Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XContent Servicewinserv[LETTER].exe"PurityScan adware"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
?hp Silent ServiceHpSrvUI.exe"HP related"
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
YMyCIO Agent Servicemyagtsvc.exe"Part of the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
XNT ServiceNTOKSRNL.EXE"Added by the RBOT-AAG WORM!"
XNT Servicesntsvc.exe"Added by the AGOBOT.VJ WORM!"
XPrint Servicesspolserv32.exe"Added by the RBOT.ZP WORM!"
YSkySurfer Management ServiceSmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XTorrent Management Servicesystem32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XTorrent Management ServiceTMANAGESVC.EX"Added by a variant of the IRCBOT TROJAN!"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows NT Service Namewinshock.exe"Added by the RBOT-PK WORM!"
XWindows NT Service Namesvchcst.exe"Added by the RBOT-NV WORM!"
XWindows SpoolaPrint Servicespoolasrv.exe"Added by the SDBOT-AYD WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Update Client Servicewindrvl32.exe"Added by the AGOBOT-MM TROJAN!"
XWindows Vista Corparation Agent Serviceswinxp_sp3.exe"Added by a variant of the IRCBOT TROJAN!"
XWindowsNT ServicesServices.com"Detected by Bitdefender as the DELF.OFC TROJAN! See here"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.