Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
Xloadwinwinsys.exe"Added by the QQPASS-J TROJAN!"
ULogMeIn GUILogMeInSystray.exe"RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft System Monitormonsys.exe"Added by the IRCBOT-YV TROJAN!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
Nmsnsyslogmsnappm.exe"Related to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying"
XMSNSysRestorepc32.exeAdded by a variant of the MASTAK VIRUS!
Unsysnsys.exe"NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xnsys32nsys32.exe"Added by the AGOBOT-SU WORM!"
NNSystemMonitorSymmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
UPrnSys ExecutablePrnSys.exe"Print screen utility bundled with some HP printer software - not required
XRemote Procedure Callwinsysrpc.exe"Added by the SDBOT-PS WORM!"
Xrunwinsys32.exe"Added by the DELF.CP BACKDOOR!"
URunSysd32RunSysd32.exeDesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
UScanSys32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
Xssate.exewinsys.exe"Added by the BEAGLE.K WORM!"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
Xsystemdll.dllwinsys32.exe"Added by the DELF.CP BACKDOOR!"
Xthis freewinsyst.exe"Added by the MADAG.A WORM!"
Xtransys"rundll32.exe transys.dllstart"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XVirusScannermnsys.exe"Added by the SDBOT-AFQ WORM!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networkingwinsys32.exe"Added by the GAOBOT.FL WORM!"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows StartupWinsys32.exe"Added by the RBOT.AAB WORM!"
XWindows SystemWINSYS.exe"Added by the RBOT-AEF WORM!"
XWINDOWS SYSTEMwinsys33.exe"Added by the MYTOB.EK WORM!"
XWindows Systemwinsys32.exe"Added by the MYTOB-IS WORM!"
XWindows System 32winsys_32.exe"Added by the RBOT-FTR WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System Managerwinsystem.exe"Added by the RBOT-AN WORM!"
XWindows System Managerwinsysmgr.exe"Added by the IRCBOT.BJG BACKDOOR!"
XWindows System32winsys32.exe"Added by the SDBOT-AHS WORM!"
XWindowsRegKey updatewinsys.exe"Added by the RBOT-JY WORM!"
XWindowsRegKeys updatewinsysi.exe"Added by the SDBOT.WE WORM!"
XWindows_Protectwinsystem.exe"Added by a variant of the RBOT WORM!"
Xwindtbswinsysvc"Added by the AGOBOT-NH WORM!"
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
UWinsysWinsys.exe"Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself"
XWINSYS[path to trojan]"Added by the GOLDPLAY TROJAN!"
Xwinsyssyschost.exeAdded by an unidentified TROJAN!
XWinSyswinmgmt.com"Added by the VB.EIW WORM!"
XWinSyssystem.exe"Added by the DAPROSY WORM!"
XWinSys32Winsys32.exe"Added by the CIGIVIP TROJAN or RECKUS WORM!"
Xwinsys32 Driverwinsys32.exe"Added by the LOONY-O TROJAN!"
UWinSysAppMonWinSysRM.exe"Home & Family Content Filter related. See here"
Xwinsysban[path to trojan]"Added by the CLICKER-CD TROJAN!"
UWinSysChecksb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinSysM371662M.exe"Added by the WINKO.AO WORM!"
XWinSysModule[path to trojan]"Added by the AGENT-DIQ TROJAN!"
XWinSysStartUpWKbLwTaskSystemDll.Exe"Added by the BACKZAT.G WORM!"
XWinSyst32winsyst32.exe"Added by the MORB WORM!"
XWinSystemwinsystem.exe"Added by the WHITEBAIT WORM!"
UWinSystemWinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinsystemFreevideo5.EXE"Added by the AGENT.FZS WORM!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
Xwinsystems25winsystems.exe"Added by the RBOT-CNZ WORM!"
Xwinsysupd[path to trojan]"Added by the STARTPA-NI TROJAN!"
XWinSysW371662L.exe"Added by the WINKO.AO WORM!"
XWLWinWINSYS.EXE"Added by the NAVER.A WORM!"
XZonesoft Cleanerrnsys.exe"Added by a variant of the SDBOT WORM!"
X[various names]NSYSCPLSTR.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]scanSYS.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.