Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows Application Layer walg32.exe"Added by the AGOBOT.ATN WORM!"
X Windows Application Layer Gateway walg32.exe"Added by the AGOBOT-AAZ WORM!"
X Windows ARP Detectionc nvudlsp.exe"Detected by Kaspersky as the AGENT.LMW BACKDOOR! See here"
X Windows ARP Detectionc winlogon.exe"Detected by Trend Micro as the RBOT.EAB WORM! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows ARP Detectioncx winlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Windows ASN Service rge.exe"Added by the RBOT-AOK WORM!"
X Windows ASN Service [random filename]"Added by the AGOBOT-TC WORM!"
X Windows Audio Components nncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Audio Control ppnsvc.exe"Added by the HAM TROJAN!"
X Windows Audio Layer narsvc.exe"Detected by Trend Micro as the IRCBOT.AFT TROJAN! See here"
X Windows Audio Panel nppsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Audio Startup nndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
X Windows Audio System nndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Authority Service lsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X windows auto update msblast.exe"Added by the BLASTER.B WORM!"
X windows auto update penis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
X Windows Auto Update winupdater.exe"Added by the SDBOT.TF WORM!"
X Windows auto update bazzi.exe"Added by the AHKER.E WORM!"
X Windows auto update LSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process which should not appear in Msconfig/Startup!"
X Windows Auto Updater WINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note that there is a space at the beginning of the filename ie "" WINDOWSUPDATE.EXE"""
X Windows Automatic Update wuamgrder.exe"Added by a variant of the RBOT WORM!"
X Windows Automatic Updater windrg.exe"Added by a variant of the RBOT WORM!"
X Windows Automatic Updates dvldr.exe"Added by the RBOT.MF WORM!"
X Windows Automatical Updater dcz.exe"Added by the RBOT.CXS WORM!"
X Windows AutomaticUpdater runddls.exe"Added by a variant of the RBOT WORM!"
X windows automation mslaugh.exe"Added by the BLASTER.E WORM!"
X Windows Automation msdspr.exe"Added by the SOLAME.A WORM!"
X Windows Autostart Loader notepad32.exe"Added by a variant of the RBOT WORM!"
X Windows Ba?lang?? Dosyas? sistem.exe"Added by the MUZK WORM!"
X Windows backup systemss.exe"Added by a variant of the SPYBOT WORM!"
X Windows Backup Configuration IEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Windows Boot winboot.exe"Detected by Trend Micro as the AGENT.HBD TROJAN! See here"
X Windows Boot windowsboot.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Booter winboot.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Booter! winbooter.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Bootup ms-wks32.exe"Added by the RBOT-AFM WORM!"
X Windows Bootup Systemwks32.exe"Added by a variant of the RBOT WORM!"
X Windows Bootup task-mngr.exe"Added by the RBOT-AWP WORM!"
X Windows Browser Services browser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Browser Services browser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Browser Services browser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Browser Services Browsr32.exe"Detected by Kaspersky as the IRCBOT.BUR TROJAN! See here"
X Windows Browser Services browsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows bypass security SMSS Service SbiCvy.exe"Added by the RBOT-GRF WORM!"
X Windows Clean-Up Pro WINDOWS CLEAN-UP PRO.Exe"Windows Clean-Up Pro spyware remover - not recommended see here"
X Windows Cleaner Service winclean.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Client Service 32 csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
X Windows Client/Server Runtime Server csrs.exe"Added by the RBOT.KD WORM!"
X Windows CODE Fix Msy Startups msyh32.exe"Added by the AGOBOT.AKK WORM!"
X Windows Command wincmd.exe"Added by the RBOT.ANV WORM!"
X Windows Communicator wincomm.exe"Added by the AGOBOT-BH WORM!"
X Windows Communicator for NT/XP osndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
X Windows Compliant [random filename]"Added by the RBOT-IR WORM!"
X Windows Computer Browser bcwsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Conf windowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Config SSYS.EXE"Added by the SPYBOT-DA WORM!"
X Windows Config wins.exe"Added by the SPYBOT.JR WORM!"
X Windows Config RUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is not the Windows system file of the same name as described here"
X Windows Config pvphost.exe"Added by a variant of the SLAPER TROJAN!"
X Windows Config winconfig.exe"Detected by Trend Micro as the IRCBOT.BAP BACKDOOR! See here"
X Windows Config Connection msicll.exe"Added by the RBOT-EXQ WORM!"
X Windows Config Loader Wincfg32.exe"Added by the SILVERFTP TROJAN!"
X Windows Config Manager winconf.exe"Added by the RBOT-AIT WORM!"
X Windows Config System config.exe"Added by a variant of the SDBOT WORM!"
X Windows Configuration wsys32.exe"Added by the GAOBOT.FB WORM!"
X Windows Configuration wincfg32.exe"Added by the MYTOB.ED WORM!"
X Windows Configuration Loader asclt.exe"Added by the SDBOT-OA WORM!"
X Windows Configuration Utility winxupdate.exe"Added by the AGOBOT.LW WORM!"
X Windows Configurator winconf.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows connection manager Internet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one it copies it's self under three other file names and folder locations"
X Windows Console wkssvc.exe"Added by the SDBOT-DJX WORM!"
X Windows Console Component wrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Console Monitor [path to worm]"Added by the KEDEBE WORM!"
X Windows Console Monitor gcasAV32.exe"Added by the KEDEBE-A WORM!"
X Windows Console Norms wnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Console Source wnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Control Control.exeBrowser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!
X Windows ControlAd WinCtlAd.exeWindupdates adware variant
X Windows Core Kernel Update win32bootcfg.exe"Added by the RANCK-EL TROJAN!"
X Windows CPU host winbog32.exe"Added by a variant of the RBOT WORM!"
X Windows Critical Alert wincrt.exe"Added by the ALEDO-A TROJAN!"
X Windows Custom Services CSRCS.EXE"Added by the SPYBOT-EI WORM!"
X Windows Data Server autodisc.exe"Added by the SPYBOT-CB WORM!"
X Windows Data Server [random name].exe"Added by the SPYBOT-DS WORM!"
X Windows Database WinDat.exeAdded by an unidentified WORM or TROJAN!
X Windows Database wiinsvc.exe"Added by the AGOBOT-RU WORM!"
X Windows Dcom2 Fix mscom32.exe"Added by the RBOT-QT WORM!"
X Windows DDE Loader windde32.exe"Added by the SDBOT-UZ WORM!"
X Windows debug logging winlogg.exe"Added by the RBOT-OY WORM!"
X Windows debug logging winloggs.exe"Added by the RBOT-QN WORM!"
X Windows Debugger windbg.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Windows Debugger msdbg32.exe"Added by a variant of the RBOT WORM!"
X Windows Debugger windbg32.exe"Added by the ZOTOB.L WORM!"
X Windows Debugging Tools updatecfg.exe"Added by the RBOT-AXU WORM!"
X Windows Default Configuration svchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X Windows Default Server wfdmgrsp.exe"Detected by Kaspersky as the IRCBOT.BCX TROJAN! See here"
X Windows Default Server winampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
Y Windows Defender MSASCui.exe"Related to Windows Defender Microsoft (anti-spyware) tool"
X Windows Defender wdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X Windows Defender Adds wda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X Windows Defender Monitor wdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X Windows Defender Updater wdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
X WINDOWS DENEME deneme.exe"Added by the MYTOB-CR WORM!"
X Windows Desktop Controler windesktop.exe"Added by the SDBOT-XH WORM!"
X Windows Desktop Daemon winpadg.exe"Added by a variant of the SPYBOT WORM!"
U Windows Desktop Search WindowsSearch.exe"Windows Desktop Search from Microsoft"
X Windows Dialup Service dialup.exe"Added by the AGOBOT.AAH WORM!"
X Windows Disk Defragmenter wpabaln32.exe"Added by the BANCOS-ASJ TROJAN!"
X Windows Disk Manager cmnvc.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Display Coupler display.exe"Added by the IRCBOT-YS TROJAN!"
X Windows DLL host winupd32.exe"Added by a variant of the SPYBOT WORM!"
X Windows DLL Host dllhost32.exeAdded by an unidentified WORM or TROJAN!
X Windows DLL Loader RUNDLL16.EXE"Added by the DOMWIS TROJAN!"
X Windows DLL Loader defragfat32z.exe"Added by the LINKBOT.A WORM!"
X Windows DLL Loader rundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
X Windows DLL Loader defragfat32pi.exe"Added by the RBOT-QQ WORM!"
X Windows DLL Loader defragfat39.exe"Added by the POEBOT-C WORM!"
X Windows DLL Loader defragfatz.exe"Added by the LINKBOT.H WORM!"
X Windows DLL Loader defragfat32.exe"Added by the SDBOT-SS WORM!"
X Windows DLL Loader defragfat32abc.exe"Added by the RBOT-RG WORM!"
X Windows DLL Loader wdevice.exe"Added by a variant of the SDBOT WORM!"
X Windows DLL Loader SYSCFG16.EXE"Added by the DOMWIS-N WORM!"
X Windows DLL Loader WINCFG32.EXE"Added by the AGOBOT-TE WORM!"
X Windows DLL Services winsvc32.exe"Added by the RBOT-ZF WORM!"
X Windows DLL Services svchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Windows DLL Services system.exe"AGENT.H spyware"
X Windows DLL Tracker spoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
X Windows DLL Verifier xptl.exe"Added by a variant of the RBOT WORM!"
X Windows DLL Verifier windlls.exe"Added by the RBOT-AZQ WORM!"
X Windows DNS windns.exe"Added by the SDBOT-XU WORM!"
X Windows DNS Daemon windnsd.exe"Added by the WOOTBOT.AS WORM!"
X Windows Domain Name Drivers windns.exe"Added by the FORBOT-EP WORM!"
X Windows DOS dosw.exe"Added by the SALAY-A WORM!"
X Windows DotFix live msdotfix.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Download Manager windlmngr.exeAdded by an unidentified TROJAN!
X Windows Drive Compatibility System32Driver32.exe"Added by the SUPOVA.Z WORM!"
X Windows Driver winxpdriver.exe"Added by the WOOTBOT.EE WORM!"
X Windows Driver windrive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Driver Adapter svchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in a ""drivers"" subfolder"
X Windows Driver Foundation MTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
X Windows Driver Services msdrvs32.exe"Added by the WOOTBOT.L WORM!"
X Windows Driver Sup windvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Driver! windrive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Driver! windriver.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Drivers ssms.exe"Added by the RBOT-AT WORM!"
X Windows drivers update windowsupdate.exe"Added by the RBOT-ACE WORM!"
X Windows Dynamic Loading Header winDLL32.exe"Added by a variant of the SDBOT WORM!"
X Windows Email Server wmserv.exe"Added by the FOUNDU-AWORM!"
X Windows Essensials mvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Event Detection wecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Event Provider wposvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Event Section sntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Event Service winserv.exe"Detected by Kaspersky as the SDBOT.XD TROJAN! See here"
X Windows Executable winmys.exe"Added by the RBOT-ABO WORM!"
X Windows Executer bling.exe"Added by the SDBOT-DFT WORM!"
X Windows Executer svchostie.exe"Detected by Kaspersky as the EGGDROP.V BACKDOOR! See here"
X Windows ExpIorer [random filename]"Added by the RBOT-AKO WORM!"
X Windows Explorer [filename].exe"Added by the SDBOT TROJAN!"
X Windows Explorer Lsas.exe"Added by the GAOBOT.AO WORM!"
X Windows Explorer olecom32.exeAdded by an unidentified WORM or TROJAN!
X Windows Explorer EEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
X Windows Explorer explorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windows Explorer explorer.pif"Added by the RBOT-AID WORM!"
X Windows Explorer system32.exe"Added by the RBOT-AJH WORM!"
X Windows Explorer explorer32.exe"Added by a variant of the SDBOT WORM!"
X Windows Explorer Windows Explorer.EXE"Added by the VB-EBA WORM!"
X Windows Explorer Services exploresys.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Explorer Shell Winexec32.exe"Added by the REDIST.B WORM!"
X Windows Explorer SP2 csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
X Windows Explorer Update Build 1142 EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
X Windows Explorer-3212 WINRE16.EXE"Added by the HARDOC WORM!"
X Windows Explorer.exe Explorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windows Express pci32b.exe"Detected by PCTools as the BUZUS.C TROJAN! See here"
X Windows Extensions for Win32 winprgs32.exe"Added by the SDBOT.AFA WORM!"
N Windows Eyes ??For blind people gives a voice description of items on the screen. Windows application which gives you total control over what you hear when you hear it and how you hear it. Available via Start -> Programs
X Windows FAT 32 WINFAT32B.exe"Added by the SPYBOT-AGT WORM!"
X Windows File Protection winprotect.exe"Added by the AGOBOT.JB WORM!"
X Windows File System Frame ntframe.exeAdded by an unidentified WORM or TROJAN!
X Windows File Verification Service wfvs.exeAdded by the RANKY.AC TROJAN!
X Windows File XP Manager wfdmgr.exe"Added by the SDBOT.XD TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list