CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Microsoft UpdateXwserv32.exeAdded by the RBOT.AF WORM!
    Microsoft Config 32bitXmscnfg32.exeAdded by the W32/RBOT-Z WORM!
    MoneyStartUp10.0NActivation.exePart of MS Money 2002. Available via Start -> Programs
    Microsoft Spool 25 ServiceXspool25.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MsVBdllXMsVBdll.pifAdded by the W32.Aimdes.A WORM!
    MPFExeXmcagent.exeAdded by the TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
    msrunocx32Xmsrunocx32.exeAdded by the SKUS VIRUS!
    MSN Messenger 32Xmsniu.exeAdded by the W32/Rbot-AWB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft UpdatesXsvdhost.exeAdded by the W32/Rbot-GVH WORM! Read the link, allows remote access Note: Located in \%WINDIR%\System32\
    Mcafee Auto ProtectXmcafeshield.exeAdded by the W32/RBOT-UH WORM!
    mousebutXmousebut.exeAdded by a CRYPTER.A trojan infection
    Microsoft Manage ServicesXsychost.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Internet SyncingXinetsync.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    m4n70s Personal FirewallXm4n70s.exeAdded by a variant of the W32.SPYBOT WORM!
    MsWinVgrXmsvgr.exeAdded by the W32.Mytob.LE WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    mspwrUpupxpman.exeRelated to Ashampoo's PowerUp XP
    MSN ManagerXusnmsn.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft WinRaRXwinrar.exeAdded by the W32/Rbot-AEC Worm!
    MonitorSDUSDMonitor.exeSpyware Detector, Adware/Spyware remover - initially considerered a "rogue" program. The latest version has since apparently mended its ways: see note
    Microsoft NT DriversXntdrv.exeAdded by the Backdoor.SdBot.ajn reported by ewido, TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft ServiceXmicrohost.exeAdded by a W32/Rbot-LC worm infection
    msdir32Xmsdir32.bat VBS/Rookie-A
    Microsoft msnseruXmsnseru.exeAdded by the W32/Rbot-APB WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Win Corp TLS VerificationXmswintls.exeAdded by the W32/Rbot-GCT WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) The hosts file may be modified.
    Media ServerXmsdts.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MPatrolPROXMPatrolPRO.exeAdded by the Malware_Patrol_Pro a rogue anti-spyware program. Note: Located in \%Program Files%\MPatrolPRO\ Note: Use Malwarebytes RogueRemover tool.
    MagicLinker3UMagicLnk.exe ThaiSoftware Thai Dictionary
    Msn PatchXmsndp.exeAdded by the RBOT.AAI WORM!
    MGA QuickdeskNMGAQDESK.EXEFor Matrox video cards. Quick access to tweak your card to your liking
    Microsoft Cab ManagerXexec.exe Affilred.B adware
    mppdsXmppds.exeAdded by the TSPY_LEGMIR.AQZ TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ steals information, typically account names and passwords, related to certain online games.
    MusIRCXmusirc4.71.exeAdded by the RANDEX.Q WORM!
    Microsoft Update 32Xmscnfg.exeAdded by the W32/Rbot-ALM WORM!
    MotMonUmotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required
    Macfee Security PatchXMpfsheild.exeAdded by the W32/RBOT-NP WORM!
    McAfee Online virus ScannerXavp.exeAdded by the RBOT-GCV WORM! Not to be confused with AOL's Active Virus Shield (by Kaspersky)
    Microsoft IPCXsvshost.exeAdded by an unidentified VIRUS!
    Microsoft Dll ManagementXwindll.exeAdded by the W32/RBOT-MT WORM!
    Microsoft DllXrunapidll.exeAdded by the W32/Rbot-GRG Worm Read the link, allows remote access
    Microsoft Update MachineXlsasse.exeAdded by the W32/RBOT-DI WORM!
    msdefender.exeXmsdefender.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    ModeminfXModeminf.exeAdded by a CRYPTER.C trojan variant infection
    Micrsoft CFG 32Xlrbzus32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    MSSHVCXMSSHVC.exeAdded by the NUFFY.A VIRUS!
    Microsoft Windows UpdateXspools.exe WORM_SDBOT.TD
    Microsoft Windows UpdaterXTMNTSrv.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update 33Xinit.exeAdded by W32/Rbot-ATT WORM!
    MscntXmscnt.exeAdded by the Troj/Dluca-C TROJAN!
    Microsoft UpdateXwuamgrd3.exeAdded by the W32/Rbot-AMC WORM!
    Microsoft Update 32Xneta.exeAdded by the W32/Rbot-AMI WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MSupdater.exeXN/A CoolWebSearch parasite related.
    Microsoft Update MachineXmemstat.exeAdded by the W32/RBOT-OM WORM!
    Microsoft Windows XP Configuration LoaderXm32svco.exeAdded by the http://vil.nai.com/vil/content/v_132310.htm" target= blank>SDBOT.WORM!.48548 WORM!
    Music01 ServerNMusic01,Server.exeJ River Media Jukebox
    msmcX ms****.exe (*,= random char) ClientMan parasite variant

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer