Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
NAHQInitahqinit.exePart of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
XAppletINITINITIATE.EXE"Added by the AGOBOT.XV TROJAN!"
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YavinitAVINIT9X.EXE"Command Antivirus related"
Yavxlniavxinit.exe"Anti-virus part of BitDefender virus scanner/firewall"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
YCertStoreInitCertStoreInit"Aladdin eToken authentication and password management"
?ChronitelInitTVCHTVINIT.EXE"??"
NDocuMagix InitPWATCH.EXE"PaperMaster is an application for the PC designed to automate the process of organizing
YDvpInitExeDvpinit.exe"Command Antivirus related"
?eSupIniteSupCmd.exe"Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
NHigh Definition Audio Property Page ShortcutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
?HP Visualize InitHpVisIni.exe"HP Visualize software related. What does it do and is it required?"
XInit[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XInit32Init32.exe"Added by the WINEX.A TROJAN!"
XInitial Pageinstall.exeEasySearch browser hijack installer
YInitialize8x88x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
UJobHisInitJobHisInit.exeUsed by Ricoh network printers to enable network printing from the client
XlogonUiInitRundll32.exe rgtndz.dll"Identified as a variant of the Trojan-Clicker.Win32.Agent.bqy malware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""rgtndz.dll"" file is found in %System%"
NMHINITMHINIT.EXEPart of the Cybermedia Clean Sweep package
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft Updatewininit.exe"Added by the RBOT-AKR WORM!"
XMicrosoft Update 32wininit.exe"Added by the RBOT-ANY WORM!"
XMicrosoft Update 32wininit32.exe"Added by the RBOT-AKJ WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32wuinit.exe"Added by the AGOBOT-UE WORM!"
XMicrosoft Update 33init.exe"Added by the RBOT-ATT WORM!"
XMicrosoft Update 64 BITwininit32.exe"Added by the RBOT-AHE WORM!"
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft WinUpdateWinNTinit32.exe"Added by the RBOT.VS WORM!"
XMicrosotufed Update 32windinit.exe"Added by the RBOT-CTJ WORM!"
XModule Call initialize"RUNDLL32.EXE reg.dll ondll_reg"
XMS Initialmstinitial.exe"Added by the IRCBOT.ASP BACKDOOR!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
UMultiCAM InitializerMCamBoot.exe"The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled"
NNInitNInit.exeNorton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
?NvColorInit"rundll32.exe NvQtwk.dll NvColorInit"
NNvInitialize"rundll32.exe NvQtwk.dll NvXTInit"
?OEPowerPlugswinoeinit.exe"??"
XPCuserinity.exe"Added by the PROVIS-A TROJAN!"
XPC2Xinitial.bat"Added by the DWNLDR-FZZ TROJAN!"
UPMXInitpmxinit.exeRestores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gamma
NPowerQuest Startup UtilityPQINIT.EXE"From a visitor - "This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up
Xrun=svcinit.exe"CoolWebSearch parasite variant"
Uscheduler_monitorinit_scheduler.exe"Scheduler for ReaConverter advanced image converter"
USchedulingAgentmstinit.exe"MS Scheduling Agent in WinNT - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting
XShellExplorer.exe init32m.exe"Added by the DLSW-B TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""init32m.exe"" file is located in %System%"
?SHINITVshinitv.exe"??"
NShockwave InitSWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
XsoftIce Update 32wininits.exe"Added by the RBOT-ANB WORM!"
XSVC Servicesvcinit.exe"Added by the SINIT TROJAN!"
XSVC Servicesvcinit.exe"CoolWebSearch parasite variant"
XSysInitsvchost.exe"Added by the STARTPA-BD TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XSysInitwininit32.exe"Added by the XABOT WORM!"
Xsysinitservices.exe"Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golumm"
XSyskeysysinit.exe"Added by the BEAGLE.AX WORM!"
XSystem Initsysteminit.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Initializationmsmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem Initializationpayload.dat"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
Xsystem32.dllsysteminit.exe"CoolWebSearch parasite variant - re-directing to your-search.info"
XSystemInitiservc.exe"Added by the FIZZER WORM!"
Xsysteminitsysteminit.exe"Added by the SILLYFDC-AN WORM!"
UTrojanShieldInit.exe"TrojanShield"
XUnix File Supportinit3.exe"Added by the RBOT-ZN WORM!"
Xupddateitwinit.exe"Added by the RBOT-MS WORM!"
XUserinitlsass.exe"Added by the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Program Files%\Common Files%\System"
Xuserinitwinlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xuserinitsmss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xuserinitchoo_003956f4"Added by the PEED.16896 TROJAN!"
Xuserinitntos.exe"Added by the AGENT-ECU TROJAN!"
XUserinitcologsver.exe"Added by the DROPPER.DJO TROJAN!"
XUserInit StartUprpcxuisu.exe"Added by a variant of the SDBOT WORM!"
Xuserinit.exeuserinit.exe"Added by the HAXDOOR-DP TROJAN!"
Xvirtualwinit.exe"Added by the MUGLY.A or MUGLY.B WORMS!"
XVxD Driver Initializationntsvxd.exe"Added by the SDBOT-LW WORM!"
XWin32 USB Driverwinxpinit.exe"Added by the SDBOT.AA TROJAN!"
XWin32 Wmls Driverwinitr32.exe"Added by the WOOTBOT.B WORM!"
XWindows Global Initngpsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service HostingUSERINIT.exe"Added by the GOMMER-A WORM!"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows System Initwinit32.exe"Added by a variant of the RBOT WORM!"
XWindowsUpdateUSRINIT.EXE"Added by the MADDIS.B WORM!"
XWinGate initializeWinGate.exe"Added by the LOVGATE.F WORM!"
Xwininitwininit.exe"Added by the WOLLF.16 TROJAN!"
XWinInitWin86.exe"Added by the SMALL-PB TROJAN!"
Xxccinitrundll33.exe xccdf16_090131a.dll"Added by the BUZUS-AD TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090131a.dll"" file is located in %Windir%"
Xxccinitrundll33.exe xccdf16_090305a.dll"Added by the BUZUS-AF TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090305a.dll"" file is located in %Windir%"
X[random name]??erinit.exe"PurityScan adware"
X[random name]userinit.exe"PurityScan adware. Do not confuse with the legitimate Userinit Logon Application (userinit.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[various names]init32.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]WinInitDll.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]XTermInit.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.