Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X strtas loc1.exe"Added by the RBOT-AZU TROJAN!"
X strto strto.exe"Added by the KILLPROC-F TROJAN!"
X strto [path to trojan]"Added by the KILLAV-AP TROJAN!"
X Sts iwnujdss2.exe"Added by the SDBOT-YI WORM!"
X Stubbish Stubbish.exe"Added by the STUBBOT-A WORM!"
X StubPath Sservice.exe"Added by the PRORAT TROJAN!"
X stup 138762763.exe"Added by the FIRESPY-A TROJAN! It will attempt to register the dropped component as a Firefox plugin and begin monitoring the user's browsing habits
X stup [path to trojan]"Added by the AGENT-CIL TROJAN!"
X stup.exe stup.exe"Added by the QQROB.LE TROJAN!"
X stup1db0t _win.exe"Added by a variant of the IRCBOT BACKDOOR!"
N StupAssist StupAssist.exeAssociated with Nikon digital cameras
X STV winscrne.exe"Added by a variant of the SDBOT WORM!"
X stxrmsgms mstats.exe"Added by the IRCBOT-AE TROJAN!"
U StyleXP StyleXP.exe"StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot
X SubAH SubAH.exeAdded by the SUBAH TROJAN!
U Subliminal Power Subliminal.exe"Subliminal Power - displays subliminal messages of your choice on your computer screen"
N Subtract the Ads AdSub.exeRemoves adverts from web pages. Although useful - not required
X suck l0ad.exe"PurityScan adware"
X suicide tempfile2.bat"Personal Protector rogue security software - not recommended
U Suitcase Startup Suitcase.exe"Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system"
X Suite SuiteOffices.exe"Added by the LAZAR TROJAN!"
X SULFNBJ.EXE SULFNBJ.EXE"Added by the PE_MAGISTR.DAM VIRUS!"
X Sun Java Console for Windows NT & XP jconsole.exe"Added by the VANEBOT-C WORM!"
X Sun Java Updater stacsv.exe"Added by the BUZUS.DBFM TROJAN!"
X Sun Java Updater v5 javajre.exe"Added by the AUTORUN-XI WORM!"
X Sun Java Updater v7.4 javawx.exe"Added by the ACKANTTA.B WORM!"
U Sunasdtserv Sunasdtserv.exe"CounterSpy by Sunbelt Software - adware/spyware protection"
U sunasServ sunasServ.exe"CounterSpy by Sunbelt Software - adware/spyware protection"
X Sunjava javasmart.exe"Added by the AGENT.AHV TROJAN!"
X SunJava Updater v7 javale.exe"Added by the ACKANTTA.B WORM!"
X SunJavaSched ccEvtMngr.exe"Added by the SDBOT-YP WORM!"
X SunJavaSched Updater avamx.exe"Added by the RBOT-ABJ WORM!"
X SunJavaUpdate smvss.exe"Added by the DEDLER-G TROJAN!"
X SunJavaUpdater javaw.exe"Added by the MYTOB.QR WORM!"
X SunJavaUpdaterv13 javaupdater.exe"Added by the ROUTROBOT WORM!"
N SunJavaUpdateSched jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
X SunJavaUpdateSched scvhost.exe"Added by the SDBOT-AVX WORM!"
X SunJavaUpdateSched javamx.exe"Added by the SDBOT-WI WORM!"
X SunJavaUpdateSched10 jushed.exe"Added by the ACKANTTA.F WORM!"
X SunJavaUpdateSched132 jschd.exe"Added by the AUTORUN-AQY WORM!"
X SunJavaUpdateSched16 jvshed.exe"Added by the ACKANTTA.G WORM!"
X SunJavaUpdatSched spoolsv.exe"Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger"
U Sunkist shwicon98.exe"Card reader for memory cards from digital cameras
U Sunkist2k shwicon2k.exe"Card reader for memory cards from digital cameras
U SunKistEM shwiconem.exe"Used by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software"
U SuNotification suatshut.exe"ShadowSurfer - ""provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC"""
Y SunProtectionServer SunProtectionServer.exe"CounterSpy antispyware software"
Y SunServer SunServer.exe"CounterSpy antispyware software"
? SupaDial SupaDial.exe"SupaNet.com modem driver related - is it required?"
N Supastatus status.exe"Supanet ISP software"
X supdate supdate.exe"Added by the MALWARE.D TROJAN!"
X supdate2.dll "rundll32.exe supdate2.dllRun"
X supdate2.dll regsvr32.exe /s supdate2.dll"Added by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""supdate2.dll"" file is found in %System%"
X super fuckbx.exe"Added by the LINEAGE-H TROJAN!"
X super super.exe"Added by the AGOBOT-QT WORM!"
U Super Popup Blocker popkill.exe"Saga Super Popup Blocker - pop-up stopper"
U Super X Desktop Version 3.4 SXDesk.exe"Super X Desktop - virtual desktop manager"
U SuperAdBlocker SAdBlock.exe"SuperAdBlocker"
Y SUPERAntiSpyware SUPERAntiSpyware.exe"SUPERAntiSpyware - spyware
X SuperBar.Component [path to services.exe]"Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Inetsrv"
X SuperBar.Component services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
U Supercleaner Supercleaner.exe"Supercleaner - all in one disk cleaner for your computer"
U SuperCool Compress Backup Main.exe""SuperCool Zip Backup software is a data backup
U SuperCopier2.exe SuperCopier2.exe"""SuperCopier replaces windows explorer file copy and adds many features"""
X SuperHeissSex SuperHeissSex.exe"HeissSex premium rate adult content dialer!"
X supernews12 newsd32.exe"Adware
X Supernova [worm filename]"Added by the SURNOVA.A (or SUPOVA) WORM!"
X superproxy superproxy.exe"Added by the DELBACK-B TROJAN!"
U SuperRam SuperRam.exe"SuperRam memory manager. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See SuperRam article and make up your own mind"
X superslut msslut32.exe"Added by the SLUTER-A WORM!"
U SuperSpamKiller Pro Ssk.exe"SuperSpamKiller Pro email spam blocker"
X Supervisor.exe Supervisor.exe"Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome"
X support-reverse-smileys [trojan filename]"Added by the LITEBOT TROJAN!"
U Support.com Scheduler and Command Dispatcher tgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
X supporter5 supporter5.exe"Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
U Sup_SmartRAM Sup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
U Sup_SmartRAM.exe Sup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
U SureCleanProfessional SRClean.exe"SureClean PC and Internet tracks cleaner"
U Sureshotpopupkiller Stopthepop.exe"Stop-the-Pop-Up popup blocker"
U Sureshotpopupkiller pusak.exe"Stop-the-Pop-Up popup blocker"
X SurfAccuracy sacc.exe"SurfAccuracy adware"
X SurfBuddy rundll32 [path] sbuddy.dll"SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
U SurfChoice SCMan.exe"SCMan is a utility that can control services on WinNT from the command line. This utility can create
X Surfer lptt01 surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Surfer ml097e surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
U SurfHelper SurfHelp.exe"Related to SurfHelper - a free tool to remove popup windows
U SurfinGuard Pro winsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
U SurfSecret ss2-full.exe""House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray
X SurfSideKick Ssk.exe"SurfSideKick adware"
X SurfSideKick 2 Ssk.exe"SurfSideKick adware"
X SurfSideKick 3 Ssk.exe"SurfSideKick adware"
U SurfStream SurfStream.exe"Conceiva ""SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"""
X Surs awab.exe"PurityScan adware"
N Surveysa surveysa.exe"Found on Sony laptops
N suScheduler UCLauncher.exe"Scheduler for versions of ThinkVantage System Update (for software updates) found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks"
X Susp Susp.exe"VX2.Transponder parasite updater/installer related"
X SuspenzorPC GDC.exe"SuspenzorPC Czech rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
X susse hpsw.exe"LinkMaker adware"
X Sustem explorer.exe"Added by an unidentified VIRUS
X SustemUpdate explorer.exe"Added by an unidentified VIRUS
X SV00LSV SV00LSV.EXE"Added by the GRAYBIRD-C TROJAN!"
X SVA Player SVAplayer.exe"SVAPlayer parasite"
X Svc svc.exe"ClientMan parasite variant"
U SVC svchost.exe"ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X svc expseny.exe"Added by the PWS-ANG TROJAN!"
X SVC Service svcinit.exe"Added by the SINIT TROJAN!"
X SVC Service svcinit.exe"CoolWebSearch parasite variant"
X SVC Service svcpack.exe"CoolWebSearch Svcinit parasite variant"
X SVC Service svc32.pif"Added by the RBOT-ASC WORM!"
X SVC Socks mstaskm.exe"CoolWebSearch parasite variant"
X svc32 svc32.exeIdentified as a variant of the Banker-EQC/DLoader.GPJI malware
X svcdata.exe svcdata.exe"Added by the SPYBOT.ZIF WORM!"
X Svced Svced.exe"Added by the DELF.F TROJAN!"
X SvcH0st msexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
X SvcH0st SHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
X SvcH0st SVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
X SvcH0st WINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
X SVCH0ST spoo1sv.exe"Added by the VB-HF TROJAN!"
X SVCH0ST SVCH0ST.EXE"Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase ""o"""
X SvcH0st msnexploren.exe"Added by the TACTSLAY.B TROJAN!"
X SvcH0st sdhch.exe"Added by the TACTSLAY.B TROJAN!"
X SVCH0ST.EXE SVCH0ST.EXE"Added by the BANCBAN-HT TROJAN!"
X SVCH0TS sp00lvs.exe"Added by the LINEAGE-AZ TROJAN!"
X svchast svchast.exe"Added by the LINEAGE-AV TROJAN!"
X svchctrl svchctrl.exe"Added by the COBFINN TROJAN!"
X svchos svchos.exe"Added by the EZIBOT-B TROJAN!"
X svchosd [path to trojan]"Added by the BANCOS-BCX TROJAN!"
X SVCHOSI SVCHOSI.EXE"Added by the VBBOT-AA WORM!"
X SVCHOST svchost.exe"System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060"
X svchost svchost.exe"Added by many TROJANS amd WORMS
X SVCHOST mrowyekdc.exe"Added by the GOTORM WORM!"
X svchost Svch0st.exe"Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
X svchost [path to trojan]"Added by the HAZZER TROJAN!"
X svchost ADMAGIC.EXE"Added by the SMIBAG WORM!"
X Svchost winhost.exe"Added by the LOLAWEB.A TROJAN!"
X Svchost svchost.exe"Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X SVCHOST var.txt.exe"Added by the LDPINCH.C TROJAN!"
X Svchost svchosl.pif"Added by the INZAE.A or INZAE.B WORMS!"
X svchost [path] SETUP.EXE"Added by the SETCLO WORM!"
X SVCHOST scvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
X SVCHOST taskgmr.exe"Added by the MYTOB.F or MYTOB.H WORMS!"
X svchost olehelp.exe"Added by the BOOKMARKER.G TROJAN!"
X SVCHOST updater32.exe"Added by the RANTS.A WORM!"
X SVCHOST SPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
X SvcHost svchost32.exe"Added by the AGOBOT-TM WORM!"
X svchost svchost.exe"Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
X SVCHOST MDM.EXE"Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
X svchost [path to explorer.exe]"Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
X svchost rundll16.exe"Added by the STARTPA-PB TROJAN!"
X Svchost svchost.exe"Added by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer"
X svchost svchost.exe"Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
X svchost svchost.exe"Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
X svchost winhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
X Svchost svchots.exe"Added by the RBOT.ADK WORM!"
X svchost ying.exe"Constructor VC2000 malware"
X svchost inetinfo.scr"Added by the ODELUD WORM!"
X SVCHOST svchost64.exe"Added by the STARTP-G TROJAN!"
X svchost svchost.com"Added by the BANLOA-ABL TROJAN!"
X svchost win.exe"Added by the VBSAUTO-A WORM!"
U svchost svchost.exe"Infine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an ""svc"" subfolder"
X svchost logon.exe"Added by the SLEGON WORM!"
X svchost svcst.exe"Added by the AGENT-LIL WORM!"
X svchost svchost.exe"Added by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""MsDtds"" sub-directory"
X svchost windowsrx.exe"Added by the AGOBOT-MZ WORM!"
