Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Windows Services Tower svctowers.exe"Detected by Trend Micro as the IRCBOT.AGJ TROJAN! See here"
X Windows Services Tower svctowing.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Services Update svch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
X Windows Serviece Agents [8 random letters].exe"Detected by Trend Micro as the AGENT.BHR TROJAN! See here for an example"
X Windows Servser serviser.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Session Manager smss32.exe"Added by a variant of the RBOT WORM!"
X Windows Session Manager Subsystem smss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
? Windows shell win70.exe"??"
X Windows Shell shell.exe"Added by the MYTOB-CA WORM!"
X Windows Shell taskgmr.exe"Added by the MYTOB.BV WORM!"
X Windows Shell Library Loader load shell.dll"CoolWebSearch parasite variant"
X windows shellext.32 mschost.exe"Added by the BLASTER.K WORM!"
X WINDOWS SKY sky.exe"Added by the MYTOB.CH WORM!"
X Windows Smart Manager smart.exe"Added by the RBOT-SL WORM!"
X Windows smss service service.exe"Added by the AGENT-FPY TROJAN!"
X Windows Socket Procedure WinSock32.exe"Added by the RBOT-FMX WORM!"
X Windows Software hbsppe.exe"Added by the RBOT-GLL WORM!"
X Windows Sound svdhost.exe"Detected by PCTools as the RBOT.ABCC WORM! See here"
X Windows Sound Driver SndMon32.exe"Added by a variant of the SPYBOT WORM!"
X Windows Sound Emulator snd32_win.exe"Added by the ATNAS.A WORM!"
X Windows Sound Manager SndMon32.exe"Added by the FORBOT-BU WORM!"
X Windows Sound Manager SndMon16.exe"Added by a variant of the FORBOT WORM!"
X Windows Sound Verifier WinIp32.exe"Added by the RBOT-FMO WORM!"
X Windows SP2 Firewall wfirewall7.exe"Added by a variant of the RBOT WORM!"
X Windows SP2 Update Sp2update.exe"Added by the WOOTBOT.BS WORM!"
X Windows SP2 Version Load wuauclt32.exe"Added by the GAOBOT.CX WORM!"
X Windows SP4 directCC.exe"Added by the RBOT-ACX WORM!"
X Windows Spool winspool.exe"Added by a variant of the IRCBOT TROJAN!"
X Windows Spool Server spoolsrv.exe"Added by the SDBOT-ACT WORM!"
X Windows SpoolaPrint Service spoolasrv.exe"Added by the SDBOT-AYD WORM!"
X Windows Spooler SPOOLSRV.EXE"Added by the SPYBOT.P WORM!"
X Windows Spooler spoolsv32.exeAdded by an unidentified WORM or TROJAN!
X Windows Spooler winsplr.exe"Detected by Trend Micro as the SHEUR.ANX TROJAN! See here"
X Windows Spooler Services spool.exe"Added by the AGOBOT-AMO WORM!"
X Windows SpoolPrint Service spoolersrv.exe"Added by the SDBOT-ZT WORM!"
X Windows Spools SV winsv.exe"Added by the RBOT-AUQ WORM!"
X Windows spoolservr Service spoolservr.exe"Added by the SDBOT-AAN WORM!"
X Windows Spoolsre Service spoolsre.exe"Added by the SDBOT-AAE WORM!"
X Windows Spoolsrv Service spoolmsv.exe"Added by the SDBOT-ZS WORM!"
X windows spoolsrv service spoolssv.exe"Added by the SDBOT-AWV WORM!"
X Windows Spoolsurf Service spoolsurf.exe"Added by the SDBOT-ZZ WORM!"
X Windows SpooltPrint Service spooltsrv.exe"Added by the SDBOT-AYE WORM!"
X Windows Spoolvvv Service spoolvvv.exe"Added by the SDBOT-AAW WORM!"
X Windows spyware remover Windows-spyware.exe"Added by the SystemPoser TROJAN!"
X Windows sq Drivers winmsn32.exe"Added by the RBOT-ADI WORM!"
