CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    svhost windows servicesXsvhost8.exeAdded by the W32/RBOT-WQ WORM!
    sysmodXsysmod.exeAdded by the W32/Spybot-DU WORM!
    srv32winUwin16dll.exe Screenspy captures screenshots silently. If you didn't install this yourself, remove it.
    System Mechanic Popup BlockerUPopupBlocker.exeRelated to System_Mechanic Utility Suite from iolo Technologies.
    shellsystemXshellsystem.exeAdded by the UPCHAN TROJAN!
    ServicesXsvchost.exeIdentified as a variant of the VirTool:Win32/DelfInject.gen!AM malware. Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    System Information ManagerXMsbb.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    SystemSettingfXTRUG.vbsAdded by the TRUG.B VIRUS!
    Security Center DistributionXsecuresec.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    SYSTRAYXUNMT.EXEAdded by a W32/Sdbot worm infection
    System DLL ResourcesUsysdll.exeAdded by the SnapKey SPYWARE! **Note if you did not intentionally install this remove it.
    sysinfo.exeXsysinfo.exeAdded by the BEAGLE.V WORM!
    SettingXsysweb.exeAdded by the SDBOT.GEN WORM!
    Services ProcessXservices.exeAdded by unidentified spyware - recognized by Kaspersky antivirus as TrojanSpy.Win32.Small.x
    Sistray32Xwin.batAdded by the W32/Jupir-C WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    sysconfigXiexplorer.exeAdded by the CULT.C VIRUS!. Note - iexplorer.exe is not to be confused with Interrnet Explorer (iexplore.exe)
    Services Manager!Xsvmanager.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Sygaete Personal FirewallXSyGate.exeAdded by the W32/Rbot-GLX WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access[/b]
    shockmachinereminderNSmReminder.exeShockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version
    System ProcessXcsrss.exeAdded by the TROJ/ADCLICK-AG TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    SecurePCSolutionsBootCheckUBootCheck.exeRelated to 1_Click_Boost from Secure PC Solutions. Optimizes your PC memory cache which makes your computer run faster and more efficiently both on and off the Internet and more... Note: Located in \%Program Files%\Secure PC Solutions\1 Click Fixer PLUS\
    SpywareStrikeXSpywareStrike.exeRogue Spyware product
    systemrXd11host.exeAdded by the Troj/VB-GX Trojan!
    SmarthruengineUQS.exeSamsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers
    SysrXsysmd.exe Ulubione adult content dialer
    sysPersonalFirewallXmsnmssgr.exeAdded by a variant of the WIN32.RBOT WORM!
    Service ControllerXservice.exeAdded by the PREVERT TROJAN!
    Security Service ProcessXsvhost.exeAdded by the AGOBOT-LC WORM!
    SymRunXccApps.exeAdded by the TROJ/KAGEN-B TROJAN!
    supernews12Xnewsd32.exeAdware, also detected as the TROJ/DLOADER-JN TROJAN!
    Sygate Personal FirewallXhost32.exeAdded by the W32/RBOT.ALD WORM!
    Service MonitorXmsnserve.exeAdded by the W32.SPYBOT.YQW WORM!
    SigXCXSigX.exe SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more."
    SmserialNsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
    SystemXrun322.exeAdded by the LANFILT VIRUS!
    SystemManagerXSysman32.exeAdded by the DOWNLOADER-BW.B VIRUS!
    System Update2Xsvchost.exeAdded by the Autotroj-C TROJAN!
    ShellExXShellEx.exeAdded by the ANAKHA VIRUS!
    SYSTEM MESSAGERXwmisg.exeAdded by the W32.Mytob.ES WORM!
    ShellRunXlexplore_.exeAdded by the Troj/MSNOpt-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    sws.exeXgd-dial.exeComponent of the "GlobalDialer" adult content premium rate dialer
    SBC Yahoo! Connection ManagerNConnectionManager.exeThe cmanager.exe process is used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection.
    systemXlsass.exeAdded by the Satiloler.E TROJAN! Read the link, rootkit type stealth involved.
    Screen Saver ControlNFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
    SSL ManagerXamsnmsgs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    SheduIerXwinagent.exeAdded by the TROJ/BDOOR-EB TROJAN!
    System Database administrationXsystemDA.exeAdded by the W32.Derdero.B WORM!
    SDR6_CheckXudcsdr.exeAdded by the DriveCleaner ROGUE PROGRAM! security assesment tool which gives exaggerated reports of security and privacy risks on a computer. Note: Located in C:\Program Files\Common Files\DriveCleaner 2006 Free\
    System MonitoringXcute.exeAdded by the W32.Rahiwi.A WORM!
    systemscrootXsystembin.exeAdded by an unidentified TROJAN! of the Rbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    spa_startXspads.dllAdded by an unidentified Trojan/Backdoor Note: Located in \%WINDIR%\System32\
    SysStartX1.exeAdded by ZenoSearch adware
    STDSBYSTDSB.exeScrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling.
    SYSWB6USYSWB6.exeWe-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content
    svchostdll.scrXsvchostdll.scrAdded by the Troj/Bancban-FM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer