Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
U$EnterNetEnternet.exe"Connection manager for the EnterNet ISP. You can also use RASPPOE"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
UARMOR2NETArmor2net.exe"Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEthernet Linkingethernet.exe"Added by a variant of the IRCBOT TROJAN!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
UGuruNetGuruNet.exe"GuruNet lets you click on any word on your screen to get the relevant information you want"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
XInetMSNmsnet.exe"Added by a variant of the SDBOT TROJAN!"
XInternetInternet.exe"Added by the PWS-CS TROJAN!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet.exeInternet.exe"Added by the MAGICCALL VIRUS!"
Xinternet.exeyinyin3345.vbs"Added by the YINI MACRO!"
XIntranetintranet.exe"Added by the CHIMOZ.AC TROJAN!"
XISSinet.exe"Meplex adware"
UMBNetmbnet.exeMBNet (Portugal) Credit Card Processing software
XMedia PlayerSysnet.exe"BANKER.MW spyware"
XMicrcoft UpdatInternet.exe"Added by the RBOT-ANA WORM!"
XMicrosoft Informationsecurenet.exe"Added by the SDBOT.AJM WORM!"
XMicrosoft Networkmsnet.exe"Added by the MOCKBOT.A WORM!"
XMicrosoft UpdateBotnet.exe"Added by the RBOT.AFL WORM!"
NMirabilis ICQICQNet.exe"If connected to the internet
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMsinetMsinet.exe"Added by the RBOT-AOA WORM!"
XMSNETmsnet.exe"Added by the BOA WORM!"
XNetworkAssociates Incinternet.exe"Added by the LOVGATE.AB WORM!"
NOvernetOvernet.exe"Overnet peer-to-peer (P2P) file sharing program"
XPcSecureNetPcSecureNet.exe"PcSecureNet rogue security software - not recommended
Xrs32netrs32net.exe"Added by the AGENT-IFH TROJAN!"
XRuntt1Internet.exe"Added by the LINEAGE-Q TROJAN!"
XShell API32svcnet.exe"Added by the TIBICK.C WORM!"
Xsysnetsysnet.exe"CasClient adware - also detected as the CMAPP TROJAN!"
Xsystemsysnet.exe"Added by the VETOR-J WORM!"
XSystem Networkingsysnet.exe"Added by the RBOT.API WORM!"
XSystem Restoresvcnet.exe"Added by the TIBICK WORM!"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem64inet.exe"Added by the DENGLE-A TROJAN!"
XSystemNetworksysnet.exe"Added by a variant of the RBOT WORM!"
XTelnetTelnet.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate telnet.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
XThe Ethernetethernet.exe"Added by a variant of the SDBOT WORM!"
XThe Ethernetintranet.exe"Added by a variant of the SDBOT WORM!"
XThe Intranetintranet.exe"Added by a variant of the SDBOT WORM!"
UWarnetwarnet.exeWarnet - system cleanup software
XWindows connection managerInternet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
XWindows NetsWinNET.exe"Added by the RBOT-MO WORM!"
Xwininetwininet.exe"Added by the STUBBOT-C WORM!"
Xwinnetwinnet.exe"CommonName Toolbar spyware. To uninstall see here"
YWinPoetWinPPPoverEthernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
?WOOKITGestMaj.exe GestionnaireInternet.exe"Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?"
Xxloadnetxloadnet.exeAdded by the VB.NCK TROJAN!
XYahoo!ethernet.exe"Added by the PROSTI.AA BACKDOOR!"
X{52-28-8E-E8-ZN}thinksnet.exe"Zeno Think-Adz adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.