Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows Debugging Tools updatecfg.exe"Added by the RBOT-AXU WORM!"
X Windows Default Configuration svchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
Y Windows Defender MSASCui.exe"Related to Windows Defender Microsoft (anti-spyware) tool"
X WINDOWS DENEME deneme.exe"Added by the MYTOB-CR WORM!"
X Windows Desktop Controler windesktop.exe"Added by the SDBOT-XH WORM!"
X Windows Desktop Daemon winpadg.exe"Added by a variant of the SPYBOT WORM!"
X Windows Dialup Service dialup.exe"Added by the AGOBOT.AAH WORM!"
X Windows DLL host winupd32.exe"Added by a variant of the SPYBOT WORM!"
X Windows DLL Host dllhost32.exeAdded by an unidentified WORM or TROJAN!
X Windows DLL Loader RUNDLL16.EXE"Added by the DOMWIS TROJAN!"
X Windows DLL Loader defragfat32z.exe"Added by the LINKBOT.A WORM!"
X Windows DLL Loader rundll32.exe"Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder
X Windows DLL Loader defragfat32pi.exe"Added by the RBOT-QQ WORM!"
X Windows DLL Loader defragfat39.exe"Added by the POEBOT-C WORM!"
X Windows DLL Loader defragfatz.exe"Added by the LINKBOT.H WORM!"
X Windows DLL Loader defragfat32.exe"Added by the SDBOT-SS WORM!"
X Windows DLL Loader defragfat32abc.exe"Added by the RBOT-RG WORM!"
X Windows DLL Loader wdevice.exe"Added by a variant of the SDBOT WORM!"
X Windows DLL Loader SYSCFG16.EXE"Added by the DOMWIS-N WORM!"
X Windows DLL Loader WINCFG32.EXE"Added by the AGOBOT-TE WORM!"
X Windows DLL Services winsvc32.exe"Added by the RBOT-ZF WORM!"
X Windows DLL Services svchost.exe"Added by the AGENT.H spyware! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X Windows DLL Services system.exe"Added by the AGENT.H spyware"
X Windows DLL Tracker spoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
X Windows DLL Verifier xptl.exe"Added by a variant of the RBOT WORM!"
X Windows DLL Verifier windlls.exe"Added by the RBOT-AZQ WORM!"
X Windows DNS windns.exe"Added by the SDBOT-XU WORM!"
X Windows DNS Daemon windnsd.exe"Added by the WOOTBOT.AS WORM!"
X Windows Domain Name Drivers windns.exe"Added by the FORBOT-EP WORM!"
X Windows DOS dosw.exe"Added by the SALAY-A WORM!"
X Windows Download Manager windlmngr.exeAdded by an unidentified TROJAN!
X Windows Drive Compatibility System32Driver32.exe"Added by the SUPOVA.Z WORM!"
X Windows Driver winxpdriver.exe"Added by the WOOTBOT.EE WORM!"
X Windows Driver Adapter svchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in a ""drivers"" subfolder"
X Windows Driver Services msdrvs32.exe"Added by the WOOTBOT.L WORM!"
X Windows drivers update windowsupdate.exe"Added by the RBOT-ACE WORM!"
X Windows Dynamic Loading Header winDLL32.exe"Added by a variant of the SDBOT WORM!"
X Windows Executable winmys.exe"Added by the RBOT-ABO WORM!"
X Windows ExpIorer [random filename]"Added by the RBOT-AKO WORM!"
X Windows Explorer [filename].exe"Added by the SDBOT TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
X Windows Explorer Lsas.exe"Added by the GAOBOT.AO WORM!"
X Windows Explorer olecom32.exeAdded by an unidentified WORM or TROJAN!
X Windows Explorer EEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
X Windows Explorer explorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder"
X Windows Explorer explorer.pif"Added by the RBOT-AID WORM!"
X Windows Explorer system32.exe"Added by the RBOT-AJH WORM!"
X Windows Explorer Shell Winexec32.exe"Added by the REDIST.B WORM!"
X Windows Explorer SP2 csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located a JavaBeans subfolder"
X Windows Explorer Update Build 1142 EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
X Windows Explorer-3212 WINRE16.EXE"Added by the HARDOC WORM!"
X Windows Extensions for Win32 winprgs32.exe"Added by the SDBOT.AFA WORM!"
N Windows Eyes ??"For blind people
X Windows FAT 32 WINFAT32B.exe"Added by the SPYBOT-AGT WORM!"
X Windows File Protection winprotect.exe"Added by the AGOBOT.JB WORM!"
X Windows Firewal Lsess.exe"Added by a variant of the RBOT WORM!"
X Windows Firewall WindowsFirewall.exe"Added by the MYTOB.AO WORM!"
X Windows Firewall Log winlog.exeAdded by an unidentified WORM or TROJAN!
X Windows Firewall Manager msfw.exe"Added by the RBOT.WR WORM!"
X Windows firewall manager chh.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows firewall manager msguard.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows Firewalll scvhost.exe"Added by the RBOT-EK WORM!"
X Windows Firewalll sphost.exe"Added by a variant of the RBOT WORM!"
X Windows Firewalll svvhost.exe"Added by a variant of the RBOT WORM!"
X Windows Firewalll winmu.exe"Added by a variant of the RBOT WORM!"
X Windows Fix integator.exe"Added by the SDBOT.ZAB WORM!"
X Windows Fixes Systems elite.exe"Added by the MYTOB.EG WORM!"
X Windows FormatAd WinForm.exeWindupdates adware variant
X Windows Frame Works frmwrks32.exe"Added by a variant of the RBOT WORM!"
X WINDOWS FUCK BY CLASIC fuck.exe"Added by the ZOTOB.H or ZOTOB.J WORMS!"
X Windows Generic Proc procmsg.exe"Added by the ALLIM.B WORM!"
X Windows GMT32 wingmt32.exe"Added by the MYTOB.KM WORM!"
X Windows Graphics Loaders wingraphics.exe"Added by the SPYBOT.JG WORM!"
U Windows Guardian thehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
U Windows Guardian Fawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
X Windows Help mailinfo.exe"Added by the MYTOB.JX WORM!"
X Windows Help File winhelper32.exe"Added by the SDBOT-QK TROJAN!"
X Windows Help Manager svchost32.exe"Added by the RBOT-OZ WORM!"
X Windows Help Service winhelpsv.exe"Added by the RBOT-LP WORM!"
X Windows Help Service winhlp.pif"Added by the RBOT-AKW WORM!"
? Windows Help System Help.pif"??"
X Windows Host hosts.exe"Added by the KELVIR.U WORM!"
X Windows Host winhost.exe"Added by the PRYSAT TROJAN!"
X Windows Host Device hostsvc.exe"Added by the ZOOTY-A WORM!"
X Windows Host Name lmass.exe"Added by the GAOBOT.O WORM!"
X Windows Host Service scvhosts.exe"Added by the SPYBOT.NLI WORM!"
X Windows Host Service host.exe"Added by KELVIR.AN WORM!"
X Windows Host Service svchoste.exe"Added by the KELVIR.BF WORM!"
X Windows Host Service svchosts32.exe"Added by the KELVIR.AW WORM!"
X Windows Host32 Starter hostserv.exe"Added by the SDBOT-WU WORM!"
X Windows Hosts hosts.exe"Added by the KELVIR-O TROJAN!"
X Windows HP Drivers hpdmws.exe"Added by the SDBOT.AQU WORM!"
X Windows HTML file reader Sysconf32.exe"Added by the NOOMY.A WORM!"
X Windows HTTP services winhttps.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Icons Manager wicomgr.exe"Added by the RBOT-AIF WORM!"
X WINDOWS ID SYSTEM wID32.exe"Added by the MYTOB.LN WORM!"
X Windows iMessenger Messenger winimsg.exe"Added by the ALLIM.A WORM!"
X Windows Incontext InSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
X Windows installer winstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
X Windows Installer ntdll.exeAdded by an unidentified WORM or TROJAN!
X Windows Internet Protocol winproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
X Windows Internet Protocol deinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
X Windows Internet Service wininet.exe"Added by the RBOT-AUX WORM!"
U Windows IP Security ipsec.exe"Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
X Windows IPv6 Drivers wipv6.exe"Added by the SDBOT-VJ WORM!"
X Windows Java Update weatherBug32.exe"Added by a variant of the RBOT WORM!"
X Windows JavaScript Daemon Winjsd.exe"Added by the WOOTBOT.AF WORM!"
X Windows Kernel 64 kernal64.exe"Added by the YIMP-B WORM!"
X Windows Kernel System Service wkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows kev Messenger mskev.exe"Added by the SDBOT-XV WORM!"
X Windows live Support wlmsngr.exe"Added by the RBOT-BKL WORM!"
? Windows Load windows.com"??"
X Windows Loader wstart32.exe"Added by the GAOBOT.CA WORM!"
X Windows Loader winServices.pifReported by Kaspersky Anti-Virus as the CARDSPY.D TROJAN!
X Windows Loader Service civsc.exe"Added by a variant of the RBOT WORM!"
X windows Loadxm Win_.exe"Added by the FODDER-A TROJAN!"
X Windows Local Services localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcman.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services websvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Logger winlog.exe"Added by the NSHADOW-B TROJAN!"
X Windows logging winlogd.exe"Added by the RBOT-ON WORM!"
X Windows Login explored.exe"Added by the GAOBOT.SY WORM!"
X Windows Login winlog.exe"Added by the AGOBOT.MG WORM!"
X Windows Login Folder winzep.exe"Added by the AGOBOT-TZ WORM!"
X Windows Login Manager winlogin.exe"Added by a variant of the SDBOT WORM!"
X Windows Login Security winlogin.pifAdded by an unidentified WORM or TROJAN!
X Windows Login Service winlog.exe"Added by the RBOT-AFN WORM!"
X Windows Login Service winlogin.pif"Added by the SDBOT-ACU WORM!"
X Windows Logon winlogin.exe"Added by the SPYBOT-C TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list