAPCHAS-M TROJAN!"
X rvde N/ARelated to li-speed****
X RVP bpc.exe"BroadcastPC adware"
X rw service alg32.exe"LOOPAD.A adware"
X rx rundll32.exe"Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process
X rx explore.exe"Added by the ZHENGTU-A TROJAN!"
N RxMon rxmon9x.exe"Part of Dell Resolution Assistant - ""a diagnostic program that allows you to contact Dell. When factory-installed by Dell
X rxres32 ati2vid.exe"Added by the RBOT-FL WORM!"
N RxUser RxUser.exe"Part of Dell Resolution Assistant - ""a diagnostic program that allows you to contact Dell. When factory-installed by Dell
X ryan1918 servidevice.exe"Added by the RBOT-GVR WORM!"
X rydanmxe.exe rydanmxe.exe"Added by the DLOADR-AZZ TROJAN!"
X ryiixhp ryiixhp.exe"Added by the IRCBOT-ABR BACKDOOR!"
X ryy rundl132.exe"Added by the PWS-ANA TROJAN!"
X rzt rundll32.exe"Added by the LINEAGE.BDP TROJAN! Note - this is not the legitimate rundll32.exe process
Y R_server r_server.exe"Radmin - remote admistrator server. Note - the file is located in %ProgramFiles%\Radmin"
X r_server service.exe"Added by the MULTIDR-CP TROJAN!"
X r_server r_server.exe"Added by the HACDEF-DR TROJAN! Note - do not confuse with the valid Radmin file with the same name which is located in %ProgramFiles%\Radmin. This one is located in %System%"
X S svhost.exe"Added by the AGOBOT-LN WORM!"
X S0undMan svch0st.exe"Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
? S24EvMon S24EvMon.exe"Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required?"
X S3 Internal Chip s3serv.exe"Added by the AGOBOT-DD WORM!"
X S3 Internal Chip s3chip3.exe"Added by the AGOBOT-FW WORM!"
N S3apphk S3apphk.exeA tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems
U S3Hotkey s3hotkey.exeHotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card
? S3Mon S3Mon.exe"S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required?"
U S3TRAY S3Tray.exeS3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
? s3tray2 s3tray2.exe"S3 display configuration taskbar utility for S3 chipset based graphics cards?"
? S3TRAYHP S3trayhp.exe"S3 Video driver related. What does it do and is it required?"
U S3Trayp S3trayp.exeS3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
U S4F S4F.exe"FilterPak from S4F
X s4helper s4helper.exe"Searchcentrix hijacker"
X s9201 av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended
X s9201 as2008xp.exe"AntiSpyware XP 2008 rogue spyware remover - not recommended
X s9201 asproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
? SA Sa3.exe"Logitech QuickCam driver. Is it required?"
? SA Service SAservice.exe"Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?"
N Sa3dsrv Sa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
X saap saap.exe"180solutions adware"
U Sabre Printing Start Sabstart.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
U Sabre Server sabserv.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
U Sabre Task Tray Icon Sabstart.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
U Sabreserver SABSERV.EXE"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
X sac sac.exe"180Search adware"
X SACC sacc.exe"SurfAccuracy adware"
N SAClient RegCon.exe"AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected
X sacmemds smcntlwio.exe"Added by the MAILBOT-BZ TROJAN!"
X Safe SafeWin.exe"Added by the FOCOSENHA TROJAN!"
X Safe [path to trojan]"Added by the BANKER-DT TROJAN!"
X SafeFighter SafeFighter.exe"SafeFighter rogue security software - not recommended
X Safeguard 2009 sf2009.exe"Safeguard 2009 rogue spyware remover - not recommended
X SafeGuard Popup Blocker Updater regsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
X SafeGuard Popup Blocker Updater (required) regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
X SafeGuard Popup Updater (required) regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
X SafeGuard Popup Updater (required) regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
X Safeguard.exe Safeguard.exe"Super Spyware Killer rogue spyware remover - not recommended"
X SafeHardDrive SysRep.exe"SafeHardDrive rogue system error and cleaning utility - not recommended
U SafeHouseSystemTray SDWTRAY.EXE"SafeHouse ""Personal Privacy"" system tray icon - PP protects and hides your private and personal photos
N SafeInstall.exe SAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older one
N SafeOFF SafeOff.exeProvides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
X SafePcAv SafePcAv.exe"SafePcAv rogue security software - not recommended
X SafePCTool SysRep.exe"SafePCTool rogue system error and cleaning utility - not recommended
X SafeSearch safesearch.exe"SafeSearch.A adware"
Y SafeSpace SafeSpaceSysTray.exe"Part of SafeSpace (from Artificial Dynamics) which ""protects computers from Internet malware infection without the need for signature updates or regular maintenance"""
X SafeStrip SafeStrip.exe"SafeStrip rogue security software - not recommended
X SafeStripReminder SafeStripReminder.exe"SafeStrip rogue security software - not recommended
X SafeSurfingUpdate SSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
X SafeSys SafeSys.exe"Added by the AUTORUN.DMI WORM!"
X Safety Anti-Spyware 3 Safety Anti-Spyware 3.exe"Safety Anti-Spyware rogue security software - not recommended
X SafetyCenter protector.exe"Safety Center rogue security software - not recommended
X SafetyKeeper SafetyKeeper.exe"SafetyKeeper rogue security software - not recommended
U SafetyNet ipcTray.exe"Safety.Net from Netveda - ""offers Internet security
U SafetyNet_Notifier ipcLn.exe"Safety.Net from Netveda - ""offers Internet security
U Safeworld Freedom.exeSafeWorld Internet Security - now no longer available
X Sagate Security Firewall sagate.exe"Added by the GAOBOT.BOW WORM!"
N SAgent2ExePath SAgent2.exeSeiko Epson printer status agent. Disable if printer is not used often
U SAGENTSERVICE Sagent.exe"TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself"
X Saggwwgg CVAvwwd.exe"Added by the LIOTEN.HT WORM!"
X sagnt sagnt.exeAdware web downloader
X SAHagent Sahagent.exe"ShopAtHomeSelect parasite"
X SAHBundle bundle.exe"ShopAtHomeSelect parasite"
X SAHBundle shop1003.exe"ShopAtHomeSelect parasite"
X saie saie.exe"180solutions adware"
U SaiMfd SaiMfd.exe"Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technolgy) configuration software for their game controllers. Create a shortcut and run manually when required"
U SAIMON SaiMon.exe"Saitek joystick driver"
X sain sain.exe"180Search adware"
X sais sais.exe"180solutions adware"
U SaiSmart SaiSmart.exe"""Smart Button Special Sauce"" - included with the latest software for Saitek game controllers. Related to the ""S""
U SaitekAutoConfigure saicnfig.exe"Configuration for Saitek game controllers"
X Sakemsneql simenu.exe"Added by the SDBOT.BTO WORM!"
X Sakora Sakora.exe"Added by the GOWELES.A TROJAN!"
N SalaatTime SalaatTime.exe"""Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world"""
X Salestart WAS7Mon.exe"Part of the WinAntiSpyware 2007 rogue spyware remover - not recommended"
X Salestart bm.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
X Salestart dcpasmon.exe"SystemDoctor rogue security software - not recommended
X Salestart dcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
X Salestart mc.exe"Part of SecurePCCleaner
X Salestart stm.exe"Part of SecurePCCleaner
X Salestart strpmon.exe"Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
X Salestart stmon.exe"Part of rogue software including members of the AVSystemCare security suite family (see here for examples) and the PcRaiser and SystemOptimizer2008 optimization utilities"
X Salestart mav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
X Salestart PASmon.exe"Part of rogue security tools
X Salestart dcmon.exe"SystemDoctor rogue security software - not recommended
X Salestart startmon.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
X salm salm.exe"180Search adware"
U Salmosa razerhid.exe"Razer Salmosa gaming mouse driver - required if you use the additional features and programmed keys/macros"
X saly saly*****.exeAdded by a variant of the AW.AWK TROJAN!
X Sam-sung Sam-sung.exe"Added by a variant of the SDBOT WORM!"
X SaMail [WORM FILE NAME].vbs"Added by the VBS.LIDO WORM!"
