Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
Xadstartupautomove.exe"Adlogix adware variant"
XAdstartupAdstartup.exe"Adlogix adware"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xcmonitorstartupmon.exe"SystemDoctor rogue security software - not recommended
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
XDC6dc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDC6_checkdc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
UDualCoreCenterStartUpDualCoreCenter.exe"Unified control center for overclocking both the graphics card and the CPU
XERSers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERS_checkers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
NeWare StartupiWareStart.exe"eWare iWare task bar. Not required"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
UFirewallStartupFirewallstartup.exe"Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
XGStartupGMT.exe"Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
UHijackThis startup scanHijackThis.exe"""HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware
UHook99startuphk2re.exe""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons
?HP OfficeJet Series xxx StartupHPOSTR03.EXE"xxx represents the series number - such as 700. What does it do and it it required?"
?HP OfficeJet Series xxx StartupHPOstr05.exe"xxx represents the series number - such as 700. What does it do and it it required?"
UIDriveE StartupIDrvieEStartup.exe"IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
NIomega Startup OptionsIMGSTART.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
NISUSPM StartupISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXE"YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs"
NLimeWire On StartupLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
XLssas Monitoring StartupLSSAS.EXE"Added by the RBOT.XJ WORM!"
XMAV_checkmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
Xmav_startupmonmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
XMicosoft Startupsyscall.exe"Added by the SDBOT-JI WORM!"
XMicosoft Startupsystall.exe"Added by the SDBOT-GM BACKDOOR!"
NMicrosoft Office Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft Office StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft startupwmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
NMicrosoft Utility StartupOSA9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Winedows startupWinKey.exe"Added by a variant of the SDBOT WORM! See here"
UML1HelperStartUpML1HEL~1.EXE"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UML1HelperStartUpML1Helper.exe"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
NMoneyStartUpMoney Startup.exeMicrosoft Money
NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
XMS lsass Startuplsass135.exe"Added by the RBOT.WM WORM!"
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMsn Startupmsnstartup.exe"Added by the ARBOT.AA WORM!"
XMSN8m Startupmsn8m.exe"Added by a variant of the RBOT WORM!"
XMsy Startupsmsyh32.exe"Added by the AGOBOT-QC WORM!"
XMsy1 Startupsmsyj32.exe"Added by the AGOBOT-QQ WORM!"
UMW1HelperStartUpMw1helper.exe"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UMW1HelperStartUpMW1HEL~1.EXE"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL NewDotNetStartup"
XNew.net Startup"rundll32 [path] NEWDOT~2.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~2.DLL NewDotNetStartup"
XNorton AV Protection StartupAti2xxx.exe"Added by a variant of the RBOT WORM!"
UNotebook Maximizermaximizer_startup.exeToshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency
XNvidia Startup Managerksvc32.exe"Added by the AGENT-IWD TROJAN!"
NOffice Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XOffice StartupExploer.exe"Added by the GAOBOT.BV WORM! Note the different filename to the valid MS Office entries"
NOffice StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NOmgStartupomgstartup.exeSony program called OpenMG Jukebox - player and music organizer
NOptiCAL StartupOptiCAL.exe"OptiCAL monitor calibration software from ColorVision for advanced amateurs
NPhotoCAL StartupPhotoCAL.exe"PhotoCAL wizard driven monitor calibration software from ColorVision for beginners and photo enthusiasts"
NPowerQuest Startup UtilityPQINIT.EXE"From a visitor - "This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up
UProPort StartupProPort.exe"Proport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill
UQTaskStartupqtask.exe"Feature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly
YQuick Heal Startup ScanQHSTRT32.EXE"Quick Heal - virus scanner"
YQuick StartupFquick32.exeFor a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
NQuicken StartupQWDLLS.EXEQuicken option to load DLLs at startup
XRegistry Startup Checkcheckreg.exe"Added by the REMLOAD-A or DANMEC-B TROJANS!"
URivaTunerStartupDaemonRivaTuner.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTunerWrapper.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URKLG Startupklg.exe"Local Keylogger Pro keystroke logger/monitoring program - remove unless you installed it yourself!"
URun StartupMonitorStartupMonitor.exe"Mike Lin's StartupMonitor
XSalestartmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
NSB Audigy 2 Startup Menu/l:eng"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
XSecure32Shell32.com StartUp"Added by the BRONTOK-CJ WORM!"
XSecure64Regedit32.com StartUp"Added by the BRONTOK-CJ WORM!"
XServices Startupservices.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XServices Startupsvhost33.exe"Added by a variant of the RBOT WORM!"
XServices32 Startupwin32dll.exe"Added by the SDBOT-XO WORM!"
USfWinStartInfosfWinStartupInfo.exeSFIRM32 Online Banking software
XSkype Startupskyp.exe"Added by the VANBOT-C WORM!"
XSkypeStartupSkype.exe"Added by the PYKSE-A WORM!"
YSoDA StartupSodaStartup.exe"Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software"
USRP Startupsrrpro.exe"System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium ""features"". This is enabled if you tick the ""Remove unnecessary System Restore information on startup"" box. Available via Start -> Settings -> Control Panel"
NStartup??Related to an Iomega drive
XStartupWinlogonStartupUnidentified malware
XStartupmirc.exe"Added by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in the Windows or Winnt folder"
XStartup Configuration[six character filename]"Added by the RBOT-ARV WORM!"
XStartup Configurationwztoid.exe"Added by the RBOT-ASD WORM!"
?Startup Launcher GUIGUI.exe"Startup manager?"
UStartup Manager ScannerStartupMonitor.exe"Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans
YStartup ScanSensor.EXE"AntiVirus Quick Heal - scheduling agent"
XStartup UpdateCvshost.exe"Added by the GAOBOT.AO WORM!"
XStartupBiniwnujdss.exe"Added by the SDBOT-XZ WORM!"
XStartUpDate[path to trojan]"Added by the BIFROSE.F BACKDOOR!"
UStartupMonitorStartupMonitor.exe"Mike Lin's StartupMonitor
XStartupOptionloadsysdisk.exe"Added by the HIDAGENT-B WORM!"
USuitcase StartupSuitcase.exe"Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system"
XSystem File Startupsys32.exe"Added by the RBOT.OTL WORM!"
USystem Mechanic Startup GuardStartupGuard.exe"System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses
USystem startupcharmapx.exeOnly required if using an oriental language
XSystem StartupVoltio.exe"Added by the RBOT.NJ WORM!"
XSystem Startupkimochi.exe"Added by a variant of the RBOT WORM!"
XSystem Startupsys.exe"Added by a variant of the IRCBOT TROJAN!"
XSystem Startup Managersmcss.exe"Added by the RBOT.AMD WORM!"
XSystem32 Runtime StartUpsysrs.exe"Added by the AGOBOT.ANW WORM!"
NTimed Backups Manager StartupBACKTIME.EXE"Backup Plus - backup software"
Xtjstartup[path to file]"Added by the TJSERV.C TROJAN!"
?TomcatStartuphpbpsttp.exe"Apache Tomcat web server
?TomcatStartup 2.5hpbpsttp.exe"Apache Tomcat web server
Nucstartupucstartup.exe"IBM Update Connector - old auto updater feature for IBM machines that connects to IBM to see if there are any new drivers
Nucstartup.exeucstartup.exe"IBM Update Connector - old auto updater feature for IBM machines that connects to IBM to see if there are any new drivers
NUC_Startucstartup.exe"IBM Update Connector - old auto updater feature for IBM machines that connects to IBM to see if there are any new drivers
NUltra Hal Assistant 4.5 StartupHalAsst.exe"Zabaware Ultra Hal Assistant - artificial intelligence conversation simulator. It is capable of being your digital secretary and companion"
XUserInit StartUprpcxuisu.exe"Added by a variant of the SDBOT WORM!"
XVekio StartupsPnksvc32.exe"Added by the AGOBOT.AJG WORM!"
XVGA Startupvgacard.exe"Added by a variant of the RBOT WORM!"
NvTunerStartUpvTuner.exe"vTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet""
NWFGStartupWFGStartup.exe"
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
XWin StartupWINCFG32.EXE"Added by the SPYBOT-CL WORM!"
XWindows Audio Startupnndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
XWindows CODE Fix Msy Startupsmsyh32.exe"Added by the AGOBOT.AKK WORM!"
XWindows Messenger Live Startupwindowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows Registry Startupwind32.exe"Added by the AGOBOT-BZ WORM!"
XWindows Startupwinsta~1.exe"GoHip foistware"
XWindows Startupwinstartup.exe"GoHip foistware"
XWindows StartupWdrun32.exe"Added by the GAOBOT.AO WORM!"
XWindows Startupservices21.exe"Added by the AGOBOT-MX WORM!"
XWindows StartupWinsys32.exe"Added by the RBOT.AAB WORM!"
XWindows Startup 32 Bitssysrun32.exeAdded by a variant of the DARKSUN TROJAN!
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWinsock StartupMain2.exe"Added by a variant of the SDBOT WORM!"
XWinSysStartUpWKbLwTaskSystemDll.Exe"Added by the BACKZAT.G WORM!"
?xkstartup"RunDll32 InstZ82.dll SetUsbPrinterPort"
XXupiter StartupXupiterStartup.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
Xxupiterstartup2003xupiterstartup2003.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
XZekio Startupsznksvc32.exe"Added by the AGOBOT-AGI WORM!"
XZekio Startupscondll.exe"Added by the AGOBOT-AGD WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.