Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X shambl3r cnf.bat"Added by the REMABL WORM!"
X shambl3r* shambl3r.exe"Added by the REMABL WORM! where * is 2 to 11"
X SHAProc SHAProc.exe"Added by the WINKO.AO WORM!"
N Share-to-Web Namespace Daemon hpgs2wnd.exe"HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites. In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs"
N Shareaza Shareaza.exe"Shareaza P2P client"
U Shareaza bindata.exe"Shareaza P2P client related"
X sharedprem sharedprem.exe"Added by the MAKECALL TROJAN!"
X ShareSearcher [path to trojan]"Added by the AGENT-FPE TROJAN!"
X ShareSearcher wsusupd.exe"Added by the ENCLAG-A TROJAN!"
Y Sharing and Mapping Software DShmap.exe"Intel AnyPoint internet sharing software. Now discontinued"
N SharkEject AEJCT32.exeAllows you to eject a disk from the Avatar Shark drive from the system tray. When loaded there is a desktop icon so this isn't required
U SharpTray SharpTray.exe"Part of Sharpdesk from Sharp Electronics. ""A desktop-based personal document management application that lets users browse edit search compose process and forward both scanned and native electronic documents"""
N Shcenter chcenter.exe"IMSI HiJaak - ""the easiest way to convert capture and manage all your graphic files"""
X shdef shdef.exe"Added by the VB-DVS TROJAN!"
X SheduIer svchst.exePremium rate adult content dialler
X SheduIer shch.exe"Added by the BDOOR-EB BACKDOOR!"
X SheduIer winagent.exe"Added by the BDOOR-EB BACKDOOR!"
X Shedule Connection arpo412.exe"Added by the PPDOOR-R WORM!"
X Sheduler nerocheck.exe"Added by the TACTSLAY.B TROJAN!"
X Shell Shell32.exe"Added by the BADSECTOR TROJAN!"
X Shell ray.exeHomepage hijacker re-directing browsers to adult content websites
X Shell Tray.exeHomepage hijacker re-directing browsers to adult content websites
X Shell wmedia16.exe"Added by the GOLDUN TROJAN!"
X Shell Open32.exe"Added by the SMALL-DL TROJAN!"
X Shell Explorer.exe sound_drive16.exe"Added by the GP TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System subfolder"
X Shell Explorer.exe msmsgs.exe"Added by the ZLOB TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder"
X Shell Explorer.exe [path] svchost.exe"Added by the DOYORG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X shell explorer.exe"Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Shell iexplore.exe"Added by the KIPIS-U WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft"
X Shell ibm0000*.exe [* = digit]"Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe ibm00002.exe ibm00005.exe and so on"
X Shell taskmrg.exe"Added by the BANCBAN-FT TROJAN!"
X Shell Explorer.exe winupdate.exe"Added by the AGENT-FD TROJAN!"
X Shell ibm[RANDOM 5 DIGIT NUMBER].exe"Added by the ANSERIN TROJAN!"
X Shell svchost.exe"Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Shell ibm00001.dll"Added by the TORPIG-Q TROJAN!"
X Shell wmedia32.exe"Added by the AGENT-BR TROJAN!"
X Shell API32 svcnet.exe"Added by the TIBICK.C WORM!"
X Shell Extension spollsv.exe"Added by the LOVGATE.Z WORM!"
X Shell Tray Window ShellTraywnd.exe"Added by the STULTDOR-A TROJAN!"
X shell update shellexec.exe"Added by the RBOT-ANC WORM!"
X Shell.exe Shell.exe"Added by the EMERLEOX.S WORM!"
X Shell32 Shell32.vbs"Added by the SCAFENE WORM!"
X shell32 ntldrt.exe"Added by the JLOK-A WORM!"
X Shell32 iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X ShellApi SHELLMSN.EXE"Added by the NETDEV.B TROJAN!"
X Shellapi32 Shellapi32.exe"Added by the NETDEVIL (or NERTE) TROJAN!"
X Shellapi32 mcvsrte.exeAdded by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name
X shellbn [random].dll"SoftStop misleading security software - not recommended see here"
X ShellCommand [path to file]"Added by the REMCON-A TROJAN!"
X Shelldaemon Shelldaemon.exeAdded by a variant of the AGENT.ALN TROJAN!
X ShellEx ShellEx.exe"Added by the ANAKHA TROJAN!"
X ShellN isca.exe"Added by the IBILL.Z TROJAN!"
X ShellOS A+++.exeAdded by the AV TROJAN!
X ShellRun lexplore_.exe"Added by the MSNOPT-A TROJAN!"
X ShellRun32 iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Shellspl lsas.exe"Added by the YALER-A TROJAN!"
X Shellspl spools.exe"Added by the PROXAGE-A TROJAN!"
X shellsystem shellsystem.exe"Added by the UPCHAN TROJAN!"
X shhost shhost.exe"Added by the AGENT.CE TROJAN!"
N shicoxp shicoxp.exeInstalled with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
X Shield Security shield.exe"Added by the RIZO.A TROJAN!"
X Shield32 Security shield32.exe"Added by the RIZO.A TROJAN!"
X Shine Shine.exe"Added by the HAPPYLOW (or NISHE-A) VIRUS!"
? SHINITV shinitv.exe"??"
X Shmgrate.exe ibot4.exe"Added by the GASTER TROJAN!"
N ShockmachineReminder SmReminder.exe"""Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline"". Could be a registration reminder for the trial version"
X Shockwave csrss.exe"Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
N Shockwave Init SWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
X Shockwave Support FlashPlayer.exe"Added by the DELF-DRA WORM!"
N ShopSafe ShopSafe.exe"Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase"
N ShortKeys 99 SHORTKEY.EXE"ShortKeys from Insight Software Solutions - allows you to program keys with text strings"
U ShortKeys Lite shklite.exe"ShortKeys Lite from Insight Software Solutions Inc. A macro utility to automate a task that you perform repeatedly or on a regular basis"
Y sHotKey sHotKey.exe"Special function key manager for Chicony keyboards - see here"
X Showbehind SHOWBEHIND.EXE"Advertisement display which can be stopped here"
X ShowFF ShowFF.exe"FFToolBar adware toolbar"
? ShowIcon_Justrams_USB Product Driver v2.12r012 shwicon.exe"Related to Just Rams USB product driver. Is it required?"
U ShowIcon_PNY_PNY Attach shwicon.exe"PNY Attach? USB flash memory stick System Tray icon - shows when the device is plugged in"
? ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
U ShowLOMControl [strange symbol]"Note that there is a strange symbol in the command field. HKLMSoftwareMicrosoftWindowsCurrent VersionRunShowLOMControl Reg_DWORD 0x00000001 (1) LOM = LAN on Motherboard.It mean Show ""LAN on Motherboard"" Control.On systems where you can install an external LAN interface it will warn you that you already have a built-in LAN interface. Appears to be a feature on certain Dell systems"
X Showme Ruden.vbs"Added by the HANDLE-A VIRUS!"
U ShowWnd ShowWnd.exe"Found on Gateway computers (and maybe others) - see here. ""Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software however if you wish it can be removed through Add or Remove Programs"""
U SHPC32 SHPC32.exePort monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
Y ShStatEXE SHSTAT.EXEFrom McAfee VirusScan NT 4.x. Handles program communication among VShield components displays VShield icon. Can be started automatically or available via Start -> Programs
U Shutdownaware shutdownaware.exe"Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system"
U ShutDownPro ShutDownPro.exe"ShutDownPro - shutdown reboot logoff your System with one mouse click"
N Si Meter SIMETER.EXE"Si Meter - keep track of things like CPU activity network activity and speed hard-drive activity hard-drive space system memory running processes or just date and time"
X si91e44b rundll32.exe si91e44b.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""si91e44b.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
U SIA2006 SIA2006.exe"Part of Steganos Internet Anonym privacy software"
U SIAPRO6 sia.exe"Steganos Internet Anonym privacy software"
X Sicom Sicom.exe"Added by the NETLIP WORM!"
U SideACT SideACT.exe"SideACT organizer software"
U Sidebar Sidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. But on other versions of Windows it can be a part of the Searchcentrix hijacker"
N SIDEBAR dsidebar.exe"""Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"""
N SideWinderTrayV4 SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
U SightSpeed SightSpeed.exe"SightSpeed Video Chat - ""lets you connect with all your friends and family easily. Make video calls phone calls and send video mails and text messages to everyone in your network anywhere in the world"""
N SigmaTel Audio setup.exe"Sigmatel audio driver"
N SigmatelSysTrayApp stsystra.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
N SigmatelSysTrayApp sttray.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
? SigX sigx.exe"??"
X SigXC SigX.exe"SigX is a ""dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3 current OS Free Ram your current time and more"""
N Simcast SimcastAlerts.exe"Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say"
N Simple Star PhotoShow Media Manager mssysmgr.exe"Simple Star PhotoShow photo editing and organizing software makes it easy to send and share digital photos. Bundled with software from Nero ComCast SnapFish MacroMedia and others"
N Simplify Media SimplifyMedia.exe"Simplify Media media manager - ""enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online"""
U SimpLite-MSN SimpLite-MSN.exeRequired if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
X sInErA .exe"Added by the SILLYFDC-AB WORM!"
X Singapore singapore.exe"Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself"
U Sinus 1054 data WLAN Manager Wifiusb.exeWireless management utility for the T-Com Sinus 1054 Data WLAN adapter
N SipDiscount SipDiscount.exe"SipDiscount - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
U SIPPS SIPPS.exeWeb.de Internet phone utility
X SiS Dns dnssvc.exe"Added by the DLOADER-UE TROJAN!"
N SiS KHooker khooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
X SiS Mpc Service mpcsvc.exe"Added by the CIADOOR-CJ TROJAN!"
U SiS Tray sistray.exeSystem Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem
U SiS Windows KeyHook keyhook.exe"SIS graphics cards related: ""Super VGA Keyboard Daemon"" - hooks into the keyboard processing chain in order to enable hotkey settings"
X sis32 winsos.exe"Added by the QQPASS.IA WORM!"
Y SiS7012Utility SiSAudUt.exeSiS Corporation sound card driver
? SISAM10M SISAM10M.exe"??"
N SiSAudio MP_S3.exeWinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems
U siscolor color.exeProbably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
U siService.exe siService.exe"Spam Inspector - anti email spam software"
? SiSPower Rundll32.exe SiSPower.dll ModeAgent"Responsible for power management for SIS chipsets - is it required?"
U SiSRaid SRaid.exe"Related to the SIS Raid system from Silicon Integrated Systems"
? SiSSetCDfmt SiSSetCDfmt.exe"Related to a Silicon Integrated Systems Corp (SiS) product?"
? SISSoundman Soundman.exe"Related to a Silicon Integrated Systems Corp (SiS) product?"
U SiSSWLED sisswled.exeSystem Tray utility for SiS 900 network cards
X Sistema wab32.exe"Added by an unidentified VIRUS WORM or TROJAN! See here"
X sistrai.exe sistrai.exe"Added by the PROVA TROJAN!"
X sistray sistray.exe"Added by the PROVA TROJAN!"
U sistray sistray.exeSystem Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem
X Sistray32 remotehost.pif"Added by the HOLCAS.A WORM!"
X Sistray32 win.bat"Added by the JUMPRED.A WORM!"
X Sistray32 virus.exe"Added by the TOMETA-C TROJAN!"
X sistry sistry.exe"Added by the CEBE WORM!"
N SiSUSBRG SiSUSBrg.exeSiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
U SiteAdvisor SiteAdv.exe"SiteAdvisor from McAfee warns you before you interact with a dangerous Web site"
X sittachasnahalbasya ntoskernel.exe"Added by the HANSAH-A WORM!"
X sixer566 sscc.exeAdded by an unidentified WORM or TROJAN!
X sixtysix sixtypopsix.exe"Medload adware"
X sjduwiwx rnxntup.exe"Added by a variant of the ORCU.B TROJAN!"
