PC Review Startup Files Database Letter num

Startup Files Database

[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]

Yes
No
Users Choice
Warning
Unknown
Normally leave to run at startup Not Required, often infrequently run tasks that can be run manually. Depends if the task is deemed necessary Typically viruses, spyware, adware and resource hogs An unknown item
Search by name/file :    

Required Process Name / Details Startup File
Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field
system32.exe
Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field
pathex.exe
Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
svchost.exe
Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
MSPF.EXE
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
dllvirtual.exe
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
dllvirtual.dll
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
dllvirtual.js
Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field
ajsha5.exe
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
pgaccount.exe
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks
procguard.exe
Part of AVG Anti-Spyware from Grisoft
avgas.exe
Part of Ewido anti-spyware
ewido.exe
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!
winrecon.exe
Connection manager for the EnterNet ISP. You can also use RASPPOE
Enternet.exe
Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
$sys$xp.exe
Added by the WELOMOCH TROJAN!
$sys$sonyTimer.exe
Added by the WELOMOCH TROJAN!
$sys$sos$sys$.exe
Added by the WELOMOCH TROJAN!
$sys$WeLoveMcCOL.exe
Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
$sys$drv.exe
Added by the WELOMOCH TROJAN!
$sys$sonyTimer.exe
Added by the WELOMOCH TROJAN!
$sys$sos$sys$.exe
Added by the WELOMOCH TROJAN!
$sys$WeLoveMcCOL.exe
Added by the WELOMOCH TROJAN!
$sys$sonyTimer.exe
Added by the WELOMOCH TROJAN!
$sys$sos$sys$.exe
Added by the WELOMOCH TROJAN!
$sys$WeLoveMcCOL.exe
Volumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"
volumouse.exe
Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
IEXPLORE.EXE
Possibly related to C-Media Mixer Control panel?
%cmpmixstr%
012.Net.il Israeli ISP software front-end
fts.exe
012.Net.il Israeli ISP dial-up software
FWPortal.exe
1776 Internet US ISP software ISP software front-end
fts.exe
1776 Internet US ISP dial-up software
FWPortal.exe
Barak013 Israeli ISP software front-end
fts.exe
Barak013 Israeli ISP dial-up software
FWPortal.exe
Friendly ISP software front-end
fts.exe
Homepage hijacker, see here (* = any digit)
winSOCKS.exe
Homepage hijacker, see here (* = any digit)
win32API.exe
Added by the BLACKMAL WORM!
[random filename].exe
Added by the HESIVE.B TROJAN!
rundll32.exe [path] Zykheptd.dll
Added by the DOWNLD-ABF TROJAN!
5640.exe
Added by the ASSIRAL.B WORM!
SP00Lsv32.pif
Added by the POPS WORM!
janis.com
Added by the STMU TROJAN!
ctxma.exe
Added by the STMU TROJAN!
cxma.exe
Added by the STMU TROJAN!
wstcl.exe
Added by the STMU TROJAN!
wucxt.exe
Added by the STMU TROJAN!
wuytc.exe
Virtumondo adware, also known as the VUNDO TROJAN!
[random filename]
Detected by F-secure as the OBFUSCATED.GP TROJAN!
aecache.exe
Added by the SDBOT.BRO WORM!
secctr.exe
Windows ME default for System Restore. Do NOT disable!
statemgr.exe
Added by the RBOT-QU WORM!
wrauclt.exe
Added by the RBOT-PG WORM!
wuanclt.exe
Added by the SPYBOT.HUR WORM!
wuaucrlt.exe
Added by the RBOT-PO WORM!
wuraclt.exe
Added by the RBOT-SY WORM!
wurauclt.exe
Added by the SPYBOT.PR WORM!
wsctl.exe
Added by the SDBOT.AVD WORM!
wkmst.exe
Added by the RBOT.AOS WORM!
wscxt.exe
Added by a variant of the RBOT WORM!
waurclt.exe
Added by the KEDEBE-B WORM!
[filename]
Added by the AGENT-TH WORM!
systemupd.exe
Added by the VUNDO TROJAN!
[trojan path] ren time:[random number]
Added by the GARGAFX TROJAN!
winstats.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
w****.exe [* = random char]
Suspected malware as it appears in 3 different registry locations - see here
wininfo.exe
Internet Security Suite used by ISPs to protect customers against many attacks
ZkRunOnceR.exe
..
Added by the DLOADR-ASH TROJAN!
ABC2007.exe
Added by the WEBUS.C TROJAN!
lassa.exe
Added by the WEBUS.D TROJAN!
lsvchost.exe
Added by the CR TROJAN!
lsvchost.exe
Added by the CMQ TROJAN!
svhost.exe
Added by the ALLOCUP.A WORM!
msveup.exe
Added by the DDOS_BOXED.X TROJAN!
mssecure.exe
??
sysmon32.exe
Added by the BOXED-H TROJAN!
rchost.exe
Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
smss.exe
Added by the BOXED.CG TROJAN!
smssb.exe
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
services.exe
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winlogon.exe
Smitfraud variant
N/A
Added by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
CSRSS.EXE
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
csrss.exe
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
lsass.exe
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
csrss.exe
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
lsass.exe
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
N/A
0
PrivateEye surveillance software. Uninstall this software unless you put it there yourself
pit.exe
LZIO.com adware downloader
hpdllhost.exe
Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
000StTHK.exe
Added by the BANCBAN-EC TROJAN!
0050726-007-i32-1.exe
Related to Advanced Desktop Shield
desksaver.exe
Related to Advanced Desktop Shield
desksaver.exe
PC Tools Firewall Plus - "powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network"
FirewallGUI.exe
Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
TCrdMain.exe
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
00THotKey.exe
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev
system32THotkey.exe
Anti-dialer program (Germany)
WARN0190.EXE
Anti-dialer program (Germany)
WARN0900.EXE
Added by the COSIAM-H TROJAN!
0mcamcap.exe
Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o"
*****.exe [* = random char]
1
Added by the ESTEEMS TROJAN!
1.exe
1
Added by the BANCOS.V TROJAN!
lsass.scr
1
Added by the BANCOS.X TROJAN!
svchost.scr
Added by the IC TROJAN!
1111swapmgr.exe
Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number
rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl
12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup"
12backup.exe
12Ghosts Clip - "Screen shots made easy"
12clip.exe
12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see"
12window.exe
12Ghosts Popup-Killer
12popup.exe
12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons"
12autosl.exe
12Ghosts SetColor - "Change your desktop icon text colors, also to transparent"
12color.exe
12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones"
12showtime.exe
12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet"
12sync.exe
12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)"
12tower.exe
12Ghosts TrayProtect - "Hide tray icons, restore after a crash"
12srvc.exe
12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files"
12wash.exe
??
N/A
NCase adware
180adsolution.exe
NCase adware
180ax.exe
180Solutions adware related
stubinstaller****.exe [* = digit]
180Solutions adware related
[path to trojan]
180Solutions adware related
******.tmp [* = random digit/char]
Added by the DLOADR-AXU TROJAN!
1916435341.exe
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
196_150_ni.exe
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
197_150_ni_3.exe
HP utility for monitoring when and how many recoveries have been done
hpdrv.exe
Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
TrayMonitor.exe
Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
mcpserver.exe
For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
TrayServer.exe
??
NETMAIL.EXE
Adult content dialler
1on1.exe
SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
SpyAgent4.exe
1u7
Added by the MURBAC-A TROJAN!
1u7.exe
SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself!
SpyBuddy.exe
Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!
Keyloggerpro.exe
WebMailSpy spyware
WebMailSpy.exe
2020Search Toolbar
mssvr.exe
252
Added by the LEGMIR-AT TROJAN!
winmgr.exe
27
Added by the SLSORVE-A TROJAN!
slsorve.exe
27
Added by the SLSORVE-D TROJAN!
csrss32.exe
27
Added by the SLSORVE-E TROJAN!
msm32.exe
2Search adware
main.exe
Added by the RANKY.L TROJAN!
[path to file]
2Wire Homeportal user interface
2portalmon.exe
Added by the DERDERO.A WORM!
thunk32.exe
333
Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory
svchost.exe
Added by the SDBOT-DEN WORM!
AutomaticUpdates.exe
Seems to be associated with software by Resplendence SP ?
Ezg1q5.exe
3Com WinModem driver. See here for more WinModem information
3cmlink.exe 3cpipe-3c1807pd
US Robotics Modem driver
3capplnk.exe
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
3CDMINIC.EXE
Required for a US Robotics WinModem as it provides the link to Windows - won't work without it
3cmcnkw.exe
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information
3CmlinkW.exe
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
3CDMINIC.EXE
Modem driver files from US Robotics
USRmlnkA.exe
Added by the JERMY.A WORM!
3D Text.scr
Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games
3DeepCTL.EXE
Added by the GIBE WORM!
GFXACC.EXE
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
3dfxMan.exe
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
3dfxCmn.dll
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
3dfxv2ps.dll
3DLabs graphics driver related. System Tray access to display settings?
3DLman.exe
Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
3dldemon.exe
Dritek System Inc. 3D Mouse driver
3DMouse.EXE
Added by the RIADOS-A TROJAN!
3d_sound.exe
Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
3qdctl.exe
Monitors status of the disk array on 3ware IDE RAID controllers
3dm.exe
Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder
explorer.exe
Added by the SDBOT-DEV WORM!
netdll32.exe
Added by the DLOADR-WZ TROJAN!
4da92ad5.exe
4oD
Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops
KHost.exe
Added by the OPASERV.AI WORM!
Natal!.pif
Adult content dialler
members-area.exe
Adult content pop-up dialler. Removal instructions here
5-2-46-112.exe
Added by the LINEAGE-S TROJAN!
grepclient1.exe
Added by the LITEBOT-C TROJAN!
[path to trojan]
ClearSearch adware
5whgue21.exe
666
Added by the PIPES TROJAN!
Ska.exe
678
Added by the SLSORVE-B TROJAN!
lsas32.exe
Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the system32 folder
z****.exe 9idf
Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled
Monitor.exe
BrowserAid/BrowserPal foistware
rundll32.exe D0CE0C16B1, D0CE0C16B1
9m
Added by the LEGMIR-AQK TROJAN!
winlog0n.exe
Allied Telesyn AT series router/modem related - apparently required
9xadiras.exe
Added by the NETSKY.M WORM!
AVprotect9x.exe
Added by the PWSLEGMIR.E TROJAN!
[filename]
Added by the AGOBOT-OV WORM where ? is a random character
?nksvc32.exe
@
Added by the SEEKER.K TROJAN!
regedit -s ..win.dll
One-click activated browsing toolbar used by various web-sites. See here for more info
AtHoc.exe
Registration reminder for @loha@home E-mail utility
reminder.exe
Adult content dialler
@tour_ww[1].exe
PurityScan/Clickspring adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder
nslookup.exe
Added by the BANCSADE-A TROJAN!
[path to file]
Added by the OPOSSUM-A WORM! The decimal number can be anything, eg, 0.12345678
[path to worm]
Added by the DREMN TROJAN!
DrWatson32.exe
Added by the NETHIEF-N TROJAN!
System.exe
Added by the LEMOOR-C WORM!
[path to worm]
Added by the LEMOOR.A WORM! where "x" represents 3 or 4
[path to worm]
Added by the WAXPOW WORM!
App.exe
Added by the SOUTHGHOST WORM!
Regsrv32.com
Added by the BANKER-CC TROJAN!
svchost.scr
Added by the BANCBAN-CX TROJAN!
svchost.scr
Added by the BANCBAN-HM TROJAN!
xphost.scr
Adsrv.com/IeDriver adware variant
avifile5.exe
Adsrv.com/IeDriver adware variant
bootvid4.exe
Adsrv.com/IeDriver adware variant
browser8.exe
Adsrv.com/IeDriver adware variant
atitvo32.exe
Adsrv.com/IeDriver adware variant
autodisc.exe
Adsrv.com/IeDriver adware variant
cabview1.exe
Adsrv.com/IeDriver adware variant
advpack1.exe
Adsrv.com/IeDriver adware variant
batmeter.exe
Adsrv.com/IeDriver adware variant
bidispl2.exe
Adsrv.com/IeDriver adware variant
asferror.exe
Adsrv.com/IeDriver adware variant
catsrvps.exe
Adsrv.com/IeDriver adware variant
admparse.exe
Adsrv.com/IeDriver adware variant
audiosrv.exe
Adsrv.com/IeDriver adware variant
bootvid2.exe
Adsrv.com/IeDriver adware variant
cmpbk321.exe
Added by the OPTIXP-N TROJAN! Note - this trojan file is found in the System (9x/Me) or System32 (NT/2K/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted
securewinload32x.exe
Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!
rsbmsc.exe
QuickLinks adware
slk8x2peu.exe
MediaMotor adware
eee2.exe
Added by the SDBOT.N TROJAN!
Svchosts.exe
Added by an unidentified VIRUS, WORM or TROJAN!
wincpu.exe
PurityScan/Clickspring adware
m?dtc.exe
PurityScan/Clickspring adware. Note - do not confuse with the Microsoft utility of the same name as described here
ping.exe
AproposMedia adware
CXTPLS_LOADER.EXE
PurityScan/Clickspring adware
??plorer.exe
PurityScan/Clickspring adware
?hkdsk.exe
PurityScan/Clickspring adware
?hkntfs.exe
PurityScan/Clickspring adware
l?gonui.exe
PurityScan/Clickspring adware
m?iexec.exe
PurityScan/Clickspring adware
r?gsvr32.exe
PurityScan/Clickspring adware
t?skmgr.exe
PurityScan/Clickspring adware
w?auboot.exe
PurityScan/Clickspring adware
w?auclt.exe
PurityScan/Clickspring adware
w?crtupd.exe
PurityScan/Clickspring adware
w?wexec.exe
PurityScan/Clickspring adware
??erinit.exe
PurityScan/Clickspring adware
d?dplay.exe
PurityScan/Clickspring adware
n?tepad.exe
PurityScan/Clickspring adware
??chost.exe
PurityScan/Clickspring adware
??oolsv.exe
PurityScan/Clickspring adware
??xplore.exe
PurityScan/Clickspring adware
r?ndll32.exe
PurityScan/Clickspring adware
se?vices.exe
PurityScan/Clickspring adware
w?nlogon.exe
PurityScan/Clickspring adware
w?nword.exe
PurityScan/Clickspring adware
??anregw.exe
PurityScan/Clickspring adware
?ttrib.exe
PurityScan/Clickspring adware
j?vaw.exe
PurityScan/Clickspring adware
l?ass.exe
PurityScan/Clickspring adware
m?config.exe
PurityScan/Clickspring adware
n?lookup.exe
PurityScan/Clickspring adware
n?pdb.exe
PurityScan/Clickspring adware
??ool32.exe
PurityScan/Clickspring adware
??rss.exe
PurityScan/Clickspring adware
??rvices.exe
PurityScan/Clickspring adware
?ti2evxx.exe
PurityScan/Clickspring adware. Unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2K/NT always be located in the WinntSystem32 or WindowsSystem32 folder, and ought moreover NOT to figure among the startups!
chkdsk.exe
PurityScan/Clickspring adware
d?xplore.exe
PurityScan/Clickspring adware
dvdplay.exe
PurityScan/Clickspring adware. Do not confuse with the legitimate Microsoft Printer Spooler Service (spoolsv.exe)
spoolsv.exe
PurityScan/Clickspring adware
w?aclt.exe
PurityScan/Clickspring adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe)
wucrtupd.exe
Added by the BANCOS-DR TROJAN!
charmapnt.exe
PurityScan/Clickspring adware
n?tdde.exe
PurityScan/Clickspring adware
r?gedit.exe
PurityScan/Clickspring adware
r?ndll.exe
PurityScan/Clickspring adware
scanregw.exe
PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup!
wuauboot.exe
PurityScan/Clickspring adware
w?nspool.exe
Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder of the Winnt or Windows folder
svchost.exe
SearchNet adware
[random name].dll
Added by the ULPM.BD TROJAN!
iexpl0ra.exe
Added by the GAMPASS-L TROJAN!
rundl13a.exe
Added by the LEGMIR-AQM TROJAN!
Servere.exe
Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one copies it's self under 9 additional file names in the System (9x/Me) or System32 (NT/2K/XP) folder
explorer.exe
Added by the ANTINNY-L WORM!
_autorun.exe
Added by the ANTINNY-L WORM!
_cfg.exe
Added by the ANTINNY-L WORM!
_config.exe
Added by the ANTINNY-L WORM!
_env.exe
Added by the ANTINNY-L WORM!
_loader.exe
Added by the ANTINNY-L WORM!
_login.exe
Added by the ANTINNY-L WORM!
_setup.exe
Added by the ANTINNY-L WORM!
_start.exe
Added by the BANCBAN-CW TROJAN!
lsass.scr
Added by the BANCBAN-CY TROJAN!
svchost.scr
Added by the BANCBAN-FS TROJAN!
Install.exe
Added by the BANCBAN-CL TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
svchost.exe
Added by the MOSUCK-H TROJAN!
[path to trojan]
Added by the WEBDOR.Y TROJAN
qtsks.exe
Elf is a hacker program, tied to a trojan server
elf.exe
Added by the FORBOT-AK WORM!
crsrs.exe
Added by any of a number of WORM or TROJAN variants
Windows32.exe
Added by the RBOT-NI WORM!
bling.exe
Added by a variant of the RBOT WORM!
mediaplayer32.exe
Added by an unidentified WORM or TROJAN!
winlogon32.exe
Added by a variant of the RBOT WORM!
svchostss.exe
Added by the RBOT-DQ WORM!
win32snd.exe
Premium rate adult content dialler
shch.exe
Wareout - malware masquerading as a spyware and dialer remover
PasswdMon.exe
Wareout - malware masquerading as a spyware and dialer remover
runload32.exe
Adware - detected by Kaspersky as the SMALL.ALW TROJAN!
dstart2.exe
Added by a variant of the AGENT.AH TROJAN!
msdos32.exe
Added by an unidentified TROJAN!
sitebar.exe
Added by a NTROOTKIT TROJAN variant!
backorif.exe
Added by a NTROOTKIT TROJAN variant!
bhoserv.exe
Added by a variant of the SDBOT WORM!
driver32.exe
Added by a NTROOTKIT TROJAN variant!
hyandex.exe
Added by a NTROOTKIT TROJAN variant!
Uint32.exe
Added by a NTROOTKIT TROJAN variant!
Uint32.exe
Wareout - malware masquerading as a spyware and dialer remover
_ctcp.exe
Wareout - malware masquerading as a spyware and dialer remover
10010.exe
Wareout - malware masquerading as a spyware and dialer remover
321102.exe
Wareout - malware masquerading as a spyware and dialer remover
34763.exe
Wareout - malware masquerading as a spyware and dialer remover
abrek.exe
Wareout - malware masquerading as a spyware and dialer remover
ActionScr.exe
Wareout - malware masquerading as a spyware and dialer remover
AliceSD.exe
Wareout - malware masquerading as a spyware and dialer remover
AppMasterCenter.exe
Wareout - malware masquerading as a spyware and dialer remover
atl_helper.exe
Wareout - malware masquerading as a spyware and dialer remover
ATLIEHELPER.exe
Wareout - malware masquerading as a spyware and dialer remover
avpmondll.exe
Wareout - malware masquerading as a spyware and dialer remover
awinrar.exe
Wareout - malware masquerading as a spyware and dialer remover
backd.exe
Wareout - malware masquerading as a spyware and dialer remover
backorif.exe
Wareout - malware masquerading as a spyware and dialer remover
barint.exe
Wareout - malware masquerading as a spyware and dialer remover
bhoserv.exe
Wareout - malware masquerading as a spyware and dialer remover
bingo9.exe
Wareout - malware masquerading as a spyware and dialer remover
bnui.exe
Wareout - malware masquerading as a spyware and dialer remover
Bogobot.exe
Wareout - malware masquerading as a spyware and dialer remover
borlandg.exe
Wareout - malware masquerading as a spyware and dialer remover
BoundRec.exe
Wareout - malware masquerading as a spyware and dialer remover
br0ken.exe
Wareout - malware masquerading as a spyware and dialer remover
Brong32.exe
Wareout - malware masquerading as a spyware and dialer remover
clamav.exe
Wareout - malware masquerading as a spyware and dialer remover
cmon14.exe
Wareout - malware masquerading as a spyware and dialer remover
cnftips.exe
Wareout - malware masquerading as a spyware and dialer remover
control64.exe
Wareout - malware masquerading as a spyware and dialer remover
corrida.exe
