Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
Y snpstd3 vsnpstd3.exe"Sonix Inc. Camera Monitor MFC Application"
N Snsicon Snsicon.exeLaunches a screensaver program from Second Nature
X SNSS.EXE SNSS.EXE"Nunci premium rate dialer"
X snvc snvc.exeAdded by an unidentified WORM or TROJAN!
? SO5 Integrator Pass One sointgr.exe"StarOffice 5. See here for more details"
? SO5 Integrator Pass Two sointgr.exe"StarOffice 5. See here for more details"
X Soar Rwon.exe"PurityScan adware"
X Social Security Agency rpcxsocsa.exe"Added by a variant of the RBOT WORM!"
X Sock32 sock32.exe"Added by the SDBOT TROJAN!"
X Socket Utility svchostz.exe"Added by the DAEMONI-E TROJAN!"
X Socket Utility socket.exe"Added by the DAEMONI-E TROJAN!"
Y SoDA Startup SodaStartup.exe"Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software"
N soffice SOFFICE.EXEDisplays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
X Soft Profile Inc hxdef.exe..."Added by the LOVGATE.AO WORM!"
X Soft Profile Inc hxdef.exe"Added by the LOVGATE.E WORM!"
X soft2 ********.exe [* = random digit]"Added by the KARDPHISHER TROJAN!"
U Softany Monitor Control MonitorControl.exe"Softany Monitor Control - ""control your computer's monitor and screensaver"""
X SoftBarrier SoftBarrier.exe"SoftBarrier rogue security software - not recommended
X SoftCop SoftCop.exe"SoftCop rogue security software - not recommended
U SoftGridTray SFTTray.exe"System Tray access to SoftGrid from Microsoft - ""the only virtualization solution that delivers applications that are never installed and dynamically delivered
X softIce Update 32 wininits.exe"Added by the RBOT-ANB WORM!"
U SoftickPPP PPPGate.exe"Softick PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer"
Y SOFTinst N/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
U SoftK56 Modem Driver carpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
X SoftSafeness SoftSafeness.exe"SoftSafeness rogue security software - not recommended
X SoftSoldier SoftSoldier.exe"SoftSoldier rogue security software - not recommended
X SoftStronghold SoftStronghold.exe"SoftStronghold rogue security software - not recommended
U SoftStuff Wallpaper Changer softstrt.exe"AzureBay wallpaper changer"
X SoftVeteran SoftVeteran.exe"SoftVeteran rogue security software - not recommended
X Software software.exe"Added by the CRABTON-B TROJAN!"
X software spools.exe"Added by the AUTORUN-CS WORM!"
X Software cipsn.exe"Added by the FORBOT-DM WORM!"
N Software Manager ISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
N Software Manager issch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
X Software Soft Stop Spyware Soft Stop.exe"SoftStop rogue security software - not recommended"
U SoftwareStation station.exe"eAcceleration Stop-Sign security software related. Previously not recommended
X SolelunaAntiVirus pgs.exe"SolelunaAntiVirus rogue security software - not recommended. A member of the AVSystemCare family"
N SolidCapture solidcapture.exe"SolidCapture - screen capture and image sharing toolkit"
U SolidWorks Task Scheduler Engine swBOEngine.exe"Task scheduler for SolidWorks 3D CAD software"
Y Solo Sentry Solosent.exe"Solo Antivirus"
U SoloSchedule Solocfg.exe"Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis"
U SoloSysCheck Syscheck.exe"Solo antivirus System Integrity Check - Monitors system registry
X SolutionReg SysRep.exe"SolutionReg rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
X somatic somatic.exe"Searchcentrix hijacker"
X some icthis.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X some scit.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X some wcs.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X Somefox [path to trojan]"Added by the DWNLDR-HHB TROJAN!"
X SondBlaster lsass.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
N Sonic A3D Control vrtxctrl.exeSound related options
X Sonic RecordNow! smsc.exe"Added by a variant of the SDBOT WORM!"
N SonicFocus SFIGUI.EXE"Sonic Focus - ""enhances music
N SoniqueQuickStart sqstart.exe"Quickstart for the discontinued Sonique audio player. Available via Start -> Programs"
N SonnReg SonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
X SonudMan SonudMan.exe"Added by the STARTPAGE.Q TROJAN!"
X SonudMan WNILOGON.exe"Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process
X SonudMon SonudMon.exe"Added by the LEWOR-J TROJAN!"
