Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows DLL Services system.exe"AGENT.H spyware"
X Windows DLL Tracker spoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
X Windows DLL Verifier xptl.exe"Added by a variant of the RBOT WORM!"
X Windows DLL Verifier windlls.exe"Added by the RBOT-AZQ WORM!"
X Windows DNS windns.exe"Added by the SDBOT-XU WORM!"
X Windows DNS Daemon windnsd.exe"Added by the WOOTBOT.AS WORM!"
X Windows Domain Name Drivers windns.exe"Added by the FORBOT-EP WORM!"
X Windows DOS dosw.exe"Added by the SALAY-A WORM!"
X Windows DotFix live msdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
X Windows Download Manager windlmngr.exeAdded by an unidentified TROJAN!
X Windows Drive Compatibility System32Driver32.exe"Added by the SUPOVA.Z WORM!"
X Windows Driver winxpdriver.exe"Added by the WOOTBOT.EE WORM!"
X Windows Driver windrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Driver Adapter svchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
X Windows Driver Foundation MTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
X Windows Driver Services msdrvs32.exe"Added by the WOOTBOT.L WORM!"
X Windows Driver Sup windvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows driver update dmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
X Windows driver update Ipconfig32.exe"Added by the SDBOT-JV WORM!"
X Windows Driver! windriver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Drivers ssms.exe"Added by the RBOT-AT WORM!"
X Windows drivers update windowsupdate.exe"Added by the RBOT-ACE WORM!"
X Windows Dynamic Library Cache dllcache.exe"Added by the INJECT-HT TROJAN!"
X Windows Dynamic Loading Header winDLL32.exe"Added by a variant of the SDBOT WORM!"
X Windows Email Server wmserv.exe"Added by the FOUNDU-AWORM!"
X Windows Enterprise Defender WindowsEDefender.exe"Windows Enterprise Defender rogue security software - not recommended
X Windows Enterprise Suite WE[random characters].exe"Windows Enterprise Suite rogue security software - not recommended
X Windows Essensials mvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Event Detection wecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Event Provider wposvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Event Section sntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Event Service winserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Executable winmys.exe"Added by the RBOT-ABO WORM!"
X Windows Executer bling.exe"Added by the SDBOT-DFT WORM!"
X Windows Executer svchostie.exe"Added by the EGGDROP.V BACKDOOR!"
X Windows ExpIorer [random filename]"Added by the RBOT-AKO WORM!"
X Windows Explorer [filename].exe"Added by the SDBOT TROJAN!"
X Windows Explorer Lsas.exe"Added by the GAOBOT.AO WORM!"
X Windows Explorer olecom32.exeAdded by an unidentified WORM or TROJAN!
X Windows Explorer EEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
X Windows Explorer explorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windows Explorer explorer.pif"Added by the RBOT-AID WORM!"
X Windows Explorer system32.exe"Added by the RBOT-AJH WORM!"
X Windows Explorer explorer32.exe"Added by a variant of the SDBOT WORM!"
X Windows Explorer Windows Explorer.EXE"Added by the VB-EBA WORM!"
X Windows Explorer system.exe"Added by the STIRAUT WORM!"
X Windows Explorer Key explorer.exe"Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windows Explorer Services exploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Explorer Shell Winexec32.exe"Added by the REDIST.B WORM!"
X Windows Explorer SP2 csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
X Windows Explorer Update Build 1142 EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
X Windows Explorer-3212 WINRE16.EXE"Added by the HARDOC WORM!"
X Windows Explorer.exe Explorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windows Express pci32b.exe"Added by the BUZUS.C TROJAN!"
X Windows Extensions for Win32 winprgs32.exe"Added by the SDBOT.AFA WORM!"
N Windows Eyes ??"For blind people
X Windows FAT 32 WINFAT32B.exe"Added by the SPYBOT-AGT WORM!"
X Windows File Migration Wizard HIMENSYST.EXE"Added by the RBOT-EMO WORM!"
X Windows File Protection winprotect.exe"Added by the AGOBOT.JB WORM!"
X Windows File System Frame ntframe.exeAdded by an unidentified WORM or TROJAN!
X Windows File Verification Service wfvs.exeAdded by the RANKY.AC TROJAN!
X Windows File XP Manager wfdmgr.exe"Added by the SDBOT.XD TROJAN!"
X Windows FileSharing Service mcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
X Windows Firevall Control C rundll.exe"Added by the GAERTOB.A TROJAN!"
X Windows Firewal Lsess.exe"Added by a variant of the RBOT WORM!"
X Windows Firewall WindowsFirewall.exe"Added by the MYTOB.AO WORM!"
X Windows Firewall svchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows Firewall ipservice32.exe"Added by a variant of the RBOT WORM!"
X Windows Firewall rundll32.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Firewall Log winlog.exeAdded by an unidentified WORM or TROJAN!
X Windows Firewall Manager msfw.exe"Added by the RBOT.WR WORM!"
X Windows firewall manager chh.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows firewall manager msguard.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows Firewall Service wfsvc.exe"Added by the IRCBOT-YL WORM!"
X Windows Firewall Updater updatees.exe"Added by the RBOT-GBX WORM!"
X Windows Firewall Updater cronos.exe"Added by the RBOT-GBY WORM!"
X Windows Firewall Updater ctfcom.exe"Added by the RBOT-GCB WORM!"
X Windows Firewall Updater windowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
X Windows Firewalll scvhost.exe"Added by the RBOT-EK WORM!"
X Windows Firewalll sphost.exe"Added by a variant of the RBOT WORM!"
X Windows Firewalll svvhost.exe"Added by a variant of the RBOT WORM!"
X Windows Firewalll winmu.exe"Added by a variant of the RBOT WORM!"
X Windows Fix integator.exe"Added by the SDBOT.ZAB WORM!"
X Windows Fixer winfix.exe"Added by the VIRUT-I VIRUS!"
X Windows Fixes Systems elite.exe"Added by the MYTOB.EG WORM!"
X Windows FormatAd WinForm.exeWindupdates adware variant
X Windows Frame Works frmwrks32.exe"Added by a variant of the RBOT WORM!"
X Windows Framework frmwrk.exe"Added by the DWNLDR-GWV TROJAN!"
X Windows Framework scvh0st.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
X WINDOWS FUCK BY CLASIC fuck.exe"Added by the ZOTOB.H or ZOTOB.J WORMS!"
X Windows Gamma Display wingamma.exe"Antivirus 2010 rogue security software - not recommended
X Windows Generic Proc procmsg.exe"Added by the ALLIM.B WORM!"
X Windows Generic Services winsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
X Windows Genuine svghost.exe"Added by a variant of the SPYBOT WORM! See here"
X Windows Genuine Validate winservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
X Windows Global Init ngpsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows GMT32 wingmt32.exe"Added by the MYTOB.KM WORM!"
X Windows Graphics Loaders wingraphics.exe"Added by the SPYBOT.JG WORM!"
X Windows Guard WAUMGRD.EXE"Added by the RBOT-GY WORM!"
X Windows Guard Pro WindowsGP.exe"Windows Guard Pro rogue security software - not recommended
U Windows Guardian thehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
U Windows Guardian Fawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
X Windows haz Layer [5 random letters].exe"Added by a variant of the RBOT WORM!"
X Windows Help mailinfo.exe"Added by the MYTOB.JX WORM!"
X Windows Help Stney.exe"Added by the AGOBOT-VI WORM!"
X Windows Help File winhelper32.exe"Added by the SDBOT-QK TROJAN!"
X Windows Help Manager svchost32.exe"Added by the RBOT-OZ WORM!"
X Windows Help Service winhelpsv.exe"Added by the RBOT-LP WORM!"
X Windows Help Service winhlp.pif"Added by the RBOT-AKW WORM!"
? Windows Help System Help.pif"??"
X Windows Helper winhelp.exe"Added by the BANKER.APE TROJAN!"
X Windows Helper wsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Hijack Protection comngr.exe"Added by the AGENT-FYD TROJAN!"
X Windows Hijack Protection System commngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
X Windows his Layer pilotGame.exe"Added by the RBOT.GLX WORM!"
X Windows Host hosts.exe"Added by the KELVIR.U WORM!"
X Windows Host winhost.exe"Added by the PRYSAT TROJAN!"
X Windows Host Booter hostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
X Windows Host Device hostsvc.exe"Added by the ZOOTY-A WORM!"
X Windows Host Name lmass.exe"Added by the GAOBOT.O WORM!"
X Windows Host Service scvhosts.exe"Added by the SPYBOT.NLI WORM!"
X Windows Host Service host.exe"Added by the KELVIR.AN WORM!"
X Windows Host Service svchoste.exe"Added by the KELVIR.BF WORM!"
X Windows Host Service svchosts32.exe"Added by the KELVIR.AW WORM!"
X Windows Host32 Starter hostserv.exe"Added by the SDBOT-WU WORM!"
X Windows Hosts hosts.exe"Added by the KELVIR-O TROJAN!"
X Windows Hosts winhosts.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows HP Drivers hpdmws.exe"Added by the SDBOT.AQU WORM!"
X Windows HTML file reader Sysconf32.exe"Added by the NOOMY.A WORM!"
X Windows HTTP services winhttps.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Icons Manager wicomgr.exe"Added by the RBOT-AIF WORM!"
X WINDOWS ID SYSTEM wID32.exe"Added by the MYTOB.LN WORM!"
X Windows Identify sysays.exe"Added by a variant of the SPYBOT WORM! See here"
X Windows Image wintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
X Windows Image Acquisition (WIASC) WIAcs.exe"Added by the RIZO.A TROJAN!"
X Windows Image Acquisition (WIASSC) WIAcss.exe"Added by the RIZO.A TROJAN!"
X Windows iMessenger Messenger winimsg.exe"Added by the ALLIM.A WORM!"
X Windows Incontext InSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
X Windows Insecure [path to worm]"Added by the RBOT-FSM WORM!"
X Windows installer winstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
X Windows Installer ntdll.exeAdded by an unidentified WORM or TROJAN!
X Windows Installer 1 msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
X Windows Instruction Services winstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Internet Browser Services internet.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Explorer 6 firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
X Windows Internet Manager svchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows Internet Protocol winproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
X Windows Internet Protocol deinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
X Windows Internet Service wininet.exe"Added by the RBOT-AUX WORM!"
U Windows IP Security ipsec.exe"Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
X Windows IP Security Service ipsecs.exe"Added by the RBOT.BPW WORM!"
X Windows IPv6 Drivers wipv6.exe"Added by the SDBOT-VJ WORM!"
X Windows Java Update weatherBug32.exe"Added by a variant of the RBOT WORM!"
X Windows JavaScript Daemon Winjsd.exe"Added by the WOOTBOT.AF WORM!"
X Windows Kernel 64 kernal64.exe"Added by the YIMP-B WORM!"
X Windows Kernel System Service wkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows kev Messenger mskev.exe"Added by the SDBOT-XV WORM!"
X Windows Keyboard Services winkeyboard.exe"Added by the IRCBOT.AFS WORM!"
X Windows Keyboard Services winkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Keyboard Services winkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live msgnms.exe"Added by the XPACK.AV TROJAN!"
X Windows Live WindowsLive.exe"Added by the REALBOT-A WORM!"
X Windows Live Care.exe WindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
X Windows Live Client msnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
U Windows Live Family Safety Filter fsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
X Windows Live Manager winlivemgr.exe"Added by the SHEUR.EB TROJAN!"
X Windows Live Messages msgnlive.exe"Added by the AGENT.AYH WORM!"
X Windows Live Messenger msnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
X Windows live Messenger msn.com"Added by the IRCBOT-AAV WORM!"
X Windows Live Messenger msnlive.exe"Added by the RBOT.BMV BACKDOOR!"
X windows Live Messenger iexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
N Windows Live Messenger msnmsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
X Windows Live Messenger [random].exe"Added by the RBOT-GVL WORM!"
X Windows Live Messenger msnd.exe"Added by the BCKDR-QQQ BACKDOOR!"
X Windows Live Messenger 8.12 ctfmon.exe"Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
X Windows Live Messenger Addon wllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Live Messenger Servicer msmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Messenger Services msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Messenger! livemsngr.exe"Added by the IRCBOT.AWE BACKDOOR!"
X Windows Live Messenger! msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Msgs wlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Msgs! wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
Y Windows Live OneCare winssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
X Windows Live Service msnlive.exe"Added by the SLENFBOT.DI WORM!"
X Windows Live Servicer usrserv.exe"Added by the SMALL.LU BACKDOOR!"
X Windows live Support wlmsngr.exe"Added by the RBOT-BKL WORM!"
U Windows Live Sync WindowsLiveSync.exe"Windows Live Sync from Microsoft (formerly known as Windows Live FolderShare) - ""a free-to-use internet-based file synchronization application by Microsoft that is designed to allow files and folders between two or more computers be in sync with each other on Windows (Vista and later) and Mac OS X based computers"""
U Windows Live™ OneCare™ Family Safety fssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
? Windows Load windows.com"??"
X Windows Loader wstart32.exe"Added by the GAOBOT.CA WORM!"
X Windows Loader winServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
X Windows Loader SysUpdate.exe"Added by a variant of the SDBOT WORM!"
X Windows Loader Service civsc.exe"Added by a variant of the RBOT WORM!"
X windows Loadxm Win_.exe"Added by the FODDER-A TROJAN!"
X Windows Local ISP winthcr.exe"Added by the SDBOT.ENZ BACKDOOR!"
X Windows Local Services localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcman.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services websvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Spooler lssas.exe"Added by the RBOT.BXQ WORM!"
X Windows Locator wsass.exe"Added by the IRCBOT.N TROJAN!"
X Windows Log Agent winlogon.exe"Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
X Windows Logger winlog.exe"Added by the NSHADOW-B TROJAN!"
X Windows logging winlogd.exe"Added by the RBOT-ON WORM!"
X Windows logging asgasg.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Logical Adapter wsrsvc.exe"Added by the IRCBOT.ARU BACKDOOR!"
X Windows Logical Connection wcnsvc.exe"Added by the VIRUT.AO VIRUS!"
X Windows Login explored.exe"Added by the GAOBOT.SY WORM!"
X Windows Login winlog.exe"Added by the AGOBOT.MG WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list