Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X sysmngr32 sys64mnger.exe"Added by a variant of the RBOT WORM!"
X sysmntrc sysmntrc.exe"Added by the BANCOS-FX TROJAN!"
X sysmod sysmod.exe"Added by the SPYBOT-DU WORM!"
X sysmon sysmon.exe"Added by the BIZEX WORM!"
X Sysmon rpcmon.exe"Added by the RANDEX.ATX WORM!"
X sysmon sysmon44.exe"Added by a variant of the BACKDOOR-CBA TROJAN!"
X SysMon wowexece.exe"Added by the MULAN-A TROJAN!"
X Sysmon SystemMonitor.exe"Added by the NUJAMA-A WORM!"
X sysmon12 [various filenames]"Wareout - malware masquerading as a spyware and dialer remover"
X SysmonLog mslog.exe"Added by the AGENT.AOV TROJAN!"
X sysmonnt sysmonnt.exe"SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server"
X SysMonXP SysMonXP.exe"Added by the NETSKY.Q WORM!"
X Sysmppcvppp SysTdSvr.dll"Generic2.PQG adware"
X sysmss sysems.exe"Added by a variant of the SLAPER TROJAN!"
X sysnate sysnate.exe"Added by the MEDIAS TROJAN!"
X Sysnet snuninst.exeUnidentified adware
X sysnet sysnet.exe"CasClient adware - also detected as the CMAPP TROJAN!"
X sysobj.exe sysobj.exe"Wareout - malware masquerading as a spyware and dialer remover"
X SysOps SysOps"Added by the MSNCORRUPT TROJAN!"
X syspare syspare.exe"Added by the BIFROSE-AN TROJAN!"
X syspath drv.exe"Added by the SOBER WORM!"
X sysPersonalFirewall msnmssgr.exe"Added by a variant of the RBOT WORM!"
X sysPersonalFirewall system.exe"Added by the WOOTBOT.FH WORM!"
X sysPersonalFirewall tskm0nitor.exe"Added by a variant of the RBOT WORM!"
U SysPilot fdxxl.exe"G Data ""PC Spion"". PC monitoring and surveilling software captures all users activity on the PC see here. Disable/remove if you didn't install it yourself!"
X sysPnP bootconf.exe"Homepage hijacker redirecting to coolwwwsearch.com; see for example here"
X SysPnP rundll32 setupapi InstallHinfSection [varies] oemsyspnp.inf"CoolWebSearch PnP parasite variant"
Y SysPool Mssvc.exeStealthDisk - hides folders files and applications. Will also encrypt them for better protection
X SysPool MSSVC32.EXE"Added by the BANCBAN-IO TROJAN!"
X SysProtect System.exe"Added by the NETSPY TROJAN!"
X SysProtect syp.exe"SysProtect is detected as a ""potentially unwanted program"". It purports to be an system repair/maintenance application but requires paid registration before any issues found can be fixed. Many of the ""invalid"" items found appear suspect. This has been reported to be distributed in wild via trojan Vundo. Other incarnations of this software exist with the same model and similar web presences (for example WinFixer). For more information see here"
X syspw32.exe syspw32.exe"Added by the APPFLET.A WORM!"
X Sysqq LSESS.exe"Added by the FORBOT-BF WORM!"
X SysR sysmd.exe"Ulubione adult content dialer"
X SysReg SysReg.exe"Added by the CHEKIN TROJAN!"
X SysReg SysReg.exe"SearchSeekFind textual marketing foistware"
X Sysres Sysres.exe"Added by the LOGMOD.A TROJAN!"
X SysRes TASKMANAGER.exe"Added by the ELIPTER.A or ELIPTER.B WORMS!"
X SysRes WWE DIVAS.exe"Added by the ELIPTER.D WORM!"
X SysRes IExpIore .exe"Added by the ELITPER.E WORM!"
X sysrest32.exe sysrest32.exe"Added by the AGENT-GIN TROJAN!"
X sysrestore32.exe sysrestore32.exe"Unknown malware detected by McAfee. See here"
X Syss ehuupdate.exe"EHU adware"
X SysScan bvt.exe"Added by the AUTOUPDER TROJAN!"
X SysSearch Regedit.exe -s pcsearch.reg"Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""pcsearch.reg"" file is located in the Winnt or Windows folder"
X SysSearch Regedit.exe -s sysreg.reg"Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""sysreg.reg"" file is located in the Winnt or Windows folder"
U SysSense SysSense.exe"""SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray"". Google AdSense account required"
X sysser [path to file]"Added by the RAHACK WORM!"
X SysService SysService.exe"Added by the DELF family of TROJANS!"
U SysService SERVICES.EXE"NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
X SysService32 SysService32.exe"Added by the KINDAL VIRUS!"
X SysService32 ln32k.dll"Added by the KINDAL VIRUS!"
