Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X windowsupdate RPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
X WindowsUpdate USRINIT.EXE"Added by the MADDIS.B WORM!"
X windowsupdate winupdate.exe"Added by the WARPI WORM!"
X WindowsUpdate svchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X WindowsUpdate winnnint.exeAdded by an unidentified WORM or TROJAN!
X WindowsUpdate [path to file]"Added by the DUPA-B TROJAN!"
X WindowsUpdate svchostw.exe"Added by the COBFINN_B TROJAN!"
X WindowsUpdate Nzil.exe"Added by the CULLER-C WORM!"
X WindowsUpdate Strad.exe"Added by the CULLER-D WORM!"
X Windowsupdate Windowsupdate.exe"Added by the BANKER.ARK TROJAN!"
X Windowsupdate wupdmgr98.exe"Added by a variant of the IRCBOT BACKDOOR!"
X WinDOwsUPdate smss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
X windowsupdate autoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
X WindowsUpdate svdhost.exe"Added by the AGOBOT-BP WORM!"
X WindowsUpdate twain.exe"Added by the AGENT.BEA TROJAN!"
X WindowsUpdate renew iexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X WindowsUpdate Service wuautlc.exe"Added by the RBOT-NR WORM!"
X Windowsupdate Service csrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
X WindowsUpdatecrss crss.exe"Added by a variant of the AGENT-HZ TROJAN!"
X WindowsUpdateDirect dupadirect.exe"Added by the DUPA-C TROJAN!"
X WindowsUpdatelsasss lsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
X WindowsUpdatem1 [path to file]"Added by the AGENT-AAJ TROJAN!"
X WindowsUpdatem2 svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X WindowsUpdateManager wupdmng.exe"Added by the IRCBOT.OE BACKDOOR!"
X WindowsUpdateNT svwhost.exe"Added by the SHELLOT-B TROJAN!"
X WindowsUpdateR regserv.exe"Added by the COBFINN_B TROJAN!"
X WindowsUpdatesvchostss svchostss.exe"Added by the AGENT-HZ TROJAN!"
X WindowsUpdatev4 w32gins.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
X WindowsUpdatewinsec winsec.exe"Added by a variant of the AGENT-HZ TROJAN!"
N WindowsWelcomeCenter "rundll32.exe oobefldr.dllShowWelcomeCenter"
X WindowsXP Module DirectX3D.exe"Malware
X WindowsXp Security spool.exe"Added by the RBOT-GRK WORM!"
X WindowsXP Update windowsxpupdate.exe"Added by the RBOT-PB WORM!"
X WindowsXPserv svcnxp32.exe"Addee by the NANINF-A TROJAN!"
X windowsxxx windowsxxx.exe"Added by the DUBING-A TROJAN!"
X windowsxxx2 windowsxxx2.exe"Added by the DUBING-A TROJAN!"
X Windows_LowLevel_Security_Core lsass.exe"Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair"
X Windows_Protect winsystem.exe"Added by a variant of the RBOT WORM!"
X Windows_Protect winregal.exe"Added by a variant of the RBOT WORM!"
X Windows_Protect lsas.exe"Added by the RBOT.ARO WORM!"
X Windows_Protect wincontrol32.exe"Added by the RBOT-ADK WORM!"
X Windows_Serivce SERVICE.exe"Added by the WOOTBOT.AH WORM!"
X Windows_Updates svthost.exe"Added by a variant of the SPYBOT WORM!"
X Windows_VXD user32.exe"Added by the PPORT TROJAN!"
X Windowz [original worm filename].vbs"Added by the NUKIP WORM!"
X Windowz Update V2.0 Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windowz Update V2.0 updater.exe"Added by the YODO-C WORM!"
X Window_Protect winsi32.exe"Added by a variant of the RBOT WORM!"
X Windoxs Update Center W32RfSA.exe"Added by a variant of the SDBOT WORM!"
X WinDrg32 windrg32.exe"Added by the DRUDGEBOT.A WORM!"
X WinDriv32 WinDriv32.exe"Added by the SMALL-BA TROJAN!"
X WinDriver Configuration windrvconf.exe"Added by the AGOBOT-LX TROJAN!"
X WinDrives WinDrives.EXE"Added by the SMALL.DIG WORM!"
X WINDRUN taskgmrs.exe"Added by the MYTOB-BT WORM!"