Wareout - malware masquerading as a spyware and dialer remover
CToolBar.exe
Wareout - malware masquerading as a spyware and dialer remover
DCC_send.exe
Wareout - malware masquerading as a spyware and dialer remover
defect08.exe
Wareout - malware masquerading as a spyware and dialer remover
Dest068.exe
Wareout - malware masquerading as a spyware and dialer remover
dialer423.exe
Wareout - malware masquerading as a spyware and dialer remover
diskserv.exe
Wareout - malware masquerading as a spyware and dialer remover
driver64.exe
Wareout - malware masquerading as a spyware and dialer remover
DTOURS.exe
Wareout - malware masquerading as a spyware and dialer remover
ERTYDF.exe
Wareout - malware masquerading as a spyware and dialer remover
ExchangeMaster.exe
Wareout - malware masquerading as a spyware and dialer remover
EXE32EXE.exe
Wareout - malware masquerading as a spyware and dialer remover
expoler.exe
Wareout - malware masquerading as a spyware and dialer remover
FLKPT.exe
Wareout - malware masquerading as a spyware and dialer remover
forces_elite.exe
Wareout - malware masquerading as a spyware and dialer remover
ftbar.exe
Wareout - malware masquerading as a spyware and dialer remover
gabber.exe
Wareout - malware masquerading as a spyware and dialer remover
hyandex.exe
Wareout - malware masquerading as a spyware and dialer remover
iehelper.exe
Wareout - malware masquerading as a spyware and dialer remover
iesetupdll.exe
Wareout - malware masquerading as a spyware and dialer remover
init32.exe
Wareout - malware masquerading as a spyware and dialer remover
InpriseMon.exe
Wareout - malware masquerading as a spyware and dialer remover
install2.exe
Wareout - malware masquerading as a spyware and dialer remover
jopplerg.exe
Wareout - malware masquerading as a spyware and dialer remover
Kargo.exe
Wareout - malware masquerading as a spyware and dialer remover
keybdll.exe
Wareout - malware masquerading as a spyware and dialer remover
KeywordFinder.exe
Wareout - malware masquerading as a spyware and dialer remover
killall.exe
Wareout - malware masquerading as a spyware and dialer remover
LOPTCON.exe
Wareout - malware masquerading as a spyware and dialer remover
media64.exe
Wareout - malware masquerading as a spyware and dialer remover
MNTP.exe
Wareout - malware masquerading as a spyware and dialer remover
MON76234.exe
Wareout - malware masquerading as a spyware and dialer remover
moniter.exe
Wareout - malware masquerading as a spyware and dialer remover
mozilla-text.exe
Wareout - malware masquerading as a spyware and dialer remover
msag.exe
Wareout - malware masquerading as a spyware and dialer remover
ms-its.exe
Wareout - malware masquerading as a spyware and dialer remover
MsNetHelper.exe
Wareout - malware masquerading as a spyware and dialer remover
new32.exe
Wareout - malware masquerading as a spyware and dialer remover
newbreed.exe
Wareout - malware masquerading as a spyware and dialer remover
nmdllw.exe
Wareout - malware masquerading as a spyware and dialer remover
NopeZ.exe
Wareout - malware masquerading as a spyware and dialer remover
NsCplTray.exe
Wareout - malware masquerading as a spyware and dialer remover
NSYSCPLSTR.exe
Wareout - malware masquerading as a spyware and dialer remover
NukeSpan.exe
Wareout - malware masquerading as a spyware and dialer remover
openstre.exe
Wareout - malware masquerading as a spyware and dialer remover
panel_its.exe
Wareout - malware masquerading as a spyware and dialer remover
ParisM.exe
Wareout - malware masquerading as a spyware and dialer remover
pizda.exe
Wareout - malware masquerading as a spyware and dialer remover
powerdll.exe
Wareout - malware masquerading as a spyware and dialer remover
PrcIdle.exe
Wareout - malware masquerading as a spyware and dialer remover
prcmon.exe
Wareout - malware masquerading as a spyware and dialer remover
Preliminary.exe
Wareout - malware masquerading as a spyware and dialer remover
prgsys0984.exe
Wareout - malware masquerading as a spyware and dialer remover
