Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
XAdtools ServiceAdTools.exe"Windupdates Adware"
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
?AspireServiceAspireService.exe"Found on Acer laptops
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
XBackup Servicebackup.svcUnidentified adware
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
Ubugwatcher servicebugwatcher.exe"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM Servicemskwda.com"Added by the AGENT-JIX TROJAN!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
NConfigServicesConfig.exePart of initial setup on a Compaq PC
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
?desk-top-servicedesk-top-service.exe"??"
XDeskAd ServiceDeskAdServ.exe"DeskAd.Service adware"
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
YDkServiceDkService.exe"From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
XDLLService32dllsvc32.exe"Added by the AGOBOT.VX WORM!"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
XDSServicedmrss.exe"Added by the AGOBOT-XX WORM!"
XDumeter Servicesdumeter.exe"Added by the SDBOT-AEQ WORM!"
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
XEnumerate Servicewsys.exe"Added by the MANIFEST TROJAN!"
UEPGServiceToolEPGClient.exe"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPGServiceToolEPGCLI~1.EXE"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
YeRecoveryServicecheck.exe"Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceMonitor.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceeRAgent.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
?EverioServiceEverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
Xfukerservicefukerz.exe"Added by a variant of the RBOT WORM!"
Ufwservicefwservice"eAcceleration Stop-Sign security software related. Previously not recommended
?GACServiceGACService.exe"Related to a Gemplus product. What does it do and is it required?"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
UGoBack Polling ServiceGBPoll.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
XGolumservices.exe"Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process
Xgolummservices.exe"Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
XGoogle serviceGooglesetup.exe"Added by the IRCBOT-RJ WORM!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
XHardware Monitor Servicemshms.exe"Added by the WOLLF-A TROJAN!"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
XHOI Servicesholsvc32.exe"Added by the AGOBOT-SF WORM!"
XHP Service Drivershdsys.exe"Added by the SDBOT-ZE WORM!"
?hp Silent ServiceHpSrvUI.exe"HP related"
XHPl Serviceshmlsvc32.exe"Added by the AGOBOT-SI WORM and variants!"
XHQI Serviceshqisvc32.exe"Added by the AGOBOT-RO WORM!"
XHQI Serviceshqlsvc32.exe"Added by the AGOBOT-RP WORM!"
XHservicemsservice.exe"Added by the AUTORUN-KL WORM!"
XICQ Chat Serviceicqjdhs.exe"Added by a variant of the RBOT WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
XICU-SuckerService32.exe"Added by the ILLNOTIFIER.D TROJAN!"
XIEService.exeIEService.exe"FastFind adware variant"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
YIKE Service 95IKEService.exe"Associated with PGP. The PGP Tray can be disabled
XIndex Servicedllhost32.exe"Added by the AGOBOT.CH WORM!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XInternet download manager serviceidman.exe"Added by the RBOT-BMS WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Security Servicemsq32.exe"Added by the RBOT-GFP WORM!"
XInternet Security Servicemsq23.exe"Added by the RBOT-GQL WORM!"
XInternet Security Servicemsql23.exe"Added by the RBOT-GML WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XIP Packet Redirect Serviceipredirect.exe"Added by the FORBOT.SM WORM!"
XiPod USB ServiceiPODService.exe"Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service
XIPOT Service Driverscompaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPOT USB Service DRV32hpsebc08.exe"Added by the SDBOT-WH WORM!"
XIPv6 STUN Servicenetstun.exe"Added by a variant of the SDBOT WORM!"
UiRiver AutoDBMLService.exe"Associated with the iRiver Music Manager"
XISPSERVICEpsycho.exe"Added by the IRCFLOOD-O TROJAN!"
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
XIST Serviceistsvc.exe"ISTBar adware"
Xist service uninstall[random filename]"ISTBar adware related"
NIVPServiceMgrivpsvmgr.exe"Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as
XJavaScript Debugging ServiceJsDbgMan.exe"Added by the DERDERO.E WORM!"
XKernelservices.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernel Servicesservice32.exe"Added by the PRX-B TROJAN!"
XKKM Servicekkm.exe"Added by the NANPY-I WORM!"
XLayersecurity ServicemonitorLSSMON.EXE"Added by the BANKER.ZAQ TROJAN!"
ULG Direct Media Button ServiceLGDMEBTN.exe"Supports the Direct Media button on LG Notebooks that support it - such as the S1 PRO EXPRESS DUAL. Pressing this button launches the application for watching movies or listening to music"
NLicCrtlrunservice.exe"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running
XLiveUpdate32services.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
XLoadServiceRest In Peace"Added by the KANGAROO-A WORM!"
XLoadService"Maaf tempatmu bukan di sin"
XLoadServiceVirus"Added by the CAGER.A WORM!"
XLocal Authority Servicelsass.exe"Added by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLocal runole servicesrvc32.exe"Added by the SMALL-DP TROJAN!"
XLocal Security Authority Servicelssas.exe"Added by the POEBOT-J WORM!"
XLocal Security Authority ServiceIsass.exe"Added by the LINKBOT.M WORM!"
XLocal ServiceIntenat.exe"Added by the NUCLEAR-J TROJAN!"
XLocal Serviceservices.exe"Added by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Cursors"
XLocator Service[filename]"Added by the AGOBOT-KY TROJAN!"
XLogin Service[path to file]"Added by the MIGMAF TROJAN!"
?LogitechCameraService(E)ElkCtrl.exeEntry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
XLogServicewincalc.exe"Added by the PAPROXY TROJAN!"
XLogServicelsass.exe"Added by the BDOOR-IU BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLogServicelsrss.exe"Added by the PAPROXY-D TROJAN!"
ULogServiceLogService.exe"SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XLSA ServiceLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
Xlsa Serviceslsa2srv.exe"Added by the TAME-C WORM!"
Xlsass servicelsass2.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
NMacrovision Update Serviceissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NMacrovision Update ServiceISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
Xmark the servicexxtra32.exe"Added by the SDBOT.APP WORM!"
UMaxBackSchedulemaxbackservice.exeBackup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick Start
UMcAfee Managed Services TrayStartMyagtTry.exeSystem tray notification for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Not required to be protected but you lose notifications
YMcAfeeVirusScanServiceAvsynmgr.exe"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe)
XMDNSservice.exe"Mirar adware variant"
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
XMedia Servicemsn64.exe"Added by the SPYBOT.EV WORM!"
XMedia servicemsnmsgxr.exe"Added by the SDBOT.TF WORM!"
XMedia serviceSYSTEM64.EXE"Added by the RBOT.QV WORM!"
XMedia servicenotpad.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMedia Services[filename].exe"Added by the AGENT-BA BACKDOOR!"
XMedia X ServicesMSNGRx.exe"Added by the RBOT.AUL WORM!"
XMedia-XP-Service-Pack3msnzx.exe"Added by the SDBOT-ACW WORM!"
UMediaLifeServiceMediaLifeService.exe"Related to MediaPlay Cordless Mouse from Logitech"
XMediaXPServicePackmxpsp.exe"Added by the SDBOT.CDT WORM!"
XMemory Allocation Servicescisrv.exe"Added by the IRCBOT.FC BACKDOOR!"
XMemory relocation servicereloc32.exe"Added by the RELFEERWORM!"
XMemory Servicefreememory.exeAdded by the RBOT.GEN WORM!
XMessenger Servicemsmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMessenger Servicenvhost.exe"Added by the JLOK-A WORM!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
XMgsgi servicewkzfn.exe"Added by the AGOBOT-AHL WORM!"
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicrcsoft Certificate Servicescflmon.exe"Added by the RBOT-FWV WORM!"
XMicrosoftsqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Authority Servicelsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Browser ServicesBrwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Browser ServicesBrwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Debug Servicedbgbgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft dll Host Servicewkssr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLL Host Servicedllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Host Servicesvcdllhst.exe"Added by the AGENT.EAK TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft DLL Serviceservicedll.exe"Added by the IRCBOT.OX BACKDOOR!"
XMicrosoft DLL Servicesvcdll.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft EV32 ServiceMSev32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicroSoft Legal ServiceSrb0ty.exe"Added by the SPYBOT.HW WORM!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft media servicesIassd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Ming Serviceming.exe"Added by the RBOT-AWS WORM!"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN 7 Servicesmsnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Nod32 Servicenood32.exe"Added by the RBOT.EJP WORM!"
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SecureMessenger.NET Service"Added by the FORBOT-AM WORM!"
