Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
N WinDates windates.exe"WinDates is a calendar
X windbs winxtc.exe"Added by the AGOBOT-WD WORM!"
X Winde winde.exe"Added by the DLUCA TROJAN!"
X windef Win32sp.vbs"Added by the ANPES WORM!"
X windef windef.exe"Added by the WURMARK-O WORM!"
X Windeows NetStart Service2 tesakrmger.exe"Added by the RBOT-AMY WORM!"
X windhost.exe osrwin32.exe"Added by the BANKER-CB TROJAN!"
X windhost.exe windhost.exe"Added by the BANKER-BV TROJAN!"
X windhost.exe winos.exe"Added by the PWSAGENT-A WORM!"
X windir winrun.exe"Added by the WINBUR.B WORM!"
X Windll Windll.exe"Added by the TRYNOMA TROJAN!"
U WINDLL WSYS.EXE"STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes
X windll windll32.exe"Added by the ASTEF or RESPAN WORMS!"
X WinDLL (wchshield.exe) wchshield.exe"Added by the IRCBOT GEN WORM!"
X Windll.exe Windll.exe"Added by the STEALER TROJAN!"
X Windll32 Windll32.exe"Added by the MSNPWS TROJAN!"
X WinDll32 _WIN32.EXE"Added by the LEGMIR.AQ TROJAN!"
X windllsys32.exe windllsys32.exe"Added by a variant of the MITGLIE-A TROJAN!"
X WinDNS windns32.exe"Added by the GAOBOT.WX WORM!"
X Windoes Kernel kernel32.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
X Window explore.exe"Added by the GAOBOT.ADW WORM!"
X Window Loader Dos32.exe"Added by the GAOBOT.AO WORM!"
X Window Monitor winmon32.exe"Added by the SDBOT.RT WORM!"
X Window service [random filename]"Added by the RBOT-ACH WORM!"
U Window Washer wwDisp.exe"Windows Washer from Webroot Software. Useful utility that deletes safe to remove files
X window.exe window.exe"Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!"
X window2 ssvchost.exe"Added by the IRCBOT.H TROJAN!"
U WindowBlinds wbload.exe"WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
X WindowEnhancer Winex.exe"SCBar foistware variant"
X Windowfdgfds DLL fgfdg Verifier winsecure.exe"Added by the RBOT.CSP WORM!"
X Windowfdgfds DLL fgfdg Verifier winsecure.exe"Added by the RBOT.CSP WORM!"
U WindowFX wfxload.exe"Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
X windown wiusyt.exe"Added by the QQPASS-M TROJAN!"
X WindowRegKey update wins.exe"Added by the SPYBOT.I WORM!"
X Windows services.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""WinSecurity"" subfolder of the Windows or Winnt folder"
X Windows Kernel32.exe"Added by the TENDOOLF WORM!"
X Windows msdos98.exeAdded by the PWSTEAL TROJAN!
X Windows Windows.exe"Added by the KAZMOR.A
X Windows explorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder"
X windows [path to trojan]"Added by the AIMWIN TROJAN!"
X windows hkey.exe"Added by the GAOBOT.AFW WORM!"
X windows system copy.exe"Added by the SALGA.A WORM!"
X Windows gearsec.exe"Added by the STUBBOT-B TROJAN!"
X Windows run.exe"Added by the SPYBOT.OFN WORM!"
X Windows system.exe"Added by the SPYBOT.OBB WORM!"
X WINDOWS windows.exe"Added by the MONBOT-A TROJAN!"
X Windows services.exe"Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in a ""WinSecurity"" subfolder of the Windows or Winnt folder"
X WINDOWS jif.exe"Added by the MYTOB.MK WORM!"
X windows iexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process
X Windows services.exe"Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""Windows"" subfolder"
X Windows smss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X windows svchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X WINDOWS ymssgr.exe"Added by the PS TROJAN! Note - deactivates the MicrosoftInternet Connection Firewall (ICF)"
X Windows (random character) diskcheck.exe"Added by the SINGU.B TROJAN!"
X Windows .Net Manager localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager svcman.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows .Net Manager websvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows 128 Module win128.exe"Added by the FORBOT-ES WORM!"
X Windows 2004 csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""Arquivos de programasWindows 2004Tools"" folder"
X Windows 32 Editor Win32edit.exe"Added by the WOOTBOT.GQ WORM!"
X Windows 32 Rescue win32resc.exe"Added by the FORBOT-EU WORM!"
X Windows 32 Update Windows-Update.exe"Added by a variant of the RBOT WORM!"
U Windows Accelerators setup.exe"KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X Windows AdControl WinAdCtl.exeWindupdates adware variant
X Windows AdService WinAdServ.exeWindupdates adware variant
X Windows AdStatus WinStat.exe"Added by the BLESHARE!DR VIRUS!"
X Windows AdTools WinAdTools.exeWindupdates adware variant
X Windows Anti-Virus Built 32 AntiVirus32.exe"Added by the SDBOT-BG WORM!"
X Windows APCI Verifier dhcpserv.exe"Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
X Windows API Control Task apitsk32.exe"Added by the MYTOB.HI WORM!"
X Windows Application Layer walg32.exe"Added by the AGOBOT.ATN WORM!"
X Windows Application Layer Gateway walg32.exe"Added by the AGOBOT-AAZ WORM!"
X Windows ASN Service rge.exe"Added by the RBOT-AOK WORM!"
X Windows ASN Service [random filename]"Added by the AGOBOT-TC WORM!"
X Windows Authority Service lsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X windows auto update penis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
X Windows Auto Update winupdater.exe"Added by the SDBOT.TF WORM!"
X Windows auto update bazzi.exe"Added by the AHKER.E WORM!"
X Windows auto update LSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
X windows auto update msblast.exe"Added by the BLASTER.B WORM!"
X Windows Automatic Update wuamgrder.exe"Added by a variant of the RBOT WORM!"
X Windows Automatic Updates dvldr.exe"Added by the RBOT.MF WORM!"
X Windows Automatical Updater dcz.exe"Added by the RBOT.CXS WORM!"
X Windows AutomaticUpdater runddls.exe"Added by a variant of the RBOT WORM!"
X windows automation mslaugh.exe"Added by the BLASTER.E WORM!"
X Windows Automation msdspr.exe"Added by the SOLAME.A WORM!"
X Windows Autostart Loader notepad32.exe"Added by a variant of the RBOT WORM!"
X Windows backup systemss.exe"Added by a variant of the SPYBOT WORM!"
X Windows Backup Configuration IEXPLORER.exe"Added by the GAOBOT.AZ WORM!"
X Windows Başlangıç Dosyası sistem.exe"Added by the MUZK WORM!"
X Windows Bootup ms-wks32.exe"Added by the RBOT-AFM WORM!"
X Windows Bootup Systemwks32.exe"Added by a variant of the RBOT WORM!"
X Windows Bootup task-mngr.exe"Added by the RBOT-AWP WORM!"
N Windows Clean-Up Pro WINDOWS CLEAN-UP PRO.Exe"Spyware remover - not recommended
X Windows Client Service 32 csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located a driverswinsdriver subfolder"
X Windows Client/Server Runtime Server csrs.exe"Added by the RBOT.KD WORM!"
X Windows Command wincmd.exe"Added by the RBOT.ANV WORM!"
X Windows Communicator wincomm.exe"Added by the AGOBOT-BH WORM!"
X Windows Communicator for NT/XP osndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
X Windows Compliant [random filename]"Added by the RBOT-IR WORM!"
X Windows Config SSYS.EXE"Added by the SPYBOT-DA WORM!"
X Windows Config wins.exe"Added by the SPYBOT.JR WORM!"
X Windows Config RUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is not the Windows system file of the same name as described here"
X Windows Config Connection msicll.exe"Added by the RBOT-EXQ WORM!"
X Windows Config Loader Wincfg32.exe"Added by the SILVERFTP TROJAN!"
X Windows Config Manager winconf.exe"Added by the RBOT-AIT WORM!"
X Windows Configuration wsys32.exe"Added by the GAOBOT.FB WORM!"
X Windows Configuration wincfg32.exe"Added by the MYTOB.ED WORM!"
X Windows Configuration Loader asclt.exe"Added by the SDBOT-OA WORM!"
X Windows connection manager Internet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
X Windows Console Monitor [path to worm]"Added by KEDEBE WORM!"
X Windows Console Monitor gcasAV32.exe"Added by the KEDEBE-A WORM!"
X Windows Control Control.exe"Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory
X Windows ControlAd WinCtlAd.exeWindupdates adware variant
X Windows Core Kernel Update win32bootcfg.exe"Added by the RANCK-EL TROJAN!"
X Windows CPU host winbog32.exe"Added by a variant of the RBOT WORM!"
X Windows Custom Services CSRCS.EXE"Added by the SPYBOT-EI WORM!"
X Windows Data Server autodisc.exe"Added by the SPYBOT-CB WORM!"
X Windows Data Server [random name].exe"Added by the SPYBOT-DS WORM!"
X Windows Database WinDat.exeAdded by an unidentified WORM or TROJAN!
X Windows Database wiinsvc.exe"Added by the AGOBOT-RU WORM!"
X Windows Dcom2 Fix mscom32.exe"Added by the RBOT-QT WORM!"
X Windows DDE Loader windde32.exe"Added by the SDBOT-UZ WORM!"
X Windows debug logging winlogg.exe"Added by the RBOT-OY WORM!"
X Windows debug logging winloggs.exe"Added by the RBOT-QN WORM!"
X Windows Debugger windbg.exe"Added by an unidentified VIRUS
X Windows Debugger msdbg32.exe"Added by a variant of the RBOT WORM!"
X Windows Debugger windbg32.exe"Added by the ZOTOB.L WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list