Welcome Guest (Log In | Create Account)
New Member? Join for free.




A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List  · Submit a Startup  · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
winui z.exe
X
Added by the Kondeli ... Read More
mulut_besar Z76V90L86L.exe
X
Added by the W32.Fishinflu@mm worm. W32.Fishinflu@mm is a mass-mailing worm that spreads through removable drives and by sending messages to mIRC user ... Read More
otak_udang Z82Y90M89R.exe
X
Added by the W32.Fishinflu@mm worm. W32.Fishinflu@mm is a mass-mailing worm that spreads through removable drives and by sending messages to mIRC user ... Read More
zaber0 zaberg.exe
X
Added by the W32/SillyFDC-HC worm.
Zacker Zacker.exe
X
Added by the GEMEL WORM!
king_za zaking.exe
X
Identified by Kaspersky Antivirus as a variant of the Worm.Win32.AutoRun.bsma removable media worm. ... Read More
zalpqbj zalpqbj.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
zameo Service zameo.exe
X
Added by the Troj/Keylog-MG keylogger.
Windows Config ZANBOR.EXE
X
Added by the W32/Spybot-MH worm and IRC backdoor.

The worm may attempt to steal passwords from the following programs/services:
... Read More
Norman ZANDA Zanda.exe
Y
Part of Norman Antivirus.
zango zango.exe
X
180Solutions/N-Case adware variant
zango sitefinder ZangoSiteFinder.exe
X
180Solutions ZangoSearch adware variant ... Read More
zango tvtimes ZANGOT~1.EXE
X
ZangoSearch adware ... Read More
[Various Names] zantu.exe
X
Part of the Wareout infection as described here.
zanu zanu.exe
X
180Solutions/N-Case adware variant ... Read More
System Zap.exe
X
Added by the W32/Culler-A worm.
ZoneAlarm Plus zaplus.exe
Y
Firewall program from Zonelabs - paid for version
Zapro Zapro.exe
Y
Firewall program from Zonelabs - paid for version
ZoneAlarm Pro Zapro.exe
Y
Firewall program from Zonelabs - paid for version
Win32 zaq.exe
X
Added by the W32/Rbot-GCE worm and IRC backdoor.
zcb zcb.exe
?
??
zcfgsvc ZCfgSvc.exe
U
Zero Config MFC Application, part of Intel’s ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the ... Read More
IntelZeroConfig ZCfgSvc.exe
U
This startup is part of Intel's ProSET utilities and is installed by the drivers for many of the Intel wireless network cards. This startup is essent ... Read More
Zcjflmoj Zcjflmoj.sys
X
Added by the Troj/Bckdr-GPJ backdoor Trojan with rootkit capabilities.
edgers zcwlnic.dll
X
Zlob Trojan which installs the VirusProtect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer has ... Read More
zdconfig ZDConfig.exe
?
Related to various brands of Wireless USB LAN Adapter - what does it do and is it required? ... Read More
zdegpig zdegpig.ini
X
Added by the Backdoor.Rustock backdoor rootkit.
{cc25189b-1b13-4abe-900e-65e08bd961af} zdhgsp.dll
X
Added by a Zlob Trojan which installs AntiVirgear 3.7 and display fake security alerts in your Windows taskbar. ... Read More
Zinio DLM ZDLM.EXE
N
Zinio - used to read magazines in digital rather than paper format
{2fdde73c-273e-4e55-84dc-455de06e4866} zdwii.dll
X
Zlob Trojan that installs VirusProtectPro 3.7 and shows fake security alerts from your Windows taskbar. ... Read More
Remote Management Agent zenrc32.exe
U
Part of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remo ... Read More
ZENRC zenrc32.exe
Y
The main component of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Leave well alone ... Read More
Novell ZfD Remote Management ZenRem32.exe
Y
Part of the Novell Windows client. It has a service name of Remote Management Agent and is found in the C:\Program Files\Novell\ZENworks\RemoteManage ... Read More
ZENRC Tray Icon zentray.exe
Y
Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Best left alone ... Read More
zeqbqwp zeqbqwp.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
zeqwur zeqwur.chm
X
Added by the Backdoor.Rustock backdoor rootkit.
ZeroSpyware ZeroSpyware.exe
U
FBM Software ZeroSpyware 2004 spyware detector and remover
ZESOFT zeta.exe
X
This file is associated with adware. It is known to download and install other spware and adware on to your computer. This service should definitely ... Read More
frowardness zfaiqwr.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
zfton.exe zfton.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ZipGenius Clean zg.exe
N
ZipGenius file compression utility
ZGNUBI ZGNUBI.exe
?
??
hypoch zgyhw.dll
X
Zlob Trojan which installs the VirusResponse Lab 2009 rogue anti-spyware program. This program displays fake security alerts stating that your comput ... Read More
f3444Adm zh59[RANDOM].exe
X
Added by the W32.Rontokbro.X@mm mass-mailing worm.
zhido zhido.exe
X
Added by the Troj/PWS-AWA password-stealing Trojan.
CHotKey zHotkey.exe
U
Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features ... Read More
Zinaps7 Zinaps7.exe
X
Added by the Zinaps Anti-Spyware 2008 rogue anti-spyware program.
ZingSpooler ZingSpooler.exe
U
Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload pho ... Read More
ZinkmoSvc ZinkmoSvc.exe
N
Added by the Zinkmo Internet Explorer and Firefox synchronization software.
zip zip.dll
X
Added by the Trojan-Downloader.Win32.Agent.ipp malware.
ziphelp ziphelp.exe
X
CoolWebSearch parasite related
zip driver loader ZipLoader.exe
X
Added by the OBLIVION TROJAN! ... Read More
LoadingAgent ZipLoader32.exe
X
Added by the OBLIVION TROJAN! This executable is one of the most common but there are more ... Read More
Zip Driver Loader ZipLoader32.exe
X
Added by the OBLIVION TROJAN! This executable is one of the most common but there are more ... Read More
test zistro.exe
X
Added by the Troj/Kimat-C Trojan.
ZENworks Imaging Service ZISWin.exe
Y
Imaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management" ... Read More
{d1e5ca97-235e-4ff0-9b92-7543c9d61ff4} zkpssqa.dll
X
Zlob Trojan that installs VirusProtectPro 3.6 and shows fake security alerts from your Windows taskbar. ... Read More
{89e4aaba-3b21-49b3-b922-8ca35193c68e} zlara.dll
X
A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar. ... Read More
zlclient zlclient.exe
Y
Firewall program from Zonelabs. This startup can appear in other version of Zone Alarm products such as their antivirus and anti-spyware products. ... Read More
Zone Labs Client zlclient.exe
Y
Firewall program from Zonelabs. This startup can appear in other version of Zone Alarm products such as their antivirus and anti-spyware products. ... Read More
zlclient zlclient.exe
X
Added by the Trojan.Syginre Trojan. Trojan.Syginre is a Trojan horse that disables the Windows Firewall and may delete some files from the compromised ... Read More
ZoneAlarm Client zlclient.exe
Y
Firewall program from Zonelabs. This startup can appear in other version of Zone Alarm products such as their antivirus and anti-spyware products. ... Read More
Zone Alarm Security zlclint.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Norman ZANDA ZLH.EXE
U
System Tray icon for Norman Antivirus
ZLH ZLH.EXE
U
System Tray icon for Norman Antivirus
[not used] zlibc.exe
X
Added by the Troj/Chorus-A browser hijacker.
topat zlip.exe
X
Added by the Troj/Flood-IG backdoor Trojan.
WindowsFZ zloader3.exe
X
Added as part of the Smitfraud infection.
blah service zlpkwj.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
ZipMagic zm32.exe
N
Zip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them first ... Read More
Z zmon.exe
X
Added by the W32/Delbot-AE worm.
Zekio Startups znksvc32.exe
X
Added by WORM_AGOBOT.AFN
ZNN znnsvc.exe
X
Added by the W32.Rinbot.D worm and IRC backdoor.
ZNN znnsvc.exe
X
Added by the W32/Sdbot-DAA worm and IRC backdoor.
winup zod32.exe
X
Added by the W32/Dozic-A AOL Instant Messenger worm.
Winupd zod32.exe
X
Added by the W32/Dozic-A AOL Instant Messenger worm.
winndata zod32.exe
X
Added by the W32/Dozic-A AOL Instant Messenger worm.
windatea zod32.exe
X
Added by the W32/Dozic-A AOL Instant Messenger worm.
winnet zod32.exe
X
Added by the W32/Dozic-A AOL Instant Messenger worm.
Messenger zone-h.ddo.jp.exe
X
Added by the Trojan.Esteems.C Trojan.
Microsoft Update Machine zonealarm.exe
X
Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program! ... Read More
Winsock2 driver ZONEALARM.EXE
X
Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program ... Read More
ZoneAlarm zonealarm.exe
Y
Firewall program from Zonelabs - free version
Winsock32driver ZoneAlarmPr0.exe
X
Added by the HACKARMY-B TROJAN!
Winsock2 driver Zonealarmupdate.exe
X
Added by a variant of the SPYBOT WORM!
Winsock32driver ZoneLockup.exe
X
Added by the HACARMY.D TROJAN!
Zoom zoom.exe
U
Zoom - speeds up Windows startup and manages startup applications
ZoomingHook ZoomingHook.exe
?
Related to the Toshiba Zooming Utility for Tablet PC. What does it do and is it required? ... Read More
Zooming ZoomingHook.exe
?
Related to the Toshiba Zooming Utility for Tablet PC.
Zopenssl zopenssl.dll
X
Added by the Trojan.Goldun.K rootkit. This program is used by the infection to stealth C:\Windows\System32\zopenssld.sys and its related service. ... Read More
OPENSSL cryptoapi zopenssld.sys
X
Added by the Trojan.Goldun.K rootkit.
{4688f900-0d0c-4788-b297-59cc10e70ccc} zpeolvh.dll
X
Zlob Trojan that installs VirusProtectPro 3.3 and shows fake security alerts from your Windows taskbar. ... Read More
{70305bc2-b289-4209-a344-be21f22bc930} zphnok.dll
X
A Trojan used by the rogue anti-spyware program VirusBurst. This Trojan, when installed, will display fake security alerts on your taskbar and install ... Read More
zero popup killer xp.lnk zpk_xp.exe
U
Intelligent anti-pop-up software product by Ax-Soft ... Read More
ZPMODEMSYSNTDRVNT zpmodemnt.sys
X
Added by the Troj/AdClick-BM Trojan.
ZPOINT32 ZPOINT32.exe
Y
USB graphics/writing tablet driver
SystemSecurity zprot32.exe
X
Added by the Troj/Agent-FK Trojan.
Terminate Popup ZPU.exe
X
Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker.
{547aaa89-7e6b-42b4-b112-a64955f86a2a} zpuwriz.dll
X
Zlob Trojan that installs VirusProtectPro 3.5 and shows fake security alerts from your Windows taskbar. ... Read More
star4 Zred2.exe
X
Added by the Troj/DwnLdr-HLK downloading Trojan.
streamzap remote zremote.exe
U
StreamZap_PC_Remote - Control Windows Media Player, iTunes, RealPlayer, Winamp, PowerPoint, MusicMatch Jukebox, and many other multimedia applications ... Read More
Zrfkupza Zrfkupza.sys
X
Added by the Troj/PcClient-N backdoor Trojan.
(default) Zrwchrhu.dll
X
Added by the Backdoor.Hesive.C backdoor Trojan.
Zrwchrhu Zrwchrhu.sys
X
Added by the Backdoor.Hesive.C backdoor Trojan. This particular part of the infection acts as a rootkit to hide and files or registry entries it crea ... Read More
zscpsdfh zscpsdfh.dll
X
Added by the Troj/PcClien-KT Trojan. This infection is hidden by the zscpsdfh.sys rootkit. ... Read More
yscpsdfh zscpsdfh.sys
X
Added by the Troj/RKPort-Fam Trojan rootkit.
Windows Zser.exe
X
Added by the W32/Culler-D worm.
ZSMCSnap211 ZSMCSnap211.exe
?
Related to ZSMC USB cameras.
zsmscc zsmscc071001.dll
X
Identified as a variant of the Trojan-Spy.Win32.Agent.adq malware.
{8A5849C4-93F3-429D-FF34-660A2068897C} zsPoCrypt.dll
X
Detected by BitDefender as Generic.Malware.dld.
zsqalpdt zsqalpdt.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
NORTON ANTIVIRUS HACKER-EDITION zsqwx.exe
X
Added by the W32/Rbot-BAK worm and IRC backdoor.
zsscheduler zsscheduler.dll
Y
Related to ZeroSpyware from FBM Software.
zSearch Zstb.exe
X
TotalVelocity zSearch parasite
zsydll zsydll.dll
X
Added by the BKDR_GINWUI.B backdoor.
[not used] zsyhide.dll
X
Added by the Backdoor.Ginwui.B backdoor Trojan.
Zsys Zsys.exe
X
Added by the PWSteal.Rivarts password-stealing Trojan.
adobe zteam.exe
X
Added by an unidentified TROJAN!
Jun Lozada ztescd32.exe
X
Added by the W32/AutoRun-XU removable media worm.
Microsoft Autorun14 ztinetzt.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
{D1351752-5628-1547-FFAB-BADC13512AFD} ztmpri.dll
X
Added by the Troj/QQPass-APA Trojan.
ztx86 ztx86.sys
X
Identified as a variant of the Backdoor:Win32/Rustock.gen!C backdoor Trojan.
Zune Launcher ZuneLauncher.exe
U
Launches the Zune software when you have a Microsoft Zune connected to your computer. ... Read More
Zune Network Sharing Service ZuneNss.exe
U
Allows you to share the media in your Zune library with other Microsoft devices such as the XBOX 360. ... Read More
zupacha.exe zupacha.exe
X
Added by the Troj/Dropper-QL Trojan.
b3dUpdate Zupdate.exe
X
B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2 ... Read More
Update Zupdate.exe
X
B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2 ... Read More
Zupdate Zupdate.exe
X
B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2 ... Read More
update" -s setup Zupdate.exe
X
B3d Projector foistware - periodically tries to access the internet. (1) Uninstall via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) ... Read More
zvaeypeb zvaeypeb.dll
X
Added by the Troj/Bckdr-QJB Trojan. This infection is hidden by the zvaeypeb.sys rootkit. ... Read More
yvaeypeb zvaeypeb.sys
X
Added by the Troj/Bckdr-QJB rootkit.
icrosoft Visual InterDevc zvslmqb.exe
X
Added by the W32/Rbot-AYP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Recylinder Check zwdomsgemw.exe
X
Added by the W32/Rbot-EGJ worm and IRC backdoor.
zwqcplsp zwqcplsp.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
Zwunzi Service zwunzi122.exe
X
Added by the Adware.Zwunzi adware.
ksrlnhm zxatgso.exe
X
Added by the Troj/Dloader-LI downloader trojan.
Zxbnredm Zxbnredm.sys
X
Added by the Backdoor.Hesive.E rootkit driver. This driver will attempt to stealth certain registry keys and files so they are not detectable or vis ... Read More
[Various Names] zxc.exe
X
Part of the Wareout infection as described here.
Zxftajzo Zxftajzo.sys
X
Added by the Backdoor.Darkmoon.D backdoor.
{9A65498A-7653-9801-1647-987114AB7F49} zxipri.dll
X
Identified by Kaspersky as the Trojan-Spy.Win32.Delf.xc password-stealing Trojan. ... Read More
yxwituxh zxwituxh.sys
X
Added by the Troj/Dropper-QV rootkit.
VasddwDg zxXZwd.exe
X
Added by the W32/Sdbot-SN WORM/IRC backdoor Trojan. Running in the background as a service, it will allow unauthorised remote access to the infected c ... Read More
(default) Zykheptd.dll
X
Added by the Backdoor.Hesive.B backdoor.
Zykheptd Zykheptd.sys
X
Added by the Backdoor.Hesive.B backdoor.
{2F164B78-F15F-49B0-11AB-4EA9BE8E14BD} zyli.dll
X
Added by the Troj/LegMir-ARJ password-stealing Trojan for the online game The Legend of Mir. ... Read More
dsd zz.exe
X
Added by the W32/Rbot-FOX worm and IRC backdoor. W32/Rbot-FOX spreads to other network computers by networks protected by weak passwords. ... Read More
{52AD3225-EC12-BAA3-E2A2-D012A4B6011D} zz33.exe
X
Added by the Troj/Delf-DLJ Trojan.
zzb zzb.exe
X
IAGold adware downloader
zzb zzb.exe
X
IAGold adware downloader
zzb2 zzb2.exe
X
IAGold_adware downloader ... Read More
MSMSGNER zzgf.exe
X
Added by the Troj/PWS-CCB password-stealing Trojan.
gshp zzgshp.vbs
X
Homepage hi-jacker
Microsoft Security Panagers zzoboony.exe
X
Added by the W32/Rbot-AOI worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
<not used> zzvetza.dll
X
Added by the Trojan.Zatvex Trojan. Trojan.Zatvex is a Trojan horse that monitors and redirects network traffic. ... Read More
zzz zzz.sys
X
Added by the Hacktool.Rootkit rootkit.
zzzzDeMe zzzx*.exe
X
Added by the Troj/Socksrv-A backdoor trojan.
zzzxSYSTEM_32 zzzxt2ve.exe
X
Added by the W32/Oddbot-D WORM!
zzzxIPSPEC_1 zzzx[random characters].exe
X
Added by the Trojan.Netdepix.B Trojan.


> Status Key
Each entry in the database will have a Status assigned to it. The key to this status is the following:
  • Y - This status flag means that this entry should be left alone and be allowed to run as if it is unchecked it may break the functionality or use of a particular program.
  • N - This status flag means it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
  • U - This status flag means it is up to you whether or not you feel this program needs to run automatically.
  • X - This status flags means the item should definitely not start up automatically. Items that have this flag are generally malware such as viruses, trojans, hijackers, spyware but could also be programs that are not desirable to run on your computer.
  • ? - This status flag means the status of this entry is unknown at this time and more research is necessary.
If you require assistance in removing one of these files you can ask us in the Startup Database Forum.

> Disclaimer
It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. BleepingComputer.com will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides


Portions of this database © Paul Collins
© 2003-2012 All Rights Reserved Bleeping Computer LLC.
PGT: 0.1044 Queries: 4