Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAi Gear HelpGearHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XccHelpccHelp.hta"Searchq adware"
NClient Access Help Updatecwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UCpu Level Up helpCpuLevelUpHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
Xcthelpcthelp.exe"Added by the SDBOT TROJAN!"
UCTHELPERCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
XCTHelpercthelper.exe"Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
UddhelperW815DM.EXE"Enuff Parental Control Software by Akrontech"
XDealHelperBrwsrdhbrwsr.exe"DealHelper adware"
XDealHelperDowndownload.exe"DealHelper adware"
XDealHelperUpdateDHUpdt.exe"DealHelper adware"
Xdebuggerhelp.pif"Added by the DELF-DRA WORM!"
NDialog HelperPDDLGHLP.EXE"Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs"
XDirectXddhelp32.exe"Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
NDLHelperEXEWATCH.exeDownload helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
XDLHelperEXE.exeN/ADownloader for Microgaming/Casino software - stealth installed
Xdllhelpdllhelp.exe"Added by the STARTPAGE.DQ hijacker"
Xdllhelpdllhlp.exe"Added by the Downloader-HI TROJAN!"
XDNHelper32DNHlp32.exeAdded by an unidentified WORM or TROJAN!
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
?ExxtremeHelperDemonexxdemon.exe"Creative Exxtreme graphics card related?"
NezHelperezHelper.exe"Part of the ezPeer+ ezHelper music sharing program."
XFCHelpFCHelp.exe"Added by either FCHelp adware or a variant of it"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
?HDhelptbhdhelp.exe"Associated with Philips Edge series soundcards. Is it required?"
?Helphelpext.exe"??"
Xhelphelp.scr"Added by the BANCOS-BBU TROJAN!"
XHelpWizardnil.exe"Added by the BANCOS-BCZ TROJAN!"
XHelplshost.exeIdentified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHelp Temp Filesemp32.exe"Added by the FORBOT-EC WORM!"
UHelpCentersprtcmd.exe /P HelpCenter"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
Xhelpctl.exehelpctl.exe"Added by the GASLIDE TROJAN!"
XHelpereschlp.exe"Added by the BLASTER.T WORM!"
XHELPERgreece_nm.exe"AsdPlug premium rate adult content dialer variant"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
XHELPERnew_zealand.exe"AsdPlug premium rate adult content dialer variant"
XHELPERsweden.exe"AsdPlug premium rate adult content dialer variant"
XHELPERcanada.exe"AsdPlug premium rate adult content dialer variant"
XHELPERfrance.exe"AsdPlug premium rate adult content dialer variant"
XHELPERtemp532.exe"AsdPlug premium rate adult content dialer variant"
Xhelper.dllrundll32.exe [path] helper.dll"CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XHelpExp.exeHelpExp.exe"Attune HelpExpress - spyware. Disable and uninstall - see here"
Xhelpmanagerspoler.exe"Added by the RANDEX.J WORM!"
Xhelpohelpo.exe"Added by the BANLOA-BU TROJAN!"
Xhelpwhelpw.exeAdware downloader
UHitman Pro SurfRight Helpersrhelper.exe"Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
UHondaHelperHondaHelper.exe"Part of Honda Music Link which allows you to use your Honda's audio system's controls to play and search for music on your iPod® in you car"
Xhosthelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XHTML Help Systemhhs.pif"Added by the RBOT-ATB WORM!"
XHTML32 Help Systemhhs32.pif"Added by the RBOT-ATE WORM!"
XIehelpersyslaunch.exeOutwar adware downloader
XIMJPMIG6.1HelpCat.exe"Added by the BESVERIT WORM!"
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
UISHelphelp.exe"ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it"
YiTunes HelperiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
XiTunes MusiciTunesHelper32.exe"Added by the SDBOT.CHK WORM!"
YiTunesHelperiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
YKB926239"rundll32.exe apphelp.dll ShimFlushCache"
XLive-Helplmns.exe"Added by the RBOT-GHE WORM!"
YLogitechCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YLogitechCommunicationsManagerCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YLogitechRegisterVideoApplicationsInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software
ULogitechVideo[inspector]InstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
XMicrosoft Data Helpercihost.exe"Malware
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Helpsvchosl.exe"Added by the AGENT-GPX TROJAN!"
XMicrosoft Help Supportmshelp32.exe"Addded by the KELVIR-BF WORM!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Help Systemmshelp32.exe"CoolWebSearch parasite variant"
XMicrosoft Helpdesk Sidemshelpdsk.exe"Added by the SPYBOT.ANJJ WORM!"
XMicrosoft Hyptertext Helpermshtha.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Security Monitor ProcessHelpMe.exe"Added by the VB.BJO TROJAN!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosoftUpdatesyshelper.exe"Added by the WOOTBOT.AC WORM!"
XMicrosoftUpdatessyshelped.exe"Added by the FORBOT-AZ WORM!"
XMircrosoft Technic HelpEditKey.exe"Added by the KOLABC.AS WORM!"
XMircrosoft Technic HelpRegKey.exe"Added by a variant of the SPYBOT WORM! See here"
UML1HelperStartUpML1HEL~1.EXE"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UML1HelperStartUpML1Helper.exe"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UMonitor Helpermonitor.exe"MyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
NMotive SmartBridgeBTHelpNotifier.exe"System tray icon for help from BT Broadband
XMSDN HELPmsdn.exe"Added by the AGOBOT.AIB WORM!"
XMSDNNhelp.exe"Added by the AGENT-GBK TROJAN!"
