Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows Login lmss.exe"Added by the AGOBOT-JA WORM!"
X Windows Login msnmsgr.exe"Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
X Windows Login login.exe"Detected by NOD32 as a variant of the BIFROSE TROJAN!"
X Windows Login lms.exe"Added by the AGOBOT-IC WORM!"
X Windows Login Folder winzep.exe"Added by the AGOBOT-TZ WORM!"
X Windows Login Manager winlogin.exe"Added by a variant of the SDBOT WORM!"
X Windows Login Security winlogin.pifAdded by an unidentified WORM or TROJAN!
X Windows Login Service winlog.exe"Added by the RBOT-AFN WORM!"
X Windows Login Service winlogin.pif"Added by the SDBOT-ACU WORM!"
X Windows Logon winlogin.exe"Added by the SPYBOT-C TROJAN!"
X Windows Logon winlogon.exe"Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
X Windows Logon Application WinIogon.exe"Added by the LINKBOT.M WORM!"
X Windows Logon Application logon.exe"Added by the POEBOT-J WORM!"
X Windows Logon Application services.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows Logon Application win32help.exe"Added by the DELBOT-X WORM!"
X Windows Logon Application winlogon.exe"Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process
X Windows Logon Application winamp.exe"Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
X Windows Logon Applicationedc winlogon.exe"Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
X Windows Logon Applicatonedc winlogon.exe"Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
X Windows Logon Manager logon.exe"Added by a variant of the RBOT WORM!"
X Windows Logon Procedure Svchoste.exe"Added by a variant of the SPYBOT WORM!"
X Windows Logon Procedure Svchosta.exe"Added by a variant of the SPYBOT WORM!"
X windows logon procedure winlogonpc.exe"Added by the WINLOGON TROJAN!"
X Windows Logon Service winlogon.pif"Added by the RBOT-AOU WORM!"
X Windows Logon Service napi32.exe"Added by the SPYBOT.ANDM WORM!"
X Windows Logon Service winlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
X Windows LoL Layer gqwdcr.exe"Added by the AGOBOT-AHS WORM!"
X Windows LoL Layer win.exe"Added by the RBOT-FTO WORM!"
X Windows LoL Layer [random filename].exe"Added by the RBOT-GMD WORM!"
X Windows LoL Layer pyvnpt.exe"Added by the RBOT-GKV WORM!"
X Windows LoL Layer winlolx.exe"Added by the RBOT-FOR WORM!"
X Windows LoL Layer azypbrx.exe"Added by the RBOT-GMZ WORM!"
X Windows LoL Layer blvpnmcny.exe"Added by the RBOT-GOR WORM!"
X Windows Lord Anti-Virus winlord32.exe"Added by the SDBOT-GW WORM!"
X Windows Management Informant wmmiexe.exe"Added by the IRCBOT-V BACKDOOR!"
X Windows Management Instrumentation mwd.exe"Added by the GRAPS WORM!"
X Windows Management Instrumentation [path to file]"Added by the QEDS-A WORM!"
X Windows Management Instrumentations winmg.exe"Added by the GAOBOT.GW WORM!"
X WINDOWS MANAGEMENT SYSTEM wm1exe.exe"Added by the RBOT-VT WORM!"
X Windows Manager winmants.exe"Added by the MANTAS WORM!"
X Windows Manager winsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Windows Manager taskmgrs.exe"Added by the SILLYFDC.BBZ WORM!"
X Windows Manager Control WINMUR32.EXE"Added by the AGOBOT-AR WORM!"
X Windows Manager Update Inc tgb.exe"Added by the SDBOT-ACM WORM!"
X Windows mangement winlogonn.exe"Added by the RANDEX.FC WORM!"
X Windows Media AP winmapp.exeAdded by an unidentified WORM or TROJAN!
X Windows Media APP wmapp.exeAdded by an unidentified WORM or TROJAN!
N Windows Media Center "RunDLL32.exe ehuihlp.dllBootMediaCenter"
X Windows Media Center smss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
N Windows Media Connect 2 WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
X Windows Media Driver msnger.exe"Added by a variant of the RBOT WORM!"
X Windows Media Loader wmloader.exe"Added by a variant of the GAOBOT WORM!"
X Windows Media Player wmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
X Windows Media Player MediaPIayer.exe"Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
X Windows Media Player [random filename]"Added by a variant of the RBOT WORM!"
X Windows Media Player msa.exe"Added by the RBOT-SI WORM!"
X Windows Media Player mcafe32.exe"Added by the RBOT-YO WORM!"
X Windows Media Player wmplayer.exe"Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
X Windows Media Player 50cent.exe"Added by a variant of the RBOT WORM!"
X Windows Media Player mpwe.exe"Added by the RBOT-TT WORM!"
X Windows Media Player msams.exe"Added by the RBOT.AHR WORM!"
X Windows Media Player vmmreg32.exe"Added by the AGENT.AQO TROJAN!"
X Windows Media Player msass43.exe"Added by the RBOT-RT WORM!"
X Windows Media Player mpupdata.exe"Added by the SDBOT.BBG WORM!"
X Windows Media Player wmplayerc.exe"Added by the SILLYFDC.DBG WORM!"
X Windows Media Player 3.6 wmpa36.exe"Added by a variant of the RBOT WORM!"
X Windows Media Player 3.6b WMPA36B.EXE"Added by the RBOT-VV WORM!"
X Windows Media Player 3.6d wmpa36d.exe"Added by the RBOT-YA WORM!"
X Windows Media Player 3.9 wmpa36.exe"Added by a variant of the RBOT WORM!"
X Windows Media Player 6.1.2 wmplayer612.exe"Added by the RBOT.AIB BACKDOOR!"
X Windows Media Player Service wmedia.exe"Added by the RBOT.213504 WORM!"
X Windows Media Player Update [random filename]"Added by the RBOT-ET WORM!"
N Windows Media Powerpoint Helper NSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
X Windows Media Server wmserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Media Server! wmserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows media service crvss.exe"Added by the SDBOT.VP WORM!"
X Windows media service crsss.exe"Added by the RBOT.ACY WORM!"
X Windows media service Sygate32.exe"Added by the RBOT.ADE WORM!"
X Windows media services cvrsss.exe"Added by the RBOT-MW WORM!"
X Windows Media SP.2.37 [random filename]"Added by the LEMIR.C TROJAN!"
X Windows Media Updater crease.exe"Added by the RBOT-ATI WORM!"
X Windows Media Upgrade NeUpgrade.exe"Added by the RBOT.BMF TROJAN!"
X Windows Media Utility wmediautil.exe"Added by a variant of the SPYBOT WORM!"
X Windows Memory Drivers memretain.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Memory Manager windowsmem.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Memory Running Services memrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
X Windows Memory Sharing memoryshr.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Memory Sharing memshare.exe"Added by the IRCBRUTE.AG TROJAN!"
X Windows Memory Sharing memshr.exe"Added by the IRCBOT.MC BACKDOOR!"
X Windows Messanger Control Center svchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Messanger Control Center svhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Messanger Control Center winlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Messanger Control Center winlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows Messanger Control Center winsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows messenger messengers.exe"Added by the MYTOB.EI WORM!"
X Windows Messenger msnsmgs.exe"Added by the RBOT-ANJ WORM!"
X Windows Messenger msnmsg.exe"Added by the SPYBOT.BV WORM!"
X Windows Messenger 4.14 landisc.exe"Added by the SDBOT-KR WORM!"
X Windows Messenger Connect wmdsvc.exe"Added by the SLENFBOT.S WORM!"
X Windows Messenger Fileshare wivsvc.exe"Added by the SILLYIM WORM!"
X Windows Messenger Live MSN winlivemsnmessenger.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Messenger Live Startup windowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
X Windows Messenger Live Startup windowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
X Windows Messenger Messenger winmsg.exe"Added by the VELKBOT.A WORM!"
X Windows Messenger Panel wbcsvc.exe"Added by the IRCBOT.ADA BACKDOOR!"
X Windows Messenger Service winsmsgr.exe"Added by the RBOT-VW WORM!"
X Windows Messenger Service kaspersky.exe"Added by the MYTOB.HY WORM!"
X Windows Messenger Share wmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Messenger Starter wmvsvc.exe"Added by the DELF.DAX TROJAN!"
X Windows MeTaLRoCk service metalrock.exe"Added by the TASTYRED TROJAN!"
X Windows Micro Drivers wupdates32.exe"Added by the RBOT-AEH WORM!"
X Windows Microsoft Service [random filename]"Added by the AGENT-HCD TROJAN!"
X Windows Microsoft Services [8 random letters].exe"Added by the KOLAB.AW WORM!"
X Windows Microsoft Update wintask32.exe"Added by a variant of the SDBOT WORM!"
X Windows Microsoft Verifier winauth23.exe"Added by a variant of the RBOT WORM!"
U Windows Mobile Device Center wmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
U Windows Mobile-based device management wmdSync.exe"Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships
U Windows Mobile-based device management wmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
X Windows mod Verifier Windows-mod.exe"Added by the RBOT.DSU WORM!"
X Windows modez Verifier w1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
X Windows modez Verifier Window2.exe"Added by a variant of the RBOT WORM!"
X Windows modez Verifier WindowsLogon.exe"Added by a variant of the SDBOT WORM!"
X Windows modez Verifier Wwuamguard.exe"Added by the RBOT.EZJ WORM!"
X Windows modez Verifier winlogom.exe"Added by a variant of the RBOT WORM!"
X Windows modez Verifier Windows-.exe"Added by the RBOT-DIO WORM!"
X Windows modez Verifier taskmngr.exe"Added by a variant of the RBOT WORM!"
X Windows modez Verifier winl0g0z.exe"Added by the RBOT-FNB WORM!"
X Windows modez Verifier wuamguard.exe"Added by the RBOT.EZJ BACKDOOR!"
X Windows Monitor winmon.exe"Added by the SDBOT.VB WORM!"
X Windows Monitor arsetup.exeAdded by the SPAZBOX.A TROJAN!
X Windows Monitor Services winmonitor.exe"Added by the RBOT-XX WORM!"
X Windows Monitoring Service winmon.exe"Added by a variant of the SDBOT WORM!"
X Windows More Choice TopContext.exe"ZQuest adware"
X Windows Mouse Services winmouse.exe"Added by the IRCBOT.AGA BACKDOOR!"
X Windows Mouse Services winmouse64.exe"Added by the IRCBOT.AIA BACKDOOR!"
X Windows Mouse Utilities mouseutils.exe"Added by the RBOT-ABU WORM!"
X Windows ms Drivers msnup32.exe"Added by the SDBOT-AAL WORM!"
X Windows MS Update 32 fhm.exe"Added by the IRCBOT.GEN WORM!"
X Windows MS Update 32 sucker.exe"Added by the FORBOT-GJ WORM!"
X Windows MS Update 32 jebote.exe"Added by the FORBOT-GK WORM!"
X Windows MSConfig Startup Logger winlog.exe"Added by the RBOT.BCU WORM!"
X Windows MSN MSN.msn"Added by the TRIXCU.A WORM!"
X Windows Msn Live Messanger msnmsgsman.exe"Added by a variant of the SDBOT WORM!"
X Windows MSN Live Messanger wmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
X Windows MSN Live Messanger livemsngs.exe"Added by a variant of the SPYBOT WORM! See here"
X Windows MSN Live Messenger winlivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
X Windows MSN Live Messenger winmessengerlive.exe"Added by the IRCBOT.EAD BACKDOOR!"
X Windows MSN Updates wnd32.exe"Added by the IRCBOT-ABA TROJAN!"
X Windows MSN2 XP swchost.exe"Added by the KOLAB.AA WORM!"
X Windows MSX drivers winmsx.exe"Added by the RBOT-AYG TROJAN!"
X Windows Net Cfg service.exe"Added by a variant of the RBOT WORM!"
X Windows NetDDe wrmana32.exe"Added by the MYTOB.IM WORM!"
X Windows Nets WinNET.exe"Added by the RBOT-MO WORM!"
X Windows NetStart Service winsN2S.exe"Added by the RBOT-ZX WORM!"
X Windows NetStart Service2 winsN2S.exe"Added by the RBOT-ABN WORM!"
X Windows NetStart Service2 winsN2SD.exe"Added by a variant of the RBOT WORM!"
X Windows Netsystem Layer Netsystem.exe"Added by the RBOT.BEI WORM!"
X Windows Network Controller Mqguard.exe"Added by the FORBOT-CL WORM!"
X Windows Network Controller WinxPupd.exe"Added by the FORBOT-DK WORM!"
X Windows Network Controller winmms32.exe"Added by the FORBOT-ED WORM!"
X Windows Network Controller wingmt.exe"Added by a variant of the SDBOT WORM!"
X Windows Network Controller Win9x.exe"Added by the WOOTBOT.I WORM!"
X Windows Network Controller winmms32.exe.exe"Added by the FORBOT-ED WORM!"
X Windows Network Firewall firewall.exe"Added by the POEBOT-J WORM! Located in %System%"
X Windows Network Logon npesvc.exe"Added by the AGENT.ERZ TROJAN!"
X Windows Network Service winvc32.exe"Added by the RBOT.RY WORM!"
X Windows Network Service Msconf32.exe"Added by a variant of the RBOT WORM!"
X Windows Network Service Realteks.exe"Added by the RBOT-GTG WORM!"
X Windows Network Services winnetwork.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Network Services winnetwork128.exe"Added by the SLENFBOT.J WORM!"
X Windows Network Services winnetwork32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Network Services winnetwork64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Network Session nspsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Networking winsys32.exe"Added by the GAOBOT.FL WORM!"
X Windows Networking Monitor mdm.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
X Windows Networking Monitorin xmdmx.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Networking Monitoring mdm.exe"Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
X Windows Networks netcog.exe"Added by the MYTOB.FH WORM!"
X Windows Nivedia Driver sysMGT.exe"Added by a variant of the RBOT WORM!"
X Windows NNT [path to trojan]"Added by the RANKY.E TROJAN!"
X Windows NT twain.exe"Added by the AGENT.BEA TROJAN!"
X Windows NT 32 ntlogin32.exe"Added by the RANDEX.BRD WORM!"
X Windows NT Login ntlogin32.exe"Added by the SDBOT.WG WORM!"
X Windows NT Login Session Manager WNSM.EXE"Added by the RBOT.BIV WORM!"
X Windows NT Logon Application winlogon.scr"Added by the RBOT-ALP WORM!"
X Windows NT Service Name winshock.exe"Added by the RBOT-PK WORM!"
X Windows NT Service Name svchcst.exe"Added by the RBOT-NV WORM!"
X Windows NT Session Manager sess.exe"Added by a variant of the RBOT WORM!"
X Windows NT Update Manager WINL0G0N.exe"Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
X Windows NTFS Volume Manage [6 random letters].exe"Added by the RBOT.EDL BACKDOOR!"
X Windows OEM Tools winres32.exe"Added by the SPYBOT.FD WORM!"
X Windows Offical Netvvorks mywriter32.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Office Monitor emdm.exe"Added by the RBOT.AFV BACKDOOR!"
X Windows OLE Automation Server ole32aut.vbe"CoolWebSearch parasite variant"
X Windows Online Updater dllman.exe"Added by the RBOT-TE WORM!"
X Windows pack Control Center taskmam.exe"Added by the TOMETA-J TROJAN!"
X Windows Pc winmgr.exe"Added by the BIBOT-A WORM!"
X Windows PC Defender WP[random characters].exe"Windows PC Defender rogue security software - not recommended
X Windows PDG winpdg.exe"Added by the RBOT-ADW WORM!"
X Windows Performance Monitor wmscupd.exe"Added by the IRCBOT_GEN WORM!"
X Windows PNP winpnp.exe"Added by the RBOT-AKN WORM!"
X Windows PNP Server pnpsrv.exe"Added by the RBOT-AKM WORM!"
X Windows Pool Manager poolsc.exe"Added by the OBOT.CH WORM!"
X Windows Pool Setup poolmc.exe"Added by the IRCBOT.RU BACKDOOR!"
X Windows Population Logger winpo32.exe"Added by the AGENT.YKR WORM!"
X Windows Portable Device Drivers MSKSVRVS.EXE"Added by a TROJAN - see here"
X Windows Portable Devices MSKSVRTSS.EXE"Added by the SPYBOT.APEO WORM!"
X Windows Print Monitor Daemon [random filename].exe"Added by a variant of the SDBOT WORM!"
? Windows Print Spooler SCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
X Windows Print Spooler NavAgent32.exe"Added by an unidentified VIRUS
X Windows Print Spooler SVEHOST.EXE"Added by the SPYBOT.H WORM!"
X Windows Printing Driver WinPrint.exe"Added by a variant of the RBOT WORM!"
X Windows Printing Driver WinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
X Windows Printing Driver ciadvs.exe"Added by the BUZUS-M TROJAN!"
X Windows Printing Driver ciadvss.exe"Added by the ARCHIVARIUS series of WORMS!"
X Windows Printing Driver gpedits.exe"Added by the DCKEYG.A WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list