Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows Update ManagerWindowsUpdateManager.exe"Added by a variant of the IRCBOT TROJAN!"
XWindowsUpdatewindows_update.exe"Added by the LOFNI WORM!"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XwindowsupdateRPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
XWindowsUpdateUSRINIT.EXE"Added by the MADDIS.B WORM!"
Xwindowsupdatewinupdate.exe"Added by the WARPI WORM!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatewinnnint.exeAdded by an unidentified WORM or TROJAN!
XWindowsUpdate[path to file]"Added by the DUPA-B TROJAN!"
XWindowsUpdatesvchostw.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdateNzil.exe"Added by the CULLER-C WORM!"
XWindowsUpdateStrad.exe"Added by the CULLER-D WORM!"
XWindowsupdateWindowsupdate.exe"Added by the BANKER.ARK TROJAN!"
XWindowsupdatewupdmgr98.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xwindowsupdateautoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
XWindowsUpdatesvdhost.exe"Added by the AGOBOT-BP WORM!"
XWindowsUpdatetwain.exe"Added by the AGENT.BEA TROJAN!"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsUpdate Servicewuautlc.exe"Added by the RBOT-NR WORM!"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWindowsUpdatecrsscrss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdateDirectdupadirect.exe"Added by the DUPA-C TROJAN!"
XWindowsUpdatelsassslsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdatem1[path to file]"Added by the AGENT-AAJ TROJAN!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdateManagerwupdmng.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindowsUpdateNTsvwhost.exe"Added by the SHELLOT-B TROJAN!"
XWindowsUpdateRregserv.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindowsUpdatev4w32gins.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
XWindowsUpdatewinsecwinsec.exe"Added by a variant of the AGENT-HZ TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.