Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*MS Setup[random filename]"Virtumondo adware
XAceu[random filename]"PurityScan adware"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
Xara-key[random filename]"Added by the ANTINNY WORM!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExploreUpdSched[random filename]"ZenoSearch adware"
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
Xist service uninstall[random filename]"ISTBar adware related"
Xjcidls[random filename]"Added by a variant of the SLAPER TROJAN!"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjysyqm[random filename]"ZenoSearch adware"
XKadoc[random filename].exe"Added by the STAPREW TROJAN!"
Xkern64dll[random filename]"Added by the TARNO.J TROJAN!"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
XMbarInstall[random filename]"Mirar adware"
XMickey Mouse Cereal[random filename].exe"Added by the RANKY.Q TROJAN!"
XMicroLoad[random filename]"Added by the DARBY WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Diagnostic[random filename]"Added by the ACEBOT TROJAN!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicroSoft Getway Dire[random filename]"Added by the IRCBRUTE.AM WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Locals 332[random filename]"Added by the RBOT-KU WORM!"
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft Tray[random filename]"Added by the DELF.BZ TROJAN!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Updote[random filename]"Added by the RBOT-ARC WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosot NT Support[random filename].exe"Added by the RBOT-CTI WORM!"
Xmmsddlx[random filename]"Added by a variant of the SLAPER TROJAN!"
XMonAppli[random filename]"Added by the DELF.IF TROJAN! The most common filenames are isys32.exe & msnmsg.exe"
XMonitor Test[random filename]"Added by the SDBOT-NC WORM!"
XMS-HTML[random filename]"Added by the LATINUS.15 TROJAN!"
XMSKCES32[random filename]"Added by the CLONER TROJAN!"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
XNvCpl[random filename]"Added by the AGOBOT-APJ WORM!"
Xnvviddrv32[random filename]"Added by the RBOT-HT BACKDOOR!"
Xpasscxd[random filename]"Added by a variant of the SLAPER TROJAN!"
XPlasdll service[random filename]"Added by a variant of the SDBOT WORM!"
XPostBootReminder[random filename]Added by and unidentified WORM or TROJAN!
Xprompt drive[random filename]"Added by the SDBOT.AMF WORM!"
Xqbotd[random filename]"Added by the BOTTEN TROJAN!"
XQuicktime Task[random filename]"Trafficadvance dialer"
Xrmalt[random filename]"Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe
XRPC Service[random filename]"Added by the BDOOR-AAD BACKDOOR!"
XRSPC Driver[random filename].exe"Added by the RBOT-SN WORM!"
XRSPC Driver D[random filename]"Added by a variant of the RBOT WORM!"
Xrtkernsw[random filename]"Added by a variant of the SLAPER TROJAN!"
XRundllrundll32.exe [random filename].dll"Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%"
XService Defender[random filename]"Added by a variant of the ZLOB TROJAN! See here"
XService Pack 1[random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
XSfKg6wIP[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XSfKg6wIPu[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
Xspoolsv.exe[random filename]"Added by the RBOT-JB WORM!"
Xsws.exe[random filename]"Haldex type adult content dialler"
XSymantec Autoscan[random filename]"Added by the RBOT-AJO WORM!"
XSysStart[random filename]"ZenoSearch adware"
XSystem backup[random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted
XSystem CPL manager[random filename]"Added by the RBOT-SR WORM!"
XSystem Update[random filename]"Added by the KORGO.W or KORGO.X WORMS!"
XSystem Update[random filename]"Added by the SOROMO-A TROJAN!"
XSystemManager[random filename]"Added by the SETTEC ROOTKIT!"
XTaskReg[random filename]"Added by the CBLAD WORM!"
XTA_Start[random filename]"Zeno Think-Adz adware"
XTelnet24[random filename]"Added by the RBOT-ARD WORM!"
XThink-Adz[random filename]"Zeno Think-Adz adware"
Xupdatesched[random filename]"ZenoSearch adware"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XUpdSys[random filename]Added by the BJ TROJAN!
XValueS0ft[random filename]"Added by a variant of the SPYBOT WORM! See here"
XValueX[random filename]"Added by the IRCBOT.EE TROJAN!"
Xvbcdtm[random filename]"Added by a variant of the SLAPER TROJAN!"
XVideo Process[random filename]"Added by the RBOT-LM WORM!"
XVoltage Manager[random filename]"Added by the DREFFORT WORM!"
Xvxcxcvfck[random filename]"Added by the RANCK-AZ TROJAN! The most common example is ""sbsvsd.exe"" located in %System%"
Xw02db700.dll[random filename]"ZenoSearch adware"
XW32Load[random filename].scr"Added by the CASPID WORM!"
XWeb Service[random filename].exe"Added by the ADMINCASH TROJAN!"
XWebRun[random filename]"Added by the ADWARELOADER TROJAN!"
Xwescmv[random filename]"Added by a variant of the SLAPER TROJAN!"
XWiFix service[random filename]"Added by a variant of the SDBOT WORM!"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
XWin32system[random filename]"Added by the DDV.B WORM!"
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Print Monitor Daemon[random filename].exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Servce Agent[random filename]"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinLoader[random filename]"Added by variants of the SUBSEVEN TROJAN!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
XWinUPPD.exe[random filename]Added by an unidentified WORM/TROJAN!
XWinz Firewall[random filename].exe"Added by a variant of the SDBOT WORM!"
Xwpxmls[random filename]"Added by a variant of the SLAPER TROJAN!"
Xzcseacrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XZeno[random filename]"ZenoSearch adware"
Xzonealarm[random filename]"Added by an unidentified VIRUS
XZ_Start[random filename]"ZenoSearch adware"
X[random filename]slk8x2peu.exe"QuickLinks adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.