Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAdobeReaderProspoolss.exe"Added by the SDBOT-AKZ WORM!"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
Xautoloadspooll.exe"Added by the SILLYFDC WORM!"
Xautoloadspool.exe"Added by the AGENT-GSG TROJAN!"
Xdumprepspoolc.exe"Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
XIPC Spool Managerwnmgre.exe"Added by the SDBOT-ZC WORM!"
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
XLaserJetspoolvs.exe"Added by the DLOADER.PFR TROJAN! This is not the file of the same name from older versions of MS Office - see the link for the location"
Xload=Spoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
XMicrcoft Exploererspoolsal.exe"Added by the RBOT-AKK WORM!"
XMicrcoft Updatspoolsae.exe"Added by the RBOT-AIB WORM!"
XMicrcoft Updatspoolsaex.exe"Added by the RBOT-AJM WORM!"
XMicroft Exploererspoolsac.exe"Added by the RBOT-AMD WORM!"
XMicrosoft Client Pcspoolsrv.exe"Added by the RBOT-AQM WORM!"
XMicrosoft DirectXSpoolserv.exe"Added by the DINFOR WORM!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Spool Svcspoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Task Manager Daemonspoolsrv.exe"Added by the SDBOT.FLL WORM!"
XMicrosoft Updatespool.exe"Added by the AGENT-GJC TROJAN!"
XMicrosoft Update 23spoolvs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32spoolvs.exe"Added by the RBOT-BBQ WORM!"
XMicrosoft Update Machinespoolserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoftPersonalFirewallspoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
XMicrosoftSysSPOOLSYS.exe"Added by the TARNO.N TROJAN!"
Xms spool servicemsspooler.exe"Added by a variant of the RBOT WORM!"
XMs Spool32MS SPOOL32.EXE"Added by the ASASSIN TROJAN!"
XNT Printing Servicespoolsc.exe"Added by the BUZUS-K WORM!"
XNTSpoolNTSpool.exe"Added by the AGENT-GPY TROJAN!"
Xntuserspool.exe"Added by the DLOADER.DYA TROJAN!"
Xntuserspools.exe"Added by the AGENT-GRO TROJAN!"
XPolicyRunspoolsv32.exe"Added by the BACKDOOR-DNV TROJAN!"
XPrint SpoolerSpoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
XPrint Spoolerspoolsvc32.exe"Added by the SDBOT.BB TROJAN!"
XPrint Spoolerspools.exe"Added by the RBOT-LD WORM!"
XPrint Spoolerspool.exe"Added by the BDOOR-IS BACKDOOR!"
XPrint Spoolerspoolsv32.exe"Added by the RBOT.SW WORM!"
XPrinter Servicesspool.exe"Added by the RBOT-Y WORM!"
XPrinter Spoolupdater.exe"Added by a variant of the RBOT WORM!"
XPrinter spool Servicespool.exe"Added by the RBOT-ACP WORM!"
Xprinter spoolercommonaccess.exe"Added by the DELF-LB TROJAN!"
XPrinter Spoolerspooler.exe"Added by the DELF-JJ TROJAN!"
XPrinter Spooler Subsystemspoolss.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Windows spoolss.exe process which is always located in %System% and should not figure in Msconfig/Startup!"
XPrinterSpool[path] RESTORE.EXE [path] SPOOL.EXE"Added by the ALADINZ.K TROJAN!"
UPrintSpoolerlass.exe"Win-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
XPrintSpoolSvSystem.exe"Added by the BDOOR-S BACKDOOR!"
Xreggsdgspoolserv.exe"Added by the SDBOT-MS WORM!"
Xreggsdgspoolsrv.exe"Added by the SDBOT-DI WORM!"
Xrpc Win32spoolscv.exe"Added by a variant of the RBOT WORM!"
XRun Services as Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XService Hostspoolxx.exe"Added by the TORVEL WORM!"
XService Host Processspoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
XServices Administratorspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XShellsplspools.exe"Added by the PROXAGE-A TROJAN!"
XSistem Servicessyspool.exe"Added by the AGOBOT-GF WORM!"
Xsoftwarespools.exe"Added by the AUTORUN-CS WORM!"
XSpool[path to trojan]"Added by the RANKY.R TROJAN!"
XSpoolwys.exe"WhileUSurf adware"
XSpoolstatic.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
XSPOOL Configurationspoolsvc.exe"Added by the SDBOT-KD WORM!"
XSpool Loaderspool.exe"Added by a variant of the RBOT WORM!"
XSpool LoadKItspoolv.exe"Added by a variant of the RBOT WORM!"
XSpool lptt01spool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpool Managerspoolsrv.exe"Added by the BANKER-FR TROJAN!"
XSpool ml097espool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpool32pool32.exe"Added by the ASSASIN-F TROJAN!"
Xspoolax[path to trojan]"Added by the PERDA-D TROJAN!"
XSpooler de Impressservices.exe"Added by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User%"
XSpooler Hostsmhost.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XSpooler ServiceSpoolsrv.exe"Added by the JOINER.C1 TROJAN!"
XSpooler Subsystemspoolsub.exe"Added by the SDBOT-ABG TROJAN!"
XSpooler SubSystem Appspoolsvc.exe"Added by the POEBOT-J WORM!"
XSpooler SubSystem AppspooIsv.exe"Added by the LINKBOT.M WORM!"
XSpooler SubSystem Appspoolv.exe"Added by the SDBOT-BN WORM!"
XSpooler SubSystem Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
XSpooler Subsytem Appspoolsvc.exe"Added by the SDBOT-MM WORM!"
XSpoolerSubSystemProcessSpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
Xspoolmsspoolms.exe"Added by the LEGMIR-ARO TROJAN!"
XSpools Service Controllerspools.exe"Added by the KASSBOT-C WORM!"
Xspoolservspoolserv.exe"Added by the SDBOT-PN WORM!"
XSpoolServicespolsv.exe"Added by the AGOBOT-CS WORM!"
Xspoolsrv.exespoolsrv.exeAdded by an unidentified WORM or TROJAN! Located in %System%
XSpoolsvSpoolsv.exe"Added by the CIADOOR.121 VIRUS! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
Xspoolsvsvchost.exe"Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
Xspoolsvspoclsv.exe"Added by the FUJACKS-M WORM!"
Xspoolsvspoolsv.exe"Added by the ZAPCHAS-EE TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%\Temp\spoolsv"
Xspoolsvspoolvs.exe"Added by the AGENT-HNV TROJAN!"
Xspoolsvspoolsv.exe"Added by the ANTINNY-BH WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\Messenger"
Xspoolsvspoolsv.exe"Added by the OURXIN.C TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in a ""spoolsv"" subfolder"
XSpoolsvspoolsv.exe"Added by the ANTINNY.F WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Program Files%\Lotus"
Xspoolsv managerSpoolMgr.exe"Added by the ASSIRAL WORM!"
Xspoolsv servicespoolsv32.exe"Added by the RBOT-AHP WORM!"
Xspoolsv.exe[random filename]"Added by the RBOT-JB WORM!"
XSPOOLSV32SPOOLSV32.EXE"Added by the CWS-I or HAZIF-B TROJANS!"
XSPOOLSV32.exeSPOOLSV32.exe"Added by the STARTPAGE.O TROJAN!"
Xspoolsvcspoolsvc.exe"Added by the DROPPER-AT TROJAN!"
XspoolsvrSPOOLSVR.EXE"Added by the RAYROB.A TROJAN!"
Xspoolsvr32csmss.exe"Added by the AGENT-AU TROJAN!"
Xspoolsvr32csmss32.exe"Added by a variant of the AGENT-AU TROJAN!"
Xspoolsvswintre.exe"Added by the SDBOT.EGQ WORM!"
Xspoolsvswincfy.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xspoolsvs.exespoolsvs.exe"Added by the DLOADER-RK TROJAN!"
XSPOOLSVUSPOOLSVU.EXE"Added by the STARTPAGE.K hijacker"
Xspoolsvvspoolsvv.exe"Searchcentrix hijacker"
XSpoolvsspoolvs.exe"Added by the SDBOT.AUS WORM!"
XSrv32 spool servicerunsrv32.exe"Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN!"
XSrv32 spool servicespoolsrv32.exe"Added by the SPYRE-B TROJAN!"
XSrv32 spool service[path to trojan]"Added by the DLOADER-LB TROJAN!"
Xstart extractingspoolvse.exe"Added by the RBOT-XF WORM!"
Xstart extractingspoolvs.exe"Added by the RBOT.BAN WORM!"
XStart Uppingspoolnt.exe"Added by the RBOT-TM WORM!"
XSunJavaUpdatSchedspoolsv.exe"Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger"
XSVCHOSTSPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
YSysPoolMssvc.exe"StealthDisk - hides folders
XSysPoolMSSVC32.EXE"Added by the BANCBAN-IO TROJAN!"
XSystemSPOOLSU.EXE"Added by the BANKER-FC TROJAN!"
Xsystem servicespoolcrv.cplAdded by the INSPIR.11 TROJAN!
Xsystem spoolsyspools.exe"Added by the DREF-T WORM/VIRUS!"
XSystem Spooler Subsystemlssas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Tray Servicesspooles32.exe"Added by the AGOBOT.ZH WORM!"
XSystem Update2winspool.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem32 Spoolwinint.exe"Added by the FORBOT-N WORM!"
XSystemsspoolsvc.exe"Added by the DLOADR-SW TROJAN!"
XTcp Application Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XVital Load ProcessSpoolsvr.exe"Added by the RBOT.AIF WORM!"
Xvscannerspooll32.exe"Added by the OPTIXPRO.10 TROJAN!"
XWCESMngrspoolsb.exe"Added by the AGOBOT-QZ WORM!"
XWin32 System Spoolspoolsvc.exe"Added by the SDBOT.UK WORM!"
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows .Net Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows DLL Trackerspoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Spoolerlssas.exe"Added by the RBOT.BXQ WORM!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Print SpoolerNavAgent32.exe"Added by an unidentified VIRUS
XWindows Print SpoolerSVEHOST.EXE"Added by the SPYBOT.H WORM!"
XWindows Printing DriverWinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Service Agentspoolvs.exe"Added by the RBOT-GXI WORM!"
XWindows Service Agentspools.exe"Added by the AGENT-GJF TROJAN!"
XWindows Service Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Spoolwinspool.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Spool Serverspoolsrv.exe"Added by the SDBOT-ACT WORM!"
XWindows SpoolaPrint Servicespoolasrv.exe"Added by the SDBOT-AYD WORM!"
XWindows SpoolerSPOOLSRV.EXE"Added by the SPYBOT.P WORM!"
XWindows Spoolerspoolsv32.exeAdded by an unidentified WORM or TROJAN!
XWindows Spoolerwinsplr.exe"Added by the SHEUR.ANX TROJAN!"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Spooler Servicesspool.exe"Added by the AGOBOT-AMO WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows Spools SVwinsv.exe"Added by the RBOT-AUQ WORM!"
XWindows spoolservr Servicespoolservr.exe"Added by the SDBOT-AAN WORM!"
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
Xwindows spoolsrv servicespoolssv.exe"Added by the SDBOT-AWV WORM!"
XWindows Spoolsurf Servicespoolsurf.exe"Added by the SDBOT-ZZ WORM!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Spoolvvv Servicespoolvvv.exe"Added by the SDBOT-AAW WORM!"
XWINDOWS SYSTEM DNSPOOLhbmail.exe"Added by the MYTOB.FW WORM!"
XWindows System GatewaySPOOLER.EXE"Added by a variant of the RBOT WORM!"
XWINDOWS SYSTEM MANAGERspoolsvc.exe"Added by the MYTOB-LY WORM!"
XWindows SYStryspoolsvr.exe"Added by the SDBOT.GN BACKDOOR!"
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Web Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Zero Spoolernmvcs.exe"Added by the SLENFBOT.JQ WORM!"
XWindowsXp Securityspool.exe"Added by the RBOT-GRK WORM!"
XWinspoolspoolsvr.exe"Added by a variant of the SDBOT WORM!"
Xwin_spool2win_spool2.exe"Added by the SCKEYLOG.B TROJAN!"
Xwnxpupdatespvspool.exe"Added by the DABORA.B WORM!"
XWSConfigurationspoolsc.exe"Added by the AGOBOT-HY WORM!"
UZingSpoolerZingSpooler.exeWas used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums
X[random name]spoolsv.exe"PurityScan adware. Note - this is not the legitimate spoolsv.exe which is always located in %System%"
X[random name]w?nspool.exe"PurityScan adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.