Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
U4oDKHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
Xahostahost.exe"Added by a variant of the SDBOT WORM!"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
Xantihostahr.exe"Added by the BANCBAN-QJ TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
Nawhost32awhost32.exe"Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file
XBakraIEHost.EXE"Added by the MULTIDR-AH TROJAN!"
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
UCBWHostCBWHost.exe"Required for Bitware to answer incoming faxes
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
Xcihost.execihost.exe"Added by the LINST TROJAN!"
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XCOM++ Systemsuchost.exe"Added by the LOVGATE-F WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCsrss Hostcsrhost.exe"Added by the IRCBOT.BIZ WORM!"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XData Filevdehost.exe"Added by the SDBOT-DOS TROJAN!"
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
XDirect settingssdchost.exe"Added by the DAEMONI-I TROJAN!"
XDirectX Driverstdhost.exe"Added by the SDBOT.GVJ BACKDOOR!"
XDirectX9svchost32.exe"Added by the RBOT.AQG WORM!"
Xdlhostdlhost.exe"Added by the EXPHOOK-A TROJAN!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDLL32dllhost.dll"Added by the SUCLOVE.A WORM!"
XDLLHostdllhst.exe"Added by the DELBOT-AC WORM!"
XDllHostdllhost.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Inf"
Xdllhostxp.exedllhostxp.exeBrowser hijacker and adware downloader
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
NDVDXGhostDVDGhost.EXE"DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xffsvhost32.exe"Added by the LINEAG-AFF TROJAN!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xfzgsvhost32.exe"Added by the DLOADER.BDK TROJAN!"
XGames Accelerationsvshost.exe"EasySearch adware"
XGames Accelerationsvshost1.exe"Added by the DLOADR-AWD TROJAN!"
Xgammasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvńhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XGhost AntivirusGhostAV.exe"Ghost Antivirus rogue security software - not recommended
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
UGhostSecuritySuitegss.exe"Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
NGhostStartTrayAppGhostStartTrayApp.exe"System Tray access to Norton Ghost - added from the 2003 version"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
YGilat SOM Enumeratordllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XG_HostgHost.exe"Added by the AUTOIT-BP WORM!"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhellodollyshost.exe"Added by the YODO WORM!"
XHelplshost.exeIdentified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
XhErcUnessofthost.exe"Added by the GARROCH WORM!"
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
XHostN/A"Added by the POPDIS or STARTPAGE.F TROJANS!"
Xhosthelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XHost Processmame.exe"Added by the RBOT-APO WORM!"
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhostdll.exehostdll.exe"Added by the BANKER-BO TROJAN!"
UHostManagerAOLHostManager.exe"Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched
NHostManagerAOLSoftware.exe"Quoted from AOL Beta Team
XHostname Manager Serverhost32srv.exe"Added by a variant of the RBOT WORM!"
XHostren.exeHostren.exe"Added by PWS.BANKER.F
Xhostservhostserv.exe"Added by the RBOT.BPZ WORM!"
Xhostservwiz98.exe"Added by a variant of the SDBOT WORM!"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
UHostsManhm.exe"""HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
XHostSVC syseHostSVC.exe"Added by the RBOT-ANZ WORM!"
XHotfix Updatsvdhost32.exe"Added by the GAOBOT.ZW WORM!"
XHyper Filesphfhost.exe"Added by the AGENT-JQO TROJAN!"
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
Xicq litescvhost.exe"Added by the AGENT-DSF TROJAN!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
XIndex Servicedllhost32.exe"Added by the AGOBOT.CH WORM!"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XIntel system toolsvehost.exe"Added by the AGENT-EBT TROJAN!"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
XIntranetschost.exe"Added by the RBOT.SV BACKDOOR!"
Xishost.exeishost.exe"Added by the DLOADR-XJ TROJAN!"
XivHosttaskManager.exe"Added by a variant of the SPYBOT WORM! See here"
XivHost[6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
XJava Updatehostwww.exe.exe"Added by the AGENT-MFH TROJAN!"
XJufualtsvhost.exe"Added by the SDBOT-ADJ WORM!"
XJvcHostjvcsvc32.exe"Added by the AGOBOT-AIU WORM!"
XKAVPersonalsvchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NkdxKHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
XKernel Faultsftphost.exe"Added by the RBOT.BHU WORM!"
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
XKernel32svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers"
XKernellAppssvshosti.exe"Added by the BANCBAN-V TROJAN!"
XKV_HOSTcxjx.exe"Added by the LEGMIR-BB TROJAN!"
Xlayersldmhostplsrvc.exe"Added by a variant of the SDBOT WORM!"
Xloadsvhost32.exe"Added by the WOWCRAFT TROJAN!"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
Xload32swchost.exe"Added by the TURTA.A WORM!"
Xload=svhost32.exe"Added by the LINEAGE-AB TROJAN!"
XLocalSystemsvchost.exe"EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XLSASS Authoritylshosts32.exe"Added by the SDBOT-UY TROJAN!"
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
XLTM2SVCHOST32.exe"Added by the LITMUS.203B TROJAN!"
XLTM2SVCHOST˙.exe"Added by the DROPPERFL.A TROJAN!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
XMastersvcghost.exe"Added by the IRCBOT.RB TROJAN!"
XMemory Allocation Hostcihost.exe"Detected by Avast as a variant of the IRCBOT-CHZ WORM!"
XMessenger Servicenvhost.exe"Added by the JLOK-A WORM!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
XMicosoft Data Core stuffsvshosts.exe"Added by the RBOT.FZA WORM!"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosof Winlog Hostwilogon32.exe"Added by the RBOT.XC WORM!"
Xmicrosoftsvchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoftsvchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoftschost.exe"Added by the RBOT.FEH BACKDOOR!"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Clientmshost.exe"Added by the RBOT-AND WORM!"
XMicrosoft Com Port Managersvdhost.exe"Added by the SDBOT-NI WORM!"
XMicrosoft Command Csshost.exe"Added by the RBOT-CMK WORM!"
XMicrosoft Command Cwinhost32.exe"Added by the SDBOT-BBA WORM!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft Data Helpercihost.exe"Malware
XMicrosoft dll Host Servicewkssr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLL Host Servicedllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Host Servicesvcdllhst.exe"Added by the AGENT.EAK TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft DNS Host Resolutionhostres.exe"Added by the AGOBOT-MK BACKDOOR!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IISsyshost.exe"Added by the FRANCETTE WORM!"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft IT UpdateRhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Officesvxhost.exe"Added by a variant of the RBOT WORM!"
NMicrosoft People Near Mep2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMicrosoft Registrosvchostt.exe"Added by the BANCOS-DH TROJAN!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Servicemicrohost.exe"Added by the RBOT-LC WORM!"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
Xmicrosoft supportsvchostt.exe"Added by the AGOBOT.AWN WORM!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft Synchronization Managerslhost.exe"Added by the SDBOT.YH WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft Synchronization Managersvxhost.exe"Added by the SDBOT-ZU WORM!"
XMicrosoft Synchronization Manager 2svhostc.exe"Added by the SLINBOT.ST WORM!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatesghost.exe"Added by the SDBOT.AKV WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Updatesvghost.exe"Added by the RBOT.BUJ WORM!"
XMicrosoft Updatesvzhost.exe"Added by the RBOT.OX WORM!"
XMicrosoft Update DLLrxxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Eventsvnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
XMicrosoft Update Machinerxhost.exe"Added by the RBOT.FC WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinerxxhost.exe"Added by the RBOT.EP WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
NMicrosoft® Windows® Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMicrosongsvchosts11.exe"Added by the SDBOT-EV WORM!"
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMircrosoft Svchost32svchost32.exe"Added by the RBOT-AZW WORM!"
NMixghostmixghost.exe"Management software for Altec Lansing speakers. If a change is needed
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
XMonitoring Servicesvchost.exe"Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
UMouseImpMImpHost.exe"MouseImp Pro - "A reliable assistant that turns your mouse into a simple
Xmssvhost32.exe"Added by the LEGMIR-AQO TROJAN!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Hostmsthost.exe"Added by the SLENFBOT.AH WORM!"
XMS Host Managerivhost.exe"Added by the RBOT-BJN WORM!"
XMS Hostsmsthosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMS Updatesyshost.exe"Added by the EVAMAN-F WORM!"
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
Xmsetsvchost.exe"Added by the BIZEX-F TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""mset"" sub-directory"
XMshostsMshosts.exe"Added by the STARTPAG.CF TROJAN!"
XMSNscvhost.exe"Added by the IRCBOT-ZW WORM!"
XMSNsvchost.exe"Added by the PUSHBOT.FA WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMSN Hostnmsnhostn.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xmsnager32svchostt.exe"Added by the WOMANIZ.E TROJAN!"
XMSStartOptimizerSCVHOST.EXE"Added by the DASMIN-E TROJAN!"
XMStasksvchost.exe"Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMSUpdatesvchosthlp.exe"Added by the BLASTER.T WORM!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xmsvccmsvchost.exe"Added by the XOMBE TROJAN!"
Xmsvcc25svcchost.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25svcchost.exe"Added by the SDBOT-CSE WORM!"
Xmsvchostmsvchost.exe"Added by the IRCBOT-AV WORM!"
Xmsvhostaig.exe"Added by the AIMBOT-BC TROJAN!"
Xnanosvchost.exe"Added by the NANO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNDAvsvhost.exe"Added by the SERFLOG.C WORM!"
XNDIS Adaptersvchosttt.exe"Added by the WOOTBOT.AN WORM!"
Xndlhostauiremsyl.exe"Added by a variant of the SDBOT WORM!"
Xnet32svhost.exeAdded by a variant of the Trojan.Clicker family
Xnet64svhoster.exe"Added by the AGENT.JVF TROJAN!"
Xnethost.exe[path to file]"Added by the PERDA-J TROJAN!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNetStartsvchost.exe"Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""NETSTART"" subfolder"
XNetwork Host Controller[path to trojan]"Added by the WHISPER TROJAN!"
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
XNetwork Host Service[random]32.exe"Added by the RBOT-BAB WORM!"
XNetwork manegersvchost.exe"Added by the AGENT.BX BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNetwork Servicesvchost.exe"Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XNETWORK SERVICESVŃHOST.exe"Added by the DELF-EW BACKDOOR!"
XnodriverSVCHOST.EXE"Added by the SPYBOT-Z BACKDOOR! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
NNorton Ghost 10.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
NNorton Ghost 9.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
XNorton Live UpdaterSochost.exe"Added by the GAOBOT.AO WORM!"
XNortons AV SYSTEMscvchost.exe"Added by a variant of the RBOT WORM!"
XNortonVPlussvchost.exe"Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
Xntusersvchost.exe"Added by the POLYCRYP.DY TROJAN!"
Xnvchostwinlogon.exe"Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvClipRsvsvchost.exe"Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvClipRsvswchost.exe"Added by the DUMARU-AK WORM!"
XOfficeAgentsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeAgentsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeQuickAccessOfficeHost.vbs"Added by the PEXMOR WORM!"
XOlive SystemSzchost.exe"Added by the MERCURYCAS.A TROJAN!"
XOnline Servicesvchost.exe"Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XOnluna Sarvicesachost.exe"Added by the TOFGER-AA TROJAN!"
XOnlune Sarvicesachost.exe"Added by the DAEMONI-J TROJAN!"
Xonly23SCVHOST.exe"Added by the BCKDR-PUQ BACKDOOR!"
XOpera addonsvhost.exe"Added by the AGENT-IBD WORM!"
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPerfomance Settingssvchost.exe"Added by the TOFGER-AP TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPersonal Computerscvhost.exe"Added by the RBOT-AJE WORM!"
XPhotoshopsvchost.exe"Added by the CDOPEN-E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
XPolicyRunsvchost.exe"Added by the SILLYFDC-AW WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UPowerDOCSAPIHostpapihost.exe"Hummingbird PowerDOCS - ""delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"""
XPowerManagersvchost.exe"Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XProcessorsvchost.exe"Added by the AGENT-KIR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
UPTHOSTTRPTHOSTTR.EXE"System Tray access to HP ProtectTools Security Manager - ""can be configured to prevent unauthorized access using Smart Cards
Xraidhostraidhost.exe"Added by the AGENT-LID TROJAN!"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
Xregeditsvchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
Xreghostreghost.exe"SpyPal surveillance software. Uninstall this software unless you put it there yourself"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
XRemote Access SlaveSynchost.exe"Added by the RIPJAC TROJAN!"
Xrenascimentosvchost.exe"Added by the BANKER.GAX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
Xreseurcesvchost.exe"Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCMSschost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xrpc Win32shost32.exe"Added by the RBOT-ABL WORM!"
XRPCall_[ComputerName]smhost.exe"Added by the REDPLUT-B TROJAN!"
Xruncchost.exe"Added by the SQUATBOT-C TROJAN!"
Xrun=svhost.exe"Added by the ADMINCASH.B TROJAN!"
XRunnersvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSsvhost.exe"Added by the AGOBOT-LN WORM!"
XScamDiskSVOHOST.exe"Added by the LEWOR.D WORM!"
XscAppsuchost.exe"Added by the ACNATT.A WORM!"
XSchedulersvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xschost[path to trojan]"Added by the TJSERV.D TROJAN!"
Xscvhostsvzhost.exe"Added by a variant of the SPYBOT WORM!"
Uscvhostscvhost.exe"Wiretap surveillance software. Uninstall this software unless you put it there yourself"
Xscvhostscvhost.exe"Added by the AGOBOT-LI WORM!"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
Xscvhost.exescvhost.exe"Added by the LOHAV-N TROJAN!"