X SVCHOST SERVlCES.EXE"Added by the DELF-LF BACKDOOR! Note that the filename has a lower case ""L"" in place of an upper case ""i"""
X svchost Agent svchost.exe"Added by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""28463"" sub-folder"
X svchost connection monitor svchost32.exe"Added by a variant of the SDBOT WORM!"
X SVCHOST Generic application svchost.exe"Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X svchost Netware Manager svchost.exe"Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X SVCHost Protocol32 scvhost32.exe"Added by a variant of the IRCBOT TROJAN!"
X Svchost Service svchost.exe"Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help"
X Svchost Windows Remote Services svhost.exe"Added by the IRCBOT-IV WORM!"
X svchost.exe svchost32.exe"CoolWebSearch Svchost32 parasite variant"
X SVCHOST.EXE SVCHOST.EXE"Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X svchost.exe [path to executeable]"Added by the BANKER-MO TROJAN!"
X svchost.exe svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
X svchost.exe swchost.exe"Added by the SADELPHI-A TROJAN!"
X svchost.exe svchost.exe"Added by the VIRUT.CF WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3361"" subfolder"
X SVCHOST.EXE svchost.exe"Added by the SILLYFDC.BBI WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Conf"" sub-directory"
X svchost.exe svcnost.exe"Added by the MISLEAD-A TROJAN!"
X svchost1 svchost1.exe"Added by the AGOBOT.ZZ WORM!"
X SVCHost2 svchost2.exe"Added by the RBOT.BLC WORM!"
X SvcHost32 svchost32.exe"Added by the MIMAIL.I or MIMAIL.J WORMS!"
X svchost32.exe svchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
X svchost64 svchost64.exeAdded by the SDBOTER.G VIRUS!
X svchosta svchosta.exe"Added by the SNIFFER-I TROJAN!"
X svchostb svchostb.exe"Added by the SNIFFER-J TROJAN!"
X SvcHostDHCP svchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
X svchostdll.scr svchostdll.scr"Added by the BANCBAN-FM TROJAN!"
X SvcHosto v1rg1n.exe"Added by the AGOBOT-TK WORM!"
X svchostr svchostr.exeAdded by an unidentified WORM or TROJAN!
X svchosts svchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
X Svchosts SCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
X svchosts.exe svchosts.exe"Added by the AGOBOT-JN WORM!"
X svchosts.scr svchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
X SVCHOT SVCHOT.exe"Added by the QQROB-U TROJAN!"
X svchst svchst.exe"Added by the KBROY-C TROJAN!"
X svcinfo svcinfo.exe"Added by the CRYPTER.A TROJAN!"
X Svclhost svcchost.exeAdded by an unidentified WORM or TROJAN!
X SvcManager restore3.exe"Added by the AGENT-DSS TROJAN!"
X SvcManager [path to trojan]"Added by the ZALON-A BACKDOOR!"
X SvcManager mdmex2.exe"Added by the ZALON-B BACKDOOR!"
U svcmon svcmon.exe"PersonInspect surveillance software. Uninstall this software unless you put it there yourself"
X Svcnost.exe svcnost.exe"Added by the SELEX.B WORM!"
X Svconr Svconr.exe"WaveRevenue-lBann adware"
X Svcphpwin sslphp32.exe"Added by the AGOBOT-ABR WORM!"
X svcroot svcroot.exe"Added by the KEYLOG-AC TROJAN!"
X svcroot xffanl.exe"Added by the AGENT-BMF TROJAN!"
X svcshare winampXP.exe"Added by the FUJACKS-J VIRUS!"
X svcshare spoclsv.exe"Added by the FUJACKS-A VIRUS!"
X svcshare CTMONTv.exe"Added by the FUJACKS-AJ WORM!"
X svcshare nvscv32.exe"Added by the FUJACKS-Z WORM!"
X SvcSys [path to file]"Added by the BANCOS.Z TROJAN!"
X Svcsys Registry Manager svcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
X svcsys32 svcsys32.exe"Added by the AGOBOT-LL WORM!"
X svctask svctask.exe"Added by the CHUCKYB-A TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list