Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Updatesalgs.exe"Added by the IRCBOT-AAM TROJAN!"
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
NHP Updates??"On HP PCs
Xieupdatesieupdates.exe"Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
XJavaUpdateSchedjusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
XMascro soft SDK updates2SDKrepair2.exe"Added by the SDBOT.BXM WORM!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosoft Corp Updateswupdates.exe"Added by the RBOT-AUU WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
XMicrosoft Updatessystemc32.exe"Added by the RBOT-GR WORM!"
XMicrosoft Updateswkssvr.exe"Added by the RBOT.R WORM!"
XMicrosoft Updateswkssvrs.exe"Added by the RBOT-EB WORM!"
XMicrosoft Updateswuamgrd.exe"Added by the RBOT-CO WORM!"
XMicrosoft Updateswtemp32.exe"Added by the RBOT-AHQ WORM!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft Updates[worm filename]"Added by the AGOBOT-AIZ WORM!"
XMicrosoft Updateswgcptsud.exe"Added by the RBOT-GTF WORM!"
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft Updates 2 USBwgafixer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updates 5 USBsp3fixer.exe"Added by the RBOT-ADS WORM!"
XMicrosoft UpdateS Machinewgrd.exe"Added by the RBOT-FI WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WinUpdatesserm32.exe"Added by the RBOT.GE WORM!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosoftUpdates[path to trojan]"Added by the DELF-LO TROJAN!"
XMicrosoftUpdatessyshelped.exe"Added by the FORBOT-AZ WORM!"
XModem Driverz Updatesmdmdrv.exe"Added by a variant of the SDBOT WORM!"
XMS Updatesmscache.exeSpyware web downloader
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
XMS Updatesaupd.exeSpyware web downloader
XMSN Auto-Updatermsnupdates.exe"Added by the AUTORUN.WORM.GEN WORM!"
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
Xmsupdatesmsupdt.exe"Added by the RBOT-JO WORM!"
XNAV Auto Updatescsrssp.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Updatesnavwindows.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Updatesslserves.exe"Added by the RBOT.COI BACKDOOR!"
XNAV Auto Updatesnavupdaterx.exe"Added by a variant of the RBOT WORM!"
NQuicken Scheduled Updatesbagent.exeQuicken background downloading module
USDAutoLiveupdateLiveUpdateSD.exe"Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
Xsp2updateupdatesp2.exe"Added by the SDBOT.CAS WORM!"
XSQUpdatesCheckeruc.exe"Xupiter SQWire toolbar related. Use Spybot S&D
NSunJavaUpdateSchedjusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XSunJavaUpdateSchedscvhost.exe"Added by the SDBOT-AVX WORM!"
XSunJavaUpdateSchedjavamx.exe"Added by the SDBOT-WI WORM!"
XSunJavaUpdateSched10jushed.exe"Added by the ACKANTTA.F WORM!"
XSunJavaUpdateSched132jschd.exe"Added by the AUTORUN-AQY WORM!"
XSunJavaUpdateSched16jvshed.exe"Added by the ACKANTTA.G WORM!"
Xsvhost updatesSvhost.exe"Added by a variant of the RBOT WORM!"
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem Updatesszwi.exe"Added by the RBOT-AXE WORM!"
XSystem Updatesunve.exe"Added by the RBOT-AWG TROJAN!"
XSystem Updateswmkl.exe"Added by the RBOT-AYJ WORM!"
XSystem Updates 4mssysfix.exe"Added by the RBOT-ADU WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XSystem Updates Serviceupdates.pif"Added by the RBOT-AMA WORM!"
XUpdatesmsupdate.exe"CoolWebSearch parasite variant"
NUpdates from HPbackweb*****.exe"See here - ""messaging service that automatically sends you support information
NUpdates from HPUpdates from HP.exeAutomatically detects an internet connection and downloads any available updates
Xupdatesched[random filename]"ZenoSearch adware"
XUpdateServicewservice.exe"Added by the DREF-K WORM!"
XUpdatestatsUpdatestats.exe"Statblaster adware"
XUpdateStatsUpdateStats.exe"SeekSeek search hijacker related - see here"
XUSB Updatesmservices.exe"Added by a variant of the SDBOT WORM!"
XUSB Updatesmsfirewalls.exe"Added by a variant of the RBOT WORM!"
XUSB Updates 2wugfixx.exe"Added by a variant of the RBOT WORM!"
XWin Process Updateswinupdates.exe"Added by a variant of the SDBOT WORM!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Automatic Updatesdvldr.exe"Added by the RBOT.MF WORM!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows MSN Updateswnd32.exe"Added by the IRCBOT-ABA TROJAN!"
XWindows Updatemsnupdates.exe"Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
XWindows Update Automatic Updates[path to backdoor]"Added by the VBBOT.AM BACKDOOR!"
XWindows Updateslsassx.exe"Added by a variant of the SDBOT WORM!"
XWindows Updateswinupd32.exe"Added by the MYTOB.CE WORM!"
XWindows Updatesw32dns.exe"Added by the SDBOT-BFW WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"
XWindows�UpdatesUpdate.exe"Added by the RBOT.TRA BACKDOOR!"
XWindowsRegKey updateWINUPDATES.EXE"Added by the RBOT-MM WORM!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindows_Updatessvthost.exe"Added by a variant of the SPYBOT WORM!"
XWindUpdates[path to trojan]"Added by the AGENT.BF TROJAN!"
XWindUpdatesWinUpdt.exeWindupdates adware variant
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
Xwinupdateswinupdates.exe"Added by the ALCRA-B WORM!"
XWUpdatesWUpdates.exe"Added by the SWEPDAT TROJAN!"
Xxpupdateupdates.exe"Added by the BROPIA.L WORM!"
XYhooUpdatesymsmsgs.exe"Added by the SMALL_K TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.