X windrv windrv32.exe"Added by an unidentified VIRUS
X WinDrv windrvx.exeAdded by a variant of the TIBSER.A downloader TROJAN!
X Winds Sers Agts [5 random letters].exe"Added by a variant of the RBOT WORM!"
X Winds Sersc Agts rzrzncrtz.exe"Added by the RBOT-GTV WORM!"
U WinDSL MTU-Adjust WinDSL_MTU.exeAdjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
? WinDSL_MTU WinDSL_MTU.exe"May be realted to Tiscali broadband
X WinDSNX Win****.exe [* = random char]"Added by the DSNX TROJAN!"
U Windstream Broadband Check-up Center matcli.exe"Part of the Windstream Broadband service from AllTel. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
X windtbs winsysvc"Added by the AGOBOT-NH WORM!"
X WindUpdates [path to trojan]"Added by the AGENT.BF TROJAN!"
X WindUpdates WinUpdt.exeWindupdates adware variant
U WINDVDpatch CTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
N WinDVR SchSvr SchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
N WinDVRCtrl WinDVRCtrl.exeControl center software for an AOpen VA1000 TV tuner card
X Windws Configuration Loader LEXPLORE.exe"Added by the SODABOT WORM!"
X WinDynManager amsnmsg.exe"Added by the SDBOT-IA BACKDOOR!"
X winenv winenv.exe"Added by a variant of the SDBOT WORM!"
X WinEssential Keyhost.exeHijacker - hailing from jraun.com
X WinEssential keyword.exe"Jraun adware"
X WineWork WineWork.exe"Added by the BANCOS.AB TROJAN!"
X WinEx lexplore_.exe"Added by the MSNOPT-A TROJAN!"
X WinExec Winexec.exe.vbs"Added by the AINESEY.A WORM!"
X WinExec WinExec.exe"Added by the FALUS-A WORM!"
X WinExec Lsass.exe"Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X WinExec32 WinExec32.exe"Added by the KAZWIN WORM!"
X Winexec32 windhelp32.exe"Added by the AGENT-HKU TROJAN!"
X winexecs winexecs.exe"Added by the SILLYFDC.BBB WORM!"
U WinFast Schedule Wfwiz.exeLeadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter
U Winfast2KLoadDefault "rundll32.exe wf2kcpl.dllDllLoadDefaultSettings"
U WinFastDTV DTVSchdl.exe"Scheduler for WinFast DTV digital TV cards from Leadtek Research Inc"
U Winfast_2K WF2K.EXESystem Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card
U WinFast_Gamma "Rundll32.exe wfcpl.dll DllLoadGammaRampSettings"
U WinFast_Taskbar "rundll32.exe wftask.dll WFDllLoadDefaultSettings"
X WinFavorites WinFavorites.exe1Loudmarketing.com adware downloader
N WinFax PRO FAXMNG32.EXE"WinFax PRO from Symantec - fax management software"
N WinFax PRO Controller WFXCTL32.EXEFrom WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Y WinFaxAppPortStarter wfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
X WinFire WF.exe"Added by the DELF-SY TROJAN!"
X WinFix service rsswjzgp.exe"Added by the RBOT-FAE WORM!"
X WinFixer 2005 wfx5.exe"WinFixer 2005 web installer - ""foistware""
X WinFixer 2006 uwfx6.exe"WinFixer 2006 web installer - ""foistware""
X WinFixer helper wfxcwr.exe"WinFixer web installer - ""foistware""
X WinFixer service [random filename].exe"Added by a variant of the SDBOT WORM!"
X WinFixer2005 uwfx5.exe"WinFixer 2005 web installer - ""foistware""
X WinFixer2006 uwfx6.exe"WinFixer 2006 web installer - ""foistware""
X WinFixer_2005 uwfx5.exe"WinFixer 2005 web installer - ""foistware""
U WinFlip WinFlip.exe"WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon
U WinFlip.exe WinFlip.exe"WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon
X WinFlyer32.dll WinFlyer32.dll"Added by the WINFLYER TROJAN!"
X winfont winfont.exe"Added by the DEATH TROJAN!"
X winform winform.exe"Added by the PWS-ALB TROJAN!"
U WinFoxV2 WF2K.EXESystem Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card
X WinFX cssrs.exe"Added by the AGOBOT.FX WORM!"
X WinFX cssrs.exe"Added by the GAOBOT.CD WORM!"
X WinFX lsas.exe"Added by the GAOBOT.CD WORM!"
U WinGate Engine Monitor wgengmon.exe"WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine
X WinGate initialize WinGate.exe"Added by the LOVGATE.F WORM!"
X wingerver2.0.exe wingerver2.0.exe"Added by the GRAYBRD-AE TROJAN!"
X wingo wingo.exe"Added by the BEAGLE.AW or BEAGLE.AV WORMS!"
X wingo [various filenames]"Added by the BAGLE-AU WORM!"
N WinGuage Pro WGPRO32.EXE"Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications
Y Winguard WGFE95.EXE"Dr Solomon's Virex antivirus"
X winguard wingrd32.exe"Added by a variant of the RBOT WORM!"
X WinGuard winguard.exe"Added by the AGOBOT-OQ WORM! The file is located in %System%"
U WinGuard Winguard.exe"Winguard Popup Remover - pop-up stopper. The file is located in %ProgramFiles%\Winguard Popup Remover"
U WinGuard Pro wgp.exe"Winguard Pro"
N WinHacker "rundll32.exe wh95.dll HackMe"
X Winhelp winhe1p.exe"Added by the QQPASS.E TROJAN!"
X WinHelp WinHelp.exe"Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir%"
X WinHelp realsched.exe"Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%"
X Winhelp TkBellExe.exe..."Added by the LOVGATE.Z WORM!"
X winhelp dns32.exe"Added by a variant of the RBOT WORM!"
X winhelp Updadv.exe"Added by the QQPASS-N TROJAN!"
X Winhelp TkBellExe.exe"Added by the LOVGATE.E WORM!"
X winhlp.exe winhlp.exe"Added by the FORMGLIEDER TROJAN!"
X winhlp3.exe winhlp3.exe"Added by a variant of the EASTO.A TROJAN!"
X Winhlp32 Wscript.exe Msexec32.vbs"Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Msexec32.vbs"" file is found in %System%"
X winhlp32.exe winhlp32.exe"Added by the EASTO.A TROJAN!"
X winhlpp32.exe winhlpp32.exe"Added by the GAOBOT.SY WORM!"
X Winhost wintt.exe"Added by the LOLAWEB.B TROJAN!"
X Winhost win.exe"Added by the DLOADER-AP TROJAN!"
X Winhost yahoo.exe"Added by the DELF-KM TROJAN!"
X Winhost winhost.exe"Added by the REATLE.F WORM!"
X winhost.exe winhost.exe"Added by the LOHAV-R TROJAN!"
X winhost32.exe winhost32.exe"Added by the TABDIM TROJAN!"
X WinHound WinHound.exe"WinHound spyware remover - not recommended
X WiniBlueSoft WiniBlueSoft.exe"WiniBlueSoft rogue security software - not recommended
X WinIeRun winierun.exe"Added by the RNWATCH-A WORM!"
X WiniFighter WiniFighter.exe"WiniFighter rogue security software - not recommended
X WinIFixer WinIFixer.exe"WinIFixer rogue security software - not recommended
X WiniGuard WiniGuard.exe"WiniGuard rogue security software - not recommended. There are number of variants in this family sharing the same user interface - see here"
X winimage wvsvc.exe"Added by the RBOT.TX WORM!"
X WinINet services.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
X wininet wininet.exe"Added by the STUBBOT-C WORM!"
X wininet.dll regperf.exe"Added by the ZLOB TROJAN and variants!"
X wininet32 wininet32.exe"Added by the RAZNEW-A TROJAN!"
X wininetd wininetd.exe"Added by the WINET TROJAN!"
X Winini.dll winini.vbs"Added by the STARTP-M TROJAN!"
X Winini32 winini32.exe"Added by the AGOBOT-J WORM!"
X wininit wininit.exe"Added by the WOLLF.16 TROJAN!"
X WinInit Win86.exe"Added by the SMALL-PB TROJAN!"
X winint winint.exe"Added by the SDBOT-ADA WORM!"
X winIogom winIogom.exe"Added by the BANCBAN-ML TROJAN!"
X winipsec winipsec.exeUnidentified malware
U WinIRXHelper WinIRXHelper.exe"MSI Media Center Deluxe software - see here"
X winis winis.exe"Added by the RBOT-WI WORM!"
X WiniShield WiniShield.exe"WiniShield rogue security software - not recommended
X Winjava xml dirx9.exe"Added by the HAXDOOR ROOTKIT!"
X Wink*.exe Wink*.exe [* = random char]"Added by a variant of the KLEZ WORM!"
U Winkb6 winkb6.exe"Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content
X WinKernel WinKer.exe"Added by the MIRAB or SERVIDOR TROJANS!"
X WinKernel [path to virus]"Added by the PLEA VIRUS!"
X winkernel32 wWin32.com"Added by the BANSAP TROJAN!"
U WinKey winkey.exe"Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system
X winla winla.exe"Added by the DLOADR-AQL TROJAN!"
X winldr [path to file]"Added by the VIDLO-P TROJAN!"
X winldr Rechnung.pdf.exe"Added by the ACS TROJAN!"
U winlgn winsplg.exe"Related to the Sentry Parental Controls software"
X winlgz2 winlgz2.exe"Added by the KILLFIL-Q TROJAN!"
X winlibs.exe winlibs.exe"Added by the EVAMAN.C WORM!"
X WinLibUpdate libupdate.exe"Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
X WinLibUpdate32 libupdate32.exeAdded by the BIONET.405 TROJAN!
X WinLibUpdte libupdte.exe"Added by the BIONET.318 TROJAN!"
X Winlink winlink32.exe"Added by the GAOBOT.AAY WORM!"
X Winlme windll.exe"Added by the GOP.F WORM!"
U WinLoad Winload.exe"PCTattletale is a surveillance software program that monitors user activity
X winload winload.exe"Added by the AGENT-GNY TROJAN! Note - the file is located in %ProgramFiles%\Internet Explorer"
X WinLoader [random filename]"Added by variants of the SUBSEVEN TROJAN!"
X winlocatorupdate updatewinlocator.exeLocator adult content toolbar related
X winlog winlog.exe"Added by the GAOBOT.DF WORM!"
X winlog windowxs.exe"Added by the SDBOT-KT BACKDOOR!"
X winlog manager winlog.exe"Added by the DONBOMB.A TROJAN!"
X winlog.exe winlog.exe"Added by the BCKDR-RBJ TROJAN!"
X WINLOG0N WINLOG0N.EXE"Added by the MYDOOM.BI WORM!"
X WinLogin winlogin.exe"Added by the AGOBOT-IX WORM!"
X winlogin win32x.exe"Browser hijacker
X winlogin ReadMe.exe"Added by the SILLYFDC.BBT WORM!"
X Winlogin.exe log.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X winlogin.exe logfile.exeAdded by the AGENT.AH TROJAN!
X winlogin.exe mspaint.exeAdded by a variant of the AGENT.AH TROJAN!
X Winlogin.exe steam.exeAdded by a variant of the AGENT.AH TROJAN!
X winlogins.exe winlogins.exe"Added by the OPTIX.H BACKDOOR!"
X winlogoff winlogoff.exe"Added by the AGOBOT-TR WORM!"
X winlogon winlogin.exe"Added by the RANDEX.E WORM!"
X winlogon winlogon.exe"Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X winlogon msreg32.exe"Added by the SDBOT.EO WORM!"
X winlogon winlogon32.exe"Added by the MASLAN.C WORM!"
X winlogon wpwlogon.exeAdded by an unidentified WORM or TROJAN!
X WINLOGON wscript.exe WINLOGON.vbs"Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
X Winlogon Lsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X winlogon nvchost.exeAdded by an unidentified WORM or TROJAN!
X Winlogon WINLOGON.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process
X winlogon system.exeAdded by a variant of the DELF.CNS TROJAN!
X winlogon cleanmg.exe"Added by the AGENT-ICR TROJAN!"
X Winlogon scssrr.exe"Added by the AGENT-LXB TROJAN!"
X winlogon service urx.exe"Added by the SPYBOT.EN WORM!"
X Winlogon Shell Explorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
X Winlogon.exe N/A"CoolWebSearch parasite variant - resets home page to an adult content site"
X winlogon.exe helper.exe"Added by the FAKESPY-A TROJAN!"
X winlogon.exe msole32.exe"Adware
X winlogon32_ [path to file]"Added by the RULAND.A WORM!"
X WinLogonnd winlogonnd.exe"Added by the AGENT-NNQ TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list