XSDAvsvhost.exe"Added by the SERFLOG.C WORM!"
Xsdchosts32vbdd.exeAdded by the RANKY.AG TROJAN!
Usds20svchost.exe"InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
Xsecuresvshost.exe"Added by the RBOT-AFO WORM!"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
XSecurity Update Service Processsvrhost23.exe"Added by the AGOBOT-GN WORM!"
?SelfHostUtilslefhost.exe"??"
XSerices Hostinservicez.exe"Added by the SLENFBOT.MF WORM!"
XServer Daemon Host Managersdhost.exe"Added by the RBOT-GWC WORM!"
XService Hostsvchost.exe"Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Host[filename].exe"Added by the TORVEL.B WORM!"
XService Hostspoolxx.exe"Added by the TORVEL WORM!"
XService Hostsvchost.exe"Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853}"
XService Hostsvchost.exe"Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random]"
XService Hostsvchosts.exe"PornCleanser spyware"
XService Host Driversvchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Host Processspoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
XService ProcessSVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Processsvchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServiceHostsvch0st.exe"Added by the VB.HE VIRUS!"
XServicesmshost.exe"Added by the LANFILT-J TROJAN!"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
XServicessvchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices HostScchost.exe"Added by the DONK WORM!"
XServices Hostsvchost32.exe"Added by the AGOBOT-TG WORM!"
XServices hostsvchost.com"Added by the RBOT-EU WORM!"
XServices Startupsvhost33.exe"Added by a variant of the RBOT WORM!"
XServicinghostd.exe"Added by the SDBOT.BUI WORM!"
XServicio Localsvhost.exe"Added by the SPYBOT.BGX WORM!"
XSetup experationsvchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShellExplorer.exe svchost.exe"Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShellsvchost.exe"Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xshhostshhost.exe"Added by the AGENT.CE TROJAN!"
XSistray32remotehost.pif"Added by the HOLCAS.A WORM!"
Xslvchost32slvchost32.exe"Added by an unidentified VIRUS
Usmrcvshost.exe"Silent Monitoring surveillance software. Uninstall this software unless you put it there yourself"
XSmss Hostsmhost.exe"Added by the IRCBOT-ACC TROJAN!"
XSNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSocket Utilitysvchostz.exe"Added by the DAEMONI-E TROJAN!"
XSoundMamSVOHOST.exe"Added by the QQROB-AAL TROJAN!"
XSpooler Hostsmhost.exe"Added by the IRCBOT.BSQ BACKDOOR!"
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
Xspoolsvsvchost.exe"Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
Xsrshost.exesrshost.exe"Added by a variant of the RBOT-ASW WORM!"
XSrv Hostsrvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
USrv32WinSvchost.exe"Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsrvhostsrvhost.exe"Added by the LIVUP.A BACKDOOR!"
XSSLsvchost.exe"Added by an unidentified VIRUS
Xssvchostssvchost.exe"Added by the HELIOS.B TROJAN!"
XStart UppingSVCHOSTES.EXE"Added by the RBOT-NB WORM!"
XStart Uppingssvcchosts.exe"Added by the SDBOT.VY WORM!"
XStarterscvhosting.exe"Added by the SDBOT.RU WORM!"
Xstarterscvhostingg.exe"Added by the FORBOT-FB WORM!"
Xstartkeyscvhost.exe"Added by the BIFROSE-PM TROJAN!"
Xstartkeysvchost32.exe"Added by a variant of the SDBOT WORM!"
Xstartkeysvchost.exe"Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XStartup UpdateCvshost.exe"Added by the GAOBOT.AO WORM!"
XSunJavaUpdateSchedscvhost.exe"Added by the SDBOT-AVX WORM!"
USVCsvchost.exe"ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSVCHOSTsvchost.exe"System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060"
Xsvchostsvchost.exe"Added by many TROJANS amd WORMS
XSVCHOSTmrowyekdc.exe"Added by the GOTORM WORM!"
XsvchostSvch0st.exe"Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
Xsvchost[path to trojan]"Added by the HAZZER TROJAN!"
XsvchostADMAGIC.EXE"Added by the SMIBAG WORM!"
XSvchostwinhost.exe"Added by the LOLAWEB.A TROJAN!"
XSvchostsvchost.exe"Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSVCHOSTvar.txt.exe"Added by the LDPINCH.C TROJAN!"
XSvchostsvchosl.pif"Added by the INZAE.A or INZAE.B WORMS!"
Xsvchost[path] SETUP.EXE"Added by the SETCLO WORM!"
XSVCHOSTscvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
XSVCHOSTtaskgmr.exe"Added by the MYTOB.F or MYTOB.H WORMS!"
Xsvchostolehelp.exe"Added by the BOOKMARKER.G TROJAN!"
XSVCHOSTupdater32.exe"Added by the RANTS.A WORM!"
XSVCHOSTSPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
XSvcHostsvchost32.exe"Added by the AGOBOT-TM WORM!"
Xsvchostsvchost.exe"Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
XSVCHOSTMDM.EXE"Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
Xsvchost[path to explorer.exe]"Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
Xsvchostrundll16.exe"Added by the STARTPA-PB TROJAN!"
XSvchostsvchost.exe"Added by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer"
Xsvchostsvchost.exe"Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
Xsvchostsvchost.exe"Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
Xsvchostwinhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
XSvchostsvchots.exe"Added by the RBOT.ADK WORM!"
Xsvchostying.exe"Constructor VC2000 malware"
Xsvchostinetinfo.scr"Added by the ODELUD WORM!"
XSVCHOSTsvchost64.exe"Added by the STARTP-G TROJAN!"
Xsvchostsvchost.com"Added by the BANLOA-ABL TROJAN!"
Xsvchostwin.exe"Added by the VBSAUTO-A WORM!"
Usvchostsvchost.exe"Infine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an ""svc"" subfolder"
Xsvchostlogon.exe"Added by the SLEGON WORM!"
Xsvchostsvcst.exe"Added by the AGENT-LIL WORM!"
Xsvchostsvchost.exe"Added by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""MsDtds"" sub-directory"
Xsvchostwindowsrx.exe"Added by the AGOBOT-MZ WORM!"
XSVCHOSTSERVlCES.EXE"Added by the DELF-LF BACKDOOR! Note that the filename has a lower case ""L"" in place of an upper case ""i"""
Xsvchost Agentsvchost.exe"Added by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""28463"" sub-folder"
Xsvchost connection monitorsvchost32.exe"Added by a variant of the SDBOT WORM!"
XSVCHOST Generic applicationsvchost.exe"Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsvchost Netware Managersvchost.exe"Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSVCHost Protocol32scvhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XSvchost Servicesvchost.exe"Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
Xsvchost.exesvchost32.exe"CoolWebSearch Svchost32 parasite variant"
XSVCHOST.EXESVCHOST.EXE"Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsvchost.exe[path to executeable]"Added by the BANKER-MO TROJAN!"
Xsvchost.exesvchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
Xsvchost.exeswchost.exe"Added by the SADELPHI-A TROJAN!"
Xsvchost.exesvchost.exe"Added by the VIRUT.CF WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3361"" subfolder"
XSVCHOST.EXEsvchost.exe"Added by the SILLYFDC.BBI WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Conf"" sub-directory"
Xsvchost.exesvcnost.exe"Added by the MISLEAD-A TROJAN!"
Xsvchost1svchost1.exe"Added by the AGOBOT.ZZ WORM!"
XSVCHost2svchost2.exe"Added by the RBOT.BLC WORM!"
XSvcHost32svchost32.exe"Added by the MIMAIL.I or MIMAIL.J WORMS!"
Xsvchost32.exesvchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
Xsvchost64svchost64.exeAdded by the SDBOTER.G VIRUS!
Xsvchostasvchosta.exe"Added by the SNIFFER-I TROJAN!"
Xsvchostbsvchostb.exe"Added by the SNIFFER-J TROJAN!"
XSvcHostDHCPsvchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
Xsvchostdll.scrsvchostdll.scr"Added by the BANCBAN-FM TROJAN!"
XSvcHostov1rg1n.exe"Added by the AGOBOT-TK WORM!"
Xsvchostrsvchostr.exeAdded by an unidentified WORM or TROJAN!
Xsvchostssvchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
Xsvchosts.exesvchosts.exe"Added by the AGOBOT-JN WORM!"
Xsvchosts.scrsvchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
XSvclhostsvcchost.exeAdded by an unidentified WORM or TROJAN!
XSVGA Adaptersvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XSVHOSTsvhost.exe"Added by the MYDOOM.I WORM! The file is located in %System%"
XSVHOSTSVHOST.EXE"Added by the ZORI.A VIRUS! The file is located in %System%\SVCHOSTV"
XSvhostSvhost.exe"Added by the VB-ASG WORM! This file is located in a ""Hwnd"" sub-directory of the Root folder (C:\)
XSvhost Loadersvshost.exe"Added by the AGOBOT.G WORM!"
XSvhost Service Serversvhostser.exe"Added by a variant of the RBOT WORM! See here"
Xsvhost updatesSvhost.exe"Added by a variant of the RBOT WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
Xsvhost1mdsn.exe"Added by the VB-EPK TROJAN!"
Xsvhost32svhost32.exe"Added by the AUTORUN-AWY WORM!"
Xsvphost.exesvphost.exe"Added by the AGENT.CS TROJAN!"
Xsvshostsvshost.exe"Added by the CHODE-H WORM!"
Xsvshostmessenger.exe"Added by the LOONY-G TROJAN!"
XSvshost Update Servicesvcbind.exe"Added by the MYTOB.LH WORM!"
Xsvshost32msgrsv32.exeAdded by the RANKY.AJ TROJAN!
Xsvshost32svshost32.exe"Added by a variant of the SDBOT WORM!"
Xsvshostdriversvshost.exe"Added by the SDBOT-HN TROJAN!"
Xsvshostdrivermsnmessengerupdate.exe"Added by the SDBOT-BI BACKDOOR!"
XSVX Control Servicesvxhost.exe"Added by the FORBOT-K WORM!"
XSwchostSwhost.exe"Added by the BDOOR-MP BACKDOOR!"
XSygate Personal Firewallhost32.exe"Added by the RBOT.ALD WORM!"
XSygate Personal Firewallhostserv.exe"Added by the RBOT.BKO WORM!"
XSymantec Secure Serversvrhost.exe"Added by the IRCBOT-UB TROJAN!"
XSymantecFilterChecksvhost.exe"Added by the BANKER-EEO TROJAN!"
XSysctrls32sevchost.exe"Added by the RBOT.ADF BACKDOOR!"
Xsyshostsyshost.exe"Added by the VB-DVZ TROJAN!"
XSysInitsvchost.exe"Added by the STARTPA-BD TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XSystemSVCHOST.EXE"Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystem configuresvchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XSystem Efficiency Monitorsvchostx.exe"Added by the KWBOT.E WORM!"
XSystem Hostscvhost.exe"Added by a variant of the RBOT WORM!"
XSystem Host Managersyshost.exe"Added by the BANWORM-C WORM!"
XSystem Host Servicesvchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XSystem Managersvchost.exe"Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processsvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Update2svchost.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSystem32svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XSystemChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
Xsystemrd11host.exe"Added by the VB-GX TROJAN!"
XSystemRegsvchost.exe"Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemsscchost.exe"Added by the DAEMOZ.A TROJAN!"
XSystems Restartslchost.exe"Added by the MULTIDROP.C TROJAN!"
XSystems Restartspchost.exeAdded by an unidentified WORM or TROJAN!
XSystemTraylsvhostwinlk.exe"Added by a variant of the SPYBOT WORM!"
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
XSysTraysvhost.exe"Added by the RAJILO-A WORM!"
XSys_Runghost.exe"Added by the LINEAGE-N TROJAN!"
Xsys_up1svchostsys.exe"Added by the MULTIDR-FL TROJAN!"
XTask Managersvchost.exe"Added by the SOHANA-P WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XTask Managersvhost32.exe"Added by the TERMX.A WORM!"
XTask Monitoring Servicesvchost.exe"Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
UTHCSsvchost.exe"AllMonitor surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in a ""drivers\imon"" subfolder"
XTIMHostTIMHost.exe"Added by the PWS-ANT TROJAN!"
XToPicks StarterIdhost.exe"TOPicks adware"
XTransaction Taskerstdhost.exe"Added by the SDBOT.HNK BACKDOOR!"
XUniversal USB Servicesvchost32.exe"Added by the KELVIR.R WORM!"
XUpdatesvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdate Checkerscvhost.exe"Added by the AGENT-DSF TROJAN!"
XUpdate InstallSchost.exe"Added by the GAOBOT.AO WORM!"
Xupdate servicesvxhost.exe"Added by the RBOT-MG WORM!"
XUPDATEMSNsvhost.exeAdded by an unidentified WORM or TROJAN!
XUpdater Service Processsvhost32.exe"Added by the AGOBOT.TY WORM!"
XUpgrade Sarvicesxchost.exe"Added by a variant of the TOFGER-I TROJAN!"
XUpgrade Servicesxchost.exe"Added by the TOFGER-I TROJAN!"
XUSB Host Serviceusbsvc.exe"Added by the RBOT-GG WORM!"
XUsbDsvhost32.exe"Added by the AGENT.IB TROJAN!"
XUser Hostusnhost.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Hosting Serviceusnhost.exe"Added by the IRCBOT.SN WORM!"
Xvaluenamesvchosts.exe"Added by a variant of the SDBOT WORM!"
XVCS Hostvcshost.exe"Added by the RBOT-FKT WORM!"
Xvhosthost.exe"Peppi adware"
XVhosts Protectionvhosts.exeAdded by an unidentified WORM or TROJAN!
XVideo Driversvchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xvirtual-machinesvchosts.exe"Added by the RBOT-US WORM!"
Xvschostvschosts.exe"Added by the VIPSY-A TROJAN!"
Xvschostvschost.exe"Added by the AGENT.QK BACKDOOR!"
XWIN HOST PROCESSWIN HOST PROCESS.EXE"Added by the KEYLOGGER.CLONE TROJAN!"
Xwin32winhost.exe"Added by the BROPIA.J WORM!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWin32Host Processwebemir.exe"Added by the TURGEN -A TROJAN!"
UWinAppLogsvchost.exe"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinbinswchost.exe"Added by the RBOT.CLS WORM!"
Xwinchostwinchost.exe"Added by the DLOADER-PO TROJAN!"
Xwindhost.exeosrwin32.exe"Added by the BANKER-CB TROJAN!"
Xwindhost.exewindhost.exe"Added by the BANKER-BV TROJAN!"
Xwindhost.exewinos.exe"Added by the PWSAGENT-A WORM!"
XWinDLL (scvhost32.dll)"rundll32.exe scvhost32.dllstart"
XWinDLL (svchost.dll)"rundll32.exe svchost.dllstart"
Xwindow2ssvchost.exe"Added by the IRCBOT.H TROJAN!"
Xwindowssvchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows CPU hostwinbog32.exe"Added by a variant of the RBOT WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows DLL hostwinupd32.exe"Added by a variant of the SPYBOT WORM!"
XWindows DLL Hostdllhost32.exeAdded by an unidentified WORM or TROJAN!
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Executersvchostie.exe"Added by the EGGDROP.V BACKDOOR!"
XWindows Firewallsvchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Firewalllsphost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllsvvhost.exe"Added by a variant of the RBOT WORM!"
XWindows Genuinesvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Help Managersvchost32.exe"Added by the RBOT-OZ WORM!"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Hostwinhost.exe"Added by the PRYSAT TROJAN!"
XWindows Host Booterhostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Namelmass.exe"Added by the GAOBOT.O WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicehost.exe"Added by the KELVIR.AN WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Host32 Starterhostserv.exe"Added by the SDBOT-WU WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Print SpoolerSVEHOST.EXE"Added by the SPYBOT.H WORM!"
XWindows Register Settingssvmhost.exe"Added by a variant of the FORBOT WORM!"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Registrywinhost.exe"Added by a variant of the RBOT WORM!"
XWindows reportswchost.exe"Added by the SMALL-BD TROJAN!"
XWindows Security Managersvchost.exe"Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Service HostingUSERINIT.exe"Added by the GOMMER-A WORM!"
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWindows Soundsvdhost.exe"Added by the SDBOT.EFX BACKDOOR!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
XWindows Stortupsvchost.exe"Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows svchostavserv.exe"Added by the PUSHBOT.FM WORM!"
XWindows svchostctfmon32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows svchosthappy2008.exe"Added by the PUSHBOT.AM WORM!"
XWindows svchostservice.exe"Added by the PUSHBOT.DU WORM!"
XWindows svchostserviceaaa.exe"Added by the PUSHBOT.ER WORM!"
XWindows svchostservicean.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows svchostsvchost.exe"Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows svchostups.exe"Added by the PUSHBOT.A WORM!"
XWindows svchostupss.exe"Added by the PUSHBOT.GJ WORM!"
XWindows svchostserviceam.exe"Added by the PUSHBOT.EY WORM!"
XWindows svchostsvchostx.exe"Added by the PUSHBOT.CC WORM!"
XWindows Svchost Authorityslsass.exe"Added by the RBOT-UA WORM!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWINDOWS SYSTEMsvchost2.exe"Added by the MYTOB.OZ WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System Trayswhost.exe"Added by an unidentified VIRUS
XWindows Sz Hostwinshvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Taskmanagersvchost.exe"Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Taskmanagertaskxphost.exe"Added by the PUSHBOT.BI WORM!"
XWindows TMSVPHOST.exe"Added by a variant of the RBOT WORM!"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
Xwindows updatesychost.exe"Added by the LEOX.B WORM!"
XWindows Updatehost32.exe"Added by the RBOT-GU WORM!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
XWindows Updatedllhostup.exe"Added by the BANCBAN-NB TROJAN!"
XWindows updatesvdhost.exe"Added by the GAOBOT.CG WORM!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
XWindows Update Hostwinupsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsExplorersvchost.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsRegKey updatesvchostc.exe"Added by the RBOT.IF WORM!"
