Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
NConfigServicesConfig.exePart of initial setup on a Compaq PC
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
XDumeter Servicesdumeter.exe"Added by the SDBOT-AEQ WORM!"
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvhst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGolumservices.exe"Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process
Xgolummservices.exe"Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
XHOI Servicesholsvc32.exe"Added by the AGOBOT-SF WORM!"
XHPl Serviceshmlsvc32.exe"Added by the AGOBOT-SI WORM and variants!"
XHQI Serviceshqisvc32.exe"Added by the AGOBOT-RO WORM!"
XHQI Serviceshqlsvc32.exe"Added by the AGOBOT-RP WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XKernelservices.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernel Servicesservice32.exe"Added by the PRX-B TROJAN!"
XLiveUpdate32services.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XLocal Serviceservices.exe"Added by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Cursors"
Xlsa Serviceslsa2srv.exe"Added by the TAME-C WORM!"
UMcAfee Managed Services TrayStartMyagtTry.exeSystem tray notification for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Not required to be protected but you lose notifications
XMedia Services[filename].exe"Added by the AGENT-BA BACKDOOR!"
XMedia X ServicesMSNGRx.exe"Added by the RBOT.AUL WORM!"
XMemory Allocation Servicescisrv.exe"Added by the IRCBOT.FC BACKDOOR!"
XMicrcsoft Certificate Servicescflmon.exe"Added by the RBOT-FWV WORM!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft Browser ServicesBrwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Browser ServicesBrwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft media servicesIassd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN 7 Servicesmsnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Security Centersavservices.exe"Added by the RBOT-ANU WORM!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Serviceslsserv.exe"Added by an unidentified VIRUS
XMicrosoft Serviceslssrv.exe"Added by the RBOT.CW WORM!"
XMicrosoft Servicesservices.exe"Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Serviceslsrv.exe"Added by the RBOT-BK WORM!"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicesbsc32.exe"Added by the BDOOR-AW BACKDOOR!"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicesmodule.exe"Added by the LAVITS WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Services UnitdMSU32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Visual SourceSafeservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMP Servicesmpsvc.exe"Added by the WOOTBOT.EQ WORM!"
XMPtask Servicesmptask.exe"Added by the LALA or AOT TROJANS!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
Xmservices.exemservices.exe"Added by the SDBOT.WJ WORM!"
XMSNservices51651.exe"Added by the IRCBOT-AAL TROJAN!"
XMSN Messenger Servicesmsnmgr.exe"Added by the RBOT.ADF TROJAN!"
XMSN Messenger Servicesmsnmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMSN User Server!msnservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicesmsnuserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSOfficeservices.exe"Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
Xnetservicesrecall.exe"Added by the WOOTBOT.D WORM!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNETServicescsxrs.exe"Added by a variant of the SDBOT WORM!"
XNetwork Servicesnetsvacs.exe"Added by the GAOBOT.AIS WORM!"
XNorton Auto-ProtectSERVICES.exe"Added by the AHKER.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Also
Xnsdcmd servicesnsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNT Printing Serviceschkdsks.exe"Added by the BUZUS-M TROJAN!"
XNT Servicesntsvc.exe"Added by the AGOBOT.VJ WORM!"
XNTSet32services.exe"Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32"
UOctoshape Streaming ServicesOctoshapeClient.exe"Octoshape Live Streaming - ""is a revolutionary technology that will reduce your bandwidth cost and improve the quality in sound and picture"""
NOdebit Multimedia V3 - ServicesOdebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
XOnline Servicestwain.exe"Added by the AGENT.BEA TROJAN!"
XOutlook Mail Servicesexpress.exe"Added by the RBOT.CJN WORM!"
XOutlook Mail Servicesoutlook.exe"Added by the RBOT-BKA TROJAN! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %System%"
XPK Servicespksvc.exe"Added by the FORBOT-BW WORM!"
XPNtask Servicespntask.exe"Added by the LALA.C TROJAN!"
XPrint Servicesspolserv32.exe"Added by the RBOT.ZP WORM!"
XPrinter Servicesspool.exe"Added by the RBOT-Y WORM!"
Xqservicesqservice.exe"Added by the PROGENT-A TROJAN!"
YRaptor Mobilevpnservices.exe"Symantec VPN Client used to connect to corporate networks. If unchecked
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
XRegDoneservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XRegistry ServicesRegistry.exe"Added by the CILE TROJAN!"
Xregservices.exeregservices.exe"Added by an unidentified VIRUS
XRemote Services Managermsrmsvc.exe"Added by the SLENFBOT.AJ WORM!"
XRPCser32gservices.exe"Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g1services.exe"Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g3services.exe"Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g4services.exe"Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32services.exe"Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gservices.exe"Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrunservices.exe"Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066"
XRun Services as Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunservicesservices.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xscssrr.exeServices.exe"Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServiceservices.exe -serv"Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServiceSERVICES.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XServiceAdministratorSERVICES.EXE"Added by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XServiceeservices.exe"Added by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServicerepclient1SERVICES.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xservicesstart.bat"Added by the ZCREW TROJAN!"
XServices[path to trojan]"Added by the METEORSHELL TROJAN!"
XServicesback32.exe ...service.exe"Added by an unidentified VIRUS
XServicesservices.exe"Added by a number of VIRUSES
XServiceswinread.exe"Added by an unidentified VIRUS
XServiceswindns.exe"Added by a variant of the RBOT WORM!"
XServicesmshost.exe"Added by the LANFILT-J TROJAN!"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
XServicescsrss.exe"Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XServicesscks32.exe"Added by a Proxy Trojan variant"
XServicessockys32.exeAdded by the RANKY.L TROJAN!
XServicessys.exe"Added by a Proxy Trojan variant"
Xserviceswindows32.exe"Added by the FLYVB-C WORM!"
Xservicessocks.exeAdded by the WIN32.SMALL.N TROJAN!
XServicesservices.exe"Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices[path to trojan]"Added by the RANCK-DB TROJAN!"
XServicesiexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XServicessvchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServicessysamp.exe"Added by a variant of the SDBOT WORM!"
XServicesprosys32.exeAdded by an unidentified WORM or TROJAN!
XServicesiexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XServicesiexploler.exe"Added by the RANCK-LT TROJAN!"
XServicesiexpolere.exe"Added by the RANCK.LU TROJAN!"
Xservicessample.exe"Added by a variant of the RANKY TROJAN!"
XServicescsrss32.exe"Added by the ANACON-D VIRUS!"
XServices Administratorlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratornetsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcman.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratortcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Controllerlsassa.exeAdded by the CIADOOR.122 VIRUS!
XServices Controllerservices.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices DLL Loadersrvdll.exe"Added by the SLENFBOT.ZS WORM!"
XServices HostScchost.exe"Added by the DONK WORM!"
XServices Hostsvchost32.exe"Added by the AGOBOT-TG WORM!"
XServices hostsvchost.com"Added by the RBOT-EU WORM!"
XServices Logonservices.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates"
XServices Management Clientsservc.exe"Added by the RIZO.A TROJAN!"
XServices Managementsservcs.exe"Added by the RBOT-GUC WORM!"
XServices Managersvsmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XServices Manager!svmanager.exe"Added by the IRCBOT.ATZ BACKDOOR!"
XServices Managerssvcmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XServices NetworkServices.exe"Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XServices Processservices.exe"Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices Start2odcwinst.exe"Added by the PYSKE-D WORM!"
XServices Startupservices.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XServices Startupsvhost33.exe"Added by a variant of the RBOT WORM!"
XServices++services.exe"Added by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLER"
XServices.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
XServices.EXEservices.exe"Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xservices.exeservicess.exe"Added by the MSNSPY-B TROJAN!"
XServices004[worm filename]"Added by the BUGBROS WORM!"
Xservices32mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
Xservices32mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
Xservices32mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
XServices32 Startupwin32dll.exe"Added by the SDBOT-XO WORM!"
XServicesActivecssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
XServicesAdministratorSERVICES.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process
XServicesaraservices.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XServicesLoadlsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServicesLogccapp32.exe"Added by the RBOT-AMX WORM!"
UServicesNotifyServicesNotify.exe"Defender Pro Antispy"
Xservicestub.exeservicestub.exe"Added by the RBOT.CN BACKDOOR!"
XSistem Servicessyspool.exe"Added by the AGOBOT-GF WORM!"
YSmcServicessmc.exeSygate Firewall
YSmcServicesspfsmc.exeSygate Firewall
XSound servicesSOUND32.EXE"Added by the AGOBOT.GG WORM!"
XSpooler de Impressservices.exe"Added by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User%"
Xsqserviceswins32.exe"Added by the PROGENT-B TROJAN!"
XSuperBar.Component[path to services.exe]"Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Inetsrv"
XSuperBar.Componentservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
XSygate Personal Firewall Startservices32.exe"Added by the RBOT-MB WORM!"
Xsysinitservices.exe"Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golumm"
USysServiceSERVICES.EXE"NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XSysServicesSERVICES.EXE"Added by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystemservices.exe"Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
XSystem Backup Servicesbackups32.exe"Added by a variant of the RBOT WORM!"
XSystem Services[random file name]"Added by a variant of the RBOT WORM!"
XSystem Servicesconnection.exeAdded by an unidentified WORM or TROJAN!
XSystem Servicessvcsenes.exe"Added by a variant of the RBOT WORM!"
XSystem Servicessvcsenes32a.exe"Added by the RBOT-AFG WORM!"
XSystem Servicesssms.exe"Added by a variant of the RBOT WORM!"
XSystem Services Monitorserver.exe"Bifrost malware"
XSystem Tray Servicesspooles32.exe"Added by the AGOBOT.ZH WORM!"
XSystem Update2services.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xsystem32.exeservices32.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
XSystemCheckservices.exe"Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system"
XSystrayServicesMsxpw.exe"Added by the CITOR WORM!"
Xtask servicetaskservices.exe"Added by a variant of the RBOT WORM!"
XTCP Internet ServicesTCPSVC32.EXE"Added by the SPYBOT.X TROJAN!"
XTerminal Servicesmstscc.exe"Added by the SDBOT-CZW WORM!"
XTEXTCONVservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XUltimateServicesultsvcs.exe"Added by the AGENT-LGT TROJAN!"
XupDpacketoservices.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\TEMPER"
XUSB Fix 1.1wuservices.exe"Added by a variant of the SDBOT WORM!"
XUSB Updatesmservices.exe"Added by a variant of the SDBOT WORM!"
XUser Input ServicesCTFMON32.EXE"Added by the MANCSYN.AK TROJAN!"
XUser Servicesusersvc.exe"Added by the REVCUSS.A TROJAN!"
XUser Servicesusrsvc.exe"Added by the IRCBOT.SN WORM!"
XUser Sharing Servicesusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XVideo Servicesexplore.exe"Added by the GAOBOT.GL WORM!"
XVideo Servicesvideol_32.exe"Added by the AGOBOT-DM WORM!"
XVideo Servicessys32.exe"Added by the AGOBOT.PS WORM!"
UVPCUserServicesVMUSrvc.exe"Part of ""DOS Virtual Machine Additions"" for Microsoft Virtual PC
XWin Updator Servicesctfnom.exe"Added by a variant of the WOOTBOT WORM!"
XWin32 NT Adv Servicestaskmngr.exe"Added by the RBOT-ADE WORM!"
XWin32 Servicesodbc32.exe"Added by the SPYBOT-EK WORM!"
XWin32 Serviceswuamngr.exe"Added by the SDBOT-N WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWin32 Services1wuamngr1.exe"Added by the SDBOT-PV WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
Xwin32servservicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
XWinCheckservices.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field"
XWinCheckservices.exe"Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
XWinDataservices.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the ""Startup Item"" field"
XWindowsservices.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the ""Startup Item"" field"
XWindowsservices.exe"Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity"
XWindowsservices.exe"Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Windows"" subfolder"
XWindows ASN4 Servicesgamo.exe"Added by the RBOT-EHK WORM!"
XWindows Audio Servicesjvm.exe"Added by the ACKANTTA.F WORM!"
XWindows Browser Servicesbrowser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser ServicesBrowsr32.exe"Added by the IRCBOT.BUR BACKDOOR!"
XWindows Browser Servicesbrowsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Custom ServicesCSRCS.EXE"Added by the SPYBOT-EI WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows HTTP serviceswinhttps.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Instruction Serviceswinstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Keyboard Serviceswinkeyboard.exe"Added by the IRCBOT.AFS WORM!"
XWindows Keyboard Serviceswinkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Keyboard Serviceswinkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows Local Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Logon Applicationservices.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows media servicescvrsss.exe"Added by the RBOT-MW WORM!"
XWindows Memory Running Servicesmemrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows Monitor Serviceswinmonitor.exe"Added by the RBOT-XX WORM!"
XWindows Mouse Serviceswinmouse.exe"Added by the IRCBOT.AGA BACKDOOR!"
XWindows Mouse Serviceswinmouse64.exe"Added by the IRCBOT.AIA BACKDOOR!"
XWindows Network Serviceswinnetwork.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork128.exe"Added by the SLENFBOT.J WORM!"
XWindows Network Serviceswinnetwork32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Reg Servicesffservice.exe"Added by the DLOADER-PL or DLOADER-XM TROJANS!"
XWindows Reg Servicesdservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesfservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesssservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Serviceslncom.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceslservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceswservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Servicesregserv.exe"Added by the SLENFBOT.BB WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Serviceservices.exe"Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows Servicesservice.exe"Added by the RANDEX.R WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Servicesavsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesservicez.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32edus.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32service.exe"Added by the AUTORUN-FU WORM!"
XWindows Servicesw32services.exe"Added by the AUTORUN-FT WORM!"
XWindows Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinudp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Servicesservices.exe"Added by the AGENT-MVC TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Agantregs32.exe"Added by the SDBOT-DIK WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services Agentmsngears.exe"Added by the VB-EMS TROJAN!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows Services Certificationsvccert.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows Services Guidesvcguides.exe"Added by the SHEUR.YS BACKDOOR!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Services Ink Platform Tablet Input Subsystemwsiptis.exe"Added by the RBOT.APC WORM!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Jogersvcjoger.exe"Added by the RBOT.CAT WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Layerwinlogz2.exe"Added by the RBOT-FZE WORM!"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows Services M7ctfmon32.exe"Added by the AGENT.WOH TROJAN!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWindows Spooler Servicesspool.exe"Added by the AGOBOT-AMO WORM!"
XWindows Startupservices21.exe"Added by the AGOBOT-MX WORM!"
XWindows Temperate Serviceswintmp.exe"Added by the SLENFBOT.ZW WORM!"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Virtual Serviceswinvirtual.exe"Added by the SLENFBOT.IE WORM!"
XWindows Virtual Serviceswinvirtual32.exe"Added by the SLENFBOT.IB WORM!"
XWindows Vista Corparation Agent Serviceswinxp_sp3.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Web Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows WKS Serviceswkssvr1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindowsNT CWServicesCWServices.com"Detected by Bitdefender as the AGENT.AGDK TROJAN! See here"
XWindowsNT ServicesServices.com"Detected by Bitdefender as the DELF.OFC TROJAN! See here"
XWindowsServicesHservicedhs.exe"Added by the AGOBOT-JD WORM!"
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
XWins Update 32services32.exe"Added by the FORBOT-FN WORM!"
XWinServicesWinServices.exe"Added by the YAHA.K or YAHA.M WORMS!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
XWinsock6 MIC driverieservicesupd.exe"Added by the SPYBOT.AFZ WORM!"
Xwinsrv3services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field"
XWMAudioservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XWMI Performance Adapter Serviceswmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
XWN Serviceswnsvc.exe"Added by the KBBOT-A TROJAN!"
XWorkstation Serviceswrkstn.exe"Added by the RBOT-OJ WORM!"
XWPSVC Serviceswpnsc.exe"Added by a variant of the IRCBOT BACKDOOR!"
UWSVCSSERVICES.EXE"WSLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XXpsystemSERVICES.EXE"Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\SERVICES"
Xxpsystemservices.exe"CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process
Xxp_systemservices.exe"Added by the KREPPER-N TROJAN and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The one is located in a %Windir%\inet***** - where ***** varies dependent upon the variant
X[random name]services.exe"PurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X_Services.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system"
X_SystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
X_WinCheckservices.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
X_WinDataservices.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData"
X_Windowsservices.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %windir%\WinSecurity"
X_WinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus"
X_WinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.