Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
XassistseASSISTSE.EXE"CnsMin (Chinese Keywords) hijacker related"
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
UBoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XComcastSUPPORTtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
Xfastsmellfastsmell.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XFastStartntnut32.exe"Added by the STARTPAGE.L TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
Xfstsvc"rundll32.exe fstsvc.dllstart"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
UGhostSecuritySuitegss.exe"Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
NGhostStartTrayAppGhostStartTrayApp.exe"System Tray access to Norton Ghost - added from the 2003 version"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
Xhostservhostserv.exe"Added by the RBOT.BPZ WORM!"
Xhostservwiz98.exe"Added by a variant of the SDBOT WORM!"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
UHostsManhm.exe"""HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
XHostSVC syseHostSVC.exe"Added by the RBOT-ANZ WORM!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
NISDN MonitorLinksts.exe"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards
XIST Serviceistsvc.exe"ISTBar adware"
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
NLinkstslinksts.exe"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards
XLSASS Authoritylshosts32.exe"Added by the SDBOT-UY TROJAN!"
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
XMicosoft Data Core stuffsvshosts.exe"Added by the RBOT.FZA WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosongsvchosts11.exe"Added by the SDBOT-EV WORM!"
XMS Hostsmsthosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
XMshostsMshosts.exe"Added by the STARTPAG.CF TROJAN!"
Xmstsdsc.exemstsdsc.exe"Added by the CIMUZ-CD TROJAN!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
UNeroHomeFirstStartNMFirstStart.exe"Associated with Nero Scout
UNMFirstStartNMFirstStart.exe"Associated with Nero Scout
NNokia FastStartNokiaMusic.exe"Part of the Nokia Music music manager. ""With Nokia Music
NOM2_MonitorFirstStart.exe"Olympus Master 2 - digital camera management tools"
NOM_MonitorFirstStart.exe"Olympus Master 1 - digital camera management tools"
Xpestsweeperpestsweeper.exe"PestSweeper rogue security software - not recommended
XPostSetupCheckRundll32.exe atgban.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""atgban.dll"" file is found in %System%"
XpostSetupCheckRundll32.exe gzmrt.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""gzmrt.dll"" file is found in %System%"
XPostSetupCheckRundll32.exe cpmsky.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""cpmsky.dll"" file is found in %System%"
Xpostsospost.exe"Added by the TATERF-Z WORM!"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
Xsdchosts32vbdd.exeAdded by the RANKY.AG TROJAN!
XService Hostsvchosts.exe"PornCleanser spyware"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
NSigmatelSysTrayAppstsystra.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
XStart Uppingssvcchosts.exe"Added by the SDBOT.VY WORM!"
UStationPlaylistStudioSPLStudio.exe"StationPlaylist Studio - ""simple to use on-air broadcast playback software for the studio and/or DJ"" for small to medium sized radio broadcasters
UStopSignSsTsMon"sstsmon.dll VerifyStatus"
XStsiwnujdss2.exe"Added by the SDBOT-YI WORM!"
Xsvchostssvchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
Xsvchosts.exesvchosts.exe"Added by the AGOBOT-JN WORM!"
Xsvchosts.scrsvchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
XSvhost Service Serversvhostser.exe"Added by a variant of the RBOT WORM! See here"
XSygate Personal Firewallhostserv.exe"Added by the RBOT.BKO WORM!"
Xsys_up1svchostsys.exe"Added by the MULTIDR-FL TROJAN!"
XTerminal Servicesmstscc.exe"Added by the SDBOT-CZW WORM!"
XTrustSoldierTrustSoldier.exe"TrustSoldier rogue security software - not recommended
Xvaluenamesvchosts.exe"Added by a variant of the SDBOT WORM!"
XVhosts Protectionvhosts.exeAdded by an unidentified WORM or TROJAN!
Xvirtual-machinesvchosts.exe"Added by the RBOT-US WORM!"
Xvschostvschosts.exe"Added by the VIPSY-A TROJAN!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Host32 Starterhostserv.exe"Added by the SDBOT-WU WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindowsDiskLogcstsm.exe"Added by the STINX-C or STINX-D TROJANS!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWNSAwnsts**.exe [* = random char]"PurityScan adware"
XYahoo Messenggerscvhosts.exe"Added by the SOHANNA-AH WORM!"
XYahoo Messenggerscvshosts.exe"Added by the TRAX-A WORM!"
X[random characters]systs.exe"Added by the AGENT-GDC TROJAN!"
X[various names]svchostss.exe"Added by a variant of the RBOT WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.