U SK51 SK51.EXE"SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
U SK60 SK60.EXE"SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
U SK9910DM SK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
U SKDAEMON SKDAEMON.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
U SkinClock AtomicAlarmClock.exe"Atomic Alarm Clock - ""Alert yourself about important events with different alarms and replace your computer tray clock using different skins. Computer Alarm clock that will play any MP3 file. It can also run a program log off wake up reboot shut down turn off etc..."""
U skinkers skinkers.exe"Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's ""Desktop Ozzy"" and Arsenal's ""Desktop Wenger"" - see here. Leave enabled if you want to receive messages"
X Skra Skra.exeIdentified as a variant of the TrojanDownloader.Matcash malware
U SKRSpyWarn Warn.exe"SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
U sks-32 SKS32P~1.EXE"SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself"
U sks-32 sks32proc.exe"SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself"
X Skunk Skunk.exe"Added by the SUNK-A WORM! Note - this file is found in the root folder (C:) (D:) etc"
Y SkyBlaster Scheduler SSFSch.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
X skynetave.exe skynetave.exe"Added by the SASSER.D WORM!"
X SkynetRevenge winlogon.scr"Added by the NETSKY.AA WORM!"
N Skype Skype.exe""Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes""
X Skype Startup skyp.exe"Added by the VANBOT-C WORM!"
N SkypeMate SkypeMate.exe"SkypeMate acts as a bridge between networks of VoIP and PSTN"
X SkypeStartup Skype.exe"Added by the PYKSE-A WORM!"
Y SkySurfer Management Service SmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
U SkyTel SkyTel.exe"Process associated with Realtek Voice Manager for some of their audio chipsets"
X sl4 rules rbot32.exe"Added by the SDBOT-QC WORM!"
X slack12 mfcee.exe"Added by a variant of the SDBOT WORM!"
X Slayhacker734 slay7383.exe"Added by the SIKBOT-A TROJAN!"
N SleepManager SleepMgr.exeThis program locates free contiguous disk spaces and allocates them for storing BASE MEMORY EXTENDED MEMORY VIDEO MEMORY and SM RAM. It helps the computer come out of hibernate mode
U Slibe.com Sliber.EXE"Sliber - freeware screen capturing & online sharing tool"
U SlickRun sr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords) so C:Program FilesOutlook Expressmsimn.exe becomes MAIL"""
X slide Iexplore.exe"Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
N slimp3 SliMP3 Server.exe"Slimp3 Server - ""presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards the SliMP3 uses your home network to access the music stored on your PC"""
N Slingshot SLINGS~1.EXE"Atomica Slingshot - ""reference tool with access to dictionary and encyclopedia terms bios technical terms history geography and much more"". Now superseed by 1-Click Answers"
Y slipcore slipcore.exe"Core module for Slipstream - internet acceleration through compression/decompression techniques intelligent cacheing on the server side and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet Wanadoo Terra OnSpeed United Online and AOL Canada. Required if the user's account is locked in to that proxy server"
Y slipgui slipgui.exe"User interface for Slipstream - internet acceleration through compression/decompression techniques intelligent cacheing on the server side and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet Wanadoo Terra OnSpeed United Online and AOL Canada. Required if the user's account is locked in to that proxy server"
Y SlipStream slipcore.exe"Core module for Slipstream - internet acceleration through compression/decompression techniques intelligent cacheing on the server side and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet Wanadoo Terra OnSpeed United Online and AOL Canada. Required if the user's account is locked in to that proxy server"
X slmss slmss.exe"SeekSeek search hijacker related - see here"
X sload sload.exe"Win SynchroAd adware also detected as DLOADER-QG TROJAN!"
X slvchost32 slvchost32.exeAdded by an unidentified VIRUS WORM or TROJAN!
X sm sa_exe.exe"Added by the OLFEB.A TROJAN!"
X sm sf_exe.exe"Added by the OLFEB.A TROJAN!"
X sm sm_exe.exe"Added by the OLFEB.A TROJAN!"
X sm sr_exe.exe"Added by the LUKUSPAM TROJAN!"
X SM iro.bat"Added by the IROFFER.CT TROJAN!"
N SM1BG SM1BG.EXEUSB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list