{"id":31386,"date":"2022-12-30T09:30:20","date_gmt":"2022-12-30T04:00:20","guid":{"rendered":"http:\/\/198.58.113.91\/blog\/?p=31386"},"modified":"2023-08-27T15:55:01","modified_gmt":"2023-08-27T10:25:01","slug":"windows-update-services-deleted-every-restart","status":"publish","type":"post","link":"https:\/\/www.winhelponline.com\/blog\/windows-update-services-deleted-every-restart\/","title":{"rendered":"Windows Update services are deleted at every restart"},"content":{"rendered":"<p>After you restore the missing Windows Update, BITS, or the Update Orchestrator Service services using registry files, you find that the services vanish again after a restart. They don&#8217;t appear in the Services MMC.<!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8498\" src=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/04\/windows-update-service-missing.png\" alt=\"windows update service missing in the list\" width=\"662\" height=\"80\" \/><\/p>\n<h2>Cause<\/h2>\n<p>This issue happens if your computer is <strong>infected<\/strong>. Malware running as a service or scheduled task is deleting the Windows Update (&#8220;wuauserv&#8221;), Background Intelligent Transfer Service (&#8220;BITS&#8221;), Update Orchestrator Service (&#8220;UsoSvc&#8221;), Delivery Optimization (&#8220;DoSvc&#8221;), and the Windows Update Medic Service (WaasMedicSvc) services at <strong>every restart<\/strong>.<\/p>\n<p>For example, a trojan named <a href=\"http:\/\/web.archive.org\/web\/20221226140906\/https:\/\/vms.drweb.cn\/virus\/?i=25402209\" target=\"_blank\" rel=\"noopener\">trojan.Siggen18.38683<\/a>, which runs as a scheduled task, deletes all the Windows Update-related services at every startup. This is just an example. There may be similar trojans that do this.<\/p>\n<div id=\"toc\">\n<li><a href=\"#one\">Step 1: Run a Malwarebytes scan<\/a><\/li>\n<li><a href=\"#two\">Step 2: Remove rogue Scheduled Tasks and Services Using Autoruns<\/a><\/li>\n<li><a href=\"#three\">Step 3: Reset Windows Security &#8220;Exclusions&#8221;<\/a><\/li>\n<li><a href=\"#four\">Step 4: Restore the missing Windows Update Services<\/a><\/li>\n<\/div>\n<h2>How to Resolve the Problem<\/h2>\n<h3><a id=\"one\"><\/a>Step 1: Run a Malwarebytes scan<\/h3>\n<p>Download Malwarebytes (<code>https:\/\/www.malwarebytes.com\/<\/code>) , update the definitions, and run a full scan.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-31389\" src=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/malwarebytes-scan-dashboard.png\" alt=\"malwarebytes scanner dashboard\" width=\"890\" height=\"645\" srcset=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/malwarebytes-scan-dashboard.png 890w, https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/malwarebytes-scan-dashboard-768x557.png 768w\" sizes=\"auto, (max-width: 890px) 100vw, 890px\" \/><\/p>\n<p><em><strong>Editor&#8217;s note:<\/strong> In a recent case, the trojan &#8220;Trojan.Siggen18.38683&#8221; seems to have somehow <strong>evaded<\/strong> the detection engines of Malwarebytes and Microsoft Defender Antivirus, even though <a href=\"https:\/\/www.virustotal.com\/gui\/file\/7330c3326d27f9cef7e9e11850fdb5f84ffcc1b9ddbf5bcc4456eaf4b397ac39\" target=\"_blank\" rel=\"noopener\">41 Antivirus vendors<\/a> (including Malwarebytes and Microsoft) flagged it as malicious. You can read about it in this <a href=\"https:\/\/answers.microsoft.com\/en-us\/windows\/forum\/windows_11-wintop_update\/i-cant-update-my-windows-11-when-i-go-to-the\/41383308-8a92-4555-bdfb-ba14806408b0\" target=\"_blank\" rel=\"noopener\">Microsoft Answers thread<\/a>.<\/em><\/p>\n<hr>\n<h3><a id=\"two\"><\/a>Step 2: Remove rogue Scheduled Tasks and Services Using Autoruns<\/h3>\n<p>After eliminating malware from the computer, download the <a href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/autoruns\" target=\"_blank\" rel=\"noopener\">Autoruns<\/a> utility from Microsoft, and run the program as administrator.<\/p>\n<p>Inspect the Autoruns output thoroughly. In a recent case, we found that the trojan created a fake scheduled task named &#8220;<code>GoogleUpdateTaskMachineGNC<\/code>&#8221; or &#8220;<code>UpdateTaskMachineQC<\/code>&#8221; that ran one of the following files at every startup.<\/p>\n<pre class=\"err\">C:\\Program Files\\Google\\Chrome\\updater.exe<\/pre>\n<pre class=\"err\">%ProgramFiles%\\Google\\Chrome\\updaterchr.exe<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-31388\" src=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/wu-services-deleted-1.png\" alt=\"windows update, bits, usosvc deleted at restart\" width=\"896\" height=\"436\" srcset=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/wu-services-deleted-1.png 896w, https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/wu-services-deleted-1-768x374.png 768w\" sizes=\"auto, (max-width: 896px) 100vw, 896px\" \/><\/p>\n<p>It&#8217;s an unsigned\/unverified file. Always be suspicious of the &#8220;(Not Verified)&#8221; entries in Autoruns; Autoruns highlights unverified items in pink. However, it <strong>doesn&#8217;t<\/strong> mean that the verified entries don&#8217;t require scrutiny. Every entry needs to be checked.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-31387\" src=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/wu-services-deleted-2.png\" alt=\"windows update, bits, usosvc deleted at restart\" width=\"331\" height=\"101\" \/><\/p>\n<div class=\"qt\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-6338 alignleft\" src=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2018\/07\/icotip.gif\" alt=\"tips bulb icon\" width=\"34\" height=\"34\" \/>When in doubt, upload the module to VirusTotal to see if it&#8217;s malware. Or use Autoruns&#8217;s built-in option to upload the file hash to VirusTotal. Select the suspicious item in the list, click the &#8220;Entry&#8221; menu, and click &#8220;Check VirusTotal.&#8221; [Ref: <a href=\"https:\/\/www.microsoftpressstore.com\/articles\/article.aspx?p=2762082\" target=\"_blank\" rel=\"noopener\">Autoruns | Microsoft Press Store<\/a>]<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-31391\" src=\"https:\/\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/12\/autoruns-check-virustotal.png\" alt=\"autoruns check virus total\" width=\"397\" height=\"294\" \/><\/p>\n<\/div>\n<p>Note that the file <code>updaterchr.exe<\/code> is malware. It hides inside the &#8220;Google\\Chrome&#8221; directory to confuse the user.<\/p>\n<p>After searching the web for the file name and task name, I came across the <a href=\"http:\/\/web.archive.org\/web\/20221226140906\/https:\/\/vms.drweb.cn\/virus\/?i=25402209\">Dr.Web article<\/a>. As you can see, the trojan deletes all the services related to Windows Update.<\/p>\n<p>See the VirusTotal report for the file(s).<\/p>\n<ul>\n<li><a href=\"https:\/\/www.virustotal.com\/gui\/file\/7330c3326d27f9cef7e9e11850fdb5f84ffcc1b9ddbf5bcc4456eaf4b397ac39\" target=\"_blank\" rel=\"noopener\">VirusTotal &#8211; File &#8211; updaterchr.exe<\/a><\/li>\n<li><a href=\"https:\/\/www.virustotal.com\/gui\/file\/8b6cf2c8c6e3cce421e4eafd9e7f3e91b1a30dbfd6336561c36a0001749a93c2\">VirusTotal &#8211; File &#8211; Updater.exe<\/a><\/li>\n<li><a href=\"https:\/\/www.joesandbox.com\/analysis\/735874\/0\/html\" target=\"_blank\" rel=\"noopener\">Automated Malware Analysis Report &#8211; Generated by Joe Sandbox<\/a><\/li>\n<\/ul>\n<p>The trojan also disables the following Microsoft Update scheduled tasks.<\/p>\n<pre>\"\\Microsoft\\Windows\\UpdateOrchestrator\\UpdateAssistantWakeupRun\"\n\"\\Microsoft\\Windows\\WindowsUpdate\\Automatic App Update\"\n\"\\Microsoft\\Windows\\WindowsUpdate\\Scheduled Start\"\n\"\\Microsoft\\Windows\\WindowsUpdate\\sih\"\n\"\\Microsoft\\Windows\\WindowsUpdate\\sihboot\"\n\"\\Microsoft\\Windows\\UpdateOrchestrator\\UpdateAssistant\"\n\"\\Microsoft\\Windows\\UpdateOrchestrator\\UpdateAssistantCalendarRun\"<\/pre>\n<p>It deletes the following Windows Update service registry keys:<\/p>\n<pre>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UsoSvc\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WaaSMedicSvc\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bits\nHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dosvc<\/pre>\n<p>Deleting the task &#8220;GoogleUpdateTaskMachineGNC&#8221; and the rogue file resolved the problem.<\/p>\n<h4>Note: Your system may have a *different* kind of malware and in a different startup entry point (not necessarily a scheduled task). The above was provided as an example.<\/h4>\n<p><strong>Realtek Audio Updater (Fake)<\/strong><\/p>\n<p>On another system, a fake Realtek Audio Updater program (updater.exe) caused the issue. The rogue module usually exists in the following folder:<\/p>\n<pre>C:\\Program Files\\Realtek\\Realtek High Definition Audio\\Updater.exe<\/pre>\n<p>And it&#8217;s configured to run as a scheduled task with the highest privileges.<\/p>\n<pre>System32\\Tasks\\Realtek =&gt; C:\\Program Files\\Realtek\\Realtek High Definition Audio\\Updater.exe<\/pre>\n<p>At every startup, the rogue Updater.exe process <strong>deletes<\/strong> your Windows Update-related services.<\/p>\n<p><strong>Fake Driver Updater<\/strong><\/p>\n<p>In another case, a fake Driver Updater caused the issue. The rogue task deleted the WU-related services whenever it was run.<\/p>\n<pre>System32\\Tasks\\DriverSetup => C:\\Program Files\\DriverSetup\\Driver\\DriverSetup.exe<\/pre>\n<p>VirusTotal &#8211; File &#8211; <a href=\"https:\/\/www.virustotal.com\/gui\/file\/62a877046bb2d30fe41863b88e896383edd9ed72baa30e39abfb9a6168d25652\/behavior\" rel=\"noopener\" target=\"_blank\">DriverSetup.exe<\/a>.<\/p>\n<hr \/>\n<h3><a id=\"three\"><\/a>Step 3: Reset Windows Security &#8220;Exclusions&#8221;<\/h3>\n<p>The above virus creates some exclusions in Windows Security.\u00a0After cleaning up the entries, open Windows Security and remove these folders from the list of &#8220;Exclusions&#8221;:<\/p>\n<ul>\n<li>C:\\Users\\{username}<\/li>\n<li>C:\\Program Files<\/li>\n<\/ul>\n<p>To reset the exclusions en masse, see the article <a href=\"https:\/\/www.winhelponline.com\/blog\/reset-exclusions-windows-defender\/\">How to Bulk Reset Exclusions in Windows Defender<\/a>.<\/p>\n<hr \/>\n<h3><a id=\"four\"><\/a>Step 4: Restore the missing Windows Update Services<\/h3>\n<p>The last step will be to restore the missing services. After importing the registry files mentioned in the following articles, the system requires a reboot for the changes to take effect.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.winhelponline.com\/blog\/missing-windows-update-wuauserv-service-windows-10-11\/\">Restore the missing Windows Update (wuauserv) Service<\/a><\/li>\n<li><a href=\"https:\/\/www.winhelponline.com\/blog\/restore-bits-service-windows\/\">Restore the missing BITS Service<\/a><\/li>\n<li><a href=\"https:\/\/www.winhelponline.com\/blog\/windows-update-something-went-wrong-reopen-settings\/\">Restore the missing &#8220;Update Orchestrator Service&#8221;<\/a><\/li>\n<li><a href=\"https:\/\/www.winhelponline.com\/blog\/restore-missing-delivery-optimization-service-dosvc\/\">Restore Missing Delivery Optimization Service (DoSvc)<\/a><\/li>\n<\/ul>\n<p>It&#8217;s crucial to eliminate the viruses from the computer before recreating the Windows Update\/BITS\/UsoSvc\/DoSvc\/WaasMedicSvc service registry keys.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After you restore the missing Windows Update, BITS, or the Update Orchestrator Service services using registry files, you find that the services vanish again after a restart. They don&#8217;t appear in the Services MMC.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[7],"tags":[56,303,688],"class_list":["post-31386","post","type-post","status-publish","format-standard","hentry","category-windows","tag-autoruns","tag-malwarebytes","tag-windows-update"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":28719,"url":"https:\/\/www.winhelponline.com\/blog\/windows-update-something-went-wrong-reopen-settings\/","url_meta":{"origin":31386,"position":0},"title":"Windows Update Something went wrong, Try to reopen Settings Later","author":"Ramesh","date":"September 26, 2022","format":false,"excerpt":"When you launch Settings and click Windows Update, the Windows Update page may show the following error: Something went wrong. Try to reopen Settings Later Cause This happens if the Update Orchestrator Service (\"UsoSvc\") is disabled or missing. This service manages Windows Updates. If stopped, your devices will not be\u2026","rel":"","context":"In &quot;Windows 10&quot;","block_context":{"text":"Windows 10","link":"https:\/\/www.winhelponline.com\/blog\/category\/microsoft\/windows\/windows-10\/"},"img":{"alt_text":"windows update something went wrong","src":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/09\/wu-something-went-wrong.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/09\/wu-something-went-wrong.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/09\/wu-something-went-wrong.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2022\/09\/wu-something-went-wrong.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":26766,"url":"https:\/\/www.winhelponline.com\/blog\/missing-windows-update-wuauserv-service-windows-10-11\/","url_meta":{"origin":31386,"position":1},"title":"Restore Missing Windows Update (wuauserv) Service in Windows 10\/11","author":"Ramesh","date":"June 14, 2022","format":false,"excerpt":"The Windows Update service (wuauserv) enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows\u2026","rel":"","context":"In &quot;Windows 10&quot;","block_context":{"text":"Windows 10","link":"https:\/\/www.winhelponline.com\/blog\/category\/microsoft\/windows\/windows-10\/"},"img":{"alt_text":"windows update service missing in the list","src":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/04\/windows-update-service-missing.