Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows Registry Services regserv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Registry Startup wind32.exe"Added by the AGOBOT-BZ WORM!"
X Windows Registry XP winxptdl.exe"Added by the IRCBOT.AUN WORM!"
X Windows Relay Service ipcbind.exe"Detected by PCTools as the DELFINJECT.F TROJAN! See here"
X Windows Relay Service irfnga.exe"Detected by Trend Micro as the DROPPER.ACO TROJAN! See here"
X Windows Remote Addressing wnpcgs.exe"Added by the DELF-EZN TROJAN!"
X Windows Remote Launcher wnpmcs.exe"Detected by Kaspersky as the IRCBOT.ASX TROJAN! See here"
X Windows Repair toxikx.exe"Added by the SDBOT-ADL WORM!"
X Windows report swchost.exe"Added by the SMALL-BD TROJAN!"
X Windows Rescue System winsto.exe"Detected by Kaspersky as the SUURCH.CG TROJAN! See here"
X Windows Reverse Preperation winrvp.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Reversed Virus Protection winrsvp.exe"Added by a variant of the IRCBOT TROJAN! See here"
X windows run system.exe"Added by the ICPASS-A WORM!"
X Windows Run-Time 64bit win64rt.exe"Added by a variant of the RBOT WORM!"
X Windows Running DLL Service rundll128.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Running DLL Service rundll64.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Runtime Help win32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
X Windows Runtime Help WinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
X Windows Runtime Proccess 32RUNdll.exe"Added by the SDBOT.QW WORM!"
X Windows SA omniscient.exe"BLAZEFIND adware"
X Windows Scheduler wmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
X Windows Scheduler! scheduler.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Screensaver Service.exe"Added by the KELVIR.P WORM!"
X WINDOWS SCREENSAVER ssaver.scr"Added by the SDBOT-YZ WORM!"
X Windows secure setver32.exe"Added by the SPYBOT.EP WORM!"
X Windows Secure Connection winsc.exe"Added by the SDBOT.BTN WORM!"
X Windows Secure Layer [random filename]"Added by the RBOT.DRF WORM!"
X Windows Secure Messaging System msnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
X Windows Secure Services ssms.exe"Added by the RBOT-GAR WORM!"
X Windows Secure talal32 [7 random letters].exe"Detected by Kaspersky as the RBOT.HTP TROJAN! See here"
X Windows Secure Update winupser.exe"Added by the RBOT-GCG WORM!"
X Windows Secure Update WinSecUp.exe"Added by the RBOT-GCD WORM!"
X Windows Secure Update load.exe"Added by the FORBOT-GU WORM!"
X WINDOWS SECURITY wingrd.exe"Added by a variant of the RBOT WORM!"
X Windows Security win.pif"Added by the RBOT-APT WORM!"
X Windows Security ms32.pif"Added by the RBOT-ARN WORM!"
X Windows Security winscure.exe"Added by the RBOT-BAF WORM!"
X Windows Security Assistant rundll32.vbe"CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!"
X Windows Security Assistant winsec.exe"CoolWebSearch parasite variant"
X Windows Security Authority Service lsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process which should not appear in Msconfig/Startup!"
X Windows Security Center Notification App wscnfty.exe"Added by a variant of the RBOT WORM!"
X Windows Security Center Notification Appls sxe.exe"Added by the RBOT-GKX WORM!"
X Windows Security Center Notification Applse sxes.exe"Added by the RBOT-GLR WORM!"
X Windows Security Center Notification Applse os.exe"Added by a variant of the RBOT-GLR WORM!"
X Windows Security Center Notification Applsee sysecurex.exe"Added by a variant of the RBOT-GKX WORM!"
X Windows Security Manager winsecurity.exe"Added by the AGOBOT-KI WORM!"
X Windows Security Manager winsecure.exe"Affilred adware"
X Windows Security Manager svchost.exe"Added by the ANTINNY.AX WORM!! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""Microsoft"" subfolder"
X Windows Security Module module.exe"Added by a variant of the RBOT WORM!"
X Windows Security Policy lsass32.exe"Added by the AGOBOT-CR WORM!"
X Windows Security Service [random file name]"Added by the RBOT-ALV WORM!"
X Windows Security Service arrdt.exe"Added by a variant of the RBOT WORM!"
X Windows Security Service windows.pif"Added by the RBOT-AMG WORM!"
X Windows Security Survy svchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Security Update security32.exe"Affilred adware"
X Windows Serv Patch Mcaffe2005.exe"Added by a variant of the RBOT WORM!"
X Windows Servce Agent [random filename]"Added by a variant of the IRCBOT TROJAN!"
X Windows Servcesc [9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
X Windows ServeAd WinServAd.exeWindupdates adware variant
X Windows Server winserv.exe"Detected by Trend Micro as the IRCBOT.AVM TROJAN! See here"
X Windows Server Client Verification Service wscvs.exe"Added by the AGENT.AWC TROJAN!"
X Windows Server Drivers syssrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Server Information servinfo.exe"Added by the FORBOT-EN WORM!"
X Windows Server IP Verification Service wsivs.exe"Added by an unidentified WORM or TROJAN! See here"
X Windows Server Peer Verification Service wspvs.exe"Added by a variant of the RANKY TROJAN!"
X Windows Server! winsvr.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Servic2 winsy.exe"Added by the RBOT-AIA WORM!"
X Windows service wuamgrd.exe"Added by the RBOT-QW WORM!"
X Windows Service dddd.exe"Detected by Kaspersky as Dialer.Salc also known to come with the Bube family of trojans"
X Windows Service prvdi.exe"Malware - detected by Kaspersky as the SMALL.RD TROJAN!"
X Windows Service video.exeAdded by an unidentified TROJAN!
X Windows Service svvhost.exe"Added by the AGOBOT-HL WORM!"
X Windows Service private-zone.exeAdded by an unidentified WORM or TROJAN!
X Windows Service pd7.exe"Added by the SMALL.VZ TROJAN!"
X Windows Service dstart4.exeAdded by an unidentified TROJAN!
X Windows Service pd14.exe"Adware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!"
X Windows Service video2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
X Windows Service services.exe"Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X Windows Service WINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
X Windows Service r.exe"Added by a variant of the SMALL.VZ TROJAN!"
X Windows Service windowz.exe"Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
X Windows Service Ag3nt [6 random letters].exe"Detected by Trend Micro as the SDBOT.EZX TROJAN! See here"
X Windows Service Agent czf.exe"Added by the RBOT-GAJ WORM!"
X Windows Service Agent [random filename].exe"Added by the IRCBOT-XE TROJAN!"
X Windows Service Agent agl23.exe"Added by the RBOT-GQU WORM!"
X Windows Service Agent co0l.exe"Added by the RBOT-GQY WORM!"
X Windows Service Agent dsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
X Windows Service Agent msnmagr.exe"Added by a variant of the SLAPER TROJAN!"
X Windows Service Agent taskmgr32.exe"Added by the RBOT-GMN WORM!"
X Windows Service Agent win32wins.exe"Added by the RBOT-LOL WORM!"
X Windows Service Agent winup32.exe"Added by the RBOT-GQX WORM!"
X Windows Service Agent winupds32.exe"Added by the RBOT-GQT WORM!"
X Windows Service Agent wit.exe"Added by the RBOT-GQV WORM!"
X Windows Service Agent wmscc.exe"Added by the RBOT-GQP WORM!"
X Windows Service Agent msngerr.exe"Added by the RBOT.EOZ WORM!"
X Windows Service Agent mssngear.exe"Detected by Kaspersky as the RBOT.KGU BACKDOOR! See here"
X Windows Service Agent 32 mrthd.exe"Added by the AGENT-GAQ TROJAN!"
X Windows Service Agnts [8 random letters].exe"Detected by Trend Micro as the SDBOT.BCQ WORM! See here for an example"
X Windows Service Ajav java128.exe"Detected by Kaspersky as the RBOT.BNG TROJAN! See here"
X Windows Service alge [random filename]"Detected by Trend Micro as the RBOT.GJO TROJAN! See here"
X Windows Service Controller services.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X Windows Service Controller Agent taksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Service DC uhpnjcjl.exe"Added by the RBOT-GLY WORM!"
X Windows Service Host scvhost.exe"Added by the SDBOT.N TROJAN!"
X Windows Service Host svchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X Windows Service Host svchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X Windows Service Host schost.exe"Added by the GAOBOT.AO WORM!"
X Windows Service Host Process [path to file]"Added by the EZIO-A WORM!"
X Windows Service Hosting USERINIT.exe"Added by the GOMMER-A WORM!"
X Windows Service Layer config.exe"Added by the RBOT.DDJ WORM!"
X Windows Service Loader Window.exe"Added by the RBOT-XO WORM!"
X Windows Service Manager userint32.exe"Added by the OSCABOT-C WORM!"
X Windows Service Manager localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager msgs.exe"Added by the OSCABOT-E WORM!"
X Windows Service Manager msnmrg.exe"Added by the OSCABOT-G WORM!"
X Windows Service Manager netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager svcman.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager svcmgr32.exe"Added by the OSCABOT-D WORM!"
X Windows Service Manager svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager websvc.exe"Added by the DLOADER-NY TROJAN!"
X Windows Service Manager taskmgr.exe"Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""fonts\svc"" sub-folder"
X Windows Service Manager initsvc.exe"Added by the RBOT-BWT WORM!"
X Windows Service Pack 2 WindowsSP2.exe"Added by the SDBOT-TQ WORM!"
X Windows Service Pack Auto Update winworks.exe"Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
X Windows Service Pack Auto Update figgaz.exe"Detected by Kaspersky as the AGENT.BT TROJAN!"
X Windows Service Pack Auto Update ballin.exeAdded by an unidentified WORM or TROJAN!
X Windows Service Pack Auto Update del-me.exeAdware also detected as the LOWZONES.BH TROJAN!
X Windows Service Pack2 svchhost.exe"Added by a variant of the RBOT WORM!"
X Windows Service Pack2 WIN43.EXE"Added by the GAOBOT.G WORM!"
X Windows Service Supply winsupply.exe"Detected by Kaspersky as the IRCBOT.BFB TROJAN! See here"
X Windows Service Support Call SVSS32.EXE"Added by the RBOT-XQ WORM!"
X Windows Service SV sv32.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Service Threads svcthreading.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Service Threads svcthreads.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Service Update livecal.exe"Added by the SDBOT-DEY WORM!"
X Windows Service Utitity winsrvc.exe"Added by the RBOT-ASI WORM!"
X Windows Service XP XpFirewall.exe"Added by the MYTOB.AM WORM!"
X Windows Servicer xqobypik.exe"Added by the SDBOT-DFB WORM!"
X Windows Services service.exe"Added by the RANDEX.R WORM!"
X Windows Services svchosts.exe"Added by the AGOBOT-KL TROJAN!"
X Windows Services Explorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Windows Services NetworkDriver32.exe"Added by the RBOT-ACR WORM!"
X Windows Services scmsg.exe"Added by a variant of the SDBOT WORM!"
X Windows Services scvhoste.exe"Added by the SPYBOT.OBZ WORM!"
X Windows Services winsvc32.exe"Added by the MYTOB-CB WORM!"
X Windows Services NetworkDrivers.exe"Added by the SDBOT-YO WORM!"
X Windows Services smsc.exe"Added by a variant of the SDBOT WORM!"
X Windows Services spoolsvc.exe"Added by the SDBOT.CPZ WORM!"
X Windows Services iexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Windows Services avsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Services servicez.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Services w32edus.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Services w32service.exe"Added by the AUTORUN-FU WORM!"
X Windows Services w32services.exe"Added by the AUTORUN-FT WORM!"
X Windows Services winlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows Services winsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Services winsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Services winudp.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows Services Agant regs32.exe"Added by the SDBOT-DIK WORM!"
X Windows Services Aganters [10 random letters].exe"Detected by Trend Micro as the RBOT.CUN WORM! See here for an example"
X Windows Services B-Runner svcbrun.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services B-Runner svcbrunner.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services Certification svccert.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services Guide svcguide.exe"Detected by Symantec as the SILLYIM WORM! See here"
X Windows Services Guide svcguides.exe"Added by the CHECKOUT WORM! See here"
X Windows Services Host svchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X Windows Services Hosts svhosts.exe"Added by the SDBOT-YH TROJAN!"
X Windows Services Ink Platform Tablet Input Subsystem wsiptis.exe"Added by the RBOT.APC WORM!"
X Windows Services Jog svcjog.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services Jog svcjogg.exe"Detected by Trend Micro as the AGENT.QAF WORM! See here"
X Windows Services Joger svcjoger.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services Jogging svcjogging.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services Joging svcjoging.exe"Detected by Trend Micro as the IRCBOT.AVI TROJAN! See here"
X Windows Services Layer winlogz2.exe"Added by the RBOT-FZE WORM!"
X Windows Services Layer winl0g0.exe"Added by the RBOT-FZQ WORM!"
X Windows Services Layer sslms.exe"Added by the RBOT-GAH WORM!"
X Windows Services M7 ctfmon32.exe"Detected by Kaspersky as the AGENT.WOH TROJAN! See here"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list