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatesvchostw.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdatesvdhost.exe"Added by the AGOBOT-BP WORM!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdateNTsvwhost.exe"Added by the SHELLOT-B TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindows_Updatessvthost.exe"Added by a variant of the SPYBOT WORM!"
XWinEssentialKeyhost.exeHijacker - hailing from jraun.com
XWinhostwintt.exe"Added by the LOLAWEB.B TROJAN!"
XWinhostwin.exe"Added by the DLOADER-AP TROJAN!"
XWinhostyahoo.exe"Added by the DELF-KM TROJAN!"
XWinhostwinhost.exe"Added by the REATLE.F WORM!"
Xwinhost.exewinhost.exe"Added by the LOHAV-R TROJAN!"
Xwinhost32.exewinhost32.exe"Added by the TABDIM TROJAN!"
Xwinlogonnvchost.exeAdded by an unidentified WORM or TROJAN!
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
?WinManagerschost.exe"??"
XWinMessengersyshost.exe"Added by the OPANKI-E WORM!"
XWinmgr.exescvhost.exe"Added by the AGOBOT.AFG WORM!"
XWinMngndllhost.exe"Added by the SIVION-A TROJAN! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\system"
XWINRUNsvchost32.exe"Added by the MYTOB-AI WORM!"
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
XWinServicehosth.exe"Added by the DWNLDR-FUX TROJAN!"
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
Xwinshost.exewinshost.exe"Added by the TOOSO WORM and variants!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWinsock32driversvchhost.exe"Added by the HACKARMY.I TROJAN!"
XWinSocketComponentnthost.exe"Added by an unidentified VIRUS
Xwinsyssyschost.exeAdded by an unidentified TROJAN!
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWinUpsvchost.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""4350"" sub-folder"
XWinUpdatesvhost.exe"Added by a variant of the SDBOT WORM!"
XWIN_DRIVR32shchostv.exe"Added by a TROJAN - see here"
Xwlsvhost32.exe"Added by the WOWPWS-AF TROJAN!"
Xwlinlessvchost.exe"Added by the LIJI-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the ""spool"" sub-folder"
Xwmsvhost32.exe"Added by the LINEAGE.CIS TROJAN!"
Xwnddrvsvchost.exe"Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
Xwsock32svchost.exe"Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWSVCHOsvhost.exe"Added by the SPYBOT-OQ WORM!"
Xxorsvchost.exe"Added by the XORDOOR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""xor"" subfolder"
Xxorsvshost.exe"Added by the AGENT.DC TROJAN!"
XXPCPHOST Settingsxpcphost.exe"Added by a variant of the RBOT WORM!"
Xxysvhost32.exe"Added by the LINEAG-ABB TROJAN!"
XYahoo Messengersvchost32.exe"Added by the SOHANA-P WORM!"
XYahoo MessenggerSVICHHOST.exe"Added by the TIOTUA-C TROJAN!"
XYahoo MessenggerRVHOST.exe"Added by the SILLYFDC-G WORM!"
XYahoo MessenggerSCVHOST.exe"Added by the SOHANA-V WORM!"
XYahoo MessenggerSSCVIHOST.exe"Added by the SOHANA-W WORM!"
XYahoo MessenggerSSCVIIHOST.exe"Added by the SOHANA-Y WORM!"
XYahoo Messenggerscvhosts.exe"Added by the SOHANNA-AH WORM!"
XYahoo Messenggerscvshosts.exe"Added by the TRAX-A WORM!"
XYahoo MessenggerSSVICSSHOST.exe"Added by the IMAUT.AA WORM!"
XZone Labs Client Exsvchost.exe"Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XZone systemszchost.exe"Added by the MULTIDR-AC TROJAN!"
Xzztpsvchost.exe"Added by the TANNICK.B TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X[filename]svchost.scr"Added by the BANKER-CC TROJAN!"
X[original filename]svchost.scr"Added by the BANCBAN-CX TROJAN!"
X[original filename]xphost.scr"Added by the BANCBAN-HM TROJAN!"
X[random name]??chost.exe"PurityScan adware"
X[random name]svchost.exe"Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
X[random name]s?chost.exe"PurityScan adware"
X[random]svchost.scr"Added by the BANCBAN-CY TROJAN!"
X[trojan name]svchost.exe"Added by the BANCBAN-CI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X[various names]svchostss.exe"Added by a variant of the RBOT WORM!"
X_ntrdlhost_Ntrdlhost.exe"Added by the DLOADER-JV TROJAN!"
X_svchost.consvchost.com"Added by the ERKEZ.C WORM!"
X_System_Run_svchost_.exe"Added by the LINEAGE-Z TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.