Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Alert!  Have a problem and would like to ask us for help? To learn how to ask your question Click Here!
Stop!  Do you have popups or other malware infecting your computer? If so, Start Here!
Question?  Are you having trouble using this site? Then you should visit the New User Orientation Center!



A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List · Submit a Startup · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · Computer Help Forums · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
bisque obicx.dll
X
Zlob Trojan which installs the VirusResponse Lab 2009 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusResponse Lab onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
{9D71D88C-C598-4935-C5D1-43AA4DB90836} cam2.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
{98542AD2-6BEE-16FA-7063-790594B10AA0} oemig32.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
{A24CDBE1-DE51-32C9-7C14-F7DF9AD1BA9E} Component.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
PsycheEnqueue PsycheEnqueue.exe
X
Identified as a variant of the TrojanSpy:Win32/Festeal.D malware.
psyche psyche.exe
X
Identified as a variant of the Spammer:Win32/Cutwail.A malware.
Qualys Security qualysguard.exe
X
Identified as a variant of the Worm:Win32/Mytob.SA mass-mailing worm.
Qualys wmpirvse.exe
X
Identified as a variant of the Worm:Win32/Mytob.SA mass-mailing worm.
Windows msvc Control Centers msvc32s.exe
X
Identified as a variant of the W32.Spybot.Worm malware.
Gool Gool.exe
X
Unknown malware.
winis winis.exe
X
Identified as a variant of the Net-Worm.Win32.Kolab malware.
Windows Layer mrtmoons.exe
X
Identified as a variant of the Net-Worm.Win32.Kolab malware.
skype.exe \iconchanger.exe
X
Identified as a variant of the Backdoor.Win32.Poison.cpb malware.
XP HOT ReHard b7r63.exe
X
Identified as a variant of the Worm:Win32/Wootbot.gen malware.
Rout111 serv454.exe
X
Identified as a variant of the Backdoor.Win32.Wootbot.db malware.
LoadAudio snd2d3d.exe
X
Identified as a variant of the VirTool:Win32/DelfInject.gen!AF malware.
qmafxprs qmafxprs.dll
X
Identified as a variant of the VideoAccessCodec.
lfstbwvd lfstbwvd.dll
X
Identified as a variant of the VideoAccessCodec.
xgpsarbm xgpsarbm.dll
X
Identified as a variant of the VideoAccessCodec.
neksolda neksolda.dll
X
Identified as a variant of the VideoAccessCodec.
WINDOWS VISTA UPDATA DEFENDAR RatBot.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
FmMgr.exe FmMgr.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Syncronization Task shrhost.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
WinAmp Player swphost.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows Defendar RatBot.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft Svchost local services Winsec32.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Transaction Tasker stdhost.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service CV (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Monitor Resolution svmhost.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft MachineUpdatese tempes.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Sub-Classing Routine Manager scvhost.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows32 Host Service Manager smsc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows System32 Management smsc32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Client Server csrcs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Basic_14_Process.exe Basic_14_process.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
VTskMgr.exe VTskMgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mmsass mldmm.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Symantec Drive SecMon symldsv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
OpenSSL rpcmon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Symantec Drive Maintenance symldsm.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
zfton.exe zfton.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN scvrun.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center fxstaller.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows XP QQ.exe
X
Added by the Troj/Agent-HWL Trojan.
Messenger Service service.exe
X
Added by the Troj/Dloadr-BVG Trojan.
Rapid Antivirus Rapid Antivirus.exe
X
Added by the RapidAntivirus rogue anti-spyware program.
ContentEraser GDC.exe
X
Added by the ContentEraser rogue privacy software.
Windows Gamma Display wingamma.exe
X
Added by the Antivirus 2010 rogue anti-spyware program.
XP Antispyware 2009 XP_AntiSpyware.exe
X
Added by the XP Antispyware 2009 rogue anti-spyware program.
mt47hub mt47hub.dll
X
A variant of the Haxdoor Trojan. This infection is hidden by the svitch.sys rootkit.


> Status Key
Each entry in the database will have a Status assigned to it. The key to this status is the following:
  • Y - This status flag means that this entry should be left alone and be allowed to run as if it is unchecked it may break the functionality or use of a particular program.
  • N - This status flag means it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
  • U - This status flag means it is up to you whether or not you feel this program needs to run automatically.
  • X - This status flags means the item should definitely not start up automatically. Items that have this flag are generally malware such as viruses, trojans, hijackers, spyware but could also be programs that are not desirable to run on your computer.
  • ? - This status flag means the status of this entry is unknown at this time and more research is necessary.
If you require assistance in removing one of these files you can ask us in the Startup Database Forum.

> Disclaimer
It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. BleepingComputer.com will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides


Portions of this database © Paul Collins
© 2003-2008 All Rights Reserved Bleeping Computer LLC.
PGT: 0.27141 Queries: 5