Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
XBT[path to trojan]"Added by the LITEBOT-B TROJAN!"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
Xcppc[path to trojan]"Added by the VB-NV BACKDOOR!"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
Xdefender[path to trojan]"Added by the VB-BAQ TROJAN!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Xdfgfdgrergd[path to trojan]"Added by the RANKY.CK TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDisk Keeper[path to trojan]"Added by the SMALL-VE TROJAN!"
XDisk Master[trojan name]"Added by the DISTER TROJAN! - a spam relayer"
Xdown[trojan filename]"Added by the SMALL-QJ TROJAN!"
Xdrin[path to trojan]"Added by the SMALL.DPB TROJAN!"
XDSKEY[path to trojan]"Added by the STARTER-G TROJAN!"
XDSS[path to trojan]"Added by the DSSDOOR-C TROJAN!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
XGames Acceleration[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
Xgimmygames[path to trojan]"Added by the DLOADR-LN TROJAN!"
XHATAPE[path to trojan]"Added by the BANKER-QF TROJAN!"
Xhxadsec[path to trojan]"Added by the ADCLICK-AP TROJAN!"
Xibin[path to trojan]"Added by the PERDA-C TROJAN!"
XICQMsn[path to trojan]"Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XImage"rundll32 [path] [trojan filename]Install"
Ximonitor[path to trojan]"Added by the IMONI-A TROJAN!"
XInit[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInternal[trojan filename]"Added by the SMOTHER and TRANSLAT TROJANS!"
XInternat[trojan filename]"Added by the CMJSPY-Y TROJAN!"
Xinternet[trojan filename].exe"Added by the MIFENG-D TROJAN!"
XInternet Connection Wizard[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Mail and News[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
XIrwftp[path to trojan]"Added by the BANCOS-AP TROJAN!"
Xixproxy[path to trojan]"Added by the XORPIX-A TROJAN!"
Xjon315[path to trojan]"Added by the MAILBOT-BI TROJAN!"
Xjusched[path to trojan]"Added by the BANKER-BWR TROJAN!"
Xkeyboard[path to trojan]"Added by the DLOADR-AOZ TROJAN!"
Xlameshit[path to trojan]"Added by the LOWZONE-H TROJAN!"
XLanGuard[path to trojan]"Added by the DLOADER-VO TROJAN!"
Xlar[trojan filename]"Added by the ROXY.C TROJAN!"
XLetsRock[path to trojan]"Added by the RANKY.Y BACKDOOR!"
XLitebot[path to trojan]"Added by the LITEBOT-A TROJAN!"
Xloaddr[path to trojan]"Added by the AGENT-DIY TROJAN!"
Xlogin[path to trojan]"Added by the HOTWORD-A TROJAN!"
XLogo[path to trojan]"Added by the DLOADER-RH TROJAN!"
XMailBlocker[path to trojan]"Added by the AGENT-LRJ TROJAN!"
Xmdetect[path to trojan]"Added by the SPABOT TROJAN!"
XMEDIA32[path to trojan]"Added by the PURSCAN-Z TROJAN!"
XMicro Office[path to trojan]"Added by the BANCBAN-QC TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft Internet Acceleration Utility[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft standard protector[path to trojan]"Added by the STOX-C TROJAN!"
XMicrosoft WPCEmail[path to trojan]"Added by the SNIFFER-N TROJAN!"
XMicrosoft WWW[path to trojan]"Added by the AGENT-DRI TROJAN!"
XMicrosoftUpdates[path to trojan]"Added by the DELF-LO TROJAN!"
Xml34[path to trojan]"Added by the MAILBOT-BH TROJAN!"
XMS Task Manager 32[trojan filename] .exe"Added by the RANKY.NF TROJAN!"
Xmsbsc[path to trojan]"Added by the BANKER-DF TROJAN!"
XMSDNMess[path to trojan]"Added by the RANKY.BA TROJAN!"
Xmsmsgss[path to trojan]"Added by the RANKY.G BACKDOOR!"
XMspatch69[path to trojan]"Added by the MPROX TROJAN!"
Xmsresear[path to trojan]"Added by the WEASYW-B TROJAN!"
Xmssvc[path to trojan]"Added by the PSK TROJAN!"
XMultimedia extensions[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XNdpldaemon[path to trojan]"Added by the RPCSDBOT-A TROJAN!"
XNetwork Host Controller[path to trojan]"Added by the WHISPER TROJAN!"
XNetwork Security Guard[path to trojan]"Added by the COLEM-A TROJAN!"
Xnewname[path to trojan]"Added by the DRSMARTL-S TROJAN!"
XNorton Firewall[path to trojan]"Added by the BANKER-ET TROJAN!"
XNTCommLib3[path to trojan]"Added by the AGENT-AXB TROJAN!"
XNtech.patchs[trojan filename]"Added by the LEMIR.G TROJAN!"
XNTP Server[path to trojan]"Added by the RANKY.F TROJAN!"
XNTupdater[path to trojan]"Added by the DIGARIX-D TROJAN!"
XNvCp1Do[path to trojan]"Added by the DWNLDR-GWE TROJAN! The most common filename seen is ""smss.exe"" - which is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNvGraphicsInterface[path to trojan]"Added by the BCKDR-QKI BACKDOOR!"
XNVidia Drivers[path to trojan]"Added by the RANCK-R TROJAN! Note - this is not related to any nVidia based motherboard or graphics card"
XOffice Monitor Word Exel R[trojan filename]"Added by the IRCBOT-VX TROJAN!"
Xoffice_update[path to trojan]"Added by the DLOADER-ZB TROJAN!"
XPHIME2OO2ASyst[path to trojan]"Added by the DBDOOR-B TROJAN!"
XPopRock[path to trojan]"Added by the AGENT-LNU TROJAN!"
Xprunnet[path to trojan]"Added by the AGENT-HVB TROJAN!"
Xqgqqft[path to Trojan]"Added by the RANKY.T TROJAN!"
Xrawload[path to trojan]"Added by the DARKIRC.QZ TROJAN!"
XReeg_[path to trojan]"Added by the BANCBAN-AW TROJAN!"
XREGRUN[path to trojan]"Added by the LOWZONE-AH TROJAN!"
Xreseurce[path to trojan]"Added by the LINEAGE-AI TROJAN!"
Xrngmf[path to trojan]"Added by the RANKY.C TROJAN!"
XRoot_Machine[path to trojan]"Added by the BANCBAN-DI TROJAN!"
XRPCInstall[path to trojan]"Added by the AGENT-DQM TROJAN!"
XRunDll[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XRunnerlsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunOnce[path to trojan]"Added by the BANCBAN-P TROJAN!"
XRunOnce2Upd[path to trojan]"Added by the MURLO.FI TROJAN!"
XSafe[path to trojan]"Added by the BANKER-DT TROJAN!"
Xschost[path to trojan]"Added by the TJSERV.D TROJAN!"
Xscrbmk[path to trojan]"Added by the DLOADER-VP TROJAN!"
XSearchClick[trojan filename]"Added by the AGENT-DWR TROJAN!"
XService[trojan filename]"Added by the KAITEX.E TROJAN!"
Xservice32.exe[path to trojan]"Added by the DLOADR-AYX TROJAN!"
XServices[path to trojan]"Added by the METEORSHELL TROJAN!"
XServices[path to trojan]"Added by the RANCK-DB TROJAN!"
XSetup[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XShareSearcher[path to trojan]"Added by the AGENT-FPE TROJAN!"
XShutdownWithoutLjiasvt.exe[path to trojan]"Added by the BIFROSE.F BACKDOOR!"
XSomefox[path to trojan]"Added by the DWNLDR-HHB TROJAN!"
XSound[path to trojan]"Added by the DROPPER.EAT TROJAN!"
Xsp"rundll32 (Path to Trojan DLL) DllInstall"
XSpool[path to trojan]"Added by the RANKY.R TROJAN!"
Xspoolax[path to trojan]"Added by the PERDA-D TROJAN!"
Xsr64[path to trojan]"Added by the AGENT.X TROJAN!"
XSrv32 spool service[path to trojan]"Added by the DLOADER-LB TROJAN!"
Xsstata[path to trojan]"Added by the RANCK-DF TROJAN!"
Xstartemdoit[path to trojan]"Added by the DLOADR-AVP TROJAN!"
XStartUpDate[path to trojan]"Added by the BIFROSE.F BACKDOOR!"
XStreams Drivers[trojan filename]"Added by the RESTARTER.E TROJAN!"
Xstrto[path to trojan]"Added by the KILLAV-AP TROJAN!"
Xstup[path to trojan]"Added by the AGENT-CIL TROJAN!"
Xsupport-reverse-smileys[trojan filename]"Added by the LITEBOT TROJAN!"
Xsvchosd[path to trojan]"Added by the BANCOS-BCX TROJAN!"
Xsvchost[path to trojan]"Added by the HAZZER TROJAN!"
XSvcManager[path to trojan]"Added by the ZALON-A BACKDOOR!"
XSymantecFilterCheck[path to trojan]"Added by the BANKER-EIN TROJAN!"
Xsysdll[trojan filename]"Added by the HUGESOT TROJAN!"
XSySPower[path to trojan]"Added by the BANCBAN-OC TROJAN!"
XSystem Update[path to trojan]"Added by the AUTOTROJ-D TROJAN!"
XSystemProcEvent[trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
Xsystrans[path to trojan]"Added by the STARTPA-GZ TROJAN!"
