Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XGames Accelerationsvshost.exe"EasySearch adware"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
Xhellodollyshost.exe"Added by the YODO WORM!"
XHelplshost.exeIdentified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
Xishost.exeishost.exe"Added by the DLOADR-XJ TROJAN!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
XMicrosoft Clientmshost.exe"Added by the RBOT-AND WORM!"
XMicrosoft Command Csshost.exe"Added by the RBOT-CMK WORM!"
XMicrosoft IISsyshost.exe"Added by the FRANCETTE WORM!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMS Updatesyshost.exe"Added by the EVAMAN-F WORM!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeAgentsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xsecuresvshost.exe"Added by the RBOT-AFO WORM!"
XServicesmshost.exe"Added by the LANFILT-J TROJAN!"
Usmrcvshost.exe"Silent Monitoring surveillance software. Uninstall this software unless you put it there yourself"
Xsrshost.exesrshost.exe"Added by a variant of the RBOT-ASW WORM!"
XStartup UpdateCvshost.exe"Added by the GAOBOT.AO WORM!"
XSvhost Loadersvshost.exe"Added by the AGOBOT.G WORM!"
Xsvshostsvshost.exe"Added by the CHODE-H WORM!"
Xsvshostdriversvshost.exe"Added by the SDBOT-HN TROJAN!"
Xsyshostsyshost.exe"Added by the VB-DVZ TROJAN!"
XSystem Host Managersyshost.exe"Added by the BANWORM-C WORM!"
XVCS Hostvcshost.exe"Added by the RBOT-FKT WORM!"
XWinMessengersyshost.exe"Added by the OPANKI-E WORM!"
Xwinshost.exewinshost.exe"Added by the TOOSO WORM and variants!"
Xxorsvshost.exe"Added by the AGENT.DC TROJAN!"
XYahoo MessenggerSSVICSSHOST.exe"Added by the IMAUT.AA WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.