Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
Uarmy logoreadmename.exe"Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements"
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
YCCDoctorLogonTestingccdoctor.exe"Checks your system to make sure it's configured properly for running IBM Rational ClearCase
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
Xfirewall 2008logoneui.exe"Added by the SILLYFDC WORM!"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
?Flow Go TVflogotv.exe"??"
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XInternetwinlogom.exe"Added by a variant of the SDBOT WORM!"
Xlogglogo_1.exe"Added by the PWFUZZ-A WORM!"
XLogo[path to trojan]"Added by the DLOADER-RH TROJAN!"
YLogoffSCTUINotify.exe"Part of Windows SteadyState
ULogon LoaderLogonLoader.exe"Logon Loader - customize boot & login screens"
ULogon Loader RandomLogonLoader.exe"Logon Loader - customize boot & login screens"
XLogon.exelogon.exe"Added by the ZINS.A TROJAN!"
XLogonCSRSS.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonAdministratorimoet.exe"Added by the RAHIWI.A WORM!"
XLogonAdministratorCSRSS.EXE"Added by the KORRON.B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
ULogOnHookLogOnHook.exe"Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
XLogonrepclient1CSRSS.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonsaracsrss.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
ULogonStudiologonstudio.exe"WinCustomize LogonStudio - "Allows Windows XP users to edit
XlogonUiInitRundll32.exe rgtndz.dll"Identified as a variant of the Trojan-Clicker.Win32.Agent.bqy malware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""rgtndz.dll"" file is found in %System%"
UMBkLogOnHookLogOnHook.exe"Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
UMcAfee Data BackupLogOnHook.exe"Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
XMicrosof Winlog Hostwilogon32.exe"Added by the RBOT.XC WORM!"
XMicrosoft Genuine Logonmsnmsg.exe"Added by the IRCBOT-XH WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Logon User Interfacelogonnui.exe"Added by the RBOT-BCC WORM!"
XMicrosoft Synchronization Managerwinlogon32.exe"Added by the SDBOT.AEU WORM!"
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMslogon lptt01mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMslogon ml097emslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsnwinlogon.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XMSWinlogonSynCor.exe"Added by the AGENT-FZL TROJAN!"
XMSWinlogonwinlogon.exe"Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNetLogonuserint.exe"Added by the SDBOT-BC WORM!"
Xnvchostwinlogon.exe"Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNVIDIA Media Center Librarywinlogon.exe"Added by the AUTORUN-AZK WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPaRaY_VMwinlogon.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XRealTimeProtectorwinlogon.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XRegDonewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XROOT_Machinewinlogon.exe"Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
XRPCserr32gwinlogon.exe"Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gWINLOGON.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrunwinlogonwinlogon.exe"Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process
XServices Logonservices.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates"
XSkynetRevengewinlogon.scr"Added by the NETSKY.AA WORM!"
XSmansaAppwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSonudManWNILOGON.exe"Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process
XSpyExWinllogo.exe"Added by the PRSKEY-A WORM!"
YSr AgentSrLogon.exe"Related to Secure Resolutions - desktop virus protection"
Xsrvwinlogon.exe"Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data"
XStartupWinlogonStartupUnidentified malware
Xsvchostlogon.exe"Added by the SLEGON WORM!"
XSymantecFilterCheckgmilogof.exe"Added by the BANKER-EKC TROJAN!"
Xsyslogonsyslogon.exe"Added by the SPYBOT-EP WORM!"
XSYSTEMwiinlogon.exe"Added by the RBOT-AVG WORM!"
XSystem Update2winlogon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process
XTEXTCONVwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NTiny Watcher Logon TimeWatcher.exe"Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items"
UTLogonPathtb2logon.exe"Timbuktu Pro - remote desktop access software"
UTMExLogonTMESRV.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
XTorjan ProgramWINLOGON.EXE"Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?TSBxLogonTMESBS2.EXE"Found on a Toshiba laptop. May be related to TMESBS?"
XUpdade Windowswinlogom.exe"Added by the TONAX-A TROJAN!"
Xupdate run doslogon.exe"Added by a variant of the SDBOT WORM!"
XUpdate Run MSwordLOGON.EXE"Added by the RBOT.TY WORM!"
Xurudjeffniwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xuser logon[path to worm]"Added by the PAHATIA-A WORM!"
Xuser logonuser logon.exe"Added by the PAHATIA.A WORM!"
Xuserinitwinlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XW1N32.DLLWINLOGON .exe"Added by the DROPPERFL.A TROJAN!"
Xwblogonubpr01.exe"Added by the AGENT-HFI TROJAN!"
Xwblogonalgg.exe"Added by the AGENT.AGGI TROJAN!"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWinAuthwinlogon.exe"Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindow UDP Control Servicwinlogon.exe"Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows ARP Detectioncwinlogon.exe"Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ARP Detectioncxwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows Log Agentwinlogon.exe"Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XWindows Logonwinlogin.exe"Added by the SPYBOT-C TROJAN!"
XWindows Logonwinlogon.exe"Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
XWindows Logon ApplicationWinIogon.exe"Added by the LINKBOT.M WORM!"
XWindows Logon Applicationlogon.exe"Added by the POEBOT-J WORM!"
XWindows Logon Applicationservices.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Logon Applicationwin32help.exe"Added by the DELBOT-X WORM!"
XWindows Logon Applicationwinlogon.exe"Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process
XWindows Logon Applicationwinamp.exe"Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XWindows Logon Applicationedcwinlogon.exe"Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Applicatonedcwinlogon.exe"Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Managerlogon.exe"Added by a variant of the RBOT WORM!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
Xwindows logon procedurewinlogonpc.exe"Added by the WINLOGON TROJAN!"
XWindows Logon Servicewinlogon.pif"Added by the RBOT-AOU WORM!"
XWindows Logon Servicenapi32.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Logon Servicewinlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
XWindows mangementwinlogonn.exe"Added by the RANDEX.FC WORM!"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows modez VerifierWindowsLogon.exe"Added by a variant of the SDBOT WORM!"
XWindows modez Verifierwinlogom.exe"Added by a variant of the RBOT WORM!"
XWindows Network Logonnpesvc.exe"Added by the AGENT.ERZ TROJAN!"
XWindows NT Logon Applicationwinlogon.scr"Added by the RBOT-ALP WORM!"
XWindows Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwindows updatelogonuit.exe"Added by the LEGMIR-AO TROJAN!"
XWindows UpdatewinlogonEvt.exe"Added by the VB-DXM TROJAN!"
XWindows Update 32winlogons.exe"Added by the FORBOT-FI WORM!"
Xwinlogoffwinlogoff.exe"Added by the AGOBOT-TR WORM!"
Xwinlogonwinlogin.exe"Added by the RANDEX.E WORM!"
Xwinlogonwinlogon.exe"Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwinlogonmsreg32.exe"Added by the SDBOT.EO WORM!"
Xwinlogonwinlogon32.exe"Added by the MASLAN.C WORM!"
Xwinlogonwpwlogon.exeAdded by an unidentified WORM or TROJAN!
XWINLOGONwscript.exe WINLOGON.vbs"Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
XWinlogonLsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwinlogonnvchost.exeAdded by an unidentified WORM or TROJAN!
XWinlogonWINLOGON.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process
Xwinlogonsystem.exeAdded by a variant of the DELF.CNS TROJAN!
Xwinlogoncleanmg.exe"Added by the AGENT-ICR TROJAN!"
XWinlogonscssrr.exe"Added by the AGENT-LXB TROJAN!"
Xwinlogon serviceurx.exe"Added by the SPYBOT.EN WORM!"
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
XWinlogon.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
Xwinlogon.exehelper.exe"Added by the FAKESPY-A TROJAN!"
Xwinlogon.exemsole32.exe"Adware
Xwinlogon32_[path to file]"Added by the RULAND.A WORM!"
XWinLogonndwinlogonnd.exe"Added by the AGENT-NNQ TROJAN!"
Xwinlogon_userccIsass.exe"Added by the SILLYFDC.BBT WORM!"
XWMAudiowinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XWNILOGONWNILOGON.exe"Added by the LEWOR-M TROJAN!"
XWormslogon.bat"Added by the DELMP3-A WORM!"
XWSAConfigurationwinlogon32.exe"Added by the AGOBOT-WC WORM!"
Xxp_systemwinlogon.exe"Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe
X[random name]w?nlogon.exe"PurityScan adware"
X[various names]winlogon32.exeAdded by an unidentified WORM or TROJAN!


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.