XTaskManager[path to trojan]"Added by the LDPINCH-CF TROJAN!"
Xtaskmgr[path to trojan]"Added by the AGENT-ENV TROJAN!"
XTaskMon[path to trojan]"Added by the DROPPER.EAT TROJAN!"
Xtaskmrg.exe[path to trojan]"Added by the BANCBAN-BN TROJAN!"
Xtaskmsgs[path to trojan]"Added by the BANCOS-BBW TROJAN!"
XTheMonitor[path to trojan]"Added by the DLOADR-LO TROJAN!"
XTorjan Program[path to trojan]"Added by the LEGMIR-BO TROJAN!"
XTrojanTrojanS_P.exe"Added by the AGENT-CQ TROJAN!"
XTrojan Guarder Gold VersionTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
UTrojancheck 6 Guardtcguard.exe"TrojanCheck anti-trojan software"
UTrojanScannerTrjscan.exe"Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed"
XTrojansFilterpgs.exe"TrojansFilter rogue security software - not recommended. A member of the AVSystemCare family"
XTrojansFiltrepgs.exe"TrojansFiltre
UTrojanShieldInit.exe"TrojanShield"
UTrojanShield ProtectorPort.exe"TrojanShield anti-hacker/anti-trojan software"
XTrojanSimulatorTSServ.exe"Trojan Simulator security risk which simulates a trojan infection and may be used to verify whether a virus scanner can properly detect the file"
XTSystem[trojan filename]"Added by the NSYS-A TROJAN!"
XTurboNet[path to trojan]"Added by the RENOS-EA TROJAN!"
XUPNP[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XUsbD[path to trojan]"Added by the CIDRA-F TROJAN!"
XUSBHWINFO[path to trojan]"Added by the LOWZONE-I TROJAN!"
Xusbn[path to trojan]"Added by the HOGIL-C TROJAN!"
XValidData[path to trojan]"Added by the RANKY.H TROJAN!"
XVidiaDrivers[path to trojan]"Added by the RANKY.U TROJAN!"
XVirus Removal Tool[path to trojan]"Added by the TOMETA-B TROJAN!"
XvXCXssdss[path to trojan]"Added by the RANCK-BO TROJAN!"
XWeb-cameinst[path to trojan]"Added by the RANCK-BP TROJAN!"
XWheelsMouse[path to trojan]"Added by the SOCKSPR-D TROJAN!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
Xwindows[path to trojan]"Added by the AIMWIN TROJAN!"
XWindows NNT[path to trojan]"Added by the RANKY.E TROJAN!"
XWindowsFY[path to trojan]"Added by the FAKEALE-E TROJAN!"
XWindowsSetup[path to trojan]"Added by the EZBOT TROJAN!"
XWindUpdates[path to trojan]"Added by the AGENT.BF TROJAN!"
XWinLsass[path to trojan]"Added by the SCANE WORM!"
XWinMedia[path to trojan]"Added by the ZEROBE-A TROJAN!"
Xwinmngr.exe[path to trojan]"Added by the AGENT-ZB TROJAN!"
Xwinreg_32[path to trojan]"Added by the BANKER-DB TROJAN!"
Xwinshow[path to trojan]"Added by the VB-DXP TROJAN!"
XWINSYS[path to trojan]"Added by the GOLDPLAY TROJAN!"
Xwinsysban[path to trojan]"Added by the CLICKER-CD TROJAN!"
XWinSysModule[path to trojan]"Added by the AGENT-DIQ TROJAN!"
Xwinsysupd[path to trojan]"Added by the STARTPA-NI TROJAN!"
XWintelUpdate[path to trojan]"Added by the SMALL-EKW TROJAN!"
XWinUpgrader[path to trojan]"Added by the AGENT-DZ TROJAN!"
Xwinzip[path to trojan]"Added by the BANCOS.G or BANCOS.K TROJANS! Note - this is not part of the popular WinZip file compression utility"
Xwlm[path to trojan]"Added by the BANCOS-BCY TROJAN!"
Xx3yy[path to trojan]"Added by the TANNICK TROJAN!"
Xxload[path to trojan]"Added by the VB-AGP TROJAN!"
XXpAspy[path to trojan]"Added by the DELF-WH BACKDOOR!"
Xxserv[path to trojan]"Added by the STUMPY-A TROJAN!"
Xyyyyyyyy[path to trojan]"Added by the MUMUBOY.B TROJAN!"
XZagrebLand[trojan filename]"Added by the RENOS-EH TROJAN!"
XZen.A[path to trojan]"Added by the ZOOMEN-A TROJAN!"
X[trojan filename]Install.exe"Added by the BANCBAN-FS TROJAN!"
X[trojan name]svchost.exe"Added by the BANCBAN-CI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X[username] config[path to trojan]"Added by the MOSUCK-H TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to trojan]"Added by the SMALL-EP TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.