Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
Ya-squareda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
Ya-squareda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-squared Anti-Dialera2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya2adguarda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya2guarda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue security software - not recommended
XAntiSpyGuardAntiSpyGuard.exe"AntiSpyGuard rogue security software - not recommended
YAntiSpyWare2GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
YAshampoo AntiSpyWare 2AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiSpyWare 2 GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
YAVGuardAVGuard.exe"AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently"
Xavguard3876000b09274b.exe"AntiVirus ransomware security software - not recommended
Ya2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
Ybgbullguard.exe"Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster"
YBullGuardmgui.exe"Part of Bullguard antivirus"
YBullGuardBullGuard.exe"Part of BullGuard antivirus"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NData LifeGuardBACKWE~1.EXEData LifeGuard diagnostic tools for Western Digital's series of hard drives
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
Udguarddguard.exe"eAcceleration Stop-Sign security software related. Previously not recommended
XDr. Guarddrguard.exe"Dr. Guard rogue security software - not recommended
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
YEmsisoft Anti-Malwarea2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
XErrorGuardErrorGuard.exe"ErrorGuard rogue spyware remover - not recommended
XFBSearchSearchGuardPlus.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
UFilterguardFiltrgrd.exe"An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ""short-cut"" to access the basic features of SOS-Guardian
XFlashGuardFlashGuard.exe"Added by the AUTOIT.AL WORM!"
UGuardGuard.exe"Related to Phoenix Technologies Core Managed Environment (cME) Integration and Certification program"
XGuard ProVH339.exe"Guard Pro rogue security software - not recommended
XGuardCenterGuardCenter.exe"GuardCenter rogue security software - not recommended"
YGuardGui ApplicationGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UGuardianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
UGuardian PC Security ToolsPfft.exe"Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
XGuardPcs.exeGuardPcs.exe"GuardPcs rogue security software - not recommended
XGuardWWWGuardWWW.exe"GuardWWW rogue security software - not recommended
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
UHDDControlGuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UHDDControlGuard.exeHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
XIGuardPc.exeIGuardPc.exe"IGuardPc rogue security software - not recommended
Xkernel32dllguardpc.exe"Added by the FORBOT-CU WORM!"
XLanGuardlanguard.exe"Adware downloader - also detected as the SECONDT-C TROJAN!"
XLanGuard[path to trojan]"Added by the DLOADER-VO TROJAN!"
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
XLowRiskFileTypessysguard.exe"Added by the FAKEAV-UY TROJAN!"
ULUGuardLUGuard.exe"PC-Duo Remote Control enables your help desk technicians to take instant control of any remote desktop PC at any location across the LAN
YMamutu Guardmamutu.exe"Background Guard feature of Mamutu from Emsi Software GmbH - which provides behaviour rather than signature based protection that ""recognizes new and unknown Trojans
UMcAfee GuardianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
XMicrosoftguard.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
XMicrosoft Updatewauguard.exe"Added by the RBOT.AEE WORM!"
XMicrosoft Updatingnavguard.exe"Added by the RBOT.HW WORM!"
XMicrosoft Updatingwuamguards.exe"Added by the RBOT-BY WORM!"
XMS Unix BinaryWinGuard.exe"Added by the RBOT-ACL WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMyAVavpguard.exe"Added by the NETSKY.J WORM!"
XNetDyVisualGuard.exe"Added by the NETSKY.N or NETSKY.W WORMS!"
UNetGuardNetGuard.exeFBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor
XNetwork Security Guard**********.exe [* = random char]"CoolWebSearch parasite variant"
XNetwork Security Guard[path to trojan]"Added by the COLEM-A TROJAN!"
NNorton Crashguard Monitorcgmenu.exeTroublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
XNorton Guard 32ntguard32.exe"Added by a variant of the RBOT WORM!"
Yntl NetguardRPS.exe"ntl Netguard - anti-virus a package of services
YOfficeGuard RegCheckerogrc.exe"Kaspersky Labs anti-virus"
XOfficeGuardUIsvcss.exe"Added by the DEDLER-C TROJAN!"
XOnlineGuardOnlineGuard.exe"OnlineGuard rogue security software - not recommended
XPC Live GuardPC[random characters].exe"PC Live Guard rogue security software - not recommended
UPC Tools Privacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
YPCBGPCBODYGUARD.EXE"PC Bodyguard from Calluna - protects system files and settings from being deleted
YPCBODYGUARDPCBODYGUARD.EXE"PC Bodyguard from Calluna - protects system files and settings from being deleted
UPeerGuardianPeerGuardian_1.99b_pr14.exe"PeerGuardian - IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists
UPeerGuardianpg2.exe"PeerGuardian - IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists
Xpersonalguardpersonalguard.exe"Personal Guard 2009 rogue security software - not recommended
XPK Guardpkguard32.exe"Added by the GUAPIM WORM!"
YPrivacy GuardianPgIndex.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Index.dat"" option is selected for IE under ""Browsers"" when the users selects ""Clean Your Computer"". Index.dat files keep a track of pages
UPrivacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
YPrivacyGuardianIndexPgIndex.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Index.dat"" option is selected for IE under ""Browsers"" when the users selects ""Clean Your Computer"". Index.dat files keep a track of pages
XPSGuardPSGuard.exe"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XPSGuard spyware removerPSGuard.exe"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
YRecguardrecguard.exe"On HP computers
XSafeguard 2009sf2009.exe"Safeguard 2009 rogue spyware remover - not recommended
XSafeGuard Popup Blocker Updaterregsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Blocker Updater (required)regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeguard.exeSafeguard.exe"Super Spyware Killer rogue spyware remover - not recommended"
UScreen Guardlaunch.exe"Part of Access Denied security and privacy software"
UScreen Guard Message Scansgms.exe"Part of Access Denied security and privacy software"
XSecurity GuardSG[random characters].exe"Security Guard rogue security software - not recommended
XSecurity iGuardSecurity iGuard.exe"Security iGuard spyware remover - not recommended
XSpecial Firewall Serviceavguard.exe"Added by the NETSKY.G WORM! Note - do not confuse with AntiVir® antivirus which uses the same filename. This one is located in %Windir%"
XSpyGuarderspyguarder.exe"SpyGuarder rogue security software - not recommended
XSpyGuardPropgs.exe"SpyGuardPro rogue security software - not recommended. A member of the AVSystemCare family"
USpyware Guard Control Panelspywareguardcp.exe"""SpywareGuard provides a real-time protection solution against spyware"""
Uspywarefighterguardspfprc.exeSpyware Fighter - anti spyware program
YSpywareGuardsgmain.exe"""SpywareGuard provides a real-time protection solution against spyware"""
XSpywareGuardwinproc32.exe"Startpage adware Trojan"
XSpywareGuarddeinst_qfe001.exe"Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
Xspywareguardspywareguard.exe"Spyware Guard 2008 rogue spyware remover - not recommended
XSpywareguard lptt01Spywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareguard ml097eSpywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareGuardPluswinmm64.exeStartPage.ht homepage hijacker
UStorageGuardsgtray.exe"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop)
USurfinGuard Prowinsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
Xsysguardsysguard.exe"Added by the FAKEAV-KI TROJAN!"
Xsysguardns"Spyware Protect 2009 rogue spyware remover - not recommended
XSystem Guardmhguard.exe"Added by the RBOT-AGU WORM!"
USystem LifeGuard SchedulerSlsched.exe"System LifeGuard scheduler"
USystem Mechanic Startup GuardStartupGuard.exe"System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses
Xsystem toolsysguard.exe"Antivirus System Pro rogue security software - not recommended
Xsystemguardsystemguard.exe"System Guard 2009 rogue security software - not recommended
?SystemGuardAlerterSystemGuardAlerter.exe"Part of the Iolo System Mechanic maintenance software. What does it do?"
XSystemGuardCenterSystemGuardCenter.exe"System Guard Center rogue security suite - not recommended
XThe Spy Guardspyguard.exe"The SpyGuard rogue spyware remover - not recommended
XThe Spy Guard Monitorspyguard_monitor.exe"The SpyGuard rogue spyware remover - not recommended
UTHGuardTH_Guard.exe"Resident memory scanning for TrojanHunter"
UTHGuardTHGuard.exe"Resident memory scanning for TrojanHunter"
Xtipguard.exetipguard.exe"Privacy Commander rogue privacy program - not recommended
XTrojan Guarder Gold VersionTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
UTrojancheck 6 Guardtcguard.exe"TrojanCheck anti-trojan software"
XUltimate System GuardMainFAVProj.exe"Ultimate System Guard rogue security software - not recommended
YVAGuardVAGNT.exe"Vexira Antivirus - virus scanner from Central Command"
XVirtualPCGuardpgs.exe"VirtualPCGuard rogue security software - not recommended
XVirusGuardPluspgs.exe"VirusGuardPlus rogue security software - not recommended
XWindows Additional GuardWI[random characters].exe"Windows Additional Guard rogue security software - not recommended
XWindows firewall managermsguard.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows GuardWAUMGRD.EXE"Added by the RBOT-GY WORM!"
XWindows Guard ProWindowsGP.exe"Windows Guard Pro rogue security software - not recommended
UWindows Guardianthehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
UWindows GuardianFawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
XWindows modez VerifierWwuamguard.exe"Added by the RBOT.EZJ WORM!"
XWindows modez Verifierwuamguard.exe"Added by the RBOT.EZJ BACKDOOR!"
XWindows Network ControllerMqguard.exe"Added by the FORBOT-CL WORM!"
XWindows System Guardegun.exe"Added by the AGENT-NHY TROJAN!"
XWindows System Guardmsdn.exe"Added by the FAKEAV-BJD TROJAN!"
XWindows System Guardmsng.exe"Added by the EGGDROP-BO WORM!"
XWindows System Guardmsns.exe"Added by the DWNLDR-IGD TROJAN!"
XWindows Updatewinmguard.exe"Added by the RBOT-EM WORM!"
XWindows Xpnortonguard.exe"Added by the MYTOB-DZ WORM!"
YWinguardWGFE95.EXE"Dr Solomon's Virex antivirus"
Xwinguardwingrd32.exe"Added by a variant of the RBOT WORM!"
XWinGuardwinguard.exe"Added by the AGOBOT-OQ WORM! The file is located in %System%"
UWinGuardWinguard.exe"Winguard Popup Remover - pop-up stopper. The file is located in %ProgramFiles%\Winguard Popup Remover"
UWinGuard Prowgp.exe"Winguard Pro"
XWiniGuardWiniGuard.exe"WiniGuard rogue security software - not recommended. There are number of variants in this family sharing the same user interface - see here"
Xwinusb.dllwinguard.exe"Added by the FORBOT-CN WORM!"
?WRECK GUARD??"??"
XWSAConfigurationntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xwuanguardwuanguard32.exe"Added by the RBOT-AAF WORM!"
XXPGuardXP-Guard.exe"XP-Guard rogue security software - not recommended
XYourPrivacyGuardGDC.exe"YourPrivacyGuard rogue privacy tool - not recommended
UzSPGuardSpguard.exe""StartPage Guard (SPG) protects your PC from cyberscam
X[random][random]sysguard.exe"Antivirus Soft


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.