Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X UpdSys [random filename]Added by the BJ TROJAN!
X Updt Service updt.pif"Added by the RBOT-AYU WORM!"
X updwebmin updwebmin.exe"Added by the BACKDOOR.GEN TROJAN!"
? UPERVGAS UPERVGAS.exe"??"
X Upgrade Sarvice sxchost.exe"Added by a variant of the TOFGER-I TROJAN!"
X Upgrade Service sxchost.exe"Added by the TOFGER-I TROJAN!"
X Upgrade Service winupd.exe"Added by the TOFGER-U TROJAN!"
X upme [filename]"Added by the MUGLY.F WORM!"
X Upme DLLMAN.EXE"Added by the MUGLY.I WORM!"
X upnp upnp.exe"Added by the DLOADR-YT WORM!"
X UPnP Manager upnpman.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X UPNPService WinSVCservice.exe"Added by the AGOBOT.UN WORM!"
U Upromise Upromise.exe"Upromise college savings program"
U Upromise Tray UpromiseTray.exe"System Tray access to the Upromise college savings program"
U Upromise Update UpromiseUa.exe"Updater for the Upromise college savings program"
U Upromise0 Upromise0.exe"Upromise college savings program"
U UpromiseRemindU wjview ...Code"Part of the Upromise saving scheme but associated with Ebates MoneyMaker adware so the choice is yours"
X uprpcw uprpcw.exe"PrivacyProtector misleading security software - not recommended see here"
Y UPS ups.exePowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon)
X UPS UPS32.exe"Added by the FEMOT.O WORM!"
Y UPSentry 2000 upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
Y UPSlim upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
U UPSMON UPSMON.exe"UPSMON Power Management software"
X UPSUtl web.exe"CoolWebSearch parasite variant"
U Uptimer4 Uptimer4.exeUptimer4 is an appbar which displays time date uptime free ram free pagefile cpu usage disk free space battery power IP addresses TCP throughput list of running processes netstat and several more things
X UpTimes service WinUp.exe"Added by the RBOT-AKB WORM!"
X UpToDate uptodate.exe"BrowserAid/BrowserPal foistware"
X uptolate nucle.exeAdded by a variant of the BIFROSE TROJAN!
X upxdn upxdn.exe"Added by the AGENT.NCC TROJAN!"
X upxdnd upxdnd.exe"Added by the JD-A TROJAN!"
X upyxo yujixit.exe"Added by the SDBOT.BIX WORM!"
Y UrlLstCk UrlLstCk.exe"Part of Norton Internet Security. From Symantec - ""UrlLstCk.exe is a necessary file that will be present in C:Program FilesNorton Internet Security. It is a URL Checklist. It should not be disabled"""
N URLMAP Urlmap.exeInstalled by MS Money and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it
Y UrtSvcExe Urt95Svc.exe"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
X urudjeffni winlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder"
X USAR USAR.exe"Ultimate Spyware Adware Remover - not recommended see here"
? Usb Usb.exe"HP related - not sure whether it's required"
X usb SASS.EXE"Added by the FUNSTA-A TROJAN!"
X USB 2.0 Driver updateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
X USB 2.0 Driver Winsys32.exe"Added by the AGOBOT-QM WORM!"
X USB 2.0 Driver updateXP.exe"Added by the AGOBOT-QP WORM!"
X USB 2.0 Driver winsystem.exe"Added by the AGOBOT-QS WORM!"
X USB 2.0 Driver UpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
X USB 2.1 Driver winupdate1.exe"Added by a variant of the RBOT WORM!"
X USB controller Svcmm32.exeSvcMM backdoor parasite downloader
X USB Device servicelog.exe"Added by the WOOTBOT.CB WORM!"
X USB Device win32usb.exe"Added by the FORBOT-BQ WORM!"
X USB Device Server! usbserver.exe"Added by a variant of the IRCBOT TROJAN!"
X USB Driver4 UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
X USB Drivers1 msupdate.exe"Added by a variant of the RBOT WORM!"
X USB Driverz2 msnplus1.exe"Added by the SDBOT-XQ WORM!"
X USB Fix 1.1 wuservices.exe"Added by a variant of the SDBOT WORM!"
X USB Fixes wuafix.exe"Added by the RBOT-ABV TROJAN!"
X USB Hardware Monitoring USBhardware.exe"Added by the RBOT-NN WORM!"
X USB Hardware326 Monitoring USBhardware326.exe"Added by a variant of the SPYBOT WORM!"
X USB Hardware32c Monitoring USBHARDWARE32C.EXE"Added by the RBOT-UU WORM!"
X USB Host Service usbsvc.exe"Added by the RBOT-GG WORM!"
? USB Hub Keyboard Patch SKBPATCH.EXEUSB HUB Update
X USB MS Update USBS.exe"Added by a variant of the RBOT WORM!"
Y USB SECURITY DEVICE CoInstaller JupitCo.exe"ButterflyMedia USB Flash drive related - required for the password security feature to work"
X USB Updates mservices.exe"Added by a variant of the SDBOT WORM!"
