Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
UButton Serverbttnserv.exe"Found on a Compaq PC
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
XDefense Centerdefcnt.exe"Defense Center rogue security software - not recommended
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
?Dixons Insert DetectInsDetect.exe"Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XDNSEDNSE.exe"Part of rogue security tools
?Duane Reade Insert DetectInsDetect.exe"Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
Xguarnsetguarnset.exe"Adlogix adware"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
?Jessops Insert DetectInsDetect.exe"Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XKernelCheckwinser.exe"Added by the TSPY_LMIR.SL TROJAN!"
NLicCrtlrunservice.exe"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running
XLicense Managerlicense_manager.exe"MediaPipe peer-to-peer file swapping program also reported as a hijacker"
Xloadwinwinset.exe"Added by the QQPASS-I TROJAN!"
NMacLicenseMacLic.exe"Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks"
XMalware Defensemdefense.exe"Malware Defense rogue security software - not recommended
YMcAfeeVirusScanServiceAvsynmgr.exe"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe)
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoft msnserumsnseru.exe"Added by the RBOT-APB WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoftMessengermsnserv.exe"Added by the DARKER.M WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Security Agentmsnsecure.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMsn Servmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMSN Service!msnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Servicermsnservicer.exe"Added by the SLENFBOT.PQ WORM!"
XMSN Servicesmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMSN Settingsmsnsettings.exe"Added by the IRCBOT.AWH BACKDOOR!"
XMSN Settings Managermsnsetmg.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN User Servermsnserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Server!msnservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Service!msnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSNServiceMSNService.exe"Added by the CARPET.C WORM!"
NNeroNETTrayIconNNServiceCtrl.exe"System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
XNetwork SecurityNSecurity.exe"Added by the IRCBOT.AAV WORM!"
XNorton Updaterwinset.exe"Added by a variant of the SPYBOT WORM!"
Xnsense.exe"Added by the AGOBOT-ML WORM!"
UNsengineNsengine.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
XPersonSecuritypsecurity.exe"Personal Security rogue security software - not recommended
UPNSetupPNSetup.exe"PopNot - pop-up killer"
NQuickenSEMessageQsemsg.exeQuicken option
YRaptor Mobilevpnservices.exe"Symantec VPN Client used to connect to corporate networks. If unchecked
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
XRunSearvicestread.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunservicesservices.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSaveDefenseSaveDefense.exe"SaveDefense rogue security software - not recommended
XServer Runtime Errorunsec.exe"Added by the SDBOT-DFA WORM!"
XService Monitormsnserve.exe"Added by the SPYBOT.YQW WORM!"
XService Processwinset.exe"Added by a variant of the SPYBOT WORM!"
YSunProtectionServerSunProtectionServer.exe"CounterSpy antispyware software"
YSunServerSunServer.exe"CounterSpy antispyware software"
?SynSetupSynTP.tmp RunOnce.exe"Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?"
USysSenseSysSense.exe"""SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray"". Google AdSense account required"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
?Tesco Insert DetectInsDetect.exe"Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XUserfile Sharing Serverusnserv.exe"Added by a variant of the IRCBOT TROJAN!"
UVerizonServicepoint.exeVerizonServicepoint.exe"Part of Verizon Online Support Manager"
XVirusResponseLab2009VirusResponseLab2009.exe"VirusResponse Lab 2009 rogue security software - not recommended
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
XWin Security 360WinSecurity360.exe"Win Security 360 rogue security software - not recommended
XWin Serverwinserv.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwinserver.exe"Added by a variant of the IMISERV TROJAN!"
Xwin32WinSetup.exe"Added by the EVILBOT.B TROJAN!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows IncontextInSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows Proffesional SecurityWinSecure32.exe"Added by the AGOBOT.VA WORM"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Namewinses.exe"Added by the RBOT-ADB WORM!"
XWindows Secure UpdateWinSecUp.exe"Added by the RBOT-GCD WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Security Assistantwinsec.exe"CoolWebSearch parasite variant"
XWindows Security Managerwinsecurity.exe"Added by the AGOBOT-KI WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows ServeAdWinServAd.exeWindupdates adware variant
XWindows Serverwinserv.exe"Added by the IRCBOT.AVM BACKDOOR!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows32 Serivceswinser32.exe"Added by the SPYBOT.AAF WORM!"
XWindowsUpdatewinsecwinsec.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWinSecwinsec16.exe"Added by the AGOBOT.ZF WORM!"
Xwinsecurewinsecure.exe"Browser hijacker
XWinSecure[random].exe"Added by the AGENT-LR TROJAN!"
XWinsecure AntivirusSecureantivirus.exe"Added by a variant of the SPYBOT WORM!"
XWinSecureAvpgs.exe"WinSecureAv rogue security software - not recommended
XWinSecured32ssmr.exe"Added by a variant of the FORBOT WORM!"
XWinSecurityuninstall.exe"Added by the SILLYFDC.BCJ WORM!"
XWinservWinserv.ila"Added by the NODMIN WORM!"
XwinserverServer.txt.vbs"Added by the DELTAD.A WORM!"
XWinservicewinmain.exeAdult content related malware
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
XWinServicehosth.exe"Added by the DWNLDR-FUX TROJAN!"
XWinServiceTtt.exe"Added by the MSNVB-D WORM!"
XWinServiceWinServ.exe"Added by the SKOWOR-O WORM!"
UWinService32ssmgr.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
XWinServicesWinServices.exe"Added by the YAHA.K or YAHA.M WORMS!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
Xwinservitcassl.exe"Added by the RBOT.ASG WORM!"
Xwinservnwinservn.exe"PurityScan adware"
Xwinservswinservs.exe"PurityScan adware"
XWinSetBrowseBasicUpdate.dll.vbs"Added by the BISCUIT.A WORM!"
XXNSearchAssistantSrchAsst.exeiWon Search Assistant - spyware
UXtreamLok License Managerxl.exe"License manager for xLok (XtreamLok) - prevents software being reverse engineered"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list