U SAMcal SAMcal.exe"SamCal - calendar/reminder program"
U Sametime Connect Connect.exe"IBM Lotus Sametime - instant messaging and Web conferencing software"
X Samsong Samsong.exe"Added by the SDBOT.BNE WORM!"
X Samsung Samsungs.exe"Added by an IRC TROJAN variant!"
U Samsung MJC-900 Series Monitor "RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
U Samsung PanelMgr SSMMgr.exe"Monitors ink levels
U SamsungSM PanelMgr SSMMgr.exe"Monitors ink levels
U SandboxieControl Control.exe"SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it"
U SandboxieControl SbieCtrl.exe"""SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"""
N SandIcon SandIcon.exe"SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds
X SanitarDiska GDC.exe"SanitarDiska Romanian rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
X SANS Service sansv.exe"Added by the VANEBOT-AH WORM!"
U SansaDispatch SansaDispatch.exe"Sansa Updater - ""The Sansa Updater is an application that checks for the latest firmware updates then downloads and installs the firmware to your Sansa device"""
X Santa Bastards Bitch SANTAS.BITCH.txt"Added by the ATNAS.A WORM!"
X sapp sapp.exe"NCase adware"
U SaskTel Accelerated Dial-up sasktelgui.exe"""Experience faster surfing
X sasserfix package.exe"Added by the DABBER.B WORM!"
X saSyncMgr "rundll32.exe sasync.dll SyncWait"
U SATARaid SATARaid.exeRAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
X satmat satmat.exe"VX2.Transponder parasite updater/installer related"
X sau sau.exe"180Search adware"
U SAUpdate SAUpdate.exe"Big Brother from Quest Software. System and network monitor"
U SAutoLaunchExe SAutoLaunchExe.exe"Sharp Zaurus PDA related
Y SAVAgent SAVAgent.exe"Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly
X Savasddwq ffasd.exe"Added by the SDBOT-SI WORM!"
X Save Save.exe"WhenU.Save adware"
X Save lssas.exe"Added by an unidentified TROJAN! See here"
X SaveArmor SaveArmor.exe"SaveArmor rogue security software - not recommended
X SaveDate SaveStartDate.ExeUnidentified adware
X SaveDefender SaveDefender.exe"SaveDefender rogue security software - not recommended
X SaveDefense SaveDefense.exe"SaveDefense rogue security software - not recommended
X SaveKeep SaveKeep.exe"SaveKeep rogue security software - not recommended
X SaveKeeper SaveKeeper.exe"SaveKeeper rogue security software - not recommended
X Savenow SaveNow.exe"WhenU.Save adware"
X SaveSoldier SaveSoldier.exe"SaveSoldier rogue security software - not recommended
X Savsvc "rundll32.exe savsvc.dllstart"
X SAW saw.exe"SmartAdware adware"
U Say The Time 5.0 SAYTIME.EXE"This program has audio cues for the system clock in male and female voices
U SB SB.exeAcer Soft Button on Acer Tablet PCs
X SB SpywareBomber.exe"SpywareBomber rogue spyware remover - not recommended
N SB Audigy 2 Startup Menu /l:eng"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
X SB Watchdog SBWatchdog.exeSpyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank
X SB13mini RYZO32.EXE"Added by the SPYBOT-EJ WORM!"
U SBAutoUpdate sbautoupdate.exe"SpywareBlaster auto-updater"
U SBC RoamingClient SBCFL.exe"Part of AT&T FreedomLink Wi-Fi connection software"
U SBC Self Support Tool matcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
N SBC Yahoo! Connection Manager ConnectionManager.exeUsed to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection
Y SBCSTray SBCSTray.exe"System Tray access to CounterSpy antispyware software"
U SBDrvDet SBDrv.exe"Detects the ""Easy Front-Panel Audio Connectivity Drive Internal Drive Bay"" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one"
N sbdrvdet sbdrvdet.exeChecks to see if Creative sound card driver should be updated
X SBHC sbhc.exe"SuperBar parasite - uninstall available here"
X SBI install_sbd_**.exe"Installer for a number of rogue security products and error fixing tools - where ** represents a 2 letter language code

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list