X USB Updates msfirewalls.exe"Added by a variant of the RBOT WORM!"
X USB Updates 2 wugfixx.exe"Added by a variant of the RBOT WORM!"
N USB2Check PCLECoInst.dll"Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system"
X USBConfigration2 wmmndir.exe"Added by the AGOBOT-SV WORM!"
X UsbD smss32.exe"Adware - detected by Kaspersky as the AGENT.CJ TROJAN!"
X UsbD svhost32.exe"Added by the AGENT.IB TROJAN!"
X Usbd usb_d.exe"Added by the CIDRA-A TROJAN!"
X UsbD [path to trojan]"Added by the CIDRA-F TROJAN!"
U USBDetector USBDetector.exeUSBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
U USBDetector UDetect.exeUSB tray icon/detection for external Belkin (and maybe other makes) under Win98
X USBDrives msfirewalI.exe"Added by the RBOT-ABP WORM!"
X usbdrv servicetask.exe"Added by a variant of the SDBOT WORM!"
X USBHWDRV gam.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWDRV msdc.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWDRV sst4.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWINFO mac.exe"Added by the LOWZONE-I TROJAN!"
X USBHWINFO [path to trojan]"Added by the LOWZONE-I TROJAN!"
X USBHWINFO sst6.exe"Added by the LOWZONE-I TROJAN!"
U USBMMKBD usbmmkbd.exeUSB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version no longer pings a server when on-line wheras the older version did but did not transmit any user information
U USBMonit.exe USBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
X usbn usbn.exe"Adult content dialer - detected by Kaspersky as the SMALL.AFA TROJAN!"
X usbn [path to trojan]"Added by the HOGIL-C TROJAN!"
U USBPhoneforSkype USBPhoneforSkype.exe"USBPhoneForSkype uses Skype to dial out from a generic USB phone"
Y USBPNP USBPNP.exeSiPix digital camera Twain USB driver
N USBTA usbtapnp.exe"System Tray access for the BeWAN Gazel 128 USB ISDN adapter"
? USBToolTip USBTip.exe"Related to Pinnacle Systems Inc. What does it do and is it required?"
X USDR6cw USDR6cw.exe"SystemDoctor misleading malware remover - not recommended see here"
X useful-soft svchst.exe"Added by the STARTPA-HH TROJAN!"
X user user32.exe"Added by the BINGHE TROJAN!"
X User .exe"Added by the PUNYA-B WORM!"
X User Debug Manager usndebug.exe"Added by a variant of the SPYBOT WORM! See here"
X User Host usnhost.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Hosting Service usnhost.exe"Detected by Trend Micro as the IRCBOT.SN WORM! See here"
X User Input Services CTFMON32.EXE"Added by the MANCSYN.AK TROJAN!"
U User Logger UsrLog.exe"UserLogger commercial surveillance software that logs keystrokes programs used and computer ID information. It also captures screenshots can hide its presence on the computer and can be disguised in the Windows Task list. Uninstall this software if you did not install it yourself"
X user logon [path to worm]"Added by the PAHATIA-A WORM!"
X user logon user logon.exe"Added by the PAHATIA.A WORM!"
X User Manager fcllls.exe"Added by the ZAGABAN-B TROJAN!"
X User Messages usrmsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Messages Manager usnmsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Messenger Manager usnmsgr.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Servicer usnsrvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Services usersvc.exe"Added by the REVCUSS.A TROJAN!"
X User Services usrsvc.exe"Added by the IRCBOT.SN WORM!"
X User Sharing usrshare.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Sharing Manager usnsharen.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Sharing Server usnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Sharing Services usnsvc.exe"Added by a variant of the KOBOT-C WORM!"
X User Sharing Wizard usnshare.exe"Detected by Trend Micro as the IRCBOT.GS WORM! See here"
X User23.exe DIAL.exeThis is a trojan trying to disguise itself as User32.dll
X User32 [filename]"Added by the NETTRASH TROJAN!"
X userd systems.com"Added by the OUTLAW-A WORM!"
N UserFaultCheck dumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
X Userfile Sharing Serv usnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Userfile Sharing Server usnserv.exe"Added by a variant of the IRCBOT TROJAN!"
X Userinit lsass.exe"Added by the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Program Files%#92;Common Files"
X userinit winlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Userinit lsass.exe"Added by a variant of the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesCommon FilesSystem folder"
X userinit smss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X userinit choo_003956f4"Added by the PEED.16896 TROJAN!"
X userinit ntos.exe"Added by the AGENT-ECU TROJAN!"
X Userinit cologsver.exe"Added by the DROPPER.DJO TROJAN!"
X UserInit StartUp rpcxuisu.exe"Added by a variant of the SDBOT WORM!"
X userinit.exe userinit.exe"Added by the HAXDOOR-DP TROJAN!"
