Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
U4oDKHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
Xahostahost.exe"Added by a variant of the SDBOT WORM!"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XBakraIEHost.EXE"Added by the MULTIDR-AH TROJAN!"
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
UCBWHostCBWHost.exe"Required for Bitware to answer incoming faxes
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xcihost.execihost.exe"Added by the LINST TROJAN!"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XCOM++ Systemsuchost.exe"Added by the LOVGATE-F WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
XCsrss Hostcsrhost.exe"Added by the IRCBOT.BIZ WORM!"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XData Filevdehost.exe"Added by the SDBOT-DOS TROJAN!"
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
XDirect settingssdchost.exe"Added by the DAEMONI-I TROJAN!"
XDirectX Driverstdhost.exe"Added by the SDBOT.GVJ BACKDOOR!"
Xdlhostdlhost.exe"Added by the EXPHOOK-A TROJAN!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDllHostdllhost.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Inf"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
NDVDXGhostDVDGhost.EXE"DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGames Accelerationsvshost.exe"EasySearch adware"
Xgammasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
YGilat SOM Enumeratordllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XG_HostgHost.exe"Added by the AUTOIT-BP WORM!"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhellodollyshost.exe"Added by the YODO WORM!"
XHelplshost.exeIdentified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
XhErcUnessofthost.exe"Added by the GARROCH WORM!"
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XHyper Filesphfhost.exe"Added by the AGENT-JQO TROJAN!"
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
Xicq litescvhost.exe"Added by the AGENT-DSF TROJAN!"
XIntel system toolsvehost.exe"Added by the AGENT-EBT TROJAN!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
XIntranetschost.exe"Added by the RBOT.SV BACKDOOR!"
Xishost.exeishost.exe"Added by the DLOADR-XJ TROJAN!"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
XJufualtsvhost.exe"Added by the SDBOT-ADJ WORM!"
XKAVPersonalsvchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NkdxKHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
XKernel Faultsftphost.exe"Added by the RBOT.BHU WORM!"
XKernel32svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
Xload32swchost.exe"Added by the TURTA.A WORM!"
XLocalSystemsvchost.exe"EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
XMastersvcghost.exe"Added by the IRCBOT.RB TROJAN!"
XMemory Allocation Hostcihost.exe"Detected by Avast as a variant of the IRCBOT-CHZ WORM!"
XMessenger Servicenvhost.exe"Added by the JLOK-A WORM!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
Xmicrosoftsvchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoftsvchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoftschost.exe"Added by the RBOT.FEH BACKDOOR!"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Clientmshost.exe"Added by the RBOT-AND WORM!"
XMicrosoft Com Port Managersvdhost.exe"Added by the SDBOT-NI WORM!"
XMicrosoft Command Csshost.exe"Added by the RBOT-CMK WORM!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft Data Helpercihost.exe"Malware
XMicrosoft DLL Host Servicedllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IISsyshost.exe"Added by the FRANCETTE WORM!"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Officesvxhost.exe"Added by a variant of the RBOT WORM!"
NMicrosoft People Near Mep2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Servicemicrohost.exe"Added by the RBOT-LC WORM!"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Synchronization Managerslhost.exe"Added by the SDBOT.YH WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft Synchronization Managersvxhost.exe"Added by the SDBOT-ZU WORM!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatesghost.exe"Added by the SDBOT.AKV WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Updatesvghost.exe"Added by the RBOT.BUJ WORM!"
XMicrosoft Updatesvzhost.exe"Added by the RBOT.OX WORM!"
XMicrosoft Update DLLrxxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Eventsvnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
XMicrosoft Update Machinerxhost.exe"Added by the RBOT.FC WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinerxxhost.exe"Added by the RBOT.EP WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
NMicrosoft® Windows® Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
NMixghostmixghost.exe"Management software for Altec Lansing speakers. If a change is needed
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
XMonitoring Servicesvchost.exe"Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
UMouseImpMImpHost.exe"MouseImp Pro - "A reliable assistant that turns your mouse into a simple
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Hostmsthost.exe"Added by the SLENFBOT.AH WORM!"
XMS Host Managerivhost.exe"Added by the RBOT-BJN WORM!"
XMS Updatesyshost.exe"Added by the EVAMAN-F WORM!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsetsvchost.exe"Added by the BIZEX-F TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""mset"" sub-directory"
XMSNscvhost.exe"Added by the IRCBOT-ZW WORM!"
XMSNsvchost.exe"Added by the PUSHBOT.FA WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMSStartOptimizerSCVHOST.EXE"Added by the DASMIN-E TROJAN!"
XMStasksvchost.exe"Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xmsvccmsvchost.exe"Added by the XOMBE TROJAN!"
Xmsvcc25svcchost.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25svcchost.exe"Added by the SDBOT-CSE WORM!"
Xmsvchostmsvchost.exe"Added by the IRCBOT-AV WORM!"
Xnanosvchost.exe"Added by the NANO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNDAvsvhost.exe"Added by the SERFLOG.C WORM!"
Xnet32svhost.exeAdded by a variant of the Trojan.Clicker family
Xnethost.exe[path to file]"Added by the PERDA-J TROJAN!"
XNetStartsvchost.exe"Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""NETSTART"" subfolder"
XNetwork manegersvchost.exe"Added by the AGENT.BX BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNetwork Servicesvchost.exe"Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XNETWORK SERVICESVÑHOST.exe"Added by the DELF-EW BACKDOOR!"
XnodriverSVCHOST.EXE"Added by the SPYBOT-Z BACKDOOR! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
XNorton Live UpdaterSochost.exe"Added by the GAOBOT.AO WORM!"
XNortons AV SYSTEMscvchost.exe"Added by a variant of the RBOT WORM!"
XNortonVPlussvchost.exe"Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
Xntusersvchost.exe"Added by the POLYCRYP.DY TROJAN!"
XNvClipRsvsvchost.exe"Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvClipRsvswchost.exe"Added by the DUMARU-AK WORM!"
XOfficeAgentsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeAgentsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XOlive SystemSzchost.exe"Added by the MERCURYCAS.A TROJAN!"
XOnline Servicesvchost.exe"Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XOnluna Sarvicesachost.exe"Added by the TOFGER-AA TROJAN!"
XOnlune Sarvicesachost.exe"Added by the DAEMONI-J TROJAN!"
Xonly23SCVHOST.exe"Added by the BCKDR-PUQ BACKDOOR!"
XOpera addonsvhost.exe"Added by the AGENT-IBD WORM!"
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPerfomance Settingssvchost.exe"Added by the TOFGER-AP TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPersonal Computerscvhost.exe"Added by the RBOT-AJE WORM!"
XPhotoshopsvchost.exe"Added by the CDOPEN-E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
XPolicyRunsvchost.exe"Added by the SILLYFDC-AW WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UPowerDOCSAPIHostpapihost.exe"Hummingbird PowerDOCS - ""delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"""
XPowerManagersvchost.exe"Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XProcessorsvchost.exe"Added by the AGENT-KIR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
Xraidhostraidhost.exe"Added by the AGENT-LID TROJAN!"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
Xregeditsvchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename"
Xreghostreghost.exe"SpyPal surveillance software. Uninstall this software unless you put it there yourself"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
XRemote Access SlaveSynchost.exe"Added by the RIPJAC TROJAN!"
Xrenascimentosvchost.exe"Added by the BANKER.GAX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
Xreseurcesvchost.exe"Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCMSschost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XRPCall_[ComputerName]smhost.exe"Added by the REDPLUT-B TROJAN!"
Xruncchost.exe"Added by the SQUATBOT-C TROJAN!"
Xrun=svhost.exe"Added by the ADMINCASH.B TROJAN!"
XRunnersvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSsvhost.exe"Added by the AGOBOT-LN WORM!"
XScamDiskSVOHOST.exe"Added by the LEWOR.D WORM!"
XscAppsuchost.exe"Added by the ACNATT.A WORM!"
XSchedulersvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xscvhostsvzhost.exe"Added by a variant of the SPYBOT WORM!"
Uscvhostscvhost.exe"Wiretap surveillance software. Uninstall this software unless you put it there yourself"
Xscvhostscvhost.exe"Added by the AGOBOT-LI WORM!"
Xscvhost.exescvhost.exe"Added by the LOHAV-N TROJAN!"
XSDAvsvhost.exe"Added by the SERFLOG.C WORM!"
Usds20svchost.exe"InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
Xsecuresvshost.exe"Added by the RBOT-AFO WORM!"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
?SelfHostUtilslefhost.exe"??"
XServer Daemon Host Managersdhost.exe"Added by the RBOT-GWC WORM!"
XService Hostsvchost.exe"Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Hostsvchost.exe"Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853}"
XService Hostsvchost.exe"Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random]"
XService Host Driversvchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService ProcessSVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XService Processsvchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServicesmshost.exe"Added by the LANFILT-J TROJAN!"
XServicessvchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServices HostScchost.exe"Added by the DONK WORM!"
XServicio Localsvhost.exe"Added by the SPYBOT.BGX WORM!"
XSetup experationsvchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShellExplorer.exe svchost.exe"Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShellsvchost.exe"Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xshhostshhost.exe"Added by the AGENT.CE TROJAN!"
Usmrcvshost.exe"Silent Monitoring surveillance software. Uninstall this software unless you put it there yourself"
XSmss Hostsmhost.exe"Added by the IRCBOT-ACC TROJAN!"
XSNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSoundMamSVOHOST.exe"Added by the QQROB-AAL TROJAN!"
XSpooler Hostsmhost.exe"Added by the IRCBOT.BSQ BACKDOOR!"
Xspoolsvsvchost.exe"Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP"
Xsrshost.exesrshost.exe"Added by a variant of the RBOT-ASW WORM!"
XSrv Hostsrvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
USrv32WinSvchost.exe"Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsrvhostsrvhost.exe"Added by the LIVUP.A BACKDOOR!"
XSSLsvchost.exe"Added by an unidentified VIRUS
Xssvchostssvchost.exe"Added by the HELIOS.B TROJAN!"
Xstartkeyscvhost.exe"Added by the BIFROSE-PM TROJAN!"
Xstartkeysvchost.exe"Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XStartup UpdateCvshost.exe"Added by the GAOBOT.AO WORM!"
XSunJavaUpdateSchedscvhost.exe"Added by the SDBOT-AVX WORM!"
USVCsvchost.exe"ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSVCHOSTsvchost.exe"System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060"
Xsvchostsvchost.exe"Added by many TROJANS amd WORMS
XSvchostwinhost.exe"Added by the LOLAWEB.A TROJAN!"
XSvchostsvchost.exe"Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSVCHOSTscvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
Xsvchostsvchost.exe"Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
XSvchostsvchost.exe"Added by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer"
Xsvchostsvchost.exe"Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
Xsvchostsvchost.exe"Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
Usvchostsvchost.exe"Infine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an ""svc"" subfolder"
Xsvchostsvchost.exe"Added by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""MsDtds"" sub-directory"
Xsvchost Agentsvchost.exe"Added by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""28463"" sub-folder"
XSVCHOST Generic applicationsvchost.exe"Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsvchost Netware Managersvchost.exe"Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSvchost Servicesvchost.exe"Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
Xsvchost.exesvchost32.exe"CoolWebSearch Svchost32 parasite variant"
XSVCHOST.EXESVCHOST.EXE"Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsvchost.exe[path to executeable]"Added by the BANKER-MO TROJAN!"
Xsvchost.exesvchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
Xsvchost.exeswchost.exe"Added by the SADELPHI-A TROJAN!"
Xsvchost.exesvchost.exe"Added by the VIRUT.CF WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3361"" subfolder"
XSVCHOST.EXEsvchost.exe"Added by the SILLYFDC.BBI WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Conf"" sub-directory"
Xsvchost.exesvcnost.exe"Added by the MISLEAD-A TROJAN!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
XSvclhostsvcchost.exeAdded by an unidentified WORM or TROJAN!
XSVGA Adaptersvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XSVHOSTsvhost.exe"Added by the MYDOOM.I WORM! The file is located in %System%"
XSVHOSTSVHOST.EXE"Added by the ZORI.A VIRUS! The file is located in %System%\SVCHOSTV"
XSvhostSvhost.exe"Added by the VB-ASG WORM! This file is located in a ""Hwnd"" sub-directory of the Root folder (C:\)
XSvhost Loadersvshost.exe"Added by the AGOBOT.G WORM!"
Xsvhost updatesSvhost.exe"Added by a variant of the RBOT WORM!"
Xsvphost.exesvphost.exe"Added by the AGENT.CS TROJAN!"
Xsvshostsvshost.exe"Added by the CHODE-H WORM!"
Xsvshostdriversvshost.exe"Added by the SDBOT-HN TROJAN!"
XSVX Control Servicesvxhost.exe"Added by the FORBOT-K WORM!"
XSwchostSwhost.exe"Added by the BDOOR-MP BACKDOOR!"
XSymantec Secure Serversvrhost.exe"Added by the IRCBOT-UB TROJAN!"
XSymantecFilterChecksvhost.exe"Added by the BANKER-EEO TROJAN!"
XSysctrls32sevchost.exe"Added by the RBOT.ADF BACKDOOR!"
Xsyshostsyshost.exe"Added by the VB-DVZ TROJAN!"
XSysInitsvchost.exe"Added by the STARTPA-BD TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XSystemSVCHOST.EXE"Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystem configuresvchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XSystem Hostscvhost.exe"Added by a variant of the RBOT WORM!"
XSystem Host Managersyshost.exe"Added by the BANWORM-C WORM!"
XSystem Host Servicesvchost.exe"Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XSystem Managersvchost.exe"Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processsvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Update2svchost.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSystem32svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XSystemChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
Xsystemrd11host.exe"Added by the VB-GX TROJAN!"
XSystemRegsvchost.exe"Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemsscchost.exe"Added by the DAEMOZ.A TROJAN!"
XSystems Restartslchost.exe"Added by the MULTIDROP.C TROJAN!"
XSystems Restartspchost.exeAdded by an unidentified WORM or TROJAN!
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
XSysTraysvhost.exe"Added by the RAJILO-A WORM!"
XSys_Runghost.exe"Added by the LINEAGE-N TROJAN!"
XTask Managersvchost.exe"Added by the SOHANA-P WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XTask Monitoring Servicesvchost.exe"Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
UTHCSsvchost.exe"AllMonitor surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in a ""drivers\imon"" subfolder"
XTIMHostTIMHost.exe"Added by the PWS-ANT TROJAN!"
XToPicks StarterIdhost.exe"TOPicks adware"
XTransaction Taskerstdhost.exe"Added by the SDBOT.HNK BACKDOOR!"
XUpdatesvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdate Checkerscvhost.exe"Added by the AGENT-DSF TROJAN!"
XUpdate InstallSchost.exe"Added by the GAOBOT.AO WORM!"
Xupdate servicesvxhost.exe"Added by the RBOT-MG WORM!"
XUPDATEMSNsvhost.exeAdded by an unidentified WORM or TROJAN!
XUpgrade Sarvicesxchost.exe"Added by a variant of the TOFGER-I TROJAN!"
XUpgrade Servicesxchost.exe"Added by the TOFGER-I TROJAN!"
XUser Hostusnhost.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Hosting Serviceusnhost.exe"Added by the IRCBOT.SN WORM!"
XVCS Hostvcshost.exe"Added by the RBOT-FKT WORM!"
Xvhosthost.exe"Peppi adware"
XVideo Driversvchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xvschostvschost.exe"Added by the AGENT.QK BACKDOOR!"
Xwin32winhost.exe"Added by the BROPIA.J WORM!"
UWinAppLogsvchost.exe"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinbinswchost.exe"Added by the RBOT.CLS WORM!"
Xwinchostwinchost.exe"Added by the DLOADER-PO TROJAN!"
Xwindhost.exeosrwin32.exe"Added by the BANKER-CB TROJAN!"
Xwindhost.exewindhost.exe"Added by the BANKER-BV TROJAN!"
Xwindhost.exewinos.exe"Added by the PWSAGENT-A WORM!"
Xwindow2ssvchost.exe"Added by the IRCBOT.H TROJAN!"
Xwindowssvchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Firewallsvchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Firewalllsphost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllsvvhost.exe"Added by a variant of the RBOT WORM!"
XWindows Genuinesvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Hostwinhost.exe"Added by the PRYSAT TROJAN!"
XWindows Host Servicehost.exe"Added by the KELVIR.AN WORM!"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
XWindows Print SpoolerSVEHOST.EXE"Added by the SPYBOT.H WORM!"
XWindows Register Settingssvmhost.exe"Added by a variant of the FORBOT WORM!"
XWindows Registrywinhost.exe"Added by a variant of the RBOT WORM!"
XWindows reportswchost.exe"Added by the SMALL-BD TROJAN!"
XWindows Security Managersvchost.exe"Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWindows Soundsvdhost.exe"Added by the SDBOT.EFX BACKDOOR!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
XWindows Stortupsvchost.exe"Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows svchostsvchost.exe"Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System Trayswhost.exe"Added by an unidentified VIRUS
XWindows Taskmanagersvchost.exe"Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Taskmanagertaskxphost.exe"Added by the PUSHBOT.BI WORM!"
XWindows TMSVPHOST.exe"Added by a variant of the RBOT WORM!"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
Xwindows updatesychost.exe"Added by the LEOX.B WORM!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
XWindows updatesvdhost.exe"Added by the GAOBOT.CG WORM!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsExplorersvchost.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatesvdhost.exe"Added by the AGOBOT-BP WORM!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdateNTsvwhost.exe"Added by the SHELLOT-B TROJAN!"
XWindows_Updatessvthost.exe"Added by a variant of the SPYBOT WORM!"
XWinEssentialKeyhost.exeHijacker - hailing from jraun.com
XWinhostwinhost.exe"Added by the REATLE.F WORM!"
Xwinhost.exewinhost.exe"Added by the LOHAV-R TROJAN!"
Xwinlogonnvchost.exeAdded by an unidentified WORM or TROJAN!
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
?WinManagerschost.exe"??"
XWinMessengersyshost.exe"Added by the OPANKI-E WORM!"
XWinmgr.exescvhost.exe"Added by the AGOBOT.AFG WORM!"
XWinMngndllhost.exe"Added by the SIVION-A TROJAN! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\system"
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
Xwinshost.exewinshost.exe"Added by the TOOSO WORM and variants!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWinsock32driversvchhost.exe"Added by the HACKARMY.I TROJAN!"
XWinSocketComponentnthost.exe"Added by an unidentified VIRUS
Xwinsyssyschost.exeAdded by an unidentified TROJAN!
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWinUpsvchost.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""4350"" sub-folder"
XWinUpdatesvhost.exe"Added by a variant of the SDBOT WORM!"
Xwlinlessvchost.exe"Added by the LIJI-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the ""spool"" sub-folder"
Xwnddrvsvchost.exe"Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwsock32svchost.exe"Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWSVCHOsvhost.exe"Added by the SPYBOT-OQ WORM!"
Xxorsvchost.exe"Added by the XORDOOR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""xor"" subfolder"
Xxorsvshost.exe"Added by the AGENT.DC TROJAN!"
XXPCPHOST Settingsxpcphost.exe"Added by a variant of the RBOT WORM!"
XYahoo MessenggerSVICHHOST.exe"Added by the TIOTUA-C TROJAN!"
XYahoo MessenggerRVHOST.exe"Added by the SILLYFDC-G WORM!"
XYahoo MessenggerSCVHOST.exe"Added by the SOHANA-V WORM!"
XYahoo MessenggerSSCVIHOST.exe"Added by the SOHANA-W WORM!"
XYahoo MessenggerSSCVIIHOST.exe"Added by the SOHANA-Y WORM!"
XYahoo MessenggerSSVICSSHOST.exe"Added by the IMAUT.AA WORM!"
XZone Labs Client Exsvchost.exe"Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XZone systemszchost.exe"Added by the MULTIDR-AC TROJAN!"
Xzztpsvchost.exe"Added by the TANNICK.B TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X[random name]??chost.exe"PurityScan adware"
X[random name]svchost.exe"Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
X[random name]s?chost.exe"PurityScan adware"
X[trojan name]svchost.exe"Added by the BANCBAN-CI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X_ntrdlhost_Ntrdlhost.exe"Added by the DLOADER-JV TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.