Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
XALG32ALG32.EXE"Added by the STARTPAGE.K hijacker"
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig33.exeConfig33.exe"Added by the SDBOT.T TROJAN!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XDebuggerdbg32.exe"Added by the MYTOB-FW WORM!"
UdvHighMemcfgmng32.exe"Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
XDxDialogdxdlg32.exe"Added by the VB-CXT TROJAN!"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
NEregreg32.exe"EReg is a software registration tool incorporated on products such as those by Broderbund
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
XG3GSMedia3.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
?g3dctlg3dctl.exe"??"
Xhotdlllvmmreg32.exe"BANKER.DX spyware"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
Xmelg34mdmd.exe"Added by an unidentified WORM or TROJAN - see here"
Xmelg3445mdmdd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft ALG32 Protocolalg32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft ALGXP Protocolalg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft boot system cfg32actboost.exe"Added by the BROPIA.R WORM!"
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Diagnosticmsdiag32.exe"Added by the RBOT-UC WORM!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft Synchronization Managerwincfg32.exe"Added by the SDBOT.DO WORM!"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Debuggerwincfg32.exe"Added by the SPYBOT.ZC WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMPR MSGmprmsg32.exe"Added by the MYTOB.CF WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
XMSCONFG32.EXEMSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
Xmsctfg32msctfg32.exe"Added by the RBOT-TJ WORM!"
XmsReg32 Loadermsreg32.exe"Added by the AGOBOT.IU WORM!"
Xmstg32.exemstg32.exeAdded by the AGENT.BI TROJAN!
XMstng32MSTng32.exe"Added by the TANG WORM!"
XMswincfgMswincfg32.exe"Added by the CYBRSPY.D TROJAN!"
XMSWindows Syspgmspg32.exe"Added by the RBOT-TB WORM!"
Xmysvcig38mysvcc.exe"Added by the RBOT-FOU WORM!"
Xmysvcig38recsl.exe"Added by a variant of the RBOT-FOU WORM!"
YNaimagent_UIEPOAgentnaimag32.exeWorkstation background program for Network Associates McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
YNaimagent_UInaimag32.exeWorkstation background program for Network Associates McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
XNT Logging ServiceSyslog32.exe"Added by the DONK.B WORM and variants!"
XOffice Monitoralg32.exe"Added by the RBOT-GMM WORM!"
NP2P Networking3P2P Networking3.exe"P2P Networking
XPC-Config32corona.exe"Added by the CORONEX.A WORM!"
XRecycleSTRmsreg32.exe"Added by the RBOT-TC WORM!"
XReg32Reg32.exeHijacker - redirecting to only-virgins.com
Xreg32reg32.exe"Added by the NOUPDATE.B TROJAN!"
XReg32reg33.exe"CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!"
XReg_WFTscanreg32.com"Added by the SENNASPY-F TROJAN!"
XRPCser32g3services.exe"Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrw servicealg32.exe"LOOPAD.A adware"
XSecureLoginMslg32.exe"Added by the REDZED WORM!"
XStrng32strngbox.exe"Added by the STRANO WORM!"
Xsyscfgsyscfg32.exe"Added by the KWBOT.S WORM!"
Xsyscfg34.exesyscfg34.exe"Added by the ELECTRON WORM!"
XSysConfigsyscfg35.exe"Added by the KAZMOR.C WORM!"
XSysConfigwincfg32.exe"Added by the SDBOT.ZD WORM!"
Xsysconfig32sysconfig32.exe"Added by the AGENT-MSP TROJAN!"
Xsysflg32sysflg32.exe"Added by a variant of the CRYPTER.C TROJAN!"
XSystem Configurationsyscfg32.exe"Added by the MYTOB.EA WORM!"
XSystem Diagnosticssysdiag32.exe"Added by the SDBOT.GEN TROJAN!"
XSystem MessengerSYSMSG32.EXE"Added by the SPYBOT-DK WORM!"
XSystem Unixsyscfg32.exe"Added by the RBOT-ZD WORM!"
Xsysug32.exesysug32.exeAdded by an unidentified TROJAN or WORM!
XT4skM4n4g3rWink3sk9.exe"Added by a variant of the IRCBOT TROJAN!"
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
XWin StartupWINCFG32.EXE"Added by the SPYBOT-CL WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 USB2 Driversyscfg32.exe"Added by the FORBOT-R WORM!"
XWindows Application Layerwalg32.exe"Added by the AGOBOT.ATN WORM!"
XWindows Application Layer Gatewaywalg32.exe"Added by the AGOBOT-AAZ WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows CPU hostwinbog32.exe"Added by a variant of the RBOT WORM!"
XWindows Debuggermsdbg32.exe"Added by a variant of the RBOT WORM!"
XWindows Debuggerwindbg32.exe"Added by the ZOTOB.L WORM!"
XWindows DLL LoaderWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Java UpdateweatherBug32.exe"Added by a variant of the RBOT WORM!"
XWindows Media Playervmmreg32.exe"Added by the AGENT.AQO TROJAN!"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWinDrg32windrg32.exe"Added by the DRUDGEBOT.A WORM!"
NWinFax PROFAXMNG32.EXE"WinFax PRO from Symantec - fax management software"
Xwinlogonmsreg32.exe"Added by the SDBOT.EO WORM!"
XWinMineD4NG3.vbs"Added by the BISCUIT.A WORM!"
XWinReg32 serviceholqdnoxpmeu.exe"Added by a variant of the SDBOT WORM!"
XWinsock2 driverdllcfg32.exe"Added by the SPYBOT.AG WORM!"
Uwsg32wsg32.exe"GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself!"
X[various names]Brong32.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.