Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XHrn_qtvhrnsvc32.exe"Added by the SDBOT-AET WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
Xmnsvcmnsvc.exe"Added by the AUTOUPDER TROJAN!"
Xmnsvcspmnsvcsp.exe"Added by an unidentified VIRUS
Xmsnmsnsvc.exe"Added by a variant of the SDBOT WORM!"
XMSN Servicemsnsvc.exe"Added by the SLENFBOT.EG WORM!"
XMSN User Servicemsnsvc.exe"Added by the SLENFBOT.NS WORM!"
XMSN User Svcmsnusnsvc.exe"Added by the IRCBOT.AVV BACKDOOR!"
UNNSvcnnsvc.exe"Net Nanny internet filter. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNsvnsvsvc.exe"Delfin Promulgate adware"
Xnsvcinn20050308.exe"Delfin Media Viewer adware related"
XNsvdrnsvdr.exeAdult content dialler
Xntupdatednsvc.exe"Added by the SDBOT-TC WORM!"
YPAVFNSVRPavFnSvr.exe"Part of Panda Antivirus and Internet Security"
XPrint Schedulerusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunsvcrunsvc.exe"Added by the SMALL-CF TROJAN!"
XSANS Servicesansv.exe"Added by the VANEBOT-AH WORM!"
XService Clientwinsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
XSystem Document Applicationwinsvc32.exe"Added by the SDBOT-VA WORM!"
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
XTCP MonitoringLanNSvc.exe"Added by the RANDEX.AAS WORM!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
XUser Sharing Servicesusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
Xusnsvc.exeusnsvc.exe"Added by the SPYBOT.AMD WORM!"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Server!winsvr.exe"Added by the IRCBOT.AYC BACKDOOR!"
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows Spools SVwinsv.exe"Added by the RBOT-AUQ WORM!"
XWINDOWS SVCwinsvc.exe"Added by the MYTOB-EY WORM!"
XWINDOWS SYSTEMwinsvc32.exe"Added by the MYTOB.HH WORM!"
XWINDOWS SYSTEMwinsvc.exe"Added by the MYTOB.LM WORM!"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindowsFirewallSvcwinsvcup.exe"Added by a variant of the SDBOT WORM!"
Xwinnsvcmsvc.exe"Added by the PWS.O TROJAN!"
XWinSvc16.exeWinSvc16.exe"Added by the SDBOT.FQ TROJAN!"
Xwinsvc32winsvc32.exe"Added by the IRCBOT-AEG WORM!"
Xwinsvc32.exewinsvc32.exe"Added by the GREPAGE TROJAN!"
XWinsvrmsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
XWinsvr managerDDEsvr.exe"Added by the TIRBOT-C WORM!"
XWinupdateewinsvcc.exe"Added by the AGENT.AN TROJAN!"
XWN Serviceswnsvc.exe"Added by the KBBOT-A TROJAN!"
XZNNznnsvc.exe"Added by the SDBOT-DAA WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.