Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcoholAutomountaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
XAss and tittiesCMD32.EXE"Added by the SDBOT-GG BACKDOOR!"
Naxcmdaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
UBelgacomsprtcmd.exe /P Belgacom"Self-help support tool for Belgacom broadband users (provided by SupportSoft
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XCinnabd Prompt32CmdPrompt32.pif"Added by the ASSIRAL-B WORM!"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
XCmdcmd32.exe"Added by the TANKED WORM!"
Xcmd32configs.exe"Hijacker
Xcmd64cmd64.exe"CoolWebSearch Msconfd parasite variant"
Xcmdbcscmdbcs.exe"Added by the LINEAG-GKW TROJAN!"
Xcmdconcmdcon.exe"Added by the CRYPTER.A TROJAN!"
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
XCmdShell.exeCmdShell.exe"Added by the BCKDR-QHY BACKDOOR!"
XCommand Prompt32CmdPrompt32.pif"Added by the ASSIRAL.B WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XCTFMON.CPLCTFM0N.CMD"Detected by Symantec as the SILLYFDC WORM! See here"
Uddoctorv2sprtcmd.exe /P ddoctorv2"Comcast Desktop Doctor (provided by SupportSoft
UDellSupportCentersprtcmd.exe /P DellSupportCenter"Dell Support Center (provided by SupportSoft
XdirectxNTCmd.exe"Added by the SDBOT.D TROJAN!"
XdirectxPipeCmd.exe"Added by the SDBOT.D TROJAN!"
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDynamic Dns BinaryCMD16.EXE"Added by the RBOT-XM WORM!"
UeFax 4.1J2GDllCmd.exe"DLL Command Utility for version 4.1 of eFax Messenger from j2 Global Communications
UeFax 4.2J2GDllCmd.exe"DLL Command Utility for version 4.2 of eFax Messenger from j2 Global Communications
UeFax 4.3J2GDllCmd.exe"DLL Command Utility for version 4.3 of eFax Messenger from j2 Global Communications
UeFax 4.4J2GDllCmd.exe"DLL Command Utility for version 4.4 of eFax Messenger from j2 Global Communications
UeFax DllCmdJ2GDllCmd.exe"DLL Command Utility for eFax Messenger from j2 Global Communications
UeFax DllCmd 3.5J2GDllCmd.exe"DLL Command Utility for version 3.5 of eFax Messenger from j2 Global Communications
UeFax DllCmd 4.0J2GDllCmd.exe"DLL Command Utility for version 4.0 of eFax Messenger from j2 Global Communications
UeFax Live Menu 3.3J2GDllCmd.exe"DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications
?eSupIniteSupCmd.exe"Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
Uhcentertgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
UHelpCentersprtcmd.exe /P HelpCenter"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
Uhkcmdhkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
Xhotdlllremote.cmd"Added by the BANKER-EHG TROJAN!"
UHotKeysCmdshkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
XHotKeysCmds[path to worm]"Added by the PAHATIA-A WORM!"
Xhpcmdcmd.exe"Added by the ADCLICK-DS TROJAN!"
Uigfxhkcmdhkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfacehkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
Xjavaremote.cmd"Added by the BANKER-EHG TROJAN!"
NLive MenuDllcmd32.exe"eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here"
UMEDICsprtcmd.exe /P MEDIC"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
Umedicsp2sprtcmd.exe /P medicsp2"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMooNlightMySqld-nt.cmd"Added by the BOBANDY-A WORM!"
XMsgSvcMgr32cmdzxdll.exe"Added by the RBOT-AEK WORM!"
Xmsnmsg.exemscmd32.exeAdded by a variant of the AGENT.AH TROJAN!
XMyLifeCmdServ.exe"Added by the HOLAR.A WORM!"
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
Xnsdcmd servicesnsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xnsdcmd vid processnsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UnTuneCmdnTuneCmd.exe"Now part of NVIDIA System Tools under the ""Peformance"" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures
UNVIDIA nTunenTuneCmd.exe"Now part of NVIDIA System Tools under the ""Peformance"" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures
Unxpclientsprtcmd.exe /P nxpclient"NetExpert - ""India's first ever automated Broadband care technology."" Identifies and automatically fixes typical problems that may occur with your high-speed internet service"
XObjectDockBrico.cmd"Added by the BOBANDY-A WORM!"
UQUICKCAREsprtcmd.exe /P QUICKCARE"Qwest Broadband QuickCare (provided by SupportSoft
UQuickCare2.2sprtcmd.exe /P QuickCare2.2"Qwest Broadband QuickCare (provided by SupportSoft
Xrelinsoncmdno.exe"Added by the DROPPER-PS TROJAN!"
Usprtcmdsprtcmd.exe"Self-help support tool for a number of high-speed internet providers and computer suppliers such as Comcast
YSpybotDeleting*****[cmd or command] /c del [path] [filename]"Generated by Spybot Search & Destroy if it encounters files that cannot be deleted during runtime because they are locked by other processes. For example
USupport.com Scheduler and Command Dispatchertgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
Usys32cmdsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
UTalkTalksprtcmd.exe /P TalkTalk"Self-help support tool for TalkTalk Broadband users (provided by SupportSoft
Utgcmdtgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
Utgcmdhcenter.exe"Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
Utgcmdprovidersbctgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
YTrueMobile 1150 Client Managercmdel.exe"Client Manager for the Dell TrueMobile 1150 Series PC Card - ""a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna"""
XUCmdfallfour.exe"Added by the SDBOT-AZA WORM!"
Uwcmdmgrwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
Nwcmdmgr.exewcmdmgr.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
Uwcmdmgrlwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
UWildTangent Web Driver updaterwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Commandwincmd.exe"Added by the RBOT.ANV WORM!"
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
XWMSDOS-ServicePack2cmd.exe /c C:WMSDOS.sys"Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted"
XWoods Incwcmd.exe"Added by the KILLFIL-O TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.