Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
XCheckdiskmscas.exe"Added by the VAGON-A TROJAN!"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
XClientMan1mscman.exe"ClientMan parasite variant"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
UImScInstImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UImScInst.exeImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
XMemScannerMemScanner.exe"Part of Enigma SpyHunter - not recommended
XMicrosoft Clientmsclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Cvrtmscvrt32.exe"Added by an unidentified VIRUS
XMicrosoft Device Managermscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
XMicrosoft Digital Clockmsclock.exe"Added by the NACKBOT-D WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicroSoftRunMSCOMM.dll"Added by the AGENT-DJG TROJAN!"
UMPSExemscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMs configsumsconfigsu.exe"Added by a variant of the SDBOT WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMS Updatesmscache.exeSpyware web downloader
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
Xmscmsc.exe"MaCatte Antivirus 2009 rogue security software - not recommended
Xmsccrtmsccrt.exe"Added by the PWS-ALA TROJAN!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
Xmschkdf.exemschkdf.exe"Added by a variant of the SDBOT WORM!"
XMSChoExEsuge.exe"Added by a variant of the RBOT WORM!"
?mscimcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
Xmsclacmsclac.exe"Added by the SDBOT-JM WORM!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmscmanmscman.exe"ClientMan parasite variant"
Xmscmsmscms.exe"Added by the AGENT-MS TROJAN!"
Umscnmscn.exePart of the SafeChildNet internet filtering program - required if you use it
XMscntmscnt.exe"Added by the DLUCA-C TROJAN!"
XMscolourmscolour.exe"Added by the GEMA TROJAN!"
XMSCommXmscommx.exe"Added by a variant of the RBOT WORM!"
XMsconf32Msconf32.exe"Added by the AGOBOT-NR WORM!"
XMSCONFG32.EXEMSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfigmsconfig.com"Added by the IRCBOT-SM WORM!"
Xmsconfigmsconfig.bat"Added by the PAHATIA.B WORM!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSConfigxwpwqf.exe"Added by the AGENT-NEW TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig.msconf.exe"Added by the BUZUS-AY WORM!"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfig45MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exe"Added by the ALCAN.A WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmsconfiguratorctfsdk.exe"Added by the DELF-ALS TROJAN!"
XMSControl28crsss.exe"Added by the SPYBOT.AJX WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
XMSCOREsyscnfg.exe"Added by an unidentified VIRUS
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
XMscsgsMSCSGS.EXE"Added by the ZEZER WORM!"
XMscsgs32MSCSGS32.EXE"Added by the ZEZER WORM!"
Xmscsvc.exemscsvc.exe"Added by the BANCOS.T TROJAN!"
Xmsctfg32msctfg32.exe"Added by the RBOT-TJ WORM!"
Xmsctrl.exemsctrl.exe"Microsoft Security Adviser rogue security software - not recommended"
XMsctrl32Msctrl32.scr"Added by the REDIST WORM!"
XMSCVTMSCVT.exe"Added by the SLIDESHOW WORM!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsmcmscpbo.exe"ClientMan parasite variant"
XMSN Managermscmgr.exeUnidentified malware - causes multiple browser windows to open
XMSN Updatemscon.exe"Added by the RBOT-QA WORM!"
Xmsnmsg.exemscmd32.exeAdded by a variant of the AGENT.AH TROJAN!
UMSPY2002ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
Xmssoulmsmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
Xmssoulmsmscc.exe"Added by the BANCOS.HKT TROJAN!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
XNvCplScanmsc32.exe"Added by the FORBOT-DD WORM!"
Xscanmscman.exe"ClientMan parasite variant"
XShellsmsc.exe"Added by the BANCBAN-OY TROJAN!"
XSonic RecordNow!smsc.exe"Added by a variant of the SDBOT WORM!"
XSysctrlsmscntrl.exe"Added by the KOLABC.BB WORM!"
XSystem Efficiency Monitormscedit32.exe"Added by the SDBOT.P TROJAN!"
XSystem Efficiency Monitormscommand.exe"Added by the KWBOT.P WORM!"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem MScvbmscvb32.exe"Added by the SOBIG.C WORM!"
XSystem Traymsccn32.exe"Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process"
Xsystemscrootsystembin.exe"Added by a variant of the RBOT WORM!"
Xvcmicrecmsccsed.exe"Added by the MAILBOT-CE TROJAN!"
XVideo Processormsconfsys88.exe"Added by the AGOBOT-QG WORM!"
?VirusScanMSCVsStat.exe"Part of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe)
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows Schedulerwmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWINDOWS SYSTEM mscdvvsmscdvvs.exe"Added by the MYTOB.MD WORM!"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
XWSSVCsmsc.exe"Added by the AUTORUN-AGA WORM!"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
X[random characters]rsbmsc.exe"Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.