Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Desktop Search Tool Tray AdminWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
XMicrosoft Windows DHCP___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows DLLHandlerbitpaint.exe"Added by the SDBOT.AHG WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMircosoft Windows Developer Enviromentdevenv.exeAdded by an unidentified WORM or TROJAN!
XMircosoft Windows Developer Enviromentdevenv.exe"Added by the RBOT.AUJ BACKDOOR!"
XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XServ-Uwssdsu.exe"Added by the MANIFEST TROJAN!"
XWindows Data Serverautodisc.exe"Added by the SPYBOT-CB WORM!"
XWindows Data Server[random name].exe"Added by the SPYBOT-DS WORM!"
XWindows DatabaseWinDat.exeAdded by an unidentified WORM or TROJAN!
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows DDE Loaderwindde32.exe"Added by the SDBOT-UZ WORM!"
XWindows debug loggingwinlogg.exe"Added by the RBOT-OY WORM!"
XWindows debug loggingwinloggs.exe"Added by the RBOT-QN WORM!"
XWindows Debuggerwindbg.exe"Added by the FORBOT-BY WORM!"
XWindows Debuggermsdbg32.exe"Added by a variant of the RBOT WORM!"
XWindows Debuggerwindbg32.exe"Added by the ZOTOB.L WORM!"
XWindows Debugging Toolsupdatecfg.exe"Added by the RBOT-AXU WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Default Serverwfdmgrsp.exe"Added by the IRCBOT.BCX BACKDOOR!"
XWindows Default Serverwinampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows Defenderwdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Addswda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Monitorwdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Updaterwdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWINDOWS DENEMEdeneme.exe"Added by the MYTOB-CR WORM!"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows Desktop Daemonwinpadg.exe"Added by a variant of the SPYBOT WORM!"
NWindows Desktop SearchWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search
XWindows Dialup Servicedialup.exe"Added by the AGOBOT.AAH WORM!"
XWindows Disk Defragmenterwpabaln32.exe"Added by the BANCOS-ASJ TROJAN!"
XWindows Disk Managercmnvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Display Couplerdisplay.exe"Added by the IRCBOT-YS TROJAN!"
XWindows DLL hostwinupd32.exe"Added by a variant of the SPYBOT WORM!"
XWindows DLL Hostdllhost32.exeAdded by an unidentified WORM or TROJAN!
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL Loaderdefragfat32z.exe"Added by the LINKBOT.A WORM!"
XWindows DLL Loaderrundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
XWindows DLL Loaderdefragfat32pi.exe"Added by the RBOT-QQ WORM!"
XWindows DLL Loaderdefragfat39.exe"Added by the POEBOT-C WORM!"
XWindows DLL Loaderdefragfatz.exe"Added by the LINKBOT.H WORM!"
XWindows DLL Loaderdefragfat32.exe"Added by the SDBOT-SS WORM!"
XWindows DLL Loaderdefragfat32abc.exe"Added by the RBOT-RG WORM!"
XWindows DLL Loaderwdevice.exe"Added by a variant of the SDBOT WORM!"
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows DLL LoaderWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows DLL Loaderdefragfatx.exe"Added by the POEBOT-F WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows DLL Trackerspoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
XWindows DLL Verifierxptl.exe"Added by a variant of the RBOT WORM!"
XWindows DLL Verifierwindlls.exe"Added by the RBOT-AZQ WORM!"
XWindows DNSwindns.exe"Added by the SDBOT-XU WORM!"
XWindows DNS Daemonwindnsd.exe"Added by the WOOTBOT.AS WORM!"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows DOSdosw.exe"Added by the SALAY-A WORM!"
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Download Managerwindlmngr.exeAdded by an unidentified TROJAN!
XWindows Drive CompatibilitySystem32Driver32.exe"Added by the SUPOVA.Z WORM!"
XWindows Driverwinxpdriver.exe"Added by the WOOTBOT.EE WORM!"
XWindows Driverwindrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver FoundationMTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Driver!windriver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Dynamic Library Cachedllcache.exe"Added by the INJECT-HT TROJAN!"
XWindows Dynamic Loading HeaderwinDLL32.exe"Added by a variant of the SDBOT WORM!"
XWindows Enterprise DefenderWindowsEDefender.exe"Windows Enterprise Defender rogue security software - not recommended
Xws_dws32.exe"Added by the LEGMIR-RL TROJAN!"
Xws_dssws32.exe"Added by the DELF-GZ TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.