progmen.exe
Wareout - malware masquerading as a spyware and dialer remover
qwe.exe
Wareout - malware masquerading as a spyware and dialer remover
RtlFindVal.exe
Wareout - malware masquerading as a spyware and dialer remover
SAPSTR.exe
Wareout - malware masquerading as a spyware and dialer remover
sbin.exe
Wareout - malware masquerading as a spyware and dialer remover
scanSYS.exe
Wareout - malware masquerading as a spyware and dialer remover
Serviceprocess.exe
Wareout - malware masquerading as a spyware and dialer remover
SetupExeDll.exe
Wareout - malware masquerading as a spyware and dialer remover
Shaitan1678.exe
Wareout - malware masquerading as a spyware and dialer remover
slamm.exe
Wareout - malware masquerading as a spyware and dialer remover
sound64.exe
Wareout - malware masquerading as a spyware and dialer remover
SpyElim.exe
Wareout - malware masquerading as a spyware and dialer remover
srbho.exe
Wareout - malware masquerading as a spyware and dialer remover
ssweeper.exe
Wareout - malware masquerading as a spyware and dialer remover
StartCpl.exe
Wareout - malware masquerading as a spyware and dialer remover
startman.exe
Wareout - malware masquerading as a spyware and dialer remover
StatusCheck.exe
Wareout - malware masquerading as a spyware and dialer remover
stuffmon.exe
Wareout - malware masquerading as a spyware and dialer remover
sysconf16.exe
Wareout - malware masquerading as a spyware and dialer remover
SysEntry.exe
Wareout - malware masquerading as a spyware and dialer remover
sysmon12.exe
Wareout - malware masquerading as a spyware and dialer remover
syspanel.exe
Wareout - malware masquerading as a spyware and dialer remover
SysSupport.exe
Wareout - malware masquerading as a spyware and dialer remover
SYSTRAV.exe
Wareout - malware masquerading as a spyware and dialer remover
TemplateDongle.exe
Wareout - malware masquerading as a spyware and dialer remover
teqq32.exe
Wareout - malware masquerading as a spyware and dialer remover
Testimonials.exe
Wareout - malware masquerading as a spyware and dialer remover
TForm1.exe
Wareout - malware masquerading as a spyware and dialer remover
TorontoMail.exe
Wareout - malware masquerading as a spyware and dialer remover
Trayz.exe
Wareout - malware masquerading as a spyware and dialer remover
TRPT.exe
Wareout - malware masquerading as a spyware and dialer remover
trycrt.exe
Wareout - malware masquerading as a spyware and dialer remover
typeconf.exe
Wareout - malware masquerading as a spyware and dialer remover
Uint32.exe
Wareout - malware masquerading as a spyware and dialer remover
uio.exe
Wareout - malware masquerading as a spyware and dialer remover
UserSp1.exe
Wareout - malware masquerading as a spyware and dialer remover
utsgmon.exe
Wareout - malware masquerading as a spyware and dialer remover
vxdman.exe
Wareout - malware masquerading as a spyware and dialer remover
WhatsNewBot.exe
Wareout - malware masquerading as a spyware and dialer remover
WinInitDll.exe
Wareout - malware masquerading as a spyware and dialer remover
wormexe.exe
Wareout - malware masquerading as a spyware and dialer remover
WTFCTF.exe
Wareout - malware masquerading as a spyware and dialer remover
XTermInit.exe
Wareout - malware masquerading as a spyware and dialer remover
xwiz.exe
Wareout - malware masquerading as a spyware and dialer remover
xxtoolbar.exe
Wareout - malware masquerading as a spyware and dialer remover
zantu.exe
Wareout - malware masquerading as a spyware and dialer remover
zxc.exe
Wareout - malware masquerading as a spyware and dialer remover
ABCXYZ.exe
Wareout - malware masquerading as a spyware and dialer remover
dePloy.exe
Wareout - malware masquerading as a spyware and dialer remover
JAguAr.exe
MediaMotor adware
80d0.exe
MediaMotor adware
exe81.exe
MediaMotor adware
exe82.exe
Wareout - malware masquerading as a spyware and dialer remover
MSTCPDLL.exe
MediaMotor adware
seli.exe
Lycos SideSearch/Fastfind.org adware
tools.exe
Added by the GAOBOT.GEN!POLY WORM!
~`d}qzxu3zYF
Part of McAfee AntiSpyware
MssCli.exe
Part of McAfee AntiSpyware
masalert.exe
Added by the SMALL.SD TROJAN!
nmmst.exe
Added by the SMALL-DT TROJAN!
nmstt.exe
Added by a variant of the SMALL-DT downloader TROJAN
msmsgrxp.exe
Added by the SMALL-EB TROJAN!
msmsgr2.exe
Added by the SPEXTA-C TROJAN!
_explore.exe
Added by the ZAFI.B WORM!
[path to file]
Added by a variant of the DWNLDR-FTB TROJAN!
_mzu_stonedrv2.exe
Added by the DWNLDR-FTB TROJAN!
_mzu_stonedrv3.exe
Added by a variant of the FTB TROJAN!
_mzu_stonedrv7.exe
Added by the DLOADER-JV TROJAN!
_Ntrdlhost.exe
Added by the DLOADER-JV TROJAN!
_ntrrs.exe
Added by the AGENT.NAK TROJAN!
_pnd_*****.exe [* = random char/digit]
Added by the BESAM WORM!
Setv.com
Added by the ERKEZ.C WORM!
svchost.com
Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder
services.exe
Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a addinsexplorer subfolder of the Winnt or Windows folder
csrss.exe
Added by the LINEAGE-Z TROJAN!
_svchost_.exe
Added by the TDISERV.A WORM!
_tdicli_.exe
Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC"
winadm.exe
Added by the SOBER.V WORM!
services.exe
Added by the SOBER.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "PoolData" subfolder of the Windows or Winnt folder
services.exe
Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder
services.exe
Added by the DLOADER-XX TROJAN!
winexec.exe
Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder
services.exe
Added by the SOBER.K TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder
smss.exe
Disconnects and redials an ISP modem to an adult content site
_x-Finder.exe
Zenosearch adware, where ** are random characters
mrdsregp.exe
Google Gmail Notifier. Alerts you when you have new Gmail messages
gnotify.exe
Scheduler for CyberLink PowerBackup - archiving/backup utility
PBKScheduler.exe
BrowserAid/BrowserPal foistware
rundll32.exe [path] stlb2.dll, DllRunMain
ZenoSearch adware
dwdsregt.exe
BrowserAid/BrowserPal foistware
rundll32.exe stlbdist.dll, DllRunMain
BrowserAid/BrowserPal foistware
rundll32.exe stlbupdt.DLL, DllRunMain
ZenoSearch adware
omdsregk.exe
Added by the SMALL-AQ TROJAN!
[path to svchost.exe]
Added by FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder
services.exe
Added by the SMALL-EP TROJAN!
[path to trojan]
Zeno Think-Adz adware
thinksnet.exe
ZenoSearch adware
dwdsregt.exe
BrowserAid/BrowserPal foistware
rundll32.exe E6F1873B.DLL, D9EBC318C
æTorrent - BitTorrent client for Windows sporting a very small footprint. It was designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clients
utorrent.exe

 

Powered By Pac's Startup list