Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Systemmsupdtm.exe"Added by the SPYBOT.PKC WORM!"
XMicrosoft Systemmssys32.exe"Added by the PETTICK.A WORM!"
XMicrosoft Systemsys.exe"Added by the RBOT.AKI WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System Administrationsystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft System CheckupCool.exe"Added by the DONK.B WORM!"
XMicrosoft System CheckupWnetlib.exe"Added by the DONK.C WORM!"
XMicrosoft System Checkupdbnetlib.exe"Added by the DONK.L WORM!"
XMicrosoft System CheckupKeymgr.exe"Added by the DONK.M WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Checkuplibsysmgr.exe"Added by the SDBOT-CAF WORM!"
XMicrosoft System Checkupsysmgr.exe"Added by the SDBOT-OO TROJAN!"
XMicrosoft System Checkupnetapi32.exe"Added by the DONK-E WORM!"
XMicrosoft System Checkupwnetmgr.exe"Added by the DONK.Q WORM!"
XMicrosoft System Checkuplibsys32.exe"Added by the SDBOT-ACK WORM!"
XMicrosoft System Checkupnetlogin32.exe"Added by the SDBOT-GN BACKDOOR!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft System Monitormonsys.exe"Added by the IRCBOT-YV TROJAN!"
XMicrosoft System Monitorsystem.exe"Added by the IRCBOT.AUT BACKDOOR!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft system Valuesys57.exe"Added by a variant of the RBOT WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XNTFSS Microsoft Systemfilees.exe"Added by the RBOT.GAB WORM!"
XNTFSS MICROSOFT SYSTEMfiless.exe"Added by the RBOT.AXZ WORM!"
XNTSF Microsoft Systemfylez.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwntsf.exe"Added by the RBOT.ATC WORM!"
XNTSF MICROSOFT SYSTEMfufffy.exe"Added by the RBOT-AEL WORM!"
XNTSF MICROSOFT SYSTEMntssf.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMmarya.exe"Added by the RBOT-AXY WORM!"
XNTSF MICROSOFT SYSTEMsysman.exe"Added by the RBOT.EDP WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.