Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
UAEZBProcaptezbp.exe"IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
XCentralProcessortaskimgr.exe"Added by the BANCOS.J TROJAN!"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCore Process Aplicationccapl.exe"Added by the QHOSTS.G TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
XCore Process Aplication x32ccapl32.exe"Added by the SRAMLER.E TROJAN!"
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
Xddeprocddeproc.exe"Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
UDiskSuiteaDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XHost Processmame.exe"Added by the RBOT-APO WORM!"
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UIBWin Background processIBackground.exe"IBackup for Windows"
XIMprocessIM-svr.EXE"IMNames adware"
UIntel Product Number UtilityIntelProcNumUtility.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
UIntelProcNumUtilitycpunumber.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
XMicro Processappconf.exeAdded by an unidentified WORM or TROJAN!
XMicrosft Remote Procedure Daemonmsrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processcmh.exe"Added by the EGGDROP.V WORM!"
XMicrosft Security Monitor Processmssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmpp.exe"Added by the SDBOT-DJW WORM!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Procedure CallMSPCALL.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Process Managerprocess32.exe"Added by the CHECKOUT WORM!"
XMicrosoft Security Monitor Processmssmp.exe"Added by the RBOT-FUB WORM!"
XMicrosoft Security Monitor Processmnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Security Monitor Processlsas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processmsword.exe"Added by the VIRUT.P VIRUS!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Monitor Processcom.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processexel.exe"Added by the SDBOT.AFX BACKDOOR!"
XMicrosoft Security Monitor Processfirewall.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
XMicrosoft Security Monitor Processflash.exe"Added by the EGGDROP.EE BACKDOOR!"
XMicrosoft Security Monitor Processhel.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor ProcessHelpMe.exe"Added by the VB.BJO TROJAN!"
XMicrosoft Security Monitor Processkar.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processlindicracker.exe"Added by the BIFROSE.GR BACKDOOR!"
XMicrosoft Security Monitor Processmail.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssmpi32.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Security Monitor Processnitty.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processofice.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processpoint.exe"Added by the IRCBOT.AVP BACKDOOR!"
XMicrosoft Security Monitor Processprinc.exe"Added by the HUPIGON.WTL TROJAN!"
XMicrosoft Security Monitor Processweb.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processword.exe"Added by the EGGDROP.DC BACKDOOR!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Server Processsvhst32.exe"Added by the BCKDR-QHR BACKDOOR!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftkeysdsystemproc.exe"Added by the FORBOT-BI WORM!"
?mmusrstpprocrun.exe"??"
Xmprocessormprocessor.exeInstallDollars.com foistware
XMs Processe Managermsproc.exe"Added by the RBOT.ATO WORM!"
XMS Remote Procedure Callmsrpc32.exe"Added by the RBOT-QL WORM!"
XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
XMS Windows Executor ProcessMSEXECP32.exe"Added by a variant of the RBOT WORM!"
XMS Windows procces 32msprocces.exe"Added by the RBOT-AEZ WORM!"
XMS Windows Process ClassMSPRCSS32.exe"Added by the RBOT-YQ WORM!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
XMsn Processe Managermsni32.exe"Added by the RBOT-ADX WORM!"
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
XNorton Service Processnavapvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton Service Processnavapsvc.exe"Added by the AGOBOT-GV WORM! Note - this is not the valid Norton Anti-Virus service which has the same file and is located in %ProgramFiles%\Norton AntiVirus. This one is located in %System%"
Xnsdcmd vid processnsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
YPavProcPavPrS9x.exe"Part of Panda Antivirus and Internet Security"
UPC Tools Disk SuiteaDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
XPopRock[path to trojan]"Added by the AGENT-LNU TROJAN!"
?POS-PartnerbatchprocessorBATCH.EXE"VISA credit card batch processing related to Appcon. Is it needed or can it be started manually via Start -> Programs or a manually created shortcut?"
XProcaprocess.exe"Added by the MOVINGMOUSE.475811 TROJAN!"
XProc992[path to file]"Added by the IXBOT-C WORM!"
XProc993wqxfne.exe"Added by the IXBOT-D WORM!"
XPROCESS SESSION MANAGERPIDSERV.EXE"Added by the RBOT-Y WORM!"
Xprocess.exeprocess.exe"Added by the BANCOS.P TROJAN!"
UProcessGovernorprocessgovernor.exe"Core engine for Process Lasso from Bitsum Technologies - ""a state-of-the-art
XProcessorsvchost.exe"Added by the AGENT-KIR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
NProcessQuickLink2ProcessQuickLink2.exe"ProcessQuickLink by Uniblue Systems Ltd - gives you quick access to their Process Library entry for a currently running process via the standard Windows Task Manager (CTRL+ALT+DEL). A System Tray icon also allows you to search the library and launch the Task Manager. Run on demand"
UProcessSupervisorGUIProcessSupervisor.exe"Graphical user interface (GUI) for Process Lasso from Bitsum Technologies - ""a state-of-the-art
UProcessTamerProcessTamerTray.exe"Mouser's Software Process Tamer ""is a tiny (140k) and super efficient utility for Microsoft Windows XP/2K/NT that runs in your system tray and constantly monitors the cpu usage of other processes"""
Xprocmonprocmon.exe"Added by the BIONET.40A TROJAN!"
NRay Process KillerPrkill.exe"Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead"
XRemote Procedure Callwinrpc.exe"Added by the RBOT-KM WORM!"
XRemote Procedure Callwinsysrpc.exe"Added by the SDBOT-PS WORM!"
XRemote Procedure Call For Windows 32bitrpc.exe"Added by the RBOT-MD WORM!"
XRemote Procedure Call LocatorRUNDLL32.EXE reg678.dll ondll_reg"Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRemote Procedure Callsmswinrpc.exe"Added by the RBOT.KJ WORM!"
XRemote Procedure Callsmswinc.exe"Added by the RBOT-IT WORM!"
XRemote Procedure Callswin.exe"Added by the SDBOT-QI WORM!"
XRuntime ProcessCsrss.exe"Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
XSecurity Update Service Processsvrhost23.exe"Added by the AGOBOT-GN WORM!"
XServer Runtime Processwbemstest.exe"Added by the SDBOT-DDB WORM!"
XService Host Processspoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
XService ProcessSVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Processwinset.exe"Added by a variant of the SPYBOT WORM!"
XService Processservice.exe"Added by the DCMBOT-C TROJAN!"
XService Processsmss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XService Processsvchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices Processservices.exe"Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XSHAProcSHAProc.exe"Added by the WINKO.AO WORM!"
Usks-32sks32proc.exe"SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself"
XSNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSOProc_RegSoAlertWxLiteNnAj"rundll32 shell32.dll ShellExec_RunDLL [path] soproc.exe"
XSpoolerSubSystemProcessSpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
XSproc32sproc32.exe"Added by the SPROCIT TROJAN!"
XSpywareGuardwinproc32.exe"Startpage adware Trojan"
Xsvcwinprocess32[path to worm]"Added by the UPERING WORM!"
XSysctrlsprocdll.exe"Added by the WEEDBOTZ.14 TROJAN!"
XSystem Database Administration Support Processsysdasp.exe"Added by the DERDERO.C WORM!"
XSystem Processcsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processsvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem ProcessCSRSR.exe"Added by the AGOBOT-SQ WORM!"
XSystem Process Analizationsysproc.exe"Added by a variant of the RBOT WORM!"
XSystem Process Analization Threadsystem.exe"Added by a variant of the RBOT WORM!"
XSystem Updater Processwmiprvsw.exe"Added by the AGOBOT-IL WORM!"
XSystemProcEvent[trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
?SystemRegPROCES.EXE"??"
UUeproc32UEPROC32.exePart of Norton Utilities - most likely associated with the Unerase Wizard in older versions
NUniblue ProcessQuickLink 2ProcessQuickLink2.exe"ProcessQuickLink by Uniblue Systems Ltd - gives you quick access to their Process Library entry for a currently running process via the standard Windows Task Manager (CTRL+ALT+DEL). A System Tray icon also allows you to search the library and launch the Task Manager. Run on demand"
XUpdater Service Processsvhost32.exe"Added by the AGOBOT.TY WORM!"
XUpdater Service Processcsrss32.exe"Added by the AGOBOT-GP BACKDOOR!"
XVideo Proceswinaps.exe"Added by the AGOBOT.HD WORM!"
XVideo Processsysconf.exe"Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!"
XVideo ProcessMS32x16.exe"Added by the RBOT.RH WORM!"
XVideo Processnetsvcs.exe"Added by the AGOBOT.LH WORM!"
XVideo ProcessMSlti64.exe"Added by the AGOBOT.UE WORM!"
XVideo Process[random filename]"Added by the RBOT-LM WORM!"
XVideo Processwinasp.exe"Added by the AGOBOT-IS WORM!"
XVideo Processmsn5.exe"Added by the AGOBOT-TW WORM!"
XVideo ProcessMStli32s.exe"Added by the RBOT-GAD WORM!"
XVideo Processwincert32.exe"Added by the AGOBOT.JT WORM!"
XVideo Processntsystm.exe"Added by the GAOBOT.ZX WORM!"
XVideo ProcessNivopsvc.exe"Added by the AGOBOT-GT WORM!"
XVideo Processwincrt32.exe"Added by the AGOBOT-GR WORM!"
XVideo ProcessAvg123.exe"Added by the AGOBOT-MS WORM!"
XVideo ProcessNavapsvcc.exe"Added by the SPYBOT-CW WORM!"
XVideo Processormsconfsys88.exe"Added by the AGOBOT-QG WORM!"
XVITAL BOOT PROCESStaskmngr.exe"Added by a variant of the RBOT WORM!"
XVITAL BOOT PROCESStaskmnsgr.exe"Added by the Rbot-VY WORM!"
XVital Load ProcessSpoolsvr.exe"Added by the RBOT.AIF WORM!"
XVMware User ProcessKHATRA.exe"Added by the AUTOIT.K TROJAN!"
XVprocessscvtw32.exe"Added by the AGOBOT-FR BACKDOOR!"
XWIN HOST PROCESSWIN HOST PROCESS.EXE"Added by the KEYLOGGER.CLONE TROJAN!"
XWin Process Updateswinupdates.exe"Added by a variant of the SDBOT WORM!"
XWin32Host Processwebemir.exe"Added by the TURGEN -A TROJAN!"
XWindows Generic Procprocmsg.exe"Added by the ALLIM.B WORM!"
XWindows Internet Protocolwinproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
Xwindows logon procedurewinlogonpc.exe"Added by the WINLOGON TROJAN!"
XWindows Processwin_update.exe"Added by the LASTWORD WORM!"
XWindows Process Managerwinproc.exeAdded by an unidentified WORM or TROJAN!
XWindows Processe Managermspn32.exe"Added by the RBOT.AXO WORM!"
XWindows Runtime Proccess32RUNdll.exe"Added by the SDBOT.QW WORM!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Socket ProcedureWinSock32.exe"Added by the RBOT-FMX WORM!"
XWindows System Manager Procwinsmc.exe"Added by the RBOT.JH WORM!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWinProc32winproc32.exe"Added by the AGOBOT-4 WORM!"
XWinprocer32 Updatewinprocer32.exe"Added by the RBOT.GW WORM!"
Xwinprocessor Updatewinprocessor.exe"Added by the RBOT.IO WORM!"
XWinXP Processor Generator v1.2intspnsr32.exe"Added by the SDBOT.LP WORM!"
NWXProcMgr ModuleWXprocMgr.exe"TVTonic from Wavexpress - ""enjoy 3 full-screen
XxDRam rar procxxwinupdaterarx.exe"Added by the RILER-W TROJAN!"
X[various names]Serviceprocess.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.