CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    User ManagerXfcllls.exeAdded by the ZAGABAN-B TROJAN!
    UberIconUUberIcon,Manager.exeRelated top Uber_Icon by Punk Labs. Creates a more customizable atmosphere on your desktop by extending Windows to perform new effects when you launch your icons and folders. Note: located in \%WINDIR%\BricoPacks\Crystal Clear\UberIcon\
    upxdndXupxdnd.exe Troj/JD-A Read the link, steals information
    updater32Xwinload32.exeAdded by the CULT.M WORM! **Note - not to be confused with the valid Windows "NOTEPAD" text editor
    Uniblue Registry BoosterURegistryBooster.exeRelated to Uniblue_Registry_Booster Keep your computer clean. Note: Located in C:\Program Files\Uniblue\Registry Booster\
    Uniblue Quick AccessUqaccess.exeQaccess.exe belongs to a new tool from Uniblue_Systems that gives information about running process entries in Task Manager.
    Ulead Photo Express x.0 CalendarNcalcheck.exeUlead Calendar Checker - part of Ulead Photo Express, where "x" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually. See here for disabling instructions
    Uniblue RegistryBooster 2URegistryBooster.exeRelated to Uniblue_Registry_Booster Keep your computer clean. Note: Located in C:\Program Files\Uniblue\Registry Booster 2\
    Update ExplorerXiexploreupd.exeAdded by a variant of the Rbot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    USB Device Server!Xusbserver.exeAdded by a A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    UpdRegNUpdreg.exeReminder to register Creative Labs SoundBlaster Live! cards
    Uptimer4UUptimer4.exeUptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things
    USB Storage ToolboxURes.EXERelated to USB_Storage_Toolbox from Koma-Code. A program with many functions. Just load it on your USB-stick and have many useful Tools in one program always at hand. Note: Located in \%Program Files%\USBToolbox
    UserinitXlsass.exeAdded by the Satiloler.D TROJAN! Read the link, rootkit type stealth involved.
    update mon sysXupdaterar.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    Unix File SupportXinit3.exeAdded by the W32/RBOT-ZN WORM!
    update serviceXsvxhost.exeAdded by the RBOT-MG WORM!
    UsbDXsvhost32.exeAdded by the TROJ_AGENT.IB TROJAN!
    USB Updates 2Xwugfixx.exeAdded by a variant of the WIN32.RBOT WORM!
    uwyw.exeXyujixit.exeAdded by the SDBOT.BGB WORM!
    UPDATEMSNXsvhost.exeAdded by an unidentified WORM or TROJAN!
    UndefinedXwinter.exeDetected as Trojan.Peed.INM by BitDefender
    UpdatesXmsupdate.exe CoolWebSearch parasite related.
    Upromise UpdateUpromiseUa.exeRelated to Upromise Save money for education by bying online at desinated locations. Note: Located in \%Program Files%\Upromise\
    Updt ServiceXupdt.pifAdded by the W32/Rbot-AYU WORM!
    USB Fix 1.1Xwuservices.exeAdded by a variant of the W32/SDBOT WORM!
    UPnP ManagerXupnpman.exeAdded by a variant of the Win32.Agobot.gen WORM!
    Update.exeXravseuper.exeAdded by the Troj/QQPass-P TROJAN!
    Uniblue SpyEraserUspyeraser.exe SpyEraser from Uniblue. Spyware detection program
    UADC_3240389055XUADCcw.exeAdded by Advanced_Cleaner a ROGUE program. Note: Located in \%Program Files%\AdvancedCleaner Free\
    UsbdXusb_d.exeAdded by the TROJ/CIDRA-A TROJAN!
    UpdateManagerUsgtray.exeStorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
    Ulead AutoDetector?Monitor.exeRelated to Ulead_AutoDetector programs. Note: Located in \%Program Files%\Ulead Systems\AutoDetector\ What does it do and is it required?
    Upgrade SarviceXsxchost.exeAdded by a variant of the TROJ/TOFGER-I TROJAN!
    usnsvc.exeXusnsvc.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    Upgrade ServiceXwinupd.exeAdded by the TROJ/TOFGER-U TROJAN!
    UpdateXSysupd.exeAdded by the SLACKBOT VIRUS!
    UniScUUnisc.exeMcAfee UnInstaller
    updatemgr.exe or UPDATE~1Nupdatemgr.exe,UPDATE~1.EXEOnce a month, your EarthLink 5.0 Update Manager contacts EarthLink\'s servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to and download the updates manually
    un32infoXun32info.ExeAdded by a CRYPTER.A trojan infection
    Userfile Sharing ServXusnsrv.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    UpmeXDLLMAN.EXEAdded by the MUGLY.I WORM!
    USB FixesXwuafix.exeAdded by the W32/RBOT-ABV TROJAN!
    UpDataXwupdata.exeAdded by the TROJ/IRCBOT-AA TROJAN!
    updatelavasoftXupdatelavasoft.exe CoolWebSearch related hijacker, redirecting to lalasearch.com
    userinitXwinlogon.exeAdded by the Troj/Dloader-TP TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
    UninstallAbilityNuability.exe UninstallAbility free uninstaller
    USBHWINFOXmmc.exeAdded by the TROJ/LOWZONE-I TROJAN!
    uhvjsul.dllX[path],rundll32.exe,[path],uhvjsul.dll,mrpmvyftrojan, detected by Panda antivirus as Trj/DisableKey.A
    userinit.exeXuserinit.exe Troj/Haxdoor-DP trojan - Note: this file is located in the Windows directory, and should NOT be confused with the legitimate file of the same name which is always located in the %SysDir% folder!
    userdXsystems.comAdded by the W32/OutLaw-A Worm
    ugdccwXUGDCcw.exeDetected as W32/WinFixer.ASK by Norman antivirus
    usbnX(path to,Trojan)Added by the Troj/Hogil-E TROJAN!
    UMonitUumonit.exeAlerts when USB device is plugged in
    User32X(random,filename)Added by the NETTRASH VIRUS!

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer