Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YavgfwsrvAVGFWSRV.EXE"Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks
YAvMaiSrvAvmaisrv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
YBDOESRVbdoesrv.exe"Bitdefender 8 antivirus and firewall"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
XClassessrv.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv2.exe"""Switch"" premium rate adult content dialler variant"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
NClipsrvClipsrv.exe"Supports Windows XP ClipBook Viewer
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XCoreSrvcoresrv.exe"Some IRC trojans/worms use this - see here for more information"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
?CTPDPSRVCTPDPSRV.EXE"Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?"
?cttdpsrvcttdpsrv.exe"??"
UDigiSrvDigiSrv.exe"Related to camera software from DigitalDreams"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
Yffprsrvffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffprsrv.exeffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffpsrvffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
Yffpsrv.exeffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
?FSDPSRVFSDPSRV.exe"??"
XgaSrvgaSrv.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XgaSrvegaSrve.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
Yhffsrvhffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
Yhffsrv.exehffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
XHijSrv32hijsrv.exe"Added by the BANKGERM-D TROJAN!"
XHostname Manager Serverhost32srv.exe"Added by a variant of the RBOT WORM!"
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
?hp Silent ServiceHpSrvUI.exe"HP related"
?IaNvSrvIaNvSrv.exe"Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?"
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
XInstant Accessmwsrvacc.exe"InstantAccess premium rate adult content dialer"
XInstant Accesslinewsrv.exe"InstantAccess premium rate adult content dialer variant"
XInternatmsgsrv32.exe"Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
YInternet Sharing Serveriss_srvr.exe"Intel AnyPoint internet sharing software. Now discontinued"
Xjohkjhsrvd.exe"Added by a variant of the SLAPER TROJAN!"
Xjohnj315srvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj3155srvcc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj3cdsrvdc.exe"Added by a variant of the SLAPER TROJAN!"
XKsrv32Ksrv32.exe"Added by the AGOBOT-PI WORM!"
Xlayersldmhostplsrvc.exe"Added by a variant of the SDBOT WORM!"
XLEMSRVlemsrv.exe"Added by the IRCBOT-TC TROJAN!"
XLive update monitorsrvany32.exe"Added by the AGOBOT.AFM WORM!"
?lmpdpsrvlmpdpsrv.exe"Related to a Lexmark printer/scanner. Printer sharing server? Is it required?"
XLocal runole servicesrvc32.exe"Added by the SMALL-DP TROJAN!"
Xlsa Serviceslsa2srv.exe"Added by the TAME-C WORM!"
Xlsasslsasrv.exe"Added by the MYDOOM.AG or MYDOOM.AS or MYDOOM.AU WORMS!"
XLTM2MSGSRV32.EXE"Added by the LITMUS.A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup! This one is located in %Windir%\Litmus"
XLTM2MPGSRV32.EXE"Added by the LITMUS.201 TROJAN!"
XLTM2MSGSRV320.EXE"Added by the LITMUS.C TROJAN!"
XMemory Allocation Servicescisrv.exe"Added by the IRCBOT.FC BACKDOOR!"
XMicrosoftnetsrv.exe"Added by the RBOT-GOS WORM!"
XMicrosoft Client Pcspoolsrv.exe"Added by the RBOT-AQM WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Serviceslssrv.exe"Added by the RBOT.CW WORM!"
XMicrosoft Serviceslsrv.exe"Added by the RBOT-BK WORM!"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Task Manager Daemonspoolsrv.exe"Added by the SDBOT.FLL WORM!"
XMicrosoft Update Servermssrv.exe"Added by an unidentified VIRUS
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicroSoft Visual SP2igfxsrvc32.exe"Added by the SDBOT.GAV WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoftPersonalFirewallspoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMsgsrv16Msgsrv16.exe"Added by the DELF family of TROJANS!"
YMSGSRV32.exemsgsrv32.exe"Windows 32-bit VxD Message Server. For more information on its function and why it's needed
UMSKServerExeMSKSrvr.exe"Part of McAfee Spamkiller"
XMsMsgSrvmsmsgsrv.exe"Added by the CQO TROJAN!"
XMSN Servicermsnsrv.exe"Added by a variant of the IRCBOT TROJAN!"
XMSNPluginSrvcsp6.exe"Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMSPluginSrvcp3.exe"Added by the RBOT-WV WORM!"
XMss Servmsssrv.exe"Added by the SLENFBOT.AA WORM!"
Xmssdbsrvmsupdtck.exeAdded by a variant of a password stealing TROJAN!
XMSUpdSrvmsupdsrv.exe"Browser hijacker
Xmsvsrv32msvsrv32.exe"Added by the AGOBOT-KM WORM!"
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
Umynswwntsrv.exe"Net Screen Watcher surveillance software. Uninstall this software unless you put it there yourself"
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
XNetBiosSrvcHPSrvPrt.exe"Added by the SDBOT-COL WORM!"
XNTsrv.exeNTsrv.exe"Added by a variant of the SERVU-O TROJAN!"
