Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
XMicosoft Data Core stuffsvshosts.exe"Added by the RBOT.FZA WORM!"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMS Hostsmsthosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
XMshostsMshosts.exe"Added by the STARTPAG.CF TROJAN!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
XService Hostsvchosts.exe"PornCleanser spyware"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
XStart Uppingssvcchosts.exe"Added by the SDBOT.VY WORM!"
Xsvchostssvchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
Xsvchosts.exesvchosts.exe"Added by the AGOBOT-JN WORM!"
Xvaluenamesvchosts.exe"Added by a variant of the SDBOT WORM!"
XVhosts Protectionvhosts.exeAdded by an unidentified WORM or TROJAN!
Xvirtual-machinesvchosts.exe"Added by the RBOT-US WORM!"
Xvschostvschosts.exe"Added by the VIPSY-A TROJAN!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XYahoo Messenggerscvhosts.exe"Added by the SOHANNA-AH WORM!"
XYahoo Messenggerscvshosts.exe"Added by the TRAX-A WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.