Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
Xasussvcasussvc.exe"Added by the AGENT-FPB TROJAN!"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
Xbabsvchst32.exe"Added by the AGENT.Q TROJAN!"
XBackup Servicebackup.svcUnidentified adware
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
UCadenzaCdzSvc.exe"Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
YCcPxySvcCCPXYSVC.exe"Part of Norton's AntiVirus 2003
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccSvcHst.execcSvcHst.exe"Added by the SDBOT-DIW WORM!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XCPQHotKeyshotkeysvc.exe"Added by the RBOT-XA WORM!"
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UDCfssvcdcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
Udcfssvedcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
XDirectX9svchost32.exe"Added by the RBOT.AQG WORM!"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDll Linksvchoist.exe"Added by the AUTOSKY WORM!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDLLService32dllsvc32.exe"Added by the AGOBOT.VX WORM!"
XDmsvc32Dmsvc32.exe"Added by the AGOBOT.ABU WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDvxwsxsvc.exe"Delfin Media Viewer or ""Promulgate"" adware variant"
Xerthgdrsvc.exe"Added by the BEAGLE.BN or BEAGLE.BP WORM!"
Xerthgdr2svc23.exe"Added by the BAGLE.CG WORM!"
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UFamilyKeyLoggercisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
XFast Homesvcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines
XFast Searchsvcnv.exe"Homepage
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
?FLSVCIFLSVCI.exe"??"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XFSHsvcnva.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
Xfstsvc"rundll32.exe fstsvc.dllstart"
Xgammasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGmsvc32gmsvc32.exe"Added by the AGOBOT.ABN WORM!"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
UGoToMyPCg2svc.exe"ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XHMI PowerSystemhmisvc32.exe"Added by the RANDEX.CZZ WORM!"
XHML PowerSourcehmlsvc32.exe"Added by the SDBOT-XL WORM!"
XHMV PowerSourcehmusvc32.exe"Added by the SDBOT-YW WORM!"
XHOI Servicesholsvc32.exe"Added by the AGOBOT-SF WORM!"
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHostSVC syseHostSVC.exe"Added by the RBOT-ANZ WORM!"
XHPl Serviceshmlsvc32.exe"Added by the AGOBOT-SI WORM and variants!"
XHQI Serviceshqisvc32.exe"Added by the AGOBOT-RO WORM!"
XHQI Serviceshqlsvc32.exe"Added by the AGOBOT-RP WORM!"
XHrn_qtvhrnsvc32.exe"Added by the SDBOT-AET WORM!"
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
UIbmpmsvcibmpmsvc.exe"Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn
Xigfxtrassvchots.exe"Added by the AUTORUN-AIW WORM!"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
YISSVCISSVC.exePart of Norton Internet Security Suite
XIST Serviceistsvc.exe"ISTBar adware"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
Xjiahussvchqs.exe"Added by the WOWPWS-AL TROJAN!"
XJvcHostjvcsvc32.exe"Added by the AGOBOT-AIU WORM!"
XkaaSVCHHS.exe"Added by the AGENT-JKP TROJAN!"
XKAVPersonalsvchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Ykavsvckavsvc.exe"Kaspersky antivirus"
XKavSvc******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
Xkavsvc[random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
XKernel32svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers"
YKPFWSvc.EXEKPFWSvc.EXE"KingSoft Personal Firewall"
XKYK Control SettingsKYSVCXD.EXE"Added by a variant of the RBOT WORM!"
Xloadsvchsot.exe"Added by the GWGHOST-O TROJAN!"
NLoadMSvcmmmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XLocalSystemsvchost.exe"EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XLogical Disk Detectionmrisvc.exe"Added by the IRCBOT.AOW BACKDOOR!"
XLTM2SVCHOST32.exe"Added by the LITMUS.203B TROJAN!"
XLTM2SVCHOSTÿ.exe"Added by the DROPPERFL.A TROJAN!"
Xltssvc"rundll32.exe ltssvc.dllstart"
XMainStartsvcmfte32.exe"Added by the STINX-A TROJAN!"
XMapiDrvmpisvc.exe"Added by the MIPSIV TROJAN!"
Xmapisvc32mapisvc32.exe"Added by the KX VIRUS and also recognised by Symantec as FPAI adware"
XMastersvcghost.exe"Added by the IRCBOT.RB TROJAN!"
YMcAfee Managed Desktop AgentMYAGTSVC.EXE"Part of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
UMedia Manager IndexerAIRSVCU.EXE"Part of MS Visual InterDev
XMessenger Sharing Controlmnwsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicrcoft Exploerersvchose.exe"Added by the RBOT-ASL WORM!"
Xmicrosoftsvchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoftsvchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft Agentsvch0st.exe"Added by the VB-DRO WORM!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft DLL Host Servicesvcdllhst.exe"Added by the AGENT.EAK TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft DLL Servicesvcdll.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Helpsvchosl.exe"Added by the AGENT-GPX TROJAN!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft IT Updatesvchsst.exe"Added by the RBOT-DH WORM!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Netviewmssvc32.exe"Added by an unidentified VIRUS
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Officemsvcp.exe"Added by the AGENT-XK TROJAN!"
XMicrosoft Outlook Express Protocolsvchst.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Registrosvchostt.exe"Added by the BANCOS-DH TROJAN!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Service 32mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Spool Svcspoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xmicrosoft supportsvchostt.exe"Added by the AGOBOT.AWN WORM!"
