Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
Xkalvsyskalv****.exe [* = random char]"EliteBar adware"
Xmicrosoft software****.exe [* = random char]Added by an unidentified WORM or TROJAN!
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft-software****.exe [* = random char]"Added by a variant of the RBOT WORM!"
Xmsmcms****.exe [* = random char]"ClientMan parasite variant"
XNarrator******.exe [* = random char]"Added by the QOOLOGIC TROJAN!"
XNetwork Security Guard**********.exe [* = random char]"CoolWebSearch parasite variant"
XorderShellorder****.exe [* = random char]"Added by the DLOADR-UN TROJAN!"
XOutlook Express Config*****.exe [* = random char]"Added by a variant of the RBOT WORM!"
Xromahere2************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
Xromahere3************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
XVbouncerDLVbouncerInner****.exe [* = random char]"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xweb******.exe [* = random char]"Added by a variant of the EASTO.A TROJAN!"
XWindowsRegKey upd4te2d4te*********.exe [* = random char]"Added by the RBOT.XQ WORM!"
XWinDSNXWin****.exe [* = random char]"Added by the DSNX TROJAN!"
XWINTwcp****.exe [* = random char]"PurityScan adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.