Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
XWindows Service Agentczf.exe"Added by the RBOT-GAJ WORM!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service Agentagl23.exe"Added by the RBOT-GQU WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
XWindows Service Agentmsnmagr.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Service Agenttaskmgr32.exe"Added by the RBOT-GMN WORM!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWindows Service Agentwinup32.exe"Added by the RBOT-GQX WORM!"
XWindows Service Agentwinupds32.exe"Added by the RBOT-GQT WORM!"
XWindows Service Agentwit.exe"Added by the RBOT-GQV WORM!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Agentspoolvs.exe"Added by the RBOT-GXI WORM!"
XWindows Service Agentspools.exe"Added by the AGENT-GJF TROJAN!"
XWindows Service Agentmsngear.exe"Added by the RBOT.AHW BACKDOOR!"
XWindows Service Agentmsngerr.exe"Added by the RBOT.EOZ WORM!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agentcxfrru.exe"Added by the SDBOT.GAV WORM!"
XWindows Service Agentizszbayz.exe"Added by the KOLAB.TC WORM!"
XWindows Service Agentjnxrcyc.exe"Added by the RBOT.XAT BACKDOOR!"
XWindows Service Agentkafdprs.exe"Added by the IRCBOT.HDE BACKDOOR!"
XWindows Service Agentkrqbs.exe"Added by the IRCBRUTE.AZ TROJAN!"
XWindows Service Agentlcaqmsp.exe"Added by the RBOT.WFR BACKDOOR!"
XWindows Service Agentmsnmsgr.exe"Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Service Agentmxjunj.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentndibbeu.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentnimcoo.exe"Added by the RBOT.EWV WORM!"
XWindows Service Agentnod32.exe"Added by the RBOT.BNG BACKDOOR!"
XWindows Service Agentsjbsm.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentsjbsmgm.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agenttjybssd.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentumvcnm.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentuqgpq.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentvbsxkhk.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agentwge23.exe"Added by the RBOT.HHK BACKDOOR!"
XWindows Service AgentWindo.exe"Added by the RBOT.NQS WORM!"
XWindows Service Agentywgma.exe"Added by the RBOT.DZT BACKDOOR!"
XWindows Service Agentwinupd32.exe"Added by the SDBOT.SYM WORM!"
XWindows Service AgentWinTcpip.exe"Added by the SPYBOT.AP WORM!"
XWindows Service Agentidvcqv.exe"Added by the AGOBOT-AJB WORM!"
XWindows Service Agent 32mrthd.exe"Added by the AGENT-GAQ TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.