Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X7f8ez****.exe 9idf"Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folder"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
UCamera DetectorCAMDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
UCamera DetectorDEVDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
Xcftmon32taskmgr*.exe [* = number]"Added by the SOWSAT.C and SOWSAT.J WORMS!"
Xcjbcjb*.exe"Added by a variant of the AGENT.ALZE TROJAN - where * is a random digit and the file is located in %ProgramFiles%\cjb"
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XCr**.exe [* = random char]Cr**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
Xctfmontaskmgr32*.exe [* = number]"Added by the SOWSAT.B WORM!"
Xctfmon32taskmgr32*.exe [* = digit]"Added by the SOWSAT.C WORM!"
XD3**.exe [* = random char]D3**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
Xdm***.exe [* = random char]dm***.exe [* = random char]"Wareout - malware masquerading as a spyware and dialer remover"
XDsidp-******.exeAdded by an unidentified adware where ****** are random characters
XDxsys*.exe [* = random number]"Added by the DEXTER.A WORM!"
UFreeRAM XPFreeRAM XP Pro *.exe"FreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XGay_Sexy_**Gay_Sexy_**.exePremium rate adult content dialler (where * is a random char)
XHot_Tarts_**Hot_Tarts_**.exePremium rate adult content dialer (where * is a random char)
Xhp centerBACKWEB-*****.exe"See here - ""messaging service that automatically sends you support information
XIE**.exe [* = random char]IE**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XieupdateMCP****.exe [**** = random char]"Added by the ASOXY TROJAN!"
XIP**.exe [* = random char]IP**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XJava**.exe [* = random char]Java**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xkalvsyskalv****.exe [* = random char]"EliteBar adware"
XKavSvc******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
XKernelChecksys****.exe [* = digit]Added by an unidentified TROJAN!
Xkeyboardkeyboard*.exe [* = number]"Detected by Kaspersky as the VB.ZG TROJAN!"
NKodak Software Updaterbackweb*****.exe"Software updater for Kodak Easyshare digital cameras"
Xli-multi****li-multi****.exeAdult web-dialler - **** is random
Xli-thund****li-thund****.exeAdult web-dialler - **** is random
Xli-vita****li-vita****.exeAdult web-dialler - **** is random
Xloader32sys*****.exe [***** = random digit]"Added by the DOMCOM TROJAN!"
XMembers area******.exe [* = random digit]Premium rate adult content dialer
XMfc**.exe [* = random char]Mfc**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xmicrosoft software****.exe [* = random char]Added by an unidentified WORM or TROJAN!
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft-software****.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosofts Security Manager****.exe [**** = random char]"Added by the RBOT-WH TROJAN!"
Xms window update******.exe [* = random character]"Added by a variant of the RBOT WORM!"
Xms************* [* = random digit]ms*************.exe [* = random digit]"WINBO adware"
XMs**.exe [* = random char]Ms**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xmsmcms****.exe [* = random char]"ClientMan parasite variant"
XMyAccessMediatmp**.exe [* = random char/digit]"My AccessMedia toolbar related
XNarrator******.exe [* = random char]"Added by the QOOLOGIC TROJAN!"
XNero.ma***.exe [*** = 2 to 3 digits]"Added by the JONBARR.D WORM!"
XNet**.exe [* = random char]Net**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XNetwork Security Guard**********.exe [* = random char]"CoolWebSearch parasite variant"
XNt**.exe [* = random char]Nt**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XorderShellorder****.exe [* = random char]"Added by the DLOADR-UN TROJAN!"
Xorder_Shellorder_****.exe [* = random letter]"Added by the AGENT.ARO TROJAN!"
XOutlook Express Config*****.exe [* = random char]"Added by a variant of the RBOT WORM!"
Xpnpsvc_lock******.exe [* = random digit]Browser hijacker
XPOPPopSrv***.exe"PeopleonPage foistware
XPublic Microsoft ODBCODBC32*.exe [* = random char]"Added by the MASLAN.D WORM!"
Xredirectredirect*.exeDotcomtoolbar/Linksummary hijacker installer - where * is a random digit
Xrequesterrequester.*.exe"Added by a variant of the MUQUEST.A trojan - NOTE: the * stands for a digit
Xromahere2************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
Xromahere3************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
Xsalysaly*****.exeAdded by a variant of the AW.AWK TROJAN!
XSBIinstall_sbd_**.exe"Installer for a number of rogue security products and error fixing tools - where ** represents a 2 letter language code
XSdk**.exe [* = random char]Sdk**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XShellibm0000*.exe [* = digit]"Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe
XSManagersmanager.*.exe [* = digit]"Added by the AGENT.BJO TROJAN!"
Xsoft2********.exe [* = random digit]"Added by the KARDPHISHER TROJAN!"
XSpecialOffersSpecialOffers*.exe [* = digit]"SpecialOffers adware"
Xsys************* [* = random digit]sys*************.exe [* = random digit]"WINBO adware"
XSys**.exe [* = random char]Sys**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XSystem service**pokapoka**.exe"EliteBar adware - where ** represents the numbers 61 to 79"
Xsystwtraytwitty**.exe [** = random digits]"Added by the KOOBFACE.C WORM!"
XThumbs Plus *.*thmbplus**.exe"Added by the AGOBOT-AAF WORM! ** is a combination of a random digits and characters"
XUlubionesys****.exe"Ulubione adware"
NUpdates from HPbackweb*****.exe"See here - ""messaging service that automatically sends you support information
XUSB Driver4UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
XVbouncerDLVbouncerInner****.exe [* = random char]"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XWAPIwts**.exe [* = random char]"PurityScan adware"
XWCPSWint**.exe [* = random char]"PurityScan adware"
Xweb******.exe [* = random char]"Added by a variant of the EASTO.A TROJAN!"
XWebsxInt*****.exeAdult content dialler - where ***** are random
Xwin************* [* = random digit]win*************.exe [* = random digit]"WINBO adware"
XWin32SystemMonitor***.exe [* = random char]Browser hijacker
XWindows Defenderwdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Addswda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Monitorwdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Updaterwdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindowsRegKey upd4te2d4te*********.exe [* = random char]"Added by the RBOT.XQ WORM!"
XWinDSNXWin****.exe [* = random char]"Added by the DSNX TROJAN!"
XWink*.exeWink*.exe [* = random char]"Added by a variant of the KLEZ WORM!"
XWinMediamsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinsvrmsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
Xwinsync******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
XWINTwcp****.exe [* = random char]"PurityScan adware"
XWINTwcp**.exe [* = random char]"PurityScan adware"
XWNSAwnsts**.exe [* = random char]"PurityScan adware"
XWNSCwnsin**.exe [* = random char]"PurityScan adware"
XWNSIwnscp**.exe [* = random char]"PurityScan adware"
XWNSTwnsapi**.exe [* = random char]"PurityScan adware"
XWTSSwapi**.exe [* = random char]"PurityScan adware"
Xxrt_Shellxrt_****.exe"XRT spyware"
X_pnd_Panda Antivirus_pnd_*****.exe [* = random char/digit]Added by the AGENT.NAK TROJAN!


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.