Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
XBT[path to trojan]"Added by the LITEBOT-B TROJAN!"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
Xcppc[path to trojan]"Added by the VB-NV BACKDOOR!"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
Xdefender[path to trojan]"Added by the VB-BAQ TROJAN!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Xdfgfdgrergd[path to trojan]"Added by the RANKY.CK TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDisk Keeper[path to trojan]"Added by the SMALL-VE TROJAN!"
Xdrin[path to trojan]"Added by the SMALL.DPB TROJAN!"
XDSKEY[path to trojan]"Added by the STARTER-G TROJAN!"
XDSS[path to trojan]"Added by the DSSDOOR-C TROJAN!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
XGames Acceleration[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
Xgimmygames[path to trojan]"Added by the DLOADR-LN TROJAN!"
XHATAPE[path to trojan]"Added by the BANKER-QF TROJAN!"
Xhxadsec[path to trojan]"Added by the ADCLICK-AP TROJAN!"
Xibin[path to trojan]"Added by the PERDA-C TROJAN!"
XICQMsn[path to trojan]"Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
Ximonitor[path to trojan]"Added by the IMONI-A TROJAN!"
XInit[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInternet Connection Wizard[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Mail and News[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
XIrwftp[path to trojan]"Added by the BANCOS-AP TROJAN!"
Xixproxy[path to trojan]"Added by the XORPIX-A TROJAN!"
Xjon315[path to trojan]"Added by the MAILBOT-BI TROJAN!"
Xjusched[path to trojan]"Added by the BANKER-BWR TROJAN!"
Xkeyboard[path to trojan]"Added by the DLOADR-AOZ TROJAN!"
Xlameshit[path to trojan]"Added by the LOWZONE-H TROJAN!"
XLanGuard[path to trojan]"Added by the DLOADER-VO TROJAN!"
XLetsRock[path to trojan]"Added by the RANKY.Y BACKDOOR!"
XLitebot[path to trojan]"Added by the LITEBOT-A TROJAN!"
Xloaddr[path to trojan]"Added by the AGENT-DIY TROJAN!"
Xlogin[path to trojan]"Added by the HOTWORD-A TROJAN!"
XLogo[path to trojan]"Added by the DLOADER-RH TROJAN!"
XMailBlocker[path to trojan]"Added by the AGENT-LRJ TROJAN!"
Xmdetect[path to trojan]"Added by the SPABOT TROJAN!"
XMEDIA32[path to trojan]"Added by the PURSCAN-Z TROJAN!"
XMicro Office[path to trojan]"Added by the BANCBAN-QC TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft Internet Acceleration Utility[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft standard protector[path to trojan]"Added by the STOX-C TROJAN!"
XMicrosoft WPCEmail[path to trojan]"Added by the SNIFFER-N TROJAN!"
XMicrosoft WWW[path to trojan]"Added by the AGENT-DRI TROJAN!"
XMicrosoftUpdates[path to trojan]"Added by the DELF-LO TROJAN!"
Xml34[path to trojan]"Added by the MAILBOT-BH TROJAN!"
Xmsbsc[path to trojan]"Added by the BANKER-DF TROJAN!"
XMSDNMess[path to trojan]"Added by the RANKY.BA TROJAN!"
Xmsmsgss[path to trojan]"Added by the RANKY.G BACKDOOR!"
XMspatch69[path to trojan]"Added by the MPROX TROJAN!"
Xmsresear[path to trojan]"Added by the WEASYW-B TROJAN!"
Xmssvc[path to trojan]"Added by the PSK TROJAN!"
XMultimedia extensions[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XNdpldaemon[path to trojan]"Added by the RPCSDBOT-A TROJAN!"
XNetwork Host Controller[path to trojan]"Added by the WHISPER TROJAN!"
XNetwork Security Guard[path to trojan]"Added by the COLEM-A TROJAN!"
Xnewname[path to trojan]"Added by the DRSMARTL-S TROJAN!"
XNorton Firewall[path to trojan]"Added by the BANKER-ET TROJAN!"
XNTCommLib3[path to trojan]"Added by the AGENT-AXB TROJAN!"
XNTP Server[path to trojan]"Added by the RANKY.F TROJAN!"
XNTupdater[path to trojan]"Added by the DIGARIX-D TROJAN!"
XNvCp1Do[path to trojan]"Added by the DWNLDR-GWE TROJAN! The most common filename seen is ""smss.exe"" - which is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNvGraphicsInterface[path to trojan]"Added by the BCKDR-QKI BACKDOOR!"
XNVidia Drivers[path to trojan]"Added by the RANCK-R TROJAN! Note - this is not related to any nVidia based motherboard or graphics card"
Xoffice_update[path to trojan]"Added by the DLOADER-ZB TROJAN!"
XPHIME2OO2ASyst[path to trojan]"Added by the DBDOOR-B TROJAN!"
XPopRock[path to trojan]"Added by the AGENT-LNU TROJAN!"
Xprunnet[path to trojan]"Added by the AGENT-HVB TROJAN!"
Xqgqqft[path to Trojan]"Added by the RANKY.T TROJAN!"
Xrawload[path to trojan]"Added by the DARKIRC.QZ TROJAN!"
XReeg_[path to trojan]"Added by the BANCBAN-AW TROJAN!"
XREGRUN[path to trojan]"Added by the LOWZONE-AH TROJAN!"
Xreseurce[path to trojan]"Added by the LINEAGE-AI TROJAN!"
Xrngmf[path to trojan]"Added by the RANKY.C TROJAN!"
XRoot_Machine[path to trojan]"Added by the BANCBAN-DI TROJAN!"
XRPCInstall[path to trojan]"Added by the AGENT-DQM TROJAN!"
XRunDll[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XRunOnce[path to trojan]"Added by the BANCBAN-P TROJAN!"
XRunOnce2Upd[path to trojan]"Added by the MURLO.FI TROJAN!"
XSafe[path to trojan]"Added by the BANKER-DT TROJAN!"
Xschost[path to trojan]"Added by the TJSERV.D TROJAN!"
Xscrbmk[path to trojan]"Added by the DLOADER-VP TROJAN!"
Xservice32.exe[path to trojan]"Added by the DLOADR-AYX TROJAN!"
XServices[path to trojan]"Added by the METEORSHELL TROJAN!"
XServices[path to trojan]"Added by the RANCK-DB TROJAN!"
XSetup[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XShareSearcher[path to trojan]"Added by the AGENT-FPE TROJAN!"
XShutdownWithoutLjiasvt.exe[path to trojan]"Added by the BIFROSE.F BACKDOOR!"
XSomefox[path to trojan]"Added by the DWNLDR-HHB TROJAN!"
XSound[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XSpool[path to trojan]"Added by the RANKY.R TROJAN!"
Xspoolax[path to trojan]"Added by the PERDA-D TROJAN!"
Xsr64[path to trojan]"Added by the AGENT.X TROJAN!"
XSrv32 spool service[path to trojan]"Added by the DLOADER-LB TROJAN!"
Xsstata[path to trojan]"Added by the RANCK-DF TROJAN!"
Xstartemdoit[path to trojan]"Added by the DLOADR-AVP TROJAN!"
XStartUpDate[path to trojan]"Added by the BIFROSE.F BACKDOOR!"
Xstrto[path to trojan]"Added by the KILLAV-AP TROJAN!"
Xstup[path to trojan]"Added by the AGENT-CIL TROJAN!"
Xsvchosd[path to trojan]"Added by the BANCOS-BCX TROJAN!"
Xsvchost[path to trojan]"Added by the HAZZER TROJAN!"
XSvcManager[path to trojan]"Added by the ZALON-A BACKDOOR!"
XSymantecFilterCheck[path to trojan]"Added by the BANKER-EIN TROJAN!"
XSySPower[path to trojan]"Added by the BANCBAN-OC TROJAN!"
XSystem Update[path to trojan]"Added by the AUTOTROJ-D TROJAN!"
Xsystrans[path to trojan]"Added by the STARTPA-GZ TROJAN!"
XTaskManager[path to trojan]"Added by the LDPINCH-CF TROJAN!"
Xtaskmgr[path to trojan]"Added by the AGENT-ENV TROJAN!"
XTaskMon[path to trojan]"Added by the DROPPER.EAT TROJAN!"
Xtaskmrg.exe[path to trojan]"Added by the BANCBAN-BN TROJAN!"
Xtaskmsgs[path to trojan]"Added by the BANCOS-BBW TROJAN!"
XTheMonitor[path to trojan]"Added by the DLOADR-LO TROJAN!"
XTorjan Program[path to trojan]"Added by the LEGMIR-BO TROJAN!"
XTurboNet[path to trojan]"Added by the RENOS-EA TROJAN!"
XUPNP[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XUsbD[path to trojan]"Added by the CIDRA-F TROJAN!"
XUSBHWINFO[path to trojan]"Added by the LOWZONE-I TROJAN!"
Xusbn[path to trojan]"Added by the HOGIL-C TROJAN!"
XValidData[path to trojan]"Added by the RANKY.H TROJAN!"
XVidiaDrivers[path to trojan]"Added by the RANKY.U TROJAN!"
XVirus Removal Tool[path to trojan]"Added by the TOMETA-B TROJAN!"
XvXCXssdss[path to trojan]"Added by the RANCK-BO TROJAN!"
XWeb-cameinst[path to trojan]"Added by the RANCK-BP TROJAN!"
XWheelsMouse[path to trojan]"Added by the SOCKSPR-D TROJAN!"
Xwindows[path to trojan]"Added by the AIMWIN TROJAN!"
XWindows NNT[path to trojan]"Added by the RANKY.E TROJAN!"
XWindowsFY[path to trojan]"Added by the FAKEALE-E TROJAN!"
XWindowsSetup[path to trojan]"Added by the EZBOT TROJAN!"
XWindUpdates[path to trojan]"Added by the AGENT.BF TROJAN!"
XWinLsass[path to trojan]"Added by the SCANE WORM!"
XWinMedia[path to trojan]"Added by the ZEROBE-A TROJAN!"
Xwinmngr.exe[path to trojan]"Added by the AGENT-ZB TROJAN!"
Xwinreg_32[path to trojan]"Added by the BANKER-DB TROJAN!"
Xwinshow[path to trojan]"Added by the VB-DXP TROJAN!"
XWINSYS[path to trojan]"Added by the GOLDPLAY TROJAN!"
Xwinsysban[path to trojan]"Added by the CLICKER-CD TROJAN!"
XWinSysModule[path to trojan]"Added by the AGENT-DIQ TROJAN!"
Xwinsysupd[path to trojan]"Added by the STARTPA-NI TROJAN!"
XWintelUpdate[path to trojan]"Added by the SMALL-EKW TROJAN!"
XWinUpgrader[path to trojan]"Added by the AGENT-DZ TROJAN!"
Xwinzip[path to trojan]"Added by the BANCOS.G or BANCOS.K TROJANS! Note - this is not part of the popular WinZip file compression utility"
Xwlm[path to trojan]"Added by the BANCOS-BCY TROJAN!"
Xx3yy[path to trojan]"Added by the TANNICK TROJAN!"
Xxload[path to trojan]"Added by the VB-AGP TROJAN!"
XXpAspy[path to trojan]"Added by the DELF-WH BACKDOOR!"
Xxserv[path to trojan]"Added by the STUMPY-A TROJAN!"
Xyyyyyyyy[path to trojan]"Added by the MUMUBOY.B TROJAN!"
XZen.A[path to trojan]"Added by the ZOOMEN-A TROJAN!"
X[username] config[path to trojan]"Added by the MOSUCK-H TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to trojan]"Added by the SMALL-EP TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.