Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

KEY:

  • L = Legit, O = Open to Debate, X = Malware/Bad

Name Process Details
L(PinnacleSys.MediaServer)pmshost.exeRelated to Pinnacle_Systems Inc.
X.NET Framework Servicesvchost.exeTrojan-PSW.Win32.Sagic.15 Virus
X.NET Framework Service (.NET Connection Service)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LAlertersvchost.exeNotifies selected users and computers of administrative alerts. If the service is stopped programs t
XAppMgmtsvchost.exe -k AppMgmtAdded by the Fuwudoor TROJAN!
LAT Host Serviceatnthost.exeRelated to WebEx
LBiometric Authentication ServiceDpHost.exeRelated to DigitalPersona Inc.
XBrowsersvchost.exe -k BrowserAdded by the Fuwudoor TROJAN!
LBullGuard Email Monitoring (BsMailProxy)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard File Monitoring (BsFileSpy)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard Firewall (BsFirewall)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard Main (BGMainSvc)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LCOM HostcomHost.exeRelated to Norton/Symantec Internet Security
XCOM Message Transfer (mscommt)svchost.exe -k mscommtAdded by the Troj/Dbit-A TROJAN!
XCOM+ System Service (DLLHOST)dllhost.exeAdded by the Backdoor.Win32.SdBot.xd as identified by Kaspersky TROJAN! Note: This worm rojan is loc
XCompatibil)svchost.exeAdded by the Troj/Keylog-AT TROJAN! Note: This is not the legitimate Windows process svchost.exe (Wh
XConfig Loaderscvhost.exeseveral Agobot variants
XDisk Monitor Services (DiskMon32)svchost.exe -k dmonAdded by the Hanmon TROJAN! Note: This trojan file is found in the System32 folder.
Xdmserversvchost.exe -k dmserverAdded by the Fuwudoor TROJAN!
XDNS Server (DNS Server)svchost.exeAdded by the Troj/Feutel-Y TROJAN! Note: This is not the legitimate Windows Process. (Which is found
XDynamic Library Host (DLLHOSTS)dllhost.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Note: This worm rojan is loca
XDynamicHost (DLHOST)dlhost.exeAdded by the W32/Tilebot-BO WORM! Note: This worm file is found in the Windows or Winnt folder.
Xgeneric host process (svchost)svchost.exeAdded by the W32/Tilebot-BB WORM! Note: This is not the legitimate Windows process svchost.exe (Whic
XHardware Detection (Serv-U)svchost.exeReported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows proces
Xhost (host)host.exeAdded by the Troj/GrayBrd-AR TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
Xhost Service For Windows (mshost)mshost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XHost Services (Host Services)myhost.exeAdded by the W32/Tilebot-AT WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XIPRIP (IPRIP)svchost.exe -k netsvcsAdded by the Backdoor.Ripgof TROJAN! Read the link rootkit type stealth involved.
Xkdcsvchost.exe -k kdcAdded by the Fuwudoor TROJAN!
XLmHostssvchost.exe -k LmHostsAdded by the Fuwudoor TROJAN!
XLoader)SVCHOST.EXEAdded by the RBOT.BZF WORM! Note: This is not the legitimate Windows process SVCHOST.EXE (Which is a
LMcAfee SiteAdvisor ServiceMcSvHost.exeMcafee Inc - commonly located at C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
XMessengersvchost.exe -k MessengerAdded by the Fuwudoor TROJAN!
XMicrosoft Agentqxchost.exeAdded by the W32/Sdbot-CWP WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
XMicrosoft Agentrschost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XMicrosoft Agentsnchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMicrosoft Agentffchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: Located in C:WindowsSystemdllcache (Win9
XMicrosoft Agentlpohost.exeAdded by the W32/Sdbot-CWQ WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
XMicrosoft Print Spooler (WINDRIVER)scvhost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XMicrosoft Windows Update (Microsoft Update)scvvhost.exeAdded by the W32/Forbot-FH WORM!
XMS Internet Countermeasures Framework (ICF)System32:svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note DO NOT delete the svchost.exe file.
XMsHS64 or cvcworking setting (cvcWork or MsHS64)syscvhost.exe or MsHS64.exeAdded by the W32/Tilebot-BU WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XNetLogonsvchost.exe -k NetLogonAdded by the Fuwudoor TROJAN!
