CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    razertraYrazertra.exe razer diamondback mouse driver
    Run XP Service PackXxpservicepack.exeAdded by a Sdbot.AQA worm infection
    Run TaskMrgXcsrss.exeAdded by the TROJ/LDPINCH-W TROJAN!
    roketpipe?rpclient.exe??
    ravtaskXsvch0st.exeAdded by the LINEAG-AIN TROJAN!
    RegistryMonitorXsysfade.exeAdded by Trojan.Sysfade Note: located in \%WINDIR%\
    Registry SystemXRegsys.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    ReceiverUPcfaxRcv.exeRelated to PC_to_Fax driver from Sharp Electronics Corp. Note: Located in \%Program Files%\SHARP\PCFAX2.0\
    requesterXrequester.12.exeAdded by the Trojan.Requester.Process Trojan
    rundll32Xrundll32.exeAdded by the Troj/Agent-EZ keylogging TROJAN! Note: This trojan file is found in the System\SHELLEXT (95/98/ME) or System32\SHELLEXT (NT/2000/XP) folder. Do not confuse this with the real rundll32.exe which resides in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RaConfig2500NRaConfig2500.exeRelated to RaLink_Config_Utility It is used to configure the RaLink Wireless LAN cards. This is a non-essential program. *Disabling or enabling it is down to your preference. Note: located in C:\WINDOWS\system32\
    run32Xrun32dll.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    rollbkXmsmpatch.exeAdded by the W32.Serflog.B WORM
    Reactor6X[random,name]32.exeAdded by the W32.Mydoom.AK WORM!
    Real Statics AgentXccreal.exeAdded by a variant of the WIN32.RBOT WORM!
    Retrospect WD ServiceUWDSVC.EXERelated to Retrospect_WD_Service Dantz Retrospect backup application. Note: Located in C:\PROGRAM FILES\DANTZ\RETROSPECT\
    RPCserv32gXNB32EXT2.EXEAdded by the BOBAX.AD WORM!
    Rnudll32Xtadxtr.exeAdded by the TROJ/QQPASS-O TROJAN!
    RegDoneXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
    Registry ServXregsvr.exeAdded by the WEBMONEY-G TROJAN! Note: Located in \%WINDIR%\System32\
    RtlMon.exeNRtlMon.exeMonitor for RealTek network card
    REGMSYSX(Path of,Executable)Added by the Troj/LowZone-AX TROJAN!
    RAX SYSTEMXscrigz.exeAdded by the MYTOB.KR WORM!
    Root_MachineX(Pathname of,the Trojan exe)Added by the Troj/Bancban-DI TROJAN!
    RealschedNrealsched.exeApplication Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry
    rbenh ml***eXrbenh.exe RapidBlaster Variant
    RegscanXregscanr.exeAdded by the TROJ/OPTIX-SE TROJAN!
    Run Services as ApplicationXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    RoxAssistNRoxAssist.exeRoxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel".) .Can be run manually
    rundll64X(path to worm)Added by the AUTEX VIRUS!
    Registry Startup CheckXcheckreg.exeAdded by the Troj/RemLoad-A or Troj/Danmec-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RapdataeXrabseuser.exeAdded by the TROJ/QQPASS-S TROJAN!
    run=Xmsxmidi.exe CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw
    rregXrreg.exeUnidentified adware
    Run POPFile in backgroundUperl.exewperl.exePOPFile - E-mail spam blocker
    RapdataXravsecs.exeAdded by the Troj/QQPass-V TROJAN!
    Realaudio PlayerXrealaudio32.exeAdded by the Worm.AGOBOT-VA.Process WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    RUSBHOLoader?rundll32.exe,RUSBHOLoader.dll, AutoRegister??
    reg32Xreg32.exeAdded by the NOUPDATE.B VIRUS!
    RPCserv32gXservices.exeAdded by the W32.BOBAX.AA WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RegRunXmActiveX.exeAdware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    RegCompresXREGCPM32.EXEAdult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
    RapdatybsXravseteyns.exe Troj/PWS-ACP Read the link, steals information
    runappXicqchk.exeAdded by the Bomka TROJAN!
    Registry ScannerXregscanr.exeAdded by the OPTIX LITE FIREWALL BYPASS VIRUS!
    RegistryCleanFixMFCXregistrycleanfix.exeAdded by RegistryCleanFix ROGUE! program. Once the scan is completed, it reports false or exaggerated system errors on the computer. Note: Located in \%Program Files%\RegistryCleanFix\
    RavMonYRavMon.exe RAV AntiVirus
    run=Xservices.exe Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
    RAID Event MonitorUiaanotif.exeIAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
    RecoverFromReboot?RecoverFromReboot.exeUnknown
    RAMDefUramdef.exeRam Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind
    RegRun WinBaitUwinbait.exePart of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different..
    RegHelpUsvchosts.exe SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."
    run=XDRDOOM.EXEAdded by the W32/SEMAPI-A WORM
    Run Google Web AcceleratorUGoogleWebAccWarden.exeRelated to Web_Accelerator from Google. Note: Located in \%Program Files%\Google\Web Accelerator\

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer