Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XBS Mediaplayerbsplyr.exe"Added by the RBOT-OU WORM!"
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
Xelitemediaelitemediapop.exe"Added by the LOWZONE-BB TROJAN! Also known as Elitebar/EliteToolbar/EliteSidebar adware"
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
?Iapiap.exe"Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XMedia PassMediaPassK.exe"WindUpdates MediaPass adware"
XMedia PassMediaPass.exe"WindUpdates MediaPass adware"
XMediaPathProyecto1.exe"Added by the GRUEL WORM!"
XMediaPathRoot.exe"Added by the GRUEL WORM!"
XMediaPipe P2P Loadermpp2pl.exe"MediaPipe peer-to-peer file swapping program also reported as a hijacker"
Xmediaplayer.exemediaplayer.exe"Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
Xmediaplayer.exemediaplayer.exe"Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
XMediaPlayeSMediaPlayer_update.exe"Added by the STARTER-K TROJAN!"
Xmediapluscash.exemediapluscash.exe"MediaGateway adware"
XMicrosoft Updatemediap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Media Playermediaplayer.exe"Added by a variant of the RBOT WORM!"
NNokiaPCSuiteTrayLaunchApplication.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NNokiaPCSyncTrayPCSync.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
XQuicktime Mediaplayerwinmplyer32.exe"Added by the RBOT-PM WORM!"
XQuicktime Mediaplayrwnmplyr.exe"Added by a variant of the RBOT WORM!"
USIAPRO6sia.exe"Steganos Internet Anonym privacy software"
XVC5MediaPlayer[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XWindows Media Playerwmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
XWindows Media PlayerMediaPIayer.exe"Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
XWMI Application Interfacewmiapi.exe"Added by the SPYBOT.RBY WORM!"
XWMI Performance Adapter Serviceswmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
X[various names]mediaplayer32.exe"Added by a variant of the RBOT WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.