CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Windows ManagerXwinsrv.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    wblogonXubpr01.exeAdded by the Troj/Agent-HFI TROJAN! Note: Located in \%WINDIR%\System32\
    WinAVXXWinAvX.exeInstalled by WinAntiSpyware Note: Located in \%WINDIR%\System32\
    Windows DefenderXwindowsdefender.exeAdded by a variant of the RBOT family of IRC Backdoor trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    WanMPSvcYWanMPSvc.exeAn AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help
    WebKeyNWebKey.exeWebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
    Web ServiceX[random file,name].exeAdded by the ADMINCASH TROJAN!
    Winsock32 driverXTesting.exeAdded by the SPYBOT.B VIRUS!
    Windows shell?win70.exe??
    winlgz2Xwinlgz2.exeAdded by the TROJ/KILLFIL-Q TROJAN!
    winrapidXwinrapid.exeAdded by a variant of the WIN32.RBOT WORM!
    windows automationXmslaugh.exeAdded by the BLASTER.E VIRUS!
    Wildwire MonitorNWWMon.exeThis places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
    Windows32Xsystem.exeUnknown malware. Note: located in \%WINDIR%\System\ Note: Use SDFix under supervision..
    WCPSXWint**.exe (* =,random char) PurityScan/Clickspring Adware
    Windows System-Control DriversXsyscontrl.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Winini.dllXwinini.vbsAdded by the Troj/Startp-M Trojan
    WinHelpXrealsched.exeAdded by a variant of the LOVGATE WORM! **Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
    WINDOWS SYSTEMXdcomuser.exeAdded by the W32.Mytob.EO WORM!
    Windows ServicesXw32edus.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Wifi Loader!Xwifiloader.exeIdentified as a variant the Backdoor.Win32.IRCBot.byu malware Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Windows Live ServicerXusrserv.exeAdded by the Trojan.Crypt.XPACK.Gen Trojan
    Windows Local ServicesXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    winsecureXwinsecure.exeBrowser hijacker, redirecting to specificsearches.com
    Windows TaskManagerXtskmngr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows TaskAdXWintaskad.exeWindUpdates WinTaskAd adware variant
    winlogonXsvchost.exeAdded by the W32/AHKHeap VIRUS! Note: Located in \%ROOT%\heap41a\ Note: Do not remove the legitimate file in \%WINDIR%\System32\
    WindowsRegKeys updateXwinsysi.exeAdded by a SDBOT.WE worm infection
    Windows Logon ApplicationXWinIogon.exeAdded by the "Cruel Intentionz" backdoor TROJAN!
    Windows TCP/IPXwintcp.exeAdded by the W32/AGOBOT-ZH WORM!
    WinPLOSIONUWinPlosion.exe WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop.
    Windows Service ManagerXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows MeTaLRoCk serviceXmetalrock.exeAdded by the TASTYRED VIRUS!
    Windows System RestorerXSystemRestorer.exeAdded by the DULOAD.C VIRUS!
    winclsXwincls.dllAdded by the W32/Akbot-AR WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) spreads to other network computers, may also modify the HOSTS file.
    Windows DLL ServicesXwinsvc32.exeAdded by the W32/RBOT-ZF WORM!
    Windows LoginXlogin.exe Detected as a variant of Win32/Bifrose by NOD32
    Windows UpdateXMcAfee3.exeAdded by a variant of the IRCBOT Note: Located in Note: Located in \%Program Files%\Common Files\System\ Note: Use SDFix under supervision.
    WinPatrolUWinPatrol.exeWinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"
    WinRaR ServiceXWinrarCO.comAdded by an unidentified TROJAN! of the RCbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Filename can also be a random with 14 characters
    Windows ServicesXsmsc.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Services TowerXsvctowers.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows SpoolerXspoolsv32.exeAdded by an unidentified WORM or TROJAN!
    win32servXdevicer.exe ,or,,servicesetup.exe,,systemdevices.exeAdded by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. Note: Located in \%WINDIR%\System32\
    Windows Rescue SystemXwinsto.exeAdded by a variant of the Trojan-Downloader.Win32.Agent.avf malware. Note: Located in %Temp%\
    winactiveXWINACTIVE.EXEActive variant of LOP.com hijacker - see here
    Windows System32Xexplorer.exeAdded by the W32/Opanki-V WORM! Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. DO NOT DELETE THE EXPLORER.EXE FILE UNLESS IT NOT FROM MICROSOFT
    Windows DNSXwindns.exeAdded by the W32/SDBOT-XU WORM!
    Windows System ManagerXwinsysmgr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    WinSvc16.exeXWinSvc16.exeAdded by the BACKDOOR.SDBOT.FQ TROJAN!
    wssysUwssys.exe WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it
    Win32 USB2.0 DriverXw32usb2.exe WORM_SPYBOT.DN
    WinAbleXwinable.exeAdded by a unknown variant of a Trojan/Backdoor TROJAN! Note: Located in \%Program Files%\WinAble\
    Win32BaseServiceMODXWintask.exeAdded by the NAVIDAD VIRUS!
    win32Xwinhost.exeAdded by the W32.BROPIA.J WORM!

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer