Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsssystem.exe"Added by a variant of the RBOT WORM!"
XCMSystemCMSystem.exe"CASClient adware"
XCommandsystem.exe"Added by the GATECRASH.A or GATECRASH.B TROJANS!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XControl PanelSystem.exe"Added by the DANI TROJAN!"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
Xgwizntsystem.exe"Added by the NITWIZ.A TROJAN!"
Xisystemisystem.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
Xjavasystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMessenger91messengersystem.exe"Added by the RBOT-FPF WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft IPCsystem.exe"Added by the NULLBOT TROJAN!"
XMicrosoft NetworkNetworksystem.exe"Added by the SDBOT-AAI WORM!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft System Administrationsystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft System Monitorsystem.exe"Added by the IRCBOT.AUT BACKDOOR!"
XMicrosoft Updatesystem.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Update 23NtKernelSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinesystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft xpsp2Networksystem.exe"Added by a variant of the SDBOT WORM!"
XMozillacorpsystem.exe"Added by the SILLYFDC WORM!"
XMSkernel32System.exe 4820"Added by the TUXDER BACKDOOR!"
XMSN MessangerSystem.exe"Added by the IRCBOT-AFX TROJAN!"
Xmsoft-updater23slssystem.exe"Added by the RBOT-ASR WORM!"
XNew Anti VirusSystem.exe"Added by the BRONTOK-CH WORM!"
XNt System Protocolntsystem.exe"Added by the RBOT.DSB TROJAN!"
XPaSystempasystem.exe"Targetsaver adware variant"
XPrintMngrsystem.exeAdded by an unidentified TROJAN!
XPrintSpoolSvSystem.exe"Added by the BDOOR-S BACKDOOR!"
XProtection Systempsystem.exe"Protection System rogue security software - not recommended
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
XRecycle Bin Handler 2005system.exe"Added by the BDOOR-HO BACKDOOR!"
Xserversystem.exe"Added by the METHS-A TROJAN!"
XServicosSystem.exe"Added by the BANCOS-BCM TROJAN!"
Xshellsystemshellsystem.exe"Added by the UPCHAN TROJAN!"
Xssgrate.exesystem.exe"Added by the MITGLIEDER.C TROJAN!"
XSYS1system.exe"Added by the SILLYFDC-AP WORM!"
XsysPersonalFirewallsystem.exe"Added by the WOOTBOT.FH WORM!"
XSysProtectSystem.exe"Added by the NETSPY TROJAN!"
XSystemsystem.exeAdded by various WORMS and TROJANS!
XSystemsystem.exe (74295303)"Added by the VB-IU WORM!"
XSystem Backupmsystem.exeAdult content dialler
XSystem Kernal Supportsystem.exe"Added by the SDBOT.BWV WORM!"
Xsystem managerSystem.exe"Added by the FORBOT-BO WORM!"
XSystem Process Analization Threadsystem.exe"Added by a variant of the RBOT WORM!"
XSystem Scannersystem.exe"Added by the AGOBOT-DI BACKDOOR!"
XSystem servicesystem.exe"Added by the BANCOS.AA TROJAN!"
XSystem Update2system.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updater Machinesystem.exe"Added by the CIADOOR.GN BACKDOOR!"
XSystem.exeSystem.exeAdded by various WORMS and TROJANS!
Xsystem.exesystem.exe"Added by the JAMPORK.E WORM!"
Xsystem.exesystem.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %WINDIR%\pchealth\helpctr\binaries"
XSystem32system.exe"Added by the BUSHTRO122 TROJAN!"
XSysTraysystem.exe"Added by the DELF.E TROJAN!"
XTaskmgrsystem.exe"Added by the PAKES.G TROJAN!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XWIN USB 2.0usbsystem.exeAdded by an unidentified WORM of TROJAN!
XWindowssystem.exe"Added by the SPYBOT.OBB WORM!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows Netsystem LayerNetsystem.exe"Added by the RBOT.BEI WORM!"
Xwindows runsystem.exe"Added by the ICPASS-A WORM!"
XWindows Systemsystem.exe"Added by the MYTOB-GN WORM!"
XWindows System Managerwinsystem.exe"Added by the RBOT-AN WORM!"
XWindows Update Softwaresystem.exe"TOFGER.BX spyware"
XWindows32system.exeUnknown malware
XWindows_Protectwinsystem.exe"Added by a variant of the RBOT WORM!"
Xwinlogonsystem.exeAdded by a variant of the DELF.CNS TROJAN!
XWinSyssystem.exe"Added by the DAPROSY WORM!"
XWinSystemwinsystem.exe"Added by the WHITEBAIT WORM!"
XWin_api_driversystem.exe"Added by the REVIRD TROJAN!"
X[Entry name]System.exe"Added by the NETHIEF-N TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.