Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft Lsass Service wintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft LSASS386 Protocol scvhost32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft LV [path to file]"Added by the BDOOR-BDL BACKDOOR!"
X Microsoft Machine winjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft machine blah.exe"Added by a variant of the RBOT WORM!"
X Microsoft machine svchost.exe"Detected by Kaspersky as the RBOT.AEU TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
X Microsoft Machine Script iexplorersis.exe"Added by the RBOT-CMH WORM!"
X Microsoft Macro Protection SubSsy msacroprots386.exe"Added by the RBOT-KE WORM!"
X Microsoft Macro Protection Subsystems msmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Macro Protection Subsystems Msmacroprot32.exe"Added by the RBOT.KN WORM!"
X Microsoft Manage Services sychost.exe"Detected by Trend Micro as the SLENFBOT.AD WORM! See here"
X Microsoft Manage Services schost.exe"Detected by PCTools as the SLENFBOT.B WORM! See here"
X Microsoft Management lmas.exe"Added by the FORBOT-CZ WORM!"
X Microsoft Management Console lssas.exe"EasySearch adware"
X Microsoft Management Console [path to trojan]"Added by the SMUTSRCH-A TROJAN!"
X Microsoft Management Console lssas1.exe"Added by the DLOADR-AWD TROJAN!"
X Microsoft Manager msmanager.exe"Added by the MYTOB.LF WORM!"
X Microsoft Map PC mappc.exe"Added by a variant of the RBOT WORM!"
X Microsoft Mapped PC mappedpc.exe"Added by a variant of the RBOT WORM!"
X Microsoft media winmplayers.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Media Manager medman.exe"Added by the RBOT.EUZ WORM!"
X Microsoft Media player 9 msmedia32.exe"Added by the RBOT-ADO WORM!"
X Microsoft media services Iassd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft media services winmplayer.exe"Added by the RBOT.ZO WORM!"
X Microsoft MediaScope winmes.exe"Added by the RBOT-XU WORM!"
X Microsoft Memory Dumping Protocol memdump.exe"Detected by Kaspersky as the IRCBOT.BJK TROJAN! See here"
X Microsoft Memory Flow Cycle flowcycle.exe"Detected by PCTools as the IRCBOT.WAD TROJAN! See here"
X Microsoft Memory Flow Cycle flowcycles.exe"Detected by Kaspersky as the WAREZOV.AAK WORM! See here"
X Microsoft Message Machine msmesg32.exe"Added by the SPYBOT.BI WORM!"
X Microsoft Messenger Management Controls msmgmctl.exe"Added by the RBOT-APA WORM!"
X Microsoft messenger sd msngersd.exeAdded by an unidentified TROJAN!
X Microsoft Messenger Service msmsg32.exe"Added by the RBOT.BOK WORM!"
X Microsoft Messenger XP MSMSN32.exe"Added by the RBOT-ZP WORM!"
X Microsoft MicroP Protocol wdgmr32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Movie Maker Mmaker.exe"Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program"
X Microsoft MSGPLUS32 Protocol msgplus32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft MSN 7 Services msnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft MSN 7 Services msnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft MSN Messenger msnmnsgr.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft MSNGR32 Protocol msngr32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft msnseru msnseru.exe"Added by the RBOT-APB WORM!"
X Microsoft MsnST msnst32.exe"Added by a variant of the RBOT WORM!"
X Microsoft MSUPDATE SpoolSvc.exe"Added by the SXTB-A TROJAN!"
X Microsoft Neser Experience nese.exe"Added by the RBOT-YH WORM!"
X Microsoft NetMeeting Associates Inc. NetMeeting.exe"Added by the LOVGATE.AB WORM!"
X Microsoft Netview gesfm32.exe"Added by the RANDEX.C WORM!"
X Microsoft Netview mssvc32.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Microsoft Netview Component v5.1 msnv32.exe"Added by the RANDEX.F WORM!"
X Microsoft Network msnet.exe"Added by the MOCKBOT.A WORM!"
X Microsoft Network Networksystem.exe"Added by the SDBOT-AAI WORM!"
X Microsoft Network Daemon for Win32 Netd32.exe"Added by the SDBOT.R TROJAN!"
X Microsoft Network Host svc0host.exe"Added by the SDBOT-AEN WORM!"
X Microsoft Network Neighbourhood networknbh.exe"Added by the RBOT.DMN WORM!"
X Microsoft Network Services Controller mmsvc32.exe"Added by the NANPY-A WORM!"
X Microsoft Networking Agent For SP2 msnac32.exe"Added by the SPYBOT.PEN WORM!"
X Microsoft Nod32 Service nood32.exe"Added by the RBOT.EJP WORM!"
X Microsoft Norotn Anti Virus mnhpot.exe"Added by the RBOT-GRO WORM!"
X Microsoft Norton Antivirus norton.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft NotePad notepad.exe"Added by a variant of the RBOT WORM!"
X Microsoft NT Drivers ntdrv.exeAdded by the SDBOT.AJN TROJAN!
X Microsoft NT Update winexec32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Nvidia Video nvidia.exe"Added by a variant of the SDBOT WORM!"
N Microsoft Office Osa.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
N Microsoft Office Msoffice.exeAlternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
X Microsoft Office MSMSGR.exe"Added by the GAOBOT.BB WORM!"
N Microsoft Office Osa9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
X Microsoft Office lserv.exe"Added by the SDBOT.MH WORM!"
X Microsoft Office Microsoft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X Microsoft Office msoicons.exe"Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
X Microsoft Office Nxcao.exe"Added by the RBOT-ZE WORM!"
X Microsoft Office nxcxtpr.exe"Added by the RBOT-YG WORM!"
X Microsoft Office svxhost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Office msoffice32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Office msoff.exe"Added by the RAKER-C TROJAN!"
X Microsoft Office microsoft.exe"Added by the BANKER-VF TROJAN!"
X Microsoft Office msvcp.exe"Added by the AGENT-XK TROJAN!"
X Microsoft Office msmsgr.exe"Added by the GAOBOT.BB WORM!"
X Microsoft Office mdm.exe"Added by the IBOT-A TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is always located in %ProgramFiles%\Microsoft Shared. This one is located in %System%"
N Microsoft Office Fast Cache Fastboot.exe"Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled"
X Microsoft Office Monitor alg2k.exe"Added by the SDBOT-CZO WORM!"
X Microsoft Office Monitor aql32.exe"Added by the RBOT-GCY TROJAN!"
U Microsoft Office OneNote 2003 Quick Launch ONENOTEM.EXEONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work
X Microsoft Office Quick Launcher iau1.exe"Added by the DLOADR-AWD TROJAN!"
N Microsoft Office Shortcut Bar Msoffice.exeAlternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
X Microsoft Office Start winupdates.exe"Added by the GAOBOT.BC WORM!"
N Microsoft Office Startup Osa.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
N Microsoft Office Startup Osa9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
X Microsoft Office Studio scvhvst.exe"Added by the RANDEX.CST WORM!"
X Microsoft OfficeXP officeXP.exe"Added by the KILLAV.MA WORM!"
X Microsoft Oftice msmsgs.exe"Added by the IRCBOT.ALT WORM! Note - not to be confused with msmsgs.exe the well known MSN Instant Messaging application!"
X Microsoft Opeions IEXwe.exe"Added by a variant of the RBOT WORM!"
X Microsoft Outlook Express Protocol svchst.exe"Added by a variant of the RBOT WORM!"
X Microsoft Patch Update bootini.exe"Added by the RBOT-FMN WORM!"
X Microsoft PC Health Remote Assistance File Open & Save controls sfrcdlg32.exe"Added by the RBOT-AVY WORM!"
X Microsoft PCHealth32 [path to file]"Added by the NICE-A TROJAN!"
X Microsoft PCHealth32 NDDENB.exe"Added by the PWSYAHOO-A TROJAN!"
X Microsoft PCI Manager mspci.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Personal Firewalls bakw.exe"Added by the RBOT-KS WORM!"
X Microsoft Problem Doctor windr128.exe"Added by the SMALLTRO.EF TROJAN!"
X Microsoft Problem Doctor windr32.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
X Microsoft Problem Doctor windr64.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
X Microsoft Proc Driver32 msprc.exe"Added by a variant of the WOOTBOT WORM!"
X Microsoft Procedure Call MSPCALL.exe"Added by a variant of the RBOT WORM!"
X Microsoft Process Manager process32.exe"Added by the CHECKOUT WORM! See here"
X Microsoft Profile Manager profile.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft PSTCP32 Data pstcp32.exe"Added by a variant of the RBOT WORM!"
X Microsoft QMGR msnqmgr.exe"Added by the IRCBOT-S TROJAN!"
X Microsoft RDLL sysconf32.exe"Added by a variant of the SDBOT TROJAN!"
X Microsoft Redirect [path to file]"Added by the BANKER-FW TROJAN!"
X Microsoft Redirect systen.exe"Added by the BANCOS-FO TROJAN!"
X Microsoft Regestry Edit Manager regedit.exe"Detected by Trend Micro as the SHEUR.HC WORM! See here"
X Microsoft Regestry Manager regedit32.exe"Added by a variant of the IRCBOT.ARD WORM!"
X Microsoft Regestry Manager registry32.exe"Added by the IRCBOT.ARD WORM!"
X Microsoft Registro svchostt.exe"Added by the BANCOS-DH TROJAN!"
X Microsoft Registry csrse.exe"Added by the RBOT-PC WORM!"
X MicroSoft Remote Secure Service MSRSS.exe"Added by a variant of the RBOT WORM!"
X Microsoft Restore scrgrd.exe"Added by the SPYBOT.BR WORM!"
X Microsoft Router Manager linksys.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Router Manager router.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Rundll windos.exe"Added by the SDBOT-WF WORM!"
X Microsoft Runtime CfgDll32.exe"Added by the RANDEX.BD WORM!"
X Microsoft Safe Mode Manager safemode.exe"Detected by Trend Micro as the IRCBOT.HM TROJAN! See here"
X Microsoft Scanreg microsoftscanreg.exe"Added by the FRANRIV.A WORM!"
X Microsoft SCVHOST32 Protocol scvhost32.exe"Added by a variant of the RBOT WORM!"
X Microsoft sddcE Contol taskmnegr.exe"Added by the RBOT-AUM WORM!"
X Microsoft sdk temp sdktemp.exe"Added by the RBOT-ANP WORM!"
X Microsoft SDKP3 mswinsdq.exe"Added by the RBOT-ARY WORM!"
X Microsoft Secure Messenger.NET Service securitychk.exe"Added by the SDBOT.VT WORM!"
X Microsoft Security winService.exe"Added by a variant of the RBOT WORM!"
X Microsoft security adviser mssadv.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Security Center savservices.exe"Added by the RBOT-ANU WORM!"
X Microsoft Security Center wcsntfy.exe"Added by the SDBOT.BYD WORM!"
X Microsoft Security Controlers fxsecues.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Security GManagers [random filename]"Added by a variant of the SDBOT WORM!"
X Microsoft Security Hot Fix Update mshotfix.exe"Affilred adware"
X Microsoft Security Management winnt.exe"Added by the RBOT-MQ WORM!"
X Microsoft Security Management winserv.exe"Added by the RBOT-MJ WORM!"
X Microsoft Security Management winamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
X Microsoft Security Management wuauct1.exe"Added by a variant of the RBOT WORM!"
X Microsoft Security Management bling.exe"Added by the RBOT.XL WORM!"
X Microsoft Security Management sp2fix.exe"Added by the RBOT.UB WORM!"
X Microsoft Security Manager winamp.exe"Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
X Microsoft Security Monitor Process mssmp.exe"Added by the RBOT-FUB WORM!"
X Microsoft Security Monitor Process mnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Security Monitor Process msmp.exe"Detected by Trend Micro as the RBOT.GKQ WORM! See here"
X Microsoft Security Monitor Process mssm32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Security Monitor Process lsas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Security Monitor Process msword.exe"Detected by Kaspersky as the VIRUT.P VIRUS! See here"
X Microsoft Security Monitor Process service.exe"Detected by PCTools as the DELF.BERW BACKDOOR! See here"
X Microsoft Security Monitor Process svcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Security Monitor Process windowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Security Monitor Process [random filename]"Added by variants of the RBOT WORM! See here"
X Microsoft Security Monitor Process com.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Security Monitor Process exel.exe"Detected by Trend Micro as the SDBOT.AFX BACKDOOR! See here"
X Microsoft Security Monitor Process firewall.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Security Monitor Process flash.exe"Detected by Trend Micro as the EGGDROP.EE BACKDOOR! See here"
X Microsoft Security Monitor Process hel.exe"Detected by Kaspersky as the EGGDROP.V BACKDOOR! See here"
X Microsoft Security Monitor Process HelpMe.exe"Detected by Kaspersky as the VB.BJO TROJAN! See here"
X Microsoft Security Monitor Process kar.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Security Monitor Process lindicracker.exe"Detected by Trend Micro as the BIFROSE.GR BACKDOOR! See here"
X Microsoft Security Monitor Process mail.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Security Monitor Process mmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Security Monitor Process mssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Security Monitor Process mssmpi32.exe"Added by a variant of the RBOT WORM! See here"
X Microsoft Security Monitor Process nitty.exe"Detected by Kaspersky as the RBOT.AEU BACKDOOR! See here"
X Microsoft Security Monitor Process ofice.exe"Detected by Kaspersky as the VIRUT.N VIRUS! See here"
X Microsoft Security Monitor Process point.exe"Detected by Trend Micro as the IRCBOT.AVP BACKDOOR! See here"
X Microsoft Security Monitor Process princ.exe"Detected by Trend Micro as the HUPIGON.WTL TROJAN! See here"
X Microsoft Security Monitor Process web.exe"Detected by Kaspersky as the EGGDROP.V BACKDOOR! See here"
X Microsoft Security Monitor Process winsys32.exe"Detected by Kaspersky as the VIRUT.N VIRUS! See here"
X Microsoft Security Monitor Process winsyss32.exe"Detected by Kaspersky as the RBOT.AEU BACKDOOR! See here"
X Microsoft Security Monitor Process word.exe"Detected by Trend Micro as the EGGDROP.DC BACKDOOR! See here"
X Microsoft Security Panager [filename]"Added by the RBOT-ANL WORM!"
X Microsoft Security Panagers [random filename]"Added by the RBOT-AIG WORM!"
X Microsoft Security Panagers zzoboony.exe"Added by the RBOT-AOI WORM!"
X Microsoft Security Process wininit.exe"Added by the RBOT-FKM WORM!"
X Microsoft Security System mssecsys.exe"Added by the IRCBOT-WJ TROJAN!"
X Microsoft Security Update security32.exe"Added by the DELF-JJ TROJAN!"
X Microsoft Server rserv.exe"Added by the AGOBOT.AVS WORM!"
X Microsoft Server Applacations msnmsg.exe"Added by the AGOBOT.BBM WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list