Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
XDrvStartHPMedia.exe"Added by the BANCBAN-QE TROJAN!"
Xdrvsys.exedrvsys.exe"Added by the BEAGLE.W WORM!"
Xdrvsyskithidr.exe"Added by the BAGLE.HR WORM!"
Xdrvsyskithldrrr.exe"Added by the BAGLE.QU TROJAN!"
XDR_SDR_S.exe"IstBar adware"
UEDRestore??"Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMSDriverundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
Xmsndrvsysmsndrvsys.exe"Added by the BROGGER-D TROJAN!"
Xsdrsssdrss.exe"Added by the SDBOT-SQ WORM!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Remote Addressingwnpcgs.exe"Added by the DELF-EZN TROJAN!"
XWindows Update Driveupdrvs.exe"Added by a variant of the SDBOT WORM!"
XWinsock2.dllWINLODR.SCR"Added by an unidentified VIRUS
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.