Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
XCLSRSSLSACS.EXE"Added by the SILLYFDC-X WORM!"
XDSAcass[path to file]"Added by the RANKY.M TROJAN!"
YElsaCapiCtlRcapi.exe"Assumed to stand for Remote Common Application Programming Interface (RCAPI)
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
UGiganews AcceleratorGiganewsAccelerator.exe"Giganews Accelerator from Giganews
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
XMicroft Exploererspoolsac.exe"Added by the RBOT-AMD WORM!"
XMicrosft Conf 32msaconf.exe"Added by the RBOT.EYA WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft UpdateIsac.exe"Added by the RBOT-AU WORM!"
XMicrosoft Updatelsac.exe"Added by the GAOBOT.XW WORM!"
XMSACMmsacm.exe"Added by the OPASERV-O WORM!"
XOnluna Sarvicesachost.exe"Added by the TOFGER-AA TROJAN!"
XOnlune Sarvicesachost.exe"Added by the DAEMONI-J TROJAN!"
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
Xsacsac.exe"180Search adware"
XSACCsacc.exe"SurfAccuracy adware"
NSAClientRegCon.exe"AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected
Xsacmemdssmcntlwio.exe"Added by the MAILBOT-BZ TROJAN!"
XServicesActivecssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
XSurfAccuracysacc.exe"SurfAccuracy adware"
YSynAsusAcpiSynAsusAcpi.exePart of the Synaptics touchpad driver for the Asus Eee PC range
XTransaction Taskerstdhost.exe"Added by the SDBOT.HNK BACKDOOR!"
NUMAX VistaAccessvsaccess.exeVistaAccess gives you quick and easy access to scanning functions right from your desktop
XWindowsACEbaracebarupdate.exe"BarACE adware"
XWSAConfigurationwmon32.exe"Added by the GAOBOT.BAJ WORM!"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationrpcxmn32.exe"Added by the AGOBOT.ABG WORM!"
XWSAConfigurationwin32upd.exe"Added by a variant of the RBOT WORM!"
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationwinlogon32.exe"Added by the AGOBOT-WC WORM!"
XWSAConfigurationntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfigurationwinmx32.exe"Added by the AGOBOT-JE WORM!"
XWSAConfigurationkernel32.exe"Added by the AGOBOT-KV WORM!"
XWSAConfigurationwinmon32.exe"Added by the AGOBOT.TM WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
XWSAConfigurationsyxtem32.exe"Added by the AGOBOT-MF BACKDOOR!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
XWSSAConfigurationwmmon32.exe"Added by the AGOBOT-KC WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.