Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XAhorreMemoriaSysRep.exe"AhorreMemoria rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
XBeschermingsToolSysRep.exe"BeschermingsTool
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
XBugsDestroyerSysRep.exe"BugsDestroyer rogue system error and cleaning utility - not recommended
XCleanPCToolSysRep.exe"CleanPCTool rogue system error and cleaning utility - not recommended
XCleanupToolSysRep.exe"CleanupTool rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XDiskRetterSysRep.exe"DiskRetter
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDokterFixSysRep.exe"DokterFix
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
XErrCleanSysRep.exe"ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
XErreurChasseurSysRep.exe"ErreurChasseur
XFestPlattenCleanerSysRep.exe"FestPlattenCleaner
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
XHataDuzelticisiSysRep.exe"HataDuzelticisi
XIsassRenascimentoIssas.exe"Added by the BANKER.GAX TROJAN!"
NIsReminderISPopup.exe"Related to GuardWare iShield - this is the registration reminder for the trial version
XLibreSystemSysRep.exe"LibreSystem
XMicrosoft Keyboard Enhance 2.0.iasrecst.exe"Added by the BCKDR-QIL BACKDOOR!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMS SyS Restoresysrestore.exe"Added by the RBOT.XM WORM!"
XMSNSysRestorepc32.exeAdded by a variant of the MASTAK VIRUS!
Xmsreg.exemsrege.exe"Added by the ZINX TROJAN!"
XmsReg32 Loadermsreg32.exe"Added by the AGOBOT.IU WORM!"
XMSREGITMsgp.exe"Added by the KRYPGHOS.13 TROJAN!"
UMSRegScanSGP.exe"SpyGator surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSSDemo.exe"SupremeSpy surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanETNKL.exe"ComKeylogger surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanKSPDemo.exe"KeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanDDSSDemo.exe"SystemSleuth surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESP+.exe"ESP surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESPDemo.exe"Eye Spy Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSBPDemo.exe"SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYEKPND.exe"EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYKPND.exe"YKPMD surveillance software. Uninstall this software unless you put it there yourself"
XMSRegSvcregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
Xmsresear[path to trojan]"Added by the WEASYW-B TROJAN!"
Xmsresearchmsresearch.exe"TROJAN! - 180SearchAssistant adware related"
Xmsresearchtool3.exe"Spy Sheriff/SpywareNO malware
Xmsservlvsrev.exe"Added by the BROWMON-B TROJAN!"
XNod32 Runtimesysregi.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XOEM32 Toolssres32.exe"Added by the RBOT.AML BACKDOOR!"
XPCToolProSysRep.exe"PCToolPro rogue system error and cleaning utility - not recommended
UPhilipsRemotePhilipsRemote.exe"Remote control support for MusicMatch Jukebox on Philips audio players such as the AZ2555 Sound Machine - see
XProtectingToolSysRep.exe"ProtectingTool rogue system error and cleaning utility - not recommended
XProtejaseuDriveSysRep.exe"ProtejaseuDrive rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XProtezioneSoftSysRep.exe"ProtezioneSoft
XRecycleSTRmsreg32.exe"Added by the RBOT-TC WORM!"
XRemndrCsRemnd.exeCasinoOnline foistware
XReparateurDeSystemeSysRep.exe"ReparateurDeSysteme
URssReaderRssReader.exe"RssReader - a free RSS reader able to display any RSS and Atom news feed (XML)"
XSafeHardDriveSysRep.exe"SafeHardDrive rogue system error and cleaning utility - not recommended
XSafePCToolSysRep.exe"SafePCTool rogue system error and cleaning utility - not recommended
XSchijfBewakerSysRep.exe"SchijfBewaker
XSicherheitsToolSysRep.exe"SicherheitsTool
XSolutionRegSysRep.exe"SolutionReg rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xsre"rundll32.exe sre.dll Register"
?srePostpone"rundll32.exe [path] srescan.dll DoSpecialAction"
XStorageProtectorSysRep.exe"StorageProtector rogue system error and cleaning utility - not recommended
XSvcsys Registry Managersvcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
XsyelimS-esreveR-troppuS[filename]"Added by the LITBOT.C TROJAN!"
XSys RenSysRen.exe"Part of FlashEnhancer adware"
XSysDepannageSysRep.exe"SysDepannage
XSysRegSysReg.exe"Added by the CHEKIN TROJAN!"
XSysRegSysReg.exe"SearchSeekFind textual marketing foistware"
XSysresSysres.exe"Added by the LOGMOD.A TROJAN!"
XSysResTASKMANAGER.exe"Added by the ELIPTER.A or ELIPTER.B WORMS!"
XSysResWWE DIVAS.exe"Added by the ELIPTER.D WORM!"
XSysResIExpIore .exe"Added by the ELITPER.E WORM!"
Xsysrest32.exesysrest32.exe"Added by the AGENT-GIN TROJAN!"
Xsysrestore32.exesysrestore32.exe"Unknown malware detected by McAfee - see here"
XSysSearchRegedit.exe -s sysreg.reg"Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""sysreg.reg"" file is located in %Windir%"
XSystem ServiceMSREXE.EXE"Added by the AML TROJAN!"
XSystemErrorFixerSysRep.exe"SystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XSystemOrdnareSysRep.exe"SystemOrdnare
XtoolsicuroSysRep.exe"ToolSicuro
XUtilisateurSurSysRep.exe"UtilisateurSur
XVideo DriverMsregdrv32.exe"Added by the SPIGOT BACKDOOR!"
XVirus Remover Profesionalvirusremover.exe"Virus Remover Profesional rogue security software - not recommended
XVirusRemover2008VRM2008.exe"VirusRemover2008 rogue security software - not recommended
XVirusRemover2009VRM2009.exe"VirusRemover2009 rogue security software - not recommended
XVirusRescueVirusRescue.exe"VirusRescue rogue security software - not recommended"
XVirusResponseLab2009VirusResponseLab2009.exe"VirusResponse Lab 2009 rogue security software - not recommended
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows System Driverssysretain.exe"Added by the SLENFBOT.BY WORM!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey upd4te2d4te*********.exe [* = random char]"Added by the RBOT.XQ WORM!"
XWindowsRegKey updatewinupdate.exe"Added by the RBOT-QJ WORM!"
XWindowsRegKey updatewindns.exe"Added by the RBOT.IE WORM!"
XWindowsRegKey updatewinupdatexx.exe"Added by the RBOT.LW WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsRegKey updatesvchostc.exe"Added by the RBOT.IF WORM!"
XWindowsRegKey updatewdnupdate.exe"Added by the SDBOT.QX WORM!"
XWindowsRegKey updateWindowsup.exe"Added by the SDBOT.PU WORM!"
XWindowsRegKey updateWINUPDATES.EXE"Added by the RBOT-MM WORM!"
XWindowsRegKey updaterkbuouoxfl.exe"Added by the RBOT-OO WORM!"
XWindowsRegKey updatewinsys.exe"Added by the RBOT-JY WORM!"
XWindowsRegKey updatewinupdat32.exe"Added by the RBOT-AGW WORM!"
XWindowsRegKey update XPwindexv1.exe"Added by the RBOT-ABM WORM!"
XWindowsRegKey%$ updatemsi332.exe"Added by the RBOT-IX WORM!"
XWindowsRegKey%updateethernet32m.exe"Added by the RBOT-EN WORM!"
XWindowsRegKeys updatewinsysi.exe"Added by the SDBOT.WE WORM!"
Xwinlogonmsreg32.exe"Added by the SDBOT.EO WORM!"
XWinPCDoctorSysRep.exe"WinPCDoctor rogue system error and cleaning utility - not recommended
XWinsock2 driversysreq.exe"Added by the SPYBOT-CC WORM!"
XWinSP[path] REGEDIT.EXE -s [path] sysreg.reg"Added by the STARTPA-ME TROJAN!"
X{**-**-**-**-**}mrdsregp.exe"Zenosearch adware
X{1C-CC-C5-54-ZN}dwdsregt.exe"ZenoSearch adware"
X{2F-FF-F4-4C-ZN}omdsregk.exe"ZenoSearch adware"
X{8C-C4-4A-A4-ZN}dwdsregt.exe"ZenoSearch adware"
X{B7-7D-D0-08-ZN}dwdsregt.exe"Added by the AGENT-GBC TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.