Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
XJufualtsvhost.exe"Added by the SDBOT-ADJ WORM!"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XNDAvsvhost.exe"Added by the SERFLOG.C WORM!"
Xnet32svhost.exeAdded by a variant of the Trojan.Clicker family
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XOpera addonsvhost.exe"Added by the AGENT-IBD WORM!"
Xrun=svhost.exe"Added by the ADMINCASH.B TROJAN!"
XSsvhost.exe"Added by the AGOBOT-LN WORM!"
XSDAvsvhost.exe"Added by the SERFLOG.C WORM!"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
XServicio Localsvhost.exe"Added by the SPYBOT.BGX WORM!"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
XSVHOSTsvhost.exe"Added by the MYDOOM.I WORM! The file is located in %System%"
XSVHOSTSVHOST.EXE"Added by the ZORI.A VIRUS! The file is located in %System%\SVCHOSTV"
XSvhostSvhost.exe"Added by the VB-ASG WORM! This file is located in a ""Hwnd"" sub-directory of the Root folder (C:\)
Xsvhost updatesSvhost.exe"Added by a variant of the RBOT WORM!"
XSymantecFilterChecksvhost.exe"Added by the BANKER-EEO TROJAN!"
XSysTraysvhost.exe"Added by the RAJILO-A WORM!"
XUPDATEMSNsvhost.exeAdded by an unidentified WORM or TROJAN!
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWinUpdatesvhost.exe"Added by a variant of the SDBOT WORM!"
XWSVCHOsvhost.exe"Added by the SPYBOT-OQ WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.