X Windows SQL management 1.33 scvhost.exe"Added by the SPYBOT-OB WORM!"
X Windows Sql Service For Windows 32 Bit winsql32.exe"Added by the FORBOT-FC WORM!"
X Windows SSH Client winssh.exe"Added by the RBOT-AXC WORM!"
X Windows SSL File winssv.exe"Added by the WOOTBOT.CA WORM!"
X Windows SSL Secondary Drivers SSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
X Windows Stand Sound Drivers Sounddrv.exe"Added by the SDBOT-XF WORM!"
X Windows Standard Securty [random 3-letter filename]"Added by the RBOT-ALF WORM!"
X Windows Start Server 2000 traficy.exe"Added by the RBOT-AHM WORM!"
X Windows Startup winsta~1.exe"GoHip foistware"
X Windows Startup Wdrun32.exe"Added by the GAOBOT.AO WORM!"
X Windows Startup services21.exe"Added by the AGOBOT-MX WORM!"
X Windows Startup winstartup.exe"GoHip foistware"
X Windows Startup 32 Bits sysrun32.exeAdded by a variant of the DARKSUN TROJAN!
X Windows Storm-Memory Drivers memorystorm.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows Stortup svchost.exe"Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Windows Streams Server localsrv.exe"Added by the SDBOT.LN WORM!"
X Windows Subsys winload.exe"Added by the NETSPREE.C WORM!"
X WINDOWS SVC winsvc.exe"Added by the MYTOB-EY WORM!"
X Windows svchost avserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Windows svchost ctfmon32.exe"Added by a variant of the SPYBOT WORM! See here"
X Windows svchost happy2008.exe"Detected by Kaspersky as the IRCBOT.AYA BACKDOOR! See here"
X Windows svchost service.exe"Detected by Kaspersky as the SDBOT BACKDOOR! See here"
X Windows svchost serviceaaa.exe"Detected by Trend Micro as the LAMER.AA BACKDOOR! See here"
X Windows svchost servicean.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows svchost svchost.exe"Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Windows svchost ups.exe"Detected by McAfee as the PUSHBOT.A WORM! See here"
X Windows svchost upss.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows Svchost Authority slsass.exe"Added by the RBOT-UA WORM!"
X Windows Svshost Service Update 32 svcsshost32.exe"Added by the FORBOT-GD WORM!"
X Windows SYN Control Center winmnon32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Windows SyncroAd SyncroAd.exeWindupdates adware variant
X WINDOWS SYSTEM beta.exe"Added by the MYTOB.DF WORM!"
X WINDOWS SYSTEM dcomuser.exe"Added by the MYTOB.EO WORM!"
X WINDOWS SYSTEM lf66prc.exe"Added by the MYTOB.GC WORM!"
X WINDOWS SYSTEM msdev32.exe"Added by the MYTOB.EH WORM!"
X WINDOWS SYSTEM nec.exe"Added by the MYTOB-L WORM and variants!"
X WINDOWS SYSTEM nibie.exe"Added by the MYTOB-BY WORM!"
X WINDOWS SYSTEM ninfoie.exe"Added by the MYTOB-EP WORM!"
X WINDOWS SYSTEM skybot.exe"Added by the MYTOB-CX WORM!"
X WINDOWS SYSTEM skybotx.exe"Added by the MYTOB-BY WORM!"
X WINDOWS SYSTEM smoc.exe"Added by the MYTOB.FU WORM!"
X WINDOWS SYSTEM smsc.exe"Added by the MYTOB-BR WORM!"
X WINDOWS SYSTEM test.exe"Added by the MYTOB.DJ WORM!"
X WINDOWS SYSTEM test2.exe"Added by the MYTOB.DJ WORM!"
X WINDOWS SYSTEM test3.exe"Added by the MYTOB.DV WORM!"
X WINDOWS SYSTEM wdns33.exe"Added by the MYTOB-BY WORM!"
X WINDOWS SYSTEM win.exe.exe"Added by the MYTOB.FA WORM!"
X WINDOWS SYSTEM winaup.exe"Added by the MYTOB-DN WORM!"
X WINDOWS SYSTEM winligon.exe"Added by the MYTOB.EP WORM!"
X WINDOWS SYSTEM winmon.exe"Added by the MYTOB.GB WORM!"
X WINDOWS SYSTEM winNTsys32.exe"Added by the MYTOB-DM WORM!"
X WINDOWS SYSTEM winsvc32.exe"Added by the MYTOB.HH WORM!"
X Windows System WINSYS.exe"Added by the RBOT-AEF WORM!"
X WINDOWS SYSTEM winsys33.exe"Added by the MYTOB.EK WORM!"
X WINDOWS SYSTEM winvnc.exe"Added by the MYTOB.EU WORM!"
X WINDOWS SYSTEM winxpserv.exe"Added by the MYTOB-BQ WORM!"
X WINDOWS SYSTEM xxx.exe"Added by the MYTOB.CZ WORM!"
X WINDOWS SYSTEM skybot.exe"Added by the MYTOB.JU WORM!"
X WINDOWS SYSTEM botzor.exe"Added by the ZOTOB WORM!"
X WINDOWS SYSTEM gothica.exe"Added by the MYTOB.HU WORM!"
X WINDOWS SYSTEM msnl.exe"Added by the MYTOB.IK WORM!"
X WINDOWS SYSTEM per.exe"Added by the ZOTOB.C WORM!"
X WINDOWS SYSTEM twunk_65.exe"Added by the MYTOB-EG WORM!"
X WINDOWS SYSTEM servce.exe"Added by the MYTOB-EI WORM!"
X WINDOWS SYSTEM servises.exe"Added by the ZOTOB-I WORM!"
X WINDOWS SYSTEM xpupdate.exe"Added by the ZOTOB-G WORM!"
X WINDOWS SYSTEM expI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
X WINDOWS SYSTEM msn32.exe"Added by the MYTOB-FX WORM!"
X WINDOWS SYSTEM sky.exe"Added by the MYTOB.LB WORM!"
X WINDOWS SYSTEM Win32IMAPSVR.exe"Added by the MYTOB-FQ or MYTOB-FU WORMS!"
X WINDOWS SYSTEM winsvc.exe"Added by the MYTOB.LM WORM!"
X WINDOWS SYSTEM mswins.exe"Added by the MYTOB.DP WORM!"
X WINDOWS SYSTEM mtrnqs.exe"Added by the MYTOB.IG WORM!"
X WINDOWS SYSTEM logic.exe"Added by the MYTOB.IC WORM!"
X Windows System winsys32.exe"Added by the MYTOB-IS WORM!"
X WINDOWS SYSTEM ctech.exe"Added by the MYTOB-KD WORM!"
X WINDOWS SYSTEM efefefe.exe"Added by the MYTOB-KH WORM!"
X Windows System 32 winsys_32.exe"Added by the RBOT-FTR WORM!"
X Windows System 32-Bat Service win32bat.exe"Added by the MYTOB.FI WORM!"
X Windows System Backup SysBackup.exeUnidentified malware
X WINDOWS SYSTEM By FEnR windasz-updote.exe"Added by the MYTOB.LR WORM!"
X WINDOWS SYSTEM Cleaner h3.exe"Added by the MYTOB.EQ WORM!"
X WINDOWS SYSTEM CLEANER iexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Windows System Configuration SYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
X Windows System Configuration Passcfg16.exe"Added by the DOMWIS-E TROJAN!"
X Windows System Configuration Winfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
X Windows System Configuration wincfg.exe"Added by the AGOBOT.OP WORM!"
X Windows System Configuration WINCFG32.EXE"Added by the AGOBOT-TE WORM!"
X Windows System Configuration WinNeth.exe"Added by the RETHE-A WORM!"
X Windows System Configuration nether.exe"Added by the OPANKI-AB WORM!"
X WINDOWS SYSTEM Dns windsns.exe"Added by the MYTOB.EY WORM!"
X WINDOWS SYSTEM DNSPOOL hbmail.exe"Added by the MYTOB.FW WORM!"
X Windows System Drivers sysretain.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Windows System File cmxp.exe"Added by the SPYBOT.KHO WORM!"
X WINDOWS SYSTEM FILE winload.exe"Added by the MYTOB.DK WORM!"
X Windows System Gateway SPOOLER.EXE"Added by a variant of the RBOT WORM!"
X Windows System Init winit32.exe"Added by a variant of the RBOT WORM!"
X Windows System Manager winsystem.exe"Added by the RBOT-AN WORM!"
X Windows System Manager sysconf.exe"Added by the MYTOB.AL WORM!"
X Windows System Manager smsc.exe"Added by a variant of the RBOT WORM!"
X Windows System Manager crssm.exe"Added by the RBOT-AFH WORM!"
X WINDOWS SYSTEM MANAGER spoolsvc.exe"Added by the MYTOB-LY WORM!"
X Windows System Manager CRSL.EXE"Added by the SDBOT.MG WORM!"
X Windows System Manager winsysmgr.exe"Detected by Trend Micro as the IRCBOT.BJG TROJAN! See here"
X Windows System Manager Loader smsls.exe"Added by the AGOBOT.TF WORM!"
X Windows System Manager Proc winsmc.exe"Added by the RBOT.JH WORM!"
X WINDOWS SYSTEM MEMORY LOADER memloader.exe"Added by the MYTOB-IN WORM!"
X WINDOWS SYSTEM mscdvvs mscdvvs.exe"Added by the MYTOB.MD WORM!"
X windows system notepad wnpsm.exe"Added by a variant of the RBOT WORM!"
X Windows System Restore Configuration Sblhost.exe"Added by a variant of the SPYBOT WORM!"
X Windows System Restorer SystemRestorer.exe"Added by the DULOAD.C WORM!"
X WINDOWS SYSTEM SCALPE scalpe91.exe"Added by the MYTOB-HI WORM!"
X Windows System Security winmp.exe"Added by the RBOT.IV WORM!"
X Windows System Security sys32.pif"Added by the RBOT-AOL WORM!"
X Windows System Security Monitor [4 random letters].exe"Added by the PINKTON.A WORM!"
X Windows System Serivce winserv.exe"Added by the RBOT.ACA WORM!"
X windows system service winsock.exe"Added by the RBOT-MR WORM!"
X Windows System Service wnuserv.exe"Added by the SPYBOT.ANDM WORM!"
X Windows System Service [worm filename]"Added by the RBOT.XG WORM!"
U Windows System Tray msni.exe"Iambigbrother monitoring software"
X Windows System Tray swhost.exeAdded by an unidentified VIRUS WORM or TROJAN!
X WINDOWS SYSTEM UPDATE xDcc.exe"Added by the MYOTB-EH WORM!"
X Windows System Update Tools upds.exe"Detected by Kaspersky as the VANBOT.CX TROJAN! See here"
X Windows System-Control Drivers syscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See
X Windows System32 windowsp.exe"Added by the MYTOB.GD WORM!"
X Windows System32 winsys32.exe"Added by the SDBOT-AHS WORM!"
X Windows System32 clsas32.exe"Added by the RBOT-AZO WORM!"
X Windows System32 explorer.exe"Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
X Windows System32 System32.exe"Added by the SDBOT-ALI WORM!"
X Windows SYSTEM32 Realplayer.exe"Added by the SPYBOT.ZH WORM!"
X Windows System32 wingrd32.exe"Added by a variant of the RBOT WORM!"
X Windows System32 Driver clsass32.exe"Added by the SDBOT-AGG WORM!"
X Windows System32 Kernel system32.exe"Added by the SDBOT-AAT WORM!"
X WINDOWS SYSTEMn servicces.exe"Added by the MYTOB-EL WORM!"
X Windows Systemnmg stagmr.exe"Added by the MYTOB.S WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list