Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xsystem32.exe"Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field"
Inc.""Miramar SystemsUatmsg.exe
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
U00THotkeysystem32THotkey.exe"For Toshiba Satellite notebook series to use the front buttons
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
XApPache SystemApPache.exe"Added by the RBOT-YP BACKDOOR!"
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
NATI CATALYST System TrayCLI.exe SystemTray"System Tray access to ATI's Catalyst™ Control Center. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
Xauto repair systemqualityx.exe"Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG Anti-Virus Systemavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
Ubeidsystemtraybeidsystemtray.exe"Related to Belgium Identity Card card reader"
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsssystem.exe"Added by a variant of the RBOT WORM!"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCMSystemCMSystem.exe"CASClient adware"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCOM+ System Applicationlsas.exe"Added by the AGOBOT-MO WORM!"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
XCOM++ Systemexploier.exe"Added by the LOVGATE.Z WORM!"
XCOM++ Systemsuchost.exe"Added by the LOVGATE-F WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
XCommandsystem.exe"Added by the GATECRASH.A or GATECRASH.B TROJANS!"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XControl PanelSystem.exe"Added by the DANI TROJAN!"
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XCore System Hardwaresyscorehd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
XD SYSTEMdd.exe"Added by the MYTOB-FN WORM!"
XDataSystem.dat.vbs"Added by the BISCUIT.A WORM!"
XDcom System PatchMicrosoft.exe"Added by the RANDEX.MS WORM!"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
XDevice IO Systemdeviceio.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XDistributed File Systemblade.exe"Added by the MYFIP.AC WORM!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
UDLink System Traydlnetst.exe"Related to D-Link DGE-530T PCI card for servers and workstations"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
Ueanth_system_patchersys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XFDD SYSTEMFdd.exe"Added by the MYTOB-FO WORM!"
XFile Systemtaskmqrs.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XFile Systemtaskmqr.exe"Added by the RBOT.BWQ WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgwizntsystem.exe"Added by the NITWIZ.A TROJAN!"
XHMI PowerSystemhmisvc32.exe"Added by the RANDEX.CZZ WORM!"
XHTML Help Systemhhs.pif"Added by the RBOT-ATB WORM!"
XHTML32 Help Systemhhs32.pif"Added by the RBOT-ATE WORM!"
XHwpsystem_wc.exe"Eziin adware"
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
NiIWiperSystemwiper.exe"System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis"
XIntel system toolhookdump.exe"Added by the SPYRE-H TROJAN!"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XIntel system toolsvehost.exe"Added by the AGENT-EBT TROJAN!"
XIntel system worksiis.exe"Added by the RBOT.QGA WORM!"
XInterceptedSystem[path to worm]"Added by the ANACON-B WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
Xioroxxo microsoft suxsystem32.exe"Added by a variant of the RBOT WORM!"
Xisystemisystem.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
Xjavasystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xkernel system daemonACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
XKernellsystems.exe"Added by the TARNO.C TROJAN!"
XLibreSystemSysRep.exe"LibreSystem
XloadSystemfile.dll.vbs"Added by an unidentified WORM or TROJAN! See here"
XLocalSystemsvchost.exe"EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
XMcafee Antivirus Monitoring System326VSStatmn326.exe"Added by a variant of the SDBOT WORM!"
XMcafee Antivirus Monitoring System32mnVSStatmn32.exe"Added by a variant of the RBOT WORM!"
XMedia serviceSYSTEM64.EXE"Added by the RBOT.QV WORM!"
XMessenger91messengersystem.exe"Added by the RBOT-FPF WORM!"
XMicr Update Systemupwin.exe"Added by the SDBOT.YS WORM!"
XMicrosofot x386 System Monitorsystem32.exe"Added by the WOOTBOT.M WORM!"
XMicrosoftsystem32.exe"Added by the IRCBOT-ZZ WORM!"
XMicrosoft boot system cfg32actboost.exe"Added by the BROPIA.R WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft DLL ExtensionsSystemDll.exe"Added by the RBOT-ADV WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft Help Systemmshelp32.exe"CoolWebSearch parasite variant"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft IPCsystem.exe"Added by the NULLBOT TROJAN!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft NetworkNetworksystem.exe"Added by the SDBOT-AAI WORM!"
XMicrosoft Security Systemmssecsys.exe"Added by the IRCBOT-WJ TROJAN!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoft Systemmsupdtm.exe"Added by the SPYBOT.PKC WORM!"
XMicrosoft Systemmssys32.exe"Added by the PETTICK.A WORM!"
XMicrosoft Systemsys.exe"Added by the RBOT.AKI WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System Administrationsystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft System CheckupCool.exe"Added by the DONK.B WORM!"
XMicrosoft System CheckupWnetlib.exe"Added by the DONK.C WORM!"
XMicrosoft System Checkupdbnetlib.exe"Added by the DONK.L WORM!"
XMicrosoft System CheckupKeymgr.exe"Added by the DONK.M WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Checkuplibsysmgr.exe"Added by the SDBOT-CAF WORM!"
XMicrosoft System Checkupsysmgr.exe"Added by the SDBOT-OO TROJAN!"
XMicrosoft System Checkupnetapi32.exe"Added by the DONK-E WORM!"
XMicrosoft System Checkupwnetmgr.exe"Added by the DONK.Q WORM!"
XMicrosoft System Checkuplibsys32.exe"Added by the SDBOT-ACK WORM!"
XMicrosoft System Checkupnetlogin32.exe"Added by the SDBOT-GN BACKDOOR!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft System Monitormonsys.exe"Added by the IRCBOT-YV TROJAN!"
XMicrosoft System Monitorsystem.exe"Added by the IRCBOT.AUT BACKDOOR!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft system Valuesys57.exe"Added by a variant of the RBOT WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMICROSOFT UNPACCKER SYSTEMunpak32.exe"Added by a variant of the RBOT WORM!"
XMICROSOFT UNPACK SYSTEMwinrarx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesystemi32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatesystem32.exe"Added by the RBOT.IS WORM!"
XMicrosoft Updatesystem.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Update 23NtKernelSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Update Machinesystemll.exe"Added by the RBOT-JT WORM!"
XMicrosoft Update MachineSystemnt.exe"Added by the RBOT.DA WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update Machinesystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Update Machinesystemi.exe"Added by the BUZUS.JKU TROJAN!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatessystemc32.exe"Added by the RBOT-GR WORM!"
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Search System TrayWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Winsock32 Systemwinsock32.exe"Added by the SPYBOT.AKKC WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft xpsp2Networksystem.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft's System ModuleSysmodule.exe"Added by the BDOOR-FJ BACKDOOR!"
XMicrosoft(R) System Managersysmgr.exe"Added by the AGENT.QTR TROJAN!"
XMicrosoftkeysdsystemproc.exe"Added by the FORBOT-BI WORM!"
XMicrosoftkeysdsystemwin32s.exe"Added by the WOOTBOT.CO WORM!"
XMicrosoft© System MapperSysMap.exe"Added by the MAPSY TROJAN!"
UMicrosoft® Windows® Operating SystemSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
NMicrosoft® Windows® Operating System"RunDLL32.exe ehuihlp.dllBootMediaCenter"
NMicrosoft® Windows® Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
UMicrosoft® Windows® Operating SystemehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
NMicrosoft® Windows® Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
NMicrosoft® Windows® Operating Systemstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
Xmicrosystemsnddrv.exe"Added by the VB.AXG TROJAN!"
XMicrsoft DerSystemuqieelpb.exe"Added by the RBOT-GRI WORM!"
XMMSystem"rundll32.exe mmsystem.dll RunDll32"
XMozillacorpsystem.exe"Added by the SILLYFDC WORM!"
XMS Domain Name SystemMSWDNS32.exe"Added by the RBOT-GKY WORM!"
XMS System Call Functionmsscf32.exe"Added by the RBOT-GBZ WORM!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMs System Configpcedit.exe"Added by a variant of the SDBOT WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMSkernel32System.exe 4820"Added by the TUXDER BACKDOOR!"
Xmsnsystem32.exe"Added by the KITRO.A WORM!"
XMSNsystems.exeIdentified as a variant of the Backdoor.PosionIvy keylogging malware
XMSN MessangerSystem.exe"Added by the IRCBOT-AFX TROJAN!"
Xmsoft-updater23slssystem.exe"Added by the RBOT-ASR WORM!"
XMSPP System Update 64wiaadmgr.exe"Detected by Kaspersky as the RANKY.GEN TROJAN!"
XMsSystemmsdos.exe"Adult content downloader - see here"
XMsSystemmssys.exe"Added by the VANTA.A TROJAN!"
XMSSYSTEMsvcsys.exe"Added by the FATOOS-C TROJAN!"
XMsUpdater Systemudpsys32.exe"Added by the RBOT.AAA WORM!"
XNAMEDPIPE SYSTEMnamedpipe.exe"Added by the MYTOB-FH TROJAN!"
XNAV Agentsystems.exe"Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name"
XNBT System alias[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM!"
XNET protection systemnetst.exe"Added by the RIZO.A TROJAN!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
XNew Anti VirusSystem.exe"Added by the BRONTOK-CH WORM!"
XNorman Worl System Abilitynwcss32.exe"Added by the DELF.IO TROJAN!"
XNorton Systemcsrs.scr"Added by the BANLOA-AFM TROJAN!"
NNorton System DoctorSysdoc32.exe"Norton Disk Doctor from Norton Utilities. Automatically runs at start-up
NNorton SystemWorkscfgwiz.exeNorton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it
XNortons AV SYSTEMscvchost.exe"Added by a variant of the RBOT WORM!"
XNortons AVS Systemsarse.exe"Added by the RBOT.AWY WORM!"
NNSystemMonitorSymmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
XNt System Protocolntsystem.exe"Added by the RBOT.DSB TROJAN!"
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XNTFSS Microsoft Systemfilees.exe"Added by the RBOT.GAB WORM!"
XNTFSS MICROSOFT SYSTEMfiless.exe"Added by the RBOT.AXZ WORM!"
XNTmessageSystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
XNTSF Microsoft Systemfylez.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwntsf.exe"Added by the RBOT.ATC WORM!"
XNTSF MICROSOFT SYSTEMfufffy.exe"Added by the RBOT-AEL WORM!"
XNTSF MICROSOFT SYSTEMntssf.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMmarya.exe"Added by the RBOT-AXY WORM!"
XNTSF MICROSOFT SYSTEMsysman.exe"Added by the RBOT.EDP WORM!"
XnVidia System Driversnvsys32.exe"Added by an unidentified WORM or TROJAN! See here"
UNVIDIA System MonitorNVMonitor.exe"NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures
UNVidia System UtilityNVSystemUtility.exe"NVidia System Utility - older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures
XNVSystem32nvscv32.exe"Added by the AGOBOT-NO WORM!"
XOffica Monitor Secura Systemewinxp_sp3.exe"Added by a variant of the RBOT WORM!"
XOffice Monitor Secure Systemaabsecure32.exe"Added by the RBOT.FPW WORM!"
XOlive SystemSzchost.exe"Added by the MERCURYCAS.A TROJAN!"
NPaperQuote System Tray IconPQTRAY.EXEPaperQuote is a "wallpaper" changer with daily quotes that are either for inspiration or motivation
XPaSystempasystem.exe"Targetsaver adware variant"
YPASystemTrayPASystemTray.exe"Related to Panda Security Software - part of Panda Administrator 3"
XPCSecureSystempgs.exe"PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
XPIC SYSTEMpicx.exe"Added by the MYTOB.LL WORM!"
XPIPE SYSTEMpipe.exe"Added by the MYTOB-FF WORM!"
XPopup Blocker SystemPopUpBlocker.exe"Added by a variant of the RBOT WORM!"
XPopup Blocker System326a MonitoringPopUpBlocker6a.exe"Added by the RBOT.AUH WORM!"
XPopup Blocker System8 MonitoringPopUpBlocker8.exe"Added by a variant of the RBOT WORM!"
XPrinter Spooler Subsystemspoolss.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Windows spoolss.exe process which is always located in %System% and should not figure in Msconfig/Startup!"
XPrintMngrsystem.exeAdded by an unidentified TROJAN!
XPrintSpoolSvSystem.exe"Added by the BDOOR-S BACKDOOR!"
XProtection Systempsystem.exe"Protection System rogue security software - not recommended
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
XRAX SYSTEMscrigz.exe"Added by the MYTOB.KR WORM!"
URCSystemDLLML.exe RCSystem"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
XRCSystemTrayMaxRCSystemTray.exe"Max Registry Cleaner rogue registry cleaner - not recommended
XRecoveru systemsvchast.exe"Added by a variant of the LINEAGE-AV TROJAN!"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XRecycle Bin Handler 2005system.exe"Added by the BDOOR-HO BACKDOOR!"
XRegistry Checkup System326a MonitorWinregs326a.exe"Added by a variant of the SDBOT WORM!"
XRegistry SystemRegsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRegistry System16 Checkup MonitorSystemReg16.exe"Added by a variant of the RBOT WORM!"
XRegistry System166 Checkup MonitorSystemReg166.exe"Added by a variant of the RBOT WORM!"
XRemote Event Systemresmsvc.exe"Added by the IRCBOT.YF BACKDOOR!"
XRemote System Protection"rundll32.exe [random].dll HUI_proc"
XReparateurDeSystemeSysRep.exe"ReparateurDeSysteme
Xruinsystem32.exe"Added by the DELF-JM TROJAN!"
XRundllsystem32Rundllsystem32.exe"Added by the NETDEVIL.B TROJAN!"
XRuntime Server Subsystemcsrss.exe"Added by the IRCBOT-XV WORM!"
USafeHouseSystemTraySDWTRAY.EXE"SafeHouse ""Personal Privacy"" system tray icon - PP protects and hides your private and personal photos
XSBR2009FSystemBooster2009.exe"SystemBooster2009 rogue system suite - not recommended
XSecure Systemintegitor.exe"Added by the AGOBOT.ACI WORM!"
XSecurity Systemsecuresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xserversystem.exe"Added by the METHS-A TROJAN!"
XService Systemkernels32.exe"Added by the BANCOS-DA TROJAN!"
XService SystemwindowsXP.exe"Added by the BANCOS-EL TROJAN!"
XService Systemkgbfsm344.exe"Added by the BANCOS-FS TROJAN!"
XService Systemwernell87.exe"Added by the BANCOS-FJ TROJAN!"
XServicosSystem.exe"Added by the BANCOS-BCM TROJAN!"
XSession Manager Subsystemsmssa.exe"Added by the RBOT-AGS WORM!"
Xshellsystemshellsystem.exe"Added by the UPCHAN TROJAN!"
XSms System32SmsSystem32.exeUnidentified malware
USMSystemAnalyzerSMSystemAnalyzer.exe"Part of the Iolo System Mechanic optimization tool"
XSound SystemWinSound1.exe"Added by an unidentified VIRUS
XSpooler Subsystemspoolsub.exe"Added by the SDBOT-ABG TROJAN!"
XSpooler SubSystem Appspoolsvc.exe"Added by the POEBOT-J WORM!"
XSpooler SubSystem AppspooIsv.exe"Added by the LINKBOT.M WORM!"
XSpooler SubSystem Appspoolv.exe"Added by the SDBOT-BN WORM!"
XSpooler SubSystem Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler SubSystem Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
XSpoolerSubSystemProcessSpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
XSpySpotter System DefenderDefender.exe"SpySpotter rogue spyware remover - not recommended
Xssgrate.exesystem.exe"Added by the MITGLIEDER.C TROJAN!"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
XStartReplySystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
XSygate Personal Firewallsystem32.exe"Added by the RBOT.VI WORM!"
NSymTray - Norton SystemWorksSYMTRAY.EXE"Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus
XSYS1system.exe"Added by the SILLYFDC-AP WORM!"
XSysmonSystemMonitor.exe"Added by the NUJAMA-A WORM!"
XsysPersonalFirewallsystem.exe"Added by the WOOTBOT.FH WORM!"
XSysProtectSystem.exe"Added by the NETSPY TROJAN!"
XSysStrtsystemc.exe"Added by the AGOBOT-QA TROJAN!"
XSystemrun322.exe"Added by the LANFILT TROJAN!"
XSystemsystem.exeAdded by various WORMS and TROJANS!
Xsystemregedit -s system.dllHomepage hijacker
Xsystemsystemsearch.htaJetseeker.com hijacker
XSystemdcomx.exe"Added by the CIREBOT TROJAN!"
XsystemExplorer.exe"Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSystemYPager.exe"Added by the JUNTADOR.K TROJAN! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger"
Xsystemoutlook.exe"Added by the MIMAIL.Q WORM! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %Windir%"
XSystemAtira.exe"Added by the KOTIRA VIRUS!"
XSYSTEMlsas.exe"Added by the SPYBOT.CJ WORM!"
XSystemkernels32.exe"Added by the DLOADER-FC TROJAN!"
USystemsysctrl.exe"Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance
XSystemcsrss.exe"Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemSVCHOST.EXE"Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystemlsasse.exe"Added by the RBOT-YL WORM!"
XSystemsystray.exe"Added by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process"
XSystemabcdefg.exe"Added by the HARWIG-B WORM!"
XSystemcber.exeAdded by an unidentified TROJAN!
XSystemserwin.exe"Added by the LDPINCH-BN TROJAN!"
XSystemsvchîst.exe"Added by the LDPINCH-BF TROJAN!"
XSystemsystem.exe (74295303)"Added by the VB-IU WORM!"
XSystemWINL0G0N.EXE"Added by the BANCOS-DB TROJAN!"
XSystemwumgrd32.exe"Added by a variant of the RBOT WORM!"
XSystemSPOOLSU.EXE"Added by the BANKER-FC TROJAN!"
XSystemsystem23.exe"Added by the LEBREAT-D WORM!"
XSystemwindowsps.exe"Added by a variant of the RBOT WORM!"
XSYSTEMd.exe"Added by the MYTOB.LP WORM!"
XSysteminetinfo.exe"Added by the PARDROP-A TROJAN!"
Xsystemservices.exe"Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
XSYSTEMVSSMON.exe"Added by the RBOT-AWW TROJAN!"
XSYSTEMwiinlogon.exe"Added by the RBOT-AVG WORM!"
XSystemkernels64.exe"Added by the VIXUP-S TROJAN!"
Xsystemlsass.exe"Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XSystemsmss.exe"Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemwinupd.exe"Added by a variant of the SDBOT WORM!"
Xsystemmessenger.exeAdded by an unidentified WORM or TROJAN!
XSystemkernels1118.exe"Added by a variant of the SDBOT WORM!"
XSystemwsscntfy.exe"Added by a variant of the SDBOT WORM!"
XSYSTEMwindmupdr.exe"Added by a variant of the RBOT WORM!"
Xsystemsvcr.exe"Added by the SPYONE TROJAN!"
XSystemkernels88.exe"Added by the TIBS-PP TROJAN!"
XSystemkernels8.exe"Added by the TIBS.AI TROJAN!"
XSystemOeApi.vbs"Added by the AGUI WORM!"
XSystemUpdaterun.exe"Added by the QQHELP-DX TROJAN!"
XSystemZap.exe"Added by the MSNVB-D WORM!"
XSystemBrO_AcT.exe"Added by the SILLYFDC-AL WORM!"
XSystemJuegs.exe"Added by the CULLER-C WORM!"
XSystemkernel8.exe"Added by the DLOADR-AOL TROJAN!"
XSystemkernelwind32.exe"Added by the VXIDL.FT TROJAN!"
XSystemXsfr.exe"Added by the CULLER-D WORM!"
XSystemkernelwind64.exe"Added by the DLOADER.DJD TROJAN!"
XSYSTEMSystemFile.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsystemssclie.exe"Added by the AGENT.LW BACKDOOR!"
XsystemWinhelp.exe"Added by the IMAUT.CN WORM!"
Xsystemkernel32.ini"Added by the SILLYFDC.CJ WORM!"
XSystemtesttestt.exe"Added by the DWNLDR-ZLC TROJAN!"
XsystemMicrosoft Office.exe"Added by the BANCBAN-LH TROJAN!"
XSystemIEXPL0RE.EXE"Added by the VB.KS WORM! Note the number ""0"" in the filename"
Xsystemsysnet.exe"Added by the VETOR-J WORM!"
Xsystemsystemdb.exe"Barracuda Antivirus and Security Central rogue security software - not recommended
XSystemwinipck.exe"Added by the RBOT-TK WORM!"
XSystemkrln32.exe"Malware installed by different rogue security software including SpyKillerPro"
Xsystemsystem64.exe"Added by the BANCBAN-PP TROJAN!"
XSystemantivirus.vbe"Added by the AUTORUN-AYI WORM!"
XSYSTEMRUNDLL16.exe"Added by the DELF-EW BACKDOOR!"
XSystemsystemz.exe"Added by the VILSEL-B TROJAN!"
XSystem 64 Driver for Gamessys64dvr.exe"Added by the SDBOT TROJAN!"
XSystem Analyzerlsass32.exe"Added by the SDBOT.CNI WORM!"
XSystem Applications Profilesap.exe"Added by the RBOT-QF WORM!"
XSystem Authsystem52.exe"Identified as a variant of the Win32:Rizo-E malware"
XSystem Backupmsystem.exeAdult content dialler
XSystem backup[random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted
XSystem Backupsysbcp32.exe"Added by the AGOBOT-NP BACKDOOR!"
XSystem Backup Servicesbackups32.exe"Added by a variant of the RBOT WORM!"
XSystem Boot Checksysload3.exe"Added by the FUBALCA WORM!"
XSystem Boot Loadersysboot32.exe"Added by the SDBOT.PG WORM!"
XSystem Buffer Applicationbuffer32.exe"Added by the SDBOT-UD WORM!"
XSystem CacheSysCache.exe"Added by an unidentified VIRUS
XSystem CGI Managersyscgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
USystem Check"Rundll32.exe SysDll32.dll SystemCheck"
Xsystem checkupdater.exeUnidentified adware downloader
XSystem Checkwin_klr32.exe"Added by the DELF-DRA WORM!"
XSystem Checkingwasul.exe"Added by the RBOT.BHM WORM!"
XSystem ConfigBF3.EXE"Added by the SPYBOT-DT WORM!"
XSystem Configsysloadcnf.exe"Added by a variant of the SDBOT WORM! See here"
XSystem Config Bootsyscgboot.exe"Added by the AGENT.VWU TROJAN!"
XSystem Config Managercrss.exe"Added by the AGOBOT.GH WORM!"
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Configurationsyscfg32.exe"Added by the MYTOB.EA WORM!"
XSystem Configurator32SYSTEMCFG.EXE"Added by the AGOBOT-KS WORM!"
Xsystem configuresvchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XSystem Core Memorysyscoremem.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem CPL manager[random filename]"Added by the RBOT-SR WORM!"
XSystem CSRSS Patchscrtkfg.exe"Added by the RBOT-ADA WORM!"
XSystem Database administrationsystemDA.exe"Added by the DERDERO.B WORM!"
XSystem Database Administration Support Processsysdasp.exe"Added by the DERDERO.C WORM!"
XSystem DataBase Rootsysdbroot.exe"Added by the QHOST-W TROJAN!"
XSystem DB Managersysdbmg.exe"Added by an unidentified WORM or TROJAN! See here"
XSystem DefenderWS[random characters].exe"System Defender rogue security software - not recommended
XSystem Devicedevices.exe"Added by the AGENT.AFIF WORM!"
XSystem Device Versionsystemdv.exe"Added by a variant of the RBOT WORM!"
XSystem Diagnosticssysdiag32.exe"Added by the SDBOT.GEN TROJAN!"
NSystem DLFcpqdiaga.exeCompaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
USystem DLL Resourcessysdll.exe"SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself"
XSystem Doctor Freesystemdoc.exe"SystemDoctor rogue security software - not recommended
XSystem Document Applicationnmod.exe"Added by the SDBOT-ABB WORM!"
XSystem Document Applicationmsdocument.exe"Added by the RANDEX.COX WORM!"
XSystem Document Applicationwins.exe"Added by the SDBOT.AUB WORM!"
XSystem Document Applicationwinsvc32.exe"Added by the SDBOT-VA WORM!"
XSystem Download ManagerSysMgr.exe"Added by the RBOT.CIG WORM!"
XSystem driverMessenger.exe"Added by the WOOTBOT.GI WORM!"
XSystem Driverswingmt.exe"Added by the SDBOT-MG WORM!"
XSystem Driverscpsq32.exe"Added by the SDBOT.AXH WORM!"
XSystem Driverssysdrv32.exe"Added by the AGOBOT-ZX WORM!"
XSystem Efficiency Monitormscedit32.exe"Added by the SDBOT.P TROJAN!"
XSystem Efficiency Monitormscommand.exe"Added by the KWBOT.P WORM!"
XSystem Efficiency Monitormsedit32.exe"Added by the STEPH-B WORM!"
XSystem Efficiency Monitorsvchostx.exe"Added by the KWBOT.E WORM!"
XSystem Error Notificationsenr32.exe"Added by the POISON-BT TROJAN!"
XSystem Event Managersecsvc.exe"Added by the RBOT.BMY WORM!"
XSystem Executable DLL LibraryEXECDLL32.exe"Added by the RANDEX.AZ WORM!"
XSystem Failure Statisticcnstat.exe"Added by the RBOT-LF WORM!"
XSystem File Driversnvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
XSystem File Startupsys32.exe"Added by the RBOT.OTL WORM!"
USystem Files UpdaterSystem Files Updater.exe"System Files Updater from Flyakiteosx ""will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"""
Xsystem firewallmakeini32.exe"Added by the AGOBOT-PS WORM!"
XSystem Firewallsysfirewall.exe"Added by the AGOBOT-ACY WORM!"
XSystem Firewallscommandprompt32.exe"Added by the RBOT.BJT WORM!"
XSystem Guardmhguard.exe"Added by the RBOT-AGU WORM!"
XSystem HandlerLSASS.EXE"Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process
Xsystem handlersrvhandle.exe"Added by the REDPLUT VIRUS!"
XSystem handlerPandawas.exe"Added by the BHARAT.A WORM!"
XSystem Hostscvhost.exe"Added by a variant of the RBOT WORM!"
XSystem Host Managersyshost.exe"Added by the BANWORM-C WORM!"
XSystem Host Servicesvchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XSystem Information ManagerNavcpe.exe"Added by the SDBOT-QB WORM!"
XSystem Information ManagerMsbb.exe"Added by the SLINBOT.YR BACKDOOR!"
XSystem Information Manageriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Information Managermslog.exe"Added by the DELF.AKO TROJAN!"
XSystem Information Managerno.exe"Added by the SPYBOT.NO WORM!"
XSystem Information Managersyspass.exe"Added by the SDBOT-MO WORM!"
XSystem Information Managerwin.exe"Added by the SDBOT-MU WORM!"
XSystem Information ManagerwindowsNt.com"Added by the SDBOT-ND WORM!"
XSystem Initsysteminit.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Initializationmsmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem Initializationpayload.dat"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem IPsystemip.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Kernal Supportsystem.exe"Added by the SDBOT.BWV WORM!"
XSystem Kernellsass.exe"Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
USystem LifeGuard SchedulerSlsched.exe"System LifeGuard scheduler"
XSystem Loadersystems.exe"Added by the AGOGBOT-FI WORM!"
XSystem Loadersyscfg.exe"Added by the AGOBOT-BS BACKDOOR!"
XSystem Loaderapsyst19b.exe"Added by the AGOBOT-AT BACKDOOR!"
XSystem Log Eventcsrss32.exe"Added by the AGOBOT-JI WORM!"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem Managersvchost.exe"Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystem managerSystem.exe"Added by the FORBOT-BO WORM!"
XSystem Managerwinsrv32.exeAdded by an unidentified WORM or TROJAN!
XSystem Managersysmng.exe"Added by the TAME-C WORM!"
XSystem Managersysmgr.exe"Added by the IRCBOT.AGW BACKDOOR!"
XSystem ManagerUser Documents.exe"Added by the VB.GF VIRUS!"
XSystem Managersysmngr.exe"Added by the IRCBOT.BAQ BACKDOOR!"
XSystem Managerncvs32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
USystem Mechanic Popup BlockerPopupBlocker.exe"Popup blocker part of Iolo System Mechanic utility suite"
USystem Mechanic Popup StopperPopupstopper.exe"Popup stopper part of Iolo System Mechanic utility suite"
NSystem Mechanic Professional Update [Incinerator.dll]SysMech4.exe /REREG: [path] Incinerator.dll"Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
USystem Mechanic Startup GuardStartupGuard.exe"System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses
XSYSTEM MESSAGERwmisg.exe"Added by the MYTOB.ES WORM!"
XSystem Messaging QueueSMCSS.EXE"Added by a variant of the RBOT WORM!"
XSystem MessengerSYSMSG32.EXE"Added by the SPYBOT-DK WORM!"
XSystem Messenger32systgmgr32.exe"Added by the SDBOT.DF WORM!"
XSystem Microsoft Coresmc.exe"Added by the RIZO.A TROJAN!"
USystem MonitorSYSMON.EXE"Comes with some Aopen motherboards. Monitors CPU temp
XSystem MonitorSysmon16.exe"Added by the SDBOT TROJAN!"
XSystem Monitoringcute.exe"Added by the RAHIWI.A WORM!"
XSystem MonitoringMooks.EXE"Added by the BHARAT.A WORM!"
XSystem Monitoringlsass.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XSystem MScvbmscvb32.exe"Added by the SOBIG.C WORM!"
XSystem Netsys32.exe"Added by the FORBOT-FX WORM!"
XSystem Net Databasesysnd.exe"Added by the RBOT-AAW WORM!"
XSystem Networkingsysnet.exe"Added by the RBOT.API WORM!"
XSystem Power Managmentsvcnost.exe"Added by the DREF-I WORM!"
XSystem Presets[temp name].exe"Added by the HOSTINF-A WORM!"
XSystem Processcsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processsvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem ProcessCSRSR.exe"Added by the AGOBOT-SQ WORM!"
XSystem Process Analizationsysproc.exe"Added by a variant of the RBOT WORM!"
XSystem Process Analization Threadsystem.exe"Added by a variant of the RBOT WORM!"
XSystem ProfileRegsrv.exe"Added by a variant of the OPTIX TROJAN!"
XSystem Protectorlsascs.exe"System Protector rogue security software - not recommended
XSystem RAID Managerraid64.exe"Added by the AGENT-NNZ TROJAN!"
XSystem Rebootrebootsys.exe"Added by the RBOT-WU WORM!"
XSystem Redirectsysbho.exe"Downloader trojan
XSystem Registry Managersysrgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
XSystem Restoresvcnet.exe"Added by the TIBICK WORM!"
XSystem Restore Data[path] repcale.exe [path] beird.exe"Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
XSystem Scannersystem.exe"Added by the AGOBOT-DI BACKDOOR!"
XSystem Security Checkerssc.exe"Added by the IRCBOT-WI TROJAN!"
XSystem Security Updatersvsmons.exe"Added by the RBOT-OW WORM!"
XSystem ServiceMSREXE.EXE"Added by the AML TROJAN!"
Xsystem servicespoolcrv.cplAdded by the INSPIR.11 TROJAN!
XSystem Servicesystems.exe"Added by the AGOBOT.VZ WORM!"
XSystem Servicecoderxt.exe"Added by the RBOT-ALD WORM!"
XSystem Serviceexp0lrer.exe"Added by a variant of the RBOT WORM!"
XSystem Serviceservicent.exe"Added by the RBOT-AJI WORM!"
XSystem servicesystem.exe"Added by the BANCOS.AA TROJAN!"
XSystem Servicemsnwindows.exe"Added by the SPYBOT.YCL WORM!"
XSystem Serviceservicez.exe"Added by the RBOT-AOY WORM!"
XSystem Servicemsnxpexe.exe"Added by the RBOT-AUA WORM!"
XSystem Serviceteskmangr.exe"Added by the RBOT-AUV WORM!"
XSystem Servicebackup.exeAdded by the PACKBOT.AA WORM!
XSystem Serviceserious.exe"Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF)"
XSystem Serviceb4db0yz.exe"Added by the RBOT-CLO WORM!"
XSYSTEM service helpersvchelper.exe"Added by the MONKBD-A WORM!"
XSYSTEM service helpersyshelp.exe"Added by a variant of the MONKBD-A WORM!"
XSystem Service Managerlsmas.exe"Added by the AGOBOT-IK BACKDOOR!"
XSystem Service Managernorton.exe"Added by the GAOBOT.AJE WORM!"
XSystem Service Manager Devicesvho.exe"Added by the RBOT.GCG BACKDOOR!"
XSystem service**pokapoka**.exe"EliteBar adware - where ** represents the numbers 61 to 79"
XSystem service78[path to file]"Added by the ELITEBAR-T and ELITEBAR-U TROJANS!"
XSystem service79[path to file]"Added by the ELITEBAR-V TROJAN!"
XSystem Services[random file name]"Added by a variant of the RBOT WORM!"
XSystem Servicesconnection.exeAdded by an unidentified WORM or TROJAN!
XSystem Servicessvcsenes.exe"Added by a variant of the RBOT WORM!"
XSystem Servicessvcsenes32a.exe"Added by the RBOT-AFG WORM!"
XSystem Servicesssms.exe"Added by a variant of the RBOT WORM!"
XSystem Services Monitorserver.exe"Bifrost malware"
XSystem Servlcelive.exe"Added by the IRCBOT-GX WORM!"
XSystem Session Managersmss.exe"Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XSystem settingsburndl32.exe"Added by the SDBOT-ZO WORM!"
XSystem Setuprpcxcmod.exeAdded by an unidentified WORM or TROJAN!
XSystem Soap Prosoap.exe"System Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoided"
Xsystem spoolsyspools.exe"Added by the DREF-T WORM/VIRUS!"
XSystem Spooler Subsystemlssas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
USystem startupcharmapx.exeOnly required if using an oriental language
XSystem StartupVoltio.exe"Added by the RBOT.NJ WORM!"
XSystem Startupkimochi.exe"Added by a variant of the RBOT WORM!"
XSystem Startupsys.exe"Added by a variant of the IRCBOT TROJAN!"
XSystem Startup Managersmcss.exe"Added by the RBOT.AMD WORM!"
XSystem StatsSystemStats.exe"Added by a variant of the WOOTBOT WORM!"
XSystem Supportsyscfg.exe"Added by the RBOT-AGQ WORM!"
XSystem Supportsystem32.exe"Added by the RBOT-AHA WORM!"
XSystem Supportsyssql.exe"Added by the RBOT-AUH WORM!"
XSystem Supporttorrent.exe"Added by a variant of the RBOT WORM!"
XSystem Task Managertaskmrg.exe"Added by a variant of the SPYBOT WORM! See here"
XSystem TerminalSYSTEM2.EXE"Added by the SPYBOT-BZ TROJAN!"
XSystem time updatorCSysTime.exe"Added by the RANDEX.S WORM!"
Xsystem toolsysguard.exe"Antivirus System Pro rogue security software - not recommended
XSystem ToolkitSystools.exe"Added by the RONOPER-G WORM!"
XSystem Traymsccn32.exe"Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process"
XSystem Traysystray.exe"Added by the FAN-A WORM! Note - the valid Microsoft systray.exe is normally located in %System% and will only run at startup on Win9x/Me systems. This one is located in %Windir%"
XSystem Tray Monitortray.exe"Added by the RBOT.UXR WORM!"
XSystem Tray Servicesspooles32.exe"Added by the AGOBOT.ZH WORM!"
XSystem Tray32SysTray32.exe"Added by the REPAD WORM!"
XSystem Unixsyscfg32.exe"Added by the RBOT-ZD WORM!"
Xsystem updataupdata.exe"Added by the LINEAGE-C TROJAN!"
XSystem Update[filename].exe"CoolWebSearch parasite variant"
XSystem Update[random filename]"Added by the KORGO.W or KORGO.X WORMS!"
XSystem Updatewupdmgr.exe"Added by the SOROMO-A TROJAN!"
XSystem Update[random filename]"Added by the SOROMO-A TROJAN!"
XSystem Updatewauluclt.exe"Added by the SDBOT.EF WORM!"
XSystem Update[path to trojan]"Added by the AUTOTROJ-D TROJAN!"
XSystem Updatemssetupconf.exe"Added by the RBOT.DLC WORM!"
XSystem Update Applicationmsbuffer.exe"Added by the SDBOT.AFF WORM!"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystem Update Servicewinupd32.exe"Added by the ADTODA-A TROJAN!"
XSystem Update Servicesystem.pif"Added by the RBOT-ALL WORM!"
XSystem Update Serviceupdate.pif"Added by the SPYBOT.WOE WORM!"
XSystem Update Servicewmiprvsv.exe"Added by the AGOBOT.YG WORM!"
XSystem Update Servicecsrss32.exe"Added by the AGOBOT-HI WORM!"
XSystem Update2explorer.exe"Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSystem Update2services.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XSystem Update2svchost.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSystem Update2system.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2taskman.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2taskmon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate Win98/Me file of the same name which is located in %Windir% as this version is located in %System%. It is not normally found on a WinXP system"
XSystem Update2update.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2webcheck.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2winlogon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process
XSystem Update2winspool.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2wupdmgr.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updatedsvchoes.exe"Added by the RBOT-ASF WORM!"
XSystem Updater Machinecrhwss.exe"Added by the CIADOOR-DQ TROJAN!"
XSystem Updater Machinesystem.exe"Added by the CIADOOR.GN BACKDOOR!"
XSystem Updater Processwmiprvsw.exe"Added by the AGOBOT-IL WORM!"
XSystem Updater Servicewmiprvsw.exe"Added by the GAOBOT.AFC WORM!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem Updatesszwi.exe"Added by the RBOT-AXE WORM!"
XSystem Updatesunve.exe"Added by the RBOT-AWG TROJAN!"
XSystem Updateswmkl.exe"Added by the RBOT-AYJ WORM!"
XSystem Updates 4mssysfix.exe"Added by the RBOT-ADU WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XSystem Updates Serviceupdates.pif"Added by the RBOT-AMA WORM!"
XSystem Uptime ServerSYSENTRY.EXE"Added by the RBOT.LK WORM!"
XSystem Uptime ServerSYSENTRY32.EXE"Added by the RBOT.LK WORM!"
Xsystem xpacdsee demo.exe"Added by the SALGA.A WORM!"
XSystem-Configmsptmf32.com"Added by the LIOTEN.FA WORM!"
XSystem-ServiceEXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
XSystem-Statsystats.exe"Added by the SDBOT.RA WORM!"
Xsystem.system..exe"Added by the OPTIXPRO.13.C TROJAN!"
Xsystem...system...exe"Added by the OPTIXPRO.13.C TROJAN!"
XSystem.exeSystem.exeAdded by various WORMS and TROJANS!
Xsystem.exesystem.exe"Added by the JAMPORK.E WORM!"
Xsystem.exesystem.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %WINDIR%\pchealth\helpctr\binaries"
XSystem132Csrtss.exe"Added by the LANFILT-I TROJAN!"
Xsystem16system16.exe"Added by the BANCBAN-OB BACKDOOR!"
Xsystem23notPad.exe"Added by the ESTEEMS.D TROJAN!"
XSystem32system.exe"Added by the BUSHTRO122 TROJAN!"
XSystem32System32.exeAdded by any number of WORMS or TROJANS!
USystem32sysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
XSystem32"system321.exe"
Xsystem32NeT-BoT.exe"Added by the AGOBOT-LJ WORM!"
XSystem32lsasss.exe"Added by the RBOT-XW WORM!"
XSystem32crsvvc.exe"Added by the RBOT.BLY WORM!"
Xsystem32QQGame.exe"Added by the QQPASS-AC TROJAN!"
XSystem32[worm filename]"Added by the NAUTICAL-A WORM!"
XSystem32winds32.exe"Added by the DWNLDR-HFY TROJAN!"
XSystem32csrss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
Xsystem32lowinplay.exe"Added by the VB.FVJ TROJAN!"
USystem32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XSystem32svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XSystem32 PCI Managersyspci32.exe"Added by the RBOT-AFR WORM!"
XSystem32 Runtime StartUpsysrs.exe"Added by the AGOBOT.ANW WORM!"
XSystem32 Spoolwinint.exe"Added by the FORBOT-N WORM!"
XSystem32 TCP Managersystcpm.exe"Added by a variant of the RBOT WORM!"
XSystem32 TCP Managersysterm.exe"Added by the RBOT.AFD WORM!"
XSystem32 Temp Servicesystmp.exe"Added by the RBOT-AET WORM!"
XSystem32-Drivercsrs32.exe"Added by the SDBOT-CP BACKDOOR!"
Xsystem32.dllsysteminit.exe"CoolWebSearch parasite variant - re-directing to your-search.info"
Xsystem32.dllsysdll32.exe"CoolWebSearch parasite variant. Redirecting to wholeworldmarket.com
Xsystem32.exeservices32.exe"Added by a variant of the IRCBOT TROJAN!"
Xsystem32.exesystem32.exe"Added by the GRAYBIRD.P TROJAN!"
XSystem32BLSJ AgentSystem32BLSJ.exe"Added by the MDROP-BPT TROJAN!"
XSystem32Check[random].exe"Added by the CHAST-A TROJAN!"
XSystem32DllDLL32SYS.EXE"Added by the SPYBOT-CZ WORM!"
XSystem32ExSystem32Ex.exe"Added by the IRCCONTACT TROJAN!"
USystem32kfvwsysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
XSystem32RootGadu-Gadu.exe"Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu"
Xsystem32WXBP Agentsystem32WXBP.exe"ARDAMAX.HR spyware"
XSystem33FB_PNU.EXE"Added by the NICHELLO-A WORM!"
Xsystem34.exesystem34.exe"Added by the DWNLDR-FXY TROJAN!"
XSystem4224411Virus"Added by the CAGER.A WORM!"
XSystem4224411Systemdll.exe"Added by the YUSUFALI-B WORM!"
Xsystem43.exesystem43.exe"Added by a variant of the SDBOT WORM!"
XSystem51616msnmsgesser.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
XSystem64inet.exe"Added by the DENGLE-A TROJAN!"
XSystemAdministrationWincmp32.exe"Added by the ASYLUM TROJAN!"
USystemAgentSage.exe"""Microsoft Plus! System Agent automatically tunes your system
XSystemArmorSystemArmor.exe"SystemArmor rogue security software - not recommended
XSystemBMessengerStopper.exe"MessStopper adware"
Xsystembsystemb.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemBackupmtx.exe"Added by the MTX VIRUS/WORM!"
XSystemBackupMicroLog.exe"Added by the MICROLOG.A TROJAN!"
XSystemBooster2009sbr_updater.exe"SystemBooster2009 rogue system suite - not recommended
?SystemBootladies.htm"Unknown but sounds very suspicious??"
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
XSystembootmsnsngr.exe"Added by a variant of the RBOT WORM!"
XSystemCheckSystemcheck.exe"Added by the LAVITS WORM!"
XSystemCheckservices.exe"Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system"
XSystemChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemCheckSysCheckBop32.exe"WINBO adware"
USystemchecksb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XSystemCheckerSyschk.exe"Added by the GALIL.F WORM!"
XSystemCleanerClean2.exe"Added by the AUTORUN-AZE WORM!"
XSystemCleanerPROsysclpro.exe"SystemCleanerPro rogue security software - not recommended
XSystemCONF98iSystemCONF98i.exe"Added by the GLITCH TROJAN!"
XSystemCopSystemCop.exe"SystemCop rogue security software - not recommended
XSystemDataMBlocker.exe"Messenger Blocker rogue security software - not recommended"
XSystemDebugSysdeb32.exe"Added by the SYSBUG TROJAN!"
XSystemDefenderSystemDefender.exe"SystemDefender rogue spyware remover - not recommended
XSystemDevicdevic.exe"Added by the MIMBOT.A WORM!"
XSystemDllSystemDll.exe"Added by the LOXOSCAM TROJAN!"
Xsystemdll.dllwinsys32.exe"Added by the DELF.CP BACKDOOR!"
Xsystemdll32.exesystemdll32.exe"Added by the FEUTEL-F TROJAN!"
XSystemDoctor 2006 Freesd2006.exe"SystemDoctor rogue security software - not recommended
XSystemDoctor Freesystemdoc.exe"SystemDoctor rogue security software - not recommended
XSystemDrivemaxpaynow1.exe"Added by the TIBS.BKU TROJAN!"
XSystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
XSystemDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
Xsystemdrvms32sys.exe"Added by an unidentified WORM or TROJAN - most likely GAOBOT variant"
XSystemEmergency[various filenames]"CoolWebSearch Smartsearch parasite variant"
XSystemErrorFixerSysRep.exe"SystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XSystemExplorerexplore.exe"Homepage hijacker - file located in the ""Services"" folder in Common Files"
XSystemeysystemey.exe"Added by the SLINBOT.JF BACKDOOR!"
XSystemFighterSystemFighter.exe"SystemFighter rogue security software - not recommended
XSystemFileSystemFile.exe"Added by the DULLDOOR-A TROJAN!"
XSystemFTPVSENMB.exe"Malware (ie
XSystemGentCVT.exe"Added by the BRONTOK-H WORM!"
Xsystemguardsystemguard.exe"System Guard 2009 rogue security software - not recommended
?SystemGuardAlerterSystemGuardAlerter.exe"Part of the Iolo System Mechanic maintenance software. What does it do?"
XSystemGuardCenterSystemGuardCenter.exe"System Guard Center rogue security suite - not recommended
XSystemHelp"RUNDLL32.EXE SystemHper.dllInstall"
XSystemInitiservc.exe"Added by the FIZZER WORM!"
Xsysteminitsysteminit.exe"Added by the SILLYFDC-AN WORM!"
XSystemiom UpdaterSystemiom.exe"Added by the SPYBOT.TY WORM!"
XSystemIronSystemIron.exe"SystemIron rogue security software - not recommended
Xsystemkernal.exesystemkernal.exe"Added by the AGENT-KPQ TROJAN!"
USystemKeyrundll32.exe [path] SystemKey.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSystemLoad32sysload32.exe"Added by the MIMAIL.E WORM!"
XSystemLoadersysldr32.exe"Added by the DOWNLDR-NS TROJAN!"
XSystemManagerSysman32.exe"Added by the DOWNLOADER-BW.B TROJAN!"
XSystemManager[random filename]"Added by the SETTEC ROOTKIT!"
XSystemMap32Netisp32.vbs"Added by the REDIST.C WORM!"
XSystemMDmd.exeHomepage hijacker
XSystemMessengerrundll32.exe [path] SystemMessenger.dll"Stealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSystemMgrIr32_a.exe"Added by the MAGANIA-OU TROJAN!"
XSystemMigrationWinMedia.exe"Added by the KELVIR.EI WORM!"
XSystemMonitorSysmon32.exe"Added by the AIDID.A WORM!"
XSystemNetworkNETSERV.EXEAdded by the NETCONTROL VIRUS!
XSystemNetworksysnet.exe"Added by a variant of the RBOT WORM!"
XSystemNTSystemNT.exe"Added by the PWSVB-EG TROJAN!"
XSystemOPsvscrtvc32.exe"Added by a variant of the SPYBOT WORM!"
XSystemOptimizer2008main.exe"SystemOptimizer2008 rogue optimization utility - not recommended
XSystemOrdnareSysRep.exe"SystemOrdnare
XSystemProcEvent[trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
Xsystemrd11host.exe"Added by the VB-GX TROJAN!"
Xsystemrgedit.exe"Added by the ADCLICK-AQ TROJAN!"
?SystemRegPROCES.EXE"??"
XSystemRegsvchost.exe"Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemRegWINREG.EXE"Added by the DEWIN.A TROJAN!"
XSystemsscchost.exe"Added by the DAEMOZ.A TROJAN!"
XSystemssvch0st.exe"Added by the MYDOOM.BI WORM!"
XSystemsSystems.exe"Added by the BANKBOA-A TROJAN!"
XSystemsitDDD.exe"Added by the DLOADER-PP TROJAN!"
XSystemssescmgr.exe"Added by the DWNLDR-GAH TROJAN!"
XSystemsspoolsvc.exe"Added by the DLOADR-SW TROJAN!"
XSystemssysmon.exe"Added by the VIXUP-BI WORM!"
XSystems Backupswindrives.exe"Added by the AGOBOT-RB WORM!"
XSystems Restartslchost.exe"Added by the MULTIDROP.C TROJAN!"
XSystems Restartspchost.exeAdded by an unidentified WORM or TROJAN!
XSystems Restart"Rundll32.exe beem.dll DllRegisterServer"
XSystems Restart"Rundll32.exe snim.dll DllRegisterServer"
XSystems Restart"Rundll32.exe zolk.dll DllRegisterServer"
XSystems Restart"Rundll32.exe boln.dll DllRegisterServer"
XSystems Servicedrivex.exe"Added by a variant of the RBOT WORM!"
Xsystems usb driverWindows2.exe"Added by a variant of the RBOT WORM!"
USystems.exeSystems.exe"Keyboard Spectator - monitoring software that creates records of everything people do on a computer
Usystems.exesystems.exe"KGBSpy is a commercial surveillance software program. It logs keystrokes
USystemSafeSyssafe.exe"System Safety Monitor - system monitoring tool with additional application firewalling"
XSYSTEMSars32csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemSASSystem32.exe"Added by the KWBOT.C WORM!"
Xsystemscrootsystembin.exe"Added by a variant of the RBOT WORM!"
XSystemSearchregedit.exe -s ie.reg"Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""ie.reg"" is located in the root folder (ie
XSystemSearchregedit.exe -s sys.reg"Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
XSystemSecurityzprot32.exe"Added by the AGENT-FK TROJAN!"
XSystemServicemsocfg.exePremium rate adult content dialler
XSystemServicenavchk.exePremium rate adult content dialler
XSystemServiceqservice.exePremium rate adult content dialler
XSystemServiceshman.exePremium rate adult content dialler
USystemServicensserver.exe"NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSystemSettingfTRUG.vbs"Added by the TRUG.B MACRO!"
USystemSuite Task ManagerMXTASK.EXE"vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro"
XSystemSv12newmaxxsv234.exe"Added by the TIBS-TS TROJAN!"
XSystemSv121n2ewma1xxsv234.exe"Added by the TIBS.TJ TROJAN!"
XSystemTasksfilez.exeAdult content dialler
XSystemTaskssexypicz.exeAdult content dialler
XSystemTasksloaded.exeAdult content dialler
XSystemToolskernels32.exe"Added by the DLOADER-FC TROJAN!"
XSystemToolskernels1118.exe"Added by the SMALL.DGK TROJAN!"
XSystemToolskernels8.exe"Added by the FNG TROJAN!"
XSystemToolskernels88.exe"Added by the TIBS-PP TROJAN!"
XSystemToolstesttestt.exe"Added by the DWNLDR-ZLC TROJAN!"
XSystemtraSystra.exe"Added by the LOVGATE-W WORM!"
