Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X3D Text3D Text.scr"Added by the JERMY.A WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAll Sea screen saverTaskTray.exe"Free screensaver
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XBatzBackBatzBack.scr"Added by the BACKZAT WORM!"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
Xcmrstcmrst.scr"Added by the DLOADER-FP TROJAN!"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XcronosMARCO!.SCR"Added by the OPASERV.G WORM!"
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
Xdarkimgst.scr"Added by the BANCOS.U TROJAN!"
Xdarkimgrt.scr"Added by the BANCBAN-FH TROJAN!"
Xdarkcsrs.scr"Added by the BANCBAN-GT or BANCBAN-GU TROJANS!"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
XExeName32Warm.scr"Added by the SCOLD WORM!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XEYORENotepad.scr"Added by the GIMLET-A WORM!"
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
NFSScrCtlFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
Xgamepatcher.scr"Added by the PSW-ED TROJAN!"
Xgremierwscript.exe gpremier.vbs"Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
Xhelphelp.scr"Added by the BANCOS-BBU TROJAN!"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XJavascriptjscript.exe"Added by the DELBOT-AD WORM!"
XJavaScript Debugging ServiceJsDbgMan.exe"Added by the DERDERO.E WORM!"
XJavaScriptMsxrsMsxrs.exe"Added by the VB.BL WORM!"
NLightscribeLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribe Control PanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribeControlPanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
Xloadctftpscr32.exe"Added by the AGENT-FPN TROJAN!"
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
XLogin Screen Saverlogin.scr"Added by the RBOT-AVN WORM!"
XMalware ScannerMalScr.exe"Malware Scanner rogue security software - not recommended
XMascro soft SDK updates2SDKrepair2.exe"Added by the SDBOT.BXM WORM!"
UMatrix Screen Lockermatrix.exe"Matrix Screen Locker is a system tray application that allows for quick and secure PC lock when you wish. The screen does a ""matrix style"" scrolling characters effect when the lock is running"
XMatrixScreen[filename]"Added by the MATRIXSCREEN TROJAN!"
XMatrixScreenSavermss.exeUnidentified malware
XMicro CRC Protocolscrc32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft machinearcpack.scr.exe"Added by the RBOT.ADF BACKDOOR!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft Restorescrgrd.exe"Added by the SPYBOT.BR WORM!"
XMicrosoft Synchronization Managerscreen.exe"Added by the SDBOT-ACO WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMS Screen Saverscrsave.scr"Added by the RBOT-AGT WORM!"
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
XMsctrl32Msctrl32.scr"Added by the REDIST WORM!"
Xmsmmsm.scr"Added by the BANKER-EHJ TROJAN!"
Xmsnscr.exemsnscr.exe"Added by the CERTIF-P TROJAN!"
XNatalNatal.scr"Added by the OPASERV.AE WORM!"
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
XNorton Systemcsrs.scr"Added by the BANLOA-AFM TROJAN!"
UOn Screen DisplayOSD.EXE"By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume
UOn screen displayTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
NOneNote 2007 Screen Clipper and LauncherONENOTEM.EXE"System Tray access to MS Office OneNote 2007 - an electronic notebook that allows you to create free-form notes
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
NPrint Screen Deluxepsdeluxe.exe"Utility allows "Print Scrn" or "Print Screen" key to capture
NPrintScreenUNWISE.EXE"Gadwin PrintScreen - utility to capture
NPrintscreen 95PRT95MIN.EXE"Printscreen 95 - utility to capture
XPrnShareWscript.exe prn_share.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""prn_share.vbs"" file is located in %System%"
XProteção de telassmaze.scr"Added by the BANCBAN-FB TROJAN!"
Xprotectprotect.scr"Added by the DLOADER-TQ TROJAN!"
XRAX SYSTEMscrigz.exe"Added by the MYTOB.KR WORM!"
XRegistrywscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in %Windir%"
URestart WSC Settingwscrestp.exe"WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes"
XRun MSupdt32wscript MSupdt32.vbs"Added by the CASER WORM!"
Xrun=Celine.scr"Added by the CELINE-A TROJAN!"
Nscscrubxp.exe"ScrubXP - utility that deletes safe to remove files
XScrscr.scr"Added by the OPASERV.T WORM!"
NScrapPadScrappad.exe"ScrapPad allows you to quickly and easily record notes
Xscrbmk[path to trojan]"Added by the DLOADER-VP TROJAN!"
UScreen Calendarscrcal.exe"Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler"
UScreen Guardlaunch.exe"Part of Access Denied security and privacy software"
UScreen Guard Message Scansgms.exe"Part of Access Denied security and privacy software"
XScreen Saverscrnsaver.scr"Added by the RBOT-AGP WORM!"
NScreen Saver ControlFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
NScreenHunter 4.0 FreeScreenHunter.exe"""ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"""
NScreenPrint32ScreenPrint32.exe"ScreenPrint32 screen capture software - can be launched manually"
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
?screxescruser2k.exe"??"
?scriptscript.bat"Maybe associated with DOS on a Win9x machine"
YScriptBlockingSBServ.exe"Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information"
YScriptSentryScriptsentry.exe"Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly"
UScroll-In-Mouse V2.0SCROLL.EXE"Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
Xscrollerfpapli.exe"CoolWebSearch parasite variant"
Xscrssscrss.exe"Added by the HACDEF-R TROJAN!"
Xscrsvcscrsvc.exe"Added by the AGENT-DS TROJAN!"
XScrSvrScrSvr.exe"Added by the OPASERV WORM!"
XScrSvrOld[worm filename]"Added by the OPASERV WORM!"
NSecureClean4RegManagerscregmanager4.exe"WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data
XServer Registryregscr32.exe"Added by the BIFROSE-ZB TROJAN!"
XSkynetRevengewinlogon.scr"Added by the NETSKY.AA WORM!"
XSpees1speedy.scr"Added by the OPASERV.Y WORM!"
XSPINXWscript.exe OXNEY.B.VBS"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""OXNEY.B.VBS"" file is located in %System%"
YsscRunSSCRun.exeAOL's firewall
XSTVwinscrne.exe"Added by a variant of the SDBOT WORM!"
Xsvchostinetinfo.scr"Added by the ODELUD WORM!"
Xsvchostdll.scrsvchostdll.scr"Added by the BANCBAN-FM TROJAN!"
Xsvchosts.scrsvchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
XSymantecFilterCheckbsyys.scr"Added by the BANLOAD.DZC TROJAN!"
XSyntax Scriptsystacq.exe"Added by the SDBOT.AI WORM!"
XSyntax Scriptsaskatcw.exe"Added by the SDBOT-TE WORM!"
XSystem CSRSS Patchscrtkfg.exe"Added by the RBOT-ADA WORM!"
XSystem-ServiceEXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
XSystemOPsvscrtvc32.exe"Added by a variant of the SPYBOT WORM!"
Xsystemscrootsystembin.exe"Added by a variant of the RBOT WORM!"
XTime Zone Synchronizationwscript zshell.js"Added by the NETDEX-A TROJAN!"
UTPKBDLEDTpScrLk.exeIBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
UTpscrexTpscrex.exe"Lenovo (IBM) ThinkPad hotkey related"
UTpScrLkTpScrLk.exeIBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
UTpScrLk.exeTpScrLk.exeIBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
XVelocidadSimplescrmain.exeVelocidadSimple rogue optimization utility - not recommended
XW32.ScranScran.exe"Added by the NARCS WORM!"
Xw32alanismope.scr"Added by the SINALA WORM!"
XW32Load[random filename].scr"Added by the CASPID WORM!"
XW32TcWTC32.scr"Added by the VOTE.D or VOTE.K WORMS!"
UWatson Subscriber for SENS Network Notificationsdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
Xwiascrwiascr.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
XWindows JavaScript DaemonWinjsd.exe"Added by the WOOTBOT.AF WORM!"
XWindows NT Logon Applicationwinlogon.scr"Added by the RBOT-ALP WORM!"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWINDOWS SCREENSAVERssaver.scr"Added by the SDBOT-YZ WORM!"
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
XWindows Updatescrigz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindowsCRCwscrc.exe"Added by the SDBOT-VU WORM!"
XWindowsCriticalUpdatewindows_critical_update.exe"Added by the ASTEF or RESPAN WORMS!"
XWinhlp32Wscript.exe Msexec32.vbs"Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Msexec32.vbs"" file is found in %System%"
XWINLOGONwscript.exe WINLOGON.vbs"Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
XWinsock2 driverwincfg.scr"Added by the SPYBOT-E TROJAN!"
XWinsock2.dllWINLODR.SCR"Added by an unidentified VIRUS
XWinsock32driverwin32server.scr"Added by the HACARMY TROJAN!"
XWinStartWscript.exe WinStart.vbs"Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
XWMI Standard Event Consumer - Scriptingscrcons32.exe"Added by the RBOT-GRD WORM!"
XWMI Standard Event Consumer - Scriptingscrcs.exe"Added by a variant of the RBOT-GRD WORM!"
Xwscript.exevabian.vbs"Added by the VABI VIRUS!"
UYou've Got Pictures Screensaverygpsstra.exeAOL You've Got Pictures Screensaver
X[filename]svchost.scr"Added by the BANKER-CC TROJAN!"
X[original filename]svchost.scr"Added by the BANCBAN-CX TROJAN!"
X[original filename]xphost.scr"Added by the BANCBAN-HM TROJAN!"
X[random]lsass.scr"Added by the BANCBAN-CW TROJAN!"
X[random]svchost.scr"Added by the BANCBAN-CY TROJAN!"
X[various names]ActionScr.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.