Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
XAdobeReaderProntkernell32.exe"Added by the RBOT-ATY WORM!"
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XdKerneldKernel.exe"Added by the DECOY-A WORM!"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
XKernelbboy.exe"Added by the MUMU.B WORM!"
XKernelservices.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xkernelkernel.exe"Added by the MATCASH.CF TROJAN!"
XKernelUpdate.exe"Added by the DELF-FN TROJAN!"
XKERNEL 32SKERNEL32.com"Added by the SEMAPI-A WORM"
UKernel and Hardware Abstraction LayerKHALMNPR.EXE"Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
XKernel Faultsftphost.exe"Added by the RBOT.BHU WORM!"
XKernel Loaderntkrnl.exe"Added by the CERVIVEC.A WORM!"
XKernel Managerkrnlmgr.exe"Added by the JUNY.A TROJAN!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernel Servicesservice32.exe"Added by the PRX-B TROJAN!"
Xkernel system daemonACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
Xkernel12.exekernel12.exeAdded by an unidentified WORM or TROJAN!
Xkernel32kern32.exe"Added by the BADTRANS.A WORM!"
XKernel32Kernel32.exe"Added by a number of VIRUSES
Xkernel32kernel.dli"Added by the NETDEVIL.B TROJAN!"
XKernel32Kernel.dll"Added by the REDLOF.M VIRUS!"
Xkernel32kernel32.dlI"Added by the NETDEVIL.15 TROJAN!"
XKernel32krnl32.exe"Added by the EPON WORM!"
XKernel32Kernel32.win"Added by the GAGGLE.D or GAGGLE.E WORMS!"
XKernel32kernel32s.exe"Added by the BCKDR-CIC BACKDOOR!"
Xkernel32kernel32.dll.vbs"Added by the WEKODE-A WORM!"
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
XKernel32svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers"
Xkernel32dllguardpc.exe"Added by the FORBOT-CU WORM!"
Xkernel32sys.dllIEXPLORER.exe"Added by the RBOT-MK WORM!"
XKernel32_sysdampersysdamp.exe"Added by an unidentified WORM or TROJAN! See here"
Xkernel44.dll"taskkill /f /fi ""PID ge 0"" /im *""Added by the VBS.LIDO WORM!"
XKernelChecksys****.exe [* = digit]Added by an unidentified TROJAN!
XKernelCheckwinser.exe"Added by the TSPY_LMIR.SL TROJAN!"
XKernelConfigdestiny32.exe"Added by the AGOBOT.AMB WORM!"
Nkernelfaultcheckdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Nkernelfaultcheckdumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
XKernelFaultCheckptool32.exe"Added by the LEGMIR-BN TROJAN!"
XKernelFaultCheckmsime.exe"Added by the TINY-P TROJAN!"
XKernelFaultChecktell32.exe"Added by the LEGMIR-BF TROJAN!"
XKernelFaultCheckwinabc3.exe"Added by the NUBYS-A VIRUS!"
XKernelFaultCheckwinbin.exe"Added by the DLOADR-AAX TROJAN!"
XKernelFaultChksms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
XKernellsystems.exe"Added by the TARNO.C TROJAN!"
XKernell32Kernell.dll"Added by the DESTINY.A TROJAN!"
XKernellAppscsrss.exe"Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""System"" subfolder"
XKernellAppslexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XKernellAppssvshosti.exe"Added by the BANCBAN-V TROJAN!"
XKernellApps32smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XKernelRuntime[path to worm]"Added by the MYTOB-JO WORM!"
XKernelwKernelw32.exe"Added by the INDOR.E WORM!"
XKernel_checkwmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!"
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XMicrosoft KernelWindows_kernel32.exe"Added by the NETSKY.AE WORM!"
XMicrosoft Update 23NtKernelSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WindowsKernel.exe"Added by the EDIBARA-A VIRUS!"
XMicrosoft WindowsKernel.vbs"Added by the EDIBARA-A VIRUS!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMSKernel32MSKernel32.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
XMSkernel32System.exe 4820"Added by the TUXDER BACKDOOR!"
XMstaskkernel32.exe"Added by the STAP-C WORM!"
YNOD32kernelNod32krn.exe"NOD32 antivirus"
UNokKernel installNok_install.exe"Installer for the NokNet Workstation Monitor surveillance software. Uninstall this software unless you put it there yourself"
NNT Kernel Patchntkrnlpt.exe"FaxServe network fax software"
XPlobkernel.com"Added by the OPTIXPRO.12 TROJAN!"
XRunDLL Kernel File Corerundll.exe"Added by a variant of the RBOT WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
Xrundll32kernel32.exe"Added by the STAP-C WORM!"
Xrundll32kernel33.exe"Added by the STAP-D WORM!"
XService Systemkernels32.exe"Added by the BANCOS-DA TROJAN!"
Xsittachasnahalbasyantoskernel.exe"Added by the HANSAH-A WORM!"
XSysBootsyskernel.exe"Added by the AUTORUN-EY WORM!"
XSystemkernels32.exe"Added by the DLOADER-FC TROJAN!"
XSystemkernels64.exe"Added by the VIXUP-S TROJAN!"
XSystemkernels1118.exe"Added by a variant of the SDBOT WORM!"
XSystemkernels88.exe"Added by the TIBS-PP TROJAN!"
XSystemkernels8.exe"Added by the TIBS.AI TROJAN!"
XSystemkernel8.exe"Added by the DLOADR-AOL TROJAN!"
XSystemkernelwind32.exe"Added by the VXIDL.FT TROJAN!"
XSystemkernelwind64.exe"Added by the DLOADER.DJD TROJAN!"
Xsystemkernel32.ini"Added by the SILLYFDC.CJ WORM!"
XSystem Kernellsass.exe"Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemToolskernels32.exe"Added by the DLOADER-FC TROJAN!"
XSystemToolskernels1118.exe"Added by the SMALL.DGK TROJAN!"
XSystemToolskernels8.exe"Added by the FNG TROJAN!"
XSystemToolskernels88.exe"Added by the TIBS-PP TROJAN!"
XWin32 Kernel core componentKernel32.pif"Added by the MOKS VIRUS!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
XWin32GKernel32.com"Added by the ESTRELLA TROJAN!"
Xwin32Kernelfindx.exe"Added by the BANLOA-EY TROJAN!"
XWin32KernelStartmicrosoft.exe"Added by the DELF-EWZ TROJAN!"
XWindoes Kernelkernel32.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
XWindowsKernel32.exe"Added by the TENDOOLF.A WORM!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows Kernel 64kernal64.exe"Added by the YIMP-B WORM!"
XWindows Kernel System Servicewkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows System32 Kernelsystem32.exe"Added by the SDBOT-AAT WORM!"
XWindows32KernelStartwks.exe"Added by the LAPURD TROJAN!"
XWinKernelWinKer.exe"Added by the MIRAB or SERVIDOR TROJANS!"
XWinKernel[path to virus]"Added by the PLEA VIRUS!"
Xwinkernel32wWin32.com"Added by the BANSAP TROJAN!"
XWSAConfigurationkernel32.exe"Added by the AGOBOT-KV WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.