Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
N uoltray exec.exeNetzero free ISP software - not required
X Up Service up32.pif"Added by the RBOT-ARI WORM!"
X upascw upascw.exe"PersonalAntiSpy rogue spyware remover - not recommended
N UpConfgVer UpgConf.exe"Part of Panda Antivirus and Internet Security. Purpose unclear
X UPCTPcw UPCTPcw.exe"Part of the PcTurboPro rogue system optimization tool - not recommended
X upd.exe upd.exe"Added by the DELF-AJW BACKDOOR!"
X Updade Windows winlogom.exe"Added by the TONAX-A TROJAN!"
X UpData wupdata.exe"Added by the IRCBOT-AA TROJAN!"
X Update [original file path]"Added by the LYNDEGG WORM!"
X Update CDUpdater.exe"""Carpe Diem"" adult premium rate dialler related"
X Update Sysupd.exeAdded by the SLACKBOT VIRUS!
X Update Zupdate.exe"Associated with B3d Projector foistware - see here"
X Update mshtm.exeBrowser hijacker - redirecting to buldog-search.com
X Update UPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
X update winis.exe"Added by the RBOT-VD WORM!"
X update r00t.exe"Added by the RBOT-ACO WORM!"
X UPDATE WinUpdater5.0.vbs"Added by the GORMLEZ-A WORM!"
X UpDate RAuth.exe"Added by the DLOADER-UL TROJAN!"
X Update csrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Update csrss.exe"Added by the MEHEERWAR TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""winupdate"" subfolder"
X Update lsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Update svchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Update Update.exe"QuickButton adware"
X Update hanz.exe"Added by a variant of the RBOT-GLJ WORM!"
X Update WinUpdate.exe"Added by the SDBOT-CV BACKDOOR!"
X Update Checker winlog.exe"Added by the IRCBOT-TJ TROJAN!"
X Update Checker scvhost.exe"Added by the AGENT-DSF TROJAN!"
X update driver SNDVOL32.EXE"Added by the SPYBOT-CU BACKDOOR!"
X Update Explorer iexploreupd.exe"Added by a variant of the RBOT WORM!"
X Update for Windows [various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
? Update for Works MSWkstz.exe"Maybe related to later versions of MS Works?"
N Update Grokster WiseUpdt.exe"Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program
X Update Install Schost.exe"Added by the GAOBOT.AO WORM!"
? Update local SetCPQLC.exe"Running on a Compaq desktop. Any ideas?"
N Update Manager UpdateManager.exe"Searches for updates for the Rogers Yahoo! Browser - can be run manually"
X update mon sys updaterar.exe"Added by a variant of the RBOT WORM!"
X update run dos logon.exe"Added by a variant of the SDBOT WORM!"
X Update Run MSword LOGON.EXE"Added by the RBOT.TY WORM!"
Y Update Service Update.exe"Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
X update service svxhost.exe"Added by the RBOT-MG WORM!"
X Update Service winu32.exe"Added by the RBOT-MG WORM!"
X update service winx.exe"Added by a variant of the RBOT WORM!"
? Update TUT WiseUpdt.exe"??"
X Update ver 1.0 Swap.exe"Added by the SWAP-C WORM!"
X Update Windows EXPLORE.EXE"Added by a variant of the SDBOT WORM!"
X Update Windows EXPLORE.EXE"Added by a variant of the SDBOT WORM!"
X Update.exe ravseuper.exe"Added by the QQPASS-P TROJAN!"
X Update32 configs.exe"Hijacker
X UpdateCheck winstall.exe"Added by the SPYBOT-CY WORM!"
N UpdateChecker UpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
X UpdateComponent CNF UPD.EXEAdded by the SPYBOT.GEN VIRUS!
? UpdateFW fwdload.exe"Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module?"
? UPDATEHOOK Rundll32.exe"??"
X updatelavasoft updatelavasoft.exe"CoolWebSearch parasite variant - redirecting to lalasearch.com"
U UpdateManager sgtray.exe"StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop)
X UpdateManager updmanager.exe"Added by the ANYHOMB.F TROJAN!"
X UpdateMedia UpdateMedia.exe"MediaUpdate foistware"
X UpdateMgr updmgr.exe"SouthBeachTel premium rate adult content dialer"
N updateMgr AdobeUpdateManager.exeAutomatic updates for the Adobe Reader file viewer
N updatemgr.exe updatemgr.exe"Once a month
X UPDATEMSN svhost.exeAdded by an unidentified WORM or TROJAN!
X updater wupdater.exe"KeenVal adware"
? updater updater.exe"??"
X Updater adservernow.exe"AdServerNow adware"
X updater wisvc.exe"Added by the ORSE-A TROJAN!"
X UpDaTer csrss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
X Updater Service Process svhost32.exe"Added by the AGOBOT.TY WORM!"
X Updater Service Process csrss32.exe"Added by the AGOBOT-GP BACKDOOR!"
X updater32 winload32.exe"Added by the CULT.M WORM!"
X updatereal realupdate.exeChinese originated adware
X UpdaterUI UpdaterUI.exe"Added by the AGENT-TM TROJAN!"
X Updates msupdate.exe"CoolWebSearch parasite variant"
N Updates from HP backweb*****.exe"See here - ""messaging service that automatically sends you support information
N Updates from HP Updates from HP.exeAutomatically detects an internet connection and downloads any available updates
X updatesched [random filename]"ZenoSearch adware"
X UpdateService wservice.exe"Added by the DREF-K WORM!"
X Updatestats Updatestats.exe"Statblaster adware"
X UpdateStats UpdateStats.exe"SeekSeek search hijacker related - see here"
N updatev01 updatev01.exeUltra-networks.com software updater/downloader
X updatewin update.exe"Added by a variant of the SDBOT WORM!"
X UpdateWin [random filename]"Added by the IRCBOT.AZW BACKDOOR!"
X updateWins systrey.exe"Added by the RANDON WORM!"
? Updatewiz updatewiz.exe"??"
X UpdateXpSp MS045-XP2.exe"Added by the IRCBOT.NY TROJAN!"
X updatexwin winxrpc.exe"Added by the AGOBOT-KJ WORM!"
N UPDATE~1 updatemgr.exe"Once a month
X upddateit winit.exe"Added by the RBOT-MS WORM!"
X Updmgr updmgr.exe"KeenVal adware"
X updmgr rvupdmgr.exe"KeenVal adware"
X upDpacketo services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\TEMPER"
N UpdReg Updreg.exeReminder to register Creative Labs SoundBlaster Live! cards
X UpdSys [random filename]Added by the BJ TROJAN!
X Updt Service updt.pif"Added by the RBOT-AYU WORM!"
X updtr.exe updtr.exe"Added by the AGENT-MXG TROJAN!"
X updwebmin updwebmin.exe"Added by the BACKDOOR.GEN TROJAN!"
? UPERVGAS UPERVGAS.exe"??"
X Upgrade Sarvice sxchost.exe"Added by a variant of the TOFGER-I TROJAN!"
X Upgrade Service sxchost.exe"Added by the TOFGER-I TROJAN!"
X Upgrade Service winupd.exe"Added by the TOFGER-U TROJAN!"
X upme [filename]"Added by the MUGLY.F WORM!"
X Upme DLLMAN.EXE"Added by the MUGLY.I WORM!"
X upnp upnp.exe"Added by the DLOADR-YT WORM!"
X UPNP [path to trojan]"Added by the DROPPER.EAT TROJAN!"
X UPNP upnpsvc.exe"Added by the CLOMP-B TROJAN!"
X UPnP Manager upnpman.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X UPNPService WinSVCservice.exe"Added by the AGOBOT.UN WORM!"
U Upromise Upromise.exe"Upromise college savings program"
U Upromise Tray UpromiseTray.exe"System Tray access to the Upromise college savings program"
U Upromise Update UpromiseUa.exe"Updater for the Upromise college savings program"
U Upromise0 Upromise0.exe"Upromise college savings program"
U UpromiseRemindU wjview ...Code"Part of the Upromise saving scheme but associated with Ebates MoneyMaker adware so the choice is yours"
X uprpcw uprpcw.exe"PrivacyProtector rogue privacy tool - not recommended
Y UPS ups.exePowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon)
X UPS UPS32.exe"Added by the FEMOT.O WORM!"
Y UPSentry 2000 upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
Y UPSlim upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
U UPSMON UPSMON.exe"UPSMON Power Management software"
X UPSUtl web.exe"CoolWebSearch parasite variant"
U Uptimer4 Uptimer4.exe"Uptimer4 is an appbar which displays time
X UpTimes service WinUp.exe"Added by the RBOT-AKB WORM!"
X UpToDate uptodate.exe"BrowserAid/BrowserPal foistware"
X uptolate nucle.exeAdded by a variant of the BIFROSE TROJAN!
X upxdn upxdn.exe"Added by the AGENT.NCC TROJAN!"
X upxdnd upxdnd.exe"Added by the JD-A TROJAN!"
X upyxo yujixit.exe"Added by the SDBOT.BIX WORM!"
Y UrlLstCk UrlLstCk.exe"Part of Norton Internet Security. From Symantec - ""UrlLstCk.exe is a necessary file that will be present in %Program Files%\Norton Internet Security. It is a URL Checklist. It should not be disabled"""
Y URLLSTCK.exe UrlLstCk.exe"Part of Norton Internet Security. From Symantec - ""UrlLstCk.exe is a necessary file that will be present in %Program Files%\Norton Internet Security. It is a URL Checklist. It should not be disabled"""
N URLMAP Urlmap.exe"Installed by MS Money
Y UrtSvcExe Urt95Svc.exe"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
X urudjeffni winlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X USA usa.exe"USAntiSpy rogue security software - not recommended
X USAR USAR.exe"Ultimate Spyware Adware Remover - not recommended
? Usb Usb.exe"HP related - not sure whether it's required"
X usb SASS.EXE"Added by the FUNSTA-A TROJAN!"
X USB 2.0 Driver updateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
X USB 2.0 Driver Winsys32.exe"Added by the AGOBOT-QM WORM!"
X USB 2.0 Driver updateXP.exe"Added by the AGOBOT-QP WORM!"
X USB 2.0 Driver winsystem.exe"Added by the AGOBOT-QS WORM!"
X USB 2.0 Driver UpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
X USB 2.1 Driver winupdate1.exe"Added by a variant of the RBOT WORM!"
U USB 3.0 Monitor nusb3mon.exe"Included with external USB 3.0 hard drives based upon NEC's µPD720200 controller (and maybe others in the future) such as the Western Digital My Book 3.0 range. Disabling it does not appear to cause a problem - but it may be required to achieve full USB 3.0 transfer speeds"
X USB controller Svcmm32.exeSvcMM backdoor parasite downloader
X USB Device servicelog.exe"Added by the WOOTBOT.CB WORM!"
X USB Device win32usb.exe"Added by the FORBOT-BQ WORM!"
X USB Device Server! usbserver.exe"Added by a variant of the IRCBOT TROJAN!"
X UsB driver msjavx86.exe"Added by the AGOBOT-PQ WORM!"
X USB Driver4 UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
X USB Drivers1 msupdate.exe"Added by a variant of the RBOT WORM!"
X USB Driverz2 msnplus1.exe"Added by the SDBOT-XQ WORM!"
X USB Fix 1.1 wuservices.exe"Added by a variant of the SDBOT WORM!"
X USB Fixes wuafix.exe"Added by the RBOT-ABV TROJAN!"
X USB Hardware Monitoring USBhardware.exe"Added by the RBOT-NN WORM!"
X USB Hardware326 Monitoring USBhardware326.exe"Added by a variant of the SPYBOT WORM!"
X USB Hardware32c Monitoring USBHARDWARE32C.EXE"Added by the RBOT-UU WORM!"
X USB Host Service usbsvc.exe"Added by the RBOT-GG WORM!"
? USB Hub Keyboard Patch SKBPATCH.EXEUSB HUB Update
X USB MS Update USBS.exe"Added by a variant of the RBOT WORM!"
Y USB SECURITY DEVICE CoInstaller JupitCo.exe"ButterflyMedia USB Flash drive related - required for the password security feature to work"
X USB Updates mservices.exe"Added by a variant of the SDBOT WORM!"
X USB Updates msfirewalls.exe"Added by a variant of the RBOT WORM!"
X USB Updates 2 wugfixx.exe"Added by a variant of the RBOT WORM!"
X USB2.0 usb-hi.exe"Added by the AGENT.US WORM!"
N USB2Check PCLECoInst.dll"Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system"
U UsbBoost TurboHddUsb.exe"LaCie USB Boost advanced driver for their range of USB hard disks which increases USB performance by up to 33%. Not required unless you use a supported external drive frequently"
X USBcillin USBcillin.exe"Added by the USBCILL-A TROJAN!"
X USBConfigration2 wmmndir.exe"Added by the AGOBOT-SV WORM!"
X UsbD smss32.exe"Adware - detected by Kaspersky as the AGENT.CJ TROJAN!"
X UsbD svhost32.exe"Added by the AGENT.IB TROJAN!"
X Usbd usb_d.exe"Added by the CIDRA-A TROJAN!"
X UsbD [path to trojan]"Added by the CIDRA-F TROJAN!"
U USBDetector USBDetector.exeUSBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
U USBDetector UDetect.exeUSB tray icon/detection for external Belkin (and maybe other makes) under Win98
X USBDrives msfirewalI.exe"Added by the RBOT-ABP WORM!"
X usbdrv servicetask.exe"Added by a variant of the SDBOT WORM!"
X USBHWDRV gam.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWDRV msdc.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWDRV sst4.exe"Added by a variant of the LOWZONE-I TROJAN!"
X USBHWINFO mac.exe"Added by the LOWZONE-I TROJAN!"
X USBHWINFO [path to trojan]"Added by the LOWZONE-I TROJAN!"
X USBHWINFO sst6.exe"Added by the LOWZONE-I TROJAN!"
U USBMMKBD usbmmkbd.exeUSB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version no longer pings a server when on-line wheras the older version did but did not transmit any user information
U USBMonit.exe USBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
X usbn usbn.exe"Adult content dialer - detected by Kaspersky as the SMALL.AFA TROJAN!"
X usbn [path to trojan]"Added by the HOGIL-C TROJAN!"
U USBPhoneforSkype USBPhoneforSkype.exe"USBPhoneForSkype uses Skype to dial out from a generic USB phone"
Y USBPNP USBPNP.exeSiPix digital camera Twain USB driver
N USBTA usbtapnp.exe"System Tray access for the BeWAN Gazel 128 USB ISDN adapter"
? USBToolTip USBTip.exe"Related to Pinnacle Systems Inc. What does it do and is it required?"
X USD Driver ccrss.exe"Added by the SDBOT.BFH WORM!"
X USDR6cw USDR6cw.exe"SystemDoctor rogue security software - not recommended
X useful-soft svchst.exe"Added by the STARTPA-HH TROJAN!"
X user user32.exe"Added by the BINGHE TROJAN!"
X User .exe"Added by the PUNYA-B WORM!"
X user users.exe"Added by the AUTORUN-AMK WORM!"
X User Debug Manager usndebug.exe"Added by a variant of the SPYBOT WORM! See here"
X User Host usnhost.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Hosting Service usnhost.exe"Added by the IRCBOT.SN WORM!"
X User Input Services CTFMON32.EXE"Added by the MANCSYN.AK TROJAN!"
U User Logger UsrLog.exe"UserLogger commercial surveillance software that logs keystrokes
X user logon [path to worm]"Added by the PAHATIA-A WORM!"
X user logon user logon.exe"Added by the PAHATIA.A WORM!"
X User Manager fcllls.exe"Added by the ZAGABAN-B TROJAN!"
X User Messages usrmsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Messages Manager usnmsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Messenger Manager usnmsgr.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Protection usrprot.exe"User Protection rogue security software - not recommended
X User Servicer usnsrvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Services usersvc.exe"Added by the REVCUSS.A TROJAN!"
X User Services usrsvc.exe"Added by the IRCBOT.SN WORM!"
X User Sharing usrshare.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Sharing Manager usnsharen.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Sharing Server usnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X User Sharing Services usnsvc.exe"Added by a variant of the KOBOT-C WORM!"
X User Sharing Wizard usnshare.exe"Added by the SLENFBOT.DF WORM!"
X User23.exe DIAL.exeThis is a trojan trying to disguise itself as User32.dll
X User32 [filename]"Added by the NETTRASH TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list