Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Compaq Service Drivers compqs.exe"Added by a variant of the SDBOT WORM!"
X Compaq Service Drivers msnt.exe"Added by the SDBOT.CQL WORM!"
X Compaq Service Drivers NtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
X Compaq Service Drivers wincmd.exe"Added by the RBOT.ATV WORM!"
X Compaq Service Drivers wind32.exe"Added by a variant of the SDBOT WORM!"
X Compaq Service Drivers winmsn.exe"Added by a variant of the SDBOT WORM!"
X Compaq Service Drivers compaq.exe"Added by the SDBOT-AFU WORM!"
X Compaq Service Drivers msnsvc.exe"Added by the RBOT.BKT WORM!"
X Compaq Service Drivers ntsys32.exe"Added by the RBOT.CIW WORM!"
X Compaq Service Drivers winsvc.exe"Added by the SDBOT-AGD WORM!"
X Compaq Service Drivers 32 compq32.exe"Added by a variant of the SDBOT WORM!"
X Compaq Service Drivrs copq.exe"Added by a variant of the RBOT WORM!"
X Compaq Services Drivers ndt32.exe"Added by the RBOT.CQZ WORM!"
X Compaq Sound Drivers For WINDOWS sounddr.exe"Added by the SDBOT-XG WORM!"
N Compaq Video CD Watcher ??For Compaq PC's. MPEG viewer
X Compaq32 Service Drivers ms32.exe"Added by the SDBOT.BWH WORM!"
X Compaq32 Service Drivers msconfig32.exe"Added by the SDBOT-ADC WORM!"
X Compaq32 Service Drivers msnt32.exe"Added by the RBOT.BVF WORM!"
? CompaqHW Comp Manager cpqhcm.exe"Running on a Compaq laptop - any ideas?"
N CompaqPrinTray printray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
X Compaqs Service Driver copypad32.exe"Added by the SDBOT.CSO WORM!"
X Compaqs Service Drivers compqs.exe"Added by a variant of the SDBOT WORM!"
N CompaqSystray cpqpscp.exeCompaq System Tray icon
X Compatibility Service Process regsvs.exe"Added by the GAOBOT.YN WORM!"
X Compd Service Drivrs codq.exe"Added by a variant of the SDBOT WORM!"
U ComproRemote ComproRemote.exe"VideoMate TV tuner and capture card - remote control driver"
U ComproSchedulerDTV ComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
X Computing Technologie Firewall lsauth.exe"Added by the SDBOT-WX WORM!"
N COMSMDEXE comsmd.exe3Com tray icon
X ComStart Trojan Guarder.exe"TrojanGuarder misleading security software - not recommended see here"
X ComTry Web Searcher wstray.exeComtry MP3 Downloader related - spyware
X comxt comxt.exe"Added by the COMXT TROJAN!"
X con [path to trojan]"Added by the BRAVE-A TROJAN!"
? Concurre concurre.exe"??"
X ConfidentUser SRP.exe"ConfidentUser rogue security software - the site's ""online scanner"" is detected by Kaspersky as WinFixer.ba"
X Config service.exe"Added by the ISRAZ.B WORM!"
X Config WinService32.exe"Added by the CRUTCHA-A TROJAN!"
X Config winconfig.exe"Added by the GIP.113.B1 TROJAN!"
X Config CONFIG.EXE"Added by the PSWGIP.B TROJAN!"
X Config Loadation iEEexplore.exe"Added by the SDBOT.H TROJAN!"
X Config Loadatiorin I3Explorer.exe"Added by the SDBOT.H TROJAN!"
X Config Loader svchosl.exe"Added by the GAOBOT.P WORM!"
X Config Loader sysldr32.exe"Added by the GAOBOT WORM!"
X Config Loader scvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
X Config Loader svhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Config Loader SYSMGR.EXE"Added by the AGOBOT.C WORM!"
X Config Loader for Microsoft Windows mwincfg32.exe"Added by the AGOBOT.BD WORM!"
X Config Loader2 explores.exe"Added by the GAOBOT.BT WORM!"
X Config Loadr winsys32.exe"Added by the AGOBOT-HN WORM!"
X Config33.exe Config33.exe"Added by the SDBOT.T TROJAN!"
X ConfiggLoader cart322.exe"Added by the GAOBOT.DJ WORM!"
U ConfigSafe CFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry INI files System asset files system hardware network connections and operating system versions -- provides a restore function. Your choice"
U ConfigSafe AUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry INI files System asset files system hardware network connections and operating system versions -- provides a restore function. Your choice"
N ConfigServices Config.exePart of initial setup on a Compaq PC
X configsetup configsetup32.exe"Added by the AGOBOT-AFP WORM!"
X configuration apphost.exe"Added by the SDBOT-VP WORM!"
X Configuration ntsys32.exe"Added by the SDBOT-LN WORM!"
X Configuration explorer32.exe"Added by the SDBOT-ML WORM!"
X Configuration Default Wuxat.exe"Added by the SPYBOT-CA WORM!"
X Configuration File Winset32.exeAdded by the FLUX.101 TROJAN!
X Configuration Loaded wupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
X Configuration Loaded lssas.exe"Added by a variant of the SDBOT WORM!"
X Configuration Loader aim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader syscfg32.exe"Added by the SDBOT.B TROJAN!"
X Configuration Loader service5.exe"Added by the GAOBOT.AF WORM!"
? Configuration Loader lfass.exe"??"
X Configuration Loader sycfg34.exe"Added by the GAOBOT.AN WORM!"
X Configuration Loader wincrt32.exe"Added by the GAOBOT.BF WORM!"
X Configuration Loader windex.exe"Added by the GAOBOT.BZ WORM!"
X Configuration Loader dosrun32.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader Service.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader Servicess.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader sw32.exe"Added by the AGOBOT.BQ WORM!"
X Configuration Loader System.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader Winreg.exe"Added by the GAOBOT.AO WORM!"
X Configuration Loader sysinfo.exe"Added by the GAOBOT.FQ WORM!"
X Configuration Loader microsoft.exe"Added by the GAOBOT.JB WORM!"
X Configuration Loader confgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
X configuration loader winicfg32.exe"Added by the GAOBOT.RQ WORM!"
X Configuration Loader svhst.exe"Added by the GAOBOT.YC WORM!"
X Configuration Loader msgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
X Configuration Loader msnss.exe"Added by the GAOBOT.AUS WORM!"
X Configuration Loader cmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader IEXPL0RE.EXE"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader loadcfg32.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader MSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
X Configuration Loader systemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader ccSort.exe"Added by the AGOBOT.SR WORM!"
X Configuration Loader smss32.exe"Added by the AGOBOT.MB WORM!"
X Configuration Loader wincffg.exe"Added by the AGOBOT.A3 WORM!"
X Configuration Loader seru32.exe"Added by the SDBOT-VR WORM!"
X Configuration Loader botss.exe"Added by the SDBOT-XS WORM!"
X Configuration Loader ldasp.exe"Added by the AGOBOT.BH WORM!"
X Configuration Loader msgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader smsai.exe"Added by the SDBOT-YE WORM!"
X Configuration Loader svupdate.exe"Added by the RANDEX.DXP WORM!"
X Configuration Loader crcss.exe"Added by the AGOBOT.ADG WORM!"
X Configuration Loader lexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
X Configuration Loader scvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
X Configuration Loader svchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X Configuration Loader svchost2.exe"Added by the AGOBOT.JR WORM!"
X Configuration Loader dezi.exe"Added by the SDBOT-OB WORM!"
X Configuration Loader mouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader msg.exe"Added by the SDBOT.BT WORM!"
X Configuration Loader WinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Configuration Loader extrac.exe"Added by the SDBOT-AFP WORM!"
X Configuration Loader DVD-Player.exe"Added by a variant of the SDBOT WORM!"
X Configuration Loader IEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Configuration Loader svchost.exe"Added by the PARADROP-AI WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X Configuration Loader wincore.exe"Added by the SDBOT.BHE WORM!"
X Configuration Loader configldr.exe"Added by the AGOBOT-PP TROJAN!"
X Configuration Loader ahnhst.exe"Added by the AGOBOT.MX WORM!"
X Configuration Loader ntdm.exe"Added by the AGOBOT.RV WORM!"
X Configuration Loader svschost.exe"Added by the SDBOT-NS WORM!"
X Configuration Loader Service Winsys32.exe"Added by the RBOT-YV WORM!"
X Configuration Loader Service devl32.exe"Added by the SDBOT-XY WORM!"
X Configuration Loader10 ip7.exe"Added by the AGOBOT-ANZ WORM!"
X Configuration Loading svchos1.exe"Added by the GAOBOT.DK WORM!"
X Configuration Loading configldr.exe"Added by the AGOBOT-EC WORM!"
X Configuration Loading Service wscel.exe"Added by the SDBOT-WJ WORM!"
X Configuration Loadr iexplore.exeeAdded by an unidentified WORM or TROJAN!
X Configuration Manager CNFGLD32.EXE"Added by the SDBOT TROJAN!"
X Configuration Manager Cnfgldr.exe"Added by the SDBOT TROJAN!"
X Configuration Manager cfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in the Winnt or Windows folder"
X Configuration Servecie sewins.exe"Added by the SDBOT-COH WORM!"
X Configuration Service suchost.exe"Added by the TREB TROJAN!"
X Configuration Services mswords.exe"Added by the SDBOT-YM WORM!"
N Configuration Utility CONFIG.EXEControls linksys wireless connection. Available from the Desktop
U Configuration Utility wlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
X Configuration Wizard Cfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
X Configuration32 Loader32 winamp32.exe"Added by the SDBOT-BIC WORM!"
U ConfigUtility ConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies Inc"
X ConfigVir services.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
X ConfLoader sysconf16.exe"Added by the SDBOT-FB TROJAN!"
N Conmgr conmgr.exeStarts Winfax pro at startup
U ConMgr.exe conmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
X conmswf conrnbne.exe"Added by the SDBOT-DEX WORM!"
U Connect Kasamba Kasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30000 registered experts in over 600 categories to choose from chances are we`ll have just the right professional in the exact area of expertise that you need"""
X Connect2Party connect2party.exeAdult content dialler
U Connection Keeper ConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle thus preventing your ISP from dropping your connection due to inactivity"""
N Connection Manager CManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
X Connectivity Tool [path to trojan]"Added by the LITEBOT-E TROJAN!"
X Connector SYS.EXE"Nunci premium rate dialer"
X Connector sms.EXE"Added by the ExDial-B premium rate adult content dialer"
N CONNECTScheduler CONNECTScheduler.exe"Scheduler for updating Sony's CONNECT music download service"
X Cons consol32.exeHijacker - redirects to an adult content portal where foistware like ISTBar gets stealth installed
X conscorr conscorr.exe"VX2.Transponder parasite updater/installer related"
X Console de Gerenciamento Microsoft csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
X Console de Gerenciamento Microsoft csrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
U Consumer Input ConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
U Consumer Input Rewarded with MyPoints Consumer Input ConsumerInputRewardedwithMyPoints ConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
U Consumer Input Rewarded with MyPoints Consumer Input Update ConsumerInputRewardedwithMyPoints ConsumerInputUa.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
? Contacte contacte.exe"Some kind of driver?"
X Content connector [random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
X ContentDownload rundll32.exe MSA64CHK.dll DllMostrar"MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""MSA64CHK.dll"" file is located in the Winnt or Windows folder"
X ContentService winservn.exeHomepage hijacker
X ContinueInstall bpsinstall.exe"BrowserAid/BrowserPal foistware"
X ContraVirus ContraVirusPro.exe"ContraVirus misleading security software - not recommended see here"
X Control rundll32.exe ctrlpan.dll Restore ControlPanel"CoolWebSearch Msconfd parasite variant"
U Control Center Center.exe"Associated with Hawking Technologies Inc wireless products. Located in %Program Files%\Hawking\WLAN Card Utilities"
X Control handler ***********.exe [* = random char]"CoolWebSearch parasite variant"
X Control handler ahjinst.exe"CoolWebSearch parasite variant"
X Control handler [10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
N control panel smctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
X Control Panel System.exe"Added by the DANI TROJAN!"
X control panel software service cprs.exe"Added by the RBOT-FPI WORM!"
X Controladores [path to trojan]"Added by the TELEFO-A TROJAN!"
Y ControlCenter ctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
N ControlCenter2.0 brctrcen.exeBrother scanner 'Control Center' application - can be started manually
N ControlCentreTray XWCTray.exeSystem Tray access for the Xerox ControlCentre 2.0 software for their range of printers copiers faxes etc
X Controlled Resource System Service crss.exe"Added by the AGOBOT.GH WORM!"
N Controller WFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
X ControlPanel rundll32 internat.dll LoadKeyboardProfile"CoolWebSearch parasite variant"
X ControlPanel host32.exe internat.dll LoadKeyboardProfile"Added by a vairant of the DELF.DW TROJAN!"
X ControlPanel cmd32.exe internat.dllLoadKeyboardProfile"Added by the DLOADER-HF TROJAN. Note - the ""cmd32.exe"" file is found in %System%"
X ControlPanel systemctrl.exe internet.dll LoadNetworkProfile"Browser hijacker also detected as STARTPA-FX"
X ControlPanel internat.dll LoadKeyboardProfile"Added by the BIZVES-A TROJAN!"
X ControlPanel popcorn.exe internat.dll LoadKeyboardProfile"Added by the BIZVES-B TROJAN!"
X ControlPanel popcorn64.exeBrowser hijacker redirecting to loadcash.biz
X ControlPanel popcorn64.exe rundll.dll LoadMouseProfile"Added by the DLOADER-OI TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list