Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X userd systems.com"Added by the OUTLAW-A WORM!"
N UserFaultCheck dumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
X Userfile Sharing Serv usnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Userfile Sharing Server usnserv.exe"Added by a variant of the IRCBOT TROJAN!"
X Userinit lsass.exe"Added by the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Program Files%\Common Files%\System"
X userinit winlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X userinit smss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X userinit choo_003956f4"Added by the PEED.16896 TROJAN!"
X userinit ntos.exe"Added by the AGENT-ECU TROJAN!"
X Userinit cologsver.exe"Added by the DROPPER.DJO TROJAN!"
X UserInit StartUp rpcxuisu.exe"Added by a variant of the SDBOT WORM!"
X userinit.exe userinit.exe"Added by the HAXDOOR-DP TROJAN!"
X userint32 userint32.exe"Added by an unidentified TROJAN via an Instant Message that says
X USERINTERFACE REPORT3R M0USE.exe"Added by the MYTOB.HS WORM!"
X Userinterface Reporter fuuuucktttttt.exe"Added by the MYTOB-DK WORM!"
X Userinterface Reporter srv32.exe"ISTBar adware"
X UserSystem [filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
X userun32 userun32.exe"Added by the LYDRA-B TROJAN!"
X ushli sscbltqu.exeObtained from an MP3 search list site. Also generates random processes on reboot
U USIUDF_Eject_Monitor USISrv.exe"Added by Ulead DVD Moviefactory. This program monitors your DVD or CD drives and alerts when you eject the media or have no media present"
X usnsvc.exe usnsvc.exe"Added by the SPYBOT.AMD WORM!"
X UsrClassEx UsrClassEx.exe"Added by the AGENT-KPU TROJAN!"
X usrgtway.exe syswrun4x.exe"Added by the MITGLIEDER.E TROJAN!"
X UsrManagementConf umcss.exe"Added by the IRCBOT-W TROJAN!"
N USRobotics 802.11g Wireless Network Utility USRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
N Usrobotics Online Registration ??Pop-up reminding customers to register their products online at US Robotics
Y USRpdA USRmlnkA.exeModem driver files from US Robotics
X Usrr rncr.exe"PurityScan adware"
X Usrr rpen.exe"PurityScan adware"
? USRSTA USRSTA.exe"Wireless Card controller. What does it do and is it required?"
? USRSTA.EXE USRSTA.EXE"Wireless Card controller. What does it do and is it required?"
X Ussi rwsa.exe"PurityScan adware"
X Ussi wnscpit.exe"PurityScan adware"
N USSShReg USSSHREG.EXERegistration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
U UStorag ustorage.exe"U-Storage is application software running under Microsoft Windows
N Ustorage Ustorage.exe"Maintenance tool (enable security functions) for a USB drive from Pretec"
X utasvc "rundll32.exe utasvc.dllstart"
X UtilisateurSur SysRep.exe"UtilisateurSur
X UtilitiesAndSoftware "rundll32.exe MSA64CHK.dllDllMostrar"
? Utility Ping UTILIT~1.EXE"??"
U Utility Tray sistray.exeSystem Tray icon for SiS based graphics. Located in %System%
N UtilityPro UtilityPro.exe"IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions"
Y UTILsInst N/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
N Utopia Angel Angel.exe"Calculator for the online Utopia game"
N uTorrent uTorrent.exe"µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent
N uTorrent.exe uTorrent.exe"µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent
X uvnx uvcx.exe"Added by the DLOADR-AWF TROJAN!"
X uvnx uvnx.exe"Added by the SMALL.CUL TROJAN!"
N UVS10 Preload uvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
N UVS11 Preload uvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
N UVS12 Preload uvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
X uwa6pcw uwa6pcw.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
X uwa7pcw uwa7pcw.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
X uwas6cw uwas6cw.exe"Part of the WinAntiSpyware 2006 rogue spyware remover - not recommended
X uwas7cw uwas7cw.exe"Part of the WinAntiSpyware 2007 rogue spyware remover - not recommended"
X uwyrl uwyrl.exe"Added by the PHEL.A TROJAN!"
X uwyw.exe yujixit.exe"Added by the SDBOT.BGB WORM!"
X uz uz.exe"Added by the AGENT-GGH WORM!"
? v WMPVer.EXE"Dritek System Inc. 3D Mouse related. Is it required?"
U V.92 Modem On Hold Ltmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
U V0220Mon.exe V0220Mon.exe"Creative Live! Cam Console Auto Launcher"
U V0230Mon.exe V0230Mon.exe"Creative Live! Cam Console Auto Launcher"
Y V0250Mon.exe V0250Mon.exePart of Creative Webcam Launcher
Y V128IID "Rundll32.exe v128iitw.dll STB_InitTweak"
? V128IITV ??"Loads drivers for some STB graphics cards. May be related to such a card with a TV out option?"
? V66SHELL V66SHELL.EXE"It looks to be part of the display driver set for ASUS V3800
U va10key va10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
X VaCtrls v7"Downloader
Y Vade Retro Outlook Express Vaderetro_oe.exe"Vade Retro anti-spam software for Outlook Express from GOTO software products"
Y VAGCtrl VAGCTRL.EXE"Vexira Antivirus - virus scanner from Central Command"
X Vagiconline vadaSq.exe"Added by the SDBOT-TD WORM!"
Y VAGuard VAGNT.exe"Vexira Antivirus - virus scanner from Central Command"
U VAIO Action Setup (Server) VAServ.exe"Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera
U VAIO Recovery PartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
U VAIO Update 2 VAIOUpdt.exeRelated to Sony Vaio Update service
X ValidData [path to trojan]"Added by the RANKY.H TROJAN!"
X valuename svchosts.exe"Added by a variant of the SDBOT WORM!"
X ValueS0ft [random filename]"Added by a variant of the SPYBOT WORM! See here"
X ValueX [random filename]"Added by the IRCBOT.EE TROJAN!"
X VasddwDg zxXZwd.exe"Added by the SDBOT-SN WORM!"
X vb6 vb6.exe"Added by the MUGLY.D WORM!"
X vbcdtm [random filename]"Added by a variant of the SLAPER TROJAN!"
X vbe [random name].vbe"Added by the UISGON-A WORM!"
X vbe win.vbe"Added by the LOSESLP-A WORM!"
X VBouncer VirtualBouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VbouncerDL VbouncerInner****.exe [* = random char]"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VbouncerDL VBouncerInner.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VBS.Ipnuker@mm [worm filename].vbs"Added by the NUKIP WORM!"
X VBS_AUTO_UPDATE 0548656X.vbs"Added by the GORMLEZ-A WORM!"
X VBundleOuterDL BundleOuter.EXE"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X vbwg cute aaa.exe"Added by the VB-DZG TROJAN!"
X vbwq cute winnt.exe"Added by the MADAG.A WORM!"
X VB_run comctl_32.exeDubious downloader from densmail.com
X VC5MediaPlayer [path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
N VC5Play VC5Play.exe"Virtual CD drive emulator - version 5. Available via Start -> Programs"
N VC6play VC6Play.exe"Virtual CD drive emulator - version 6. Available via Start -> Programs"
N VC7Play VC7Play.exe"Virtual CD drive emulator - version 7. Available via Start -> Programs"
N VC7Player VC7Play.exe"Virtual CD drive emulator - version 7. Available via Start -> Programs"
U VC9Player VC9Play.exe"Virtual CD from H H Software GmbH. ""With Virtual CD
X VCatch Vcatch.exe"CommonSearch Vcatch - ""antivirus"" software which actually bundles spy/adware itself!"
X VCatch Premium VCatchpre.exe"VCatch antivirus. Considered spyware itself - see here"
X vcbbjf keepSafe.exe"Added by the KILLAV.KAX TROJAN!"
X vccacA sdaxzl.exe"Added by the SDBOT-RP WORM!"
N VCDPlayer VCDPlayer.exe"Virtual CD drive emulator. Available via Start -> Programs"
N vcdplayx vcdplayx.exe"CD emulation part of GameDrive & VirtualDrive from Farstone. Not required as starting these programs load this automatically"
U VCDTower VCDTower.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
? VCDWATCH VCDWATCH.EXE"Confirmed as Voyetra CD Watcher as it was found in a Compaq/Voyetra/AS2 directory but what does it do?"
X vcmicrec msccsed.exe"Added by the MAILBOT-CE TROJAN!"
X VCMnet11 VCMnet11.exe"Windows AFA Internet Enhancement - a browser hijacker
X VCS Host vcshost.exe"Added by the RBOT-FKT WORM!"
N VCSPlayer vcsplay.exe"Virtual CD drive emulator. Available via Start -> Programs"
X VCXD Settings phqg.EXE"Added by the RBOT.BRF WORM!"
U VC_Log keylog.exe"PaqKeylog is a surveillance software program that logs keystrokes and can run in stealth mode. Uninstall this software unless you put it there yourself"
X Vdat Update lalaa.exe"Added by a variant of the RBOT WORM!"
? VDI Manager (HP) HPO0VDX05.exe"HP (Hewlett-Packard) related. Now - what does it do?"
U VDrive2 WebLifeDisk.exe"EarthLink WebLife Disk - ""Consumers can quickly save files from their desktop into WebLife Disk
N vdtask vdtask.exe"Program part of GameDrive & VirtualDrive virtual CD/DVD drive emulators from Farstone. Not required as starting these programs load this automatically"
N Vegas Palms - Launcher Launcher.exe"Vegas Palms on-line cassino"
X VeiligheidAgent pgs.exe"VeiligheidAgent
X veja_fotos.exe veja_fotos.exe"Added by the MDROP-F TROJAN!"
X Vekio Startups Pnksvc32.exe"Added by the AGOBOT.AJG WORM!"
X VelocidadSimple scrmain.exeVelocidadSimple rogue optimization utility - not recommended
U VentaDrv vfdrv32.exe"Related to VentaFax Voice - send and receive black-and-white or color faxes
U Venturi Configurator ventcfg.exe"Venturi Wireless mobile broadband configuration utility"
U Veo Velocity Connect stim11.exeSupport software for the Veo Velocity Connect webcam
U Veoh VeohClient.exe"Veoh lets you share your video with other internet users"
U VERBATIM STORE 'N' G verbatim store 'n' go.exe"Loads the driver for the Verbatim Store'n'Go PRO USB Flash Drive - reportedly required only on systems running Windows 98 and Millennium"
X Verif vxst.exe"Added by the NOPIR.B WORM!"
X Verificador do sistema cssrs.exe"Added by the MOCON WORM!"
X Veritas Patch veritas.exe"Added by the RBOT-XT WORM!"
N Verizon Control Pad cpad.exe"Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience"
? Verizon Custom Uninstall Tracking InstallHelper.exe"Verizon related installation tracker. What does it do and is it required?"
U Verizon Online Support Center matcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
U VerizonServicepoint.exe VerizonServicepoint.exe"Part of Verizon Online Support Manager"
X vern16.dll regsvr32.exe vernn16.dll"DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""vernn16.dll"" file is found in %System%"
U versato versato.exe"""Hot"" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards"
X verse verse.exe"Added by the STAP-C WORM!"
X Version Version.exe"JRAUN adware variant"
X Version manage.exe"JRAUN adware variant"
X version [random].exe"DealHelper adware"
Y Vet Alert vetmsg9x.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software"
Y Vet Alert VETMSG.EXE"Computer Associates Vet Anti-Virus software"
Y Vet Start Up vet98.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system
Y Vet Start Up vet32.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system
Y VetAlert VETMSG.EXE"Computer Associates Vet Anti-Virus software"
U VetTray vettray.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. System Tray quicklaunch access
X VFW Encoder/Decoder Settings RUNDLL32.exe MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X VGA Startup vgacard.exe"Added by a variant of the RBOT WORM!"
X VgaDriver RsrVga32.exe"Added by the KEYLOG-AH TROJAN!"
X VGATune VGATune.exe"Added by the RBOT-AWM WORM!"
U VGAUtil G-VGA.exe"Gigabyte VGA Utility - access card options (application needs to be run at startup
X vhost host.exe"Peppi adware"
X Vhosts Protection vhosts.exeAdded by an unidentified WORM or TROJAN!
N vid Vid.exe"""Logitech Vid™ is the fast
X vid32cntl vid32cntl.Exe"Added by the CRYPTER.A TROJAN!"
N Vidalia Vidalia.exe"Vidalia is a cross-platform GUI controller for the Tor anonymityn package. Using Vidalia
X vidcntl vidcntl.Exe"Added by the CRYPTER.A TROJAN!"
X Vidcompat Vidcompat.exe"Added by the GEMA TROJAN!"
X vidctrl vidctrl.exe"Delfin Promulgate adware variant"
X Video explored.exe"Added by the GAOBOT.RF WORM!"
X Video winamp32.exe"Added by the AGOBOT-NG WORM!"
X Video Camera Frog wcamfrog.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Video Card Driver (do not remove) tsasi.exe"Added by the SPYBOT-EF WORM!"
X Video Display VDISP.EXE"Added by the AGOBOT-KE WORM!"
X Video Driver svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Video Driver Msregdrv32.exe"Added by the SPIGOT BACKDOOR!"
X Video Lan Player VideoLanPlayer.exe"Added by the RBOT-MY WORM!"
X Video Manager videomgr.exe"Added by the PANDEM.C WORM!"
X Video Multimedia Driver ndrives32.exe"Added by the RBOT-DK WORM!"
X Video Poes winii.exe"Added by the AGOBOT-CP WORM!"
X Video Proces winaps.exe"Added by the AGOBOT.HD WORM!"
X Video Process sysconf.exe"Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!"
X Video Process MS32x16.exe"Added by the RBOT.RH WORM!"
X Video Process netsvcs.exe"Added by the AGOBOT.LH WORM!"
X Video Process MSlti64.exe"Added by the AGOBOT.UE WORM!"
X Video Process [random filename]"Added by the RBOT-LM WORM!"
X Video Process winasp.exe"Added by the AGOBOT-IS WORM!"
X Video Process msn5.exe"Added by the AGOBOT-TW WORM!"
X Video Process MStli32s.exe"Added by the RBOT-GAD WORM!"
X Video Process wincert32.exe"Added by the AGOBOT.JT WORM!"
X Video Process ntsystm.exe"Added by the GAOBOT.ZX WORM!"
X Video Process Nivopsvc.exe"Added by the AGOBOT-GT WORM!"
X Video Process wincrt32.exe"Added by the AGOBOT-GR WORM!"
X Video Process Avg123.exe"Added by the AGOBOT-MS WORM!"
X Video Process Navapsvcc.exe"Added by the SPYBOT-CW WORM!"
X Video Processor msconfsys88.exe"Added by the AGOBOT-QG WORM!"
X Video Proes winaii.exe"Added by the AGOBOT-FH WORM!"
X Video Services explore.exe"Added by the GAOBOT.GL WORM!"
X Video Services videol_32.exe"Added by the AGOBOT-DM WORM!"
X Video Services sys32.exe"Added by the AGOBOT.PS WORM!"
X Videocntl Videocntl.exe"Added by a variant of the GEMA.D TROJAN!"
X VideoDriver [filename]"Added by the GSPOT20.A TROJAN!"
X VideoDriver videodrv.exe"Added by the MIMAIL.A WORM!"
X VideoDriver gspotbot.exe"Added by the SPIGOT.C TROJAN!"
X VideoDriverHook vmdriver.exe"Added by the BCKDR-PSS BACKDOOR!"
X Videool32 VIDEOL32.EXE"Added by the AGOBOT.EC WORM!"
X videopci videopci.exe"Added by the AGENT-W TROJAN!"
X videoporno.exe videoporno.exePremium rate adult content dialer
Y Videora Videora.exe"Video Holding personal video downloading program"
X VidiaDrivers [path to trojan]"Added by the RANKY.U TROJAN!"
X vidmon VIDMON.EXE"Delfin Media Viewer adware related"
X Vido Pes vmwa32.exe"Added by the AGOBOT-GU WORM!"
N VidSvr vidsvr.exeMS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X vietato.exe vietato.exeAdult content dialler
X VIEW POINT DRIVERS phqghum.exe"Added by the RBOT.BRX WORM!"
X VIEW POINT DRIVERS FOR WIN32 phqghu.exe"Added by a variant of the RBOT WORM!"
U Viewbar Viewbar.exe"Agloco Viewbar is a small toolbar that rests on the bottom of your screen or browser window while you surf the Internet. The Viewbar software is what enables AGLOCO to collect the money you are earning while browsing the Internet"". Get paid for browsing but you must consent to them collecting your personal information"
N ViewMgr ViewMgr.exe"Viewpoint Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL
U ViewpointPhotosDeviceConnect FotomatDeviceConnect.exe"Related to Viewpoint which is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything ""bad"". This will change from what we know in 2006 according to this article. You can remove it via Start -> Settings -> Control Panel -> Add/Remove Programs list..."
U ViGlance ViGlance.exe"ViGlance (Windows 7 SuperBar for XP) adds a Windows 7 style SuperBar for Windows XP users and can be loaded at boot time or started manually"
U ViivMonitor ViivMonitor.exe"Related to Intel Media Share Software. ""Stream or download media files from your Intel® Core®2 Processor with Viiv® technology-based PC"""
? Vinny ??"??"
U ViOrb ViOrb.exe"ViOrb (Vista Start Button for XP) adds a Vista style Start Button for Windows XP users and can be loaded at boot time or started manually"
X vipantispyware vipantispyware.exe"VipAntiSpyware rogue spyware remover - not recommended"
X VirRL2009 VirRL2009.exe"VirusResponse Lab 2009 rogue security software - not recommended"
X Virscanner smss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list