Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
UBlueSoleilBLUESO~1.EXE"BlueSoleil Bluetooth wireless manager from IVT Corporation"
Xbolenjabolenja.exe"Added by the WANTVI.BF TROJAN!"
Xbolenjxbolenjx.exe"Added by the ELDYCOW.O TROJAN!"
Xboler.exesyser.exe"Added by the RBOT-AYS WORM!"
UCobian Backup BoletusCobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UDevicesolesvr.exe"Salfeld Child Control - parental control software"
Xegikugunapolecy.exe"Added by the SDBOT.AOE WORM!"
Xhelpmanagerspoler.exe"Added by the RANDEX.J WORM!"
XLocal runole servicesrvc32.exe"Added by the SMALL-DP TROJAN!"
XMicrosoft Debug Manager Consolemdm32.exe"Added by the AGOBOT-AQ WORM!"
XMicrosoft Management Consolelssas.exe"EasySearch adware"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Security Controlersfxsecues.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
?MS management consolemms.exe"Suspicious as the legitimate ""Microsoft Management Console"" is ""mmc.exe"" and not ""mms.exe"" and doesn't normally run at startup"
Xms spool servicemsspooler.exe"Added by a variant of the RBOT WORM!"
XMSOleath32winss.exe"Added by the KATHER TROJAN!"
XNetworks ControlerNetsis.exe"Added by the RBOT-NG WORM!"
XOLE[filename]"Added by the STAWIN or TARNO.D TROJANS!"
XOLE Automation Serverole32aut.vbe"CoolWebSearch parasite variant"
Xoleaccrcoleaccrc.exe"Adware - detected by Kaspersky as the AGENT.AM TROJAN!"
XOLEDb Servicerunoledb32.exe"Added by a variant of the SPYRE.B TROJAN!"
Xolehelpolehelp.exe"Added by the BOOKMARKER.D or BOOKMARKER.G TROJANS!"
XOleLoaderole32.exeAdded by the DELF.BR TROJAN!
Uolesvrolesvr.exe"Salfeld Child Control - parental control software"
NPioletpiolet.exe"Piolet - peer-to-peer file sharing client"
YPrevxOnePXConsole.exe"Prevx intrusion prevention software"
XPrint SpoolerSpoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
XPrint Spoolerspoolsvc32.exe"Added by the SDBOT.BB TROJAN!"
XPrint Spoolerspools.exe"Added by the RBOT-LD WORM!"
XPrint Spoolerspool.exe"Added by the BDOOR-IS BACKDOOR!"
XPrint Spoolerspoolsv32.exe"Added by the RBOT.SW WORM!"
Xprinter spoolercommonaccess.exe"Added by the DELF-LB TROJAN!"
XPrinter Spoolerspooler.exe"Added by the DELF-JJ TROJAN!"
XPrinter Spooler Subsystemspoolss.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Windows spoolss.exe process which is always located in %System% and should not figure in Msconfig/Startup!"
UPrintSpoolerlass.exe"Win-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
XProtocolEventTskcsrwjd.exe"Added by the STINX-N TROJAN!"
XSchijfControleurGDC.exe"SchijfControleur Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XServicesiexploler.exe"Added by the RANCK-LT TROJAN!"
XServicesiexpolere.exe"Added by the RANCK.LU TROJAN!"
XSolelunaAntiViruspgs.exe"SolelunaAntiVirus rogue security software - not recommended. A member of the AVSystemCare family"
XSpooler de Impressservices.exe"Added by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User%"
XSpooler Hostsmhost.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XSpooler ServiceSpoolsrv.exe"Added by the JOINER.C1 TROJAN!"
XSpooler Subsystemspoolsub.exe"Added by the SDBOT-ABG TROJAN!"
XSpooler SubSystem Appspoolsvc.exe"Added by the POEBOT-J WORM!"
XSpooler SubSystem AppspooIsv.exe"Added by the LINKBOT.M WORM!"
XSpooler SubSystem Appspoolv.exe"Added by the SDBOT-BN WORM!"
XSpooler SubSystem Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
XSpooler Subsytem Appspoolsvc.exe"Added by the SDBOT-MM WORM!"
XSpoolerSubSystemProcessSpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
Xsvchostolehelp.exe"Added by the BOOKMARKER.G TROJAN!"
XSystem Spooler Subsystemlssas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Tray Servicesspooles32.exe"Added by the AGOBOT.ZH WORM!"
XsystrasxCONSOLES.EXE"Added by the SDBOT-NW WORM!"
UT3ConsoleT3Console.exe"Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data"
UTaakcontroletaskmon.exe"Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users
?VMConsole.exeVMConsole.exe"Sony VAIO Media Console - installed on the VAIO Media Integrated Server PCs. What does it do and is it required?"
XWin Updateoleupdate.exe"Added by the AGENT-UY TROJAN!"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows Local Spoolerlssas.exe"Added by the RBOT.BXQ WORM!"
XWindows OLE Automation Serverole32aut.vbe"CoolWebSearch parasite variant"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Print SpoolerNavAgent32.exe"Added by an unidentified VIRUS
XWindows Print SpoolerSVEHOST.EXE"Added by the SPYBOT.H WORM!"
XWindows Printing DriverWinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Recovery Consolerecovery.exe"Added by the RANSOM.FD WORM!"
XWindows SpoolerSPOOLSRV.EXE"Added by the SPYBOT.P WORM!"
XWindows Spoolerspoolsv32.exeAdded by an unidentified WORM or TROJAN!
XWindows Spoolerwinsplr.exe"Added by the SHEUR.ANX TROJAN!"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Spooler Servicesspool.exe"Added by the AGOBOT-AMO WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows System GatewaySPOOLER.EXE"Added by a variant of the RBOT WORM!"
XWindows USB controlerwinusb.exe"Added by the RBOT-HR WORM!"
XWindows Zero Spoolernmvcs.exe"Added by the SLENFBOT.JQ WORM!"
Xwinlogon.exemsole32.exe"Adware
YWinPatrol ExplorerWinPatrolEx.exe"Part of WinPatrol"
NWintercooler ProWINCOOL.EXE"Wintercooler Pro - utility that monitors CPU usage
NWireless Consolewcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWireless Console 2wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWireless Console 3wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
UZingSpoolerZingSpooler.exeWas used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums
XZolero TranslatorZoleroTranslator.exe"Zolero Translator - added by Clickspring
X[various names]expoler.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.