Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer


NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.


  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

Startup Name Process Name Details
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
XAutoUpdateraupdate.exe"Tinybar variant"
XAutoUpdaterAutoUpdate.exe"PeopleonPage foistware"
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
Xb3dUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
NBMupdateBMupdate.exe"Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XccUpdateccUpdate.exe"Added by the AGOBOT.YS WORM!"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
UClauerUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
UClUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
Ucwupdatecwupdate.exe"ContentProtect from ContentWatch - internet filter"
Xd3dupdate.exebbeagle.exe"Added by the BEAGLE.A WORM!"
XDAupdateDAupdate.exeNavEnhance adware
XDeskMateAutoUpdateDeskMateAutoUpdate.exe"DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related"
YDigital Patrol Update 5update.exe"Digital Patrol - ""a powerful anti trojan scanner
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
XDxupdate.exeDxupdate.exe"Added by the MAFEG WORM!"
XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
NGoogle UpdateGoogleUpdate.exe"Update manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %AppData%\Google\Update"
XGoogle UpdateGoogleUpdate.exe"Added by the BUZUS.DBFM TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %System%"
XGreasyPalmUpdateGreasyPalmUpdate.exe"SearchFast adware"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XIcqBetawebcamupdate.exeAdded by an unidentified TROJAN!
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XKernelUpdate.exe"Added by the DELF-FN TROJAN!"
NLG Intelligent Updateautoupdate.exe"Automatic update utility for LG Notebooks"
ULGODDFUfwupdate.exeAuto firmware update program for LG Electronics CD-ROM/DVD writer
ULiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
YMcAfee SecurityCenterMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
YMcUpdateMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
YMCUpdateExeMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
XMediaPlayeSMediaPlayer_update.exe"Added by the STARTER-K TROJAN!"
XMicrooft Timingpupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft DirectXwupdate.exe"Added by the RBOT-L WORM!"
XMicrosoft Generic Update Managerwupdate.exe"Added by the RBOT-AWC TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft UpdateMupdate.exe"Added by the RBOT-AG WORM!"
XMicrosoft Updatemcupdate.exe"Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
XMicrosoft Updateupdate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updattingmiroupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoftCorpupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftCorpwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftNAPCupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftNAPCwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftUpdateMicrosoftUpdate.exe"Added by the BANKER-EHC TROJAN!"
XMouseDrvupdate.exe"Added by the ZOTOB.N WORM!"
XMS Unix Binarymsnupdate.exe"Added by the RBOT-AAM WORM!"
XMS Unix Binaryoutlookexpressupdate.exe"Added by the RBOT-YU WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Unix BinaryNorton2005Update.exe"Added by a variant of the RBOT WORM!"
XMS Unix Binarytrmupdate.exe"Added by the RBOT-ACC WORM!"
XMS UPDATERupdate.exe"Added by the RBOT-VC WORM!"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
Xmsliveupdatemsliveupdate.exe"Added by the AGOBOT.ALT WORM!"
XMsn Messenger Updatemsnupdate.exe"Added by a variant of the RBOT WORM!"
XMSN Updatingmsnupdate.exe"Added by the QHOST.AEI TROJAN!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
Xmsupdatemsupdate.exe"Added by the RBOT-MZ WORM!"
XMSUpdatecriticalUpdate.exe"Affilred adware"
Xmsupdateupdate.exe"Added by a variant of the SDBOT WORM!"
XMSupdate.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMyFastAccessmyfastupdate.exeMy-Fast-Access toolbar updater
Xnapv.exewupdate.exe"Added by the AGOBOT-JX BACKDOOR!"
XNAV_UpdateNAV_Update.exeUnidentified WORM or TROJAN!
?netfxupdatenetfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
XNorton UpdateccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton UpdatecUpdate.exe"Added by the AGOBOT.APP WORM!"
XNorton UpdaterNortonUpdate.exeAdded by an unidentified WORM or TROJAN!
XNorton UpdaterccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNSupdateNSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
UOpenwares LiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XOrbitUpdateupdate.exe"Xupiter OrbitExplorer toolbar related. Drive-by foistware. Use Spybot S&D
XOuterinfoUpdateOuterinfoUpdate.exe"Clickspring.Outerinfo adware"
Xoutpostupdateoutpostupdate.exe"Added by the COSIAM-C TROJAN!"
XPCHEasySearchSTUpdate.exePCH EasySearch bar
NQuickbooks Update Agentqbupdate.exeAssociated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
XQuickTimeUpdateQuickUpdate.exe"Added by the BIFROSE-CW TROJAN!"
?RealTimeUpdateRealTimeUpdate.exe"Product description in properties is ""InternetExplorerCommunicationAgent Module"" ?"
XRunDLL32winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
XSafeSurfingUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
USAUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
USBAutoUpdatesbautoupdate.exe"SpywareBlaster auto-updater"
XScanRegistryupdate.exe"Added by the DWNLDR-FZY TROJAN!"
Xsdfsdfsdfsp2update.exe"Added by a variant of the SPYBOT WORM!"
XSecurityWindowsSecurityUpdate.exe"Added by a variant of the SDBOT WORM!"
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
Xsp2updatesp2update.exe"SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer"
XSpyFighterUpdateAutoUpdate.exe"SpyFighter spyware remover - not recommended
YSpywareTerminatorUpdateSpywareTerminatorUpdate.exe"Automatic updates for Spyware Terminator. Initially not recommended due to false positives but the later versions have since improved - see here"
NSSBkgdUpdateSSBkgdupdate.exe"Automatic updates for ScanSoft (now Nuance) products such as OmniPage and PaperPort. Can be disabled using the main program's options. Note - if you have a Soundblaster Audigy2 ZS soundcard installed on your computer and the volume of your sound system is turned on extremely high disabling this will solve the problem"
XSSUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
XStart Uppingsmssupdate.exe"Added by a variant of the RBOT WORM!"
Xstartkeyupdate.exe"Added by the BIFROSE-DG TROJAN!"
Xsupdatesupdate.exe"Added by the MALWARE.D TROJAN!"
Xsvshostdrivermsnmessengerupdate.exe"Added by the SDBOT-BI BACKDOOR!"
XSwf32AVupdate.exe"Added by the MERKUR.E WORM!"
XSygate Personal FirewallMcafeeupdate.exe"Added by the RBOT.YN WORM!"
XSygate Personal Port Blockerwinupdate.exe"Added by a variant of the RBOT WORM!"
XSysctrlswinupdate.exeAdded by an unidentified WORM or TROJAN!
XSyssehuupdate.exe"EHU adware"
XSystem Update2update.exe"Added by the AUTOTROJ-C TROJAN!"
Xtmaxpupdate.exeAdware pop-up generator
XUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
XUpdateUpdate.exe"QuickButton adware"
XUpdateWinUpdate.exe"Added by the SDBOT-CV BACKDOOR!"
YUpdate ServiceUpdate.exe"Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
XUpdate.exeravseuper.exe"Added by the QQPASS-P TROJAN!"
Xupdaterealrealupdate.exeChinese originated adware
XUpdatesmsupdate.exe"CoolWebSearch parasite variant"
Xupdatewinupdate.exe"Added by a variant of the SDBOT WORM!"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XWin UpdateSysUpdate.exe"Added by the AGOBOT-TN WORM!"
XWin Updateoleupdate.exe"Added by the AGENT-UY TROJAN!"
Xwin updatewupdate.exe"Added by the RBOT-P BACKDOOR!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
Xwin32updatewin32update.exe"Added by the GENOME.AQUV TROJAN!"
Xwindow2ieupdate.exe"Added by the FORBOT-BM WORM!"
XWindows 32 UpdateWindows-Update.exe"Added by a variant of the RBOT WORM!"
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Processwin_update.exe"Added by the LASTWORD WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows SP2 UpdateSp2update.exe"Added by the WOOTBOT.BS WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMwupdate.exe"Added by the MYTOB-HT WORM!"
XWindows Updatewupdate.exe"Wengs adware"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows UpdateUpdate.exe"Added by the DELF-FN TROJAN!"
XWindows Updatewinupdate.exe"Added by the SDBOT-WS WORM!"
XWindows Updatemplupdate.exe"Added by the MOEGA WORM!"
XWindows updatewudupdate.exe"ISTBar adware related"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Managerwupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update.exeN/AHomepage hijacker
XWindows Updaterwupdate.exe"Added by the WOOTBOT.AJ WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"
XWindows USB Monitorservupdate.exe"Added by the IRCBRUTE.AQ TROJAN!"
XWindows XP Automatic UpdatewXPupdate.exe"Added by the RBOT-AFC WORM!"
XWindowsACEbaracebarupdate.exe"BarACE adware"
XWindowsCriticalUpdatewindows_critical_update.exe"Added by the ASTEF or RESPAN WORMS!"
XWindows�UpdatesUpdate.exe"Added by the RBOT.TRA BACKDOOR!"
XWindowsRegKey updatewinupdate.exe"Added by the RBOT-QJ WORM!"
XWindowsRegKey updatewdnupdate.exe"Added by the SDBOT.QX WORM!"
XWindowsUpdatewindows_update.exe"Added by the LOFNI WORM!"
Xwindowsupdatewinupdate.exe"Added by the WARPI WORM!"
XWindowsupdateWindowsupdate.exe"Added by the BANKER.ARK TROJAN!"
Xwindowsupdateautoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
XWindowsXP Updatewindowsxpupdate.exe"Added by the RBOT-PB WORM!"
XWinLibUpdatelibupdate.exe"Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
XWinsock driverwinnt update.exe"Added by the SPYBOT-DM TROJAN!"
XWinsock2 driverwinupdate.exe"Added by the SPYBOT-BX WORM!"
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
Xwinupdatewinupdate.exe"Added by the ALCAN.B WORM!"
Xwinupdate.exewinupdate.exe"Added by the RADO TROJAN!"
Xwinupdate.regwinupdate.exe"Added by the SPYBOT.EAS WORM!"
XWinUpdaterupdate.exe"Added by the STARTPAGE.C TROJAN!"
Xwmupdatewmupdate.exe"Added by the AGENT-GGJ TROJAN!"
XWxp4Norton Update.exe"Added by the ERKEZ.D WORM!"
Xxpiupdatexpiupdate.exe"Added by the RBOT-AAB WORM!"
Xxpsp2installxpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpsp2Updatexpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!" adware downloader
XZi5AntiVirus Update.exe"Added by the ERKEZ.G WORM!"
XZupdateZupdate.exe"Associated with B3d Projector foistware - see here"
X{C0FB7D08-056E-1033-0501-03020730002c}Update.exe"Added by the AGENT-EOG TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.