Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*MS Setup[random filename]"Virtumondo adware
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
XAceu[random filename]"PurityScan adware"
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAdd**32.exe [* = random char]Add**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
Xantiwareelite***32.exe [*** = random char]"Added by the DLOADER-HW TROJAN!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xara-key[random filename]"Added by the ANTINNY WORM!"
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAtl**32.exe [* = random char]Atl**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
Xbxproxy[random].dll"SoftStop rogue security software - not recommended"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
Xcenter[random name]32.exe"Added by the BOFRA.A WORM!"
Xcheckrunelite***32.exe [* = random char]"EliteBar adware"
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCr**.exe [* = random char]Cr**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XCr**32.exe [* = random char]Cr**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
Xcyberfree.exe****.dat [* = random char]Unidentified adware
XD3**.exe [* = random char]D3**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XD3**32.exe [* = random char]D3**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
Xdm***.exe [* = random char]dm***.exe [* = random char]"Wareout - malware masquerading as a spyware and dialer remover"
Xdm[3 random letters].exedm[3 random letters].exe"Added by the RUINDEM TROJAN!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
Xdwqblwppx.exe[random].exe"Okcashbackmall adware"
Xdwqblwpvl.exe[random].exe"Okcashbackmall adware"
Xdwqblwrsq.exe[random].exe"Okcashbackmall adware"
XDxsys*.exe [* = random number]"Added by the DEXTER.A WORM!"
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
XEfata[random 5 characters].exe"Added by the FLUKAN-D WORM!"
XEnterprise SuiteWE[random characters].exe"Enterprise Suite rogue security software - not recommended
Xetbrunelit***32.exe [* = random char]"EliteBar adware"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExploreUpdSched[random filename]"ZenoSearch adware"
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
XGPLv3[random name].dll"Vundo adware"
Xgrgtgvgb.exe[random].exe"Added by the AGENT-EBF TROJAN!"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Xicccomp[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
Xidlesam[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
XIE**.exe [* = random char]IE**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIE**32.exe [* = random char]IE**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XieupdateMCP****.exe [**** = random char]"Added by the ASOXY TROJAN!"
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
XIP**.exe [* = random char]IP**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIP**32.exe [* = random char]IP**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
Xist service uninstall[random filename]"ISTBar adware related"
XivHost[6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
XJava**.exe [* = random char]Java**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XJava**32.exe [* = random char]Java**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xjcidls[random filename]"Added by a variant of the SLAPER TROJAN!"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjysyqm[random filename]"ZenoSearch adware"
XKadoc[random filename].exe"Added by the STAPREW TROJAN!"
Xkalvsyskalv****.exe [* = random char]"EliteBar adware"
Xkalvsyskalv***32.exe [* = random char]"EliteBar adware"
XKavSvc******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
Xkavsvc[random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
Xkdmsx[8 random letters].exe"Added by the SDBOT.AIJ BACKDOOR!"
Xkern64dll[random filename]"Added by the TARNO.J TROJAN!"
Xklop[random].tmp"Found with Trojan.Win32.StartPage.aw. Possibly a variant of the AGENT-WQ TROJAN!"
XLive PC CareLP[random characters].exe"Live PC Care rogue security software - not recommended
Xloader32sys*****.exe [***** = random digit]"Added by the DOMCOM TROJAN!"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
ULogon Loader RandomLogonLoader.exe"Logon Loader - customize boot & login screens"
XMalware Cleaner[random numbers].exe"Malware Cleaner rogue security software - not recommended
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
XMbarInstall[random filename]"Mirar adware"
Xmceipww[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
XMDM Rock 4[8 random letters].exe"Added by the SDBOT.CHG BACKDOOR!"
XMembers area******.exe [* = random digit]Premium rate adult content dialer
XMemoryManager[random name].dllVirtumondo adware related
XMfc**.exe [* = random char]Mfc**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMfc**32.exe [* = random char]Mfc**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMickey Mouse Cereal[random filename].exe"Added by the RANKY.Q TROJAN!"
XMicroLoad[random filename]"Added by the DARBY WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Diagnostic[random filename]"Added by the ACEBOT TROJAN!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicroSoft Getway Dire[random filename]"Added by the IRCBRUTE.AM WORM!"
XMicroSoft Getway mqbol[12 random letters].exe"Added by the RBOT.GBA WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Locals 332[random filename]"Added by the RBOT-KU WORM!"
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
Xmicrosoft software****.exe [* = random char]Added by an unidentified WORM or TROJAN!
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft Tray[random filename]"Added by the DELF.BZ TROJAN!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Updote[random filename]"Added by the RBOT-ARC WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft-software****.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft.exe[random].exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosofts Security Manager****.exe [**** = random char]"Added by the RBOT-WH TROJAN!"
XMicrosot NT Support[random filename].exe"Added by the RBOT-CTI WORM!"
Xmmsddlx[random filename]"Added by a variant of the SLAPER TROJAN!"
Xmobiswing[random].exe"Mobis adware"
XMonAppli[random filename]"Added by the DELF.IF TROJAN! The most common filenames are isys32.exe & msnmsg.exe"
XMonitor Test[random filename]"Added by the SDBOT-NC WORM!"
Xms window update******.exe [* = random character]"Added by a variant of the RBOT WORM!"
Xms************* [* = random digit]ms*************.exe [* = random digit]"WINBO adware"
XMs**.exe [* = random char]Ms**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMs**32.exe [* = random char]Ms**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMS-HTML[random filename]"Added by the LATINUS.15 TROJAN!"
XMSKCES32[random filename]"Added by the CLONER TROJAN!"
Xmsmcms****.exe [* = random char]"ClientMan parasite variant"
XMSMSGNER[4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"
XMSN 9.0 Plus[random letters].exe"Added by the RBOT-ALY WORM!"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
XMSPQFileMSA****.TMP [* = random char]Homepage hijacker
XMSServer"Rundll32.exe [random].dll#1"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
XMy Security EngineMS[random characters].exe"My Security Engine rogue security software - not recommended
XMy Security WallMS[random characters].exe"My Security Wall rogue security software - not recommended
XMyAccessMediatmp**.exe [* = random char/digit]"My AccessMedia toolbar related
XNarrator******.exe [* = random char]"Added by the QOOLOGIC TROJAN!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
XNAVNet***.tmp [* = random digit]Unidentified adware
XNet**.exe [* = random char]Net**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XNet**32.exe [* = random char]Net**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
XNetwork Host Service[random]32.exe"Added by the RBOT-BAB WORM!"
XNetwork Security Guard**********.exe [* = random char]"CoolWebSearch parasite variant"
XNo Credit Cardplugin-[random].exeAdult content pop-up dialler
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
XNt**.exe [* = random char]Nt**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XNt**32.exe [* = random char]Nt**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XNvCpl[random filename]"Added by the AGOBOT-APJ WORM!"
XNvid[8 random charachters]Unidentified adware
Xnvviddrv32[random filename]"Added by the RBOT-HT BACKDOOR!"
XorderShellorder****.exe [* = random char]"Added by the DLOADR-UN TROJAN!"
Xorder_Shellorder_****.exe [* = random letter]"Added by the AGENT.ARO TROJAN!"
XOutlook Express Config*****.exe [* = random char]"Added by a variant of the RBOT WORM!"
Xpasscxd[random filename]"Added by a variant of the SLAPER TROJAN!"
XPC Live GuardPC[random characters].exe"PC Live Guard rogue security software - not recommended
XPCShieldregsvr32 sfg_****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPlasdll service[random filename]"Added by a variant of the SDBOT WORM!"
Xpnpsvc_lock******.exe [* = random digit]Browser hijacker
XPopup Blocker Updaterregsvr32 veev****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPostBootReminder[random filename]Added by and unidentified WORM or TROJAN!
XPreinAPP****.tmp [* = random char or digit]Unidentified adware
XProgram Access Service[10 random letters].exe"Added by the RBOT.GJJ WORM!"
Xprompt drive[random filename]"Added by the SDBOT.AMF WORM!"
Xproses[5 random letters].exe"Added by a variant of the RBOT WORM!"
XPublic Microsoft ODBCODBC32*.exe [* = random char]"Added by the MASLAN.D WORM!"
Xqbotd[random filename]"Added by the BOTTEN TROJAN!"
XQuicktime Task[random filename]"Trafficadvance dialer"
Xrandomrandom.exe"Added by the DLOADER-KM TROJAN!"
XRandom Interface Networkrst.exe"Added by the DELBOT-P WORM!"
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
XRandom Unique ID[worm filename]"Added by the XROVE-A WORM!"
XRandomWin32mgnwin32.exe"Added by the SDBOT-DV WORM!"
XReactor3[random name]32.exe"Added by the BOFRA.A WORM!"
XReactor5[random name]32.exe"Added by the BOFRA.D WORM!"
XReactor6[random name]32.exe"Added by the BOFRA.C WORM!"
XReactor7[random name]32.exe"Added by the BOFRA.B WORM!"
XReactor8[random name]32.exe"Added by the BOFRA.E WORM!"
XReactor9[random name]32.exe"Added by the BOFRA.E WORM!"
URegistryclass0117[random].exe"Blackbox captures emails and chat logs
XRemote System Protection"rundll32.exe [random].dll HUI_proc"
Xreszrv[8 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XRhino[random name]32.exe"Added by the BOFRA.A WORM!"
Xrmalt[random filename]"Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe
Xromahere2************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
Xromahere3************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
XRPC Service[random filename]"Added by the BDOOR-AAD BACKDOOR!"
XRSPC Driver[random filename].exe"Added by the RBOT-SN WORM!"
XRSPC Driver D[random filename]"Added by a variant of the RBOT WORM!"
Xrtkernsw[random filename]"Added by a variant of the SLAPER TROJAN!"
XRundllrundll32.exe [random filename].dll"Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%"
Xrunner1retadpu[random digits].exe"Added by the SMALL.CTV TROJAN!"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSdk**.exe [* = random char]Sdk**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XSdk**32.exe [* = random char]Sdk**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xsecure[random].exe"DealHelper adware"
XSecurity AntivirusSA[random characters].exe"Security Antivirus rogue security software - not recommended
XSecurity GuardSG[random characters].exe"Security Guard rogue security software - not recommended
XSecurity Master AVSM[random characters].exe"Security Master AV rogue security software - not recommended
XService Defender[random filename]"Added by a variant of the ZLOB TROJAN! See here"
XService Pack 1[random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
XSfKg6wIP[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XSfKg6wIPu[random filename]Identified as a variant of the TrojanDownloader.Matcash malware
XShellExplorer.exe [path] ibm[RANDOM 5 DIGIT NUMBER].exe"Added by the ANSERIN TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files"
Xshellbn[random].dll"SoftStop rogue security software - not recommended"
XSmart Virus EliminatorSM[random characters].exe"Smart Virus Eliminator rogue security software - not recommended
XSM[random][random].exe"Malware Protector 2008 rogue security software - not recommended
Xsoft2********.exe [* = random digit]"Added by the KARDPHISHER TROJAN!"
Xspoolsv.exe[random filename]"Added by the RBOT-JB WORM!"
Xsws.exe[random filename]"Haldex type adult content dialler"
XSymantec Autoscan[random filename]"Added by the RBOT-AJO WORM!"
Xsys************* [* = random digit]sys*************.exe [* = random digit]"WINBO adware"
XSys**.exe [* = random char]Sys**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XSys**32.exe [* = random char]Sys**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XSys29win***32.exe [* = random char]"EliteBar adware"
XSysAwin***32.exe [* = random char]"EliteBar adware"
XSysStart[random filename]"ZenoSearch adware"
XSystem backup[random filename]"Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted
XSystem CPL manager[random filename]"Added by the RBOT-SR WORM!"
XSystem DefenderWS[random characters].exe"System Defender rogue security software - not recommended
XSystem Services[random file name]"Added by a variant of the RBOT WORM!"
XSystem Update[random filename]"Added by the KORGO.W or KORGO.X WORMS!"
XSystem Update[random filename]"Added by the SOROMO-A TROJAN!"
XSystem32Check[random].exe"Added by the CHAST-A TROJAN!"
XSystemManager[random filename]"Added by the SETTEC ROOTKIT!"
Xsystwtraytwitty**.exe [** = random digits]"Added by the KOOBFACE.C WORM!"
Xsyswin.txt[3 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
XTaskReg[random filename]"Added by the CBLAD WORM!"
XTA_Start[random filename]"Zeno Think-Adz adware"
XTelnet24[random filename]"Added by the RBOT-ARD WORM!"
XTempCom[randomname].com"Added by the TRAXG WORM!"
XThink-Adz[random filename]"Zeno Think-Adz adware"
XTok-Cirrhatus-1959[random].exe"Added by the BRONTOK-CF WORM!"
XTok-Cirrhatus-[4 random digits]br[4 random digits]on.exe"Added by the BRONTOK-M WORM!"
Xttool[random numbers].exe"Added by the BCKDR-QII BACKDOOR! The filename seen most often is ""9129837.exe"""
Xupdatesched[random filename]"ZenoSearch adware"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XUpdSys[random filename]Added by the BJ TROJAN!
XUSB Driver4UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
XValueS0ft[random filename]"Added by a variant of the SPYBOT WORM! See here"
XValueX[random filename]"Added by the IRCBOT.EE TROJAN!"
Xvbcdtm[random filename]"Added by a variant of the SLAPER TROJAN!"
Xvbe[random name].vbe"Added by the UISGON-A WORM!"
XVbouncerDLVbouncerInner****.exe [* = random char]"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xversion[random].exe"DealHelper adware"
XVideo Process[random filename]"Added by the RBOT-LM WORM!"
XVirtual CD v6[random].exe"Added by the RBOT-AZV WORM!"
XVirus DoctorVdoc[random].exe"Virus Doctor rogue security software - not recommended
XVirus Protector[random].exe"Virus Protector rogue security software - not recommended
XVolcano Security SuiteVS[random characters].exe"Volcano Security Suite rogue security software - not recommended
XVoltage Manager[random filename]"Added by the DREFFORT WORM!"
Xvxcxcvfck[random filename]"Added by the RANCK-AZ TROJAN! The most common example is ""sbsvsd.exe"" located in %System%"
Xw02db700.dll[random filename]"ZenoSearch adware"
XW32Load[random filename].scr"Added by the CASPID WORM!"
XWAPIwts**.exe [* = random char]"PurityScan adware"
XWCPSWint**.exe [* = random char]"PurityScan adware"
Xweb******.exe [* = random char]"Added by a variant of the EASTO.A TROJAN!"
XWeb Service[random filename].exe"Added by the ADMINCASH TROJAN!"
XWebRun[random filename]"Added by the ADWARELOADER TROJAN!"
Xwescmv[random filename]"Added by a variant of the SLAPER TROJAN!"
XWiFix service[random filename]"Added by a variant of the SDBOT WORM!"
XWiinamp[random].exe"Added by the IRCBOT-OH TROJAN!"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
Xwin************* [* = random digit]win*************.exe [* = random digit]"WINBO adware"
XWin32system[random filename]"Added by the DDV.B WORM!"
XWin32SystemMonitor***.exe [* = random char]Browser hijacker
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindows (random character)diskcheck.exe"Added by the SINGU.B TROJAN!"
XWindows Additional GuardWI[random characters].exe"Windows Additional Guard rogue security software - not recommended
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows Data Server[random name].exe"Added by the SPYBOT-DS WORM!"
XWindows Enterprise SuiteWE[random characters].exe"Windows Enterprise Suite rogue security software - not recommended
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows haz Layer[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Live Messenger[random].exe"Added by the RBOT-GVL WORM!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows NTFS Volume Manage[6 random letters].exe"Added by the RBOT.EDL BACKDOOR!"
XWindows PC DefenderWP[random characters].exe"Windows PC Defender rogue security software - not recommended
XWindows Print Monitor Daemon[random filename].exe"Added by a variant of the SDBOT WORM!"
XWindows Protection SuiteWI[random characters].exe"Windows Protection Suite rogue security software - not recommended
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Secure talal32[7 random letters].exe"Added by the RBOT.HTP TROJAN!"
XWindows Security Service[random file name]"Added by the RBOT-ALV WORM!"
XWindows Security SuiteWI[random characters].exe"Windows Security Suite rogue security software - not recommended
XWindows Servce Agent[random filename]"Added by a variant of the IRCBOT TROJAN!"
XWindows Servcesc[9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows Service Agccnt[random].exe"Added by the SDBOT-DHL WORM!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Serviece Agents[8 random letters].exe"Added by the AGENT.BHR TROJAN!"
XWindows Standard Securty[random 3-letter filename]"Added by the RBOT-ALF WORM!"
XWindows System DefenderWS[random characters].exe"Windows System Defender rogue security software - not recommended
XWindows System Security Monitor[4 random letters].exe"Added by the PINKTON.A WORM!"
XWindows System SuiteWS[random characters].exe"Windows System Suite rogue security software - not recommended
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey upd4te2d4te*********.exe [* = random char]"Added by the RBOT.XQ WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowsService[random name].dll"Added by the VUNDO-X TROJAN!"
XwindowsupdateRPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
XWinds Sers Agts[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWinDSNXWin****.exe [* = random char]"Added by the DSNX TROJAN!"
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
XWink*.exeWink*.exe [* = random char]"Added by a variant of the KLEZ WORM!"
XWinLoader[random filename]"Added by variants of the SUBSEVEN TROJAN!"
XWinMediamsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinNetDDE[random characters].exe"Added by the NETDEPIX.B TROJAN!"
XWinSecure[random].exe"Added by the AGENT-LR TROJAN!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsvrmsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
Xwinsync******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
XWINTwcp****.exe [* = random char]"PurityScan adware"
XWINTwcp**.exe [* = random char]"PurityScan adware"
Xwinupd"RUNDLL32.EXE [random value].dll _mainRD"
XwinupdtRUNDLL32.EXE [random.dll]"Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder"
XWinUPPD.exe[random filename]Added by an unidentified WORM/TROJAN!
XWinz Firewall[random filename].exe"Added by a variant of the SDBOT WORM!"
Xwin_[4 random char][4 random num][4 random char][4 random num].exe"Added by the BANCOS.C TROJAN!"
XWNSAwnsts**.exe [* = random char]"PurityScan adware"
XWNSCwnsin**.exe [* = random char]"PurityScan adware"
XWNSIwnscp**.exe [* = random char]"PurityScan adware"
XWNSTwnsapi**.exe [* = random char]"PurityScan adware"
Xwpxmls[random filename]"Added by a variant of the SLAPER TROJAN!"
XWTSSwapi**.exe [* = random char]"PurityScan adware"
Xxswdmse[8 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
Xyahoo!"rundll32.exe [random]don.dllSet"
Xzcseacrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XZeno[random filename]"ZenoSearch adware"
Xzonealarm[random filename]"Added by an unidentified VIRUS
XZ_Start[random filename]"ZenoSearch adware"
X[12 random characters]avifile5.exe"IeDriver adware variant"
X[12 random characters]bootvid4.exe"IeDriver adware variant"
X[12 random characters]browser8.exe"IeDriver adware variant"
X[12 random characters]atitvo32.exe"IeDriver adware variant"
X[12 random characters]autodisc.exe"IeDriver adware variant"
X[12 random characters]cabview1.exe"IeDriver adware variant"
X[12 random characters]advpack1.exe"IeDriver adware variant"
X[12 random characters]batmeter.exe"IeDriver adware variant"
X[12 random characters]bidispl2.exe"IeDriver adware variant"
X[12 random characters]asferror.exe"IeDriver adware variant"
X[12 random characters]catsrvps.exe"IeDriver adware variant"
X[12 random characters]admparse.exe"IeDriver adware variant"
X[12 random characters]audiosrv.exe"IeDriver adware variant"
X[12 random characters]bootvid2.exe"IeDriver adware variant"
X[12 random characters]cmpbk321.exe"IeDriver adware variant"
X[12 random characters]ADPTIF67.exe"IeDriver adware variant"
X[12 random characters]asycfilt.exe"IeDriver adware variant"
X[12 random characters]ati2dvag.exe"IeDriver adware variant"
X[12 random characters]atl91036.exe"IeDriver adware variant"
X[12 random characters]blackbox.exe"IeDriver adware variant"
X[12 random characters]browser5.exe"IeDriver adware variant"
X[12 random characters]bthserv1.exe"IeDriver adware variant"
X[12 random characters]camocx28.exe"IeDriver adware variant"
X[12 random characters]CAMOCX74.exe"IeDriver adware variant"
X[12 random characters]capesnpn.exe"IeDriver adware variant"
X[14 random numbers]mradll.exe"Green AV rogue security software - not recommended
X[14 random numbers]rwg.exe"Green AV rogue security software - not recommended
X[3 random char]srv32[3 random char]srv.exe"Added by the BANCOS.N TROJAN!"
X[3-4 random letters]nslookup.exe"PurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder"
X[3-4 random letters]Srv32[path to file]"Added by the BANCSADE-A TROJAN!"
X[32 random hex numbers]tsc.exe"Total Security rogue security software - not recommended
X[32 random hex numbers]badware-protector.exe"Badware Protector rogue security software - not recommended
X[32 random numbers]av2009.exe"AntiVirus 2009 rogue security software - not recommended
X[32 random numbers]av360.exe"Antivirus 360 rogue security software - not recommended
X[32 random numbers]AVS.exe"Antivirus Sentry rogue security software - not recommended
X[32 random numbers]xpa.exe"XP Antivirus rogue security software - not recommended"
X[32 random numbers]total.exe"Total Antivirus rogue security software - not recommended
X[random characters]securewinload32x.exe"Added by the OPTIXP-N TROJAN!"
X[random characters]rsbmsc.exe"Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
X[random characters]_default[random].pif"Added by the BRONTOK-AI WORM and variants!"
X[random characters]j[random].exe"Added by the BRONTOK-AI WORM and variants!"
X[random characters]sv[random].exe"Added by the BRONTOK-AI WORM and variants!"
X[random characters]yesbron.com"Added by the BRONTOK-AI WORM and variants!"
X[random characters]systs.exe"Added by the AGENT-GDC TROJAN!"
X[random characters]xvassdf.exe"Added by the AUTORUN-BAD WORM!"
X[random filename]slk8x2peu.exe"QuickLinks adware"
X[random names]eee2.exe"MediaMotor adware"
X[random name]wincpu.exe"Added by an unidentified VIRUS
X[random name]m?dtc.exe"PurityScan adware"
X[random name]ping.exe"PurityScan adware. Note - do not confuse with the Microsoft utility of the same name as described here"
X[random name]CXTPLS_LOADER.EXE"AproposMedia adware"
X[random name]??plorer.exe"PurityScan adware"
X[random name]?hkdsk.exe"PurityScan adware"
X[random name]?hkntfs.exe"PurityScan adware"
X[random name]l?gonui.exe"PurityScan adware"
X[random name]m?iexec.exe"PurityScan adware"
X[random name]r?gsvr32.exe"PurityScan adware"
X[random name]t?skmgr.exe"PurityScan adware"
X[random name]w?auboot.exe"PurityScan adware"
X[random name]w?auclt.exe"PurityScan adware"
X[random name]w?crtupd.exe"PurityScan adware"
X[random name]w?wexec.exe"PurityScan adware"
X[random name]??erinit.exe"PurityScan adware"
X[random name]d?dplay.exe"PurityScan adware"
X[random name]n?tepad.exe"PurityScan adware"
X[random name]??chost.exe"PurityScan adware"
X[random name]??oolsv.exe"PurityScan adware"
X[random name]??xplore.exe"PurityScan adware"
X[random name]r?ndll32.exe"PurityScan adware"
X[random name]se?vices.exe"PurityScan adware"
X[random name]w?nlogon.exe"PurityScan adware"
X[random name]w?nword.exe"PurityScan adware"
X[random name]??anregw.exe"PurityScan adware"
X[random name]?ttrib.exe"PurityScan adware"
X[random name]j?vaw.exe"PurityScan adware"
X[random name]l?ass.exe"PurityScan adware"
X[random name]m?config.exe"PurityScan adware"
X[random name]n?lookup.exe"PurityScan adware"
X[random name]n?pdb.exe"PurityScan adware"
X[random name]??ool32.exe"PurityScan adware"
X[random name]??rss.exe"PurityScan adware"
X[random name]??rvices.exe"PurityScan adware"
X[random name]?ti2evxx.exe"PurityScan adware"
X[random name]d?xplore.exe"PurityScan adware"
X[random name]chkdsk.exe"PurityScan adware. Note - the legitimate Windows chkdsk.exe will always be located in %System% and will NOT figure among the startups!"
X[random name]dvdplay.exe"PurityScan adware"
X[random name]spoolsv.exe"PurityScan adware. Note - this is not the legitimate spoolsv.exe which is always located in %System%"
X[random name]w?aclt.exe"PurityScan adware"
X[random name]wucrtupd.exe"PurityScan adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) process"
X[random name]charmapnt.exe"Added by the BANCOS-DR TROJAN!"
X[random name]n?tdde.exe"PurityScan adware"
X[random name]r?gedit.exe"PurityScan adware"
X[random name]r?ndll.exe"PurityScan adware"
X[random name]scanregw.exe"PurityScan adware. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines"
X[random name]wuauboot.exe"PurityScan adware. Note - do not confuse with the legitimate wuauboot.exe process which should not figure in Msconfig/Startup!"
X[random name]w?nspool.exe"PurityScan adware"
X[random name]svchost.exe"Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config"
X[random name][random name].dll"SearchNet adware"
X[random name]iexpl0ra.exe"Added by the ULPM.BD TROJAN!"
X[random name]rundl13a.exe"Added by the GAMPASS-L TROJAN!"
X[random name]Servere.exe"Added by the LEGMIR-AQM TROJAN!"
X[random name]twain_32.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
X[random name]explore3.exe"Added by the DELF.FAN TROJAN!"
X[random name]taskmngr.exe"Added by the AGOBOT-CB WORM!"
X[random name]netdde.exe"PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[random name]chkntfs.exe"PurityScan adware. Do not confuse with the legitimate NTFS Volume Maitenance Utility (chkntfs.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[random name]notepad.exe"PurityScan adware. Note - this is not Windows Notepad which has the same executable name"
X[random name]services.exe"PurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X[random name]ntvdm.exe"PurityScan adware. Do not confuse with the legitimate ntvdm.exe process which is always located in %System% and should not figure in Msconfig/Startup!"
X[random name]msiexec.exe"PurityScan adware. Do not confuse with the legitimate Windows® Installer (msiexec.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[random name]userinit.exe"PurityScan adware. Do not confuse with the legitimate Userinit Logon Application (userinit.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[random name]regedit.exe"PurityScan adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup!"
X[random name]wuauclt.exe"PurityScan adware. Note - this is not the legitimate wuauclt.exe process
X[random name]?ervices.exe"PurityScan adware"
X[random name]s?chost.exe"PurityScan adware"
X[random name]c?rss.exe"PurityScan adware"
X[random name]mrgdll.exe"Nortel Antivirus rogue security software - not recommended"
X[random name]wox.exe"Nortel Antivirus rogue security software - not recommended"
X[random number]"rundll32.exe shell32.dllControl_RunDLL [random number].cpl"
X[random number]explorer.exe"Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
X[Randomly chosen existing folder name]_autorun.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_cfg.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_config.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_env.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_loader.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_login.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_setup.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_start.exe"Added by the ANTINNY-L WORM!"
X[random]lsass.scr"Added by the BANCBAN-CW TROJAN!"
X[random]svchost.scr"Added by the BANCBAN-CY TROJAN!"
X[random][random]tssd.exe"Antivirus Suite and AntiSpyware Soft rogue security software - not recommended
X[random][random]sysguard.exe"Antivirus Soft
X[random][random]sftav.exe"Antivirus Soft rogue security software - not recommended
X_pnd_Panda Antivirus_pnd_*****.exe [* = random char/digit]Added by the AGENT.NAK TROJAN!


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.