XMicrosoft Secure Messenger.NET Servicesecuritychk.exe"Added by the SDBOT.VT WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Centersavservices.exe"Added by the RBOT-ANU WORM!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Servicemicrohost.exe"Added by the RBOT-LC WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicerundll.exe"Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoft Serviceservice.exe"Added by the IRCBOT-XX BACKDOOR!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft servicecssrs.exe"Added by the STARTP-DC TROJAN!"
XMicrosoft Service 32mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service 32sysddm32.exe"Added by the SDBOT.AKC WORM!"
XMicrosoft Service Access ManagerAccess.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Service Bootsboot.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
XMicrosoft Service Disk Cycledisksave.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service Execution Managerexecute.exe"Added by a variant of the IRCBOT TROJAN! See here"
XMicrosoft Service firewall Managerfirewall.exe"Added by a variant of the SDBOT BACKDOOR! Located in %System%"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Service Login Managerwinlogin.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Managerservice32.exe"Added by the IRCBOT.WDW BACKDOOR!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Service ToolsMStools1.exe"Added by the RBOT-BHT WORM!"
XMicrosoft Serviceslsserv.exe"Added by an unidentified VIRUS
XMicrosoft Serviceslssrv.exe"Added by the RBOT.CW WORM!"
XMicrosoft Servicesservices.exe"Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Serviceslsrv.exe"Added by the RBOT-BK WORM!"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicesbsc32.exe"Added by the BDOOR-AW BACKDOOR!"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicesmodule.exe"Added by the LAVITS WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Services UnitdMSU32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicez Managerservicemgrz.exe"Added by the RBOT-ASN WORM!"
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft Updateservice.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Update Machineservicez.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update SERVICEphqghum.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft uptime Servicesysuptime.exe"Added by the RBOT-ACG WORM!"
XMicrosoft uptime Servicesycuptime.exe"Added by the RBOT-AHY WORM!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XMicrosoft Virtual Service Managervservice32.exe"Added by the MSNWORM.T WORM!"
XMicrosoft Vista Upgrade Validation Servicecfmon.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Visual SourceSafeservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoft XML Servicemsxmlx.exe"Added by the RBOT.KS WORM!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagermstask32.exe"Added by the YAHA.P WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftServiceManagermsupdat.exe"Added by the YAHA.AA WORM!"
XMicrosoftXP Service Pack 2servicepack2.exe"Added by the RBOT.EMC WORM!"
XMicrost dds servicewsrss.exeAdded by an unidentified WORM or TROJAN!
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
NMMReminderServiceMMReminderService.exe"Mind Manager from Mindjet - ""easy way to organize ideas and information"". Registration reminder"
XMMtask Servicemmtask.exe"Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename"
XMonitoring Servicesvchost.exe"Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XMP Servicesmpsvc.exe"Added by the WOOTBOT.EQ WORM!"
XMPtask Servicesmptask.exe"Added by the LALA or AOT TROJANS!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMS Registry ServiceMSRMS32.exe"Added by the RBOT-AKP WORM!"
XMS Security Authority Servicelsass.exe"Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process
XMS Security Hotfixservice5.exe"Added by the GAOBOT.AG WORM!"
XMS servicemsservice.exe"Added by the RBOT-ZG WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
Xms spool servicemsspooler.exe"Added by a variant of the RBOT WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS-DOS Boot ServiceBoot32.pif"Added by the RBOT-AMF WORM!"
XMS-DOS Security Servicems-dos.pif"Added by the RBOT-AMR WORM!"
XMS-DOS ServiceMS-DOS.pif"Added by the RBOT-AII WORM!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMSDOS Security Servicemsdos.pif"Added by the RBOT-AMP WORM!"
XMSDOS ServiceMSDOS.PIF"Added by the RBOT-AIY WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
Xmservices.exemservices.exe"Added by the SDBOT.WJ WORM!"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
Xmsjava servicexpcd.exe"Added by the SDBOT.VM WORM!"
XMSNservices51651.exe"Added by the IRCBOT-AAL TROJAN!"
XMSNmsservice.exe"Added by the IRCBOT-ABZ TROJAN!"
XMSN BETAservice.exe"Added by the RBOT.AUU WORM!"
XMSN Message Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN messenger servicemssgs.exeAdded by an unidentified TROJAN!
XMsn Messenger Servicemsnmsg.exe"Added by the SDBOT.BMU WORM!"
XMSN Messenger Service Startermsnmgsr.exe"Added by the RBOT-AOS WORM!"
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Messenger Servicesmsnmgr.exe"Added by the RBOT.ADF TROJAN!"
XMSN Messenger Servicesmsnmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN servicemsnmgr16.exe"Added by a variant of the RBOT WORM!"
XMSN Serviceamsnmsgrs.exe"Added by a variant of the SDBOT WORM!"
XMsn Servicematrixcam.exe"Added by the MYTOB.JH WORM!"
XMsn Serviceraloded.exe"Added by the MYTOB-DY WORM!"
XMSN servicemsnmsgr16.exe"Added by the RBOT-RZ WORM!"
XMSN serviceNTDKRN.EXE"Added by the RBOT.UJ WORM!"
XMSN Servicemsnsvc.exe"Added by the SLENFBOT.EG WORM!"
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
XMSN Service Utilitiesnkn.exe"Added by the KELVIR-BC WORM!"
XMSN Service!msnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Servicermsnsrv.exe"Added by a variant of the IRCBOT TROJAN!"
XMSN Servicermsnservicer.exe"Added by the SLENFBOT.PQ WORM!"
XMSN Servicesmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMsn Update Serviceuserx.exe"Added by the MYTOB.JF WORM!"
XMSN Update Servicemsnupdsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Server!msnservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicemsnsvc.exe"Added by the SLENFBOT.NS WORM!"
XMSN User Service!msnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicesmsnuserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN32 X ServiceMSN32x.EXEAdded by an unidentified WORM!
XMSNServiceMSNService.exe"Added by the CARPET.C WORM!"
XMSOfficeservices.exe"Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
XMSOfficeCfgqservice.exePremium rate adult content dialer
Xmsservicemsserv.exe"Added by the HYD WORM!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XMSService_v1.0vfp02.exe"NewWeb adware"
XMsvcServicemsvcs.exe"Added by the RBOT-RK WORM!"
Xmswkork Servicemsework.exe"Added by a variant of the RBOT WORM!"
XMultimedia extensionsmservice.exe"EasySearch adware"
XMultimedia extensionsmservice1.exe"Added by the DLOADR-AWD TROJAN!"
Nmumservicemumservice.exe"Software updater for Motorola products"
NMutexServiceExSys32Smm.exe"Webroot Sofware's discontinued ""Privacy Master"""
XMyappservice.exeHomepage hijacker
YMyCIO Agent Servicemyagtsvc.exe"Part of the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
YNaimagent_serviceEPOAgentnaimas32.exe"Networked version of McAfee VirusScan. Installs
XNAV Scan ServiceNAVSCAN32.EXE"Added by the SDBOT.VG WORM!"
NNeroNETTrayIconNNServiceCtrl.exe"System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
XNetManagerServicentss.exe"Added by the BESTPICS.A TROJAN!"
UNetscapeInstallService.exeRelated to Netscape installation
XNetServicentsvc.exe"Added by the QQPASS-DU TROJAN!"
Xnetservicesrecall.exe"Added by the WOOTBOT.D WORM!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNETServicescsxrs.exe"Added by a variant of the SDBOT WORM!"
XNetwork Administration Servicersvc32.exe"Added by the RBOT.ABH WORM!"
UNetwork Associates Error Reporting ServiceTBMon.exeNetwork Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
XNetwork Host Service[random]32.exe"Added by the RBOT-BAB WORM!"
XNetwork Protocol Servicewuamgrd.exe"Added by the RBOT.EA WORM!"
XNetwork protocol servicewintcp.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Provisioning ServiceWinNPS.exeAdded by an unidentified WORM/TROJAN!
XNetwork Servicesvchost.exe"Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XNetwork ServiceMccTrayApp.exeAdded by an unidentified WORM or TROJAN!
XNETWORK SERVICESVÑHOST.exe"Added by the DELF-EW BACKDOOR!"
XNetwork Service Managernetsvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Servicesnetsvacs.exe"Added by the GAOBOT.AIS WORM!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
?News Serviceispnews.exe"F-Secure antivirus related. However
UNFM ServiceNPDOR9x.exe"Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
?nMTaskBarServicenMtsk.exe"Taskbar control for ISDN NetMod modem. What does it do and is it required?"
XNod23 Servicenod23.exe"Added by the RBOT-GMK WORM!"
XNod29 Servicenodwr.exe"Added by a variant of the RBOT WORM!"
XNod32 Servicenod64.exe"Added by the RBOT.ESJ WORM!"
XNod32 Servicealserv32.exe"Added by the RBOT.DHN WORM!"
XNod32 ServiceAutoUpdateWin32.exe"Added by the SDBOT-DJG WORM!"
XNod32 Servicenod6.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XNorton Auto-ProtectSERVICES.exe"Added by the AHKER.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Also
XNorton Service Driverwsul.exe"Added by the RBOT-ABI WORM!"
XNorton Service Processnavapvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton Service Processnavapsvc.exe"Added by the AGOBOT-GV WORM! Note - this is not the valid Norton Anti-Virus service which has the same file and is located in %ProgramFiles%\Norton AntiVirus. This one is located in %System%"
?NovaPortal Single User ServiceNPSU.exe"??"
Xnsdcmd servicesnsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNT Logging ServiceSyslog32.exe"Added by the DONK.B WORM and variants!"
XNT Printing Servicespoolsc.exe"Added by the BUZUS-K WORM!"
XNT Printing Servicechkdsks.exe"Added by the ARCHIVARIUS series of WORMS!"
XNT Printing Servicechkdskss.exe"Added by the ARCHIVARIUS series of WORMS!"
XNT Printing Serviceschkdsks.exe"Added by the BUZUS-M TROJAN!"
XNT ServiceNTOKSRNL.EXE"Added by the RBOT-AAG WORM!"
XNT Servicesntsvc.exe"Added by the AGOBOT.VJ WORM!"
XNTSet32services.exe"Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32"
UNVIDIA® NVRAIDnvraidservice.exe"Part of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
UNVRaidServicenvraidservice.exe"Part of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
UOctoshape Streaming ServicesOctoshapeClient.exe"Octoshape Live Streaming - ""is a revolutionary technology that will reduce your bandwidth cost and improve the quality in sound and picture"""
NOdebit Multimedia V3 - ServicesOdebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
XOLEDb Servicerunoledb32.exe"Added by a variant of the SPYRE.B TROJAN!"
XOnline Servicesvchost.exe"Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XOnline Servicestwain.exe"Added by the AGENT.BEA TROJAN!"
XOpen Service Driversopiater.exe"Added by a variant of the RBOT WORM!"
NOptusNet Desktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
XOutlook Mail Servicesexpress.exe"Added by the RBOT.CJN WORM!"
XOutlook Mail Servicesoutlook.exe"Added by the RBOT-BKA TROJAN! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %System%"
UPanda Antispam Server ServicePasSrv.exe"AntiSpam part of an older version of Panda Internet Security"
YPanda Preventium+ ServicePREVSRV.EXE"Part of the 2004 & 2005 versions of Panda Antivirus and Internet Security"
NPCMServicePCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
Npdservicepdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
NPDService.exepdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
?PeeramidPService.exe"In a ""Koptimizer"" folder in Program Files. What does it do and is it required?"
UPGPSERVICEpgpservice.exe"PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice
UpiiserviceOEN/A"Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE"
XPK Servicespksvc.exe"Added by the FORBOT-BW WORM!"
XPlasdll service[random filename]"Added by a variant of the SDBOT WORM!"
NPlayMoviePMVService.exe"Part of Acer Arcade Deluxe lets you browse pictures
?PMCSPMC.Service.Main.exe"Related to MediaCenterService from Pinnacle Systems. What does it do and is it required?"
XPNtask Servicespntask.exe"Added by the LALA.C TROJAN!"
XPreview AdServicePrevAdServ.exeWindupdates adware variant
XPrint Driver Helper Servicecrsrr.exe"Added by the AGENT-BC TROJAN!"
XPrint Servicesspolserv32.exe"Added by the RBOT.ZP WORM!"
XPrinter Servicesspool.exe"Added by the RBOT-Y WORM!"
XPrinter spool Servicespool.exe"Added by the RBOT-ACP WORM!"
NPrivateDiskpdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
XProgram Access Service[10 random letters].exe"Added by the RBOT.GJJ WORM!"
XPrU Async Service[path to worm]"Added by the IRCBOT-UG WORM!"
XPServicesvcnow32.exe"Added by the SPYBOT-DJ TROJAN!"
Xpushbotservice52.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
UQPServiceQPService.exe"HP QuickPlay - ""brings your favorite music and movies to life with the touch of a button"""
Xqservicesqservice.exe"Added by the PROGENT-A TROJAN!"
YRaptor Mobilevpnservices.exe"Symantec VPN Client used to connect to corporate networks. If unchecked
XRasCon Remote Access Service Managerrasmngr.exe"Added by the SPYBOT.EM WORM!"
XrCrondservice.exe"""Switch"" premium rate adult content dialler variant"
XReg Servicewinsy.exe"Added by a variant of the SPYBOT WORM!"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XReg Serviceipcfg.exe"Added by the AGOBOT-SO WORM!"
XReg ServiceREGSRV32.EXE"Added by the RBOT.ZW WORM!"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XReg ServiceNT32.exe"Added by the AGOBOT.G TROJAN!"
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
XRegDoneservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XRegistration Servicetoker.exe"Added by the SDBOT-BB WORM!"
XRegistration Servicemsvdm6.exe"Added by the SDBOT-HE TROJAN!"
XRegistry ServiceREGSRV32.EXE"Added by a variant of the RBOT WORM!"
XRegistry Serviceresvs.exe"Added by the DELBOT-I WORM!"
XRegistry Serviceregsvc.exe"Added by the IRCBOT-ZM BACKDOOR!"
XRegistry ServicesRegistry.exe"Added by the CILE TROJAN!"
XRegistry Value Nameservice.exe"Added by the RBOT-AHT WORM!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
Xregservices.exeregservices.exe"Added by an unidentified VIRUS
XRemote Access Service Managerrasmngr.exe"Added by the AGOBOT.KU WORM!"
XRemote Services Managermsrmsvc.exe"Added by the SLENFBOT.AJ WORM!"
XRequired Service Driversmicront.exe"Added by the RBOT-ABD WORM!"
XRPC Service[random filename]"Added by the BDOOR-AAD BACKDOOR!"
XRPCser32gservices.exe"Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g1services.exe"Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g3services.exe"Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g4services.exe"Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32services.exe"Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gservices.exe"Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrunservices.exe"Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066"
XRun Services as Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
URunAlertAService.exe"PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/2K"
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunservicesservices.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrw servicealg32.exe"LOOPAD.A adware"
Xr_serverservice.exe"Added by the MULTIDR-CP TROJAN!"
?SA ServiceSAservice.exe"Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?"
USAGENTSERVICESagent.exe"TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself"
XSANS Servicesansv.exe"Added by the VANEBOT-AH WORM!"
XScheduler Servicewsass.exe"Added by the LIOTEN.KX WORM!"
Xscssrr.exeServices.exe"Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsecurity servicesyss.exeAdded by an unidentified WORM or TROJAN!
XSecurity Servicesecsvc.exe"Added by the RBOT-GGF WORM!"
XSecurity Service DBsecservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
XSecurity Update Servicewmiprvce.exe"Added by the AGOBOT.ZW WORM!"
XSecurity Update Service Processsvrhost23.exe"Added by the AGOBOT-GN WORM!"
XSerices Hostinservicez.exe"Added by the SLENFBOT.MF WORM!"
XServiceservice.exe"Added by the ALADINZ.H TROJAN!"
XService[trojan filename]"Added by the KAITEX.E TROJAN!"
XServiceservices.exe -serv"Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServiceSYSNT.exe"Added by the CHA TROJAN!"
XServiceService.pif"Added by the ASSIRAL-C WORM!"
XservicewN2S.exe"Added by a variant of the RBOT WORM!"
UService Centrelauncher.exe"Management tool for the Open Networks iConnect series of products - as used by Australian ISP's such as iiNet and Hotkey"
XService Cleanerfilen.exe"Added by the RBOT.BRH WORM!"
XService Clientwinsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
NService Connectionsccenter.exeFor Compaq PC's. Part of Backweb
NService Connectionbwtray.exeFor Compaq PC's. Part of Backweb
XService Control Managerscm.exe"Added by the AGOBOT-GD BACKDOOR!"
XService ControllerCsrrs.exe"Added by the GAOBOT.AO WORM!"
XService Controllerservice.exe"Added by the PREVERT TROJAN!"
XService Defender[random filename]"Added by a variant of the ZLOB TROJAN! See here"
XService Driversmsnpg.exe"Added by the RBOT.BMD WORM!"
XService DriversPC.EXE"Added by the SDBOT-WK WORM!"
XService DriversCompt.exe"Added by the RBOT-ZJ WORM!"
XService Driversabl.exe"Added by the SDBOT-YX WORM!"
XService DriversMSNMEssenger.exe"Added by a variant of the RBOT WORM!"
XService Hostsvchost.exe"Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Host[filename].exe"Added by the TORVEL.B WORM!"
XService Hostspoolxx.exe"Added by the TORVEL WORM!"
XService Hostsvchost.exe"Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853}"
XService Hostsvchost.exe"Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random]"
XService Hostsvchosts.exe"PornCleanser spyware"
XService Host Driversvchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Host Processspoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
NService Managersqlmangr.exe"SQL Server Service Manager - provides tray access to SQL server
XService ManagerSERVICEMGR.EXE"Added by the PASSMAIL-D VIRUS!"
XService Managerdxsound.exe"Added by the PROXY-GRIC TROJAN!"
Xservice managerservice.exe"Added by the DONBOMB.A TROJAN!"
XService Managerserv3manager.exe"Added by the SDBOT-AGO WORM!"
XService Monitormsnfilen.exe"Added by the RBOT-ALE WORM!"
XService Monitorjavams32.exe"Added by the DELF-NK TROJAN!"
XService Monitorjavams64.exe"Added by the SDBOT-AFO WORM!"
XService Monitormsnserve.exe"Added by the SPYBOT.YQW WORM!"
XService MonitorWinOcx.exe"Added by the RBOT-AQJ WORM!"
XService Monitorcsnss.exe"Added by the RBOT.EEH WORM!"
XService Monitorfilen.exe"Added by a variant of the RBOT WORM!"
XService Monitorwinxpser.exe"Added by the RBOT-BDF WORM!"
XService Pack[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
XService Pack 1[random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
XService Pack DLL Runtimespdll32.exe"Added by a variant of the RBOT WORM!"
XService PAck SFVP[worm filename].exe"Added by a variant of the RBOT WORM! The filename is 4 random characters"
XService ProcessSVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Processwinset.exe"Added by a variant of the SPYBOT WORM!"
XService Processservice.exe"Added by the DCMBOT-C TROJAN!"
XService Processsmss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XService Processsvchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XService Registry NT Savejdbgmgrnt.exe"Added by the BANCOS-CG TROJAN!"
XService Registry NT Savetaskmgrnt.exe"Added by the BANCOS-BY TROJAN!"
XService Registry NT Saveregeditnt.exe"Added by the BANCOS-BM TROJAN!"
XService Schedulerscheduler.exe"Added by the AGOBOT-PH WORM!"
XService Systemkernels32.exe"Added by the BANCOS-DA TROJAN!"
XService SystemwindowsXP.exe"Added by the BANCOS-EL TROJAN!"
XService Systemkgbfsm344.exe"Added by the BANCOS-FS TROJAN!"
XService Systemwernell87.exe"Added by the BANCOS-FJ TROJAN!"
Xservice updaerqualityz.exe"Added by an unidentified VIRUS
XService Update Clientsvcupdcli.exe"Added by an unidentified WORM or TROJAN! See here"
XService.exeService.exe"""servedby.advertising"" popup generator"
XService2Service2.exeIdentified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel
Xservice32service32.exe"Added by the AGOBOT-ST WORM!"
Xservice32.exe[path to trojan]"Added by the DLOADR-AYX TROJAN!"
XServiceSERVICES.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XServiceAdministratorSERVICES.EXE"Added by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
UServiceConfigispbeg.exe"Comcast Transition Wizard. On June 30th
Xserviceconnectserviceconnect.exe"Added by the AGOBOT.AIR WORM!"
XServiceeservices.exe"Added by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServiceHostsvch0st.exe"Added by the VB.HE VIRUS!"
XServiceHstsvcnost.exe"Added by the AGOBOT-RS WORM!"
Xservicelayerservicelayer.exe"Added by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
Xservicemngservice.exe"Added by the TAME-C WORM!"
XServiceOptionMP3winamp.dll.exe"Added by the SAMSON-A TROJAN!"
XServicerservcr.exe"Added by the SDBOT.BAH TROJAN!"
XServicerepclient1SERVICES.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xservicesstart.bat"Added by the ZCREW TROJAN!"
XServices[path to trojan]"Added by the METEORSHELL TROJAN!"
XServicesback32.exe ...service.exe"Added by an unidentified VIRUS
XServicesservices.exe"Added by a number of VIRUSES
XServiceswinread.exe"Added by an unidentified VIRUS
XServiceswindns.exe"Added by a variant of the RBOT WORM!"
XServicesmshost.exe"Added by the LANFILT-J TROJAN!"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
XServicescsrss.exe"Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XServicesscks32.exe"Added by a Proxy Trojan variant"
XServicessockys32.exeAdded by the RANKY.L TROJAN!
XServicessys.exe"Added by a Proxy Trojan variant"
Xserviceswindows32.exe"Added by the FLYVB-C WORM!"
Xservicessocks.exeAdded by the WIN32.SMALL.N TROJAN!
XServicesservices.exe"Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices[path to trojan]"Added by the RANCK-DB TROJAN!"
XServicesiexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XServicessvchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServicessysamp.exe"Added by a variant of the SDBOT WORM!"
XServicesprosys32.exeAdded by an unidentified WORM or TROJAN!
XServicesiexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XServicesiexploler.exe"Added by the RANCK-LT TROJAN!"
XServicesiexpolere.exe"Added by the RANCK.LU TROJAN!"
Xservicessample.exe"Added by a variant of the RANKY TROJAN!"
XServicescsrss32.exe"Added by the ANACON-D VIRUS!"
XServices Administratorlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratornetsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcman.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratortcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Controllerlsassa.exeAdded by the CIADOOR.122 VIRUS!
XServices Controllerservices.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices DLL Loadersrvdll.exe"Added by the SLENFBOT.ZS WORM!"
XServices HostScchost.exe"Added by the DONK WORM!"
XServices Hostsvchost32.exe"Added by the AGOBOT-TG WORM!"
XServices hostsvchost.com"Added by the RBOT-EU WORM!"
XServices Logonservices.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates"
XServices Management Clientsservc.exe"Added by the RIZO.A TROJAN!"
XServices Managementsservcs.exe"Added by the RBOT-GUC WORM!"
XServices Managersvsmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XServices Manager!svmanager.exe"Added by the IRCBOT.ATZ BACKDOOR!"
XServices Managerssvcmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XServices NetworkServices.exe"Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XServices Processservices.exe"Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices Start2odcwinst.exe"Added by the PYSKE-D WORM!"
XServices Startupservices.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XServices Startupsvhost33.exe"Added by a variant of the RBOT WORM!"
XServices++services.exe"Added by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLER"
XServices.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
XServices.EXEservices.exe"Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xservices.exeservicess.exe"Added by the MSNSPY-B TROJAN!"
XServices004[worm filename]"Added by the BUGBROS WORM!"
Xservices32mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
Xservices32mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
Xservices32mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
XServices32 Startupwin32dll.exe"Added by the SDBOT-XO WORM!"
XServicesActivecssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
XServicesAdministratorSERVICES.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process
XServicesaraservices.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XServicesLoadlsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServicesLogccapp32.exe"Added by the RBOT-AMX WORM!"
UServicesNotifyServicesNotify.exe"Defender Pro Antispy"
Xservicestub.exeservicestub.exe"Added by the RBOT.CN BACKDOOR!"
XServicewinHide32.exe"Added by the MSNVB-D WORM!"
XSES Servicesesvc.exe"Added by the SDBOT-CZU WORM!"
XSFtrb Servicecftrb32.exe"Added by the SOBIG.D WORM!"
XSiS Mpc Servicempcsvc.exe"Added by the CIADOOR-CJ TROJAN!"
UsiService.exesiService.exe"Spam Inspector - anti email spam software"
XSistem Servicessyspool.exe"Added by the AGOBOT-GF WORM!"
YSkySurfer Management ServiceSmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
NSmart Card ServiceScardSvr.exe"For Smart Card readers. Known to cause problems
YSMC Servicesmc.exeSygate Firewall
YSMC Servicespfsmc.exeSygate Firewall
YSmcServicesmc.exeSygate Firewall
YSmcServicessmc.exeSygate Firewall
YSmcServicesspfsmc.exeSygate Firewall
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
XSound servicesSOUND32.EXE"Added by the AGOBOT.GG WORM!"
