Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
X%Temp%%Temp%delwdef2008.bat"WinDefender 2008 rogue privacy program - not recommended
XASDPLUGINtemp532.exe"AsdPlug premium rate adult content dialer"
UCleanTempCLEANT~1.EXE"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
UCleanTempCleanTemp.exe"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
?DelTmpDelTemp.exe"Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHelp Temp Filesemp32.exe"Added by the FORBOT-EC WORM!"
XHELPERtemp532.exe"AsdPlug premium rate adult content dialer variant"
XIDTemplatesIDTemplate.exe"Added by the BRONTOK-H WORM!"
XIEACCESStemp532.exe"AsdPlug premium rate adult content dialer variant"
Ujv16 PT TempFileToolTempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
XMicrosoft Machinetemp.exe"Added by the RBOT-FSQ WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft sdk tempsdktemp.exe"Added by the RBOT-ANP WORM!"
XMicrosoft Updateswtemp32.exe"Added by the RBOT-AHQ WORM!"
XMicrosoftkeysdsystemproc.exe"Added by the FORBOT-BI WORM!"
XSpoolerSubSystemProcessSpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
Xsuicidetempfile2.bat"Personal Protector rogue security software - not recommended
XSystem Presets[temp name].exe"Added by the HOSTINF-A WORM!"
XSystem32 Temp Servicesystmp.exe"Added by the RBOT-AET WORM!"
XSystemProcEvent[trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
XTempCom[randomname].com"Added by the TRAXG WORM!"
Xtempxtempx.exeAdded by the TEMPEX.A TROJAN!
XTok-CirrhatusIDTemplate.exe"Added by the RONTOKBRO.A WORM!"
NToshiba TEMPOToshiba.Tempo.UI.TrayApplication.exe"TEMPO is a software service developed by Toshiba. It will advise you on how to fine-tune the performance of your notebook and keep you informed of the latest Toshiba software and driver updates as soon as they are released. It does this by delivering various types of alerts into a special TEMPO inbox area on your notebook PC"
NTray TemperatureWeatherbug.exe"Weatherbug provides current outdoor temperature in the System Tray
Xwinabc"rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
XWindows Temperate Serviceswintmp.exe"Added by the SLENFBOT.ZW WORM!"
X[various names]TemplateDongle.exe"Wareout - malware masquerading as a spyware and dialer remover"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.