Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows FileSharing Service mcwsvc.exe"Detected by Trend Micro as the IRCBOT.AJF TROJAN! See here"
X Windows Firewal Lsess.exe"Added by a variant of the RBOT WORM!"
X Windows Firewall WindowsFirewall.exe"Added by the MYTOB.AO WORM!"
X Windows Firewall svchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Windows Firewall ipservice32.exe"Added by a variant of the RBOT WORM!"
X Windows Firewall rundll32.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Firewall Log winlog.exeAdded by an unidentified WORM or TROJAN!
X Windows Firewall Manager msfw.exe"Added by the RBOT.WR WORM!"
X Windows firewall manager chh.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows firewall manager msguard.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows Firewall Service wfsvc.exe"Added by the IRCBOT-YL WORM!"
X Windows Firewall Updater updatees.exe"Added by the RBOT-GX WORM!"
X Windows Firewall Updater cronos.exe"Added by the RBOT-GBY WORM!"
X Windows Firewall Updater ctfcom.exe"Added by the RBOT-GCB WORM!"
X Windows Firewalll scvhost.exe"Added by the RBOT-EK WORM!"
X Windows Firewalll sphost.exe"Added by a variant of the RBOT WORM!"
X Windows Firewalll svvhost.exe"Added by a variant of the RBOT WORM!"
X Windows Firewalll winmu.exe"Added by a variant of the RBOT WORM!"
X Windows Fix integator.exe"Added by the SDBOT.ZAB WORM!"
X Windows Fixes Systems elite.exe"Added by the MYTOB.EG WORM!"
X Windows FormatAd WinForm.exeWindupdates adware variant
X Windows Frame Works frmwrks32.exe"Added by a variant of the RBOT WORM!"
X Windows Framework frmwrk.exe"Added by the DWNLDR-GWV TROJAN!"
X WINDOWS FUCK BY CLASIC fuck.exe"Added by the ZOTOB.H or ZOTOB.J WORMS!"
X Windows Generic Proc procmsg.exe"Added by the ALLIM.B WORM!"
X Windows Genuine svghost.exe"Added by a variant of the SPYBOT WORM! See here"
X Windows Genuine Validate winservicessss.exe"Detected by PCTools as the IRCBOT.UUI BACKDOOR! See here"
X Windows Global Init ngpsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows GMT32 wingmt32.exe"Added by the MYTOB.KM WORM!"
X Windows Graphics Loaders wingraphics.exe"Added by the SPYBOT.JG WORM!"
X Windows Guard WAUMGRD.EXE"Added by the RBOT-GY WORM!"
U Windows Guardian thehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
U Windows Guardian Fawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
X Windows haz Layer [5 random letters].exe"Added by a variant of the RBOT WORM!"
X Windows Help mailinfo.exe"Added by the MYTOB.JX WORM!"
X Windows Help File winhelper32.exe"Added by the SDBOT-QK TROJAN!"
X Windows Help Manager svchost32.exe"Added by the RBOT-OZ WORM!"
X Windows Help Service winhelpsv.exe"Added by the RBOT-LP WORM!"
X Windows Help Service winhlp.pif"Added by the RBOT-AKW WORM!"
? Windows Help System Help.pif"??"
X Windows Helper winhelp.exe"Detected by Kaspersky as the BANKER.APE TROJAN! See here"
X Windows Helper wsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Hijack Protection comngr.exe"Added by the AGENT-FYD TROJAN!"
X Windows Hijack Protection System commngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
X Windows his Layer pilotGame.exe"Added by the RBOT.GLX WORM!"
X Windows Host hosts.exe"Added by the KELVIR.U WORM!"
X Windows Host winhost.exe"Added by the PRYSAT TROJAN!"
X Windows Host Booter hostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
X Windows Host Device hostsvc.exe"Added by the ZOOTY-A WORM!"
X Windows Host Name lmass.exe"Added by the GAOBOT.O WORM!"
X Windows Host Service scvhosts.exe"Added by the SPYBOT.NLI WORM!"
X Windows Host Service host.exe"Added by the KELVIR.AN WORM!"
X Windows Host Service svchoste.exe"Added by the KELVIR.BF WORM!"
X Windows Host Service svchosts32.exe"Added by the KELVIR.AW WORM!"
X Windows Host32 Starter hostserv.exe"Added by the SDBOT-WU WORM!"
X Windows Hosts hosts.exe"Added by the KELVIR-O TROJAN!"
X Windows Hosts winhosts.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows HP Drivers hpdmws.exe"Added by the SDBOT.AQU WORM!"
X Windows HTML file reader Sysconf32.exe"Added by the NOOMY.A WORM!"
X Windows HTTP services winhttps.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Icons Manager wicomgr.exe"Added by the RBOT-AIF WORM!"
X WINDOWS ID SYSTEM wID32.exe"Added by the MYTOB.LN WORM!"
X Windows Identify sysays.exe"Added by a variant of the SPYBOT WORM! See here"
X Windows Image wintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
X Windows Image Acquisition (WIASC) WIAcs.exe"Added by the RIZO.A TROJAN!"
X Windows Image Acquisition (WIASSC) WIAcss.exe"Added by the RIZO.A TROJAN!"
X Windows iMessenger Messenger winimsg.exe"Added by the ALLIM.A WORM!"
X Windows Incontext InSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
X Windows Insecure [path to worm]"Added by the RBOT-FSM WORM!"
X Windows installer winstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
X Windows Installer ntdll.exeAdded by an unidentified WORM or TROJAN!
X Windows Installer 1 msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
X Windows Instruction Services winstruct32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Browser Services internet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Internet Explorer 6 firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
X Windows Internet Manager svchost.exe"Added by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Windows Internet Protocol winproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
X Windows Internet Protocol deinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
X Windows Internet Service wininet.exe"Added by the RBOT-AUX WORM!"
U Windows IP Security ipsec.exe"Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
X Windows IP Security Service ipsecs.exe"Added by the RBOT.BPW WORM!"
X Windows IPv6 Drivers wipv6.exe"Added by the SDBOT-VJ WORM!"
X Windows Java Update weatherBug32.exe"Added by a variant of the RBOT WORM!"
X Windows JavaScript Daemon Winjsd.exe"Added by the WOOTBOT.AF WORM!"
X Windows Kernel 64 kernal64.exe"Added by the YIMP-B WORM!"
X Windows Kernel System Service wkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
X Windows kev Messenger mskev.exe"Added by the SDBOT-XV WORM!"
X Windows Keyboard Services winkeyboard.exe"Detected by Trend Micro as the IRCBOT.AFS WORM! See here"
X Windows Keyboard Services winkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Keyboard Services winkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live msgnms.exe"Detected by Trend Micro as the XPACK.AV TROJAN! See here"
X Windows Live Care.exe WindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
X Windows Live Client msnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Manager winlivemgr.exe"Detected by Trend Micro as the SHEUR.EB WORM! See here"
X Windows Live Messages msgnlive.exe"Detected by Trend Micro as the AGENT.AYH WORM! See here"
X Windows live Messenger msn.com"Added by the IRCBOT-AAV WORM!"
X Windows Live Messenger msnlive.exe"Detected by Kaspersky as the RBOT.BMV TROJAN! See here"
X Windows Live Messenger Addon wllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Live Messenger Servicer msmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Messenger Services msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Messenger! livemsngr.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Messenger! msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Msgs wlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Msgs! wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Service msnlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Live Servicer usrserv.exe"Added by the SMALL.LU BACKDOOR!"
X Windows live Support wlmsngr.exe"Added by the RBOT-BKL WORM!"
? Windows Load windows.com"??"
X Windows Loader wstart32.exe"Added by the GAOBOT.CA WORM!"
X Windows Loader winServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
X Windows Loader SysUpdate.exe"Added by a variant of the SDBOT WORM!"
X Windows Loader Service civsc.exe"Added by a variant of the RBOT WORM!"
X windows Loadxm Win_.exe"Added by the FODDER-A TROJAN!"
X Windows Local ISP winthcr.exe"Detected by Trend Micro as the SDBOT.ENZ BACKDOOR! See here"
X Windows Local Services localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcman.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Local Services websvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Locator wsass.exe"Added by the IRCBOT.N TROJAN!"
X Windows Log Agent winlogon.exe"Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
X Windows Logger winlog.exe"Added by the NSHADOW-B TROJAN!"
X Windows logging winlogd.exe"Added by the RBOT-ON WORM!"
X Windows logging asgasg.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Logical Adapter wsrsvc.exe"Detected by Kaspersky as the IRCBOT.ARU TROJAN! See here"
X Windows Logical Connection wcnsvc.exe"Detected by Kaspersky as the VIRUT.AO VIRUS! See here"
X Windows Login explored.exe"Added by the GAOBOT.SY WORM!"
X Windows Login winlog.exe"Added by the AGOBOT.MG WORM!"
X Windows Login lmss.exe"Added by the AGOBOT-JA WORM!"
X Windows Login login.exe"Detected by NOD32 as a variant of the BIFROSE TROJAN!"
X Windows Login Folder winzep.exe"Added by the AGOBOT-TZ WORM!"
X Windows Login Manager winlogin.exe"Added by a variant of the SDBOT WORM!"
X Windows Login Security winlogin.pifAdded by an unidentified WORM or TROJAN!
X Windows Login Service winlog.exe"Added by the RBOT-AFN WORM!"
X Windows Login Service winlogin.pif"Added by the SDBOT-ACU WORM!"
X Windows Logon winlogin.exe"Added by the SPYBOT-C TROJAN!"
X Windows Logon winlogon.exe"Detected by Kaspersky as the VB.HE VIRUS! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
X Windows Logon Application WinIogon.exe"Added by the LINKBOT.M WORM!"
X Windows Logon Application logon.exe"Added by the POEBOT-J WORM!"
X Windows Logon Application services.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X Windows Logon Application win32help.exe"Added by the DELBOT-X WORM!"
X Windows Logon Application winlogon.exe"Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
X Windows Logon Application winamp.exe"Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
X Windows Logon Applicationedc winlogon.exe"Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
X Windows Logon Manager logon.exe"Added by a variant of the RBOT WORM!"
X Windows Logon Procedure Svchoste.exe"Added by a variant of the SPYBOT WORM!"
X Windows Logon Procedure Svchosta.exe"Added by a variant of the SPYBOT WORM!"
X windows logon procedure winlogonpc.exe"Added by the WINLOGON TROJAN!"
X Windows Logon Service winlogon.pif"Added by the RBOT-AOU WORM!"
X Windows Logon Service napi32.exe"Added by the SPYBOT.ANDM WORM!"
X Windows LoL Layer gqwdcr.exe"Added by the AGOBOT-AHS WORM!"
X Windows LoL Layer win.exe"Added by the RBOT-FTO WORM!"
X Windows LoL Layer [random filename].exe"Added by the RBOT-GMD WORM!"
X Windows LoL Layer pyvnpt.exe"Added by the RBOT-GKV WORM!"
X Windows LoL Layer winlolx.exe"Added by the RBOT-FOR WORM!"
X Windows LoL Layer azypbrx.exe"Added by the RBOT-GMZ WORM!"
X Windows LoL Layer blvpnmcny.exe"Added by the RBOT-GOR WORM!"
X Windows Management Instrumentation mwd.exe"Added by the GRAPS WORM!"
X Windows Management Instrumentation [path to file]"Added by the QEDS-A WORM!"
X WINDOWS MANAGEMENT SYSTEM wm1exe.exe"Added by the RBOT-VT WORM!"
X Windows Manager winmants.exe"Added by the MANTAS WORM!"
X Windows Manager winsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Windows Manager Update Inc tgb.exe"Added by the SDBOT-ACM WORM!"
X Windows mangement winlogonn.exe"Added by the RANDEX.FC WORM!"
X Windows Media AP winmapp.exeAdded by an unidentified WORM or TROJAN!
X Windows Media APP wmapp.exeAdded by an unidentified WORM or TROJAN!
N Windows Media Center RunDLL32.exe ehuihlp.dll BootMediaCenter"Starts Windows Media Center every time Windows Vista (Home Premium or Ultimate) boots. Disable by unchecking the ""Start Windows Media Center when Windows Starts"" option via Windows Media Center -> Tasks -> Settings -> General -> Startup and Window Behaviour"
N Windows Media Connect 2 WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
X Windows Media Driver msnger.exe"Added by a variant of the RBOT WORM!"
X Windows Media Loader wmloader.exe"Added by a variant of the GAOBOT WORM!"
X Windows Media Player wmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
X Windows Media Player MediaPIayer.exe"Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
X Windows Media Player [random filename]"Added by a variant of the RBOT WORM!"
X Windows Media Player msa.exe"Added by the RBOT-SI WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list