Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X MSACM msacm.exe"Added by the OPASERV-O WORM!"
X msadcheck msadcheck32.exeBrowser hijacker redirecting to search-system.com
X MSAdmin jdbgmrg.exe"Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
X MSAgent mshtm.exeBrowser hijacker - redirecting to buldog-search.com
X MSAgent hhnt.exe"AGENT.JI spyware"
X MSAgentXP MSAgentXP.exe"Detected by Ewido Security Suite as the REQLOOK.C TROJAN!"
U msaim msaolim.exe"MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X msappts32 msappts32.exe"Added by the ELBURRO-A TROJAN!"
X MsAudio explorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X MsAudio MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"Added by the LEGMIR-BY TROJAN! Note - this is not associated with C-Media based audio which uses a similar command entry (see here)"
X msavsc.exe msavsc.exe"Detected by Kaspersky as the AGENT.ANQ TROJAN! See here"
X MSbackups backups.exe"Added by the BANLOAD-TL TROJAN!"
X MSBB msbb.exeAdvertising spyware
X msbcs msbcs.exe"Added by the DADOBRA-G TROJAN!"
X MsBootMgr.exe MsBootMgr.exe"Added by the VERIFY TROJAN!"
X msbsc [path to trojan]"Added by the BANKER-DF TROJAN!"
X msccrt msccrt.exe"Added by the PWS-ALA TROJAN!"
X mscheck rundll32.exe wincheck071008.dll mymain"Detected by Trend Micro as the AGENT.ADXH TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X mschkdf.exe mschkdf.exe"Added by a variant of the SDBOT WORM!"
X MSChoExE suge.exe"Added by a variant of the RBOT WORM!"
? msci mcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
X mscman mscman.exe"ClientMan parasite variant"
U mscn mscn.exePart of the SafeChildNet internet filtering program - required if you use it
X Mscnt mscnt.exe"Added by the DLUCA-C TROJAN!"
X Mscolour mscolour.exe"Added by the GEMA TROJAN!"
X MSCommX mscommx.exe"Added by a variant of the RBOT WORM!"
X Msconf32 Msconf32.exe"Added by the AGOBOT-NR WORM!"
X MSCONFG32.EXE MSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
N MSConfig msconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
X MSConfig MSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
X msconfig msconfig.exe"CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
X Msconfig msconfig.exe"Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun"
X msconfig wins.exe"Added by the RBOT.PF WORM!"
X MSConfig MSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
X msconfig scvhost.exe"Added by the AGENT-DSF TROJAN!"
X msconfig winlog.exe"Added by the IRCBOT-TJ TROJAN!"
X Msconfig icpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
X msconfig msconfig.com"Added by the IRCBOT-SM WORM!"
X msconfig msconfig.bat"Added by the PAHATIA.B WORM!"
X Msconfig lptt01 msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X MSConfig Manager msupdate.exe"CoolWebSearch parasite variant"
X Msconfig ml097e msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X msconfig service MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
X msconfig.exe proxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X msconfig.exe uline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
X msconfig38 mssvcc.exe"Added by the RBOT-BJV WORM!"
X MSConfig45 MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
X MSConfigr jdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
N MSConfigReminder msconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
X MsConfigs MsConfigs.exe"Added by the ALCAN.A WORM!"
X MSConfigs RUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
X MSControl28 crsss.exe"Added by the SPYBOT.AJX WORM!"
X MSControl31 winnsyst.exe"Added by the RBOT.CFY WORM!"
X MSControl3d1 isasse.exe"Added by the RBOT.CGU WORM!"
X MSCORE syscnfg.exe"Added by an unidentified VIRUS WORM or TROJAN! ""syscnfg.exe"" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside"
X Mscsgs MSCSGS.EXE"Added by the ZEZER WORM!"
X Mscsgs32 MSCSGS32.EXE"Added by the ZEZER WORM!"
X mscsvc.exe mscsvc.exe"Added by the BANCOS.T TROJAN!"
X msctrl.exe msctrl.exe"Detected by Kaspersky as the AGENT.ANQ TROJAN! See here"
X Msctrl32 Msctrl32.scr"Added by the REDIST WORM!"
X MSCVT MSCVT.exe"Added by the SLIDESHOW WORM!"
X msdbgm.exe msdbgm.exe"Added by the CIMUZ-CQ TROJAN!"
X MSDcom MSDcom.exe"Added by a variant of the SDBOT WORM!"
X msdefender msdefender.exe"Identified as a variant of the PAKES.CMD TROJAN! See here for an example"
X msdefender.exe msdefender.exe"Detected by Trend Micro as the PAKES.ZL TROJAN! See here"
X msdev msdev.exe"Added by the FORBOT-CR WORM!"
X msdev msconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
X msdev control msdevctrl.exe"Added by the SPYBOT.N BACKDOOR!"
X msdir32 msdir32.bat"Added by the ROOKIE-A TROJAN!"
X msdirect.exe msdirect.exe"Added by the CERTIF-L TROJAN!"
X MSDLL syscnfg.exe"Added by an unidentified VIRUS WORM or TROJAN! ""syscnfg.exe"" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside"
X Msdmxm msdmxm.exe"Added by the DLUCA-DC TROJAN!"
X MSDN nese.exeAdded by the SDBOT.AHY WORM!
X MSDN for Windows NT msdn.exe"Added by a variant of the RBOT WORM!"
X MSDN for Windows NT & WinXP msdnxp.exe"Added by the IRCBOT-PE WORM!"
X MSDN for Windows with NT's msdn-nt.exe"Added by the RBOT-EWD WORM!"
X MSDN HELP msdn.exe"Added by the AGOBOT.AIB WORM!"
X MSDNN help.exe"Added by the AGENT-GBK TROJAN!"
X MSDOS Security Service msdos.pif"Added by the RBOT-AMP WORM!"
X MSDOS Service MSDOS.PIF"Added by the RBOT-AIY WORM!"
X MSDOS Windows Service MSDOS.PIF"Added by the RBOT-AKF WORM!"
X Msdos32 Msdos32.pif"Added by the RECORY WORM!"
X msdos423 msdos423.exe"Added by the MENACE.A WORM!"
X MSDosdrv msdosdrv.exe"Added by the BACROS WORM!"
X MSDrive rundll32.exe drvkoc.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvkoc.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X MSDrive rundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X MSDrive rundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvsoh.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X msdrvctrl msdrvctrl.exe"Detected by Kaspersky as the AGENT.BN TROJAN! See here"
N MSDTC msdtc.exeMS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
X Msemu32 Msemu32.exeUnidentified spyware/adware/hijacker
X msennger l4m3r.exe"Added by the PROGENT-AF TROJAN!"
X mservices.exe mservices.exe"Added by the SDBOT.WJ WORM!"
X Msfind Msfind.exe"CoolWebSearch parasite variant"
X MSFind32 msfind32.exe"Added by the CAYAM WORM!"
X msfindosa.exe msfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
X MSFTP Service Config r3grun.exe"Added by a variant of the SDBOT WORM!"
X msfw.exe msfw.exe"Detected by Kaspersky as the AGENT.ANQ TROJAN! See here"
X MSFWAVTSM FTPDev.exe"Added by the RBOT-ACF WORM!"
X Msg Fixage msgfixed.exe"Added by the SDBOT.ZD WORM!"
X MsgApi [path to file]"Added by the DEDLER-D TROJAN!"
X msgb1 msgb1.exeAdded by the DLUCA.GEN TROJAN!
N MsgCenterExe RealOneMessageCenter.exe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
X msgex32 msgex32.exe"Added by the APPFLET-A WORM!"
X Msgmgr [path to worm]"Added by the BABYBEAR WORM!"
X msgserv_ Syss.exe"Added by the FANTA TROJAN!"
X msgsm32 msgsm32.exe"Added by the RBOT-ASG WORM!"
X Msgsrv16 Msgsrv16.exe"Added by the DELF family of TROJANS!"
Y MSGSRV32.exe msgsrv32.exe"Windows 32-bit VxD Message Server. For more information on its function and why it's needed see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background"
X Msgsvc32 [worm filename]"Added by the NAUTICAL-A WORM!"
X MsgSvcMgr32 cmdzxdll.exe"Added by the RBOT-AEK WORM!"
X msgsvr32 msgsvr32.exe"Added by the DEADHAT.B WORM! Note - not to be confused with the valid ""msgsrv32.exe"" file which resides in the same directory (C:WindowsSystem) on a Win9x/Me machine"
U MSGTAG MSGTAG.exe"MSGTAG is an application that tells you when your emails have been received and opened"
X Msgtray sys16.exeAdded by an unknown VIRUS!
X Mshelp32 mshelp32.exe"CoolWebSearch parasite variant"
X Mshosts Mshosts.exe"Added by the STARTPAG.CF TROJAN!"
X MSHT@ MSHT@.EXE"Added by the MAGISTR.A VIRUS!"
X mshtmll mshtmll.dll"Added by the DELF.BAS TROJAN!"
X MSI Configuration msiconf.exe"Added by the AGENT.AKSZ TROJAN!"
X msiconf.exe msiconf.exeAdded by a variant of the FAKEALERT TROJAN!
X msidle msidle.exe"Added by the OPASERV-O WORM!"
X MsIdle32.exe MsIdle32.exe"Added by the VERIFY TROJAN!"
X MSIdll winmp.exe"Added by a variant of the RBOT WORM!"
X MSIE Parsers MSIE32ab.exe"Added by the SDBOT.MV WORM!"
X msiemon.exe msiemon.exe"Detected by Kaspersky as the AGENT.ANQ TROJAN! See here"
X msiew mseiw.exe"Added by the LITTLOG TROJAN!"
X MSIEXEC MSIEXEC32.exe"Added by the AINESEY.A WORM!"
X MSIEXEC MSIEXEC.EXE"Added by the YOSENIO-A VIRUS!"
X msiexecs.exe msiexecs.exe"Added by a variant of the SDBOT WORM!"
X msig disk10.exe"Added by the BANBRA-KF TROJAN!"
X MsIMMs32 MsIMMs32.exe"ONLINEG.GDJ spyware"
X msimn msimn.exe"Added by the AGOBOT.JL WORM!"
X MSIMN32 MSIMN32.EXE"Added by the CWS-M TROJAN!"
? MSIN MSin.exe"??"
X Msinet Msinet.exe"Added by the RBOT-AOA WORM!"
X MSInfo msinfo.exe"Added by the ALADINZ.M TROJAN!"
X MSInfo AVBgle.exe"Added by the NETSKY.O WORM!"
X MSInstall smvss.exe"Added by the DEDLER-G TROJAN!"
X msjava service xpcd.exe"Added by the SDBOT.VM WORM!"
U MSKAGENTEXE MskAgent.exe"McAfee Spamkiller"
X MSKCES32 [random filename]"Added by the CLONER TROJAN!"
U MSKDetectorExe MSKDetct.exe"Part of McAfee Spamkiller"
X MSKernel32 MSKernel32.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
X MSkernel32 System.exe 4820"Added by the TUXDER BACKDOOR!"
U MSKExe spamkiller.exe"McAfee Spamkiller"
X mskj mskj.exe"Added by the KAEMON TROJAN!"
X mskrider maskrider.dll.vbs"Added by the SOLOW-F WORM!"
U MSKServerExe MSKSrvr.exe"Part of McAfee Spamkiller"
X mslagent mslagent.exe"Added by the WINTRIM-F TROJAN!"
X MSLARISSA MSLARISSA.pif"Added by the ASSIRAL.B WORM!"
? MSLIB32 mswatch32.exe"??"
X msliveupdate msliveupdate.exe"Added by the AGOBOT.ALT WORM!"
X MSLog MicrosoftLog.exe"Added by a variant of the SDBOT WORM!"
X Mslogon lptt01 mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Mslogon ml097e mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X msm msm.scr"Added by the BANKER-EHJ TROJAN!"
X msmacro32 msmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!
X MsManager msmgr32.exe"Added by the YAHA.AF WORM!"
X msmanager32 msmngr32.exe"Added by the RANDON-R (or WOMANIZ.A) WORM!"
X msmautoprotect msmssgs.exe"Added by the BIFROSE-AJ TROJAN!"
X msmc mscpbo.exe"ClientMan parasite variant"
X msmc msgdmf.exe"ClientMan parasite variant"
X msmc msongn.exe"ClientMan parasite variant"
X msmc msmc.exe"ClientMan parasite variant"
X msmc ms****.exe [* = random char]"ClientMan parasite variant"
X MSMcAfeee Avsynmgr32e.exe"Added by the FRAMAR TROJAN!"
X MSMcAfeeh Avsynmgr32h.exe"Added by the FRANGO TROJAN!"
X MSMcAfeeS Avsynmgr32S.exe"Added by the VOLAC or VOLAC.DR TROJANS!"
X MSMessnger msnupd.exe"Added by the RBOT-ADY WORM!"
? msmgr msmgr.exe"??"
X msMGR rtkmsg.exe"Added by the SDBOT-BPY WORM!"
X Msmgt msmgt.exe"Total Velocity adware/hijacker"
X msmmi msmmi.exe"Added by the AGENT.RFR TROJAN!"
X MSMNTGNT MSMNTGNT.EXE"Added by the BANKER-IE TROJAN!"
X MSMNTJBE MSMNTJBE.EXE"Added by the BANCOS-EF TROJAN!"
X MSMNTJNG MSMNTJNG.EXE"Added by the GRABER-G TROJAN!"
X MSMNTMTS MSMNTMTS.EXE"Added by the BANKER-GZ TROJAN!"
X msmon msmon.exe"Added by a variant of the GEMA.D TROJAN!"
X MsMovies MsMovies.exe"Malware - detected by Kaspersky as the WINAD.H TROJAN!"
? MsmqIntCert regsvr32 /s mqrt.dll"Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?"
X MSMSGNER [4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list