Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Win32G Scandisk.com"Added by the ESTRELLA TROJAN!"
X win32gb win32gb.exe"Added by the DLUCA-F TROJAN!"
X Win32Host Process webemir.exe"Added by the TURGEN -A TROJAN!"
X win32info win32info.exeAdult content dialler
X win32ini systroy.exe"Added by the IRC.ALADINZ.C TROJAN!"
X WIN32io clienttimer.exe"Eziin adware"
X win32Kernel findx.exe"Added by the BANLOA-EY TROJAN!"
X Win32KernelStart microsoft.exe"Added by the DELF-EWZ TROJAN!"
X Win32R Server.com"Added by the ESTRELLA TROJAN!"
X WIn32S Java DLL kavsvx.exe"Added by the AGOBOT-RZ WORM!"
X win32serv devicer.exe"Added by the CHECKOUT WORM!"
X win32serv servicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
X win32serv systemdevices.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
X win32servv load.exe"iSearch adware"
X win32servv ms1.exe"iSearch adware"
Y WIN32SL Win32sl.exe"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
X WIN32SNDS banc.exeAdded by an unidentified WORM or TROJAN!
X Win32system [random filename]"Added by the DDV.B WORM!"
X Win32System win32s.exe"Added by the MYDOOM.V WORM!"
X Win32SystemMonitor ***.exe [* = random char]Browser hijacker
X Win32SysV xin.exe"Added by the FORBOT-EO WORM!"
X win32update win32update.exe"Added by the GENOME.AQUV TROJAN!"
X Win32Updater KERNAL32.EXE"Added by the SPYBOT-OK WORM!"
X win32us win32us.exeAll-In-One-Telcom (adult content dialler) variant
X win32usbd ssrs.exe"Added by the RBOT-RA WORM!"
X Win32Usr WinCab.exe"Added by the DEDMIR-A WORM!"
X WIN32WN system_wc.exe"Eziin adware"
X win32_i lptt01 win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X win32_i ml097e win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Win386 Win386.exe"Added by the GOSUSUB VIRUS!"
X Win386 sp32.dllHomepage hijacker. Not a dll but a regfile in disguise
X WIN3S2SNDS winabsmod.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
X WIN3S2SNDS winiprtx.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
X Win64 Compatibility Check load win64.drv"CoolWebSearch parasite variant"
X WIN95DEFVIEW [path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
X win98 DNS wingrd.exe"Added by a variant of the RBOT WORM!"
X winabc "rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
X WinAble winable.exe"Added by the MATCASH.BG TROJAN!"
X WinAC v4 klsuicbn.exe"Added by the FORBOT-CS WORM!"
U Winacsr Winacsr.exe"AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X winactive WINACTIVE.EXE"WinActive variant of the LOP.com hijacker"
X WinActiveJ WinActiveJ.exeAdded by the ROTARRAN VIRUS!
X Winad Client Winad.exeWinAd adware by eXact Advertising
X WinAdCnt.exe WinAdCnt.exe"Added by the BANKER-BU TROJAN!"
X winadm winadm.exe"Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN!"
? WinAgent WinAgent.exe"Standard Life Insurance program. Is it required at startup?"
X Winahlp.exe Winahlp.exe"Added by a variant of the VAGRNOCKER TROJAN!"
X winallap winallap.exe"Added by the DELF.E TROJAN!"
X winallapu winallapu.exe"Added by the DELF.E TROJAN!"
X Winammp mccm.exe"Added by the IRCBOT-HH BACKDOOR!"
X Winamp winamp.htaHijacker - re-directing to adult content sites. Note - this isn't the real Winamp
X Winamp winamp.exe"Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player"
X WinAMP winamp62.exe"Added by the SDBOT-WN WORM!"
N Winamp winamp.exe"Winamp media player. Resides in a ""Winamp"" subdirectory of the Program Files directory"
X Winamp Agent winamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is ""winampa.exe"" - see here"
X Winamp Agent cvscc.exe"Added by the AGOBOT-GK WORM!"
X Winamp Media qmedia.exe"Added by the DIAZMON-A TROJAN!"
X Winamp media player winapa.exe"Added by an unidentified VIRUS
X Winamp Media Player winamap.exe"Added by the SDBOT.ACJM BACKDOOR!"
X Winamp Media Player winamp.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%"
X WinAmp Player winampp.exe"Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename"
X Winamp Player 6 Winamp6.exe"Added by a variant of the SPYBOT WORM!"
U Winamp to Google Talk winamptogoogletalk.exe"Winamp to Google Talk
X Winamp Update yhn.exe"Added by the SDBOT-ACR WORM!"
U Winampa WINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
X Winampa winampa.exe"Added by the AGOBOT-GS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
X Winampa Agent WINAMPA.EXE"Added by the SPYBOT-BR WORM! Note - this is NOT the popular Winamp media player which is normally located in %ProgramFiles%\Winamp. This one is found in %System%"
U WinampAgent WINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
X WinAmpAgent Msexploren.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
X WinAmpAgent Shch.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
X WinAmpAgent svchst.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
X WinAmpAgent Winagent.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
X WinAmpAgent msnexploren.exe"Added by the TACTSLAY.B TROJAN!"
X WinAmpAgent sdhch.exe"Added by the TACTSLAY.B TROJAN!"
X WinAnonymous GDC.exe"WinAnonymous rogue privacy tool - not recommended
X WinAntiSpyware 2005 was5.exe"WinAntiSpyware 2005 rogue spyware remover - not recommended
X WinAntiSpyware 2006 was6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
X WinAntiSpyware 2006 Free was6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
X WinAntiSpyware 2006 Scanner was6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
X WinAntiSpyware 2007 was7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
X WinAntiSpyware 2007 Free was7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
X WinAntispyware2008 WinAntispyware2008.exe"WinAntiSpyware 2008 rogue spyware remover - not recommended
X WinAntivirus AVSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
X WinAntiVirus Pro 2007 WinAv.exe"WinAntiVirus Pro 2007 rogue security software - not recommended
X WinAntiVirusPro2006 WinAV.exe"WinAntiVirus Pro 2006 rogue security software - not recommended
X WinApi winapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
X WINAPLOGUPD WINAPLOGUPD.EXE"Added by the CAPSIDE-C WORM!"
X Winapp winpup32.exeProduces popup ads to adult content sites
X WinApp32 msapp.exe"Added by the RSBOT TROJAN!"
U WinAppLog svchost.exe"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
X WinAuth winlogon.exe"Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X WinAvX WinAvX.exe"Added by the VIRANTIX TROJAN!"
X WinAvX WinAvXX.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the SPYWAD-AR TROJAN!"
X WinAwk WinAwk.exe"Added by the SDBOT-AYF WORM!"
U WinBackup Scheduler Wbsched.exe"LIUtilities WinBackup scheduler - backup software"
U WinBar WinBar.exe""WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls""
X winbar.pif packe.pif"Added by the RBOT-AVI WORM!"
X Winbed winbed.exeHijacker
X Winbin swchost.exe"Added by the RBOT.CLS WORM!"
X winbin32 win32exe.exe"Added by the RBOT-ZL WORM!"
X WinBlueSoft WinBlueSoft.exe"WinBlueSoft rogue spyware remover - not recommended
X winbo32 winbo32.exe"Added by the RBOT-GRU WORM!"
X winboot winboot.exe"Added by the BANLOAD-W TROJAN!"
X winbot winbot.exe"Added by the MIDRUG-A TROJAN!"
U WinBrush winbrush.exe"WinBrush - ""handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories
X WinButler WinButler.exeIdentified as a variant of the Trojan-Dropper.Agent.DKN malware
X wincfg syscnfg.exe"Added by an unidentified VIRUS
X WinCheck services.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field"
X WinCheck WinCheck.exe"Added by the PWS-CY TROJAN!"
X WinCheck services.exe"Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
X WinCheck check.exe"Added by the DELBOT-Y WORM!"
U winchk winchk.exe"RemoteSpy surveillance software. Uninstall this software unless you put it there yourself"
X winchost winchost.exe"Added by the DLOADER-PO TROJAN!"
N WINCINEMAMGR WINCIN~1.EXE"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
N WinCinemaMgr WinCinemaMgr.exe"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
U WINCINEMAMGR WinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
X winclean winclean.exe"Added by the AGENT.GXR TROJAN!"
X wincls "rundll32.exe wincls.dllstart"
X wincmap wincmapp.exe"CasClient adware variant - also detected as the CMAPP TROJAN!"
U WinColorReminder WinColorReminder.exe"The Microsoft Color Control Panel Applet for Windows XP ""helps you manage Windows color settings in one place."" Part of the Pro Imaging Powertoys"
X wincom vbrun6win.exe"Added by the AGOBOT-AFK WORM!"
X WinConfig9324 wincfgkop9.exe"Added by the RBOT.BVD WORM!"
X winconn vbrun6nt.exe"Added by the AGOBOT-AEI BACKDOOR!"
X WinCore32.exe WinCore32.exe"Added by the CLICKER-EN TROJAN!"
X wincrt.exe [path to worm]"Added by the STRATIO-HA WORM!"
X WinCRT32 wincrt32.exe"Added by the DOGBOT-D WORM!"
X WinCSRSS MSGRT32.EXE"Added by the REWINDO-A TROJAN!"
X winctl winctl.exe"Added by the IRCBOT-YI TROJAN!"
X WINCX wincore332.exe"Added by the AGOBOT-MG WORM!"
X Wind Logd File servicelogd.exe"Added by a variant of the RBOT WORM!"
X Wind Optimizer WindOptimizer.exe"Wind Optimizer rogue system optimization tool - not recommended
X Wind River Systems vxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
X Wind Security mswi32.pif"Added by the RBOT-ARH WORM!"
X wind.exe wind.exe"Added by the MITGLIEDER.BD TROJAN!"
X WIND0WS WIND0WS.exe"Added by the SPYBOT.DQ WORM!"
X WIND0WS mella.bat"Added by the ALLEM WORM!"
X Wind0ws wordpad.exe"Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System%"
X Wind0ws Ser7ice Agent colwindos.exe"Added by the RBOT-GQO TROJAN!"
X Wind0ws Sharing ssprotecter.exe"Added by the RBOT-AHW WORM!"
X Wind32 Wind32.exeIdentified as a variant of the Backdoor.Win32.Poison.avs malware
X WinData services.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the ""Startup Item"" field"
N WinDates windates.exe"WinDates is a calendar
X windbs winxtc.exe"Added by the AGOBOT-WD WORM!"
X Winde winde.exe"Added by the DLUCA TROJAN!"
X windef Win32sp.vbs"Added by the ANPES WORM!"
X windef windef.exe"Added by the WURMARK-O WORM!"
X windefender windefender.exe"Added by the AGENT.BYH TROJAN!"
X WinDefender 2008 WDefDemo.exe"WinDefender 2008 rogue privacy program - not recommended
X WinDefender2009 windef.exe"WinDefender 2009 rogue security software - not recommended
X Windeows NetStart Service2 tesakrmger.exe"Added by the RBOT-AMY WORM!"
X WinDevils WinDevils.exe"Added by the BRONTOK-BS WORM!"
X windhost.exe osrwin32.exe"Added by the BANKER-CB TROJAN!"
X windhost.exe windhost.exe"Added by the BANKER-BV TROJAN!"
X windhost.exe winos.exe"Added by the PWSAGENT-A WORM!"
X windir winrun.exe"Added by the WINBUR.B WORM!"
X Windir Working wuaumqr1.exe"Added by a variant of the IRCBOT TROJAN!"
X WinDirectories tdirs.exe"Added by the VB-EPB VIRUS!"
X Windll Windll.exe"Added by the TRYNOMA TROJAN!"
U WINDLL WSYS.EXE"STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes
X windll windll32.exe"Added by the ASTEF or RESPAN WORMS!"
X windll windotnetsrv.exe"Added by the AUTORUN-ANO WORM!"
X WinDLL (algs.exe) "rundll32.exe algs.exestart"
X WinDLL (aqls32.exe) aqls32.exe"Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""aqls32.exe"" file is found in %System%"
X WinDLL (asdfsa.exe) "rundll32.exe asdfsa.exestart"
X WinDLL (bee.dll) "rundll32.exe bee.dllstart"
X WinDLL (bix.exe) "rundll32.exe bix.exestart"
X WinDLL (csmss.exe) "rundll32.exe CSMSS.EXEstart"
X WinDLL (ctfmonm.exe) "rundll32.exe ctfmonm.exestart"
X WinDLL (dasda.com) "rundll32.exe dasda.comstart"
X WinDLL (diem.exe) "rundll32.exe diem.exestart"
X WinDLL (dlfksdld.exe) "rundll32.exe dlfksdld.exestart"
X WinDLL (jbi32.dll) "rundll32.exe jbi32.dllstart"
X WinDLL (lcass.exe) "rundll32.exe lcass.exestart"
X WinDLL (mysnlive.exe) "rundll32.exe mysnlive.exestart"
X WinDLL (ProsFix.exe) ProsFix.exe"Added by a variant of the IRCBOT BACKDOOR! The ""ProsFix.exe"" file is found in %System%"
X WinDLL (qwex.dll) "rundll32.exe qwex.dllstart"
X WinDLL (redyLive.exe) "rundll32.exe redyLive.exestart"
X WinDLL (scvhost32.dll) "rundll32.exe scvhost32.dllstart"
X WinDLL (service.exe) service.exe"Added by the AGENT.BX WORM! The ""service.exe"" file is found in %System%"
X WinDLL (slmss.exe) "rundll32.exe slmss.exestart"
X WinDLL (slsass.exe) "rundll32.exe slsass.exestart"
X WinDLL (smaprnter.exe) "rundll32.exe smaprnter.exestart"
X WinDLL (smms.exe) "rundll32.exe smms.exestart"
X WinDll (sslms.exe) "rundll32.exe sslms.exestart"
X WinDLL (start0s.exe) "rundll32.exe start0s.exestart"
X WinDLL (steam.dll) "rundll32.exe steam.dllstart"
X WinDLL (svc.exe) "rundll32.exe svc.exestart"
X WinDLL (svchost.dll) "rundll32.exe svchost.dllstart"
X WinDLL (sysx32.dll) "rundll32.exe sysx32.dllstart"
X WinDLL (tepmlayer.exe) "rundll32.exe tepmlayer.exestart"
X WinDLL (tmp.exe) "rundll32.exe tmp.exestart"
X WinDLL (tock24.dll) "rundll32.exe tock24.dllstart"
X WinDLL (tqurity.exe) "rundll32.exe tqurity.exestart"
X WinDLL (v4mon.dll) "rundll32.exe v4mon.dllstart"
X WinDLL (vdm32.dll) "rundll32.exe vdm32.dllstart"
X WinDLL (vxd32.dll) "rundll32.exe vxd32.dllstart"
X WinDLL (wchshield.exe) "rundll32.exe wchshield.exestart"
X WinDLL (wimimi.exe) "rundll32.exe wimimi.exestart"
X WinDLL (windns32.dll) "rundll32.exe windns32.dllstart"
X WinDLL (wingatey32.exe) "rundll32.exe wingatey32.exestart"
X WinDLL (wintmp.exe) "rundll32.exe wintmp.exestart"
X WinDLL (Wseclayer.exe) "rundll32.exe Wseclayer.exestart"
X WinDLL (wsync32.dll) "rundll32.exe wsync32.dllstart"
X WinDLL (xvd32.dll) "rundll32.exe xvd32.dllstart"
X Windll.exe Windll.exe"Added by the STEALER TROJAN!"
X Windll32 Windll32.exe"Added by the MSNPWS TROJAN!"
X WinDll32 _WIN32.EXE"Added by the LEGMIR.AQ TROJAN!"
X windllsys32.exe windllsys32.exe"Added by a variant of the MITGLIE-A TROJAN!"
X WinDNS windns32.exe"Added by the GAOBOT.WX WORM!"
X Windo Servic Agen alirexe.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windo Servic Agent 32 xagw.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windoes Kernel kernel32.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
X WindoFix WindoFix.exe"WindoFix rogue system error utility"
X Windos Seres Agnts [worm filename].exe"Added by the RBOT-GUN WORM!"
X Windosupdate manager runwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
X Window explore.exe"Added by the GAOBOT.ADW WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list