Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
?encapsulated command toolwintr.com"??"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
XMCwintrims.exe"Added by the WINTRIM TROJAN!"
XMCWINTRIM.EXE"Added by the WINTRIM.A TROJAN!"
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft TCP Protocolwintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XNetwork protocol servicewintcp.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XPopMarkWinTask.exe"""Pop Marketing"" adware"
Xspoolsvswintre.exe"Added by the SDBOT.EGQ WORM!"
Xssgrate.exewintems.exe"Added by the MITGLIEDER.Q TROJAN!"
XUndefinedwinter.exe"Added by the KILLAV.LW TROJAN!"
XWCPCwintsvcc.exe"PurityScan adware"
XWCPIwintsvit.exe"PurityScan adware"
XWCPSWint**.exe [* = random char]"PurityScan adware"
XWCPTwintsvtr.exe"PurityScan adware"
XWin FTPwintftp.exe"Added by the SDBOT-KE WORM!"
XWin32BaseServiceMODWintask.exe"Added by the NAVIDAD WORM!"
XWinDLL (wintmp.exe)"rundll32.exe wintmp.exestart"
XWindows Imagewintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
XWindows Local ISPwinthcr.exe"Added by the SDBOT.ENZ BACKDOOR!"
XWindows Microsoft Updatewintask32.exe"Added by a variant of the SDBOT WORM!"
XWindows Service AgentWinTcpip.exe"Added by the SPYBOT.AP WORM!"
XWindows TaskAdWintaskad.exeWindupdates adware variant
XWindows TCP/IPwintcp.exe"Added by the AGOBOT-ZH WORM!"
XWindows Telnet Serverwintel.exe"Added by the AGOBOT-MW WORM!"
XWindows Temperate Serviceswintmp.exe"Added by the SLENFBOT.ZW WORM!"
UWindowsTranslatorDWinTrsl.exe"Delta Translator® English < > Portugese (Brazilian) version - ""an automatic
UWindowsTranslator_EspanholDWinTrsl.exe"Delta Translator® Spanish < > Portugese (Brazilian) version - ""an automatic
XWinhostwintt.exe"Added by the LOLAWEB.B TROJAN!"
XWINTwcp****.exe [* = random char]"PurityScan adware"
XWINTwcp**.exe [* = random char]"PurityScan adware"
XWinTaskWintask.exe"Added by the HIPO or LEMIR.F TROJANS!"
XWINTASKtaskgmr.exe"Added by the MYTOB.I WORM and variants!"
XWINTASKtaskgamr.exe"Added by the MYTOB.AU WORM!"
XWINTASKsys32.exe"Added by the MYTOB.K WORM!"
XWINTASKmsmgrxp.exe"Added by the MYTOB.AQ WORM!"
XWINTASKiexplorer.exe"Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWINTASKtaskgmr32.exe"Added by the MYTOB.BU WORM!"
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWINTASKt4skmgr.exe"Added by the MYTOB-AK WORM!"
XWINTASKtaskfile.exe"Added by the MYTOB.EF WORM!"
XWINTASKtaskgm.exe"Added by the MYTOB-AO WORM!"
XWINTASKtaskgmrs.exe"Added by the MYTOB.DH WORM!"
XWINTASKyahooicons.exe"Added by the MYTOB-HM WORM!"
XWINTASKt4skgmr.exe"Added by the MYTOB.CM WORM!"
XWINTASK DLLjusched32.exe"Added by the MYTOB.AI WORM!"
XWINTASK DLL32smsrss.exe"Added by the MYTOB.BS WORM!"
XWINTASK DLL32updatewin"Added by the MYTOB.NI WORM!"
XWinTask driverwintask.exe"Added by the DLOADER-NA TROJAN!"
XWINTASK32taskgmr32.exe"Added by the MYTOB.BN WORM!"
XWINTASK32taskgmrr.exe"Added by the MYTOB.FX WORM!"
Xwintask32Jwintask.com"Added by the NAFBOT-A WORM!"
XWINTASKMANAGERtaskgmr.exe"Added by the MYTOB-AF WORM!"
XWINTASKMGRccsrs.exe"Added by the MYTOB.Q WORM!"
XWINTASKMGRsp2winfix.exe"Added by the MYTOB.KJ WORM!"
XWINTASKStaskgmr.exe"Added by the MYTOB.BO WORM!"
XWINTASKSwinxpro.exe"Added by the MYTOB.EZ WORM!"
XWinTasks DLL Library (32-bits)winkll.exe"Added by the RBOT-AJZ WORM!"
UWinTasks Traybarwintasks.exe"WinTasks - ""Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task
Xwintasks.exewintasks.exe"Added by the EVAMAN WORM!"
XWintbp.exewintbp.exe"Added by the ZOTOB.E WORM!"
XWintbpx.exewintbpx.exe"Added by the ZOTOB.F WORM!"
Uwintectivewintective.exe"Wintective logs keystrokes
XWintelUpdate[path to trojan]"Added by the SMALL-EKW TROJAN!"
Xwinterhappy.exe"Added by the SDBOT-YF WORM!"
NWintercooler ProWINCOOL.EXE"Wintercooler Pro - utility that monitors CPU usage
Xwinthelpwinthelp.exe"Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here"
NWinTidyWinTidy.exe"Desktop icon manager from
XWintimeWintime.exe"Added by the HARNIG TROJAN!"
UWinTimewintime.exe"WinTime - change desktop icons' color and font"
NWintime WtxploadWxpload.exe Wintime"Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
XWintlmsdred.exeIdentified as a variant of the Trojan-Spy.Win32.Agent.cch malware
Xwintnask32.exewintnask32.exe"Added by the RBOT-AFP WORM!"
Xwintnl.exewintnl.exe"Added by a variant of the ZOTOB.K WORM!"
Xwintnpx.exewintnpx.exe"Added by the ZOTOB.H WORM!"
XWinToolsWToolsA.exe"Wintools adware"
NWinTOTAL Schedulerguru.exeWinTOTAL Real estate appraisal software related
XWinTouchWinTouch.exe"Detected by Kaspersky as the AGENT.BUO TROJAN!"
XWinTraywintray.exe"Added by the LEGUARDIEN.B TROJAN!"
Xwintsk32dllwintsk32dll.exe"Added by the RBOT-AAJ WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.