Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
U ipsecdialer IPSECD~1.EXE"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
U ipsecdialer ipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
Y IPSecMon IPSecMon.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
X IPTable Configuration Winipcfgs.exe"Added by a variant of the RBOT WORM!"
N iptray iptray.exe"System Tray access to Intel Desktop Utilities - ""provides you with the means to monitor system temperatures voltages fan speeds and hard drive health; view detailed system information and test your system hardware for common errors"""
X IPv6 Helper Driver csass.exe"Added by the AGOBOT.TC WORM!"
X IPv6 STUN Service netstun.exe"Added by a variant of the SDBOT WORM!"
N IPW IPW.exe"Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to ""make and receive free Internet calls on your regular phone"" whilst ""at the same time make and receive regular (landline) calls on your phone"""
N ipw usbipw.exe"Related to Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to ""make and receive free Internet calls on your regular phone"" whilst ""at the same time make and receive regular (landline) calls on your phone"""
X ipwf ipwf.exe"Added by the SCHOEBERL TROJAN!"
X IpWins ipwins.exe"IPWins adware"
X ipxwshel ipxwshel.exe"Added by the WAREZOV.DG WORM!"
? IQES.exe iqes.exe"??"
U Ir41_32.ax regsvr32.exe Ir41_32.ax"Intel® Indeo® video 4.4 Decompression Filter related. The ""Ir41_32.ax"" file is located in %System%"
X irassync irasyncd.exe"IRASSync adware"
X irc session sessionmgr.exe"Added by the SDBOT-ACE WORM!"
Y IREIKE IreIKE.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
N iRis Active Monitor winmon32.exeIris Antivirus - discontinued replace with good alternative
N iRiS AntiVirus Active Monitor WIMMUN32.exeIris Antivirus - discontinued replace with good alternative
U iRiver AutoDB MLService.exe"Associated with the iRiver Music Manager"
N iRiver Updater Updater.exe"Updates for the iRiver Music Manager - used with their digital music players"
U IrMon IRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
? IRPMonitor itcnmon.exe"??"
X irssyncd irssyncd.exe"SafeSurfing adware variant"
X Irwftp [path to trojan]"Added by the BANCOS-AP TROJAN!"
X irwftp iexplorer.exe"Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X irwftp ftpmon.exe"Added by the BANCBAN-BO TROJAN!"
U IrXfer IrXfer.exeMicrosoft Infrared Transfer application
X ir_ftp ir_ftp.exe"Added by the IRFTP TROJAN!"
X ir_ftp irwftp.exe"Added by the BANCOS.H TROJAN!"
N IS CfgWiz cfgwiz.exeNorton Internet Security configuration wizard
X Isass Isass.exe"Added by the FUTRO TROJAN!"
X IsassRenascimento Issas.exe"Detected by Kaspersky as the BANKER.GAX TROJAN! See here"
U ISBMgr.exe ISBMgr.exeRelated to Sony ISB Utility
X iscch iscch.exe"Added by the LCPRANK-A WORM!"
N isdbdc isdbdc.exeFor Compaq PC's. May install properties in dial-up networking when you register with an ISP
U isDeleteMe isDel.batUsed by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product
N ISDN Monitor Linksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly you will never need to use this icon
U ISDNwatch IWatch.exe"FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"""
X iSecurity applet rundll32.exe iSecurity.cpl SecurityMonitor"Detected by Trend Micro as the DLOADER.UZO TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
U ISHelp help.exe"ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it"
U iShield iShield.exe"""GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser"""
X ishost.exe ishost.exe"Added by the DLOADR-XJ TROJAN!"
Y ISLP2STA ISLP2STA.EXEA process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers
X ISMModule ISMModule.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule2 ISMModule2.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule3 ISMModule3.exe"Internet Speed Monitor C adware"
X ISMModule4 ISMModule4.exe"Internet Speed Monitor A adware related"
X ISMModule6 ISMModule6.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule7 ISMModule7.exe"Internet Speed Monitor C adware related - see example here"
X ISMModule8 ISMModule8.exe"Internet Speed Monitor C adware related"
X ISMPack5 ISMPack5.exe"Internet Speed Monitor C adware related - see example here"
X ISMPack6 ISMPack6.exe"Internet Speed Monitor C adware related - see example here"
X ISMPack7 ISMPack7.exe"Internet Speed Monitor C adware"
X ISMPack8 ISMPack8.exe"Internet Speed Monitor C adware related - see example here"
Y ISP.COM High Speed slipgui.exe"User interface for Slipstream - internet acceleration through compression/decompression techniques intelligent cacheing on the server side and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet Wanadoo Terra OnSpeed United Online and AOL Canada. Required if the user's account is locked in to that proxy server"
X ISPSERVICE psycho.exe"Added by the IRCFLOOD-O TROJAN!"
X ISPSERVICE wintmp.exe"Detected by Trend Micro as the FLOOD.BC BACKDOOR! See here"
U iSpyNOW ispynow.exe"iSpyNOW - remote monitoring and surveillance software"
X Israfel Israfel.vbs"Added by the GAGGLE.D or GAGGLE.E WORMS!"
N IsReminder ISPopup.exe"Related to GuardWare iShield - this is the registration reminder for the trial version so not required in startup"
X ISS inet.exe"Meplex adware"
X issearch.exe issearch.exe"Added by the ZLOB-QF TROJAN!"
X issEnc32Svr issEnc32.exe"Added by a variant of the RBOT WORM!"
N ISSI EZUpdate Service issimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
U ISStart ISStart.exe"LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation"
Y ISSVC ISSVC.exePart of Norton Internet Security Suite
Y ISS_Certtool certtool.exe"IBM Client Security Certification Tool"
X IST Service istsvc.exe"ISTBar adware"
X ist service uninstall [random filename]"ISTBar adware related"
X istinstall zazzer.exe istinstall zazzer.exeUnidentified adware downloader/installer
U ISTray pctsTray.exe"Part of Spyware Doctor anti-spyware from PC Tools"
N ISUSPM Startup ISUSPM.exeInstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version
N ISUSScheduler issch.exeInstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version
U ISW.exe ISW.exe"Related to Internet Security Wizard from AT&T (formerly BellSouth Premium Internet Security) alerts users about any potential security threats. It should not be uninstalled unless the user wants to completely remove all traces of AT&T Internet Security Suite"
X isxa isxa.exe"Added by the SMALL-EIV TROJAN!"
N iSysCleaner iSysCleaner.exe"iSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user"
X isystem isystem.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
X ItalU italfds.exe"Added by a TROJAN - see here"
U Itk Itk.exe"In The Know - surveillance software that creates records of everything people do on a computer ie spying or monitoring depending upon how you call it"
U itk.exe itk.exe"Insert ToggleKey by Mike Lin. ITK sounds a tone whenever you press Insert"
U iTouch iTouch.exeLoads the iTouch configuration program for Logitech keyboards. It's needed if your keyboard has shortcut buttons and if you use them. It's also needed if your keyboard does not have the num lock caps lock and scroll lock lights on it and you use the on-screen displays for num lock caps lock and scroll lock
N ItsDeductiblePopUp ItsDeductible.exe"ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip"
X ITUNES itune.exe"Added by the RBOT-ZU WORM!"
X ITUNES itunes.exe"Added by the OSCABOT-L WORM! Note - this file will be placed in the WindowsSystem32 or WinntSystem32 folder and should not be confused with the (legitimate) Apple iTunes process always located in the Program FilesiTunes folder"
X Itunes dials.exe"Detected by Kaspersky as the AGENT.MM TROJAN!"
Y iTunes Helper iTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
X iTunes Music iTunesHelper32.exe"Added by the SDBOT.CHK WORM!"
X iTunesAgent ita.exe"Added by the TACTSLAY.U TROJAN!"
X itunesff itunesff.exe"Added by the EB adult premium dialer"
Y iTunesHelper iTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
U itype itype.exe"Microsoft IntelliType Pro related. Allows you to map the extra function keys to any program you like. The extra keys are set to defaults such as Messenger Mail My Document etc. Not required unless you want to use the extra keys"
N Iusage netdet.exe"Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up"
X iut75 uzcx.exe"Added by the DLOADER-AXV TROJAN!"
X ivHost taskManager.exe"Added by a variant of the SPYBOT WORM! See here"
N IVPServiceMgr ivpsvmgr.exeToshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as whenever you are connected to the Internet it will check for Windows updates and Toshiba updates
X ivy.exe ivy.exe"Added by the AGENT-ENZ TROJAN!"
N IW ControlCenter iwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files create new directories right on your CD-R CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis"
U iwctrl iwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files create new directories right on your CD-R CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis"
X ixplore ixplore.exe"Added by the SDBOT-CY TROJAN!"
X ixproxy [path to trojan]"Added by the XORPIX-A TROJAN!"
X ixsso ixsso.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD"" ""Winamp Remote"" ""Windows Media Player"" and ""Futuremark"""
X iyelejiv yujixit.exe"Added by the SDBOT.BJK WORM!"
? IZE N/A"??"
N j2 Tray Menu HotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
X JA Cfg Util v2 jacfg2.exe"Added by the RBOT-AL WORM!"
X JA Config 32 Awesome32.exe"Added by a variant of the SDBOT WORM!"
U Jammer jammer.exe"Jammer by Agnitum - ""Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"""
X Jammer2nd Jammer2nd.exe"Added by the NETSKY.Z WORM!"
X java remote.cmd"Added by the BANKER-EHG TROJAN!"
X java system.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Java applet javaup.exe"Added by the SDBOT-ACF WORM!"
X Java Auto Update ujm.exe"Added by the SDBOT-ADH WORM!"
X Java Runtime Environment jbuild.exe"Added by the DELBOT-J WORM!"
X Java Runtime Value runjava.exe"Added by the RBOT-DDJ WORM!"
X Java Runtimes iexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
X Java Softe Java32.com"Detected by Kaspersky as the RBOT.ECN WORM! See here"
X Java Update keeper.exe"Added by the AGENT-DIS TROJAN!"
X Java Virtual Machine javaw.exe"Added by a variant of the RBOT WORM!"
X Java**.exe [* = random char] Java**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
X Java**32.exe [* = random char] Java**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
X java-plugin javasctp.exe"Added by the VB.AMX TROJAN!"
X Java32 Configuration Loader msnmesgr.exe"Added by a variant of the RBOT WORM!"
X JavaCore JavaCore.exe"Detected by Trend Micro as the DROPPER.AIO TROJAN! See here"
X Javascript jscript.exe"Added by the DELBOT-AD WORM!"
X JavaScript Debugging Service JsDbgMan.exe"Added by the DERDERO.E WORM!"
X JavaScriptMsxrs Msxrs.exe"Detected by Kaspersky as the BANLOAD.ERP TROJAN! See here"
X JavaUpdate0.07 [filename]"Added by the JUPDATE TROJAN!"
X JavaUpdateSched jusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
X JavaVM java.exe"Added by the MYDOOM.M or MYDOOM.N or other variants of the MYDOOM WORMS! Note - not to be confused with the valid Windows ""java.exe"" which resides in C:WindowsSystem (Win9x/Me) C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) as this resides in C:Windows or C:Winnt"
X jawa32 jawa32.exe"Added by the AGENT.BG WORM!"
X Jawa322 jawa32.exe"Added by a variant of the AGENT.BG trojan"
N JB Jiffybar.exe"Get Paid As You surf" application
X jcidls [random filename]"Added by a variant of the SLAPER TROJAN!"
U Jessops Insert Detect InsDetect.exe"Jessops Insert Detect from Jessops Picture Suite"
N Jet Detection ADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Y JetAdmin Discovery Indicator HPJETDSC.EXEHP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry and remains active to control the Discovery Indicator
X jete yujixit.exe"Added by the SDBOT.BRT WORM!"
X jiahus svchqs.exe"Added by the WOWPWS-AL TROJAN!"
X jijbl ezlwy.bat"Added by the REDDW WORM!"
X jkdfj94kgdftdf winlogan.exe"Added by the ZLOB.BZ TROJAN!"
U JMB36X Configure JMRaidTool.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
Y JMB36X Configure JMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
U JMB36X IDE Setup JMInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
U JMB36X IDE Setup xInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
U Job-oversigt taskmon.exeTask Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users loading TaskMonitor will typically solve many if not most of those annoying IE scripting errors (per Symantec's Knowledgebase)
U JobHisInit JobHisInit.exeUsed by Ricoh network printers to enable network printing from the client
U Jog Serve JogServ2.exe"Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
U JogServ2 JogServ2.exe"Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
X johkjh srvd.exe"Added by a variant of the SLAPER TROJAN!"
X john315 srrvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
X johnj315 srvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
X johnj3155 srvcc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
X johnj3cd srvdc.exe"Added by a variant of the SLAPER TROJAN!"
X jon315 [path to trojan]"Added by the MAILBOT-BI TROJAN!"
? jotl millenzje.exe"??"
U JOYTECH USB Neo S Controller JoytechNeoSTrayIcon.exe"System Tray access to Joytech Neo S PC gamepad controller software"
X jpgdiag [path to worm]"Added by the STRATION-AN WORM!"
X jpupd jpupd.exe"Added by the DIALER.CM TROJAN!"
X Jreg Jreg2b.exe"FlashEnhancer adware"
X jucheck jucheck.exe"Added by the SCRIMGE.O WORM!"
X Jufualt winxp2.exe"Added by the SDBOT-AAB WORM!"
X Jufualt svhost.exe"Added by the SDBOT-ADJ WORM!"
N Juno_uoltray exec.exeJuno ISP software - not required
N jusched jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
X jusched [path to trojan]"Added by the BANKER-BWR TROJAN!"
X jusched jusched.exe"Added by the BANKER-BOV TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
X jushed32.exe jushed32.exe"CoolWebSearch parasite variant - also detected as the BIZTEN-L TROJAN!"
X jusodl severe.exe"Added by the QQPASS.48436 TROJAN!"
U JussDropUtility JussDrop.exe"Related to DropShots Inc. A subscription based service for family to connect converse and share photos and videos"
N JustVoip JustVoip.exe"JustVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
X jutsu jutsu.exe"Added by the RBOT-LS WORM!"
U jv16 PT TempFileTool TempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
U jv16PT - Privacy Protector Task.jvb"jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer every time you start your computer"""
U Jv16pt Network Resident jv16pt_network.exe"jv16 PowerTools network resident program. Only needed if you are using the program's network features"
X JvcHost jvcsvc32.exe"Added by the AGOBOT-AIU WORM!"
X jvdnlssn fljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
X JVM0 JVM0.exe"Added by the BANLOA-AX TROJAN!"
X JVM0.12 [random filename]"Added by the TEADOOR-A TROJAN!"
X JVM0.14 [random filename]"Added by the TEADOOR-B TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list