Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
UBearFlixBearFlix.exe"BearFlix is optimized for the fast download of video files"
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
UcbInterfacecbInterface.exe"System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 7 Interfacecobui.exe"System Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Interface 6cobui.exe"System Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
NCTPerformanceUtilityCTPowUti.exe"Related to Creative PowerSysTrayApp. This program is a non-essential process
Xcyberfree.exe****.dat [* = random char]Unidentified adware
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XDokterFixSysRep.exe"DokterFix
?ENCSurfsurfboard.exe"??"
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
XErrorFixErrorFix.exe"ErorrFix rogue system error and cleaning utility - not recommended
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xexplorerf.exeexplorerf.exe"Added by the AGENT-GDZ TROJAN!"
Ufreesurferfs20.exe"EMS Free Surfer mk II - pop-up stopper"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
UHitman Pro SurfRight Helpersrhelper.exe"Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
?hpScannerFirstBootscannerfb.exe"HP scanner related"
XIEACCESSsurfya.exe"
UIntel(R) Common User Interfaceigfxtray.exe"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfacehkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
UMailbox Verifiermboxvrfy.exe"Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)"
XMicrosoftmsngerf.exe"Added by the RBOT-GLW WORM!"
XMicrosoft Logon User Interfacelogonnui.exe"Added by the RBOT-BCC WORM!"
UMicrotek Scanner FinderScannerFinder.exeMonitors whether a scanner is present. Provided with Microtek scanners
UMirrorFolderShellmrfshl.exe"MirrorFolder backup software"
Xmssurfer lptt01mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssurfer ml097emssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMsys32morfitwebentrance.exe"Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage"
XNetSurfageAssureGDC.exe"NetSurfageAssure French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XNorton GProtectngrfn.exe"Added by a variant of the RBOT WORM!"
XNvGraphicsInterface[path to trojan]"Added by the BCKDR-QKI BACKDOOR!"
UOnlinePCfix SmoothSurferSS.exe"Smooth-Surfer - blocks banners
XOptimum OnlineNetsurf.exeOptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UPCPerfpcperf.exe"PC Accelerator 2007 from DefendGate Inc. ""Powerful all-in-one PC performance and Internet acceleration solution designed to help increase your system and online performance and security"""
XPerfect Defender 2009pdfndr.exe"Perfect Defender 2009 rogue security software - not recommended
NPerfectPrintpfppop70.exePrint engine used by Corel WordPerfect 7 and Presentations 7
UPerfectSuitedthtml.exe"PerfectSuite™ from ViewSonic. Rebranded version of Display Tune from Portrait Displays
XPerfFont (Performance True Type Font)perfont.exe"Added by the MUTECH-E TROJAN!"
Uperfmonperfmon.vbs"MindStorm AnalyzerPro from Secure Associates. ""A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices"""
XPerfomance Monitordavcsync.exe"Added by the LAMUD-A WORM!"
XPerfomance Settingssvchost.exe"Added by the TOFGER-AP TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPerformanceMyHeart.exe"Added by the PESIN-D WORM!"
NPerformance CenterApcMain.exe"Ascentive Performance Center - not recommended
XPerforms peer to peer connectionWinPTTP.exe"Added by the RBOT-GMI WORM!"
UPopUpStopperFreeEditionPSFREE.EXE"Panicware's Pop-Up Stopper - free limited features version"
UPowerForPhonePowerForPhone.exe"""ASUS Power 4 Phone is a telephone terminal emulation utility which can use hotkeys to handle a phone call from Skype or Modem in your notebook system."" For more information you can find a user's manual here"
XPrizeSurferprizesurfer.exe"""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware"
NQBReminderFlashQBReminder.exe"Upgrade reminder for Intuit's QuickBooks"
XRandom Interface Networkrst.exe"Added by the DELBOT-P WORM!"
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
NReality Fusion GameCam SERFTRay.exeReality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
NRecoverFromRebooRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebooRecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
XRFEC.exe"Added by the LINEAGE-U TROJAN!"
Urfagentrfagent.exe"Registry First Aid - scans the Windows registry for orphan file/folder references
XrforceEXP1ORER.EXE"Added by the DROPPER.KN TROJAN! Note the number ""1"" in the filename rather than letter ""L"". It also drops another file named DEVICEMAP.SYS which is the ROOTKIT.O TROJAN!"
NRFTrayRFTRay.exeReality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
YrfwRfw.exe"RAV AntiVirus"
YRfwMainrfwmain.exe"Rising antivirus"
?rfwydgrfwydg.exe"??"
NRFX_auto_upgraderundll32.exe npvpg005.dll"A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade"
Xrmdrfje.dll"rundll32.exe rmdrfje.dll[random characters]"
XSafeSurfingUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
Xsasserfixpackage.exe"Added by the DABBER.B WORM!"
YSkySurfer Management ServiceSmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
NSmart Label RFViewerSSLFVIEW.EXEPart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
?SRFirstRun"rundll32 srclient.dll CreateFirstRunRp"
YStart RF Wireless Keyboardktrexe.exeYuanxun Electronics RF wireless keyboard driver
YStart RF Wireless Mousecm20.exeYuanxun Electronics RF wireless mouse driver
UStartSurfingSTARTS.exe"Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows
NStat 'n' PerfStatnPerf.exe"Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes"
XSurfAccuracysacc.exe"SurfAccuracy adware"
XSurfBuddyrundll32 [path] sbuddy.dll"SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
USurfChoiceSCMan.exe"SCMan is a utility that can control services on WinNT from the command line. This utility can create
XSurfer lptt01surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSurfer ml097esurfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
USurfHelperSurfHelp.exe"Related to SurfHelper - a free tool to remove popup windows
USurfinGuard Prowinsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
USurfSecretss2-full.exe""House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray
XSurfSideKickSsk.exe"SurfSideKick adware"
XSurfSideKick 2Ssk.exe"SurfSideKick adware"
XSurfSideKick 3Ssk.exe"SurfSideKick adware"
USurfStreamSurfStream.exe"Conceiva ""SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"""
XSystemErrorFixerSysRep.exe"SystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
?Thdetrfthdetr32.exe"Appears to be related to Lycos advertising"
NUserFaultCheckdumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
XUserfile Sharing Servusnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUserfile Sharing Serverusnserv.exe"Added by a variant of the IRCBOT TROJAN!"
XUSERINTERFACE REPORT3RM0USE.exe"Added by the MYTOB.HS WORM!"
XUserinterface Reporterfuuuucktttttt.exe"Added by the MYTOB-DK WORM!"
XUserinterface Reportersrv32.exe"ISTBar adware"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows Relay Serviceirfnga.exe"Added by the DROPPER.ACO TROJAN!"
XWindows Service Findwrfkuk.exe"Added by the IRCBOT-XZ TROJAN!"
XWindows Spoolsurf Servicespoolsurf.exe"Added by the SDBOT-ZZ WORM!"
XWindows-TCP-IPrfkampig.exe"Added by the GIPMA TROJAN!"
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
XWindoxs Update CenterW32RfSA.exe"Added by a variant of the SDBOT WORM!"
Xwininet.dllregperf.exe"Added by the ZLOB TROJAN and variants!"
XWinPerformanceWinPerformance.lnk"Windows Performance rogue optimization utility - not recommended"
XWMI Application Interfacewmiapi.exe"Added by the SPYBOT.RBY WORM!"
XWMI Performance Adapter Serviceswmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
UWonderFrogWonderFrog.exe"Wonder Frog typing monitor"
NWordPerfect Office 1215Registration.exe"Corel WordPerfect Office 12 registration wizard"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.