XMicrosoft SVCmssvc.exe"Added by the BIFROSE-UQ TROJAN!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesnlogsvc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Updating Clientwebsvc.exe"Added by the RBOT.AQ WORM!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
UMicrosoft Webserversvctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosongsvchosts11.exe"Added by the SDBOT-EV WORM!"
XMicroszoft Update Mach1nezssvchst.exe"Added by the RBOT-ED WORM!"
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMircrosoft Svchost32svchost32.exe"Added by the RBOT-AZW WORM!"
XMmgsvcmmgsvc.exeMmgsvc spyware
Xmnsvcmnsvc.exe"Added by the AUTOUPDER TROJAN!"
Xmnsvcspmnsvcsp.exe"Added by an unidentified VIRUS
XModemlocatesvc.exe"Added by a variant of the SPYBOT WORM!"
XMonitoring Servicesvchost.exe"Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
NMovielink Manager Uninstallmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XMP Servicesmpsvc.exe"Added by the WOOTBOT.EQ WORM!"
Xmptsgsvc.exemptsgsvc.exe"Hacker Tool - detected by DiamondCS TDS-3 anti-trojan as ""HackTool.Win32.Hidd.j"""
XMQT Svcmqtsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xmrsvctrmrsvctr.exe"Added by a variant of the SDBOT WORM!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
Xmscsvc.exemscsvc.exe"Added by the BANCOS.T TROJAN!"
Xmsetsvchost.exe"Added by the BIZEX-F TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""mset"" sub-directory"
XMsgsvc32[worm filename]"Added by the NAUTICAL-A WORM!"
XMsgSvcMgr32cmdzxdll.exe"Added by the RBOT-AEK WORM!"
XMSMsgSvcMSMSGSVC.exe"Browser hijacker
Xmsnmsnsvc.exe"Added by a variant of the SDBOT WORM!"
XMSNsvchost.exe"Added by the PUSHBOT.FA WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMSN Servicemsnsvc.exe"Added by the SLENFBOT.EG WORM!"
XMSN User Servicemsnsvc.exe"Added by the SLENFBOT.NS WORM!"
XMSN User Svcmsnusnsvc.exe"Added by the IRCBOT.AVV BACKDOOR!"
Xmsnager32svchostt.exe"Added by the WOMANIZ.E TROJAN!"
XMsnExplorerSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
NMSNIAMSNIASVC.EXEAdded with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG
XMsnMessengerSvcmsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSRegSvcregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
XMss VCmssvc.exe"Added by the OPANKI.AB WORM!"
Xmssvc[path to trojan]"Added by the PSK TROJAN!"
XMSSVCsvcsys.exe"Added by the FATOOS-C TROJAN!"
YMSSVC.EXEMSSVC.EXE"StealthDisk - hides folders
Xmssvc32mssvc32.exe"Added by the AGOBOT-ME WORM!"
XMSSYSTEMsvcsys.exe"Added by the FATOOS-C TROJAN!"
XMStasksvchost.exe"Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMSTaskbar 32tbsvc32.exe"Added by the RBOT.BQZ WORM!"
XMSUpdatesvchosthlp.exe"Added by the BLASTER.T WORM!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xmsvc32msvc32.exe"ClientMan parasite variant"
Xmsvc32msvc32.exe"Added by the AGOBOT-NT WORM!"
Xmsvcavmsvcav.exe"Added by the AGENT-ACR TROJAN!"
Xmsvccmsvchost.exe"Added by the XOMBE TROJAN!"
Xmsvcc25svcchost.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25salvage.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25svcchost.exe"Added by the SDBOT-CSE WORM!"
Xmsvccc66svcchosst.exe"Added by the RBOT-GLS WORM!"
Xmsvccc66dload.exe"Added by a variant of the RBOT WORM!"
Xmsvchostmsvchost.exe"Added by the IRCBOT-AV WORM!"
XMsvcServicemsvcs.exe"Added by the RBOT-RK WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMy AppSMSSvc.exe"Added by the NEGASMS.A TROJAN!"
YMyCIO Agent Servicemyagtsvc.exe"Part of the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
XMySLScanmsvc32.exe"Added by the FORBOT-EH WORM!"
Xmysvcig38mysvcc.exe"Added by the RBOT-FOU WORM!"
Xmysvcig38recsl.exe"Added by a variant of the RBOT-FOU WORM!"
Xnanosvchost.exe"Added by the NANO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNDIS Adaptersvchosttt.exe"Added by the WOOTBOT.AN WORM!"
Xnetcsvc.exe"Added by the VESLORUKI.DWK TROJAN!"
XNetServicentsvc.exe"Added by the QQPASS-DU TROJAN!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNetStartsvchost.exe"Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""NETSTART"" subfolder"
XNetwork Administration Servicersvc32.exe"Added by the RBOT.ABH WORM!"
XNetwork manegersvchost.exe"Added by the AGENT.BX BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNetwork Securitysecsvc.exe"Added by the RBOT-ALX WORM!"
XNetwork Security XPnvsvc86.exe"Added by the RBOT-GUI WORM!"
XNetwork Servicesvchost.exe"Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNetwork Service Managernetsvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UniSvcLocniSvcLoc.exe"Related to National Instruments Corp. LabView"
?NMSSvcNMSSVC.EXENIC Management Service - diagnostics program for Intel Pro family network cards
YNMSVCnmSvc.exe"Covenant Eyes - surveillance software that creates records of everything people do on a computer
UNNSvcnnsvc.exe"Net Nanny internet filter. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XnodriverSVCHOST.EXE"Added by the SPYBOT-Z BACKDOOR! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
XNorton Live UpdaterCavapsvc.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterAvapsvc.exe"Added by the AGOBOT-BG BACKDOOR!"
