List Information

Started by: Paul Collins

Maintained by: random/random, nasdaq, Vino Rosso
Startup List

The Startup List catalogues startup applications - not running processes.
For information on the difference, please see here.

These are entries for programs that can start automatically with your computer.

Status Key:
Y = Normally leave to run at start-up
N = Not required - often infrequently used tasks that can be started manually, if necessary
U = User's choice - depends whether a user deems it necessary
X = Malware, spyware, adware, or other potentially unwanted items
? = Currently unknown status
Search Results
(displaying 91 results)

Name Filename Description Status
WinXP-98CSRSS.exeAdded by the Troj/Banker-DS TROJAN! Note: Located in \%Program Files%\WinXP-98\Tools\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
auto_updatecsrss.exeAdded by the W32.SillyFDC WORM! Note: Located in \%Program Files%\microsoft frontpage\X
2csrss.exeAdded by the Mal/Behav-043 MALWARE! Note: Located in \%Documents and Settings%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ Note: This entry is loaded through one of the "Policies" startup keys.X
1csrss.exeAdded by the Mal/Behav-043 MALWARE! Note: Located in \%Program Files%\microsoft frontpage\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ Note: This entry is loaded through one of the "Policies" startup keys.X
winlogoncsrss.exeIdentified as Trojan-Proxy.Win32.Agent.kj. Note: Located in \%WINDIR%\X
csrss.execsrss.exeAdded by the W32.Dalbug.Worm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
SernellApp.pcxcsrss.exeAdded by the Troj/Bancban-BJ TROJAN! Note: Located in \%WINDIR%\System\D5133\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Runtime ProcessCsrss.exeAdded by the Troj/Ciadoor-J TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Runnercsrss.exeAdded by the Troj/AdClick-AG TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
FirewallActiviescsrss.exeAdded by the Troj/Banker-AQ TROJAN! Note: Located in \%WINDIR%\System32\3041\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
csrss.execsrss.exeAdded by the W32.Dalbug.Worm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
_SystemDrivercsrss.exeAdded by the Trojan.Ascetic.B TROJAN! Note: Located in \%WINDIR%\addins\explorer\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
LogonAdministratorCSRSS.EXEAdded by the W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible drives on the compromised computer. Note: Located in \%Documents and Settings%\Administrator\Local Settings\Application Data\WINDOWS\ Note: Do not remove the legitimate csrss.exe file which is always found in \%WINDIR%\%System%\X
WinUpdateProtectioncsrss.exeEmployeeWatch is a commercial spyware program designed to monitor user activity on a computer.U
WinUpdateProtectioncsrss.exeICE_Remote_Spy monitoring software, "secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you." - Note - this file is installed in a C:\Windowsupdate\Ufp\Irs7 folder, and it is NOT the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which is located in the System32 directory.U
WinUpdateAdministratorCSRSS.EXEAdded by the W32/Punya-A WORM! Note: Located in \%AppData%\WINDOWS\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Windowsupdate Servicecsrss.exeAdded by the WORM_BUCHON.E WORM! Note: Located in \%ROOT%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Windows Updatecsrss.exeAdded by the Troj/Banker-HM TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Windows Explorer SP2csrss.exeAdded by the Troj/Banker-DM TROJAN! Note: Located in \%WINDIR%\System32\JavaBeans\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Windows Client Service 32csrss.exeAdded by the W32/Rbot-ALB WORM! Note: Located in \%WINDIR%\System32\drivers\winsdriver\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Windows 2004CSRSS.exeAdded by the Troj/Banker-DY TROJAN! Note: Located in \%Program Files%\Windows 2004\Tools\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Updatecsrss.exeAdded by the Trojan.Meheerwar TROJAN! Note: Located in \%WINDIR%\System%\winupdate\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
.svchostCSRSS.EXEAdded by the Trojan.Webus.F TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
PKWAREcsrss.exeAdded by an Unidentified malware. Note: Located in \%AppData%\roaming\ Note: Do not remove the legitimate (csrss.exe) file which is always found in \%Windir%\%System%\X
Client_Runtime_Servicecsrss.exeRelated to Trojan.fakems is a malicious trojan that opens up a backdoor to enable a computer attacker. Note: Located in \%AppData%\Roaming\Microsoft\Windows\Runtime\X
IcyWildflowercsrss.exeAdded by an Unidentified malware. Note: Located in \%Windir%\rss\ Note: Do not remove the legitimate (csrss.exe) file which is always found in \%Windir%\%System%\X
WINLOG0Ncsrss.exeAdded by the csrss.exe Unknown malware. Note: Located in \%Windir%\ Note: Do not delete the csrss.exe located in \%Windir%\%System%\X
nvdisplaycsrss.exeIdentified as an Infostealer trojan, detected by Kaspersky antivirus as Trojan.Win32.VBKrypt.blpf Note: Located in %AppData%X
Microsoft Windows Firewallcsrss.exeIdentified as Infostealer trojan, detected by Malwarebytes Anti-Malware as "Trojan.Agent.MSGen" Note: Located in %ProgramFiles%\LogitechDriver Note: Triggered by the HKLM\..\Policies\Explorer\Run keyX
Microsoft Windows Defendercsrss.exeIdentified as Infostealer trojan, detected by Malwarebytes Anti-Malware as "Trojan.Agent.MSGen" Note: Located in %ProgramFiles%\LogitechDriverX
bootstatcsrss.exeAdded by the Troj/Swysin-Gen Trojan. Note: Located in \%Windir%\Media\X
Intelcsrss.exeUnknown malware. Note: Located in \%AppData%\X
Safer Networking Limitedcsrss.exeAdded by an Identified by ESET Nod32 as a variant of the Trojan.Generic.KD.373098 malware. Note: Located in \%AppData%\ Note: Do not remove the legitimate (csrss.exe) file which is always found in \%Windir%\%System%\X
LeechFTPcsrss.exeAdded by an Unidentified malware. Note: Located in \%AppData%\roaming\ Note: Do not remove the legitimate (csrss.exe) file which is always found in \%Windir%\%System%\X
SYSTEMSars32csrss.exeAdded by the W32.Ahlem.A@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
VMware, Inc.csrss.exeAdded by the Unidentified malware. Note: Located in \%AppData%\ Note: Do not remove the legitimate csrss.exe file which is always found in \%Windir%\%System%\X
Windows System Devices Managercsrss.exeAdded by the Troj/Inject-PX Trojan. Note: Located in \%Windir%\X
MSWUpdatecsrss.exeAdded by the Mal/DrkBot-A malware. Note: Located in \%AppData%\X
Policiescsrss.exeAdded by the Unidentified trojan Note: Located in \%Program Files%\shopNon\Bit Defender\ Note: Do not remove the legitimate csrss.exe file which is always found in \%WINDIR%\%System%\ Note: This entry is loaded through one of the "Policies" startup keys.X
Defender32bitcsrss.exeAdded by the Unidentified trojan Note: Located in \%Program Files%\shopNon\Bit Defender\ Note: Do not remove the legitimate csrss.exe file which is always found in \%WINDIR%\%System%\X
Microsoft Windows Defendercsrss.exeAdded by the Unidentified trojan Note: Located in \%Program Files%\shopNon\Bit Defender\ Note: Do not remove the legitimate csrss.exe file which is always found in \%WINDIR%\%System%\X
ZakariaGcsrss.exeIdentified by Microsoft as Worm:Win32/Orbina!rts. Information at Threat Expert Note: Located in %windir%X
RunonceCSRSS.exeAdded by the Worm.Win32.AutoRun.dkk Note: Located in \%WINDIR%\X
csrsscsrss.exeAdded by the Armadillo IRCbot. Note: Located in \%TEMP%\tmp-3\X
srss.execsrss.exeAdded by the Backdoor:Win32/Poisonivy.E Note: Located in \%WINDIR%\X
Csrsscsrss.exeAdded by the W32.Chod@mm WORM! Note: Located in \%WINDIR%\System32\(random folder name)\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
SystemDrivercsrss.exeAdded by the Trojan.Ascetic.B TROJAN! Note: Located in \%WINDIR%\addins\explorer\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
KernellAppscsrss.exeAdded by the Troj/Bancban-AC TROJAN! Note: Located in \%WINDIR%\System\System Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
FiendlyTypecsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
DIECOXcsrss.exeAdded by the BackDoor-ATM.gen TROJAN! Note: Located in \%ROOT%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
csrssLevel4csrss.exeAdded by an Unidentified malware Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
CsrssCSRSS.EXEAdded by the W32/Punya-B WORM! Note: Located in \%AppData%\WINDOWS\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
csrsscsrss.exeAdded by the Troj/Keylog-AQ TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
csrsscsrss.exeAdded by the W32/Chode-J WORM! Note: Located in \%WINDIR%\System32\(random name)\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
csrsscsrss.exeAdded by the Spyware.BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. - NOTE - this file is placed in the Program Files\Supremtec folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!?
Csrsscsrss.exeAdded by the W32.Chod.B@mm WORM! Note: Located in \%WINDIR%\System32\(random folder name)\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Key Loggercsrss.exeAdded by the W32.Buchon.A@mm WORM! Note: Located in \%ROOT%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
CSRSSCSRSS.EXEAdded by an unidentified malware. Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Console de Gerenciamento Microsoftcsrss.exeAdded by the Troj/Bancban-ET TROJAN! Note: Located in \%WINDIR%\System32\Central de Segurança\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
ccpAppscsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
BuildLabscsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
BagleAVcsrss.exeAdded by the W32.Netsky.AB@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
AtiSoundcsrss.exeAdded by the Added by the WinSpy surveillance software. Note: Uninstall this software unless you put it there yourself Note: Located in \%Program Files%\Winspy\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\?
ASP.NET State Servicecsrss.exeAdded by the Troj/Dloader-QI TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
AdRotator.Applicationcsrss.exeAdRotator adware variant - Note - do NOT be confuse with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt\System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!X
.WMAudiocsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
.TEXTCONVcsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
RegDone Excsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
System Processcsrss.exeAdded by the Troj/AdClick-AG TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Systemcsrss.exeAdded by the Troj/LdPinch-PT TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
State Servicecsrss.exeAdded by the Troj/Dadobra-CP TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Shockwavecsrss.exeAdded by the W32.Sndog@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Servicescsrss.exeAdded by the Backdoor.Ranky.U TROJAN! Note: Located in %PATH TO TROJAN% Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Svchostcsrss.exeIdentified by Avira as a variant of the BDS/Bandok.HR backdoor Trojan. Note: Located in \%allusersprofile%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
rundll32csrss.exeAdded by the Trojan.Gutta TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Run TaskMrgcsrss.exeAdded by the Troj/LdPinch-W TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
RPCserv32gCSRSS.EXEAdded by the WORM_BOBAX.AD WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
RegWritecsrss.exeAdded by the Backdoor.Sokacaps TROJAN! Note: Located in \%WINDIR%\media\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Krnlcheckcsrss.exeAdded by the Backdoor.Botnachala TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Progcsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
NTDLMcsrss.exeAdded by the Backdoor.Hale TROJAN! Note: Located in \%WINDIR%\System32\qossrv\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Norton Protect Activiescsrss.exeAdded by the Troj/Banker-CZ TROJAN! Note: Located in \%WINDIR%\System32\D5133\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft ® Windows TCP/IP Socket Drivercsrss.exeAdded by the TROJ_RANKY.HW TROJAN! Note: Located in \%WINDIR%\winsock\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft ® Windows Client/Server Runtime Servicecsrss.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\WINDOWS\i386\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft Word Profissionalcsrss.exeAdded by the Troj/Bancban-DB or Troj/Bancos-DP TROJANS! Note: Located in \%WINDIR%\System32\JavaVM\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft Windows Update Clientcsrss.exeAdded by the W32/Kebede-G WORM! Note: Located in \%WINDIR%\Systems32\ Note: Your csrss.exe file my be compromised. ckeck it out. Note: Submit the file for investigation: Virus scanX
Microsoft Windows CSRSScsrss.exeAdded by the W32/Kalel-A WORM! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft SourceSafecsrss.exeAdded by the Trojan.Webus TROJAN! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft (R) Windows TCP/IP Socket Drivercsrss.exeAdded by the Troj/Proxy-DD TROJAN! Note: Located in (Path to Trojan EXE) Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Audio Drivercsrss.exe , config.exeAdded by the Unidentified malware. Note: Located in \%AppData%\ Note: Do not remove the legitimate csrss.exe or config.exe files are is always found in \%Windir%\%System%\X
hsf87efjhdsf87f3jfsdi7fhsuj
fd
avp32.exe, csrss.exe, debug.exe, drweb.exe, hexdump.exe, login.exe, lsass.exe, smss.exe, taskmgr.exe, win32.exe, ozrfi .exe, win.exe, system.exeAdded by the TrojanClicker:Win32/Hatigh.C TROJAN! Note: Located in \%TEMP%\ Note: Do not delete similar filenames in other folders.X


Powered by SystemLookup Engine. © 2008-2018 BrightFort. All Rights Reserved. | Privacy Policy | Terms of Use