Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
Y HWinst N/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
X Hwp system_wc.exe"Eziin adware"
X hws hws.exe"Added by the STARTPA-CT TROJAN!"
U HWSetup HWSetup.exe hwSetUP"""Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows."" Allows the user to change BIOS hard disk memory boot disk priority and other settings"
X hxadsec [path to trojan]"Added by the ADCLICK-AP TROJAN!"
X HXDL.EXE HXDL.EXE"Attune HelpExpress - spyware. Disable and uninstall - see here"
X HXIUL.EXE HXIUL.EXE"Attune HelpExpress - spyware. Disable and uninstall - see here"
U HydarVisionDesktopManager desk95.exe"ATI's HydraVision desktop management software allowing for multi-monitor support as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems such as this one. HydraVision can be uninstalled through Add/Remove Programs"
U HydraVisionDesktopManager desk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
U HydraVisionDesktopManager HydraDM.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
U HydraVisionViewport viewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
X Hyper Start instantmsgrs.exe"Added by the RBOT-NH WORM!"
X I am not Ranky. I am eTunnel! msyervice.exeAdded by an unidentified WORM or TROJAN!
X I am not Ranky. I am eTunnel! winsys.exeAdded by an unidentified WORM or TROJAN!
X I am not Ranky. I am eTunnel! disney.exeAdded by an unidentified WORM or TROJAN!
X I just want to say I love Milko and I need a drink svchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
X I-Worm.GiGu uGiG.eXe"Added by the GINK WORM!"
X I/O Controllers svcnet.exe"Added by the TIBIK-B TROJAN!"
X I386 I386.exe"Added by the MYPOWER WORM!"
? I81SHELL I81SHELL.exe"Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard"
U i8kfangui i8kfangui.exeGraphical interface for fan speed control
U IAAnotif iaanotif.exe"IAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - ""a performance software package for desktop PCs using select Intel® chipsets"" that ""replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs."" If you use the RAID version it's required to notify you if a RAID 1 disk has failed"
Y iamapp iamapp.exeAtGuard personal firewall engine. As Atguard was bought by Symantec some time ago it's now the Norton Personal Firewall executable as well
X Iamnacho On Irc.MusIrc.com Is a Homosexual! XBox64.exe"Added by the RANDEX.Y WORM!"
? IaNvSrv IaNvSrv.exe"Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %Pr"
? Iap iap.exe"Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about monitor the status of or change the state of the client computer such as shutting it down remotely?"
U ias ias.exe"InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X IASHLPR IASHLPR.EXE"Added by the OPASERV.T WORM!"
X ibin [path to trojan]"Added by the PERDA-C TROJAN!"
X ibm ibm.exe"Added by the LEGMIR-AH TROJAN!"
X IBM Keyboard Driver ikeybdrv.exe"Added by the SDBOT.IC TROJAN!"
? IBM Warranty Notification ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
N ibmmessages ibmmessages.exe"Allows IBM to push messages onto users' computers. Quote: ""The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"""
? Ibmmon.exe Ibmmon.exe"??"
U Ibmpmsvc ibmpmsvc.exePower management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn F3 F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes
? IBMPRC ibmprc.exeIBM application - what does it do and is it required?
U IBMUltraBayHotSwapCPLLoader IBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
? IBMUltraBayHotSwapSound IBMBAYSN.EXE"Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
Y IBM_PWMGR pwmgr.exeIBM Password Manager
X Ibs ibs.exe"Added by the HIDEDIAL-B TROJAN!"
U IBWin Background process IBackground.exe"IBackup for Windows"
U IBWin Monitor IBMonitor.exe"IBackup for Windows"
Y IcaBar icabar.exeRelated to Citrix MetaFrame
X icasServ icasServ.exe"Browser hijacker redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN!"
X icccomp [8 random letters].exe"Detected by Kaspersky as the ZHELATIN.EQ WORM! See here"
X ICcontrol iccontrol.exe"ICcontrol premium rate adult content dialer"
X icdd7ee6 rundll32.exe icdd7ee6.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""icdd7ee6.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X icddefff rundll32.exe icddefff.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""icddefff.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
N ICH Synth eusexe.exe"Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
X icifati yujixit.exe"Added by the SDBOT.ZZH WORM!"
U iClean iClean.exe"IEClean - ""advanced comprehensive package of tools which perform a number of functions to allow you to control your online privacy"""
U ICM ICM.EXE"Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
N iCn NAG.EXEiChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy if they exist. Not related to the Mac icon program of the same name
U ICO ICO.EXEFound on some Sony Vaio IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
N Icon Animation HDE.EXEPart of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
N Icon Hearit 95 hearit95.exeAudio desktop customization utility from Moon Valley Software. Resource hog
N Icon Hearit 98 hearit98.exeAudio desktop customization utility from Moon Valley Software. Resource hog
X Icon lptt01 icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Icon ml097e icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Y iconcache icon.bat"Related to the Vista Customization Pack"
Y ICONCLNT iconclnt.exe"APC PowerChute® Personal Edition tray icon"
U ICONDESK ICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop icons
N Iconfig.exe Iconfig.exeIcon for LS-120 "Superdisk"
X iConfigLoader DIIhost.exe"Added by the GAOBOT.AO WORM!"
N Iconoid Iconoid.exe"Iconoid is a desktop icon manager"
N Iconsaver Iconsaver.exe"IconSaver is a desktop icon manager"
X ICQ ICQNET.vbs"Added by the GORMLEZ-A WORM!"
X ICQ Agent icq6.exe"Added by the AGENT-FZJ TROJAN!"
X ICQ Center [path to worm]"Added by the RANDIN WORM!"
X ICQ Chat Service icqjdhs.exe"Added by a variant of the RBOT WORM!"
X ICQ Hacking Pro ICQpro.exe"Added by a variant of the NETSPY TROJAN!"
N ICQ Lite ICQLite.exe"ICQ Lite - compact version of the popular messaging program"
X icq lite scvhost.exe"Added by the AGENT-DSF TROJAN!"
X icq lite winlog.exe"Added by the IRCBOT-TJ TROJAN!"
X ICQ Lite Messenger [random filename]Added by an unidentified VIRUS WORM or TROJAN! Unlike the legitimate ICQ Lite executable which will be located in the ICQLITE folder in Program Files this particular impostor is located in the Windows or WinntSystem32 directory
X ICQ Messenger 2002 ICQ2002.exe"Added by the SDBOT-ABL WORM!"
X ICQ Net winlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
N ICQ Plus vplus.exe"ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs"
X IcqBeta webcamupdate.exeAdded by an unidentified TROJAN!
X ICQNet winlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder"
X icrosof Avps32 Control av32.pif"Added by the RBOT-AVC WORM!"
X icrosoft Visual plscx.exe"Added by the RBOT-AYO WORM!"
X icrosoft Visual InterDevc zvslmqb.exe"Added by the RBOT-AYP WORM!"
X icrosoft Windows DLL Services Configuration poker3.exe"Added by the SDBOT-AER WORM!"
X icrosoftf Avpx Control avpx.exe"Added by the RBOT-AYN WORM!"
U ICSDCLT rundll32.exe Icsdclt.dll ICSClientInternet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
N ICServer Icserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
Y ICSMGR ICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
X ICU-Sucker Service32.exe"Added by the ILLNOTIFIER.D TROJAN!"
N IC_KEY_3 spvic.exe"Instant Chess related"
N ID Commander IDCom.exeCaller ID utility for identifying incoming telephone numbers
X ID8525 ID8525.exe"Added by the ID8525.A TROJAN!"
X ID8525 id85255.exe"Added by the ID8525.A TROJAN!"
? IDA IDA.EXE"HP related - in a Program FilesHewlett-PackardPC COE folder"
X IDE ide.exe"Added by the ASSASIN.F TROJAN!"
X IDE Loader IDElibr32.exe"Added by the XILON TROJAN! Related to the game ""Diablo II"""
X idecntl idecntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
U iDesktop idesktop.exe"Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse"
X idlesam [8 random letters].exe"Detected by Kaspersky as the ZHELATIN.EQ WORM! See here"
N IDMan IDMan.exe"Internet Download Manager - download files faster schedule and resume"
X idmlssp [random filename]"Added by a variant of the SLAPER TROJAN!"
X IDTemplates IDTemplate.exe"Added by the BRONTOK-H WORM!"
N IDW Logging Tool idwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
X IE configure explorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
U IE Doctor IEDoctor.exe"IE Doctor Toolbar - ""IE Doctor can help you to Repair IE easily protect IE and OE from all malicious changes. It can Repair the HomePage context menu IE toolbar button startup items Favorites typed URLs and the entire Internet Options"""
X IE Java Update iejava.exe"Added by the AGENT-HD TROJAN!"
X IE Menu Extension toolbar rundll32.exe [path] tbextn.dll DllShowTB"Topconverting.com180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
U IE New Window Maximizer iemaximizer.exe"IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
X IE Runtime wini.exe"Added by the PICRATE.B WORM!"
X IE Runtimes winis.exe"Added by the RBOT-ADZ TROJAN!"
X IE**.exe [* = random char] IE**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
X IE**32.exe [* = random char] IE**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
X IE-Bar iebar.exe"DesktopMedia adware"
X IE6 wkstmg.exe"Added by a variant of the SDBOT WORM!"
X IE6 ssmss.exe"Added by the GAOBOT.DXO WORM!"
X IE6 porn.pif"Added by the RBOT-ATF WORM!"
X IE6 winsnt.exe"Added by the RBOT-GOV WORM!"
X IEACCESS temp532.exe"AsdPlug premium rate adult content dialer variant"
X IEACCESS surfya.exe"IEAccess premium rate adult content dialer variant"
X IEAgent update check iewatch.exe"Added by the BOMKA TROJAN!"
X IECache IECache.exe"Detected by Bitdefender as the DELF.OFC TROJAN! See here"
N iecheck iecheck.exe"Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2"
X IECheck MSDTCs.exe"Added by the TIRBOT-D WORM!"
X IECheck xpssl.exe"Added by the TIRBOT-E WORM!"
X IECheck mssvp.exe"Added by the TIRBOT-G WORM!"
U IECleanAux Ieboot6.exe"IEClean by Kevin McAleavy - cookie manager cache cleaner history cleaner etc. Performs cleaning tasks at startup"
X iedll iedll.exeHomepage hijacker redirecting to coolwwwsearch.com
X IEDriver IEDriver.exe"IEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze"
X IEDriver xplore.exe"IeDriver adware variant"
X IEDriver TD.exe"IeDriver adware variant"
X iedwa104 iedwa104.exe"Added by the DLOADR-BBW TROJAN!"
X IEengine IEeng.exe"STARTPAG.AI hijacker"
X IEexplorer AUpdate IEexplore32.exe"Added by the RBOT-GRE WORM!"
X IEFeatures IEFeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
X IEFeatures Internetfeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
X IefxTray IefxTray.exe"Added by the RILER-H TROJAN!"
X ieharv.exe ieharv.exe"Added by the BANKER-HH TROJAN!"
X Iehelper syslaunch.exeOutwar adware downloader
X iel2cde8 rundll32.exe iel2cde8.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""iel2cde8.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X ielcaabe rundll32.exe ielcaabe.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""ielcaabe.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X IELoader32 iexplore32.exe"Added by the SPEX or SPEX.B WORMS!"
X Iesar Iesar.exeBrowser hijacker - redirecting to an adult web page
X Iesearch.exe Iesearch.exe"LookNSearch adware"
X IEService.exe IEService.exeFastFind parasite variant
X IESet IExplorer.dll"Added by the PWS-BLUEDIT TROJAN!"
X iesetupi.exe iesetupi.exe"Added by a variant of the RBOT WORM!"
Y IEShow IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources"
X iestart iexp1orer.exe"Added by the NEMOG.C TROJAN!"
N ietsr ietsr.exe"IEClean by Kevin McAleavy - cookie manager cache cleaner history cleaner etc"
X ieupdate MCP****.exe [**** = random char]"Added by the ASOXY TROJAN!"
X ieupdate mcpdll32.exeAdware downloader trojan
X ieupdates ieupdates.exe"Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
X IEXPL0RER IEXPL0RER.EXE"Added by the AGOBOT-QL WORM!
X iexplo iexplor.exe"Added by the SIDEA TROJAN!"
X IExploer svshosts.exe"Added by the IRCBOT.BT TROJAN!"
X Iexploit Iexploit.html"Added by the INKER.B WORM!"
X iexplor.exe iexplor.exe"Added by an unidentified WORM or TROJAN! See here"
X Iexplore iexplore.exe"Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X IEXPLORE iexplore.exe"Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X IExplore IEXPLORE.EXE"Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
X IEXPLORE IEXPLORE.EXE"Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X iExplore Ini ie4uini.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Iexplore Services iexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
X IEXPLORE.EXE [path to trojan]"Added by the BANCOS-CJ TROJAN!"
X IEXPLORE.EXE goot.exe"Added by the BIFROSE-C TROJAN!"
X IExplorer Iexplor32.exe"Added by the BDOOR-BY BACKDOOR!"
X IExplorer IExplorer.EXE"Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X IEXPLORER msiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-I"
X Iexplorer explorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X iexplorer lptt01 iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X iexplorer ml097e iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Iexplorer.exe Iexplorer.exe"Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X IExplorer32 Java Scripting IExplore32b.exe"Added by the RBOT.ABO WORM!"
X IExplorer32c Java Scripting IExplore32cb.exe"Added by the RBOT.ABN WORM!"
X IExplorer6 Java Scripting IExplore326.exe"Added by a variant of the SDBOT WORM!"
X IExplorer7 Java Scripting IExplore327.exe"Added by a variant of the SDBOT WORM!"
X IExplorerService WinSock.exe"Detected by Kaspersky as the AGENT.KIU TROJAN! See here"
X iExpresser iexpresser.exe"Detected by Trend Micro as the SLENFBOT.AP WORM! See here"
X ifp ipf.exe"Added by the CLAGGER-AG TROJAN!"
X ifperx [random filename]"Added by a variant of the SLAPER TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list