CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    WindowsRegKey updateX[random or,different file,name]Added by the RBOT.QT WORM!
    Windows System ConfigurationXwincfg.exeAdded by the AGOBOT.OP WORM!
    Win32SystemXwin32s.exeAdded by the W32.Mydoom.V WORM!
    Windows Service Pack Auto UpdateXfiggaz.exeAdded by a TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.bt
    Windows Logon ProcedureXSvchosta.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows LoL LayerXwinlolx.exe W32/Rbot-FOR Read the link, allows remote access
    WinStartXservices.exeAdded by the W32.SOBER.O WORM! - Note - this file is placed in a "%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    WIN32XWIN32.EXEAdded by the WIN32/MYTOB.AD WORM!
    Win32 Word ServicesXmsword32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows EssensialsXmvnesc.exeA variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows svchostXups.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Windows DLL HostXdllhost32.exeAdded by an unidentified WORM or TROJAN!
    Windows TMXSVPHOST.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows SpoolPrint ServiceXspoolersrv.exeAdded by the W32/Sdbot-ZT WORM!
    WindowsRegKey updateX16winupdate32.exeAdded by a variant of the WIN32.RBOT WORM!
    winxpdll32.exeXwinxpdll32.exeAdded by a variant of the Win32.SMALL downloader TROJAN!
    W32.ScranXScran.exeAdded by the W32.Narcs WORM!
    WindowsServiceX(random,name).dll Troj/Vundo-X Read the link, steals information
    wait4IPUwait4IP.exePackard Bell net2Plug allows you to network PCs anywhere in your house
    winltmpvXwinln.exeAdded by the TCXMEDI-C TROJAN!
    WIN32SNDSXbanc.exeAdded by an unidentified WORM or TROJAN!
    Windows UpdateXusnsvc.exeAdded by the W32/Kobot-C WORM! Note: Located in \%Program Files%\Common Files\System\ Read the link, allows remote access Note: Use SDFix under supervision.
    Windows DebuggerXwindbg.exeAdded by an unknown worm or trojan infection!
    Wireless-G Notebook AdapterYGcc.exeLinkSys Wireless-G Notebook Adapter diver
    Win32 USB2 DriverXmsn.exeAdded by the W32/FORBOT-EX WORM!
    Windows NetDDeXwrmana32.exeAdded by the W32.Mytob.IM WORM!
    Windows Service AgentXmssngear.exeAdded by a variant of the RBOT family of IRC Backdoor trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows UpdateXmsi.exeAdded by the Troj/Banker-XB TROJAN!
    WinCheckXWinCheck.exeAdded by the PWS-CY VIRUS!
    win msdt serviceXmswindtc.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Media Player 3.6Xwmpa36.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows UDP Control CenterXmsnpd.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows Update 63Xshupd64.exeAdded by the W32/Forbot-GA WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WIN32DSXclienttimer.exeAdded by Eziin adware
    Windows Data ServerXautodisc.exeAdded by the W32/SPYBOT-CB WORM!
    Windows Registry StartupXwind32.exeAdded by the W32/Agobot-BZ WORM!
    Win386Xsp32.dllHomepage hijacker. Not a dll but a regfile in disguise
    Windows CPU hostXwinbog32.exeAdded by a variant of the WIN32.RBOT WORM!
    WXProcMgr ModuleNWXprocMgr.exeTVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system
    Windows Security Center Notification ApplseXsxes.exe W32/Rbot-GLR Read the link, allows remote access
    Windows Serviece AgentsXkgsxwhl.exeAdded by a variant of the Worm.Rbot.ABFK Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. The filename is random
    Windows System ManagerXsmsc.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Logon ProcedureXSvchoste.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows FAT 32XWINFAT32B.exeAdded by the W32/SPYBOT-AGT WORM!
    Windows Spoolsrv ServiceXspoolmsv.exeAdded by the W32/Sdbot-ZS WORM!
    Windows SubsysXwinload.exeAdded by the NETSPREE.C WORM!
    Win32 Usb DriverXAvpG.exeAdded by the W32/FORBOT-BX WORM!
    www.symantec.comXoz11111.exeAdded by the W32.Mydoom.W WORM!
    WaveTop Upload ManagerNN/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
    WinDrg32Xwindrg32.exeAdded by the DRUDGEBOT.A WORM!
    Windows Browser ServicesXBrowsr32.exeAdded by a A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    winupdate.exeXwinupdate.exeAdded by the RADO VIRUS!
    Windows UpdateXwininfo.exeAdded by the W32.Mytob.GA WORM!
    Win32 FRT DriverXmsfr32.exeAdded by a variant of the W32/FORBOT WORM!
    Windows Secure Messaging SystemXmsnmsgrsrvc.exeAdded by the W32/RBOT-RE WORM!

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer