Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X(*)API MachinewinSOCKS.exe"Homepage hijacker see here (* = any digit)"
X(*)Runwin32API.exe"Homepage hijacker see here (* = any digit)"
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winlog.exe"Unidentified adware. Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads animated gifs things you don't want to see"""
U1Win32CfgSpyBuddy.exe"SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself!"
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X@regedit -s ..win.dll"Added by the SEEKER.K TROJAN!"
X@wincms.exe"Added by the RBOT.CBR WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion WinPoET is attractive to equipment providers modem suppliers RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking"
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
XAccess Control Appwinsto.exe"Detected by Kaspersky as the AGENT.DGO TROJAN! See here"
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive convenient and enjoyable"""
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically in a fully configurable way"""
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam spyware dangerous or time-wasting content phishing scams hackers and intruders"""
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XAudio Device Managerwinfp.exe"Detected by PCTools as the IRCBOT.BIV TROJAN! See here"
XAudio Device ManagerWinNT.exe"Added by the BANKER.BTG TROJAN!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
Xautowin32.exe"Added by the SMALL!SD5 TROJAN!"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
Xautoloadwindowsupdate.exe"Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
Xbawindobawindo.exe"Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
XCalc Microsoft Windowswincalc.exeAdded by an unidentied WORM or TROJAN!
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
XcftmonWindowsUpdate.exe"Detected by Kaspersky as the AGENT.AQK BACKDOOR! See here"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
YClamWinClamTray.exe"ClamWin antivirus"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XContentServicewinservn.exeHomepage hijacker
XControlPaneltwink64.exe internat.dllLoadKeyboardProfile"Added by the DLOADER-BW TROJAN. Note - the ""twink64.exe"" file is found in %System%"
Xcpanelwinlogin32.exe"Added by the RBOT-FOY WORM!"
Xcpntmgcwincomp.exe"Added by the WINTRIM.A TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
Xcwingllibatllsimm.exe"Added by a variant of the SDBOT WORM!"
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UELSA WINman SuiteWinmsuit.exeAllows you to totally customize your ELSA graphics card settings including overclocking the GPU
?encapsulated command toolwintr.com"??"
XEnh Win Updtenhupdt.exe"Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
Xerghgjhgdrwindlhhl.exe"Added by the BEAGLE.BG WORM!"
Xerghgjhjgdrwindlhhl.exe"Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
Xerthgdrwindll.exe"Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
XeTunnelwinfw.exeAdded by an unidentified TROJAN!
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XFirewall auto setupwinlogon.exe"Added by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
NFolding@homeWINFAH.EXEFolding@Home is a distributed computing project which studies protein folding misfolding aggregation and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
NFromine WinPopupwinpopup.exeInstant Messenger program
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture print or save the current window"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicesvchost.exe"Added by the SPYBOT.NC WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessv?h?st.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XgetwinwinB_.exe"Added by the BANKER-HS TROJAN!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
Xgpmcewindow.exe"Detected by Kaspersky as the VB.CK WORM! See here"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
NGWInkMonitorGWInkMonitor.exeGateway ink monitor - makes an annoying popup that says your printer may be running out of ink do you want to buy some!
XHardware Shell DetectionWinHSD.exe"Added by a variant of the RBOT WORM!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun)"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
XHWINFO*HWINFO*"Added by the PUROL WORM! where * is a random character"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
UIBWin Background processIBackground.exe"IBackup for Windows"
UIBWin MonitorIBMonitor.exe"IBackup for Windows"
Xicq litewinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
UIE New Window Maximizeriemaximizer.exe"IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
XIE6winsnt.exe"Added by the RBOT-GOV WORM!"
XIExplorerServiceWinSock.exe"Detected by Kaspersky as the AGENT.KIU TROJAN! See here"
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
Xinfwininfwin.exe"VX2.Transponder parasite updater/installer related"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XInternalregedit.exe /s %windir%c:[month number]"Added by the FORTNIGHT.D TROJAN!"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
XInternetwinlogom.exe"Added by a variant of the SDBOT WORM!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
XInternetwins.exe"Detected by PCTools as the RBOT.AAYF WORM! See here"
XInternet Security Servicemysqlwin32.exe"Detected by Trend Micro as the RBOT.UX TROJAN! See here"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
XInterUWINDRV.EXE"Added by the IRCINTER.A TROJAN!"
NIntervideo Win Cinema ManagerWinCi