CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    (random)Xsvchost.scrAdded by Troj/Bancban-CY Trojan! Read the link, keylogger/password stealing TROJAN(S) involved.
    (Random)Xsvshost.exeAdded by the W32/Kelvir-AX WORM! Note: This worm\trojan file is found in the System\(random folder name) (95/98/ME) or System32\(random folder name) (NT/2000/XP) folder.
    (random)Xsvchost.exeAdded by the Troj/Bancban-JC TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    (Randomly chosen existing folder name)X_cfg.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_login.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_start.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_config.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_autorun.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_loader.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_env.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_setup.exeAdded by the W32/Antinny-L WORM!
    (Registry Value Name)Xroses.exeAdded by the W32/Rbot-AFT Worm! Read the link, keylogger/password stealing TROJAN(S) involved.
    (unknown)Xcharmapnt.exeAdded by the Troj/Bancos-DR TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    (User name) configX(Path to Trojan exe)Added by the Troj/Mosuck-H TROJAN!
    (various file names)Xmediaplayer32.exeAdded by a variant of the WIN32.RBOT WORM!
    (various file names)Xbling.exeAdded by the W32/RBOT-NI WORM! Read the link, keylogger/password stealing TROJAN(S) involved.
    (various names)Xwin32snd.exeAdded by the W32/RBOT-DQ WORM!
    (various names)Xsvchostss.exeAdded by a variant of the WIN32.RBOT WORM!
    (various names)XPasswdMon.exeAdded by Wareout Rogue Software
    (various names)Xrunload32.exeAdded by Wareout Rogue Software
    )Start ServiceUupssrv.exeCyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner."
    *Xtwain_32.exeIdentified as Trj/Downloader.SV by Panda. TROJAN! Note: located in \%WINDIR%\
    ******** (* = random char or digit)Xrsbmsc.exeAdded by what AntiVir antivirus detects as the BDS/Agent.adt TROJAN!
    *BandookXmsdll.exeAdd a variant of the Trojan/Backdoor TROJAN! Note: Located in \%WINDIR%\System32\
    *JanisRuckenbrodIIXjanis.comAdded by the POPS VIRUS!

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer