Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
XDefaultConfigurationdefaultconfh.exe"Added by the AGOBOT-JC WORM!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Configuration 35microsot1.exe"Added by an unidentified TROJAN!"
XMicrosoft Configuration Wizardtaskmrg.exe"Added by the SDBOT-MX TROJAN!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMS ConfigurationMSFramer.exe"Added by the RANDEX.OL WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMSI Configurationmsiconf.exe"Added by the AGENT.AKSZ TROJAN!"
XMSN Configurationmsnconfig.exe"Added by a variant of the IRCBOT TROJAN!"
XMsn Configuration Loadermsngms.exe"Added by the KELVIR.T WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
NNAV Configuration Wizardcfgwiz.exe"Introduced with Norton Anti-Virus 2002
XOS Boot Configurationbootconfig.exe"Added by the IRCBOT.HJ WORM!"
XOS Boot Configuration!bootconf.exe"CoolWebSearch BootConf adware"
XSPOOL Configurationspoolsvc.exe"Added by the SDBOT-KD WORM!"
XStartup Configuration[six character filename]"Added by the RBOT-ARV WORM!"
XStartup Configurationwztoid.exe"Added by the RBOT-ASD WORM!"
XSymantec Configuration LoaderccApp32.exe"Added by the AGOBOT-EE WORM!"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Configurationsyscfg32.exe"Added by the MYTOB.EA WORM!"
NThinkPad Configuration UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
UU.S.Robotics WLAN Adapter Configuration UtilityUSRWLAN.exe"U.S.Robotics LAN Adapter - wireless LAN (WLAN) configuration utility"
XVolume Shadow Configurationvbmsvc.exe"Added by the SLENFBOT.DH WORM!"
XWifi Configurationwificonfig.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWifi Configuration!wificonfigs.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWin32 Configurationvideosd32.exe"Added by the SDBOT.TT WORM!"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 Configurationmplayer.exe"Added by the FORBOT-BZ WORM!"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows ConfigurationWINHUB.EXE"Added by the SPYBOT-CG WORM!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System ConfigurationWinfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
XWinDriver Configurationwindrvconf.exe"Added by the AGOBOT-LX TROJAN!"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
UWireless PCI Card Configuration UtilityWMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XWSAConfigurationwmon32.exe"Added by the GAOBOT.BAJ WORM!"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationrpcxmn32.exe"Added by the AGOBOT.ABG WORM!"
XWSAConfigurationwin32upd.exe"Added by a variant of the RBOT WORM!"
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationwinlogon32.exe"Added by the AGOBOT-WC WORM!"
XWSAConfigurationntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfigurationwinmx32.exe"Added by the AGOBOT-JE WORM!"
XWSAConfigurationkernel32.exe"Added by the AGOBOT-KV WORM!"
XWSAConfigurationwinmon32.exe"Added by the AGOBOT.TM WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
XWSAConfigurationsyxtem32.exe"Added by the AGOBOT-MF BACKDOOR!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
XWSConfigurationspoolsc.exe"Added by the AGOBOT-HY WORM!"
UWSEP Status+ConfigurationcontroldGUI.exe"User interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from Watchguard"
XWSSAConfigurationwmmon32.exe"Added by the AGOBOT-KC WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.