Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X MS DVD DirectX Sound Drivers msdrvdx.exe"Added by the SDBOT-XJ WORM!"
X MS Explorer mexplore.exe"Added by the YAHA.AE WORM!"
X MS FIREWALL msfrewall.exe"Added by the SDBOT-PU WORM!"
X MS FIREWALL msfirewall.exe"Added by the SDBOT-QH WORM!"
X MS HTML msHtml.exe"Added by the PESTDOOR.31 TROJAN!"
X MS HTML mslat.exe"Added by the LATINUS.SVR TROJAN!"
X MS HTML Location Class MSHTML32.exe"Added by the RBOT-YD WORM!"
X MS Internet Executor 32 MSIXEC32.exe"Added by the RBOT-AEQ WORM!"
X MS Java Applets for Windows NT & XP javaapplet.exe"Added by the RBOT.BHG WORM!"
X Ms Java for Windows NT MS32.exe"Added by the VANEBOT-H WORM!"
X Ms Java for Windows NT msi32java.exe"Added by the VANEBOT-I WORM!"
X Ms Java for Windows NT msjava.exe"Added by the VANEBOT-E WORM!"
X MS Java for Windows XP & NT javanet.exe"Added by the VANEBOT-A WORM!"
U MS Java Service Wrapper for Windows NT & XP wrapper.exe"Added by the VANEBOT-D WORM!"
X Ms Java Update For Windows NT/XP msijavaupdt32.exe"Added by the RANDEX.AF WORM!"
X MS lsass Startup lsass135.exe"Added by the RBOT.WM WORM!"
? MS management console mms.exe"Suspicious as the Microsoft Management Console is ""mmc.exe"" and doesn't normally run at startup"
X MS Microsoft Socket Deamon MSSCKD32.exe"Added by a variant of the RBOT WORM!"
X MS MSN Menssenger 7.0 MSMSN7.exe"Added by the RBOT-ACA WORM!"
X MS MSN Menssenger 7.0 MSEXPORT.exe"Added by a variant of the SDBOT WORM!"
X MS Network Control mswin.exe"Added by the DUMBA TROJAN!"
X ms ownage winPE.exe"Added by the RBOT-AJL WORM!"
X MS PLUS INC wpad.exe"Added by the MYTOB-AN WORM!"
X Ms Processe Manager msproc.exe"Added by the RBOT.ATO WORM!"
X MS Real Player RealPlyr.exe"Added by the RBOT.MR WORM!"
X MS Registry Service MSRMS32.exe"Added by the RBOT-AKP WORM!"
X MS Remote Procedure Call msrpc32.exe"Added by the RBOT-QL WORM!"
X MS Screen Saver scrsave.scr"Added by the RBOT-AGT WORM!"
X MS Security systm.pif"Added by the RBOT-AQN WORM!"
X MS Security Authority Service lsass.exe"Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
X MS Security Hotfix service5.exe"Added by the GAOBOT.AG WORM!"
X MS Security Update 993 msident.exe"Added by a variant of the SDBOT WORM!"
X MS service msservice.exe"Added by the RBOT-ZG WORM!"
X MS Service Drivers winscv.exe"Added by the SDBOT-COG WORM!"
X MS Sound Config 16bit sndcfg16.exe"Added by the SDBOT.MB TROJAN!"
X Ms Sound Drivers msdrv.exe"Added by the SDBOT-WR WORM!"
X Ms Spool32 MS SPOOL32.EXE"Added by the ASASSIN TROJAN!"
X MS SyS Restore sysrestore.exe"Added by the RBOT.XM WORM!"
X MS Sys Security mswin.pif"Added by the RBOT-APJ WORM!"
X Ms System Config Mscfg.exe"Added by the SDBOT-CCR WORM!"
X MS System Security mswin32.pif"Added by the RBOT-AOX WORM!"
X Ms task manager tskmgr.exe"Added by the SDBOT.CCD WORM!"
X MS taskbar crssr.exe"Added by the RBOT-AGO WORM!"
X MS taskbar nts.exe"Added by the RBOT-AGB WORM!"
X MS taskbar taskbars.exe"Added by the RBOT.BRW WORM!"
X MS Taskbars taskbars.exe"Added by the SDBOT-ACV WORM!"
X MS taskmanager tskmgr.exe"Added by the RBOT-AKA WORM!"
X MS UniX navupdate64.exe"Added by a variant of the RBOT WORM!"
X MS Unix Binary win32ttb.exe"Added by the SPYBOT.OQ WORM!"
X MS Unix Binary msmq2inst.exe"Added by the RBOT-YF WORM!"
X MS Unix Binary msnupdate.exe"Added by the RBOT-AAM WORM!"
X MS Unix Binary outlookexpressupdate.exe"Added by the RBOT-YU WORM!"
X MS Unix Binary Win32Update.exe"Added by the RBOT-BAS WORM!"
X MS Unix Binary Norton2005Update.exe"Added by a variant of the RBOT WORM!"
X MS Unix Binary trmupdate.exe"Added by the RBOT-ACC WORM!"
X MS Unix Binary WinGuard.exe"Added by the RBOT-ACL WORM!"
X MS Unix Binary msnq3insller.exe"Added by a variant of the RBOT WORM!"
X MS Update syshost.exe"Added by the EVAMAN-F WORM!"
X Ms Update WinServices NT/XP winservnt32.exe"Added by the VANEBOT-G WORM!"
X MS Updates mscache.exeSpyware web downloader
X MS Updates syshosts.exe"Added by the MYDOOM.Y WORM!"
X MS Updates aupd.exeSpyware web downloader
X MS Updating Utility msupdater.exe"Added by the RBOT-XR WORM!"
X MS USB 2.0 Windows Support msusb32.exe"Added by a variant of the RBOT WORM!"
X Ms Valud Loader Svhots.exe"Added by the AGOBOT-SP WORM!"
X ms window update ******.exe [* = random character]"Added by a variant of the RBOT WORM!"
X MS Windows AOL Driver MSAOLdrv.exe"Added by the RBOT-ASP WORM!"
X MS windows Data list process MSDATLST.exeAdded by an unidentified WORM or TROJAN!
X MS Windows procces 32 msprocces.exe"Added by the RBOT-AEZ WORM!"
X MS Windows Process Class MSPRCSS32.exe"Added by the RBOT-YQ WORM!"
X MS Windows Process Init MSWPI32.exe"Added by the RBOT-ASQ WORM!"
X MS Windows Security Updater updater.pif"Added by the RBOT-AKY WORM!"
X MS Windows Update scguard.exe"Added by the RBOT-YZ WORM!"
X MS WINS Binary ign32.pif"Added by the RBOT-ASB WORM!"
X ms************* [* = random digit] ms*************.exe [* = random digit]"WINBO adware"
X Ms**.exe [* = random char] Ms**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X Ms**32.exe [* = random char] Ms**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X MS-Connect arr.exe"Adult content dialler - see here"
X MS-Connect cdm.exe"Adult content dialler - see here"
X MS-Connect game.exe"Adult content dialler - see here"
X MS-Connect msite18.exe"Adult content dialler - see here"
X MS-Connect web.exe"Adult content dialler - see here"
X MS-DOS Boot Service Boot32.pif"Added by the RBOT-AMF WORM!"
X MS-DOS Security Service ms-dos.pif"Added by the RBOT-AMR WORM!"
X MS-DOS Service MS-DOS.pif"Added by the RBOT-AII WORM!"
X MS-DOS Windows Service MS-DOS.PIF"Added by the RBOT-AJW WORM!"
X MS-HTML [random filename]"Added by the LATINUS.15 TROJAN!"
X MS-patch msconfig32.exe"Added by the RBOT-AUF WORM!"
X MS-patch mspatch32.exe"Added by the RBOT-AWF TROJAN!"
X MS-RunKey arr.exeMS-Connect dialler/hijacker
X ms2src ms2src.exe"Added by a TROJAN - see here"
X MS7531 ms7531.exeHomepage hijacker
X MSACM msacm.exe"Added by the OPASERV-O WORM!"
X msadcheck msadcheck32.exe"Browser hijacker
X MSAdmin jdbgmrg.exe"Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
X MSAgent mshtm.exeBrowser hijacker - redirecting to buldog-search.com
X MSAgent hhnt.exe"Added by the AGENT.JI spyware"
X MSAgentXP MSAgentXP.exe"Reported by Ewido Security Suite as TrojanDownloader.Reqlook.c"
U msaim msaolim.exe"MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X msappts32 msappts32.exe"Added by the ELBURRO-A TROJAN!"
X MsAudio explorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder"
X MsAudio "MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
X MSbackups backups.exe"Added by BANLOAD-TL TROJAN!"
X MSBB msbb.exeAdvertising spyware
X msbcs msbcs.exe"Added by the DADOBRA-G TROJAN!"
X MsBootMgr.exe MsBootMgr.exe"Added by the VERIFY TROJAN!"
X msbsc [path to trojan]"Added by the BANKER-DF TROJAN!"
X MSChoExE suge.exe"Added by a variant of the RBOT WORM!"
? msci mcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
X mscman mscman.exe"ClientMan parasite variant"
U mscn mscn.exePart of the SafeChildNet internet filtering program - required if you use it
X Mscnt mscnt.exe"Added by the DLUCA-C TROJAN!"
X Mscolour mscolour.exe"Added by the GEMA TROJAN!"
X MSCommX mscommx.exe"Added by a variant of the RBOT WORM!"
X MSCONFG32.EXE MSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
N MSConfig msconfig.exe"Entry that appears when you uncheck an item in the MSConfig Startup group
X MSConfig MSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
X msconfig msconfig.exe"CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
X Msconfig msconfig.exe"Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun"
X msconfig wins.exe"Added by the RBOT.PF WORM!"
X MSConfig MSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
X Msconfig lptt01 msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X MSConfig Manager msupdate.exe"CoolWebSearch parasite variant"
X Msconfig ml097e msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X msconfig service MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
X msconfig.exe proxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X msconfig.exe uline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X msconfig38 mssvcc.exe"Added by the RBOT-BJV WORM!"
X MSConfig45 MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
X MSConfigr jdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
N MSConfigReminder msconfig.exe"Entry that appears when you uncheck an item in the MSConfig Startup group
X MsConfigs MsConfigs.exe"Added by the ALCAN.A WORM!"
X MSControl28 crsss.exe"Added by the SPYBOT.AJX WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list