XSpecial Firewall Serviceavguard.exe"Added by the NETSKY.G WORM! Note - do not confuse with AntiVir® antivirus which uses the same filename. This one is located in %Windir%"
XSpooler de Impressservices.exe"Added by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User%"
XSpooler ServiceSpoolsrv.exe"Added by the JOINER.C1 TROJAN!"
XSpools Service Controllerspools.exe"Added by the KASSBOT-C WORM!"
XSpoolServicespolsv.exe"Added by the AGOBOT-CS WORM!"
Xspoolsv servicespoolsv32.exe"Added by the RBOT-AHP WORM!"
USpriteServiceSpriteService.exe"Sprite Backup is a backup application for Windows Mobile Pocket PC or Smartphone"
XSQL Server Servicesql.exe"Added by the RBOT-ADF"
Xsqserviceswins32.exe"Added by the PROGENT-B TROJAN!"
XSrv32 spool servicerunsrv32.exe"Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN!"
XSrv32 spool servicespoolsrv32.exe"Added by the SPYRE-B TROJAN!"
XSrv32 spool service[path to trojan]"Added by the DLOADER-LB TROJAN!"
USSC Service Utilityssc_serv.exe"SSC Service Utility is a printer utility for refilled Epson cartridges"
XSSK Servicewinssk32.exe"Added by the SOBIG.E WORM!"
UStart Serviceupssrv.exe"Cyber Power PowerPanelPlus software. ""During a power failure the system automatically saves and closes open files within the battery backup time and safely powers down your computer"""
XState Servicecsrss.exe"Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
USTOPzilla ServiceSZNTSVC.EXE"StopZilla! - pop-up killer"
XStubPathSservice.exe"Added by the PRORAT TROJAN!"
XSuperBar.Component[path to services.exe]"Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Inetsrv"
XSuperBar.Componentservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XSVC Servicesvcinit.exe"Added by the SINIT TROJAN!"
XSVC Servicesvcinit.exe"CoolWebSearch parasite variant"
XSVC Servicesvcpack.exe"CoolWebSearch Svcinit parasite variant"
XSVC Servicesvc32.pif"Added by the RBOT-ASC WORM!"
XSvchost Servicesvchost.exe"Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
XSvhost Service Serversvhostser.exe"Added by a variant of the RBOT WORM! See here"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
XSvshost Update Servicesvcbind.exe"Added by the MYTOB.LH WORM!"
XSVX Control Servicesvxhost.exe"Added by the FORBOT-K WORM!"
XSygate Personal Firewallservice.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewall Startservices32.exe"Added by the RBOT-MB WORM!"
USyGateServicesgserv95.exe"SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs"
XSymantec ServiceccApp.exe"Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename"
Xsysinitservices.exe"Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golumm"
XSysServiceSysService.exe"Added by the BDFORM-A BACKDOOR!"
USysServiceSERVICES.EXE"NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XSysService32SysService32.exe"Added by the KINDAL VIRUS!"
XSysService32ln32k.dll"Added by the KINDAL VIRUS!"
XSysService32lsystask32l.exe"Added by the THEUG WORM!"
XSysServicesSERVICES.EXE"Added by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystemservices.exe"Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
XSystem Backup Servicesbackups32.exe"Added by a variant of the RBOT WORM!"
XSystem Host Servicesvchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem ServiceMSREXE.EXE"Added by the AML TROJAN!"
Xsystem servicespoolcrv.cplAdded by the INSPIR.11 TROJAN!
XSystem Servicesystems.exe"Added by the AGOBOT.VZ WORM!"
XSystem Servicecoderxt.exe"Added by the RBOT-ALD WORM!"
XSystem Serviceexp0lrer.exe"Added by a variant of the RBOT WORM!"
XSystem Serviceservicent.exe"Added by the RBOT-AJI WORM!"
XSystem servicesystem.exe"Added by the BANCOS.AA TROJAN!"
XSystem Servicemsnwindows.exe"Added by the SPYBOT.YCL WORM!"
XSystem Serviceservicez.exe"Added by the RBOT-AOY WORM!"
XSystem Servicemsnxpexe.exe"Added by the RBOT-AUA WORM!"
XSystem Serviceteskmangr.exe"Added by the RBOT-AUV WORM!"
XSystem Servicebackup.exeAdded by the PACKBOT.AA WORM!
XSystem Serviceserious.exe"Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF)"
XSystem Serviceb4db0yz.exe"Added by the RBOT-CLO WORM!"
XSYSTEM service helpersvchelper.exe"Added by the MONKBD-A WORM!"
XSYSTEM service helpersyshelp.exe"Added by a variant of the MONKBD-A WORM!"
XSystem Service Managerlsmas.exe"Added by the AGOBOT-IK BACKDOOR!"
XSystem Service Managernorton.exe"Added by the GAOBOT.AJE WORM!"
XSystem Service Manager Devicesvho.exe"Added by the RBOT.GCG BACKDOOR!"
XSystem service**pokapoka**.exe"EliteBar adware - where ** represents the numbers 61 to 79"
XSystem service78[path to file]"Added by the ELITEBAR-T and ELITEBAR-U TROJANS!"
XSystem service79[path to file]"Added by the ELITEBAR-V TROJAN!"
XSystem Services[random file name]"Added by a variant of the RBOT WORM!"
XSystem Servicesconnection.exeAdded by an unidentified WORM or TROJAN!
XSystem Servicessvcsenes.exe"Added by a variant of the RBOT WORM!"
XSystem Servicessvcsenes32a.exe"Added by the RBOT-AFG WORM!"
XSystem Servicesssms.exe"Added by a variant of the RBOT WORM!"
XSystem Services Monitorserver.exe"Bifrost malware"
XSystem Tray Servicesspooles32.exe"Added by the AGOBOT.ZH WORM!"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystem Update Servicewinupd32.exe"Added by the ADTODA-A TROJAN!"
XSystem Update Servicesystem.pif"Added by the RBOT-ALL WORM!"
XSystem Update Serviceupdate.pif"Added by the SPYBOT.WOE WORM!"
XSystem Update Servicewmiprvsv.exe"Added by the AGOBOT.YG WORM!"
XSystem Update Servicecsrss32.exe"Added by the AGOBOT-HI WORM!"
XSystem Update2services.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XSystem Updater Servicewmiprvsw.exe"Added by the GAOBOT.AFC WORM!"
XSystem Updates Serviceupdates.pif"Added by the RBOT-AMA WORM!"
XSystem-ServiceEXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
XSystem32 Temp Servicesystmp.exe"Added by the RBOT-AET WORM!"
Xsystem32.exeservices32.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
XSystemCheckservices.exe"Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system"
XSystems Servicedrivex.exe"Added by a variant of the RBOT WORM!"
XSystemServicemsocfg.exePremium rate adult content dialler
XSystemServicenavchk.exePremium rate adult content dialler
XSystemServiceqservice.exePremium rate adult content dialler
XSystemServiceshman.exePremium rate adult content dialler
USystemServicensserver.exe"NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsystr2SERVICE.exe"Added by the VB-DQY WORM!"
XSystrayServicesMsxpw.exe"Added by the CITOR WORM!"
XSYS_CLEANService.exe"Added by the FLOPCOPY WORM!"
XTask Monitoring Servicesvchost.exe"Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
Xtask servicetaskservices.exe"Added by a variant of the RBOT WORM!"
XTask servicetaskmgs.exe"Added by a variant of the RBOT WORM!"
XTaskbar Servicetaskbar.svcUnidentified adware
XTCP Internet ServicesTCPSVC32.EXE"Added by the SPYBOT.X TROJAN!"
YTELUS Security servicefreedom.exe"Freedom Internet Security & Privacy - anti-virus
XTerminal Servicesmstscc.exe"Added by the SDBOT-CZW WORM!"
XText Tray Servicetstray.exe"Added by the SILLYFDC.BCC WORM!"
XTEXTCONVservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XThe Service Pack Loaderspxp.exe"Added by the RBOT-BYM WORM!"
XTimeServicetrun.exe"TlfLic-A premium rate adult content dialler"
XTorrent Management Servicesystem32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XTorrent Management ServiceTMANAGESVC.EX"Added by a variant of the IRCBOT TROJAN!"
Utpopservicetpopservice.exeDirecWay two-way satellite internet service enhanced POP proxy server for email
?TSServiceNSSERVICE.EXE"??"
Xtwunk servicetwunk16.exe"Added by the RBOT.BAT WORM!"
XUltimateServicesultsvcs.exe"Added by the AGENT-LGT TROJAN!"
