Source=Paul Collins Startup list
[Delete Me]
Confirmed=X
Filename=worm.exe
Description=Added by the DOOMHUNTER WORM!
Source=Paul Collins Startup list
[Dell AIO Printer A***]
Confirmed=N
Filename=dlbabmgr.exe
Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
Source=Paul Collins Startup list
[Dell AIO Printer A***]
Confirmed=N
Filename=dlbfbmgr.exe
Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
Source=Paul Collins Startup list
[Dell AIO Printer A***]
Confirmed=N
Filename=dlbkbmgr.exe
Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
Source=Paul Collins Startup list
[Dell Alert]
Confirmed=N
Filename=DAMon.exe
Description="Dell Alert" utility, that's supposed to make interaction with Support easier
Source=Paul Collins Startup list
[DellDMI]
Confirmed=?
Filename=delldmi.exe
Description=Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?
Source=Paul Collins Startup list
[DELLMMKB]
Confirmed=U
Filename=DELLMMKB.EXE
Description=Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
Source=Paul Collins Startup list
[DellSC]
Confirmed=N
Filename=dellsc.exe
Description=Dell Solution Center - web-based troubleshooting tools and educational offerings
Source=Paul Collins Startup list
[DellTouch]
Confirmed=U
Filename=MMKeybd.exe
Description=Dell multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[DellTouch]
Confirmed=U
Filename=DELLMMKB.EXE
Description=Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
Source=Paul Collins Startup list
[delmsbb]
Confirmed=X
Filename=delmsbb.exe
Description=nCase adware
Source=Paul Collins Startup list
[delsubmit]
Confirmed=X
Filename=rundll32.exe advpack.dll, DelNodeRunDLL32 submit.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[DelTmp]
Confirmed=?
Filename=DelTemp.exe
Description=Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?
Source=Paul Collins Startup list
[DeltTray]
Confirmed=N
Filename=deltray.exe
Description=System Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[demon]
Confirmed=?
Filename=demon.exe
Description=Part of the French Wanadoo ADSL extense pack. What does it do and is it required?
Source=Paul Collins Startup list
[DepFrez]
Confirmed=U
Filename=frzstate.exe
Description=Deep Freeze from Hyper Technologies. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example
Source=Paul Collins Startup list
[Description of Shortcuts]
Confirmed=?
Filename=*.exe
Description=* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e., 4EBD23F5 is actually Works Calender Reminder (found via a registry search)
Source=Paul Collins Startup list
[Desire]
Confirmed=X
Filename=desires.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[desk-top-service]
Confirmed=?
Filename=desk-top-service.exe
Description=??
Source=Paul Collins Startup list
[DeskAd Service]
Confirmed=X
Filename=DeskAdServ.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[DeskColor]
Confirmed=N
Filename=DESKCOLOR.EXE
Description=Provides transparent icon text backgrounds and coloured icon text
Source=Paul Collins Startup list
[Deskflag]
Confirmed=N
Filename=Deskflag.exe
Description=DeskFlag - animated USA flag on the desktop
Source=Paul Collins Startup list
[DeskMateAutoUpdate]
Confirmed=X
Filename=DeskMateAutoUpdate.exe
Description=DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related
Source=Paul Collins Startup list
[Desksite CMA]
Confirmed=U
Filename=cma.exe
Description=DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
Source=Paul Collins Startup list
[Desktop]
Confirmed=X
Filename=rundll32.exe msconfd.dll, Restore ControlPanel
Description=Added by the BOOKMARKER TROJAN!
Source=Paul Collins Startup list
[desktop]
Confirmed=X
Filename=desktop.exe
Description=Added by the SDBOT.MD WORM!
Source=Paul Collins Startup list
[Desktop Architect]
Confirmed=N
Filename=DATRAY.EXE
Description=Desktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc
Source=Paul Collins Startup list
[Desktop Plant]
Confirmed=N
Filename=AZARE10S.PLT
Description=Vritual plant from here - this version is an Azalea, there are others so the filename may be different
Source=Paul Collins Startup list
[Desktop Search]
Confirmed=X
Filename=desktop.exe
Description=iSearch "Desktop Search" hijacker
Source=Paul Collins Startup list
[Desktop Service Centre]
Confirmed=?
Filename=DSC.exe
Description=OptusNet DSL or Dial-Up connection software - is it required?
Source=Paul Collins Startup list
[Desktop Weather]
Confirmed=N
Filename=THE WEATHER CHANNEL.exe
Description=Desktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc
Source=Paul Collins Startup list
[Desktop Weather 3]
Confirmed=N
Filename=THE WEATHER CHANNEL.exe
Description=Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc
Source=Paul Collins Startup list
[Desktop Weather 3]
Confirmed=N
Filename=THEWEA~1.EXE
Description=Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc
Source=Paul Collins Startup list
[desktopmgr]
Confirmed=N
Filename=desktopmgr.exe
Description=Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the "Blackberry"
Source=Paul Collins Startup list
[DesktopX]
Confirmed=U
Filename=DESKTOPX.EXE
Description=A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking
Source=Paul Collins Startup list
[deskup]
Confirmed=N
Filename=deskup.exe
Description=Adds Iomega Zip drive icons to the desktop
Source=Paul Collins Startup list
[detect]
Confirmed=U
Filename=idetect.exe
Description=iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled
Source=Paul Collins Startup list
[detect]
Confirmed=?
Filename=turbodetect.exe
Description=??
Source=Paul Collins Startup list
[Detector]
Confirmed=N
Filename=detector.exe
Description=USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software
Source=Paul Collins Startup list
[DEventAgent]
Confirmed=U
Filename=eventagt.exe
Description=DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
Source=Paul Collins Startup list
[Device Configuration Loader]
Confirmed=X
Filename=msdvc32.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Device Detector]
Confirmed=U
Filename=DevDetect.exe
Description=Watches for external digital imaging products being connected from ACD Systems
Source=Paul Collins Startup list
[DeviceDiscovery]
Confirmed=U
Filename=hpotdd01.exe
Description=Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
Source=Paul Collins Startup list
[DevicePath]
Confirmed=X
Filename=Proyecto1.exe
Description=Added by the GRUEL WORM!
Source=Paul Collins Startup list
[DevicePath]
Confirmed=X
Filename=Root.exe
Description=Added by the GRUEL WORM!
Source=Paul Collins Startup list
[Devices]
Confirmed=U
Filename=olesvr.exe
Description=Salfeld Child Control 2003 - parental control software
Source=Paul Collins Startup list
[devldr16]
Confirmed=U
Filename=devldr16.exe
Description=Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Source=Paul Collins Startup list
[Devlog]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[Devlog]
Confirmed=?
Filename=devlog.exe
Description=Apparently mainboard/chipset related, by a French company called AS Media - what exactly is it, and is it required
Source=Paul Collins Startup list
[DGJM]
Confirmed=?
Filename=DGJM.exe
Description=??
Source=Paul Collins Startup list
[dguard]
Confirmed=N
Filename=dguard.exe
Description=eAcceleration Stop-Sign related - not recommended, see note
Source=Paul Collins Startup list
[DHCP Server]
Confirmed=X
Filename=regsvr.exe
Description=Added by the RBOT-PR WORM!
Source=Paul Collins Startup list
[dhcpagnt]
Confirmed=Y
Filename=dhcpagnt.exe
Description=Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
Source=Paul Collins Startup list
[DHNUXB]
Confirmed=?
Filename=DHNUXB.exe
Description=??
Source=Paul Collins Startup list
[diagent]
Confirmed=N
Filename=diagent.exe
Description=System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
Source=Paul Collins Startup list
[Dial22]
Confirmed=X
Filename=dlm.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Dial33]
Confirmed=X
Filename=dlm.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Dialer]
Confirmed=X
Filename=rundll32.exe msa32chk.dll
Description=Unidentfied malware
Source=Paul Collins Startup list
[Dialer Control]
Confirmed=U
Filename=dc.exe
Description=Dialer-Control. Detects and protects from premium rate p0rn diallers
Source=Paul Collins Startup list
[Dialer Detect]
Confirmed=U
Filename=dd.exe
Description=DialerDetect detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing it
Source=Paul Collins Startup list
[Dialgo SDK]
Confirmed=U
Filename=PhoneAnswer.exe
Description=Dialgo Wave Modem ActiveX - "Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis"
Source=Paul Collins Startup list
[DialNet]
Confirmed=X
Filename=mxt32.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Dialog Box Assistant]
Confirmed=N
Filename=OSDEx.exe
Description=Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders
Source=Paul Collins Startup list
[Dialog Helper]
Confirmed=N
Filename=PDDLGHLP.EXE
Description=Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs
Source=Paul Collins Startup list
[DIECOX]
Confirmed=X
Filename=csrss.exe
Description=Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[DietK]
Confirmed=U
Filename=DietK.exe
Description=DietK - add-on for Kazaa Media Desktop; "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results"
Source=Paul Collins Startup list
[DigiCell]
Confirmed=U
Filename=DigiCell.exe
Description=MSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center"
Source=Paul Collins Startup list
[DigiD]
Confirmed=X
Filename=DigitalSound.exe
Description=Adware downloader
Source=Paul Collins Startup list
[DigiGuide]
Confirmed=N
Filename=CLIENT.EXE
Description=TV guide and reminder
Source=Paul Collins Startup list
[DigiGuide]
Confirmed=N
Filename=client01.exe
Description=TV guide and reminder
Source=Paul Collins Startup list
[Digital Dashboard]
Confirmed=N
Filename=devgulp.exe
Description=For Compaq PC's. Loads Digital Dashboard options
Source=Paul Collins Startup list
[Digital Line Detect]
Confirmed=N
Filename=DLG.exe
Description=Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
Source=Paul Collins Startup list
[Digital River eBot]
Confirmed=N
Filename=downlo~1.exe
Description=Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here
Source=Paul Collins Startup list
[DigitalNames]
Confirmed=X
Filename=DigitalNamesStart.exe
Description=DigitalNames spyware variant
Source=Paul Collins Startup list
[DigitalWizard]
Confirmed=N
Filename=ISWizard.exe
Description=InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
Source=Paul Collins Startup list
[DigitalWizard Monitor]
Confirmed=N
Filename=dwMon.exe
Description=InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
Source=Paul Collins Startup list
[DIGStream]
Confirmed=N
Filename=digstream.exe
Description=DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
Source=Paul Collins Startup list
[Dimension]
Confirmed=U
Filename=Dimension.exe
Description=Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol
Source=Paul Collins Startup list
[Dimension4]
Confirmed=U
Filename=d4.exe
Description=Dimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
Source=Paul Collins Startup list
[Dino3]
Confirmed=X
Filename=dino3.exe
Description=Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
Source=Paul Collins Startup list
[Dir1]
Confirmed=X
Filename=caKe
Description=Added by the CAKE WORM!
Source=Paul Collins Startup list
[Direct settings]
Confirmed=X
Filename=sdchost.exe
Description=Added by the DAEMONI-I TROJAN!
Source=Paul Collins Startup list
[Direct Update]
Confirmed=U
Filename=DUControl.exe
Description=DirectUpdate dynamic DNS updater
Source=Paul Collins Startup list
[Direct X Direct3D]
Confirmed=X
Filename=dxd3d.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Direct X Opengl]
Confirmed=X
Filename=dxopengl.exe
Description=Added by a variant of the RBOT-CJ WORM!
Source=Paul Collins Startup list
[DirectCD]
Confirmed=N
Filename=DirectCD.exe
Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
Source=Paul Collins Startup list
[directs.exe]
Confirmed=X
Filename=directs.exe
Description=Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!
Source=Paul Collins Startup list
[DIRECTVDSL]
Confirmed=U
Filename=Directvdsl.exe
Description=Starts DirectTV DSL modem at boot up. Can also be started manually
Source=Paul Collins Startup list
[DirectX]
Confirmed=X
Filename=ddhelp32.exe
Description=Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=Directx.exe
Description=Added by the SDBOT.D TROJAN!
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=Sqlexploit.exe
Description=Added by the SDBOT.D TROJAN!
Source=Paul Collins Startup list
[DirectX]
Confirmed=X
Filename=DirectX.exe
Description=Added by the BLAXE or LOGPOLE WORMS!
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=NTCmd.exe
Description=Added by the SDBOT.D TROJAN!
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=PipeCmd.exe
Description=Added by the SDBOT.D TROJAN!
Source=Paul Collins Startup list
[DirectX For Microsoft Windows]
Confirmed=X
Filename=dtxservice.exe
Description=Added by the PROGENT TROJAN!
Source=Paul Collins Startup list
[DirectX for Microsoft Windows]
Confirmed=X
Filename=Fservice.exe
Description=Added by the PRORAT TROJAN!
Source=Paul Collins Startup list
[DirectX for Microsoft Windows]
Confirmed=X
Filename=Sservice.exe
Description=Added by the PRORAT TROJAN!
Source=Paul Collins Startup list
[DirectX Video Driver]
Confirmed=X
Filename=dxterm5.exe
Description=Added by the WILAB-A TROJAN!
Source=Paul Collins Startup list
[DirectX64]
Confirmed=X
Filename=DirectXset.exe
Description=Added by the BROWNEY.A WORM!
Source=Paul Collins Startup list
[Dirkey]
Confirmed=U
Filename=Dirkey.exe
Description=Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders
Source=Paul Collins Startup list
[Disable EHCI]
Confirmed=?
Filename=nousb20.exe
Description=??
Source=Paul Collins Startup list
[Disc Detector]
Confirmed=N
Filename=CtNotify.exe
Description=For Creative sound cards. Detects when you insert a CD, DVD, etc
Source=Paul Collins Startup list
[disc detector]
Confirmed=?
Filename=qnetquestnotifty.exe
Description=??
Source=Paul Collins Startup list
[discoveg]
Confirmed=?
Filename=discoveg.exe
Description=??
Source=Paul Collins Startup list
[DiscoverDeskshop]
Confirmed=N
Filename=Deskshop.exe
Description=Discover Deskshop - single use "virtual" credit card
Source=Paul Collins Startup list
[Disk Master]
Confirmed=X
Filename=[trojan name]
Description=Added by the DISTER TROJAN! - a spam relayer
Source=Paul Collins Startup list
[DiskeeperSystray]
Confirmed=N
Filename=DkIcon.exe
Description=DisKeeper defragmentation software - can be started manually
Source=Paul Collins Startup list
[diskinf]
Confirmed=X
Filename=diskinf.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[DISKMON.EXE]
Confirmed=?
Filename=DISKMON.EXE
Description=??
Source=Paul Collins Startup list
[Disknag]
Confirmed=N
Filename=disknag.exe
Description=Dell program that reminds you to make your backup diskettes
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=Code.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=cat.exe
Description=MS-Connect dialler
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=hit.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=Snt.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Disk_Monitor]
Confirmed=U
Filename=Disk_Monitor.exe
Description=Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader
Source=Paul Collins Startup list
[Display Drivers]
Confirmed=X
Filename=cssrs.exe
Description=Added by the AGOBOT.FX WORM!
Source=Paul Collins Startup list
[Display Settings]
Confirmed=N
Filename=hptasks.exe
Description=Allows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers
Source=Paul Collins Startup list
[DisplayTrayIcon]
Confirmed=N
Filename=TrayIcon.exe
Description=System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display
Source=Paul Collins Startup list
[Distiller Assistant 3.01]
Confirmed=N
Filename=DISTASST.EXE
Description=From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
Source=Paul Collins Startup list
[Distributed File System]
Confirmed=X
Filename=Dfsvc.exe
Description=Added by the MYFIP.A or MYFIP.K WORMS!
Source=Paul Collins Startup list
[Distributed File System]
Confirmed=X
Filename=kernel32dll.exe
Description=Added by the MYFIP-C or MYFIP.K WORMS!
Source=Paul Collins Startup list
[distributed.net client]
Confirmed=U
Filename=DNETC.EXE
Description=Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses
Source=Paul Collins Startup list
[Dit]
Confirmed=Y
Filename=dit.exe
Description="Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found
Source=Paul Collins Startup list
[DiTask.exe]
Confirmed=N
Filename=DiTask.exe
Description=Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs
Source=Paul Collins Startup list
[Divamon.exe]
Confirmed=?
Filename=Divamon.exe
Description=Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?
Source=Paul Collins Startup list
[DivX MediaPlayer 7.0]
Confirmed=X
Filename=Dr.DivX.exe
Description=Added by the ALADINZ.G TROJAN!
Source=Paul Collins Startup list
[DivX Player]
Confirmed=X
Filename=DivXPlayer.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[DivX Updater]
Confirmed=X
Filename=DivX.Exe
Description=Added by the NALDEM TROJAN or MASTAK VIRUS!
Source=Paul Collins Startup list
[Divx4 codec]
Confirmed=X
Filename=devldr32.exe
Description=Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file
Source=Paul Collins Startup list
[DJREGFIX]
Confirmed=N
Filename=regedit /s c:\hpdjregfix.reg
Description=DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers
Source=Paul Collins Startup list
[DkService]
Confirmed=Y
Filename=DkService.exe
Description=From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled, otherwise you could have problems starting it manually.
Source=Paul Collins Startup list
[DKTime]
Confirmed=X
Filename=dktime.exe
Description=Added by the LUNII TROJAN!
Source=Paul Collins Startup list
[Dkware lptt01]
Confirmed=X
Filename=dkware.exe
Description=Variant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Dkware ml097e]
Confirmed=X
Filename=dkware.exe
Description=Variant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[dkzzixm]
Confirmed=?
Filename=dkzzixm.exe
Description=??
Source=Paul Collins Startup list
[dla]
Confirmed=Y
Filename=tfswctrl.exe
Description=Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
Source=Paul Collins Startup list
[DlaTray]
Confirmed=N
Filename=Dlatray.exe
Description=System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
Source=Paul Collins Startup list
[dlder]
Confirmed=X
Filename=dlder.exe
Description=Advertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see here). Reported in the past as a virus
Source=Paul Collins Startup list
[DlDir1]
Confirmed=X
Filename=caKe
Description=Added by the CAKE WORM!
Source=Paul Collins Startup list
[DLForcerExe]
Confirmed=?
Filename=DLForcerEXE.exe
Description=??
Source=Paul Collins Startup list
[DLF_00000B00]
Confirmed=N
Filename=Vcdlf.exe
Description=Known to cause problems with "Out of memory" errors (see here). Otherwise, it's purpose is unknown
Source=Paul Collins Startup list
[DLG]
Confirmed=N
Filename=DLGCHBW.exe
Description=Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
Source=Paul Collins Startup list
[DLHelperEXE]
Confirmed=N
Filename=WATCH.exe
Description=Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
Source=Paul Collins Startup list
[DLHelperEXE.exe]
Confirmed=X
Filename=N/A
Description=Downloader for Microgaming/Casino software - stealth installed
Source=Paul Collins Startup list
[Dlite]
Confirmed=X
Filename=dllmanager.exe
Description=Added by the WOOTBOT.DN WORM!
Source=Paul Collins Startup list
[DLL Service Manager]
Confirmed=X
Filename=[path to worm]
Description=Added by the RPCBOT.F TROJAN!
Source=Paul Collins Startup list
[DLL32]
Confirmed=X
Filename=dllmem32.exe
Description=Added by the KWBOT.E WORM!
Source=Paul Collins Startup list
[DllCacherv2]
Confirmed=X
Filename=dllcachev2.exe
Description=Added by the LATEDA TROJAN!
Source=Paul Collins Startup list
[dlldmt]
Confirmed=X
Filename=dlldmt.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[dllhelp]
Confirmed=X
Filename=dllhelp.exe
Description=Added by the STARTPAGE.DQ hijacker
Source=Paul Collins Startup list
[dllhelp]
Confirmed=X
Filename=dllhlp.exe
Description=Added by the Downloader-HI TROJAN!
Source=Paul Collins Startup list
[dllhostxp.exe]
Confirmed=X
Filename=dllhostxp.exe
Description=Browser hijacker and adware downloader
Source=Paul Collins Startup list
[dllreg]
Confirmed=X
Filename=dllreg.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[DLLService32]
Confirmed=X
Filename=dllsvc32.exe
Description=Added by the AGOBOT.VX WORM!
Source=Paul Collins Startup list
[DLT]
Confirmed=?
Filename=dlt.exe
Description=??
Source=Paul Collins Startup list
[dluca]
Confirmed=X
Filename=dluca.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[dluca]
Confirmed=X
Filename=dluca.exe
Description=Added by the DLUCA.C TROJAN!
Source=Paul Collins Startup list
[dluxde]
Confirmed=X
Filename=dluxde.exe
Description=All-In-One-Telcom (adult content dialler) variant
Source=Paul Collins Startup list
[Dluxjp]
Confirmed=X
Filename=cnfrm.exe
Description=Added by the DLUCA.D TROJAN!
Source=Paul Collins Startup list
[DM mgr]
Confirmed=X
Filename=dm_mgr.exe
Description=Added by the JITTAR TROJAN!
Source=Paul Collins Startup list
[DMILDR]
Confirmed=N
Filename=dmildr.exe
Description=Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs
Source=Paul Collins Startup list
[DMISL]
Confirmed=N
Filename=DMISL.EXE
Description=DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
Source=Paul Collins Startup list
[DMISLAPP]
Confirmed=N
Filename=DMISLAPP.exe
Description=DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
Source=Paul Collins Startup list
[Dmsvc32]
Confirmed=X
Filename=Dmsvc32.exe
Description=Added by the AGOBOT.ABU WORM!
Source=Paul Collins Startup list
[dmtdll]
Confirmed=X
Filename=dmtdll.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[DM_server]
Confirmed=X
Filename=dmserver.exe
Description=Comet Cursor adware
Source=Paul Collins Startup list
[Dnar]
Confirmed=X
Filename=Dnar.exe
Description=Unknown, except that it is not necessary. Tends to phone home a lot. DMI related - see here
Source=Paul Collins Startup list
[DNE Binding Watchdog]
Confirmed=Y
Filename=rundll dnes.dll, DnDneCheckBindings
Description=Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
Source=Paul Collins Startup list
[DNE DUN Watchdog]
Confirmed=Y
Filename=rundll dnes.dll, DnDneCheckDUN13
Description=Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
Source=Paul Collins Startup list
[DNS Service]
Confirmed=X
Filename=dnsresolver.exe
Description=Added by the RBOT-PQ WORM!
Source=Paul Collins Startup list
[DNS2GoClient]
Confirmed=?
Filename=dns2goclient.exe
Description=DNS2Go is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. Is it required?
Source=Paul Collins Startup list
[DNXVC]
Confirmed=?
Filename=dnxvc.exe
Description=??
Source=Paul Collins Startup list
[DocTor]
Confirmed=X
Filename=Doctor.exe
Description=Added by the DOTOR.A WORM!
Source=Paul Collins Startup list
[DocuMagix Init]
Confirmed=N
Filename=PWATCH.EXE
Description=PaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed
Source=Paul Collins Startup list
[DOGStart]
Confirmed=X
Filename=GSDOGST.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
Source=Paul Collins Startup list
[Doing]
Confirmed=?
Filename=doing.exe
Description=??
Source=Paul Collins Startup list
[Don't Panic]
Confirmed=U
Filename=dontpanicdemodp.exe
Description=30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite."
Source=Paul Collins Startup list
[Don't Panic Pop-Up Stopper]
Confirmed=U
Filename=dpps2.exe
Description=Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Source=Paul Collins Startup list
[dos]
Confirmed=X
Filename=dos64.exe
Description=Adware downloader trojan
Source=Paul Collins Startup list
[Dosbat]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[DoUWantIt]
Confirmed=N
Filename=duwi.exe
Description=DoUWantIt - online shopping assistant. Start it manually
Source=Paul Collins Startup list
[Download Accelerator Plus 5.0]
Confirmed=N
Filename=DAP.exe
Description=Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is "adware" based
Source=Paul Collins Startup list
[Download Plus]
Confirmed=X
Filename=DownloadPlus.exe
Description=DownloadPlus parasite - opens pop-up adverts
Source=Paul Collins Startup list
[Download Wonder]
Confirmed=N
Filename=DownloadWonder.exe
Description=Download Wonder from Forty Software. Download manager for resuming downloads, amongst other features
Source=Paul Collins Startup list
[DownloadLegalMusic]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=MatrixDialer related
Source=Paul Collins Startup list
[DownloadWare]
Confirmed=X
Filename=dw.exe
Description=DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
Source=Paul Collins Startup list
[DownloadWare Engine]
Confirmed=X
Filename=Dwe.exe
Description=DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
Source=Paul Collins Startup list
[Downxz]
Confirmed=X
Filename=Downxz.bat
Description=Added by the MYDOOM.W WORM
Source=Paul Collins Startup list
[DPAgnt]
Confirmed=N
Filename=DPAgnt.exe
Description=digitalPersona fingerprint scanner
Source=Paul Collins Startup list
[Dpcnav]
Confirmed=Y
Filename=dpcnav.exe
Description=DirecWay from DirectTV satellite based high-speed internet access
Source=Paul Collins Startup list
[dpcproxy]
Confirmed=X
Filename=dpcproxy.exe
Description=Added by the GOLDENP-A TROJAN!
Source=Paul Collins Startup list
[DPCProxyLoadOnStartup]
Confirmed=Y
Filename=dpcstart.exe
Description=DirecWay from DirectTV satellite based high-speed internet access
Source=Paul Collins Startup list
[Dpcstart]
Confirmed=Y
Filename=dpcstart.exe
Description=DirecWay from DirectTV satellite based high-speed internet access. Proxy software
Source=Paul Collins Startup list
[Dpcstart]
Confirmed=U
Filename=dpcstart.exe
Description=Startup program for Direcway 2-way satellite internet service. Loads DirecWay's Navigator, tray icon, etc
Source=Paul Collins Startup list
[dpi]
Confirmed=X
Filename=dpi.exe
Description=Delfin Media Viewer or "Promulgate" adware
Source=Paul Collins Startup list
[dpps2]
Confirmed=U
Filename=dpps2.exe
Description=Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Source=Paul Collins Startup list
[dps]
Confirmed=X
Filename=dps.exe
Description=scumware-remover.org foistware, bogus adware/spyware remover, is in fact itself a browser hijacker, redirecting to smartestsearch.com
Source=Paul Collins Startup list
[Drag'n'Drop_Autolaunch]
Confirmed=N
Filename=Autolaunch.exe
Description=Iomega HotBurn - CD-RW burning software
Source=Paul Collins Startup list
[DragDrop]
Confirmed=?
Filename=DragDrop.exe
Description=??
Source=Paul Collins Startup list
[dregfix]
Confirmed=?
Filename=ph_finder.exe
Description=??
Source=Paul Collins Startup list
[DrgToDsc]
Confirmed=N
Filename=DrgToDsc.exe
Description=Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
Source=Paul Collins Startup list
[dried.exe]
Confirmed=?
Filename=dried.exe
Description=??
Source=Paul Collins Startup list
[DriveLED]
Confirmed=N
Filename=OODLed.exe
Description=O&O DriveLED - displays your HDD LED on your monitor. Start manually
Source=Paul Collins Startup list
[Driver]
Confirmed=X
Filename=gbot.exe
Description=Added by the JUNTADOR.K TROJAN!
Source=Paul Collins Startup list
[Driver32]
Confirmed=X
Filename=Scam32.exe
Description=Added by the SIRCAM WORM!
Source=Paul Collins Startup list
[DriveSelect]
Confirmed=N
Filename=driveselect.exe
Description=DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
Source=Paul Collins Startup list
[dRMON SmartAgent]
Confirmed=U
Filename=SmartAgt.exe
Description=Part of the network monitoring program group for 3Com NIC cards. See here for more info
Source=Paul Collins Startup list
[drmu]
Confirmed=X
Filename=W95Mm.exe
Description=Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread
Source=Paul Collins Startup list
[drocher]
Confirmed=X
Filename=d.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[drvddll.exe]
Confirmed=X
Filename=drvddll.exe
Description=Added by the BEAGLE.AP WORM!
Source=Paul Collins Startup list
[Drvddll_exe]
Confirmed=X
Filename=drvddll.exe
Description=Added by the BEAGLE.X WORM!
Source=Paul Collins Startup list
[DrvListnr]
Confirmed=?
Filename=DrvListnr.exe
Description=Analog Devices SoundMAX soundcard related. What does it do and is it required?
Source=Paul Collins Startup list
[drvlsnr]
Confirmed=U
Filename=drvlsnr.exe
Description=Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
Source=Paul Collins Startup list
[drvr32h]
Confirmed=X
Filename=drvr32h.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[drvrmanager]
Confirmed=X
Filename=drvrquery32.exe
Description=Added by the BOOHOO WORM!
Source=Paul Collins Startup list
[drvsys.exe]
Confirmed=X
Filename=drvsys.exe
Description=Added by the BEAGLE.W WORM!
Source=Paul Collins Startup list
[drvupd]
Confirmed=X
Filename=rundll32 ..drvupd.inf
Description=Hijacker - drvupd.inf file installs a "searchforge.com" hijack
Source=Paul Collins Startup list
[Drwebscheduler]
Confirmed=Y
Filename=Drwebscd.exe
Description=Dr. Web antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem
Source=Paul Collins Startup list
[DR_S]
Confirmed=X
Filename=DR_S.exe
Description=AdShooter adware
Source=Paul Collins Startup list
[DS Clock]
Confirmed=U
Filename=dsclock.exe
Description=Digital desktop clock including synchronization with atomic servers - see here
Source=Paul Collins Startup list
[dsa]
Confirmed=X
Filename=dsa.exe
Description=Homepage hijacker - redirecting to downseek.com
Source=Paul Collins Startup list
[DSAcass]
Confirmed=X
Filename=[path to file]
Description=Added by the RANKY.M TROJAN!
Source=Paul Collins Startup list
[DSB]
Confirmed=X
Filename=DSB.exe
Description=EnergyPlugin adware
Source=Paul Collins Startup list
[DSentry]
Confirmed=N
Filename=DSentry.exe
Description=Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
Source=Paul Collins Startup list
[Dsi]
Confirmed=X
Filename=dp-******.exe
Description=Added by an unidentified adware where ****** are random characters
Source=Paul Collins Startup list
[Dskcompat]
Confirmed=X
Filename=Dskcompat.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[DSL Monitor]
Confirmed=N
Filename=spdstrm.exe
Description=Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
Source=Paul Collins Startup list
[DSLagentexe]
Confirmed=Y
Filename=DSLagent.exe
Description=Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection
Source=Paul Collins Startup list
[dslmon]
Confirmed=Y
Filename=dslmon.exe
Description=Sagem DSL modem related. Apparently needed to detect the modem
Source=Paul Collins Startup list
[DSLSTATEXE]
Confirmed=U
Filename=dslstat.exe
Description=System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
Source=Paul Collins Startup list
[DSS]
Confirmed=X
Filename=dssagent.exe
Description=DSSAgent by Brřderbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info
Source=Paul Collins Startup list
[DSSSGENS]
Confirmed=?
Filename=dssagens.exe
Description=??
Source=Paul Collins Startup list
[DU Meter]
Confirmed=N
Filename=DUMETER.EXE
Description=Hagel Technologies internet bandwidth monitor
Source=Paul Collins Startup list
[dumprep 0 -k]
Confirmed=N
Filename=dumprep 0 -k
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[dumprep 0 -u]
Confirmed=U
Filename=dumprep 0 -u
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[dvd43]
Confirmed=N
Filename=DVD43_Tray.exe
Description=DVD43 is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"
Source=Paul Collins Startup list
[dvd98]
Confirmed=X
Filename=windvd98.exe
Description=Added by the CULT.P WORM!
Source=Paul Collins Startup list
[DVDBitSet]
Confirmed=U
Filename=DVDBitSet.exe
Description=DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
Source=Paul Collins Startup list
[Dvdcompat]
Confirmed=X
Filename=Dvdcompat.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[DVDLauncher]
Confirmed=N
Filename=DVDLauncher.exe
Description=A process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use
Source=Paul Collins Startup list
[DVDSentry]
Confirmed=N
Filename=DSentry.exe
Description=Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
Source=Paul Collins Startup list
[DVDTray]
Confirmed=?
Filename=DVDTray.exe
Description=HP CD/DVD Tray icon. What does it do, and is it required
Source=Paul Collins Startup list
[DVDUpgrade]
Confirmed=?
Filename=DVDUpgrd.exe
Description=??
Source=Paul Collins Startup list
[Dvp95]
Confirmed=Y
Filename=Dvp95.exe
Description=Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine
Source=Paul Collins Startup list
[dvpapi9x]
Confirmed=Y
Filename=DVPAPI9X.exe
Description=Command AntiVirus for Windows 95/98/Me
Source=Paul Collins Startup list
[DvpInitExe]
Confirmed=Y
Filename=Dvpinit.exe
Description=Command Antivirus related
Source=Paul Collins Startup list
[dvprpt]
Confirmed=Y
Filename=Dvprpt.exe
Description=Command Antivirus real time protection
Source=Paul Collins Startup list
[dvraudio]
Confirmed=X
Filename=dvraudio.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[dvsfss]
Confirmed=X
Filename=fbsfsdrs.exe
Description=Added by the SDBOT-QA WORM!
Source=Paul Collins Startup list
[DVSync]
Confirmed=U
Filename=dvsync.exe
Description=DVSync is the program that allows you to synchronize your daVinci’s PDA's data with your Personal Information Manager on the PC
Source=Paul Collins Startup list
[Dvx]
Confirmed=X
Filename=wsxsvc.exe
Description=Delfin Media Viewer or "Promulgate" adware variant
Source=Paul Collins Startup list
[dw]
Confirmed=X
Filename=dw.exe
Description=DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
Source=Paul Collins Startup list
[DWHeartbeatMonitor]
Confirmed=U
Filename=DWHeartbeatMonitor.exe
Description=DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
Source=Paul Collins Startup list
[DwlClient]
Confirmed=N
Filename=support.exe
Description=Download manager for Dell support alerts
Source=Paul Collins Startup list
[Dx]
Confirmed=X
Filename=sys*.exe [* = random number]
Description=Added by the DEXTER.A WORM!
Source=Paul Collins Startup list
[Dx8compat]
Confirmed=X
Filename=Dx8compat.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[DXDllRegExe]
Confirmed=N
Filename=dxdllreg.exe
Description=Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it
Source=Paul Collins Startup list
[DxLoad]
Confirmed=X
Filename=DX3DRndr.exe
Description=Added by the GIBE.B WORM!
Source=Paul Collins Startup list
[DXM6Patch_981116]
Confirmed=N
Filename=p_981116.exe
Description=Win32 cabinet self extractor. More info here
Source=Paul Collins Startup list
[Dxsty]
Confirmed=X
Filename=Dxsty.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Dxupdate.exe]
Confirmed=X
Filename=Dxupdate.exe
Description=Added by the MAFEG WORM!
Source=Paul Collins Startup list
[DyFuCA]
Confirmed=X
Filename=optimize.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[DyFuCA Active Alert]
Confirmed=X
Filename=actalert.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[DynDNS-Updater Traytool]
Confirmed=N
Filename=ddutray.exe
Description=DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually
Source=Paul Collins Startup list
[Dynu Basic Client]
Confirmed=U
Filename=dynubas.exe
Description=Dynu online dynamic IP update client. Useful when using a dial up modem
Source=Paul Collins Startup list
[DZKillMe]
Confirmed=?
Filename=DZSAVEME.EXE
Description=??
Source=Paul Collins Startup list
[E-Card]
Confirmed=X
Filename=ecard.exe
Description=Added by the YODI WORM!
Source=Paul Collins Startup list
[E-color]
Confirmed=U
Filename=IconMgr.Exe
Description=Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
Source=Paul Collins Startup list
[E6TaskPanel]
Confirmed=N
Filename=TaskPanl.exe
Description=Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space
Source=Paul Collins Startup list
[eabconfg.cpl]
Confirmed=U
Filename=EabServr.exe
Description=Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
Source=Paul Collins Startup list
[Eac Download]
Confirmed=X
Filename=download.exe
Description=Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here
Source=Paul Collins Startup list
[EACLEAN]
Confirmed=U
Filename=eaclean.exe
Description=For Compaq PC's. Easy Access button support for the keyboard
Source=Paul Collins Startup list
[Eac_Cnry]
Confirmed=X
Filename=canary.exe
Description=Added by the CANARY TROJAN!
Source=Paul Collins Startup list
[Eac_rnvdl]
Confirmed=?
Filename=ANTIVIRUS_INSTALL.EXE
Description=??
Source=Paul Collins Startup list
[EanthologyApp]
Confirmed=X
Filename=EANTHO~1.EXE
Description=Stop-Sign from eAccelerration. Detects spyware, malware, viruses and keyloggers and stops popups. Spyware itself - read their privacy statement here
Source=Paul Collins Startup list
[eanth_critical_update_alert]
Confirmed=X
Filename=sys_alert.exe
Description=Stop-Sign from eAcceleration. Purports to detect spyware, malware, viruses and keyloggers, but is in fact spyware itself - read their privacy statement here
Source=Paul Collins Startup list
[eanth_system_patcher]
Confirmed=N
Filename=sys_alert.exe
Description=eAcceleration Stop-Sign related - not recommended, see note
Source=Paul Collins Startup list
[Eapcisetup]
Confirmed=N
Filename=sbsetup.exe
Description=Rockwell RipTide soundcard application software. Sound works without it
Source=Paul Collins Startup list
[EAPCISETUP]
Confirmed=N
Filename=wizard.exe
Description=Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
Source=Paul Collins Startup list
[EarthLink ToolBar 5.0]
Confirmed=N
Filename=etoolbar.exe
Description=EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time
Source=Paul Collins Startup list
[Easy Key]
Confirmed=U
Filename=easykey.exe
Description=For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
Source=Paul Collins Startup list
[Easy Start Button]
Confirmed=N
Filename=esb.exe
Description=Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
Source=Paul Collins Startup list
[EasyAV]
Confirmed=X
Filename=EasyAV.exe
Description=Added by the NETSKY.S or NETSKY.T WORMS!
Source=Paul Collins Startup list
[EasyDates]
Confirmed=X
Filename=EasyDates.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[EasyDates_nl]
Confirmed=X
Filename=EasyDates_nl.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[EasyKey]
Confirmed=U
Filename=easykey.exe
Description=For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
Source=Paul Collins Startup list
[EasyMessage]
Confirmed=U
Filename=em2.exe
Description=Easy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See here
Source=Paul Collins Startup list
[EasySearchBar]
Confirmed=X
Filename=ESBUpdate.exe
Description=EasySearchBar adware downloader
Source=Paul Collins Startup list
[easyServ]
Confirmed=X
Filename=Server.exe
Description=Added by the EASYSERV TROJAN!
Source=Paul Collins Startup list
[EasySync Pro]
Confirmed=U
Filename=XCPCMenu.exe
Description=EasySync Pro is a Lotus program for synchronizing a PDA with Lotus Notes
Source=Paul Collins Startup list
[EasyTuneIII]
Confirmed=U
Filename=EasyTune.exe
Description=Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
Source=Paul Collins Startup list
[EasyTuneIV]
Confirmed=U
Filename=ET4Tray.exe
Description=Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
Source=Paul Collins Startup list
[easywww]
Confirmed=X
Filename=easywww2.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[EbatesMoeMoneyMaker]
Confirmed=N
Filename=wjview ...Code
Description=Ebates adware
Source=Paul Collins Startup list
[EbatesMoeMoneyMaker0]
Confirmed=X
Filename=EbatesMoeMoneyMaker0.exe
Description=Ebates adware
Source=Paul Collins Startup list
[eBay Toolbar]
Confirmed=X
Filename=EBAYTBAR.EXE
Description=eBay Toolbar - reportes as spyware as it "phones home"
Source=Paul Collins Startup list
[eBoard]
Confirmed=U
Filename=Eboard.exe
Description=eMachines multimedia keyboard manager. Required if you use the extra keys
Source=Paul Collins Startup list
[eBot]
Confirmed=N
Filename=DownloadWizard.exe
Description=eBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs
Source=Paul Collins Startup list
[ecpe]
Confirmed=?
Filename=ECPE.EXE
Description=??
Source=Paul Collins Startup list
[edexter]
Confirmed=?
Filename=edexter.exe
Description=??
Source=Paul Collins Startup list
[editpad]
Confirmed=X
Filename=editpad.exe
Description=Added by the CONSPER-B TROJAN!
Source=Paul Collins Startup list
[EDLoader]
Confirmed=N
Filename=DTLoader.exe
Description=Effective Desktop from MiniStars Software - desktop management software no longer being supported
Source=Paul Collins Startup list
[EDRestore]
Confirmed=U
Filename=??
Description=Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP"
Source=Paul Collins Startup list
[educational writer]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-LZ WORM!
Source=Paul Collins Startup list
[Edwizard]
Confirmed=U
Filename=Edwizard.exe
Description=SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
Source=Paul Collins Startup list
[eFax.com Tray Menu]
Confirmed=N
Filename=HotTray.exe
Description=eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
Source=Paul Collins Startup list
[efaxs lptt01]
Confirmed=X
Filename=efaxs.exe
Description=Variant of the RapidBlaster parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[efaxs ml097e]
Confirmed=X
Filename=efaxs.exe
Description=Variant of the RapidBlaster parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Efpap.exe]
Confirmed=U
Filename=Efpap.exe
Description=Easy File & Folder Protector. Deny access to certain files and folders, or to hide them securely from viewing and searching
Source=Paul Collins Startup list
[ehTray]
Confirmed=?
Filename=ehtray.exe
Description=eHome Media Center PC related - what does it do and is it required?
Source=Paul Collins Startup list
[ei10.exe]
Confirmed=X
Filename=ei10.exe
Description=Added by the AGOBOT-NK WORM!
Source=Paul Collins Startup list
[Eicon NetworksLAN_DAEMON]
Confirmed=U
Filename=watch.exe
Description=Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Source=Paul Collins Startup list
[Eicon TechnologyLAN_DAEMON]
Confirmed=U
Filename=watch.exe
Description=Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Source=Paul Collins Startup list
[eixfi]
Confirmed=X
Filename=china.bat
Description=Added by the WCUP.A WORM!
Source=Paul Collins Startup list
[Elbycheck]
Confirmed=U
Filename=ElbyCheck.exe
Description=From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
Source=Paul Collins Startup list
[Electron Microscope]
Confirmed=U
Filename=EMIII.exe
Description=Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home, FAH. It will monitor up to 50 clients and give you the details about each client's progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues
Source=Paul Collins Startup list
[Element]
Confirmed=X
Filename=Element.txt
Description=Added by the ELEM TROJAN!
Source=Paul Collins Startup list
[elm]
Confirmed=N
Filename=Elmenv.exe
Description=ViaTech eLicense for securing, distributing and selling music online
Source=Paul Collins Startup list
[ELSA WINman Suite]
Confirmed=U
Filename=Winmsuit.exe
Description=Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU
Source=Paul Collins Startup list
[ElsaCapiCtl]
Confirmed=Y
Filename=Rcapi.exe
Description=Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem
Source=Paul Collins Startup list
[ELSAChipGuard]
Confirmed=U
Filename=elsavect.exe
Description=ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking
Source=Paul Collins Startup list
[EMA.exe]
Confirmed=N
Filename=EMA.EXE
Description=Time management system which helps you to manage your time and appointments
Source=Paul Collins Startup list
[eMachines eBoard]
Confirmed=U
Filename=Eboard.exe
Description=eMachines multimedia keyboard manager. Required if you use the extra keys
Source=Paul Collins Startup list
[emsw.exe]
Confirmed=X
Filename=emsw.exe
Description=Attune HelpExpress - spyware. Disable and uninstall - see here
Source=Paul Collins Startup list
[eMusicClient Systray]
Confirmed=N
Filename=eMusicClient.exe
Description=eMusic MP3 download software
Source=Paul Collins Startup list
[EM_EXEC]
Confirmed=U
Filename=EM_EXEC.EXE
Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
Source=Paul Collins Startup list
[EN4060C Taskbar]
Confirmed=N
Filename=en4060ct.exe
Description=Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
Source=Paul Collins Startup list
[encapsulated command tool]
Confirmed=?
Filename=wintr.com
Description=??
Source=Paul Collins Startup list
[Encarta Dictionary Quickshelf]
Confirmed=N
Filename=QSHLFED.EXE
Description=Provides quick access to Encarta's Dictionary features?
Source=Paul Collins Startup list
[ENCMONITOR]
Confirmed=N
Filename=monitor.exe
Description=The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
Source=Paul Collins Startup list
[Encoder Agent]
Confirmed=N
Filename=WMENCAGT.EXE
Description=MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
Source=Paul Collins Startup list
[Encompass_ENCMONTR]
Confirmed=U
Filename=ENCMONTR.EXE
Description=Optional simple browser from Yahoo (Encompass)
Source=Paul Collins Startup list
[ENCSurf]
Confirmed=?
Filename=surfboard.exe
Description=??
Source=Paul Collins Startup list
[Energizer FileSaver]
Confirmed=U
Filename=Energizer FileSaver.exe
Description=Energizer FileSaver - UPS back-up utility for Energizer UPS products
Source=Paul Collins Startup list
[EngUtil]
Confirmed=Y
Filename=EngUtil.exe
Description=Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
Source=Paul Collins Startup list
[Enh Win Updt]
Confirmed=X
Filename=enhupdt.exe
Description=Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h
Source=Paul Collins Startup list
[enhance32]
Confirmed=X
Filename=enhance32.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[EnigmaPopupStop]
Confirmed=N
Filename=EnigmaPopupStop.exe
Description=SpyHunter - spyware remover of somewhat dubious repute, see note
Source=Paul Collins Startup list
[ENSApServer2_0]
Confirmed=?
Filename=APSERVER.EXE
Description=Intel AnyPoint Wireless II Home Network related. What does it do and is it required?
Source=Paul Collins Startup list
[ENSMIX32.EXE]
Confirmed=?
Filename=ENSMIX32.EXE
Description=Sound card driver. Is it required?
Source=Paul Collins Startup list
[EnsoniqMixer]
Confirmed=U
Filename=starter.exe
Description=Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility
Source=Paul Collins Startup list
[Enumerate Service]
Confirmed=X
Filename=wsys.exe
Description=Added by the MANIFEST TROJAN!
Source=Paul Collins Startup list
[eonemng]
Confirmed=U
Filename=eOneMng.exe
Description=eOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC
Source=Paul Collins Startup list
[ePrompter]
Confirmed=U
Filename=ePrompter.exe
Description=ePrompter - E-mail notification software
Source=Paul Collins Startup list
[EPS]
Confirmed=N
Filename=e_srcv02.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPS]
Confirmed=N
Filename=e_srcv03.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Background Monitor]
Confirmed=N
Filename=STMS.EXE
Description=Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
Source=Paul Collins Startup list
[EPSON CardMonitor]
Confirmed=U
Filename=EPSON CardMonitor1.0.exe
Description=Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check]
Confirmed=N
Filename=e_srcv03.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check]
Confirmed=N
Filename=e_srcv02.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check 2]
Confirmed=N
Filename=e_srcv03.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check 2]
Confirmed=N
Filename=e_srcv02.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[Epson Stylus C62 Series]
Confirmed=U
Filename=E-S0BIC1.EXE
Description=Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
Source=Paul Collins Startup list
[Epson Stylus C82 Series]
Confirmed=U
Filename=e_s0hic1.EXE
Description=Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
Source=Paul Collins Startup list
[EpsonPhotoStarter]
Confirmed=U
Filename=EPSON_PhotoStarter.exe
Description=Only needed if you want to make full use of the capabilities of an Epson printer that included this
Source=Paul Collins Startup list
[Equipmen]
Confirmed=?
Filename=Equipmen.exe
Description=??
Source=Paul Collins Startup list
[EReg]
Confirmed=N
Filename=reg32.exe
Description=EReg is a software registration tool incorporated on products such as those by Brřderbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it
Source=Paul Collins Startup list
[erm]
Confirmed=?
Filename=erm.exe
Description=??
Source=Paul Collins Startup list
[eros.exe]
Confirmed=X
Filename=eros.exe
Description=Adult content dailler
Source=Paul Collins Startup list
[ErrorGuard]
Confirmed=X
Filename=ErrorGuard.exe
Description=Spyware remover of dubious repute
Source=Paul Collins Startup list
[erthgdr]
Confirmed=X
Filename=windll.exe
Description=Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
Source=Paul Collins Startup list
[ERTS0749]
Confirmed=?
Filename=ERTS0749.exe
Description=IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?
Source=Paul Collins Startup list
[eSafe Protect]
Confirmed=Y
Filename=ESPWatch.exe
Description=eSafe from Aladdin - internet security for gateway and E-mail servers
Source=Paul Collins Startup list
[ESB]
Confirmed=U
Filename=esb.exe
Description=Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
Source=Paul Collins Startup list
[eScan Monitor]
Confirmed=Y
Filename=AVKWCTL9X.EXE
Description=eScan antivirus
Source=Paul Collins Startup list
[eScan Scheduler]
Confirmed=U
Filename=avkserv.exe
Description=eScan antivirus scheduler
Source=Paul Collins Startup list
[eScan Updater]
Confirmed=U
Filename=Trayicos.exe
Description=eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads
Source=Paul Collins Startup list
[EScorcher]
Confirmed=X
Filename=escorcher.exe
Description=Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
Source=Paul Collins Startup list
[ESFTP]
Confirmed=N
Filename=esftp.exe
Description=ESftp - FTP client for transfering files between a local PC and another remote computer
Source=Paul Collins Startup list
[Esoh]
Confirmed=X
Filename=Esoh123.exe
Description=Added by the AGOBOT.FF WORM!
Source=Paul Collins Startup list
[ESPN BottomLine]
Confirmed=N
Filename=bline.exe
Description=ESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."
Source=Paul Collins Startup list
[ESS Daemon]
Confirmed=?
Filename=Essd.exe
Description=Related to an ESS based soundacard. Is it required?
Source=Paul Collins Startup list
[essapm]
Confirmed=?
Filename=essapm.exe
Description=ESS Solo soundcard driver. Is it required?
Source=Paul Collins Startup list
[Essdc]
Confirmed=Y
Filename=essdc.exe
Description=Related to an ESS Solo soundcard. Seems as though it's required
Source=Paul Collins Startup list
[ESSNDSYS]
Confirmed=?
Filename=ESSNDSYS.EXE
Description=Related to an ESS based soundacard. Is it required?
Source=Paul Collins Startup list
[ESSOLO]
Confirmed=Y
Filename=ESSOLO.exe
Description=Sound card driver that re-instates itself every time it's removed
Source=Paul Collins Startup list
[esspk]
Confirmed=Y
Filename=esspk.exe
Description=ESS Technology modem speaker driver file. Required to get on-line with this modem
Source=Paul Collins Startup list
[EssSpkPhone]
Confirmed=U
Filename=essspk.exe
Description=ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
Source=Paul Collins Startup list
[Ethernet]
Confirmed=N
Filename=tcaudiag.exe
Description=3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Source=Paul Collins Startup list
[Etraffic]
Confirmed=X
Filename=JavaRun.exe
Description=Marketing software from TopMoxie
Source=Paul Collins Startup list
[eTrust EZ Firewall]
Confirmed=Y
Filename=efpeadm.exe
Description=eTrust EZ Firewall
Source=Paul Collins Startup list
[eTrust PestPatrol Active Protection]
Confirmed=U
Filename=PPActiveDetection.exe
Description=PestPatrol real-time protection feature. "Stops spyware before it infects your system"
Source=Paul Collins Startup list
[eTrustCIPE]
Confirmed=Y
Filename=ezdsmain.exe
Description=eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
Source=Paul Collins Startup list
[EuroGlot]
Confirmed=U
Filename=EuroGlot.exe
Description=Euroglot - "multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian"
Source=Paul Collins Startup list
[Event Log]
Confirmed=?
Filename=eventlog.exe
Description=??
Source=Paul Collins Startup list
[Event Planner Reminders]
Confirmed=N
Filename=PLNRnote.exe
Description=Sierra Event Planner tray icon
Source=Paul Collins Startup list
[Event Reminder]
Confirmed=N
Filename=pmremind.exe
Description=A calendar/alarm program that installs with Brřderbund Printmaster
Source=Paul Collins Startup list
[EVENTLISTENER]
Confirmed=U
Filename=EvLstnr.exe
Description=Used with a Nikon digital camera to recognize when the camera is plugged in
Source=Paul Collins Startup list
[eventmgr]
Confirmed=N
Filename=eventmgr.exe
Description=Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
Source=Paul Collins Startup list
[Evidence Eliminator]
Confirmed=N
Filename=ee.exe
Description=Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis
Source=Paul Collins Startup list
[evntsvc]
Confirmed=N
Filename=evntsc.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version
Source=Paul Collins Startup list
[EVOLOSTA]
Confirmed=U
Filename=EVOLOSTA.EXE
Description=Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it
Source=Paul Collins Startup list
[EvtHtm]
Confirmed=X
Filename=evthtm.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[EW Message Server]
Confirmed=U
Filename=msg32.exe
Description=Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
Source=Paul Collins Startup list
[eWare Startup]
Confirmed=N
Filename=iWareStart.exe
Description=eWare iWare task bar. Not required
Source=Paul Collins Startup list
[ewupdater]
Confirmed=X
Filename=ewupdater.exe
Description=EasyWebSearch adware updater
Source=Paul Collins Startup list
[Excite Platform]
Confirmed=N
Filename=Exlaunch.exe
Description=Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
Source=Paul Collins Startup list
[Excite Private Messenger Pipe]
Confirmed=?
Filename=x8impipe.exe
Description=??
Source=Paul Collins Startup list
[ExciteAssistantEXE]
Confirmed=N
Filename=ASSISTANT.EXE
Description=With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open
Source=Paul Collins Startup list
[exdl.exe]
Confirmed=X
Filename=exdl.exe
Description=BargainBuddy foistware
Source=Paul Collins Startup list
[exe lptt01]
Confirmed=X
Filename=exe.exe
Description=Variant of the RapidBlaster parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[exe ml097e]
Confirmed=X
Filename=exe.exe
Description=Variant of the RapidBlaster parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[execfg4]
Confirmed=X
Filename=execfg4.exe
Description=Added by the ELECTRON WORM!
Source=Paul Collins Startup list
[Execute]
Confirmed=?
Filename=delfolders.exe
Description=??
Source=Paul Collins Startup list
[ExeName32]
Confirmed=X
Filename=Warm.scr
Description=Added by the SCOLD WORM!
Source=Paul Collins Startup list
[exgiwsl]
Confirmed=?
Filename=exgiwsl.exe
Description=??
Source=Paul Collins Startup list
[Exif Launcher]
Confirmed=U
Filename=Exiflaquickdcr.exe
Description=USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
Source=Paul Collins Startup list
[Exif Launcher]
Confirmed=U
Filename=QuickDCF.exe
Description=USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
Source=Paul Collins Startup list
[ExitKiller]
Confirmed=U
Filename=Ekiller.exe
Description=Exit Killer - automatically closes pop-up windows in your browser
Source=Paul Collins Startup list
[exmon]
Confirmed=?
Filename=hpimoniter.exe
Description=Some kind of hp digital camera maybe or a photo smart connection probe?
Source=Paul Collins Startup list
[Explkw]
Confirmed=X
Filename=expup.exe
Description=Keywords hijacker
Source=Paul Collins Startup list
[explore]
Confirmed=X
Filename=explore.exe
Description=Added by any number of VIRUSES, WORMS or TROJANS!
Source=Paul Collins Startup list
[Explore]
Confirmed=X
Filename=Explorer.exe
Description=Added by the IRC.FLOOD.G TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[Explore]
Confirmed=X
Filename=explore.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[explore.exe]
Confirmed=X
Filename=Explore.exe
Description=Added by the GRAYBIRD.G TROJAN!
Source=Paul Collins Startup list
[explorer]
Confirmed=U
Filename=explorer.exe
Description=Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL
Source=Paul Collins Startup list
[explorer]
Confirmed=X
Filename=wscript.exe [filename]
Description=Sneaky way to start any VBS script. Many viruses use VBS files
Source=Paul Collins Startup list
[Explorer]
Confirmed=X
Filename=shellexpl.exe
Description=Added by the GPIX and SHELDOR VIRUSES!
Source=Paul Collins Startup list
[explorer]
Confirmed=X
Filename=expl32.exe
Description=Added by the RATSOU TROJAN!
Source=Paul Collins Startup list
[Explorer]
Confirmed=X
Filename=[path to worm]
Description=Added by the AUTEX WORM!
Source=Paul Collins Startup list
[Explorer]
Confirmed=X
Filename=shellexp.exe
Description=Added by a variant of the SHELDOR TROJAN!
Source=Paul Collins Startup list
[Explorer lptt01]
Confirmed=X
Filename=explorer.exe
Description=Variant of the RapidBlaster parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually!
Source=Paul Collins Startup list
[Explorer ml097e]
Confirmed=X
Filename=explorer.exe
Description=Variant of the RapidBlaster parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually!
Source=Paul Collins Startup list
[Explorer Updater]
Confirmed=X
Filename=IEXPLORE.exe
Description=Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Explorer32]
Confirmed=X
Filename=Expl32.exe
Description=Added by the HACKTACK.B TROJAN!
Source=Paul Collins Startup list
[Exshow95]
Confirmed=U
Filename=EXSHOW95.exe
Description=Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
Source=Paul Collins Startup list
[ExtraDNS]
Confirmed=U
Filename=ExtraDNS.exe
Description=ExtraDNS - DNS configuration tool
Source=Paul Collins Startup list
[Extranet AutoDial]
Confirmed=?
Filename=AutoExt.exe
Description=Nortel Networks Contivity Extranet Switching Software
Source=Paul Collins Startup list
[ExxtremeHelperDemon]
Confirmed=?
Filename=exxdemon.exe
Description=Creative Exxtreme graphics card related?
Source=Paul Collins Startup list
[Eye Tide Launcher]
Confirmed=N
Filename=oneeyetideone.exe
Description=Nascar wallpaper
Source=Paul Collins Startup list
[ezagent]
Confirmed=N
Filename=ezagent.exe
Description=EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs
Source=Paul Collins Startup list
[EZDesk]
Confirmed=N
Filename=EZDESK.EXE
Description=Utility that remembers icon locations for each user and resolution. Available here
Source=Paul Collins Startup list
[EzEjMnAp]
Confirmed=N
Filename=EzEjMnAp.exe
Description=For IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs
Source=Paul Collins Startup list
[eZmmod]
Confirmed=X
Filename=mmod.exe
Description=Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information
Source=Paul Collins Startup list
[EZNORUN]
Confirmed=?
Filename=EZNORUN.EXE
Description=Easy Internet related?
Source=Paul Collins Startup list
[ezPS_Px]
Confirmed=Y
Filename=ezSP_PxEngine.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[ezPS_Px]
Confirmed=Y
Filename=ezSP_Px.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[ezShieldProtector for Px]
Confirmed=Y
Filename=ezSP_Px.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[ezShieldProtector for Px]
Confirmed=Y
Filename=ezSP_PxEngine.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[EZSMART App]
Confirmed=U
Filename=ezsmart.exe
Description=EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
Source=Paul Collins Startup list
[ezula]
Confirmed=X
Filename=eZmmod.exe
Description=Regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information
Source=Paul Collins Startup list
[eZulaMain]
Confirmed=X
Filename=eZulaMain.exe
Description=Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information
Source=Paul Collins Startup list
[eZuluMain]
Confirmed=X
Filename=eZuluMain.exe
Description=Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
Source=Paul Collins Startup list
[eZWO]
Confirmed=X
Filename=wo.exe
Description=Ezula "Web Offer" foistware
Source=Paul Collins Startup list
[E_S10IC2]
Confirmed=U
Filename=E_S10IC2.exe
Description=Epson Stylus printer monitor - for checking ink levels, etc.
Source=Paul Collins Startup list
[E_S23]
Confirmed=U
Filename=E_SICN03.exe
Description=Epson printer status monitor - for checking ink levels, etc.
Source=Paul Collins Startup list
[E_S4I2F1]
Confirmed=N
Filename=E_S4I2F1.exe
Description=Epson Status Monitor 3 for the Epson Stylus Photo R300 (and probably others) printers - monitors the status of a print job spooled to that printer
Source=Paul Collins Startup list
[E_S4I2G1]
Confirmed=?
Filename=E_S4I2G1.EXE
Description=Related to the Epson Stylus CX5400 printer/scanner/copier. What does it do and is it required?
Source=Paul Collins Startup list
[E_SOEIC1]
Confirmed=U
Filename=E_SOEIC1.exe
Description=Epson Stylus printer monitor - for checking ink levels, etc.
Source=Paul Collins Startup list
[F-Secure Management Agent]
Confirmed=U
Filename=FSMA32.EXE
Description=F-Secure Antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products
Source=Paul Collins Startup list
[F-Secure Manager]
Confirmed=Y
Filename=FSM32.EXE
Description=F-Secure Antivirus - carry out scheduled virus scans automatically
Source=Paul Collins Startup list
[F-Secure Startup Wizard]
Confirmed=Y
Filename=FSSW.EXE
Description=F-Secure antivirus
Source=Paul Collins Startup list
[F-Secure TNB]
Confirmed=Y
Filename=TNBUtil.exe
Description=F-Secure antivirus
Source=Paul Collins Startup list
[F-StopW]
Confirmed=Y
Filename=F-StopW.exe
Description=F-Prot anti-virus background scanner by F-Risk Software
Source=Paul Collins Startup list
[f1Tray.exe]
Confirmed=U
Filename=F1TRAY.EXE
Description=System Tray icon for FusionOne’s MightyPhone software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"
Source=Paul Collins Startup list
[f607]
Confirmed=X
Filename=f607.exe
Description=Added by the URAT.B TROJAN!
Source=Paul Collins Startup list
[FamilyKeyLogger]
Confirmed=U
Filename=cisvc.exe
Description="Family Keylogger - is your best choice, if you want to know what other users on your machine are typing". Note! - this is not the cisvc.exe service.
Source=Paul Collins Startup list
[fapmon]
Confirmed=?
Filename=fapmon.exe
Description=Fair Access Policy monitor for DirecPC/DirecWay internet access
Source=Paul Collins Startup list
[farmmext]
Confirmed=X
Filename=farmmext.exe
Description=Transponder parasite updater/installer
Source=Paul Collins Startup list
[Fash]
Confirmed=X
Filename=Fash.exe
Description=Unidentified adware
Source=Paul Collins Startup list
[fast]
Confirmed=N
Filename=fast.exe
Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
Source=Paul Collins Startup list
[FAST Defrag]
Confirmed=N
Filename=FAST2.EXE
Description=FastDefrag defragmenting software
Source=Paul Collins Startup list
[Fast start]
Confirmed=X
Filename=Ntut.exe
Description=Added by unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i
Source=Paul Collins Startup list
[FastCache]
Confirmed=U
Filename=fc.exe
Description=FastCache from AnalogX - speeds up browsing by resolving DNS requests locally
Source=Paul Collins Startup list
[FastTrack Accelerator]
Confirmed=N
Filename=SPEED UP.EXE
Description=FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus
Source=Paul Collins Startup list
[FastUsr]
Confirmed=N
Filename=fast.exe
Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
Source=Paul Collins Startup list
[FatPipe]
Confirmed=U
Filename=DHCP
Description=Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
Source=Paul Collins Startup list
[Fatpipe Dialer]
Confirmed=U
Filename=fpdialer.exe
Description=Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
Source=Paul Collins Startup list
[FBDirect]
Confirmed=U
Filename=FBDirect.exe
Description=Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[FBI]
Confirmed=?
Filename=FBISM.exe
Description=Compaq related but what does it do?
Source=Paul Collins Startup list
[fc]
Confirmed=X
Filename=runfc.exe
Description=Added by the CAMPURF WORM!
Source=Paul Collins Startup list
[FD_SAP]
Confirmed=?
Filename=FD.exe
Description=Genicom SAP Printer driver. Is it required?
Source=Paul Collins Startup list
[FEELitDeviceManager]
Confirmed=U
Filename=feelitdm.exe
Description=Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
Source=Paul Collins Startup list
[fegoze]
Confirmed=X
Filename=SVCH0ST.EXE
Description=Added by the GRAYBIRD.D TROJAN!
Source=Paul Collins Startup list
[Fellowes Proxy]
Confirmed=U
Filename=R3proxy.exe
Description=Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
Source=Paul Collins Startup list
[Fen Startups]
Confirmed=X
Filename=fensvc32.exe
Description=Added by the RANDEX.CCF WORM!
Source=Paul Collins Startup list
[FerrariWallPaper]
Confirmed=U
Filename=FerrariWP.exe
Description=Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
Source=Paul Collins Startup list
[ffis]
Confirmed=X
Filename=ffisearch.exe
Description=iSearch "Desktop Search" hijacker
Source=Paul Collins Startup list
[FG1_00]
Confirmed=U
Filename=frntgate.exe
Description=FrontGate MX - e-mail spam blocker
Source=Paul Collins Startup list
[fGQEGqHOME]
Confirmed=X
Filename=gwwgtp.exe
Description=Added by the RANKY.J TROJAN!
Source=Paul Collins Startup list
[Fhtisxk]
Confirmed=U
Filename=fhtisxk.exe
Description=XtraKeys - keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove via Spybot S&D (for example)
Source=Paul Collins Startup list
[FieldForms Sync]
Confirmed=U
Filename=SyncService.exe
Description=Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well
Source=Paul Collins Startup list
[FiendlyType]
Confirmed=X
Filename=csrss.exe
Description=Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[file indexing service]
Confirmed=?
Filename=msfindfile.exe
Description=New version of MS FindFast and still a resource hog?
Source=Paul Collins Startup list
[File System Service]
Confirmed=X
Filename=wmiprvsc.exe
Description=Added by the AGOBOT-HZ TROJAN!
Source=Paul Collins Startup list
[FileFreedom_Plugin]
Confirmed=N
Filename=wtm.exe
Description=FileFreedom peer-to-peer sharing program
Source=Paul Collins Startup list
[FileManager32]
Confirmed=X
Filename=Wscript.exe ..ChkMgr32.vbs
Description=Added by the NOTUP.A WORM!
Source=Paul Collins Startup list
[FileSoft]
Confirmed=X
Filename=Wscript.exe UpdataFiles.vbs
Description=Added by the SST.B WORM!
Source=Paul Collins Startup list
[FilterGate]
Confirmed=U
Filename=filtergate.exe
Description=Filtergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items
Source=Paul Collins Startup list
[Filterguard]
Confirmed=U
Filename=Filtrgrd.exe
Description=An icon located in the lower left of the screen and looks like a lifesaver. This icon is a “short-cut” to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by “right-clicking” on the icon
Source=Paul Collins Startup list
[Find Fast]
Confirmed=X
Filename=Findfast.exe
Description=Complete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier
Source=Paul Collins Startup list
[Find Virus Launch Program]
Confirmed=Y
Filename=fvlaunch.exe
Description=Part of Dr. Solomon's Antivirus
Source=Paul Collins Startup list
[FinePrint Dispatcher vx]
Confirmed=N
Filename=FPDISPxA.EXE
Description=FinePrint - virtual printer for use with any printer. Search for "dispatcher" here for more information. If removed, it will re-install when program is run - hence the Y recommendation
Source=Paul Collins Startup list
[FineReader7NewsReaderPro]
Confirmed=N
Filename=AbbyyNewsReader.exe
Description=ABBYY FineReader OCR software
Source=Paul Collins Startup list
[FirewallSvr]
Confirmed=X
Filename=FirewallSvr.exe
Description=Added by the NETSKY.X or NETSKY.Y WORMS!
Source=Paul Collins Startup list
[FireWire Driver]
Confirmed=X
Filename=samx.exe
Description=Added by the SDBOT.AE WORM!
Source=Paul Collins Startup list
[First Home Page]
Confirmed=X
Filename=http://find.naupoint.com
Description=Naupoint browser hijacker
Source=Paul Collins Startup list
[Fix-it]
Confirmed=Y
Filename=mxtask.exe
Description=Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required
Source=Paul Collins Startup list
[Fix-it AV]
Confirmed=Y
Filename=memcheck.exe
Description=Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
Source=Paul Collins Startup list
[fkSysMon]
Confirmed=N
Filename=fksysmon.exe
Description=fkWrae SysMon - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more"
Source=Paul Collins Startup list
[FLASH32]
Confirmed=?
Filename=-flash32.exe
Description=??
Source=Paul Collins Startup list
[FlashPath Monitor]
Confirmed=N
Filename=SDSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[FlashPath Monitor]
Confirmed=N
Filename=FLSHSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[FlashPath Status]
Confirmed=N
Filename=SDSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[FlashPath Status]
Confirmed=N
Filename=FLSHSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[Flexicd]
Confirmed=U
Filename=Flexicd.exe
Description=CD player - part of the Win95 Power Toys
Source=Paul Collins Startup list
[FLMTRUSTKB]
Confirmed=?
Filename=KbdAp32A.exe
Description=Keyboard utility for a Trust brand keyboard. What does it do and is it required?
Source=Paul Collins Startup list
[FLMTRUSTMOUSE]
Confirmed=?
Filename=mouse32a.exe
Description=Mouse utility for a Trust brand mouse. What does it do and is it required?
Source=Paul Collins Startup list
[FLooDNeT]
Confirmed=X
Filename=FLooDeR.exe
Description=Added by of the ENDOOL TROJAN!
Source=Paul Collins Startup list
[Flow Go TV]
Confirmed=?
Filename=flogotv.exe
Description=??
Source=Paul Collins Startup list
[flps]
Confirmed=X
Filename=flps.vbs
Description=Added by the BYRON WORM!
Source=Paul Collins Startup list
[flpycntl]
Confirmed=X
Filename=flpycntl.exe
Description=Added by the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[FLSVCI]
Confirmed=?
Filename=FLSVCI.exe
Description=??
Source=Paul Collins Startup list
[FltProcess]
Confirmed=Y
Filename=msinet.exe
Description=Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done
Source=Paul Collins Startup list
[FlyswatDesktop]
Confirmed=X
Filename=flydesk.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[FmctrlTray]
Confirmed=U
Filename=Fmctrl.EXE
Description=Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
Source=Paul Collins Startup list
[fmnwebassist]
Confirmed=X
Filename=fmnwebassist.exe
Description=Adware popup generator
Source=Paul Collins Startup list
[FMStart]
Confirmed=U
Filename=Fmstart.exe
Description=GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop
Source=Paul Collins Startup list
[FMSZ]
Confirmed=X
Filename=fmsz.exe
Description=Added by the FMSZ TROJAN!
Source=Paul Collins Startup list
[Focus]
Confirmed=?
Filename=Focus.exe
Description=ISDN configuration wizard?
Source=Paul Collins Startup list
[Folder Service]
Confirmed=X
Filename=wssdtu.exe
Description=Added by the MANIFEST TROJAN!
Source=Paul Collins Startup list
[Folding@home]
Confirmed=N
Filename=WINFAH.EXE
Description=Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
Source=Paul Collins Startup list
[FoneSyncSystemTray]
Confirmed=N
Filename=FoneSyncSystemTray.exe
Description=System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
Source=Paul Collins Startup list
[FontFix]
Confirmed=X
Filename=fontfix.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[FONTVIEW]
Confirmed=X
Filename=FONTVIEW.EXE
Description=Added by the OPASERV.T WORM!
Source=Paul Collins Startup list
[foobin lptt01]
Confirmed=X
Filename=adaware.exe
Description=Variant of the RapidBlaster parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[foobin ml097e]
Confirmed=X
Filename=adaware.exe
Description=Variant of the RapidBlaster parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[FoolProof]
Confirmed=Y
Filename=fpwinldr.exe
Description=FoolProof Security PC security software from SmartStuff
Source=Paul Collins Startup list
[FoolProofSweep]
Confirmed=Y
Filename=??
Description=Part of FoolProof Security PC security software from SmartStuff
Source=Paul Collins Startup list
[Forbes]
Confirmed=N
Filename=ForbesAlerts.exe
Description=Forbes Business News Alerts - displays business news headlines in a little window on the screen
Source=Paul Collins Startup list
[ForceShow]
Confirmed=X
Filename=rundll32.exe QaBar.dll, ForceShowBar
Description=AdultLinks/QAbar parasite related
Source=Paul Collins Startup list
[Forget Me Not]
Confirmed=N
Filename=AGRemind.exe
Description=Calendar reminder part of American Greetings® CreataCard®
Source=Paul Collins Startup list
[FotoStation Easy AutoLaunch]
Confirmed=N
Filename=FotoStation Easy AutoLaunch.exe
Description=Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
Source=Paul Collins Startup list
[Foul PX]
Confirmed=U
Filename=FoulPX.exe
Description=Foul PX, Optusnet usage stat checker
Source=Paul Collins Startup list
[FourthDay]
Confirmed=U
Filename=FourthDay.exe
Description=The Fourth Day - "astronomical clock and almanac for your system tray"
Source=Paul Collins Startup list
[FP Loader]
Confirmed=Y
Filename=loadfp.exe
Description=FoolProof Security - PC security software from SmartStuff
Source=Paul Collins Startup list
[FPWGMWZD]
Confirmed=?
Filename=FPWGMWZD.exe
Description=??
Source=Paul Collins Startup list
[Fpx]
Confirmed=N
Filename=mnmsrvc.exe
Description=Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
Source=Paul Collins Startup list
[France]
Confirmed=X
Filename=svchost.exe
Description=Added by the MIMAIL.L WORM!. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Fraps]
Confirmed=U
Filename=fraps.exe
Description=Fraps Real-Time Video Capture software
Source=Paul Collins Startup list
[Free Download Manager]
Confirmed=N
Filename=fdm.exe
Description="Free Download Manager" - see here
Source=Paul Collins Startup list
[Free Downloads Monitor]
Confirmed=?
Filename=fdcmon.exe
Description=??
Source=Paul Collins Startup list
[Freedom]
Confirmed=Y
Filename=Freedom.exe
Description=Zero Knowledge Freedom - Anti-Virus, Personal Firewall and Parental Control, it also blocks ads, safeguards your personal information, encrypts your passwords, and much more
Source=Paul Collins Startup list
[FreeMem Pro]
Confirmed=U
Filename=FMEMPRO.EXE
Description=Some users swear by memory management utilities such as FreeMem Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
Source=Paul Collins Startup list
[FreeMemVn2]
Confirmed=U
Filename=FreeMem.exe
Description=Some users swear by memory management utilities such as FreeMem but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
Source=Paul Collins Startup list
[FreeMP3download]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=MatrixDialer related
Source=Paul Collins Startup list
[FreeRAM XP]
Confirmed=U
Filename=FreeRAM XP Pro x.exe
Description=Some users swear by memory management utilities such as FreeRAM XP Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind. "x" indicates the version number
Source=Paul Collins Startup list
[freesurfer]
Confirmed=U
Filename=fs20.exe
Description=EMS Free Surfer mk II - pop-up stopper
Source=Paul Collins Startup list
[Fresh Desktop]
Confirmed=U
Filename=freshdesktop.exe
Description=Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals
Source=Paul Collins Startup list
[freshclam]
Confirmed=N
Filename=freshclam.exe
Description=Auto update agent of the open source Clamwin virus scanner
Source=Paul Collins Startup list
[frguk]
Confirmed=?
Filename=shdrkmck.exe
Description=??
Source=Paul Collins Startup list
[FridaysInHellInstaller]
Confirmed=?
Filename=FridaysInHellInstaller.exe
Description=??
Source=Paul Collins Startup list
[FriendlyType]
Confirmed=X
Filename=lsass.exe
Description=Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[FriendlyTypeName]
Confirmed=X
Filename=services.exe
Description=Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[FriendlyTypeName]
Confirmed=X
Filename=winlogon.exe
Description=Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[FriendlyWebQuick-Launch]
Confirmed=N
Filename=SELFCERT.EXE
Description=selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
Source=Paul Collins Startup list
[FRISK FP-Scheduler]
Confirmed=U
Filename=F-Sched.exe
Description=Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis
Source=Paul Collins Startup list
[Fromine WinPopup]
Confirmed=N
Filename=winpopup.exe
Description=Instant Messenger program
Source=Paul Collins Startup list
[Frsk]
Confirmed=X
Filename=frsk.exe
Description=Unidentified adware downloader trojan
Source=Paul Collins Startup list
[FRW_EXE]
Confirmed=Y
Filename=FRW.EXE
Description=ConSeal Signal9 firewall - now McAfee Personal firewall
Source=Paul Collins Startup list
[frxmxins]
Confirmed=Y
Filename=frxmxins.exe
Description=ATI 3D Studio MAX/VIZ driver
Source=Paul Collins Startup list
[FSCBoss]
Confirmed=N
Filename=FSCBoss.exe
Description=Free Store Club shop online software
Source=Paul Collins Startup list
[FSDPSRV]
Confirmed=?
Filename=FSDPSRV.exe
Description=??
Source=Paul Collins Startup list
[fsg_4104.exe]
Confirmed=?
Filename=fsg_4104.exe
Description=Installed with Kazaa and believed to be Gator adware?
Source=Paul Collins Startup list
[fsp]
Confirmed=U
Filename=fsp.exe
Description=Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents
Source=Paul Collins Startup list
[fspr]
Confirmed=Y
Filename=FolderShield.exe
Description=Folder Shield - hide personal files and folders
Source=Paul Collins Startup list
[FSScrCtl]
Confirmed=N
Filename=FSScrCtl.exe
Description=Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
Source=Paul Collins Startup list
[fsserv]
Confirmed=U
Filename=fserv.exe
Description=Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time
Source=Paul Collins Startup list
[FSW]
Confirmed=X
Filename=FSW.exe
Description=FreeScratchAndWin parasite
Source=Paul Collins Startup list
[FTMSFLT(USB)]
Confirmed=U
Filename=FTMSFLTU.EXE
Description=Fujitsu's Touch Panel Message Notifier
Source=Paul Collins Startup list
[FTPGraber]
Confirmed=X
Filename=FTPGraber.exe
Description=Added by the DLOADER-DT TROJAN!
Source=Paul Collins Startup list
[Ftpqueue]
Confirmed=U
Filename=Ftpsched.exe
Description=Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers
Source=Paul Collins Startup list
[fukerservice]
Confirmed=X
Filename=fukerz.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[fwenc.exe]
Confirmed=Y
Filename=fwenc.exe
Description=Check Point SecuRemote VPN client - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers"
Source=Paul Collins Startup list
[Fwr Command Module]
Confirmed=X
Filename=fwr.exe
Description=Added by the SDBOT-PP WORM!
Source=Paul Collins Startup list
[fwrastrc]
Confirmed=N
Filename=fwrastrc.exe
Description=Dial-up software for Friendly Technologies/1NationOnLine free ISP
Source=Paul Collins Startup list
[fwservice]
Confirmed=X
Filename=fwservice
Description=eAcceleration Stop-Sign related - not recommended, see note
Source=Paul Collins Startup list
[FX]
Confirmed=X
Filename=ieloader.exe
Description=Added by the SMALL.RR TROJAN!
Source=Paul Collins Startup list
[fxredir]
Confirmed=U
Filename=fxredir.exe
Description=Canon MultiPASS fax redirector
Source=Paul Collins Startup list
[f~a]
Confirmed=X
Filename=ra32.exe
Description=Password stealer trojan
Source=Paul Collins Startup list
[G00123]
Confirmed=X
Filename=[worm filename]
Description=Added by the BUGBROS WORM!
Source=Paul Collins Startup list
[g3dctl]
Confirmed=?
Filename=g3dctl.exe
Description=??
Source=Paul Collins Startup list
[Gadu-Gadu]
Confirmed=N
Filename=gg.exe
Description=Polish language Instant Messaging client
Source=Paul Collins Startup list
[Gadwin PrintScreen]
Confirmed=N
Filename=PrintScreen.exe
Description=Gadwin PrintScreen - utility to capture, print or save the current window
Source=Paul Collins Startup list
[Gainward]
Confirmed=U
Filename=TBPanel.exe
Description=Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Game Device]
Confirmed=N
Filename=JOYUPDRV.EXE
Description=Genius game controller profile activator
Source=Paul Collins Startup list
[Games Acceleration]
Confirmed=X
Filename=svshost.exe
Description=EasySearch adware
Source=Paul Collins Startup list
[Games toolbar]
Confirmed=X
Filename=rundll32.exe [path] tbGame.dll, DllShowTB
Description=Topconverting.com\180Search "Games Toolbar" adware
Source=Paul Collins Startup list
[GameSpot]
Confirmed=N
Filename=kontiki.exe
Description=Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
Source=Paul Collins Startup list
[gameutil.exe]
Confirmed=U
Filename=gameutil.exe
Description=Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
Source=Paul Collins Startup list
[GammaHotKeys]
Confirmed=U
Filename=setgamma.exe
Description=Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
Source=Paul Collins Startup list
[Gator]
Confirmed=X
Filename=gator.exe
Description=Spyware - see here for removal instructions
Source=Paul Collins Startup list
[Gator eWallet]
Confirmed=X
Filename=gator.exe
Description=Gator eWallet from The Gator Corporation. Spyware - see here for removal instructions
Source=Paul Collins Startup list
[Gay_Sexy_**]
Confirmed=X
Filename=Gay_Sexy_**.exe
Description=Premium rate adult content dialler (where * is a random char)
Source=Paul Collins Startup list
[GazelDisplay]
Confirmed=U
Filename=gsyno.exe
Description=BT Digital Access USB - Gazel ISDN installation System Tray icon
Source=Paul Collins Startup list
[GBTray]
Confirmed=U
Filename=GBTray.exe
Description=System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[gcasDtServ]
Confirmed=U
Filename=gcasDtServ.exe
Description=Giant Antispyware
Source=Paul Collins Startup list
[gcasServ]
Confirmed=U
Filename=gcasServ.exe
Description=Giant Antispyware
Source=Paul Collins Startup list
[GCC Reminder]
Confirmed=?
Filename=gccrem.exe
Description=Associated with AcraMax Greeting Card Creator. Is it a registration reminder?
Source=Paul Collins Startup list
[GCS]
Confirmed=N
Filename=GrabClipSave.exe
Description=GrabClipSave screen capture tool
Source=Paul Collins Startup list
[GDAX]
Confirmed=X
Filename=[path to backdoor]
Description=Added by the RANKY.K TROJAN!
Source=Paul Collins Startup list
[GDrive]
Confirmed=N
Filename=GDriver.exe
Description=Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
Source=Paul Collins Startup list
[Gearbox]
Confirmed=N
Filename=confsvr.exe
Description=NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here
Source=Paul Collins Startup list
[GEARsec]
Confirmed=N
Filename=gearsec.exe
Description=Installed by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player
Source=Paul Collins Startup list
[GEDZAC]
Confirmed=X
Filename=GEDZAC.exe
Description=Added by the GEMEL WORM!
Source=Paul Collins Startup list
[GemStRmW]
Confirmed=N
Filename=GemStRmW.exe
Description=For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually
Source=Paul Collins Startup list
[Gene USB Monitor]
Confirmed=U
Filename=USBMonit.exe
Description=Monitors USB ports for insertion of Sandisk USB flashdrives
Source=Paul Collins Startup list
[general lptt01]
Confirmed=X
Filename=general.exe
Description=Variant of the RapidBlaster parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[general ml097e]
Confirmed=X
Filename=general.exe
Description=Variant of the RapidBlaster parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Generic host proccess for windows]
Confirmed=X
Filename=SVCHOSTS.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Generic Host Process]
Confirmed=X
Filename=SCHOST.EXE
Description=Added by the RBOT-NC WORM!
Source=Paul Collins Startup list
[Generic Host Process for Win32 Services]
Confirmed=X
Filename=ntspcv.exe
Description=Added by the SDBOT.S TROJAN!
Source=Paul Collins Startup list
[Generic Host Process for Win32 Services]
Confirmed=X
Filename=intspvc.exe
Description=Added by the DINFOR.D WORM!
Source=Paul Collins Startup list
[Generic Host Process for Win32 Services]
Confirmed=X
Filename=winsvc.exe
Description=Added by the SDBOT-O WORM!
Source=Paul Collins Startup list
[Generic Host Service]
Confirmed=X
Filename=lshost.exe
Description=Added by the RBOT.LU WORM!
Source=Paul Collins Startup list
[Generic Service Process]
Confirmed=X
Filename=regsvc32.exe
Description=Added by the GAOBOT.UJ or GAOBOT.UL WORMS!
Source=Paul Collins Startup list
[Generic Services Process]
Confirmed=X
Filename=regsvc32.exe
Description=Added by the GAOBOT.SY WORM!
Source=Paul Collins Startup list
[Genie USB Monitor]
Confirmed=Y
Filename=USBmonitor.exe
Description=Port monitor for an external USB hard drive. Required to enable access to the drive
Source=Paul Collins Startup list
[Get Smile]
Confirmed=N
Filename=getsmile.exe
Description=Puts smilie faces in your E-mail. Run manually when required
Source=Paul Collins Startup list
[GetRight Tray Icon]
Confirmed=N
Filename=GETRIGHT.EXE
Description=GetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs
Source=Paul Collins Startup list
[GetTheMusic]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=MatrixDialer related
Source=Paul Collins Startup list
[GhostStartService]
Confirmed=N
Filename=GhostStartService.exe
Description=Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard
Source=Paul Collins Startup list
[GhostStartTrayApp]
Confirmed=N
Filename=GhostStartTrayApp.exe
Description=System Tray access to Norton Ghost - added from the 2003 version
Source=Paul Collins Startup list
[GhostSurfDelSatellite]
Confirmed=?
Filename=DeleteSatellite.exe
Description=SpyCatcher spyware remover related. What does it do and is it required?
Source=Paul Collins Startup list
[gigabit.exe]
Confirmed=X
Filename=gigabit.exe
Description=Added by the BEAGLE.U WORM!
Source=Paul Collins Startup list
[GigaByte]
Confirmed=X
Filename=Cheatle.exe
Description=Added by the SHODI.B VIRUS!
Source=Paul Collins Startup list
[Gilat SOM Enumerator]
Confirmed=Y
Filename=dllhost.exe
Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Source=Paul Collins Startup list
[GilatFTC]
Confirmed=Y
Filename=ftc.exe
Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Source=Paul Collins Startup list
[GinaDll]
Confirmed=X
Filename=ntgina.dll
Description=Added by the ANIG.A WORM!
Source=Paul Collins Startup list
[GisdnLog]
Confirmed=?
Filename=gisdnlog.exe
Description=BT Digital Access USB
Source=Paul Collins Startup list
[Glass2k]
Confirmed=U
Filename=Glass2k.exe
Description="Glass2k is a small little program that allows Win2K/XP users to make any window transparent"
Source=Paul Collins Startup list
[Glide]
Confirmed=Y
Filename=Glidew32.exe
Description=Cirque touchpad driver
Source=Paul Collins Startup list
[GLSetIT32]
Confirmed=X
Filename=msiexec16.exe
Description=Added by the OPTIX PRO TROJAN!
Source=Paul Collins Startup list
[GLSetIT32]
Confirmed=X
Filename=isass.exe
Description=Added by a variant of the OPTIX PRO TROJAN!
Source=Paul Collins Startup list
[GLSetT32]
Confirmed=X
Filename=smsiexec.exe
Description=Added by the OPTIX-D TROJAN!
Source=Paul Collins Startup list
[gluon]
Confirmed=?
Filename=gluon.exe
Description=In a gluon/bin sub-directory
Source=Paul Collins Startup list
[Gmouse]
Confirmed=Y
Filename=Gmouse.exe
Description=Amouse mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Gnetmous]
Confirmed=U
Filename=gnetmous.exe
Description=Genius NetScroll+ mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[gnub]
Confirmed=?
Filename=gnub.exe
Description=??
Source=Paul Collins Startup list
[Go!Zilla]
Confirmed=X
Filename=gozilla.exe
Description=Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
Source=Paul Collins Startup list
[Go!Zilla Monster Downloads]
Confirmed=X
Filename=Go.exe
Description=Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
Source=Paul Collins Startup list
[GoBack]
Confirmed=U
Filename=GBMenu.exe
Description=Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GoBack]
Confirmed=U
Filename=GBTray.exe
Description=System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GoBack Polling Service]
Confirmed=U
Filename=GBPoll.exe
Description=Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GoBack Tray Icon]
Confirmed=U
Filename=GBTray.exe
Description=System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GOG]
Confirmed=X
Filename=GOG.exe
Description=Added by the PHILIS.B VIRUS!
Source=Paul Collins Startup list
[Goldensoft_MndlSvr]
Confirmed=U
Filename=MndlSvr.exe
Description=Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
Source=Paul Collins Startup list
[golumm]
Confirmed=X
Filename=services.exe
Description=CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Google Desktop Search]
Confirmed=N
Filename=GoogleDesktop.exe
Description=Google Desktop Search - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks"
Source=Paul Collins Startup list
[GoogleDCClient]
Confirmed=N
Filename=GoogleDCC.exe
Description=Google Compute Client - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing"
Source=Paul Collins Startup list
[GoToMyPC]
Confirmed=U
Filename=g2svc.exe
Description=ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser
Source=Paul Collins Startup list
[gouday.exe]
Confirmed=X
Filename=readme.exe
Description=Added by the BEAGLE.C WORM!
Source=Paul Collins Startup list
[GRA]
Confirmed=N
Filename=gra.exe
Description=Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility
Source=Paul Collins Startup list
[gramdate]
Confirmed=?
Filename=2Stop.exe
Description=??
Source=Paul Collins Startup list
[Gravis Appawareloader]
Confirmed=U
Filename=dbserver.exe
Description=Looks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them
Source=Paul Collins Startup list
[Gravis Xperience Driver Support]
Confirmed=U
Filename=Grxp4exe.exe
Description=Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used
Source=Paul Collins Startup list
[GrdSys32]
Confirmed=?
Filename=GrdSys32.exe
Description=X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?
Source=Paul Collins Startup list
[Greetings Workshop]
Confirmed=N
Filename=GWREMIND.EXE
Description=You really want to be reminded about somebody's birthday at the expense of resources?
Source=Paul Collins Startup list
[gremier]
Confirmed=X
Filename=wscript.exe gpremier.vbs
Description=Added by the GPREMIER WORM!
Source=Paul Collins Startup list
[Gremlin]
Confirmed=X
Filename=intrenat.exe
Description=Added by the DOOMJUICE WORM!
Source=Paul Collins Startup list
[Grokster]
Confirmed=N
Filename=Grokster.exe
Description=Grokster Peer-To-Peer File Sharing program
Source=Paul Collins Startup list
[GrpConv]
Confirmed=N
Filename=grpconv.exe
Description=To facilitate the upgrade from Windows 3.1 to Win95/98, an executable file named GRPCONV.EXE is included with Win95/98. This file provides the translation of groups and group items to folders and links unless you need to access Win 3.1 Group files
Source=Paul Collins Startup list
[Gscbc]
Confirmed=?
Filename=Gscbc.exe
Description=??
Source=Paul Collins Startup list
[gshp]
Confirmed=X
Filename=zzgshp.vbs
Description=Homepage hi-jacker
Source=Paul Collins Startup list
[Gsiconexe]
Confirmed=N
Filename=Gsicon.exe
Description=ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities
Source=Paul Collins Startup list
[GSOrganizer]
Confirmed=N
Filename=GSOrganizer.exe
Description=GoldenSection Organizer - personal information manager
Source=Paul Collins Startup list
[gssomatic]
Confirmed=X
Filename=gssomatic.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[GStartup]
Confirmed=X
Filename=GMT.exe
Description=Gator spyware variant. See Gator
Source=Paul Collins Startup list
[Gtwatch]
Confirmed=N
Filename=gtwatch.exe
Description=Associated with a Mustec scanner and not required
Source=Paul Collins Startup list
[Guardian]
Confirmed=N
Filename=CMGrdian.exe
Description=McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
Source=Paul Collins Startup list
[GuruNet]
Confirmed=U
Filename=GuruNet.exe
Description=GuruNet lets you click on any word on your screen to get the relevant information you want
Source=Paul Collins Startup list
[GustavVED]
Confirmed=X
Filename=[filename].exe
Description=Added by the OPASERV.H WORM!
Source=Paul Collins Startup list
[gvagfxj]
Confirmed=X
Filename=rundll32 ...gvagfxj.dll
Description=Unidentified adware, spyware or virus
Source=Paul Collins Startup list
[gw port controller]
Confirmed=Y
Filename=PORTCT95.EXE
Description=From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by Samsung
Source=Paul Collins Startup list
[GWInkMonitor]
Confirmed=N
Filename=GWInkMonitor.exe
Description=Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!
Source=Paul Collins Startup list
[GWMDMMSG]
Confirmed=N
Filename=GWMDMMSG.exe
Description=Used with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
Source=Paul Collins Startup list
[GWMDMpi]
Confirmed=U
Filename=GWMDMpi.exe
Description=Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information
Source=Paul Collins Startup list
[gwum]
Confirmed=U
Filename=gwum.exe
Description=Gigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers"
Source=Paul Collins Startup list
[gyy]
Confirmed=?
Filename=gyy.exe
Description=Possibly Gator (and therefore spyware) related?
Source=Paul Collins Startup list
[H/PC Connection Agent]
Confirmed=U
Filename=WCESCOMM.EXE
Description=Active sync for use with Windows CE based palm PC
Source=Paul Collins Startup list
[HalifaxHowardCluster]
Confirmed=U
Filename=skinkers.exe
Description=Howard the Weatherman desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages
Source=Paul Collins Startup list
[HaMFrontPanel]
Confirmed=U
Filename=hampanel.exe
Description=Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless
Source=Paul Collins Startup list
[Handy Backup 3.9]
Confirmed=U
Filename=hbagent.exe
Description=Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers
Source=Paul Collins Startup list
[Hardware Doctor]
Confirmed=U
Filename=Hwdoctor.exe
Description=Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you're concerned about your system temperature - typically for "overclocked" systems
Source=Paul Collins Startup list
[Hardware Profile]
Confirmed=X
Filename=hxdef.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Hardware Profile]
Confirmed=X
Filename=hxdef.exe...
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Hardware Sensors Monitor]
Confirmed=U
Filename=hmonitor.exe
Description=Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
Source=Paul Collins Startup list
[Hare]
Confirmed=U
Filename=hare.exe
Description=Hare - improve and optimize performance of desktop/laptop PCs
Source=Paul Collins Startup list
[HawkEye]
Confirmed=U
Filename=HAWK_95.EXE
Description=Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[HawkEye IV Control Panel]
Confirmed=U
Filename=HAWK_32.EXE
Description=Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[Hbinst]
Confirmed=X
Filename=Hbinst.exe
Description=Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here
Source=Paul Collins Startup list
[HC Reminder]
Confirmed=N
Filename=hc.exe
Description=For Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed
Source=Paul Collins Startup list
[HCDetect]
Confirmed=N
Filename=HCDetect.exe
Description=MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem
Source=Paul Collins Startup list
[Hcontrol]
Confirmed=U
Filename=hcontrol.exe
Description=Hotkeys on an ASUS Notebook. Only required if you use the additional keys
Source=Paul Collins Startup list
[HDDHealth]
Confirmed=U
Filename=hddhealth.exe
Description=HDD Health is a "full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure"
Source=Paul Collins Startup list
[HDhelp]
Confirmed=?
Filename=tbhdhelp.exe
Description=Associated with Philips Edge series soundcards. Is it required?
Source=Paul Collins Startup list
[HDtray]
Confirmed=N
Filename=HDtray.exe
Description=Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[he3e3fc4]
Confirmed=X
Filename=rundll32.exe [path] he3e3fc4.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[hellodolly]
Confirmed=X
Filename=shost.exe
Description=Added by the YODO WORM!
Source=Paul Collins Startup list
[Help]
Confirmed=?
Filename=helpext.exe
Description=??
Source=Paul Collins Startup list
[helpctl.exe]
Confirmed=X
Filename=helpctl.exe
Description=Added by the GASLIDE TROJAN!
Source=Paul Collins Startup list
[Helper]
Confirmed=X
Filename=eschlp.exe
Description=Added by the BLASTER.T WORM!
Source=Paul Collins Startup list
[helper.dll]
Confirmed=X
Filename=helper.dll, Rundll32
Description=CnsMin "Chinese Keywords" hijacker related
Source=Paul Collins Startup list
[HelpExp.exe]
Confirmed=X
Filename=HelpExp.exe
Description=Attune HelpExpress - spyware. Disable and uninstall - see here
Source=Paul Collins Startup list
[helpmanager]
Confirmed=X
Filename=spoler.exe
Description=Added by the RANDEX.J WORM!
Source=Paul Collins Startup list
[helpw]
Confirmed=X
Filename=helpw.exe
Description=Adware downloader
Source=Paul Collins Startup list
[hen]
Confirmed=X
Filename=[filename].exe
Description=Added by the TARNO.G TROJAN!
Source=Paul Collins Startup list
[hErcUnes]
Confirmed=X
Filename=softhost.exe
Description=Added by the GARROCH WORM!
Source=Paul Collins Startup list
[Hermes Messenger]
Confirmed=U
Filename=DGDRHE~1.EXE
Description=A LAN messenger alternative to WinPopUp - Digital Dreams Software
Source=Paul Collins Startup list
[Hewlett Packard Recorder]
Confirmed=N
Filename=Remind32.exe
Description=HP multifunction registration
Source=Paul Collins Startup list
[Hf]
Confirmed=U
Filename=Hf.exe
Description=Hide Folders - hide your folders so only you can view them
Source=Paul Collins Startup list
[hfxp]
Confirmed=U
Filename=hfxp.exe
Description=Hide Folders XP - hide your folders so only you can view them
Source=Paul Collins Startup list
[HGTXPEI]
Confirmed=N
Filename=FirstReboot.exe
Description=Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[HiberMonitor]
Confirmed=?
Filename=HCount.exe
Description=??
Source=Paul Collins Startup list
[Hibernation]
Confirmed=U
Filename=hib32.exe
Description=Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly
Source=Paul Collins Startup list
[Hid.exe]
Confirmed=X
Filename=hid.exe
Description=Added by the RATSOU.B TROJAN!
Source=Paul Collins Startup list
[HideRun.exe]
Confirmed=X
Filename=Hiderun.exe and svhost.exe and pro.gif
Description=Added by the BOOHOO WORM!
Source=Paul Collins Startup list
[HideStyle]
Confirmed=X
Filename=Ante Browse Trust.exe
Description=IE toolbar taking you to Lop.com. If the exe is running, end it and remove the "Stupidmore" directory from C:\Program Files
Source=Paul Collins Startup list
[hidserv]
Confirmed=U
Filename=hidserv.exe
Description=This is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards
Source=Paul Collins Startup list
[High Definition Audio Property Page Shortcut]
Confirmed=N
Filename=HDAudPropShortcut.exe
Description=Realtek audio card related - probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required
Source=Paul Collins Startup list
[HistoryKill]
Confirmed=N
Filename=histkill.exe
Description=HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs
Source=Paul Collins Startup list
[HitwarePKLite]
Confirmed=U
Filename=HITWAR~1.EXE
Description=Hitware Popup Killer Lite
Source=Paul Collins Startup list
[HIV]
Confirmed=X
Filename=HIV.exe
Description=Added by the HIVA TROJAN!
Source=Paul Collins Startup list
[hkcmd]
Confirmed=U
Filename=hkcmd.exe
Description=Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel
Source=Paul Collins Startup list
[HKLM\Run]
Confirmed=X
Filename=windowsupdate.exe
Description=Added by the FORBOT-BJ WORM! (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)
Source=Paul Collins Startup list
[hkserv]
Confirmed=U
Filename=HKserv.exe
Description=Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
Source=Paul Collins Startup list
[hkss]
Confirmed=U
Filename=hkss.exe
Description=Compaq HotKey Support - multimedia keyboard support
Source=Paul Collins Startup list
[HLL Data Parameter]
Confirmed=X
Filename=hllcxpa.exe
Description=Added by the RBOT.AFG WORM!
Source=Paul Collins Startup list
[Hmonitor]
Confirmed=U
Filename=Hmonitor.exe
Description=Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status
Source=Paul Collins Startup list
[Holiday Lights]
Confirmed=N
Filename=Holiday Lights.exe
Description=Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs
Source=Paul Collins Startup list
[HomeAlarm]
Confirmed=U
Filename=HomeAlarm.exe
Description=Chameleon Clock - system tray clock replacement
Source=Paul Collins Startup list
[HomeCentre WakeUp]
Confirmed=?
Filename=LGWAKEUP.EXE
Description=Associated with the no longer supported Xerox HomeCentre printer/scanner
Source=Paul Collins Startup list
[Honor]
Confirmed=?
Filename=honor.exe
Description=??
Source=Paul Collins Startup list
[Hook99startup]
Confirmed=U
Filename=hk2re.exe
Description="Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent"
Source=Paul Collins Startup list
[HookSys]
Confirmed=U
Filename=HookSys.exe
Description=SurfinGuard Pro - protects against all malicious code delivered through executables, scripting files, ActiveX and Java
Source=Paul Collins Startup list
[HorngTech4D]
Confirmed=Y
Filename=bally4d.exe
Description=HorngTech 4D mouse driver
Source=Paul Collins Startup list
[Host]
Confirmed=X
Filename=N/A
Description=Added by the POPDIS or STARTPAGE.F TROJANS!
Source=Paul Collins Startup list
[HostManager]
Confirmed=?
Filename=AOLHostManager.exe
Description=In a Program Files\Common Files\AOL folder. What does it do, and is it required?
Source=Paul Collins Startup list
[Hot Corners]
Confirmed=U
Filename=Hotc.exe
Description=Hot Corners - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"
Source=Paul Collins Startup list
[Hot Key Kbd 2690 Daemon]
Confirmed=U
Filename=SK9910DM.exe
Description=Multimedia keyboard manager - required if you use any special keys
Source=Paul Collins Startup list
[Hot Key Keybd 9910 Daemon]
Confirmed=U
Filename=SK9910DM.exe
Description=Multimedia keyboard manager - required if you use any special keys
Source=Paul Collins Startup list
[Hot Party 22]
Confirmed=?
Filename=hotpart22.exe
Description=??
Source=Paul Collins Startup list
[Hotbar]
Confirmed=X
Filename=Hbinst.exe
Description=Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here
Source=Paul Collins Startup list
[Hotfix Updat]
Confirmed=X
Filename=svdhost32.exe
Description=Added by the GAOBOT.ZW WORM!
Source=Paul Collins Startup list
[HotIDE]
Confirmed=U
Filename=hotide.exe
Description=HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
Source=Paul Collins Startup list
[HotkeyApp]
Confirmed=U
Filename=HotkeyApp.exe
Description=Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[HotKeysCmds]
Confirmed=U
Filename=hkcmd.exe
Description=Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via Control Panel -> Display Properties
Source=Paul Collins Startup list
[HotPix]
Confirmed=X
Filename=hotpix.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[hotplug]
Confirmed=X
Filename=hotplug.exe
Description=Added by the SILLYDL TROJAN!
Source=Paul Collins Startup list
[HotSync Manager]
Confirmed=N
Filename=hotsync.exe
Description=Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start -> Programs
Source=Paul Collins Startup list
[hotwetlove]
Confirmed=X
Filename=hotwetlove.exe
Description=Adult content dialler. Will not uninstall - components have to be manually deleted
Source=Paul Collins Startup list
[Hot_Kiss]
Confirmed=X
Filename=Hot_Kiss.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Hot_Tarts]
Confirmed=X
Filename=Hot_Tarts.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Hot_Tarts_**]
Confirmed=X
Filename=Hot_Tarts_**.exe
Description=Premium rate adult content dialer (where * is a random char)
Source=Paul Collins Startup list
[HoverDesk]
Confirmed=U
Filename=HoverDesk.exe
Description=HoverDesk - desktop replacement software
Source=Paul Collins Startup list
[hp 1000 firmware]
Confirmed=?
Filename=fwdl.exe
Description=HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?
Source=Paul Collins Startup list
[HP AutoIndexer]
Confirmed=U
Filename=hppautoindexer.exe
Description=Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
Source=Paul Collins Startup list
[HP CD Writer]
Confirmed=N
Filename=hpcdtray.exe
Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
Source=Paul Collins Startup list
[HP CD-DVD]
Confirmed=N
Filename=hpcdtray.exe
Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
Source=Paul Collins Startup list
[hp center]
Confirmed=X
Filename=BACKWEB-137903.exe
Description=Based upon HP's own description from here - "With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music" I have classified this as adware. The number may change - if yours is different let me know
Source=Paul Collins Startup list
[hp center UI]
Confirmed=X
Filename=ShadowBar.exe
Description=User Interface for HP Center
Source=Paul Collins Startup list
[HP Component Manager]
Confirmed=N
Filename=hpcmpmgr.exe
Description=Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
Source=Paul Collins Startup list
[HP Deskjet]
Confirmed=X
Filename=HP_DeskJet_500.exe
Description=Added by the FORBOT-DA WORM!
Source=Paul Collins Startup list
[HP Display Settings]
Confirmed=N
Filename=hpdisply.exe
Description=Sets default display settings. Unchecking this item has been reported to cure a "Problem sending command to keyboard" error message
Source=Paul Collins Startup list
[HP IDScheduler]
Confirmed=?
Filename=HPIDSCHD.exe
Description=HP Instant Delivery Scheduler
Source=Paul Collins Startup list
[HP Info Express]
Confirmed=N
Filename=??
Description=On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
Source=Paul Collins Startup list
[HP Instant Support]
Confirmed=U
Filename=matcli.exe
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[HP Internet Center]
Confirmed=N
Filename=SURFBRD.EXE
Description=Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
Source=Paul Collins Startup list
[HP JetDiscovery]
Confirmed=N
Filename=HPJETDSC.EXE
Description=HP JetAdmin software which monitors printing jobs on a network environment
Source=Paul Collins Startup list
[HP JetSpeed Autostart]
Confirmed=N
Filename=AUTOSTART.EXE
Description=Autostart executable for the old multiplayer game HP Jetspeed
Source=Paul Collins Startup list
[HP Laser Jet Director]
Confirmed=U
Filename=hppdirector.exe
Description=System Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc
Source=Paul Collins Startup list
[HP Network Registry Agent]
Confirmed=?
Filename=hpnra.exe
Description=??
Source=Paul Collins Startup list
[HP OfficeJet Series xxx Startup]
Confirmed=?
Filename=HPOSTR03.EXE
Description=xxx represents the series number - such as 700. What does it do and it it required?
Source=Paul Collins Startup list
[HP OfficeJet Series xxx Startup]
Confirmed=?
Filename=HPOstr05.exe
Description=xxx represents the series number - such as 700. What does it do and it it required?
Source=Paul Collins Startup list
[HP Parallel Port Test]
Confirmed=N
Filename=hppt.exe
Description=Associated with a HP ScanJet scanner
Source=Paul Collins Startup list
[HP Port Resolver]
Confirmed=?
Filename=hpbpro.exe
Description=??
Source=Paul Collins Startup list
[HP Precision Scan]
Confirmed=N
Filename=hpmdlbwx.exe
Description=HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
Source=Paul Collins Startup list
[HP Presentation Ready]
Confirmed=N
Filename=PresRdy.exe
Description=HP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
Source=Paul Collins Startup list
[hp psc 2000 Series]
Confirmed=U
Filename=hpobnz08.exe
Description=System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
Source=Paul Collins Startup list
[HP RecordNow]
Confirmed=U
Filename=??
Description=From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."
Source=Paul Collins Startup list
[HP ScanPatch]
Confirmed=U
Filename=HPScanFix.exe
Description=Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting
Source=Paul Collins Startup list
[HP ScanPicture]
Confirmed=N
Filename=hpsplmwa.exe
Description=HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
Source=Paul Collins Startup list
[HP SchedIndexer]
Confirmed=U
Filename=hppschedindexer.exe
Description=Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
Source=Paul Collins Startup list
[hp Silent Service]
Confirmed=?
Filename=HpSrvUI.exe
Description=HP related
Source=Paul Collins Startup list
[HP Simple Trax]
Confirmed=N
Filename=Hpcron.exe
Description=Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
Source=Paul Collins Startup list
[HP software update]
Confirmed=N
Filename=HPWuSchd2.exe
Description=HP software updates. If a shortcut doesn't exist create your own and run it manually
Source=Paul Collins Startup list
[HP software update]
Confirmed=N
Filename=HPWuSchd.exe
Description=HP software updates. If a shortcut doesn't exist, create your own and run it manually
Source=Paul Collins Startup list
[HP software update]
Confirmed=N
Filename=HPWuSchd2.exe
Description=HP software updates. If a shortcut doesn't exist, create your own and run it manually
Source=Paul Collins Startup list
[HP Status]
Confirmed=N
Filename=hpstatus.exe
Description=HP Printer Status and Alerts
Source=Paul Collins Startup list
[HP Status Server]
Confirmed=?
Filename=hpboid.exe
Description=??
Source=Paul Collins Startup list
[HP Updates]
Confirmed=N
Filename=??
Description=On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
Source=Paul Collins Startup list
[HP Visualize Init]
Confirmed=?
Filename=HpVisIni.exe
Description=HP Visualize software related. What does it do and is it required?
Source=Paul Collins Startup list
[HP-Aio Flight]
Confirmed=N
Filename=Remind32.exe
Description=HP multifunction registration
Source=Paul Collins Startup list
[hpaiodevice]
Confirmed=N
Filename=hpodev07.exe
Description=Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
Source=Paul Collins Startup list
[HPAiODevice(hp psc 900 series) -1]
Confirmed=N
Filename=hpobrt07.exe
Description=Installed with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry
Source=Paul Collins Startup list
[HPAIO_PrintFolderMgr]
Confirmed=N
Filename=hpoopm07.exe
Description=Directly from HP: "This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
Source=Paul Collins Startup list
[hpcmpmgr]
Confirmed=?
Filename=hpcmpmgr.exe
Description=??
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsbol.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsd02.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsb04.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsb05.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[hpfsched]
Confirmed=N
Filename=hpfsched.exe
Description=HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
Source=Paul Collins Startup list
[HPGamesActiveMenu]
Confirmed=U
Filename=ActiveMenu.exe
Description=WildTangent games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[hpgs2wnd]
Confirmed=N
Filename=hpgs2wnd.exe
Description="HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites." Available via Start -> Programs
Source=Paul Collins Startup list
[HPHAxMON]
Confirmed=U
Filename=HPHAxMON.EXE
Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. "x" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards
Source=Paul Collins Startup list
[HPHmon**]
Confirmed=U
Filename=HPHMON**.EXE
Description=Monitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn't inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don't use the reader
Source=Paul Collins Startup list
[HPHmon04]
Confirmed=U
Filename=hphmon04.exe
Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature
Source=Paul Collins Startup list
[HPHmon05]
Confirmed=?
Filename=hphmon05.exe
Description=??
Source=Paul Collins Startup list
[Hphome]
Confirmed=X
Filename=hphome.js
Description=Homepage hijacker
Source=Paul Collins Startup list
[HPHUPD**]
Confirmed=N
Filename=hphupd**.exe
Description=HP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs
Source=Paul Collins Startup list
[HPHUPD05]
Confirmed=?
Filename=hphupd05.exe
Description=??
Source=Paul Collins Startup list
[hpjsiroute]
Confirmed=?
Filename=hpjsira.exe
Description=Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2"
Source=Paul Collins Startup list
[HpLamp]
Confirmed=Y
Filename=HPLAMP.EXE
Description=HP Scanner Utility that controls your scanner’s light bulb. Needed if it's switched on. Also refer here for troubleshooting
Source=Paul Collins Startup list
[hplampc]
Confirmed=U
Filename=hplampc.exe
Description=HP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off
Source=Paul Collins Startup list
[HPLJ Config]
Confirmed=Y
Filename=SetConfig.exe
Description=Connects system to networked HP printer.
Source=Paul Collins Startup list
[HPLogiFinder]
Confirmed=U
Filename=hp_finder.exe
Description=HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
Source=Paul Collins Startup list
[HpMmKbd]
Confirmed=U
Filename=HpMmKbd.exe
Description=HP’s multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
Source=Paul Collins Startup list
[hpodblia]
Confirmed=N
Filename=hpodblia.exe
Description=HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Source=Paul Collins Startup list
[hpoddt01.exe]
Confirmed=N
Filename=N/A
Description=Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started
Source=Paul Collins Startup list
[hpodlb08]
Confirmed=N
Filename=hpodlb08.exe
Description=HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Source=Paul Collins Startup list
[hpotdd01.exe]
Confirmed=Y
Filename=hpotdd01.exe
Description=Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
Source=Paul Collins Startup list
[hpppta]
Confirmed=Y
Filename=HPPPTA.exe
Description=HP parallel port driver for certain hardware
Source=Paul Collins Startup list
[HPPROPTY]
Confirmed=N
Filename=HPPROPTY.EXE
Description=HP LaserJet Toolbox
Source=Paul Collins Startup list
[HPPWRSAV]
Confirmed=U
Filename=HPPWRSAV.EXE
Description=Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com, pick your OS option under the SUPPORT tab, follow the instructions and you will find an updated lamp control patch
Source=Paul Collins Startup list
[hpqcmon]
Confirmed=?
Filename=hpqcmon.exe
Description=From HP and related to digital imaging
Source=Paul Collins Startup list
[HPSCANMonitor]
Confirmed=U
Filename=hpsjvxd.exe
Description=HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
Source=Paul Collins Startup list
[hpScannerFirstBoot]
Confirmed=?
Filename=scannerfb.exe
Description=HP scanner related
Source=Paul Collins Startup list
[hpsjbmgr]
Confirmed=N
Filename=hpsjbmgr.exe
Description=HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment
Source=Paul Collins Startup list
[HPStart]
Confirmed=N
Filename=hpstart.wsf
Description=This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
Source=Paul Collins Startup list
[hpsysconf1]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the VIVIA.A TROJAN!
Source=Paul Collins Startup list
[hpsysdrv]
Confirmed=U
Filename=hpsysdrv.exe
Description=This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working
Source=Paul Collins Startup list
[HPU]
Confirmed=N
Filename=ProvenTactics.exe
Description=Proven Internet Marketing software
Source=Paul Collins Startup list
[HPZTS04]
Confirmed=N
Filename=hpzts04.exe
Description=Hewlett Packard printer toolbox shortcut that resides in the system tray
Source=Paul Collins Startup list
[HP_dla]
Confirmed=N
Filename=dlatray.exe
Description=On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD
Source=Paul Collins Startup list
[HREF.OCX]
Confirmed=U
Filename=regsvr32.exe ....HREF.OCX
Description=HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller
Source=Paul Collins Startup list
[hsim]
Confirmed=X
Filename=isearch.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[hsim]
Confirmed=X
Filename=sexgame.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[hsim]
Confirmed=X
Filename=toolbar.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[Hti]
Confirmed=U
Filename=npdor.exe
Description=Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
Source=Paul Collins Startup list
[HTpatch]
Confirmed=U
Filename=htpatch.exe
Description=HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
Source=Paul Collins Startup list
[HtProtect]
Confirmed=X
Filename=AVprotect.exe
Description=Added by the NETSKY.L WORM!
Source=Paul Collins Startup list
[httpd]
Confirmed=X
Filename=c_pan.exe
Description=Added by a variant of the DELF-A TROJAN!
Source=Paul Collins Startup list
[https-ssl]
Confirmed=X
Filename=https.exe
Description=Added by the MOEGA.D WORM!
Source=Paul Collins Startup list
[huhdir]
Confirmed=?
Filename=huhdir.exe
Description=??
Source=Paul Collins Startup list
[huigezi]
Confirmed=X
Filename=HgzServer.exe
Description=Added by the GRAYBIRD.C TROJAN!
Source=Paul Collins Startup list
[Hvid]
Confirmed=X
Filename=Hvid.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[HWINFO*]
Confirmed=X
Filename=HWINFO*
Description=Added by the PUROL WORM! where * is a random character
Source=Paul Collins Startup list
[HWinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[HXDL.EXE]
Confirmed=X
Filename=HXDL.EXE
Description=Attune HelpExpress - spyware. Disable and uninstall - see here
Source=Paul Collins Startup list
[HXIUL.EXE]
Confirmed=X
Filename=HXIUL.EXE
Description=Attune HelpExpress - spyware. Disable and uninstall - see here
Source=Paul Collins Startup list
[HydarVisionDesktopManager]
Confirmed=U
Filename=desk95.exe
Description=ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this one. HydraVision can be uninstalled through Add/Remove Programs
Source=Paul Collins Startup list
[HydraVisionDesktopManager]
Confirmed=U
Filename=desk98.exe
Description=ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
Source=Paul Collins Startup list
[HydraVisionViewport]
Confirmed=U
Filename=viewport.exe
Description=ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
Source=Paul Collins Startup list
[Hyper Start]
Confirmed=X
Filename=instantmsgrs.exe
Description=Added by the RBOT-NH WORM!
Source=Paul Collins Startup list
[I-Worm.GiGu]
Confirmed=X
Filename=uGiG.eXe
Description=Added by the GINK WORM!
Source=Paul Collins Startup list
[I386]
Confirmed=X
Filename=I386.exe
Description=Added by the MYPOWER WORM!
Source=Paul Collins Startup list
[I81SHELL]
Confirmed=?
Filename=I81SHELL.exe
Description=Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard
Source=Paul Collins Startup list
[i8kfangui]
Confirmed=U
Filename=i8kfangui.exe
Description=Graphical interface for fan speed control
Source=Paul Collins Startup list
[IAAnotif]
Confirmed=U
Filename=iaanotif.exe
Description=IAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
Source=Paul Collins Startup list
[iamapp]
Confirmed=Y
Filename=iamapp.exe
Description=AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well
Source=Paul Collins Startup list
[Iamnacho On Irc.MusIrc.com Is a Homosexual!]
Confirmed=X
Filename=XBox64.exe
Description=Added by the RANDEX.Y WORM!
Source=Paul Collins Startup list
[Iap]
Confirmed=?
Filename=iap.exe
Description=Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?
Source=Paul Collins Startup list
[IASHLPR]
Confirmed=X
Filename=IASHLPR.EXE
Description=Added by the OPASERV.T WORM!
Source=Paul Collins Startup list
[IBM Warranty Notification]
Confirmed=?
Filename=ERTS0749.exe
Description=IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?
Source=Paul Collins Startup list
[ibmmessages]
Confirmed=N
Filename=ibmmessages.exe
Description=Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"
Source=Paul Collins Startup list
[Ibmmon.exe]
Confirmed=?
Filename=Ibmmon.exe
Description=??
Source=Paul Collins Startup list
[Ibmpmsvc]
Confirmed=U
Filename=ibmpmsvc.exe
Description=Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes
Source=Paul Collins Startup list
[IBMUltraBayHotSwapCPLLoader]
Confirmed=U
Filename=IBMBAY2N.EXE
Description=Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
Source=Paul Collins Startup list
[IBMUltraBayHotSwapSound]
Confirmed=?
Filename=IBMBAYSN.EXE
Description=Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?
Source=Paul Collins Startup list
[icdd7ee6]
Confirmed=X
Filename=rundll32.exe [path] icdd7ee6.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[ICH Synth]
Confirmed=N
Filename=eusexe.exe
Description=Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices
Source=Paul Collins Startup list
[iClean]
Confirmed=U
Filename=iClean.exe
Description=IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"
Source=Paul Collins Startup list
[iCn]
Confirmed=N
Filename=NAG.EXE
Description=iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist
Source=Paul Collins Startup list
[ICO]
Confirmed=N
Filename=ICO.EXE
Description=Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
Source=Paul Collins Startup list
[Icon Animation]
Confirmed=N
Filename=HDE.EXE
Description=Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
Source=Paul Collins Startup list
[Icon Hearit 95]
Confirmed=N
Filename=hearit95.exe
Description=Audio desktop customization utility from Moon Valley Software. Resource hog
Source=Paul Collins Startup list
[Icon Hearit 98]
Confirmed=N
Filename=hearit98.exe
Description=Audio desktop customization utility from Moon Valley Software. Resource hog
Source=Paul Collins Startup list
[Icon lptt01]
Confirmed=X
Filename=icon.exe
Description=Variant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Icon ml097e]
Confirmed=X
Filename=icon.exe
Description=Variant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[ICONCLNT]
Confirmed=Y
Filename=iconclnt.exe
Description=APC PowerChute Tray Icon. Associated with the UPS listing
Source=Paul Collins Startup list
[ICONDESK]
Confirmed=U
Filename=ICONDESK.EXE
Description=Small utility which will allow you the option of hiding or showing your desktop icons
Source=Paul Collins Startup list
[Iconfig.exe]
Confirmed=N
Filename=Iconfig.exe
Description=Icon for LS-120 "Superdisk"
Source=Paul Collins Startup list
[iConfigLoader]
Confirmed=X
Filename=DIIhost.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Iconoid]
Confirmed=N
Filename=Iconoid.exe
Description=Iconoid is a desktop icon manager
Source=Paul Collins Startup list
[Iconsaver]
Confirmed=N
Filename=Iconsaver.exe
Description=IconSaver is a desktop icon manager
Source=Paul Collins Startup list
[ICQ Center]
Confirmed=X
Filename=[path to worm]
Description=Added by the RANDIN WORM!
Source=Paul Collins Startup list
[ICQ Hacking Pro]
Confirmed=X
Filename=ICQpro.exe
Description=Added by a variant of the NETSPY TROJAN!
Source=Paul Collins Startup list
[ICQ Lite]
Confirmed=N
Filename=ICQLite.exe
Description=ICQ Lite - compact version of the popular messaging program
Source=Paul Collins Startup list
[ICQ Lite Messenger]
Confirmed=X
Filename=[random filename]
Description=Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or Winnt\System32 directory
Source=Paul Collins Startup list
[ICQ Net]
Confirmed=X
Filename=winlogon.exe
Description=Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[ICQ Plus]
Confirmed=N
Filename=vplus.exe
Description=ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs
Source=Paul Collins Startup list
[ICSDCLT]
Confirmed=U
Filename=rundll32.exe Icsdclt.dll, ICSClient
Description=Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
Source=Paul Collins Startup list
[ICServer]
Confirmed=N
Filename=Icserver.exe
Description=Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
Source=Paul Collins Startup list
[ICSMGR]
Confirmed=Y
Filename=ICSMGR.EXE
Description=Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you’re sharing the internet on various computers
Source=Paul Collins Startup list
[IC_KEY_3]
Confirmed=N
Filename=spvic.exe
Description=Instant Chess related
Source=Paul Collins Startup list
[ID Commander]
Confirmed=N
Filename=IDCom.exe
Description=Caller ID utility for identifying incoming telephone numbers
Source=Paul Collins Startup list
[ID8525]
Confirmed=X
Filename=ID8525.exe
Description=Added by the ID8525.A TROJAN!
Source=Paul Collins Startup list
[ID8525]
Confirmed=X
Filename=id85255.exe
Description=Added by the ID8525.A TROJAN!
Source=Paul Collins Startup list
[IDA]
Confirmed=?
Filename=IDA.EXE
Description=HP related - in a Program FilesHewlett-PackardPC COE folder
Source=Paul Collins Startup list
[IDE]
Confirmed=X
Filename=ide.exe
Description=Added by the ASSASIN.F TROJAN!
Source=Paul Collins Startup list
[IDE Loader]
Confirmed=X
Filename=IDElibr32.exe
Description=Added by the XILON TROJAN! Related to the game "Diablo II"
Source=Paul Collins Startup list
[idecntl]
Confirmed=X
Filename=idecntl.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[iDesktop]
Confirmed=U
Filename=idesktop.exe
Description=Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse
Source=Paul Collins Startup list
[IDMan]
Confirmed=N
Filename=IDMan.exe
Description=Internet Download Manager - download files faster, schedule and resume
Source=Paul Collins Startup list
[IDW Logging Tool]
Confirmed=N
Filename=idwlog.exe
Description=Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
Source=Paul Collins Startup list
[IE Doctor]
Confirmed=U
Filename=IEDoctor.exe
Description=IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
Source=Paul Collins Startup list
[IE Menu Extension toolbar]
Confirmed=X
Filename=rundll32.exe [path] tbextn.dll DllShowTB
Description=Topconverting.com/180Search "IEMenuExtension" toolbar
Source=Paul Collins Startup list
[iecheck]
Confirmed=N
Filename=iecheck.exe
Description=Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
Source=Paul Collins Startup list
[IECleanAux]
Confirmed=U
Filename=Ieboot6.exe
Description=IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
Source=Paul Collins Startup list
[iedll]
Confirmed=X
Filename=iedll.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com
Source=Paul Collins Startup list
[IEDriver]
Confirmed=X
Filename=IEDriver.exe
Description=Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
Source=Paul Collins Startup list
[IEDriver]
Confirmed=X
Filename=xplore.exe
Description=IEDriver adware variant
Source=Paul Collins Startup list
[IEDriver]
Confirmed=X
Filename=TD.exe
Description=IEDriver adware variant
Source=Paul Collins Startup list
[IEengine]
Confirmed=X
Filename=IEeng.exe
Description=STARTPAG.AI hijacker
Source=Paul Collins Startup list
[IEFeatures]
Confirmed=X
Filename=IEFeatures.exe
Description=Added by the POPMON.A TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[IEFeatures]
Confirmed=X
Filename=Internetfeatures.exe
Description=Added by the POPMON.A TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[Iehelper]
Confirmed=X
Filename=syslaunch.exe
Description=Outwar adware downloader
Source=Paul Collins Startup list
[iel2cde8]
Confirmed=X
Filename=rundll32.exe [path] iel2cde8.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[IELoader32]
Confirmed=X
Filename=iexplore32.exe
Description=Added by the SPEX or SPEX.B WORMS!
Source=Paul Collins Startup list
[Iesar]
Confirmed=X
Filename=Iesar.exe
Description=Browser hijacker - redirecting to an adult web page
Source=Paul Collins Startup list
[Iesearch.exe]
Confirmed=X
Filename=Iesearch.exe
Description=LookNSearch adware
Source=Paul Collins Startup list
[iestart]
Confirmed=X
Filename=iexp1orer.exe
Description=Added by the NEMOG.C TROJAN!
Source=Paul Collins Startup list
[ietsr]
Confirmed=N
Filename=ietsr.exe
Description=IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
Source=Paul Collins Startup list
[ieupdate]
Confirmed=X
Filename=MCP****.exe [**** = random char]
Description=Added by the ASOXY TROJAN!
Source=Paul Collins Startup list
[ieupdate]
Confirmed=X
Filename=mcpdll32.exe
Description=Adware downloader trojan
Source=Paul Collins Startup list
[Iexplore]
Confirmed=X
Filename=iexplore.exe
Description=Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[IEXPLORE]
Confirmed=X
Filename=iexplore.exe
Description=Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Iexplore Services]
Confirmed=X
Filename=iexplore.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[iexplorer lptt01]
Confirmed=X
Filename=iexplorer.exe
Description=Variant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[iexplorer ml097e]
Confirmed=X
Filename=iexplorer.exe
Description=Variant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[IFSplash.exe]
Confirmed=U
Filename=IFSplash.exe
Description=I-FORCE driver for force feedback steering wheel
Source=Paul Collins Startup list
[igfxtray]
Confirmed=N
Filename=igfxtray.exe
Description=Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[igsex2x]
Confirmed=X
Filename=igsex2x.exe
Description=NewDial premium rate adult content dialler
Source=Paul Collins Startup list
[iilc]
Confirmed=X
Filename=IILC.EXE
Description=Homepage hijacker
Source=Paul Collins Startup list
[Iinl]
Confirmed=X
Filename=iptl.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[iIWiper]
Confirmed=N
Filename=Systemwiper.exe
Description=System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
Source=Paul Collins Startup list
[IJ75P2PSERVER]
Confirmed=Y
Filename=IJ75P2PS.EXE
Description=Printer utility which is required in order to make the printer work correctly
Source=Paul Collins Startup list
[IKE Service 95]
Confirmed=Y
Filename=IKEService.exe
Description=Associated with PGP. The PGP Tray can be
disabled, but without IKESERVICE you won't be able to de- or encrypt anything
Source=Paul Collins Startup list
[iKeyWorks]
Confirmed=U
Filename=IKEYMAIN.EXE
Description=A4Tech wireless keyboard driver and utility
Source=Paul Collins Startup list
[iLLeGaL]
Confirmed=X
Filename=Mplayer.exe
Description=Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
Source=Paul Collins Startup list
[iLLeGaL.exe]
Confirmed=X
Filename=Mplayer.exe
Description=Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
Source=Paul Collins Startup list
[ILO_Office_Manager]
Confirmed=?
Filename=IntEdReg.exe /OFFMAN
Description=Intense Educational Ltd - Language Office Software. Is it required?
Source=Paul Collins Startup list
[iLyric]
Confirmed=U
Filename=iLyric.exe
Description=iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
Source=Paul Collins Startup list
[iM Start Center]
Confirmed=N
Filename=iM_Tray.exe
Description=Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
Source=Paul Collins Startup list
[Image]
Confirmed=X
Filename=rundll32 image.dll, Install
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Image & Restore]
Confirmed=Y
Filename=IMAGE32.exe
Description=Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run
Source=Paul Collins Startup list
[ImageDrive-{hex numbers}]
Confirmed=U
Filename=ImageDrive.exe
Description=Nero ImageDrive from Ahead - virtual CD/DVD drive software
Source=Paul Collins Startup list
[Imagefox]
Confirmed=U
Filename=imagefox.exe
Description=ImageFox 2.0 is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes
Source=Paul Collins Startup list
[Imagemgt32]
Confirmed=X
Filename=Imagemgt32.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[imekrig]
Confirmed=N
Filename=imekrig.exe
Description=Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
Source=Paul Collins Startup list
[IMEKRMIG6.1]
Confirmed=N
Filename=IMEKRMIG.EXE
Description=Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
Source=Paul Collins Startup list
[Imesh]
Confirmed=N
Filename=??
Description=Imesh is a file sharing system
Source=Paul Collins Startup list
[Imesh Auto Update]
Confirmed=N
Filename=??
Description=Update check for the Imesh file sharing system. Turn the update off under "options"
Source=Paul Collins Startup list
[ImgIcon]
Confirmed=U
Filename=ImgIcon.exe
Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Source=Paul Collins Startup list
[ImgStart]
Confirmed=N
Filename=ImgStart.exe
Description=Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
Source=Paul Collins Startup list
[imjpmig]
Confirmed=N
Filename=IMJPMIG.EXE
Description=Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
Source=Paul Collins Startup list
[Imjpmig8.1]
Confirmed=N
Filename=IMJPMIG.EXE
Description=Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
Source=Paul Collins Startup list
[immcheck.exe]
Confirmed=?
Filename=immcheck.exe
Description=Related to I-FORCE driver for force feedback steering wheel?
Source=Paul Collins Startup list
[IMOL]
Confirmed=U
Filename=IMOLApp.exe
Description=IncrediMail for Office Outlook Add-On
Source=Paul Collins Startup list
[Imonitor]
Confirmed=N
Filename=Plguni.exe
Description=McAfee QuickClean 3.0 - removes internet clutter and unwanted programs
Source=Paul Collins Startup list
[IMStart]
Confirmed=U
Filename=IMStart.exe
Description=InterMute security software related
Source=Paul Collins Startup list
[IMwire]
Confirmed=X
Filename=imwireup.exe
Description=SafeSurfing parasite variant
Source=Paul Collins Startup list
[InCD]
Confirmed=N
Filename=incd.exe
Description=Ahead InCD packet writing software. Similar to DirectCD. On my system there isn't an entry, on another visitor's there is. Run manually before insert an appropriately formatted CD-RW disk
Source=Paul Collins Startup list
[IncMail]
Confirmed=N
Filename=IncMail.exe
Description="IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
Source=Paul Collins Startup list
[InControl Desktop Manager]
Confirmed=N
Filename=DMHKEY.EXE
Description=For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
Source=Paul Collins Startup list
[Incredimail]
Confirmed=N
Filename=incredimail.exe
Description="IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
Source=Paul Collins Startup list
[IndexSearch]
Confirmed=N
Filename=IndexSearch.exe
Description=Associated with PaperPort scanner software from ScanSoft
Source=Paul Collins Startup list
[Inet DataBase]
Confirmed=X
Filename=Inetdbs.exe
Description=Added by the QEDS WORM!
Source=Paul Collins Startup list
[Inet Delivery]
Confirmed=X
Filename=Intdel.exe
Description=Spyware
Source=Paul Collins Startup list
[Inet Delivery]
Confirmed=X
Filename=intdel_2.exe
Description=Spyware
Source=Paul Collins Startup list
[Inetapi]
Confirmed=X
Filename=Netapi.exe
Description=Added by the NETDEVIL.14 TROJAN!
Source=Paul Collins Startup list
[inetcntrl]
Confirmed=U
Filename=inetcntrl.exe
Description=Bsafe Online - internet filter
Source=Paul Collins Startup list
[InetConf]
Confirmed=?
Filename=inetconf.exe
Description=??
Source=Paul Collins Startup list
[Inetd]
Confirmed=U
Filename=INETD32.EXE
Description=Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation
Source=Paul Collins Startup list
[inetinfo.exe]
Confirmed=U
Filename=inetinfo.exe
Description=Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more)
Source=Paul Collins Startup list
[inetmgr]
Confirmed=X
Filename=inetmgr.exe
Description=Actual Names (AdvSearch) Internet Keywords parasite
Source=Paul Collins Startup list
[InetMSN]
Confirmed=X
Filename=msnet.exe
Description=Added by a variant of the SDBOT TROJAN!
Source=Paul Collins Startup list
[Info Select]
Confirmed=U
Filename=is.exe
Description=Info Select from Micro Logic - personal information manager
Source=Paul Collins Startup list
[Info32x]
Confirmed=X
Filename=Info32x.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Infoplay.exe]
Confirmed=?
Filename=Infoplay.exe
Description=Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed?
Source=Paul Collins Startup list
[Infra-red Monitor]
Confirmed=U
Filename=IRMON.EXE
Description=System Tray access to infra-red devices. Not required unless you use infra-red devices
Source=Paul Collins Startup list
[infus]
Confirmed=X
Filename=infus.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Infuzer]
Confirmed=U
Filename=Infuzer.exe
Description=Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"
Source=Paul Collins Startup list
[infwin]
Confirmed=X
Filename=infwin.exe
Description=Msview parasite variant
Source=Paul Collins Startup list
[Initial Page]
Confirmed=X
Filename=install.exe
Description=EasySearch browser hijack installer
Source=Paul Collins Startup list
[Initialize8x8]
Confirmed=Y
Filename=8x8_init.exe
Description=Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
Source=Paul Collins Startup list
[Ink Monitor]
Confirmed=N
Filename=InkMonitor.exe
Description=Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
Source=Paul Collins Startup list
[InkWatch]
Confirmed=N
Filename=InkWatch.exe
Description=Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
Source=Paul Collins Startup list
[InoRPC]
Confirmed=Y
Filename=InoRpc.exe
Description=Associated with eTrust Antivirus/InoculateIT
Source=Paul Collins Startup list
[InoRT]
Confirmed=Y
Filename=InoRT9x.exe
Description=Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see here
Source=Paul Collins Startup list
[InoTask]
Confirmed=U
Filename=InoTask.exe
Description=Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see here
Source=Paul Collins Startup list
[insCOA5]
Confirmed=?
Filename=insCOA5.exe
Description=??
Source=Paul Collins Startup list
[Install Pending Files]
Confirmed=?
Filename=sifxinst.exe
Description=Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?
Source=Paul Collins Startup list
[InstallAurealDemos]
Confirmed=N
Filename=InstallAurealDemos.js
Description=Used to initialize the Aureal A3D demos InstallShield wizard
Source=Paul Collins Startup list
[InstallBuddy]
Confirmed=U
Filename=Ibtna.exe
Description=InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync
Source=Paul Collins Startup list
[Installed shell32.dll]
Confirmed=X
Filename=Office.exe...
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[InstallNAIProduct]
Confirmed=?
Filename=SETUP.EXE
Description=Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?
Source=Paul Collins Startup list
[Instant Access]
Confirmed=X
Filename=rundll32.exe EGDHTML_1023.dll, InstantAccess
Description=Adult content dialler related
Source=Paul Collins Startup list
[Instant Update Center]
Confirmed=N
Filename=reminder.exe
Description=From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG. PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner
Source=Paul Collins Startup list
[Instant Wireless Configuration Utility]
Confirmed=U
Filename=WUSB11cfg.exe
Description=Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
Source=Paul Collins Startup list
[InstantAccess]
Confirmed=N
Filename=INSTAN~1.EXE
Description=From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
Source=Paul Collins Startup list
[InstantDrive]
Confirmed=U
Filename=InstantDrive.exe
Description=Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software
Source=Paul Collins Startup list
[InstantPleasure]
Confirmed=X
Filename=instantpleasure.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[InstantPleasureXXX]
Confirmed=X
Filename=instantpleasurexxx.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[InstantTray]
Confirmed=N
Filename=PCLETray.exe
Description=Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually
Source=Paul Collins Startup list
[instit]
Confirmed=X
Filename=instit.bat
Description=Added by the OPASERV.H WORM!
Source=Paul Collins Startup list
[instit]
Confirmed=X
Filename=INSTIT.BAT
Description=Added by the OPASERV.K WORM!
Source=Paul Collins Startup list
[InstUtlR.exe]
Confirmed=?
Filename=InstUtlR.exe
Description=??
Source=Paul Collins Startup list
[intdctrr]
Confirmed=X
Filename=idctup20.exe
Description=SafeSurfing parasite variant
Source=Paul Collins Startup list
[Intel Active Monitor]
Confirmed=U
Filename=imontray.exe
Description=System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
Source=Paul Collins Startup list
[Intel File Transfer]
Confirmed=U
Filename=xfr.exe
Description=Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
Source=Paul Collins Startup list
[Intel PDS]
Confirmed=U
Filename=pds.exe
Description=Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
Source=Paul Collins Startup list
[Intel Product Number Utility]
Confirmed=U
Filename=IntelProcNumUtility.exe
Description=Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
Source=Paul Collins Startup list
[Intel PROSet Tray Icon]
Confirmed=N
Filename=promon.exe
Description=System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
Source=Paul Collins Startup list
[Intel system works]
Confirmed=X
Filename=iis.exe
Description=Added by the RBOT.QGA WORM!
Source=Paul Collins Startup list
[InteliSys]
Confirmed=X
Filename=smss.exe
Description=Advertisingvision adware - file is located in C:\Windows or C:\Winnt, and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file which would normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[Intellitype]
Confirmed=U
Filename=type32.exe
Description=For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them
Source=Paul Collins Startup list
[IntelMEM]
Confirmed=U
Filename=IntelMEM.exe
Description=Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line
Source=Paul Collins Startup list
[IntelProcNumUtility]
Confirmed=U
Filename=cpunumber.exe
Description=Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
Source=Paul Collins Startup list
[Intel® Common User Interface]
Confirmed=N
Filename=igfxtray.exe
Description=Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Intense Registry Service]
Confirmed=?
Filename=IntEdReg.exe /CHECK
Description=Intense Educational Ltd - Language Office Software. Is it required?
Source=Paul Collins Startup list
[InterceptedSystem]
Confirmed=X
Filename=[path to worm]
Description=Added by the ANACON-B WORM!
Source=Paul Collins Startup list
[InterCheck Monitor]
Confirmed=Y
Filename=Icmon.exe
Description=Part of Sophos ant-virus sofware
Source=Paul Collins Startup list
[Interdll]
Confirmed=X
Filename=Interdll.exe
Description=Added by the DELF family of TROJANS!
Source=Paul Collins Startup list
[Internal]
Confirmed=X
Filename=[trojan filename]
Description=Added by the SMOTHER and TRANSLAT TROJANS!
Source=Paul Collins Startup list
[Internal]
Confirmed=X
Filename=regedit.exe /s %windir%c:\[month number]
Description=Added by the FORTNIGHT.D TROJAN!
Source=Paul Collins Startup list
[InternalSystray]
Confirmed=X
Filename=Kazza.exe
Description=Added by a variant of the OPTIX TROJAN! Note - unlike the valid KaZaA executable, this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP)
Source=Paul Collins Startup list
[internat]
Confirmed=X
Filename=internat.exe
Description=Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
Source=Paul Collins Startup list
[Internat]
Confirmed=X
Filename=systray.exe
Description=Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process
Source=Paul Collins Startup list
[Internat Conf]
Confirmed=X
Filename=bootconf.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com; see for example here
Source=Paul Collins Startup list
[internat.exe]
Confirmed=N
Filename=internat.exe
Description=Language selection icon in system tray
Source=Paul Collins Startup list
[Internat.exe]
Confirmed=X
Filename=internat.exe
Description=Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon
Source=Paul Collins Startup list
[internct]
Confirmed=X
Filename=WinSocks5.exe
Description=Added by the GRAYBIRD.F TROJAN!
Source=Paul Collins Startup list
[Internet Answering Machine]
Confirmed=U
Filename=IAMNET~1.EXE
Description=From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
Source=Paul Collins Startup list
[Internet Answering Machine]
Confirmed=U
Filename=IAM.exe
Description=From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
Source=Paul Collins Startup list
[Internet Config]
Confirmed=X
Filename=svchosts.exe
Description=Added by the SDBOT TROJAN!
Source=Paul Collins Startup list
[Internet Connection Wizard]
Confirmed=X
Filename=stisvsq.exe
Description=EasySearch adware
Source=Paul Collins Startup list
[Internet Download Accelerator]
Confirmed=U
Filename=ida.exe
Description=Internet Download Accelerator download manager
Source=Paul Collins Startup list
[Internet Exploere Services]
Confirmed=X
Filename=urlmon32.dll.exe
Description=Added by the EVIAN.C WORM!
Source=Paul Collins Startup list
[Internet Explorer]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the LORSIS WORM! Note - the legitimate IE (iexplore.exe) does not figure in Msconfig/Startup unless added manually and this loads from the "RunServices" key
Source=Paul Collins Startup list
[Internet Explorer]
Confirmed=X
Filename=IEXPLORE.EXE
Description=Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Internet Explorer Updater]
Confirmed=X
Filename=lexbac.exe
Description=Added by the DOWNLOAD TROJAN!
Source=Paul Collins Startup list
[Internet Explorer Updater]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Source=Paul Collins Startup list
[Internet History Eraser]
Confirmed=U
Filename=HERASER.exe
Description=Internet History Eraser - deletes your browsing tracks
Source=Paul Collins Startup list
[Internet Loader1]
Confirmed=X
Filename=MSInstall61.exe
Description=Added by the KWBOT.B WORM!
Source=Paul Collins Startup list
[Internet Mail and News]
Confirmed=X
Filename=msqdevl.exe
Description=EasySearch adware
Source=Paul Collins Startup list
[Internet Optimizer]
Confirmed=U
Filename=optimize.exe
Description=Internet connection optimizer. Leave this enabled if you find it improves your connection
Source=Paul Collins Startup list
[Internet Send]
Confirmed=X
Filename=More log.exe
Description=Unidentfied adware
Source=Paul Collins Startup list
[Internet Service]
Confirmed=X
Filename=intersvc.exe
Description=Added by the SPYBOT-DE WORM!
Source=Paul Collins Startup list
[internet service]
Confirmed=X
Filename=syscfg32.exe
Description=Added by the RBOT-QS WORM!
Source=Paul Collins Startup list
[Internet Services]
Confirmed=X
Filename=systemdev.exe
Description=Added by the SDBOT-PW WORM!
Source=Paul Collins Startup list
[INTERNET SERVISES]
Confirmed=X
Filename=winz32.exe
Description=Added by the KWBOT.Z WORM!
Source=Paul Collins Startup list
[Internet Sharing Server]
Confirmed=Y
Filename=iss_srvr.exe
Description=Intel AnyPoint internet sharing software
Source=Paul Collins Startup list
[Internet Sweeper]
Confirmed=N
Filename=Sweeper.exe
Description=Internet Sweeper - removes unnecessart left over files after browsing the internet
Source=Paul Collins Startup list
[Internet Timer]
Confirmed=U
Filename=ITIMER.exe
Description=Shareware dial-up connection call cost calculator from Ratsoft
Source=Paul Collins Startup list
[Internet Washer Pro]
Confirmed=X
Filename=iw.exe
Description=Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
Source=Paul Collins Startup list
[Internet.exe]
Confirmed=X
Filename=Internet.exe
Description=Added by the MAGICCALL VIRUS!
Source=Paul Collins Startup list
[InternetWasherPro]
Confirmed=X
Filename=iw.exe
Description=Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
Source=Paul Collins Startup list
[INTERNET_SERVISES]
Confirmed=X
Filename=winz32.exe
Description=Added by the SDBOT.Q TROJAN!
Source=Paul Collins Startup list
[Internt]
Confirmed=X
Filename=Internt.exe
Description=Added by the PEEPER or CARUFAX.A TROJANS!
Source=Paul Collins Startup list
[InterTrust Quick Start]
Confirmed=N
Filename=it_cpq~1.exe
Description=InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business
Source=Paul Collins Startup list
[InterU]
Confirmed=X
Filename=WINDRV.EXE
Description=Added by the IRCINTER.A TROJAN!
Source=Paul Collins Startup list
[Intervideo Win Cinema Manager]
Confirmed=N
Filename=WinCinemaMgr.exe
Description=WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo Win Cinema Manager]
Confirmed=N
Filename=WINCIN~1.EXE
Description=WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinCinema Manager]
Confirmed=N
Filename=WinCinemaMgr.exe
Description=WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinCinema Manager]
Confirmed=N
Filename=WINCIN~1.EXE
Description=WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinScheduler]
Confirmed=N
Filename=WinScheduler.exe
Description=WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinScheduler]
Confirmed=N
Filename=SchSvr.exe
Description=WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Source=Paul Collins Startup list
[InterWARN]
Confirmed=U
Filename=interwarn.exe
Description=InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs
Source=Paul Collins Startup list
[Intmgr]
Confirmed=X
Filename=Intmgr.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Intrenat]
Confirmed=X
Filename=Intrenat.exe
Description=Added by the LEMIR.E TROJAN!
Source=Paul Collins Startup list
[Introducing Media Manager]
Confirmed=N
Filename=SPLASHA.EXE
Description=MS Media Manager tour. Not required
Source=Paul Collins Startup list
[Introduction-Registration]
Confirmed=N
Filename=??
Description=For Compaq PC's. Should only run first time, PC Introduction & Compaq registration
Source=Paul Collins Startup list
[IntruderAlert]
Confirmed=X
Filename=ia99.exe
Description=Intruder Alert '99 from Bonzi - spyware
Source=Paul Collins Startup list
[Ioadqm]
Confirmed=X
Filename=Media Player.exe
Description=Added by the HAWAWI WORM!
Source=Paul Collins Startup list
[iolo Task Agent]
Confirmed=U
Filename=Task_Agent.exe
Description=iOlo System Mechanic Task Agent. Scheduled maintenance
Source=Paul Collins Startup list
[Iomega Automatic Backup]
Confirmed=U
Filename=ibackup.exe
Description=Iomega Automatic Backup - automatic backups for use with Iomega portable HDD
Source=Paul Collins Startup list
[Iomega Automatic Backup 1.0.1]
Confirmed=U
Filename=ibackup.exe
Description=Iomega Automatic Backup - automatic backups for use with Iomega portable HDD
Source=Paul Collins Startup list
[Iomega Backup Scheduler]
Confirmed=N
Filename=dtiom98.exe
Description=Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
Source=Paul Collins Startup list
[Iomega Disk Icons]
Confirmed=U
Filename=IMGICON.EXE
Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Source=Paul Collins Startup list
[Iomega Drive Icons]
Confirmed=U
Filename=IMGICON.EXE
Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Source=Paul Collins Startup list
[Iomega ImIconXP]
Confirmed=U
Filename=imiconxp.exe
Description=Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks
Source=Paul Collins Startup list
[Iomega QuickSync]
Confirmed=?
Filename=Quicksync.exe
Description=??
Source=Paul Collins Startup list
[Iomega Startup Options]
Confirmed=N
Filename=IMGSTART.EXE
Description=Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
Source=Paul Collins Startup list
[Iomega Watch]
Confirmed=N
Filename=IOWATCH.EXE
Description=Used by Iomega drives. Available via Start -> Programs
Source=Paul Collins Startup list
[IomegaWare]
Confirmed=N
Filename=COMMANDER.EXE
Description=Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
Source=Paul Collins Startup list
[Iomon98.exe]
Confirmed=U
Filename=Iomon98.exe
Description=PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
Source=Paul Collins Startup list
[IP Stack]
Confirmed=X
Filename=ipstack.exe
Description=Added by the AGOBOT.CW WORM!
Source=Paul Collins Startup list
[iPalm]
Confirmed=N
Filename=mon.exe
Description=Installed with a Panasonic iPalm digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded
Source=Paul Collins Startup list
[ipcfg.exe]
Confirmed=X
Filename=ipcfg.exe
Description=Adware - recognized by McAfee antivirus as a variant of the AdClicker-BM trojan
Source=Paul Collins Startup list
[IPConfig]
Confirmed=X
Filename=svcxnv32.exe
Description=Added by the HACARMY.E TROJAN!
Source=Paul Collins Startup list
[IpCtrl]
Confirmed=X
Filename=ipcon32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[IPInSightLAN 01]
Confirmed=X
Filename=ipclient.exe
Description=Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly "phones home" and wastes resource - hence the "X" status
Source=Paul Collins Startup list
[IPInSightMonitor 01]
Confirmed=N
Filename=ipmon32.exe
Description=Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information
Source=Paul Collins Startup list
[IPinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[ipmon.exe]
Confirmed=X
Filename=ipmon.exe
Description=Added by the RECERV or R3C.B TROJANS!
Source=Paul Collins Startup list
[iPodManager]
Confirmed=U
Filename=iPodManager.exe
Description=Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods
Source=Paul Collins Startup list
[iPodWatcher]
Confirmed=?
Filename=iPodWatcher.exe
Description=Associated with Apple's iPod MP3 player. Detects when the iPod is connected?
Source=Paul Collins Startup list
[iProtectYou]
Confirmed=U
Filename=ip.exe
Description=iProtectYou - internet filtering/parental control and network monitoring software
Source=Paul Collins Startup list
[IPSecMon]
Confirmed=Y
Filename=IPSecMon.exe
Description=Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
Source=Paul Collins Startup list
[IPTable Configuration]
Confirmed=X
Filename=Winipcfgs.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[IPv6 Helper Driver]
Confirmed=X
Filename=csass.exe
Description=Added by the AGOBOT.TC WORM!
Source=Paul Collins Startup list
[IPv6 STUN Service]
Confirmed=X
Filename=netstun.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[IPW]
Confirmed=?
Filename=IPW.exe
Description=??
Source=Paul Collins Startup list
[IQES.exe]
Confirmed=?
Filename=iqes.exe
Description=??
Source=Paul Collins Startup list
[irc session]
Confirmed=X
Filename=sessionmgr.exe
Description=Added by the SDBOT-ACE WORM!
Source=Paul Collins Startup list
[IREIKE]
Confirmed=Y
Filename=IreIKE.exe
Description=Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
Source=Paul Collins Startup list
[iRis Active Monitor]
Confirmed=N
Filename=winmon32.exe
Description=Iris Antivirus - discontinued, replace with good alternative
Source=Paul Collins Startup list
[iRiS AntiVirus Active Monitor]
Confirmed=N
Filename=WIMMUN32.exe
Description=Iris Antivirus - discontinued, replace with good alternative
Source=Paul Collins Startup list
[iRiver Updater]
Confirmed=N
Filename=Updater.exe
Description=Updates for the iRiver Music Manager - used with their digital music players
Source=Paul Collins Startup list
[IrMon]
Confirmed=U
Filename=IRMON.EXE
Description=System Tray access to infra-red devices. Not required unless you use infra-red devices
Source=Paul Collins Startup list
[IRPMonitor]
Confirmed=?
Filename=itcnmon.exe
Description=??
Source=Paul Collins Startup list
[Irwftp]
Confirmed=X
Filename=[path to trojan]
Description=Added by the BANCOS.CR TROJAN!
Source=Paul Collins Startup list
[irwftp]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the BANKER-AN TROJAN!
Source=Paul Collins Startup list
[IrXfer]
Confirmed=U
Filename=IrXfer.exe
Description=Microsoft Infrared Transfer application
Source=Paul Collins Startup list
[ir_ftp]
Confirmed=X
Filename=ir_ftp.exe
Description=Added by the IRFTP TROJAN!
Source=Paul Collins Startup list
[ir_ftp]
Confirmed=X
Filename=irwftp.exe
Description=Added by the BANCOS.H TROJAN!
Source=Paul Collins Startup list
[IS CfgWiz]
Confirmed=N
Filename=cfgwiz.exe
Description=Norton Internet Security configuration wizard
Source=Paul Collins Startup list
[Isass]
Confirmed=X
Filename=Isass.exe
Description=Added by the FUTRO TROJAN!
Source=Paul Collins Startup list
[isdbdc]
Confirmed=N
Filename=isdbdc.exe
Description=For Compaq PC's. May install properties in dial-up networking when you register with an ISP
Source=Paul Collins Startup list
[ISDN Monitor]
Confirmed=N
Filename=Linksts.exe
Description=Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
Source=Paul Collins Startup list
[ISDNwatch]
Confirmed=U
Filename=IWatch.exe
Description=FRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"
Source=Paul Collins Startup list
[ISLP2STA]
Confirmed=N
Filename=ISLP2STA.EXE
Description=Possibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though
Source=Paul Collins Startup list
[iSpyNOW]
Confirmed=U
Filename=ispynow.exe
Description=iSpyNOW - remote monitoring and surveillance software
Source=Paul Collins Startup list
[Israfel]
Confirmed=X
Filename=Israfel.vbs
Description=Added by the GAGGLE.D or GAGGLE.E WORMS!
Source=Paul Collins Startup list
[ISStart]
Confirmed=U
Filename=ISStart.exe
Description=LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Source=Paul Collins Startup list
[IST Service]
Confirmed=X
Filename=istsvc.exe
Description=ISTBar foistware
Source=Paul Collins Startup list
[ist service uninstall]
Confirmed=X
Filename=[random filename]
Description=ISTBar parasite related
Source=Paul Collins Startup list
[ISUSPM Startup]
Confirmed=N
Filename=ISUSPM.exe
Description=InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you’re always working with the most current version
Source=Paul Collins Startup list
[ISUSScheduler]
Confirmed=N
Filename=issch.exe
Description=InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you’re always working with the most current version
Source=Paul Collins Startup list
[Itk]
Confirmed=U
Filename=Itk.exe
Description=In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Source=Paul Collins Startup list
[iTouch]
Confirmed=U
Filename=iTouch.exe
Description=iTouch loads the iTouch configuration program for Logitech keyboards. It’s needed if your keyboard has shortcut buttons and if you use them. It’s also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock
Source=Paul Collins Startup list
[ItsDeductiblePopUp]
Confirmed=N
Filename=ItsDeductible.exe
Description=ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip
Source=Paul Collins Startup list
[iTunes Helper]
Confirmed=Y
Filename=iTunesHelper.exe
Description=Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
Source=Paul Collins Startup list
[Iusage]
Confirmed=N
Filename=netdet.exe
Description=Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up
Source=Paul Collins Startup list
[IW ControlCenter]
Confirmed=N
Filename=iwctrl.exe
Description=Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
Source=Paul Collins Startup list
[iwctrl]
Confirmed=U
Filename=iwctrl.exe
Description=Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
Source=Paul Collins Startup list
[IZE]
Confirmed=?
Filename=N/A
Description=??
Source=Paul Collins Startup list
[j2 Tray Menu]
Confirmed=N
Filename=HotTray.exe
Description=eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
Source=Paul Collins Startup list
[Jammer]
Confirmed=U
Filename=jammer.exe
Description=Jammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"
Source=Paul Collins Startup list
[Jammer2nd]
Confirmed=X
Filename=Jammer2nd.exe
Description=Added by the NETSKY.Z WORM!
Source=Paul Collins Startup list
[Java Runtimes]
Confirmed=X
Filename=iexplore.exe
Description=Added by the KILLAV.B TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[JavaUpdate0.07]
Confirmed=X
Filename=[filename]
Description=Added by the JUPDATE TROJAN!
Source=Paul Collins Startup list
[JavaVM]
Confirmed=X
Filename=java.exe
Description=Added by the MYDOOM.M or MYDOOM.N WORMS! Note - not to be confused with the valid Windows "java.exe" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt
Source=Paul Collins Startup list
[jawa32]
Confirmed=X
Filename=jawa32.exe
Description=Added by the AGENT.BG WORM!
Source=Paul Collins Startup list
[Jawa322]
Confirmed=X
Filename=jawa32.exe
Description=Added by a variant of the AGENT.BG trojan
Source=Paul Collins Startup list
[JB]
Confirmed=N
Filename=Jiffybar.exe
Description="Get Paid As You surf" application
Source=Paul Collins Startup list
[Jet Detection]
Confirmed=N
Filename=ADGJDet.exe
Description=Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Source=Paul Collins Startup list
[JetAdmin Discovery Indicator]
Confirmed=Y
Filename=HPJETDSC.EXE
Description=HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator
Source=Paul Collins Startup list
[jijbl]
Confirmed=X
Filename=ezlwy.bat
Description=Added by the REDDW WORM!
Source=Paul Collins Startup list
[JobHisInit]
Confirmed=U
Filename=JobHisInit.exe
Description=Used by Ricoh network printers to enable network printing from the client
Source=Paul Collins Startup list
[Jog Serve]
Confirmed=U
Filename=JogServ2.exe
Description="Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
Source=Paul Collins Startup list
[JogServ2]
Confirmed=U
Filename=JogServ2.exe
Description="Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
Source=Paul Collins Startup list
[jotl]
Confirmed=?
Filename=millenzje.exe
Description=??
Source=Paul Collins Startup list
[Jreg]
Confirmed=X
Filename=Jreg2b.exe
Description=BroadcastPC adware variant
Source=Paul Collins Startup list
[jusched]
Confirmed=N
Filename=jusched.exe
Description=Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
Source=Paul Collins Startup list
[jushed32.exe]
Confirmed=X
Filename=jushed32.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[jutsu]
Confirmed=X
Filename=jutsu.exe
Description=Added by the RBOT-LS WORM!
Source=Paul Collins Startup list
[jv16 PT TempFileTool]
Confirmed=U
Filename=TempTool.exe
Description=jv16 PowerTools' temporary file remover
Source=Paul Collins Startup list
[Jv16pt Network Resident]
Confirmed=U
Filename=jv16pt_network.exe
Description=jv16 PowerTools' network resident program. Only needed if you are using the program's network features
Source=Paul Collins Startup list
[jvdnlssn]
Confirmed=X
Filename=fljzsshc.exe
Description=Flingstone.com adware - and its Golden Palace Casino program
Source=Paul Collins Startup list
[Jzi16]
Confirmed=?
Filename=jzi16.exe
Description=??
Source=Paul Collins Startup list
[K2ps_full.task]
Confirmed=X
Filename=K2ps_full.exe
Description=Added by the JUNTADOR.K TROJAN!
Source=Paul Collins Startup list
[K6CPU.EXE]
Confirmed=N
Filename=K6CPU.EXE
Description=Authenticates CPU as K6 in system properties
Source=Paul Collins Startup list
[kak]
Confirmed=X
Filename=kak.hta
Description=Added by the KAKWORM WORM!
Source=Paul Collins Startup list
[Kalibump]
Confirmed=U
Filename=Kalibump.exe
Description=Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy
Source=Paul Collins Startup list
[kalvsys]
Confirmed=X
Filename=kalv****.exe [* = random char]
Description=EliteBar/SearchMiracle adware installer
Source=Paul Collins Startup list
[kalvsys]
Confirmed=X
Filename=kalv***32.exe [* = random char]
Description=EliteBar/SearchMiracle adware installer
Source=Paul Collins Startup list
[Kana Reminder]
Confirmed=N
Filename=Reminder.exe
Description=Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time
Source=Paul Collins Startup list
[Kaspersky Antivirus]
Confirmed=X
Filename=KasperskyAV.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[KasperskyAv]
Confirmed=X
Filename=kaspersky.exe
Description=Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky AntiVirus
Source=Paul Collins Startup list
[KasperskyAVEng]
Confirmed=X
Filename=Kasperskyaveng.exe
Description=Added by the NETSKY.V WORM!
Source=Paul Collins Startup list
[KAVPersonal50]
Confirmed=Y
Filename=Kav.exe
Description=Kaspersky Anti-Virus Personal 5.0
Source=Paul Collins Startup list
[KavRuns]
Confirmed=X
Filename=Windll.exe
Description=Added by the TRYNOMA TROJAN!
Source=Paul Collins Startup list
[KAVutil]
Confirmed=X
Filename=[worm filename]
Description=Added by the WINTOO.B WORM!
Source=Paul Collins Startup list
[KAZAA]
Confirmed=N
Filename=kazaa.exe
Description=KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it
Source=Paul Collins Startup list
[Kazaa Download Accelerator Updater (required)]
Confirmed=X
Filename=regsvr32 [path] kdp****.dll [* = random char]
Description=SafeguardProtect/Veevo hijacker
Source=Paul Collins Startup list
[Kazaa lptt01]
Confirmed=X
Filename=kazaa.exe
Description=Variant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
Source=Paul Collins Startup list
[Kazaa ml097e]
Confirmed=X
Filename=kazaa.exe
Description=Variant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
Source=Paul Collins Startup list
[KAZAACuf]
Confirmed=X
Filename=9
Description=Added by the KITRO.D (or ARGEN.A) WORM!
Source=Paul Collins Startup list
[kazaalite]
Confirmed=N
Filename=kazaalite.exe
Description=Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms
Source=Paul Collins Startup list
[KaZooM]
Confirmed=N
Filename=KaZooM.Exe
Description=KaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"
Source=Paul Collins Startup list
[KBD]
Confirmed=U
Filename=KBD.EXE
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[KBD MediaCenter]
Confirmed=U
Filename=MEDIACTR.EXE
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[kbddrv32]
Confirmed=X
Filename=kbddrv32.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[kbddrvinf]
Confirmed=X
Filename=kbddrvinf.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[KCeasy]
Confirmed=N
Filename=KCeasy.exe
Description=KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella
Source=Paul Collins Startup list
[KClient]
Confirmed=U
Filename=kstatus.exe
Description=KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
Source=Paul Collins Startup list
[kdx]
Confirmed=N
Filename=KHost.exe
Description=KonTiki Secure Delivery Plug In related. "The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers"
Source=Paul Collins Startup list
[KE9801]
Confirmed=U
Filename=DriBat32.exe
Description=KE-9801 multimedia keyboard - required if you use the multimedia keys
Source=Paul Collins Startup list
[Keenvalue]
Confirmed=X
Filename=Keenvalue.exe
Description=Keenvalue spyware - see here
Source=Paul Collins Startup list
[KEMailKb]
Confirmed=U
Filename=KEMailKb.EXE
Description=Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down
Source=Paul Collins Startup list
[Kemet]
Confirmed=?
Filename=kemet.exe
Description=??
Source=Paul Collins Startup list
[kern64dll]
Confirmed=X
Filename=[random filename]
Description=Added by the TARNO.J TROJAN!
Source=Paul Collins Startup list
[kernctl32]
Confirmed=X
Filename=rundll32 kctl32.dll, initialize
Description=Added by the AGENT.AT TROJAN!
Source=Paul Collins Startup list
[Kernel]
Confirmed=X
Filename=bboy.exe
Description=Added by the MUMU.B WORM!
Source=Paul Collins Startup list
[Kernel Loader]
Confirmed=X
Filename=ntkrnl.exe
Description=Added by the CERVIVEC.A WORM!
Source=Paul Collins Startup list
[kernel system daemon]
Confirmed=X
Filename=ACTIVAT0R.exe
Description=Added by the RANDEX.AW WORM!
Source=Paul Collins Startup list
[kernel32]
Confirmed=X
Filename=kern32.exe
Description=Added by the BADTRANS.A WORM!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=Kernel32.exe
Description=Added by a number of VIRUSES, WORMS and TROJANS!
Source=Paul Collins Startup list
[kernel32]
Confirmed=X
Filename=kernel.dli
Description=Added by the NETDEVIL.B TROJAN!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=Kernel.dll
Description=Added by the REDLOF.M VIRUS!
Source=Paul Collins Startup list
[kernel32]
Confirmed=X
Filename=kernel32.dlI
Description=Added by the NETDEVIL.15 TROJAN!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=krnl32.exe
Description=Added by the EPON WORM!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=Kernel32.win
Description=Added by the GAGGLE.D or GAGGLE.E WORMS!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=kernel32s.exe
Description=Added by the SDBOT-PU TROJAN!
Source=Paul Collins Startup list
[kernel32dll]
Confirmed=X
Filename=guardpc.exe
Description=Added by the FORBOT-CU WORM!
Source=Paul Collins Startup list
[kernelfaultcheck]
Confirmed=N
Filename=dumprep 0 -k
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[kernelfaultcheck]
Confirmed=N
Filename=dumprep 0 -u
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[KernelFaultChk]
Confirmed=X
Filename=sms.exe
Description=Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u"
Source=Paul Collins Startup list
[Kernell]
Confirmed=X
Filename=systems.exe
Description=Added by the TARNO.C TROJAN!
Source=Paul Collins Startup list
[Kernell32]
Confirmed=X
Filename=Kernell.dll
Description=Added by the DESTINY.A TROJAN!
Source=Paul Collins Startup list
[KernellApps]
Confirmed=X
Filename=csrss.exe
Description=Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Kernelw]
Confirmed=X
Filename=Kernelw32.exe
Description=Added by the INDOR.E WORM!
Source=Paul Collins Startup list
[Kernel_check]
Confirmed=X
Filename=wmiprvse.exe
Description=Added by the SONEBOT-B WORM!
Source=Paul Collins Startup list
[key]
Confirmed=X
Filename=sysxp.exe
Description=Added by the BEAGLE.AB WORM!
Source=Paul Collins Startup list
[key]
Confirmed=X
Filename=sys_xp.exe
Description=Added by the BEAGLE.AC WORM!
Source=Paul Collins Startup list
[key]
Confirmed=X
Filename=winxp.exe
Description=Added by the BEAGLE.AG WORM!
Source=Paul Collins Startup list
[Key Logger]
Confirmed=X
Filename=csrss.exe
Description=Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Key Text]
Confirmed=N
Filename=KeyText.exe
Description=Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs
Source=Paul Collins Startup list
[Key1]
Confirmed=X
Filename=Rlid.exe
Description=Added by the LIXY TROJAN!
Source=Paul Collins Startup list
[Key2]
Confirmed=?
Filename=serve.exe
Description=??
Source=Paul Collins Startup list
[KeyAccess]
Confirmed=Y
Filename=keyacc32.exe
Description=KeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"
Source=Paul Collins Startup list
[Keybdcntl]
Confirmed=X
Filename=keybdcntl.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[Keyboard Manager]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[Keyboard Preload Check]
Confirmed=Y
Filename=Preload.exe
Description=Millenium Multi-Function Keyboard driver
Source=Paul Collins Startup list
[KeyMaestro]
Confirmed=U
Filename=kmaestro.exe
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[keymap]
Confirmed=U
Filename=keymap.exe
Description=System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
Source=Paul Collins Startup list
[keymgrldr]
Confirmed=X
Filename=rundll32 setupapi, InstallHinfSection... keymgr3.inf
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[KeyPatrol]
Confirmed=U
Filename=KeyPatrol.exe
Description=KeyPatrol - detects Key Loggers ("keyboard loggers" or "keyloggers") using both behavioral and pattern-matching algorithms
Source=Paul Collins Startup list
[KeyWallet]
Confirmed=U
Filename=KWallet.exe
Description="KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"
Source=Paul Collins Startup list
[kfienq]
Confirmed=X
Filename=masbl.bat
Description=Added by the KIFER TROJAN!
Source=Paul Collins Startup list
[khooker]
Confirmed=N
Filename=khooker.exe
Description=SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
Source=Paul Collins Startup list
[KICKMON.EXE]
Confirmed=U
Filename=KICKMON.EXE
Description=KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required
Source=Paul Collins Startup list
[Kill Popup]
Confirmed=U
Filename=KillPopup.exe
Description=KillPopup - pop-up stopper
Source=Paul Collins Startup list
[Kinberlink]
Confirmed=N
Filename=Kinberlink.exe
Description=Kinberlink network messaging. Available via Start -> Programs
Source=Paul Collins Startup list
[KK Loader]
Confirmed=U
Filename=loadkk.exe
Description=KeyKey XP Professional from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user."
Source=Paul Collins Startup list
[klp]
Confirmed=U
Filename=run32dll.exe
Description=PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online
Source=Paul Collins Startup list
[KM9801U]
Confirmed=U
Filename=MMHotKey.exe
Description=Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
Source=Paul Collins Startup list
[kmw_run.exe]
Confirmed=U
Filename=kmw_run.exe
Description=Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features
Source=Paul Collins Startup list
[kmw_show.exe]
Confirmed=U
Filename=kmw_show.exe
Description=Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features
Source=Paul Collins Startup list
[Kodak Batch Transfer]
Confirmed=N
Filename=pezdow1.exe
Description=Part of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
Source=Paul Collins Startup list
[Kodak EasyShare software]
Confirmed=U
Filename=EasyShare.exe
Description=Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
Source=Paul Collins Startup list
[Kodak Picture Transfer Software]
Confirmed=N
Filename=pts.exe
Description=Looks for Kodak camera connection and media insertion. Available via Start -> Programs
Source=Paul Collins Startup list
[Kodak Software Updater]
Confirmed=N
Filename=backweb*****.exe
Description=Software updater for Kodak Easyshare digital cameras
Source=Paul Collins Startup list
[KodakCCS]
Confirmed=Y
Filename=KodakCCS.exe
Description=Kodak DC File System Driver
Source=Paul Collins Startup list
[Konni Symbol Autostart]
Confirmed=N
Filename=KonniSymbol.exe
Description=Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5
Source=Paul Collins Startup list
[kontiki]
Confirmed=N
Filename=kontiki.exe
Description=Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
Source=Paul Collins Startup list
[KREC32]
Confirmed=U
Filename=krec32.exe
Description=StarrCommander Pro Keystroke logging software
Source=Paul Collins Startup list
[Krnlmod]
Confirmed=U
Filename=Krnlmod.exe
Description=Keylogger - see here. Given a "U" recommendation because it depends if you intentionally installed it. If you didn't, treat it as "X" and uninstall or remove via Spybot S&D (for example)
Source=Paul Collins Startup list
[ktchnsnk]
Confirmed=U
Filename=ktchnsnk.exe
Description=HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted
Source=Paul Collins Startup list
[kv3000]
Confirmed=X
Filename=lover.vbe
Description=Added by the ZSYANG.B WORM!