XSystemTraCDPlay.EXE"Added by the LOVGATE.Z WORM!"
XSystemTraVideo.EXE"Added by the LOVGATE.E WORM!"
USystemTraySysTray.Exe"For Win9x/Me - System Tray Services. Provides the Volume Control
XSystemTraySystemTray.exe"Added by the BIGFOOT TROJAN! Note - this is not the legitimate systray.exe process"
XSystemTraySysTray.exe"Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
XSystemTraylsvhostwinlk.exe"Added by a variant of the SPYBOT WORM!"
XSystemTraymssgl2.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemTraywekls4.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemTrayWindowsupd.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemTray MonitorSysTraymon.exe"Added by a variant of the SPYBOT WORM! See here"
USystemTraySDSDSystemTray.exe"Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
USystemTraySRSRSystemTray.exe"Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
XSystemTunerSystemTuner.exe"System Tuner rogue system suite - not recommended
NSystemUpdSystemUpd.exe"Updater for Swapoo.com
XSystemUpdateNegdo.exe"Added by the CULLER-C WORM!"
XSystemUpdateXeyu.exe"Added by the CULLER-D WORM!"
XSystemVeteran.exeSystemVeteran.exe"SystemVeteran rogue security software - not recommended
Xsystemw32systemw32.exe"Added by a variant of the RBOT WORM!"
XSystemWarriorSystemWarrior.exe"SystemWarrior rogue security software - not recommended
USystemWebrundll32.exe [path] SystemWeb.dll rdl"StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSystemWideHook for Windows NT%WinHook32.exe"Added by the MYDOOM.AC WORM!"
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
USystemWizard SnifferSniffer.exe"SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC"
XSystemXnzm.exe"Added by a variant of the RBOT WORM!"
Xsystemx32systemx32.exe"Added by a variant of the RBOT WORM!"
Xsystemyom Updatersystemyom.exe"Added by a variant of the IRCBOT TROJAN!"
XSYSTEMZ PatchSYSZ.exe"Added by the ALADINZ.P TROJAN!"
USystem_Messagespprsen.exe"TerminatorX - ""offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA
XSysTraysystem.exe"Added by the DELF.E TROJAN!"
Xsystraysystem234.exe"Added by the AUTORUN.AEV WORM!"
XTaskbar Systemtasksys.exe"Added by a variant of the SDBOT WORM!"
XTaskmgrsystem.exe"Added by the PAKES.G TROJAN!"
YThinkVantage Active Protection SystemTpShocks.exe"Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T
XTorrent Management Servicesystem32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XTray manager systemtraysys.exe"Added by the RIZO.A TROJAN!"
XTSystem[trojan filename]"Added by the NSYS-A TROJAN!"
XTurBoSystem.Trubo.vbs"Added by the AUTOM-C WORM!"
XTweak SystemGenderowo.exe"Added by the SILLYFDC WORM!"
XUltimate System GuardMainFAVProj.exe"Ultimate System Guard rogue security software - not recommended
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
Xuserdsystems.com"Added by the OUTLAW-A WORM!"
XUserSystem[filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
YWarning: do not remove it! (system)cfpsys.exe"Folder Password Protect - a program that lets you set a password on folders of your choice"
XWDNS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
XWDNS SYSTEMskybotx.exe"Added by the MYTOB-BY WORM!"
XWDNS SYSTEMwdns33.exe"Added by the MYTOB-BY WORM!"
XWIN USB 2.0usbsystem.exeAdded by an unidentified WORM of TROJAN!
XWin32system32.vbs"Added by the SWERUN VIRUS!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWin32 System Spoolspoolsvc.exe"Added by the SDBOT.UK WORM!"
Xwin32servsystemdevices.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
XWin32system[random filename]"Added by the DDV.B WORM!"
XWin32Systemwin32s.exe"Added by the MYDOOM.V WORM!"
XWin32SystemMonitor***.exe [* = random char]Browser hijacker
XWIN32WNsystem_wc.exe"Eziin adware"
XWind River Systemsvxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
Xwindowssystem copy.exe"Added by the SALGA.A WORM!"
XWindowssystem.exe"Added by the SPYBOT.OBB WORM!"
XWindows Activate Systemsyssv.exe"Added by a variant of the SPYBOT WORM!"
XWindows Audio Systemnndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows BootupSystemwks32.exe"Added by a variant of the RBOT WORM!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows Drive CompatibilitySystem32Driver32.exe"Added by the SUPOVA.Z WORM!"
XWindows Explorersystem32.exe"Added by the RBOT-AJH WORM!"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
?Windows Help SystemHelp.pif"??"
XWindows Hijack Protection Systemcommngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
XWINDOWS ID SYSTEMwID32.exe"Added by the MYTOB.LN WORM!"
XWindows Kernel System Servicewkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Netsystem LayerNetsystem.exe"Added by the RBOT.BEI WORM!"
XWindows Rescue Systemwinsto.exe"Added by the SUURCH.CG TROJAN!"
Xwindows runsystem.exe"Added by the ICPASS-A WORM!"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Services Ink Platform Tablet Input Subsystemwsiptis.exe"Added by the RBOT.APC WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XWINDOWS SYSTEMbeta.exe"Added by the MYTOB.DF WORM!"
XWINDOWS SYSTEMdcomuser.exe"Added by the MYTOB.EO WORM!"
XWINDOWS SYSTEMlf66prc.exe"Added by the MYTOB.GC WORM!"
XWINDOWS SYSTEMmsdev32.exe"Added by the MYTOB.EH WORM!"
XWINDOWS SYSTEMnec.exe"Added by the MYTOB-L WORM and variants!"
XWINDOWS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMninfoie.exe"Added by the MYTOB-EP WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB-CX WORM!"
XWINDOWS SYSTEMskybotx.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMsmoc.exe"Added by the MYTOB.FU WORM!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWINDOWS SYSTEMtest.exe"Added by the MYTOB.DJ WORM!"
XWINDOWS SYSTEMtest2.exe"Added by the MYTOB.DJ WORM!"
XWINDOWS SYSTEMtest3.exe"Added by the MYTOB.DV WORM!"
XWINDOWS SYSTEMwdns33.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMwin.exe.exe"Added by the MYTOB.FA WORM!"
XWINDOWS SYSTEMwinaup.exe"Added by the MYTOB-DN WORM!"
XWINDOWS SYSTEMwinligon.exe"Added by the MYTOB.EP WORM!"
XWINDOWS SYSTEMwinmon.exe"Added by the MYTOB.GB WORM!"
XWINDOWS SYSTEMwinNTsys32.exe"Added by the MYTOB-DM WORM!"
XWINDOWS SYSTEMwinsvc32.exe"Added by the MYTOB.HH WORM!"
XWindows SystemWINSYS.exe"Added by the RBOT-AEF WORM!"
XWINDOWS SYSTEMwinsys33.exe"Added by the MYTOB.EK WORM!"
XWINDOWS SYSTEMwinvnc.exe"Added by the MYTOB.EU WORM!"
XWINDOWS SYSTEMwinxpserv.exe"Added by the MYTOB-BQ WORM!"
XWINDOWS SYSTEMxxx.exe"Added by the MYTOB.CZ WORM!"
XWindows Systemwinsys32.exe"Added by the MYTOB-IS WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB.JU WORM!"
XWINDOWS SYSTEMbotzor.exe"Added by the ZOTOB WORM!"
XWINDOWS SYSTEMgothica.exe"Added by the MYTOB.HU WORM!"
XWINDOWS SYSTEMmsnl.exe"Added by the MYTOB.IK WORM!"
XWINDOWS SYSTEMper.exe"Added by the ZOTOB.C WORM!"
XWINDOWS SYSTEMtwunk_65.exe"Added by the MYTOB-EG WORM!"
XWINDOWS SYSTEMservce.exe"Added by the MYTOB-EI WORM!"
XWINDOWS SYSTEMservises.exe"Added by the ZOTOB-I WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMexpI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
XWINDOWS SYSTEMmsn32.exe"Added by the MYTOB-FX WORM!"
XWINDOWS SYSTEMsky.exe"Added by the MYTOB.LB WORM!"
XWINDOWS SYSTEMWin32IMAPSVR.exe"Added by the MYTOB-FQ or MYTOB-FU WORMS!"
XWINDOWS SYSTEMwinsvc.exe"Added by the MYTOB.LM WORM!"
XWINDOWS SYSTEMmswins.exe"Added by the MYTOB.DP WORM!"
XWINDOWS SYSTEMmtrnqs.exe"Added by the MYTOB.IG WORM!"
XWINDOWS SYSTEMlogic.exe"Added by the MYTOB.IC WORM!"
XWINDOWS SYSTEMctech.exe"Added by the MYTOB-KD WORM!"
XWINDOWS SYSTEMefefefe.exe"Added by the MYTOB-KH WORM!"
XWINDOWS SYSTEMsvchost2.exe"Added by the MYTOB.OZ WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB.EB WORM!"
XWINDOWS SYSTEMwupdate.exe"Added by the MYTOB-HT WORM!"
XWindows Systemsystem.exe"Added by the MYTOB-GN WORM!"
XWindows System 32winsys_32.exe"Added by the RBOT-FTR WORM!"
XWindows System 32-Bat Servicewin32bat.exe"Added by the MYTOB.FI WORM!"
XWindows System BackupSysBackup.exeUnidentified malware
XWINDOWS SYSTEM By FEnRwindasz-updote.exe"Added by the MYTOB.LR WORM!"
XWINDOWS SYSTEM Cleanerh3.exe"Added by the MYTOB.EQ WORM!"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System ConfigurationWinfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System DefenderWS[random characters].exe"Windows System Defender rogue security software - not recommended
XWINDOWS SYSTEM Dnswindsns.exe"Added by the MYTOB.EY WORM!"
XWINDOWS SYSTEM DNSPOOLhbmail.exe"Added by the MYTOB.FW WORM!"
XWindows System Driverssysretain.exe"Added by the SLENFBOT.BY WORM!"
XWindows System Filecmxp.exe"Added by the SPYBOT.KHO WORM!"
XWINDOWS SYSTEM FILEwinload.exe"Added by the MYTOB.DK WORM!"
XWindows System GatewaySPOOLER.EXE"Added by a variant of the RBOT WORM!"
XWindows System Guardegun.exe"Added by the AGENT-NHY TROJAN!"
XWindows System Guardmsdn.exe"Added by the FAKEAV-BJD TROJAN!"
XWindows System Guardmsng.exe"Added by the EGGDROP-BO WORM!"
XWindows System Guardmsns.exe"Added by the DWNLDR-IGD TROJAN!"
XWindows System Initwinit32.exe"Added by a variant of the RBOT WORM!"
XWindows System Managerwinsystem.exe"Added by the RBOT-AN WORM!"
XWindows System ManagerCRSL.EXE"Added by the SDBOT.MG WORM!"
XWindows System Managersysconf.exe"Added by the MYTOB.AL WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWindows System Managercrssm.exe"Added by the RBOT-AFH WORM!"
XWINDOWS SYSTEM MANAGERspoolsvc.exe"Added by the MYTOB-LY WORM!"
XWindows System Managerwinsysmgr.exe"Added by the IRCBOT.BJG BACKDOOR!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWindows System Manager Procwinsmc.exe"Added by the RBOT.JH WORM!"
XWINDOWS SYSTEM MEMORY LOADERmemloader.exe"Added by the MYTOB-IN WORM!"
XWINDOWS SYSTEM mscdvvsmscdvvs.exe"Added by the MYTOB.MD WORM!"
Xwindows system notepadwnpsm.exe"Added by a variant of the RBOT WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System RestorerSystemRestorer.exe"Added by the DULOAD.C WORM!"
XWINDOWS SYSTEM SCALPEscalpe91.exe"Added by the MYTOB-HI WORM!"
XWindows System Securitywinmp.exe"Added by the RBOT.IV WORM!"
XWindows System Securitysys32.pif"Added by the RBOT-AOL WORM!"
XWindows System Security Monitor[4 random letters].exe"Added by the PINKTON.A WORM!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
Xwindows system servicewinsock.exe"Added by the RBOT-MR WORM!"
XWindows System Servicewnuserv.exe"Added by the SPYBOT.ANDM WORM!"
XWindows System Service[worm filename]"Added by the RBOT.XG WORM!"
XWindows System SuiteWS[random characters].exe"Windows System Suite rogue security software - not recommended
UWindows System Traymsni.exe"Iambigbrother monitoring software"
XWindows System Trayswhost.exe"Added by an unidentified VIRUS
XWINDOWS SYSTEM UPDATExDcc.exe"Added by the MYOTB-EH WORM!"
XWindows System Update Toolsupds.exe"Added by the VANBOT.CX BACKDOOR!"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows System32windowsp.exe"Added by the MYTOB.GD WORM!"
XWindows System32winsys32.exe"Added by the SDBOT-AHS WORM!"
XWindows System32clsas32.exe"Added by the RBOT-AZO WORM!"
XWindows System32explorer.exe"Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
XWindows System32System32.exe"Added by the SDBOT-ALI WORM!"
XWindows SYSTEM32Realplayer.exe"Added by the SPYBOT.ZH WORM!"
XWindows System32wingrd32.exe"Added by a variant of the RBOT WORM!"
XWindows System32windows32.exe"Added by the RBOT-FPB WORM!"
XWindows System32 Driverclsass32.exe"Added by the SDBOT-AGG WORM!"
XWindows System32 Kernelsystem32.exe"Added by the SDBOT-AAT WORM!"
XWindows SystemDllSYSTEMDLL.EXE"Added by the AGOBOT-LP WORM!"
XWINDOWS SYSTEMnservicces.exe"Added by the MYTOB-EL WORM!"
XWindows Systemnmgstagmr.exe"Added by the MYTOB.S WORM!"
XWindows Systems16winjews16.exe"Added by the SDBOT-CXT WORM!"
XWindows Taskbar Systemtasksys.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Firewall Systemctfmoom.exe"Added by the RBOT-GAN WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Update Firewall Systemctfmom.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update Softwaresystem.exe"TOFGER.BX spyware"
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows-SystemSystem32.exe"Added by the LOGPOLE.C WORM!"
XWindows32system.exeUnknown malware
XWindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
XWindowsFileSystemwinsfs32.exe"Added by the RBOT-FMQ WORM!"
XWindowsFileSystemcidaemon32.exe"Added by the RBOT-FSP WORM!"
XWindowsSystem32asper.exe"Added by the AGENT-EFP TROJAN!"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XWindowsSystem32[path to worm]"Added by the SDBOT-DFG WORM!"
XWindowsSystem32msnmssgr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindowsSystem32msn_kilo.exe"Added by the AGENT.ALY BACKDOOR!"
XWindowsSystem32msnmgaer.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows_Protectwinsystem.exe"Added by a variant of the RBOT WORM!"
Xwinlogonsystem.exeAdded by a variant of the DELF.CNS TROJAN!
XWINOWS SYSTEMwinnt.exe"Added by the MYTOB.ID WORM!"
Xwinphonics7536vbsystem35.exe setups.exe vb.vb"Added by a variant of the MUTIN-C TROJAN!"
XWinsk system Loaderwinsk.exe"Added by the AGOBOT-IZ WORM!"
XWinsock2 driverSYSTEM32.EXE"Added by the SPYBOT-EG WORM!"
XWinsock32 driversystem32.exe"Added by the IRCBOT-VT TROJAN!"
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
XWinSyssystem.exe"Added by the DAPROSY WORM!"
XWinSysStartUpWKbLwTaskSystemDll.Exe"Added by the BACKZAT.G WORM!"
XWinSystemwinsystem.exe"Added by the WHITEBAIT WORM!"
UWinSystemWinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinsystemFreevideo5.EXE"Added by the AGENT.FZS WORM!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
Xwinsystems25winsystems.exe"Added by the RBOT-CNZ WORM!"
Xwinupdate2846vbsystem35.exe msvbrun.exe"Added by a variant of the MUTIN-C TROJAN!"
XWin_api_driversystem.exe"Added by the REVIRD TROJAN!"
XWorking System Analyzersyswork.exe"Added by the FORBOT-FZ WORM!"
UX1 System TrayX1Systray.exe"Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
XXP Systemsystemxp.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xxpsystemy.exe"CoolWebSearch parasite variant"
XXpsystemSERVICES.EXE"Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\SERVICES"
Xxpsystemservices.exe"CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process
XxpsystemMSXMIDI.EXE"CoolWebSearch parasite variant
Xxp_system[filename]"Added by the BOOKMARKER.J TROJAN! The file is located in %Windir%\inet20004"
Xxp_systemwinlogon.exe"Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe
Xxp_systemservices.exe"Added by the KREPPER-N TROJAN and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The one is located in a %Windir%\inet***** - where ***** varies dependent upon the variant
XYahoo Messenggersystem3_.exe"Added by the AUTORUN-AOA WORM!"
XZone systemszchost.exe"Added by the MULTIDR-AC TROJAN!"
X[Entry name]System.exe"Added by the NETHIEF-N TROJAN!"
X_SystemBootservices.exe"Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help"
X_SystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
X_System_Run_svchost_.exe"Added by the LINEAGE-Z TROJAN!"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.