CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    .mscdrXlsvchost.exeAdded by the WEBUS.D TROJAN!
    .mscdsrXlsvchost.exeAdded by the Troj/Bdoor-CR Trojan!
    .mscsblXsvhost.exeAdded by the BACKDOOR-CMQ TROJAN!
    .msfupdateXmsveup.exeAdded by the W32.ALLOCUP.A WORM!
    .mssecureXmssecure.exeAdded by the DDOS_BOXED.X TROJAN!
    .mssecureXmssecure.exeAdded by the Troj/Borobot-B Trojan!
    .NET config?sysmon32.exe??
    .NET.Xmsnmgnr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    .nortonXrchost.exeAdded by a variant of the BOXED-A TROJAN!
    .nvsvcXsmss.exeAdded by the BackDoor-CXT TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System (XP/WinNT/2K) and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file.
    .nvsvcbXsmssb.exeAdded by the Win32/Boxed.CG TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Will attempt to disable antivirus, firewall and Windows Update software
    .ProgXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe ) process
    .ProgXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
    .protectedX(no name)Added by a Smithfraud infection.
    .svchostXCSRSS.EXEAdded by the WEBUS.F TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    .TEXTCONVXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    .WMAudioXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process" which provides text window support, shutdown, and hard-error handling
    .WMAudioXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    /l:engNN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup
    000Upit.exeAdded by the PrivateEye SPYWARE! **Note - If you did not intentionally install this remove it.
    0006 - C:Documents and SettingsCompaq_OwnerStart
    MenuProgramsHP Internet Connection Center
    Ncommand.comRelated to HP_Internet_Connection_Center provides access to a variety of valuable offers from Internet Service Providers.
    0008 - C:Documents and SettingsCompaq_OwnerStart
    MenuProgramshp deskjet 990c series v3.0
    Ncommand.comRelated to HP_Internet_Connection_Center provides access to a variety of valuable offers from Internet Service Providers.
    000hpdllhosXhpdllhost.exe LZIO.com adware downloader
    000StTHKU000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
    0050726-007-i32-1X0050726-007-i32-1.exeAdded by the Troj/Bancban-EC TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer