Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microft Update 32 winssx.exe"Added by the RBOT-AQS WORM!"
X MicroLoad [random filename]"Added by the DARBY WORM!"
X Micromedia Flash Update wdfmrg.exe"Added by a variant of the SDBOT WORM!"
X Micromedia Flash Update xptxt.exe"Added by the RBOT-GAB WORM!"
X Microoft Timing pupdate.exe"Added by a variant of the RBOT WORM!"
X MICROSFT ANTIVIRUS UPDATE SUPPORT [random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
X MICROSFT ANTIVIRUS UPDATE SUPPORT MSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
X Microsft Conf 32 msaconf.exe"Added by the RBOT.EYA WORM!"
X Microsft Confige 32 msaconfigurez.exe"Added by the RBOT.CLC WORM!"
X Microsft Corporation Version 2001.12.4414 comrel.exe"Added by a variant of the SDBOT TROJAN!"
X Microsft Corporation Version 2002.12.2414 comserv.exe"Added by a variant of the SLAPER TROJAN!"
X MICROSFT MX UPDATE SUPPORT taskmngrs.exe"Added by the RBOT-AUZ WORM!"
X MICROSFT MX UPDATE SUPPORT winmx32.EXE"Added by the IRCBOT-FD WORM!"
X MICROSFT RAMA UPDATE SUPPORT [random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
X MICROSFT RAMA UPDATE SUPPORT MSN32.EXE"Added by the RBOT-AWJ WORM!"
X MICROSFT RAMA UPDATE SUPPORT mtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
X Microsft Remote Procedure Daemon msrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsft Security Monitor Process cmh.exe"Detected by Kaspersky as the EGGDROP.V BACKDOOR! See here"
X Microsft Security Monitor Process mssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsft Security Monitor Process mssmpp.exe"Detected by Kaspersky as the VIRUT.B VIRUS! See here"
X Microsft Updtes sarvice.exe"Added by a variant of the SDBOT WORM!"
X Microsft Upgraed [random filename].exe"Added by a variant of the SDBOT WORM!"
X Microsft Windows Adapter 5.1.3013 [random filename]"Detected by Kaspersky as the SMALL.HIT TROJAN! See here"
X microsft windows updates mwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
X Microsof Value nmatt.exe"Added by a variant of the RBOT WORM!"
X Microsof Windows Host svhost32.exe"Added by the RBOT.ADY WORM!"
X Microsof Winlog Host wilogon32.exe"Added by the RBOT.XC WORM!"
X Microsofot x386 System Monitor system32.exe"Added by the WOOTBOT.M WORM!"
X microsoft svchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X microsoft microsoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X Microsoft win32.exe"Added by the DARKMOON TROJAN!"
X Microsoft iexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Microsoft svchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Microsoft wuauclt.exe"Added by the QQROB-AAQ TROJAN! Note - this is not the legitimate wuauclt.exe process which should not appear in Msconfig/Startup!"
X Microsoft guard.exe"Added by a variant of the SDBOT WORM!"
X Microsoft wcsntfy.exe"Added by the AGOBOT-AHT WORM!"
X Microsoft ssmss.exe"Added by the RBOT-FZF WORM!"
X Microsoft lsass.ppf"Added by the RBOT-GAA WORM!"
X Microsoft msvchost.exe"Added by the RBOT-GAW WORM!"
X Microsoft mixers.exe"Added by the AGOBOT-AHU WORM!"
X Microsoft msmsger.exe"Added by a variant of the SDBOT WORM!"
X Microsoft MSUPDATE.exeAdded by an unidentified WORM or TROJAN!
X Microsoft radnom.exe"Added by the RBOT-GHO WORM!"
X Microsoft rtvcscan.exe"Added by the RBOT-GGU WORM!"
X Microsoft taskbar.exe"Added by a variant of the RBOT WORM!"
X Microsoft updater.exe"Added by the RBOT-GHP WORM!"
X Microsoft windl32.exe"Added by the SDBOT-DCZ WORM!"
X Microsoft aim.exe"Added by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility"
X Microsoft Explorerr.exe"Added by the IRCBOT-WG TROJAN!"
X Microsoft kasperskyLive32.exe"Added by the RBOT-GRT WORM!"
X Microsoft msngerf.exe"Added by the RBOT-GLW WORM!"
X Microsoft netsrv.exe"Added by the RBOT-GOS WORM!"
X Microsoft rundll.exe"Added by the RBOT-GSJ WORM!"
X Microsoft WinSecUp.exe"Added by the RBOT-GPL WORM!"
X Microsoft wsim32.exe"Added by the RBOT-GTL WORM!"
X Microsoft wplayer.exe"Detected by Kaspersky as the RBOT.DYU TROJAN! See here"
X Microsoft Explorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft install.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft internetdat.exe"Detected by Kaspersky as the RBOT.ETY BACKDOOR! See here"
X Microsoft ntsvr.exe"Added by a variant of the RBOT WORM!"
X Microsoft schost.exe"Detected by Kaspersky as the RBOT.FEH BACKDOOR! See here"
X Microsoft soundvol32.exe"Detected by Kaspersky as the RBOT.CIJ BACKDOOR! See here"
X Microsoft sqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft svhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft winampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft winline.exe"Detected by Kaspersky as the AGENT.KT TROJAN! See here"
X Microsoft wplayer.exe"Detected by Kaspersky as the RBOT.GHZ BACKDOOR! See here"
X Microsoft Associates Inc. iexplorer.exe"Added by the LOVGATE.Z WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Microsoft (C) HTML Application host [random filename]"Added by the RBOT-YB WORM!"
X Microsoft (R) Windows Configuration Backup Service svchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in either a ""config"" ""mapping"" or ""security"" subfolder of the Winnt or Windows folder"
X Microsoft (R) Windows DLL Loader rundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process which is found in %Windir% (98ME) or %System% (NT2000XP). This one is located in %Windir%\dll"
X Microsoft (R) Windows Network Latency Controller 1.tmp"Added by a generic password stealer TROJAN - see here"
X Microsoft (R) Windows Network Latency Controller nlc.exe"Added by a generic password stealer TROJAN - see here"
X Microsoft (R) Windows Network Latency Controller sp2vc.exe"Added by a generic password stealer TROJAN - see here"
X Microsoft (R) Windows Network Security Management Service nsms.exe"Added by the RANKY.LC TROJAN!"
X Microsoft (R) Windows Protected Content Restoration Service services.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
X Microsoft (R) Windows Protocol Deployment Manager [random].tmpAdded by an unidentified WORM or TROJAN!
X Microsoft (R) Windows TCP/IP Socket Driver [path to trojan]"Added by the PROXY-DD TROJAN!"
X Microsoft (R) Windows TCP/IP Socket Layer services.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
X Microsoft (R) Windows Update Service wuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process which should not appear in Msconfig/Startup!"
X Microsoft (R) Windows Vista/NT Runtime Compatibility Service nrcs.exe"Added by the RANKY.X TROJAN!"
X Microsoft .NET Confingurator msnconf.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Microsoft 16Bit Update wuapdate16.exe"Added by the RBOT.CZ WORM!"
X Microsoft 64 Bit Runtime Updater wupdt64.exe"Added by a variant of the RBOT WORM!"
X Microsoft ActiveX Debugger NT [path to trojan]"Added by the BANCOS-DO TROJAN!"
X Microsoft Admin Protocal MSADNIN.exe"Added by a variant of the RBOT WORM!"
X Microsoft ADservice [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft Agent mdss32.exe"Added by the KEYLOG-AG TROJAN!"
X Microsoft Agent svch0st.exe"Added by the VB-DRO WORM!"
X Microsoft ALG32 Protocol alg32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft ALGXP Protocol alg32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft all mmall.exeWopla.ac malware variant
N Microsoft Announcement Listener Annclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X Microsoft Ansti Update msie.exe"Added by the RBOT-LE WORM!"
X Microsoft Anti Virus Controller msavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Anti Virus Controller msavc32.exe"Detected by Kaspersky as the SDBOT.EPW BACKDOOR! See here"
X Microsoft Anti-Spy [random filename]"Added by a variant of the SDBOT WORM!"
X Microsoft AntiSpyware Bazzi.exe"Added by the AHKER.J WORM!"
X Microsoft AntiSpyware KT06.pif"Added by the IRCBOT.GEN WORM!"
X Microsoft AOL Instant Messenger MSAOL32.exe"Added by the RBOT-AAI WORM!"
X Microsoft AOL32 Protocol aol32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Application Center mappc.exe"Added by a variant of the RBOT WORM!"
X Microsoft Application Manager msapl32.exe"Added by the BROPIA-AE TROJAN!"
X Microsoft AUT Update MSlti32.exe"Added by the RBOT-X WORM!"
X Microsoft AUT Update MSlti16.exe"Added by the RBOT.EB WORM!"
X Microsoft Authority Service lsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process which should not appear in Msconfig/Startup!"
X Microsoft auto update winupdate.exe"Added by the BMBOT TROJAN!"
X Microsoft Auto Update WINHLP16.EXE"Added by the RBOT.GY WORM!"
X Microsoft auto update wuauclt.exe"Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process which should not appear in Msconfig/Startup!"
X Microsoft Automatic Update Serivce msautou.exe"Added by the RBOT-AOB WORM!"
X Microsoft Automatic Updater Explorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft AutoUpdater svhost.exe"Added by the RBOT.QG WORM!"
X Microsoft Bool Value MV2.exe"Added by a variant of the RBOT WORM!"
X Microsoft boot system cfg32 actboost.exe"Added by the BROPIA.R WORM!"
U Microsoft Broadband Networking MSBNTray.exeMicrosoft Broadband Networking Tray Application
X Microsoft Browser Services Brwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Browser Services Brwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Cab Manager exec.exe"Affilred adware"
X Microsoft Cab Manager cab.exe"Added by the DELF-JJ TROJAN!"
X Microsoft Calculator calc.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft checker MsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Client mshost.exe"Added by the RBOT-AND WORM!"
X Microsoft Client msclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Client Pc spoolsrv.exe"Added by the RBOT-AQM WORM!"
X Microsoft Client/Server Runtime Server Subsystem csrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Client/Server Runtime Server Subsystem csrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Command Line wincmd.exe"Added by a variant of the RBOT WORM!"
X Microsoft Conf Ldr sysconf.exe"Added by a variant of the SDBOT TROJAN!"
X Microsoft ConfgKeys wurmgrd32.exe"Added by the RBOT-ARX WORM!"
X Microsoft Config msconf.exe"Added by the RBOT.PV WORM!"
X Microsoft Config MSCONF.EXE"Added by the RBOT-LG WORM!"
X Microsoft Config 32 msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
X Microsoft Config 32bit mscnfg32.exe"Added by the RBOT-Z WORM!"
X Microsoft Config File config.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
X Microsoft Config Loader msconfig32.exe"Added by the AGOBOT.XX WORM!"
X Microsoft Config Loader msconf32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Configoration Service msconfigs.exe"Added by the RBOT-ETT WORM!"
X Microsoft Configs 32 msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Configuration 35 microsot1.exe"Added by an unidentified TROJAN!"
X Microsoft Configuration Wizard taskmrg.exe"Added by the SDBOT-MX TROJAN!"
X Microsoft Configure 32 msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Connection Manager Monitor cmmon.pif"Added by the RBOT-AKV WORM!"
X Microsoft Control Center crtl.exe"Added by the RBOT-VX WORM!"
X Microsoft Core Support MSxUP32.exe"Added by the RBOT-ANR WORM!"
X Microsoft Core Support [random filename]"Added by a variant of the RBOT TROJAN!"
X Microsoft Corp SQL Certificates sqlcer.exe"Added by the ZYBOT-C WORM!"
X Microsoft Corp SSL Certificates windowz.exe"Added by the RBOT-GCZ WORM!"
X Microsoft Corp TLS Certificates msauth.exe"Added by the RBOT-GAC WORM!"
X Microsoft Corp Updates wupdates.exe"Added by the RBOT-AUU WORM!"
X Microsoft Corporaticn SQL Handler sqlhandler.exe"Added by a variant of the RBOT WORM!"
X Microsoft Corporation [random filename]Added by various VIRUSES WORMS & TROJANS!
X Microsoft Corporation jview.exe"Added by the RBOT-AOD WORM!"
X Microsoft Corporation Svchost Service mssvc.exe"Added by a variant of the SDBOT WORM! See here"
X Microsoft Corporation Svchost Service mswsc.exeAdded by the AGENT.MAB TROJAN!
X Microsoft Corporation SYM monitor mssym.exe"Added by the RBOT-GDB WORM!"
X Microsoft CP Web Manager webcp.exe"Added by the IRCBOT.HP TROJAN!"
X Microsoft CPU Over Heat Manager CPU.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft CPXP Protocol cpxp.exe"Added by the RBOT.ATP WORM!"
X Microsoft Critical Services svhhost.exe"Added by the AGOBOT-AJA WORM!"
X Microsoft Crs Fix Serv wincrs.exe"Added by the SDBOT.BWF WORM!"
X Microsoft CRT Monitor Manager crtmon.exe"Detected by Trend Micro as the ROBOTON.A WORM! See here"
X Microsoft CSRSS Service nsmscrs.exe"Added by the RBOT-BPT WORM!"
X Microsoft CSRSS32 Protocol csrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft CSRSS386 Protocol csrss386.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Cvrt mscvrt32.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Microsoft Data Helper cihost.exe"Malware possibly a variant of the LINST TROJAN"
X Microsoft Data Machine csdata32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Database Handler mssql32.exe"Added by the RANDEX.AX WORM!"
X Microsoft Datalog Application msdata.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DDE Control wupades.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DDEs Control Erun.pif"Added by the RBOT-AMU WORM!"
X Microsoft Debug Service dbgbgr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Decryption Technology Msfenoe.exe"Added by the SPYBOT-DG WORM!"
X Microsoft Desktop Manager msdesk32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Dev iexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Development Debugger msdev.exe"Added by a variant of the RBOT WORM!"
X Microsoft Development Services msdevelop.exe"Added by the RBOT-FWS WORM!"
X Microsoft Device Manager msdevmgr32.exe"Added by the LATEDA.B TROJAN!"
X Microsoft Device Manager mscmtl32.exe"Detected by Kaspersky as the AGENT.BMQ TROJAN! See here"
X Microsoft Device Manager svcswin.exe"Added by the IRCBOT-YH TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list