Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
UALTOOLSAccessL.exe"ALTools family of PC utilities"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
UCypressLinkMonCypressLinkMon.exe"Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store
Xhttps-sslhttps.exe"Added by the MOEGA.D WORM!"
XIECheckxpssl.exe"Added by the TIRBOT-E WORM!"
Ximcsslxmliwvug.exe"Added by the SLAPER.U TROJAN!"
XMicrosoft Corp SSL Certificateswindowz.exe"Added by the RBOT-GCZ WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
YPassLockerPassLocker.exe"""PassLocker is a complete password manager helping you to manage and safely store your passwords"""
XSecure Socket Layer Certificationsslcert.exe"Added by the VANEBOT-AN WORM!"
Xshccdewinssled.exe"Added by the BUZUS.CQMU TROJAN!"
NSmart Label O Serverssloserv.exePart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
NSmart Label RFViewerSSLFVIEW.EXEPart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
XsmssLevel4smss.exe"Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4"
XSSLsvchost.exe"Added by an unidentified VIRUS
XSSLSearchNDestrou.exe"Added by the SDBOT-WG WORM!"
XSSL Manageramsnmsgs.exe"Added by a variant of the SDBOT WORM!"
XSSLDynSSLDyn.exE"FRETHOG.MM spyware"
Xsuperslutmsslut32.exe"Added by the SLUTER-A WORM!"
XSvcphpwinsslphp32.exe"Added by the AGOBOT-ABR WORM!"
XSySSLsysl.exe"Added by the RBOT-CKH WORM!"
XSySSLsyssl.exe"Added by the RBOT-DAA WORM!"
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
Xttoolessledv.exe"Added by the ZBOT-KM TROJAN!"
Xttoolessldev.exe"Added by the AGENT-LWB TROJAN!"
NvTPassvtpassld.exe"Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs
XWin Drivers SSLhpws.exe"Added by the IRCBOT.67098 WORM!"
XWin Drivers SSLTASKMAN4.exe"Added by a variant of the RBOT WORM!"
XWin Drivers SSL32hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
XWin SSLSP2s.exe"Added by the RBOT.BBI WORM!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWinDll (sslms.exe)"rundll32.exe sslms.exestart"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows SSL Filewinssv.exe"Added by the WOOTBOT.CA WORM!"
XWindows SSL Secondary DriversSSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
Xwinservitcassl.exe"Added by the RBOT.ASG WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.