Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Note the filename has a ""0"" rather than an upper case ""o"""
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*MS Setup[random filename]"Virtumondo adware
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
XAceu[random filename]"PurityScan adware"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
Xara-key[random filename]"Added by the ANTINNY WORM!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
XcAgOu[filename].hta"Added by the KAKWORM WORM!"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
Xdown[trojan filename]"Added by the SMALL-QJ TROJAN!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xfilenfilen.exe"Added by the VBNAM-A WORM!"
Xfilenamefilename.exe"Added by the VB.FSY TROJAN!"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
XGustavVED[filename].exe"Added by the OPASERV.H WORM!"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
Xhen[filename].exe"Added by the TARNO.G TROJAN!"
XHOT FIXfilename.exe"Added by the SDBOT-DKM WORM!"
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
XImage"rundll32 [path] [trojan filename]Install"
XInternal[trojan filename]"Added by the SMOTHER and TRANSLAT TROJANS!"
XInternat[trojan filename]"Added by the CMJSPY-Y TROJAN!"
Xinternet[trojan filename].exe"Added by the MIFENG-D TROJAN!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
Xist service uninstall[random filename]"ISTBar adware related"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
Xjcidls[random filename]"Added by a variant of the SLAPER TROJAN!"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjysyqm[random filename]"ZenoSearch adware"
XKadoc[random filename].exe"Added by the STAPREW TROJAN!"
Xkavsvc[random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
XKAVutil[worm filename]"Added by the WINTOO.B WORM!"
Xkern64dll[random filename]"Added by the TARNO.J TROJAN!"
Xlar[trojan filename]"Added by the ROXY.C TROJAN!"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
XLocator Service[filename]"Added by the AGOBOT-KY TROJAN!"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
XMantis[filename]"Added by the MANTIBE VIRUS!"
XMatrixScreen[filename]"Added by the MATRIXSCREEN TROJAN!"
Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
XMbarInstall[random filename]"Mirar adware"
XMedia Services[filename].exe"Added by the AGENT-BA BACKDOOR!"
Xmessnger[worm filename]"Added by the DELODER WORM!"
XMickey Mouse Cereal[random filename].exe"Added by the RANKY.Q TROJAN!"
XMicroLoad[random filename]"Added by the DARBY WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Diagnostic[random filename]"Added by the ACEBOT TROJAN!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicroSoft Getway Dire[random filename]"Added by the IRCBRUTE.AM WORM!"
XMicrosoft IIS[filename]"Added by the FRANCETTE-S WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft Locals 332[random filename]"Added by the RBOT-KU WORM!"
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Panager[filename]"Added by the RBOT-ANL WORM!"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft Tray[random filename]"Added by the DELF.BZ TROJAN!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Updates[worm filename]"Added by the AGOBOT-AIZ WORM!"
XMicrosoft Updote[random filename]"Added by the RBOT-ARC WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosot NT Support[random filename].exe"Added by the RBOT-CTI WORM!"
XMioft Wiws Seice ent[worm filename].exe"Added by the RBOT-GIJ WORM!"
Xmmsddlx[random filename]"Added by a variant of the SLAPER TROJAN!"
XMonAppli[random filename]"Added by the DELF.IF TROJAN! The most common filenames are isys32.exe & msnmsg.exe"
XMonitor Test[random filename]"Added by the SDBOT-NC WORM!"
XMS Task Manager 32[trojan filename] .exe"Added by the RANKY.NF TROJAN!"
XMS-HTML[random filename]"Added by the LATINUS.15 TROJAN!"
XMsgsvc32[worm filename]"Added by the NAUTICAL-A WORM!"
XMSKCES32[random filename]"Added by the CLONER TROJAN!"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
XMyapp[filename]"Added by the FATEE.B WORM!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
XNavScan[filename]"Added by the OBSORB TROJAN!"
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
XNotePad[worm filename]"Added by the SILLYFDC-G WORM!"
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
XNtech.patchs[trojan filename]"Added by the LEMIR.G TROJAN!"
XNvCpl[random filename]"Added by the AGOBOT-APJ WORM!"
Xnvviddrv32[random filename]"Added by the RBOT-HT BACKDOOR!"
XOffice Monitor Word Exel R[trojan filename]"Added by the IRCBOT-VX TROJAN!"
XOLE[filename]"Added by the STAWIN or TARNO.D TROJANS!"
Xpasscxd[random filename]"Added by a variant of the SLAPER TROJAN!"
XPGStub.exe[various filenames]Unidentified adware
XPlasdll service[random filename]"Added by a variant of the SDBOT WORM!"
XPNP FIX[worm filename]"Added by the RBOT-AKQ WORM!"
XPostBootReminder[random filename]Added by and unidentified WORM or TROJAN!
XPrivateNet[various filenames]Premium rate adult content dialler
Xprompt drive[random filename]"Added by the SDBOT.AMF WORM!"
Xputil[filename]"Added by the LDPINCH TROJAN!"
Xqbotd[random filename]"Added by the BOTTEN TROJAN!"
XQuicktime Task[random filename]"Trafficadvance dialer"
XRandom Unique ID[worm filename]"Added by the XROVE-A WORM!"
XRavTimeXP[worm filename]"Added by the WULLIK.B WORM!"
XRavTimXP[worm filename]"Added by the WULLIK.B WORM!"
Xrdvs[worm filename]"Added by the ULTIMAX.B WORM!"
Xrmalt[random filename]"Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe
XRPC Service[random filename]"Added by the BDOOR-AAD BACKDOOR!"
XRSPC Driver[random filename].exe"Added by the RBOT-SN WORM!"
XRSPC Driver D[random filename]"Added by a variant of the RBOT WORM!"
Xrtkernsw[random filename]"Added by a variant of the SLAPER TROJAN!"
XRundllrundll32.exe [random filename].dll"Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%"
XRunnerlsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XScanreg[filename]"Added by the QQPASS.E TROJAN!"
XScrSvrOld[worm filename]"Added by the OPASERV WORM!"
XSearchClick[trojan filename]"Added by the AGENT-DWR TROJAN!"
XService[trojan filename]"Added by the KAITEX.E TROJAN!"
XService Cleanerfilen.exe"Added by the RBOT.BRH WORM!"
XService Defender[random filename]"Added by a variant of the ZLOB TROJAN! See here"
XService Host[filename].exe"Added by the TORVEL.B WORM!"
XService Monitormsnfilen.exe"Added by the RBOT-ALE WORM!"
XService Monitorfilen.exe"Added by a variant of the RBOT WORM!"
XService Pack[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
XService Pack 1[random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
XService PAck SFVP[worm filename].exe"Added by a variant of the RBOT WORM! The filename is 4 random characters"
XServices004[worm filename]"Added by the BUGBROS WORM!"
XSfKg6wIP[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XSfKg6wIPu[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XSilentSoftech[worm filename]"Added by the SILLYFDC-BL WORM!"
XSNInstall[various filenames]"Spy Sheriff/SpywareNO malware
XSpeedBoss[worm filename]"Added by the OPASERV.AD WORM!"
Xspoolsv.exe[random filename]"Added by the RBOT-JB WORM!"
YSpybotDeleting*****[cmd or command] /c del [path] [filename]"Generated by Spybot Search & Destroy if it encounters files that cannot be deleted during runtime because they are locked by other processes. For example
XSrv32Old[worm filename].PIF"Added by the OPASERV.J WORM!"
XStartup Configuration[six character filename]"Added by the RBOT-ARV WORM!"
Xstdlib[filename]"Added by the PERDA-E TROJAN!"
XStreams Drivers[trojan filename]"Added by the RESTARTER.E TROJAN!"
XSupernova[worm filename]"Added by the SURNOVA.A (or SUPOVA) WORM!"
Xsupport-reverse-smileys[trojan filename]"Added by the LITEBOT TROJAN!"
Xsws.exe[random filename]"Haldex type adult content dialler"
XsyelimS-esreveR-troppuS[filename]"Added by the LITBOT.C TROJAN!"
XSymantec Autoscan[random filename]"Added by the RBOT-AJO WORM!"
Xsysdll[trojan filename]"Added by the HUGESOT TROJAN!"
Xsysmon12[various filenames]"Wareout - malware masquerading as a spyware and dialer remover"
XSysStart[random filename]"ZenoSearch adware"
XSystem backup[random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted
XSystem CPL manager[random filename]"Added by the RBOT-SR WORM!"
XSystem Update[filename].exe"CoolWebSearch parasite variant"
XSystem Update[random filename]"Added by the KORGO.W or KORGO.X WORMS!"
XSystem Update[random filename]"Added by the SOROMO-A TROJAN!"
XSystem32[worm filename]"Added by the NAUTICAL-A WORM!"
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystemEmergency[various filenames]"CoolWebSearch Smartsearch parasite variant"
XSystemManager[random filename]"Added by the SETTEC ROOTKIT!"
XSystemProcEvent[trojan filename]"Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe
XSystray[filename.exe]"Winfavorites adware"
XTaskReg[random filename]"Added by the CBLAD WORM!"
XTA_Start[random filename]"Zeno Think-Adz adware"
XTelnet24[random filename]"Added by the RBOT-ARD WORM!"
XThink-Adz[random filename]"Zeno Think-Adz adware"
XTSystem[trojan filename]"Added by the NSYS-A TROJAN!"
XUpdate for Windows[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
Xupdatesched[random filename]"ZenoSearch adware"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XUpdSys[random filename]Added by the BJ TROJAN!
Xupme[filename]"Added by the MUGLY.F WORM!"
XUser32[filename]"Added by the NETTRASH TROJAN!"
XUserSystem[filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
XValueS0ft[random filename]"Added by a variant of the SPYBOT WORM! See here"
XValueX[random filename]"Added by the IRCBOT.EE TROJAN!"
Xvbcdtm[random filename]"Added by a variant of the SLAPER TROJAN!"
XVBS.Ipnuker@mm[worm filename].vbs"Added by the NUKIP WORM!"
XVideo Process[random filename]"Added by the RBOT-LM WORM!"
XVideoDriver[filename]"Added by the GSPOT20.A TROJAN!"
XVisual Element FX5[various filenames]"ClearStream Accelerator adware"
XVoltage Manager[random filename]"Added by the DREFFORT WORM!"
Xvxcxcvfck[random filename]"Added by the RANCK-AZ TROJAN! The most common example is ""sbsvsd.exe"" located in %System%"
Xw02db700.dll[random filename]"ZenoSearch adware"
XW32Load[random filename].scr"Added by the CASPID WORM!"
XWeb Service[random filename].exe"Added by the ADMINCASH TROJAN!"
XWebRun[random filename]"Added by the ADWARELOADER TROJAN!"
Xwescmv[random filename]"Added by a variant of the SLAPER TROJAN!"
XWiFix service[random filename]"Added by a variant of the SDBOT WORM!"
XWin I5oahder[worm filename]"Added by the AGOBOT-DS WORM!"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
XWin2Drv[worm filename]"Added by the WINTOO WORM!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32system[random filename]"Added by the DDV.B WORM!"
Xwinabc"rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
XWindos Seres Agnts[worm filename].exe"Added by the RBOT-GUN WORM!"
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Print Monitor Daemon[random filename].exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Servce Agent[random filename]"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Standard Securty[random 3-letter filename]"Added by the RBOT-ALF WORM!"
XWindows System Service[worm filename]"Added by the RBOT.XG WORM!"
XWindows Update[filename]"Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowz[original worm filename].vbs"Added by the NUKIP WORM!"
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
Xwingo[various filenames]"Added by the BAGLE-AU WORM!"
XWinLoader[random filename]"Added by variants of the SUBSEVEN TROJAN!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
XWinUPPD.exe[random filename]Added by an unidentified WORM/TROJAN!
XWinz Firewall[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinzip[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
Xworknote1[filename].exe"Added by the MEETOT WORM!"
Xwpxmls[random filename]"Added by a variant of the SLAPER TROJAN!"
XWupdate driver[various filenames]"Added by a variant of the SPYBOT WORM!"
Xxp_system[filename]"Added by the BOOKMARKER.J TROJAN! The file is located in %Windir%\inet20004"
XZaCker[filename].PIF"Added by the HOLAR.A WORM!"
XZagrebLand[trojan filename]"Added by the RENOS-EH TROJAN!"
Xzcseacrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XZeno[random filename]"ZenoSearch adware"
Xzonealarm[random filename]"Added by an unidentified VIRUS
XZStart[various filenames]"VX2.Transponder parasite updater/installer related"
XZ_Start[random filename]"ZenoSearch adware"
X[filename]svchost.scr"Added by the BANKER-CC TROJAN!"
X[original filename]svchost.scr"Added by the BANCBAN-CX TROJAN!"
X[original filename]xphost.scr"Added by the BANCBAN-HM TROJAN!"
X[random filename]slk8x2peu.exe"QuickLinks adware"
X[trojan filename]Install.exe"Added by the BANCBAN-FS TROJAN!"
X[various filenames]qtsks.exeAdded by the WEBDOR.Y TROJAN


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.