Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X System Update [random filename]"Added by the SOROMO-A TROJAN!"
X System Update wauluclt.exe"Added by the SDBOT.EF WORM!"
X System Update [path to trojan]"Added by the AUTOTROJ-D TROJAN!"
X System Update mssetupconf.exe"Added by the RBOT.DLC WORM!"
X System Update Application msbuffer.exe"Added by the SDBOT.AFF WORM!"
X System Update Service wmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
X System Update Service winupd32.exe"Added by the ADTODA-A TROJAN!"
X System Update Service system.pif"Added by the RBOT-ALL WORM!"
X System Update Service update.pif"Added by the SPYBOT.WOE WORM!"
X System Update Service wmiprvsv.exe"Added by the AGOBOT.YG WORM!"
X System Update Service csrss32.exe"Added by the AGOBOT-HI WORM!"
X System Update2 explorer.exe"Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X System Update2 services.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X System Update2 svchost.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X System Update2 system.exe"Added by the AUTOTROJ-C TROJAN!"
X System Update2 taskman.exe"Added by the AUTOTROJ-C TROJAN!"
X System Update2 taskmon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate Win98/Me file of the same name which is located in %Windir% as this version is located in %System%. It is not normally found on a WinXP system"
X System Update2 update.exe"Added by the AUTOTROJ-C TROJAN!"
X System Update2 webcheck.exe"Added by the AUTOTROJ-C TROJAN!"
X System Update2 wininet.exe"Added by the AUTOTROJ-C TROJAN!"
X System Update2 winlogon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process
X System Update2 winspool.exe"Added by the AUTOTROJ-C TROJAN!"
X System Update2 wupdmgr.exe"Added by the AUTOTROJ-C TROJAN!"
X System Updated svchoes.exe"Added by the RBOT-ASF WORM!"
X System Updater Machine crhwss.exe"Added by the CIADOOR-DQ TROJAN!"
X System Updater Machine system.exe"Added by the CIADOOR.GN BACKDOOR!"
X System Updater Process wmiprvsw.exe"Added by the AGOBOT-IL WORM!"
X System Updater Service wmiprvsw.exe"Added by the GAOBOT.AFC WORM!"
X System Updates winsci.exe"Added by a variant of the RBOT WORM!"
X System Updates szwi.exe"Added by the RBOT-AXE WORM!"
X System Updates unve.exe"Added by the RBOT-AWG TROJAN!"
X System Updates wmkl.exe"Added by the RBOT-AYJ WORM!"
X System Updates 4 mssysfix.exe"Added by the RBOT-ADU WORM!"
X System Updates Manager winserv32.exe"Added by the AGOBOT-AGA WORM!"
X System Updates Service updates.pif"Added by the RBOT-AMA WORM!"
X System Uptime Server SYSENTRY.EXE"Added by the RBOT.LK WORM!"
X System Uptime Server SYSENTRY32.EXE"Added by the RBOT.LK WORM!"
X system xp acdsee demo.exe"Added by the SALGA.A WORM!"
X System-Config msptmf32.com"Added by the LIOTEN.FA WORM!"
X System-Service EXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
X System-Stat systats.exe"Added by the SDBOT.RA WORM!"
X system. system..exe"Added by the OPTIXPRO.13.C TROJAN!"
X system... system...exe"Added by the OPTIXPRO.13.C TROJAN!"
X System.exe System.exeAdded by various WORMS and TROJANS!
X system.exe system.exe"Added by the JAMPORK.E WORM!"
X system.exe system.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %WINDIR%\pchealth\helpctr\binaries"
X System132 Csrtss.exe"Added by the LANFILT-I TROJAN!"
X system16 system16.exe"Added by the BANCBAN-OB BACKDOOR!"
X system23 notPad.exe"Added by the ESTEEMS.D TROJAN!"
X System32 system.exe"Added by the BUSHTRO122 TROJAN!"
X System32 System32.exeAdded by any number of WORMS or TROJANS!
U System32 sysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
X System32 "system321.exe"
X system32 NeT-BoT.exe"Added by the AGOBOT-LJ WORM!"
X System32 lsasss.exe"Added by the RBOT-XW WORM!"
X System32 crsvvc.exe"Added by the RBOT.BLY WORM!"
X system32 QQGame.exe"Added by the QQPASS-AC TROJAN!"
X System32 [worm filename]"Added by the NAUTICAL-A WORM!"
X System32 winds32.exe"Added by the DWNLDR-HFY TROJAN!"
X System32 csrss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
X system32 lowinplay.exe"Added by the VB.FVJ TROJAN!"
U System32 sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
X System32 svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
X System32 PCI Manager syspci32.exe"Added by the RBOT-AFR WORM!"
X System32 Runtime StartUp sysrs.exe"Added by the AGOBOT.ANW WORM!"
X System32 Spool winint.exe"Added by the FORBOT-N WORM!"
X System32 TCP Manager systcpm.exe"Added by a variant of the RBOT WORM!"
X System32 TCP Manager systerm.exe"Added by the RBOT.AFD WORM!"
X System32 Temp Service systmp.exe"Added by the RBOT-AET WORM!"
X System32-Driver csrs32.exe"Added by the SDBOT-CP BACKDOOR!"
X system32.dll systeminit.exe"CoolWebSearch parasite variant - re-directing to your-search.info"
X system32.dll sysdll32.exe"CoolWebSearch parasite variant. Redirecting to wholeworldmarket.com
X system32.exe services32.exe"Added by a variant of the IRCBOT TROJAN!"
X system32.exe system32.exe"Added by the GRAYBIRD.P TROJAN!"
X System32BLSJ Agent System32BLSJ.exe"Added by the MDROP-BPT TROJAN!"
X System32Check [random].exe"Added by the CHAST-A TROJAN!"
X System32Dll DLL32SYS.EXE"Added by the SPYBOT-CZ WORM!"
X System32Ex System32Ex.exe"Added by the IRCCONTACT TROJAN!"
U System32kfvw sysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
X System32Root Gadu-Gadu.exe"Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu"
X system32WXBP Agent system32WXBP.exe"ARDAMAX.HR spyware"
X System33 FB_PNU.EXE"Added by the NICHELLO-A WORM!"
X system34.exe system34.exe"Added by the DWNLDR-FXY TROJAN!"
X System4224411 Virus"Added by the CAGER.A WORM!"
X System4224411 Systemdll.exe"Added by the YUSUFALI-B WORM!"
X system43.exe system43.exe"Added by a variant of the SDBOT WORM!"
X System51616 msnmsgesser.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
X System64 inet.exe"Added by the DENGLE-A TROJAN!"
X SystemAdministration Wincmp32.exe"Added by the ASYLUM TROJAN!"
U SystemAgent Sage.exe"""Microsoft Plus! System Agent automatically tunes your system
X SystemArmor SystemArmor.exe"SystemArmor rogue security software - not recommended
X SystemB MessengerStopper.exe"MessStopper adware"
X systemb systemb.exe"Added by a variant of the IRCBOT TROJAN!"
X SystemBackup mtx.exe"Added by the MTX VIRUS/WORM!"
X SystemBackup MicroLog.exe"Added by the MICROLOG.A TROJAN!"
X SystemBooster2009 sbr_updater.exe"SystemBooster2009 rogue system suite - not recommended
? SystemBoot ladies.htm"Unknown but sounds very suspicious??"
X SystemBoot Mshta.exe ...filename.htaAdult content dialler
X SystemBoot services.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
X Systemboot msnsngr.exe"Added by a variant of the RBOT WORM!"
X SystemCheck Systemcheck.exe"Added by the LAVITS WORM!"
X SystemCheck services.exe"Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system"
X SystemCheck svchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
X SystemCheck SysCheckBop32.exe"WINBO adware"
U Systemcheck sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
X SystemChecker Syschk.exe"Added by the GALIL.F WORM!"
X SystemCleaner Clean2.exe"Added by the AUTORUN-AZE WORM!"
X SystemCleanerPRO sysclpro.exe"SystemCleanerPro rogue security software - not recommended
X SystemCONF98i SystemCONF98i.exe"Added by the GLITCH TROJAN!"
X SystemCop SystemCop.exe"SystemCop rogue security software - not recommended
X SystemData MBlocker.exe"Messenger Blocker rogue security software - not recommended"
X SystemDebug Sysdeb32.exe"Added by the SYSBUG TROJAN!"
X SystemDefender SystemDefender.exe"SystemDefender rogue spyware remover - not recommended
X SystemDevic devic.exe"Added by the MIMBOT.A WORM!"
X SystemDll SystemDll.exe"Added by the LOXOSCAM TROJAN!"
X systemdll.dll winsys32.exe"Added by the DELF.CP BACKDOOR!"
X systemdll32.exe systemdll32.exe"Added by the FEUTEL-F TROJAN!"
X SystemDoctor 2006 Free sd2006.exe"SystemDoctor rogue security software - not recommended
X SystemDoctor Free systemdoc.exe"SystemDoctor rogue security software - not recommended
X SystemDrive maxpaynow1.exe"Added by the TIBS.BKU TROJAN!"
X SystemDriver csrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
X SystemDriverCheck svchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
X SystemDriverLoad svchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
X systemdrv ms32sys.exe"Added by an unidentified WORM or TROJAN - most likely GAOBOT variant"
X SystemEmergency [various filenames]"CoolWebSearch Smartsearch parasite variant"
X SystemErrorFixer SysRep.exe"SystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
X SystemExplorer explore.exe"Homepage hijacker - file located in the ""Services"" folder in Common Files"
X Systemey systemey.exe"Added by the SLINBOT.JF BACKDOOR!"
X SystemFighter SystemFighter.exe"SystemFighter rogue security software - not recommended
X SystemFile SystemFile.exe"Added by the DULLDOOR-A TROJAN!"
X SystemFTP VSENMB.exe"Malware (ie
X SystemGent CVT.exe"Added by the BRONTOK-H WORM!"
X systemguard systemguard.exe"System Guard 2009 rogue security software - not recommended
? SystemGuardAlerter SystemGuardAlerter.exe"Part of the Iolo System Mechanic maintenance software. What does it do?"
X SystemGuardCenter SystemGuardCenter.exe"System Guard Center rogue security suite - not recommended
X SystemHelp "RUNDLL32.EXE SystemHper.dllInstall"
X SystemInit iservc.exe"Added by the FIZZER WORM!"
X systeminit systeminit.exe"Added by the SILLYFDC-AN WORM!"
X Systemiom Updater Systemiom.exe"Added by the SPYBOT.TY WORM!"
X SystemIron SystemIron.exe"SystemIron rogue security software - not recommended
X systemkernal.exe systemkernal.exe"Added by the AGENT-KPQ TROJAN!"
U SystemKey rundll32.exe [path] SystemKey.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X SystemLoad32 sysload32.exe"Added by the MIMAIL.E WORM!"
X SystemLoader sysldr32.exe"Added by the DOWNLDR-NS TROJAN!"
X SystemManager Sysman32.exe"Added by the DOWNLOADER-BW.B TROJAN!"
X SystemManager [random filename]"Added by the SETTEC ROOTKIT!"
X SystemMap32 Netisp32.vbs"Added by the REDIST.C WORM!"
X SystemMD md.exeHomepage hijacker
X SystemMessenger rundll32.exe [path] SystemMessenger.dll"Stealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X SystemMgr Ir32_a.exe"Added by the MAGANIA-OU TROJAN!"
X SystemMigration WinMedia.exe"Added by the KELVIR.EI WORM!"
X SystemMonitor Sysmon32.exe"Added by the AIDID.A WORM!"
X SystemNetwork NETSERV.EXEAdded by the NETCONTROL VIRUS!
X SystemNetwork sysnet.exe"Added by a variant of the RBOT WORM!"
X SystemNT SystemNT.exe"Added by the PWSVB-EG TROJAN!"
X SystemOPsv scrtvc32.exe"Added by a variant of the SPYBOT WORM!"
X SystemOptimizer2008 main.exe"SystemOptimizer2008 rogue optimization utility - not recommended
X SystemOrdnare SysRep.exe"SystemOrdnare
X SystemProcEvent [trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
X systemr d11host.exe"Added by the VB-GX TROJAN!"
X systemr gedit.exe"Added by the ADCLICK-AQ TROJAN!"
? SystemReg PROCES.EXE"??"
X SystemReg svchost.exe"Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X SystemReg WINREG.EXE"Added by the DEWIN.A TROJAN!"
X Systems scchost.exe"Added by the DAEMOZ.A TROJAN!"
X Systems svch0st.exe"Added by the MYDOOM.BI WORM!"
X Systems Systems.exe"Added by the BANKBOA-A TROJAN!"
X Systems itDDD.exe"Added by the DLOADER-PP TROJAN!"
X Systems sescmgr.exe"Added by the DWNLDR-GAH TROJAN!"
X Systems spoolsvc.exe"Added by the DLOADR-SW TROJAN!"
X Systems sysmon.exe"Added by the VIXUP-BI WORM!"
X Systems Backups windrives.exe"Added by the AGOBOT-RB WORM!"
X Systems Restart slchost.exe"Added by the MULTIDROP.C TROJAN!"
X Systems Restart spchost.exeAdded by an unidentified WORM or TROJAN!
X Systems Restart "Rundll32.exe beem.dll DllRegisterServer"
X Systems Restart "Rundll32.exe snim.dll DllRegisterServer"
X Systems Restart "Rundll32.exe zolk.dll DllRegisterServer"
X Systems Restart "Rundll32.exe boln.dll DllRegisterServer"
X Systems Service drivex.exe"Added by a variant of the RBOT WORM!"
X systems usb driver Windows2.exe"Added by a variant of the RBOT WORM!"
U Systems.exe Systems.exe"Keyboard Spectator - monitoring software that creates records of everything people do on a computer
U systems.exe systems.exe"KGBSpy is a commercial surveillance software program. It logs keystrokes
U SystemSafe Syssafe.exe"System Safety Monitor - system monitoring tool with additional application firewalling"
X SYSTEMSars32 csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X SystemSAS System32.exe"Added by the KWBOT.C WORM!"
X systemscroot systembin.exe"Added by a variant of the RBOT WORM!"
X SystemSearch regedit.exe -s ie.reg"Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""ie.reg"" is located in the root folder (ie
X SystemSearch regedit.exe -s sys.reg"Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
X SystemSecurity zprot32.exe"Added by the AGENT-FK TROJAN!"
X SystemService msocfg.exePremium rate adult content dialler
X SystemService navchk.exePremium rate adult content dialler
X SystemService qservice.exePremium rate adult content dialler
X SystemService shman.exePremium rate adult content dialler
U SystemService nsserver.exe"NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X SystemSettingf TRUG.vbs"Added by the TRUG.B MACRO!"
U SystemSuite Task Manager MXTASK.EXE"vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro"
X SystemSv12 newmaxxsv234.exe"Added by the TIBS-TS TROJAN!"
X SystemSv121 n2ewma1xxsv234.exe"Added by the TIBS.TJ TROJAN!"
X SystemTasks filez.exeAdult content dialler
X SystemTasks sexypicz.exeAdult content dialler
X SystemTasks loaded.exeAdult content dialler
X SystemTools kernels32.exe"Added by the DLOADER-FC TROJAN!"
X SystemTools kernels1118.exe"Added by the SMALL.DGK TROJAN!"
X SystemTools kernels8.exe"Added by the FNG TROJAN!"
X SystemTools kernels88.exe"Added by the TIBS-PP TROJAN!"
X SystemTools testtestt.exe"Added by the DWNLDR-ZLC TROJAN!"
X Systemtra Systra.exe"Added by the LOVGATE-W WORM!"
X SystemTra CDPlay.EXE"Added by the LOVGATE.Z WORM!"
X SystemTra Video.EXE"Added by the LOVGATE.E WORM!"
U SystemTray SysTray.Exe"For Win9x/Me - System Tray Services. Provides the Volume Control
X SystemTray SystemTray.exe"Added by the BIGFOOT TROJAN! Note - this is not the legitimate systray.exe process"
X SystemTray SysTray.exe"Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
X SystemTray lsvhostwinlk.exe"Added by a variant of the SPYBOT WORM!"
X SystemTray mssgl2.exe"Added by a variant of the IRCBOT TROJAN!"
X SystemTray wekls4.exe"Added by a variant of the IRCBOT TROJAN!"
X SystemTray Windowsupd.exe"Added by a variant of the IRCBOT TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list