UNorton Program SchedulerNPSsvc.exe"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95
XNorton protectnvsvc.exe"Added by a variant of the RBOT WORM!"
XNorton Service Processnavapsvc.exe"Added by the AGOBOT-GV WORM! Note - this is not the valid Norton Anti-Virus service which has the same file and is located in %ProgramFiles%\Norton AntiVirus. This one is located in %System%"
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNortonVPlussvchost.exe"Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNsvnsvsvc.exe"Delfin Promulgate adware"
Xnsvcinn20050308.exe"Delfin Media Viewer adware related"
XNT MICROSOFT SVCDntvsvcd.exe"Added by a variant of the RBOT WORM!"
XNT Servicesntsvc.exe"Added by the AGOBOT.VJ WORM!"
Xntupdatednsvc.exe"Added by the SDBOT-TC WORM!"
Xntusersvchost.exe"Added by the POLYCRYP.DY TROJAN!"
XNvClipRsvsvchost.exe"Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvCplDmnNAVSVC.EXE"Added by an unidentified VIRUS
XNvidia Control Daemonnksvc32.exeAdded by an unidentified WORM or TROJAN!
XNvidia Control Panelncsvc32.exe"Added by an unidentified VIRUS
XnVidia Display Drivernvsvc64.exe"Added by the IRCBOT-YK WORM! Note - this is not related to any nVidia based graphics card"
XNvidia Startup Managerksvc32.exe"Added by the AGENT-IWD TROJAN!"
NNvSvcnvsvc.exe"NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active
Xnvsvcnvsvc.exe"Added by the BANKER-HQ TROJAN! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XNVSVCnvsvc.exe"Added by the AGOBOT.ALX WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
UNvSvc"RUNDLL32.EXE nvsvc.dllnvsvcStart"
Unvsvc16nvsvc16.exe"MySuperSPy surveillance software. Uninstall this software unless you put it there yourself"
Xnvsvca32nvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
Xnvsvca32clfmon.exe"Added by the TACTSLAY.E TROJAN!"
Xnxgsvc"rundll32.exe nxgsvc.dllstart"
XOffice Monitornvsvc86.exe"Added by the IRCBOT.BVO BACKDOOR!"
XOffice Monitor Word Exel Rsvch.exe"Added by the DWNLDR-GWW TROJAN!"
XOfficeAgentsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeAgentsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeGuardUIsvcss.exe"Added by the DEDLER-C TROJAN!"
UOn screen displayTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
XOnline Servicesvchost.exe"Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPcsvpcsvc.exe"Delfin Media Viewer or ""Promulgate"" adware"
UPD0620 STISvcP0620Pin.dllCreative Technology Ltd installation plug-in related
XPDA Commanderstisvc32.exe"Added by the AGOBOT-TX WORM!"
XPerfomance Settingssvchost.exe"Added by the TOFGER-AP TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YPGPSDKSVCpgpsdkserv.exe"PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings
XPhotoshopsvchost.exe"Added by the CDOPEN-E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
XPK Servicespksvc.exe"Added by the FORBOT-BW WORM!"
Xpnpsvc_lock******.exe [* = random digit]Browser hijacker
Xpnpsvc_lockstartsvs.exeBrowser hijacker
XPolicyRunsvchost.exe"Added by the SILLYFDC-AW WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPowerManagersvchost.exe"Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UPPSVC[path to file]"PC Police surveillance software that logs keystrokes
XPrint Schedulerusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XPrint Spoolerspoolsvc32.exe"Added by the SDBOT.BB TROJAN!"
XProcessorsvchost.exe"Added by the AGENT-KIR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
XProtocolDiskChksvcvlw32.exe"Added by the STINX-Y TROJAN!"
XPServicesvcnow32.exe"Added by the SPYBOT-DJ TROJAN!"
YPSIMSVCPSIMSVC.exe"Part of Panda Antivirus and Internet Security"
XQTSvcmsocfg.exePremium rate adult content dialler
XQTSvcnavchk.exePremium rate adult content dialler
XQTSvcshman.exePremium rate adult content dialler
XQTSvcssvr.exePremium rate adult content dialler
XRavshellsvch0st.exe"Added by the NSPM.PU TROJAN! Notice the digit ""0"" in the filename rather than the lower case ""O"""
Xravtasksvch0st.exe"Added by the LINEAG-AIN TROJAN!"
XRecoveru systemsvchast.exe"Added by a variant of the LINEAGE-AV TROJAN!"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
Ureg2.0SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
Xregeditsvchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
XRegistry Serviceregsvc.exe"Added by the IRCBOT-ZM BACKDOOR!"
XRegsvcregsv.exeAdded by an unidentified TROJAN!
Xregsvcsysd"Sys Detective+ spyware"
Xregsvc32regsvc32.exeHomepage hijacker that changes your homepage to an adult content site
XRemote Access Adapterrvasvc.exe"Added by the IRCBOT.BIF BACKDOOR!"
XRemote Access Domainrswsvc.exe"Added by the IRCBOT.BFA TROJAN!"
XRemote Access Monitorrpgsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRemote Access Toolrwosvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRemote Event Systemresmsvc.exe"Added by the IRCBOT.YF BACKDOOR!"
XRemote Services Managermsrmsvc.exe"Added by the SLENFBOT.AJ WORM!"
XRemote Storage Accessrmasvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRemote Terminal Taskrtsbsvc.exe"Added by the IRCBOT.AUZ BACKDOOR!"
