Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xregedit.exe /s appboost.reg"Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
X0_AVD32xzboot.exe"Added by the AGENT-IWI TROJAN!"
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin Wireless G Notebook Card Client UtilityBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
Xbooboo.exe"Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN!"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
UBookmarkbookmark.exe"System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer
UBookmark.exebookmark.exe"System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer
NBookmarkCentralBMLauncher.exe"Bookmark Express - "offers a more flexible way to manage Web site bookmarks
NBookMarkSinksyncit.exeBookmark synchronization utility
NBookMarkSyncsyncit.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
NBookMarkSync2Itsync2it.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
UBoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xbootboot.exe"Added by the PUPPET-A TROJAN! Located in the %System%"
UBootBoot.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
XBoot Checkbootchk.exe"Added by the DELBOT-AB WORM!"
XBoot Clientbootcli.exe"Added by the IRCBOT-ACF BACKDOOR!"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XBoot Kbootk.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot ManagerNjgal.exe"Added by the KILO TROJAN!"
XBoot Managerbootmng.exe"Added by a variant of the SPYBOT WORM!"
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Verifybootvfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
XBootCTRLbootctrl.exeAdded by an unidentified WORM or TROJAN!
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
Xbootpd.exebootpd.exe"Added by the AGENT-DT TROJAN!"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
UBootStatusBOOTST~1.EXE"Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it
UBootWarnBootWarn.exe"From here: ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
?BTSETBOOTKEYBTSetBootKey.exe"Related to a USB Bluetooth adaptor. What does it do and is it required?"
UCacheBoosttrayicon.exe"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers
XccExecutebootcfg1.exe"Added by the NEMSI-B VIRUS!"
Xcfgboostcfgboot.exeAdded by an unidentified WORM or TROJAN!
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
Xdeejayforboo.exe"Added by the FORBOT-AY WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
XFontboot.exe"Added by the AGENT-LZW TROJAN!"
NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
UHPBootOpHPBootOp.exe"""HP Boot Optimizer intelligently and dynamically launches software during startup
?hpScannerFirstBootscannerfb.exe"HP scanner related"
UIECleanAuxIeboot6.exe"IEClean by Kevin McAleavy - cookie manager
XInternat Confbootconf.exe"Homepage hijacker
ULaunch Ai BoosterOverClk.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
XMasterBoot Switchpopupkill.exe"Added by a variant of the RBOT WORM!"
UMemoryBoostMemoryBoost.exe"MemoryBoost - memory optimizing program made by Tenebril Inc. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/ME. See this article and make up your own mind"
?mfgboot??"??"
XMicrosoft Bool ValueMV2.exe"Added by a variant of the RBOT WORM!"
XMicrosoft boot system cfg32actboost.exe"Added by the BROPIA.R WORM!"
NMicrosoft Office Fast CacheFastboot.exe"Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled"
XMicrosoft Patch Updatebootini.exe"Added by the RBOT-FMN WORM!"
XMicrosoft Security Panagerszzoboony.exe"Added by the RBOT-AOI WORM!"
XMicrosoft Service Bootsboot.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windowsbootini.exe"Added by the VANEBOT-K WORM!"
XMicrosoft WordBootSector.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
NMimBootmimboot.exe"Starts Musicmatch Jukebox at bootup - can be started manually"
UMoodBookmb.exe"MoodBook is a free Windows utility that brings art to your desktop"
XMS-DOS Boot ServiceBoot32.pif"Added by the RBOT-AMF WORM!"
XMsBootMgr.exeMsBootMgr.exe"Added by the VERIFY TROJAN!"
XMSN Boostermsnbooster.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Bootmsnbootcfg.exe"Added by the IRCBOT.BFU BACKDOOR!"
UMultiCAM InitializerMCamBoot.exe"The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled"
UNotebook Maximizermaximizer_startup.exeToshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency
UNotebookHardwareControlnhc.exe"""With Notebook Hardware Control you can easily control the hardware components of your Notebook"""
?NotebookManagernbm.exe"Associated with Acer notebook PCs. What does it do and is it required?"
?NWERebootdummy.exe"??"
XOS Boot Configurationbootconfig.exe"Added by the IRCBOT.HJ WORM!"
XOS Boot Configuration!bootconf.exe"CoolWebSearch BootConf adware"
XOS Boot Loadbootload.exe"Added by a variant of the IRCBOT TROJAN!"
UPando Media BoosterPMB.exe"Pando Media Booster from Pando Networks
UPC Boosterpcbooster.exe"PC Booster from inKline Global - ""easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition"""
UPcBoostPcBoost.exe"PCBoost from PGWARE
NPicabooPicabooMain.exe"Picaboo - ""Easily create stunning photo books and cards with your digital photos"""
XPostBootReminder[random filename]Added by and unidentified WORM or TROJAN!
UQuickBooks Database Server ManagerQBServerUtilityMgr.exe"Part of QuickBooks Pro/Premier from Intuit - ""QuickBooks Database Server Manager is a utility that allows you to configure the QuickBooks Server for multi-user access."" See here for further information"
NQuickBooks Delivery AgentQBDAGENT.EXEAs far QAGENT but for QuickBooks. Can also have the version number in the name
NQuickbooks Update Agentqbupdate.exeAssociated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
URadBootRadBoot.exeRadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings
XRamBooster2rb.exe"Added by the AKAK TROJAN!"
NRebootReboot.exeMS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
NRecoverFromRebooRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebooRecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
NRegistryBoosterRegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
?RIS2PostRebootLaunchRIS2.exe"Part of the programming software for LEGO® Mindstorms robotic building system. What does it do and is it required?"
XSBR2009FSystemBooster2009.exe"SystemBooster2009 rogue system suite - not recommended
XSecbootw32tm.exe"Added by the HAXDOOR.D TROJAN!"
Xsecbootmszx23.exe"Added by a variant of the HAXDOOR.BC TROJAN!"
Xsecbootvtd 16.exe"Added by the HAXDOOR-AE TROJAN!"
USecurePCSolutionsBootCheckBootCheck.exe"1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
XSysBootsyskernel.exe"Added by the AUTORUN-EY WORM!"
XsysPnPbootconf.exe"Homepage hijacker
XSystem Boot Checksysload3.exe"Added by the FUBALCA WORM!"
XSystem Boot Loadersysboot32.exe"Added by the SDBOT.PG WORM!"
XSystem Config Bootsyscgboot.exe"Added by the AGENT.VWU TROJAN!"
XSystem Rebootrebootsys.exe"Added by the RBOT-WU WORM!"
XSystemBooster2009sbr_updater.exe"SystemBooster2009 rogue system suite - not recommended
?SystemBootladies.htm"Unknown but sounds very suspicious??"
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
XSystembootmsnsngr.exe"Added by a variant of the RBOT WORM!"
NTypingSatelliteKBOOST.exe"Typing Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs"
NUniblue Registry BoosterRegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
NUniblue RegistryBooster 2RegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
NUniblue RegistryBooster 2009RegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
UUsbBoostTurboHddUsb.exe"LaCie USB Boost advanced driver for their range of USB hard disks which increases USB performance by up to 33%. Not required unless you use a supported external drive frequently"
XVITAL BOOT PROCESStaskmngr.exe"Added by a variant of the RBOT WORM!"
XVITAL BOOT PROCESStaskmnsgr.exe"Added by the Rbot-VY WORM!"
XVital Master-boot DLLcrsss.exe"Added by the RBOT.ASE WORM!"
YVrBootScanVRBScan.exe"Boot scan feature of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal
XWifi Bootwifiboot.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWifi Booterwifibooter.exe"Added by the IRCBOT.ATH BACKDOOR!"
Xwinbootwinboot.exe"Added by the BANLOAD-W TROJAN!"
XWindows Bootwinboot.exe"Added by the AGENT.HBD TROJAN!"
XWindows Bootwindowsboot.exe"Added by the IRCBOT.AZT BACKDOOR!"
XWindows Booterwinboot.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Booter!winbooter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Bootupms-wks32.exe"Added by the RBOT-AFM WORM!"
XWindows BootupSystemwks32.exe"Added by a variant of the RBOT WORM!"
XWindows Bootuptask-mngr.exe"Added by the RBOT-AWP WORM!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows Host Booterhostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Update Managerbootwiz.exeAdded by the MYBOT WORM!
XWindowsBoolaimplg.exe"Added by the SDBOT-CNG WORM!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
XWin_BooT[path to file]"Added by the BANKER-GI TROJAN!"
YWireless-G Notebook AdapterGcc.exeLinkSys Wireless-G Notebook Adapter driver
UWireless-G Notebook Adapter UtilityWPC54CFG.EXE"Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)"
NWMBootN/A"Associated with Logitech Wingman game controllers. Not required but what does it do?"
NWMC_RebootCheckunregmp2.exe"Corrects problems with installations of Windows Media Player from version 9 onwards - see here and search for ""unregmp2.exe"""
Uxbtlbootldr.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
?zzz-hpi-boothpi-boot.exe"Associated with HP Photosmart printers"
X[12 random characters]bootvid4.exe"IeDriver adware variant"
X[12 random characters]bootvid2.exe"IeDriver adware variant"
X[random name]w?auboot.exe"PurityScan adware"
X[random name]wuauboot.exe"PurityScan adware. Note - do not confuse with the legitimate wuauboot.exe process which should not figure in Msconfig/Startup!"
X_SystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.