CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    WINDOWS MANAGEMENT SYSTEMXwm1exe.exeAdded by the W32/RBOT-VT WORM!
    winupdate2846X(path),vbsystem35.exe,(path),msvbrun.exeAdded by a Mutin-C IRC backdoor trojan infection
    Windows LogonXwinlogin.exeAdded by the TROJ/SPYBOT-C TROJAN!
    WUSB11B.exeYWUSB11B.exeLinksys WUSB11 WLAN USB adapter
    Winsock2 driverXAMSNMGR.EXEAdded by a variant of the W32.SPYBOT WORM!
    Windows Reverse PreperationXwinrvp.exeIdentified as a variant of the Backdoor.Win32.IRCBot.axp worm. Note: Located in \%WINDIR%\System32\
    Windows MeTaLRoCk serviceXmetalrock.exeAdded by the TASTYRED VIRUS!
    Windows System DriversXsysretain.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows Secure ServicesXssms.exeAdded by a variant of the W32/SDBOT WORM! Note: Located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    WindowsXmsdos98.exeAdded by the PWSTEAL VIRUS!
    WebCpr0XWebCpr0.exe Web_CPR/TopMoxie adware
    winreg_32Xsvchosst.exeAdded by the BANCOS-CE TROJAN! Read the link, keylogger/password stealing trojan(s) involved.
    WindowsKeyUpdateXmaster.exeAdded by the W32.JOSAM WORM!
    winupd.exeXwinupd.exeAdded by the BEAGLE.M or BEAGLE.N WORMS!
    Windows Messenger MessengerXwinmsg.exeAdded by W32.Velkbot.A WORM!
    wlsassXwlsass.exeAdded by the WLSASS/32.Process TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    WSAConfigurationXsvchostt.exeAdded by the AGOBOT.ZT WORM!
    WinMsrv32XWinMsrv32.exeAdded by the GAOBOT.AFJ WORM!
    Windows Registry SecurityXcrss.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    Winampa AgentXWINAMPA.EXEAdded by the W32/SPYBOT-BR WORM! - NOTE: this is NOT the Winamp Media Player, as described here
    WinCheckXWinCheck.exeAdded by the PWS-CY VIRUS!
    Windows Remote LauncherXwnpmcs.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Located in \%WINDIR%\System32\
    WinLsassX(path to file)Added by the W32/WORT-B TROJAN!
    Win32 Usb DriverXAvpG.exeAdded by the W32/FORBOT-BX WORM!
    WindUpdatesXWinUpdt.exeWindupdates adware
    Wireless ConsoleNwcourier.exeRelated to Wireless_Console installed alongside Asus wireless components. Provides configuration options for these devices. Note: Located in C:\Program Files\Generic\Wireless Consol
    WireLessKeyboardUPS2USBKbdDrv.exeRelated to WireLess_Keyboard Multimedia Combo Set by SANSUN Industries. Note: Located in C:\Program Files\Multimedia Combo Set\
    WinGuage ProNWGPRO32.EXEPart of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
    Windows Service AgentX******.exe (* =,random char)Added by a variant of the WIN32.RBOT WORM!
    WinAC v4Xklsuicbn.exeAdded by the W32/FORBOT-CS WORM!
    Windows Live ServicerXusrserv.exeAdded by the Trojan.Crypt.XPACK.Gen Trojan
    Windows FirewalllXsvvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Printing DriverXWinSpooler.exeAdded by an Unknown malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows Hijack ProtectionXcomngr.exeAdded by a variant of the W32/SDBOT WORM! Note: Located in \%WINDIR%\System32\Com\
    WinDLL (dlfksdld.exe)Xdlfksdld.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. DO NOT DELETE THIS FILE C:\WINDOWS\RUNDLL32.EXE
    Win32UsrXWinCab.exe W32/Dedmir-A
    Windows Messenger ServiceXwinsmsgr.exeAdded by the W32/RBOT-VW WORM!
    Windows TaskmanagerXwinpifviewer.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows Media PlayerXmsass43.exeAdded by a variant of the WIN32.RBOT WORM!
    Win32 Security ProtocolXsecure32.exeAdded by the W32/Rbot-ETI WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    wscript.exeXvabian.vbsAdded by the VABI VIRUS!
    Windows ConfigurationXwsys32.exeAdded by the GAOBOT.FB WORM!
    WinLibUpdteXlibupdte.exeAdded by the BIONET.318 VIRUS!
    Windows Update 63Xshupd64.exeAdded by the W32/Forbot-GA WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Host32 StarterXhostserv.exeAdded by the W32/SDBOT-WU WORM!
    Windows Service ManagerXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    WINDOWS SYSTEMXservises.exeAdded by the W32/Zotob-I WORM! Note: (servises.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (services.exe) should not be seen in Msconfig or as a Startup item.
    Windows FirewallXsvchost.exeAdded by the Troj/Proxy-HT Trojan Read the link, allows remote access
    WindowsUpdateXpath to,executableAdded by the Troj/Dupa-B TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Winkb6Uwinkb6.exePart of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed
    Windows firewall managerXmsguard.exeAdded by a variant of W32.Randex.GEL WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) steal information and terminate anti-virus applications
    WINDOWS SYSTEM By FEnRXwindasz-updote.exeAdded by the MYTOB.LR WORM!
    WinUpdsvXwinupdsv.exeAdded by the X97M.DROPO Macro VIRUS!
    Windows Update Firewall SystemXwinmsfw.exeAdded by the W32/Rbot-EEO WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Ssteal product registration information from certain software and turn off security software such as anti-virus or firewall
    WNSTXwns*****.exe (*,= random char) PurityScan/Clickspring Adware

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer