Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XWINDOWS SECURITYwingrd.exe"Added by a variant of the RBOT WORM!"
XWindows Securitywin.pif"Added by the RBOT-APT WORM!"
XWindows Securityms32.pif"Added by the RBOT-ARN WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Assistantrundll32.vbe"CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!"
XWindows Security Assistantwinsec.exe"CoolWebSearch parasite variant"
XWindows Security Authority Servicelsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process
XWindows Security Center Notification Appwscnfty.exe"Added by a variant of the RBOT WORM!"
XWindows Security Center Notification Applssxe.exe"Added by the RBOT-GKX WORM!"
XWindows Security Center Notification Applsesxes.exe"Added by the RBOT-GLR WORM!"
XWindows Security Center Notification Applseos.exe"Added by a variant of the RBOT-GLR WORM!"
XWindows Security Center Notification Applseesysecurex.exe"Added by a variant of the RBOT-GKX WORM!"
XWindows Security Controlwuaucls.exe"Added by the FORBOT-V WORM!"
XWindows Security Managerwinsecurity.exe"Added by the AGOBOT-KI WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security Managersvchost.exe"Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows Security Modulemodule.exe"Added by a variant of the RBOT WORM!"
XWindows Security Policylsass32.exe"Added by the AGOBOT-CR WORM!"
XWindows Security Service[random file name]"Added by the RBOT-ALV WORM!"
XWindows Security Servicearrdt.exe"Added by a variant of the RBOT WORM!"
XWindows Security Servicewindows.pif"Added by the RBOT-AMG WORM!"
XWindows Security SuiteWI[random characters].exe"Windows Security Suite rogue security software - not recommended
XWindows Security Survysvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows Security Updatesecurity32.exe"Affilred adware"
XWindows Security Updatendsass.exe"Added by the RBOT.ESM BACKDOOR!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.