Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UBMMGAG"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
Xcwriterucookw.exe"Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
Xcwritercwriter.exe"Part of PcRaiser
Xdwqblwrsq.exe[random].exe"Okcashbackmall adware"
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
Xewrgetujgeurge.exe"Added by the AUTOINF-AK WORM!"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFwr Command Modulefwr.exe"Added by the SDBOT-PP WORM!"
Nfwrastrcfwrastrc.exeDial-up software for Friendly Technologies/1NationOnLine free ISP
NGreetings WorkshopGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
NHP CD Writerhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
NHP CD-Writerhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
UHPPWRSAVHPPWRSAV.EXE"Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com
YIntelWirelessifrmewrk.exeAssociated with the Intel PRO/Set Wireless software
Xkvasoftkva8wr.exe"Added by the ONLINEG.ICC WORM!"
Xlanmanwrk.exelanmanwrk.exe"Added by the AGENT.AIA TROJAN!"
ULidPolicypwrschem.exeA utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery
ULoadPowerProfileRundll32.exe powrprof.dll"Power management specifics such as monitor shut-off
XLogitech Desktop Controllerwrcam.exe"Added by a variant of the RBOT WORM!"
NLowRateVoipLowRateVoip.exe"LowRateVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XLowRiskFileTypessysguard.exe"Added by the FAKEAV-UY TROJAN!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
NMicrosoft Greetings Workshop ReminderGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
XMicrosoft Updatingsyswr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
XMicrosoft Winsock Wrapperws2_32s.exe"Added by a variant of the SPYBOT WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMSNavWHMSWkwrH.exe"Added by the ANAV-A WORM!"
Umspwrpupstman.exe"""Transparent icon background"" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)"
Umspwrpupxpman.exe"Related to Ashampoo's PowerUp XP"
Umspwrpwrupst.exe"Ashampoo's PowerUp XP is a ""tool for fine-tuning your Windows NT4
UmspwrPuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
XNod29 Servicenodwr.exe"Added by a variant of the RBOT WORM!"
Unwrecmsgnwrecmsg.exe"Broadcast message handler part of Novell Netware that displays server
XPixelpwr32Pixelpwr32.exe"Added by the GEMA TROJAN!"
Xpm32ctrlpwr32crtl.exe"Added by the CRYPTER.A TROJAN!"
YPowerChutePwrchute.exe""During a power outage
XPowerChutePwrchute.exe"Added by the LAZAR-A TROJAN! Note - this is located in %ProgramFiles%\APC_Power"
Xpshowerpshwr.exe"SafeSurfing adware variant"
XPwr32ctrPwr32ctr.exe"Added by the GEMA TROJAN!"
XPwr32ctrlPwr32ctrl.exe"Added by the GEMA TROJAN!"
XPwr32mgtPwr32mgt.exe"Added by the GEMA TROJAN!"
UPWRESETpwreset.exe"Related to the Avaya IP Softphone"
NPWRISOVM.EXEPWRISOVM.EXE"PowerISO - a powerful CD/DVD image file processing tool"
YPWRMGRTRPWRMGRTR.DLL"Power Manager - background monitor module for IBM ThinkPad laptops. Leave it alone to ensure proper power management functions"
Upwrmonit"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
XPwroffPwroff.exe"Added by the GEMA TROJAN!"
UPwrsavePwrsave.exeToshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
?Pwruploginpulogin.exe"??"
UPwrUpManagerPuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
UPwrUpSwDeskSwitchDesk.exe"PowerUp SwitchDesk - virtual desktop manager which allows ""you have the possibility to launch games
UPwrupTweakMePUPXPTWK.EXE"Ashampoo's PowerUp XP is a ""tool for fine-tuning your Windows NT4
XRegWritecsrss.exe"Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
URivaTunerRivaTunerWrapper.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTunerWrapper.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerWrapper ApplicationRivaTunerWrapper.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
NSourcePathgwreg.exeUsed to update Gateway registry settings for System Restoration Kit and Web update programs
UTabletWizardSPLSHWRP.EXEMicrosoft Tablet PC Component
YTPwrMainTPwrMain.EXEPower management software for Toshiba laptops
?TPwrMgrTPwrMgr.exe"Found on a Toshiba laptop. Related to power management?"
YTpwrtrayTPWRTRAY.EXEToshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use
Xusrgtway.exesyswrun4x.exe"Added by the MITGLIEDER.E TROJAN!"
NWillow RoadWillowRoad.exeWillow Road Screen Saver
XWindowRegKey updatewins.exe"Added by the SPYBOT.I WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Frame Worksfrmwrks32.exe"Added by a variant of the RBOT WORM!"
XWindows Frameworkfrmwrk.exe"Added by the DWNLDR-GWV TROJAN!"
XWindows NetDDewrmana32.exe"Added by the MYTOB.IM WORM!"
XWindows Offical Netvvorksmywriter32.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Runtime HelpWinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
XWindows Service Findwrfkuk.exe"Added by the IRCBOT-XZ TROJAN!"
XWindows Task Manager Emulatorkennewr.exe"Added by the SPYBOT-FA WORM!"
XWinFixer helperwfxcwr.exe"WinFixer web installer - ""foistware""
XWorkstation Serviceswrkstn.exe"Added by the RBOT-OJ WORM!"
?wrWR.EXE"??"
?WR Commandwr.exe"??"
Xwrclib"rundll32.exe wrclib.dllstart"
NWrCtrlWrCtrl.exe"Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work
XWRDialerWrDialer.exeWinPoet DSL dialler
?WRECK GUARD??"??"
?WregBioswregbios.exe"Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?"
Uwrexecwrexec.exe"Watch Right - monitoring program
?wristewriste.exe"??"
UWrite DVD-R!saimon.exe"Saimon's WriteDVD! ""gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks"""
UWrtMon.exeWrtMon.exe"Related to Presto PageManager which is bundled with Canon Scanners"
Uz-WrDialerWrDialer.exeWinPoet DSL dialer


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.