XMshelp32mshelp32.exe"CoolWebSearch parasite variant"
XMSNiTuneshelp.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Message Acount Helper 7.7msnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xmssyslanhelpermsmsgri32.exe"Added by the RANDEX.D WORM!"
UMW1HelperStartUpMw1helper.exe"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UMW1HelperStartUpMW1HEL~1.EXE"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XNetbios Helpernbthlp.exe"Added by the BANKER.Y TROJAN!"
UNetShow Powerpoint HelperNSPPTHLP.EXE"If disabled
UNSHelperaexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
Xolehelpolehelp.exe"Added by the BOOKMARKER.D or BOOKMARKER.G TROJANS!"
Xoncehelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XOnlineHelpmateGDC.exe"OnlineHelpmate rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
?OOLHELPTOOLHELPT.exe"??"
UP17Helper"Rundll32 P17.dll P17Helper"
?P17Helper"Rundll32 SPIRun.dll RunDLLEntry"
Xpqhelperpqhelper.exe"Searchcentrix hijacker"
XPrint Driver Helper Servicecrsrr.exe"Added by the AGENT-BC TROJAN!"
NQuickTime Update Completion xquicktimeupdatehelper.exe"Different numbers caused by number of launches. So if 3 updates are made separately
URegClean Expert SchedulerRCHelper.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
NRemHelpRemhelp.exeBT Voyager ADSL Modem Help related
XRemote Desktop Help Session ManagerWinRDH.exe"Added by a variant of the SDBOT WORM!"
XRichMediaHBHelper.dll"HenBang adware"
XRunhelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
Xs4helpers4helper.exe"Searchcentrix hijacker"
Xsck121helpsyss.exeAdded by a variant of the MAILBOT TROJAN!
NSM56 Helper Win32 Utilitysm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSOUNDMAN Microsoft Helpsoun.pif"Added by the RBOT-AIU WORM!"
UStormCodec_HelperStormSet.exe"Storm Codec is a codec pack for Windows"
USurfHelperSurfHelp.exe"Related to SurfHelper - a free tool to remove popup windows
Xsvchostolehelp.exe"Added by the BOOKMARKER.G TROJAN!"
Xsvchostwinhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xsyshelpsyshelp.exe"Added by the LOVGATE.C WORM!"
XsystemWinhelp.exe"Added by the IMAUT.CN WORM!"
XSYSTEM service helpersvchelper.exe"Added by the MONKBD-A WORM!"
XSYSTEM service helpersyshelp.exe"Added by a variant of the MONKBD-A WORM!"
XSystemHelp"RUNDLL32.EXE SystemHper.dllInstall"
XTask Helpwualcts.exe"Added by a variant of the RBOT WORM!"
XToolHelphwpv.exe"Added by a variant of the INFOSTEALER TROJAN!"
NTPKMAPHELPERTpKmapAp.exe"Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also
Ntray_helpertray_helper.exe"Tray Helper is an Email checker with additional tools
?Verizon Custom Uninstall TrackingInstallHelper.exe"Verizon related installation tracker. What does it do and is it required?"
XVmlistapphelps.dll"Added by the ALAMNAHE.A VIRUS!"
UWatcherHelperWaHelper.exe"Sierra Wireless Watcher™ - wireless configuration utility"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 FireWire DriverCTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
XWin32 Help32 Servicewin32help.exe"Added by the DELBOT-U WORM!"
XWindows Helpmailinfo.exe"Added by the MYTOB.JX WORM!"
XWindows HelpStney.exe"Added by the AGOBOT-VI WORM!"
XWindows Help Filewinhelper32.exe"Added by the SDBOT-QK TROJAN!"
XWindows Help Managersvchost32.exe"Added by the RBOT-OZ WORM!"
XWindows Help Servicewinhelpsv.exe"Added by the RBOT-LP WORM!"
XWindows Help Servicewinhlp.pif"Added by the RBOT-AKW WORM!"
?Windows Help SystemHelp.pif"??"
XWindows Helperwinhelp.exe"Added by the BANKER.APE TROJAN!"
XWindows Helperwsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Logon Applicationwin32help.exe"Added by the DELBOT-X WORM!"
NWindows Media Powerpoint HelperNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
XWindows Runtime Helpwin32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime HelpWinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
UWINDVDpatchCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
XWinexec32windhelp32.exe"Added by the AGENT-HKU TROJAN!"
XWinFixer helperwfxcwr.exe"WinFixer web installer - ""foistware""
XWinhelpwinhe1p.exe"Added by the QQPASS.E TROJAN!"
XWinHelpWinHelp.exe"Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir%"
XWinHelprealsched.exe"Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%"
XWinhelpTkBellExe.exe..."Added by the LOVGATE.Z WORM!"
Xwinhelpdns32.exe"Added by a variant of the RBOT WORM!"
XwinhelpUpdadv.exe"Added by the QQPASS-N TROJAN!"
XWinhelpTkBellExe.exe"Added by the LOVGATE.E WORM!"
UWinIRXHelperWinIRXHelper.exe"MSI Media Center Deluxe software - see here"
Xwinlogon.exehelper.exe"Added by the FAKESPY-A TROJAN!"
Xwinthelpwinthelp.exe"Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here"
Xws2helpws2help.exe"Added by a variant of the SMALL.AN TROJAN!"
Xwzhelperwzhelper.exe"Searchcentrix hijacker"
Xziphelpziphelp.exe"CoolWebSearch parasite variant"
X[various names]atl_helper.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]ATLIEHELPER.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]iehelper.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]MsNetHelper.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.