CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

StartupList Index

Currently 16937 startuplist entries and growing...
Last updated on 2008-07-04 18:52:24 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Microsoft InternetXmsnm.exe W32/Sdbot worm variant
    MswincfgXMswincfg32.exeAdded by the BACKDOOR.CYBSPY TROJAN!
    Microsoft UpdattingXmiroupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update Xspool.exeAdded by the Troj/Agent-GJC TROJAN!
    MatrixScreenX[filename]Added by the MATRIXSCREEN TROJAN!
    Microsoft UpdateXtaskmgr32.exeAdded by the W32/Rbot-CV WORM!
    MSInstallXsmvss.exeAdded by the TROJ/DEDLER-G TROJAN!
    MSKExeUspamkiller.exeMcAfee SpamKiller
    MSN messangerXmsnmsgsm.exeAdded by the W32/Rbot-FMP WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MplSetupUMplSetup.exeUsed by Ricoh network printers to enable network printing from the client
    Microsoft Internet FirewallXfirewall.exeA variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Macromedia Critical UpdaterXrarww.exeAdded by a variant of the WIN32.RBOT WORM!
    msresearchXtool3.exeSpy Sheriff/SpywareNO malware component, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
    Microsoft Windows Update x86Xfirefox.exe ,or, opera.exeAdded by a variant of the Rbot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Microsoft Sidewinder Game Controller SoftwareNSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
    MS Internet ExploreXMSIEx.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Located in \%WINDIR%\System32\
    Mailbox VerifierUmboxvrfy.exeMailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
    Micrsft UpdeseXxagwxz.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Memory Flow CycleXflowcycles.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Update Win32xXwinupdate32x.exeAdded by the W32/Rbot-AJN WORM!
    Motorola Desktop Suite mRouter ConfigUmRouterConfig.exeRelated to mRouterConfig is for configuration of mRouterRuntime. Used by Datassuite Software from Nokia / Siemens Sybian-Based. Note: located in C:\Program Files\...
    Microsoft Update ServicesXwsnfty.exeAdded by the W32/RBOT-AFU WORM!
    Microsoft Update Device DriversXwuauclt.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\drivers\ (Win9x/Me), C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K)
    Microsoft SCVHOST32 ProtocolXscvhost32.exeAdded by a variant of the WIN32.RBOT WORM!
    msvccc66Xdload.exeAdded by a variant of the W32/Rbot-GLS family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Microsoft ServicesXmodule.exeAdded by the LAVITS WORM!
    Microsoft Windows Logon ProcessXwinlogon.exeAdded by the Troj/Proxyser-R TROJAN!
    MSConfigrXjdbgmrg.exeAdded by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
    MS Java for Windows NT, XP & MEXxpjavams.exeAdded by the W32/Kassbot-V WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Internet Explorer ManagerXie.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    msconfigXmsconfig.exe CoolWebSearch parasite related. **Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
    Microsoft CPU Over Heat ManagerXCPU.exeAdded by a variant of the Backdoor.IRCBot.USP family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MicrosoftXmsvchost.exeAdded by the W32/Rbot-GAW WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft CorporationX(random,filename)Added by various VIRUSES such as VISAGES, BABYBEAR and TOFACED
    Microsoft-softwareX****.exe (where,* = random,char)Added by a variant of the WIN32.RBOT WORM!
    Microsoft PCHealth32X[path to file]Added by the TROJ/NICE-A TROJAN!
    MSPP System Update 64Xwiaadmgr.exeReported by Kaspersky Anti-Virus as Trojan-Proxy.Win32.Ranky.gen. Note: This trojan file is found in the System32 folder (NT/2000/XP). May be found in the System folder for (95/98/ME).
    Microsoft Locals 332Xsywrscds.exe, random file,namesAdded by a W32/Rbot-KU worm infection
    Microsoft UpdateXmsconfg.exeAdded by the Win32.Rbot.H WORM!
    MSN MessengerXlive.messenger.comAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Multi-function keyboardUGWHotkey.exeSoftware that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)
    Microsoft Windows UpdateXMSNMSGR.EXEAdded by the W32/SDBOT-WM WORM!
    Micrcsoft Certificate ServicesXcflmon.exeAdded by the W32/Rbot-FWV WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) modifies the system HOSTS file, preventing access to certain anti-virus websites.
    MDNXMDN.exeAdded by the RBOT.AOA WORM!
    Microsoft Viral Scanning ProtectionXmsviral.exeAdded by the W32/Sdbot-CLH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft UpdateXms.exeAdded by the BKDR_SDBOT.CC WORM!
    Microsoft DLL Host ServiceXsvcdllhst.exeAdded by the BKDR_AGENT.EAK Note: Located in \%WINDIR%\System32\
    mule_st_keyXflec006.exeAdded by the Trojan.Lodeight.C aka TROJ_BAGLE.AV Located in %UserProfile%\Application Data\m\flec006.exe Note: %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP).
    Micrsoft CFG 32Xlrbzus32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    mnsaXmnso.exeAdded by the Troj/Lineag-AI Trojan Read the link, steals information
    Microsoft Security PanagersX[random file,name]Added by the W32/RBOT-AIG WORM!
    MsnExplorerXSVCHST.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    msvload32Xmsvload32.exeAdded by the W32/RBOT-ACI WORM!
    Ms Update WinServices NT/XPXwinservnt32.exeAdded by the W32/Vanebot-G Read the link, keylogger/password stealing trojan(s) involved. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MultiCAM InitializerUMCamBoot.exeThe MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer