Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y*Restorerstrui.exePart of Windows System Restore and added as a RunOnce registry entry. Leave alone
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
UEDRestore??"Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
YImage & RestoreIMAGE32.exe"Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased
NMania Win RestoreRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
UMcAfee Backup and RestoreMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
XMicrosoft Restorescrgrd.exe"Added by the SPYBOT.BR WORM!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMS SyS Restoresysrestore.exe"Added by the RBOT.XM WORM!"
XMSNSysRestorepc32.exeAdded by a variant of the MASTAK VIRUS!
XPrinterSpool[path] RESTORE.EXE [path] SPOOL.EXE"Added by the ALADINZ.K TROJAN!"
URapid Restorerrpcsb.exe"XPoint ""Rapid Restore PC"" - ""a Managed Recovery solution that enables IT Administrators to protect the corporate image
XRestorerestore.exe"Antispyware Shield Pro rogue security software - not recommended
XRestore Operationsvchots.exe"Added by a variant of the RBOT WORM!"
URestoreDesktopRestoreDesktop.exe"Softwarium Restore Desktop ""is a Windows Context Menu addition that automatically saves and restores the icons' positions on the Windows desktop after a resolution change"""
YRestoreIT!VBPTASK.EXE"RestoreIT! from FarStone - ""automatically backs up all files on your computer to a protected partition on your hard drive"""
Xrestorer32_arestorer32_a.exe"Added by the AGENT.CQQB TROJAN!"
Xrestorer64_arestorer64_a.exe"Added by the DLDR-BY TROJAN!"
XSvcManagerrestore3.exe"Added by the AGENT-DSS TROJAN!"
Xsysrestore32.exesysrestore32.exe"Unknown malware detected by McAfee - see here"
XSystem Restoresvcnet.exe"Added by the TIBICK WORM!"
XSystem Restore Data[path] repcale.exe [path] beird.exe"Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System RestorerSystemRestorer.exe"Added by the DULOAD.C WORM!"
Xwinrestore1winrestore.exe"Added by the KILLFIL-Q TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.