Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X UPNPService WinSVCservice.exe"Added by the AGOBOT.UN WORM!"
U Upromise0 Upromise0.exe"Upromise college savings program"
Y UPS ups.exePowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon)
X UPS UPS32.exe"Added by the FEMOT.O WORM!"
Y UPSentry 2000 upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
Y UPSlim upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
U UPSMON UPSMON.exe"UPSMON Power Management software"
X UPSUtl web.exe"CoolWebSearch parasite variant"
U Uptimer4 Uptimer4.exe"Uptimer4 is an appbar which displays time
X UpTimes service WinUp.exe"Added by the RBOT-AKB WORM!"
X UpToDate uptodate.exe"BrowserAid/BrowserPal foistware"
X upyxo yujixit.exe"Added by the SDBOT.BIX WORM!"
Y UrlLstCk UrlLstCk.exe"Part of Norton Internet Security. From Symantec - ""UrlLstCk.exe is a necessary file that will be present in C:Program FilesNorton Internet Security. It is a URL Checklist. It should not be disabled"""
N URLMAP Urlmap.exe"Installed by MS Money
Y UrtSvcExe Urt95Svc.exe"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
? Usb Usb.exe"HP related - not sure whether it's required"
X usb SASS.EXE"Added by the FUNSTA-A TROJAN!"
X USB 2.0 Driver updateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
X USB 2.0 Driver Winsys32.exe"Added by the AGOBOT-QM WORM!"
X USB 2.0 Driver updateXP.exe"Added by the AGOBOT-QP WORM!"
X USB 2.0 Driver winsystem.exe"Added by the AGOBOT-QS WORM!"
X USB 2.1 Driver winupdate1.exe"Added by a variant of the RBOT WORM!"
X USB controller Svcmm32.exeSvcMM backdoor parasite downloader
X USB Device servicelog.exe"Added by the WOOTBOT.CB WORM!"
X USB Device win32usb.exe"Added by the FORBOT-BQ WORM!"
X USB Driver4 UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
X USB Drivers1 msupdate.exe"Added by a variant of the RBOT WORM!"
X USB Driverz2 msnplus1.exe"Added by the SDBOT-XQ WORM!"
X USB Fix 1.1 wuservices.exe"Added by a variant of the SDBOT WORM!"
X USB Fixes wuafix.exe"Added by the RBOT-ABV TROJAN!"
X USB Hardware Monitoring USBhardware.exe"Added by the RBOT-NN WORM!"
Y USB Hardware326 Monitoring USBhardware326.exe"Added by a variant of the SPYBOT WORM!"
X USB Hardware32c Monitoring USBHARDWARE32C.EXE"Added by the RBOT-UU WORM!"
X USB Host Service usbsvc.exe"Added by the RBOT-GG WORM!"
? USB Hub Keyboard Patch SKBPATCH.EXEUSB HUB Update
Y USB SECURITY DEVICE CoInstaller JupitCo.exe"ButterflyMedia USB Flash drive related - required for the password security feature to work"
X USB Updates mservices.exe"Added by a variant of the SDBOT WORM! - see here"
X USB Updates msfirewalls.exe"Added by a variant of the RBOT WORM!"
X USB Updates 2 wugfixx.exe"Added by a variant of the RBOT WORM!"
N USB2Check PCLECoInst.dll"Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system"
X USBConfigration2 wmmndir.exe"Added by the AGOBOT-SV WORM!"
X UsbD smss32.exe"Adware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj"
X UsbD svhost32.exe"Added by the AGENT.IB TROJAN!"
X Usbd usb_d.exe"Added by the CIDRA-A TROJAN!"
X UsbD [path to trojan]"Added by the CIDRA-F TROJAN!"
U USBDetector USBDetector.exeUSBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
U USBDetector UDetect.exeUSB tray icon/detection for external Belkin (and maybe other makes) under Win98
X USBDrives msfirewalI.exe"Added by the RBOT-ABP WORM!"
X usbdrv servicetask.exe"Added by a variant of the SDBOT WORM!"
X USBHWDRV gam.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWDRV msdc.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWDRV sst4.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWINFO mac.exe"Added by the LOWZONE-I TROJAN!"
X USBHWINFO mmc.exe"Added by the LOWZONE-I TROJAN!"
X USBHWINFO sst6.exe"Added by the LOWZONE-I TROJAN!"
U USBMMKBD usbmmkbd.exeUSB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version no longer pings a server when on-line wheras the older version did but did not transmit any user information
U USBMonit.exe USBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
X usbn usbn.exe"Adult content dialer - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa"
X usbn [path to trojan]"Added by the HOGIL-C TROJAN!"
Y USBPNP USBPNP.exeSiPix digital camera Twain USB driver
N USBTA usbtapnp.exe"System Tray access for the BeWAN Gazel 128 USB ISDN adapter"
? USBToolTip USBTip.exe"Related to Pinnacle Systems Inc. What does it do and is it required?"
X useful-soft svchst.exe"Added by the STARTPA-HH TORJAN!"
X user user32.exe"Added by the BINGHE TROJAN!"
U User Logger UsrLog.exe"UserLogger is a commercial surveillance software program. It logs keystrokes
X User Manager fcllls.exe"Added by the ZAGABAN-B TROJAN!"
X User Services usersvc.exe"Added by the REVCUSS.A TROJAN!"
X User23.exe DIAL.exeThis is a trojan trying to disguise itself as User32.dll
X User32 [filename]"Added by the NETTRASH TROJAN!"
N UserFaultCheck dumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
X Userinit lsass.exe"Added by a variant of the DLOADER-TP TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesCommon Files folder"
X userinit winlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process
X Userinit lsass.exe"Added by a variant of the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesCommon FilesSystem folder"
X userinit smss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This trojan file is found in the Windows or Winnt folder"
X UserInit StartUp rpcxuisu.exe"Added by a variant of the SDBOT WORM!"
X userint32 userint32.exe"Added by an unidentified TROJAN via an Instant Message that says
X USERINTERFACE REPORT3R M0USE.exe"Added by the MYTOB.HS WORM!"
X Userinterface Reporter fuuuucktttttt.exe"Added by the MYTOB-DK WORM!"
X Userinterface Reporter srv32.exe"ISTBar adware"
X UserSystem [filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
X ushli sscbltqu.exeObtained from an MP3 search list site. Also generates random processes on reboot
X usrgtway.exe syswrun4x.exe"Added by the MITGLIEDER.E TROJAN!"
N USRobotics 802.11g Wireless Network Utility USRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
N Usrobotics Online Registration ??Pop-up reminding customers to register their products online at US Robotics
Y USRpdA USRmlnkA.exeModem driver files from US Robotics
X Usrr rncr.exe"PurityScan/Clickspring adware"
X Usrr rpen.exe"PurityScan/Clickspring adware"
? USRSTA USRSTA.exe"Wireless Card controller. What does it do and is it required?"
? USRSTA.EXE USRSTA.EXE"Wireless Card controller. What does it do and is it required?"
N USSShReg USSSHREG.EXERegistration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
U UStorag ustorage.exe"U-Storage is application software running under Microsoft Windows
N Ustorage Ustorage.exe"Maintenance tool (enable security functions) for a USB drive from Pretec"
? Utility Ping UTILIT~1.EXE"??"
N UtilityPro UtilityPro.exe"IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions"
Y UTILsInst N/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
N Utopia Angel Angel.exe"Calculator for the online Utopia game"
X uwyrl uwyrl.exe"Added by the PHEL.A TROJAN!"
X uwyw.exe yujixit.exe"Added by the SDBOT.BGB WORM!"
? v WMPVer.EXE"Dritek System Inc. 3D Mouse related. Is it required?"
U V.92 Modem On Hold Ltmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
Y V128IID "Rundll32.exe v128iitw.dll STB_InitTweak"
? V128IITV ??"Loads drivers for some STB graphics cards. May be related to such a card with a TV out option?"
? V66SHELL V66SHELL.EXE"It looks to be part of the display driver set for ASUS V3800
U va10key va10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
Y VAGCtrl VAGCTRL.EXE"Vexira Antivirus - virus scanner from Central Command"
Y VAGuard VAGNT.exe"Vexira Antivirus - virus scanner from Central Command"
U VAIO Action Setup (Server) VAServ.exe"Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera
U VAIO Recovery PartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
U VAIO Update 2 VAIOUpdt.exe"Related to Sony Vaio Update service. This program is non-essential process to the running of the program
X ValidData [path to trojan]"Added by the RANKY.H TROJAN!"
X valuename svchosts.exe"Added by a variant of the SDBOT WORM!"
X vb6 vb6.exe"Added by the MUGLY.D WORM!"
X VBouncer VirtualBouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VbouncerDL VbouncerInner****.exe [* = random char]"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VbouncerDL VBouncerInner.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VBS.Ipnuker@mm [worm filename].vbs"Added by the NUKIP WORM!"
X VBS_AUTO_UPDATE 0548656X.vbs"Added by the GORMLEZ-A WORM!"
X VBundleOuterDL BundleOuter.EXE"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
X VB_run comctl_32.exeDubious downloader from densmail.com
X VC5MediaPlayer csmss.exe"Added by the DEDLER-B WORM!"
N VC5Play VC5Play.exe"Virtual CD drive emulator - version 5. Available via Start -> Programs"
Y VC6play VC6Play.exeDriver for Virtual CD version 6. Essential to use the software
X VCatch Vcatch.exe"CommonSearch Vcatch - ""antivirus"" software which actually bundles spy/adware itself!"
X VCatch Premium VCatchpre.exe"VCatch antivirus. Considered spyware itself - see here"
N VCDPlayer VCDPlayer.exe"Virtual CD drive emulator. Available via Start -> Programs"
N vcdplayx vcdplayx.exe"CD emulation part of GameDrive & VirtualDrive from Farstone. Not required as starting these programs load this automatically "
U VCDTower VCDTower.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
? VCDWATCH VCDWATCH.EXE"Confirmed as Voyetra CD Watcher as it was found in a Compaq/Voyetra/AS2 directory but what does it do?"
X VCS Host vcshost.exe"Added by the RBOT-FKT WORM!"
N VCSPlayer vcsplay.exe"Virtual CD drive emulator. Available via Start -> Programs"
X VCXD Settings phqg.EXE"Added by the RBOT.BRF WORM!"
U VC_Log keylog.exe"PaqKeylog is a surveillance software program that logs keystrokes and can run in stealth mode. If you didn't install this yourself remove it"
X Vdat Update lalaa.exe"Added by a variant of the RBOT WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list