Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft Updatemsupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatemsupdate32.exe"Added by the SPYBOT.LZ WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Update 32MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMS Unix Binaryoutlookexpressupdate.exe"Added by the RBOT-YU WORM!"
XMS Updating Utilitymsupdater.exe"Added by the RBOT-XR WORM!"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMSUpdatewupd.exe"Added by the ALADINZ.M TROJAN!"
XMSUpdatesvchosthlp.exe"Added by the BLASTER.T WORM!"
Xmsupdatemsupdate.exe"Added by the RBOT-MZ WORM!"
XMSUpdatecriticalUpdate.exe"Affilred adware"
Xmsupdateupdate.exe"Added by a variant of the SDBOT WORM!"
XMsupdateexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdateoutIook.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XMSupdate.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
XMSUpdateDevKitaxfd.exe"Added by the SDBOT-ZD WORM!"
Xmsupdatermsupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XMsUpdater Systemudpsys32.exe"Added by the RBOT.AAA WORM!"
XMSupdater.exeN/A"CoolWebSearch parasite variant. Installs the Winshow.dll browser plugin"
Xmsupdater25lsasser.exe"Added by the RBOT-ATS WORM!"
Xmsupdatesmsupdt.exe"Added by the RBOT-JO WORM!"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
XNSupdateNSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
XSafeSurfingUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
XSSUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
XStart Uppingsmssupdate.exe"Added by a variant of the RBOT WORM!"
Xsupdatesupdate.exe"Added by the MALWARE.D TROJAN!"
Xsupdate2.dll"rundll32.exe supdate2.dllRun"
Xsupdate2.dllregsvr32.exe /s supdate2.dll"Added by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""supdate2.dll"" file is found in %System%"
Xsysupdatecmman32.exe"Added by a variant of the SDBOT WORM!"
XUpdatesmsupdate.exe"CoolWebSearch parasite variant"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XWebSUpdaterwupda.exe"Added by the STARTPAGE.C TROJAN!"
XWin UpdateSysUpdate.exe"Added by the AGOBOT-TN WORM!"
XWindosupdate managerrunwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows Update ManagerWindowsUpdateManager.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindowsUpdatewindows_update.exe"Added by the LOFNI WORM!"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XwindowsupdateRPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
XWindowsUpdateUSRINIT.EXE"Added by the MADDIS.B WORM!"
Xwindowsupdatewinupdate.exe"Added by the WARPI WORM!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatewinnnint.exeAdded by an unidentified WORM or TROJAN!
XWindowsUpdate[path to file]"Added by the DUPA-B TROJAN!"
XWindowsUpdatesvchostw.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdateNzil.exe"Added by the CULLER-C WORM!"
XWindowsUpdateStrad.exe"Added by the CULLER-D WORM!"
XWindowsupdateWindowsupdate.exe"Added by the BANKER.ARK TROJAN!"
XWindowsupdatewupdmgr98.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xwindowsupdateautoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
XWindowsUpdatesvdhost.exe"Added by the AGOBOT-BP WORM!"
XWindowsUpdatetwain.exe"Added by the AGENT.BEA TROJAN!"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsUpdate Servicewuautlc.exe"Added by the RBOT-NR WORM!"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWindowsUpdatecrsscrss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdateDirectdupadirect.exe"Added by the DUPA-C TROJAN!"
XWindowsUpdatelsassslsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdatem1[path to file]"Added by the AGENT-AAJ TROJAN!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdateManagerwupdmng.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindowsUpdateNTsvwhost.exe"Added by the SHELLOT-B TROJAN!"
XWindowsUpdateRregserv.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindowsUpdatev4w32gins.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
XWindowsUpdatewinsecwinsec.exe"Added by a variant of the AGENT-HZ TROJAN!"
Xwinsupdaterwinsupdater.exe"Added by the ALCRA-F WORM!"
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.