Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
ME & XP"MS Java Applets for Windows NTUjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder"
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(*)Runwin32API.exe"Homepage hijacker
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
U1Win32CfgSpyBuddy.exe"SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself!"
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X@regedit -s ..win.dll"Added by the SEEKER.K TROJAN!"
XA New Windows Updaterw32NTupdt.exe"Added by MYTOB.BM WORM!"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
XAnti-Virus Update Schedulerwinsp3.exe"Malware - recognized by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other systems via the compromised system"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
YApvxdAPVXDWIN.EXE"Part of Panda Anti-Virus. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Anti-Virus. Required to enable permanent virus protection"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
Xautoupdate"WINUP2DATE.DLL SHStart"
Xbawindobawindo.exe"Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
XBrowserUpdateSchedqwinnsap.exe"ZenoSearch adware"
XBrowserUpdateSchedtwinorag.exe"ZenoSearch adware"
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSVCMnet11.exeVCMnet11.exe"Windows AFA Internet Enhancement - a browser hijacker
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
XCalc Microsoft Windowswincalc.exeAdded by an unidentied WORM or TROJAN!
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
YClamWinClamTray.exe"ClamWin antivirus"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XContentServicewinservn.exeHomepage hijacker
Xcpntmgcwincomp.exe"Added by the WINTRIM_A TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
UDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
?encapsulated command toolwintr.com"??"
XEnh Win Updtenhupdt.exe"Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h"
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
Xerghgjhgdrwindlhhl.exe"Added by the BEAGLE.BG WORM!"
Xerghgjhjgdrwindlhhl.exe"Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
Xerthgdrwindll.exe"Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
XeTunnelwinfw.exeAdded by an unidentified TROJAN!
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
NFolding@homeWINFAH.EXE"Folding@Home is a distributed computing project which studies protein folding
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NFromine WinPopupwinpopup.exeInstant Messenger program
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XgetwinwinB_.exe"Added by the BANKER-HS TROJAN!"
XGlobal StartupWinDash.EXE"Recognized by Kaspersky antivirus as IM-Worm.Win32.VB.q
NGWInkMonitorGWInkMonitor.exe"Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun)"
XHWINFO*HWINFO*"Added by the PUROL WORM! where * is a random character"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
UIBWin Background processIBackground.exe"IBackup for Windows"
UIBWin MonitorIBMonitor.exe"IBackup for Windows"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
UIE New Window Maximizeriemaximizer.exe"IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the a href=""http://www.sophos.com/virusinfo/analyses/w32rbotadz.html"" target=_blank>RBOT-ADZ TROJAN!"
Xinfwininfwin.exe"VX2.Transponder parasite updater/installer related"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XInternalregedit.exe /s %windir%c:[month number]"Added by the FORTNIGHT.D TROJAN!"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
XInterUWINDRV.EXE"Added by the IRCINTER.A TROJAN!"
NIntervideo Win Cinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
XIpWinsipwins.exe"Added by Maxfiles adware"
NiRis Active Monitorwinmon32.exe"Iris Antivirus - discontinued
XJufualtwinxp2.exe"Added by the SDBOT-AAB WORM!"
XKAVFOXwin1ogoin.exe"Added by GWGHOST-M TROJAN!"
XKavRunsWindll.exe"Added by the TRYNOMA TROJAN!"
XKernel32Kernel32.win"Added by the GAGGLE.D or GAGGLE.E WORMS!"
Xkeywinxp.exe"Added by the BEAGLE.AG WORM!"
Xkey2winlog.exe"Added by the BAGLEDI-AL TROJAN!"
NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXE"YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
Xload32winldra.exe"Added by the BACKDOOR.NIBU.J or DUMARU-BI TROJANS! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
Xload=win32exec.exe"Added by the BITTER WORM!"
Xloadwinwinset.exe"Added by the QQPASS-I TROJAN!"
Xloadwinwinsys.exe"Added by the QQPASS-J TROJAN!"
XLoadWindowsFile[filename]"Added by the DELF.B TROJAN! where [filename] is the infected file"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
ULoginwinlog.exe"Salfeld Child Control 2003 - parental control software"
XLogServicewincalc.exe"Added by the PAPROXY TROJAN!"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
XLTM2winscan.exe"Added by the LITMUS-B TROJAN!"
YLTWinModem1ltmsg.exe"One of the ""popular"" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
NMania Win RestoreRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
XMCwintrims.exe"Added by the WINTRIM TROJAN!"
XMCWINTRIM.EXE"Added by the WINTRIM_A TROJAN!"
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
NMcAfee Winguage??"Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications
XMD IE Pluginwiny.exeAdware
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosof Winlog Hostwilogon32.exe"Added by the RBOT.XC WORM!"
XMicrosoftwin32.exe"Added by the DARKMOON TROJAN!"
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Dll Managementwindll.exe"Added by the RBOT-MT WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Internetwindows32.exe"Added by the SDBOT-F WORM!"
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-GL WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft KernelWindows_kernel32.exe"Added by the NETSKY.AE WORM!"
XMicrosoft Loginwinlogin.exe"Added by the RBOT-AJP WORM!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"