Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X27msm32.exe"Added by the SLSORVE-E TROJAN!"
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
Xb99msmm.exe"ClientMan parasite variant"
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
NCOMSMDEXEcomsmd.exe3Com tray icon
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
Xltwobmsmbw.exe"Added by the SERFLOG.A WORM!"
Xmackfy.exemsms.exe"Added by the SDBOT-DID WORM!"
XMessage Queuingmsmqs.exe"Added by the FREEFORS TROJAN!"
NMessengermsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMessenger Gatewaymsmgs.exe"Added by the AGENT-IGK TROJAN!"
XMessenger Servicemsmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoftmsmsger.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Excelemsmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Managermsmanager.exe"Added by the MYTOB.LF WORM!"
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft Msn Messengermsmsgs.exe"Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft OfficeMSMSGR.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Officemsmsgr.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Ofticemsmsgs.exe"Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
XMS Unix Binarymsmq2inst.exe"Added by the RBOT-YF WORM!"
Xmsmmsm.scr"Added by the BANKER-EHJ TROJAN!"
Xmsmacro32msmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!
Xmsmacro32msmacro64.exe"Added by a variant of the BACKDOOR-DOQ TROJAN!"
XMsManagermsmgr32.exe"Added by the YAHA.AF WORM!"
Xmsmanager32msmngr32.exe"Added by the RANDON-R (or WOMANIZ.A) WORM!"
Xmsmautoprotectmsmssgs.exe"Added by the BIFROSE-AJ TROJAN!"
Xmsmcmscpbo.exe"ClientMan parasite variant"
Xmsmcmsgdmf.exe"ClientMan parasite variant"
Xmsmcmsongn.exe"ClientMan parasite variant"
Xmsmcmsmc.exe"ClientMan parasite variant"
Xmsmcms****.exe [* = random char]"ClientMan parasite variant"
XMSMcAfeeeAvsynmgr32e.exe"Added by the FRAMAR TROJAN!"
XMSMcAfeehAvsynmgr32h.exe"Added by the FRANGO TROJAN!"
XMSMcAfeeSAvsynmgr32S.exe"Added by the VOLAC or VOLAC.DR TROJANS!"
XMSMessngermsnupd.exe"Added by the RBOT-ADY WORM!"
?msmgrmsmgr.exe"??"
XmsMGRrtkmsg.exe"Added by the SDBOT-BPY WORM!"
XMsmgtmsmgt.exe"Total Velocity adware/hijacker"
Xmsmmimsmmi.exe"Added by the AGENT.RFR TROJAN!"
XMSMNTGNTMSMNTGNT.EXE"Added by the BANKER-IE TROJAN!"
XMSMNTJBEMSMNTJBE.EXE"Added by the BANCOS-EF TROJAN!"
XMSMNTJNGMSMNTJNG.EXE"Added by the GRABER-G TROJAN!"
XMSMNTMTSMSMNTMTS.EXE"Added by the BANKER-GZ TROJAN!"
Xmsmonmsmon.exe"Added by a variant of the GEMA.D TROJAN!"
XMsMon32MsMon32b.exe"Added by the SDBOT.O BACKDOOR!"
XMsMoviesMsMovies.exe"Added by the ALCRA-E WORM!"
?MsmqIntCertregsvr32 /s mqrt.dll"Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?"
XMSMSGNER[4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"
XMSMSGNERzzgf.exe"Added by the PWS-CCB TROJAN!"
XMSMSGNERfgozmox.exe"Added by the AGENT-EBJ BACKDOOR!"
Xmsmsgrmsmsgss.exe"Detected by Kaspersky as the RBOT.AJJ WORM!"
NMSMSGSmsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMsmsgsMsmsgs.exe"Added by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMsgsmsmessgs.exe"Added by the SMALL-EW TROJAN!"
Xmsmsgsmsmsgs.exe"Added by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMsMsgSrvmsmsgsrv.exe"Added by the CQO TROJAN!"
Xmsmsgss[path to trojan]"Added by the RANKY.G BACKDOOR!"
XMSMsgSvcMSMSGSVC.exe"Browser hijacker
Xmsmsngrmsmsngr.exe"Added by the DOPBOT-B WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN MESSENGERmsmmsgr.exe"Added by the KELVIR.Q WORM!"
XMSN Messengermsmsgs.exe"Added by the ZLOB TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSN Messenger User Controlsmsmsgr.exe"Added by the KELVIR.HI WORM!"
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMsn Update Manager (Sp2)MSMSGS.EXE"Added by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
Xmssoulmsmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
Xmssoulmsmscc.exe"Added by the BANCOS.HKT TROJAN!"
Xmssyslanhelpermsmsgri32.exe"Added by the RANDEX.D WORM!"
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
Xnotepad.exemsmsgs.exe"Added by the ZLOB TROJAN and variants! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XNvCplDaemonmsmsgrs.exe"Added by the DLOADER-YI TROJAN!"
XRegSvr32msmsgs.exe"Added by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
Xrollbkmsmpatch.exe"Added by the SERFLOG.B WORM!"
?Roxio EngineMSMNGR32.EXE"Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!"
XSchedulerMSMSGS.EXE"Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XSecurity Accounts Manager SMsamsm.exe"Added by the SPYBOT.JE WORM!"
Xserpemsmbw.exe"Added by the SERFLOG.A WORM!"
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
Xsmsmsmsm.exe"Added by the BANKER-CO TROJAN!"
XSystem Initializationmsmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows32 Messenger Servicemsmsgv.exe"Added by the RBOT.ANS WORM!"
XWINTASKmsmgrxp.exe"Added by the MYTOB.AQ WORM!"
XYhooUpdatesymsmsgs.exe"Added by the SMALL_K TROJAN!"
X_Cat3msmsgrxp.exe"Added by a variant of the SMALL-DT downloader TROJAN"
X_Cat4msmsgr2.exe"Added by the SMALL-EB TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.