Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
NAolFixAolFix.exe"Run on Gateway Astra computers
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
XAXPFixerAXPFixer.exe"AdvancedXPFixer rogue security software - not recommended
NbigfixBIGFIX.EXE"BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
YCPQSTUTFIXstutfix.exe"For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton"
NDJRegFixregedit /s c:hpdjregfix.reg"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
XErrorFixErrorFix.exe"ErorrFix rogue system error and cleaning utility - not recommended
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
XFix ToolFix-Tool.exe"Fix Tool rogue system error and cleaning utility - not recommended"
YFix-itmxtask.exe"Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard
YFix-it AVmemcheck.exePart of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
XFixnicevcvw.exe"Added by the SDBOT TROJAN!"
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Mediaskxs��'�'%''msn'�%'fix''.exe"Added by the AGENT.ZOY TROJAN!"
XFontFixfontfix.exe"Added by an unidentified VIRUS
XHOT FIXGothic.exe"Added by the SDBOT.FIR WORM!"
XHOT FIXfilename.exe"Added by the SDBOT-DKM WORM!"
XHOT FIXE0chis.exe"Added by the HUPIGON.JTY TROJAN!"
XHOT FIXQOching.exe"Added by the WOOTBOT.VH WORM!"
XHOT FIXView.exe"Added by the WOOTBOT.BN WORM!"
XHOT FIXwindsys2.exe"Added by the AGOBOT.AOI BACKDOOR!"
Xhotefixmsnmanegers.exe"Added by the IRCBRUTE.AS TROJAN!"
Xhotfixmsnnmaneger.exe"Added by the WOOTBOT.AF WORM!"
XHotfix Updatsvdhost32.exe"Added by the GAOBOT.ZW WORM!"
UHP ScanPatchHPScanFix.exe"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used
XInternet2 Optimizerwkfix.exe"Added by a variant of the RBOT WORM!"
ULSPFixLSPmonitor.exe"eAcceleration Stop-Sign security software related. Previously not recommended
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft FixUppevblbvr.exe"Added by the RBOT.DWK WORM!"
XMicrosoft FixUpwnpzjpuw.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Hot Fix Updatemshotfix.exe"Affilred adware"
XMicrosoft Security Managementsp2fix.exe"Added by the RBOT.UB WORM!"
XMicrosoft Updatewkfix.exe"Added by the RBOT-ABZ WORM!"
XMicrosoft Updater ResourcesWinFixd32.exe"Added by the SPYBOT.CA WORM!"
XMicrosoft Updates 2 USBwgafixer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updates 5 USBsp3fixer.exe"Added by the RBOT-ADS WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdatespfix.exe"Added by a variant of the RBOT WORM!"
XMS Security Hotfixservice5.exe"Added by the GAOBOT.AG WORM!"
XMsg Fixagemsgfixed.exe"Added by the SDBOT.ZD WORM!"
XMSNFixdriver.exe"Added by the SILLYFDC.BBY WORM!"
?MsnFixermsnfixjs.js"Located in the HPbinmsnfix directory of a HP PC"
?Mufixmufix.exe"Part of INFOConnect
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
XNOD32 FiXregedt32.exe"NodFix is a is a potentially unwanted application. This application is given an (X) status because we does not and will not support Cracks or Warez. Do not delete the regedt32.exe as it is the legitimate Windows application. NodFix interferes with the default settings of the NOD32 AV application allowing to bypass its free using period as well as changes the default update server to that eval signatures thus allowing to update NOD32 without password. Note - to avoid interfering with the NOD32 application original settings no full cleanup can be provided"
UOnlinePCfix SmoothSurferSS.exe"Smooth-Surfer - blocks banners
?PLFFAPHotfixQ0306270.exe"Prolific Technology Inc. USB Flash Disk driver - is it required in startup?"
XPNP FIX[worm filename]"Added by the RBOT-AKQ WORM!"
XRecommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}RH.DLL"SmartPops search hijacker"
XRegistryCleanFixMFCregistrycleanfix.exe"RegistryCleanFix rogue registry cleaner - not recommended"
XRegistryFix.exeregistryfix.exe"RegistryFix rogue registry cleaner - not recommended
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
UResumeFixClocksresumefix.exe"Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards"
XRPC DCOM Vulnerability Patchmsgfix.exe"Added by the RBOT.S WORM!"
Nrun=pcfix2k.exepcfix2k splash screen
Xsasserfixpackage.exe"Added by the DABBER.B WORM!"
XSmartfixerSmartFixer.exe"SmartFixer rogue system error and cleaning utility - not recommended"
XSyncMonfixcomdos.exe"Added by the CLUNKY-B TROJAN!"
XSystem Updates 4mssysfix.exe"Added by the RBOT-ADU WORM!"
XSystemErrorFixerSysRep.exe"SystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
NTgAddServertgfix.exe"Software from SupportSoft (aka provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast
UTgsetsitetgfix.exe"See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation"
XUltimate FixerUltimateFixer.exe"UltimateFixer rogue system error and cleaning utility - not recommended"
XUSB Fix 1.1wuservices.exe"Added by a variant of the SDBOT WORM!"
XUSB Fixeswuafix.exe"Added by the RBOT-ABV TROJAN!"
XUSB Updates 2wugfixx.exe"Added by a variant of the RBOT WORM!"
XVundoFixToolVundoFixTool.exe"VundoFixTool rogue security software - not recommended. Note - do not confuse with the free VundoFix removal tool by Atribune"
XWiFix service[random filename]"Added by a variant of the SDBOT WORM!"
XWinDLL (ProsFix.exe)ProsFix.exe"Added by a variant of the IRCBOT BACKDOOR! The ""ProsFix.exe"" file is found in %System%"
XWindoFixWindoFix.exe"WindoFix rogue system error utility"
XWindows CODE Fix Msy Startupsmsyh32.exe"Added by the AGOBOT.AKK WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Fixintegator.exe"Added by the SDBOT.ZAB WORM!"
XWindows Fixerwinfix.exe"Added by the VIRUT-I VIRUS!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows Secure FixiPodFixer.exe"Added by the WOOTBOT.BM BACKDOOR!"
XWindows WMF Fixwinfix.exe"Added by the RBOT-FTQ WORM!"
XWinFix servicersswjzgp.exe"Added by the RBOT-FAE WORM!"
XWinFixer 2005wfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinFixer 2006uwfx6.exe"WinFixer 2006 web installer - ""foistware""
XWinFixer helperwfxcwr.exe"WinFixer web installer - ""foistware""
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinFixer2005uwfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinFixer2006uwfx6.exe"WinFixer 2006 web installer - ""foistware""
XWinFixer_2005uwfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinIFixerWinIFixer.exe"WinIFixer rogue security software - not recommended
XWINTASKMGRsp2winfix.exe"Added by the MYTOB.KJ WORM!"
XWinXP fix[path to file]"Added by the RANKY.P TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.