Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X System Juegs.exe"Added by the CULLER-C WORM!"
X System kernel8.exe"Added by the DLOADR-AOL TROJAN!"
X System kernelwind32.exe"Added by the VXIDL.FT TROJAN!"
X System Xsfr.exe"Added by the CULLER-D WORM!"
X System kernelwind64.exe"Added by the DLOADER.DJD TROJAN!"
X SYSTEM SystemFile.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X system ssclie.exe"Added by the AGENT.LW BACKDOOR!"
X system Winhelp.exe"Added by the IMAUT.CN WORM!"
X system kernel32.ini"Added by the SILLYFDC.CJ WORM!"
X System testtestt.exe"Added by the DWNLDR-ZLC TROJAN!"
X system Microsoft Office.exe"Added by the BANCBAN-LH TROJAN!"
X System IEXPL0RE.EXE"Added by the VB.KS WORM! Note the number ""0"" in the filename"
X system sysnet.exe"Added by the VETOR-J WORM!"
X system systemdb.exe"Barracuda Antivirus and Security Central rogue security software - not recommended
X System winipck.exe"Added by the RBOT-TK WORM!"
X System krln32.exe"Malware installed by different rogue security software including SpyKillerPro"
X system system64.exe"Added by the BANCBAN-PP TROJAN!"
X System antivirus.vbe"Added by the AUTORUN-AYI WORM!"
X SYSTEM RUNDLL16.exe"Added by the DELF-EW BACKDOOR!"
X System systemz.exe"Added by the VILSEL-B TROJAN!"
X System 64 Driver for Games sys64dvr.exe"Added by the SDBOT TROJAN!"
X System Analyzer lsass32.exe"Added by the SDBOT.CNI WORM!"
X System Applications Profile sap.exe"Added by the RBOT-QF WORM!"
X System Auth system52.exe"Identified as a variant of the Win32:Rizo-E malware"
X System Backup msystem.exeAdult content dialler
X System backup [random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted
X System Backup sysbcp32.exe"Added by the AGOBOT-NP BACKDOOR!"
X System Backup Services backups32.exe"Added by a variant of the RBOT WORM!"
X System Boot Check sysload3.exe"Added by the FUBALCA WORM!"
X System Boot Loader sysboot32.exe"Added by the SDBOT.PG WORM!"
X System Buffer Application buffer32.exe"Added by the SDBOT-UD WORM!"
X System Cache SysCache.exe"Added by an unidentified VIRUS
X System CGI Manager syscgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
U System Check "Rundll32.exe SysDll32.dll SystemCheck"
X system check updater.exeUnidentified adware downloader
X System Check win_klr32.exe"Added by the DELF-DRA WORM!"
X System Checking wasul.exe"Added by the RBOT.BHM WORM!"
X System Config BF3.EXE"Added by the SPYBOT-DT WORM!"
X System Config sysloadcnf.exe"Added by a variant of the SDBOT WORM! See here"
X System Config Boot syscgboot.exe"Added by the AGENT.VWU TROJAN!"
X System Config Manager crss.exe"Added by the AGOBOT.GH WORM!"
X System Config Manager smssl.exe"Added by the AGOBOT-ZJ WORM!"
X System Configuration iexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X System Configuration syscfg32.exe"Added by the MYTOB.EA WORM!"
X System Configurator32 SYSTEMCFG.EXE"Added by the AGOBOT-KS WORM!"
X system configure svchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X System Core Memory syscoremem.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X System CPL manager [random filename]"Added by the RBOT-SR WORM!"
X System CSRSS Patch scrtkfg.exe"Added by the RBOT-ADA WORM!"
X System Database administration systemDA.exe"Added by the DERDERO.B WORM!"
X System Database Administration Support Process sysdasp.exe"Added by the DERDERO.C WORM!"
X System DataBase Root sysdbroot.exe"Added by the QHOST-W TROJAN!"
X System DB Manager sysdbmg.exe"Added by an unidentified WORM or TROJAN! See here"
X System Defender WS[random characters].exe"System Defender rogue security software - not recommended
X System Device devices.exe"Added by the AGENT.AFIF WORM!"
X System Device Version systemdv.exe"Added by a variant of the RBOT WORM!"
X System Diagnostics sysdiag32.exe"Added by the SDBOT.GEN TROJAN!"
N System DLF cpqdiaga.exeCompaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
U System DLL Resources sysdll.exe"SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself"
X System Doctor Free systemdoc.exe"SystemDoctor rogue security software - not recommended
X System Document Application nmod.exe"Added by the SDBOT-ABB WORM!"
X System Document Application msdocument.exe"Added by the RANDEX.COX WORM!"
X System Document Application wins.exe"Added by the SDBOT.AUB WORM!"
X System Document Application winsvc32.exe"Added by the SDBOT-VA WORM!"
X System Download Manager SysMgr.exe"Added by the RBOT.CIG WORM!"
X System driver Messenger.exe"Added by the WOOTBOT.GI WORM!"
X System Drivers wingmt.exe"Added by the SDBOT-MG WORM!"
X System Drivers cpsq32.exe"Added by the SDBOT.AXH WORM!"
X System Drivers sysdrv32.exe"Added by the AGOBOT-ZX WORM!"
X System Efficiency Monitor mscedit32.exe"Added by the SDBOT.P TROJAN!"
X System Efficiency Monitor mscommand.exe"Added by the KWBOT.P WORM!"
X System Efficiency Monitor msedit32.exe"Added by the STEPH-B WORM!"
X System Efficiency Monitor svchostx.exe"Added by the KWBOT.E WORM!"
X System Error Notification senr32.exe"Added by the POISON-BT TROJAN!"
X System Event Manager secsvc.exe"Added by the RBOT.BMY WORM!"
X System Executable DLL Library EXECDLL32.exe"Added by the RANDEX.AZ WORM!"
X System Failure Statistic cnstat.exe"Added by the RBOT-LF WORM!"
X System File Drivers nvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
X System File Startup sys32.exe"Added by the RBOT.OTL WORM!"
U System Files Updater System Files Updater.exe"System Files Updater from Flyakiteosx ""will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"""
X system firewall makeini32.exe"Added by the AGOBOT-PS WORM!"
X System Firewall sysfirewall.exe"Added by the AGOBOT-ACY WORM!"
X System Firewalls commandprompt32.exe"Added by the RBOT.BJT WORM!"
X System Guard mhguard.exe"Added by the RBOT-AGU WORM!"
X System Handler LSASS.EXE"Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process
X system handler srvhandle.exe"Added by the REDPLUT VIRUS!"
X System handler Pandawas.exe"Added by the BHARAT.A WORM!"
X System Host scvhost.exe"Added by a variant of the RBOT WORM!"
X System Host Manager syshost.exe"Added by the BANWORM-C WORM!"
X System Host Service svchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
X System Information Manager Navcpe.exe"Added by the SDBOT-QB WORM!"
X System Information Manager Msbb.exe"Added by the SLINBOT.YR BACKDOOR!"
X System Information Manager iexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X System Information Manager mslog.exe"Added by the DELF.AKO TROJAN!"
X System Information Manager no.exe"Added by the SPYBOT.NO WORM!"
X System Information Manager syspass.exe"Added by the SDBOT-MO WORM!"
X System Information Manager win.exe"Added by the SDBOT-MU WORM!"
X System Information Manager windowsNt.com"Added by the SDBOT-ND WORM!"
X System Init systeminit.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X System Initialization msmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
X System Initialization payload.dat"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
X System IP systemip.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X System Kernal Support system.exe"Added by the SDBOT.BWV WORM!"
X System Kernel lsass.exe"Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
U System LifeGuard Scheduler Slsched.exe"System LifeGuard scheduler"
X System Loader systems.exe"Added by the AGOGBOT-FI WORM!"
X System Loader syscfg.exe"Added by the AGOBOT-BS BACKDOOR!"
X System Loaderap syst19b.exe"Added by the AGOBOT-AT BACKDOOR!"
X System Log Event csrss32.exe"Added by the AGOBOT-JI WORM!"
X System Management Service smsc.exe"Added by the RBOT-ANN WORM!"
X System Manager svchost.exe"Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X system manager System.exe"Added by the FORBOT-BO WORM!"
X System Manager winsrv32.exeAdded by an unidentified WORM or TROJAN!
X System Manager sysmng.exe"Added by the TAME-C WORM!"
X System Manager sysmgr.exe"Added by the IRCBOT.AGW BACKDOOR!"
X System Manager User Documents.exe"Added by the VB.GF VIRUS!"
X System Manager sysmngr.exe"Added by the IRCBOT.BAQ BACKDOOR!"
X System Manager ncvs32.exe"Added by a variant of the IRCBOT BACKDOOR!"
X System Manager Updates winsvc.exe"Added by the AGOBOT.AEM WORM!"
U System Mechanic Popup Blocker PopupBlocker.exe"Popup blocker part of Iolo System Mechanic utility suite"
U System Mechanic Popup Stopper Popupstopper.exe"Popup stopper part of Iolo System Mechanic utility suite"
N System Mechanic Professional Update [Incinerator.dll] SysMech4.exe /REREG: [path] Incinerator.dll"Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
U System Mechanic Startup Guard StartupGuard.exe"System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses
X SYSTEM MESSAGER wmisg.exe"Added by the MYTOB.ES WORM!"
X System Messaging Queue SMCSS.EXE"Added by a variant of the RBOT WORM!"
X System Messenger SYSMSG32.EXE"Added by the SPYBOT-DK WORM!"
X System Messenger32 systgmgr32.exe"Added by the SDBOT.DF WORM!"
X System Microsoft Core smc.exe"Added by the RIZO.A TROJAN!"
U System Monitor SYSMON.EXE"Comes with some Aopen motherboards. Monitors CPU temp
X System Monitor Sysmon16.exe"Added by the SDBOT TROJAN!"
X System Monitoring cute.exe"Added by the RAHIWI.A WORM!"
X System Monitoring Mooks.EXE"Added by the BHARAT.A WORM!"
X System Monitoring lsass.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
X System MScvb mscvb32.exe"Added by the SOBIG.C WORM!"
X System Net sys32.exe"Added by the FORBOT-FX WORM!"
X System Net Database sysnd.exe"Added by the RBOT-AAW WORM!"
X System Networking sysnet.exe"Added by the RBOT.API WORM!"
X System Power Managment svcnost.exe"Added by the DREF-I WORM!"
X System Presets [temp name].exe"Added by the HOSTINF-A WORM!"
X System Process csrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X System Process lsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X System Process svchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X System Process CSRSR.exe"Added by the AGOBOT-SQ WORM!"
X System Process Analization sysproc.exe"Added by a variant of the RBOT WORM!"
X System Process Analization Thread system.exe"Added by a variant of the RBOT WORM!"
X System Profile Regsrv.exe"Added by a variant of the OPTIX TROJAN!"
X System Protector lsascs.exe"System Protector rogue security software - not recommended
X System RAID Manager raid64.exe"Added by the AGENT-NNZ TROJAN!"
X System Reboot rebootsys.exe"Added by the RBOT-WU WORM!"
X System Redirect sysbho.exe"Downloader trojan
X System Registry Manager sysrgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
X System Restore svcnet.exe"Added by the TIBICK WORM!"
X System Restore Data [path] repcale.exe [path] beird.exe"Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
X System Scanner system.exe"Added by the AGOBOT-DI BACKDOOR!"
X System Security Checker ssc.exe"Added by the IRCBOT-WI TROJAN!"
X System Security Updaters vsmons.exe"Added by the RBOT-OW WORM!"
X System Service MSREXE.EXE"Added by the AML TROJAN!"
X system service spoolcrv.cplAdded by the INSPIR.11 TROJAN!
X System Service systems.exe"Added by the AGOBOT.VZ WORM!"
X System Service coderxt.exe"Added by the RBOT-ALD WORM!"
X System Service exp0lrer.exe"Added by a variant of the RBOT WORM!"
X System Service servicent.exe"Added by the RBOT-AJI WORM!"
X System service system.exe"Added by the BANCOS.AA TROJAN!"
X System Service msnwindows.exe"Added by the SPYBOT.YCL WORM!"
X System Service servicez.exe"Added by the RBOT-AOY WORM!"
X System Service msnxpexe.exe"Added by the RBOT-AUA WORM!"
X System Service teskmangr.exe"Added by the RBOT-AUV WORM!"
X System Service backup.exeAdded by the PACKBOT.AA WORM!
X System Service serious.exe"Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF)"
X System Service b4db0yz.exe"Added by the RBOT-CLO WORM!"
X SYSTEM service helper svchelper.exe"Added by the MONKBD-A WORM!"
X SYSTEM service helper syshelp.exe"Added by a variant of the MONKBD-A WORM!"
X System Service Manager lsmas.exe"Added by the AGOBOT-IK BACKDOOR!"
X System Service Manager norton.exe"Added by the GAOBOT.AJE WORM!"
X System Service Manager Device svho.exe"Added by the RBOT.GCG BACKDOOR!"
X System service** pokapoka**.exe"EliteBar adware - where ** represents the numbers 61 to 79"
X System service78 [path to file]"Added by the ELITEBAR-T and ELITEBAR-U TROJANS!"
X System service79 [path to file]"Added by the ELITEBAR-V TROJAN!"
X System Services [random file name]"Added by a variant of the RBOT WORM!"
X System Services connection.exeAdded by an unidentified WORM or TROJAN!
X System Services svcsenes.exe"Added by a variant of the RBOT WORM!"
X System Services svcsenes32a.exe"Added by the RBOT-AFG WORM!"
X System Services ssms.exe"Added by a variant of the RBOT WORM!"
X System Services Monitor server.exe"Bifrost malware"
X System Servlce live.exe"Added by the IRCBOT-GX WORM!"
X System Session Manager smss.exe"Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
X System settings burndl32.exe"Added by the SDBOT-ZO WORM!"
X System Setup rpcxcmod.exeAdded by an unidentified WORM or TROJAN!
X System Soap Pro soap.exe"System Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoided"
X system spool syspools.exe"Added by the DREF-T WORM/VIRUS!"
X System Spooler Subsystem lssas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
U System startup charmapx.exeOnly required if using an oriental language
X System Startup Voltio.exe"Added by the RBOT.NJ WORM!"
X System Startup kimochi.exe"Added by a variant of the RBOT WORM!"
X System Startup sys.exe"Added by a variant of the IRCBOT TROJAN!"
X System Startup Manager smcss.exe"Added by the RBOT.AMD WORM!"
X System Stats SystemStats.exe"Added by a variant of the WOOTBOT WORM!"
X System Support syscfg.exe"Added by the RBOT-AGQ WORM!"
X System Support system32.exe"Added by the RBOT-AHA WORM!"
X System Support syssql.exe"Added by the RBOT-AUH WORM!"
X System Support torrent.exe"Added by a variant of the RBOT WORM!"
X System Task Manager taskmrg.exe"Added by a variant of the SPYBOT WORM! See here"
X System Terminal SYSTEM2.EXE"Added by the SPYBOT-BZ TROJAN!"
X System time updator CSysTime.exe"Added by the RANDEX.S WORM!"
X system tool sysguard.exe"Antivirus System Pro rogue security software - not recommended
X System Toolkit Systools.exe"Added by the RONOPER-G WORM!"
X System Tray msccn32.exe"Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process"
X System Tray systray.exe"Added by the FAN-A WORM! Note - the valid Microsoft systray.exe is normally located in %System% and will only run at startup on Win9x/Me systems. This one is located in %Windir%"
X System Tray Monitor tray.exe"Added by the RBOT.UXR WORM!"
X System Tray Services spooles32.exe"Added by the AGOBOT.ZH WORM!"
X System Tray32 SysTray32.exe"Added by the REPAD WORM!"
X System Unix syscfg32.exe"Added by the RBOT-ZD WORM!"
X system updata updata.exe"Added by the LINEAGE-C TROJAN!"
X System Update [filename].exe"CoolWebSearch parasite variant"
X System Update [random filename]"Added by the KORGO.W or KORGO.X WORMS!"
X System Update wupdmgr.exe"Added by the SOROMO-A TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list