Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
XBatsecure2.bat"Added by the ZCREW.C TROJAN!"
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
XF-Secure Gatekeeper[malware name].exe"Added by the NUWAR.AXQ WORM!"
UF-Secure Management AgentFSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
YF-Secure ManagerFSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
YF-Secure TNBTNBUtil.exe"F-Secure antivirus"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
UGoTrustedGoTrusted Secure Tunnel.exe"""GoTrusted is the fast
XHF Securityhfsecure.exe"Added by the AGOBOT-TI WORM!"
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
XKvmSecure.exeKvmSecure.exe"KvmSecure rogue security software - not recommended
XMenaceSecurepgs.exe"MenaceSecure rogue security software - not recommended. A member of the AVSystemCare family"
XMicrosoft DLL Authentificationdllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Informationsecurenet.exe"Added by the SDBOT.AJM WORM!"
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SecureMessenger.NET Service"Added by the FORBOT-AM WORM!"
XMicrosoft Secure Messenger.NET Servicesecuritychk.exe"Added by the SDBOT.VT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Securetywurguar.exe"Added by the RBOT-KY WORM!"
XMicrosoftCorpsecurebind.exe"Added by the INJECT TROJAN!"
XMicrosoftNAPCsecurebind.exe"Added by the INJECT TROJAN!"
XMSN Security Agentmsnsecure.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMyPcSecureMyPcSecure.exe"MyPcSecure rogue security software - not recommended
XOffice Monitor Secure Systemaabsecure32.exe"Added by the RBOT.FPW WORM!"
XPcSecureNetPcSecureNet.exe"PcSecureNet rogue security software - not recommended
XPCSecureSystempgs.exe"PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
XPcsSecurePcsSecure.exe"PcsSecure rogue security software - not recommended
XProvan Securitypsecure.exe"Added by the RBOT.BRV WORM!"
Xrundll***die.exe [path] secure.bat"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] secure.exe"Added by the SUMTAX TROJAN! where *** is 134
Xsecure[random].exe"DealHelper adware"
Xsecuresvshost.exe"Added by the RBOT-AFO WORM!"
XSecure AntiVirus Proav.exe"Secure AntiVirus Pro rogue security software - not recommended
Xsecure socket layerwins32a.exe"Added by an IRCBOT TROJAN!"
XSecure Socket Layer Certificationsslcert.exe"Added by the VANEBOT-AN WORM!"
XSecure Systemintegitor.exe"Added by the AGOBOT.ACI WORM!"
XSecure32Shell32.com StartUp"Added by the BRONTOK-CJ WORM!"
XSecure64Regedit32.com StartUp"Added by the BRONTOK-CJ WORM!"
NSecureClean4RegManagerscregmanager4.exe"WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data
NSecureClean4Traysctray4.exe"WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data
XSecureCleanerSecureCleaner.exe"SecureCleaner spyware remover - not recommended
NSecureCleanIECleanSCIEClean.exe"SecureClean - scans your system for hidden temporary files
XSecureExpertCleanersec.exe"Secure Expert Cleaner rogue privacy program - not recommended
XSecureFighterSecureFighter.exe"SecureFighter rogue security software - not recommended
USecureItProSecureitpro470p.exe"SecureIt Pro - lock your computer when you're not there
XSecureKeeperSecureKeeper.exe"SecureKeeper rogue security software - not recommended
XSecureLoginMslg32.exe"Added by the REDZED WORM!"
USecureOnlineAccountNumbersSOAN.exe"Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions"
XSecurePcAvSecurePcAv.exe"SecurePcAv rogue security software - not recommended
XSecurePCCleanerGDC.exe"SecurePCCleaner rogue privacy tool - not recommended
USecurePCSolutionsBootCheckBootCheck.exe"1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
Xsecures23mssecure.exe"Added by the AGOBOT-ABY WORM!"
XSecureVeteranSecureVeteran.exe"SecureVeteran rogue security software - not recommended
XSecureWarriorSecureWarrior.exe"SecureWarrior rogue security software - not recommended
XSecurity Center Distributionsecuresec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSecurity Monitorsecuremon.exe"Added by the SLENFBOT.ABH WORM!"
XSecurity Systemsecuresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSmallAndSecuremssecure.exe"Added by the RBOT.CU WORM!"
XSpyware-SecureSpyware-Secure_trial.exe"Spyware-Secure rogue spyware remover - not recommended
XSymantec Secure Serversvrhost.exe"Added by the IRCBOT-UB TROJAN!"
XTotalSecure2009scan.exe"Total Secure 2009 rogue security software - not recommended
NWebSecureAlertWebSecureAlert.exe"WebSecureAlert - ""helps to protect your browser security by monitoring for unauthorized tampering with Internet Explorer's security settings
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Security Protocolsecure32.exe"Added by the RBOT-ETI WORM!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindows Proffesional SecurityWinSecure32.exe"Added by the AGOBOT.VA WORM"
XWindows securesetver32.exe"Added by the SPYBOT.EP WORM!"
XWindows Secure Connectionwinsc.exe"Added by the SDBOT.BTN WORM!"
XWindows Secure FixiPodFixer.exe"Added by the WOOTBOT.BM BACKDOOR!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Secure talal32[7 random letters].exe"Added by the RBOT.HTP TROJAN!"
XWindows Secure Updatewinupser.exe"Added by the RBOT-GCG WORM!"
XWindows Secure UpdateWinSecUp.exe"Added by the RBOT-GCD WORM!"
XWindows Secure Updateload.exe"Added by the FORBOT-GU WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Securetywurger.exe"Added by the AGOBOT-NC BACKDOOR!"
XWindows Security Center Notification Applseesysecurex.exe"Added by a variant of the RBOT-GKX WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
Xwinsecurewinsecure.exe"Browser hijacker
XWinSecure[random].exe"Added by the AGENT-LR TROJAN!"
XWinsecure AntivirusSecureantivirus.exe"Added by a variant of the SPYBOT WORM!"
XWinSecureAvpgs.exe"WinSecureAv rogue security software - not recommended
XWinSecured32ssmr.exe"Added by a variant of the FORBOT WORM!"
X[random characters]securewinload32x.exe"Added by the OPTIXP-N TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.