Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X startkey explore32.exe"Added by the BDOOR-MT BACKDOOR!"
X startkey CKOTS.exe"Added by the BIFROSE-HM TROJAN!"
X StartKey pligde.exe"Added by the BIFROSE.E TROJAN!"
X startkey RunWinRaR.exeAdded by a variant of the BIFROSE-LV TROJAN!
X startkey Mysia.exeAdded by the CEP TROJAN!
X startkey explorer.exe"Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X startkey furzi.exe"Added by the BIFROSE-OK TROJAN!"
X startkey krnl.exe"Added by the BIFROSE-S TROJAN!"
X startkey royale.exe"Added by a variant of the SDBOT WORM!"
X startkey rtfmsv.exe"Added by the EDEPOL-C TROJAN!"
X startkey scvhost.exe"Added by the BIFROSE-PM TROJAN!"
X startkey server.exe"Added by the BIFROSE-DB TROJAN!"
X startkey win32i.exe"Added by the BIFROSE-R TROJAN!"
X startkey winampXP.exe"Added by the BIFROSE-OY TROJAN!"
X startkey svchost32.exe"Added by a variant of the SDBOT WORM!"
X startkey winlogin.exe"Added by the BIFROSE-PM TROJAN!"
X startkey antivir.exe"Added by the BIFROSE-TO TROJAN!"
X startkey svchost.exe"Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
N startl.exe startl.exe"Lingocom LingoWare - translates any application into your language"
X StartMenu deamon.exe"Added by the TACTSLAY.C TROJAN!"
X StartMenu msgaol.exe"Added by the TACTSLAY.C TROJAN!"
X StartMenu s_menu.exe"Added by the TACTSLAY.C TROJAN!"
X StartMenu browse.exe"Added by the DROWSY-C TROJAN!"
X startpage startpage.exeBrowser hijacker - redirecting to pages2start.com
U STARTPAGE start1.exe"NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder"
U StartSecurDoc SDPin.exe"SecurDoc from WinMagic Inc - ""Provides full disk encryption to protect sensitive information stored on laptops desktops and PDAs"""
U StartStop STARTSTOP.EXE"StartStop from TFI Technology - startup manager"
U StartSurfing STARTS.exe"Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows Mouse Traps Window Resizing and scripts that attempt to record your personal information. Available via Start -> Programs"
N Startup ??Related to an Iomega drive
X Startup WinlogonStartupUnidentified malware
X Startup mirc.exe"Added by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in the Windows or Winnt folder"
X Startup Configuration [six character filename]"Added by the RBOT-ARV WORM!"
X Startup Configuration wztoid.exe"Added by the RBOT-ASD WORM!"
? Startup Launcher GUI GUI.exe"Startup manager?"
U Startup Manager Scanner StartupMonitor.exe"Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans adult-dialers and other scumware"
Y Startup Scan Sensor.EXE"AntiVirus Quick Heal - scheduling agent"
X Startup Update Cvshost.exe"Added by the GAOBOT.AO WORM!"
X StartupBin iwnujdss.exe"Added by the SDBOT-XZ WORM!"
U StartupMonitor StartupMonitor.exe"Mike Lin's StartupMonitor throws up an alert and asks your permission every time any change is made to your start-up configuration either in the registry or start menu"
X Startwd rundll32.exe wd081025.dllHook"Detected by Kaspersky as the AGENT.DE TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wd081025.dll"" file is found in %System%"
X startwin startwin.exe"Added by the ANTIMAN.A WORM!"
X startwindowskeyuser rundle2.exe"Added by the JAVAKILLER TROJAN!"
N Stat 'n' Perf StatnPerf.exe"Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes"
X StatBar STATBAR.exe"StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory CPU uptime and much more). Due to the sheer number of resources (over 60%) consumed by this program it is unsuitable for Windows 9x/Me"
X State Service csrss.exe"Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
U StationPlaylistStudio SPLStudio.exe"StationPlaylist Studio - ""simple to use on-air broadcast playback software for the studio and/or DJ"" for small to medium sized radio broadcasters and internet webcasters"
X Statistics statslist.exe"Added by the OPANKI-S WORM!"
N Status Monitor BrMfcWnd.exeBrother scanner status monitor - can be started manually
U Status Monitor CLJ1500 HPPOUMUI.exeStatus monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status checking ink levels etc
N Status Monitor XE ENGSS.EXEThe Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
? StatusClient StatusClient.exePart of Hewlett Packard network printer drivers
? StatusClient 2.6 StatusClient.exePart of Hewlett Packard network printer drivers
N StatusView StatusView.exe"Status View intra-office messaging"
N Stay Connected! StayCon.exeMore than just a pinger actually simulates online activity. Supports AOL NetZero MSN ATT WorldNet CompuServe and many other ISPs as well. Available via Start -> Programs
U StayAlive sa.exe"StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen keeping your programs running so you can save your work.""
U StayAlive StayAlive.Exe"Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net"
? STBVision STBVisn.exe"Related to the STB Velocity graphics card. What does it do and is it required?"
N STBWEBTV STBWEBTV.EXEUsed to display TV on your PC
X stcinstaller id53.exe"Added by the SCTHOUGHT.L TROJAN!"
X stcloader stcloader.exe"SecondThought adware"
X STCLOA~1 STCLOA~1.EXE"SecondThought adware"
Y STCPO STCPO.exeSophos Sweep antivirus software
X StdAFX stdafx.exe"Added by the DELBOT-AF WORM!"
X stdlib [filename]"Added by the PERDA-E TROJAN!"
Y STDSB STDSB.exeScrollbar driver for notebooks. If taken out of the Startup it will not provide scrolling
U Stealth Anonymizer 2.5 stealth25.exe"Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy"
X stealth.dcom.exe stealth.dcom.exe"Added by the THEALS.A WORM!"
X stealth.ddos.exe stealth.ddos.exe"Added by the THEALS.A WORM!"
X stealth.exe stealth.exe"Added by the THEALS.A WORM!"
X stealth.injector.exe stealth.injector.exe"Added by the THEALS.A WORM!"
X stealth.stat.exe stealth.stat.exe"Added by the THEALS.A WORM!"
X stealth.wm.exe stealth.wm.exe"Added by the THEALS.A WORM!"
X stealth.worm.exe stealth.worm.exe"Added by the THEALS.A WORM!"
N Steam steam.exe"Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life Counter-Strike and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game"
X steam steam.exe"Added by the RBOT-AJT WORM! Note - the file steam.exe will be found in the WindowsSystem folder and is not associated with Valve Software's game client"
X SteFanie SteFanie.vbs"Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders"
? stgclean w32main2.exe"Related to IBM Standard Software Installer. What does it do and is it required?"
N Stickies Stickies.exe"Stickies - ""lets you put yellow sticky notes on your Windows desktop much like the popular Mac OS application. It is very simple very customizable and completely free!"". Available via Start → Programs"
N Sticky Notes stikynot.exeMicrosoft Sticky Notes - virtual sticky notes tool
U Sticky Pad StickyPad.exe"Sticky Pad from Green Eclipse. Place sticky notes on your desktop"
N StickyNote StickyNote.exeUtility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
U StillImageMonitor Stimon.exeStimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example if your scanning device has a scan button it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners
X stisrv stisrv.exe"Added by the RBOT.BQF WORM!"
X stlbdist rundll32exe stlbdist.DLL DllRunMainHijacker pointing to www.searchandclick.com
X stlbupdt rundll32.exe stlbupdt.DLL DllRunMain"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
N STManager drst.exe"Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here"
X stmha wkfxi.js"Added by the SPETH WORM!"
X stonedrv stonedrv.exe"Added by the COSIMA-K TROJAN!"