Yoeprsrvoeprsrv.exe"Outlook Express Privacy - which ""lets you control access to Outlook Express and its email message database. When you enable protection
Yoeprsrv.exeoeprsrv.exe"Outlook Express Privacy - which ""lets you control access to Outlook Express and its email message database. When you enable protection
Yoepsrvoepsrv.exe"Outlook Express Protector from Ixis Research
Yoepsrv.exeoepsrv.exe"Outlook Express Protector from Ixis Research
Yoessrvoessrv.exe"Outlook Express Security - which is used ""to control access to Outlook Express and its databases. When it is active
Yoessrv.exeoessrv.exe"Outlook Express Security - which is used ""to control access to Outlook Express and its databases. When it is active
Xoe_drop_spamoesrv.exe"Dropspam adware"
XOnSrvrOnSrvr.exeOnWebMedia adware
UPanda Antispam Server ServicePasSrv.exe"AntiSpam part of an older version of Panda Internet Security"
YPanda Preventium+ ServicePREVSRV.EXE"Part of the 2004 & 2005 versions of Panda Antivirus and Internet Security"
Updp Serverctpdpsrvr.exeIncluded and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
UPDVDDXSrvPDVDDXSrv.exe"Remote Control background application for Cyberlink's PowerDVD DX - a Dell specific version of their standard PowerDVD product. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
XPersonal Firwallptmedsrv.exe"Added by the SDBOT.XY WORM!"
?PFW_PullSrvPULL.EXE"Personal Firewall related?"
XPluto! Pagersrvhandle.exe"Added by the REDPLUT VIRUS!"
XPmediawinsrvc.exe"Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!"
XPOPPopSrv***.exe"PeopleonPage foistware
Xpopsrv146popsrv146.exe"AproposMedia adware"
Xqappsrvc32.exeqappsrvc32.exe"Detected by Kaspersky as the WEBBER.M TROJAN!"
XReg ServiceREGSRV32.EXE"Added by the RBOT.ZW WORM!"
XREGEDITRegsrv32.com"Added by the SOUTHGHOST WORM!"
Xreggsdgspoolsrv.exe"Added by the SDBOT-DI WORM!"
XRegistry Serverregsrv32.exe"Added by the RBOT-GM WORM!"
XRegistry ServiceREGSRV32.EXE"Added by a variant of the RBOT WORM!"
XRegScanDLLSRV32.EXE"Added by the AGOBOT.AEW WORM!"
Xregsrvregsrv.exe"Added by the OPTIXPRO.11 TROJAN!"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
XRegSrv64DRegSrv64D.exE"Added by the WINKO.AO WORM!"
Xregsrvcregsrvc.exe"Added by the STOPED-A TROJAN!"
Xrsrvmon.exersrvmon.exe"Added by the AGENT.NY TROJAN!"
NSa3dsrvSa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
XScanRegistrynsrvnt.exe"Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe"
XScvsrv32scvsrv32.exe"Added by the AGOBOT-PM BACKDOOR!"
XServer Registryregsrv32.exe"Added by the VB-EJD TROJAN!"
XServices DLL Loadersrvdll.exe"Added by the SLENFBOT.ZS WORM!"
Xsmcservwinsrv.exe"Added by the AGOBOT-OU WORM!"
Xsmsrvsmsrv.exe"Added by the AGOBOT-SX WORM!"
?sndsrvcSNDSRVC.EXE"Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required?"
XSpool Managerspoolsrv.exe"Added by the BANKER-FR TROJAN!"
XSpooler ServiceSpoolsrv.exe"Added by the JOINER.C1 TROJAN!"
Xspoolsrv.exespoolsrv.exeAdded by an unidentified WORM or TROJAN! Located in %System%
Xsrvwinlogon.exe"Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data"
XSrv Hostsrvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSrv RPCromNClienti386.exe"Added by the WATSOON.A TROJAN!"
XSrv32Srv32.exe"Added by the OPASERV.J WORM!"
XSrv32 spool servicerunsrv32.exe"Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN!"
XSrv32 spool servicespoolsrv32.exe"Added by the SPYRE-B TROJAN!"
XSrv32 spool service[path to trojan]"Added by the DLOADER-LB TROJAN!"
XSrv325Srv325.exe"Added by the AGOBOT-PR WORM!"
XSrv32Old[worm filename].PIF"Added by the OPASERV.J WORM!"
USrv32WinSpyAgent4.exe"SpyAgent - monitoring software that creates records of everything people do on a computer
USrv32WinSvchost.exe"Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
USrv32Winsysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
Usrv32winwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself remove it"
XSrvce Pack Updtesvcpack.exe"Added by a variant of the RBOT WORM!"
Xsrvexc.exesrvexc.exe"Added by the SERVSAX TROJAN!"
Xsrvhostsrvhost.exe"Added by the LIVUP.A BACKDOOR!"
Usrvprcsrvprc.exe"ActMon surveillance software. Uninstall this software unless you put it there yourself"
NSSDPSRVssdpsrv.exe"Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program
UStart Serviceupssrv.exe"Cyber Power PowerPanelPlus software. ""During a power failure the system automatically saves and closes open files within the battery backup time and safely powers down your computer"""
Xstisrvstisrv.exe"Added by the RBOT.BQF WORM!"
XSygate Personal FirewallMSNSRV32.exe"Added by a variant of the RBOT WORM!"
Xsystem handlersrvhandle.exe"Added by the REDPLUT VIRUS!"
XSystem Managerwinsrv32.exeAdded by an unidentified WORM or TROJAN!
XSystem ProfileRegsrv.exe"Added by a variant of the OPTIX TROJAN!"
YThpSrvthpsrv.exeToshiba Hard Drive Protection Utility - moves the Hard Drive head to a safe position in case of shock or vibration to reduce the risk of damage that could be caused by head-to-disk contact
UTMESRV.EXETMESRV11.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMESRV.EXETMESRV21.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMESRV.EXETMESRV31.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMESRV31TMESRV31.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMExLogonTMESRV.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
XTmntsrv32Tmntsrv32.exe"Added by the STARTPAGE.O TROJAN!"
?ToPassSrvPktopass.exe"Related to Caere Pagekeeper scanning software (now taken over by Scansoft)
UTrackpointSrvdaemon.exe"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
UTrackpointSrvtp4serv.exeSupports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
UTrackPointSrvtp4mon.exe"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
Xtsrvt2serv.exe"Added by the WAREZOV.AT WORM!"
Xtsrvtsrv.exe"Added by the WAREZOV.W WORM!"
NTwkSCardSrvSCardS32.ExeUsed with Towitoko SmartCard Readers for card recognition
Uuklwmpusrvc.exe"Ultimate Keylogger surveillance software. Uninstall this software unless you put it there yourself"
XUser Servicerusnsrvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Sharing Serverusnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUserfile Sharing Servusnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUserinterface Reportersrv32.exe"ISTBar adware"
UUSIUDF_Eject_MonitorUSISrv.exe"Added by Ulead DVD Moviefactory. This program monitors your DVD or CD drives and alerts when you eject the media or have no media present"
XVgaDriverRsrVga32.exe"Added by the KEYLOG-AH TROJAN!"
UVPCUserServicesVMUSrvc.exe"Part of ""DOS Virtual Machine Additions"" for Microsoft Virtual PC
Nvspdfprsrv.exevspdfprsrv.exe"Visage PDF Printer"
Xvsrv32vsrv32.exe"Added by the AGOBOT.AIF WORM!"
XWIN USB SUPPORTgrxsrv.exe"Added by a variant of the RBOT WORM!"
Xwin32winsrv32.exe"Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites"
XWin32msnsrv.exe"Added by a variant of the SDBOT WORM!"
Xwindllwindotnetsrv.exe"Added by the AUTORUN-ANO WORM!"
XWindows DLL Trackerspoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
XWindows Managerwinsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows PNP Serverpnpsrv.exe"Added by the RBOT-AKM WORM!"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Server Driverssyssrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Service Utititywinsrvc.exe"Added by the RBOT-ASI WORM!"
XWindows Servicesavsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Spool Serverspoolsrv.exe"Added by the SDBOT-ACT WORM!"
XWindows SpoolaPrint Servicespoolasrv.exe"Added by the SDBOT-AYD WORM!"
XWindows SpoolerSPOOLSRV.EXE"Added by the SPYBOT.P WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
Xwindows spoolsrv servicespoolssv.exe"Added by the SDBOT-AWV WORM!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Streams Serverlocalsrv.exe"Added by the SDBOT.LN WORM!"
XWindows Time ServerTimeSRV.exe"Added by the SPYBOT.DNC WORM!"
XWindows Updatelivesrvs.exe"Added by a variant of the RBOT WORM!"
XWinMsrv32WinMsrv32.exe"Added by the GAOBOT.AFJ WORM!"
Xwinregsrvwinregsrv.exe"Added by the SYNRG TROJAN!"
XWinSrvkn0x.exe"Added by the HOBBIT.F WORM!"
XWinSrvSHIZZLE.EXE"Added by the HOBBIT.C WORM!"
XWinsrvwinsrv.exe"Added by the OPASERV.T WORM!"
Xwinsrvwinsrv.exe"Added by the NETSNAK-B TROJAN!"
Xwinsrv3services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWMI Performance Adapter Serviceswmiapsrvs.exe"Added by the RBOT.COU BACKDOOR!"
Xwmisrvwmisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xwsrv32wsrv32.exe"Detected by Kaspersky as the AGENT.EP TROJAN!"
XxxsrSrv32xxsrsrv.exe"Added by the BANCSDE-E TROJAN!"
X[12 random characters]catsrvps.exe"IeDriver adware variant"
X[12 random characters]audiosrv.exe"IeDriver adware variant"
X[3 random char]srv32[3 random char]srv.exe"Added by the BANCOS.N TROJAN!"
X[3-4 random letters]Srv32[path to file]"Added by the BANCSADE-A TROJAN!"
X[executed file name]Regsrv32.com"Added by the SOUTHGHOST WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.