XNetwork Connections Sharing (RpcTftpd)svchost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start manually
XNetwork DDE DSMA (NetDDEdsma)svchost.exeAdded by the W32/Sdbot-BMG WORM! Note: This is not the legitimate Windows Process. (Which is found i
Xntmssvcsvchost.exe -k ntmssvcAdded by the Fuwudoor TROJAN!
XNVIDIA Driver ServiceĦĦ (NVSv )svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LPCHostpchost.exeRelated to PCHost
XPolicy Agentsvchost.exe -k Policy AgentAdded by the Fuwudoor TROJAN!
XPower Manager (PowerManager)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XProcess)svchost.exeAdded by the W32/Tilebot-DM WORM! Note: This worm rojan is located in C:%WINDIR% folder.Note: This i
XProtectedStoragesvchost.exe -k ProtectedStorageAdded by the Fuwudoor TROJAN!
XRasAt (Remote Connection)svchost.exeAdded by the Troj/Singu-AF TROJAN!
LRockwell Application Services (RsvcHost)RsvcHost.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
XServer Management Servicesvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XService Hosts (ServiceHost)shost.exeAdded by the W32/Rbot-AXG WORM! Note: This worm file is found in the Windows or Winnt folder.
XserviceMangr (tcphost.exe)TCPHOST.EXEAdded by the SDBOT.CSG WORM! Read the link rootkit type stealth involved.
Xstchost.exe (moto)stchost.exeAdded by the Troj/Vixup-L TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
Xsvahostsvahost.exeAdded by the Backdoor.Win32.SdBot.aad as identified by Kaspersky TROJAN! Note: This worm rojan is lo
XSVC Module (SVC Module)svchost.exeAdded by the W32/Sdbot-ADG WORM! Note: This is not the legitimate Windows Process. (Which is found i
XsvchostSVCHOST.EXEAdded by the SDBOT.CNK WORM! Note: This is not the legitimate Windows process svchost.exe (Which is
Xsvchost.exe (moto)svchost.exeAdded by the Troj/Agent-MD TROJAN! Note: This worm rojan is located in C:%WINDIR%
Xsvchost.exe (svchost.exe)svchost.exeAdded by the Troj/GrayBird-X TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
XSystem Event Messagingsvchost.exeSeems to be viral
Xtaskmng (svchost)svchost.exeAdded by the W32/Tilebot-AW WORM! Read the link rootkit type stealth involved.
XTrkSvrsvchost.exe -k TrkSvrAdded by the Fuwudoor TROJAN!
XTrkWkssvchost.exe -k TrkWksAdded by the Fuwudoor TROJAN!
LUnicenter Remote Control Host (rcHost)rcHost.exeRelated to Unicenter_Remote_Control_Host From Computer Associates Note: Located in C:BA_MGMTTNGRCORC
XW32Timesvchost.exe -k W32TimeAdded by the Fuwudoor TROJAN!
XWin32 Kernel Update (Win32Kernel)win32host.exeAdded by the W32/Tilebot-FE WORM! Note: This worm file is found in the Windows or Winnt folder. Allo
XWindows Configuration Backup Service (CfgBackupSvc)svchost.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%CONF
XWindows Configuration Manager (ConfigMgr)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindows Host Services (DLLHOST32)dllhost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindows Kernelsvchost.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in C:Wi
XWindows Kernel (Windows Kernel)svchost.exeAdded by the W32/Rbot-ANO WORM! Note: This is not the legitimate Windows Process. (Which is found in
?Windows LAN Service Managersvchost.exeUnknow origin
XWindows Management (Windows Management)svchost.exeAdded by the Troj/Feutel-AN WORM! Note: This is not the legitimate Windows process(Which is always f
XWindows Network Mapping Service (NetMap)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. This worm rojan is located in C:%WINDIR%system
XWindows Security Drivers (csrs)svchost.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
XWindows Smrss Servicesvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows Update Client (WUClient)upnphost.exeAdded by the W32.Janx WORM!
XWindows Update Client (WUClient)pnphost.exeAdded by the W32.Janx WORM!
XWINS Client (RpcPatch)dllhost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start automatically
XWksPatchSvchost.exeAdded by the W32.Welchia.B or W32.Welchia.C or W32.Welchia.D or W32.Welchia.K WORM! **Note - Service