Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Note the filename has a ""0"" rather than an upper case ""o"""
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)"rundll32.exe [path to DLL file]Do98Work"
X*MS Setup[random filename]"Virtumondo adware
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
XAceu[random filename]"PurityScan adware"
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
XAqujyjax[path to file]"Added by the RANCK-CQ TROJAN!"
Xara-key[random filename]"Added by the ANTINNY WORM!"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
XBand-Aid[path to file]"Added by the RANKY.O TROJAN!"
XBeSys[path to file]"BeSys adware"
XBigfileSearchBigfileSearch.exe"BigfileSearch adware. File located in %Program Files%\BigfileSearch"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
XcAgOu[filename].hta"Added by the KAKWORM WORM!"
Xcartao[path to file]"Added by the DLOADER-QD TROJAN!"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
XClient Agent[path to file]"Added by the PPDOOR-J TROJAN!"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
XClrSchLoader[path to file]"ClearSearch adware"
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
XCommon Filestwain.exe"Added by the AGENT.BEA TROJAN!"
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
XCtykd[path to file]"SMALL.SN spyware"
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
XData Filevdehost.exe"Added by the SDBOT-DOS TROJAN!"
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
XDI2[path to file]"BroadcastPC adware"
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XDistributed File Systemblade.exe"Added by the MYFIP.AC WORM!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDllExecutable[path to file]"Added by the VB-SP WORM!"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
Xdown[trojan filename]"Added by the SMALL-QJ TROJAN!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
XDSAcass[path to file]"Added by the RANKY.M TROJAN!"
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
XenBrowser[name of file]"WINBO adware"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExploreUpdSched[random filename]"ZenoSearch adware"
XFILEabcdefg.exe"Added by the KELVIR.DD WORM!"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile Protection Monitorfilemon.exe"Added by a variant of the RBOT WORM!"
XFile Systemtaskmqrs.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XFile Systemtaskmqr.exe"Added by the RBOT.BWQ WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFile-Sharing Wizardshwizard.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFile0_0MD1.exe"Added by the DLOADER-OR TROJAN!"
XFile1Dia Claro.htm"Added by the DLOADER-OR TROJAN!"
XFileFreedom_Pluginwtm.exe"FileFreedom peer-to-peer sharing program"
Nfilehippo.comUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
NFileHippo.com Update CheckerUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
Xfilenfilen.exe"Added by the VBNAM-A WORM!"
Xfilenamefilename.exe"Added by the VB.FSY TROJAN!"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
XGustavVED[filename].exe"Added by the OPASERV.H WORM!"
XHardware Profilehxdef.exe"Added by the LOVGATE.AB WORM!"
XHardware Profilehxdef.exe..."Added by the LOVGATE.Z WORM!"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHelp Temp Filesemp32.exe"Added by the FORBOT-EC WORM!"
Xhen[filename].exe"Added by the TARNO.G TROJAN!"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
XHOT FIXfilename.exe"Added by the SDBOT-DKM WORM!"
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
XHyper Filesphfhost.exe"Added by the AGENT-JQO TROJAN!"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
XImage"rundll32 [path] [trojan filename]Install"
Ximgit[path to file]"Added by the BANKER-EM TROJAN!"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
XInternal[trojan filename]"Added by the SMOTHER and TRANSLAT TROJANS!"
XInternal Memory Filesysintmemory.exe"Added by the RBOT-GKT WORM!"
XInternat[trojan filename]"Added by the CMJSPY-Y TROJAN!"
Xinternet[trojan filename].exe"Added by the MIFENG-D TROJAN!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
Xist service uninstall[random filename]"ISTBar adware related"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
Xjcidls[random filename]"Added by a variant of the SLAPER TROJAN!"
Ujv16 PT TempFileToolTempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjysyqm[random filename]"ZenoSearch adware"
XKadoc[random filename].exe"Added by the STAPREW TROJAN!"
Xkavsvc[random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
XKAVutil[worm filename]"Added by the WINTOO.B WORM!"
Xkern64dll[random filename]"Added by the TARNO.J TROJAN!"
Xklop[path to file]"Added by the AGENT-WQ TROJAN!"
Xlar[trojan filename]"Added by the ROXY.C TROJAN!"
Xlk3h1[path to file]"Added by the MOSUCK-G TROJAN!"
XloadSystemfile.dll.vbs"Added by an unidentified WORM or TROJAN! See here"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
XLoadPowerProfileASDAPI.EXE"Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
ULoadPowerProfileRundll32.exe powrprof.dll"Power management specifics such as monitor shut-off
XLoadPowerProfileRundll.exe powerprof.dll"Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
XLoadPowerProfilerundl.exe"Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
XLoadPowerProfileRundll32.exe"Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
XLocator Service[filename]"Added by the AGOBOT-KY TROJAN!"
XLogin Service[path to file]"Added by the MIGMAF TROJAN!"
XLowRiskFileTypessysguard.exe"Added by the FAKEAV-UY TROJAN!"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
XMantis[filename]"Added by the MANTIBE VIRUS!"
XMatrixScreen[filename]"Added by the MATRIXSCREEN TROJAN!"
Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
XMbarInstall[random filename]"Mirar adware"
XMedia Services[filename].exe"Added by the AGENT-BA BACKDOOR!"
Xmessnger[worm filename]"Added by the DELODER WORM!"
XMickey Mouse Cereal[random filename].exe"Added by the RANKY.Q TROJAN!"
XMicroLoad[random filename]"Added by the DARBY WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Diagnostic[random filename]"Added by the ACEBOT TROJAN!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft DLL Verifierfile.exe"Added by the RBOT-AED WORM!"
XMicrosoft DLL Verifierchkfile.exe"Added by the RBOT-AOC WORM!"
XMicrosoft File Demand Managerwmgrdf.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Getway Dire[random filename]"Added by the IRCBRUTE.AM WORM!"
XMicrosoft IIS[filename]"Added by the FRANCETTE-S WORM!"
XMicrosoft Internet Acceleration Utility[path to file]"Added by the AGENT-CX TROJAN!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft Locals 332[random filename]"Added by the RBOT-KU WORM!"
XMicrosoft LV[path to file]"Added by the BDOOR-BDL BACKDOOR!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft PCHealth32[path to file]"Added by the NICE-A TROJAN!"
XMicrosoft Profile Managerprofile.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Redirect[path to file]"Added by the BANKER-FW TROJAN!"
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Panager[filename]"Added by the RBOT-ANL WORM!"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
XMicrosoft Transfer File Servermtfs.exe"Added by the RBOT.AFE WORM!"
XMicrosoft Tray[random filename]"Added by the DELF.BZ TROJAN!"
XMicrosoft Update 32[path to file]"Added by the RBOT-AJJ WORM!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Updates[worm filename]"Added by the AGOBOT-AIZ WORM!"
XMicrosoft Updote[random filename]"Added by the RBOT-ARC WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft Windows[path to file]"Added by the BDOOR-LI BACKDOOR!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosot NT Support[random filename].exe"Added by the RBOT-CTI WORM!"
Xminimo[path to file]"Added by the MOSUCK-X TROJAN!"
XMioft Wiws Seice ent[worm filename].exe"Added by the RBOT-GIJ WORM!"
Xmmsddlx[random filename]"Added by a variant of the SLAPER TROJAN!"
XMonAppli[random filename]"Added by the DELF.IF TROJAN! The most common filenames are isys32.exe & msnmsg.exe"
XMonitor Test[random filename]"Added by the SDBOT-NC WORM!"
XMoussaEvil[path to file]"Added by the MUSANUB-A WORM!"
XMP3files"rundll32.exe MSA64CHK.dllDllMostrar"
XMS Task Manager 32[trojan filename] .exe"Added by the RANKY.NF TROJAN!"
XMS-HTML[random filename]"Added by the LATINUS.15 TROJAN!"
XMsgApi[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XMsgsvc32[worm filename]"Added by the NAUTICAL-A WORM!"
XMSKCES32[random filename]"Added by the CLONER TROJAN!"
XMSN File & Folder Sharing Appmsnfileshare.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN File Sharingmsnusr.exe"Added by the SLENFBOT.AM WORM!"
XMSN File Sharing Wizardmsnsharewiz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN File Sharing!msnuser.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
Xmsnmsgy[path to file]"Added by the BANKER-EQ TROJAN!"
XMSPQFileMSA****.TMP [* = random char]Homepage hijacker
XMSSGisg[path to file]"Added by the RANKY.N TROJAN!"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
XMyapp[filename]"Added by the FATEE.B WORM!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
XNavScan[filename]"Added by the OBSORB TROJAN!"
XNeroFileCheckmsjavam32.exe"Added by the AGOBOT.AKM WORM!"
Xnethost.exe[path to file]"Added by the PERDA-J TROJAN!"
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
XNI.ERS_9999_N91S3108[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.GA6PU_0001_N108E1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6PU_0001_N120C2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6P_0001_N105E2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GA6P_0001_N111C1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115C0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115E0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122E0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_2001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GDCDE_0001_N122C1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.GDC_0001_N111C1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GDC_0001_N122C1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GES_0001_N122C2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UAVIFR_0001_N105M2404[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UERSM_0001_N68M1602[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.UGA6P[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.UGA6PH_0001_N122M2910[path to file]"Installer for the AntiVirusAskeladd rogue security software - see here"
XNI.UGA6PK_0001_N122M1302[path to file]"Installer for the VirusForsvar Danish rogue security software - see here"
XNI.UGA6PL_0001_N108M2808[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PL_0001_N120M1302[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PM_0001_N108M2108[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M1202[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M3010[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PT_0001_N108M2208[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M1202[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M2910[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PU_0001_N108M1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M1202[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PV_0001_N108M0207[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M1202[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M2910[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6P_0001_N105M2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N111M1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N115M0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N119M1510[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N120M1710[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0007_N125M2002[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.UGA6P_1001_N122M0402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_1002_N122M1402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4001_N122M2111[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4444_N122M2811[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5001_N122M1902[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5555_N122M0312[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGDC1_0001_N119M0911[path to file]"Installer for the FilterProgram rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0307[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0511[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M1712[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCDE_0001_N111M3007[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCDE_0001_N122M1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M0307[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M1812[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCNL_0001_N111M3007[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M1912[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M3011[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCPL_0001_N108M0207[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCPL_0001_N122M2012[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCRU_0001_N111M0208[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCRU_0001_N122M2012[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCTH_0001_N122M1712[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDCTR_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N111M1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M0502[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2603[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2610[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2802[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2811[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0002_N108M1007[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0003_N108M2407[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGESF_0001_N122M0201[path to file]"Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N105M0405[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M0303[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M2911[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESM_0001_N122M0303[path to file]"Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N108M2006[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M0303[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M2811[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M3010[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M0502[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2111[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2602[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2603[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0002_N108M1607[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNiroFile UpdatedNiroFile.exe"Added by a variant of the IRCBOT TROJAN!"
XNorton Antivirus 7.0a[path to file]"Added by the PERDA-B or RANCK-CT TROJANS!"
XNotePad[worm filename]"Added by the SILLYFDC-G WORM!"
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
XNT Virtual Machine[path to file]"Added by the SCAERBOT-A WORM!"
XNtech.patchs[trojan filename]"Added by the LEMIR.G TROJAN!"
XNTFSS Microsoft Systemfilees.exe"Added by the RBOT.GAB WORM!"
XNTFSS MICROSOFT SYSTEMfiless.exe"Added by the RBOT.AXZ WORM!"
XNvCpl[random filename]"Added by the AGOBOT-APJ WORM!"
Xnvviddrv32[random filename]"Added by the RBOT-HT BACKDOOR!"
XOffice Monitor Word Exel R[trojan filename]"Added by the IRCBOT-VX TROJAN!"
UOfflineFileSyncOfflineFileSyn.exe"Offline synchronization part of ZANTAZ EAS (Enterprise Archive Solution) - which ""is a secure
XOLE[filename]"Added by the STAWIN or TARNO.D TROJANS!"
XOPQFileregedit.exe /s ...rad03FA6.tmpUnsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
Xpasscxd[random filename]"Added by a variant of the SLAPER TROJAN!"
UPCDrProfilerRunProfiler.exePart of PC Doctor software installed for some machines. Disabling or enabling it is down to your preference
XPcEXPLODEspecialfile.exe"Added by the RBOT.RH WORM!"
XPGStub.exe[various filenames]Unidentified adware
XPlasdll service[random filename]"Added by a variant of the SDBOT WORM!"
XPNP FIX[worm filename]"Added by the RBOT-AKQ WORM!"
Xpopuppers65[path to file]"Medload adware"
XPostBootReminder[random filename]Added by and unidentified WORM or TROJAN!
XPowerPrifile"rundl132 kenel.dll PowerProfileEnable"
XPowerProfilemfcp30.exe"Added by the RINDAS-A TROJAN!"
