Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
NAdobeUpdaterAdobeUpdater.exeAutomatic updater for Adobe software - run manually
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
XAdUpdatersysupudt.exeUnidentified adware downloader/updater
Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
Xaolupdater.exeaolupdater.exe"Added by a variant of the IRCBOT TROJAN!"
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
XatiupdateATIUPDATE5.EXE"Added by the DEBESKI.A TROJAN!"
Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
XATIUpdateratiupdxx.exe"Added by the RBOT-ABX WORM!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAuto UpdateAUP.exeAdded by an unididentified WORM or TROJAN!
XAuto Updatedma.exe"Added by the RBOT-AVO WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Updatesalgs.exe"Added by the IRCBOT-AAM TROJAN!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
Xautoupdate"rundll32 DATADX.DLLSHStart"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoUpdateraupdate.exe"Tinybar variant"
XAutoUpdaterAutoUpdate.exe"PeopleonPage foistware"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
Xautoupdatev2autoupdatev2.exe"Detected by Kaspersky as the AGENT.FQ TROJAN!"
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
XAVupdate32 UpdateAVupdate32.exe"Added by the RBOT.CNI TROJAN!"
Xb3dUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
XBeegees Updatebeegees.exe"Added by the SDBOT-ADK WORM!"
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
NBMupdateBMupdate.exe"Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBrowserUpdateSched[random filename]"ZenoSearch adware"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
XccUpdateccUpdate.exe"Added by the AGOBOT.YS WORM!"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
UClauerUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
NClient Access Help Updatecwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
XClient Updatewup.exe"Added by the OPANKI.O WORM!"
UClUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
NCriticalUpdateWucrtupd.exe"MS Windows Critical Update Notification. If you want to keep Windows up-to-date
XCriticalUpdatewucrtupd.exe"Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
XCTUpdatectupdclt.exe"Added by the RBOT-ABG WORM!"
Ucwupdatecwupdate.exe"ContentProtect from ContentWatch - internet filter"
XCydoorUpdateCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
Xd3dupdate.exebbeagle.exe"Added by the BEAGLE.A WORM!"
XDAupdateDAupdate.exeNavEnhance adware
XDealHelperUpdateDHUpdt.exe"DealHelper adware"
XDeskMateAutoUpdateDeskMateAutoUpdate.exe"DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related"
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
YDigital Patrol Update 5update.exe"Digital Patrol - ""a powerful anti trojan scanner
UDirect UpdateDUControl.exe"DirectUpdate dynamic DNS updater"
UDiscUpdateManagerDiscUpdMgr.exe"Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
NDiscUpdateManagerDiscUpdateMgr.exe"DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple
XDivX UpdaterDivX.Exe"Added by the NALDEM TROJAN or MASTAK VIRUS!"
XDLLUPDATE32dllupdate32.exe"Added by the AGOBOT.IA WORM!"
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDxupdate.exeDxupdate.exe"Added by the MAFEG WORM!"
UDynDNS UpdaterDynDNS.exe"Dynamic DNS IP address updater tool
NDynDNS-Updater Traytoolddutray.exe"DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
Ueanth_critical_update_alertsys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertEANTHO~1.EXE"eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted
XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
UeScan UpdaterTrayicos.exe"MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
Xewupdaterewupdater.exe"EasyWebSearch adware updater"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Nfilehippo.comUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
NFileHippo.com Update CheckerUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
UGoogle IME AutoupdaterGooglePinyinDaemon.exe"Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone
NGoogle UpdateGoogleUpdate.exe"Update manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %AppData%\Google\Update"
XGoogle UpdateGoogleUpdate.exe"Added by the BUZUS.DBFM TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %System%"
NGoogle UpdaterGOOGLE~1.EXE"Downloads and installs updates for Google applications (Google Earth
NGoogle UpdaterGoogleUpdater.exe"Downloads and installs updates for Google applications (Google Earth
XGoogleUpdater3GoogleMapper.exe"Added by the ROUTROBOT WORM!"
Xgotnewupdate000.exegotnewupdate000.exe"Added by the FAKEAV-BGA TROJAN!"
XGP Updatergpupdater.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XGraphic Updateopenglx.exe"Added by the IRCBOT.AMU WORM!"
XGreasyPalmUpdateGreasyPalmUpdate.exe"SearchFast adware"
XHanUpdatehanz.exe"Added by the RBOT-GLJ WORM!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
NHP software updateHPWuSchd2.exeHP software updates. If a shortcut doesn't exist create your own and run it manually
NHP software updateHPWuSchd.exe"HP software updates. If a shortcut doesn't exist
XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
NHP Updates??"On HP PCs
XIcqBetawebcamupdate.exeAdded by an unidentified TROJAN!
XIE Java Updateiejava.exe"Added by the AGENT-HD TROJAN!"
XIEAgent update checkiewatch.exe"Added by the BOMKA TROJAN!"
XIEexplorer AUpdateIEexplore32.exe"Added by the RBOT-GRE WORM!"
XieupdateMCP****.exe [**** = random char]"Added by the ASOXY TROJAN!"
Xieupdatemcpdll32.exeAdware downloader trojan
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
Xieupdatesieupdates.exe"Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
NImesh Auto Update??"Update check for the Imesh file sharing system. Turn the update off under ""options"""
XInformation Updateiu.exe"Detected by Kaspersky as the CENTIM.CH TROJAN!"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
NInstant Update Centerreminder.exe"Event reminder for calendar dates
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Explorer Updaterlexbac.exe"Added by the DOWNLOAD TROJAN!"
XInternet Explorer Updateriexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
NiRiver UpdaterUpdater.exe"Updates for the iRiver Music Manager - used with their digital music players"
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
XJava Auto Updateujm.exe"Added by the SDBOT-ADH WORM!"
XJava updatejavaqs.exe"Added by the SWARLEY.A WORM!"
XJava Updatekeeper.exe"Added by the AGENT-DIS TROJAN!"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
XJava Updatehostwww.exe.exe"Added by the AGENT-MFH TROJAN!"
NJava(TM) Platform SE Auto Updater 2 0jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
XJavaUpdateSchedjusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XKernelUpdate.exe"Added by the DELF-FN TROJAN!"
NKodak Software Updaterbackweb*****.exe"Software updater for Kodak Easyshare digital cameras"
NKODAK Software UpdaterKodak Software Updater.exe"Software updater for Kodak Easyshare digital cameras"
NLG Intelligent Updateautoupdate.exe"Automatic update utility for LG Notebooks"
ULGODDFUfwupdate.exeAuto firmware update program for LG Electronics CD-ROM/DVD writer
XLife FireWall Update1FireWall-Update1.exe"Added by the RBOT-ARS WORM!"
XLive update monitorsrvany32.exe"Added by the AGOBOT.AFM WORM!"
Xlive update monitorumxlu32.exe"Added by the AGOBOT.ADK WORM!"
ULiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
NLiveUpdateCopyer.exe"Samsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions
XLiveUpdate32services.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
NLogitechSoftwareUpdateManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
Xlsass2k Updatelsass2k.exe"Added by a variant of the RBOT WORM!"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
XLzioMediaUpdaterLzioMediaUpdater.exe"LZIO.com adware downloader"
XM1cr0s0ft Upd4t4zSupdate32.exe"Added by the RBOT-MI WORM!"
XMachine Update Softwusas.exeAdded by an unidfentified WORM!
XMacromedia Critical Updaterrarww.exe"Added by a variant of the RBOT WORM!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
NMacrovision Update Serviceissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NMacrovision Update ServiceISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
XMascro soft SDK updates2SDKrepair2.exe"Added by the SDBOT.BXM WORM!"
YMcAfee SecurityCenterMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
UMcAfee.InstantUpdate.MonitorRuLaunch.exe"Instant Updater for McAfee's VirusScan
YMcAfeeUpdaterUIUpdaterUI.exeMcAfee common updater user interface
YMcAfeeUpdaterUIUdaterUI.exeUpdater user interface for McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
XMcrosoftr UpdateMcrosoftr.exe"Added by a variant of the RBOT WORM!"
YMcUpdateMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
YMCUpdateExeMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
XMCX Updatewisp.exe"Added by the RBOT-AQH WORM!"
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
XMedia Player Updatexpsp1mfh.exe"Added by a variant of the RBOT WORM!"
XMedia Software UPdatersscs.exe"Added by the RBOT-ABE WORM!"
XMediaPlayeSMediaPlayer_update.exe"Added by the STARTER-K TROJAN!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
XMicr Updatesoundblaster.exe"Added by the SDBOT.NP WORM!"
XMicr Update Systemupwin.exe"Added by the SDBOT.YS WORM!"
XMicro Updatedailin.exe"Added by the RBOT-ER WORM!"
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMicromedia Flash Updatewdfmrg.exe"Added by a variant of the SDBOT WORM!"
XMicromedia Flash Updatexptxt.exe"Added by the RBOT-GAB WORM!"
XMicrooft Timingpupdate.exe"Added by a variant of the RBOT WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMICROSFT MX UPDATE SUPPORTtaskmngrs.exe"Added by the RBOT-AUZ WORM!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMICROSFT RAMA UPDATE SUPPORTMSN32.EXE"Added by the RBOT-AWJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTmtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTMSGUPDAT32.EXE"Added by the RBOT-BBB WORM!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftupdater.exe"Added by the RBOT-GHP WORM!"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft 16Bit Updatewuapdate16.exe"Added by the RBOT.CZ WORM!"
XMicrosoft 64 Bit Runtime Updaterwupdt64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft AUT UpdateMSlti32.exe"Added by the RBOT-X WORM!"
XMicrosoft AUT UpdateMSlti16.exe"Added by the RBOT.EB WORM!"
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft auto updatewuauclt.exe"Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft Automatic UpdaterExplorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Corp Updateswupdates.exe"Added by the RBOT-AUU WORM!"
XMicrosoft DirectXwupdate.exe"Added by the RBOT-L WORM!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Generic Update Managerwupdate.exe"Added by the RBOT-AWC TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Internet Firewall Updateupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft IT UpdateIEserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatesvchsst.exe"Added by the RBOT-DH WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-JM WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft IT UpdateRhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
XMicrosoft Patch Updatebootini.exe"Added by the RBOT-FMN WORM!"
XMicrosoft Security Hot Fix Updatemshotfix.exe"Affilred adware"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Updatesecurity32.exe"Added by the DELF-JJ TROJAN!"
XMicrosoft Software Updatenmon.exe"Added by the RBOT.HZ WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMicrosoft Taskmanager Updaterkeyboard.exe"Added by the RBOT-ALU WORM!"
XMicrosoft UMA UpdateMSuma32.exe"Added by the RBOT.FS WORM!"
XMicrosoft UpdateMicrosoft.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemssmgrd.exe"Added by the SDBOT.JT WORM!"
XMicrosoft Updatemvsc.exe"Added by the SPYBOT.DAZ WORM!"
XMicrosoft Updateascdl.exe"Added by the GAOBOT.SY WORM!"
XMicrosoft UpdateIsac.exe"Added by the RBOT-AU WORM!"
XMicrosoft Updateautomgr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemediap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoftx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft UpdateMslti32.exe"Added by the RBOT-LX WORM!"
XMicrosoft Updatemuamgrd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatenavmgrd.exe"Added by the SDBOT.DP TROJAN!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Updatesys32cfg.exe"Added by the RBOT.DR WORM!"
XMicrosoft UpdateVPC32.EXE"Added by the AGOBOT.XM WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatewuamgrd.exe"Added by the RBOT-LK WORM!"
XMicrosoft Updatewuammgr32.exe"Added by the RBOT-AW WORM!"
XMicrosoft Updatewudmate.exe"Added by the RBOT.AP WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatewuamgrd32.exe"Added by the RBOT.ZB WORM!"
XMicrosoft UpdateNAV.exe"Added by the RBOT-IV WORM!"
XMicrosoft Updatesystemi32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft Updatewebm.exe"Added by the SDBOT.WK WORM!"
XMicrosoft Updatewuagrd.exe"Added by the RBOT-FK WORM!"
XMicrosoft Updateaaupdt.exe"Added by the RBOT-RQ WORM!"
XMicrosoft Updatelsac.exe"Added by the GAOBOT.XW WORM!"
XMicrosoft UpdateMupdate.exe"Added by the RBOT-AG WORM!"
XMicrosoft Updateprowind32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatesnlogsvc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatewauguard.exe"Added by the RBOT.AEE WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewserv32.exe"Added by the RBOT.AF WORM!"
XMicrosoft Updatewtm32.exe"Added by the RBOT-AQ WORM!"
XMicrosoft Updatewumgrd.exe"Added by the SDBOT-KY WORM!"
XMicrosoft Updatewuampd.exe"Added by the RBOT-UT WORM!"
XMicrosoft Updatemsupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft UpdateBotnet.exe"Added by the RBOT.AFL WORM!"
XMicrosoft Updatesghost.exe"Added by the SDBOT.AKV WORM!"
XMicrosoft Updateupdate_w.exe"Added by the RBOT-EW WORM!"
XMicrosoft Updatewindows24.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewingrd32.exe"Added by the RBOT-DW WORM!"
XMicrosoft Updatewssvr.exe"Added by the RBOT-OD WORM!"
XMicrosoft Updatewuamagr32.exe"Added by the SPYBOT.CG WORM!"
XMicrosoft UpdateWinUpdate32.exe"Added by the RBOT-TI WORM!"
XMicrosoft Updatewkfix.exe"Added by the RBOT-ABZ WORM!"
XMicrosoft UpdateKkk.exe"Added by the RBOT-AHL WORM!"
XMicrosoft Updatemcupdate.exe"Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
XMicrosoft UpdateMicr0s0ft.exe"Added by the AGOBOT.AAR WORM!"
XMicrosoft UpdateMsnmsngr.exe"Added by the RBOT.BQS WORM!"
XMicrosoft Updatemsupdate32.exe"Added by the SPYBOT.LZ WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Updatesvghost.exe"Added by the RBOT.BUJ WORM!"
XMicrosoft Updatesys.exe"Added by the RBOT-AJ WORM!"
XMicrosoft Updateup2dat5.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
XMicrosoft Updatewin-mang.exe"Added by the RBOT-AFK WORM!"
XMicrosoft Updatewinupdater.exe"Added by the RBOT.BIN WORM!"
XMicrosoft Updatewuamk0032.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamk032.exe"Added by the RBOT-AHD WORM!"
XMicrosoft Updatewuamk0p32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamkop.exe"Added by the RBOT-AFI WORM!"
XMicrosoft Updatewuamkop32.exe"Added by the RBOT.BGU WORM!"
XMicrosoft Updatewuampkd.exe"Added by the SDBOT.BBX WORM!"
XMicrosoft Updatesvzhost.exe"Added by the RBOT.OX WORM!"
XMicrosoft Updatewin32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewininit.exe"Added by the RBOT-AKR WORM!"
XMicrosoft Updatewuamgrd3.exe"Added by the RBOT-AMC WORM!"
XMicrosoft UpdateWudates.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatems.exe"Added by the SDBOT.CC WORM!"
XMicrosoft Updatewuagmsd.exe"Added by the RBOT-AX WORM!"
XMicrosoft Updatecmss.exe"Added by the RBOT-ATQ WORM!"
XMicrosoft Updatewuamgrb.exe"Added by the RBOT-AZE WORM!"
XMicrosoft UpdateWINDOC.EXE"Added by the SDBOT.PF WORM!"
XMicrosoft Updatephqghumea.exe"Added by the SDBOT.AFO WORM!"
XMicrosoft Updatesystem32.exe"Added by the RBOT.IS WORM!"
XMicrosoft Updatebling.exe"Added by the RBOT-AVK WORM!"
XMicrosoft UpdateSygate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updateupdate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft UpdateWinDrv32.exe"Added by the RBOT.EGW WORM!"
XMicrosoft Updatedevmks32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Updatemixer.exe"Added by the RBOT-AIR WORM!"
XMicrosoft Updatetaskmgr32.exe"Added by the RBOT-CV WORM!"
XMicrosoft Updatedrive.exe"Added by the BIFROSE-PN WORM!"
XMicrosoft Updatewangard.exe"Added by the RBOT-LH WORM!"
XMICROSOFT UPDATEWUAGTRD.EXE"Added by the RBOT-CJ WORM!"
XMicrosoft Updatespool.exe"Added by the AGENT-GJC TROJAN!"
XMicrosoft Updatebnmveqfts.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatedqbxhupdt"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Updateenule.exe"Added by the IRCBOT.DU BACKDOOR!"
XMicrosoft Updateexplorer.exe"Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Updateimchemaoa.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatelivemessenger.com"Added by the ADLOAD-LN TROJAN!"
XMicrosoft Updatemsnmsgl.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatennwyaupdt"Added by the RBOT.RHK BACKDOOR!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft Updaterundll32.dll"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Updatewuamgrdx.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatewutr.exe"Added by the SPYBOT.AAR WORM!"
XMicrosoft UpdateSetPoints.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Updatesystem.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Updateservice.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Updatemsgn.exe"Added by the RBOT.RQ BACKDOOR!"
XMicrosoft Updatewuamgrd16.exe"Added by the RBOT-BQ WORM!"
XMicrosoft Updatewindows32.exe"Added by the RBOT-BHQ WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Update 23NtKernelSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 23spoolvs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32explore32.exe"Added by the SPYBOT.CYM WORM!"
XMicrosoft Update 32MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update 32wininit.exe"Added by the RBOT-ANY WORM!"
XMicrosoft Update 32wininit32.exe"Added by the RBOT-AKJ WORM!"
XMicrosoft Update 32[path to file]"Added by the RBOT-AJJ WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Update 32servic.exe"Added by the RBOT-AXN WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32mssetup32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32wiit.exe"Added by the RBOT-AMS WORM!"
XMicrosoft Update 32explorer.exe"Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update 32network.exe"Added by the RBOT-ARZ WORM!"
XMicrosoft Update 32om4r.exe"Added by the RBOT-AQP WORM!"
XMicrosoft Update 32winin.exe"Added by the RBOT-ARR WORM!"
XMicrosoft Update 32wuinit.exe"Added by the AGOBOT-UE WORM!"
XMicrosoft Update 32neta.exe"Added by the RBOT-AMI WORM!"
XMicrosoft Update 32spoolvs.exe"Added by the RBOT-BBQ WORM!"
XMicrosoft Update 32rundll32.exe"Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe
XMicrosoft Update 32taskMangr.exe"Added by the RBOT.AIE BACKDOOR!"
XMicrosoft Update 32winssx.exe"Added by the RBOT-ARW WORM!"
XMicrosoft Update 33init.exe"Added by the RBOT-ATT WORM!"
XMicrosoft Update 64 BITwininit32.exe"Added by the RBOT-AHE WORM!"
XMicrosoft Update 64 BITwinman32.exe"Added by the RBOT-AKI WORM!"
XMicrosoft Update 64 BITschvost.exe"Added by the RBOT.CAU WORM!"
XMicrosoft Update 64 BITwinl32xe.exe"Added by the RBOT-AQO WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update ControlMs64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Debuggerwincfg32.exe"Added by the SPYBOT.ZC WORM!"
XMicrosoft Update Deviceflolo.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Update Device Driverswuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update DLLrxxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Emulatorkern-mxe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Emulatorwuaddsff.exe"Added by the RBOT-GX WORM!"
XMicrosoft Update Eventsvnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update Machinerxhost.exe"Added by the RBOT.FC WORM!"
XMicrosoft Update Machineservicz.exe"Added by the RBOT-HU WORM!"
XMicrosoft Update MachineSP2.exe"Added by the SPYBOT.FP WORM!"
XMicrosoft Update Machinewinini.exe"Added by the RBOT-KV WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinememstat.exe"Added by the RBOT-OM WORM!"
XMicrosoft Update Machinentce.exe"Added by the RBOT-FA WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Update Machinewuawx.exe"Added by the RBOT-CE WORM!"
XMicrosoft Update Machinezonealarm.exe"Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
XMicrosoft Update Machinesystemll.exe"Added by the RBOT-JT WORM!"
XMicrosoft Update Machinewinupdt.exe"Added by the RBOT-FP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinewuamgd.exe"Added by the SDBOT.HQ WORM!"
XMicrosoft Update Machinewupdt32x.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelinux.exe"Added by the RBOT-IM WORM!"
XMicrosoft Update Machinelmrss.exe"Added by the RBOT-DY WORM!"
XMicrosoft Update Machinewindowsu.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewininigo.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewinmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Update Machinewuamgrd.exe"Added by the RBOT-HE WORM!"
XMicrosoft Update Machinewuagrd.exe"Added by the RBOT-GF WORM!"
XMicrosoft Update MachineLANWAKE.EXE"Added by the RBOT-QZ WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update MachineWUAMGRDXS.EXE"Added by the RBOT-GL WORM!"
XMicrosoft Update Machinecrss32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelsasse.exe"Added by the RBOT-DI WORM!"
XMicrosoft Update Machineqwerty.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinerxxhost.exe"Added by the RBOT.EP WORM!"
XMicrosoft Update Machineservicez.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Update Machinespoolserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineSystemnt.exe"Added by the RBOT.DA WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update Machinetaskmngrs.exe"Added by the RBOT-CR WORM!"
XMicrosoft Update Machinewindowsup.exe"Added by the RBOT-FV WORM!"
XMicrosoft Update Machinewuamgard.exe"Added by the SPYBOT.CS WORM!"
XMicrosoft Update Machinewupdate32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinesystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTMEMSER.EXE"Added by the RBOT-NQ WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinortho.exe"Added by the RBOT-NW WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update Machineserviz.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTASKMAN4.EXE"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewftestb.exe"Added by the RBOT-AFZ WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machinejkfrnz.exe"Added by the RBOT-GOZ WORM!"
XMicrosoft Update Machinewlimyc.exe"Added by the RBOT-GQN WORM!"
XMicrosoft Update Machinexagwxzy.exe"Added by the RBOT.S WORM!"
XMicrosoft Update Machinejkydxg.exe"Added by the RBOT.AEA BACKDOOR!"
XMicrosoft Update Machineopmmve.exe"Added by the KOLABC.DES WORM!"
XMicrosoft Update Machinepaxrxo.exe"Added by the PUSHBOT.A WORM!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Update Machinesyadpo.exe"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Update Machinesystemi.exe"Added by the BUZUS.JKU TROJAN!"
XMicrosoft Update Machinethvfyq.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machineubthec.exe"Added by the AGENT.AWZ TROJAN!"
XMicrosoft Update Machinewinmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
XMicrosoft Update Machinegbhglj.exe"Added by the IRCBOT-ZJ TROJAN!"
XMicrosoft Update Machinewuamgdr.exe"Added by the RBOT-IO BACKDOOR!"
XMicrosoft Update ManagerWINRLS.EXE"Added by the RBOT-AF WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Update Managerscvideo.exe"Added by the SDBOT-CVP TROJAN!"
XMicrosoft Update MecheneUpdatez.exe"Added by the RBOT-GI WORM!"
XMicrosoft Update Modulerundll24.exe"Added by the RBOT-PS WORM!"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Update Security Patchmssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
XMicrosoft Update Servermssrv.exe"Added by an unidentified VIRUS
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update SERVICEphqghum.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Update Timewuam.exe"Added by the RBOT-M WORM!"
XMicrosoft Update USB2wuammgrd32.exe"Added by the RBOT-ADT WORM!"
XMicrosoft Update v2.6lxxex.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Update Win32xwinupdate32x.exe"Added by the RBOT-AJN WORM!"
XMicrosoft Update32wuamgrd32.exe"Added by the RBOT-PU WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Updatervbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updaterwuamgrds.exe"Added by the RBOT.A WORM!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updater ResourcesWinFixd32.exe"Added by the SPYBOT.CA WORM!"
XMicrosoft Updater v2[path to worm]"Added by the AUTORUN-BCI WORM!"
XMicrosoft UPDATER32lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
XMicrosoft UPDATER32LSASS32.EXE"Added by the RANDEX.AR WORM!"
XMicrosoft Updaterstskmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Updatessystemc32.exe"Added by the RBOT-GR WORM!"
XMicrosoft Updateswkssvr.exe"Added by the RBOT.R WORM!"
XMicrosoft Updateswkssvrs.exe"Added by the RBOT-EB WORM!"
XMicrosoft Updateswuamgrd.exe"Added by the RBOT-CO WORM!"
XMicrosoft Updateswtemp32.exe"Added by the RBOT-AHQ WORM!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft Updates[worm filename]"Added by the AGOBOT-AIZ WORM!"
XMicrosoft Updateswgcptsud.exe"Added by the RBOT-GTF WORM!"
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft Updates 2 USBwgafixer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updates 5 USBsp3fixer.exe"Added by the RBOT-ADS WORM!"
XMicrosoft UpdateS Machinewgrd.exe"Added by the RBOT-FI WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updattingmiroupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft upnp Updatemsie.exe"Added by the RBOT-LQ WORM!"
XMicrosoft VertupdateMSvert32.exe"Added by the MYTOB-CY WORM!"
XMicrosoft web updatewebmsn.exe"Added by the RBOT-EMQ WORM!"
XMicrosoft Win UpdateWinUP.exe"Added by the RBOT-BPR WORM!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Winedows UpdateingNinKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
XMicrosoft WinUpdatesyslx32.exe"Added by an unidentified VIRUS
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft WinUpdatespfix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinamp61.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinupd32.exe"Added by the RBOT.MQ WORM!"
XMicrosoft WinUpdateWinNTinit32.exe"Added by the RBOT.VS WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft WinUpdatesserm32.exe"Added by the RBOT.GE WORM!"
NMicrosoft Works Update Detectionwkdetect.exeChecks for updates to MS Works
XMicrosoft X Updatewuamkoppnp.exe"Added by the RBOT-ANI WORM!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-Updatewngard.exe"Added by the RBOT-JV WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
XMicrosoftCorpupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftCorpwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftNAPCupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftNAPCwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosofts Updatezcmsssr.exe"Added by an unidentified VIRUS
XMicrosofts Updatezexploirez.exe"Added by a variant of the RBOT WORM!"
XMicrosoftUpdatesyshelper.exe"Added by the WOOTBOT.AC WORM!"
XMicrosoftUpdateWinUp32.exe"Added by an unidentified VIRUS
XMicrosoftUpdateMicrosoftUpdate.exe"Added by the BANKER-EHC TROJAN!"
XMicrosoftUpdatewindll.exe"Added by the RBOT-IH WORM!"
XMicrosoftUpdateRBuilder.exe"Added by the DLOADR-BMV TROJAN!"
XMicrosoftUpdatesvhest.exe"Added by the RBOT-ES WORM!"
XMicrosoftUpdatedownnew.exe"Added by the TANTO-D TROJAN!"
XMicrosoftUpdates[path to trojan]"Added by the DELF-LO TROJAN!"
XMicrosoftUpdatessyshelped.exe"Added by the FORBOT-AZ WORM!"
XMicrosotufed Update 32windinit.exe"Added by the RBOT-CTJ WORM!"
XMicroszoft Update Mach1nezssvchst.exe"Added by the RBOT-ED WORM!"
XMiosf Updatewimsqaad.exe"Added by the SDBOT.AG TROJAN!"
XMircosoft Updatewuampkd.exe"Added by a variant of the SDBOT WORM!"
XModem Driverz Updatesmdmdrv.exe"Added by a variant of the SDBOT WORM!"
XMouseDrvupdate.exe"Added by the ZOTOB.N WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS Security Update 993msident.exe"Added by a variant of the SDBOT WORM!"
XMS UniXnavupdate64.exe"Added by the RBOT.CRZ BACKDOOR!"
XMS Unix Binarymsnupdate.exe"Added by the RBOT-AAM WORM!"
XMS Unix Binaryoutlookexpressupdate.exe"Added by the RBOT-YU WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Unix BinaryNorton2005Update.exe"Added by a variant of the RBOT WORM!"
XMS Unix Binarytrmupdate.exe"Added by the RBOT-ACC WORM!"
XMS Updatesyshost.exe"Added by the EVAMAN-F WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS UPDATERupdate.exe"Added by the RBOT-VC WORM!"
XMS Updatesmscache.exeSpyware web downloader
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
XMS Updatesaupd.exeSpyware web downloader
XMS Updating Utilitymsupdater.exe"Added by the RBOT-XR WORM!"
Xms window update******.exe [* = random character]"Added by a variant of the RBOT WORM!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsliveupdatemsliveupdate.exe"Added by the AGOBOT.ALT WORM!"
XMSN Auto-Updatermsnaupdater.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Auto-Updatermsnupdates.exe"Added by the AUTORUN.WORM.GEN WORM!"
XMsn Messenger Updatemsnupdate.exe"Added by a variant of the RBOT WORM!"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Plus Updatermsnplus.exe"Added by the RBOT-MU WORM!"
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
XMSN Updatemscon.exe"Added by the RBOT-QA WORM!"
XMSN Updatemsn32.exe"Added by the RBOT.AHN WORM!"
XMSN UpdateDLLCON.EXE"Added by the RBOT-EA WORM!"
XMSN Update Cfgmsnupdbt.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Update Clientmsnupdater.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Update Clientmsnupdcli.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Update Manager (Sp2)MSMSGS.EXE"Added by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMsn Update Serviceuserx.exe"Added by the MYTOB.JF WORM!"
XMSN Update Servicemsnupdsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
XMSN Updatermsnms.exe"Added by the FORBOT-CG WORM!"
XMsn Updatermsnplugins.exe"Added by the RBOT-HS WORM!"
XMsn Updaterwindatemanager.exe"Added by the SDBOT.TS WORM!"
XMSN UPDATERSvirtualmemory.exe"Added by the RBOT-JK WORM!"
XMSN Updatingmsnupdate.exe"Added by the QHOST.AEI TROJAN!"
XMSN6.1 Auto-Updaterv6msn.exe"Added by the AUTORUN-MM WORM!"
Xmsoft-updater23mssysstems.exe"Added by the RBOT-ATU WORM!"
Xmsoft-updater23slssystem.exe"Added by the RBOT-ASR WORM!"
Xmsoupdatermsoupdater.exe"Added by the DLOADER.GBD TROJAN!"
XMSPP System Update 64wiaadmgr.exe"Detected by Kaspersky as the RANKY.GEN TROJAN!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
XMSUpdatewupd.exe"Added by the ALADINZ.M TROJAN!"
XMSUpdatesvchosthlp.exe"Added by the BLASTER.T WORM!"
Xmsupdatemsupdate.exe"Added by the RBOT-MZ WORM!"
XMSUpdatecriticalUpdate.exe"Affilred adware"
Xmsupdateupdate.exe"Added by a variant of the SDBOT WORM!"
XMsupdateexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdateoutIook.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XMSupdate.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
XMSUpdateDevKitaxfd.exe"Added by the SDBOT-ZD WORM!"
Xmsupdatermsupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XMsUpdater Systemudpsys32.exe"Added by the RBOT.AAA WORM!"
XMSupdater.exeN/A"CoolWebSearch parasite variant. Installs the Winshow.dll browser plugin"
Xmsupdater25lsasser.exe"Added by the RBOT-ATS WORM!"
Xmsupdatesmsupdt.exe"Added by the RBOT-JO WORM!"
Xmsvupdatermsvupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMSWUpdate[path to worm]"Added by the SILLYFD-V WORM! The most common filename is lsass.exe but it not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMS_Update Checkwdfmgr.exe"Added by the AGOBOT-TB WORM!"
XMS_update_0704_KB74073.exeMS_update_0704_KB74073.exe"Added by a variant of the UPDATEKB TROJAN!"
XMyFastAccessmyfastupdate.exeMy-Fast-Access toolbar updater
Xnapv.exewupdate.exe"Added by the AGOBOT-JX BACKDOOR!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
XNAV Auto Updateiamsad.exe"Added by the SPYBOT-CE BACKDOOR!"
XNAV Auto UpdateSadness.exe"Added by the SPYBOT-E WORM!"
XNAV Auto Updatescsrssp.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Updatesnavwindows.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Updatesslserves.exe"Added by the RBOT.COI BACKDOOR!"
XNAV Auto Updatesnavupdaterx.exe"Added by a variant of the RBOT WORM!"
XNAV Live Update[path to worm]"Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec"
XNAV_UpdateNAV_Update.exeUnidentified WORM or TROJAN!
XNero Updater.6.12wmp9.exe"Added by the AGOBOT-AAG WORM!"
XNeroUpdate Checkmsjava.exe"Added by the AGOBOT.AMH WORM!"
XNeroUpdater6.8winjava.exe"Added by the AGOBOT.AMK WORM!"
?netfxupdatenetfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
Xnetupdate32netupdate32.exe"Added by the RBOT-GQZ WORM!"
XNiroFile UpdatedNiroFile.exe"Added by a variant of the IRCBOT TROJAN!"
XNod32 ServiceAutoUpdateWin32.exe"Added by the SDBOT-DJG WORM!"
YNokia Software Updaternsu_ui_client.exe"Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices"
XNorton Antivirus Updaternortonav.exe"Added by the DELBOT-T WORM! Note - this is not the real Norton AV!"
XNorton Live Update Servercpsdv.exe"Added by the AGOBOT.EW TROJAN!"
XNorton Live UpdaterCavapsvc.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterSochost.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterAvapsvc.exe"Added by the AGOBOT-BG BACKDOOR!"
XNorton SpySweeper AutoUpdatenavsw.exe"Added by the FORBOT-AS WORM!"
XNorton UpdateccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNorton UpdatecUpdate.exe"Added by the AGOBOT.APP WORM!"
XNorton updatedNVSV32.EXE"Added by the SDBOT.ABH WORM!"
XNorton Updaterwinset.exe"Added by a variant of the SPYBOT WORM!"
XNorton Updaterlsa.exe"Added by a variant of the RBOT WORM!"
XNorton UpdaterNortonUpdate.exeAdded by an unidentified WORM or TROJAN!
XNorton UpdaterccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton Updaternavupdtr.exe"Added by the SDBOT.AXV WORM!"
XNSupdateNSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
Xntupdatednsvc.exe"Added by the SDBOT-TC WORM!"
XNTupdater[path to trojan]"Added by the DIGARIX-D TROJAN!"
XNvUpdaternwiz32.exe"Added by a variant of the RBOT WORM!"
XOB Updaterob.exe"Added by the AGOBOT-IH WORM!"
XOffice MonitorsGoogleUpdater.exe"Added by the RBOT-GKZ WORM! Note - this is not the updater for the popular Google tools"
Xoffice_update[path to trojan]"Added by the DLOADER-ZB TROJAN!"
UOpenDNS UpdateOpenDNS Updater.exe"Updater for OpenDNS which ""is a free service that works for networks of all sizes
UOpenwares LiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
Xopsql update checkopsql.exe"Added by the RBOT-ACJ WORM!"
NOrangeSharkOSharkUpdater.exe"Orange Shark updater - online games for all ages"
XOrbitUpdateupdate.exe"Xupiter OrbitExplorer toolbar related. Drive-by foistware. Use Spybot S&D
XOuterinfoUpdateOuterinfoUpdate.exe"Clickspring.Outerinfo adware"
Xoutpostupdateoutpostupdate.exe"Added by the COSIAM-C TROJAN!"
NPalo Alto Software Update Manager 8.0PAS8_UD.exe"Update manager for small business planning software from Palo Alto Software - such as Business Plan Pro
XPCHEasySearchSTUpdate.exePCH EasySearch bar
XPersonal Firewall V9Firewall-UpdateV9.exe"Added by the RBOT-BJR WORM!"
NPluckSvrPluckUpdater.exe"Pluck Toolbar updater"
XPopup Blocker Updaterregsvr32 veev****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPopup Defence Updaterregsvr32 pdfupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
UPP2000 InstaupdatePPInupdt.exeProtector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
UPPUpdateppupdater.exe"PPUpdater - updater that used to be part of PestPatrol before CA's acquisition"
XPrinter Spoolupdater.exe"Added by a variant of the RBOT WORM!"
?Printer UpdateCFGREG.EXE"Maybe a registration reminder or automatically updates drivers or application software for a printer?"
YQH Live Update SchedulerUPSCHD.EXE"Quick Heal Anti-Virus"
NQuickbooks Update Agentqbupdate.exeAssociated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
NQuicken Scheduled Updatesbagent.exeQuicken background downloading module
NQuickTime Update Completion xquicktimeupdatehelper.exe"Different numbers caused by number of launches. So if 3 updates are made separately
XQuickTimeUpdateQuickUpdate.exe"Added by the BIFROSE-CW TROJAN!"
XRCAutoLiveUpdateMaxLURC.exe"Max Registry Cleaner rogue registry cleaner - not recommended
XReal player updaterrealupd.exe"Added by the PARLAY TROJAN!"
XRealPlayerUpdaterrealupd32.exe"Added by the LOHAV-T TROJAN!"
?RealTimeUpdateRealTimeUpdate.exe"Product description in properties is ""InternetExplorerCommunicationAgent Module"" ?"
XRealUpdaterrealupd.exe"Added by the PARLAY or MITGLIEDER.I TROJANS!"
URegUpdatesb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
YRemote Update Monitorimonitor.exe"Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer"
XRunDLL32winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
Xrunner1updater.exeAdded by the CRYPT.ULPM.GEN TROJAN!
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
XSafeGuard Popup Blocker Updaterregsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Blocker Updater (required)regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeSurfingUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
USAUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
USBAutoUpdatesbautoupdate.exe"SpywareBlaster auto-updater"
XScanRegistryupdate.exe"Added by the DWNLDR-FZY TROJAN!"
USDAutoLiveupdateLiveUpdateSD.exe"Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
Xsdfsdfsdfsp2update.exe"Added by a variant of the SPYBOT WORM!"
XSDKcore Update Components2SDKC0R3.exe"Added by the RBOT-ABA WORM!"
Xsdkupdate22SDK0mCORE.exe"Added by the FORBOT-DT WORM!"
XSecurityWindowsSecurityUpdate.exe"Added by a variant of the SDBOT WORM!"
XSecurity PatchWinUpdate32.exe"Added by the SDBOT-BM WORM!"
XSecurity Update Servicewmiprvce.exe"Added by the AGOBOT.ZW WORM!"
XSecurity Update Service Processsvrhost23.exe"Added by the AGOBOT-GN WORM!"
XService Update Clientsvcupdcli.exe"Added by an unidentified WORM or TROJAN! See here"
XSGPUpdatersgpUpdaters.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
Xshell updateshellexec.exe"Added by the RBOT-ANC WORM!"
XsoftIce Update 32wininits.exe"Added by the RBOT-ANB WORM!"
NSony Auto Update Tray ApplicationCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XSP2 Firewall/Internet Updatercrssrs.exe"Added by the RBOT.BJO WORM!"
Xsp2updatesp2update.exe"SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer"
Xsp2updateupdatesp2.exe"Added by the SDBOT.CAS WORM!"
XSpruce - Auto UpdateSpruce.exe"Rabio ""Search Enhancer"" adware variant"
XSpyFighterUpdateAutoUpdate.exe"SpyFighter spyware remover - not recommended
YSpywareTerminatorUpdateSpywareTerminatorUpdate.exe"Automatic updates for Spyware Terminator. Initially not recommended due to false positives but the later versions have since improved - see here"
XSQUpdatesCheckeruc.exe"Xupiter SQWire toolbar related. Use Spybot S&D
XSrchfstUpdatesrchupdt.exeSearchFast adware downloader
NSSBkgdUpdateSSBkgdupdate.exe"Automatic updates for ScanSoft (now Nuance) products such as OmniPage and PaperPort. Can be disabled using the main program's options. Note - if you have a Soundblaster Audigy2 ZS soundcard installed on your computer and the volume of your sound system is turned on extremely high disabling this will solve the problem"
XSSUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
XStart Uppingsmssupdate.exe"Added by a variant of the RBOT WORM!"
Xstartkeyupdate.exe"Added by the BIFROSE-DG TROJAN!"
XStartup UpdateCvshost.exe"Added by the GAOBOT.AO WORM!"
XStartUpDate[path to trojan]"Added by the BIFROSE.F BACKDOOR!"
XSun Java Updaterstacsv.exe"Added by the BUZUS.DBFM TROJAN!"
XSun Java Updater v5javajre.exe"Added by the AUTORUN-XI WORM!"
XSun Java Updater v7.4javawx.exe"Added by the ACKANTTA.B WORM!"
XSunJava Updater v7javale.exe"Added by the ACKANTTA.B WORM!"
XSunJavaSched Updateravamx.exe"Added by the RBOT-ABJ WORM!"
XSunJavaUpdatesmvss.exe"Added by the DEDLER-G TROJAN!"
XSunJavaUpdaterjavaw.exe"Added by the MYTOB.QR WORM!"
XSunJavaUpdaterv13javaupdater.exe"Added by the ROUTROBOT WORM!"
NSunJavaUpdateSchedjusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XSunJavaUpdateSchedscvhost.exe"Added by the SDBOT-AVX WORM!"
XSunJavaUpdateSchedjavamx.exe"Added by the SDBOT-WI WORM!"
XSunJavaUpdateSched10jushed.exe"Added by the ACKANTTA.F WORM!"
XSunJavaUpdateSched132jschd.exe"Added by the AUTORUN-AQY WORM!"
XSunJavaUpdateSched16jvshed.exe"Added by the ACKANTTA.G WORM!"
Xsupdatesupdate.exe"Added by the MALWARE.D TROJAN!"
Xsupdate2.dll"rundll32.exe supdate2.dllRun"
Xsupdate2.dllregsvr32.exe /s supdate2.dll"Added by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""supdate2.dll"" file is found in %System%"
XSustemUpdateexplorer.exe"Added by an unidentified VIRUS
XSVCHOSTupdater32.exe"Added by the RANTS.A WORM!"
Xsvhost updatesSvhost.exe"Added by a variant of the RBOT WORM!"
XSvshost Update Servicesvcbind.exe"Added by the MYTOB.LH WORM!"
Xsvshostdrivermsnmessengerupdate.exe"Added by the SDBOT-BI BACKDOOR!"
XSwf32AVupdate.exe"Added by the MERKUR.E WORM!"
XSygate Personal FirewallMcafeeupdate.exe"Added by the RBOT.YN WORM!"
XSygate Personal Port Blockerwinupdate.exe"Added by a variant of the RBOT WORM!"
XSysctrlswinupdate.exeAdded by an unidentified WORM or TROJAN!
XSyssehuupdate.exe"EHU adware"
XSystemUpdaterun.exe"Added by the QQHELP-DX TROJAN!"
Xsystem checkupdater.exeUnidentified adware downloader
USystem Files UpdaterSystem Files Updater.exe"System Files Updater from Flyakiteosx ""will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"""
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
NSystem Mechanic Professional Update [Incinerator.dll]SysMech4.exe /REREG: [path] Incinerator.dll"Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
XSystem Security Updatersvsmons.exe"Added by the RBOT-OW WORM!"
XSystem Update[filename].exe"CoolWebSearch parasite variant"
XSystem Update[random filename]"Added by the KORGO.W or KORGO.X WORMS!"
XSystem Updatewupdmgr.exe"Added by the SOROMO-A TROJAN!"
XSystem Update[random filename]"Added by the SOROMO-A TROJAN!"
XSystem Updatewauluclt.exe"Added by the SDBOT.EF WORM!"
XSystem Update[path to trojan]"Added by the AUTOTROJ-D TROJAN!"
XSystem Updatemssetupconf.exe"Added by the RBOT.DLC WORM!"
XSystem Update Applicationmsbuffer.exe"Added by the SDBOT.AFF WORM!"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystem Update Servicewinupd32.exe"Added by the ADTODA-A TROJAN!"
XSystem Update Servicesystem.pif"Added by the RBOT-ALL WORM!"
XSystem Update Serviceupdate.pif"Added by the SPYBOT.WOE WORM!"
XSystem Update Servicewmiprvsv.exe"Added by the AGOBOT.YG WORM!"
XSystem Update Servicecsrss32.exe"Added by the AGOBOT-HI WORM!"
XSystem Update2explorer.exe"Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSystem Update2services.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XSystem Update2svchost.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XSystem Update2system.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2taskman.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2taskmon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate Win98/Me file of the same name which is located in %Windir% as this version is located in %System%. It is not normally found on a WinXP system"
XSystem Update2update.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2webcheck.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2winlogon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process
XSystem Update2winspool.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2wupdmgr.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updatedsvchoes.exe"Added by the RBOT-ASF WORM!"
XSystem Updater Machinecrhwss.exe"Added by the CIADOOR-DQ TROJAN!"
XSystem Updater Machinesystem.exe"Added by the CIADOOR.GN BACKDOOR!"
XSystem Updater Processwmiprvsw.exe"Added by the AGOBOT-IL WORM!"
XSystem Updater Servicewmiprvsw.exe"Added by the GAOBOT.AFC WORM!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem Updatesszwi.exe"Added by the RBOT-AXE WORM!"
XSystem Updatesunve.exe"Added by the RBOT-AWG TROJAN!"
XSystem Updateswmkl.exe"Added by the RBOT-AYJ WORM!"
XSystem Updates 4mssysfix.exe"Added by the RBOT-ADU WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XSystem Updates Serviceupdates.pif"Added by the RBOT-AMA WORM!"
XSystemBooster2009sbr_updater.exe"SystemBooster2009 rogue system suite - not recommended
XSystemiom UpdaterSystemiom.exe"Added by the SPYBOT.TY WORM!"
XSystemUpdateNegdo.exe"Added by the CULLER-C WORM!"
XSystemUpdateXeyu.exe"Added by the CULLER-D WORM!"
Xsystemyom Updatersystemyom.exe"Added by a variant of the IRCBOT TROJAN!"
Xsysupdatecmman32.exe"Added by a variant of the SDBOT WORM!"
XTask managerUPDATEWIN.exe"Added by the RBOT.BBS WORM!"
XTCPXP Updatetcpxp.exe"Added by the RBOT-UL WORM!"
Xtcupdatertcupdater.exeTopconverting.com/180Search adware updater
XTerminal Updatebiosefui.exe"Added by the PPDOOR-O TROJAN!"
Xtlcupdate911.jsHijacker installer
Xtmaxpupdate.exeAdware pop-up generator
Xtpcupdaterupdatetc.exe"Antivirus XP 2008 rogue security software - not recommended"
XUpdate[original file path]"Added by the LYNDEGG WORM!"
XUpdateCDUpdater.exe"""Carpe Diem"" adult premium rate dialler related"
XUpdateSysupd.exeAdded by the SLACKBOT VIRUS!
XUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
XUpdatemshtm.exeBrowser hijacker - redirecting to buldog-search.com
XUpdateUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
Xupdatewinis.exe"Added by the RBOT-VD WORM!"
Xupdater00t.exe"Added by the RBOT-ACO WORM!"
XUPDATEWinUpdater5.0.vbs"Added by the GORMLEZ-A WORM!"
XUpDateRAuth.exe"Added by the DLOADER-UL TROJAN!"
XUpdatecsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdatecsrss.exe"Added by the MEHEERWAR TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""winupdate"" subfolder"
XUpdatelsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdatesvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdateUpdate.exe"QuickButton adware"
XUpdatehanz.exe"Added by a variant of the RBOT-GLJ WORM!"
XUpdateWinUpdate.exe"Added by the SDBOT-CV BACKDOOR!"
XUpdate Checkerwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XUpdate Checkerscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xupdate driverSNDVOL32.EXE"Added by the SPYBOT-CU BACKDOOR!"
XUpdate Exploreriexploreupd.exe"Added by a variant of the RBOT WORM!"
XUpdate for Windows[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
?Update for WorksMSWkstz.exe"Maybe related to later versions of MS Works?"
NUpdate GroksterWiseUpdt.exe"Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program
XUpdate InstallSchost.exe"Added by the GAOBOT.AO WORM!"
?Update localSetCPQLC.exe"Running on a Compaq desktop. Any ideas?"
NUpdate ManagerUpdateManager.exe"Searches for updates for the Rogers Yahoo! Browser - can be run manually"
Xupdate mon sysupdaterar.exe"Added by a variant of the RBOT WORM!"
Xupdate run doslogon.exe"Added by a variant of the SDBOT WORM!"
XUpdate Run MSwordLOGON.EXE"Added by the RBOT.TY WORM!"
YUpdate ServiceUpdate.exe"Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
Xupdate servicesvxhost.exe"Added by the RBOT-MG WORM!"
XUpdate Servicewinu32.exe"Added by the RBOT-MG WORM!"
Xupdate servicewinx.exe"Added by a variant of the RBOT WORM!"
?Update TUTWiseUpdt.exe"??"
XUpdate ver 1.0Swap.exe"Added by the SWAP-C WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate.exeravseuper.exe"Added by the QQPASS-P TROJAN!"
XUpdate32configs.exe"Hijacker
XUpdateCheckwinstall.exe"Added by the SPYBOT-CY WORM!"
NUpdateCheckerUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
XUpdateComponentCNF UPD.EXEAdded by the SPYBOT.GEN VIRUS!
?UpdateFWfwdload.exe"Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module?"
?UPDATEHOOKRundll32.exe"??"
Xupdatelavasoftupdatelavasoft.exe"CoolWebSearch parasite variant - redirecting to lalasearch.com"
UUpdateManagersgtray.exe"StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop)
XUpdateManagerupdmanager.exe"Added by the ANYHOMB.F TROJAN!"
XUpdateMediaUpdateMedia.exe"MediaUpdate foistware"
XUpdateMgrupdmgr.exe"SouthBeachTel premium rate adult content dialer"
NupdateMgrAdobeUpdateManager.exeAutomatic updates for the Adobe Reader file viewer
Nupdatemgr.exeupdatemgr.exe"Once a month
XUPDATEMSNsvhost.exeAdded by an unidentified WORM or TROJAN!
Xupdaterwupdater.exe"KeenVal adware"
?updaterupdater.exe"??"
XUpdateradservernow.exe"AdServerNow adware"
Xupdaterwisvc.exe"Added by the ORSE-A TROJAN!"
XUpDaTercsrss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XUpdater Service Processsvhost32.exe"Added by the AGOBOT.TY WORM!"
XUpdater Service Processcsrss32.exe"Added by the AGOBOT-GP BACKDOOR!"
Xupdater32winload32.exe"Added by the CULT.M WORM!"
Xupdaterealrealupdate.exeChinese originated adware
XUpdaterUIUpdaterUI.exe"Added by the AGENT-TM TROJAN!"
XUpdatesmsupdate.exe"CoolWebSearch parasite variant"
NUpdates from HPbackweb*****.exe"See here - ""messaging service that automatically sends you support information
NUpdates from HPUpdates from HP.exeAutomatically detects an internet connection and downloads any available updates
Xupdatesched[random filename]"ZenoSearch adware"
XUpdateServicewservice.exe"Added by the DREF-K WORM!"
XUpdatestatsUpdatestats.exe"Statblaster adware"
XUpdateStatsUpdateStats.exe"SeekSeek search hijacker related - see here"
Nupdatev01updatev01.exeUltra-networks.com software updater/downloader
Xupdatewinupdate.exe"Added by a variant of the SDBOT WORM!"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XupdateWinssystrey.exe"Added by the RANDON WORM!"
?Updatewizupdatewiz.exe"??"
XUpdateXpSpMS045-XP2.exe"Added by the IRCBOT.NY TROJAN!"
Xupdatexwinwinxrpc.exe"Added by the AGOBOT-KJ WORM!"
NUPDATE~1updatemgr.exe"Once a month
UUpromise UpdateUpromiseUa.exe"Updater for the Upromise college savings program"
XUSB 2.0 DriverupdateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
XUSB 2.0 DriverupdateXP.exe"Added by the AGOBOT-QP WORM!"
XUSB 2.0 DriverUpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
XUSB 2.1 Driverwinupdate1.exe"Added by a variant of the RBOT WORM!"
XUSB Driver4UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XUSB MS UpdateUSBS.exe"Added by a variant of the RBOT WORM!"
XUSB Updatesmservices.exe"Added by a variant of the SDBOT WORM!"
XUSB Updatesmsfirewalls.exe"Added by a variant of the RBOT WORM!"
XUSB Updates 2wugfixx.exe"Added by a variant of the RBOT WORM!"
UVAIO Update 2VAIOUpdt.exeRelated to Sony Vaio Update service
XVBS_AUTO_UPDATE0548656X.vbs"Added by the GORMLEZ-A WORM!"
XVdat Updatelalaa.exe"Added by a variant of the RBOT WORM!"
XvirusbyevirusbyeUpdater.exe"VirusBye rogue security software - not recommended"
XVnCplUpdatemsdm.exe"Masssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in
XWebSUpdaterwupda.exe"Added by the STARTPAGE.C TROJAN!"
UWildTangent Web Driver updaterwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
XWin Process Updateswinupdates.exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
Xwin updatewupda32.exe"Added by the SDBOT.J WORM!"
Xwin updatewapdate.exe"Added by a variant of the RBOT WORM!"
XWin UpdateSysUpdate.exe"Added by the AGOBOT-TN WORM!"
XWin Updateoleupdate.exe"Added by the AGENT-UY TROJAN!"
XWin Updatemsnmger.exe"Added by the RBOT-GDP WORM!"
Xwin updatewupdate.exe"Added by the RBOT-P BACKDOOR!"
XWin UpdaterWINUPDATER.EXE"Added by the RBOT.IP WORM!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 Ms Auto UpdaterAutomsUPD.exe"Added by a variant of the RBOT WORM!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWin32 Updatedl32.exeAdded by an unidentified WORM or TROJAN!
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
XWin32 USB2 Driverupdatemgr.exe"Added by a variant of the FORBOT WORM!"
Xwin32updatewin32update.exe"Added by the GENOME.AQUV TROJAN!"
XWin32UpdaterKERNAL32.EXE"Added by the SPYBOT-OK WORM!"
XWinamp Updateyhn.exe"Added by the SDBOT-ACR WORM!"
XWindosupdate managerrunwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
Xwindow2ieupdate.exe"Added by the FORBOT-BM WORM!"
XWindowRegKey updatewins.exe"Added by the SPYBOT.I WORM!"
XWindows 32 UpdateWindows-Update.exe"Added by a variant of the RBOT WORM!"
Xwindows auto updatemsblast.exe"Added by the BLASTER.B WORM!"
Xwindows auto updatepenis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
XWindows Auto Updatewinupdater.exe"Added by the SDBOT.TF WORM!"
XWindows auto updatebazzi.exe"Added by the AHKER.E WORM!"
XWindows auto updateLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows Automatic Updatewuamgrder.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updaterwindrg.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updatesdvldr.exe"Added by the RBOT.MF WORM!"
XWindows Automatical Updaterdcz.exe"Added by the RBOT.CXS WORM!"
XWindows AutomaticUpdaterrunddls.exe"Added by a variant of the RBOT WORM!"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows Debugging Toolsupdatecfg.exe"Added by the RBOT-AXU WORM!"
XWindows Defender Updaterwdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Firewall Updaterupdatees.exe"Added by the RBOT-GBX WORM!"
XWindows Firewall Updatercronos.exe"Added by the RBOT-GBY WORM!"
XWindows Firewall Updaterctfcom.exe"Added by the RBOT-GCB WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows Java UpdateweatherBug32.exe"Added by a variant of the RBOT WORM!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Manager Update Inctgb.exe"Added by the SDBOT-ACM WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
XWindows Media Updatercrease.exe"Added by the RBOT-ATI WORM!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows Microsoft Updatewintask32.exe"Added by a variant of the SDBOT WORM!"
XWindows MS Update 32fhm.exe"Added by the IRCBOT.GEN WORM!"
XWindows MS Update 32sucker.exe"Added by the FORBOT-GJ WORM!"
XWindows MS Update 32jebote.exe"Added by the FORBOT-GK WORM!"
XWindows MSN Updateswnd32.exe"Added by the IRCBOT-ABA TROJAN!"
XWindows NT Update ManagerWINL0G0N.exe"Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
XWindows Online Updaterdllman.exe"Added by the RBOT-TE WORM!"
XWindows Processwin_update.exe"Added by the LASTWORD WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Secure Updatewinupser.exe"Added by the RBOT-GCG WORM!"
XWindows Secure UpdateWinSecUp.exe"Added by the RBOT-GCD WORM!"
XWindows Secure Updateload.exe"Added by the FORBOT-GU WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Security Updatesecurity32.exe"Affilred adware"
XWindows Security Updatendsass.exe"Added by the RBOT.ESM BACKDOOR!"
