Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Window Loader Dos32.exe"Added by the GAOBOT.AO WORM!"
X Window Monitor winmon32.exe"Added by the SDBOT.RT WORM!"
X Window Msn Live Messanger msnmsgsls.exe"Added by the RBOT.BJD BACKDOOR!"
X Window service [random filename]"Added by the RBOT-ACH WORM!"
X Window UDP Control Servic winlogon.exe"Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Window upadate pe2.exe"Added by a variant of the RBOT WORM!"
U Window Washer wwDisp.exe"Window Washer from Webroot Software. Useful utility that deletes safe to remove files
X window.exe window.exe"Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!"
X window2 ssvchost.exe"Added by the IRCBOT.H TROJAN!"
X window2 ieupdate.exe"Added by the FORBOT-BM WORM!"
U WindowBlinds wbload.exe"WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
X WindowEnhancer Winex.exe"SCBar foistware variant"
X Windowfdgfds DasdLL Verifier winupdatr.exe"Added by the AGOBOT.HZ WORM!"
X Windowfdgfds DasdLL Verifiew [path to worm]"Added by the RBOT-GGX WORM!"
X Windowfdgfds DLL fgfdg Verifier Windowsdldfglcheckkk.exe"Added by the RBOT.CSP WORM!"
X Windowfdgfds DLL fgfdg Verifier winsecure.exe"Added by a variant of the RBOT WORM!"
U WindowFX wfxload.exe"Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
X windown wiusyt.exe"Added by the QQPASS-M TROJAN!"
X WindowRegKey update wins.exe"Added by the SPYBOT.I WORM!"
X Windows services.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the ""Startup Item"" field"
X Windows Kernel32.exe"Added by the TENDOOLF.A WORM!"
X Windows msdos98.exeAdded by the PWSTEAL TROJAN!
X Windows Windows.exe"Added by the KAZMOR.A
X Windows explorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X windows [path to trojan]"Added by the AIMWIN TROJAN!"
X windows hkey.exe"Added by the GAOBOT.AFW WORM!"
X windows system copy.exe"Added by the SALGA.A WORM!"
X Windows gearsec.exe"Added by the STUBBOT-B WORM!"
X Windows run.exe"Added by the SPYBOT.OFN WORM!"
X Windows system.exe"Added by the SPYBOT.OBB WORM!"
X WINDOWS windows.exe"Added by the MONBOT-A TROJAN!"
X Windows services.exe"Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity"
X WINDOWS jif.exe"Added by the MYTOB.MK WORM!"
X windows iexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Windows services.exe"Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Windows"" subfolder"
X Windows smss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X windows svchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X WINDOWS ymssgr.exe"Added by the BCKDR-PS BACKDOOR! Note - deactivates the Microsoft\Internet Connection Firewall (ICF)"
X Windows taskmngr.exe"Added by a variant of the SDBOT WORM!"
X Windows Cfreer.exe"Added by the CULLER-C WORM!"
X Windows Zser.exe"Added by the CULLER-D WORM!"
X Windows spoovlss.exe"Added by an unidentified WORM or TROJAN! See here"
X windows VBSyS.vbs"Added by the ROCK-D WORM!"
U Windows WpcUmi.exe"Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as ""Reminder: View the Parental Controls activity report"". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray"
U Windows & Internet Cleaner Pro WICleaner.exe"Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
X Windows (ICS) Spooler crtss.exe"Added by a variant of the RBOT WORM!"
X Windows (random character) diskcheck.exe"Added by the SINGU.B TROJAN!"
X Windows .Net Manager localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager svcman.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager websvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows 128 Module win128.exe"Added by the FORBOT-ES WORM!"
X Windows 2004 csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
X Windows 32 Editor Win32edit.exe"Added by the WOOTBOT.GQ WORM!"
X Windows 32 Rescue win32resc.exe"Added by the FORBOT-EU WORM!"
X Windows 32 Update Windows-Update.exe"Added by a variant of the RBOT WORM!"
X Windows 32-bit DLL Integrity Verifier dllrun.exe"Added by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote location"
U Windows Accelerators setup.exe"KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X Windows Account Alternation wauclt.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Acer Service acersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
X Windows Action csrs.exe"Added by the SECCMU-A WORM!"
X Windows Activate System syssv.exe"Added by a variant of the SPYBOT WORM!"
X Windows AdControl WinAdCtl.exeWindupdates adware variant
X Windows Additional Guard WI[random characters].exe"Windows Additional Guard rogue security software - not recommended
X Windows AdService WinAdServ.exeWindupdates adware variant
X Windows AdStatus WinStat.exe"Added by the BLESHARE!DR VIRUS!"
X Windows AdTools WinAdTools.exeWindupdates adware variant
X Windows Anti Verifier Windows-Anti.exe"Added by the RBOT.ETT WORM!"
X Windows Anti Virus Control Center avrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Anti Virus Control Center winavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Anti-Virus Built 32 AntiVirus32.exe"Added by the SDBOT-BG WORM!"
X Windows APCI Verifier dhcpserv.exe"Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
X Windows API Control Task apitsk32.exe"Added by the MYTOB.HI WORM!"
X Windows Application Layer walg32.exe"Added by the AGOBOT.ATN WORM!"
X Windows Application Layer Gateway walg32.exe"Added by the AGOBOT-AAZ WORM!"
X Windows applications server SysShield.exe"Added by the unregistered version of Personal Anti Malware rogue security software - not recommended
X Windows ARP Detectionc nvudlsp.exe"Added by the AGENT.LMW BACKDOOR!"
X Windows ARP Detectionc winlogon.exe"Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Windows ARP Detectioncx winlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Windows ASN Service rge.exe"Added by the RBOT-AOK WORM!"
X Windows ASN Service [random filename]"Added by the AGOBOT-TC WORM!"
X Windows ASN4 Services gamo.exe"Added by the RBOT-EHK WORM!"
X Windows Audio snd.exe"Added by the ACKANTTA.C WORM!"
X Windows Audio Components nncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Audio Control ppnsvc.exe"Added by the HAM TROJAN!"
X Windows Audio Layer narsvc.exe"Added by the IRCBOT.AFT BACKDOOR!"
X Windows Audio Panel nppsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Audio Service sndmic32.exe"Added by the ACKANTTA.C WORM!"
X Windows Audio Services jvm.exe"Added by the ACKANTTA.F WORM!"
X Windows Audio Startup nndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
X Windows Audio System nndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Authority Service lsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X windows auto update msblast.exe"Added by the BLASTER.B WORM!"
X windows auto update penis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
X Windows Auto Update winupdater.exe"Added by the SDBOT.TF WORM!"
X Windows auto update bazzi.exe"Added by the AHKER.E WORM!"
X Windows auto update LSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
X Windows Auto Updater WINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
X Windows Automatic Update wuamgrder.exe"Added by a variant of the RBOT WORM!"
X Windows Automatic Updater windrg.exe"Added by a variant of the RBOT WORM!"
X Windows Automatic Updates dvldr.exe"Added by the RBOT.MF WORM!"
X Windows Automatical Updater dcz.exe"Added by the RBOT.CXS WORM!"
X Windows AutomaticUpdater runddls.exe"Added by a variant of the RBOT WORM!"
X windows automation mslaugh.exe"Added by the BLASTER.E WORM!"
X Windows Automation msdspr.exe"Added by the SOLAME.A WORM!"
X Windows Autostart Loader notepad32.exe"Added by a variant of the RBOT WORM!"
X Windows backup systemss.exe"Added by a variant of the SPYBOT WORM!"
X Windows Backup Configuration IEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Windows Başlangıç Dosyası sistem.exe"Added by the MUZK WORM!"
X Windows Boot winboot.exe"Added by the AGENT.HBD TROJAN!"
X Windows Boot windowsboot.exe"Added by the IRCBOT.AZT BACKDOOR!"
X Windows Booter winboot.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Booter! winbooter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Bootup ms-wks32.exe"Added by the RBOT-AFM WORM!"
X Windows Bootup Systemwks32.exe"Added by a variant of the RBOT WORM!"
X Windows Bootup task-mngr.exe"Added by the RBOT-AWP WORM!"
X Windows Browser Services browser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Browser Services browser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Browser Services browser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Browser Services Browsr32.exe"Added by the IRCBOT.BUR BACKDOOR!"
X Windows Browser Services browsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows bypass security SMSS Service SbiCvy.exe"Added by the RBOT-GRF WORM!"
X Windows cfg ascv.exe"Added by the AGOBOT-SZ BACKDOOR!"
X Windows Clean-Up Pro WINDOWS CLEAN-UP PRO.Exe"Windows Clean-Up Pro spyware remover - not recommended
X Windows Cleaner Service winclean.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Client client.exe"Added by the BACKDR-AM BACKDOOR!"
X Windows Client Service 32 csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
X Windows Client/Server Runtime Server csrs.exe"Added by the RBOT.KD WORM!"
X Windows CODE Fix Msy Startups msyh32.exe"Added by the AGOBOT.AKK WORM!"
X Windows Command wincmd.exe"Added by the RBOT.ANV WORM!"
X Windows Communicator wincomm.exe"Added by the AGOBOT-BH WORM!"
X Windows Communicator for NT/XP osndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
X Windows Compliant [random filename]"Added by the RBOT-IR WORM!"
X Windows Computer Browser bcwsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Conf windowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Config SSYS.EXE"Added by the SPYBOT-DA WORM!"
X Windows Config wins.exe"Added by the SPYBOT.JR WORM!"
X Windows Config RUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X Windows Config pvphost.exe"Added by a variant of the SLAPER TROJAN!"
X Windows Config winconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
X Windows Config ZANBOR.EXE"Added by the SPYBOT-MH WORM!"
X Windows Config Connection msicll.exe"Added by the RBOT-EXQ WORM!"
X Windows Config Loader Wincfg32.exe"Added by the SILVERFTP TROJAN!"
X Windows Config Manager winconf.exe"Added by the RBOT-AIT WORM!"
X Windows Config Manager Wincfgman32.exe"Added by the AGOBOT-AL BACKDOOR!"
X Windows Config System config.exe"Added by a variant of the SDBOT WORM!"
X Windows Configuration wsys32.exe"Added by the GAOBOT.FB WORM!"
X Windows Configuration wincfg32.exe"Added by the MYTOB.ED WORM!"
X Windows Configuration WINHUB.EXE"Added by the SPYBOT-CG WORM!"
X Windows Configuration Loader asclt.exe"Added by the SDBOT-OA WORM!"
X Windows Configuration Loader msgfix.exe"Added by the SDBOT-NP WORM!"
X Windows Configuration System IExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Windows Configuration Utility winxupdate.exe"Added by the AGOBOT.LW WORM!"
X Windows Configurator winconf.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows connection manager Internet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
X Windows Console wkssvc.exe"Added by the SDBOT-DJX WORM!"
X Windows Console Component wrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Console Monitor [path to worm]"Added by the KEDEBE WORM!"
X Windows Console Monitor gcasAV32.exe"Added by the KEDEBE-A WORM!"
X Windows Console Norms wnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Console Source wnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Control Control.exe"Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder
X Windows ControlAd WinCtlAd.exeWindupdates adware variant
X Windows Controls Center winudmr.exe"Added by the LAMER.AA BACKDOOR!"
X Windows Core Kernel Update win32bootcfg.exe"Added by the RANCK-EL TROJAN!"
X Windows CPU host winbog32.exe"Added by a variant of the RBOT WORM!"
X Windows Critical Alert wincrt.exe"Added by the ALEDO-A TROJAN!"
X Windows Custom Services CSRCS.EXE"Added by the SPYBOT-EI WORM!"
X Windows Data Server autodisc.exe"Added by the SPYBOT-CB WORM!"
X Windows Data Server [random name].exe"Added by the SPYBOT-DS WORM!"
X Windows Database WinDat.exeAdded by an unidentified WORM or TROJAN!
X Windows Database wiinsvc.exe"Added by the AGOBOT-RU WORM!"
X Windows Dcom2 Fix mscom32.exe"Added by the RBOT-QT WORM!"
X Windows DDE Loader windde32.exe"Added by the SDBOT-UZ WORM!"
X Windows debug logging winlogg.exe"Added by the RBOT-OY WORM!"
X Windows debug logging winloggs.exe"Added by the RBOT-QN WORM!"
X Windows Debugger windbg.exe"Added by the FORBOT-BY WORM!"
X Windows Debugger msdbg32.exe"Added by a variant of the RBOT WORM!"
X Windows Debugger windbg32.exe"Added by the ZOTOB.L WORM!"
X Windows Debugging Tools updatecfg.exe"Added by the RBOT-AXU WORM!"
X Windows Default Configuration svchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X Windows Default Server wfdmgrsp.exe"Added by the IRCBOT.BCX BACKDOOR!"
X Windows Default Server winampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
Y Windows Defender MSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
X Windows Defender wdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X Windows Defender Adds wda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X Windows Defender Monitor wdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X Windows Defender Updater wdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X WINDOWS DENEME deneme.exe"Added by the MYTOB-CR WORM!"
X Windows Desktop Controler windesktop.exe"Added by the SDBOT-XH WORM!"
X Windows Desktop Daemon winpadg.exe"Added by a variant of the SPYBOT WORM!"
N Windows Desktop Search WindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search
X Windows Dialup Service dialup.exe"Added by the AGOBOT.AAH WORM!"
X Windows Disk Defragmenter wpabaln32.exe"Added by the BANCOS-ASJ TROJAN!"
X Windows Disk Manager cmnvc.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Display Coupler display.exe"Added by the IRCBOT-YS TROJAN!"
X Windows DLL host winupd32.exe"Added by a variant of the SPYBOT WORM!"
X Windows DLL Host dllhost32.exeAdded by an unidentified WORM or TROJAN!
X Windows DLL Loader RUNDLL16.EXE"Added by the DOMWIS TROJAN!"
X Windows DLL Loader defragfat32z.exe"Added by the LINKBOT.A WORM!"
X Windows DLL Loader rundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
X Windows DLL Loader defragfat32pi.exe"Added by the RBOT-QQ WORM!"
X Windows DLL Loader defragfat39.exe"Added by the POEBOT-C WORM!"
X Windows DLL Loader defragfatz.exe"Added by the LINKBOT.H WORM!"
X Windows DLL Loader defragfat32.exe"Added by the SDBOT-SS WORM!"
X Windows DLL Loader defragfat32abc.exe"Added by the RBOT-RG WORM!"
X Windows DLL Loader wdevice.exe"Added by a variant of the SDBOT WORM!"
X Windows DLL Loader SYSCFG16.EXE"Added by the DOMWIS-N WORM!"
X Windows DLL Loader WINCFG32.EXE"Added by the AGOBOT-TE WORM!"
X Windows DLL Loader defragfatx.exe"Added by the POEBOT-F WORM!"
X Windows DLL Services winsvc32.exe"Added by the RBOT-ZF WORM!"
X Windows DLL Services svchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list