Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microfot Update winldx32.exe"Added by a variant of the RBOT WORM!"
X Microft Exploerer spoolsac.exe"Added by the RBOT-AMD WORM!"
X Microft Update 32 winssx.exe"Added by the RBOT-AQS WORM!"
X MicroLoad [random filename]"Added by the DARBY WORM!"
X Micromedia Flash Update wdfmrg.exe"Added by a variant of the SDBOT WORM!"
X Microoft Timing pupdate.exe"Added by a variant of the RBOT WORM!"
X MICROSFT ANTIVIRUS UPDATE SUPPORT [random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
X MICROSFT ANTIVIRUS UPDATE SUPPORT MSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
X Microsft Confige 32 msaconfigurez.exe"Added by the RBOT.CLC WORM!"
X MICROSFT MX UPDATE SUPPORT taskmngrs.exe"Added by the RBOT-AUZ WORM!"
X MICROSFT MX UPDATE SUPPORT winmx32.EXE"Added by the IRCBOT-FD WORM!"
X MICROSFT RAMA UPDATE SUPPORT [random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
X MICROSFT RAMA UPDATE SUPPORT MSN32.EXE"Added by the RBOT-AWJ WORM!"
X MICROSFT RAMA UPDATE SUPPORT mtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
X Microsft Updtes sarvice.exe"Added by a variant of the SDBOT WORM!"
X Microsft Upgraed [random filename].exe"Added by a variant of the SDBOT WORM!"
X microsft windows updates mwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
X Microsof Value nmatt.exe"Added by a variant of the RBOT WORM!"
X Microsof Windows Host svhost32.exe"Added by the RBOT.ADY WORM!"
X Microsof Winlog Host wilogon32.exe"Added by the RBOT.XC WORM!"
X Microsofot x386 System Monitor system32.exe"Added by the WOOTBOT.M WORM!"
X microsoft svchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X microsoft microsoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X Microsoft win32.exe"Added by the DARKMOON TROJAN!"
X Microsoft iexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder"
X Microsoft svchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Microsoft (C) HTML Application host [random filename]"Added by the RBOT-YB WORM!"
X Microsoft .NET Confingurator msnconf.exe"Added by an unidentified VIRUS
X Microsoft 16Bit Update wuapdate16.exe"Added by the RBOT.CZ WORM!"
X Microsoft 64 Bit Runtime Updater wupdt64.exe"Added by a variant of the RBOT WORM!"
X Microsoft ActiveX Debugger NT [path to trojan]"Added by the BANCOS-DO TROJAN!"
X Microsoft ADservice [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft Agent mdss32.exe"Added by the KEYLOG-AG TROJAN!"
X Microsoft ALG32 Protocol alg32.exe"Added by a variant of the SPYBOT WORM!"
N Microsoft Announcement Listener Annclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X Microsoft Ansti Update msie.exe"Added by the RBOT-LE WORM!"
X Microsoft Anti-Spy [random filename]"Added by a variant of the SDBOT WORM!"
X Microsoft AntiSpyware Bazzi.exe"Added by the AHKER.J WORM!"
X Microsoft AntiSpyware KT06.pif"Added by the IRCBOT.GEN WORM!"
X Microsoft AOL Instant Messenger MSAOL32.exe"Added by the RBOT-AAI WORM!"
X Microsoft AOL32 Protocol aol32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Application Center mappc.exe"Added by a variant of the RBOT WORM!"
X Microsoft Application Manager msapl32.exe"Added by the BROPIA-AE TROJAN!"
X Microsoft AUT Update MSlti32.exe"Added by the RBOT-X WORM!"
X Microsoft AUT Update MSlti16.exe"Added by the RBOT.EB WORM!"
X Microsoft Authority Service lsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
X Microsoft auto update winupdate.exe"Added by the BMBOT TROJAN!"
X Microsoft Automatic Update Serivce msautou.exe"Added by the RBOT-AOB WORM!"
X Microsoft Automatic Updater Explorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System32 subfolder"
X Microsoft AutoUpdater svhost.exe"Added by the RBOT.QG WORM!"
X Microsoft Bool Value MV2.exe"Added by a variant of the RBOT WORM!"
X Microsoft boot system cfg32 actboost.exe"Added by the BROPIA.R WORM!"
U Microsoft Broadband Networking MSBNTray.exeMicrosoft Broadband Networking Tray Application
X Microsoft Cab Manager exec.exe"Affilred adware"
X Microsoft checker MsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Client mshost.exe"Added by the RBOT-AND WORM!"
X Microsoft Client Pc spoolsrv.exe"Added by the RBOT-AQM WORM!"
X Microsoft Client/Server Runtime Server Subsystem csrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Client/Server Runtime Server Subsystem csrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Command Line wincmd.exe"Added by a variant of the RBOT WORM!"
X Microsoft Conf Ldr sysconf.exe"Added by a variant of the SDBOT TROJAN!"
X Microsoft ConfgKeys wurmgrd32.exe"Added by the RBOT-ARX WORM!"
X Microsoft Config msconf.exe"Added by the RBOT.PV WORM!"
X Microsoft Config MSCONF.EXE"Added by the RBOT-LG WORM!"
X Microsoft Config 32 msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
X Microsoft Config 32bit mscnfg32.exe"Added by the RBOT-Z WORM!"
X Microsoft Config File config.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
X Microsoft Configoration Service msconfigs.exe"Added by the RBOT-ETT WORM!"
X Microsoft Configs 32 msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Configure 32 msgconfigre.exe"Added by a variant of the GAOBOT/AGOBOT WORM!"
X Microsoft Connection Manager Monitor cmmon.pif"Added by the RBOT-AKV WORM!"
X Microsoft Control Center crtl.exe"Added by the RBOT-VX WORM!"
X Microsoft Core Support MSxUP32.exe"Added by the RBOT-ANR WORM!"
X Microsoft Core Support [random filename]"Added by a variant of the RBOT TROJAN!"
X Microsoft Corp Updates wupdates.exe"Added by the RBOT-AUU WORM!"
X Microsoft Corporation [random filename]"Added by various VIRUSES
X Microsoft Corporation jview.exe"Added by the RBOT-AOD WORM!"
X Microsoft Crs Fix Serv wincrs.exe"Added by the SDBOT.BWF WORM!"
X Microsoft CSRSS32 Protocol csrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft CSRSS386 Protocol csrss386.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Cvrt mscvrt32.exe"Added by an unidentified VIRUS
X Microsoft Data Helper cihost.exe"Malware
X Microsoft Data Machine csdata32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Database Handler mssql32.exe"Added by the RANDEX.AX WORM!"
X Microsoft Datalog Application msdata.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DDE Control wupades.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DDEs Control Erun.pif"Added by the RBOT-AMU WORM!"
X Microsoft Debug Service dbgbgr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Decryption Technology Msfenoe.exe"Added by the SPYBOT-DG WORM!"
X Microsoft Desktop Manager msdesk32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Dev iexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Development Debugger msdev.exe"Added by a variant of the RBOT WORM!"
X Microsoft Device Manager msdevmgr32.exe"Added by the LATEDA.B TROJAN!"
X Microsoft Diagnostic [random filename]"Added by the ACEBOT TROJAN!"
X Microsoft Diagnostic msdiag32.exe"Added by the RBOT-UC WORM!"
X Microsoft Digital Clock msclock.exe"Added by the NACKBOT-D WORM!"
X Microsoft DirectX Spoolserv.exe"Added by the DINFOR WORM!"
X Microsoft DirectX rasmngr.exe"Added by a variant of the RBOT WORM!"
X Microsoft DirectX PDSched.exe"Added by the SDBOT.CN WORM!"
X Microsoft DirectX wuamgrd.exe"Added by the SDBOT.MY WORM!"
X Microsoft DirectX time123.exe"Added by the SDBOT.MD WORM!"
X Microsoft Directx directxat.exe"Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
X Microsoft DirktorWin [random filename]"Added by the SPYBOT.GEN3 TROJAN!"
X Microsoft DLL fumeta.exe"Added by the RBOT-AUG WORM!"
X Microsoft DLL Extensions SystemDll.exe"Added by the RBOT-ADV WORM!"
X Microsoft Dll Management windll.exe"Added by the RBOT-MT WORM!"
X Microsoft Dll Printer Manager dllpt.exe"Added by the SDBOT.BIH WORM!"
X Microsoft DLL Verifier file.exe"Added by the RBOT-AED WORM!"
X Microsoft DLL Verifier chkfile.exe"Added by the RBOT-AOC WORM!"
X Microsoft DLL Verifier csrssv.exe"Added by the RBOT-ATK WORM!"
X Microsoft DLLSet32 dllset32.exe"Added by the RBOT.OZ WORM!"
X Microsoft DNS Query msdns.exe"Added by a variant of the WOOTBOT WORM!"
X Microsoft Document krisp.exe"Added by the SDBOT-RQ WORM!"
X Microsoft Domain Controller mstc.exe"Added by the NUGACHE.A WORM!"
X Microsoft Driver faet.exe"Added by a variant of the RBOT WORM!"
X Microsoft Driver Control windrv.exe"Added by the SDBOT.FW WORM!"
X Microsoft Driver Manager mswindrv.exe"Added by the FORBOT-EZ WORM!"
X Microsoft driver update Mshome.exeAdded by the SDBOT.BL WORM!
X Microsoft Drivers WSconf.exe"Added by a variant of the SDBOT WORM!"
X Microsoft ErgoPack wserb32.exe"Added by the RBOT-RI WORM!"
X Microsoft EV32 Service MSev32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Event Engine EvtEngn.exe"Added by the RBOT-XV WORM!"
X Microsoft Excel msexcel.exe"Added by the RBOT-TQ WORM!"
X Microsoft Excell wuamngr32.exe"Added by the RBOT-QH WORM!"
X Microsoft Executing microsoft.exe"Added by the AGOBOT.UV WORM!"
X Microsoft Explorer svapache.exe"Added by the RBOT-VR WORM!"
X Microsoft Explorer explorer.scr"Added by the RBOT-ADH WORM!"
X Microsoft Explorer explorer.pif"Added by the SDBOT-ACX WORM!"
X Microsoft Explorer2 system.exe"Added by the IRCBOT.BS TROJAN!"
X Microsoft Explorer2 nome.exe"Added by the RANDEX.AA WORM!"
X Microsoft Explorer2 bitchbot.exe"Added by the SDBOT.EV WORM!"
X Microsoft EXPLOREXP Protocol explorexp.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Features ms32cfg.exe"Added by the RBOT.HO WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list