Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
Xffsvhost32.exe"Added by the LINEAG-AFF TROJAN!"
Xfzgsvhost32.exe"Added by the DLOADER.BDK TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
Xicq litescvhost.exe"Added by the AGENT-DSF TROJAN!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
XivHosttaskManager.exe"Added by a variant of the SPYBOT WORM! See here"
XivHost[6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
XJufualtsvhost.exe"Added by the SDBOT-ADJ WORM!"
Xloadsvhost32.exe"Added by the WOWCRAFT TROJAN!"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
Xload=svhost32.exe"Added by the LINEAGE-AB TROJAN!"
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
XMessenger Servicenvhost.exe"Added by the JLOK-A WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft Synchronization Manager 2svhostc.exe"Added by the SLINBOT.ST WORM!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
Xmssvhost32.exe"Added by the LEGMIR-AQO TROJAN!"
XMS Host Managerivhost.exe"Added by the RBOT-BJN WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
XMSNscvhost.exe"Added by the IRCBOT-ZW WORM!"
XMSStartOptimizerSCVHOST.EXE"Added by the DASMIN-E TROJAN!"
Xmsvhostaig.exe"Added by the AIMBOT-BC TROJAN!"
XNDAvsvhost.exe"Added by the SERFLOG.C WORM!"
Xnet32svhost.exeAdded by a variant of the Trojan.Clicker family
Xnet64svhoster.exe"Added by the AGENT.JVF TROJAN!"
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
Xonly23SCVHOST.exe"Added by the BCKDR-PUQ BACKDOOR!"
XOpera addonsvhost.exe"Added by the AGENT-IBD WORM!"
XPersonal Computerscvhost.exe"Added by the RBOT-AJE WORM!"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
Xrun=svhost.exe"Added by the ADMINCASH.B TROJAN!"
XSsvhost.exe"Added by the AGOBOT-LN WORM!"
Xscvhostsvzhost.exe"Added by a variant of the SPYBOT WORM!"
Uscvhostscvhost.exe"Wiretap surveillance software. Uninstall this software unless you put it there yourself"
Xscvhostscvhost.exe"Added by the AGOBOT-LI WORM!"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
Xscvhost.exescvhost.exe"Added by the LOHAV-N TROJAN!"
XSDAvsvhost.exe"Added by the SERFLOG.C WORM!"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
XServices Startupsvhost33.exe"Added by a variant of the RBOT WORM!"
XServicio Localsvhost.exe"Added by the SPYBOT.BGX WORM!"
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
XSrv Hostsrvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsrvhostsrvhost.exe"Added by the LIVUP.A BACKDOOR!"
XStarterscvhosting.exe"Added by the SDBOT.RU WORM!"
Xstarterscvhostingg.exe"Added by the FORBOT-FB WORM!"
Xstartkeyscvhost.exe"Added by the BIFROSE-PM TROJAN!"
XSunJavaUpdateSchedscvhost.exe"Added by the SDBOT-AVX WORM!"
XSVCHOSTscvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
XSVCHost Protocol32scvhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
XSVHOSTsvhost.exe"Added by the MYDOOM.I WORM! The file is located in %System%"
XSVHOSTSVHOST.EXE"Added by the ZORI.A VIRUS! The file is located in %System%\SVCHOSTV"
XSvhostSvhost.exe"Added by the VB-ASG WORM! This file is located in a ""Hwnd"" sub-directory of the Root folder (C:\)
XSvhost Loadersvshost.exe"Added by the AGOBOT.G WORM!"
XSvhost Service Serversvhostser.exe"Added by a variant of the RBOT WORM! See here"
Xsvhost updatesSvhost.exe"Added by a variant of the RBOT WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
Xsvhost1mdsn.exe"Added by the VB-EPK TROJAN!"
Xsvhost32svhost32.exe"Added by the AUTORUN-AWY WORM!"
XSymantecFilterChecksvhost.exe"Added by the BANKER-EEO TROJAN!"
XSystem Hostscvhost.exe"Added by a variant of the RBOT WORM!"
XSystemTraylsvhostwinlk.exe"Added by a variant of the SPYBOT WORM!"
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
XSysTraysvhost.exe"Added by the RAJILO-A WORM!"
XTask Managersvhost32.exe"Added by the TERMX.A WORM!"
XUpdate Checkerscvhost.exe"Added by the AGENT-DSF TROJAN!"
XUPDATEMSNsvhost.exeAdded by an unidentified WORM or TROJAN!
XUpdater Service Processsvhost32.exe"Added by the AGOBOT.TY WORM!"
XUsbDsvhost32.exe"Added by the AGENT.IB TROJAN!"
Xvhosthost.exe"Peppi adware"
XVhosts Protectionvhosts.exeAdded by an unidentified WORM or TROJAN!
XWinDLL (scvhost32.dll)"rundll32.exe scvhost32.dllstart"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Firewalllsvvhost.exe"Added by a variant of the RBOT WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWinmgr.exescvhost.exe"Added by the AGOBOT.AFG WORM!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWinUpdatesvhost.exe"Added by a variant of the SDBOT WORM!"
Xwlsvhost32.exe"Added by the WOWPWS-AF TROJAN!"
Xwmsvhost32.exe"Added by the LINEAGE.CIS TROJAN!"
XWSVCHOsvhost.exe"Added by the SPYBOT-OQ WORM!"
Xxysvhost32.exe"Added by the LINEAG-ABB TROJAN!"
XYahoo MessenggerRVHOST.exe"Added by the SILLYFDC-G WORM!"
XYahoo MessenggerSCVHOST.exe"Added by the SOHANA-V WORM!"
XYahoo Messenggerscvhosts.exe"Added by the SOHANNA-AH WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.