CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Malwarebytes Anti-Malware RebootUmbam.exe Malwarebytes'_Anti-Malware - "Malwarebytes’ Anti-Malware monitors every process and actually stops malicious processes before they even start. It uses our impressive technology that is in fact a completely novel way of heuristic scanning and it is our response to the increasingly complex malware threats." Note: Located in \%Program Files%\Malwarebytes' Anti-Malware\
    Microsoft UpdateXwinupdater.exeAdded by the RBOT.BIN WORM!
    Microsoft Windows XP Configuration LoaderXm32svco.exeAdded by the http://vil.nai.com/vil/content/v_132310.htm" target= blank>SDBOT.WORM!.48548 WORM!
    Media PlayerXSysdll.exeAdded by the TROJ/BANKER-BR TROJAN!
    Mioft Wiws Seice entXeuxabnuqfn.exeAdded by the WORM! Note: Located in \%WINDIR%\System32\ Note: Uses a Random filename.
    Microsoft ServicesXlssrv.exe WORM_RBOT.CW
    mailman.exeXmailman.exeAdded by the CERTIF-E TROJAN!
    msvccc66Xdload.exeAdded by a variant of the W32/Rbot-GLS family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    mnpolXmnpol.exeAdded by the DOWNLOADER.DLUCA.B TROJAN!
    Msgsrv16XMsgsrv16.exeAdded by the DELF family of VIRUSES!
    msservXmsserv.exeAdded by the Troj/Blacklog-A TROJAN! Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Miosf UpdateXwimsqaad.exeAdded by the BACKDOOR.SDBOT.AG WORM!
    Ms**32.exe (* = random char)XMs**32.exe (* =,random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Microsoft Update MachineXwupdt32x.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft messenger sdXmsngersd.exeAdded by an unidentified TROJAN! Note: Located in \%WINDIR%\System32\
    Msn Configuration LoaderXmsngms.exeAdded by the W32.KELVIR.T WORM!
    Messenger Sharing ControlXmnwsvc.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MozilaXmozila.exe W32/Delbot-AJ Read the link, allows remote access
    Microsoft DLL ServiceXsvcdll.exeAdded by the BKDR_AGENT.EAK Note: Located in \%WINDIR%\System32\
    Microsoft Memory Flow CycleXflowcycles.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft ExplorerXsvapache.exeAdded by the W32/RBOT-VR WORM!
    MSMSGSXwinlogon.exeAdded by the W32.Rahiwi.A WORM! - NOTE - this file is placed in the Application Data folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    MioSyncUmioSync.exeRelated to Mio_GPS navigation devices. Note: Located in \%Program Files%\Mio Technology\MioSync\
    MSNXmsn16.exeAdded by the W32/Sdbot-VN WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Update 64 BITXwininit32.exeAdded by the W32/RBOT-AHE or W32/RBOT-ATO or W32/Rbot-AST WORM!
    main_moduleXdrvmmx32.exeAdded by the Win32.Dila downloader TROJAN!
    Microsoft ServiceXmicrohost.exeAdded by a W32/Rbot-LC worm infection
    Microsoft UpdateXwserv32.exeAdded by the RBOT.AF WORM!
    MS Config LoaderXsvcrhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update USB2Xwuammgrd32.exeAdded by the W32/Rbot-ADT Worm!
    Machine Debug ManagerXmsdn.exeAdded by a variant of the WIN32.RBOT WORM!
    mscheckXwincheck071008.dllAdded by a variant of the Trojan-Spy.Win32.Agent.adq Malware! Note: Located in \%WINDIR%\System32\
    Microsoft Update ProcessXwmipcvse.exeAdded by the TROJ/AGOBOT-JF TROJAN!
    msoffwzXmsoffwz.EXEAdded by the Troj/Bancban-HQ TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Lmhosting ServiceXlmhosts.exeAdded by the W32/RBOT-RC WORM!
    MSService_v1.0Xrealsched.exe EHU_Installer
    MSN serviceXmsnmgr16.exeAdded by a variant of the WIN32.RBOT WORM!
    MemScannerNMemScanner.exeSpyHunter - spyware remover of somewhat dubious repute; see note
    Mcafee Auto ProtectXmcafeshield.exeAdded by the W32/RBOT-UH WORM!
    Microsoft (R) Windows TCP/IP Socket DriverXcsrss.exeAdded by the Troj/Proxy-DD TROJAN! This worm\trojan is located in C:\Windows\winsock\ (Win9x/Me), C:\%WINDIR%\winsock\ (XP/WinNT/2K)
    Microsoft Winsock WrapperXws2_32s.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft WPCEmailXsvchost.exeAdded by the Troj/Sniffer-N Note: This worm\trojan is located in C:\Windows\ (Win9x/Me), C:\%WINDIR%\ (XP/WinNT/2K) Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    MSN Messenger Live LoginXmsnmessengerlive.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft DLLSet32Xdllset32.exeAdded by the RBOT.OZ WORM!
    Microsoft Messenger XPXMSMSN32.exeAdded by the W32/RBOT-ZP WORM!
    Microsoft Windows SystemXsrwhost.exeAdded by a variant of the W32/Rbot-ASW worm! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft xpsp2Xxpsp2.exeAdded by the W32/Sdbot-YQ Worm!
    Microsoft Setup InitializazionXlocalhost.exeA variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    main16Xmain16.exeAdded by a CRYPTER.A trojan infection
    msiexecs.exeXmsiexecs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ more here
    My Essentials Wireless USB UtilityUO-Maxwcui.exeRelated to My_Essentials_Wireless_USB Utility from Belkin International, Inc. Note: Located in \%Program Files%\My Essentials\USB ME1001-USB\Wireless Utility\
    microsoftm eegs cuntrolXloor.pifAdded by a variant of the WIN32.RBOT WORM!
    Microsoftf DDEs ContrDLXrunm.pifAdded by the W32/Rbot-AFQ Worm!
    MicrosoftXWinSecUp.exe W32/Rbot-GPL Read the link, allows remote access
    Matrox PowerdeskNPDesk.exeFor Matrox video cards. Quick access to tweak your card to your liking

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer