CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    678Xlsas32.exeAdded by the Troj/Slsorve-C TROJAN!
    756349DC-6D9E-4F2A-9B24-269661F073C3Xsysoghcx.exeAdded by the SmitFraud Trojan
    7f8eXz****.exe 9idfDetected by NOD32 as Win32/TrojanDropper.Small.ALI , Note: it creates a number of extra z****.dll files in the system32 folder
    7v3jXz1844.exe gdtghAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) The file name is random z(Random Number).exe followed by gdtgh
    802.11b+g USB Wireless LAN UtilityUZDWlan.exeRelated to USB_Wifi_device Wireless Lan. Note: Located in \%Program Files%\WLAN\802.11b g USB WLAN\
    802.11g Wireless AdatperUMonitor.exeRelated to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled.
    85Xrundl132.exeAdded by the Troj/Gampass-L TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ Monitor user activity and log keystrokes. It also attempts to suppress detection alerts for an anti-virus product (random key name).
    852EBF20-A95D-4F1F-B9C2-B2CD24350F3EXsysodkcs.exeAdded by the SmitFraud Trojan
    98D0CE0C16B1Xrundll32.exe D0CE0C16B1,D0CE0C16B1 BrowserAid/BrowserPal Foistware
    9mXwinlog0n.exe Troj/LegMir-AQK Read the link, steals information
    9xadirasY9xadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    9xHtProtectXAVprotect9x.exeAdded by the W32.NETSKY.M WORM!
    ;RundllX(random filename)Added by the PWSLEGMIR.E VIRUS!
    XRegsrv32.comAdded by the SOUTHGHOST VIRUS!
    XApp.exeAdded by the WAXPOW VIRUS! where <filename> is the executed filename
    Xwincpu.exeAdded by an unidentified VIRUS!
    Xelf.exeElf is a hacker program, tied to a trojan server
    ??QQ?QQ.exeRelated to QQ_IM program popular in China. (It's similar to MSN Messenger.) there are many add-ons created for QQ and of course, some add-ons are malware. If you didn't get his QQ from the official site, or you installed some add-ons it is suggested that you remove it and have install a fresh copy from the official Tencent Inc. site. Note: Located in \%Program Files%\Tencent\QQ\
    ?ekio StartupsX?nksvc32.exeAdded by the W32/AGOBOT-OV WORM! Read the link, keylogger/password stealing trojan(s) involved.
    @Xregedit -s ..win.dllAdded by the SEEKER.K VIRUS!
    @Hoc ToolbarNAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more info
    @lohaNreminder.exeRegistration reminder for @loha@home E-mail utility
    @tour_wwX@tour_ww[1].exeAdult content dialler
    aXa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
    aXjesse.exeAdded by the W32/Melo-A WORM! Note: This worm file is found in the system32\drivers\etc folder.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer