Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiolsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
NAUTOPROPREGPROP.EXE WMPADDIN.DLL"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently
UAWMONAd-Watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
UAWMONAd-Monitor.exe"F-Secure Anti-Spyware"
XccAppWMADZ.EXE"Added by the RBOT-LJ WORM!"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
NCoolwallpapercwm_tray.exe"Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers"
XCtfmonwmisys.exe"Added by the IRCBOT-ADS WORM!"
UCyber Trioshowmode.exe"From G-Tek Technologies. Allows you to set the PC in one of three modes
UDDWMonddwmon.exe"Direct Disc Writer Event Monitor from TOSHIBA"
NDELL Webcam ManagerDellWMgr.exeDell Webcam Manager - Webcam management software provided on Dell PCs
NDigitalWizard MonitordwMon.exe"InstallShield's DigitalWizard - free
XDivXCodecNEWMAIL.exe"Added by the DELF-RQ BACKDOOR!"
XDowmingzuDowmingzu.dll.vbs"Added by the SOLOW-E WORM!"
NEncoder AgentWMENCAGT.EXE"MS Windows Media Encoder
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFirewallwmlaunch .exe"Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
XFirewallwmlaunch .exe"Added by the ELIPTER.D WORM!"
NFullAudioWMPImporter.exeUsed to import settings from Windows Media Player into Music Now software (from www.musicnow.com - which is no longer available) and possibly others
NGWMDMMSGGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
UGWMDMpiGWMDMpi.exe"Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information"
UHidetools Spy Monitorwmispe.exe"HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
YIBM Password Managerpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
YIBM_PWMGRpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XJW Managerjwmngr.exe"Added by the DELBOT-G WORM!"
XKernel_checkwmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!"
XloaderWMPLAYER.EXEUnknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XLoadPFWwmimgr.exe"Added by the QEDS-B WORM!"
Ulxdwmon.exelxdwmon.exeLexmark 7600 Series printer device monitor
Xmachine-debuggerWMIPRVSW.exe"Added by the AGOBOT.WW WORM!"
Xmdwmdmspmdwmdmsp.exe"Adware - detected by Kaspersky as the AGENT.AM TROJAN!"
XMedia Playerwmplayer.exe"Added by a variant of the AGOBOT.BM WORM! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
XMessengerWmsngr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft File Demand Managerwmgrdf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft startupwmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
XMicrosoft Synchronization Managerwmedia.exe"Added by the SDBOT.BFC WORM!"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Viewer Monitor Managerviewmon.exe"Added by the XPAK.A TROJAN!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft WMmswm32.exe"Added by the BCKDR-AM BACKDOOR!"
UMicrosoft® Windows Mobile® Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMSNwmev.exe"Added by a variant of the SPYBOT WORM! See here"
XNAV Agentwmilib32.exe"Added by the VB-XU TROJAN!"
XNero Updater.6.12wmp9.exe"Added by the AGOBOT-AAG WORM!"
YNettGain2000WgwMngr.exe"Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution
XNewmanplayavi.exe"Added by the LINEAGE-AT TROJAN!"
XNewMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NNkVwMon.exeNkVwMon.exeNikon View - for transferring pictures from Nikon digital cameras
XNTmessageSystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
XOWMngrOWMngr.exe"OnWebMedia/SearchSeekFind advertising foistware"
UPC Dynamics SdwMon32sdwmon32.exe"SafeHouse ""Personal Privacy"" protects and hides your private and personal photos
Ypwmgrpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
YRfwMainrfwmain.exe"Rising antivirus"
Xrun=wmplayer.exe"CoolWebSearch Smartsearch parasite variant"
XscAppwmiprvse.exe"Added by the SILLYFDC-AW WORM!"
XSecurity Update Servicewmiprvce.exe"Added by the AGOBOT.ZW WORM!"
XShellwmedia16.exe"Added by the GOLDUN TROJAN!"
XShellwmedia32.exe"Added by the AGENT-BR TROJAN!"
XShowmeRuden.vbs"Added by the HANDLE-A VIRUS!"
XStartReplySystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
Xstealth.wm.exestealth.wm.exe"Added by the THEALS.A WORM!"
Xsysregedit sysdllwm.reg"CoolWebSearch parasite variant - also detected as the FEMAD-L TROJAN!"
XSYSTEM MESSAGERwmisg.exe"Added by the MYTOB.ES WORM!"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystem Update Servicewmiprvsv.exe"Added by the AGOBOT.YG WORM!"
XSystem Updater Processwmiprvsw.exe"Added by the AGOBOT-IL WORM!"
XSystem Updater Servicewmiprvsw.exe"Added by the GAOBOT.AFC WORM!"
XSystem Updateswmkl.exe"Added by the RBOT-AYJ WORM!"
XSystemSv12newmaxxsv234.exe"Added by the TIBS-TS TROJAN!"
XSystemSv121n2ewma1xxsv234.exe"Added by the TIBS.TJ TROJAN!"
Uuklwmpusrvc.exe"Ultimate Keylogger surveillance software. Uninstall this software unless you put it there yourself"
XUSBConfigration2wmmndir.exe"Added by the AGOBOT-SV WORM!"
?vWMPVer.EXE"Dritek System Inc. 3D Mouse related. Is it required?"
NViewMgrViewMgr.exe"Viewpoint Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL
YWgwMngrWgwMngr.exe"Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution
NWildwire MonitorWWMon.exeThis places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
XWin32 Wmls Driverwinitr32.exe"Added by the WOOTBOT.B WORM!"
XWindows Email Serverwmserv.exe"Added by the FOUNDU-AWORM!"
XWindows Management Informantwmmiexe.exe"Added by the IRCBOT-V BACKDOOR!"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Media APPwmapp.exeAdded by an unidentified WORM or TROJAN!
NWindows Media Connect 2WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
XWindows Media Loaderwmloader.exe"Added by a variant of the GAOBOT WORM!"
XWindows Media Playerwmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
XWindows Media Playerwmplayer.exe"Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
XWindows Media Playerwmplayerc.exe"Added by the SILLYFDC.DBG WORM!"
XWindows Media Player 3.6wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 3.6bWMPA36B.EXE"Added by the RBOT-VV WORM!"
XWindows Media Player 3.6dwmpa36d.exe"Added by the RBOT-YA WORM!"
XWindows Media Player 3.9wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 6.1.2wmplayer612.exe"Added by the RBOT.AIB BACKDOOR!"
XWindows Media Player Servicewmedia.exe"Added by the RBOT.213504 WORM!"
XWindows Media Serverwmserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Media Server!wmserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Media Utilitywmediautil.exe"Added by a variant of the SPYBOT WORM!"
XWindows Messenger Connectwmdsvc.exe"Added by the SLENFBOT.S WORM!"
XWindows Messenger Sharewmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Messenger Starterwmvsvc.exe"Added by the DELF.DAX TROJAN!"
UWindows Mobile Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UWindows Mobile-based device managementwmdSync.exe"Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships
UWindows Mobile-based device managementwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows Schedulerwmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows WMF Fixwinfix.exe"Added by the RBOT-FTQ WORM!"
XWinManagewmanage.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xwinmgmtwmiprvse.exe"Added by the AGENT-GHP TROJAN!"
Ywinmodemwmexe.exe"Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
XWinUpdatewmbem.exe"Added by the REVCUSS.B TROJAN!"
UWireless PCI Card Configuration UtilityWMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
Xwmsvhost32.exe"Added by the LINEAGE.CIS TROJAN!"
NWM VCRWMVCR.exe"WM Recorder allows you to record Windows Media(tm) streaming Video or Audio content. Can be accessed via Start Menu -> Programs"
YWm24PanWm24Pan.Exe"ESI external sound card driver"
Xwm41a398"rundll32.exe wm41a398.dll EnableRunDLL32"
XWMAudioservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XWMAudiowinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NWMBootN/A"Associated with Logitech Wingman game controllers. Not required but what does it do?"
Xwmcbaaca"rundll32.exe wmcbaaca.dll EnableRunDLL32"
NWMC_RebootCheckunregmp2.exe"Corrects problems with installations of Windows Media Player from version 9 onwards - see here and search for ""unregmp2.exe"""
XWMDM PMSP Servicecssrss.exe"Added by the KNOCKIT-A TROJAN!"
XWMedia32wmedia32.exe"Added by the BANGER TROJAN!"
XWMI Application Interfacewmiapi.exe"Added by the SPYBOT.RBY WORM!"
XWMI Performance Adapter Serviceswmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
XWMI Service Clientwmispv.exe"Added by the AUTORUN-ASX WORM!"
XWMI Standard Event Consumer - Scriptingscrcons32.exe"Added by the RBOT-GRD WORM!"
XWMI Standard Event Consumer - Scriptingscrcs.exe"Added by a variant of the RBOT-GRD WORM!"
UWMIEXE.exewmiexe.exe"NT component
XWminfWminf.exe"Added by the GEMA TROJAN!"
XWminfoWminfo.exe"Added by the GEMA TROJAN!"
Xwmiprevsewmiprevse.exe"Added by the BANKER-EPN TROJAN!"
Xwmiprvwmiprv.exe"Added by the RBOT-WM WORM!"
Xwmisrvwmisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xwmonjusched.exe"Added by the AGOBOT-OW WORM! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
XWMP Auto UpdateWINMEDUP.EXE"Added by the RBOT.CF WORM!"
YWMP54Gv4WMP54Gv4.exe"Linksys WMP54Gv4 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first
Xwmplayervergon1885.exe"Added by the BRONTOK-DG WORM!"
Xwmplayer.exewmplayer.exe"Added by the BANCBAN-CZ TROJAN! Note - this is not the valid Windows Media Player as the file is located in %Windir% rather than %ProgramFiles%\Windows Media Player"
UWMPNSCFGWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
Xwms3wms3.exe"Added by the LEGMIR-AQG TROJAN!"
XWMSDOS-ServicePack2cmd.exe /c C:WMSDOS.sys"Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted"
Xwmsrc.exewmsrc.exe"PrivacyRedeemer rogue privacy program - not recommended
Xwmsys32wmsys32.exe"Added by the BANPAES.B TROJAN!"
UWMUAgent.exeWMUAgent.exe"""WakeMeUp! is an advanced alarm clock for computers with Windows 2000
Xwmupdatewmupdate.exe"Added by the AGENT-GGJ TROJAN!"
Xwmvwinmonv.exe"Added by the AGENT-DG TROJAN!"
?WM_LOGINMSGLOGIN.EXE"Part of McAfee Firewall. What is it for and is it needed?"
UWorkstation Schedulerwm95.exe"Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled
Xwpwmgrswpwmgrs.exe"Added by the MYTOB-DH WORM!"
XWSAConfigurationwmon32.exe"Added by the GAOBOT.BAJ WORM!"
XWSSAConfigurationwmmon32.exe"Added by the AGOBOT-KC WORM!"
XXMLmedia 10.0wmsdkns.exe"Added by the FAKEALERT TROJAN!"
?XWMSUSBAPIXWMSAPI.EXE"Part of the installation of a Xerox WorkCentre printer/scanner. Is it required?"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.