N Sony Auto Update Tray Application CONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
N Sony Ericsson PC Suite Application Launcher.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
N Sony Ericsson PC Suite SEPCSuite.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
U SonyPowerCfg SPMgr.exeRelated to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices
? Soot rcea.exe"??"
? sophagnt sophagnt.exe"Possibly related to Sophocles Screenwriting Software?"
X SOProc_RegSoAlertWxLiteNnAj "rundll32 shell32.dll ShellExec_RunDLL [path] soproc.exe"
X SOS SOS.exe"Added by the PHILIS VIRUS!"
? SoSyncMonitor SoSyncMonitor.exe"SuperOffice related. What does it do and is it required?"
X Sound [path to trojan]"Added by the DROPPER.EAT TROJAN!"
X Sound Loader sndloader.exe"Added by the AGOBOT-BV WORM!"
X Sound services SOUND32.EXE"Added by the AGOBOT.GG WORM!"
X Sound System WinSound1.exe"Added by an unidentified VIRUS
X Sound Volume svchosI.exe"Added by a variant of the IRCBOT TROJAN! See here"
X soundcontrl soundcontrl.exe"Added by the GAOBOT.AFJ WORM!"
X sounddrv sndbdrv3104.exe"CoolWebSearch parasite variant"
? SoundFusion rundll32 cwcprops.cpl"Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?"
? SoundFusion "rundll32 hercplgs.cpl BootEntryPoint"
? SoundFusion "RunDll32 cwaprops.cpl C25CrystalControlWnd"
X SoundMam SVOHOST.exe"Added by the QQROB-AAL TROJAN!"
U SoundMan SOUNDMAN.EXE"Realtek Sound Manager
X SoundMan soundman.exe"Added by the AGOBOT.HM WORM! Note - this is not the legitimate SiS or Realtek file of the same name that is located in the Windows or WINNT directory"
X SOUNDMAN Microsoft Help soun.pif"Added by the RBOT-AIU WORM!"
N SoundMAX Smax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
X SoundMAX SoundMAX.exe"Added by the RIZON-A WORM! Note - this file is placed in the Startup folder itself
N SoundMAX soundmax.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
X SoundMax Audio Drivers SndMAX.exe"Added by a variant of the SDBOT WORM!"
N SoundMAX Control Panel Smax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
N SoundMAX Integrated Digital Audio Smtray.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
U SoundMAXPnP SMax4PNP.exe"Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones
X soundmix soundmix.exe"Added by the AGENT.PGV WORM!"
X SoundMixer smvss.exe"Added by the DEDLER-G TROJAN!"
X SoundMnEx32 [path to worm]"Added by the STRATION-FW WORM!"
X Soundmx Soundmx.exe"CoolWebSearch Tapicfg parasite variant"
X soundtask soundtask.exe"Added by the AGOBOT-MD WORM!"
X soundtasks soundtasks.exe"Added by a variant of the CRYPTER.C TROJAN!"
X soundtctrls soundtctrls.exe"Added by the AGOBOT-ZV WORM!"
X SoundView msdview32.exeTrojan downloader
X sounofts sounofts.exe"Added by the AGOBOT-ND WORM!"
X sountskmanager sountaskmgrAdded by an unidentified WORM or TROJAN!
N SourcePath gwreg.exeUsed to update Gateway registry settings for System Restoration Kit and Web update programs
X sp sp.regIE search hijacker - changes the default search to http://www.gocybersearch.com/
X sp regedit-s .... sp.dll"Malicious javascript annoyance that changes the default search engine in IE to one of many including ""topsearcher"". See here for more and a fix"
X sp "se.dllDllInstall"
X sp "rundll32 (Path to Trojan DLL) DllInstall"
U SP TimeSync SP TimeSync.exe"SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server)"
X SP00LSV Sp00lsv.exe"Added by the GRAYBIRD.E TROJAN!"
U SP2 Connection Patcher SP2ConnPatcher.exeChanges limit of concurrent TCP connections of Windows Service Pack 2
X SP2 data [path] repcale.exe [path] apc.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\winstat"
X SP2 Firewall/Internet Updater crssrs.exe"Added by the RBOT.BJO WORM!"
X sp2chk.exe sp2chk.exe"Added by the ALUROOT.A TROJAN!"
X sp2ctr sp2ctr.exe"Added by the DLUCA-M TROJAN!"
X sp2fwxp sp2fwxp.exeAdded by the SMALL.ABW TROJAN!
