Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
NcsaRemspqmdmui.exeCompaq modem country selection
NGWMDMMSGGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
UGWMDMpiGWMDMpi.exe"Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information"
Xloadmdm.exe"Added by the BINGHE TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
UMachine Debug ManagerMDM.EXE"Used by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to ""hang"" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the ""RunServices"" key in Me (located in C:\WINDOWS\SYSTEM). It also loads a service in XP/Vista (located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug)"
XMachine Debug Managermdm.exe"Added by the SDBOT-APE WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
XMachine Debug Managermdms.exe"Added by the SDBOT-CH WORM!"
Xmachine-debuggermdmsv.exe"Added by the AGOBOT-BR WORM!"
XMdmMdm.vbs"Added by the WHITEHO VIRUS or TRAPPY WORM!"
Xmdmmdm.exe"Added by the LYDRA-F TROJAN! ! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only). This one is located in %Windir%"
XMDM Rock 4[8 random letters].exe"Added by the SDBOT.CHG BACKDOOR!"
UMDM7MDM.EXE"Used by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to ""hang"" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the ""RunServices"" key in 98/Me. It also loads as a service in XP/Vista. In both cases it's located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug"
XMdmdllmdmdll.exe"Added by the CRYPTER TROJAN!"
XMdmdll32mdmdll32.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xmdwmdmspmdwmdmsp.exe"Adware - detected by Kaspersky as the AGENT.AM TROJAN!"
Xmelg34mdmd.exe"Added by an unidentified WORM or TROJAN - see here"
Xmelg3445mdmdd.exe"Added by a variant of the RBOT WORM!"
XMicrosoftmdms.exe"Added by the AGENT-GHY TROJAN!"
XMicrosoft Debug Manager Consolemdm32.exe"Added by the AGOBOT-AQ WORM!"
XMicrosoft Officemdm.exe"Added by the IBOT-A TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XMicrosoft Visual Debugermdm.exe"Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
Xmmsassmmdmm.exe"Added by the SDBOT.SO WORM!"
XModem Driverz Updatesmdmdrv.exe"Added by a variant of the SDBOT WORM!"
NModemUtilitymdmsetpe.exeSystem Tray configuration icon for Aztech modems
XSVCHOSTMDM.EXE"Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
XSvcManagermdmex2.exe"Added by the ZALON-B BACKDOOR!"
XSysMemory managermdms.exe"Added by the CIMUZ-D TROJAN!"
Uwcmdmgrwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
Nwcmdmgr.exewcmdmgr.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
Uwcmdmgrlwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
UWildTangent Web Driver updaterwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
XWindows Networking Monitormdm.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networking Monitorinxmdmx.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networking Monitoringmdm.exe"Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Office Monitoremdm.exe"Added by the RBOT.AFV BACKDOOR!"
XWMDM PMSP Servicecssrss.exe"Added by the KNOCKIT-A TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.