X userint32 userint32.exe"Added by an unidentified TROJAN via an Instant Message that says ""This was cool check it out here."" Also contains Aurora popups"
X USERINTERFACE REPORT3R M0USE.exe"Added by the MYTOB.HS WORM!"
X Userinterface Reporter fuuuucktttttt.exe"Added by the MYTOB-DK WORM!"
X Userinterface Reporter srv32.exe"ISTBar adware"
X UserSystem [filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
X userun32 userun32.exe"Added by the LYDRA-B TROJAN!"
X ushli sscbltqu.exeObtained from an MP3 search list site. Also generates random processes on reboot
U USIUDF_Eject_Monitor USISrv.exe"Added by Ulead DVD Moviefactory. This program monitors your DVD or CD drives and alerts when you eject the media or have no media present"
X usnsvc.exe usnsvc.exe"Detected by Trend Micro as the SPYBOT.AMD WORM! See here"
X usrgtway.exe syswrun4x.exe"Added by the MITGLIEDER.E TROJAN!"
N USRobotics 802.11g Wireless Network Utility USRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties"
N Usrobotics Online Registration ??Pop-up reminding customers to register their products online at US Robotics
Y USRpdA USRmlnkA.exeModem driver files from US Robotics
X Usrr rncr.exe"PurityScan/Clickspring adware"
X Usrr rpen.exe"PurityScan/Clickspring adware"
? USRSTA USRSTA.exe"Wireless Card controller. What does it do and is it required?"
? USRSTA.EXE USRSTA.EXE"Wireless Card controller. What does it do and is it required?"
N USSShReg USSSHREG.EXERegistration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
U UStorag ustorage.exe"U-Storage is application software running under Microsoft Windows it provides functions and utility to manage STF flash drive (USB drive) for security partition boot-ability and recovery. See note"
N Ustorage Ustorage.exe"Maintenance tool (enable security functions) for a USB drive from Pretec"
X utasvc rundll32.exe utasvc.dllstart"Added by the AKBOT-AB WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""utasvc.dll"" file is found in %System%"
? Utility Ping UTILIT~1.EXE"??"
N UtilityPro UtilityPro.exe"IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions"
Y UTILsInst N/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
N Utopia Angel Angel.exe"Calculator for the online Utopia game"
X uvnx uvcx.exe"Added by the DLOADR-AWF TROJAN!"
X uvnx uvnx.exe"Added by the SMALL.CUL TROJAN!"
U UVS10 Preload uvPL.exe"Related to Ulead VideoStudio video editing and DVD authoring software"
X uwa7pcw uwa7pcw.exe"WinAntiVirus Pro 2007 misleading virus software - not recommended see here"
X uwas7cw uwas7cw.exe"WinAntiSpyware spyware remover - not recommended see here"
X uwyrl uwyrl.exe"Added by the PHEL.A TROJAN!"
X uwyw.exe yujixit.exe"Added by the SDBOT.BGB WORM!"
? v WMPVer.EXE"Dritek System Inc. 3D Mouse related. Is it required?"
U V.92 Modem On Hold Ltmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
U V0220Mon.exe V0220Mon.exe"Creative Live! Cam Console Auto Launcher"
U V0230Mon.exe V0230Mon.exe"Creative Live! Cam Console Auto Launcher"
Y V0250Mon.exe V0250Mon.exePart of Creative Webcam Launcher
Y V128IID Rundll32.exe v128iitw.dll STB_InitTweakLoads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages
? V128IITV ??"Loads drivers for some STB graphics cards. May be related to such a card with a TV out option?"
? V66SHELL V66SHELL.EXE"It looks to be part of the display driver set for ASUS V3800 V6600 and V6800 display adapters. Probably a system tray quick access control?"
U va10key va10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
X VaCtrls v7Downloader detected as a variant of the ALPHABET TROJAN!
Y Vade Retro Outlook Express Vaderetro_oe.exe"Vade Retro anti-spam software for Outlook Express from GOTO software products"
Y VAGCtrl VAGCTRL.EXE"Vexira Antivirus - virus scanner from Central Command"
Y VAGuard VAGNT.exe"Vexira Antivirus - virus scanner from Central Command"
U VAIO Action Setup (Server) VAServ.exeSony Vaio utility that auto-launches selected applications when you plug in a digital video camera digital still camera etc. via iLink (FireWire) or USB
U VAIO Recovery PartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
U VAIO Update 2 VAIOUpdt.exeRelated to Sony Vaio Update service
X ValidData [path to trojan]"Added by the RANKY.H TROJAN!"
X valuename svchosts.exe"Added by a variant of the SDBOT WORM!"
X ValueS0ft [random filename]"Added by a variant of the SPYBOT WORM! See here"
X ValueX [random filename]"Detected by Trend Micro as the IRCBOT.EE TROJAN! See here"
X vb6 vb6.exe"Added by the MUGLY.D WORM!"
X vbcdtm [random filename]"Added by a variant of the SLAPER TROJAN!"
X vbe [random name].vbe"Added by the UISGON-A WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list