CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    WINDOWS SYSTEMXefefefe.exe W32/Mytob-KH Read the link, allows remote access
    Windows UpdateXSecretStub.exeIdentified as the Trojan-Dropper.Win32.Sramler.c downloader TROJAN!. Note: This trojan is located in \%WINDIR%\
    WindowsUpdateXsvchost.exeAdded by the TROJ/AGENT-V TROJAN!
    Windows Media PlayerXwmplayer.exeAdded by the W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM!
    WinpowerUWinpower.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:\Program Files\UpsPilot\
    winlogonXwinlogin.exeAdded by the RANDEX.E or P2LOAD.A WORM!
    Windows Firewall LogXwinlog.exeAdded by an unidentified WORM or TROJAN!
    Windows LoL LayerXwin.exeAdded by the W32/Rbot-FTO WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win32UsrXWinCab.exe W32/Dedmir-A
    winupated.exeXwinupated.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Audio SystemXnndsvc.exeAdded by a A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    WebSavingsFromEbates0XWebSavingsFromEbates0.exe"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
    WindowsRegKey updateXrkbuouoxfl.exeAdded by the RBOT-OO WORM!
    Windows Servce AgentXcolwindos.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN! The filename is a (Random 8 Letter).exe
    winskypeXwinskype.exeAdded by the Troj/Brogger-C TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Wins Update 32Xservices32.exeAdded by the W32/Forbot-FN WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows Registry SecurityXcrss.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    Windows MSN UpdatesXwnd32.exeAdded by the Troj/IRCBot-ABA worm and IRC backdoor. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows SpoolXwinspool.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    wormexeXwinstart.exeAdded by the EARLYBIRD VIRUS!
    WintelUpdateXexujd.exeIdentified as a variant of the Backdoor.Win32.Small.crw backdoor. Note: located in \%WINDIR%\ Note: Use SDFix under supervision.
    WAPIXwts**.exe (* =,random char) PurityScan/Clickspring Adware
    Win32 Firewall DriverXwinfw.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows UpdateXmsi.exeAdded by the Troj/Banker-XB TROJAN!
    WindowsRegKey AutoupdateXExplorer.exeAdded by a variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Explorer.exe!
    Win UpdatesXwinupdates.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows NTFS Volume ManageX(Random 6,Letter).exeAdded by a variant of the Backdoor.Win32.Rbot.edl family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    WinDLL (wchshield.exe)Xwchshield.exe,startAdded by Worm_Ircbot_Gen Reported by Prevx. Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    WINDOWS SYSTEMXxpupdate.exeAdded by the W32/ZOTOB-G WORM!
    Win Net Wks32Xnetwks32.exeAdded by the WORM_RBOT.AA Read the link, modifies the hosts file. Adds a rootkit infection.
    Windows Security ServiceXarrdt.exeAdded by a variant of the WIN32.RBOT WORM!
    winstartXwinstart.exeAdded by the TROJ/SCKEYLO-AB TROJAN!
    winnetXwinnet.exeCommonName Toolbar spyware. To uninstall see here
    Windows FirewalllXwinmu.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows ServiceXvideo2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
    winreg_32Xsysdll.exeAdded by the TROJ/DLOADER-IJ TROJAN!
    Windows_ProtectXwinsystem.exeAdded by a variant of the WIN32.RBOT WORM!
    WinStart001 or WinStart001.EXEXWinStart001.exeFromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
    windows updateXWruaclt.exeAdded by the RBOT.XZ WORM!
    wlmX[Path to trojan,file]Added by the Troj/Bancos-BCY Trojan Read the link, steals information
    winupdate_X[path to file]Added by the W32.COMDOR.A WORM!
    Windows Live ServiceXmsnlive.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Winproxy PersonalXWINPROXY.EXEAdded by the SDBOT.BMF WORM!
    Windows Autostart LoaderXnotepad32.exeAdded by a variant of the WIN32.RBOT WORM!
    WIN USB SUPPORTXgrxsrv.exeAdded by a variant of the WIN32.RBOT WORM!
    Winlogin.exeXsteam.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    Winsock2 driverXWUAUMQR.EXEAdded by the W32/SPYBOT-DP WORM!
    Windows Service Pack2XWIN43.EXEAdded by the GAOBOT.G WORM!
    WINTASKXtaskgmrs.exeAdded by the W32.Mytob.DH WORM!
    Wifi BooterXwifibooter.exeIdentified as a variant the Backdoor.Win32.IRCBot.byu malware Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Windows spoolservr ServiceXspoolservr.exeAdded by the W32/Sdbot-AAN WORM!
    Windows System 32Xwinsys_32.exeAdded by the W32/Rbot-FTR WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    WindowsSystem32X[Path to Worm]Added by the W32/Sdbot-DFG Worm Read the link, allows remote access
    win32servvXload.exeAdded by an unidentified trojan or adware
    Wind0wsXwordpad.exeAdded by the W32/Agobot-TL WORM! Note: This is not the legitimate Windows application wordpad.exe (Which is found in the Program Files\Accessories folder.) The legitimate Windows application should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer