Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
XWindows servicewuamgrd.exe"Added by the RBOT-QW WORM!"
XWindows Servicedddd.exe"Detected by Kaspersky as Dialer.Salc
XWindows Serviceprvdi.exe"Malware - detected by Kaspersky as the SMALL.RD TROJAN!"
XWindows Servicevideo.exeAdded by an unidentified TROJAN!
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Serviceprivate-zone.exeAdded by an unidentified WORM or TROJAN!
XWindows Servicepd7.exe"Added by the SMALL.VZ TROJAN!"
XWindows Servicedstart4.exeAdded by an unidentified TROJAN!
XWindows Servicepd14.exe"Adware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!"
XWindows Servicevideo2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
XWindows Serviceservices.exe"Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Servicer.exe"Added by a variant of the SMALL.VZ TROJAN!"
XWindows Servicewindowz.exe"Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows serviceiexpl0rer.exe"Added by the SDBOT.RO WORM!"
XWindows Serviceservice.exe"Added by the IRCBOT-ACV WORM!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows Service Agccntjeqcfyo.exe"Added by the RBOT-GST WORM!"
XWindows Service Agccnt[random].exe"Added by the SDBOT-DHL WORM!"
XWindows Service Agccntrmizjgz.exe"Added by the SDBOT-SIM WORM!"
XWindows Service Agentczf.exe"Added by the RBOT-GAJ WORM!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service Agentagl23.exe"Added by the RBOT-GQU WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
XWindows Service Agentmsnmagr.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Service Agenttaskmgr32.exe"Added by the RBOT-GMN WORM!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWindows Service Agentwinup32.exe"Added by the RBOT-GQX WORM!"
XWindows Service Agentwinupds32.exe"Added by the RBOT-GQT WORM!"
XWindows Service Agentwit.exe"Added by the RBOT-GQV WORM!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Agentspoolvs.exe"Added by the RBOT-GXI WORM!"
XWindows Service Agentspools.exe"Added by the AGENT-GJF TROJAN!"
XWindows Service Agentmsngear.exe"Added by the RBOT.AHW BACKDOOR!"
XWindows Service Agentmsngerr.exe"Added by the RBOT.EOZ WORM!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agentcxfrru.exe"Added by the SDBOT.GAV WORM!"
XWindows Service Agentizszbayz.exe"Added by the KOLAB.TC WORM!"
XWindows Service Agentjnxrcyc.exe"Added by the RBOT.XAT BACKDOOR!"
XWindows Service Agentkafdprs.exe"Added by the IRCBOT.HDE BACKDOOR!"
XWindows Service Agentkrqbs.exe"Added by the IRCBRUTE.AZ TROJAN!"
XWindows Service Agentlcaqmsp.exe"Added by the RBOT.WFR BACKDOOR!"
XWindows Service Agentmsnmsgr.exe"Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Service Agentmxjunj.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentndibbeu.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentnimcoo.exe"Added by the RBOT.EWV WORM!"
XWindows Service Agentnod32.exe"Added by the RBOT.BNG BACKDOOR!"
XWindows Service Agentsjbsm.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentsjbsmgm.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agenttjybssd.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentumvcnm.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentuqgpq.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentvbsxkhk.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agentwge23.exe"Added by the RBOT.HHK BACKDOOR!"
XWindows Service AgentWindo.exe"Added by the RBOT.NQS WORM!"
XWindows Service Agentywgma.exe"Added by the RBOT.DZT BACKDOOR!"
XWindows Service Agentwinupd32.exe"Added by the SDBOT.SYM WORM!"
XWindows Service AgentWinTcpip.exe"Added by the SPYBOT.AP WORM!"
XWindows Service Agentidvcqv.exe"Added by the AGOBOT-AJB WORM!"
XWindows Service Agent 32mrthd.exe"Added by the AGENT-GAQ TROJAN!"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service Ajavjava128.exe"Added by the RBOT.BNG WORM!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service DCuhpnjcjl.exe"Added by the RBOT-GLY WORM!"
XWindows Service ExecServiceLayer.exe"Added by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
XWindows Service Findwrfkuk.exe"Added by the IRCBOT-XZ TROJAN!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Service HostingUSERINIT.exe"Added by the GOMMER-A WORM!"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows Service LoaderWindow.exe"Added by the RBOT-XO WORM!"
XWindows Service Managementsvcmngmt.exe"Added by the AGOBOT-NM WORM!"
XWindows Service Manageruserint32.exe"Added by the OSCABOT-C WORM!"
XWindows Service Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managermsgs.exe"Added by the OSCABOT-E WORM!"
XWindows Service Managermsnmrg.exe"Added by the OSCABOT-G WORM!"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcmgr32.exe"Added by the OSCABOT-D WORM!"
XWindows Service Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertaskmgr.exe"Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""fonts\svc"" sub-folder"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows Service Pack 2WindowsSP2.exe"Added by the SDBOT-TQ WORM!"
XWindows Service Pack Auto Updatewinworks.exe"Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updatefiggaz.exe"Detected by Kaspersky as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updateballin.exeAdded by an unidentified WORM or TROJAN!
XWindows Service Pack Auto Updatedel-me.exe"Adware
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Service Pack2WIN43.EXE"Added by the GAOBOT.G WORM!"
XWindows Service Supplywinsupply.exe"Added by the SLENFBOT.CZ WORM!"
XWindows Service Support CallSVSS32.EXE"Added by the RBOT-XQ WORM!"
XWindows Service SVsv32.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Threadssvcthreading.exe"Added by the SHEUR.AUM TROJAN!"
XWindows Service Threadssvcthreads.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service Updatelivecal.exe"Added by the SDBOT-DEY WORM!"
XWindows Service Updatecrsss.exe"Added by the SDBOT.CWX WORM!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWindows Service Utititywinsrvc.exe"Added by the RBOT-ASI WORM!"
XWindows Service XPXpFirewall.exe"Added by the MYTOB.AM WORM!"
XWindows Servicerxqobypik.exe"Added by the SDBOT-DFB WORM!"
XWindows Servicesservice.exe"Added by the RANDEX.R WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Servicesavsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesservicez.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32edus.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32service.exe"Added by the AUTORUN-FU WORM!"
XWindows Servicesw32services.exe"Added by the AUTORUN-FT WORM!"
XWindows Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinudp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Servicesservices.exe"Added by the AGENT-MVC TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Agantregs32.exe"Added by the SDBOT-DIK WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services Agentmsngears.exe"Added by the VB-EMS TROJAN!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows Services Certificationsvccert.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows Services Guidesvcguides.exe"Added by the SHEUR.YS BACKDOOR!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Services Ink Platform Tablet Input Subsystemwsiptis.exe"Added by the RBOT.APC WORM!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Jogersvcjoger.exe"Added by the RBOT.CAT WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Layerwinlogz2.exe"Added by the RBOT-FZE WORM!"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows Services M7ctfmon32.exe"Added by the AGENT.WOH TROJAN!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.