Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X secures23 mssecure.exe"Added by the AGOBOT-ABY WORM!"
X SecureVeteran SecureVeteran.exe"SecureVeteran rogue security software - not recommended
X SecureWarrior SecureWarrior.exe"SecureWarrior rogue security software - not recommended
X Security WindowsSecurityUpdate.exe"Added by a variant of the SDBOT WORM!"
X Security 2009 Security2009.exe"Security 2009 rogue security suite - not recommended
X Security Accounts Manager SM samsm.exe"Added by the SPYBOT.JE WORM!"
X Security Agent securag.exe"Added by the BANCBAN-F TROJAN!"
X Security Agent Manager mssams.exe"Added by the RBOT-SV WORM!"
X Security Antivirus SA[random characters].exe"Security Antivirus rogue security software - not recommended
X Security Antivirus Xp 1 inetfor.exe"Added by the SDBOT.BAV WORM!"
X Security Center AppControl.exe"Added by the SDBOT.CFT WORM!"
X Security Center Distribution securesec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Security essentials 2010 SE2010.exe"Security Essentials 2010 rogue security software - not recommended
X Security Guard SG[random characters].exe"Security Guard rogue security software - not recommended
X Security iGuard Security iGuard.exe"Security iGuard spyware remover - not recommended
U Security Manager SecurityManager.exe"A ComCast Internet software suite that provides a variety of features (firewall
X Security Master AV SM[random characters].exe"Security Master AV rogue security software - not recommended
X Security Mechanic lsascs.exe"Security Mechanic rogue security software - not recommended
X Security Monitor securemon.exe"Added by the SLENFBOT.ABH WORM!"
X Security Patch scmss.exe"Added by the RBOT-ZW WORM!"
X Security Patch WinUpdate32.exe"Added by the SDBOT-BM WORM!"
X Security Patches msnkn.exe"Added by the RBOT.WW WORM!"
X Security Patches WinLab32.exe"Added by the SDBOT-KB WORM!"
X Security Server DB secserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X security service syss.exeAdded by an unidentified WORM or TROJAN!
X Security Service secsvc.exe"Added by the RBOT-GGF WORM!"
X Security Service DB secservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Security Service Process svhost.exe"Added by the AGOBOT-LC WORM!"
X Security System securesys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Security Update Service wmiprvce.exe"Added by the AGOBOT.ZW WORM!"
X Security Update Service Process svrhost23.exe"Added by the AGOBOT-GN WORM!"
X SecurityCenter securitycenter.exe"Desktop Security 2010 rogue security software - not recommended
X SecurityFighter SecurityFighter.exe"SecurityFighter rogue security software - not recommended
X SecurityScanner ss2008.exe"Security Scanner 2008 rogue security software - not recommended
X SecuritySoldier SecuritySoldier.exe"SecuritySoldier rogue security software - not recommended
X securw Nctrup.exe"Added by the NOPIR.A WORM!"
Y SECWIZ98 SECWIZ98.EXE"Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here"
X seekmo seekmo.exe"180Solutions.Seekmo adware - also see here"
X SeekmoOE OEAddOn.exe"180Solutions.Seekmo adware variant - also see here"
X SeekmoSA SeekmoSA.exe"180Solutions.Seekmo adware variant - also see here"
X SeekmoToolbar ${HOOKOE_FILE}"180Solutions.Seekmo adware - also see here"
X seeve seeve.exe"Medload adware"
X Select server slcsvr.exe"Added by the DLOADER-WD TROJAN!"
? SelfHostUtil slefhost.exe"??"
X seli [path to file]"Added by the LOWZONE-AS TROJAN!"
X SemanticInsight SemanticInsight.exe"RXToolbar adware. Software that displays pop-up/pop-under advertisements when the primary user interface is not visible"
U SeMS SeMS.exe"PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone"
X Sen tlii.exe"Detected by Kaspersky as PurityScan.ah"
U SendMail SendMail.exe"Part of the MySuperSPy surveillance software. Uninstall this software unless you put it there yourself. Located in %ProgramFiles%\Myss"
U Sensiva Sensiva.exe"Symbol Commander makes the use of your PC
X SENTRY SENTRY.exe"From IP Insight. Allows website owners ""to instantly determine the precise geographic location
X Sepate Security Firewall sepate.exe"Added by the RBOT.BLC BACKDOOR!"
N SEPCSuite SEPCSuite.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
X septpop06apsept septpop06apsept.exe"MediaMotor.Popupwithcast adware"
X Serials serials.exeAny one of a variety of worms and trojans
X Serices Hostin servicez.exe"Added by the SLENFBOT.MF WORM!"
X SernellApp.pcx csrss.exe"Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
X serpe formatsys.exe"Added by the SERFLOG.A WORM!"
X serpe msmbw.exe"Added by the SERFLOG.A WORM!"
X serpe serbw.exe"Added by the SERFLOG.A WORM!"
Y serrdctl.exe serrdctl.exe"Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems
X serrv serrv.exe"Added by the WAREZOV.DC WORM!"
X SERV PacK2 nerx.exe"Added by the SDBOT-ACP WORM!"
N Serv-U serv-u32.exeFTP server
X Serv-U wssdsu.exe"Added by the MANIFEST TROJAN!"
X server server.exe"Added by the DELTAD.A WORM!"
X server system.exe"Added by the METHS-A TROJAN!"
X server server.exe"Added by the SINGU-Q TROJAN!"
Y Server Application for MFP Server ServoApp.exe"Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520"
X Server Backbone server05.exe"Added by the RBOT-ZM WORM!"
X Server Daemon Host Manager sdhost.exe"Added by the RBOT-GWC WORM!"
X Server Registry regscr32.exe"Added by the BIFROSE-ZB TROJAN!"
X Server Registry regsrv32.exe"Added by the VB-EJD TROJAN!"
X Server Runtime Error unsec.exe"Added by the SDBOT-DFA WORM!"
X Server Runtime Process wbemstest.exe"Added by the SDBOT-DDB WORM!"
X SERVER.EXE SERVER.EXE"Added by the BUSHTRO122 or SMOKODOOR TROJANS!"
X serverex Server.txt.vbs"Added by the DELTAD.A WORM!"
X Serverx Serverx.exe"Added by the MADANGEL VIRUS!"
X Service service.exe"Added by the ALADINZ.H TROJAN!"
X Service [trojan filename]"Added by the KAITEX.E TROJAN!"
X Service services.exe -serv"Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Service SYSNT.exe"Added by the CHA TROJAN!"
X Service Service.pif"Added by the ASSIRAL-C WORM!"
X service wN2S.exe"Added by a variant of the RBOT WORM!"
U Service Centre launcher.exe"Management tool for the Open Networks iConnect series of products - as used by Australian ISP's such as iiNet and Hotkey"
X Service Cleaner filen.exe"Added by the RBOT.BRH WORM!"
X Service Client winsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
N Service Connection sccenter.exeFor Compaq PC's. Part of Backweb
N Service Connection bwtray.exeFor Compaq PC's. Part of Backweb
X Service Control Manager scm.exe"Added by the AGOBOT-GD BACKDOOR!"
X Service Controller Csrrs.exe"Added by the GAOBOT.AO WORM!"
X Service Controller service.exe"Added by the PREVERT TROJAN!"
X Service Defender [random filename]"Added by a variant of the ZLOB TROJAN! See here"
X Service Drivers msnpg.exe"Added by the RBOT.BMD WORM!"
X Service Drivers PC.EXE"Added by the SDBOT-WK WORM!"
X Service Drivers Compt.exe"Added by the RBOT-ZJ WORM!"
X Service Drivers abl.exe"Added by the SDBOT-YX WORM!"
X Service Drivers MSNMEssenger.exe"Added by a variant of the RBOT WORM!"
X Service Host svchost.exe"Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Service Host [filename].exe"Added by the TORVEL.B WORM!"
X Service Host spoolxx.exe"Added by the TORVEL WORM!"
X Service Host svchost.exe"Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853}"
X Service Host svchost.exe"Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random]"
X Service Host svchosts.exe"PornCleanser spyware"
X Service Host Driver svchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Service Host Process spoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
N Service Manager sqlmangr.exe"SQL Server Service Manager - provides tray access to SQL server
X Service Manager SERVICEMGR.EXE"Added by the PASSMAIL-D VIRUS!"
X Service Manager dxsound.exe"Added by the PROXY-GRIC TROJAN!"
X service manager service.exe"Added by the DONBOMB.A TROJAN!"
X Service Manager serv3manager.exe"Added by the SDBOT-AGO WORM!"
X Service Monitor msnfilen.exe"Added by the RBOT-ALE WORM!"
X Service Monitor javams32.exe"Added by the DELF-NK TROJAN!"
X Service Monitor javams64.exe"Added by the SDBOT-AFO WORM!"
X Service Monitor msnserve.exe"Added by the SPYBOT.YQW WORM!"
X Service Monitor WinOcx.exe"Added by the RBOT-AQJ WORM!"
X Service Monitor csnss.exe"Added by the RBOT.EEH WORM!"
X Service Monitor filen.exe"Added by a variant of the RBOT WORM!"
X Service Monitor winxpser.exe"Added by the RBOT-BDF WORM!"
X Service Pack [various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
X Service Pack 1 [random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
X Service Pack DLL Runtime spdll32.exe"Added by a variant of the RBOT WORM!"
X Service PAck SFVP [worm filename].exe"Added by a variant of the RBOT WORM! The filename is 4 random characters"
X Service Process SVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Service Process winset.exe"Added by a variant of the SPYBOT WORM!"
X Service Process service.exe"Added by the DCMBOT-C TROJAN!"
X Service Process smss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
X Service Process svchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
X Service Registry NT Save jdbgmgrnt.exe"Added by the BANCOS-CG TROJAN!"
X Service Registry NT Save taskmgrnt.exe"Added by the BANCOS-BY TROJAN!"
X Service Registry NT Save regeditnt.exe"Added by the BANCOS-BM TROJAN!"
X Service Scheduler scheduler.exe"Added by the AGOBOT-PH WORM!"
X Service System kernels32.exe"Added by the BANCOS-DA TROJAN!"
X Service System windowsXP.exe"Added by the BANCOS-EL TROJAN!"
X Service System kgbfsm344.exe"Added by the BANCOS-FS TROJAN!"
X Service System wernell87.exe"Added by the BANCOS-FJ TROJAN!"
X service updaer qualityz.exe"Added by an unidentified VIRUS
X Service Update Client svcupdcli.exe"Added by an unidentified WORM or TROJAN! See here"
X Service.exe Service.exe"""servedby.advertising"" popup generator"
X Service2 Service2.exeIdentified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel
X service32 service32.exe"Added by the AGOBOT-ST WORM!"
X service32.exe [path to trojan]"Added by the DLOADR-AYX TROJAN!"
X Service SERVICES.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
X ServiceAdministrator SERVICES.EXE"Added by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
U ServiceConfig ispbeg.exe"Comcast Transition Wizard. On June 30th
X serviceconnect serviceconnect.exe"Added by the AGOBOT.AIR WORM!"
X Servicee services.exe"Added by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X ServiceHost svch0st.exe"Added by the VB.HE VIRUS!"
X ServiceHst svcnost.exe"Added by the AGOBOT-RS WORM!"
X servicelayer servicelayer.exe"Added by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
X servicemng service.exe"Added by the TAME-C WORM!"
X ServiceOptionMP3 winamp.dll.exe"Added by the SAMSON-A TROJAN!"
X Servicer servcr.exe"Added by the SDBOT.BAH TROJAN!"
X Servicerepclient1 SERVICES.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
X services start.bat"Added by the ZCREW TROJAN!"
X Services [path to trojan]"Added by the METEORSHELL TROJAN!"
X Services back32.exe ...service.exe"Added by an unidentified VIRUS
X Services services.exe"Added by a number of VIRUSES
X Services winread.exe"Added by an unidentified VIRUS
X Services windns.exe"Added by a variant of the RBOT WORM!"
X Services mshost.exe"Added by the LANFILT-J TROJAN!"
X services Svchosts.exe"Added by the SDBOT-N TROJAN!"
X Services csrss.exe"Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Services scks32.exe"Added by a Proxy Trojan variant"
X Services sockys32.exeAdded by the RANKY.L TROJAN!
X Services sys.exe"Added by a Proxy Trojan variant"
X services windows32.exe"Added by the FLYVB-C WORM!"
X services socks.exeAdded by the WIN32.SMALL.N TROJAN!
X Services services.exe"Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Services [path to trojan]"Added by the RANCK-DB TROJAN!"
X Services iexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Services svchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Services sysamp.exe"Added by a variant of the SDBOT WORM!"
X Services prosys32.exeAdded by an unidentified WORM or TROJAN!
X Services iexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
X Services iexploler.exe"Added by the RANCK-LT TROJAN!"
X Services iexpolere.exe"Added by the RANCK.LU TROJAN!"
X services sample.exe"Added by a variant of the RANKY TROJAN!"
X Services csrss32.exe"Added by the ANACON-D VIRUS!"
X Services Administrator localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator svcman.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator websvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Controller lsassa.exeAdded by the CIADOOR.122 VIRUS!
X Services Controller services.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Services DLL Loader srvdll.exe"Added by the SLENFBOT.ZS WORM!"
X Services Host Scchost.exe"Added by the DONK WORM!"
X Services Host svchost32.exe"Added by the AGOBOT-TG WORM!"
X Services host svchost.com"Added by the RBOT-EU WORM!"
X Services Logon services.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates"
X Services Management Clients servc.exe"Added by the RIZO.A TROJAN!"
X Services Managements servcs.exe"Added by the RBOT-GUC WORM!"
X Services Manager svsmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Services Manager! svmanager.exe"Added by the IRCBOT.ATZ BACKDOOR!"
X Services Managers svcmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Services Network Services.exe"Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Services Process services.exe"Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process
X Services Process smss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
X Services Start2 odcwinst.exe"Added by the PYSKE-D WORM!"
X Services Startup services.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
X Services Startup svhost33.exe"Added by a variant of the RBOT WORM!"
X Services++ services.exe"Added by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLER"
X Services.dll smss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
X Services.EXE services.exe"Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X services.exe servicess.exe"Added by the MSNSPY-B TROJAN!"
X Services004 [worm filename]"Added by the BUGBROS WORM!"
X services32 mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
X services32 mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
X services32 mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
X Services32 Startup win32dll.exe"Added by the SDBOT-XO WORM!"
X ServicesActive cssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
X ServicesAdministrator SERVICES.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list