Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

KEY:

  • L = Legit, O = Open to Debate, X = Malware/Bad

Name Process Details
X.NET Framework Servicesvchost.exeTrojan-PSW.Win32.Sagic.15 Virus
X.NET Framework Service (.NET Connection Service)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LAlertersvchost.exeNotifies selected users and computers of administrative alerts. If the service is stopped programs t
XAppMgmtsvchost.exe -k AppMgmtAdded by the Fuwudoor TROJAN!
XBrowsersvchost.exe -k BrowserAdded by the Fuwudoor TROJAN!
LBullGuard Email Monitoring (BsMailProxy)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard File Monitoring (BsFileSpy)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard Firewall (BsFirewall)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard Main (BGMainSvc)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
XCOM Message Transfer (mscommt)svchost.exe -k mscommtAdded by the Troj/Dbit-A TROJAN!
XCompatibil)svchost.exeAdded by the Troj/Keylog-AT TROJAN! Note: This is not the legitimate Windows process svchost.exe (Wh
XDisk Monitor Services (DiskMon32)svchost.exe -k dmonAdded by the Hanmon TROJAN! Note: This trojan file is found in the System32 folder.
Xdmserversvchost.exe -k dmserverAdded by the Fuwudoor TROJAN!
XDNS Server (DNS Server)svchost.exeAdded by the Troj/Feutel-Y TROJAN! Note: This is not the legitimate Windows Process. (Which is found
Xgeneric host process (svchost)svchost.exeAdded by the W32/Tilebot-BB WORM! Note: This is not the legitimate Windows process svchost.exe (Whic
XHardware Detection (Serv-U)svchost.exeReported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows proces
XIPRIP (IPRIP)svchost.exe -k netsvcsAdded by the Backdoor.Ripgof TROJAN! Read the link rootkit type stealth involved.
Xkdcsvchost.exe -k kdcAdded by the Fuwudoor TROJAN!
XLmHostssvchost.exe -k LmHostsAdded by the Fuwudoor TROJAN!
XLoader)SVCHOST.EXEAdded by the RBOT.BZF WORM! Note: This is not the legitimate Windows process SVCHOST.EXE (Which is a
XMessengersvchost.exe -k MessengerAdded by the Fuwudoor TROJAN!
XMS Internet Countermeasures Framework (ICF)System32:svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note DO NOT delete the svchost.exe file.
XNetLogonsvchost.exe -k NetLogonAdded by the Fuwudoor TROJAN!
XNetwork Connections Sharing (RpcTftpd)svchost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start manually
XNetwork DDE DSMA (NetDDEdsma)svchost.exeAdded by the W32/Sdbot-BMG WORM! Note: This is not the legitimate Windows Process. (Which is found i
Xntmssvcsvchost.exe -k ntmssvcAdded by the Fuwudoor TROJAN!
XNVIDIA Driver ServiceĦĦ (NVSv )svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XPolicy Agentsvchost.exe -k Policy AgentAdded by the Fuwudoor TROJAN!
XPower Manager (PowerManager)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XProcess)svchost.exeAdded by the W32/Tilebot-DM WORM! Note: This worm rojan is located in C:%WINDIR% folder.Note: This i
XProtectedStoragesvchost.exe -k ProtectedStorageAdded by the Fuwudoor TROJAN!
XRasAt (Remote Connection)svchost.exeAdded by the Troj/Singu-AF TROJAN!
LRockwell Application Services (RsvcHost)RsvcHost.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
XServer Management Servicesvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XSVC Module (SVC Module)svchost.exeAdded by the W32/Sdbot-ADG WORM! Note: This is not the legitimate Windows Process. (Which is found i
XsvchostSVCHOST.EXEAdded by the SDBOT.CNK WORM! Note: This is not the legitimate Windows process svchost.exe (Which is
Xsvchost.exe (moto)svchost.exeAdded by the Troj/Agent-MD TROJAN! Note: This worm rojan is located in C:%WINDIR%
Xsvchost.exe (svchost.exe)svchost.exeAdded by the Troj/GrayBird-X TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
XSystem Event Messagingsvchost.exeSeems to be viral
Xtaskmng (svchost)svchost.exeAdded by the W32/Tilebot-AW WORM! Read the link rootkit type stealth involved.
XTrkSvrsvchost.exe -k TrkSvrAdded by the Fuwudoor TROJAN!
XTrkWkssvchost.exe -k TrkWksAdded by the Fuwudoor TROJAN!
XW32Timesvchost.exe -k W32TimeAdded by the Fuwudoor TROJAN!
XWindows Configuration Backup Service (CfgBackupSvc)svchost.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%CONF
XWindows Configuration Manager (ConfigMgr)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindows Kernelsvchost.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in C:Wi
XWindows Kernel (Windows Kernel)svchost.exeAdded by the W32/Rbot-ANO WORM! Note: This is not the legitimate Windows Process. (Which is found in
?Windows LAN Service Managersvchost.exeUnknow origin
XWindows Management (Windows Management)svchost.exeAdded by the Troj/Feutel-AN WORM! Note: This is not the legitimate Windows process(Which is always f
XWindows Network Mapping Service (NetMap)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. This worm rojan is located in C:%WINDIR%system
XWindows Security Drivers (csrs)svchost.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
XWindows Smrss Servicesvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWksPatchSvchost.exeAdded by the W32.Welchia.B or W32.Welchia.C or W32.Welchia.D or W32.Welchia.K WORM! **Note - Service