Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*MS Setup[random filename]"Virtumondo adware
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
XAdVantage SetupAdVantageSetup.exe"MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the ""DAEMON Tools sponsor ad module"" option during install) and possibly others"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
NEapcisetupsbsetup.exeRockwell RipTide soundcard application software. Sound works without it
NEAPCISETUPwizard.exePart of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
UFJTWAIN SetupFjtwSetup.exeFujitsu scanner utility
UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
XGoogle serviceGooglesetup.exe"Added by the IRCBOT-RJ WORM!"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
XHLcleanuphlsetup2.exe"LinkReplacer/FFinder adware"
UHWSetupHWSetup.exe hwSetUP"""Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows."" Allows the user to change BIOS
Xiesetupi.exeiesetupi.exe"Added by a variant of the RBOT WORM!"
?InstallNAIProductSETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
YJMB36X ConfigureJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJMB36X IDE SetupJMInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJMB36X IDE SetupxInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
Xkeymgrldr"rundll32 setupapi InstallHinfSection... keymgr3.inf"
?LanzarL2007[path] setup.exe"??"
?LLMODCL2"rundll.exe setupx.dll InstallHinfSection ..LLMODCL2.INF"
NLogitech Desktop Messengersetup-8876480.exe"Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products
YLusetupLUSetup.exe"Symantec LiveUpdate installer - required to install a new version of the application. Will only run once
XMCAFEEIPSsetup.exe"Added by the WHITEWELL TROJAN!"
XMemConfigSetupIE.com"Added by the TAPLAK WORM!"
NMGA_CD_Installmgasetup.exeMatrox Millennium video driver. Not required once drivers installed
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Driver Setupccdrive32.exe"Added by the AGENT-LYL TROJAN!"
XMicrosoft Driver Setupcidrive32.exe"Added by the AGENT-NES TROJAN!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Update 32mssetup32.exe"Added by a variant of the RBOT WORM!"
?MigrationVendorSetupCaller"rundll32.exe migrate.dll CallVendorSetupDlls"
?MM Installsetup.exe"Possibly Money Manager from Moneysoft?"
UMplSetupMplSetup.exeUsed by Ricoh network printers to enable network printing from the client
XMSN SetupMSN.msn"Added by the JAMBU WORM!"
XMS_SETUP.EXEMS_SETUP.EXE"Added by the CHARGE TROJAN!"
XMyVBAppsetup.exe"Detected by Kaspersky as the VB.KB TROJAN! File location is in the root folder (i.e.
NNetworkSetupdlink.exe"D-Link System Tray icon"
XNI.UGES_0001_N108M2006setup_en.exe"Installer for the MyContentAssistant rogue privacy tool"
YNuTCSetupEnvironncoeenv.exe"Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows
XOESETsetup60.exe"Added by the WAREZDL.28672 TROJAN!"
UPNSetupPNSetup.exe"PopNot - pop-up killer"
XPostSetupCheckRundll32.exe atgban.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""atgban.dll"" file is found in %System%"
XpostSetupCheckRundll32.exe gzmrt.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""gzmrt.dll"" file is found in %System%"
XPostSetupCheckRundll32.exe cpmsky.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""cpmsky.dll"" file is found in %System%"
UPPK Setup(Server)SEServe.exe"Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button
?RjLyraInstallersetup.exe"??"
Nsetuphphprld.exe ....setup.exeHP DeskJet Setup - printers function normally without it
XSetup[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XSetup experationsvchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsetup.exesetup.exe"Added by the GOLDUN-GB TROJAN!"
Xsetuparunt32.exe"Added by the QQPASS-K TROJAN!"
Xsetupdatarnll32.exe"Added by the QQPASS-AC TROJAN!"
NSetupICWDesktopicwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
Xsetupuserregedit.exe setupuser.log"Regfile in disguise - another CoolWebSearch parasite variant"
NSigmaTel Audiosetup.exe"Sigmatel audio driver"
USmart Connect SetupSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
XStart Xp Setupmsxp.exe"Added by the RBOT.AKK WORM!"
Xsvchost[path] SETUP.EXE"Added by the SETCLO WORM!"
?SynSetupSynTP.tmp RunOnce.exe"Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?"
XSysPnP"rundll32 setupapi InstallHinfSection [varies] oemsyspnp.inf"
XSystem Setuprpcxcmod.exeAdded by an unidentified WORM or TROJAN!
XSystem Updatemssetupconf.exe"Added by the RBOT.DLC WORM!"
?TangoSetup.exe"Tango Broadband access software. Is it required?"
XTASK SETUPtasksetup.exe"Added by the RBOT-YR WORM!"
?TB_setupTB_ANI~1.EXE"??"
XTB_setuptb_setup.exe"HuntBar hijacker
XToolbarInstallMirarSetup.exe"Mirar adware"
UVAIO Action Setup (Server)VAServ.exe"Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera
XWifi Setupwifisetup.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xwin32Setup_32.exe"Added by the EVILBOT.B TROJAN!"
Xwin32WinSetup.exe"Added by the EVILBOT.B TROJAN!"
XWin32arsetup.exeAdded by the SPAZBOX.A TROJAN!
Xwin32servservicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
UWindows Acceleratorssetup.exe"KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XWindows Monitorarsetup.exeAdded by the SPAZBOX.A TROJAN!
XWindows Pool Setuppoolmc.exe"Added by the IRCBOT.RU BACKDOOR!"
XWindowsSetup[path to trojan]"Added by the EZBOT TROJAN!"
Xwinphonics7536vbsystem35.exe setups.exe vb.vb"Added by a variant of the MUTIN-C TROJAN!"
?zzzCamlnSuitelllsetup.exe 46***"??"
?zzzhpsetupsetup.exe"??"
X[Randomly chosen existing folder name]_setup.exe"Added by the ANTINNY-L WORM!"
X[various names]iesetupdll.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]SetupExeDll.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.