Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
X2Searchmain.exe"2Search adware"
?AidemHotKeyDVMAIN.EXE"Keyboard related"
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
Xbgoomain.exebgoomain.exe"Baigoo.a malware"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit
UCanonSolutionMenuCNSLMAIN.exe"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
YcnfgCavCMain.exe"Part of Comodo Antivirus"
XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
XErrorProtector Freeertmain.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XeZulaMaineZulaMain.exe"eZula TopText adware"
XeZuluMaineZuluMain.exeComes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
UhpWirelessAssistantHPWAMain.exeWireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
UiKeyWorksIKEYMAIN.EXE"A4Tech wireless keyboard driver and utility"
UKADxMainKADxMain.exe"System Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction
UMAINmain.exe"SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan"
?Main Executable (HP)HP05T0R5.exe"HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
Xmain16main16.exe"Added by the CRYPTER.A TROJAN!"
Xmain32main32.exe"Added by the CRYPTER.A TROJAN!"
XMainDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMainStartsvcmfte32.exe"Added by the STINX-A TROJAN!"
Xmainviewexmainviewex.exe"Added by the GEMA.D TROJAN!"
Xmain_moduledrvmmx32.exe"Added by the DILA TROJAN!"
XMicrosoft Domain Controllermstc.exe"Added by the NUGACHE.A WORM!"
XMS Domain Name Server DeamonMSDNSD32.exe"Added by the RBOT-CMZ WORM!"
XMS Domain Name SystemMSWDNS32.exe"Added by the RBOT-GKY WORM!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
XMSNMESENGERMain.exe"Added by the PRORAT TROJAN!"
XPcRaisermain.exe"PcRaiser rogue optimization utility - not recommended"
NPerformance CenterApcMain.exe"Ascentive Performance Center - not recommended
NPicabooPicabooMain.exe"Picaboo - ""Easily create stunning photo books and cards with your digital photos"""
?PMCSPMC.Service.Main.exe"Related to MediaCenterService from Pinnacle Systems. What does it do and is it required?"
XPSC mainsttool32.exe"Added by the OBFUSCATED.EV TROJAN!"
XPSCMainpscmain2.exe"Added by the OBFUSCATED.EV TROJAN!"
XRemote Access Domainrswsvc.exe"Added by the IRCBOT.BFA TROJAN!"
YRfwMainrfwmain.exe"Rising antivirus"
NScheduled MaintenanceScheduled_Maintenance.exe"Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs"
USpyCop ScanCheckMAIN.EXE"SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan"
YSpywareGuardsgmain.exe"""SpywareGuard provides a real-time protection solution against spyware"""
?stgcleanw32main2.exe"Related to IBM Standard Software Installer. What does it do and is it required?"
USuperCool Compress BackupMain.exe""SuperCool Zip Backup software is a data backup
XSysMainbuff.exe"Added by the AGENT-ECW TROJAN!"
XSystemOptimizer2008main.exe"SystemOptimizer2008 rogue optimization utility - not recommended
?TheMainStartN/A"??"
UTPSmainTPSMain.exeToshiba Power Saver - associated with Toshiba laptops/desktops. Manages the power save function to make sure that the system goes to a power saver mode when not used
YTPwrMainTPwrMain.EXEPower management software for Toshiba laptops
UTSkrMainTSkrMain.exe"TOSHIBA Accelerometer Utilities - hardware utilities that work with the motion sensors built into their Tablet PCs. Detect the way you are holding it at any given moment
XUltimate System GuardMainFAVProj.exe"Ultimate System Guard rogue security software - not recommended
XVelocidadSimplescrmain.exeVelocidadSimple rogue optimization utility - not recommended
UWheelMouse4DMAIN.EXE"Mouse software for ""Fellowes"" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide"
UWheelMouseAMOUMAIN.EXE"A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWinmainwinmain.exe"One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder
XWinservicewinmain.exeAdult content related malware
XWinsock StartupMain2.exe"Added by a variant of the SDBOT WORM!"
Xwow64main.exewow64main.exe"Added by the ALUREON.BT TROJAN!"
XYDTMain.exeYDTMain.exe"180solutions adware"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
X_WinMainwinexec.exe"Added by the DLOADER-XX TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.