UPPSVC[path to file]"PC Police surveillance software that logs keystrokes
XPrinter[path to file]"Added by the LOWTAPER TROJAN!"
XPrivateNet[various filenames]Premium rate adult content dialler
Xpro[path to file]"Added by the SPYWAD-F TROJAN!"
XProc992[path to file]"Added by the IXBOT-C WORM!"
XProfileProfile.vbs"Added by the WHITEHO VIRUS or TRAPPY WORM!"
NProfilerProfiler.exe"Enables the "Profiler" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs"
Xprofilerliteout.exe"Added by the ZAPCHAS-G WORM!"
Xprofilerprof.exe"Added by the ZAPCHAS-G WORM!"
NProfilerProfilerU.exe"Enables the ""Profiler"" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs"
NProfilerUProfilerU.exe"Saitek SST (Saitek Smart Technolgy) Profile Launcher - allows System Tray access to the ""Profiler"" and ""Control Panel"" for Saitek's game controllers. Start manually via Start -> Programs -> Saitek SD6 Programming Software -> Profiler"
XProgram FileProgmon.exe"Added by the PEEPER TROJAN!"
Xprompt drive[random filename]"Added by the SDBOT.AMF WORM!"
Xputil[filename]"Added by the LDPINCH TROJAN!"
Xqbotd[random filename]"Added by the BOTTEN TROJAN!"
XQuick Time file managerquicktimeprom.exe"Added by the SDBOT TROJAN!"
XQuicktime Task[random filename]"Trafficadvance dialer"
XRandom Unique ID[worm filename]"Added by the XROVE-A WORM!"
XRavTimeXP[worm filename]"Added by the WULLIK.B WORM!"
XRavTimXP[worm filename]"Added by the WULLIK.B WORM!"
Xrdvs[worm filename]"Added by the ULTIMAX.B WORM!"
XRealP1ayer[path to file]"Added by the RPLAY.A TROJAN! Note that the name has a number ""1"" in place of the second lower case ""L"""
XREEGRUN[path to file]"Added by the SECDROP.AI TROJAN"
Xregcheck[path to file]"Added by the SERVPAM TROJAN!"
XREGMSYS[path to file]"Added by the LOWZONE-AX TROJAN!"
Xrmalt[random filename]"Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe
XRPC Service[random filename]"Added by the BDOOR-AAD BACKDOOR!"
XRSPC Driver[random filename].exe"Added by the RBOT-SN WORM!"
XRSPC Driver D[random filename]"Added by a variant of the RBOT WORM!"
Xrtkernsw[random filename]"Added by a variant of the SLAPER TROJAN!"
URun POPFile in backgroundperl.exe"POPFile - E-mail spam blocker"
URun POPFile in backgroundwperl.exe"POPFile - E-mail spam blocker"
Xrunddlfilerunddl.exe"Added by the DELF.D TROJAN!"
XRundllrundll32.exe [random filename].dll"Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%"
XRunDLL Kernel File Corerundll.exe"Added by a variant of the RBOT WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XRunnerlsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XrunSubvalues[path to file]"Added by the DLOADER-QY TROJAN!"
XRunWin[path to file]"Added by the BANKER-ES TROJAN!"
XSaMail[WORM FILE NAME].vbs"Added by the VBS.LIDO WORM!"
?ScanFile??"??"
YScanner File UtilityNsCatCom.exe"Kycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstation"
XScanreg[filename]"Added by the QQPASS.E TROJAN!"
XScrSvrOld[worm filename]"Added by the OPASERV WORM!"
XSearchClick[trojan filename]"Added by the AGENT-DWR TROJAN!"
XSeekmoToolbar${HOOKOE_FILE}"180Solutions.Seekmo adware - also see here"
Xseli[path to file]"Added by the LOWZONE-AS TROJAN!"
XService[trojan filename]"Added by the KAITEX.E TROJAN!"
XService Cleanerfilen.exe"Added by the RBOT.BRH WORM!"
XService Defender[random filename]"Added by a variant of the ZLOB TROJAN! See here"
XService Host[filename].exe"Added by the TORVEL.B WORM!"
XService Monitormsnfilen.exe"Added by the RBOT-ALE WORM!"
XService Monitorfilen.exe"Added by a variant of the RBOT WORM!"
XService Pack[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
XService Pack 1[random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
XService PAck SFVP[worm filename].exe"Added by a variant of the RBOT WORM! The filename is 4 random characters"
XServices004[worm filename]"Added by the BUGBROS WORM!"
XSfKg6wIP[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XSfKg6wIPu[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XShellCommand[path to file]"Added by the REMCON-A TROJAN!"
XSilentSoftech[worm filename]"Added by the SILLYFDC-BL WORM!"
XSNInstall[various filenames]"Spy Sheriff/SpywareNO malware
XSoft Profile Inchxdef.exe..."Added by the LOVGATE.AO WORM!"
XSoft Profile Inchxdef.exe"Added by the LOVGATE.E WORM!"
XSpeedBoss[worm filename]"Added by the OPASERV.AD WORM!"
Xspoolsv.exe[random filename]"Added by the RBOT-JB WORM!"
YSpybotDeleting*****[cmd or command] /c del [path] [filename]"Generated by Spybot Search & Destroy if it encounters files that cannot be deleted during runtime because they are locked by other processes. For example
XSrv32Old[worm filename].PIF"Added by the OPASERV.J WORM!"
NStart Wingman Profilerlwtest.exe"Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer
NStart Wingman ProfilerLWEMon.exePart of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed
XStartup Configuration[six character filename]"Added by the RBOT-ARV WORM!"
Xstdlib[filename]"Added by the PERDA-E TROJAN!"
XStreams Drivers[trojan filename]"Added by the RESTARTER.E TROJAN!"
Xsuicidetempfile2.bat"Personal Protector rogue security software - not recommended
XSupernova[worm filename]"Added by the SURNOVA.A (or SUPOVA) WORM!"
Xsupport-reverse-smileys[trojan filename]"Added by the LITEBOT TROJAN!"
XSvcSys[path to file]"Added by the BANCOS.Z TROJAN!"
Xsws.exe[random filename]"Haldex type adult content dialler"
XSYDNEY[file path]"Added by the SYNEY WORM!"
XsyelimS-esreveR-troppuS[filename]"Added by the LITBOT.C TROJAN!"
XSymantec Autoscan[random filename]"Added by the RBOT-AJO WORM!"
XSymlcs[path to file]"Added by the YASPY-A TROJAN!"
USysBkup[path to file]"Keyspy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSysData[path to file]"Added by the RANCK-BA TROJAN!"
Xsysdll[trojan filename]"Added by the HUGESOT TROJAN!"
Xsysfilersysfiler.exe"Added by the RETSAM TROJAN!"
Xsysin[path to file]"Added by the DSRC-A TROJAN!"
Xsysmon12[various filenames]"Wareout - malware masquerading as a spyware and dialer remover"
Xsysser[path to file]"Added by the RAHACK WORM!"
XSysStart[random filename]"ZenoSearch adware"
XSYSTEMSystemFile.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Applications Profilesap.exe"Added by the RBOT-QF WORM!"
XSystem backup[random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted
XSystem CPL manager[random filename]"Added by the RBOT-SR WORM!"
XSystem File Driversnvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
XSystem File Startupsys32.exe"Added by the RBOT.OTL WORM!"
USystem Files UpdaterSystem Files Updater.exe"System Files Updater from Flyakiteosx ""will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"""
XSystem ProfileRegsrv.exe"Added by a variant of the OPTIX TROJAN!"
XSystem service78[path to file]"Added by the ELITEBAR-T and ELITEBAR-U TROJANS!"
XSystem service79[path to file]"Added by the ELITEBAR-V TROJAN!"
XSystem Services[random file name]"Added by a variant of the RBOT WORM!"
XSystem Update[filename].exe"CoolWebSearch parasite variant"
XSystem Update[random filename]"Added by the KORGO.W or KORGO.X WORMS!"
XSystem Update[random filename]"Added by the SOROMO-A TROJAN!"
XSystem32[worm filename]"Added by the NAUTICAL-A WORM!"
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystemEmergency[various filenames]"CoolWebSearch Smartsearch parasite variant"
XSystemFileSystemFile.exe"Added by the DULLDOOR-A TROJAN!"
XSystemManager[random filename]"Added by the SETTEC ROOTKIT!"
XSystemProcEvent[trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
XSystemTasksfilez.exeAdult content dialler
XSystray[filename.exe]"Winfavorites adware"
XTaskmgo[path to file]"Added by the BANCBAN-T TROJAN!"
XTaskReg[random filename]"Added by the CBLAD WORM!"
