Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xpathex.exe"Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field"
Note the filename has a ""0"" rather than an upper case ""o"""
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
NAccuWeather.comŽ DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XBarThemebartent32.exe"Added by the AGOBOT-UG WORM!"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
XClickTheButtonCTB.EXE"ClickTheButton adware"
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XClickTheButtoncd_load.exe"Added by the DOWNLOADER-MY TROJAN!"
Ncssauthecssauthe.exe"Part of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
Xcthelpcthelp.exe"Added by the SDBOT TROJAN!"
UCTHELPERCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
XCTHelpercthelper.exe"Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XDaily Weather Forecastweather.exe"Added by the DLOADER-IP TROJAN!"
NDesktop WeatherTHE WEATHER CHANNEL.exe"Desktop Weather by The Weather Channel - provides current temperature
NDesktop Weather 3THE WEATHER CHANNEL.exe"Desktop Weather 3 by The Weather Channel - provides current temperature
NDesktop Weather 3THEWEA~1.EXE"Desktop Weather 3 by The Weather Channel - provides current temperature
UdisplayThe_Eye.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
NDulux WeatherShield WeatherDeskweather.exe"Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
NDW4Weather.exe"Desktop Weather 4 by The Weather Channel - provides current temperature
NDW4DesktopWeather.exe"Desktop Weather 4 by The Weather Channel - provides current temperature
NDW6DesktopWeather.exe"Desktop Weather 6 by The Weather Channel - provides current temperature
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
NEthernettcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsnger.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEthernet Linkingethernet.exe"Added by a variant of the IRCBOT TROJAN!"
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
NHome Theater SchSvrSchSvr.exe"WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
Xmark the servicexxtra32.exe"Added by the SDBOT.APP WORM!"
XMicrosoft DLL Authentificationdllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Update Machineubthec.exe"Added by the AGENT.AWZ TROJAN!"
XMotherboard ConfigAti2xxx.exe"Added by the RBOT-AIK WORM!"
XMotherBoard SoundsSounds.exe"Added by the RBOT-AAP WORM!"
NMotive SmartBridgeBTHelpNotifier.exe"System tray icon for help from BT Broadband
XMP3Themes"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3ToTheMax"rundll32.exe MSA64CHK.dllDllMostrar"
NPush The Freakin' Buttonptfb.exe"Push the Freakin' Button - "When a dialog causes irritation
XRBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Serverglossary.exe"Added by the VANEBOT-J WORM!"
USay The Time 5.0SAYTIME.EXE"This program has audio cues for the system clock in male and female voices
XStart aThe Rollenotxa2.exe"Added by the RBOT-PV BACKDOOR!"
XStart The Rollenotax2.exe"Added by the RBOT.XO WORM!"
NSubtract the AdsAdSub.exeRemoves adverts from web pages. Although useful - not required
USureshotpopupkillerStopthepop.exe"Stop-the-Pop-Up popup blocker"
XThEwind0s.exeAdded by an unidentified WORM or TROJAN!
NThe AssistanteSched.exe"Related to WinTotal from a la mode inc. FormFiller for appraisers"
UThe Easy Bee's HiveATCEgSvr.exe"The Easy Bee is a software that allows you to record Internet navigation sequences
XThe Ethernetethernet.exe"Added by a variant of the SDBOT WORM!"
XThe Ethernetintranet.exe"Added by a variant of the SDBOT WORM!"
XThe Intranetintranet.exe"Added by a variant of the SDBOT WORM!"
NThe ProxomitronProxomitron.exe"A free
XThe Registry SentinelThe Registry Sentinel.exe"The Registry Sentinel rogue security software - not recommended
XThe Service Pack Loaderspxp.exe"Added by the RBOT-BYM WORM!"
XThe Spy Guardspyguard.exe"The SpyGuard rogue spyware remover - not recommended
XThe Spy Guard Monitorspyguard_monitor.exe"The SpyGuard rogue spyware remover - not recommended
XThe Web SentinelThe Web Sentinel.exe"The Web Sentinel rogue security software - not recommended
XTheBestMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTheDefend.exeTheDefend.exe"TheDefend rogue security software - not recommended
XTheLastDefenderLastDefender.exe"The Last Defender rogue security software - not recommended
?TheMainStartN/A"??"
XThemeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTheMonitor[path to trojan]"Added by the DLOADR-LO TROJAN!"
XTheMonitorDuce6.exe"YourEnhancement downloader"
XTheSpyBotTheSpyBot.exe"TheSpyBot rogue security software - not recommended
NTray TemperatureWeatherbug.exe"Weatherbug provides current outdoor temperature in the System Tray
UUCmore XP - The Search Accelerator"rundll32.exe UCMTSAIE.dll DllShowTB"
UViStart - The Vista Start MenuViStart.exe"ViStart (Vista Start Menu for XP) adds a Vista style Start Menu for Windows XP users and can be loaded at boot time or started manually"
NWEATHERWEATHER.EXE"Weatherbug provides current outdoor temperature in the System Tray
UWeather Pulseweatherpulse.exe"Weather Pulse from Tropic Designs. ""Display popular Satellite images and video from around the globe
NWeatherCastWeather.exeWeather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
NWeatherEyeWeatherEye.exe"WeatherEye - desktop weather from TheWeatherNetwork"
XWeatherOnTrayWeatherOnTray.exe"Hotbar adware"
XWeatherOnTraySbWeatherOnTray.exe"Hotbar adware"
NWeatherscopeWeatherscope.exe"WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XWeatherStudio DesktopWeatherStudio Desktop.exe"WeatherStudio adware"
NWeatherWatcherww.exe"WeatherWatcher - weather reporting in the System Tray"
XWeirdOnTheWebWeirdOnTheWeb.exe"WeirdOnTheWeb adware"
XWin32 FireWire DriverCTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
UWindows Guardianthehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
XWindows Java UpdateweatherBug32.exe"Added by a variant of the RBOT WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindowsRegKey%updateethernet32m.exe"Added by the RBOT-EN WORM!"
UWINDVDpatchCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
YWinPoetWinPPPoverEthernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
Xwinthelpwinthelp.exe"Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here"
?xBrotherMeComBrMeCom.exe"Related to Brother MFC-9200c printer. What does it do and is it required?"
XYahoo!ethernet.exe"Added by the PROSTI.AA BACKDOOR!"
X[various names]MsNetHelper.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.