Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft Diagnostic [random filename]"Added by the ACEBOT TROJAN!"
X Microsoft Diagnostic msdiag32.exe"Added by the RBOT-UC WORM!"
X Microsoft Digital Clock msclock.exe"Added by the NACKBOT-D WORM!"
X Microsoft Digital Cryptors mdigits.exe"Added by the SDBOT.LM WORM!"
X Microsoft DirectX Spoolserv.exe"Added by the DINFOR WORM!"
X Microsoft DirectX rasmngr.exe"Added by a variant of the RBOT WORM!"
X Microsoft DirectX PDSched.exe"Added by the SDBOT.CN WORM!"
X Microsoft DirectX wuamgrd.exe"Added by the SDBOT.MY WORM!"
X Microsoft DirectX time123.exe"Added by the SDBOT.MD WORM!"
X Microsoft Directx directxat.exe"Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
X Microsoft Directx click directxclick.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft Directx clicks directxclickers.exe"Added by the RBOT-GHT WORM!"
X Microsoft Directx push directxpushup.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft Directxsp directxbt.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft Directxspnew directxnew.exe"Added by a variant of the RBOT-GHT WORM!"
X Microsoft DirktorWin [random filename]"Added by the SPYBOT.GEN3 TROJAN!"
X Microsoft Disk Scanner scansdisk.exe"Added by the WOOTBOT.DT WORM!"
X Microsoft DLL fumeta.exe"Added by the RBOT-AUG WORM!"
X Microsoft Dll runapidll.exe"Added by the RBOT-GRG WORM!"
X Microsoft DLL Authentification dllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Extensions SystemDll.exe"Added by the RBOT-ADV WORM!"
X Microsoft dll Host Service wkssr.exe"Added by a variant of the SDBOT WORM!"
X Microsoft DLL Host Service dllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Host Service svcdllhst.exe"Added by the AGENT.EAK TROJAN!"
X Microsoft dll Host Service svchost.exe"Detected by Kaspersky as the RBOT.BMS WORM! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
X Microsoft DLL Library winlib32.exe"Added by the ATNAS.A WORM!"
X Microsoft Dll Management windll.exe"Added by the RBOT-MT WORM!"
X Microsoft Dll Manager microsoft32dll.exe"Detected by Trend Micro as the SHEUR.LH TROJAN! See here"
X Microsoft DLL Monitor dllmon32.exe"Detected by Trend Micro as the AGENT.WP WORM! See here"
X Microsoft DLL Monitor dllmon64.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Monitor dllmonitor.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Dll Printer Manager dllpt.exe"Added by the SDBOT.BIH WORM!"
X Microsoft DLL Service servicedll.exe"Detected by Trend Micro as the RCBOT.OX TROJAN! See here"
X Microsoft DLL Service svcdll.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft DLL Source dllsrc.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft DLL Verifier file.exe"Added by the RBOT-AED WORM!"
X Microsoft DLL Verifier chkfile.exe"Added by the RBOT-AOC WORM!"
X Microsoft DLL Verifier csrssv.exe"Added by the RBOT-ATK WORM!"
X Microsoft DLL Verifier mscon.exe"Added by the SDBOT.EAH WORM!"
X Microsoft DLL Verifier winavguard.exeAdded by the SDBOT.AAD WORM!
X Microsoft DLLSet32 dllset32.exe"Added by the RBOT.OZ WORM!"
X Microsoft DNS Query msdns.exe"Added by a variant of the WOOTBOT WORM!"
X Microsoft DNSx mdnex.exe"Added by the DELBOT-AI WORM!"
X Microsoft Document krisp.exe"Added by the SDBOT-RQ WORM!"
X Microsoft Domain Controller mstc.exe"Added by the NUGACHE.A WORM!"
X Microsoft Driver faet.exe"Added by a variant of the RBOT WORM!"
X Microsoft Driver Control windrv.exe"Added by the SDBOT.FW WORM!"
X Microsoft Driver Manager mswindrv.exe"Added by the FORBOT-EZ WORM!"
X Microsoft driver update Mshome.exeAdded by the SDBOT.BL WORM!
X Microsoft Drivers WSconf.exe"Added by a variant of the SDBOT WORM!"
X Microsoft ErgoPack wserb32.exe"Added by the RBOT-RI WORM!"
X Microsoft EV32 Service MSev32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Event Engine EvtEngn.exe"Added by the RBOT-XV WORM!"
X Microsoft Excel msexcel.exe"Added by the RBOT-TQ WORM!"
X Microsoft Excele msmsgs.exe"Detected by Kaspersky as the AGENT.XFO TROJAN! See here"
X Microsoft Excell wuamngr32.exe"Added by the RBOT-QH WORM!"
X Microsoft Executing microsoft.exe"Added by the AGOBOT.UV WORM!"
X Microsoft Explorer svapache.exe"Added by the RBOT-VR WORM!"
X Microsoft Explorer explorer.scr"Added by the RBOT-ADH WORM!"
X Microsoft Explorer explorer.pif"Added by the SDBOT-ACX WORM!"
X Microsoft Explorer explorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft Explorer Service msexplore.exe"Detected by Kaspersky as the IRCBOT.AYB TROJAN! See here"
X Microsoft explorer Update internal.exeAdded by an unidentified WORM or TROJAN!
X Microsoft Explorer2 system.exe"Added by the IRCBOT.BS TROJAN!"
X Microsoft Explorer2 nome.exe"Added by the RANDEX.AA WORM!"
X Microsoft Explorer2 bitchbot.exe"Added by the SDBOT.EV WORM!"
X Microsoft EXPLOREXP Protocol explorexp.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Features ms32cfg.exe"Added by the RBOT.HO WORM!"
X Microsoft Features msie.exe"Added by a variant of the RBOT WORM!"
X Microsoft File Demand Manager wmgrdf.exe"Added by a variant of the RBOT WORM!"
N Microsoft Find Fast Findfast.exeResource hog from older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier
X Microsoft Firewall firewallsp2.exe"Added by the RBOT-MC WORM!"
Y MICROSOFT FIREWALL CLIENT ISATRAY.EXE"MS Internet Security and Acceleration Server - see here"
X Microsoft FixUp pevblbvr.exe"Added by the RBOT.DWK WORM!"
X Microsoft FixUp wnpzjpuw.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Games gamemanager.exe"Added by the SPYBOT.AHQ WORM!"
X Microsoft Generic Update Manager wupdate.exe"Added by the RBOT-AWC TROJAN!"
X Microsoft Genetic Procress svchost.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Genuine Logon msnmsg.exe"Added by the IRCBOT-XH WORM!"
X Microsoft Genuine Logon svchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X MicroSoft Getway Dire [random filename]"Detected by Trend Micro as the IRCBRUTE.AM WORM! See here"
X MicroSoft Getway mqbol [12 random letters].exe"Detected by Trend Micro as the RBOT.GBA WORM! See here"
X Microsoft Gina V Encryption MSGINAV.EXEAdded by an unidentified VIRUS WORM or TROJAN!
N Microsoft Greetings Reminder MHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
N Microsoft Greetings Reminders MHPRMIND.EXEMicrosoft Home Publishing greetings reminder
N Microsoft Greetings Workshop Reminder Gwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
X Microsoft HDCP for NT msdhcp.exe"Added by a variant of the RBOT WORM!"
X Microsoft HDCP for NT and Win9x msdhcprs.exe"Added by a variant of the PEERBOT WORM!"
X Microsoft Help svh0st.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Help Support mshelp32.exe"Addded by the KELVIR-BF WORM!"
X Microsoft Help SVC msnmngr.exe"Added by the SDBOT-PQ WORM!"
X Microsoft Help System mshelp32.exe"CoolWebSearch parasite variant"
X Microsoft Host Protocol svhost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Hosting Service WINHOSTING.EXE"Added by the RBOT.AEV WORM!"
X Microsoft Hosts Service Isass.exe"Added by a variant of the RBOT WORM!"
U microsoft hotmail monitor mshotmon.exe"Added by the MYTOB-FL WORM!"
X Microsoft hren1 mmhren1.exeAdded by a variant of the AGENT.IWW TROJAN!
X Microsoft Hyptertext Helper mshtha.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft IDCN mshe1p.exeAdded by an unidentified TROJAN!
X Microsoft IE Iexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Microsoft IE Execute shell IEExec.exe"Added by the ALADINZ.N TROJAN!"
X MicroSoft IE Sasser ISASS.EXE"Added by the SDBOT.MX WORM!"
X Microsoft IIS syshost.exe"Added by the FRANCETTE WORM!"
X Microsoft IIS [filename]"Added by the FRANCETTE-S WORM!"
X Microsoft Inc. iexplorer.exe"Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Microsoft Inc. iexplorer.exe…"Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Microsoft Incroporate mfs.exe"Added by the RBOT-ANF WORM!"
X Microsoft Inet Xp.. teekids.exe"Added by the BLASTER.C WORM!"
X Microsoft Information Check microsoft.exe"Added by the IRCBOT.AUH TROJAN!"
X Microsoft Initialization Service initsvc.exe"Detected by Trend Micro as the IRCBOT.AXK BACKDOOR! See here"
X Microsoft Initialization Services initserv.exe"Added by the IRCBOT-ABO TROJAN!"
X Microsoft Install Shield Services rundll64"Added by the RBOT-FSH WORM!"
X Microsoft Installshield nundll32.exe"Added by the AGOBOT-AHZ WORM!"
X Microsoft Instant Messenger msngmsngr32.exe"Added by the SPYBOTER.GEN TROJAN!"
X Microsoft Int Service MsIntSrv.exe"Added by a variant of the RBOT WORM!"
U Microsoft Intellitype Pro speedkey.exeAdditional keyboard shortcuts on MS programmable keyboard
X Microsoft Internal AntiVirus Systems dIlhost.exe"Added by the RBOT-AEV WORM!"
X Microsoft Internel Corporat netvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Internel Corporat smbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Internet expl0rer.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Internet windows32.exe"Added by the SDBOT-F WORM!"
X Microsoft Internet wincfg16.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Internet Acceleration Utility iau.exe"EasySearch adware"
X Microsoft Internet Acceleration Utility [path to file]"Added by the AGENT-CX TROJAN!"
X Microsoft Internet Acceleration Utility [path to trojan]"Added by the SMUTSRCH-A TROJAN!"
X Microsoft Internet Antivirus Protection antivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
X Microsoft Internet Dumping Protocol inetdump.exe"Detected by Kaspersky as the IRCBOT.BLL TROJAN! See here"
X Microsoft Internet Exp iiexplorer.exe"Added by the RBOT-KX WORM!"
X Microsoft Internet Explorer iexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Microsoft Internet Explorer iexplorer.exe"Added by the SDBOT-XN
X Microsoft Internet Explorer crsys32.exe"Added by the RBOT.UZ WORM!"
X Microsoft Internet Explorer movies.exe"Added by the BANCOS-DZ TROJAN!"
X Microsoft Internet Explorer svzhost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Internet Explorer mccagent.exe"Added by the DLOADER-UD TROJAN!"
X Microsoft Internet Explorer sysini.exe"Added by the DELF-LN TROJAN!"
X Microsoft Internet Explorer svchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""drivers"" subfolder"
X Microsoft Internet Explorer lEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
X Microsoft Internet Explorer Manager ie.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Internet Explorer Update ieupdate.exe"Detected by Trend Micro as the SHEUR.MH WORM! See here"
X Microsoft Internet Firewall firewall.exe"Detected by PCTools as the IRCBOT.BMD TROJAN! See here"
X Microsoft Internet Firewall Manager GMT16.exe"Added by the RANDEX.AT WORM!"
X Microsoft Internet Firewall Update updater.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Internet Services Smss32.exe"Added by the RBOT.MS WORM!"
X Microsoft Internet Syncing inetsync.exe"Detected by Kaspersky as the IRCBOT.BLL TROJAN! See here"
X Microsoft Intrenet Explorer goaw.pif"Added by the RBOT-API WORM!"
X Microsoft Intrenet Explorer Soundsyst.exe"Added by the RBOT-AQU WORM!"
X Microsoft Intrenet Explorer cnsg.pif"Added by the RBOT-ARO WORM!"
X Microsoft Intrenet Explorer wcumrg.exe"Added by the SDBOT-AFD WORM!"
X Microsoft IPC system.exe"Added by the NULLBOT TROJAN!"
X Microsoft IPC svshost.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Microsoft IT Update win64.exe"Added by the RBOT.GA WORM!"
X Microsoft IT Update [random filename]"Added by a variant of the RBOT WORM!"
X Microsoft IT Update IEserv.exe"Added by a variant of the RBOT WORM!"
X Microsoft IT Update msupdate.exe"Added by a variant of the RBOT WORM!"
X Microsoft IT Update winn43.exe"Added by a variant of the RBOT WORM!"
X Microsoft IT Update svchsst.exe"Added by the RBOT-DH WORM!"
X Microsoft IT Update win43.exe"Added by the RBOT-SA WORM!"
X Microsoft IT Update windows.exe"Added by the RBOT-JM WORM!"
X Microsoft IT Update winsyst32.exe"Added by the RBOT-FC WORM!"
X Microsoft IT Update Rhost32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Java Virtual Machine winscr32.exe"Added by a variant of the WOOTBOT WORM!"
X Microsoft Java Virtual Machine MsConfiG.exe"Added by the FORBOT-DV WORM!"
X Microsoft Java Virtual Machine msjvm.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Java Virtual Machine javavm.exe"Added by a variant of the RBOT WORM!"
X Microsoft Java Windows Update [filename]"Added by the RBOT-DZ WORM!"
X Microsoft JavaVM msjarun.exe"Added by the RBOT-JW WORM!"
X Microsoft Kernel Windows_kernel32.exe"Added by the NETSKY.AE WORM!"
X Microsoft Keyboard Enhance 2.0. iasrecst.exe"Added by the BCKDR-QIL TROJAN!"
X Microsoft Keyboard Enhance V2.0 iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
X Microsoft Kinetik Svc msftksvc.exe"Detected by Trend Micro as the AGENT.AGDO TROJAN! See here"
X Microsoft LAN32 Protocol lanXp.exe"Added by the RBOT-SS WORM!"
X MicroSoft Legal Syst3m32 Syst3m32.exe"Detected by PCTools as the RBOT.UYL WORM! See here"
X Microsoft Lmhosting Service lmhosts.exe"Added by the RBOT-RC WORM!"
X Microsoft Locals 332 [random filename]"Added by the RBOT-KU WORM!"
U Microsoft Location Finder LocationFinder.exe"Microsoft Location Finder ""is a client-side application that turns a regular WiFi enabled laptop Tablet or PC into a location determining device without the addition of any separate hardware"""
X Microsoft Login winlogin.exe"Added by the RBOT-AJP WORM!"
X Microsoft LSA layer MSLSA32.exe"Added by the RBOT-AKZ WORM!"
X Microsoft Lsass Center Isass.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Lsass Center telecomes.exe"Added by a variant of the RBOT WORM!"
X Microsoft Lsass Manager lsass.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list