X SysService32l systask32l.exe"Added by the THEUG WORM!"
X SYSsfitb SYSsfitb.exe"AdShooter adware"
X SySSL sysl.exe"Added by the RBOT-CKH WORM!"
X SysStart [random filename]"ZenoSearch adware"
X SysStart syswin.exe 1"Added by the AUTORUN-EY WORM!"
X SysStrt systemc.exe"Added by the AGOBOT-QA TROJAN!"
X syst syst.exe"Added by the DUMB.A ""Joke"" virus"
X Systam13 f1r5st83.exe"Added by the IRCBOT-YM WORM!"
X System run322.exe"Added by the LANFILT TROJAN!"
X System system.exeAdded by various WORMS and TROJANS!
X system regedit -s system.dllHomepage hijacker
X system systemsearch.htaJetseeker.com hijacker
X System dcomx.exe"Added by the CIREBOT TROJAN!"
X system Explorer.exe"Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X System YPager.exe"Added by the JUNTADOR.K TROJAN! Note - this is not Yahoo! Messenger"
X system outlook.exe"Added by the MIMAIL.Q WORM! Note that the valid MS Outlook executeable is located in the Program FilesMicrosoft OfficeOffice directory wheras this one is found in the Windows or Winnt directory"
X System Atira.exe"Added by the KOTIRA VIRUS!"
X SYSTEM lsas.exe"Added by the SPYBOT.CJ WORM!"
X System kernels32.exe"Added by the DLOADER-FC TROJAN!"
U System sysctrl.exe"Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance those copies will be identified as spyware"
X System csrss.exe"Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X System svchost.exe"Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X system lsasse.exe"Added by the RBOT-YL WORM!"
X System systray.exe"Added by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process"
X System abcdefg.exe"Added by the HARWIG-B WORM!"
X System cber.exeAdded by an unidentified TROJAN!
X System serwin.exe"Added by the LDPINCH-BN TROJAN!"
X System svch?st.exe"Added by the LDPINCH-BF TROJAN!"
X System system.exe (74295303)"Added by the VB-IU WORM!"
X System WINL0G0N.EXE"Added by the BANCOS-DB TROJAN!"
X System wumgrd32.exe"Added by a variant of the RBOT WORM!"
X System SPOOLSU.EXE"Added by the BANKER-FC TROJAN!"
X System system23.exe"Added by the LEBREAT-D WORM!"
X System windowsps.exe"Added by a variant of the RBOT WORM!"
X SYSTEM d.exe"Added by the MYTOB.LP WORM!"
X System inetinfo.exe"Added by the PARDROP-A TROJAN!"
X system services.exe"Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""HELP"" subfolder of the Windows or Winnt folder"
X SYSTEM VSSMON.exe"Added by the RBOT-AWW TROJAN!"
X SYSTEM wiinlogon.exe"Added by the RBOT-AVG WORM!"
X System kernels64.exe"Added by the VIXUP-S TROJAN!"
X system lsass.exe"Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesCommon Filessystem folder"
X System smss.exe"Added by the AGENT.AEP TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
X System winupd.exe"Added by a variant of the SDBOT WORM!"
X system messenger.exeAdded by an unidentified WORM or TROJAN!
X System kernels1118.exe"Added by a variant of the SDBOT WORM!"
X System wsscntfy.exe"Added by a variant of the SDBOT WORM!"
X SYSTEM windmupdr.exe"Added by a variant of the RBOT WORM!"
X system svcr.exe"Added by the SPYONE TROJAN!"
X System kernels88.exe"Added by the TIBS-PP TROJAN!"
X System kernels8.exe"Added by the TIBS.AI TROJAN!"
X System OeApi.vbs"Added by the AGUI WORM!"
X System Updaterun.exe"Added by the QQHELP-DX TROJAN!"
X System Zap.exe"Added by the MSNVB-D WORM!"
X System BrO_AcT.exe"Added by the SILLYFDC-AL WORM!"
X System Juegs.exe"Added by the CULLER-C WORM!"
X System kernel8.exe"Added by the DLOADR-AOL TROJAN!"
X System kernelwind32.exe"Added by the VXIDL.FT TROJAN!"
X System Xsfr.exe"Added by the CULLER-D WORM!"
X System kernelwind64.exe"Added by the DLOADER.DJD TROJAN!"
X SYSTEM SystemFile.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X system ssclie.exe"Added by the AGENT.LW BACKDOOR!"
X System 64 Driver for Games sys64dvr.exe"Added by the SDBOT TROJAN!"
X System Analyzer lsass32.exe"Added by the SDBOT.CNI WORM!"
X System Applications Profile sap.exe"Added by the RBOT-QF WORM!"
X System Auth system52.exe"Identified as a variant of the Win32:Rizo-E malware"
X System Backup msystem.exeAdult content dialler
X System backup [random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted examples: web.exe soft.exe msxmidi.exe wmplayer.exe as well as completely random ones such as 9a2de006.exe 36c75e3c.exe and so on"
X System Backup Services backups32.exe"Added by a variant of the RBOT WORM!"
X System Boot Check sysload3.exe"Added by the FUBALCA WORM!"
X System Buffer Application buffer32.exe"Added by the SDBOT-UD WORM!"
X System Cache SysCache.exeAdded by an unidentified VIRUS WORM or TROJAN!
X System CGI Manager syscgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
U System Check Rundll32.exe SysDll32.dll SystemCheck"XPCSpy Pro keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X system check updater.exeUnidentified adware downloader
X System Check win_klr32.exe"Added by the DELF-DRA WORM!"
X System Checking wasul.exe"Added by the RBOT.BHM WORM!"
X System Config BF3.EXE"Added by the SPYBOT-DT WORM!"
X System Config sysloadcnf.exe"Added by a variant of the SDBOT WORM! See here"
X System Config Boot syscgboot.exe"Detected by Kaspersky as the AGENT.VWU TROJAN! See here"
X System Config Manager crss.exe"Added by the AGOBOT.GH WORM!"
X System Config Manager smssl.exe"Added by the AGOBOT-ZJ WORM!"
X System Configuration iexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X System Configuration syscfg32.exe"Added by the MYTOB.EA WORM!"
X system configure svchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X System Core Memory syscoremem.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X System CPL manager [random filename]"Added by the RBOT-SR WORM!"
X System CSRSS Patch scrtkfg.exe"Added by the RBOT-ADA WORM!"
X System Database administration systemDA.exe"Added by the DERDERO.B WORM!"
X System Database Administration Support Process sysdasp.exe"Added by the DERDERO.C WORM!"
X System DataBase Root sysdbroot.exe"Added by the QHOST-W TROJAN!"
X System DB Manager sysdbmg.exe"Added by an unidentified WORM or TROJAN! See here"
X System Device devices.exe"Detected by Trend Micro as the AGENT.AFIF WORM! See here"
X System Device Version systemdv.exe"Added by a variant of the RBOT WORM!"
X System Diagnostics sysdiag32.exe"Added by the SDBOT.GEN TROJAN!"
N System DLF cpqdiaga.exeCompaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
U System DLL Resources sysdll.exe"SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself"
X System Document Application nmod.exe"Added by the SDBOT-ABB WORM!"
X System Document Application msdocument.exe"Added by the RANDEX.COX WORM!"
X System Document Application wins.exe"Added by the SDBOT.AUB WORM!"
X System Download Manager SysMgr.exe"Added by the RBOT.CIG WORM!"
X System driver Messenger.exe"Added by the WOOTBOT.GI WORM!"
X System Drivers wingmt.exe"Added by the SDBOT-MG WORM!"
X System Drivers cpsq32.exe"Added by the SDBOT.AXH WORM!"
X System Efficiency Monitor mscedit32.exe"Added by the SDBOT.P TROJAN!"
X System Efficiency Monitor mscommand.exe"Added by the KWBOT.P WORM!"
X System Efficiency Monitor msedit32.exe"Added by the STEPH-B WORM!"
X System Efficiency Monitor svchostx.exe"Added by the KWBOT.E WORM!"
X System Event Manager secsvc.exe"Added by the RBOT.BMY WORM!"
X System Executable DLL Library EXECDLL32.exe"Added by the RANDEX.AZ WORM!"
X System Failure Statistic cnstat.exe"Added by the RBOT-LF WORM!"
X System File Drivers nvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
X System File Startup sys32.exe"Detected by PCTools as the RBOT.OTL WORM! See here"
U System Files Updater System Files Updater.exe"System Files Updater from Flyakiteosx ""will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"""
X system firewall makeini32.exe"Added by the AGOBOT-PS WORM!"
X System Firewalls commandprompt32.exe"Added by the RBOT.BJT WORM!"
X System Guard mhguard.exe"Added by the RBOT-AGU WORM!"
X System Handler LSASS.EXE"Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
X system handler srvhandle.exe"Added by the REDPLUT VIRUS!"
X System handler Pandawas.exe"Added by the BHARAT.A WORM!"
X System Host scvhost.exe"Added by a variant of the RBOT WORM!"
X System Host Manager syshost.exe"Added by the BANWORM-C WORM!"
X System Host Service svchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
X System Information Manager Navcpe.exe"Added by the SDBOT-QB WORM!"
X System Information Manager Msbb.exe"Added by a variant of the IRCBOT TROJAN!"
X System Information Manager iexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X System Information Manager mslog.exe"Detected by Kaspersky as the DELF.AKO TROJAN! See here"
X System Information Manager no.exe"Added by the SPYBOT.NO WORM!"
X System Information Manager syspass.exe"Added by the SDBOT-MO WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list