Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
Xafskfask8fsfjasj8.exe"Added by the ONLINEG-L TROJAN!"
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
Xcftmonsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!
Xcmrsfcmrsf.exe"Added by the DELF-HU TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
Xdaskaskfsak6dsfids6.exe"Added by the ONLINEG-J TROJAN!"
?DellTransferAgentTransferAgent.exe"Found on Dell computers. What does it do and is it required?"
XDfqwSfSffsqsd.exe"Added by the SDBOT-SH WORM!"
XdsfghjgjkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xdvsfssfbsfsdrs.exe"Added by the SDBOT-QA WORM!"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
NESFTPesftp.exe"ESftp - FTP client for transfering files between a local PC and another remote computer"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
Xfsdsft[path to backdoor]"Added by the RANKY.S BACKDOOR!"
UFTMSFLT(USB)FTMSFLTU.EXEFujitsu's Touch Panel Message Notifier
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
NHPStarthpstart.wsfThis a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
NImage TransferSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
Xitunesffitunesff.exe"Added by the EB adult premium dialer"
NKodak Batch Transferpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
NKodak Picture Easy *.* Batch TransferPezDownload.exe"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
NKodak Picture Transfer Softwarepts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
XMedia Transfer Protocalsmsstc.exe"Added by a variant of the IRCBOT TROJAN!"
XMi7sft sdceb0yz.exe"Added by the RBOT.CWG WORM!"
XMi7sft sdceMNSQ.exe"Added by the RBOT.DMU WORM!"
XMi7sft sdcescorti.exe"Added by the RBOT.ELC WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMicrosft Conf 32msaconf.exe"Added by the RBOT.EYA WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMICROSFT MX UPDATE SUPPORTtaskmngrs.exe"Added by the RBOT-AUZ WORM!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMICROSFT RAMA UPDATE SUPPORTMSN32.EXE"Added by the RBOT-AWJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTmtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTMSGUPDAT32.EXE"Added by the RBOT-BBB WORM!"
XMicrosft Remote Procedure Daemonmsrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processcmh.exe"Added by the EGGDROP.V WORM!"
XMicrosft Security Monitor Processmssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmpp.exe"Added by the SDBOT-DJW WORM!"
XMicrosft Updtessarvice.exe"Added by a variant of the SDBOT WORM!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosoft Decryption TechnologyMsfenoe.exe"Added by the SPYBOT-DG WORM!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft Netviewgesfm32.exe"Added by the RANDEX.C WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft Transfer File Servermtfs.exe"Added by the RBOT.AFE WORM!"
XMicrosoft Update Emulatorwuaddsff.exe"Added by the RBOT-GX WORM!"
XMicrsft Updesexagwxz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicsorosft Security Centerwcnsfty.exe"Added by the RBOT-AHU WORM!"
XMiosf Updatewimsqaad.exe"Added by the SDBOT.AG TROJAN!"
XMS ConfigurationMSFramer.exe"Added by the RANDEX.OL WORM!"
XMS FIREWALLmsfrewall.exe"Added by the SDBOT-PU WORM!"
XMS FIREWALLmsfirewall.exe"Added by the SDBOT-QH WORM!"
XMsfindMsfind.exe"CoolWebSearch parasite variant"
XMSFind32msfind32.exe"Added by the CAYAM WORM!"
Xmsfindosa.exemsfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
Xmsfw.exemsfw.exe"Microsoft Security Adviser rogue security software - not recommended"
XMSFWAVTSMFTPDev.exe"Added by the RBOT-ACF WORM!"
XMsServermsfun80.exe"Added by the VB-CYG WORM!"
XMsServermsfir80.exe"Added by the VB-CYJ TROJAN!"
Xmssfossfool.exe"Added by the RANDEX.EUS WORM!"
NMySoftware NewsFlashNewsflsh.exe"Runs in your task bar and receives alerts and release information on MySoftware products from Avenquest"
XNAV Auto Protectmsfwe1.exe"Added by a variant of the RBOT WORM!"
Xnetwork device drivermsfirewall.exe"Added by the DELF-LB TROJAN!"
XNI.UGESF_0001_N122M0201[path to file]"Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
XNTSF Microsoft Systemfylez.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwntsf.exe"Added by the RBOT.ATC WORM!"
XNTSF MICROSOFT SYSTEMfufffy.exe"Added by the RBOT-AEL WORM!"
XNTSF MICROSOFT SYSTEMntssf.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMmarya.exe"Added by the RBOT-AXY WORM!"
XNTSF MICROSOFT SYSTEMsysman.exe"Added by the RBOT.EDP WORM!"
XNvCpl28Deamonmdosft.exe"Added by the SPYBOT-AD WORM!"
XPCShieldregsvr32 sfg_****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
YPersFwPersFw.exe"Kerio or Tiny Personal Firewall"
UPopUpStopperFreeEditionPSFREE.EXE"Panicware's Pop-Up Stopper - free limited features version"
UPSFreePSFree.exe"Pop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
NQD FastAndSafeQDCSFS.exeAutomatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
XRegistryMonitorsysfade.exe"Added by the SYSFADE TROJAN!"
XSafeguard 2009sf2009.exe"Safeguard 2009 rogue spyware remover - not recommended
XSafeGuard Popup Blocker Updaterregsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Blocker Updater (required)regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XService PAck SFVP[worm filename].exe"Added by a variant of the RBOT WORM! The filename is 4 random characters"
Xsfsf.exe"SurfEnhance adware component"
NSFIGUISFIGUI.EXE"Sonic Focus - ""enhances music
Xsfitasfita.exe"Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware"
XSfKg6wrayiou.exe"Added by the AGENT.BUO WORM!"
XSfKg6wIP[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XSfKg6wIPu[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
NSFPvzSFPWin.EXEVerizon Online Support Center - prompts for online updates
Usfpcsfpc.exe"Spy4PC surveillance software. Uninstall this software unless you put it there yourself"
XSFtrb Servicecftrb32.exe"Added by the SOBIG.D WORM!"
USfWinStartInfosfWinStartupInfo.exeSFIRM32 Online Banking software
YSkyBlaster SchedulerSSFSch.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Xsmsf_exe.exe"Added by the OLFEB.A TROJAN!"
NSnappy Faxsf4.exe"Snappy Fax desktop fax program with an extensive set of features - version 4"
?Snappy Fax Printer Agentsfpagent.exe"Related to the Snappy Fax desktop fax program. What does it do and is it required?"
?Snappy Fax Printer virtual printer agentsfpagent.exe"Related to the Snappy Fax desktop fax program. What does it do and is it required?"
USoftGridTraySFTTray.exe"System Tray access to SoftGrid from Microsoft - ""the only virtualization solution that delivers applications that are never installed and dynamically delivered
NSonicFocusSFIGUI.EXE"Sonic Focus - ""enhances music
USPAMfighter AgentSFAgent.exe"SPAMfighter anti email spam filter"
Xstartisfmntr.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
USurfinGuard Prowinsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
Xsysfbtraybill102.exe"Added by the VB-ENI TROJAN!"
Xsysfbtraybill106.exe"Added by the MDROP-CLV TROJAN!"
Xsysfilersysfiler.exe"Added by the RETSAM TROJAN!"
XSYSfitSYSfit.exe"AdShooter adware variant"
Xsysflg32sysflg32.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xsysformatsysformat.exe"Added by the BAGLE-BK WORM!"
Xsysfrcxsysfrcx.exe"Added by the KEYLOG-SCLOG TROJAN!"
Xsysftray2bolivar19.exe"Added by the KOOBFACE.I WORM!"
XSYSsfitbSYSsfitb.exe"AdShooter adware"
XSystemXsfr.exe"Added by the CULLER-D WORM!"
XSystem Firewallsysfirewall.exe"Added by the AGOBOT-ACY WORM!"
XSystem Updates 4mssysfix.exe"Added by the RBOT-ADU WORM!"
YTiny Personal Firewallpersfw.exe"Tiny Personal Firewall"
UTivoTransferTivoTransfer.exe"Tivo Transfer Service. TiVo Desktop is an easy-to-use application that lets you publish and share digital music
XTrojansFilterpgs.exe"TrojansFilter rogue security software - not recommended. A member of the AVSystemCare family"
XTrojansFiltrepgs.exe"TrojansFiltre
XUSB Updatesmsfirewalls.exe"Added by a variant of the RBOT WORM!"
XUSBDrivesmsfirewalI.exe"Added by the RBOT-ABP WORM!"
XVirusForsvarpgs.exe"VirusForsvar
XWebSavingsfromEbatesWebSavingsfromEbatesrun.exe"Web Savings From Ebates Software
XWebSavingsFromEbates0WebSavingsFromEbates0.exe"Web Savings From Ebates Software
XWIN-BUGSFIXWIN-BUGSFIX.EXE"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
XWin32 FRT Drivermsfr32.exe"Added by the WOOTBOT.EJ WORM!"
XWinDLL (ProsFix.exe)ProsFix.exe"Added by a variant of the IRCBOT BACKDOOR! The ""ProsFix.exe"" file is found in %System%"
XWindows FirewallWindowsFirewall.exe"Added by the MYTOB.AO WORM!"
XWindows Firewall Managermsfw.exe"Added by the RBOT.WR WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindowsFileSystemwinsfs32.exe"Added by the RBOT-FMQ WORM!"
XWindowsFileSystemcidaemon32.exe"Added by the RBOT-FSP WORM!"
XWindowsFirewalllsass.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsFirewallSvcwinsvcup.exe"Added by a variant of the SDBOT WORM!"
XWINDOWSflashbrgsqldata1.exe"Added by a variant of the AGENT-IC TROJAN!"
XWindowsFSwinfs.exe"Added by the AGOBOT-BO WORM!"
XWindowsfwvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XWindowsfwwindowsfw.exe"Added by the AGOBOT-TA WORM!"
XWindowsFYwp.exe"Part of a ""Security IGuard"" parasite infestation - also detected as DESKTOPHIJACK"
XWindowsFYbsw.exe"Added by a variant of the DESKTOPHIJACK TROJAN! For removal see here"
XWindowsFY[path to trojan]"Added by the FAKEALE-E TROJAN!"
XWindowsFZ[path to file]"Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN!"
XWindowsFZA5281300.so"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindowsFZzloader3.exe"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
Xwinsfcwinsfc.exe"Added by the WISFC VIRUS!"
NWorksFUDwkfud.exeA marketing program for MS Works
Xxzkadsfk10afslkfasl10.exe"Added by the ONLINEG-R TROJAN!"
X[12 random characters]asferror.exe"IeDriver adware variant"
X[random][random]sftav.exe"Antivirus Soft rogue security software - not recommended
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}syssfzvakqg.exe"Added by the FAKEALERT-AM TROJAN!"
X{C2220120-1C24-4a79-BA7A-DDCBFC209DB3}sysfbdgv.exe"Added by the FAKEALERT-AM TROJAN!"
X{C599792D-C6D9-461d-93CA-B48BFF8E37B1}sysfdyev.exe"Added by the FAKEALERT-AM TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.