Source=Paul Collins Startup list
[kvern16.dll]
Confirmed=X
Filename=regsvr32.exe [path] kvern16.dll
Description=DailyWinner adware
Source=Paul Collins Startup list
[kw3eef76]
Confirmed=X
Filename=rundll32.exe [path] kw3eef76.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[kX Mixer]
Confirmed=N
Filename=kxmixer.exe
Description=Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards
Source=Paul Collins Startup list
[LanGuard]
Confirmed=X
Filename=languard.exe
Description=Adware downloader
Source=Paul Collins Startup list
[LanSpeed2]
Confirmed=U
Filename=LanSpeed2.exe
Description=Monitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
Source=Paul Collins Startup list
[LapLink scheduler]
Confirmed=U
Filename=Llsched.exe
Description=Utility that automatically performs file transfers as unattended background operations
Source=Paul Collins Startup list
[Lar]
Confirmed=X
Filename=Llass.exe
Description=Added by the INOR-A TROJAN!
Source=Paul Collins Startup list
[lar]
Confirmed=X
Filename=[trojan filename]
Description=Added by the ROXY.C TROJAN!
Source=Paul Collins Startup list
[Lasb]
Confirmed=?
Filename=ewat.exe
Description=??
Source=Paul Collins Startup list
[LAsIAf32]
Confirmed=X
Filename=RePEAtLD.exe
Description=Added by the REPEATLD WORM!
Source=Paul Collins Startup list
[LASTinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[Later]
Confirmed=?
Filename=later.exe
Description=??
Source=Paul Collins Startup list
[LaunApp]
Confirmed=U
Filename=LaunApp.exe
Description=Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[Launcg]
Confirmed=?
Filename=launcg.exe
Description=??
Source=Paul Collins Startup list
[Launch Ai Booster]
Confirmed=U
Filename=OverClk.exe
Description=ASUS Ai Booster is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup
Source=Paul Collins Startup list
[Launch YahooPOPs! at Windows startup]
Confirmed=N
Filename=YAHOOPOPS.EXE
Description=YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs
Source=Paul Collins Startup list
[LaunchAp]
Confirmed=U
Filename=LaunchAp.exe
Description=Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[LaunchApp]
Confirmed=U
Filename=Alaunch.exe
Description=Acer Launch tool utility on laptops
Source=Paul Collins Startup list
[Launchboard]
Confirmed=U
Filename=lnchbrd.exe
Description="LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions"
Source=Paul Collins Startup list
[Launcher]
Confirmed=X
Filename=launcher.exe
Description=Spyware component related to DownloadWare and found in Program FilesKFH
Source=Paul Collins Startup list
[Launcher]
Confirmed=N
Filename=relaunch.exe
Description=Audio Applications Launcher for the Philips Rythmiic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs
Source=Paul Collins Startup list
[Lavasoft Ad-Aware]
Confirmed=X
Filename=Ad-Aware.exe
Description=Added by the RBOT-SO WORM! Note - this is not the popular Ad-aware spware/adware removal tool
Source=Paul Collins Startup list
[Lavasoft Adwatch]
Confirmed=U
Filename=Ad-watch.exe
Description=Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
Source=Paul Collins Startup list
[laxmsp32.exe]
Confirmed=Y
Filename=laxmsp32.exe
Description=Lexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work
Source=Paul Collins Startup list
[LCDC]
Confirmed=U
Filename=LCDC.exe
Description=LCDC is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins
Source=Paul Collins Startup list
[lcfep]
Confirmed=N
Filename=lcfep.exe
Description=Tivoli ‘TME’ System Tray icon - "'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"
Source=Paul Collins Startup list
[lcvga]
Confirmed=X
Filename=lcvga.exe
Description=Added by the HOSTOL-A TROJAN!
Source=Paul Collins Startup list
[ld]
Confirmed=X
Filename=ld.exe
Description=CoolWebSearch parasite related - redirects to fastwebfinder.com
Source=Paul Collins Startup list
[LDM]
Confirmed=N
Filename=backweb-8876480.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[LDM]
Confirmed=N
Filename=ldmconf.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[LED TRAY]
Confirmed=U
Filename=LEDTRAY.EXE
Description=Installs a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work
Source=Paul Collins Startup list
[LeechGet]
Confirmed=N
Filename=LeechGet.exe
Description=LeechGet download manager
Source=Paul Collins Startup list
[LetsSearch]
Confirmed=X
Filename=LetsSearch.exe
Description=BrowserAid/BrowserPal foistware variant
Source=Paul Collins Startup list
[Lexmark 3100 Series]
Confirmed=Y
Filename=lxbrbmgr.exe
Description=Lexmark printer button manager. Required for correct operation
Source=Paul Collins Startup list
[Lexmark X5100 Series]
Confirmed=U
Filename=lxbabmgr.exe
Description=System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
Source=Paul Collins Startup list
[Lexmark X74-X75]
Confirmed=U
Filename=lxbabmgr.exe
Description=System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
Source=Paul Collins Startup list
[Lexmark Xxx Button Manager]
Confirmed=Y
Filename=AcBtnMgr_Xxx.exe
Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
Source=Paul Collins Startup list
[Lexmark Xxx Button Monitor]
Confirmed=Y
Filename=ACMonitor_Xxx.exe
Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
Source=Paul Collins Startup list
[LexmarkPrinTray]
Confirmed=N
Filename=printray.exe
Description=Lexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray
Source=Paul Collins Startup list
[lexpps]
Confirmed=N
Filename=lexpps.exe
Description=For Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all". It is known that firewalls can however alert you to "lexpps.exe" requesting server privileges
Source=Paul Collins Startup list
[LexStart]
Confirmed=U
Filename=lexstart.exe
Description=Lexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance
Source=Paul Collins Startup list
[Lfsndmng]
Confirmed=U
Filename=lfsndmng.exe
Description=LightningFAX Enterprise Fax Server - "puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents"
Source=Paul Collins Startup list
[lhttseng]
Confirmed=N
Filename=rundll32.exe ..lhttseng.inf, RemoveCabinet
Description=Left over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine
Source=Paul Collins Startup list
[li-multi****]
Confirmed=X
Filename=li-multi****.exe
Description=Adult web-dialler - **** is random
Source=Paul Collins Startup list
[li-speed****]
Confirmed=X
Filename=dlres.exe
Description=Adult web-dialler - **** is random
Source=Paul Collins Startup list
[li-thund****]
Confirmed=X
Filename=li-thund****.exe
Description=Adult web-dialler - **** is random
Source=Paul Collins Startup list
[li-vita****]
Confirmed=X
Filename=li-vita****.exe
Description=Adult web-dialler - **** is random
Source=Paul Collins Startup list
[li01f948]
Confirmed=X
Filename=rundll32.exe [path] li01f948.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[LicCrtl]
Confirmed=N
Filename=runservice.exe
Description=eLicense, licensing system incorporated with some software and games
Source=Paul Collins Startup list
[LicCtrl]
Confirmed=U
Filename=rundll32.exe [path] MMFS.DLL, Service
Description=Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
Source=Paul Collins Startup list
[LicCtrl]
Confirmed=U
Filename=runservice.exe
Description=Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
Source=Paul Collins Startup list
[LifeScape Media Detector]
Confirmed=N
Filename=PicasaMediaDetector.exe
Description=Media detector for Picasa's automatic photo organizer
Source=Paul Collins Startup list
[Lightning Download]
Confirmed=U
Filename=Lightning.exe
Description=Lightning Download download manager. Can be launched manually, but will need to start up if you want it to "catch clicks" off Internet Explorer
Source=Paul Collins Startup list
[LimeWire x.x]
Confirmed=N
Filename=LimeWire.exe
Description=LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware
Source=Paul Collins Startup list
[Line Speed Meter V3.0]
Confirmed=N
Filename=LineSpeedMeter.exe
Description=LineSpeedMeter - detect the download and upload speed of your internet connection
Source=Paul Collins Startup list
[Linksts]
Confirmed=N
Filename=linksts.exe
Description=Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
Source=Paul Collins Startup list
[Linksts]
Confirmed=X
Filename=linksts.exe
Description=Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
Source=Paul Collins Startup list
[Linux]
Confirmed=X
Filename=Linux.vbs
Description=Added by the LOVELETTER.AS VIRUS!
Source=Paul Collins Startup list
[LiquidView]
Confirmed=U
Filename=lviewj.exe
Description="Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display's native resolution. The software lets you increase the size of items that are hard to read on your monitor"
Source=Paul Collins Startup list
[LIU]
Confirmed=N
Filename=LIU.exe
Description=Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
Source=Paul Collins Startup list
[LIU]
Confirmed=N
Filename=Rubicon.exe
Description=Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
Source=Paul Collins Startup list
[Live Menu]
Confirmed=N
Filename=Dllcmd32.exe
Description=eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here
Source=Paul Collins Startup list
[LiveMonitor]
Confirmed=N
Filename=LMonitor.exe
Description=MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
Source=Paul Collins Startup list
[LiveNote]
Confirmed=N
Filename=Livenote.exe
Description=Asus graphics card driver live update feature
Source=Paul Collins Startup list
[LiveSexCams]
Confirmed=X
Filename=LiveSexCams.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[LiveUpdate]
Confirmed=U
Filename=LiveUpdate.exe
Description=Web-update utility as used by various types of software - see here
Source=Paul Collins Startup list
[LiveUpdate]
Confirmed=X
Filename=[Windows username]05.exe
Description=Added by the LINEAGE TROJAN!
Source=Paul Collins Startup list
[Livre]
Confirmed=X
Filename=Dibane.bat
Description=Added by the BANEDI VIRUS!
Source=Paul Collins Startup list
[LLMODCL2]
Confirmed=?
Filename=rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF
Description=??
Source=Paul Collins Startup list
[LManager]
Confirmed=U
Filename=QtZgAcer.EXE
Description=Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
Source=Paul Collins Startup list
[LManager]
Confirmed=U
Filename=QtZpAcer.exe
Description=Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
Source=Paul Collins Startup list
[LMonitor]
Confirmed=N
Filename=LMonitor.exe
Description=MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
Source=Paul Collins Startup list
[lmpdpsrv]
Confirmed=?
Filename=lmpdpsrv.exe
Description=Related to a Lexmark printer/scanner. Printer sharing server? Is it required?
Source=Paul Collins Startup list
[LMSTATUS]
Confirmed=N
Filename=LMSTATUS.EXE
Description=Lexmark Status Monitor. Checks the current status of Lexmark printers (and other devices?)
Source=Paul Collins Startup list
[lnternet Explorer]
Confirmed=X
Filename=AMSNDMGR.EXE
Description=Added by the KWBOT.R WORM! Note that the "l" is a lower case "L" and not an upper case "I"
Source=Paul Collins Startup list
[LOAD WB]
Confirmed=U
Filename=LOADWB.EXE
Description=Part of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it
Source=Paul Collins Startup list
[Load-Guard]
Confirmed=X
Filename=Wscript.exe LGuarg.exe.vbs
Description=Added by the YENO.B and YENO.C WORMS!
Source=Paul Collins Startup list
[LOAD32]
Confirmed=X
Filename=Lorena.exe
Description=Added by the MAPSON.C WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=load32.exe
Description=Added by the NIBU, BAMBO TROJANS and DUMARU WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=l32x.exe
Description=Added by the DUMARU.Z or DUMARU.Y or DUMARU.AD WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=1111a.exe
Description=Added by the DUMARU.AH WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=swchost.exe
Description=Added by the TURTA.A WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=netda.exe
Description=Added by the NIBU.E TROJAN!
Source=Paul Collins Startup list
[load=]
Confirmed=N
Filename=adw30.exe
Description=After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Source=Paul Collins Startup list
[load=]
Confirmed=U
Filename=asistat.exe
Description=Status monitor for an NEC SuperScript printer
Source=Paul Collins Startup list
[load=]
Confirmed=?
Filename=cfgsys32.exe
Description=??
Source=Paul Collins Startup list
[load=]
Confirmed=U
Filename=esspk.exe
Description=Speakerphone capability through a soundcard for an ESS modem
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=hotkey.exe
Description=Solo 5300 display driver for Win2K on some Gateway laptops
Source=Paul Collins Startup list
[load=]
Confirmed=N
Filename=HPWHRC.EXE
Description=Loads the Status Window software for the HP Laserjet printers
Source=Paul Collins Startup list
[load=]
Confirmed=?
Filename=WPSLOAD.EXE
Description=Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
Source=Paul Collins Startup list
[load=]
Confirmed=N
Filename=vi_grm.exe
Description=Monitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
Source=Paul Collins Startup list
[load=]
Confirmed=?
Filename=WINOSCFG.EXE
Description=Could it be something to do with configuring Windows on a new PC from an OEM supplier?
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=wpshrc.exe
Description=Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others)
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=Bfrecv.exe
Description=Bitware modem driver
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=msater.exe
Description=Added by the RETSAM TROJAN!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=shambl3r.exe
Description=Added by the REMABL WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=Spoolsv.exe
Description=Added by the CIADOOR.B TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
Source=Paul Collins Startup list
[Load=]
Confirmed=?
Filename=wtfeat.exe
Description=Associated with the Wintab Digitizer
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=AICLIENT.EXE
Description=Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=hint.exe
Description=Added by the ATAK WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=win32exec.exe
Description=Added by the BITTER WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=a1g.exe
Description=Added by the ATAK.B WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=dapdll.exe
Description=Added by the ATAK.E WORM!
Source=Paul Collins Startup list
[LoadBlackD]
Confirmed=Y
Filename=blackd.exe
Description=This is the "intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility)
Source=Paul Collins Startup list
[LoadBtnHnd]
Confirmed=?
Filename=BtnHnd.exe
Description=Fujitsu LifeBook related
Source=Paul Collins Startup list
[LoadDBackUp]
Confirmed=X
Filename=BcTool.exe
Description=Added by the GIBE WORM!
Source=Paul Collins Startup list
[LoadDvpApi9x]
Confirmed=?
Filename=DVPAPI9X.exe
Description=Part of Command AntiVirus for Windows 95/98/Me. Is it needed?
Source=Paul Collins Startup list
[loader]
Confirmed=X
Filename=loader.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe
Source=Paul Collins Startup list
[loader]
Confirmed=X
Filename=WMPLAYER.EXE
Description=Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
Source=Paul Collins Startup list
[LoadFonts]
Confirmed=X
Filename=LoadFonts.vbs
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[LoadFonts]
Confirmed=X
Filename=Tahoma.vbs
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[LoadHTML]
Confirmed=X
Filename=rundll32.exe mshtmpre.dll, MShtmpre
Description=Browser hijacker
Source=Paul Collins Startup list
[LoadingAgent]
Confirmed=X
Filename=ZipLoader32.exe
Description=Added by the OBLIVION TROJAN! This executable is one of the most common but there are more
Source=Paul Collins Startup list
[LoadingAgent]
Confirmed=X
Filename=msload32.exe
Description=Added by the OBLIVION TROJAN! This executable is one of the most common but there are more
Source=Paul Collins Startup list
[LoadManager]
Confirmed=X
Filename=msload.exe
Description=Added by the OPASERV.T WORM!
Source=Paul Collins Startup list
[LoadMSvcmm]
Confirmed=N
Filename=msvcmm32.exe
Description=Auto-update for Movielink - internet movie rental System Tray access
Source=Paul Collins Startup list
[LoadOrderVerification]
Confirmed=X
Filename=[random filename]
Description=Added by the TRON.A TROJAN!
Source=Paul Collins Startup list
[Loadout Manager]
Confirmed=U
Filename=nost_LM.exe
Description=Manager for the Belkin Nostromo n50 SpeedPad game controller - see here
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=ASDAPI.EXE
Description=Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=U
Filename=Rundll32.exe powrprof.dll
Description=Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=Rundll.exe powerprof.dll
Description=Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe"
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=rundl.exe
Description=Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=Rundll32.exe
Description=Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line
Source=Paul Collins Startup list
[LoadQM]
Confirmed=U
Filename=loadqm.exe
Description=Installed with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it
Source=Paul Collins Startup list
[loads.exe]
Confirmed=X
Filename=loads.exe
Description=Popuppers.com adware downloader
Source=Paul Collins Startup list
[loads.exe]
Confirmed=X
Filename=medload.exe
Description=Popuppers.com adware downloader
Source=Paul Collins Startup list
[loads.exe]
Confirmed=X
Filename=suploads.exe
Description=Popuppers.com adware downloader
Source=Paul Collins Startup list
[LoadSIPS]
Confirmed=X
Filename=rundll32.exe [path] SIPSPI32.dll, SIPSPI32
Description=123Mania adware
Source=Paul Collins Startup list
[LoadWatcher]
Confirmed=?
Filename=Test.exe
Description=Reportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct?
Source=Paul Collins Startup list
[LoadWindowsFile]
Confirmed=X
Filename=[filename]
Description=Added by the DELF.B TROJAN! where [filename] is the infected file
Source=Paul Collins Startup list
[Local Page]
Confirmed=X
Filename=http://find.naupoint.com
Description=Naupoint browser hijacker
Source=Paul Collins Startup list
[Locator Service]
Confirmed=X
Filename=[filename]
Description=Added by the AGOBOT-KY TROJAN!
Source=Paul Collins Startup list
[Lock My PC]
Confirmed=U
Filename=lockpc.exe
Description=Lock_My_PC - a tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse
Source=Paul Collins Startup list
[Login]
Confirmed=U
Filename=winlog.exe
Description=Salfeld Child Control 2003 - parental control software
Source=Paul Collins Startup list
[Login Service]
Confirmed=X
Filename=[path to file]
Description=Added by the MIGMAF TROJAN!
Source=Paul Collins Startup list
[LoginPassport]
Confirmed=X
Filename=Lgnpsp32.exe
Description=Added by the REDIST.C WORM!
Source=Paul Collins Startup list
[Logitech Desktop Messenger]
Confirmed=N
Filename=backweb-8876480.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[Logitech Desktop Messenger]
Confirmed=N
Filename=ldmconf.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[Logitech Hardware Abstraction Layer]
Confirmed=?
Filename=Khalmnpr.exe
Description=Logitech Bluetooth mouse Hardware Abstraction layer. A "hardware abstraction layer" is an interface that enables adding support for new devices and new ways of connecting devices to the computer, without modifying every application that uses the device. What does it do, and is it required?
Source=Paul Collins Startup list
[Logitech SetPoint]
Confirmed=U
Filename=KEM.exe
Description=Keyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
Source=Paul Collins Startup list
[Logitech Utility]
Confirmed=U
Filename=Logi_MwX.exe
Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
Source=Paul Collins Startup list
[Logitech Wakeup]
Confirmed=N
Filename=lgwakeup.exe
Description=Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
Source=Paul Collins Startup list
[LogitechGalleryRepair]
Confirmed=U
Filename=ISStart.exe
Description=LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Source=Paul Collins Startup list
[LogitechImageStudioTray]
Confirmed=N
Filename=LogiTray.exe
Description=Logitech Image Studio - installed with Logitech QuickCams
Source=Paul Collins Startup list
[LogitechSoftwareUpdate]
Confirmed=?
Filename=ManifestEngine.exe
Description=Updater, part of Logitech Image Studio - installed with Logitech QuickCam cameras. Probably not required
Source=Paul Collins Startup list
[LogitechVideoRepair]
Confirmed=U
Filename=ISStart.exe
Description=LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Source=Paul Collins Startup list
[LogitechVideoTray]
Confirmed=N
Filename=LogiTray.exe
Description=Logitech Image Studio - installed with Logitech QuickCams
Source=Paul Collins Startup list
[LogiTray]
Confirmed=N
Filename=LogiTray.exe
Description=Logitech Image Studio - installed with Logitech QuickCams
Source=Paul Collins Startup list
[Logi_Mwx]
Confirmed=U
Filename=Logi_MwX.exe
Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
Source=Paul Collins Startup list
[Logon.exe]
Confirmed=X
Filename=logon.exe
Description=Added by the ZINS.A TROJAN!
Source=Paul Collins Startup list
[LogonStudio]
Confirmed=U
Filename=logonstudio.exe
Description=WinCustomize LogonStudio - "Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users"
Source=Paul Collins Startup list
[LogWatch]
Confirmed=U
Filename=logwat95.exe
Description=Licensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll - see here. Not required if you already have a newer version or the patch has been applied
Source=Paul Collins Startup list
[Look 'n' Stop]
Confirmed=Y
Filename=looknstop.exe
Description=Look 'n' Stop personal firewall
Source=Paul Collins Startup list
[LookNMeet]
Confirmed=N
Filename=Agent.exe
Description=LooknMeet dating service
Source=Paul Collins Startup list
[Lookup_Sys]
Confirmed=X
Filename=lookupsys.exe
Description=P04n trojan
Source=Paul Collins Startup list
[Lotus Organizer EasyClip]
Confirmed=N
Filename=easyclip.exe
Description="The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page." Available via Start -> Programs
Source=Paul Collins Startup list
[Lotus QuickStart]
Confirmed=N
Filename=smartctr.exe
Description=Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs
Source=Paul Collins Startup list
[Lotus SuiteStart]
Confirmed=U
Filename=suitest.exe
Description=Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs
Source=Paul Collins Startup list
[LowVersionSupport]
Confirmed=X
Filename=[filename]
Description=Added by the LASTRAS TROJAN!
Source=Paul Collins Startup list
[Lpr]
Confirmed=X
Filename=Lpr123.exe
Description=Added by the REMPSTEAL password stealer TROJAN!
Source=Paul Collins Startup list
[Lpr123]
Confirmed=X
Filename=Lpr123.exe
Description=Added by the REMPSTEAL password stealer TROJAN!
Source=Paul Collins Startup list
[LPS]
Confirmed=U
Filename=Lps.exe
Description=Local Port Scanner - "With LPS you're able to check your computer for open or listening ports"
Source=Paul Collins Startup list
[LPtask]
Confirmed=U
Filename=lptask.exe
Description=Program Lock It And Protect Pro - lock and protect your folders from being opened, moved or deleted
Source=Paul Collins Startup list
[LS120 Superdisk]
Confirmed=N
Filename=??
Description=Supposed to accelerate transfer rate on LS-120, contributes to system lockups
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=lsass.exe
Description=Added by the RATSOU.B TROJAN! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=start.bat
Description=Added by the ZCREW TROJAN!
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=[path to lsass.exe]
Description=Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=lsasrv.exe
Description=Added by the MYDOOM.AG WORM!
Source=Paul Collins Startup list
[LSASS Daemon]
Confirmed=X
Filename=LSASSd.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[lsass service]
Confirmed=X
Filename=lsass2.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[lsasss.exe]
Confirmed=X
Filename=lsasss.exe
Description=Added by the SASSER.E WORM!
Source=Paul Collins Startup list
[LSPFix]
Confirmed=X
Filename=LSPmonitor.exe
Description=eAcceleration Stop-Sign related - foistware. Read their privacy statement here
Source=Paul Collins Startup list
[LSPmonitor]
Confirmed=X
Filename=LSPmonitor.exe
Description=eAcceleration Stop-Sign related - foistware. Read their privacy statement here
Source=Paul Collins Startup list
[lssass]
Confirmed=X
Filename=lssas.exe
Description=Added by the AGOBOT.RL WORM!
Source=Paul Collins Startup list
[LSvr]
Confirmed=X
Filename=LSvr.exe
Description=PowerStrip foistware
Source=Paul Collins Startup list
[LT DAEMON]
Confirmed=Y
Filename=ltdaemon.exe
Description=Acts as a data spooler for the DSL modem (similar to a cache). Do not uncheck if the DSL modem is being used
Source=Paul Collins Startup list
[LTDMgr]
Confirmed=X
Filename=LTDMgr.exe
Description=PowerStrip foistware
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=MSGSRV32.EXE
Description=Added by the LITMUS.A TROJAN! Note - MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:\Windows\System
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=MPGSRV32.EXE
Description=Added by the LITMUS.201 TROJAN!
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=MSGSRV320.EXE
Description=Added by the LITMUS.C TROJAN!
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=winupdate.exe
Description=Added by the LITMUS.203 TROJAN!
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=bible.exe
Description=Added by the LITMUS.203 TROJAN!
Source=Paul Collins Startup list
[LtMoh]
Confirmed=U
Filename=Ltmoh.exe
Description=Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
Source=Paul Collins Startup list
[LTMSG]
Confirmed=Y
Filename=ltmsg.exe
Description=One of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
Source=Paul Collins Startup list
[LTSMMSG]
Confirmed=N
Filename=LTSMMSG.exe
Description=Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too
Source=Paul Collins Startup list
[LTSMSG]
Confirmed=X
Filename=Shell32.exe
Description=Added by the LEMIR.B TROJAN!
Source=Paul Collins Startup list
[LTWinModem1]
Confirmed=Y
Filename=ltmsg.exe
Description=One of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
Source=Paul Collins Startup list
[Lusetup]
Confirmed=Y
Filename=LUSetup.exe
Description=Symantec LiveUpdate installer - required to install a new version of the application. Will only run once, and the entry is automatically deleted after a reboot
Source=Paul Collins Startup list
[LVComs]
Confirmed=U
Filename=lvcoms.exe
Description=Lvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera
Source=Paul Collins Startup list
[LVCOMSX]
Confirmed=?
Filename=LVCOMSX.EXE
Description=Logitech webcam related. What does it do and is it required?
Source=Paul Collins Startup list
[LWBMOUSE]
Confirmed=U
Filename=lwbwheel.exe
Description=Mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[LWBMOUSE]
Confirmed=U
Filename=MOUSE32A.EXE
Description=Mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Lwinst Run Profiler]
Confirmed=N
Filename=lwtest.exe
Description=Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
Source=Paul Collins Startup list
[lxamsp32]
Confirmed=?
Filename=lxamsp32.exe
Description=Associated with a Lexmark Printer - is it required?
Source=Paul Collins Startup list
[LXbbmgr]
Confirmed=?
Filename=LXbbmgr.exe
Description=Lexmark printer button manager? Is it required?
Source=Paul Collins Startup list
[LXBLKsk]
Confirmed=?
Filename=LXBLKsk.exe
Description=Lexmark related. What does it do, and is it required?
Source=Paul Collins Startup list
[lxbrbmgr]
Confirmed=Y
Filename=lxbrbmgr.exe
Description=Lexmark printer button manager. Required for correct operation
Source=Paul Collins Startup list
[LXBRKsk]
Confirmed=?
Filename=LXBRKsk.exe
Description=Lexmark printer related. What does it do and is it required?
Source=Paul Collins Startup list
[LXSUPMON]
Confirmed=N
Filename=LXSUPMON.EXE
Description=Lexmark Printer. The printer should work fine without it
Source=Paul Collins Startup list
[LzioMediaUpdater]
Confirmed=X
Filename=LzioMediaUpdater.exe
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[M Player Post Installer]
Confirmed=?
Filename=postinstallm.exe
Description=??
Source=Paul Collins Startup list
[M-soft Office]
Confirmed=X
Filename=M-soft Office.hta
Description=HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
Source=Paul Collins Startup list
[M1cr0s0ft S3rcurity]
Confirmed=X
Filename=systemconfig.exe
Description=Added by the RBOT.BKB WORM!
Source=Paul Collins Startup list
[M1cr0s0ft Upd4t4zS]
Confirmed=X
Filename=update32.exe
Description=Added by the RBOT-MI WORM!
Source=Paul Collins Startup list
[m32info]
Confirmed=X
Filename=m32info.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[M3Tray]
Confirmed=N
Filename=m3tray.exe
Description=Movielink - internet movie rental System Tray access
Source=Paul Collins Startup list
[Macfee Security Patch]
Confirmed=X
Filename=Mpfsheild.exe
Description=Added by the RBOT-NP WORM!
Source=Paul Collins Startup list
[Machine Debug Manager]
Confirmed=U
Filename=mdm.exe
Description=Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable
Source=Paul Collins Startup list
[MacLic]
Confirmed=N
Filename=MacLic.exe
Description=Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
Source=Paul Collins Startup list
[MacName]
Confirmed=N
Filename=MacName.exe
Description=Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
Source=Paul Collins Startup list
[MAD.EXE]
Confirmed=Y
Filename=MAD.EXE
Description=MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up?
Source=Paul Collins Startup list
[MadExe]
Confirmed=N
Filename=LaunchRA.exe
Description=Dell Resolution Assistant
Source=Paul Collins Startup list
[MagicDsk]
Confirmed=U
Filename=MAGICDSK.EXE
Description=Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons
Source=Paul Collins Startup list
[Magitime]
Confirmed=N
Filename=Magitime.exe
Description=Magitime - connection tracking utility which monitors online time, expense, data transfer
Source=Paul Collins Startup list
[Mail.com]
Confirmed=?