U StopSignSsTsMon sstsmon.dll VerifyStatus"eAcceleration Stop-Sign security software related. Previously not recommended see here"
U StopSignStatus stopsinfo.dll"eAcceleration Stop-Sign security software related. Previously not recommended see here"
U STOPzilla Stopzilla.exe"StopZilla! - pop-up killer"
U STOPzilla Service SZNTSVC.EXE"StopZilla! - pop-up killer"
U StorageGuard sgtray.exe"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop) Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups"
X StorageProtector SysRep.exe"StorageProtector misleading security software - not recommended see here"
U StormCodec_Helper StormSet.exe"Storm Codec is a codec pack for Windows"
? STPMGR STPMGR.EXE"Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs"
X stratas xmconfig.exe"Added by the RBOT-AHR WORM!"
X stratas lockx.exe"Added by the SDBOT-ADD WORM!"
X Stratas ggfig.exe"Added by the OPANKI.W WORM!"
X StreamAppliance wuauclt14.exe"Added by the RBOT-GMB WORM!"
X StreamAppliance wuauclt16.exe"Added by the RBOT-GME WORM!"
N Streamload Downloader SlDB.exe"Downloader for MediaMax (was Streamload) - ""gives you a private and secure place to upload store access and share your personal videos photos movies music and files"""
N Streamload Uploader StreamMgr.exe"Uploader for MediaMax (was Streamload) - ""gives you a private and secure place to upload store access and share your personal videos photos movies music and files"""
X Streams Drivers [trojan filename]"Detected by Trend Micro as the RESTARTER.E TROJAN! See here"
U StreamZap Remote zremote.exe"StreamZap PC Remote - control Windows Media Player iTunes RealPlayer Winamp PowerPoint MusicMatch Jukebox and many other multimedia applications"
U StrgSync.exe StrgSync.exeSimpleTech Inc's StorageSync backup software - backs up an entire PC or selected files and folders
X strkjhk sdflkj3.exe"Added by an unidentified WORM or TROJAN - see here"
X strmsnmgrs msnxmsgrsc.exe"Added by the SDBOT.JDR WORM!"
X strmsnmsgr msnmsgrs.exe"Added by the RBOT-ACQ WORM!"
X strmsnmsgrs msnmsgrsc.exe"Added by a variant of the RBOT WORM!"
X strmsnnms msnmegrs.exe"Added by the SDBOT-YU TROJAN!"
X strmsnnrs msnmcgrs.exe"Added by the RBOT-ACT TROJAN!"
X strmsoums msnmegrse.exe"Added by the SDBOT-ZK TROJAN!"
X Strng32 strngbox.exe"Added by the STRANO WORM!"
U StrokeIt strokeit.exe"StrokeIt is an ""advanced mouse gesture recognition engine and command processor"""
X strtas lock1.exe"Added by the SDBOT-ADQ WORM!"
X strtas lockx.exe"Added by the SDBOT-AEB WORM!"
X strtas l074.exe"Added by the AGENT-II TROJAN!"
X strtas loc1.exe"Added by the RBOT-AZU TROJAN!"
X strto strto.exe"Added by the KILLPROC-F TROJAN!"
X strto [path to trojan]"Added by the KILLAV-AP TROJAN!"
X Sts iwnujdss2.exe"Added by the SDBOT-YI WORM!"
X Stubbish Stubbish.exe"Added by the STUBBOT-A WORM!"
X StubPath Sservice.exe"Added by the PRORAT TROJAN!"
X stup 138762763.exe"Added by the FIRESPY-A TROJAN! It will attempt to register the dropped component as a Firefox plugin and begin monitoring the user's browsing habits stealing information including monitoring and logging information from Web forms"
X stup1db0t _win.exe"Added by a variant of the IRCBOT BACKDOOR!"
N StupAssist StupAssist.exeAssociated with Nikon digital cameras
X STV winscrne.exe"Added by a variant of the SDBOT WORM!"
X stxrmsgms mstats.exe"Added by the IRCBOT-AE TROJAN!"
U StyleXP StyleXP.exe"StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot therefore uninstall it if you don't want it"
X SubAH SubAH.exeAdded by the SUBAH TROJAN!
U Subliminal Power Subliminal.exe"Subliminal Power - displays subliminal messages of your choice on your computer screen"
N Subtract the Ads AdSub.exeRemoves adverts from web pages. Although useful - not required
X suck l0ad.exe"PurityScan/Clickspring adware"
U Suitcase Startup Suitcase.exe"Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system"
X Suite SuiteOffices.exe"Added by the LAZAR TROJAN!"
