Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Microsoft Update Machine winupdte.exe"Added by the RBOT-GKL WORM!"
X Microsoft Update Machine jkfrnz.exe"Added by the RBOT-GOZ WORM!"
X Microsoft Update Machine wlimyc.exe"Added by the RBOT-GQN WORM!"
X Microsoft Update Machine jkydxg.exe"Detected by Kaspersky as the RBOT.AEA BACKDOOR! See here"
X Microsoft Update Machine opmmve.exe"Detected by Kaspersky as the KOLABC.DES WORM! See here"
X Microsoft Update Machine paxrxo.exe"Detected by McAfee as the PUSHBOT.A WORM! See here"
X Microsoft Update Machine psmszw.exe"Detected by Trend Micro as the KOLABC.CC WORM! See here"
X Microsoft Update Machine syadpo.exe"Detected by Kaspersky as the CIADOOR.GN BACKDOOR! See here"
X Microsoft Update Machine systemi.exe"Detected by McAfee as the PUSHBOT.A WORM! See here"
X Microsoft Update Machine thvfyq.exe"Detected by Kaspersky as the RBOT.AEA BACKDOOR! See here"
X Microsoft Update Machine ubthec.exe"Detected by Kaspersky as the AGENT.AWZ TROJAN! See here"
X Microsoft Update Manager WINRLS.EXE"Added by the RBOT-AF WORM!"
X Microsoft Update Manager svshost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Manager scvhost.exe"Added by the AGOBOT.AXJ WORM!"
X Microsoft Update Manager scvideo.exe"Added by the SDBOT-CVP TROJAN!"
X Microsoft Update Mechene Updatez.exe"Added by the RBOT-GI WORM!"
X Microsoft Update Module rundll24.exe"Added by the RBOT-PS WORM!"
X Microsoft Update Process wmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
X Microsoft Update Security Patch mssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
X Microsoft Update Server mssrv.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Microsoft Update Service csrss32.exe"Added by the AGOBOT-HC WORM!"
X Microsoft Update Service mswin32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft update service systemm.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Update SERVICE phqghum.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Service msupdate.pif"Added by the RBOT-AQB WORM!"
X Microsoft Update Services wcsnfty.exe"Added by the RBOT-AGK WORM!"
X Microsoft Update Services wsnfty.exe"Added by the RBOT-AFU WORM!"
X Microsoft Update Time wuam.exe"Added by the RBOT-M WORM!"
X Microsoft Update USB2 wuammgrd32.exe"Added by the RBOT-ADT WORM!"
X Microsoft Update v2.6 lxxex.exe"Added by a variant of the RBOT WORM!"
X Microsoft Update Win32a winupdate32a.exe"Added by the RBOT-LO WORM!"
X Microsoft Update Win32x winupdate32x.exe"Added by the RBOT-AJN WORM!"
X Microsoft Updater Winsys32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updater msconsole.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Updater svhost.exe"Detected by Kaspersky as the AGENT.CDF TROJAN! See here"
X Microsoft Updater vbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Updater wuamgrds.exe"Added by the RBOT.A WORM!"
X Microsoft Updater Resources WinFixd32.exe"Added by the SPYBOT.CA WORM!"
X Microsoft UPDATER32 lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
X Microsoft UPDATER32 LSASS32.EXE"Added by the RANDEX.AR WORM!"
X Microsoft Updaters tskmgr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updaters sysconfigs.exe"Added by the RBOT-DF TROJAN!"
X Microsoft Updaters Pros WINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
X Microsoft Updates systemc32.exe"Added by the RBOT-GR WORM!"
X Microsoft Updates wkssvr.exe"Added by the RBOT.R WORM!"
X Microsoft Updates wkssvrs.exe"Added by the RBOT-EB WORM!"
X Microsoft Updates wuamgrd.exe"Added by the RBOT-CO WORM!"
X Microsoft Updates wtemp32.exe"Added by the RBOT-AHQ WORM!"
X Microsoft Updates svehost.exe"Added by the RBOT-GRW WORM!"
X Microsoft Updates svshost.exe"Added by the AGOBOT-AIW WORM!"
X Microsoft Updates svdhost.exe"Added by the RBOT-GVH WORM!"
X Microsoft Updates service.exe"Detected by Kaspersky as the POISON.HPT BACKDOOR! See here"
X Microsoft Updates 2 USB wgafixer.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updates 5 USB sp3fixer.exe"Added by the RBOT-ADS WORM!"
X Microsoft Updates Resources WinFixIDs.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updating navguard.exe"Added by the RBOT.HW WORM!"
X Microsoft Updating syswr.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updating wuamguards.exe"Added by the RBOT-BY WORM!"
X Microsoft Updating Client websvc.exe"Added by the RBOT.AQ WORM!"
X Microsoft Updating Machine sysc0de.exe"Added by the RBOT.RB WORM!"
X Microsoft Updatting miroupdate.exe"Added by a variant of the RBOT WORM!"
X Microsoft Updote [random filename]"Added by the RBOT-ARC WORM!"
X Microsoft UpMachine doezs.exe"Added by the RBOT.BCT WORM!"
X Microsoft upnp Update msie.exe"Added by the RBOT-LQ WORM!"
X Microsoft uptime Service sysuptime.exe"Added by the RBOT-ACG WORM!"
X Microsoft uptime Service sycuptime.exe"Added by the RBOT-AHY WORM!"
X Microsoft UpToDate Driver (32-bits) [random filename].exe"Added by the SPYBOT.LXJ WORM!"
X Microsoft Urlmon urlmon.exe"Added by the AGENT-GOO TROJAN!"
X Microsoft USB2 Driver crmss.exe"Added by the RBOT-VK WORM!"
X Microsoft usnsvc Service usnsvc.exe"Added by a variant of the KOBOT-C WORM!"
N Microsoft Utility Startup OSA9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
X Microsoft Values igfkishc.exe"Added by the RBOT-GLO WORM!"
X Microsoft Vertupdate MSvert32.exe"Added by the MYTOB-CY WORM!"
X Microsoft Video Capture Controls MSsrvs32.exe"Added by the SDBOT-AAK WORM!"
X Microsoft Video Controls tskmsgr.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Viewer Monitor Manager viewmon.exe"Detected by Trend Micro as the XPAK.A TROJAN! See here"
X Microsoft Virtual Service Manager vservice32.exe"Detected by Trend Micro as the MSNWORM.T WORM! See here"
X Microsoft Virual Machine sms.exe"Added by the RBOT-SP WORM!"
X Microsoft Vista Upgrade Validation Service cfmon.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Microsoft Visual Application vpcrtf.exe"Added by the IRCBOT-XJ TROJAN!"
X Microsoft Visual SourceSafe services.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X Microsoft Visual SourceSafe winlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
X MicroSoft Visual SP2 igfxsrvc32.exe"Detected by Trend Micro as the SDBOT.GAV WORM! See here"
X Microsoft Visual Studio plscdksxg.exe"Added by the RBOT-AWV WORM!"
X Microsoft Visual Studio VSA varpc32.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Web CP Manager webcp32.exe"Added by a variant of the SDBOT WORM! See here"
X Microsoft Web Device wdevice.exe"Added by a variant of the SDBOT WORM!"
X Microsoft web update webmsn.exe"Added by the RBOT-EMQ WORM!"
U Microsoft Webserver svctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
X Microsoft Win Corp TLS Verification mswintls.exe"Added by the RBOT-GCT WORM!"
X Microsoft WIN32 DOS MSdos32.exe"Added by a variant of the SDBOT WORM!"
X Microsoft WIN32 Security MSsec32.exe"Added by the RBOT-DOQ TROJAN!"
X MicroSoft Wind0ws Updater winsupdater.exe"Added by a variant of the RBOT WORM!"
X MicroSoft Window Updater winsupdater.exe"Added by the RBOT-ZZ WORM!"
X Microsoft Windows mstask0.exe"Added by the SDBOT.FQ WORM!"
X Microsoft Windows atup"Added by a variant of the RBOT WORM!"
X Microsoft Windows Microsoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X Microsoft Windows explorar.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows [path to file]"Added by the BDOOR-LI BACKDOOR!"
X Microsoft Windows bootini.exe"Added by the VANEBOT-K WORM!"
X Microsoft Windows Kernel.exe"Added by the EDIBARA-A VIRUS!"
X Microsoft Windows Kernel.vbs"Added by the EDIBARA-A VIRUS!"
X Microsoft Windows pwjbvphi.exe"Added by the RBOT-GQK WORM!"
X Microsoft Windows (D) iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
X Microsoft Windows 128bit Subsystem system12.exe"Added by the RANCK-CZ TROJAN!"
X Microsoft Windows 16Bit mswinn16.exe"Added by a variant of the SPYBOT WORM!"
X Microsoft Windows 2000 Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
X Microsoft Windows 32 Update win32update.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Windows 32Bit mswinn32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows 64 Bit mswin32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Adapter 5.1.3214 [worm filename].exe"Detected by Trend Micro as the STRAT.GEN-3 WORM! See here"
X Microsoft Windows Client Firewall msclt.exe"Added by the VANEBOT-F WORM!"
X Microsoft Windows Communicator for NT/XP wincomm.exe"Added by the RBOT.ATH WORM!"
X Microsoft Windows Config 32 win32conf.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Control mswctl32.exe"Added by the RBOT.JP WORM!"
X Microsoft Windows CSRSS csrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Microsoft Windows DHCP ___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
X Microsoft Windows DLL 32-BIT msncheck32.exe"Added by the SDBOT-XX WORM!"
X Microsoft Windows DLL Services mwindll.exe"Added by the SDBOT-VX WORM!"
X Microsoft Windows DLL Services Configuration newdll.exe"Added by the SDBOT-ZR WORM!"
X Microsoft Windows DLL Services Configuration newdll2.exe"Added by the SDBOT-ABD WORM!"
X Microsoft Windows DLL Services Configuration poker.exe"Added by the SDBOT-ZY WORM!"
X Microsoft Windows DLL Services Configuration poker3.exe"Added by the SDBOT-AAH WORM!"
X Microsoft Windows DLL Services Configuration proxy.exe"Added by the SDBOT-ZL WORM!"
X Microsoft Windows DLL Services Configuration windir32.exe"Added by the SDBOT.BHF WORM!"
X Microsoft Windows DLL Services Configuration windir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
X Microsoft Windows DLL Services Configuration windll32.exe"Added by the SDBOT.BHD WORM!"
X Microsoft Windows DLL Services Configuration winDSL.exe"Added by the SDBOT-ZG WORM!"
X Microsoft Windows DLL Services Configuration dllmanager32.exe"Added by the SDBOT-BTU WORM!"
X Microsoft Windows DLLHandler bitpaint.exe"Added by the SDBOT.AHG WORM!"
X Microsoft Windows Drivers windrv.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows DVR windvr.exe"Added by the RBOT-AXD WORM!"
X Microsoft Windows Expl0rer expl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Windows Explorer iexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Microsoft Windows Explorer explorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
X Microsoft Windows Express Microsoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
X Microsoft Windows Express websploit.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Windows Express windowslogonb.exe"Detected by PCTools as the SDBOT.ABOO WORM! See here"
X Microsoft Windows Files Loader cgy32win.exe"Added by the RBOT-AXR WORM!"
X Microsoft Windows Game Updater msgame32.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows GUI Windowz.exe"Added by the RANDEX.AEV WORM!"
X Microsoft Windows GUI msmonk32.exe"Added by the SDBOT-PE WORM!"
X Microsoft Windows Kernel Services winkrnl386.exe"Added by the ZEBROXY TROJAN!"
X Microsoft Windows Loader wloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Microsoft Windows Logon Process winlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Winnt or Windows folder"
X Microsoft Windows Media Player mediaplayer.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Media Player wimp.exe"Added by the RBOT-FN WORM!"
X Microsoft Windows Registry Service wregistry.exe"Added by the AGOBOT.AKG WORM!"
X Microsoft Windows Secure windocs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Secure windocs.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Secure Server rpcxWindows.exe"Added by the RBOT-LL WORM!"
X Microsoft Windows Secure Update rpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
X Microsoft Windows Securety wurguar.exe"Added by the RBOT-KY WORM!"
X Microsoft Windows Security spvsper.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Security wscndrives.exe"Added by the RBOT-AJK WORM!"
X Microsoft Windows Service winsys.exe"Added by the RBOT-ADP WORM!"
X Microsoft Windows Service Pack winspkn.exe"Added by the RBOT-AYD WORM!"
X Microsoft Windows Services msw32.exe"Added by the RBOT-FWQ WORM!"
X Microsoft Windows Services Edt ssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
X Microsoft Windows Services Edt dllrun32.exe"Added by the RBOT-GAF WORM!"
X Microsoft Windows Session Manager Subsystem smss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Microsoft Windows Socketx32 Services winsockx32.exe"Added by the RBOT-FWT WORM!"
X Microsoft Windows Sound svghost.exe"Added by a variant of the SPYBOT WORM! See here"
X Microsoft Windows Sound svshost.exe"Detected by Kaspersky as the RBOT.ME BACKDOOR! See here"
X Microsoft Windows Sound svuhost.exe"Detected by PCTools as the KOLAB.XC WORM! See here"
X Microsoft Windows Storage Machine Service winms.exe"Added by the RBOT-AHK WORM!"
X Microsoft Windows SVCHOST SVCHOST.exe"Detected by Kaspersky as the VB.KV WORM! See here. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Microsoft Windows System srwhost.exe"Added by a variant of the RBOT-ASW WORM!"
X Microsoft Windows System syshost.exe"Added by the RBOT-ASW WORM!"
X Microsoft Windows System System.exe"Detected by Kaspersky as the VB.KV WORM! See here"
X Microsoft Windows System Kernel kernel32.exe"Added by a variant of the IRCBOT TROJAN!"
X Microsoft Windows System Service Manager winsvc.exe"Added by the SPYBOT.LR WORM!"
X Microsoft Windows Task Management mstasks.exe"Added by a variant of the SDBOT WORM!"
X Microsoft Windows Task Manger Mstosk.exe"Added by the SDBOT-WW WORM!"
X Microsoft Windows Tasks Management taskmng.exe"Added by the RBOT-FXK WORM!"
X Microsoft Windows Updata scvhost.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Updata windows.exe"Added by a variant of the RBOT WORM!"
X Microsoft Windows Update rundlls.exe"Added by the HABRACK WORM!"
X Microsoft Windows Update msoffice2.exe"Added by the RBOT-GB WORM!"
X Microsoft Windows Update spools.exe"Added by the SDBOT.TD WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list