X sp2svc sp2svc.exe"Added by a variant of the RBOT WORM!"
X sp2update sp2update.exe"SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer"
X sp2update updatesp2.exe"Added by the SDBOT.CAS WORM!"
X Spam Blocker for Outlook Express SBInst.exe"Hotbar adware"
X SPAM FIREWALL mfirewall.exe"Added by the SDBOT.AOU WORM!"
U Spam Monitor SpamMonitor.Exe"System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users
U Spam Sleuth SpamSleuth.exeSpam Sleuth E-mail spam detection program
X SpamBlocker SbOEAddOn.exe"Hotbar adware"
U SPAMfighter Agent SFAgent.exe"SPAMfighter anti email spam filter"
U spamihilator spamihilator.exe"Spamihilator - spam filter"
U SpamMonitor SpamMonitor.Exe"System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users
U SpamMonitor Application SpamMonitor.Exe"System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users
U SpamPal spampal.exe"SpamPal - anti-spam tool"
U SpamSubtract SpamSubtract.exe"Intermute SpamSubtract - junk email detection and removal program"
U spamsubtract SpamSub.exeInterMute™ SpamSubtract - junk email detection and removal program. InterMute™ is now part of Trend Micro and their products are no longer supported
U Spare Backup SpareBackup.exe"Spare Backup - ""Once Spare Backup is installed
U Spark Spark.exe"Spark instant messaging client"
N SparVoip SparVoip.exe"SparVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
X spa_start Rundll32.exe spads.dll"IconAds adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""spads.dll"" file is located in the Winnt or Windows folder"
X spa_start Rundll32.exe sprt_ads.dll"Superiorads adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""sprt_ads.dll"" file is located in %System%"
? SPC610NC_Monitor Monitor.exe"Related to the Philips SPC610NC webcam. What does it do and is it required?"
N spc_w hcm.exe"NetZero Search Enhancement related"
N spc_w blspc.exe"NetZero Search Enhancement related"
N spc_w nzspc.exe"NetZero Search Enhancement related"
N Spdstart Spdstart.exe"Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications
U Speaking Clock Deluxe SpClDlx.exe"Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date
X Special Firewall Service avguard.exe"Added by the NETSKY.G WORM! Note - do not confuse with AntiVir® antivirus which uses the same filename. This one is located in %Windir%"
X SpecialOffers SpecialOffers*.exe [* = digit]"SpecialOffers adware"
X SpecialOffers SpecialOffers.exe"SpecialOffers adware"
X specific specixic.exe"Added by a variant of the SDBOT WORM!"
N Speed racer CTSRReg.exeSoftware for a Creative sound card
U Speed Tec speedtec.exe"Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled"
N SpeedBitVideoAccelerator VideoAccelerator.exe"""SpeedBit Video Accelerator makes videos from YouTube and over 150 sites stream faster and play smoother by reducing buffering problems and video interruptions or hiccups"""
X SpeedBoss [worm filename]"Added by the OPASERV.AD WORM!"
U SpeedItUp SPEEDITUP.EXE"Speed It Up - ""all in one Speed Booster designed to significantly increase the speed of your computer and boost your PC available memory"". Installs PC-Checkup and Search Defender (which is detected by DrWeb as the STARTPAGE.ORIGIN TROJAN) without permission"
U SpeedItUpEX SpeedItUpEx.exe"""Speed-It-Up Extreme is designed to speed of your computer up to 3 times faster and boost your PC available memory"""
U Speedkey SPEEDKEY.EXEAdditional keyboard shortcuts on MS programmable keyboard
U SpeedMeter SpeedMeter.exeApplication measuring upload and download speed
U SpeedOptimizer spo.exe"SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing
U Speedport W 100 Stick WLAN Manager Wifiusb.exeWireless management utility for the Speedport W 100 Stick WLAN USB stick
X SpeedRunner SpeedRunner.exeIdentified as a variant of the TrojanDownloader.Matcash malware
U SpeedswitchXP SpeedswitchXP.exe"SpeedswitchXP is a CPU frequency control for notebooks running Windows XP"
U Speedtouch USB Diagnostics Dragdiag.exeFor an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
U SpeedUpMyPC speedupmypc.exe"Older version of SpeedUpMyPC from Uniblue - which ""lets you monitor and control all your PC resources with easy
X Spees1 speedy.scr"Added by the OPASERV.Y WORM!"
X Spees2 Speedy.bat"Added by the OPASERV.AD WORM!"
X Spees3 SPEEDY.PIF"Added by the OPASERV.AD WORM!"
N Spellex Anywhere sa.exe"Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used"
U Spiceworks spicetray_silent.exe"System Tray access to Spiceworks - which ""combines everything you need to manage IT in one easy-to-use application"""
Y SpIDerMail spiderml.exe"DrWeb antivirus Spider Mail e-mail scanner"
N Spinner Plus spinner.exe""Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed
X SPINX Wscript.exe OXNEY.B.VBS"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""OXNEY.B.VBS"" file is located in %System%"
? SPIRun "Rundll32 SPIRun.dll RunDLLEntry"
Y SpkrCnfg DSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
X SPnt SPnt.exePremium rate adult content dialler
U SpokeSysTray SpokeSysTray.exe"Spoke Software client application. Spoke ""uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private
X spoo1sv spoo1sv.exe"Added by the SOULJET TROJAN!"
X Spool [path to trojan]"Added by the RANKY.R TROJAN!"
X Spool wys.exe"WhileUSurf adware"
X Spool static.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
X SPOOL Configuration spoolsvc.exe"Added by the SDBOT-KD WORM!"
X Spool Loader spool.exe"Added by a variant of the RBOT WORM!"
X Spool LoadKIt spoolv.exe"Added by a variant of the RBOT WORM!"
X Spool lptt01 spool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Spool Manager spoolsrv.exe"Added by the BANKER-FR TROJAN!"
X Spool ml097e spool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Spool32 pool32.exe"Added by the ASSASIN-F TROJAN!"
X spoolax [path to trojan]"Added by the PERDA-D TROJAN!"
X Spooler de Impress services.exe"Added by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User%"
X Spooler Host smhost.exe"Added by the IRCBOT.BSQ BACKDOOR!"
X Spooler Service Spoolsrv.exe"Added by the JOINER.C1 TROJAN!"
X Spooler Subsystem spoolsub.exe"Added by the SDBOT-ABG TROJAN!"
X Spooler SubSystem App spoolsvc.exe"Added by the POEBOT-J WORM!"
X Spooler SubSystem App spooIsv.exe"Added by the LINKBOT.M WORM!"
X Spooler SubSystem App spoolv.exe"Added by the SDBOT-BN WORM!"
X Spooler SubSystem Application localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application svcman.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Spooler SubSystem Application websvc.exe"Added by the DLOADER-NY TROJAN!"
X Spooler Subsystem Application smss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
X Spooler Subsytem App spoolsvc.exe"Added by the SDBOT-MM WORM!"
X SpoolerSubSystemProcess SpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
X spoolms spoolms.exe"Added by the LEGMIR-ARO TROJAN!"
X Spools Service Controller spools.exe"Added by the KASSBOT-C WORM!"
X spoolserv spoolserv.exe"Added by the SDBOT-PN WORM!"
X SpoolService spolsv.exe"Added by the AGOBOT-CS WORM!"
X spoolsrv.exe spoolsrv.exeAdded by an unidentified WORM or TROJAN! Located in %System%
X Spoolsv Spoolsv.exe"Added by the CIADOOR.121 VIRUS! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
X spoolsv scvhosts.exe"Added by the SMALL-AW TROJAN!"
X spoolsv svchost.exe"Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
X spoolsv spoclsv.exe"Added by the FUJACKS-M WORM!"
X spoolsv spoolsv.exe"Added by the ZAPCHAS-EE TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%\Temp\spoolsv"
X spoolsv spoolvs.exe"Added by the AGENT-HNV TROJAN!"
X spoolsv spoolsv.exe"Added by the ANTINNY-BH WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\Messenger"
X spoolsv spoolsv.exe"Added by the OURXIN.C TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in a ""spoolsv"" subfolder"
X Spoolsv spoolsv.exe"Added by the ANTINNY.F WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Program Files%\Lotus"
X spoolsv manager SpoolMgr.exe"Added by the ASSIRAL WORM!"
X spoolsv service spoolsv32.exe"Added by the RBOT-AHP WORM!"
X spoolsv.exe [random filename]"Added by the RBOT-JB WORM!"
X SPOOLSV32 SPOOLSV32.EXE"Added by the CWS-I or HAZIF-B TROJANS!"
X SPOOLSV32.exe SPOOLSV32.exe"Added by the STARTPAGE.O TROJAN!"
X spoolsvc spoolsvc.exe"Added by the DROPPER-AT TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list