CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Microsoft Help SVCXmsnmngr.exeAdded by a W32/Sdbot-PQ worm infection
    MedionVFDUMdionLCM.exeRelated to Medion_Display display Information. Note: Located in C:\Program Files\Medion Info Display\
    Microsoft Telecoms CenterXwinupn.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    msnmsgXasgag.exeAdware trojan - probably CoolWebSearch parasite related.
    mspwrUpupxpman.exeRelated to Ashampoo's PowerUp XP
    MSPQFileXMSA****.TMPHomepage hijacker. See here for more information. **** can be anything
    Microsoft--UpdatesXsxvhost.exeAdded by a W32/Rbot-FH worm infection
    Microsoft Updates 2 USBXwgafixer.exeAdded by a variant of the WIN32.RBOT WORM!
    MONPluginSrIvcsXn3monap23.exeAdded by a variant of the WIN32.RBOT WORM!
    MSN Messenger Service StarterXmsnmgsr.exeAdded by the W32/Rbot-AOS WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MS MSN Menssenger 7.0XMSMSN7.exeAdded by the W32/RBOT-ACA WORM!
    Malware-WipeXMalware-Wipe.exeAdded by Malware-Wipe ROGUE PROGRAM. Issue fake taskbar alerts as a scare tactics in order to have you purchase the commercial version of the software. Note: Located in C:\Program Files\Malware-Wipe\
    MSWinlogonXSynCor.exeAdded by the Troj/Agent-FZL Trojan
    mackfy.exeXmsms.exeAdded by the W32/Sdbot-DID WORM! Note: Located in \%WINDIR%\System32\ Read the link, allows remote access
    MicroSoft IE SasserXISASS.EXEAdded by the SDBOT.MX WORM!
    MSDNNXhelp.exeAdded by the Troj/Agent-GBK TROJAN! Note: located in \%WINDIR%\
    Microsoft Hosting ServiceXWINHOSTING.EXEAdded by the RBOT.AEV WORM!
    MicroSoft Getway mqbolX(Random 12,Letter).exeAdded by a variant of the Backdoor.Win32.Rbot.etg family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Microsoft Conf LdrXsysconf.exeAdded by a variant of the SDBOT WORM!
    Mioft Wiws Seice entXeuxabnuqfn.exeAdded by the WORM! Note: Located in \%WINDIR%\System32\ Note: Uses a Random filename.
    media_driverXmedia_driver.exeAdded by the TUPEG VIRUS! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    Microsoft Windows UpdateXMSNMSGR.EXEAdded by the W32/SDBOT-WM WORM!
    Microsoft Visual SourceSafeXwinlogon.exeAdded by the W32.Neveg.B worm
    Microsoft Software UpdateXnmon.exeAdded by a RBOT.HZ worm infection
    Microsoft UpdateXmvsc.exeAdded by a variant of the W32.Spybot.DAZ WORM!
    MsupdateXsvcrhost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    Microsoft CronD ServiceXMSCRON.EXEUnidentified AIM-based worm/trojan
    Microsoft JavaVMXmsjarun.exe W32/Rbot-JW worm
    Microsoft Web CP ManagerXwebcp32.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft MSN 7 ServicesXmsnmsger.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MyWebSearch Email PluginXmwsoemon.exeAdded by MyWay An IE Browser Helper Object used by adware WeSearch to add an IE toolbar to provide search features, and hijack browser search requests to its controlling servers run by MyWay. Note: Located in \%Program Files%\MYWEBSEARCH\BAR\5.BIN\
    MscntXmscnt.exeAdded by the Troj/Dluca-C TROJAN!
    Machine Debug ManagerUmdm.exeUsed by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable
    MalwareAlarmXMalwareAlarm.exeAdded by Malware_Alarm ROGUE PROGRAM. False positives work as goad to purchase; inadequate scan reporting. Note: Located in \%Program Files%\MalwareAlarm\
    MessengerPlus, MessengerPlus2, MessengerPlus3NMsgPlus.exe MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that "sponsor program"!
    Microsoft Windows UpdaterXwindates.exeAdded by the SDBOT.TE WORM!
    Microsoft DirectXXwuamgrd.exeAdded by the SDBOT.MY WORM!
    MCX UpdateXwisp.exeAdded by the W32/Rbot-AQH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows DLL 32-BITXmsncheck32.exeAdded by the W32/SDBOT-XX WORM!
    morphstbXmorphstb.exeAdware downloader - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Stubby.c
    Microsoft UpdateXIsac.exeAdded by the W32/Rbot-AU WORM!
    Microsoft RegistroXsvchostt.exeAdded by the TROJ/BANCOS-DH TROJAN! Read the link, keylogger/password stealing trojan(s) involved.
    Microsoft DiagnosticXmsdiag32.exeAdded by the W32/RBOT-UC WORM!
    MicrosoftUpdateXsyshelper.exeAdded by the WOOTBOT.AC WORM!
    MonTestXvccxzq.exeAdded by the W32/SDBOT-EA WORM!
    Microsoft Spool 21 ServiceXspool21.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsft UpgraedX(Random,Name).exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MsgApiX(path to file)Added by a Dedler-D trojan infection
    Microsoft Windows DLL Services ConfigurationXnewdll.exeAdded by the W32/Sdbot-ZR WORM!
    MS HostsXmsthosts.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MSControl28Xcrsss.exeAdded by the SPYBOT.AJX WORM!
    Microsoft IPCXsvshost.exeAdded by an unidentified VIRUS!
    MediaPathXProyecto1.exe, Root.exeAdded by the GRUEL VIRUS!
    Microsoft Update 32Xservic.exeAdded by the W32/Rbot-AXN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MPtask ServicesXmptask.exeAdded by the LALA or DOWNLOADER-BN.B or AOT VIRUSES!

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer