Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
N WhitephonePersonal WhitePhonePersonal.exe"WhitePhone Personal from Voice Commerce Group - ""provides free PC to PC calls globally and access to low cost calls to phones worldwide."" Free internet telephony utility using the VoIP (Voice over Internet Protocol). No longer appears to be available"
U Whitney2_S2P Scan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier
U WHITNEY2_XRX_S2P Scan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer
U WhitneyXerox_S2P Scan2pc.exeScan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer
U WHITNEY_S2P Scan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers
X Whvlxd Whvlxd.exe"Added by the ZAPCHAS-CS TROJAN!"
X whxpin service ssvsol.exe"Added by a variant of the SDBOT WORM!"
X wiascr wiascr.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
N WIAWizardMenu "RUNDLL32.EXE sti_ci.dll WiaCreateWizardMenu"
X widelink widelinke.exe"WideLink adware. File located in %Program Files%\widelink"
X Widnows Xp Web scan xpscan.exe"Added by a variant of the SDBOT WORM!"
X wifeman wifeman.exeUnidentified malware
X Wifi Boot wifiboot.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Wifi Booter wifibooter.exe"Added by the IRCBOT.ATH BACKDOOR!"
X Wifi Configuration wificonfig.exe"Added by the IRCBOT.AWB BACKDOOR!"
X Wifi Configuration! wificonfigs.exe"Added by the IRCBOT.AWB BACKDOOR!"
X Wifi Connection wificon.exe"Added by the SLENFBOT.AC WORM!"
X Wifi Connection! wificonnect.exe"Added by the IRCBOT.XEL BACKDOOR!"
X Wifi Debug wifidebug.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Wifi Loader wifiload.exe"Added by the IRCBOT.XEL BACKDOOR!"
X Wifi Loader! wifiloader.exe"Added by the IRCBOT.XES BACKDOOR!"
X Wifi Setup wifisetup.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X WiFix service [random filename]"Added by a variant of the SDBOT WORM!"
X Wiinamp [random].exe"Added by the IRCBOT-OH TROJAN!"
X WildFlics WildFlics.exe"Direct-B premium rate adult content dialler"
? WildTangent CDA "RUNDLL32.exe cdaEngine0400.dll cdaEngineMain"
U WildTangent Web Driver updater wcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
N Wildwire Monitor WWMon.exeThis places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
X Will I Ever anqbse.exe"Added by the SDBOT-TK WORM!"
N Willow Road WillowRoad.exeWillow Road Screen Saver
X WillPolo WillPolo.vbs"Added by the SOLOW.AF VIRUS!"
X wimpas wimpas.exe"Added by the AGENT2.FGG TROJAN!"
X win regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X win xwinxrpc32.exe"Added by the AGOBOT-MV WORM!"
X win xwinxrpc.exe"Added by the AGOBOT-MV WORM!"
X WIN ehshell.exe"Added by the MYTOB-CQ WORM!"
X WIN windows.exe"Added by the REATLE.C WORM!"
U win homesec.exe"Related to the Sentry Parental Controls software"
X Win Antispyware Center av.exe"Win Antispyware Center rogue security software - not recommended
X Win Antivir 2008 Win Antivir 2008.exe"Win Antivir 2008 rogue security software - not recommended
X Win Antivirus 2008 Win Antivirus 2008.exe"Win Antivirus 2008 rogue security software - not recommended
U Win Chimes winchi~1.exe"WinChimes - enhancement software for the system clock that runs in the system tray"
X Win Comm WinComm.exe"Added by the WINCOM TROJAN!"
X Win Command command32.exe"Added by the AGOBOT.XQ WORM!"
X Win Config winconfig.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Win CPU sysin.pif"Added by the RBOT-AXL WORM!"
X win ctl app wuctl.exe"Added by a variant of the SDBOT WORM!"
X Win Defrag windfrag.exe"Added by a variant of the SDBOT WORM! See here"
X Win Defrag! windefrag.exe"Added by a variant of the SDBOT WORM! See here"
X Win Defrags defrag.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Win Drivers SSL hpws.exe"Added by the IRCBOT.67098 WORM!"
X Win Drivers SSL TASKMAN4.exe"Added by a variant of the RBOT WORM!"
X Win Drivers SSL32 hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
X Win exe file managr crss.exe"Added by the RBOT.CCI WORM!"
X Win FTP wintftp.exe"Added by the SDBOT-KE WORM!"
X WIN HOST PROCESS WIN HOST PROCESS.EXE"Added by the KEYLOGGER.CLONE TROJAN!"
X Win I5oahder [worm filename]"Added by the AGOBOT-DS WORM!"
X Win INI 32 msrp32.exe"Added by the RBOT-FZC WORM!"
X Win l5oahder winampa.exe"Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
X Win Login winlogin.exe"Added by the RBOT-AWE WORM!"
X Win Microsoft 98 win14.exe"Added by the RBOT-AKX WORM!"
? win name stat.exe"??"
X Win Net Wks32 netwks32.exe"Added by the RBOT.AA WORM!"
X Win Patch ntldr.exe"Added by the SDBOT-GS WORM!"
X Win Process Updates winupdates.exe"Added by a variant of the SDBOT WORM!"
X Win Prosess0r [random filename]"Added by the RBOT-BIT WORM!"
X WIN prosessor16 [random filename].exe"Added by a variant of the SDBOT WORM!"
X Win Proxy32 Protocol bsvtem.exe"Added by a variant of the SDBOT WORM!"
X Win Secure Update [random filename]"Added by the RBOT-AGI WORM!"
X Win Security msw32.pif"Added by the RBOT-AQT WORM!"
X Win Security winsecure.exe"Added by the SLENFBOT.RD WORM!"
X Win Security 360 WinSecurity360.exe"Win Security 360 rogue security software - not recommended
X Win Server winserv.exe"Added by the IMISERV.A TROJAN!"
X Win Server Updt wupdt.exe"Added by the IMISERV.A TROJAN!"
X Win Server Updt winserver.exe"Added by a variant of the IMISERV TROJAN!"
X Win Server Updt pxckdla.exe"IEPlugin adware"
X Win SSL SP2s.exe"Added by the RBOT.BBI WORM!"
X Win startup mscfg32.exe"Added by the SPYBOT-AE WORM!"
X Win Startup WINCFG32.EXE"Added by the SPYBOT-CL WORM!"
X Win Sync montr winsyncupx.exe"Added by the RBOT.BYJ BACKDOOR!"
X Win TaskLoader msgmr.exe"Added by the MYTOB.L WORM!"
X win update wupda32.exe"Added by the SDBOT.J WORM!"
X win update wapdate.exe"Added by a variant of the RBOT WORM!"
X Win Update SysUpdate.exe"Added by the AGOBOT-TN WORM!"
X Win Update oleupdate.exe"Added by the AGENT-UY TROJAN!"
X Win Update msnmger.exe"Added by the RBOT-GDP WORM!"
X win update wupdate.exe"Added by the RBOT-P BACKDOOR!"
X Win Updater WINUPDATER.EXE"Added by the RBOT.IP WORM!"
X Win Updator Services ctfnom.exe"Added by a variant of the WOOTBOT WORM!"
X WIN USB 2.0 usbsystem.exeAdded by an unidentified WORM of TROJAN!
X WIN USB 2.0 winusb.exe"Added by a variant of the RBOT WORM!"
X Win USB 2.0 USB Driver HPPrint.exe"Added by the SPYBOT.DNB WORM!"
X WIN USB SUPPORT grxsrv.exe"Added by a variant of the RBOT WORM!"
X Win Validation Application DBExecCom.exe"Added by the VBSILLY-A WORM!"
X Win WinAmp winamp.exe"Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%. This file is located in %System%"
X win************* [* = random digit] win*************.exe [* = random digit]"WINBO adware"
X WIN-BUGSFIX WIN-BUGSFIX.EXE"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
X win-xp nvsc32.exe"Added by the BROPIA.N WORM!"
X win-xp winis.exe"Added by the BROPIA.N WORM!"
X win.exe win.exe"Added by the PODROP-C TROJAN!"
U win16.dll win16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself
X win23.exe win23.exe"Added by the BIFROSE.BSJ BACKDOOR!"
X Win2Drv [worm filename]"Added by the WINTOO WORM!"
X WIN32 WIN32.EXE"Added by the RATEGA TROJAN!"
X win32 Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
X win32 Setup_32.exe"Added by the EVILBOT.B TROJAN!"
X Win32 Win32.exe"Added by the ISRAZ.A WORM!"
X win32 winsrv32.exe"Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites"
X win32 WinSetup.exe"Added by the EVILBOT.B TROJAN!"
X Win32 system32.vbs"Added by the SWERUN VIRUS!"
X Win32 Game.exe.vbs"Added by the SCAFENE WORM!"
X Win32 arsetup.exeAdded by the SPAZBOX.A TROJAN!
X win32 winhost.exe"Added by the BROPIA.J WORM!"
X Win32 winnnit.exe"Added by a variant of the SDBOT WORM!"
X Win32 msnsrv.exe"Added by a variant of the SDBOT WORM!"
X Win32 sysmon.exe"Added by the MYTOB-HQ TROJAN!"
X Win32 zaq.exe"Added by the RBOT-GCE WORM!"
X Win32 Bios Winbios.exe"Added by the SEMAPI-A WORM!"
X Win32 Cnfg32 msconfgh.exe"Added by the MYTOB.NB WORM!"
X Win32 Configuration videosd32.exe"Added by the SDBOT.TT WORM!"
X Win32 Configuration dllhelp.exe"Added by the SDBOT.UL WORM!"
X Win32 Configuration mplayer.exe"Added by the FORBOT-BZ WORM!"
X Win32 Console cmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Win32 Critical File Win32.exe"Added by the RBOT-GUB WORM!"
X WIN32 DDOSSER dos.exe"Added by the KELVIR.F WORM!"
X Win32 Debug Manager Win32Debug.exe"Added by a variant of the WOOTBOT WORM!"
X Win32 Debug Manager microsoftupd.exe"Added by the RBOT-GRJ WORM!"
X Win32 Device Loader Win32ldr.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Win32 Driver svchosts.exe"Added by the FORBOT-FD WORM!"
X Win32 Driver sysmls.exe"Added by the MYTOB.JH WORM!"
X Win32 Drivers winlogons.exe"Added by the FORBOT-FG WORM!"
X Win32 DRK Driver wdrk32.exe"Added by the WOOTBOT.CY WORM!"
X Win32 exe file winstr32.exe"Added by a variant of the SPYBOT WORM!"
X Win32 Explorer Explorer32.exe"StartPa-MN homepage hijacker"
X Win32 Firewall Driver winfw.exe"Added by a variant of the RBOT WORM!"
X Win32 Firewall Drivers winfirewall.exe"Added by the WOOTBOT.GX WORM!"
X Win32 FireWire Driver CTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
X Win32 FRT Driver msfr32.exe"Added by the WOOTBOT.EJ WORM!"
X Win32 Help32 Service win32help.exe"Added by the DELBOT-U WORM!"
X Win32 Info windowsnfo.exe"Added by a variant of the IRCBOT TROJAN!"
X Win32 Information Service crsrs.exe"Added by the RINBOT.Y WORM!"
X win32 internet server winserver.exe"Added by the DERMON-D TROJAN!"
X Win32 Kernel core component Kernel32.pif"Added by the MOKS VIRUS!"
X Win32 Kernel Update win32update.exe"Added by the PROXY-BS TROJAN!"
X Win32 LSA Driver lsa.exe"Added by the FORBOT-FJ WORM!"
X Win32 Ms Auto Updater AutomsUPD.exe"Added by a variant of the RBOT WORM!"
X Win32 NDIS Ndiswin.exe"Added by the RBOT.AMG WORM!"
X Win32 NDIS Driver xpndis.exe"Added by a variant of the RBOT WORM!"
X Win32 NDIS Driver Ndistcp.exe"Added by the WOOTBOT.EU WORM!"
X Win32 Network Driver crss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Win32 NT Adv Services taskmngr.exe"Added by the RBOT-ADE WORM!"
X Win32 nvc nvcva.exe"Added by the RBOT-ABF WORM!"
X Win32 NVIDIA Driver MSPMSPSU.EXE"Added by a variant of the WOOTBOT.Y WORM!"
X win32 regedit msn32.exeAdded by an unidentified WORM or TROJAN!
X Win32 Rundll Loader Rundll32.exe"Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!"
X Win32 Secure msconfigsvc.exe"Added by a variant of the SDBOT WORM!"
X Win32 Security Protocol secure32.exe"Added by the RBOT-ETI WORM!"
X Win32 Security Service crsss.exe"Added by the DELBOT-O WORM!"
X win32 security updates downloader tskmngr.exe"Added by a variant of the SDBOT WORM! See here"
X Win32 Service bazzi.exe"Added by the AHKER.E WORM!"
X Win32 Service [trojan filename]"Added by the AGENT-GBO TROJAN!"
X Win32 Services odbc32.exe"Added by the SPYBOT-EK WORM!"
X Win32 Services wuamngr.exe"Added by the SDBOT-N WORM!"
X Win32 Services Config winwkys.exe"Added by the RBOT.BKY WORM!"
X Win32 Services1 wuamngr1.exe"Added by the SDBOT-PV WORM!"
X Win32 Src Service win32src.exe"Added by the RBOT-SX WORM!"
X Win32 SSL Driver winssv.exe"Added by the FORBOT-BH WORM!"
X Win32 Svchosts Driver svchosts.exe"Added by the FORBOT-FO WORM!"
X Win32 System Kernel winservice.exe"Added by the SDBOT.KIN WORM!"
X win32 system server winserver.exe"Added by the DERMON-A TROJAN!"
X Win32 System Spool spoolsvc.exe"Added by the SDBOT.UK WORM!"
X Win32 Test bleatest.exe"Added by a variant of the RBOT WORM!"
X Win32 Update svchosts.exe"Added by a variant of the SDBOT WORM!"
X Win32 Update dl32.exeAdded by an unidentified WORM or TROJAN!
X win32 update service svchostt.exe"Added by a variant of the SDBOT WORM!"
X Win32 USB Driver winxpinit.exe"Added by the SDBOT.AA TROJAN!"
X Win32 USB Driver mvsecn.exe"Added by the FORBOT-BK WORM!"
X Win32 Usb Driver svhosint32.exe"Added by the FORBOT-BE or FORBOT-J WORMS!"
X Win32 Usb Driver usb32.exe"Added by the SDBOT-OV WORM!"
X Win32 Usb Driver AvpG.exe"Added by the FORBOT-BX WORM!"
X Win32 USB Driver rundll.exe"Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X Win32 USB2 wins32.exe"Added by a variant of the RBOT WORM!"
X Win32 USB2 Driver win32usb.exe"Added by the SPYBOT.DHV WORM!"
X Win32 USB2 Driver smsc.exe"Added by the SDBOT.FO WORM!"
X Win32 USB2 Driver svchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
X Win32 USB2 Driver sys32.exe"Added by the WOOTBOT.X WORM!"
X Win32 USB2 Driver sys32snd.exe"Added by the FORBOT-AN WORM!"
X Win32 USB2 Driver wind32.exe"Added by the FORBOT-AH WORM!"
X Win32 USB2 Driver winupdate.exe"Added by the AGOBOT.YE WORM!"
X Win32 USB2 Driver updatemgr.exe"Added by a variant of the FORBOT WORM!"
X Win32 USB2 Driver winsnd32.exe"Added by a variant of the SDBOT WORM!"
X Win32 USB2 Driver msn.exe"Added by the FORBOT-EX WORM!"
X Win32 USB2 Driver syscfg32.exe"Added by the FORBOT-R WORM!"
X Win32 USB2 Driver algg.exe"Added by the TIBS.BF WORM!"
X Win32 USB2 Driver usb2.exe"Added by the FORBOT-Y WORM!"
X Win32 USB2 Driver winusb32.exe"Added by the FORBOT-M WORM!"
X Win32 USB2.0 Driver 386.exe"Added by the IRCBOT.D WORM!"
X Win32 USB2.0 Driver rundll16.exe"Added by the WOOTBOT.H WORM!"
X Win32 USB2.0 Driver w32usb2.exe"Added by the SPYBOT.DN WORM!"
X Win32 USB2.0 Driver service.exe"Added by the SDBOT-QF WORM!"
X Win32 USB3 Driver win32tool.exe"Added by a variant of the RBOT WORM!"
X Win32 Wmls Driver winitr32.exe"Added by the WOOTBOT.B WORM!"
X Win32 Word Services msword32.exe"Added by a variant of the RBOT WORM!"
X win32.exe win32.exe"Added by the STARTPAGE TROJAN!"
X Win32.exe Win32.exe"Added by the AWQ.A TROJAN!"
X Win32.Exploit.mzH mzrun.exe"Added by the PAINTER TROJAN!"
X Win32.Trojan.Downloader netstat2.exe"Added by the PAINTER TROJAN!"
X win3208022-1336687 win3208022-1336687.exe"Added by the VB-CFG TROJAN!"
X Win32BaseServiceMOD Wintask.exe"Added by the NAVIDAD WORM!"
X win32beta win32sys4.exe"Added by the BANKER-DA TROJAN!"
X win32clf win32clf.exe"Added by an unidentified VIRUS
X win32debug win32debug.exe"Added by the GUDEB WORM!"
X Win32DLL Win32DLL.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
X Win32dll Win32dll.exe"Added by the BANPAES TROJAN!"
X WIN32DS clienttimer.exe"Eziin adware"
X Win32G Kernel32.com"Added by the ESTRELLA TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list