CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    System Update2Xexplorer.exeAdded by the Autotroj-C TROJAN!
    SiteAdvisorUSiteAdv.exeRelated to SiteAdvisor from McAfee SiteAdvisor warns you before you interact with a dangerous Web site. Note: Located in C:\Program Files\SiteAdvisor\...\
    SystemServiceXnavchk.exePremium rate adult material dialer
    Slayhacker734Xslay7383.exeAdded by the Troj/SikBot-A TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    SManagerXsmanager.7.exeAdded by the Troj/DwnLdr-GVG Trojan
    SyswindowXSyswindow.exeAdded by the COW VIRUS!
    svrrunXsvrrun.exeadware hailing from Deskwizz.com
    screxe?scruser2k.exe??
    Sygate Personal 3Xsvrv.exeAdded by the W32/RBOT-XD WORM!
    SpoolsvXSpoolsv.exeAdded by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
    System ServicesXsvcsenes.exeAdded by a variant of the WIN32.RBOT WORM!
    SmartalecUpcaccel.exeSmartalec PC Accelerator - system optimization utility
    sys************* ( * = random digit)Xsys*************.exe, ( * = random,digit) WINBO adware component
    SVCHOSTXSVCH0ST.EXEAdded by the Troj/MMThief-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    StratasXggfig.exeAdded by the OPANKI.W WORM! Read the link, rootkit type stealth involved.
    SysDesktopXfswanQQ.exeAdded by the Troj/QQSend-A TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SYSTEMSars32Xcsrss.exeAdded by the AHLEM.A VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling
    startkeyXRunWinRaR.exeAdded by a variant of Bifrose-LV as reported by VirusTotal. TROJAN! Note: Located in C:\Windows\
    SfKg6wIPX(RandomName).exeIdentified as a variant the Trojan-Downloader.Win32.Agent TROJAN! Note: Located in %AppData%\Microsoft\Windows\ Note: Use SDFix under supervision.
    SndcompatXSndcompat.exeAdded by the GEMA TROJAN!
    SunJavaUpdateSchedXscvhost.exeAdded by the W32/SDBOT-AVX WORM!
    spolsvr2Xspolsvr2.exeAdded by the Win32/Evilsock.10 TROJAN! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    SpyGuarderXspyguarder.exeAdded by the SpyGuarder rogue anti-spyware program. Note: Located in \%userprofile%\ Note: Use SDFix under supervision.
    Spyware NukerUswn2.exeA "spyware removal program" by TrekBlue, Previously found to be of dubious repute. SpywareWarrior_List It was delisted. Make sure you have the latest version
    System service62Xpokapoka63.exe EliteBar adware component
    snpstd?vsnpstd.exe Sonix PC Camera Monitor MFC Application - what does it do and is it required?
    ShellXtaskmrg.exeAdded by the Troj/Bancban-FT TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SK51USK51.EXE SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!
    supernews12Xnewsd32.exeAdware, also detected as the TROJ/DLOADER-JN TROJAN!
    SAHBundleXshop1003.exe ShopAtHomeSelect adware
    SVCH ServiceXsvch32.pifAdded by the W32/Rbot-ASZ or W32/Rbot-ASY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ServicesLogXccapp32.exeAdded by the W32/Rbot-AMX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    SystemTrayXSystemTray.exe Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray ( SysTray.exe )
    spoolvsXspoolvs.exeIdentified by Kaspersky antivirus as a variant of the Trojan.Win32.Qhost.aes malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    strmsnnrsXmsnmcgrs.exeAdded by the TROJ/RBOT-ACT TROJAN!
    Service ProcessXSVCHOST.EXEAdded by the DARKER VIRUS! Note - not the valid svchost.exe as described here. Located in %Windir% not %Sysdir%
    System Messaging QueueXSMCSS.EXEAdded by a variant of the WIN32.RBOT WORM!
    Switchboard.com ToolbarNAtHoc.exeToolbar for the on-line version of Yellow Pages in the US - Switchboard.com
    sssasasb32Xsssasasb32.exeAdded by the WIN32.TACTSLAY.F TROJAN!
    SpySpotter System DefenderXDefender.exeAdded by SpySpotter Spyware remover of dubious repute. Aggressive/deceptive advertising. Note: Located in \%Program Files%\SpySpotter3\
    svchostXsvchost.exeAdded by the MORB or TARNO VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32
    SuiteXSuiteOffices.exe,/cleandbAdded by the Lazar TROJAN!
    SysMonXwowexece.exeAdded by the Troj/Mulan-A TROJAN!
    System ServicesXconnection.exeAdded by an unidentified WORM or TROJAN!
    Server BackboneXserver05.exeAdded by the W32/RBOT-ZM WORM! Read the link, keylogger/password stealing trojan(s) involved.
    SpyCleanXSpyClean.exeAdded by Netcom3_Cleaner a rogue antispyware program that displays legitimate files and Windows Registry entries as malware on your computer. Note: Located in \%Program Files%\ Note: Use Malwarebytes' http://www.malwarebytes.org/rogueremover.php RogueRemover tool.
    SXsvhost.exeAdded by the AGOBOT-LN WORM!
    svctaskXsvctask.exeAdded by the Troj/Chuckyb-A TROJAN!
    StatusClientNStatusClient.exePart of Hewlett Packard network printer drivers
    Sdk**32.exe (* = random char)XSdk**32.exe (*,= random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    SpywareQuakeXSpywareQuake.exeBogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN!
    System32DllXDLL32SYS.EXEAdded by a W32/Spybot-CZ worm infection
    SpyCop ScanCheckUMAIN.EXESpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
    SVGA AdapterXsvghost.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    sms_msn40Xsms_msn40.exeAdded by an unknown WORM or TROJAN infection.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer