Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XWin Serverwinserv.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwinserver.exe"Added by a variant of the IMISERV TROJAN!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows ServeAdWinServAd.exeWindupdates adware variant
XWindows Serverwinserv.exe"Added by the IRCBOT.AVM BACKDOOR!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
XWinservWinserv.ila"Added by the NODMIN WORM!"
XwinserverServer.txt.vbs"Added by the DELTAD.A WORM!"
XWinservicewinmain.exeAdult content related malware
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
XWinServicehosth.exe"Added by the DWNLDR-FUX TROJAN!"
XWinServiceTtt.exe"Added by the MSNVB-D WORM!"
XWinServiceWinServ.exe"Added by the SKOWOR-O WORM!"
UWinService32ssmgr.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
XWinServicesWinServices.exe"Added by the YAHA.K or YAHA.M WORMS!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
Xwinservitcassl.exe"Added by the RBOT.ASG WORM!"
Xwinservnwinservn.exe"PurityScan adware"
Xwinservswinservs.exe"PurityScan adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.