CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    RemindMeURemindMe.exeRemind-Me - calendar software
    Remote Access AdapterXrvasvc.exeAdded by a variant of the Backdoor.Win32.IRCBot.alo family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Rundil32XUpdadv.exeAdded by the Troj/QQPass-N TROJAN!
    run=?wallflip.exeDesktop wallpaper changer?
    rundll32Xrundll32.exeAdded by the SANKER VIRUS! Note that the valid "rundll32.exe" resides in C:\Windows\System32 wheras this version resides in C:\Windows
    Remote Procedure CallsXmswinc.exeAdded by the W32/RBOT-IT WORM!
    Restart_VS?Viewsonic.exeCould be a left-over from the installation of a Viewsonic flat panel display
    RealschedNrealsched.exeApplication Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry
    RundllXRundll~.exeAdded by the W32/DELF-KT TROJAN!
    restoryXrestory.exeAdded by the RETSAM VIRUS!
    RunOnceURUNONCE.EXEPart of MS Data Access Components - only required if you use these
    rundll32XMSDTC.exe Added by the W32/Stap-E Worm
    RemoteURemote.exeRelated to LifeView_FlyVideo_TVR Note: Located under C:\Program Files\LifeView TVR
    RapidBlasterXrb32.exeHomepage hijacker (adult content) - see this newsgroup thread
    RunDllXRunDll.exeAdded by Troj/QQPass-AH TROJAN!
    regsrvcXregsrvc.exeAdded by the TROJ/STOPED-A TROJAN!
    RUNLOUDXloud.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    ReminderNRemind_XP.exeSubscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package
    regsvrXregsvr.exeAdded by the WEBMONEY-G TROJAN!
    run=Uramsys.exeAdvanced Startup Manager from Rays Lab
    Run[0]Xsyscnfg.exeAdded as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
    RRMedicXrrmedic.exeTroubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection
    RSRCMTZ?RSRCMTZ.exe??
    RDLLXRunDll16.exeAdded by the SDBOT.F WORM!
    RjLyraInstaller?setup.exe??
    RSPC Driver DX(random,filename)Added by a variant of the WIN32.RBOT WORM!
    runXluapvs.dllIdentified as Trojan:Win32/Emurbo.A Note: Located in \%WINDIR%\System32\ or %AppData%\sp1\ Note: Use SDFix under supervision.
    runingXwin.exeAdded by the Troj/Delf-LC TROJAN!
    Remote Services ManagerXmsrmsvc.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    RealJukeboxSystrayNtsystray.exeSystem Tray icon for RealJukebox
    rsrvmon.exeXrsrvmon.exeIdentyfied as a variant of the Trojan-Clicker.Win32.Agent Note: Located in \%WINDIR%\System32\drivers\ Note: Use SDFix under supervision.
    RegDoneXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
    RegcxnXRegcxn.exeAdded by the COIBOA-D TROJAN!
    Recycle Bin HandlerXrecycler.exeAdded by the TROJ/SHUCKBOT-A TROJAN!
    RegistryChkXwinbackup.exeAdded by the MERTIAN VIRUS!
    RPCSS.exeYrpcss.exeRemote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here
    RexSyMonNrexsymon.exeIntellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC
    REGRUNX(pathname of,the Trojan,executable)Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    RSPC DriverX(random,filename)Added by the W32/RBOT-SN WORM!
    RunCAYInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
    Remote ControlNRc.exeHinet Hi-Five ISP software
    RegXReg.htaHomepage hi-jacker. Removal instructions here
    RegrxXrundll32.exeAdded by the TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
    Restore OperationXsvchots.exeAdded by a variant of the Trojan-Downloader.Win32.Small.ddx family of TROJAN! Note This trojan is located in C:\%WINDIR%\TEMP\ folder.
    rn4dXdirote.exeAdded by the BKDR_MAROON.A TROJAN!
    run=Xmsxmidi.exe CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw
    run=Nfmedia.exeFMedia FaxWorks related - can be run manually
    RunAlertUAService.exeMSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system
    runwin32Xrunwin32.exe Troj/ESearch-A trojan
    rollbkXsysup.exeAdded by the W32.Serflog.B WORM
    RegCompresXREGCPM32.EXEAdult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
    rundl332Xmath.exe,...pluged.exeAdded by the DOOMJUICE VIRUS!
    Registry LoaderXregloadr.exeAdded by the GAOBOT.AO WORM!
    RP32Urp32.exeControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems.
    Rundll32.exeXProyecto1.exeRoot.exeAdded by the GRUEL VIRUS!

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer