Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Inc.""Miramar SystemsUatmsg.exe
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
XKernellsystems.exe"Added by the TARNO.C TROJAN!"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMSNsystems.exeIdentified as a variant of the Backdoor.PosionIvy keylogging malware
XNAV Agentsystems.exe"Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name"
XNortons AVS Systemsarse.exe"Added by the RBOT.AWY WORM!"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
Xsystemsystemsearch.htaJetseeker.com hijacker
XSystem Loadersystems.exe"Added by the AGOGBOT-FI WORM!"
XSystem Servicesystems.exe"Added by the AGOBOT.VZ WORM!"
XSystem StatsSystemStats.exe"Added by a variant of the WOOTBOT WORM!"
XSystemsscchost.exe"Added by the DAEMOZ.A TROJAN!"
XSystemssvch0st.exe"Added by the MYDOOM.BI WORM!"
XSystemsSystems.exe"Added by the BANKBOA-A TROJAN!"
XSystemsitDDD.exe"Added by the DLOADER-PP TROJAN!"
XSystemssescmgr.exe"Added by the DWNLDR-GAH TROJAN!"
XSystemsspoolsvc.exe"Added by the DLOADR-SW TROJAN!"
XSystemssysmon.exe"Added by the VIXUP-BI WORM!"
XSystems Backupswindrives.exe"Added by the AGOBOT-RB WORM!"
XSystems Restartslchost.exe"Added by the MULTIDROP.C TROJAN!"
XSystems Restartspchost.exeAdded by an unidentified WORM or TROJAN!
XSystems Restart"Rundll32.exe beem.dll DllRegisterServer"
XSystems Restart"Rundll32.exe snim.dll DllRegisterServer"
XSystems Restart"Rundll32.exe zolk.dll DllRegisterServer"
XSystems Restart"Rundll32.exe boln.dll DllRegisterServer"
XSystems Servicedrivex.exe"Added by a variant of the RBOT WORM!"
Xsystems usb driverWindows2.exe"Added by a variant of the RBOT WORM!"
USystems.exeSystems.exe"Keyboard Spectator - monitoring software that creates records of everything people do on a computer
Usystems.exesystems.exe"KGBSpy is a commercial surveillance software program. It logs keystrokes
USystemSafeSyssafe.exe"System Safety Monitor - system monitoring tool with additional application firewalling"
XSYSTEMSars32csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemSASSystem32.exe"Added by the KWBOT.C WORM!"
Xsystemscrootsystembin.exe"Added by a variant of the RBOT WORM!"
XSystemSearchregedit.exe -s ie.reg"Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""ie.reg"" is located in the root folder (ie
XSystemSearchregedit.exe -s sys.reg"Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
XSystemSecurityzprot32.exe"Added by the AGENT-FK TROJAN!"
XSystemServicemsocfg.exePremium rate adult content dialler
XSystemServicenavchk.exePremium rate adult content dialler
XSystemServiceqservice.exePremium rate adult content dialler
XSystemServiceshman.exePremium rate adult content dialler
USystemServicensserver.exe"NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSystemSettingfTRUG.vbs"Added by the TRUG.B MACRO!"
USystemSuite Task ManagerMXTASK.EXE"vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro"
XSystemSv12newmaxxsv234.exe"Added by the TIBS-TS TROJAN!"
XSystemSv121n2ewma1xxsv234.exe"Added by the TIBS.TJ TROJAN!"
Xuserdsystems.com"Added by the OUTLAW-A WORM!"
XWind River Systemsvxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows Systems16winjews16.exe"Added by the SDBOT-CXT WORM!"
UWinSystemWinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
Xwinsystems25winsystems.exe"Added by the RBOT-CNZ WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.