Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft Server Applacations wuauct1.exe"Added by a variant of the RBOT WORM!"
X Microsoft Server Applacations lsasss.exe"Added by the RBOT-AQQ WORM!"
X Microsoft Server Applacations Q8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
X Microsoft Server Applacations cli.exe"Added by the RBOT-GAQ WORM!"
X Microsoft Server Application Sound.exe"Added by the RBOT-NE WORM!"
X microsoft server base lass.exe"Added by a variant of the RBOT WORM!"
X Microsoft Server Process svhst32.exe"Added by the BCKDR-QHR BACKDOOR!"
X Microsoft Service microhost.exe"Added by the RBOT-LC WORM!"
X Microsoft Service winsvc.exe"Added by the SPYBOT-DB WORM!"
X Microsoft Service rundll.exe"Added by the POPO-A WORM! Note - this is NOT the Windows system file of the same name as described here"
X Microsoft Service 32 mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Service 32 sysddm32.exe"Detected by Kaspersky as the SDBOT.AKC TROJAN! See here"
X Microsoft Service Access Manager Access.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Microsoft Service Boot sboot.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Service Controller services.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X Microsoft Service Disk Cycle disksave.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Service Drivers System.exe"Added by a variant of the RBOT WORM!"
X Microsoft Service Drivers VSADNIM.exe"Added by a variant of the RBOT WORM!"
X Microsoft Service Execution Manager execute.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Microsoft Service firewall Manager firewall.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Service Host Manager 32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Service Host Process svchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""Help"" subfolder of the Winnt or Windows folder"
X Microsoft Service Information msnservices.exe"Added by the RBOT.ID WORM!"
X Microsoft Service Login Manager winlogin.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Service Manager service32.exe"Added by a variant of the RBOT WORM! See here"
X Microsoft Service Manager winsvc.exe"Added by a variant of the RBOT WORM! See here"
X Microsoft Service Pack WindowsSP.exe"Added by the RBOT-RF WORM!"
X Microsoft Service Pack2.1 svchost2.exe"Added by a variant of the RBOT WORM!"
X Microsoft Services lsserv.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Microsoft Services lssrv.exe"Added by the RBOT.CW WORM!"
X Microsoft Services services.exe"Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X Microsoft Services lsrv.exe"Added by the RBOT-BK WORM!"
X Microsoft Services svshost.exe"Added by the ALETS.B TROJAN!"
X Microsoft Services bsc32.exe"Added by the BDOOR-AW BACKDOOR!"
X Microsoft Services Smss32.exe"Added by the RBOT-AD WORM!"
X Microsoft Services svssshost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Services module.exe"Added by the LAVITS WORM!"
X Microsoft Services msmpserv.exe"Detected by Trend Micro as the IRCBOT.BKA TROJAN! See here"
X Microsoft Services Unitd MSU32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Servicez Manager servicemgrz.exe"Added by the RBOT-ASN WORM!"
X Microsoft Session Manager Subsystem smss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
X Microsoft Setup Initializazion localhost.exe"Added by a variant of the IRCBOT TROJAN!"
N Microsoft Sidewinder Game Controller Software SWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
X Microsoft Sinsup odjiwjf.exe"Added by the RBOT-DN WORM!"
X Microsoft Software sysinfo33.exe"Added by the RBOT.LS WORM!"
X microsoft software ****.exe [* = random char]Added by an unidentified WORM or TROJAN!
X Microsoft software cdaccess.exe"Added by the RBOT.ABK WORM!"
X Microsoft Software Update nmon.exe"Added by the RBOT.HZ WORM!"
X Microsoft Sound Driver sound32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Sound Technology winsound.exe"Added by the RBOT-AGG WORM!"
N Microsoft Sound Volume Tool mssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
X Microsoft Sounds soundman.exe"Added by the RBOT-GCI WORM!"
X Microsoft SourceSafe csrss.exe"Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Microsoft SpA Service msapps.exe"Added by the RBOT-VI WORM!"
X Microsoft SpA Service win32.exe"Added by the RBOT.ATS WORM!"
X Microsoft SpA Service Winupd32.exe"Added by the RBOT.LT WORM!"
X Microsoft Special offer infoebay.exe"Added by a variant of the RBOT WORM!"
X Microsoft Spool ** Service spool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
X Microsoft Spool Server for Win32 spoolsrv.exe"Added by the RANDEX.H WORM!"
X Microsoft Spool Svc spoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Spooler Services Spoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
X MicroSoft ssas3s1 SADASDA.exe"Detected by PCTools as the RBOT.URF WORM! See here"
X Microsoft SSISVRI32 Protocol ssisvri.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Standard Executions Library win32lib.exe"Added by the RBOT-AUK WORM!"
X Microsoft standard protector winsocks5.exeAdded by the SMALL.CF TROJAN!
X Microsoft standard protector [path to trojan]"Added by the STOX-C TROJAN!"
X Microsoft startup wmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
X Microsoft Stuff you know winslogin.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Sum32 sum32.exe"Added by the RBOT-YW WORM!"
X Microsoft Support sys32ms.exe"Added by the RBOT-AHI WORM!"
X microsoft support svchostt.exe"Added by the AGOBOT.AWN WORM!"
X Microsoft SVC mssvc.exe"Added by the BIFROSE-UQ TROJAN!"
X Microsoft Svchost local services winoem.exe"Added by the RBOT-FPE WORM!"
X Microsoft Svchost local services nzm23.exe"Added by the RBOT-GMC WORM!"
X Microsoft Svchost local services msnserver.exe"Added by the RBOT-GPM WORM!"
X Microsoft Syn Manager Manager.exe"Added by the SDBOT.BEF WORM!"
X Microsoft Synchronization Manager asgard.exe"Added by the SDBOT-AEA WORM!"
X Microsoft Synchronization Manager bot.exe"Added by the SDBOT.IH WORM!"
X Microsoft Synchronization Manager netscape.exe"Added by the RANDEX.AE WORM!"
X Microsoft Synchronization Manager slhost.exe"Added by the SDBOT.YH WORM!"
X Microsoft Synchronization Manager svhost.exe"Added by the SDBOT-PY WORM!"
X Microsoft Synchronization Manager WinLoginnn.exe"Added by the SPYBOT.FO WORM!"
X Microsoft Synchronization Manager winupdate.exe"Added by the SDBOT.ER WORM!"
X Microsoft Synchronization Manager xXx.exe"Added by the SDBOT-KZ WORM!"
X Microsoft Synchronization Manager ___synmgr.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
X Microsoft Synchronization Manager al.exe"Added by the OPTXPRO.132 TROJAN!"
X Microsoft Synchronization Manager win.exe"Added by the SDBOT.AK WORM!"
X Microsoft Synchronization Manager java.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Synchronization Manager svchosts.exe"Added by the SDBOT-LM WORM!"
X Microsoft Synchronization Manager winlogon32.exe"Added by the SDBOT.AEU WORM!"
X Microsoft Synchronization Manager svxhost.exe"Added by the SDBOT-ZU WORM!"
X Microsoft Synchronization Manager wincfg32.exe"Added by the SDBOT.DO WORM!"
X Microsoft Synchronization Manager screen.exe"Added by the SDBOT-ACO WORM!"
X Microsoft Synchronization Manager devldr32.exe"Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file"
X Microsoft Synchronization Manager explorer.exe"Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Microsoft Synchronization Manager firewire.exe"Added by the SDBOT-AFC WORM!"
X Microsoft Synchronization Manager wmedia.exe"Added by the SDBOT.BFC WORM!"
X Microsoft Synchronization Manager win932.exe"Added by the SDBOT.AH WORM!"
X MicroSoft sys32 sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
X MicroSoft sys3s1 h4ckn3t.exe"Detected by PCTools as the RBOT.QTY WORM! See here"
X Microsoft System msupdtm.exe"Added by the SPYBOT.PKC WORM!"
X Microsoft System mssys32.exe"Added by the PETTICK.A WORM!"
X Microsoft System sys.exe"Added by the RBOT.AKI WORM!"
X Microsoft System Administration system.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft System Backup [random filename]"Added by the RBOT-AGM WORM!"
X Microsoft System Checkup Cool.exe"Added by the DONK.B WORM!"
X Microsoft System Checkup Wnetlib.exe"Added by the DONK.C WORM!"
X Microsoft System Checkup dbnetlib.exe"Added by the DONK.L WORM!"
X Microsoft System Checkup Keymgr.exe"Added by the DONK.M WORM!"
X Microsoft System Checkup inetman.exe"Added by the DONK.O WORM!"
X Microsoft System Checkup ntsysmgr.exe"Added by the DONK.S WORM!"
X Microsoft System Checkup ntsysman.exe"Added by the SDBOT-QW WORM!"
X Microsoft System Checkup libsysmgr.exe"Added by the SDBOT-CAF WORM!"
X Microsoft System Checkup sysmgr.exe"Added by the SDBOT-OO TROJAN!"
X Microsoft System Checkup netapi32.exe"Added by the DONK-E WORM!"
X Microsoft System Checkup wnetmgr.exe"Added by the DONK.Q WORM!"
X Microsoft System Checkup libsys32.exe"Added by the SDBOT-ACK WORM!"
X Microsoft System Debug services32.exe"Added by the RBOT.AKH WORM!"
X Microsoft System DLL Services Configuration windir32.exe"Added by the SDBOT-ACY TROJAN!"
X Microsoft System File svchots.exe"Added by the RBOT.BYU WORM!"
X Microsoft System Firewall 2006.2 msmsgr.exe"Added by a variant of the SDBOT WORM!"
X Microsoft System Firewall 2006.2 msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility"
X Microsoft System Firewall 2006.2 reg32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft System Init mtmnr0.exe"Added by the SDBOT.BR TROJAN!"
X Microsoft System Monitor monsys.exe"Added by the IRCBOT-YV TROJAN!"
X Microsoft System Monitor system.exe"Detected by Trend Micro as the IRCBOT.AUT TROJAN! See here"
X Microsoft System NT svhost.exe"Added by the SDBOT.COU WORM!"
X Microsoft System Restore Configuration CBRSS.EXE"Added by a variant of the SPYBOT WORM!"
X Microsoft System Saver [path to worm]"Added by the RBOT.BSK WORM!"
X Microsoft System Security Agent MSTSA.EXE"Added by the RBOT.CCM WORM!"
X Microsoft System Service dnservice.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft System Service taskmgr1.exe"Detected by Kaspersky as the SDBOT.CSX TROJAN! See here"
X Microsoft System Service winIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft System Service Device mssdh.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft System Services msnmgsr.exe"Added by the KELVIR.K WORM!"
X Microsoft System Services msmsgr.exe"Added by the RBOT-ZH WORM!"
X Microsoft System Update sysupdate.exe"Added by the SDBOT.DG WORM!"
X Microsoft system Value sys57.exe"Added by a variant of the RBOT WORM!"
X Microsoft System32 Update cmsrg.exe"Added by the RBOT-GN WORM!"
X Microsoft task tray monitor ctray.exe"Added by a variant of the RBOT WORM!"
X Microsoft Task32 Protocol taskmgr32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Taskmanager Updater keyboard.exe"Added by the RBOT-ALU WORM!"
X Microsoft TCP Protocol wintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft TCP/IP Connection Monitor svchost32.exe"Added by the RBOT.KS WORM!"
X Microsoft Telecom Center tellecom.exe"Added by a variant of the RBOT WORM!"
X Microsoft Telecoma Center tellcoma.exe"Added by the RBOT-AWX WORM!"
X Microsoft Telecoms Center telcoms.exe"Added by the IRCBOT.GEN WORM!"
X Microsoft Telecoms Center xpfilesys.exeAdded by the RBOT.BCJ TROJAN!
X Microsoft Telecoms Center winupn.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Telecoms Center svcchost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Time Manager dveldr.exe"Added by the RBOT-HQ WORM!"
X MicroSoft Toolbar key.exe"Added by the RBOT-AEW WORM!"
X Microsoft Transfer File Server mtfs.exe"Added by the RBOT.AFE WORM!"
X Microsoft Tray [random filename]"Added by the DELF.BZ TROJAN!"
X Microsoft TTL Verifier msttl.exe"Added by the RBOT-GAP WORM!"
X Microsoft U wuamkopxp.exe"Added by the RBOT-AHC WORM!"
X Microsoft UMA Update MSuma32.exe"Added by the RBOT.FS WORM!"
X MICROSOFT UNPACCKER SYSTEM unpak32.exe"Added by a variant of the RBOT WORM!"
X MICROSOFT UNPACK SYSTEM winrarx.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updat3 mswkst32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Microsoft.exe"Added by the GAOBOT.AFJ WORM!"
X Microsoft Update mssmgrd.exe"Added by the SDBOT.JT WORM!"
X Microsoft Update mvsc.exe"Added by the SPYBOT.DAZ WORM!"
X Microsoft Update Isac.exe"Added by the RBOT-AU WORM!"
X Microsoft Update ascdl.exe"Added by the GAOBOT.SY WORM!"
X Microsoft Update automgr32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update mediap.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Microsoftx.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update msconfg.exe"Added by the RBOT.H WORM!"
X Microsoft Update Mslti32.exe"Added by the RBOT-LX WORM!"
X Microsoft Update muamgrd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Update navmgrd.exe"Added by the SDBOT.DP TROJAN!"
X Microsoft Update Smss32.exe"Added by the RBOT-CB WORM!"
X Microsoft Update sys32cfg.exe"Added by the RBOT.DR WORM!"
X Microsoft Update VPC32.EXE"Added by the AGOBOT.XM WORM!"
X Microsoft Update winsys32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update wuamgrd.exe"Added by the RBOT-LK WORM!"
X Microsoft Update wuammgr32.exe"Added by the RBOT-AW WORM!"
X Microsoft Update wudmate.exe"Added by the RBOT.AP WORM!"
X Microsoft Update msawindows.exe"Added by the GAOBOT.AFJ WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list