Xrenascimentosvchost.exe"Added by the BANKER.GAX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
Xreseurcesvchost.exe"Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRestore Operationsvchots.exe"Added by a variant of the RBOT WORM!"
XRun Services as Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
Xrun=svcinit.exe"CoolWebSearch parasite variant"
YRunCAInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
Xrundll32svchs0t.exe"Added by the PWSTEAL-E TROJAN!"
XRunnersvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunsvcrunsvc.exe"Added by the SMALL-CF TROJAN!"
XS0undMansvch0st.exe"Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XSavsvc"rundll32.exe savsvc.dllstart"
XScheduIrsvchst.exe"Added by a variant of the SDBOT WORM!"
XSchedulersvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvchst.exe"Added by the TACTSLAY.B TROJAN!"
Xscrsvcscrsvc.exe"Added by the AGENT-DS TROJAN!"
Usds20svchost.exe"InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
Xsecsvc32secsvcnt.exe"Added by the GLOBAL PATROL TROJAN!"
XSecurity Servicesecsvc.exe"Added by the RBOT-GGF WORM!"
XService Clientwinsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
XService Hostsvchost.exe"Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Hostsvchost.exe"Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853}"
XService Hostsvchost.exe"Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random]"
XService Hostsvchosts.exe"PornCleanser spyware"
XService Host Driversvchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Host Processspoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
XService ProcessSVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Processsvchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XService Update Clientsvcupdcli.exe"Added by an unidentified WORM or TROJAN! See here"
XServiceHostsvch0st.exe"Added by the VB.HE VIRUS!"
XServiceHstsvcnost.exe"Added by the AGOBOT-RS WORM!"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
XServicessvchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices Administratorlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratornetsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcman.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratortcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Administratorwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Hostsvchost32.exe"Added by the AGOBOT-TG WORM!"
XServices hostsvchost.com"Added by the RBOT-EU WORM!"
XServices Managerssvcmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSES Servicesesvc.exe"Added by the SDBOT-CZU WORM!"
XSetup experationsvchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSheduIersvchst.exePremium rate adult content dialler
XShellExplorer.exe svchost.exe"Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShellsvchost.exe"Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShell API32svcnet.exe"Added by the TIBICK.C WORM!"
Xshoketsvchs0t.exe"Added by the WOWPWS-E TROJAN!"
XSiS Dnsdnssvc.exe"Added by the DLOADER-UE TROJAN!"
XSiS Mpc Servicempcsvc.exe"Added by the CIADOOR-CJ TROJAN!"
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
XSMSvc32smsvc32.exe"Added by the AGOBOT-OL WORM!"
XSNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSocket Utilitysvchostz.exe"Added by the DAEMONI-E TROJAN!"
XSound VolumesvchosI.exe"Added by a variant of the IRCBOT TROJAN! See here"
Xsp2svcsp2svc.exe"Added by a variant of the RBOT WORM!"
XSPOOL Configurationspoolsvc.exe"Added by the SDBOT-KD WORM!"
XSpooler SubSystem Appspoolsvc.exe"Added by the POEBOT-J WORM!"
XSpooler SubSystem Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler Subsytem Appspoolsvc.exe"Added by the SDBOT-MM WORM!"
Xspoolsvsvchost.exe"Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
Xspoolsvcspoolsvc.exe"Added by the DROPPER-AT TROJAN!"
YSR AgentAGENTSVC.EXE"Related to Secure Resolutions - desktop virus protection"
USrv32WinSvchost.exe"Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSrvce Pack Updtesvcpack.exe"Added by a variant of the RBOT WORM!"
XSSLsvchost.exe"Added by an unidentified VIRUS
Xssvchostssvchost.exe"Added by the HELIOS.B TROJAN!"
XStart It Uppingsvchosets.exe"Added by a variant of the RBOT WORM!"
XStart Pagesvcnt32.exe"Homepage hijacker
XStart UppingSVCHOSTES.EXE"Added by the RBOT-NB WORM!"
XStart Uppingssvcchosts.exe"Added by the SDBOT.VY WORM!"
XStarting upwvsvc.exe"Added by the RBOT-NF WORM!"
Xstartkeysvcmgr.exe"Added by the HIPPER-B TROJAN!"
Xstartkeysvchost32.exe"Added by a variant of the SDBOT WORM!"
Xstartkeysvchost.exe"Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
USTOPzilla ServiceSZNTSVC.EXE"StopZilla! - pop-up killer"
XSvcsvc.exe"ClientMan parasite variant"
USVCsvchost.exe"ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsvcexpseny.exe"Added by the PWS-ANG TROJAN!"
XSVC Servicesvcinit.exe"Added by the SINIT TROJAN!"
XSVC Servicesvcinit.exe"CoolWebSearch parasite variant"
XSVC Servicesvcpack.exe"CoolWebSearch Svcinit parasite variant"
XSVC Servicesvc32.pif"Added by the RBOT-ASC WORM!"
XSVC Socksmstaskm.exe"CoolWebSearch parasite variant"
Xsvc32svc32.exeIdentified as a variant of the Banker-EQC/DLoader.GPJI malware
Xsvcdata.exesvcdata.exe"Added by the SPYBOT.ZIF WORM!"
XSvcedSvced.exe"Added by the DELF.F TROJAN!"
XSvcH0stmsexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
XSvcH0stSHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvcH0stSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvcH0stWINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
XSVCH0STspoo1sv.exe"Added by the VB-HF TROJAN!"
XSVCH0STSVCH0ST.EXE"Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase ""o"""
XSvcH0stmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XSvcH0stsdhch.exe"Added by the TACTSLAY.B TROJAN!"
XSVCH0ST.EXESVCH0ST.EXE"Added by the BANCBAN-HT TROJAN!"
XSVCH0TSsp00lvs.exe"Added by the LINEAGE-AZ TROJAN!"
Xsvchastsvchast.exe"Added by the LINEAGE-AV TROJAN!"
Xsvchctrlsvchctrl.exe"Added by the COBFINN TROJAN!"
Xsvchossvchos.exe"Added by the EZIBOT-B TROJAN!"
Xsvchosd[path to trojan]"Added by the BANCOS-BCX TROJAN!"
XSVCHOSISVCHOSI.EXE"Added by the VBBOT-AA WORM!"
XSVCHOSTsvchost.exe"System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060"
Xsvchostsvchost.exe"Added by many TROJANS amd WORMS
XSVCHOSTmrowyekdc.exe"Added by the GOTORM WORM!"
XsvchostSvch0st.exe"Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
Xsvchost[path to trojan]"Added by the HAZZER TROJAN!"
XsvchostADMAGIC.EXE"Added by the SMIBAG WORM!"
XSvchostwinhost.exe"Added by the LOLAWEB.A TROJAN!"
XSvchostsvchost.exe"Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSVCHOSTvar.txt.exe"Added by the LDPINCH.C TROJAN!"
XSvchostsvchosl.pif"Added by the INZAE.A or INZAE.B WORMS!"
Xsvchost[path] SETUP.EXE"Added by the SETCLO WORM!"
XSVCHOSTscvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
XSVCHOSTtaskgmr.exe"Added by the MYTOB.F or MYTOB.H WORMS!"
Xsvchostolehelp.exe"Added by the BOOKMARKER.G TROJAN!"
XSVCHOSTupdater32.exe"Added by the RANTS.A WORM!"
XSVCHOSTSPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
XSvcHostsvchost32.exe"Added by the AGOBOT-TM WORM!"
Xsvchostsvchost.exe"Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
XSVCHOSTMDM.EXE"Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
Xsvchost[path to explorer.exe]"Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
Xsvchostrundll16.exe"Added by the STARTPA-PB TROJAN!"
XSvchostsvchost.exe"Added by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer"
Xsvchostsvchost.exe"Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
Xsvchostsvchost.exe"Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
Xsvchostwinhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
XSvchostsvchots.exe"Added by the RBOT.ADK WORM!"
Xsvchostying.exe"Constructor VC2000 malware"
Xsvchostinetinfo.scr"Added by the ODELUD WORM!"
XSVCHOSTsvchost64.exe"Added by the STARTP-G TROJAN!"
Xsvchostsvchost.com"Added by the BANLOA-ABL TROJAN!"
Xsvchostwin.exe"Added by the VBSAUTO-A WORM!"
Usvchostsvchost.exe"Infine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an ""svc"" subfolder"
Xsvchostlogon.exe"Added by the SLEGON WORM!"
Xsvchostsvcst.exe"Added by the AGENT-LIL WORM!"
Xsvchostsvchost.exe"Added by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""MsDtds"" sub-directory"
Xsvchostwindowsrx.exe"Added by the AGOBOT-MZ WORM!"
XSVCHOSTSERVlCES.EXE"Added by the DELF-LF BACKDOOR! Note that the filename has a lower case ""L"" in place of an upper case ""i"""
Xsvchost Agentsvchost.exe"Added by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""28463"" sub-folder"
Xsvchost connection monitorsvchost32.exe"Added by a variant of the SDBOT WORM!"
XSVCHOST Generic applicationsvchost.exe"Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsvchost Netware Managersvchost.exe"Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSVCHost Protocol32scvhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XSvchost Servicesvchost.exe"Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
Xsvchost.exesvchost32.exe"CoolWebSearch Svchost32 parasite variant"
XSVCHOST.EXESVCHOST.EXE"Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsvchost.exe[path to executeable]"Added by the BANKER-MO TROJAN!"
Xsvchost.exesvchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
Xsvchost.exeswchost.exe"Added by the SADELPHI-A TROJAN!"
Xsvchost.exesvchost.exe"Added by the VIRUT.CF WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3361"" subfolder"
XSVCHOST.EXEsvchost.exe"Added by the SILLYFDC.BBI WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Conf"" sub-directory"
Xsvchost.exesvcnost.exe"Added by the MISLEAD-A TROJAN!"
Xsvchost1svchost1.exe"Added by the AGOBOT.ZZ WORM!"
XSVCHost2svchost2.exe"Added by the RBOT.BLC WORM!"
XSvcHost32svchost32.exe"Added by the MIMAIL.I or MIMAIL.J WORMS!"
Xsvchost32.exesvchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
Xsvchost64svchost64.exeAdded by the SDBOTER.G VIRUS!
Xsvchostasvchosta.exe"Added by the SNIFFER-I TROJAN!"
Xsvchostbsvchostb.exe"Added by the SNIFFER-J TROJAN!"
XSvcHostDHCPsvchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
Xsvchostdll.scrsvchostdll.scr"Added by the BANCBAN-FM TROJAN!"
XSvcHostov1rg1n.exe"Added by the AGOBOT-TK WORM!"
Xsvchostrsvchostr.exeAdded by an unidentified WORM or TROJAN!
Xsvchostssvchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
Xsvchosts.exesvchosts.exe"Added by the AGOBOT-JN WORM!"
Xsvchosts.scrsvchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
XSVCHOTSVCHOT.exe"Added by the QQROB-U TROJAN!"
Xsvchstsvchst.exe"Added by the KBROY-C TROJAN!"
Xsvcinfosvcinfo.exe"Added by the CRYPTER.A TROJAN!"
XSvclhostsvcchost.exeAdded by an unidentified WORM or TROJAN!
XSvcManagerrestore3.exe"Added by the AGENT-DSS TROJAN!"
XSvcManager[path to trojan]"Added by the ZALON-A BACKDOOR!"
XSvcManagermdmex2.exe"Added by the ZALON-B BACKDOOR!"
Usvcmonsvcmon.exe"PersonInspect surveillance software. Uninstall this software unless you put it there yourself"
XSvcnost.exesvcnost.exe"Added by the SELEX.B WORM!"
XSvconrSvconr.exe"WaveRevenue-lBann adware"
XSvcphpwinsslphp32.exe"Added by the AGOBOT-ABR WORM!"
Xsvcrootsvcroot.exe"Added by the KEYLOG-AC TROJAN!"
Xsvcrootxffanl.exe"Added by the AGENT-BMF TROJAN!"
XsvcsharewinampXP.exe"Added by the FUJACKS-J VIRUS!"
Xsvcsharespoclsv.exe"Added by the FUJACKS-A VIRUS!"
XsvcshareCTMONTv.exe"Added by the FUJACKS-AJ WORM!"
Xsvcsharenvscv32.exe"Added by the FUJACKS-Z WORM!"
XSvcSys[path to file]"Added by the BANCOS.Z TROJAN!"
XSvcsys Registry Managersvcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
Xsvcsys32svcsys32.exe"Added by the AGOBOT-LL WORM!"
Xsvctasksvctask.exe"Added by the CHUCKYB-A TROJAN!"
Xsvcwinprocess32[path to worm]"Added by the UPERING WORM!"
XSvshost Update Servicesvcbind.exe"Added by the MYTOB.LH WORM!"
XSygate Personal Firewallsvchots.exe"Added by the RBOT.ABT WORM!"
YSymantec Core LCsymlcsvc.exe"Part of Norton AntiVirus 2004. What does it do?"
USymantec PIF AlertEngPIFSvc.exe"Symantec LiveUpdate Notice Service"
XSymantec Security Addonnvsvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM! Note - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here"
XSysEQsvclgx32.exe"Added by the IRCBOT-AC TROJAN!"
XSysInitsvchost.exe"Added by the STARTPA-BD TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
YSysPoolMssvc.exe"StealthDisk - hides folders
XSysPoolMSSVC32.EXE"Added by the BANCBAN-IO TROJAN!"
XSystemSVCHOST.EXE"Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemsvchîst.exe"Added by the LDPINCH-BF TROJAN!"
Xsystemsvcr.exe"Added by the SPYONE TROJAN!"
Xsystem configuresvchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XSystem Document Applicationwinsvc32.exe"Added by the SDBOT-VA WORM!"
XSystem Efficiency Monitorsvchostx.exe"Added by the KWBOT.E WORM!"
XSystem Event Managersecsvc.exe"Added by the RBOT.BMY WORM!"
XSystem File Driversnvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
XSystem Host Servicesvchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XSystem Managersvchost.exe"Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
XSystem Power Managmentsvcnost.exe"Added by the DREF-I WORM!"
XSystem Processsvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Restoresvcnet.exe"Added by the TIBICK WORM!"
XSYSTEM service helpersvchelper.exe"Added by the MONKBD-A WORM!"
XSystem Servicessvcsenes.exe"Added by a variant of the RBOT WORM!"
XSystem Servicessvcsenes32a.exe"Added by the RBOT-AFG WORM!"
XSystem Update2svchost.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSystem Updatedsvchoes.exe"Added by the RBOT-ASF WORM!"
XSystem32svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XSystemChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemRegsvchost.exe"Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemssvch0st.exe"Added by the MYDOOM.BI WORM!"
XSystemsspoolsvc.exe"Added by the DLOADR-SW TROJAN!"
Xsys_up1svchostsys.exe"Added by the MULTIDR-FL TROJAN!"
USZMsgSvc.exeSZMsgSvc.exe"StopZilla! - pop-up killer"
XTask Alertcmosvc.exe"Added by a variant of the IRCBOT TROJAN!"
XTask Commanderregsvc32.exe"Added by the AGOBOT-RX WORM!"
XTask Managersvchost.exe"Added by the SOHANA-P WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XTask Monitoring Servicesvchost.exe"Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XTask Scheduler Engineschedsvc32.exe"Added by the RBOT-ASJ WORM!"
XTaskbar Servicetaskbar.svcUnidentified adware
XTcp Application Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XTcp Application Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XTCP Internet ServicesTCPSVC32.EXE"Added by the SPYBOT.X TROJAN!"
XTCP MonitoringLanNSvc.exe"Added by the RANDEX.AAS WORM!"
Xtcpipsvc.exetcpipsvc.exe"Added by the AGOBOT-PG WORM!"
UTHCSsvchost.exe"AllMonitor surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in a ""drivers\imon"" subfolder"
NTkBell.Exeevntsvc.exe"Application Scheduler installed along with RealOne Player. Once installed
NTkBellExeevntsvc.exe"Application Scheduler installed along with RealOne Player. Once installed
XTorrent Management ServiceTMANAGESVC.EX"Added by a variant of the IRCBOT TROJAN!"
UTPHOTKEYTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
UTPOSDSVCTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
UTPOSDSVC.exeTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
XTrkwkstrkwksvc.exe"Added by the IRCBOT.AW WORM!"
Xtsvcinn20050308.exe"Delfin Media Viewer adware related"
XUltimateServicesultsvcs.exe"Added by the AGENT-LGT TROJAN!"
XUniversal USB Servicesvchost32.exe"Added by the KELVIR.R WORM!"
XUpdatesvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xupdaterwisvc.exe"Added by the ORSE-A TROJAN!"
XUPNPupnpsvc.exe"Added by the CLOMP-B TROJAN!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
YUrtSvcExeUrt95Svc.exe"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
XUSB controllerSvcmm32.exeSvcMM backdoor parasite downloader
XUSB Host Serviceusbsvc.exe"Added by the RBOT-GG WORM!"
Xuseful-softsvchst.exe"Added by the STARTPA-HH TROJAN!"
XUser Servicesusersvc.exe"Added by the REVCUSS.A TROJAN!"
XUser Servicesusrsvc.exe"Added by the IRCBOT.SN WORM!"
XUser Sharing Servicesusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
Xusnsvc.exeusnsvc.exe"Added by the SPYBOT.AMD WORM!"
Xutasvc"rundll32.exe utasvc.dllstart"
Xvaluenamesvchosts.exe"Added by a variant of the SDBOT WORM!"
XVekio StartupsPnksvc32.exe"Added by the AGOBOT.AJG WORM!"
XVideo Driversvchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XVideo Processnetsvcs.exe"Added by the AGOBOT.LH WORM!"
XVideo ProcessNivopsvc.exe"Added by the AGOBOT-GT WORM!"
XVideo ProcessNavapsvcc.exe"Added by the SPYBOT-CW WORM!"
Xvirtual-machinesvchosts.exe"Added by the RBOT-US WORM!"
XVolume Shadow Configurationvbmsvc.exe"Added by the SLENFBOT.DH WORM!"
XVolume Shadow Managervbcsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
YWanMPSvcWanMPSvc.exe"An AOL component
XWCPCwintsvcc.exe"PurityScan adware"
?Webcam Go Sti Service Applicationwbcgosvc.exe"Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required?"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 System Spoolspoolsvc.exe"Added by the SDBOT.UK WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWinAmpAgentsvchst.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAntivirusAVSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
UWinAppLogsvchost.exe"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinDLL (svc.exe)"rundll32.exe svc.exestart"
XWinDLL (svchost.dll)"rundll32.exe svchost.dllstart"
Xwindow2ssvchost.exe"Added by the IRCBOT.H TROJAN!"
Xwindowssvchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows .Net Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Audio Componentsnncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Audio Layernarsvc.exe"Added by the IRCBOT.AFT BACKDOOR!"
XWindows Audio Panelnppsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Startupnndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
XWindows Audio Systemnndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Computer Browserbcwsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows Event Detectionwecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Providerwposvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Sectionsntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Executersvchostie.exe"Added by the EGGDROP.V BACKDOOR!"
XWindows FileSharing Servicemcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
XWindows Firewallsvchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Firewall Servicewfsvc.exe"Added by the IRCBOT-YL WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Global Initngpsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Help Managersvchost32.exe"Added by the RBOT-OZ WORM!"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Local Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Logical Adapterwsrsvc.exe"Added by the IRCBOT.ARU BACKDOOR!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messenger Connectwmdsvc.exe"Added by the SLENFBOT.S WORM!"
XWindows Messenger Filesharewivsvc.exe"Added by the SILLYIM WORM!"
XWindows Messenger Panelwbcsvc.exe"Added by the IRCBOT.ADA BACKDOOR!"
XWindows Messenger Sharewmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Messenger Starterwmvsvc.exe"Added by the DELF.DAX TROJAN!"
XWindows Network Logonnpesvc.exe"Added by the AGENT.ERZ TROJAN!"
XWindows Network Sessionnspsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows NT Service Namesvchcst.exe"Added by the RBOT-NV WORM!"
XWindows Protected Storagenpssvc.exe"Added by the IRCBOT.AUL BACKDOOR!"
XWindows Registry Scansvcdll.exe"Added by the RBOT-TP WORM!"
XWindows Security Managersvchost.exe"Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
XWindows Security Survysvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Managementsvcmngmt.exe"Added by the AGOBOT-NM WORM!"
XWindows Service Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcmgr32.exe"Added by the OSCABOT-D WORM!"
XWindows Service Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Service Threadssvcthreading.exe"Added by the SHEUR.AUM TROJAN!"
XWindows Service Threadssvcthreads.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows Services Certificationsvccert.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows Services Guidesvcguides.exe"Added by the SHEUR.YS BACKDOOR!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Jogersvcjoger.exe"Added by the RBOT.CAT WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWindows Stortupsvchost.exe"Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWINDOWS SVCwinsvc.exe"Added by the MYTOB-EY WORM!"
XWindows svchostavserv.exe"Added by the PUSHBOT.FM WORM!"
XWindows svchostctfmon32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows svchosthappy2008.exe"Added by the PUSHBOT.AM WORM!"
XWindows svchostservice.exe"Added by the PUSHBOT.DU WORM!"
XWindows svchostserviceaaa.exe"Added by the PUSHBOT.ER WORM!"
XWindows svchostservicean.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows svchostsvchost.exe"Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows svchostups.exe"Added by the PUSHBOT.A WORM!"
XWindows svchostupss.exe"Added by the PUSHBOT.GJ WORM!"
XWindows svchostserviceam.exe"Added by the PUSHBOT.EY WORM!"
XWindows svchostsvchostx.exe"Added by the PUSHBOT.CC WORM!"
XWindows Svchost Authorityslsass.exe"Added by the RBOT-UA WORM!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWINDOWS SYSTEMwinsvc32.exe"Added by the MYTOB.HH WORM!"
XWINDOWS SYSTEMwinsvc.exe"Added by the MYTOB.LM WORM!"
XWINDOWS SYSTEMsvchost2.exe"Added by the MYTOB.OZ WORM!"
XWINDOWS SYSTEM MANAGERspoolsvc.exe"Added by the MYTOB-LY WORM!"
XWindows Taskmanagersvchost.exe"Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Taskmanagerwdtsvc.exe"Added by the PUSHBOT.AU WORM!"
XWindows Terminal Managerrmbsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Tracking Clientctwsvc.exe"Added by the AGENT-GMB TROJAN!"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindows Update Hostwinupsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows USB v3wsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Video Acquisition (WVA)wvsvc.exe"Added by the AGOBOT.YM WORM!"
XWindows Video Componentwvcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Video Inputviwsvc.exe"Added by the SLENFBOT.GS WORM!"
XWindows Virus Scannerwinvsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Volume Controlongsvc.exe"Added by the SLENFBOT.DZ WORM!"
XWindows Web Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Workstation Servicewkssvc.exe"Added by the IRCBOT-AAI WORM!"
XWindows Workstation Service (32-bits)wkssvc32.exe"Added by a variant of the SDBOT WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsDiskEvtsvcsvh32.exe"Added by the NANINF.D TROJAN!"
XWindowsExplorersvchost.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsFirewallSvcwinsvcup.exe"Added by a variant of the SDBOT WORM!"
XWindowsIPRelaywinipsvc.exe"Added by the IRCBOT-AAA WORM!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsRegKey updatesvchostc.exe"Added by the RBOT.IF WORM!"
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatesvchostw.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindowsXPservsvcnxp32.exe"Addee by the NANINF-A TROJAN!"
Xwindtbswinsysvc"Added by the AGOBOT-NH WORM!"
Xwinimagewvsvc.exe"Added by the RBOT.TX WORM!"
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
Xwinnsvcmsvc.exe"Added by the PWS.O TROJAN!"
Xwinreg_32svchosst.exe"Added by the BANCOS-CE TROJAN!"
XWINRUNsvchost32.exe"Added by the MYTOB-AI WORM!"
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
Xwinsocksvch0st.exe"Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWinsock2 driversvchorsst.exe"Added by the SPYBOT-EE WORM!"
XWinsock32driversvchhost.exe"Added by the HACKARMY.I TROJAN!"
XWinSvc16.exeWinSvc16.exe"Added by the SDBOT.FQ TROJAN!"
Xwinsvc32winsvc32.exe"Added by the IRCBOT-AEG WORM!"
Xwinsvc32.exewinsvc32.exe"Added by the GREPAGE TROJAN!"
XWinUpsvchost.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""4350"" sub-folder"
XWinUpdatesvchots.exe"Added by the SMALL.GXJ TROJAN!"
XWinupdateewinsvcc.exe"Added by the AGENT.AN TROJAN!"
XWin_LibraryINISvc.exe"Added by the ANARCH WORM!"
XWksSVCEXPLORER.exe"Added by the MYTOB-BW WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwlinlessvchost.exe"Added by the LIJI-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the ""spool"" sub-folder"
XWN Serviceswnsvc.exe"Added by the KBBOT-A TROJAN!"
Xwnddrvsvchost.exe"Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWPSVC Serviceswpnsc.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xws2 32svchst.exe"Added by the VOKEN-A TROJAN!"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
Xwscsvc.exewscsvc.exe"Added by a password stealing BANKER TROJAN!"
Xwscsvc32.exewscsvc32.exe"Antivirus rogue security software - not recommended
Xwsock32svchost.exe"Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWSSVCsmsc.exe"Added by the AUTORUN-AGA WORM!"
XWSVCHOsvhost.exe"Added by the SPYBOT-OQ WORM!"
UWSVCSSERVICES.EXE"WSLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWTSCwapisvcc.exe"PurityScan adware"
XWudfSvcWudfSvc.exe"Added by the SHEUR.BBB TROJAN!"
Xwupdsymcsvc.exe"Added by the ABWIZ.C TROJAN!"
Xwupdatewisvccz.exe"Added by the ORSE-B TROJAN!"
YWUSB54GSInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
YWUSB54Gv2InvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
Xxorsvchost.exe"Added by the XORDOOR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""xor"" subfolder"
XYahoo Messengersvchost32.exe"Added by the SOHANA-P WORM!"
UZcfgsvcZCfgSvc.exe"Zero Config MFC Application
UZCfgSvc.exeZCfgSvc.exe"Zero Config MFC Application
XZekio Startupsznksvc32.exe"Added by the AGOBOT-AGI WORM!"
XZNNznnsvc.exe"Added by the SDBOT-DAA WORM!"
XZone Labs Client Exsvchost.exe"Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XzSecurity Serviceszsvc.exe"Added by the SDBOT-DAB WORM!"
Xzztpsvchost.exe"Added by the TANNICK.B TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X[filename]svchost.scr"Added by the BANKER-CC TROJAN!"
X[original filename]svchost.scr"Added by the BANCBAN-CX TROJAN!"
X[random name]svchost.exe"Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
X[random]svchost.scr"Added by the BANCBAN-CY TROJAN!"
X[trojan name]svchost.exe"Added by the BANCBAN-CI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X[various names]svchostss.exe"Added by a variant of the RBOT WORM!"
X_svchost.consvchost.com"Added by the ERKEZ.C WORM!"
X_System_Run_svchost_.exe"Added by the LINEAGE-Z TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.