Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Winsock32driver sp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
X Winsock32driver win32server.exe"Added by the BACKDOOR-AZV TROJAN!"
X Winsock32driver ZoneAlarmPr0.exe"Added by the HACKARMY-B TROJAN!"
X Winsock32driver ZoneLockup.exe"Added by the HACARMY.D TROJAN!"
X Winsock32driver win32server.exe"Added by the HACARMY.F TROJAN!"
X Winsock32driver winXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
X Winsock32driver svchhost.exe"Added by the HACKARMY.I TROJAN!"
X Winsock6 MIC driver ieservicesupd.exe"Added by the SPYBOT.AFZ WORM!"
X winsockdriver tskmg.exe"Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!"
X winsockdriver winsock2.2.exe"Added by a variant of the SPYBOT WORM!"
X winsockdriver iexplor.exe"Added by the BLATIC.A WORM!"
X winsockdriver winsock3.exe"Added by the SPYBOT-DO WORM!"
X winsockdriver bot.exe"Added by the WARPIGS-D WORM!"
X winsockdriver winsock4.1.exe"Added by a variant of the IRCBOT TROJAN! See here"
X winsockdriver winsock2.exe"Added by the SPYBOT-AC WORM!"
X WinSocketComponent nthost.exe"Added by an unidentified VIRUS
X Winsocks2 driver mznmgr.exe"Added by a variant of the SDBOT WORM!"
U WINSOS VERIFY WINSOS.EXE"WinSOS - ""deletes spyware
X WinSP [path] REGEDIT.EXE -s [path] sysreg.reg"Added by the STARTPA-ME TROJAN!"
X WINSP00L WINSP00L.EXE"Added by the AGENT.XAB TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
X winspd32dll winspd32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X WinSPF windrv32.exe"Added by the MYDOOM.T WORM!"
X WinSPF winspf32.exe"Added by the MYDOOM.S WORM!"
X Winspl winsplx.exe"Added by a variant of the TROLL-A TROJAN!"
X winsplog wsmmlog.exe"Added by the MAILBOT-CA TROJAN!"
X Winspool spoolsvr.exe"Added by a variant of the SDBOT WORM!"
X WinSpyControl pgs.exe"WinSpyControl rogue security software - not recommended. A member of the AVSystemCare family"
X WinSpyDemo WinSpyDemo.exe"WinSpy rogue spyware remover - not recommended"
X WinSpyKiller WinSpyKiller.exe"WinSpyKiller rogue spyware remover - not recommended
X WinSpywareProtect WinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
X WinSpywareProtect (ver. 5.1) WinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
X WinSrv kn0x.exe"Added by the HOBBIT.F WORM!"
X WinSrv SHIZZLE.EXE"Added by the HOBBIT.C WORM!"
X Winsrv winsrv.exe"Added by the OPASERV.T WORM!"
X winsrv winsrv.exe"Added by the NETSNAK-B TROJAN!"
X winsrv3 services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Y winssnotify winssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
X WinsSystem syssmss.exe"Added by the DELF.IG TROJAN!"
X WinStabilizer WinStabilizer.exe"Added by the AGOBOT-SW WORM!"
X WinStar IEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
X WinStart services.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field"
X WinStart WinStart.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
X WinStart Wscript.exe WinStart.vbs"Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
X WinStart winstart32.exe"Added by the PUROL WORM!"
X WinStart WinStart.pif"Added by the CONE.E WORM!"
X winstart winstart.exe"Added by the SCKEYLO-AB TROJAN!"
X WinStart001 WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
X WinStart001.EXE WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
X winstats winstats.exe"Added by the GARGAFX TROJAN!"
X Winsta~1 winsta~1.exe"GoHip foistware"
X WinSth16 WinSth16.exe"Added by the CAKE WORM!"
X winstro RUN32DLL.exe"Added by the FTP_ANA TROJAN!"
X winsupdater winsupdater.exe"Added by the ALCRA-F WORM!"
X winsupdatesysmngr64 winsys64mnger.exe"Added by the RBOT-BAG WORM!"
X WinSvc16.exe WinSvc16.exe"Added by the SDBOT.FQ TROJAN!"
X winsvc32 winsvc32.exe"Added by the IRCBOT-AEG WORM!"