X SULFNBJ.EXE SULFNBJ.EXE"Added by the PE_MAGISTR.DAM VIRUS!"
X Sun Java Console for Windows NT & XP jconsole.exe"Added by the VANEBOT-C WORM!"
U Sunasdtserv Sunasdtserv.exe"CounterSpy by Sunbelt Software - adware/spyware protection"
U sunasServ sunasServ.exe"CounterSpy by Sunbelt Software - adware/spyware protection"
X Sunjava javasmart.exe"Added by the AGENT.AHV TROJAN!"
X SunJavaSched ccEvtMngr.exe"Added by the SDBOT-YP WORM!"
X SunJavaSched Updater avamx.exe"Added by the RBOT-ABJ WORM!"
X SunJavaUpdate smvss.exe"Added by the DEDLER-G TROJAN!"
N SunJavaUpdateSched jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
X SunJavaUpdateSched scvhost.exe"Added by the SDBOT-AVX WORM!"
X SunJavaUpdateSched javamx.exe"Added by the SDBOT-WI WORM!"
U Sunkist shwicon98.exeCard reader for memory cards from digital cameras etc
U Sunkist2k shwicon2k.exeCard reader for memory cards from digital cameras etc
U SunKistEM shwiconem.exe"Used by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software"
U SuNotification suatshut.exe"ShadowSurfer - ""provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC"""
U SunProtectionServer SunProtectionServer.exe"CounterSpy antispyware software"
U SunServer SunServer.exe"CounterSpy antispyware software"
? SupaDial SupaDial.exe"SupaNet.com modem driver related - is it required?"
N Supastatus status.exe"Supanet ISP software"
X supdate supdate.exe"Added by the MALWARE.D TROJAN!"
X supdate2.dll rundll32.exe supdate2.dll"Added by the ZLOB-VL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""supdate2.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X super fuckbx.exe"Added by the LINEAGE-H TROJAN!"
X super super.exe"Added by the AGOBOT-QT WORM!"
U Super Popup Blocker popkill.exe"Saga Super Popup Blocker - pop-up stopper"
U Super X Desktop Version 3.4 SXDesk.exe"Super X Desktop - virtual desktop manager"
U SuperAdBlocker SAdBlock.exe"SuperAdBlocker"
U SUPERAntiSpyware SUPERAntiSpyware.exe"""SUPERAntiSpyware is the most thorough scanner on the market. Our Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware that other products miss! SUPERAntiSpyware will remove ALL the Spyware NOT just the easy ones!"""
X SuperBar.Component [path to services.exe]"Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an ""Inetsrv"" subfolder"
X SuperBar.Component services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
U Supercleaner Supercleaner.exe"Supercleaner - all in one disk cleaner for your computer"
U SuperCool Compress Backup Main.exe""SuperCool Zip Backup software is a data backuprestore and file synchronization program"""
X SuperHeissSex SuperHeissSex.exe"HeissSex premium rate adult content dialer!"
X supernews12 newsd32.exe"Adware also detected as the DLOADER-JN TROJAN!"
X Supernova [worm filename]"Added by the SURNOVA.A (or SUPOVA) WORM!"
X superproxy superproxy.exe"Added by the DELBACK-B TROJAN!"
U SuperRam SuperRam.exe"SuperRam memory manager. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See SuperRam article and make up your own mind"
X superslut msslut32.exe"Added by the SLUTER-A WORM!"
U SuperSpamKiller Pro Ssk.exe"SuperSpamKiller Pro email spam blocker"
X Supervisor.exe Supervisor.exe"Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome"
X support-reverse-smileys [trojan filename]"Added by the LITEBOT TROJAN!"
X supporter5 supporter5.exe"Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
U Sup_SmartRAM Sup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
U Sup_SmartRAM.exe Sup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
U SureCleanProfessional SRClean.exe"SureClean PC and Internet tracks cleaner"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list