XUniversal USB Servicesvchost32.exe"Added by the KELVIR.R WORM!"
XUp Serviceup32.pif"Added by the RBOT-ARI WORM!"
YUpdate ServiceUpdate.exe"Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
Xupdate servicesvxhost.exe"Added by the RBOT-MG WORM!"
XUpdate Servicewinu32.exe"Added by the RBOT-MG WORM!"
Xupdate servicewinx.exe"Added by a variant of the RBOT WORM!"
XUpdater Service Processsvhost32.exe"Added by the AGOBOT.TY WORM!"
XUpdater Service Processcsrss32.exe"Added by the AGOBOT-GP BACKDOOR!"
XUpdateServicewservice.exe"Added by the DREF-K WORM!"
XupDpacketoservices.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\TEMPER"
XUpdt Serviceupdt.pif"Added by the RBOT-AYU WORM!"
XUpgrade Servicesxchost.exe"Added by the TOFGER-I TROJAN!"
XUpgrade Servicewinupd.exe"Added by the TOFGER-U TROJAN!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
XUpTimes serviceWinUp.exe"Added by the RBOT-AKB WORM!"
XUSB Deviceservicelog.exe"Added by the WOOTBOT.CB WORM!"
XUSB Fix 1.1wuservices.exe"Added by a variant of the SDBOT WORM!"
XUSB Host Serviceusbsvc.exe"Added by the RBOT-GG WORM!"
XUSB Updatesmservices.exe"Added by a variant of the SDBOT WORM!"
Xusbdrvservicetask.exe"Added by a variant of the SDBOT WORM!"
XUser Hosting Serviceusnhost.exe"Added by the IRCBOT.SN WORM!"
XUser Input ServicesCTFMON32.EXE"Added by the MANCSYN.AK TROJAN!"
XUser Servicerusnsrvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Servicesusersvc.exe"Added by the REVCUSS.A TROJAN!"
XUser Servicesusrsvc.exe"Added by the IRCBOT.SN WORM!"
XUser Sharing Servicesusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
UVerizonServicepoint.exeVerizonServicepoint.exe"Part of Verizon Online Support Manager"
XVideo Servicesexplore.exe"Added by the GAOBOT.GL WORM!"
XVideo Servicesvideol_32.exe"Added by the AGOBOT-DM WORM!"
XVideo Servicessys32.exe"Added by the AGOBOT.PS WORM!"
UVPCUserServicesVMUSrvc.exe"Part of ""DOS Virtual Machine Additions"" for Microsoft Virtual PC
XWeb Service[random filename].exe"Added by the ADMINCASH TROJAN!"
XWeb Servicesm.exe"Added by the BUBE-F VIRUS!"
XWeb ServiceMSXMIDI.EXE"CoolWebSearch parasite variant
?Webcam Go Sti Service Applicationwbcgosvc.exe"Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required?"
Xwhxpin servicessvsol.exe"Added by a variant of the SDBOT WORM!"
XWiFix service[random filename]"Added by a variant of the SDBOT WORM!"
XWin Updator Servicesctfnom.exe"Added by a variant of the WOOTBOT WORM!"
XWin32 Help32 Servicewin32help.exe"Added by the DELBOT-U WORM!"
XWin32 Information Servicecrsrs.exe"Added by the RINBOT.Y WORM!"
XWin32 NT Adv Servicestaskmngr.exe"Added by the RBOT-ADE WORM!"
XWin32 Security Servicecrsss.exe"Added by the DELBOT-O WORM!"
XWin32 Servicebazzi.exe"Added by the AHKER.E WORM!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32 Servicesodbc32.exe"Added by the SPYBOT-EK WORM!"
XWin32 Serviceswuamngr.exe"Added by the SDBOT-N WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWin32 Services1wuamngr1.exe"Added by the SDBOT-PV WORM!"
XWin32 Src Servicewin32src.exe"Added by the RBOT-SX WORM!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
XWin32BaseServiceMODWintask.exe"Added by the NAVIDAD WORM!"
Xwin32servservicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
XWinCheckservices.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field"
XWinCheckservices.exe"Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
XWind Logd Fileservicelogd.exe"Added by a variant of the RBOT WORM!"
XWinDataservices.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the ""Startup Item"" field"
XWindeows NetStart Service2tesakrmger.exe"Added by the RBOT-AMY WORM!"
XWinDLL (service.exe)service.exe"Added by the AGENT.BX WORM! The ""service.exe"" file is found in %System%"
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindowsservices.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the ""Startup Item"" field"
XWindowsservices.exe"Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity"
XWindowsservices.exe"Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Windows"" subfolder"
XWindows Acer Serviceacersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
XWindows AdServiceWinAdServ.exeWindupdates adware variant
XWindows ASN Servicerge.exe"Added by the RBOT-AOK WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows ASN4 Servicesgamo.exe"Added by the RBOT-EHK WORM!"
XWindows Audio Servicesndmic32.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Servicesjvm.exe"Added by the ACKANTTA.F WORM!"
XWindows Authority Servicelsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XWindows Browser Servicesbrowser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser ServicesBrowsr32.exe"Added by the IRCBOT.BUR BACKDOOR!"
XWindows Browser Servicesbrowsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows Cleaner Servicewinclean.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Custom ServicesCSRCS.EXE"Added by the SPYBOT-EI WORM!"
XWindows Dialup Servicedialup.exe"Added by the AGOBOT.AAH WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows File Verification Servicewfvs.exeAdded by the RANKY.AC TROJAN!
XWindows FileSharing Servicemcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
XWindows Firewallipservice32.exe"Added by a variant of the RBOT WORM!"
XWindows Firewall Servicewfsvc.exe"Added by the IRCBOT-YL WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Help Servicewinhelpsv.exe"Added by the RBOT-LP WORM!"
XWindows Help Servicewinhlp.pif"Added by the RBOT-AKW WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicehost.exe"Added by the KELVIR.AN WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows HTTP serviceswinhttps.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Instruction Serviceswinstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
XWindows IP Security Serviceipsecs.exe"Added by the RBOT.BPW WORM!"
XWindows Kernel System Servicewkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows Keyboard Serviceswinkeyboard.exe"Added by the IRCBOT.AFS WORM!"
XWindows Keyboard Serviceswinkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Keyboard Serviceswinkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows Live Servicerusrserv.exe"Added by the SMALL.LU BACKDOOR!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
XWindows Local Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Login Servicewinlog.exe"Added by the RBOT-AFN WORM!"
XWindows Login Servicewinlogin.pif"Added by the SDBOT-ACU WORM!"
XWindows Logon Applicationservices.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Logon Servicewinlogon.pif"Added by the RBOT-AOU WORM!"
XWindows Logon Servicenapi32.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Logon Servicewinlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
XWindows Media Player Servicewmedia.exe"Added by the RBOT.213504 WORM!"
XWindows media servicecrvss.exe"Added by the SDBOT.VP WORM!"
XWindows media servicecrsss.exe"Added by the RBOT.ACY WORM!"
XWindows media serviceSygate32.exe"Added by the RBOT.ADE WORM!"
XWindows media servicescvrsss.exe"Added by the RBOT-MW WORM!"
XWindows Memory Running Servicesmemrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Messenger Servicekaspersky.exe"Added by the MYTOB.HY WORM!"
XWindows MeTaLRoCk servicemetalrock.exe"Added by the TASTYRED TROJAN!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows Monitor Serviceswinmonitor.exe"Added by the RBOT-XX WORM!"
XWindows Monitoring Servicewinmon.exe"Added by a variant of the SDBOT WORM!"
XWindows Mouse Serviceswinmouse.exe"Added by the IRCBOT.AGA BACKDOOR!"
XWindows Mouse Serviceswinmouse64.exe"Added by the IRCBOT.AIA BACKDOOR!"
XWindows Net Cfgservice.exe"Added by a variant of the RBOT WORM!"
XWindows NetStart ServicewinsN2S.exe"Added by the RBOT-ZX WORM!"
XWindows NetStart Service2winsN2S.exe"Added by the RBOT-ABN WORM!"
XWindows NetStart Service2winsN2SD.exe"Added by a variant of the RBOT WORM!"
XWindows Network Servicewinvc32.exe"Added by the RBOT.RY WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows Network ServiceRealteks.exe"Added by the RBOT-GTG WORM!"
XWindows Network Serviceswinnetwork.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork128.exe"Added by the SLENFBOT.J WORM!"
XWindows Network Serviceswinnetwork32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows NT Service Namewinshock.exe"Added by the RBOT-PK WORM!"
XWindows NT Service Namesvchcst.exe"Added by the RBOT-NV WORM!"
XWindows Reg Servicesffservice.exe"Added by the DLOADER-PL or DLOADER-XM TROJANS!"
XWindows Reg Servicesdservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesfservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesssservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Serviceslncom.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceslservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceswservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Servicesregserv.exe"Added by the SLENFBOT.BB WORM!"
XWindows Relay Serviceipcbind.exe"Added by the DELFINJECT.F TROJAN!"
XWindows Relay Serviceirfnga.exe"Added by the DROPPER.ACO TROJAN!"
XWindows Running DLL Servicerundll128.exe"Added by the IRCBOT.XDH BACKDOOR!"
XWindows Running DLL Servicerundll64.exe"Added by the SLENFBOT.HV WORM!"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Security Authority Servicelsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process
XWindows Security Service[random file name]"Added by the RBOT-ALV WORM!"
XWindows Security Servicearrdt.exe"Added by a variant of the RBOT WORM!"
XWindows Security Servicewindows.pif"Added by the RBOT-AMG WORM!"
XWindows Server Client Verification Servicewscvs.exe"Added by the AGENT.AWC TROJAN!"
XWindows Server IP Verification Servicewsivs.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Server Peer Verification Servicewspvs.exe"Added by a variant of the RANKY TROJAN!"
XWindows servicewuamgrd.exe"Added by the RBOT-QW WORM!"
XWindows Servicedddd.exe"Detected by Kaspersky as Dialer.Salc
XWindows Serviceprvdi.exe"Malware - detected by Kaspersky as the SMALL.RD TROJAN!"
XWindows Servicevideo.exeAdded by an unidentified TROJAN!
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Serviceprivate-zone.exeAdded by an unidentified WORM or TROJAN!
XWindows Servicepd7.exe"Added by the SMALL.VZ TROJAN!"
XWindows Servicedstart4.exeAdded by an unidentified TROJAN!
XWindows Servicepd14.exe"Adware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!"
XWindows Servicevideo2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
XWindows Serviceservices.exe"Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Servicer.exe"Added by a variant of the SMALL.VZ TROJAN!"
XWindows Servicewindowz.exe"Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows serviceiexpl0rer.exe"Added by the SDBOT.RO WORM!"
XWindows Serviceservice.exe"Added by the IRCBOT-ACV WORM!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows Service Agccntjeqcfyo.exe"Added by the RBOT-GST WORM!"
XWindows Service Agccnt[random].exe"Added by the SDBOT-DHL WORM!"
XWindows Service Agccntrmizjgz.exe"Added by the SDBOT-SIM WORM!"
XWindows Service Agentczf.exe"Added by the RBOT-GAJ WORM!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service Agentagl23.exe"Added by the RBOT-GQU WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
XWindows Service Agentmsnmagr.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Service Agenttaskmgr32.exe"Added by the RBOT-GMN WORM!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWindows Service Agentwinup32.exe"Added by the RBOT-GQX WORM!"
XWindows Service Agentwinupds32.exe"Added by the RBOT-GQT WORM!"
XWindows Service Agentwit.exe"Added by the RBOT-GQV WORM!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Agentspoolvs.exe"Added by the RBOT-GXI WORM!"
XWindows Service Agentspools.exe"Added by the AGENT-GJF TROJAN!"
XWindows Service Agentmsngear.exe"Added by the RBOT.AHW BACKDOOR!"
XWindows Service Agentmsngerr.exe"Added by the RBOT.EOZ WORM!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agentcxfrru.exe"Added by the SDBOT.GAV WORM!"
XWindows Service Agentizszbayz.exe"Added by the KOLAB.TC WORM!"
XWindows Service Agentjnxrcyc.exe"Added by the RBOT.XAT BACKDOOR!"
XWindows Service Agentkafdprs.exe"Added by the IRCBOT.HDE BACKDOOR!"
XWindows Service Agentkrqbs.exe"Added by the IRCBRUTE.AZ TROJAN!"
XWindows Service Agentlcaqmsp.exe"Added by the RBOT.WFR BACKDOOR!"
XWindows Service Agentmsnmsgr.exe"Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Service Agentmxjunj.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentndibbeu.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentnimcoo.exe"Added by the RBOT.EWV WORM!"
XWindows Service Agentnod32.exe"Added by the RBOT.BNG BACKDOOR!"
XWindows Service Agentsjbsm.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentsjbsmgm.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agenttjybssd.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentumvcnm.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentuqgpq.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentvbsxkhk.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agentwge23.exe"Added by the RBOT.HHK BACKDOOR!"
XWindows Service AgentWindo.exe"Added by the RBOT.NQS WORM!"
XWindows Service Agentywgma.exe"Added by the RBOT.DZT BACKDOOR!"
XWindows Service Agentwinupd32.exe"Added by the SDBOT.SYM WORM!"
XWindows Service AgentWinTcpip.exe"Added by the SPYBOT.AP WORM!"
XWindows Service Agentidvcqv.exe"Added by the AGOBOT-AJB WORM!"
XWindows Service Agent 32mrthd.exe"Added by the AGENT-GAQ TROJAN!"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service Ajavjava128.exe"Added by the RBOT.BNG WORM!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service DCuhpnjcjl.exe"Added by the RBOT-GLY WORM!"
XWindows Service ExecServiceLayer.exe"Added by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
XWindows Service Findwrfkuk.exe"Added by the IRCBOT-XZ TROJAN!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Service HostingUSERINIT.exe"Added by the GOMMER-A WORM!"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows Service LoaderWindow.exe"Added by the RBOT-XO WORM!"
XWindows Service Managementsvcmngmt.exe"Added by the AGOBOT-NM WORM!"
XWindows Service Manageruserint32.exe"Added by the OSCABOT-C WORM!"
XWindows Service Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managermsgs.exe"Added by the OSCABOT-E WORM!"
XWindows Service Managermsnmrg.exe"Added by the OSCABOT-G WORM!"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcmgr32.exe"Added by the OSCABOT-D WORM!"
XWindows Service Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertaskmgr.exe"Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""fonts\svc"" sub-folder"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows Service Pack 2WindowsSP2.exe"Added by the SDBOT-TQ WORM!"
XWindows Service Pack Auto Updatewinworks.exe"Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updatefiggaz.exe"Detected by Kaspersky as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updateballin.exeAdded by an unidentified WORM or TROJAN!
XWindows Service Pack Auto Updatedel-me.exe"Adware
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Service Pack2WIN43.EXE"Added by the GAOBOT.G WORM!"
XWindows Service Supplywinsupply.exe"Added by the SLENFBOT.CZ WORM!"
XWindows Service Support CallSVSS32.EXE"Added by the RBOT-XQ WORM!"
XWindows Service SVsv32.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Threadssvcthreading.exe"Added by the SHEUR.AUM TROJAN!"
XWindows Service Threadssvcthreads.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service Updatelivecal.exe"Added by the SDBOT-DEY WORM!"
XWindows Service Updatecrsss.exe"Added by the SDBOT.CWX WORM!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWindows Service Utititywinsrvc.exe"Added by the RBOT-ASI WORM!"
XWindows Service XPXpFirewall.exe"Added by the MYTOB.AM WORM!"
XWindows Servicerxqobypik.exe"Added by the SDBOT-DFB WORM!"
XWindows Servicesservice.exe"Added by the RANDEX.R WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Servicesavsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesservicez.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32edus.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32service.exe"Added by the AUTORUN-FU WORM!"
XWindows Servicesw32services.exe"Added by the AUTORUN-FT WORM!"
XWindows Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinudp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Servicesservices.exe"Added by the AGENT-MVC TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Agantregs32.exe"Added by the SDBOT-DIK WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services Agentmsngears.exe"Added by the VB-EMS TROJAN!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows Services Certificationsvccert.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows Services Guidesvcguides.exe"Added by the SHEUR.YS BACKDOOR!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Services Ink Platform Tablet Input Subsystemwsiptis.exe"Added by the RBOT.APC WORM!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Jogersvcjoger.exe"Added by the RBOT.CAT WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Layerwinlogz2.exe"Added by the RBOT-FZE WORM!"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows Services M7ctfmon32.exe"Added by the AGENT.WOH TROJAN!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWindows SpoolaPrint Servicespoolasrv.exe"Added by the SDBOT-AYD WORM!"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Spooler Servicesspool.exe"Added by the AGOBOT-AMO WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows spoolservr Servicespoolservr.exe"Added by the SDBOT-AAN WORM!"
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
Xwindows spoolsrv servicespoolssv.exe"Added by the SDBOT-AWV WORM!"
XWindows Spoolsurf Servicespoolsurf.exe"Added by the SDBOT-ZZ WORM!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Spoolvvv Servicespoolvvv.exe"Added by the SDBOT-AAW WORM!"
XWindows Sql Service For Windows 32 Bitwinsql32.exe"Added by the FORBOT-FC WORM!"
XWindows Startupservices21.exe"Added by the AGOBOT-MX WORM!"
XWindows svchostservice.exe"Added by the PUSHBOT.DU WORM!"
XWindows svchostserviceaaa.exe"Added by the PUSHBOT.ER WORM!"
XWindows svchostservicean.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows svchostserviceam.exe"Added by the PUSHBOT.EY WORM!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWindows System 32-Bat Servicewin32bat.exe"Added by the MYTOB.FI WORM!"
Xwindows system servicewinsock.exe"Added by the RBOT-MR WORM!"
XWindows System Servicewnuserv.exe"Added by the SPYBOT.ANDM WORM!"
XWindows System Service[worm filename]"Added by the RBOT.XG WORM!"
XWindows Task Service (32-bits)tasksys.exe"Added by the DREFIR.D WORM!"
XWindows Taskmanagerservice.exe"Added by the PUSHBOT.OR WORM!"
XWindows TaskManager Servicewindns32.exe"Added by the AGOBOT-JP WORM!"
XWindows Temperate Serviceswintmp.exe"Added by the SLENFBOT.ZW WORM!"
XWindows Timetmservice.exe"Added by a variant of the RBOT-YK WORM!"
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Update Client Servicewindrvl32.exe"Added by the AGOBOT-MM TROJAN!"
XWindows Update Monitoring Servicewinupdt.exe"Added by the RBOT-PL WORM!"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Serviceupdate32.pif"Added by the RBOT-ALC WORM!"
XWindows Update Servicetrest.exeIdentified by BitDefender as a variant of the PEED TROJAN!
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Updater Service Managerwinupdatr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Updating Serviceupdating.pif"Added by the RBOT-ALW WORM!"
XWindows USB 2.0 Driverusbservice.exe"Added by the RBOT-BLF WORM!"
XWindows USB Service666.exe"Added by the MYTOB.AR WORM!"
XWindows Version Servicesysvers.exe"Added by the SLENFBOT.IF WORM!"
XWindows Version Servicesysvers32.exe"Added by the SLENFBOT.HZ WORM!"
XWindows Virtual Serviceswinvirtual.exe"Added by the SLENFBOT.IE WORM!"
XWindows Virtual Serviceswinvirtual32.exe"Added by the SLENFBOT.IB WORM!"
XWindows Vista Corparation Agent Serviceswinxp_sp3.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Web Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Winhlp32 Stub Servicewinhlp32.pif"Added by the AIMBOT.AH TROJAN!"
XWindows WKS Serviceswkssvr1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindows Workstation Servicewkssvc.exe"Added by the IRCBOT-AAI WORM!"
XWindows Workstation Service (32-bits)wkssvc32.exe"Added by a variant of the SDBOT WORM!"
XWindows Workstation Service [5.1-2600]windrm.exe"Added by the RBOT-CNY WORM!"
XWindows Workstation Start Servicemslanmgr.exe"Added by a variant of the RBOT WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows-XP-Service-Packxpspz.exe"Added by the SDBOT-AAC WORM!"
XWindows32 Messenger Servicemsmsgv.exe"Added by the RBOT.ANS WORM!"
XWindowsNT CWServicesCWServices.com"Detected by Bitdefender as the AGENT.AGDK TROJAN! See here"
XWindowsNT ServicesServices.com"Detected by Bitdefender as the DELF.OFC TROJAN! See here"
XWindowss Service Agentmssngear.exe"Added by the RBOT.KGU BACKDOOR!"
XWindowsService[random name].dll"Added by the VUNDO-X TROJAN!"
XWindowsServicesHservicedhs.exe"Added by the AGOBOT-JD WORM!"
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWindowsUpdate Servicewuautlc.exe"Added by the RBOT-NR WORM!"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWindows_SerivceSERVICE.exe"Added by the WOOTBOT.AH WORM!"
XWinFix servicersswjzgp.exe"Added by the RBOT-FAE WORM!"
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
Xwinlogon serviceurx.exe"Added by the SPYBOT.EN WORM!"
XWinLsassservicec.exe"Added by the SCANE WORM!"
XWinRaR ServiceWinrarCO.comAdded by an unidentified WORM/TROJAN!
XWinReg32 serviceholqdnoxpmeu.exe"Added by a variant of the SDBOT WORM!"
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
XWins Update 32services32.exe"Added by the FORBOT-FN WORM!"
XWinservicewinmain.exeAdult content related malware
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
XWinServicehosth.exe"Added by the DWNLDR-FUX TROJAN!"
XWinServiceTtt.exe"Added by the MSNVB-D WORM!"
XWinServiceWinServ.exe"Added by the SKOWOR-O WORM!"
UWinService32ssmgr.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
XWinServicesWinServices.exe"Added by the YAHA.K or YAHA.M WORMS!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
XWinsock6 MIC driverieservicesupd.exe"Added by the SPYBOT.AFZ WORM!"
Xwinsrv3services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field"
XWinupdate Servicewinxp.exe"Added by the SPYBOT.IR WORM!"
XWinux Piriax ServicePH32.EXE"Added by the RANDEX.G WORM!"
XWinXPServicelsass.exe"Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
XWinXPServicetaksmgr.exeIdentified as a variant of the IRC/Flood.tool malware
XWinXPServiceTskdbg.exe"Added by the MDROP-BPQ TROJAN!"
XWinXPServicectfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""ctf"" sub-folder"
XWinXPServicemirc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWinXPServicenero.exe"Added by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in the root directory
XWinXPServicewacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %Windir%\Fonts"
XWinXPServicewacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%\mnut"
XWinZix Servicewakeservice.exe"WinZix adware"
XWMAudioservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XWMDM PMSP Servicecssrss.exe"Added by the KNOCKIT-A TROJAN!"
XWMI Performance Adapter Serviceswmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
XWMI Service Clientwmispv.exe"Added by the AUTORUN-ASX WORM!"
XWMSDOS-ServicePack2cmd.exe /c C:WMSDOS.sys"Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted"
XWN Serviceswnsvc.exe"Added by the KBBOT-A TROJAN!"
XWorkstation Serviceswrkstn.exe"Added by the RBOT-OJ WORM!"
XWPSVC Serviceswpnsc.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWsdata serviceWSconf.exe"Added by the SDBOT.ZU WORM!"
UWServiceWService.exe"Tablet client Driver for UC-Logic Pen/Graphics Tablet"
UWSVCSSERVICES.EXE"WSLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
YWUOLServiceWUOLService9x.exe"Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)"
UWZCBDLServiceWZCBDL9X.exeWZCBDLService Launcher from D-Link - configuration/drivers
Xwzservicehess.exeAdded by the HACKARMY.W TROJAN!
UX10 Device Network Servicex10nets.exeBelongs to X10 video streaming device(s)
XXML Servicemsxml.exe"Added by the RBOT-HD WORM!"
XXP Service Packxpservicepack.exe"Added by the SDBOT.AQA WORM!"
Xxp service pack 2xpsp2.exe"Added by the RBOT-KW WORM!"
XXpsystemSERVICES.EXE"Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\SERVICES"
Xxpsystemservices.exe"CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process
Xxp_systemservices.exe"Added by the KREPPER-N TROJAN and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The one is located in a %Windir%\inet***** - where ***** varies dependent upon the variant
XXTN Service Driverswinxtn.exe"Added by the SDBOT-YK WORM!"
XXTServiceUpdateXTServiceUpdate.exehahame.net adware downloader
YZENworks Imaging ServiceZISWin.exe"Imaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management""
XzSecurity Serviceszsvc.exe"Added by the SDBOT-DAB WORM!"
Xzsmsgsiservice.exe"Added by the BANCOS-BU TROJAN!"
X[random name]services.exe"PurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X[various names]Serviceprocess.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_ntrRescueService_ntrrs.exe"Added by the DLOADER-JV TROJAN!"
X_Services.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system"
X_SystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
X_WinCheckservices.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
X_WinDataservices.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData"
X_Windowsservices.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %windir%\WinSecurity"
X_WinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus"
X_WinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.