Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
NMacrovision Update Serviceissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NMacrovision Update ServiceISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update SERVICEphqghum.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Update Serviceuserx.exe"Added by the MYTOB.JF WORM!"
XMSN Update Servicemsnupdsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSecurity Update Servicewmiprvce.exe"Added by the AGOBOT.ZW WORM!"
XSecurity Update Service Processsvrhost23.exe"Added by the AGOBOT-GN WORM!"
XSvshost Update Servicesvcbind.exe"Added by the MYTOB.LH WORM!"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystem Update Servicewinupd32.exe"Added by the ADTODA-A TROJAN!"
XSystem Update Servicesystem.pif"Added by the RBOT-ALL WORM!"
XSystem Update Serviceupdate.pif"Added by the SPYBOT.WOE WORM!"
XSystem Update Servicewmiprvsv.exe"Added by the AGOBOT.YG WORM!"
XSystem Update Servicecsrss32.exe"Added by the AGOBOT-HI WORM!"
YUpdate ServiceUpdate.exe"Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
Xupdate servicesvxhost.exe"Added by the RBOT-MG WORM!"
XUpdate Servicewinu32.exe"Added by the RBOT-MG WORM!"
Xupdate servicewinx.exe"Added by a variant of the RBOT WORM!"
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Serviceupdate32.pif"Added by the RBOT-ALC WORM!"
XWindows Update Servicetrest.exeIdentified by BitDefender as a variant of the PEED TROJAN!
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindowsUpdate Servicewuautlc.exe"Added by the RBOT-NR WORM!"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWinupdate Servicewinxp.exe"Added by the SPYBOT.IR WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.