Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
?ADSL_A2A2Installed"Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?"
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
NAIMWDInstallAIMWDInstall.exe"Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XCABCInstallCABCInstall.exe"Ignite Technologies (was CABC) content delivery software"
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
Ueanthology_install.exeeanthology_install.exe"eAcceleration Stop-Sign security software related. Previously not recommended
XexplorerYinstall.exe"PurityScan/Clickspring adware"
Xf2install.exef2install.exe"Added by the IEFEAT-I TROJAN!"
XFlash_Player_Installying.exe"Constructor VC2000 malware"
?FridaysInHellInstallerFridaysInHellInstaller.exe"??"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
XInitial Pageinstall.exeEasySearch browser hijack installer
XInstallInstall.exe"Added by the BANCBAN-HG TROJAN!"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
xinstall32install32.exe"Added by the NUCLEAR.DG BACKDOOR!"
NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
UInstallBuddyIbtna.exe"InstallBuddy - automatically translates and installs your desktop documents
XInstallCleanerInstallCleaner.exe"Added by the ANYHOMB.F TROJAN!"
XInstalled shell32.dllOffice.exe..."Added by the LOVGATE.AO WORM!"
XInstalled shell32.dllOffice.exe"Added by the LOVGATE.E WORM!"
XInstallerdial.exe"Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
?InstallNAIProductSETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstalls SP2[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
UInstallstubinstallstub.exe"Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
Xist service uninstall[random filename]"ISTBar adware related"
Xistinstall zazzer.exeistinstall zazzer.exeUnidentified adware downloader/installer
YLogitechRegisterVideoApplicationsInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software
ULogitechVideo[inspector]InstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
?M Player Post Installerpostinstallm.exe"??"
XM3Development_WhenUSave_InstallerM3Development_WhenUSave_Installer.exe"WhenU.Save adware"
NMagicalUnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
NMagUninstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
XMbarInstall[random filename]"Mirar adware"
YMcAfee Application Installermcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
XMediaLoads Installerdw.exe"Medialoads adware"
NMGA_CD_Installmgasetup.exeMatrox Millennium video driver. Not required once drivers installed
XMicrosoftinstall.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Installshieldnundll32.exe"Added by the AGOBOT-AHZ WORM!"
?MM Installsetup.exe"Possibly Money Manager from Moneysoft?"
NMovielink Manager Uninstallmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XMSInstallsmvss.exe"Added by the DEDLER-G TROJAN!"
XMSNinstall.exe"Added by the AGENT-GDO TROJAN!"
XMyVBAppinstall.exe"Detected as Generic Downloader.s by McAfee
XNBInstallMBDownloader_876919.exe"Added by the MIRAR_D TROJAN!"
UNetscapeInstallService.exeRelated to Netscape installation
XNI.USYPSysProtectScannerInstall.exe"Installer for the SysProtect rogue security software
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWAS5LP_0001_0811UWAS5LP_0001_0811NetInstaller.exe"Installer for the WinAntiSpyware 2005 rogue spyware remover - not recommended
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWAS6_0001_N68M2301UWAS6_0001_N68M2301NetInstaller.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5UWFX5NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0614UWFX5LP_0001_0614NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0715UWFX5LP_0001_0715NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0802UWFX5LP_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0803UWFX5LP_0001_0803NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5TUWFX5TNetInstaller.exe"Added by the DOWNLDR-BO TROJAN!"
XNI.UWFX5V_0001_0802UWFX5V_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX6_0001_N68M2301UWFX6_0001_N68M2301NetInstaller.exe"WinFixer 2006 web installer - ""foistware""
UNokKernel installNok_install.exe"Installer for the NokNet Workstation Monitor surveillance software. Uninstall this software unless you put it there yourself"
UNSHelperaexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
UNUAgentInstallPathNU_Install.exe"Installer associated with Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourself"
UOSSelectorReinstalloss_reinstall.exe"Related to Acronis Disk Director Suite"
Xoverinstallpgs.exe"Part of VirtualPCGuard
XPreInstall Windows[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\detr"
YQCDriverInstallerLqdsw.exe"Launches the camera driver setup wizard on the first reboot after installing Logitech's ClickSmart
XQuickInstallPackQuickInstallPack.exe"Installed and used by rogue security products such as Cleaner2009
XQuickInstallPackCLN_2009FreeInstall.exe"Installed and used by rogue security products such as Cleaner2009
?RjLyraInstallersetup.exe"??"
XRPCInstall[path to trojan]"Added by the AGENT-DQM TROJAN!"
NSafeInstall.exeSAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older one
XSBIinstall_sbd_**.exe"Installer for a number of rogue security products and error fixing tools - where ** represents a 2 letter language code
XSNInstall[various filenames]"Spy Sheriff/SpywareNO malware
USpyware Nuker InstallerSpywareNukerInstaller.exe"Spyware remover by TrekBlue. Previously not recommended but the latest version was delisted here"
XSQInstallerSQInstaller.exe"Xupiter SQWire toolbar related. Use Spybot S&D
USRUUninstallmsiexec.exeSymantec Network Driver Update - part of LiveUpdate
Xstcinstallerid53.exe"Added by the SCTHOUGHT.L TROJAN!"
XTClock.exetclock_install.exe"TClock - distributed and installed without user permission by other rogue software or malware. TClock contains no uninstall facility through Windows. As TClock is of dubious origin and usefulness
XToolbarInstallMirarSetup.exe"Mirar adware"
UTSClientMSIUninstallertscuinst.vbs"Related to Terminal Services Client Remote Desktop Connection Software from Microsoft"
XUninstall****upd.exeAdult content based screen saver where **** can be any number
NUninstallAbilityuability.exe"UninstallAbility free uninstaller"
XUninstallHLPreUninstallHL.exe"LinkReplacer/FFinder adware"
XUninstallQLPreUninstallQL.exe"LinkReplacer/FFinder adware"
XUninstall_TBPSTBuninst.exe"WebSearch Toolbar - HuntBar hijacker
XUpdate InstallSchost.exe"Added by the GAOBOT.AO WORM!"
XUpdateCheckwinstall.exe"Added by the SPYBOT-CY WORM!"
YUSB SECURITY DEVICE CoInstallerJupitCo.exe"ButterflyMedia USB Flash drive related - required for the password security feature to work"
?Verizon Custom Uninstall TrackingInstallHelper.exe"Verizon related installation tracker. What does it do and is it required?"
XWebInstallWebInstall.exeClipGenie adware downloader
XWebInstall2WebInstall.exeClipGenie adware downloader
XWindows installerwinstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
XWindows Installerntdll.exeAdded by an unidentified WORM or TROJAN!
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows UDP Control Centerinstaller.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updateinstall.exe"Added by the BANKER-IB TROJAN!"
XWindowsInstaller[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XWinSecurityuninstall.exe"Added by the SILLYFDC.BCJ WORM!"
Xxpsp2installxpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
X[trojan filename]Install.exe"Added by the BANCBAN-FS TROJAN!"
X[various names]install2.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.