CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Registry IntegritycheckXWCPDT.EXEAdded by the W32/AGOBOT-RF WORM!
    RegistryMonitorXsysfade.exeAdded by Trojan.Sysfade Note: located in \%WINDIR%\
    RegptmensXREGPTMENS.EXEAdded by the Troj/Bancos-ED TROJAN! Read the link, keylogger/password stealing trojan(s) involved.
    RCSyncXRCSync.exePrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware
    rmoc3260.dll OCXUrmoc3260.dll rmoc3260.dll A module that contains COM components for media playback used by both RealPlayer and Windows Media Player. Note: Located in \%WINDIR%\System32\
    ryan1918Xservidevice.exeAdded by the W32/Checkout!0e4a3c52 mass-mailing worm. Note: located in \%WINDIR%\
    runwin32Xrunwin32.exe Troj/ESearch-A trojan
    Ray Process KillerNPrkill.exeRay Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL ALT DEL instead
    Regkey for autostartXwinservice.exeAdded by the W32/RBOT-NU WORM!
    Runmarc8mManagerUmarc8m95.exeMARC Sound System Manager for the Marc_8_MIDI sound card - allows for easy adjustment of the settings
    Remote Storage AccessXrmasvc.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    RavTimerXexplores.exeAdded by the Troj/Homey-A TROJAN! Note: This is not the legitimate Windows process explorer.exe (Notice the difference in the spelling.) This trojan file (explores.exe) is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RemStart?remstart.exePart of McAfee\'s Remote Desktop 32 Agent application. What does it do and is it required?
    Realtek Sound ManagerXTecompntwx.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    regsrvXregsrv.exeAdded by the OPTIXPRO.11 VIRUS!
    RealAudioXRealAudio.exeAdded by the CEEGAR TROJAN!
    RA ServerXSlave.exeAdded by the RA VIRUS!
    Remote Access AdapterXrvasvc.exeAdded by a variant of the Backdoor.Win32.IRCBot.alo family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Recommended Hotfix - {0421701D-CF13-4E70-ADF0XRH.DLLSmartPops adware
    RxMonNrxmon9x.exeDell Resolution Assistant
    retimeXretime.exeAdded by the GIPMA VIRUS!
    Rundll32 P17?Rundll32,P17.dll, P17Helper ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
    runXdec25.exeAdded by the W32.ATAK.F WORM!
    rundl332Xmath.exe,...pluged.exeAdded by the DOOMJUICE VIRUS!
    RouterXRouter.exeIdentified as a variant of the Trojan.Matcash MALWARE! Note: Located in \%Program Files%\Router\
    restoryXrestory.exeAdded by the RETSAM VIRUS!
    RavTimeXPX(worm filename)Added by the WULLIK.B VIRUS!
    Rnudll32Xtadxtr.exeAdded by the TROJ/QQPASS-O TROJAN!
    RealSPEEDURealSPEED.ExeRelated to Stay_Alive Stay connected even after a period of inactiviry on the net.
    Remote Procedure CallsXmswinc.exeAdded by the W32/RBOT-IT WORM!
    Reminder-hpcXXXXXNremind32.exeHP CD-Writer Registration
    Reminder-cpqXXXXXNremind32.exeCompaq printer Registration
    Real-TensXReal-Tens.exe DownloadWare Adware.
    Rundll32_7Xrundll32.exe,MSIEFR40.DLL, DllRunServer BrowserAid/BrowserPal Foistware
    REGIST~1UREGIST~1.EXEPart of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
    RandomWin32Xmgnwin32.exeAdded by the W32/SDBOT-DV WORM!
    reseurceX(Path to,Trojan)Added by the Troj/Lineage-AI TROJAN!
    rfagentUrfagent.exe Registry_First_Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders
    Restore OperationXsvchots.exeAdded by a variant of the Trojan-Downloader.Win32.Small.ddx family of TROJAN! Note This trojan is located in C:\%WINDIR%\TEMP\ folder.
    ReminderNreminder.exeFrom MS Money. Reminds you of your bills
    Reg ServiceXREGSRV32.EXEAdded by the RBOT.ZW WORM!
    runner1Xupdater.exeDetected by Antivir as TR/Crypt.ULPM.Gen
    RAID Event MonitorUiaanotif.exeIAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
    rundll64X(path to worm)Added by the AUTEX VIRUS!
    run=Xwinlogon.exe CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process!
    Registry oidetXwin32.exeAdded by the RBOT.BMT WORM!
    regeditXsvchost.exe,ccRegVfyAdded by the Trojan.Rona Trojan!
    Reg ServiceXwinslogon.exeAdded by the W32/AGOBOT-SC or W32/Agobot-SY WORM!
    Register SeqChk?regsvr32.exe,..csseqchk.dll?
    rtosXrtos.exeIRC trojan
    RecoverFromReboot?RECOVE~1.EXEUnknown
    Rundll32XRUNDDLL32.EXEAdded by a downloader TROJAN! - detected by Panda antivirus as Adware/StartPage.AXH
    Registry Startup CheckXcheckreg.exeAdded by the Troj/RemLoad-A or Troj/Danmec-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RSRCMTZ?RSRCMTZ.exe??
    ResumeFixClocksUresumefix.exePart of the RadeonTweaker utility for overclocking ATI Radeon graphics cards

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer