Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
UBTModemProtectionBTModemProtection.exe"BT Privacy Online modem protection software
?CPCopyProtectionNotifier.exe"Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition"
XData Protectiondatprot.exe"Data Protection rogue security software - not recommended
XDigital Protectiondigprot.exe"Digital Protection rogue security software - not recommended
XDrProtectionDrProtection.exe"DrProtection rogue security software - not recommended"
YEarthlink Protection Control Centerelnk_pcc.exe"EarthLink Protection Control Center - ""powerful
YEmail Protectionemlproxy.exe"AntiVirus Quick Heal - E-mail protection"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFile Protection Monitorfilemon.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus ProtectionmcafeeAV.exe"Added by a variant of the RBOT WORM!"
YMcAfee Family Protectionmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMS Agent Protectionag1.exe"Added by the IRCBOT.AZ BACKDOOR!"
XMS Auto-IPSec ProtectionMSASP32.exe"Added by the RBOT-AER WORM!"
XNET protection systemnetst.exe"Added by the RIZO.A TROJAN!"
XNorton AV Protection StartupAti2xxx.exe"Added by a variant of the RBOT WORM!"
XNorton Drive Protectionmsdt32.exe"Added by the FORBOT-GB WORM! Note - this not a valid Norton program!"
XPC Protection CenterPcProtection.exe"PC Protection Center 2008 rogue security software - not recommended
YPER Email Protectionpavmail.exe"PER Antivirus"
XProtection[path] runtask.exe [path] protection.exeAdded by a variant of the AGENT.3.AU TROJAN!
XProtectionProtection.exe"Added by the FEBELNECK-A WORM!"
XProtectionFirewall.exe"Added by the ELIPTER.A or ELIPTER.B WORMS! Located in %ProgramFiles%\Internet Explorer"
XProtectionIExplore .exe"Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XProtectionNorton Internet Security.exe"Added by the ELITPER.E WORM!"
XProtection Centercntprot.exe"Protection Center rogue security software - not recommended
XProtection Systempsystem.exe"Protection System rogue security software - not recommended
XProtectionCompletepgs.exe"ProtectionComplete rogue security software - not recommended. A member of the AVSystemCare family"
XProtectionConuepgs.exe"ProtectionConue rogue security software - not recommended. A member of the AVSystemCare family"
XProtectionDeDriverGDC.exe"ProtectionDeDriver rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XProtectionsProtEX32.exe"Ultimate SecuritySuite rogue malware remover - not recommended
YQuick Heal On-Line ProtectionCateye.exe"Quick Heal - virus scanner"
XRemote System Protection"rundll32.exe [random].dll HUI_proc"
USearch ProtectionSearchProtection.exe"""Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
USearchProtectionSearchProtection.exe"""Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
YSunProtectionServerSunProtectionServer.exe"CounterSpy antispyware software"
YThinkVantage Active Protection SystemTpShocks.exe"Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T
XTotal Virus ProtectionTotalVirusProtection.exe"Total Virus Protection rogue security software - not recommended
XUser Protectionusrprot.exe"User Protection rogue security software - not recommended
XVhosts Protectionvhosts.exeAdded by an unidentified WORM or TROJAN!
XWindows File Protectionwinprotect.exe"Added by the AGOBOT.JB WORM!"
XWindows Hijack Protectioncomngr.exe"Added by the AGENT-FYD TROJAN!"
XWindows Hijack Protection Systemcommngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
XWindows Protection SuiteWI[random characters].exe"Windows Protection Suite rogue security software - not recommended
XWindows Reversed Virus Protectionwinrsvp.exe"Added by the SLENFBOT.HX WORM!"
XWinPatch Protectionwinpatch.exeAdded by an unidentified WORM or TROJAN!
Xwinprotectionccsrss.exe"Added by the SILLYFDC.BBT WORM!"
UWinUpdateProtectioncsrss.exe"EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
XXP Protection CenterXPProtectionCenter.exe"XP Protection Center rogue security software - not recommended
XYour Protectionurpprot.exe"Your Protection rogue security software - not recommended
UYSearchProtectionSearchProtection.exe"""Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.