Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
XAHU[path to worm]"Added by the ANACON-B WORM!"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XApp.EXEName[path to worm]"Added by the BODIRU WORM!"
XArman[path to worm]"Added by the IRCBOT-TG WORM!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
Xbackup[path to worm]"Added by the AGOBOT-H WORM!"
Xbrwdiag[path to worm]"Added by the STRATIO-BN WORM!"
XC7[path to worm]"Added by the MEDIAKILL.A WORM!"
XCekirge[path to worm]"Added by the KERGEZ.A WORM!"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
XeMCryT Sh3ars Panagers[path to worm]"Added by the RBOT-AWI WORM!"
XExplorer[path to worm]"Added by the AUTEX WORM!"
Xff[path to worm]"Added by the RBOT-XL WORM!"
XFindHack[path to worm]"Added by the KELVIR-BA WORM!"
XFlash Player2[path to worm]"Added by the IRCBOT.PD WORM!"
XFolderRaper[path to worm]"Added by the VB.GOZ WORM!"
Xhimem.exe[path to worm]"Added by the STRATION-FW WORM!"
XHotKeysCmds[path to worm]"Added by the PAHATIA-A WORM!"
XICQ Center[path to worm]"Added by the RANDIN WORM!"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XInterceptedSystem[path to worm]"Added by the ANACON-B WORM!"
Xjpgdiag[path to worm]"Added by the STRATION-AN WORM!"
XKernelRuntime[path to worm]"Added by the MYTOB-JO WORM!"
XLetum[path to worm]"Added by the LETUM.A WORM!"
Xload[path to worm]"Added by the KELVIR.AI WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft Updater v2[path to worm]"Added by the AUTORUN-BCI WORM!"
XMouseDrv[path to worm]"Added by the ZOLOAD-B WORM!"
XMsgmgr[path to worm]"Added by the BABYBEAR WORM!"
XMSN Message Background loader[path to worm]"Added by the RBOT-AIE WORM!"
XMSPRO32[path to worm]"Added by the IBERIO WORM!"
XMSWUpdate[path to worm]"Added by the SILLYFD-V WORM! The most common filename is lsass.exe but it not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xmxb2[path to worm]"Added by the IXBOT-G WORM!"
XNAV Live Update[path to worm]"Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec"
XNocana[path to worm]"Added by the ANACON-B WORM!"
XOffice Monitorse[path to worm]"Added by the SDBOT-CZX WORM!"
XOffices Monitors[path to worm]"Added by the RBOT-GKO WORM!"
XOffices Monitorse[path to worm]"Added by the RBOT-GKO WORM!"
XPatah Hati[path to worm]"Added by the PAHATIA-A WORM!"
XPromoReg[path to worm]"Added by the WALEDAC.C WORM!"
XPrU Async Service[path to worm]"Added by the IRCBOT-UG WORM!"
XRPC Patcher[path to worm]"Added by the BOLGI WORM!"
Xrundll32[path to worm]"Added by the AUTEX WORM!"
Xrundll64[path to worm]"Added by the AUTEX WORM!"
XSoundMnEx32[path to worm]"Added by the STRATION-FW WORM!"
Xsvcwinprocess32[path to worm]"Added by the UPERING WORM!"
XSystry[path to worm]"Added by the AUTEX WORM!"
XSystryt[path to worm]"Added by the AUTEX WORM!"
Xuser logon[path to worm]"Added by the PAHATIA-A WORM!"
Xwincrt.exe[path to worm]"Added by the STRATIO-HA WORM!"
XWindowfdgfds DasdLL Verifiew[path to worm]"Added by the RBOT-GGX WORM!"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindowsSystem32[path to worm]"Added by the SDBOT-DFG WORM!"
XWinres32vis[path to worm]"Added by the THRAX.A WORM!"
XWkyo86[path to worm]"Added by the PITIN-A WORM!"
X[decimal number][path to worm]"Added by the OPOSSUM-A WORM! The decimal number can be anything


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.