XWindows Service Pack Auto Updatewinworks.exe"Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updatefiggaz.exe"Detected by Kaspersky as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updateballin.exeAdded by an unidentified WORM or TROJAN!
XWindows Service Pack Auto Updatedel-me.exe"Adware
XWindows Service Updatelivecal.exe"Added by the SDBOT-DEY WORM!"
XWindows Service Updatecrsss.exe"Added by the SDBOT.CWX WORM!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWindows SP2 UpdateSp2update.exe"Added by the WOOTBOT.BS WORM!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMwupdate.exe"Added by the MYTOB-HT WORM!"
XWINDOWS SYSTEM UPDATExDcc.exe"Added by the MYOTB-EH WORM!"
XWindows System Update Toolsupds.exe"Added by the VANBOT.CX BACKDOOR!"
XWindows Update[filename]"Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
Xwindows updateuddater.exe"Added by the LEOX TROJAN!"
XWindows Updatewudate.exe"Added by the AGOBOT.ML WORM!"
XWindows Updatewupdate.exe"Wengs adware"
Xwindows updatesychost.exe"Added by the LEOX.B WORM!"
XWindows UpdateWuamgrd.exe"Added by a variant of the SPYBOT WORM!"
XWindows Updateinetinf.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows Updatehost32.exe"Added by the RBOT-GU WORM!"
Xwindows updatewuraclt.exe"Added by the RBOT-PO WORM!"
Xwindows updateWuanclt.exe"Added by the RBOT.XZ WORM!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows Updateebay.exe"Added by the GAOBOT.BUU WORM!"
XWindows Updatewindows.exe"Added by the RBOT-RB WORM!"
Xwindows updatewuaurlt.exe"Added by the RBOT.ADG WORM!"
XWindows UpdateUpdate.exe"Added by the DELF-FN TROJAN!"
XWindows Updatewinmguard.exe"Added by the RBOT-EM WORM!"
XWindows Updatewuampd.exe"Added by the RBOT.UM WORM!"
Xwindows updatewuarclt.exe"Added by the RBOT-OF WORM!"
XWindows Updatewinupdate.exe"Added by the SDBOT-WS WORM!"
XWindows Updatemsnwinsb.exe"Added by the RBOT-AAH WORM!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
Xwindows updateMicrosoft.exe"Added by the LMIR.A TROJAN!"
XWindows Updatemplupdate.exe"Added by the MOEGA WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows Updatetaskmr.exe"Added by the MYTOB-GZ WORM!"
XWindows Updateupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Updatewininfo.exe"Added by the MYTOB.GA WORM!"
XWindows Updatewinlogin.exe"Added by the BANKER-DV TROJAN!"
XWindows Updatemsnupdates.exe"Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
XWindows Updateqtask.exe"Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here"
Xwindows updatereal.exe"Added by the LEGMIR-AU WORM!"
XWindows Updatewindowsx.exe"Added by the BANCD-A TROJAN!"
XWindows updatewudupdate.exe"ISTBar adware related"
XWindows Updatewupdmgr.exe"Added by the BANCBAN-FC TROJAN and variants!"
XWindows Updatecsrss.exe"Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows UpdateXPLoogNT.exe"Added by the BANCD-B TROJAN!"
XWindows Updateinstall.exe"Added by the BANKER-IB TROJAN!"
XWindows Updatemsi.exe"Added by the BANKER-XB TROJAN!"
XWindows UpdateSqltob.exe"Added by the DASHER.A WORM!"
Xwindows updatelogonuit.exe"Added by the LEGMIR-AO TROJAN!"
XWindows Updateavkir.exe"Added by the RBOT-GJP WORM!"
XWindows Updateeasypwnt.exe"Added by a variant of the SDBOT WORM!"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows UpdateSecretStub.exe"Added by the SRAMLER.C WORM!"
XWindows UpdateWinload.exe"Added by the DEDMIR-A WORM!"
XWindows Updatetaskngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows Updatelivesrvs.exe"Added by a variant of the RBOT WORM!"
XWindows UpdateMcAfee.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
XWindows UpdateMcAfee3.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatescrigz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updatewinsc.exe"Added by the BUZUS.RYI TROJAN!"
XWindows Updatewuauclt32.exe"Added by the SDBOT.DHY WORM!"
XWindows Updatedllhostup.exe"Added by the BANCBAN-NB TROJAN!"
XWindows Updateexplored.exe"Added by the GAOBOT.MF WORM!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows Updatesysdrv.exe"Added by the AGENT-IYE TROJAN!"
XWindows Updatewinupupdate1.exe"Added by the RBOT-UV WORM!"
XWindows Updateklass.exe"Added by the BIFROSE-ZH TROJAN!"
XWindows UpdatewinlogonEvt.exe"Added by the VB-DXM TROJAN!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
XWindows Updatefdos.exe"Added by the RBOT-COG WORM!"
XWindows Updateleak32x.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows updatemsb32.exe"Added by the GAOBOT.CG WORM!"
XWindows updatesvdhost.exe"Added by the GAOBOT.CG WORM!"
XWindows Updatetskmngr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows Updatewindb32.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update 32winlogons.exe"Added by the FORBOT-FI WORM!"
XWindows Update 32rempss.exe"Added by the FORBOT-FW WORM!"
XWindows Update 32slsys.exe"Added by the FORBOT-FT WORM!"
XWindows update 32bitwinupd32.exe"Added by the SDBOT.BE WORM!"
XWindows Update 63shupd64.exe"Added by the FORBOT-GA WORM!"
XWindows Update 64nbupd64.exe"Added by a variant of the FORBOT WORM!"
XWindows Update 64WinV.exe"Added by the FORBOT-FP WORM!"
XWindows Update Auto Updatewuaumgr.exe"Added by a variant of the SPYBOT WORM!"
XWindows Update Automatic Updates[path to backdoor]"Added by the VBBOT.AM BACKDOOR!"
XWindows Update Automationwinuptdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwaucult.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwuauclt.exe"Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process
XWindows Update AutoUpdate Client Productwuauct.exe"Added by the AGOBOT.ACL WORM!"
XWindows Update Centersvthx.exe"Added by the STUBBOT.A WORM!"
XWindows Update CenterW32RSA.exeAdded by an unidentified WORM or TROJAN!
XWindows Update Checksyslodr.exe"Added by the SMALL.LU TROJAN!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update Checkermsupdte32.exe"Added by the SDBOT-AEF WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Clientwuclient.exe"Added by the SMALL-RN TROJAN!"
XWindows Update Client Servicewindrvl32.exe"Added by the AGOBOT-MM TROJAN!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows Update Dravendraven.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Driveupdrvs.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Filesdnetc.exe"Added by an unidentified VIRUS
XWindows Update Firewall Systemctfmoom.exe"Added by the RBOT-GAN WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Update Firewall Systemctfmom.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Update GUI Executable x32xwupdategux32.exe"Added by the RBOT.CXY WORM!"
XWindows Update Hostwinupsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Update IPv6 LayerWIN32IPV6.EXE"Added by the RBOT.DUD WORM!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Managerwupdmngr.exe"Added by the RANDEX.BTB WORM!"
XWindows Update ManagerWinlog0n.exe"Added by the AGENT-BO TROJAN!"
XWindows Update Managerwupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update Managerbootwiz.exeAdded by the MYBOT WORM!
XWindows Update ManagerWindowsUpdateManager.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Update Manager for NTwupdmgr32.exe"Added by the SDBOT.AH WORM!"
Xwindows update microsoftupdatem.exe"Added by the RBOT-CHE WORM!"
XWindows Update Monitoring Servicewinupdt.exe"Added by the RBOT-PL WORM!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Serviceupdate32.pif"Added by the RBOT-ALC WORM!"
XWindows Update Servicetrest.exeIdentified by BitDefender as a variant of the PEED TROJAN!
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Update Softwaresystem.exe"TOFGER.BX spyware"
XWindows Update SP3Windat.EXE"Added by the RBOT-GTS WORM!"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindows Update.exeN/AHomepage hijacker
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Updatedupdatr.exe"Added by the RBOT-AYB WORM!"
XWindows Updaterwupdmgr32.exe"Added by a variant of the DOS.AUTOCAT TROJAN!"
XWindows Updateriexplorerrs.exe"Added by the RBOT-TN WORM!"
XWindows Updatersvigost.exe"Added by the RBOT-VS WORM!"
XWindows Updaterwupdate.exe"Added by the WOOTBOT.AJ WORM!"
XWindows Updatersdsys.exe"Added by the FORBOT-JG WORM!"
XWindows Updater Onlinewinupdatexx.exe"Added by a variant of the RBOT WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows Updater Service Managerwinupdatr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
Xwindows updaterswinupdats.exe"Added by the SPYBOT-IS WORM!"
XWindows Updateslsassx.exe"Added by a variant of the SDBOT WORM!"
XWindows Updateswinupd32.exe"Added by the MYTOB.CE WORM!"
XWindows Updatesw32dns.exe"Added by the SDBOT-BFW WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"
XWindows USB Monitorservupdate.exe"Added by the IRCBRUTE.AQ TROJAN!"
XWindows XP Automatic UpdatewXPupdate.exe"Added by the RBOT-AFC WORM!"
XWindowsACEbaracebarupdate.exe"BarACE adware"
XWindowsCriticalUpdatewindows_critical_update.exe"Added by the ASTEF or RESPAN WORMS!"
XWindows�UpdatesUpdate.exe"Added by the RBOT.TRA BACKDOOR!"
XWindowsKeyUpdatemaster.exe"Added by the JOSAM WORM!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey updatewinupdate.exe"Added by the RBOT-QJ WORM!"
XWindowsRegKey updatewindns.exe"Added by the RBOT.IE WORM!"
XWindowsRegKey updatewinupdatexx.exe"Added by the RBOT.LW WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsRegKey updatesvchostc.exe"Added by the RBOT.IF WORM!"
XWindowsRegKey updatewdnupdate.exe"Added by the SDBOT.QX WORM!"
XWindowsRegKey updateWindowsup.exe"Added by the SDBOT.PU WORM!"
XWindowsRegKey updateWINUPDATES.EXE"Added by the RBOT-MM WORM!"
XWindowsRegKey updaterkbuouoxfl.exe"Added by the RBOT-OO WORM!"
XWindowsRegKey updatewinsys.exe"Added by the RBOT-JY WORM!"
XWindowsRegKey updatewinupdat32.exe"Added by the RBOT-AGW WORM!"
XWindowsRegKey update XPwindexv1.exe"Added by the RBOT-ABM WORM!"
XWindowsRegKey%$ updatemsi332.exe"Added by the RBOT-IX WORM!"
XWindowsRegKey%updateethernet32m.exe"Added by the RBOT-EN WORM!"
XWindowsRegKeys updatewinsysi.exe"Added by the SDBOT.WE WORM!"
XWindowsUpdatewindows_update.exe"Added by the LOFNI WORM!"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XwindowsupdateRPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
XWindowsUpdateUSRINIT.EXE"Added by the MADDIS.B WORM!"
Xwindowsupdatewinupdate.exe"Added by the WARPI WORM!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatewinnnint.exeAdded by an unidentified WORM or TROJAN!
XWindowsUpdate[path to file]"Added by the DUPA-B TROJAN!"
XWindowsUpdatesvchostw.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdateNzil.exe"Added by the CULLER-C WORM!"
XWindowsUpdateStrad.exe"Added by the CULLER-D WORM!"
XWindowsupdateWindowsupdate.exe"Added by the BANKER.ARK TROJAN!"
XWindowsupdatewupdmgr98.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xwindowsupdateautoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
XWindowsUpdatesvdhost.exe"Added by the AGOBOT-BP WORM!"
XWindowsUpdatetwain.exe"Added by the AGENT.BEA TROJAN!"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsUpdate Servicewuautlc.exe"Added by the RBOT-NR WORM!"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWindowsUpdatecrsscrss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdateDirectdupadirect.exe"Added by the DUPA-C TROJAN!"
XWindowsUpdatelsassslsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdatem1[path to file]"Added by the AGENT-AAJ TROJAN!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdateManagerwupdmng.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindowsUpdateNTsvwhost.exe"Added by the SHELLOT-B TROJAN!"
XWindowsUpdateRregserv.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindowsUpdatev4w32gins.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
XWindowsUpdatewinsecwinsec.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsXP Updatewindowsxpupdate.exe"Added by the RBOT-PB WORM!"
XWindows_Updatessvthost.exe"Added by a variant of the SPYBOT WORM!"
XWindowz Update V2.0Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindowz Update V2.0updater.exe"Added by the YODO-C WORM!"
XWindoxs Update CenterW32RfSA.exe"Added by a variant of the SDBOT WORM!"
XWindUpdates[path to trojan]"Added by the AGENT.BF TROJAN!"
XWindUpdatesWinUpdt.exeWindupdates adware variant
XWinLibUpdatelibupdate.exe"Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
XWinLibUpdate32libupdate32.exeAdded by the BIONET.405 TROJAN!
Xwinlocatorupdateupdatewinlocator.exeLocator adult content toolbar related
Xwinnt DNS identwinupdate32.exe"Added by a variant of the RBOT WORM!"
XWinprocer32 Updatewinprocer32.exe"Added by the RBOT.GW WORM!"
Xwinprocessor Updatewinprocessor.exe"Added by the RBOT.IO WORM!"
XWins Update 32services32.exe"Added by the FORBOT-FN WORM!"
XWinSetBrowseBasicUpdate.dll.vbs"Added by the BISCUIT.A WORM!"
XWinShowUpdatecopy [path] winshow.new [path] winshow.dll"Winshow parasiate related - from the ""RunOnce"" keys it replaces ""winshow.dll"" with a new version"
XWinsock driverwinnt update.exe"Added by the SPYBOT-DM TROJAN!"
XWinsock driverwinupdate32.exe"Added by the SPYBOT-JZ TROJAN!"
XWinsock2 driverwinupdate.exe"Added by the SPYBOT-BX WORM!"
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
Xwinsupdaterwinsupdater.exe"Added by the ALCRA-F WORM!"
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
XWINTASK DLL32updatewin"Added by the MYTOB.NI WORM!"
XWintelUpdate[path to trojan]"Added by the SMALL-EKW TROJAN!"
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
XWinUpdateRBSKQQBO.EXE"Added by the VBSWG2B.A WORM!"
XWinUpdatewmbem.exe"Added by the REVCUSS.B TROJAN!"
XWinUpdateupdsys.exe"Added by a variant of the RBOT WORM!"
Xwinupdatewinupdate.exe"Added by the ALCAN.B WORM!"
XWinUpdatesvhost.exe"Added by a variant of the SDBOT WORM!"
XWinUpdatesvchots.exe"Added by the SMALL.GXJ TROJAN!"
Xwinupdatejusched.exe"Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
XWinupdatelsas.exe"Added by the COSPET.JR TROJAN!"
XWinupdate Enginewupeng.exe"MalwareCrush rogue security software - not recommended
XWinUpdate Loadermsnnm.exe"Added by the REVCUSS.C TROJAN!"
XWinupdate Servicewinxp.exe"Added by the SPYBOT.IR WORM!"
Xwinupdate.exewinupdate.exe"Added by the RADO TROJAN!"
Xwinupdate.regwinupdate.exe"Added by the SPYBOT.EAS WORM!"
Xwinupdate2846vbsystem35.exe msvbrun.exe"Added by a variant of the MUTIN-C TROJAN!"
Xwinupdate86.exewinupdate86.exe"Added by the FAKEAV-AHQ TROJAN!"
XWinUpdateAdministratorCSRSS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
XWinUpdateBbreatle.exe"Added by the BRATLE.AWORM!"
Xwinupdateconn[path to file]"Added by the COMBRA-A WORM!"
Xwinupdateconn_Explorer.EXE"Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWinupdateewinsvcc.exe"Added by the AGENT.AN TROJAN!"
Xwinupdatefiv_[path to file]"Added by the COMBRA.C WORM!"
UWinUpdateProtectioncsrss.exe"EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
XWinUpdaterupdate.exe"Added by the STARTPAGE.C TROJAN!"
Xwinupdateswinupdates.exe"Added by the ALCRA-B WORM!"
Xwinupdate_[path to file]"Added by the COMDOR.A WORM!"
XWinxDiagUpdateWinxDiagUpdate"Added by the RBOT.BWQ BACKDOOR!"
XWinxp updateCappp.exe"Added by the RBOT.DKO WORM!"
XWinXp Updaterwinxp32.exe"Added by the RBOT-HG WORM!"
XWinXpUpdate32WinXpUpdate32.exe"Added by the AGENT.YWL WORM!"
XWinZip UpdateWinZip.exe"Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility"
XWMP Auto UpdateWINMEDUP.EXE"Added by the RBOT.CF WORM!"
Xwmupdatewmupdate.exe"Added by the AGENT-GGJ TROJAN!"
Xwnxpupdatespvspool.exe"Added by the DABORA.B WORM!"
Xwnxupdateupdatexp.exe"Added by the COMBRA-G WORM!"
Xwon updateWAPDATE.EXE"Added by the RBOT.N WORM!"
Xwupdatewisvccz.exe"Added by the ORSE-B TROJAN!"
Xwupdatewi32.exe"Detected by Panda as Trustbid spyware"
XWUpdate1037v.exe"Added by the CLAGGER-AR TROJAN!"
XWupdate driver[various filenames]"Added by a variant of the SPYBOT WORM!"
XWupdate driverwupdadte.exe"Added by the SPYBOT-CQ WORM!"
XWUpdatesWUpdates.exe"Added by the SWEPDAT TROJAN!"
XWxp4Norton Update.exe"Added by the ERKEZ.D WORM!"
XxDRam rar procxxwinupdaterarx.exe"Added by the RILER-W TROJAN!"
Xxp32winxpupdater02.exe"Added by the MOSUCK-A TROJAN!"
Xxpiupdatexpiupdate.exe"Added by the RBOT-AAB WORM!"
Xxpsp2installxpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpsp2Updatexpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpupdateupdates.exe"Added by the BROPIA.L WORM!"
XXTServiceUpdateXTServiceUpdate.exehahame.net adware downloader
XYahoo UpdateYahoo!.exe"Added by the YAHOO! TROJAN!"
XYahoo UpdateYahoo.exe"Added by the RBOT.AH BACKDOOR!"
XYahoo UpdaterMessenger.exe"Added by the FORBOT-FE WORM!"
XYhooUpdatesymsmsgs.exe"Added by the SMALL_K TROJAN!"
Xzervpack2update2.exe"Added by the SDBOT.WD WORM!"
XZi5AntiVirus Update.exe"Added by the ERKEZ.G WORM!"
UZoneUpdatecsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
XZupdateZupdate.exe"Associated with B3d Projector foistware - see here"
X{C0FB7D08-056E-1033-0501-03020730002c}Update.exe"Added by the AGENT-EOG TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.