Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XWindows Update[filename]"Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
Xwindows updateuddater.exe"Added by the LEOX TROJAN!"
XWindows Updatewudate.exe"Added by the AGOBOT.ML WORM!"
XWindows Updatewupdate.exe"Wengs adware"
Xwindows updatesychost.exe"Added by the LEOX.B WORM!"
XWindows UpdateWuamgrd.exe"Added by a variant of the SPYBOT WORM!"
XWindows Updateinetinf.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows Updatehost32.exe"Added by the RBOT-GU WORM!"
Xwindows updatewuraclt.exe"Added by the RBOT-PO WORM!"
Xwindows updateWuanclt.exe"Added by the RBOT.XZ WORM!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows Updateebay.exe"Added by the GAOBOT.BUU WORM!"
XWindows Updatewindows.exe"Added by the RBOT-RB WORM!"
Xwindows updatewuaurlt.exe"Added by the RBOT.ADG WORM!"
XWindows UpdateUpdate.exe"Added by the DELF-FN TROJAN!"
XWindows Updatewinmguard.exe"Added by the RBOT-EM WORM!"
XWindows Updatewuampd.exe"Added by the RBOT.UM WORM!"
Xwindows updatewuarclt.exe"Added by the RBOT-OF WORM!"
XWindows Updatewinupdate.exe"Added by the SDBOT-WS WORM!"
XWindows Updatemsnwinsb.exe"Added by the RBOT-AAH WORM!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
Xwindows updateMicrosoft.exe"Added by the LMIR.A TROJAN!"
XWindows Updatemplupdate.exe"Added by the MOEGA WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows Updatetaskmr.exe"Added by the MYTOB-GZ WORM!"
XWindows Updateupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Updatewininfo.exe"Added by the MYTOB.GA WORM!"
XWindows Updatewinlogin.exe"Added by the BANKER-DV TROJAN!"
XWindows Updatemsnupdates.exe"Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
XWindows Updateqtask.exe"Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here"
Xwindows updatereal.exe"Added by the LEGMIR-AU WORM!"
XWindows Updatewindowsx.exe"Added by the BANCD-A TROJAN!"
XWindows updatewudupdate.exe"ISTBar adware related"
XWindows Updatewupdmgr.exe"Added by the BANCBAN-FC TROJAN and variants!"
XWindows Updatecsrss.exe"Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows UpdateXPLoogNT.exe"Added by the BANCD-B TROJAN!"
XWindows Updateinstall.exe"Added by the BANKER-IB TROJAN!"
XWindows Updatemsi.exe"Added by the BANKER-XB TROJAN!"
XWindows UpdateSqltob.exe"Added by the DASHER.A WORM!"
Xwindows updatelogonuit.exe"Added by the LEGMIR-AO TROJAN!"
XWindows Updateavkir.exe"Added by the RBOT-GJP WORM!"
XWindows Updateeasypwnt.exe"Added by a variant of the SDBOT WORM!"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows UpdateSecretStub.exe"Added by the SRAMLER.C WORM!"
XWindows UpdateWinload.exe"Added by the DEDMIR-A WORM!"
XWindows Updatetaskngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows Updatelivesrvs.exe"Added by a variant of the RBOT WORM!"
XWindows UpdateMcAfee.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
XWindows UpdateMcAfee3.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatescrigz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updatewinsc.exe"Added by the BUZUS.RYI TROJAN!"
XWindows Updatewuauclt32.exe"Added by the SDBOT.DHY WORM!"
XWindows Updatedllhostup.exe"Added by the BANCBAN-NB TROJAN!"
XWindows Updateexplored.exe"Added by the GAOBOT.MF WORM!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows Updatesysdrv.exe"Added by the AGENT-IYE TROJAN!"
XWindows Updatewinupupdate1.exe"Added by the RBOT-UV WORM!"
XWindows Updateklass.exe"Added by the BIFROSE-ZH TROJAN!"
XWindows UpdatewinlogonEvt.exe"Added by the VB-DXM TROJAN!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
XWindows Updatefdos.exe"Added by the RBOT-COG WORM!"
XWindows Updateleak32x.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows updatemsb32.exe"Added by the GAOBOT.CG WORM!"
XWindows updatesvdhost.exe"Added by the GAOBOT.CG WORM!"
XWindows Updatetskmngr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows Updatewindb32.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update 32winlogons.exe"Added by the FORBOT-FI WORM!"
XWindows Update 32rempss.exe"Added by the FORBOT-FW WORM!"
XWindows Update 32slsys.exe"Added by the FORBOT-FT WORM!"
XWindows update 32bitwinupd32.exe"Added by the SDBOT.BE WORM!"
XWindows Update 63shupd64.exe"Added by the FORBOT-GA WORM!"
XWindows Update 64nbupd64.exe"Added by a variant of the FORBOT WORM!"
XWindows Update 64WinV.exe"Added by the FORBOT-FP WORM!"
XWindows Update Auto Updatewuaumgr.exe"Added by a variant of the SPYBOT WORM!"
XWindows Update Automatic Updates[path to backdoor]"Added by the VBBOT.AM BACKDOOR!"
XWindows Update Automationwinuptdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwaucult.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwuauclt.exe"Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process
XWindows Update AutoUpdate Client Productwuauct.exe"Added by the AGOBOT.ACL WORM!"
XWindows Update Centersvthx.exe"Added by the STUBBOT.A WORM!"
XWindows Update CenterW32RSA.exeAdded by an unidentified WORM or TROJAN!
XWindows Update Checksyslodr.exe"Added by the SMALL.LU TROJAN!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update Checkermsupdte32.exe"Added by the SDBOT-AEF WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Clientwuclient.exe"Added by the SMALL-RN TROJAN!"
XWindows Update Client Servicewindrvl32.exe"Added by the AGOBOT-MM TROJAN!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows Update Dravendraven.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Driveupdrvs.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Filesdnetc.exe"Added by an unidentified VIRUS
XWindows Update Firewall Systemctfmoom.exe"Added by the RBOT-GAN WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Update Firewall Systemctfmom.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Update GUI Executable x32xwupdategux32.exe"Added by the RBOT.CXY WORM!"
XWindows Update Hostwinupsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Update IPv6 LayerWIN32IPV6.EXE"Added by the RBOT.DUD WORM!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Managerwupdmngr.exe"Added by the RANDEX.BTB WORM!"
XWindows Update ManagerWinlog0n.exe"Added by the AGENT-BO TROJAN!"
XWindows Update Managerwupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update Managerbootwiz.exeAdded by the MYBOT WORM!
XWindows Update ManagerWindowsUpdateManager.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Update Manager for NTwupdmgr32.exe"Added by the SDBOT.AH WORM!"
Xwindows update microsoftupdatem.exe"Added by the RBOT-CHE WORM!"
XWindows Update Monitoring Servicewinupdt.exe"Added by the RBOT-PL WORM!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Serviceupdate32.pif"Added by the RBOT-ALC WORM!"
XWindows Update Servicetrest.exeIdentified by BitDefender as a variant of the PEED TROJAN!
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Update Softwaresystem.exe"TOFGER.BX spyware"
XWindows Update SP3Windat.EXE"Added by the RBOT-GTS WORM!"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindows Update.exeN/AHomepage hijacker
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Updatedupdatr.exe"Added by the RBOT-AYB WORM!"
XWindows Updaterwupdmgr32.exe"Added by a variant of the DOS.AUTOCAT TROJAN!"
XWindows Updateriexplorerrs.exe"Added by the RBOT-TN WORM!"
XWindows Updatersvigost.exe"Added by the RBOT-VS WORM!"
XWindows Updaterwupdate.exe"Added by the WOOTBOT.AJ WORM!"
XWindows Updatersdsys.exe"Added by the FORBOT-JG WORM!"
XWindows Updater Onlinewinupdatexx.exe"Added by a variant of the RBOT WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows Updater Service Managerwinupdatr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
Xwindows updaterswinupdats.exe"Added by the SPYBOT-IS WORM!"
XWindows Updateslsassx.exe"Added by a variant of the SDBOT WORM!"
XWindows Updateswinupd32.exe"Added by the MYTOB.CE WORM!"
XWindows Updatesw32dns.exe"Added by the SDBOT-BFW WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.