Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
YashMaiSvashmaisv.exe"E-mail scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
XeMakeSVEMAKESV.EXE"""Switch"" adult content dialer"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
Xgsvgsv.exeAdded by the ROBAL 1.0 backdoor TROJAN!
XhuigeziSP00LSV.EXE"Added by the GRAYBIRD.J BACKDOOR! Note the digit ""0"" in the command"
Xload=Spoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
Xmachine-debuggermdmsv.exe"Added by the AGOBOT-BR WORM!"
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
XMicrosoft DLL Verifiercsrssv.exe"Added by the RBOT-ATK WORM!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMSN Managermsnmgrsv.exe"Added by the IRCBOT.BAZ BACKDOOR!"
XMSN Update Servicemsnupdsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xnetsv32sv.exe"Added by the DELF.CCD TROJAN!"
XNtsysvntsysv.exe"Added by the MIFENG-E TROJAN!"
Xpoolsvpoolsv.exeAdded by an unidentified WORM or TROJAN!
XPrint SpoolerSpoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
XRegsvregsv.exeSearch hijacker - redirecting to scheo.com
XRegsvcregsv.exeAdded by an unidentified TROJAN!
XSANS Servicesansv.exe"Added by the VANEBOT-AH WORM!"
XShell Extensionspollsv.exe"Added by the LOVGATE.Z WORM!"
XSP00LSVSp00lsv.exe"Added by the GRAYBIRD.E TROJAN!"
Xspoo1svspoo1sv.exe"Added by the SOULJET TROJAN!"
XSpooler SubSystem AppspooIsv.exe"Added by the LINKBOT.M WORM!"
XSpoolServicespolsv.exe"Added by the AGOBOT-CS WORM!"
XSpoolsvSpoolsv.exe"Added by the CIADOOR.121 VIRUS! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
Xspoolsvspoclsv.exe"Added by the FUJACKS-M WORM!"
Xspoolsvspoolsv.exe"Added by the ZAPCHAS-EE TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%\Temp\spoolsv"
Xspoolsvspoolsv.exe"Added by the ANTINNY-BH WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\Messenger"
Xspoolsvspoolsv.exe"Added by the OURXIN.C TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in a ""spoolsv"" subfolder"
XSpoolsvspoolsv.exe"Added by the ANTINNY.F WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Program Files%\Lotus"
Xspoolsv.exe[random filename]"Added by the RBOT-JB WORM!"
USprint SmartViewSprintSV.exe"Sprint SmartView wireless connectivity manager which supports cards from multiple manufacturers including Intel
Xstartkeyrtfmsv.exe"Added by the EDEPOL-C TROJAN!"
XSun Java Updaterstacsv.exe"Added by the BUZUS.DBFM TROJAN!"
XSunJavaUpdatSchedspoolsv.exe"Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger"
XSV00LSVSV00LSV.EXE"Added by the GRAYBIRD-C TROJAN!"
XSVCH0STspoo1sv.exe"Added by the VB-HF TROJAN!"
XSVCHOSTSPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
Xsvcsharespoclsv.exe"Added by the FUJACKS-A VIRUS!"
XSyBot v2.1 By Sky-DancerHPSV.exe"Added by the ZOTOB.I WORM!"
XSystem Update Servicewmiprvsv.exe"Added by the AGOBOT.YG WORM!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWindows Acer Serviceacersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
XWindows Activate Systemsyssv.exe"Added by a variant of the SPYBOT WORM!"
XWindows Help Servicewinhelpsv.exe"Added by the RBOT-LP WORM!"
XWindows Spools SVwinsv.exe"Added by the RBOT-AUQ WORM!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
Xwindows spoolsrv servicespoolssv.exe"Added by the SDBOT-AWV WORM!"
XWindows SSL Filewinssv.exe"Added by the WOOTBOT.CA WORM!"
XWinsock2 driverSPOLSV.EXE"Added by the SPYBOT-CM WORM!"
XWinUpdsvwinupdsv.exe"Added by the DROPO MACRO!"
X[random name]??oolsv.exe"PurityScan adware"
X[random name]spoolsv.exe"PurityScan adware. Note - this is not the legitimate spoolsv.exe which is always located in %System%"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.