Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
?GrdSys32GrdSys32.exe"X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XintranetSYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
XLasErmaErmasys32.exe"Added by the LERMA-A WORM!"
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Supportsys32ms.exe"Added by the RBOT-AHI WORM!"
XMicroSoft sys32sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Systemmssys32.exe"Added by the PETTICK.A WORM!"
XMicrosoft System Checkuplibsys32.exe"Added by the SDBOT-ACK WORM!"
XMicrosoft Updatesys32cfg.exe"Added by the RBOT.DR WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMsUpdater Systemudpsys32.exe"Added by the RBOT.AAA WORM!"
XMsVBdllsys32dll.exe"Added by the AIMDES.B or AIMDES.C WORMS!"
XMsys32morfitwebentrance.exe"Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as Any installed application including this must be un-installed before you can reset your homepage"
NMutexServiceExSys32Smm.exe"Webroot Sofware's discontinued ""Privacy Master"""
XNorton AntiVirus SysNAVsys32.exe"Added by a variant of the WOOTBOT WORM!"
Xnsdrivernssys32.exe"NetShagg adware"
Xnsys32nsys32.exe"Added by the AGOBOT-SU WORM!"
XnVidia System Driversnvsys32.exe"Added by an unidentified WORM or TROJAN! See here"
Xrunwinsys32.exe"Added by the DELF.CP BACKDOOR!"
UScanSys32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
Xsdxsys32sdxsys32.exe"Added by the BROGGER-A TROJAN!"
XServicesprosys32.exeAdded by an unidentified WORM or TROJAN!
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
Xsvcsys32svcsys32.exe"Added by the AGOBOT-LL WORM!"
Xsys32SYS32.EXE"Added by the FLUX.E BACKDOOR! The file is located in %System%"
Xsys32sysx32.exe"Added by the KVEX-A VIRUS!"
XSys32Sys32.exe"Added by the AUTORUN-KL WORM! The file is located in %Windir%"
Usys32cmdsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsys32dllsys32dll.exe"Added by the AIMDES.B WORM!"
Usys32sqlsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsys32_novsys32_nov.exe"Added by the AGENT-LAX TROJAN!"
XSystem File Startupsys32.exe"Added by the RBOT.OTL WORM!"
XSystem Netsys32.exe"Added by the FORBOT-FX WORM!"
Xsystemdll.dllwinsys32.exe"Added by the DELF.CP BACKDOOR!"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XVideo Servicessys32.exe"Added by the AGOBOT.PS WORM!"
XWin32 USB2 Driversys32.exe"Added by the WOOTBOT.X WORM!"
XWin32 USB2 Driversys32snd.exe"Added by the FORBOT-AN WORM!"
Xwindllsys32.exewindllsys32.exe"Added by a variant of the MITGLIE-A TROJAN!"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Networkingwinsys32.exe"Added by the GAOBOT.FL WORM!"
XWindows StartupWinsys32.exe"Added by the RBOT.AAB WORM!"
XWINDOWS SYSTEMwinNTsys32.exe"Added by the MYTOB-DM WORM!"
XWindows Systemwinsys32.exe"Added by the MYTOB-IS WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System Securitysys32.pif"Added by the RBOT-AOL WORM!"
XWindows System32winsys32.exe"Added by the SDBOT-AHS WORM!"
XWindows TMwindowssys32.exe"Added by a variant of the RBOT WORM!"
XWinsock2 driverntsys32.exe"Added by the SPYBOT-DD WORM!"
XWinSys32Winsys32.exe"Added by the CIGIVIP TROJAN or RECKUS WORM!"
Xwinsys32 Driverwinsys32.exe"Added by the LOONY-O TROJAN!"
XWINTASKsys32.exe"Added by the MYTOB.K WORM!"
Xwmsys32wmsys32.exe"Added by the BANPAES.B TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.