Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X WinXPService mirc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X WinXPService nero.exe"Added by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%"
X WinXPService taksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
X WinXPService taksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in the root directory
X WinXPService wacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %Windir%\Fonts"
X WinXPService wacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%\mnut"
X WinXpUpdate32 WinXpUpdate32.exe"Added by the AGENT.YWL WORM!"
X winxpusbd winxp64.exe"Added by a variant of the RBOT WORM!"
X winystems25 winystems.exe"Added by a variant of the SDBOT WORM!"
X Winz Firewall [random filename].exe"Added by a variant of the SDBOT WORM!"
X WinZap Check winzbp.exe"Added by the RBOT-AWZ WORM!"
X winzip [path to trojan]"Added by the BANCOS.G or BANCOS.K TROJANS! Note - this is not part of the popular WinZip file compression utility"
X Winzip [various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
X winzip winzip.exe"Added by the RBOT.BDA WORM! Note - this is not part of the popular WinZip file compression utility"
X winzip ir_ftp.exe"Added by the BANCBAN-S TROJAN!"
X Winzip Application winzip81.exe"Added by the RBOT-BKZ WORM!"
X Winzip Compression Utility Winzip32.exe"Added by the SDBOT-UI BACKDOOR!"
N WinZip Quick Pick WZQKPICK.EXE"Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip
X WinZip Update WinZip.exe"Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility"
X winzip32 winzip32.exe"Added by the BANCBAN-OE TROJAN! Note - this is not part of the popular WinZip file compression utility"
X WinZix Service wakeservice.exe"WinZix adware"
X winzSystam xly.exe"Added by a variant of the SDBOT WORM!"
X Win_api_driver system.exe"Added by the REVIRD TROJAN!"
X Win_BooT [path to file]"Added by the BANKER-GI TROJAN!"
X WIN_DRIVR32 shchostv.exe"Added by a TROJAN - see here"
X win_drivr32 zxhstn.exe"Added by the SMALL.CXO TROJAN!"
X Win_Library INISvc.exe"Added by the ANARCH WORM!"
X win_spool2 win_spool2.exe"Added by the SCKEYLOG.B TROJAN!"
X win_supp00.exe Win Const.exe"Added by the ASSASIN-H TROJAN!"
X win_upd.exe WINdirect.exe"Added by the MITGLIEDER.M TROJAN!"
X win_upd2.exe WINdirect.exe"Added by the BEAGLE.AO WORM!"
X Win_vader Win_vader.vbs"Added by the INVASION.A VIRUS!"
X win_[4 random char][4 random num] [4 random char][4 random num].exe"Added by the BANCOS.C TROJAN!"
X WIP Config GUI Winipcfgs.exe"Added by the RBOT-CN WORM!"
X Wireless Conections WireConnect.exe"Added by the SDBOT-VF WORM!"
U Wireless Connection Manager wirelesscm.exe"Wireless adapter configuration utility for D-Link's range"
X Wireless Connections WIRECONNECT.EXE"Added by the SDBOT-VM WORM!"
N Wireless Console wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
N Wireless Console 2 wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
N Wireless Console 3 wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
U Wireless PCI Card Configuration Utility WMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
U Wireless Presenter Wireless Presenter.exe"""Use your Nokia phone as a remote control for your PC with Nokia Wireless Presenter. Using Bluetooth wireless technology
X Wireless Provider Server wpsvr.exe"Added by the FORBOT-AD WORM!"
U Wireless Switching Setting Utility Switcher.exe"On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN
Y Wireless-G Notebook Adapter Gcc.exeLinkSys Wireless-G Notebook Adapter driver
U Wireless-G Notebook Adapter Utility WPC54CFG.EXE"Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)"
U WireLessKeyboard PS2USBKbdDrv.exe"Related to WireLess Keyboard Multimedia Combo Set by SANSUN Industries"
U WireLessMouse StartAutorun.exe MouseDrv.exe"Related to WireLess Mouse Multimedia Combo Set by SANSUN Industries"
X wise clockwise.exe"Added by the LAZAR-A TROJAN!"
X wistaantivirus wistaantivirus.exe"Wista Antivirus rogue security software - not recommended
X WIZZ dazzler.exe"Detected by Kaspersky as the DIALER.IS TROJAN!"
N wjview wjview.exeMS tool used to view window-based Java applications from the command line
N wkcalrem wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
N WkDetect WkDetect.exeChecks for updates to MS Works
N wkfud wkfud.exeA marketing program for MS Works
N WksSb WksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file
X WksSVC EXPLORER.exe"Added by the MYTOB-BW WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
N WkUFind WkUFind.exe"MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet
X Wkyo86 [path to worm]"Added by the PITIN-A WORM!"
X wl svhost32.exe"Added by the WOWPWS-AF TROJAN!"
X Wlan Drier Winusb2.exe"Added by the WOOTBOT.DC WORM!"
X Wlan Driver avscan.exe"Added by the WOOTBOT.DH WORM!"
U WLAN Manager WLANManager.exeWireless management utility for the T-Com Speedport W 100 Card WLAN PCMCIA card
N WLAN Status Tray Applet WLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
U wlancfg wlancfg.exeInventel wireless router related - required in order to automatically connect to the Net at bootup
Y wlancfg5 wlancfg5.exe"NetGear WG311v3 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first
N WLANSTA.EXE WLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
Y WLAN_Cfg.exe WLAN_Cfg.exeLinksys Instant Wireless USB Network Adapter driver
X wlinles svchost.exe"Added by the LIJI-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the ""spool"" sub-folder"
X WLiveCD.exe WLiveCD.exe"Added by the VB-EQI TROJAN!"
X wlm [path to trojan]"Added by the BANCOS-BCY TROJAN!"
X wlsass wlsass.exe"Added by the RANKY.CY TROJAN!"
N wltray wltray.exeSystem tray access to wireless LAN card configuration options
X WLWin WINSYS.EXE"Added by the NAVER.A WORM!"
X wm svhost32.exe"Added by the LINEAGE.CIS TROJAN!"
N WM VCR WMVCR.exe"WM Recorder allows you to record Windows Media(tm) streaming Video or Audio content. Can be accessed via Start Menu -> Programs"
Y Wm24Pan Wm24Pan.Exe"ESI external sound card driver"
X wm41a398 "rundll32.exe wm41a398.dll EnableRunDLL32"
X WMAudio services.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X WMAudio winlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
N WMBoot N/A"Associated with Logitech Wingman game controllers. Not required but what does it do?"
X wmcbaaca "rundll32.exe wmcbaaca.dll EnableRunDLL32"
N WMC_RebootCheck unregmp2.exe"Corrects problems with installations of Windows Media Player from version 9 onwards - see here and search for ""unregmp2.exe"""
X WMDM PMSP Service cssrss.exe"Added by the KNOCKIT-A TROJAN!"
X WMedia32 wmedia32.exe"Added by the BANGER TROJAN!"
X WMI Application Interface wmiapi.exe"Added by the SPYBOT.RBY WORM!"
X WMI Performance Adapter Services wmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
X WMI Service Client wmispv.exe"Added by the AUTORUN-ASX WORM!"
X WMI Standard Event Consumer - Scripting scrcons32.exe"Added by the RBOT-GRD WORM!"
X WMI Standard Event Consumer - Scripting scrcs.exe"Added by a variant of the RBOT-GRD WORM!"
U WMIEXE.exe wmiexe.exe"NT component
X Wminf Wminf.exe"Added by the GEMA TROJAN!"
X Wminfo Wminfo.exe"Added by the GEMA TROJAN!"
X wmiprevse wmiprevse.exe"Added by the BANKER-EPN TROJAN!"
X wmiprv wmiprv.exe"Added by the RBOT-WM WORM!"
X wmisrv wmisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X wmon jusched.exe"Added by the AGOBOT-OW WORM! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
X WMP Auto Update WINMEDUP.EXE"Added by the RBOT.CF WORM!"
Y WMP54Gv4 WMP54Gv4.exe"Linksys WMP54Gv4 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first
X wmplayer vergon1885.exe"Added by the BRONTOK-DG WORM!"
X wmplayer.exe wmplayer.exe"Added by the BANCBAN-CZ TROJAN! Note - this is not the valid Windows Media Player as the file is located in %Windir% rather than %ProgramFiles%\Windows Media Player"
U WMPNSCFG WMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
X wms3 wms3.exe"Added by the LEGMIR-AQG TROJAN!"
X WMSDOS-ServicePack2 cmd.exe /c C:WMSDOS.sys"Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted"
X wmsrc.exe wmsrc.exe"PrivacyRedeemer rogue privacy program - not recommended
X wmsys32 wmsys32.exe"Added by the BANPAES.B TROJAN!"
U WMUAgent.exe WMUAgent.exe"""WakeMeUp! is an advanced alarm clock for computers with Windows 2000
X wmupdate wmupdate.exe"Added by the AGENT-GGJ TROJAN!"
X wmv winmonv.exe"Added by the AGENT-DG TROJAN!"
? WM_LOGIN MSGLOGIN.EXE"Part of McAfee Firewall. What is it for and is it needed?"
X WN Services wnsvc.exe"Added by the KBBOT-A TROJAN!"
X WNAD WNAD.EXE"Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system
X wnddrv svchost.exe"Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X WNILOGON WNILOGON.exe"Added by the LEWOR-M TROJAN!"
X WNSA wnsts**.exe [* = random char]"PurityScan adware"
X WNSC wnsin**.exe [* = random char]"PurityScan adware"
X Wnsck2 driver wlogf.exe"Added by the SPYBOT-AF WORM!"
X WNSI wnscp**.exe [* = random char]"PurityScan adware"
X WNSI rwsa.exe"PurityScan adware"
X WNSO WNSO.exe"Baidu.SoBar adware"
X WNST wnsapi**.exe [* = random char]"PurityScan adware"
X wntlgns wntlgns.exe"CoolWebSearch parasite variant"
X wnxpupdate spvspool.exe"Added by the DABORA.B WORM!"
X wnxupdate updatexp.exe"Added by the COMBRA-G WORM!"
X won update WAPDATE.EXE"Added by the RBOT.N WORM!"
U WonderFrog WonderFrog.exe"Wonder Frog typing monitor"
N WooCnxMon CnxMon.exe"Wanadoo ISP software related - not required - here's how to bypass it"
X Woods Inc wcmd.exe"Added by the KILLFIL-O TROJAN!"
? WOOKIT GestMaj.exe EspaceWanadoo.exe"Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?"
? WOOKIT Shell.exe appLaunchClientZone.shl"Related to the Wanadoo broadband ISP (now rebranded as Orange). What does it do and is it required?"
? WOOKIT GestMaj.exe GestionnaireInternet.exe"Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?"
X woopie winamp.exe"Added by the AGOBOT.XV WORM! Note - this is NOT the popular Winamp media player"
N WOOTASKBARICON GestMaj.exe TaskbarIcon.exe"Wanadoo broadband ISP (now rebranded as Orange) taskbar icon - not required"
N Woowatch Watch.exe"Wanadoo broadband ISP (now rebranded as Orange) related - not required"
X WOOZ autodisc.exe"Added by the AGENT-CPS TROJAN!"
X word pair bopotsvr.exe"Added by the SHED-A TROJAN!"
N WordPerfect Office 1215 Registration.exe"Corel WordPerfect Office 12 registration wizard"
Y WordQ carat flag WordQcrs.exe"Related to WordQ Writing Aid Software"
X Words Words.exe"Added by the AGENT.GIT TROJAN!"
N WordWeb wweb32.exe"WordWeb - free theasaurus and dictionary. Start manually"
N WordWeb Pro wweb32.exe"WordWeb Pro - theasaurus and dictionary. Start manually"
? Workflo workflow.exe"Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required?"
X Working System Analyzer syswork.exe"Added by the FORBOT-FZ WORM!"
X worknote1 [filename].exe"Added by the MEETOT WORM!"
U WorkPace 3.0 workpace.exe"WorkPace - stress injury prevention software"
N Works Calendar Reminder wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
N WorksFUD wkfud.exeA marketing program for MS Works
U Workstation Scheduler wm95.exe"Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled
X Workstation Services wrkstn.exe"Added by the RBOT-OJ WORM!"
X Workstation Ver 5.0 vmware.exe"Added by the RBOT-AHB WORM!"
X WorldAntiSpy worldantispy.exe"WorldAntiSpy rogue spyware remover - not recommended
U WorldTime.exe WorldTime.exe"Part of AnyTime Organizer Deluxe from Individual Software Inc - ""Check the time anywhere in the world and know when to communicate. Place up to twelve clocks on your desktop"""
U Worm Detector wd.exe"Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam"
X wormexe winstart.exe"Added by the EARLYBIRD WORM!"
X Worms logon.bat"Added by the DELMP3-A WORM!"
X wovax wovax.exe"Added by the DAQA.A TROJAN!"
X wow bar.exe"PurityScan adware"
X wow wwf.exe"Added by the LINEAGE-Y TROJAN!"
X wow Launcher.exe"Added by the DELF-DOR TROJAN!"
X wow gewow.exe"Added by the WOWPWS-KA TROJAN!"
X wow64main.exe wow64main.exe"Added by the ALUREON.BT TROJAN!"
N Wpctrl wpctrlnt.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
N Wpctrl wpctrl95.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
N wpctrl95 wpctrlnt.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
N wpctrl95 wpctrl95.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
U WPCUMI WpcUmi.exe"Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as ""Reminder: View the Parental Controls activity report"". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray"
Y WPCycle.exe WpCycleWin.exe"Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end
X wpds.exe doriot.exe"Added by the SMALL-KY TROJAN!"
X wpds.exe wwnrot.exe"Added by the BAGLEDI-B TROJAN!"
X WPlayer WPlayer.exeIdentified as a variant of the LDPinch.A malware
X WPSVC Services wpnsc.exe"Added by a variant of the IRCBOT BACKDOOR!"
X wpwmgrs wpwmgrs.exe"Added by the MYTOB-DH WORM!"
X wpxmls [random filename]"Added by a variant of the SLAPER TROJAN!"
X wqdfadads sdqdad.exe"Added by the MULDROP.F TROJAN!"
X WQK WQK.exe"Added by the KLEZ.H WORM!"
? wr WR.EXE"??"
? WR Command wr.exe"??"
X wrclib "rundll32.exe wrclib.dllstart"
N WrCtrl WrCtrl.exe"Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work
X WRDialer WrDialer.exeWinPoet DSL dialler
? WRECK GUARD ??"??"
? WregBios wregbios.exe"Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?"
U wrexec wrexec.exe"Watch Right - monitoring program
? wriste wriste.exe"??"
U Write DVD-R! saimon.exe"Saimon's WriteDVD! ""gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks"""
U WrtMon.exe WrtMon.exe"Related to Presto PageManager which is bundled with Canon Scanners"
X ws2 32 svchst.exe"Added by the VOKEN-A TROJAN!"
X ws2help ws2help.exe"Added by a variant of the SMALL.AN TROJAN!"
X ws2_64.exe ws2_64.exe"Added by the AGENT.AOXK TROJAN!"
X WSAConfiguration wmon32.exe"Added by the GAOBOT.BAJ WORM!"
X WSAConfiguration svchostt.exe"Added by the AGOBOT.ZT WORM!"
X WSAConfiguration rpcxmn32.exe"Added by the AGOBOT.ABG WORM!"
X WSAConfiguration win32upd.exe"Added by a variant of the RBOT WORM!"
X WSAConfiguration drrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X WSAConfiguration winlogon32.exe"Added by the AGOBOT-WC WORM!"
X WSAConfiguration ntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X WSAConfiguration csrsvcs.exe"Added by the AGOBOT.VI WORM!"
X WSAConfiguration winmx32.exe"Added by the AGOBOT-JE WORM!"
X WSAConfiguration kernel32.exe"Added by the AGOBOT-KV WORM!"
X WSAConfiguration winmon32.exe"Added by the AGOBOT.TM WORM!"
X WSAConfiguration msnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
X WSAConfiguration syxtem32.exe"Added by the AGOBOT-MF BACKDOOR!"
X WSAConfiguration svchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
X WSAConfiguration1 csass.exe"Added by the AGOBOT.WH WORM!"
X wsass32 wsass32.exe"Added by the BANKEM-V TROJAN!"
? wsbklite wsbklite.exe"Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?"
X wsc mstdl.exe"MaCatte Antivirus 2009 rogue security software - not recommended
U WScheduler WScheduler.exe"Windows Scheduler - "schedule unattended running of applications
X wscmgr wscmgr.exe"Added by the AUTORUN-AA WORM!"
X wscnfty wscnfty.exe"Added by a variant of the RBOT WORM!"
X wscntfys wsscntfy.exe"Added by the SDBOT-TN WORM!"
X WSConfiguration spoolsc.exe"Added by the AGOBOT-HY WORM!"
X wscript.exe vabian.vbs"Added by the VABI VIRUS!"
X wscsvc.exe wscsvc.exe"Added by a password stealing BANKER TROJAN!"
X wscsvc32.exe wscsvc32.exe"Antivirus rogue security software - not recommended
X wsctf.exe wsctf.exe"Added by the JAMPORK.E WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list