XTA_Start[random filename]"Zeno Think-Adz adware"
XTelnet24[random filename]"Added by the RBOT-ARD WORM!"
XThink-Adz[random filename]"Zeno Think-Adz adware"
Xtjstartup[path to file]"Added by the TJSERV.C TROJAN!"
XTok-Cirrhatus[path to file]"Added by the BRONTOK-F WORM!"
XTrickler[path to file]"GAIN adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XTSystem[trojan filename]"Added by the NSYS-A TROJAN!"
XUnix File Supportinit3.exe"Added by the RBOT-ZN WORM!"
XUpdate[original file path]"Added by the LYNDEGG WORM!"
XUpdate for Windows[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
Xupdatesched[random filename]"ZenoSearch adware"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XUpdSys[random filename]Added by the BJ TROJAN!
Xupme[filename]"Added by the MUGLY.F WORM!"
XUser32[filename]"Added by the NETTRASH TROJAN!"
XUserfile Sharing Servusnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUserfile Sharing Serverusnserv.exe"Added by a variant of the IRCBOT TROJAN!"
XUserSystem[filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
XValueS0ft[random filename]"Added by a variant of the SPYBOT WORM! See here"
XValueX[random filename]"Added by the IRCBOT.EE TROJAN!"
Xvbcdtm[random filename]"Added by a variant of the SLAPER TROJAN!"
XVBS.Ipnuker@mm[worm filename].vbs"Added by the NUKIP WORM!"
XVC5MediaPlayer[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XVideo Process[random filename]"Added by the RBOT-LM WORM!"
XVideoDriver[filename]"Added by the GSPOT20.A TROJAN!"
XVisual Element FX5[various filenames]"ClearStream Accelerator adware"
XVoltage Manager[random filename]"Added by the DREFFORT WORM!"
Xvxcxcvfck[random filename]"Added by the RANCK-AZ TROJAN! The most common example is ""sbsvsd.exe"" located in %System%"
Xw02db700.dll[random filename]"ZenoSearch adware"
XW32Load[random filename].scr"Added by the CASPID WORM!"
UWashAndGo - Cleanup of old Backupfileschecker.exe"WashAndGo - temp file cleaner"
XWeb Service[random filename].exe"Added by the ADMINCASH TROJAN!"
XWebRun[random filename]"Added by the ADWARELOADER TROJAN!"
Xwescmv[random filename]"Added by a variant of the SLAPER TROJAN!"
XWiFix service[random filename]"Added by a variant of the SDBOT WORM!"
XWin exe file managrcrss.exe"Added by the RBOT.CCI WORM!"
XWin I5oahder[worm filename]"Added by the AGOBOT-DS WORM!"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
XWin2Drv[worm filename]"Added by the WINTOO WORM!"
XWin32 Critical FileWin32.exe"Added by the RBOT-GUB WORM!"
XWin32 exe filewinstr32.exe"Added by a variant of the SPYBOT WORM!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32system[random filename]"Added by the DDV.B WORM!"
XWIN95DEFVIEW[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
Xwinabc"rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
XWind Logd Fileservicelogd.exe"Added by a variant of the RBOT WORM!"
XWindos Seres Agnts[worm filename].exe"Added by the RBOT-GUN WORM!"
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows File Protectionwinprotect.exe"Added by the AGOBOT.JB WORM!"
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows File Verification Servicewfvs.exeAdded by the RANKY.AC TROJAN!
XWindows File XP Managerwfdmgr.exe"Added by the SDBOT.XD TROJAN!"
XWindows FileSharing Servicemcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
XWindows Help Filewinhelper32.exe"Added by the SDBOT-QK TROJAN!"
XWindows HTML file readerSysconf32.exe"Added by the NOOMY.A WORM!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows Management Instrumentation[path to file]"Added by the QEDS-A WORM!"
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Messenger Filesharewivsvc.exe"Added by the SILLYIM WORM!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Print Monitor Daemon[random filename].exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Security Service[random file name]"Added by the RBOT-ALV WORM!"
XWindows Servce Agent[random filename]"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows SSL Filewinssv.exe"Added by the WOOTBOT.CA WORM!"
XWindows Standard Securty[random 3-letter filename]"Added by the RBOT-ALF WORM!"
XWindows System Filecmxp.exe"Added by the SPYBOT.KHO WORM!"
XWINDOWS SYSTEM FILEwinload.exe"Added by the MYTOB.DK WORM!"
XWindows System Service[worm filename]"Added by the RBOT.XG WORM!"
XWindows Taskbar Manager[path to file]"Added by the PROTORIDE.B WORM!"
XWindows Update[filename]"Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update Filesdnetc.exe"Added by an unidentified VIRUS
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindowsFileSystemwinsfs32.exe"Added by the RBOT-FMQ WORM!"
XWindowsFileSystemcidaemon32.exe"Added by the RBOT-FSP WORM!"
XWindowsFZ[path to file]"Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN!"
XWindowsInstaller[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowsUpdate[path to file]"Added by the DUPA-B TROJAN!"
XWindowsUpdatem1[path to file]"Added by the AGENT-AAJ TROJAN!"
XWindowz[original worm filename].vbs"Added by the NUKIP WORM!"
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
Xwingo[various filenames]"Added by the BAGLE-AU WORM!"
Xwinldr[path to file]"Added by the VIDLO-P TROJAN!"
XWinLoader[random filename]"Added by variants of the SUBSEVEN TROJAN!"
Xwinlogin.exelogfile.exeAdded by the AGENT.AH TROJAN!
Xwinlogon32_[path to file]"Added by the RULAND.A WORM!"
XWinProfileCommand.exe"Added by the BUDDY.E TROJAN!"
XWinProfilesndcfg16.exe"Added by the SNDC.A WORM!"
Xwinprofileiexpiore.exeAdded by a variant of the MONCHER WORM!
XWinProfileiexpIore.exe"Added by the CHUM-C TROJAN!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
XWINTASKtaskfile.exe"Added by the MYTOB.EF WORM!"
Xwinupdateconn[path to file]"Added by the COMBRA-A WORM!"
Xwinupdatefiv_[path to file]"Added by the COMBRA.C WORM!"
Xwinupdate_[path to file]"Added by the COMDOR.A WORM!"
XWinUPPD.exe[random filename]Added by an unidentified WORM/TROJAN!
XWinXP fix[path to file]"Added by the RANKY.P TROJAN!"
XWinz Firewall[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinzip[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
XWin_BooT[path to file]"Added by the BANKER-GI TROJAN!"
Xworknote1[filename].exe"Added by the MEETOT WORM!"
Xwpxmls[random filename]"Added by a variant of the SLAPER TROJAN!"
XWupdate driver[various filenames]"Added by a variant of the SPYBOT WORM!"
XWXcmeinst[path to file]"Added by the RANCK-CD TROJAN!"
UX1FileMonitor.exeX1FileMonitor.exe"Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
UXFilesDialogXFilesDialog.EXE"""XFilesDialog is designed to improve all the (more or less standard) Windows file dialogs (Open / Load / Save)"""
Xxp_system[filename]"Added by the BOOKMARKER.J TROJAN! The file is located in %Windir%\inet20004"
XYahoo Messenggerwinfiles.exe"Added by the AUTORUN-BCY WORM!"
XYahooStock[path to file]"Adtomi adware"
XZaCker[filename].PIF"Added by the HOLAR.A WORM!"
XZagrebLand[trojan filename]"Added by the RENOS-EH TROJAN!"
Xzcseacrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XZeno[random filename]"ZenoSearch adware"
Xzonealarm[random filename]"Added by an unidentified VIRUS
XZStart[various filenames]"VX2.Transponder parasite updater/installer related"
XZ_Start[random filename]"ZenoSearch adware"
X[12 random characters]avifile5.exe"IeDriver adware variant"
X[3-4 random letters]Srv32[path to file]"Added by the BANCSADE-A TROJAN!"
X[executed file name]App.exe"Added by the WAXPOW WORM!"
X[executed file name]Regsrv32.com"Added by the SOUTHGHOST WORM!"
X[filename]svchost.scr"Added by the BANKER-CC TROJAN!"
X[original filename]svchost.scr"Added by the BANCBAN-CX TROJAN!"
X[original filename]xphost.scr"Added by the BANCBAN-HM TROJAN!"
X[random filename]slk8x2peu.exe"QuickLinks adware"
X[trojan filename]Install.exe"Added by the BANCBAN-FS TROJAN!"
X[various filenames]qtsks.exeAdded by the WEBDOR.Y TROJAN
X_Hazafibb[path to file]"Added by the ZAFI.B WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.