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/04\/windows-update-service-missing.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/04\/windows-update-service-missing.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":31401,"url":"https:\/\/www.winhelponline.com\/blog\/restore-missing-delivery-optimization-service-dosvc\/","url_meta":{"origin":31386,"position":2},"title":"Restore Missing Delivery Optimization Service (DoSvc)","author":"Ramesh","date":"December 30, 2022","format":false,"excerpt":"If the Delivery Optimization Service (DoSvc) is missing in the Services MMC console in Windows 10\/11, use the registry fix in this article to restore it. Restore Missing DoSvc Service Download dosvc_service.zip and extract the contents to a folder. Double-click the registry file applicable to your OS (Windows 10 or\u2026","rel":"","context":"In &quot;Windows 10&quot;","block_context":{"text":"Windows 10","link":"https:\/\/www.winhelponline.com\/blog\/category\/microsoft\/windows\/windows-10\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":5911,"url":"https:\/\/www.winhelponline.com\/blog\/fix-windows-update-errors\/","url_meta":{"origin":31386,"position":3},"title":"Fix Windows Update Issues in Windows 10 and 11","author":"Ramesh","date":"November 2, 2017","format":false,"excerpt":"Sometimes, you may encounter errors such as 0x80244007, 0x8024a105 or other errors when installing updates via the Windows Update channel. Here are some sample error messages: There were problems downloading some updates, but we'll try again later. If you keep seeing this, try searching the web or contacting support for\u2026","rel":"","context":"In &quot;Windows&quot;","block_context":{"text":"Windows","link":"https:\/\/www.winhelponline.com\/blog\/category\/microsoft\/windows\/"},"img":{"alt_text":"windows update error 80248007","src":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2017\/11\/wu-80248007.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2017\/11\/wu-80248007.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2017\/11\/wu-80248007.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2017\/11\/wu-80248007.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":26763,"url":"https:\/\/www.winhelponline.com\/blog\/restore-bits-service-windows\/","url_meta":{"origin":31386,"position":4},"title":"Restore Missing BITS Service in Windows 10\/11","author":"Ramesh","date":"June 14, 2022","format":false,"excerpt":"The Background Intelligent Transfer Service (BITS) service transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update, will be unable to automatically download programs and other information. If the BITS service is missing in the\u2026","rel":"","context":"In &quot;Windows 10&quot;","block_context":{"text":"Windows 10","link":"https:\/\/www.winhelponline.com\/blog\/category\/microsoft\/windows\/windows-10\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":76737,"url":"https:\/\/www.winhelponline.com\/blog\/windows-update-service-keeps-disabled\/","url_meta":{"origin":31386,"position":5},"title":"Fix: Windows Update service keeps getting disabled","author":"Ramesh","date":"October 13, 2024","format":false,"excerpt":"When you enable and start the Windows Update and BITS services, they may get disabled automatically after a few seconds. A background service may be disabling Windows Update and related services, such as BITS, Delivery Optimization, WaasMedicSvc, etc. Resolution To verify if a third-party service is turning off the Windows\u2026","rel":"","context":"In &quot;Windows 10&quot;","block_context":{"text":"Windows 10","link":"https:\/\/www.winhelponline.com\/blog\/category\/microsoft\/windows\/windows-10\/"},"img":{"alt_text":"disable non microsoft services in msconfig","src":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/07\/msconfig-disable-non-microsoft-services.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/07\/msconfig-disable-non-microsoft-services.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/www.winhelponline.com\/blog\/wp-content\/uploads\/2019\/07\/msconfig-disable-non-microsoft-services.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/posts\/31386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/comments?post=31386"}],"version-history":[{"count":0,"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/posts\/31386\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/media?parent=31386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/categories?post=31386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.winhelponline.com\/blog\/wp-json\/wp\/v2\/tags?post=31386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}