CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    00DSKSVR00Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00DSKSVR01Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00ERSRRRNKYUeraser.exeRelated to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here
    00ERSRRRNKYUerasrv.exeRelated to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here
    00PCTFWYFirewallGUI.exeRelated to PC_Tools Firewall. Note: Located in \%Program Files%\PC Tools Firewall Plus\
    00TCrdMainYTCrdMain.exeRelated to flash_card slot on the Toshiba laptop. Ending this process will disable access to the flash cards. Note: located in %ProgramFiles%\TOSHIBA\FlashCards\
    00THotkeyU00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    00THotkeyUsystem32THotkey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    0190 WarnerUWARN0190.EXEAnti-dialer program (Germany)
    0900 WarnerUWARN0900.EXEAnti-dialer program (Germany)
    09734482329566253820889118044258Xav2009.exeAdded by the Antivirus_2009 rogue anti-spyware program. Note: Located in \%Program Files%\Antivirus 2009\
    0mcamcapX0mcamcap.exeAdded by Troj/Cosiam-H TROJAN! Prevx identifies it has Haxdoor Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    0utlook ExpressX*****.exe (where * = random char)Added by the W32/RBOT-CC WORM!
    1X1.exeAdded by the ESTEEMS TROJAN!
    1Xsvchost.scrAdded by PWSteal.Bancos.X Trojan. Read the link, keylogger/password stealing TROJAN(S) involved.
    1X lsass.scrAdded by the PWSteal.Bancos.V TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    1Xmrcmgr.exeIdentified as a variant of the Trojan-Banker.Win32.Banker.rqk malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    1&1 EasyLoginUEasyLogin.exeRelated to 1&1_EasyLogin an Internet Provider. Note: Located in \%Program Files%\1&1\1&1 EasyLogin\
    101ClipsU101Clips.exeRelated to 101Clips 101 is the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. Note: Located in \%Program Files%\101 Clips\
    1029BB4B-16A9-4E77-AA3D-96930BD68EECXsysockeu.exeAdded by the SmitFraud Trojan
    108Mbps Wireless LAN AdapteUTRENDnet.exeRelated to TRENDnet Wireless LAN Adapter. Note: Located in \%Program Files%\TRENDnet\Model number\
    11Xfaxcomdos.exeAdded by the Tuimer TROJAN!
    1111swapmgr.exeX1111swapmgr.exeAdded by the BDOOR-IC TROJAN!
    123456Xrundll32.exe shell32.dll, Control_RunDLL ...123456.cplAdded by the KITRO.C (or DANDI.A) VIRUS! 123456 can be any random 3 to 6 digit number
    1234567Xsvcost.exeAdded by the Backdoor.Bifrose.YA family of trojan. Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer