CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Money ExpressNmoneyexpress.exePart of MS Money. Available via Start -> Programs
    MICROSFT RAMA UPDATE SUPPORTXMSN32.EXEAdded by the W32/Rbot-AWJ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    msccrtXmsccrt.exe Troj/PWS-ALA Read the link, steals information
    MSN MessangerXmsnmsgsmn.exe W32/Rbot-FOQ Read the link, allows remote access
    Matrox PowerdeskNPDesk.exeFor Matrox video cards. Quick access to tweak your card to your liking
    Mspatch69X(path to,trojan)Added by the MPROX VIRUS!
    mwsoemonXmwsoemon.exeAdded by MyWay An IE Browser Helper Object used by adware WeSearch to add an IE toolbar to provide search features, and hijack browser search requests to its controlling servers run by MyWay. Note: Located in \%Program Files%\MYWEBSEARCH\BAR\5.BIN\
    myhuyXhuy2.exeAdded by the W32/Blaster-L WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    mssfosXsfool.exeAdded by the W32.Randex.EUS WORM!
    MSN ConfigurationXmsnconfig.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MSWinupdXwinupd.exeAdded by the Troj/DwnLdr-GUO TROJAN! Note: This trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access
    MailScan DispatcherYLaunch.exeMailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned
    Microsoft Java Virtual MachineXmsjvm.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft UpdateXmsconfg.exeAdded by the Win32.Rbot.H WORM!
    MicrosoftXnetsrv.exeAdded by the W32/Rbot-GOS WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access
    msupdatesXmsupdt.exeAdded by a W32/Rbot-JO worm infection
    Mfc**32.exe (* = random char)XMfc**32.exe (*,= random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Microsoft AutoUpdaterXsvhost.exeAdded by a RBOT.QG worm infection
    Microsoft Windows Update LogonXwin-logon.exeAdded by a variant of the WIN32.RBOT WORM!
    McLogLch_exeNMcLogLch.exeRelated to McAfee_security suite. This is a non-essential program, but should not be disabled unless suspected to be causing problems. Note: Located in C:\Program Files\McAfee\MSC\
    Msn Update Manager (Sp2)XMSMSGS.EXEAdded by the W32/AGOBOT-NL WORM!
    Microsoft UpdateXwuamk032.exeAdded by the W32/RBOT-AHD WORM!
    msconfig.exeXuline.exeAdded by a variant of the WIN32.AGENT.AH downloader TROJAN!
    MutexServiceExNSys32Smm.exeWebroot Sofware's discontinued "Privacy Master"
    Music01 ServerNMusic01,Server.exeJ River Media Jukebox
    Microsoft Spool 20 ServiceXspool20.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Directx clickXdirectxclick.exeAdded by a variant of the W32/Rbot-GHT WORM! red]Note: This worm is located in C:\%WINDIR%\ Read the link, rootkit type stealth involved. More here
    Microsoft UpdateXwebm.exeAdded by the SDBOT.WK WORM!
    MediaMonitorNMediam~1.exeInstalled by Smartdisk MVP CD burning software. Software will work fine without it
    MicrosoftWindowsXMagicSearch - a CoolWebSearch parasite variant,
    MemoryMeterXMemoryMeter.exeAutoinstalling spyware by Total Velocity
    Microsoft Servicez ManagerXservicemgrz.exeAdded by the W32/Rbot-ASN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Service Host ManagerX32svchost.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Update 32Xmscnfg.exeAdded by the W32/Rbot-ALM WORM!
    MSNPluginSrvcsXsagate.exeAdded by the SDBOT.AKJ WORM!
    MSN Rx ManagerXmsnrxmgr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Genuine LogonXmsnmsg.exe Added by the W32/IRCBot-XH Worm Read the link, allows remote access
    Microsoft OfficeXnxcxtpr.exeAdded by the W32/RBOT-YG WORM!
    mysvcig38Xmysvcc.exeAdded by the W32/Rbot-FOU WORM! This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft System CheckupXntsysmgr.exeAdded by the W32.Donk.S WORM!
    Microsoft allXmmall.exeIdentified as a variant of the Proxy.Wopla.ac malware. Note: located in \%WINDIR%\ Note: Use SDFix under supervision.
    msreg.exeXmsrege.exeAdded by the ZINX VIRUS!
    My-disgoUMyKey disgo.exeRelated to disgo_pro Program will synchronize data.
    MicrosoftXrundll.exeAdded by the W32/Rbot-GSJ Worm Read the link, allows remote access
    Microsoft AntiSpywareXBazzi.exeAdded by the AHKER.J WORM!
    misiCTRL?misiCTRL.exeMiro video driver related. Is it required?
    MS Service DriversXwinscv.exeAdded by the W32/Sdbot-COG WORM! Note: This worm\trojan is located in C:\%WINDIR%\
    moviemkXmoviemk.exe Troj/DwnLdr-GTB
    Microsoft Service Evaluator EnginXmssee.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsofts Security ManagerX****.exe [****,= random char]Added by the RBOT-WH TROJAN!
    mswsplXwmplayer.exe, other file,namesAdded by a TROJ_SMALL.IQ trojan downloader infection
    MSN StartXmsnmsgr7.exeAdded by the W32/RBOT-PH WORM!
    mousedrvXmousedrv.exeAdded by a CRYPTER.A trojan infection
    Microsoft UpdateXms.exeAdded by the BKDR_SDBOT.CC WORM!
    Microsoft InstallshieldXnundll32.exe W32/Agobot-AHZ Read the link, allows remote access

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer