Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
N SSDPSRV ssdpsrv.exe"Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program
X sserrvv sserrvv.exe"Added by the STRATION.DB WORM!"
X ssgrate.exe system.exe"Added by the MITGLIEDER.C TROJAN!"
X ssgrate.exe irun.exe"Added by the MITGLIEDER.D TROJAN!"
X ssgrate.exe irun4.exe"Added by the MITGLIEDER.F TROJAN!"
X ssgrate.exe sysdoor.exe"Added by the MITGLIEDER.N TROJAN!"
X ssgrate.exe winerdir.exe"Added by the MITGLIEDER.O TROJAN!"
X ssgrate.exe winsystems.exe"Added by the BAGLEDL-J TROJAN!"
X ssgrate.exe wintems.exe"Added by the MITGLIEDER.Q TROJAN!"
U SSh32 SSh32.exe"2Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
X SSK Service winssk32.exe"Added by the SOBIG.E WORM!"
X SSL svchost.exe"Added by an unidentified VIRUS
X SSL SearchNDestrou.exe"Added by the SDBOT-WG WORM!"
X SSL Manager amsnmsgs.exe"Added by a variant of the SDBOT WORM!"
X SSLDyn SSLDyn.exE"FRETHOG.MM spyware"
U SSMMgr SSMMgr.exe"Monitors ink levels
X ssms.exe SSMS.EXE"Added by the GISMOR WORM!"
X ssms.exe winn.exe"Added by the SDBOT-DHE WORM!"
X ssmss ssmss.exe"Added by the AGENT-MOF TROJAN!"
X ssp2.exe ssp2.exe"Added by the RBOT-BBK WORM!"
U SSPY SSYTEM.EXE"SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
U SSS7 SSS7.exe"Steganos Security Suite 7 - ""A comprehensive collection of methods to prevent your data falling into the wrong hands
X sssasasb32 sssasasb32.exe"Added by the TACTSLAY.F TROJAN!"
X sssasasb32 msnmsgq32.exe"Added by the TACTSLAY.F TROJAN!"
X sstata dwdas.exe"Added by the DASDA TROJAN!"
X sstata [path to trojan]"Added by the RANCK-DF TROJAN!"
X SStb.exe SStb.exe" ""ServerSide"" keyword hijacker"
N sstray sstray.exenVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
X SSUpdate SSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
X ssvchost ssvchost.exe"Added by the HELIOS.B TROJAN!"
X SSWPlauncher comet.exe"Comet Cursor adware"
N Stacmon Stacmon.exeInstalled with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
N StacSysTray StacSysTray.exeSystem Tray control panel for SigmaTel C-Major on-board audio - as used on some Dell and Packard Bell PCs
X staeck12 mfcee.exeAdded by an unidentified WORM or TROJAN!
X staeck122 mfceee.exeAdded by an unidentified WORM or TROJAN!
X standalone.exe standalone.exe"Added by the AGOBOT-ADS WORM!"
U Stardock ObjectDock ObjectDock.exe"Stardock ObjectDock is a program that enables users to organize their shortcuts
U StarSkin starskin.exe"StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes"
Y Start Quick95.exeFor a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
X Start windows.vbsHomepage hijacker
? start start.exe"??"
X start sdcc.exeAdded by the AGENT.CSX TROJAN!
X start isfmntr.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X start sbmntr.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X start iebtm.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
X Start aThe Roll enotxa2.exe"Added by the RBOT-PV BACKDOOR!"
X Start aThx Roll f0mered.exe"Added by the RBOT.AAV WORM!"
X Start CurePCSolution CurePCSolution.exe"CurePCSolution spyware remover - not recommended
X start extracting spoolvse.exe"Added by the RBOT-XF WORM!"
X start extracting spoolvs.exe"Added by the RBOT.BAN WORM!"
X start extracting mcafee.exe"Added by the RBOT.FO BACKDOOR! Note - this is not a valid McAfee program and is located in %System%"
N Start Getright getright.exe"Entry added with older versions of the GetRight download manager from Headlight Software
X Start It Upping svchosets.exe"Added by a variant of the RBOT WORM!"
U Start Network Scanner Tool sdFTP.exe"Part of
X Start Page"Naupoint browser hijacker"
X Start Page svcnt32.exe"Homepage hijacker
Y Start RF Wireless Keyboard ktrexe.exeYuanxun Electronics RF wireless keyboard driver
Y Start RF Wireless Mouse cm20.exeYuanxun Electronics RF wireless mouse driver
U Start Service upssrv.exe"Cyber Power PowerPanelPlus software. ""During a power failure the system automatically saves and closes open files within the battery backup time and safely powers down your computer"""
X Start The Roll enotax2.exe"Added by the RBOT.XO WORM!"
U Start Up Cop startcop.exe"
X start uploading smsss.exe"Added by a variant of the SDBOT WORM!"
X start uploading crsss.exe"Added by the RBOT-SZ WORM!"
X Start Upping taskmrg.exe"Added by the RBOT-MA WORM!"
X Start Upping SVCHOSTES.EXE"Added by the RBOT-NB WORM!"
X Start Upping taksmgr.exe"Added by the RBOT-QK WORM!"
X Start Upping mcrt32.exe"Added by a variant of the SPYBOT WORM!"
X Start Upping windupds.exe"Added by the SDBOT.AFH WORM!"
X Start Upping windupdts.exe"Added by a variant of the RBOT WORM!"
X Start Upping xdcc.exe"Added by the SPYBOT.OY WORM!"
X Start Upping spoolnt.exe"Added by the RBOT-TM WORM!"
X Start Upping iexplorerupdt.exe"Added by the RBOT-RR WORM!"
X Start Uppings svcchosts.exe"Added by the SDBOT.VY WORM!"
X Start Uppings mssupdate.exe"Added by a variant of the RBOT WORM!"
N Start Wingman Profiler lwtest.exe"Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer
N Start Wingman Profiler LWEMon.exePart of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed
X Start Xp Setup msxp.exe"Added by the RBOT.AKK WORM!"
U Startacc startacc.exe"Launches Webroot's Accelerate 2000 software that ""speeds up your Internet connection by up to 300%"". Leave enabled if you find it improves internet connection"
N StartCCC CLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
X startdrv startdrv.exe"Added by the DROPRK-A TROJAN!"
U StartEAK StartEAK.exe"Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys"
U StartEase StartEase.exe"
X startemdoit [path to trojan]"Added by the DLOADR-AVP TROJAN!"
X Starter scvhosting.exe"Added by the SDBOT.RU WORM!"
X starter scvhostingg.exe"Added by the FORBOT-FB WORM!"
X starter iexplore.exe"Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
U StartFoxie StartFoxie.exe"Foxie Suite from Softonic International. ""This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements"""
X Starting up wvsvc.exe"Added by the RBOT-NF WORM!"
X startkey svcmgr.exe"Added by the HIPPER-B TROJAN!"
X startkey update.exe"Added by the BIFROSE-DG TROJAN!"
X startkey XMCHAI.EXE"Added by the BIFROSE-AO TROJAN!"
X startkey explore32.exe"Added by the BDOOR-MT BACKDOOR!"
X startkey CKOTS.exe"Added by the BIFROSE-HM TROJAN!"
X StartKey pligde.exe"Added by the BIFROSE.E TROJAN!"
X startkey RunWinRaR.exeAdded by a variant of the BIFROSE-LV TROJAN!
X startkey Mysia.exeAdded by the CEP TROJAN!
X startkey explorer.exe"Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X startkey furzi.exe"Added by the BIFROSE-OK TROJAN!"
X startkey krnl.exe"Added by the BIFROSE-S TROJAN!"
X startkey royale.exe"Added by a variant of the SDBOT WORM!"
X startkey rtfmsv.exe"Added by the EDEPOL-C TROJAN!"
X startkey scvhost.exe"Added by the BIFROSE-PM TROJAN!"
X startkey server.exe"Added by the BIFROSE-DB TROJAN!"
X startkey win32i.exe"Added by the BIFROSE-R TROJAN!"
X startkey winampXP.exe"Added by the BIFROSE-OY TROJAN!"
X startkey svchost32.exe"Added by a variant of the SDBOT WORM!"
X startkey winlogin.exe"Added by the BIFROSE-PM TROJAN!"
X startkey antivir.exe"Added by the BIFROSE-TO TROJAN!"
X startkey svchost.exe"Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X StartKey msnmsie.exe"Added by the BIFROSE.M BACKDOOR!"
N startl.exe startl.exe"Lingocom LingoWare - translates any application into your language"
X StartMenu deamon.exe"Added by the TACTSLAY.C TROJAN!"
X StartMenu msgaol.exe"Added by the TACTSLAY.C TROJAN!"
X StartMenu s_menu.exe"Added by the TACTSLAY.C TROJAN!"
X StartMenu browse.exe"Added by the DROWSY-C TROJAN!"
X startpage startpage.exeBrowser hijacker - redirecting to
U STARTPAGE start1.exe" - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder"
X StartReplySystem loadnewmessage.exe"Added by the HIDAGENT-B WORM!"
U StartSecurDoc SDPin.exe"SecurDoc from WinMagic Inc - ""Provides full disk encryption to protect sensitive information stored on laptops
U StartStop STARTSTOP.EXE"StartStop from TFI Technology - startup manager"
U StartSurfing STARTS.exe"Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows
N Startup ??Related to an Iomega drive
X Startup WinlogonStartupUnidentified malware
X Startup mirc.exe"Added by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in the Windows or Winnt folder"
X Startup Configuration [six character filename]"Added by the RBOT-ARV WORM!"
X Startup Configuration wztoid.exe"Added by the RBOT-ASD WORM!"
? Startup Launcher GUI GUI.exe"Startup manager?"
U Startup Manager Scanner StartupMonitor.exe"Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans
Y Startup Scan Sensor.EXE"AntiVirus Quick Heal - scheduling agent"
X Startup Update Cvshost.exe"Added by the GAOBOT.AO WORM!"
X StartupBin iwnujdss.exe"Added by the SDBOT-XZ WORM!"
X StartUpDate [path to trojan]"Added by the BIFROSE.F BACKDOOR!"
U StartupMonitor StartupMonitor.exe"Mike Lin's StartupMonitor
X StartupOption loadsysdisk.exe"Added by the HIDAGENT-B WORM!"
X Startwd "rundll32.exe wd081025.dllHook"
X startwin startwin.exe"Added by the ANTIMAN.A WORM!"
X startwindowskeyuser rundle2.exe"Added by the JAVAKILLER TROJAN!"
N Stat 'n' Perf StatnPerf.exe"Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes"
X StatBar STATBAR.exe"StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory
X State Service csrss.exe"Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
U StationPlaylistStudio SPLStudio.exe"StationPlaylist Studio - ""simple to use on-air broadcast playback software for the studio and/or DJ"" for small to medium sized radio broadcasters
X Statistics statslist.exe"Added by the OPANKI-S WORM!"
X statloads pgjd83sa.exe"Added by the SDBOT-UM WORM!"
N Status Monitor BrMfcWnd.exeBrother scanner status monitor - can be started manually
U Status Monitor CLJ1500 HPPOUMUI.exe"Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status
N Status Monitor XE ENGSS.EXEThe Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
? StatusClient StatusClient.exePart of Hewlett Packard network printer drivers
? StatusClient 2.6 StatusClient.exePart of Hewlett Packard network printer drivers
N StatusView StatusView.exe"Status View intra-office messaging"
N Stay Connected! StayCon.exe"More than just a pinger
U StayAlive StayAlive.Exe"Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net"
U StayAlive sa.exe"StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen
? STBVision STBVisn.exe"Related to the STB Velocity graphics card. What does it do and is it required?"
N STBWEBTV STBWEBTV.EXEUsed to display TV on your PC
X stcinstaller id53.exe"Added by the SCTHOUGHT.L TROJAN!"
X stcloader stcloader.exe"SecondThought adware"
X STCLOA~1 STCLOA~1.EXE"SecondThought adware"
Y STCPO STCPO.exeSophos Sweep antivirus software
X StdAFX stdafx.exe"Added by the DELBOT-AF WORM!"
X stdlib [filename]"Added by the PERDA-E TROJAN!"
Y STDSB STDSB.exe"Scrollbar driver for notebooks. If taken out of the Startup
U Stealth Anonymizer 2.5 stealth25.exe"Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy"
X stealth.dcom.exe stealth.dcom.exe"Added by the THEALS.A WORM!"
X stealth.ddos.exe stealth.ddos.exe"Added by the THEALS.A WORM!"
X stealth.exe stealth.exe"Added by the THEALS.A WORM!"
X stealth.injector.exe stealth.injector.exe"Added by the THEALS.A WORM!"
X stealth.stat.exe stealth.stat.exe"Added by the THEALS.A WORM!"
X stealth.wm.exe stealth.wm.exe"Added by the THEALS.A WORM!"
X stealth.worm.exe stealth.worm.exe"Added by the THEALS.A WORM!"
N Steam steam.exe"Valve Corporation's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life
X steam steam.exe"Added by the RBOT-AJT WORM! Note - the file steam.exe will be found in %System% and is not associated with Valve Software's game client"
X SteFanie SteFanie.vbs"Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders"
? stgclean w32main2.exe"Related to IBM Standard Software Installer. What does it do and is it required?"
N Stickies Stickies.exe"Stickies - ""lets you put yellow sticky notes on your Windows desktop
N Sticky Notes stikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
U Sticky Pad StickyPad.exe"Sticky Pad from Green Eclipse. Place sticky notes on your desktop"
N StickyNote StickyNote.exeUtility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
U StillImageMonitor Stimon.exe"Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example
X stisrv stisrv.exe"Added by the RBOT.BQF WORM!"
X stlbdist "rundll32exe stlbdist.DLL DllRunMain"
X stlbupdt "rundll32.exe stlbupdt.DLLDllRunMain"
N STManager drst.exe"Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here"
X stmha wkfxi.js"Added by the SPETH WORM!"
X stonedrv stonedrv.exe"Added by the COSIMA-K TROJAN!"
X StopingSpy StopingSpy.exe"StopingSpy rogue security software - not recommended
U StopSignSsTsMon "sstsmon.dll VerifyStatus"
U StopSignStatus stopsinfo.dll"eAcceleration Stop-Sign security software related. Previously not recommended
U STOPzilla Stopzilla.exe"StopZilla! - pop-up killer"
U STOPzilla Service SZNTSVC.EXE"StopZilla! - pop-up killer"
U StorageGuard sgtray.exe"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop)
X StorageProtector SysRep.exe"StorageProtector rogue system error and cleaning utility - not recommended
U StormCodec_Helper StormSet.exe"Storm Codec is a codec pack for Windows"
? STPMGR STPMGR.EXE"Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs"
X stratas xmconfig.exe"Added by the RBOT-AHR WORM!"
X stratas lockx.exe"Added by the SDBOT-ADD WORM!"
X Stratas ggfig.exe"Added by the OPANKI.W WORM!"
X StreamAppliance wuauclt14.exe"Added by the RBOT-GMB WORM!"
X StreamAppliance wuauclt16.exe"Added by the RBOT-GME WORM!"
N Streamload Downloader SlDB.exe"Downloader for MediaMax (was Streamload) - ""gives you a private and secure place to upload
N Streamload Uploader StreamMgr.exe"Uploader for MediaMax (was Streamload) - ""gives you a private and secure place to upload
X Streams Drivers [trojan filename]"Added by the RESTARTER.E TROJAN!"
U StreamZap Remote zremote.exe"StreamZap PC Remote - control Windows Media Player
U StrgSync.exe StrgSync.exe"SimpleTech Inc's StorageSync backup software - backs up an entire PC
X strkjhk sdflkj3.exe"Added by an unidentified WORM or TROJAN - see here"
X strmsnmgrs msnxmsgrsc.exe"Added by the SDBOT.JDR WORM!"
X strmsnmsgr msnmsgrs.exe"Added by the RBOT-ACQ WORM!"
X strmsnmsgrs msnmsgrsc.exe"Added by a variant of the RBOT WORM!"
X strmsnnms msnmegrs.exe"Added by the SDBOT-YU TROJAN!"
X strmsnnrs msnmcgrs.exe"Added by the RBOT-ACT TROJAN!"
X strmsoums msnmegrse.exe"Added by the SDBOT-ZK TROJAN!"
X Strng32 strngbox.exe"Added by the STRANO WORM!"
U StrokeIt strokeit.exe"StrokeIt is an ""advanced mouse gesture recognition engine and command processor"""
X strpmon strpmon.exe"Part of BugsDestroyer
X strtas lock1.exe"Added by the SDBOT-ADQ WORM!"
X strtas lockx.exe"Added by the SDBOT-AEB WORM!"
X strtas l074.exe"Added by the AGENT-II TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list