X winsvc32.exe winsvc32.exe"Added by the GREPAGE TROJAN!"
X Winsvr msupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
X Winsvr [random filename].exe"Added by the ADCLICK-DK TROJAN!"
X Winsvr manager DDEsvr.exe"Added by the TIRBOT-C WORM!"
X winsy32.exe winsy32.exe"CoolWebSearch parasite variant"
X winsync ******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
U Winsys Winsys.exe"Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself"
X WINSYS [path to trojan]"Added by the GOLDPLAY TROJAN!"
X winsys syschost.exeAdded by an unidentified TROJAN!
X WinSys winmgmt.com"Added by the VB.EIW WORM!"
X WinSys system.exe"Added by the DAPROSY WORM!"
X WinSys32 Winsys32.exe"Added by the CIGIVIP TROJAN or RECKUS WORM!"
X winsys32 Driver winsys32.exe"Added by the LOONY-O TROJAN!"
U WinSysAppMon WinSysRM.exe"Home & Family Content Filter related. See here"
X winsysban [path to trojan]"Added by the CLICKER-CD TROJAN!"
U WinSysCheck sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
X winsyslog lptt01 winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X WinSysM 371662M.exe"Added by the WINKO.AO WORM!"
X WinSysModule [path to trojan]"Added by the AGENT-DIQ TROJAN!"
X WinSysStartUpWKbLw TaskSystemDll.Exe"Added by the BACKZAT.G WORM!"
X WinSyst32 winsyst32.exe"Added by the MORB WORM!"
X WinSystem winsystem.exe"Added by the WHITEBAIT WORM!"
U WinSystem WinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
X Winsystem Freevideo5.EXE"Added by the AGENT.FZS WORM!"
X winsystem.sys smss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
X WinSystems winsystems16.exe"Added by the SDBOT-CZT WORM!"
X winsystems25 winsystems.exe"Added by the RBOT-CNZ WORM!"
X winsysupd [path to trojan]"Added by the STARTPA-NI TROJAN!"
X WinSysW 371662L.exe"Added by the WINKO.AO WORM!"
X WINT wcp****.exe [* = random char]"PurityScan adware"
X WINT wcp**.exe [* = random char]"PurityScan adware"
X WinTask Wintask.exe"Added by the HIPO or LEMIR.F TROJANS!"
X WINTASK taskgmr.exe"Added by the MYTOB.I WORM and variants!"
X WINTASK taskgamr.exe"Added by the MYTOB.AU WORM!"
X WINTASK sys32.exe"Added by the MYTOB.K WORM!"
X WINTASK msmgrxp.exe"Added by the MYTOB.AQ WORM!"
X WINTASK iexplorer.exe"Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X WINTASK taskgmr32.exe"Added by the MYTOB.BU WORM!"
X WINTASK msvhost.exe"Added by the MYTOB-AR WORM!"
X WINTASK t4skmgr.exe"Added by the MYTOB-AK WORM!"
X WINTASK taskfile.exe"Added by the MYTOB.EF WORM!"
X WINTASK taskgm.exe"Added by the MYTOB-AO WORM!"
X WINTASK taskgmrs.exe"Added by the MYTOB.DH WORM!"
X WINTASK yahooicons.exe"Added by the MYTOB-HM WORM!"
X WINTASK t4skgmr.exe"Added by the MYTOB.CM WORM!"
X WINTASK DLL jusched32.exe"Added by the MYTOB.AI WORM!"
X WINTASK DLL32 smsrss.exe"Added by the MYTOB.BS WORM!"
X WINTASK DLL32 updatewin"Added by the MYTOB.NI WORM!"
X WinTask driver wintask.exe"Added by the DLOADER-NA TROJAN!"
X WINTASK32 taskgmr32.exe"Added by the MYTOB.BN WORM!"
X WINTASK32 taskgmrr.exe"Added by the MYTOB.FX WORM!"
X wintask32 Jwintask.com"Added by the NAFBOT-A WORM!"
X WINTASKMANAGER taskgmr.exe"Added by the MYTOB-AF WORM!"
X WINTASKMGR ccsrs.exe"Added by the MYTOB.Q WORM!"
X WINTASKMGR sp2winfix.exe"Added by the MYTOB.KJ WORM!"
X WINTASKS taskgmr.exe"Added by the MYTOB.BO WORM!"
X WINTASKS winxpro.exe"Added by the MYTOB.EZ WORM!"
X WinTasks DLL Library (32-bits) winkll.exe"Added by the RBOT-AJZ WORM!"
U WinTasks Traybar wintasks.exe"WinTasks - ""Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task
X wintasks.exe wintasks.exe"Added by the EVAMAN WORM!"
X Wintbp.exe wintbp.exe"Added by the ZOTOB.E WORM!"
X Wintbpx.exe wintbpx.exe"Added by the ZOTOB.F WORM!"
U wintective wintective.exe"Wintective logs keystrokes
X WintelUpdate [path to trojan]"Added by the SMALL-EKW TROJAN!"
X winter happy.exe"Added by the SDBOT-YF WORM!"
N Wintercooler Pro WINCOOL.EXE"Wintercooler Pro - utility that monitors CPU usage
X winthelp winthelp.exe"Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here"
N WinTidy WinTidy.exe"Desktop icon manager from
X Wintime Wintime.exe"Added by the HARNIG TROJAN!"
U WinTime wintime.exe"WinTime - change desktop icons' color and font"
N Wintime Wtxpload Wxpload.exe Wintime"Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet
X WinTimer msupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
X Wintl msdred.exeIdentified as a variant of the Trojan-Spy.Win32.Agent.cch malware
X wintnask32.exe wintnask32.exe"Added by the RBOT-AFP WORM!"
X wintnl.exe wintnl.exe"Added by a variant of the ZOTOB.K WORM!"
X wintnpx.exe wintnpx.exe"Added by the ZOTOB.H WORM!"
X WinTools WToolsA.exe"Wintools adware"
N WinTOTAL Scheduler guru.exeWinTOTAL Real estate appraisal software related
X WinTouch WinTouch.exe"Detected by Kaspersky as the AGENT.BUO TROJAN!"
X WinTray wintray.exe"Added by the LEGUARDIEN.B TROJAN!"
X wintsk32dll wintsk32dll.exe"Added by the RBOT-AAJ WORM!"
X winudll.exe winudll.exe"Added by the MITGLIE-CE TROJAN!"
X winui z.exe"Added by the KONDELI TROJAN!"
X WinUp svchost.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""4350"" sub-folder"
X winupated.exe winupated.exe"Added by a variant of the SDBOT WORM!"
X winupd "RUNDLL32.EXE [random value].dll _mainRD"
X winupd winupd.exe"SearchNew adware"
X winupd.exe winupd.exe"Added by the BEAGLE.M or BEAGLE.N WORMS!"
X WinUPD32 explorer.exe"Added by an unidentified VIRUS
X winupdat winupdat.exe"Added by the CANBOT.A WORM!"
X WinUpdate RBSKQQBO.EXE"Added by the VBSWG2B.A WORM!"
X WinUpdate wmbem.exe"Added by the REVCUSS.B TROJAN!"
X WinUpdate updsys.exe"Added by a variant of the RBOT WORM!"
X winupdate winupdate.exe"Added by the ALCAN.B WORM!"
X WinUpdate svhost.exe"Added by a variant of the SDBOT WORM!"
X WinUpdate svchots.exe"Added by the SMALL.GXJ TROJAN!"
X winupdate jusched.exe"Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
X Winupdate lsas.exe"Added by the COSPET.JR TROJAN!"
X Winupdate Engine wupeng.exe"MalwareCrush rogue security software - not recommended
X WinUpdate Loader msnnm.exe"Added by the REVCUSS.C TROJAN!"
X Winupdate Service winxp.exe"Added by the SPYBOT.IR WORM!"
X winupdate.exe winupdate.exe"Added by the RADO TROJAN!"
X winupdate.reg winupdate.exe"Added by the SPYBOT.EAS WORM!"
X winupdate2846 vbsystem35.exe msvbrun.exe"Added by a variant of the MUTIN-C TROJAN!"
X winupdate86.exe winupdate86.exe"Added by the FAKEAV-AHQ TROJAN!"
X WinUpdateAdministrator CSRSS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
X WinUpdateB breatle.exe"Added by the BRATLE.AWORM!"
X winupdateconn [path to file]"Added by the COMBRA-A WORM!"
X winupdateconn_ Explorer.EXE"Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Winupdatee winsvcc.exe"Added by the AGENT.AN TROJAN!"
X winupdatefiv_ [path to file]"Added by the COMBRA.C WORM!"
U WinUpdateProtection csrss.exe"EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
X WinUpdater update.exe"Added by the STARTPAGE.C TROJAN!"
X winupdates winupdates.exe"Added by the ALCRA-B WORM!"
X winupdate_ [path to file]"Added by the COMDOR.A WORM!"
X WinUpdating WinUpdating.exe"Added by the AGENT-GSC TROJAN!"
X WinUPDbc winupdbc.exe"Added by the BANKER-DSN TROJAN!"
X WinUpdsv winupdsv.exe"Added by the DROPO MACRO!"
X winupdt RUNDLL32.EXE [random.dll]"Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder"
X winupdtl winupdtl.exe"SecondThought adware"
X WinUpgrader [path to trojan]"Added by the AGENT-DZ TROJAN!"
X WinUPPD.exe [random filename]Added by an unidentified WORM/TROJAN!
X winur winrun.exe"Added by the WINUR.B WORM!"
X winusb.dll winguard.exe"Added by the FORBOT-CN WORM!"
X WinUser32K usr32wink.exeAdded by the HK TROJAN!
X WinUsr WinUsr.exe K1S2"Added by the CLUNK.A WORM!"
U WinUtilities Memory Optimizer ToolMemoryOptimizer.exe"""WinUtilities Memory Optimizer optimizes the memory management of your system and boost-up its performance amazingly!"" MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
X Winux Piriax Service PH32.EXE"Added by the RANDEX.G WORM!"
X winversion winversion.exe"Browser hijacker
U WinVNC WinVNC.exe"WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet. Now superseded by RealVNC"
X WinVNC iexplorer.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X winvxd32 winvxd32.exe"Added by the GABLOLIZ.A WORM!"
X winwan lptt01 winwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X winwan ml097e winwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X WinwebSecurity WinwebSecurity.exe"Winweb Security rogue security software - not recommended
X winword winword.exe"Added by the TORPID-C TROJAN!"
X WINWORD.exe WINWORD.exe"Added by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name
X WinWorks vstmgr.exe"Added by the AGOBOT.ACJ WORM!"
X winwsl.exe winwsl.exe"Added by the ZOTOB-J WORM!"
X WinX Security Center WinX Security Center.exe"WinX Security Center rogue security software - not recommended
X WINX16 winx16.exe"Added by the AGOBOT-LS WORM!"
X WinXDefender WinXDefender.exe"WinXDefender rogue spyware remover - not recommended
X WinxDiagUpdate WinxDiagUpdate"Added by the RBOT.BWQ BACKDOOR!"
X winXP 33.exe"Added by the ANPES WORM!"
X WinXP plugin1.exeAdded by the Downloader-JW TROJAN!
X WinXP csrss.exe"Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools"
X winxp winxp.exe"Added by the BRONTOK-DN WORM!"
X WinXP fix [path to file]"Added by the RANKY.P TROJAN!"
X WinXP Processor Generator v1.2 intspnsr32.exe"Added by the SDBOT.LP WORM!"
X Winxp update Cappp.exe"Added by the RBOT.DKO WORM!"
X WinXp Updater winxp32.exe"Added by the RBOT-HG WORM!"
X WinXP-98 CSRSS.exe"Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools"
X winxpdll32.exe winxpdll32.exeAdded by a variant of the SMALL downloader TROJAN!
X WinXPHome plugin2.exe"Added by the malicious INOR.T SCRIPT!"
U WinXPLoad "Rundll32 LoadDll LoadExe WinXPLoad.exe"
X WinXProtector WinXProtector.exe"WinXProtector rogue security software - not recommended
X WinXPService lsass.exe"Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
X WinXPService taksmgr.exeIdentified as a variant of the IRC/Flood.tool malware
X WinXPService Tskdbg.exe"Added by the MDROP-BPQ TROJAN!"
X WinXPService ctfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""ctf"" sub-folder"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list