Filename=mcalert.exe
Description=Mail.com - free web-mail service. Does mcalert.exe notify you when new mail has arrived?
Source=Paul Collins Startup list
[MailBell]
Confirmed=U
Filename=mailbell.exe
Description=MailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
Source=Paul Collins Startup list
[Mailbox Verifier]
Confirmed=U
Filename=mboxvrfy.exe
Description=Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
Source=Paul Collins Startup list
[MailScan Dispatcher]
Confirmed=Y
Filename=Launch.exe
Description=MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned
Source=Paul Collins Startup list
[Mail_Check]
Confirmed=X
Filename=Mail_Check.exe
Description=Added by the PANOIL.C WORM!
Source=Paul Collins Startup list
[MAIN]
Confirmed=U
Filename=main.exe
Description=SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
Source=Paul Collins Startup list
[Main Executable (HP)]
Confirmed=?
Filename=HP05T0R5.exe
Description=HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?
Source=Paul Collins Startup list
[main16]
Confirmed=X
Filename=main16.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[main32]
Confirmed=X
Filename=main32.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[mainviewex]
Confirmed=X
Filename=mainviewex.exe
Description=Added by the GEMA.D TROJAN!
Source=Paul Collins Startup list
[Mania Win Restore]
Confirmed=N
Filename=RESWIN.EXE
Description=Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
Source=Paul Collins Startup list
[Mantis]
Confirmed=X
Filename=[filename]
Description=Added by the MANTIBE VIRUS!
Source=Paul Collins Startup list
[MapiDrv]
Confirmed=X
Filename=mpisvc.exe
Description=Added by the MIPSIV TROJAN!
Source=Paul Collins Startup list
[mapisvc32]
Confirmed=X
Filename=mapisvc32.exe
Description=Added by the KX VIRUS and also recognised by Symantec as FPAI adware
Source=Paul Collins Startup list
[masqform.exe]
Confirmed=N
Filename=masqform.exe
Description=PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms
Source=Paul Collins Startup list
[Mass storage check registry]
Confirmed=N
Filename=rundll32.exe MSDServ.dll, check registry
Description=Used with a USB based smartmedia card reader
Source=Paul Collins Startup list
[Master Volume Spy]
Confirmed=U
Filename=MASTERVOLUMESPY.EXE
Description=Volume control for the Gateway Destination "DestiVu" media interface
Source=Paul Collins Startup list
[Matador]
Confirmed=U
Filename=mlfbuddy.exe
Description=MailFrontier - anti-spam application
Source=Paul Collins Startup list
[Matador]
Confirmed=U
Filename=mantispm.exe
Description=MailFrontier Desktop (Matador) email spam blocker software
Source=Paul Collins Startup list
[MatrixScreen]
Confirmed=X
Filename=[filename]
Description=Added by the MATRIXSCREEN TROJAN!
Source=Paul Collins Startup list
[MatrixScreenSaver]
Confirmed=X
Filename=mss.exe
Description=Malware, see here
Source=Paul Collins Startup list
[Matrox Color Control]
Confirmed=N
Filename=hgcctl95.exe
Description=For Matrox video cards. Quick access to changing colors
Source=Paul Collins Startup list
[Matrox Control Center]
Confirmed=N
Filename=mgactrl.exe
Description=For Matrox video cards. Quick access to settings
Source=Paul Collins Startup list
[Matrox Diagnostic]
Confirmed=N
Filename=mgadiag.exe
Description=For Matrox video cards. Quick access to diagnostics
Source=Paul Collins Startup list
[Matrox Powerdesk]
Confirmed=N
Filename=PDesk.exe
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[Matrox PowerDesk 8]
Confirmed=N
Filename=Matrox.PowerDesk.exe /silent
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[Matrox QuickDesk]
Confirmed=N
Filename=mgaqdesk.exe
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[MaxAlerts]
Confirmed=X
Filename=max.exe
Description=Bonzi MaxALERT - spyware
Source=Paul Collins Startup list
[MaxtorCombo]
Confirmed=Y
Filename=ComboButton.exe
Description=Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
Source=Paul Collins Startup list
[MaxtorReg]
Confirmed=U
Filename=AUTOREG.EXE
Description=Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
Source=Paul Collins Startup list
[MBM 4]
Confirmed=U
Filename=MBM4.exe
Description=Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[MBM 5]
Confirmed=U
Filename=MBM5.exe
Description=Motherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[MBProbe]
Confirmed=U
Filename=mbrpobe.exe
Description=MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[MC]
Confirmed=X
Filename=wintrims.exe
Description=Added by the WINTRIM TROJAN!
Source=Paul Collins Startup list
[Mcafee Anti Scan]
Confirmed=X
Filename=NortonScn.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Mcafee Antivirus Monitoring System32mn]
Confirmed=X
Filename=VSStatmn32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[McAfee Firewall]
Confirmed=Y
Filename=CPD.EXE
Description=Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
Source=Paul Collins Startup list
[McAfee Guardian]
Confirmed=N
Filename=CMGRDIAN.EXE
Description=McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
Source=Paul Collins Startup list
[McAfee QuickClean Imonitor]
Confirmed=N
Filename=Plguni.exe
Description=McAfee QuickClean 3.0 - removes internet clutter and unwanted programs
Source=Paul Collins Startup list
[McAfee Winguage]
Confirmed=N
Filename=??
Description=Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
Source=Paul Collins Startup list
[McAfee.InstantUpdate.Monitor]
Confirmed=U
Filename=RuLaunch.exe
Description=Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
Source=Paul Collins Startup list
[McAfeeUpdaterUI]
Confirmed=?
Filename=UpdaterUI.exe
Description=Associated with McAfee Enterprise 7.0.0. Updater for McAfee anti-virus and security programs?
Source=Paul Collins Startup list
[McAfeeVirusScanService]
Confirmed=Y
Filename=Avsynmgr.exe
Description=From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application
Source=Paul Collins Startup list
[McAfeeWebscanX]
Confirmed=Y
Filename=WebScanX.exe
Description=From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
Source=Paul Collins Startup list
[Mcaffe Antivirus]
Confirmed=X
Filename=Mcafeescn.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[McAgentExe]
Confirmed=U
Filename=mcagent.exe
Description=From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed
Source=Paul Collins Startup list
[Mcappins.exe]
Confirmed=?
Filename=mcappins.exe
Description=McAfee Application Installer. What does it do and is it required?
Source=Paul Collins Startup list
[MChanger]
Confirmed=N
Filename=MChanger.exe
Description=Media Changer - utility that allows you to change wallpapers, sounds, themes, etc
Source=Paul Collins Startup list
[McRegWiz]
Confirmed=?
Filename=mcregwiz.exe
Description=McAfee antivirus related. What does it do and is it required?
Source=Paul Collins Startup list
[McUpdateExe]
Confirmed=U
Filename=mcupdate.exe
Description=From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions
Source=Paul Collins Startup list
[McVsRte]
Confirmed=Y
Filename=mcusrt.exe
Description=Part of McAfee's SecurityCenter. Must remain checked but one user reports Windows glitches with no response from McAfee as to why
Source=Paul Collins Startup list
[mcvsshld]
Confirmed=Y
Filename=mcvsshld.exe
Description=McAfee VirusScan On-line. See also the McAgentExe entry
Source=Paul Collins Startup list
[MD IE Plugin]
Confirmed=X
Filename=md.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[MD IE Plugin]
Confirmed=X
Filename=winy.exe
Description=Adware
Source=Paul Collins Startup list
[mdac_runonce]
Confirmed=N
Filename=runonce.exe
Description=Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe".
Source=Paul Collins Startup list
[mdetect]
Confirmed=X
Filename=[path to trojan]
Description=Added by the SPABOT TROJAN!
Source=Paul Collins Startup list
[Mdm]
Confirmed=X
Filename=Mdm.vbs
Description=Added by the WHITEHO VIRUS or TRAPPY WORM!
Source=Paul Collins Startup list
[mdm]
Confirmed=X
Filename=mdm.exe
Description=Added by the LYDRA-F TROJAN! Note - this is not the valid Machine Debug Manager which shares the same filename
Source=Paul Collins Startup list
[MDM7]
Confirmed=U
Filename=mdm.exe
Description=Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable
Source=Paul Collins Startup list
[Mdmdll]
Confirmed=X
Filename=mdmdll.exe
Description=Added by the CRYPTER TROJAN!
Source=Paul Collins Startup list
[Mdmdll32]
Confirmed=X
Filename=mdmdll32.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[mdwmdmsp]
Confirmed=X
Filename=mdwmdmsp.exe
Description=Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am
Source=Paul Collins Startup list
[MECA]
Confirmed=N
Filename=Meca.exe
Description=Meca instant messenging client
Source=Paul Collins Startup list
[Media Load]
Confirmed=X
Filename=msn32.exe
Description=Added by a unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Media Manager Indexer]
Confirmed=U
Filename=AIRSVCU.EXE
Description=Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here
Source=Paul Collins Startup list
[Media Player]
Confirmed=X
Filename=media.exe
Description=Added by the FLDMEDIA-A TROJAN!
Source=Paul Collins Startup list
[Media Player]
Confirmed=X
Filename=wmplayer.exe
Description=Added by the AGOBOT-BM WORM!
Source=Paul Collins Startup list
[Media Plug x.1.2]
Confirmed=X
Filename=msdm.exe
Description=Added by the MULDROP.352 VIRUS!
Source=Paul Collins Startup list
[Media Service]
Confirmed=X
Filename=msn64.exe
Description=Added by the SPYBOT.EV WORM!
Source=Paul Collins Startup list
[Media service]
Confirmed=X
Filename=msnmsgxr.exe
Description=Added by the SDBOT.TF WORM!
Source=Paul Collins Startup list
[Media service]
Confirmed=X
Filename=SYSTEM64.EXE
Description=Added by the RBOT.QV WORM!
Source=Paul Collins Startup list
[MediaFace Integration]
Confirmed=N
Filename=Sethook.exe
Description=Fellowes Neato™ cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
Source=Paul Collins Startup list
[Mediafour Mac Volume Notifications]
Confirmed=U
Filename=Macvntfy.exe
Description=Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
Source=Paul Collins Startup list
[Mediafour XPlay Tray Notification Icon]
Confirmed=U
Filename=Xptryicn.exe
Description=Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
Source=Paul Collins Startup list
[MediaKey]
Confirmed=U
Filename=MediaKey.exe
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[MediaLoads]
Confirmed=X
Filename=dw.exe
Description=Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information
Source=Paul Collins Startup list
[MediaLoads Installer]
Confirmed=X
Filename=dw.exe
Description=Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information
Source=Paul Collins Startup list
[MediaMonitor]
Confirmed=N
Filename=Mediam~1.exe
Description=Installed by Smartdisk MVP CD burning software. Software will work fine without it
Source=Paul Collins Startup list
[mediamotor.exe]
Confirmed=X
Filename=mmups.exe
Description=Roimoi/Media-Motor adware
Source=Paul Collins Startup list
[MediaPath]
Confirmed=X
Filename=Proyecto1.exe
Description=Added by the GRUEL WORM!
Source=Paul Collins Startup list
[MediaPath]
Confirmed=X
Filename=Root.exe
Description=Added by the GRUEL WORM!
Source=Paul Collins Startup list
[MediaRing Talk]
Confirmed=N
Filename=mrtalk.exe
Description=Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs
Source=Paul Collins Startup list
[media_manager]
Confirmed=X
Filename=mediaman.exe
Description=Mini-Player, IMESH related foistware, see here
Source=Paul Collins Startup list
[media_stub]
Confirmed=X
Filename=stub.exe
Description=Mini-Player, IMESH related foistware, see here
Source=Paul Collins Startup list
[MemConfig]
Confirmed=X
Filename=SetupIE.com
Description=Added by the TAPLAK WORM!
Source=Paul Collins Startup list
[MemoKit]
Confirmed=U
Filename=MK.EXE
Description=Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
Source=Paul Collins Startup list
[Memory Check]
Confirmed=X
Filename=memore.exe
Description=Added by the KILLAV.C TROJAN!
Source=Paul Collins Startup list
[Memory Stick Monitor]
Confirmed=N
Filename=MSTAT.exe
Description=Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer
Source=Paul Collins Startup list
[Memory Stick Monitor]
Confirmed=U
Filename=MSstat.exe
Description=Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
Source=Paul Collins Startup list
[Memory Watcher]
Confirmed=X
Filename=MemoryWatcher.exe
Description=MemoryWatcher spyware
Source=Paul Collins Startup list
[Memory+]
Confirmed=U
Filename=tfimemsr.exe
Description=Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
Source=Paul Collins Startup list
[MemoryMeter]
Confirmed=X
Filename=MemoryMeter.exe
Description=Autoinstalling spyware by Total Velocity
Source=Paul Collins Startup list
[MemScanner]
Confirmed=N
Filename=MemScanner.exe
Description=SpyHunter - spyware remover of somewhat dubious repute, see note
Source=Paul Collins Startup list
[MemTurbo]
Confirmed=U
Filename=memturbo.exe
Description=MemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
Source=Paul Collins Startup list
[MenuSnap]
Confirmed=N
Filename=MenuSnap.exe
Description=MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe
Source=Paul Collins Startup list
[Message Queuing]
Confirmed=X
Filename=msmqs.exe
Description=Added by the FREEFORS TROJAN!
Source=Paul Collins Startup list
[MessagerStarter Freeserve]
Confirmed=N
Filename=StartMessager.exe
Description=Freeserve Messenger
Source=Paul Collins Startup list
[Message_Blocker]
Confirmed=U
Filename=messageblock.exe
Description=Message Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message"
Source=Paul Collins Startup list
[Messenger]
Confirmed=X
Filename=messenger.exe
Description=Added by the KUTEX TROJAN!
Source=Paul Collins Startup list
[Messenger Block]
Confirmed=X
Filename=msngrblock.exe
Description=Added by the PATOO WORM!
Source=Paul Collins Startup list
[Messenger start-up]
Confirmed=X
Filename=Msgran.exe
Description=Added by the GRAMOS WORM!
Source=Paul Collins Startup list
[Messenger6]
Confirmed=X
Filename=command.pif
Description=Added by the INZAE.B WORM!
Source=Paul Collins Startup list
[MessengerDiscovery]
Confirmed=U
Filename=MessengerDiscovery.exe
Description=MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features
Source=Paul Collins Startup list
[MessengerPlus]
Confirmed=N
Filename=MsgPlus.exe
Description=MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
Source=Paul Collins Startup list
[MessengerPlus2]
Confirmed=N
Filename=MsgPlus.exe
Description=MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
Source=Paul Collins Startup list
[MessengerPlus3]
Confirmed=N
Filename=MsgPlus.exe
Description=MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
Source=Paul Collins Startup list
[messnger]
Confirmed=X
Filename=[worm filename]
Description=Added by the DELODER WORM!
Source=Paul Collins Startup list
[messnger]
Confirmed=X
Filename=Dvldr32.exe
Description=Added by the DELODER.A WORM!
Source=Paul Collins Startup list
[MeTaLRoCk (irc.musirc.com) has sex with printers]
Confirmed=X
Filename=metalrock-is-gay.exe
Description=Added by the RANDEX.Q WORM!
Source=Paul Collins Startup list
[mfgboot]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[mfin32]
Confirmed=X
Filename=mfin32.exe
Description=MyFreeInternetUpdate - adware downloader
Source=Paul Collins Startup list
[MGA Hook]
Confirmed=?
Filename=Mgahook.exe
Description=MATROX Graphics card related. What does it do and is it required?
Source=Paul Collins Startup list
[MGA Quickdesk]
Confirmed=N
Filename=MGAQDESK.EXE
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[Mgabg]
Confirmed=?
Filename=Mgabg.exe
Description=Matrox BIOS Guard. What does it do and is it required?
Source=Paul Collins Startup list
[mgavctrl]
Confirmed=Y
Filename=mgavrtcl.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[mgavctrl]
Confirmed=Y
Filename=mgavrte.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[mgavrtclexe]
Confirmed=Y
Filename=mgavrtcl.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[mgavrtclexe]
Confirmed=Y
Filename=mgavrte.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[MGA_CD_Install]
Confirmed=N
Filename=mgasetup.exe
Description=Matrox Millennium video driver. Not required once drivers installed
Source=Paul Collins Startup list
[MHDOGStart]
Confirmed=X
Filename=mhdogst.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
Source=Paul Collins Startup list
[MHINIT]
Confirmed=N
Filename=MHINIT.EXE
Description=Part of the Cybermedia Clean Sweep package
Source=Paul Collins Startup list
[Mickey Mouse Cereal]
Confirmed=X
Filename=[random filename].exe
Description=Added by the RANKY.Q TROJAN!
Source=Paul Collins Startup list
[Micr Update]
Confirmed=X
Filename=soundblaster.exe
Description=Added by the SDBOT.NP WORM!
Source=Paul Collins Startup list
[Microangelo Desktop]
Confirmed=U
Filename=Muamgr.exe
Description=Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs
Source=Paul Collins Startup list
[microAttuneDownload]
Confirmed=N
Filename=atmdlusr.exe
Description=USR (US Robotics) modem auto updater. May be a sub-set of Attune
Source=Paul Collins Startup list
[MicroDialler]
Confirmed=U
Filename=atdialler1.exe
Description=Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered
Source=Paul Collins Startup list
[Microfinder lptt01]
Confirmed=X
Filename=mcf.exe
Description=Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Microfinder ml097e]
Confirmed=X
Filename=mcf.exe
Description=Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[MicroLoad]
Confirmed=X
Filename=[random filename]
Description=Added by the DARBY WORM!
Source=Paul Collins Startup list
[Microsof Windows Host]
Confirmed=X
Filename=svhost32.exe
Description=Added by the RBOT.ADY WORM!
Source=Paul Collins Startup list
[Microsof Winlog Host]
Confirmed=X
Filename=wilogon32.exe
Description=Added by the RBOT.XC WORM!
Source=Paul Collins Startup list
[Microsofot x386 System Monitor]
Confirmed=X
Filename=system32.exe
Description=Added by the WOOTBOT.M WORM!
Source=Paul Collins Startup list
[microsoft]
Confirmed=X
Filename=svchost.exe
Description=Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[microsoft]
Confirmed=X
Filename=microsoft.hta
Description=HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
Source=Paul Collins Startup list
[Microsoft Associates, Inc.]
Confirmed=X
Filename=iexplorer.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Microsoft .NET Confingurator]
Confirmed=X
Filename=msnconf.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft 16Bit Update]
Confirmed=X
Filename=wuapdate16.exe
Description=Added by the RBOT.CZ WORM!
Source=Paul Collins Startup list
[Microsoft ALG32 Protocol]
Confirmed=X
Filename=alg32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Announcement Listener]
Confirmed=N
Filename=Annclist.exe
Description=MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
Source=Paul Collins Startup list
[Microsoft Ansti Update]
Confirmed=X
Filename=msie.exe
Description=Added by the RBOT-LE WORM!
Source=Paul Collins Startup list
[Microsoft AOL32 Protocol]
Confirmed=X
Filename=aol32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Associates, Inc.]
Confirmed=X
Filename=iexplorer.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Microsoft AUT Update]
Confirmed=X
Filename=MSlti32.exe
Description=Added by the RBOT-X WORM!
Source=Paul Collins Startup list
[Microsoft AUT Update]
Confirmed=X
Filename=MSlti16.exe
Description=Added by the RBOT.EB WORM!
Source=Paul Collins Startup list
[Microsoft auto update]
Confirmed=X
Filename=winupdate.exe
Description=Added by the BMBOT TROJAN!
Source=Paul Collins Startup list
[Microsoft AutoUpdater]
Confirmed=X
Filename=svhost.exe
Description=Added by the RBOT.QG WORM!
Source=Paul Collins Startup list
[Microsoft Conf Ldr]
Confirmed=X
Filename=sysconf.exe
Description=Added by a variant of the SDBOT TROJAN!
Source=Paul Collins Startup list
[Microsoft Config]
Confirmed=X
Filename=msconf.exe
Description=Added by the RBOT.PV WORM!
Source=Paul Collins Startup list
[Microsoft Config]
Confirmed=X
Filename=MSCONF.EXE
Description=Added by the RBOT-LG WORM!
Source=Paul Collins Startup list
[Microsoft Config File]
Confirmed=X
Filename=config.exe
Description=Added by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
Source=Paul Collins Startup list
[Microsoft Corporation]
Confirmed=X
Filename=[random filename]
Description=Added by various VIRUSES, WORMS & TROJANS!
Source=Paul Collins Startup list
[Microsoft CSRSS32 Protocol]
Confirmed=X
Filename=csrss32.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Microsoft CSRSS386 Protocol]
Confirmed=X
Filename=csrss386.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Cvrt]
Confirmed=X
Filename=mscvrt32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Data Helper]
Confirmed=X
Filename=cihost.exe
Description=Malware, possibly a variant of the LINST TROJAN
Source=Paul Collins Startup list
[Microsoft Data Machine]
Confirmed=X
Filename=csdata32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Database Handler]
Confirmed=X
Filename=mssql32.exe
Description=Added by the RANDEX.AX WORM!
Source=Paul Collins Startup list
[Microsoft Decryption Technology]
Confirmed=X
Filename=Msfenoe.exe
Description=Added by the SPYBOT-DG WORM!
Source=Paul Collins Startup list
[Microsoft Diagnostic]
Confirmed=X
Filename=[random filename]
Description=Added by the ACEBOT TROJAN!
Source=Paul Collins Startup list
[Microsoft Digital Clock]
Confirmed=X
Filename=msclock.exe
Description=Added by the NACKBOT-D WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=Spoolserv.exe
Description=Added by the DINFOR WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=rasmngr.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=PDSched.exe
Description=Added by the SDBOT.CN WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the SDBOT.MY WORM!
Source=Paul Collins Startup list
[Microsoft Dll Management]
Confirmed=X
Filename=windll.exe
Description=Added by the RBOT-MT WORM!
Source=Paul Collins Startup list
[Microsoft DNS Query]
Confirmed=X
Filename=msdns.exe
Description=Added by a variant of the WOOTBOT WORM!
Source=Paul Collins Startup list
[Microsoft Document]
Confirmed=X
Filename=krisp.exe
Description=Added by the SDBOT-RQ WORM!
Source=Paul Collins Startup list
[Microsoft Drivers]
Confirmed=X
Filename=WSconf.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Microsoft ErgoPack]
Confirmed=X
Filename=wserb32.exe
Description=Added by the RBOT-RI WORM!
Source=Paul Collins Startup list
[Microsoft Excell]
Confirmed=X
Filename=wuamngr32.exe
Description=Added by the RBOT-QH WORM!
Source=Paul Collins Startup list
[Microsoft Executing]
Confirmed=X
Filename=microsoft.exe
Description=Added by the AGOBOT.UV WORM!
Source=Paul Collins Startup list
[Microsoft EXPLOREXP Protocol]
Confirmed=X
Filename=explorexp.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Features]
Confirmed=X
Filename=ms32cfg.exe
Description=Added by the RBOT.HO WORM!
Source=Paul Collins Startup list
[Microsoft Find Fast]
Confirmed=X
Filename=Findfast.exe
Description=Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier
Source=Paul Collins Startup list
[Microsoft Firewall]
Confirmed=X
Filename=firewallsp2.exe
Description=Added by the RBOT-MC WORM!
Source=Paul Collins Startup list
[MICROSOFT FIREWALL CLIENT]
Confirmed=Y
Filename=ISATRAY.EXE
Description=MS Internet Security and Acceleration Server 2000
Source=Paul Collins Startup list
[Microsoft Gina V Encryption]
Confirmed=X
Filename=MSGINAV.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Greetings Reminders]
Confirmed=N
Filename=MHPRMIND.EXE
Description=Microsoft Home Publishing greetings reminder
Source=Paul Collins Startup list
[Microsoft Greetings Workshop Reminder]
Confirmed=N
Filename=Gwremind.exe
Description=You really want to be reminded about somebody's birthday at the expense of resources?
Source=Paul Collins Startup list
[Microsoft Greetings Reminder]
Confirmed=N
Filename=MHPRMINF.EXE
Description=You really want to be reminded about somebody's birthday at the expense of resources?
Source=Paul Collins Startup list
[Microsoft Help SVC]
Confirmed=X
Filename=msnmngr.exe
Description=Added by the SDBOT-PQ WORM!
Source=Paul Collins Startup list
[Microsoft Help System]
Confirmed=X
Filename=mshelp32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft IE]
Confirmed=X
Filename=Iexplore.exe
Description=Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Microsoft IE Execute shell]
Confirmed=X
Filename=IEExec.exe
Description=Added by the ALADINZ.N TROJAN!
Source=Paul Collins Startup list
[Microsoft IIS]
Confirmed=X
Filename=syshost.exe
Description=Added by the FRANCETTE WORM!
Source=Paul Collins Startup list
[Microsoft Inc.]
Confirmed=X
Filename=iexplorer.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Microsoft Inet Xp..]
Confirmed=X
Filename=teekids.exe
Description=Added by the BLASTER.C WORM!
Source=Paul Collins Startup list
[Microsoft Intellitype Pro]
Confirmed=U
Filename=speedkey.exe
Description=Additional keyboard shortcuts on MS programmable keyboard
Source=Paul Collins Startup list
[Microsoft Internet]
Confirmed=X
Filename=expl0rer.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Internet]
Confirmed=X
Filename=windows32.exe
Description=Added by the SDBOT-F WORM!
Source=Paul Collins Startup list
[Microsoft Internet Acceleration Utility]
Confirmed=X
Filename=iau.exe
Description=EasySearch adware
Source=Paul Collins Startup list
[Microsoft Internet Exp]
Confirmed=X
Filename=iiexplorer.exe
Description=Added by the RBOT-KX WORM!
Source=Paul Collins Startup list
[Microsoft Internet Explorer]
Confirmed=X
Filename=iexplore.exe
Description=Downloader trojan. Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Microsoft Internet Firewall Manager]
Confirmed=X
Filename=GMT16.exe
Description=Added by the RANDEX.AT WORM!
Source=Paul Collins Startup list
[Microsoft Internet Services]
Confirmed=X
Filename=Smss32.exe
Description=Added by the RBOT.MS WORM!
Source=Paul Collins Startup list
[Microsoft IPC]
Confirmed=X
Filename=system.exe
Description=Added by the NULLBOT TROJAN!
Source=Paul Collins Startup list
[Microsoft IPC]
Confirmed=X
Filename=svshost.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=win64.exe
Description=Added by the RBOT.GA WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=IEserv.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=msupdate.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=winn43.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=svchsst.exe
Description=Added by the RBOT-DH WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=win43.exe
Description=Added by the RBOT-SA WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=windows.exe
Description=Added by the RBOT-GL WORM!
Source=Paul Collins Startup list
[Microsoft Java Virtual Machine]
Confirmed=X
Filename=winscr32.exe
Description=Added by a variant of the WOOTBOT WORM!
Source=Paul Collins Startup list
[Microsoft Java Windows Update]
Confirmed=X
Filename=[filename]
Description=Added by the RBOT-DZ WORM!
Source=Paul Collins Startup list
[Microsoft JavaVM]
Confirmed=X
Filename=msjarun.exe
Description=Added by the RBOT-JW WORM!
Source=Paul Collins Startup list
[Microsoft Kernel]
Confirmed=X
Filename=Windows_kernel32.exe
Description=Added by the NETSKY.AE WORM!
Source=Paul Collins Startup list
[Microsoft Lmhosting Service]
Confirmed=X
Filename=lmhosts.exe
Description=Added by the RBOT-RC WORM!
Source=Paul Collins Startup list
[Microsoft Locals 332]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-KU WORM!
Source=Paul Collins Startup list
[Microsoft LSASS386 Protocol]
Confirmed=X
Filename=scvhost32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Macro Protection SubSsy]
Confirmed=X
Filename=msacroprots386.exe
Description=Added by the RBOT-KE WORM!
Source=Paul Collins Startup list
[Microsoft Macro Protection Subsystems]
Confirmed=X
Filename=msmacroprotxz.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Macro Protection Subsystems]
Confirmed=X
Filename=Msmacroprot32.exe
Description=Added by the RBOT.KN WORM!
Source=Paul Collins Startup list
[Microsoft Management]
Confirmed=X
Filename=lmas.exe
Description=Added by the FORBOT-CZ WORM!
Source=Paul Collins Startup list
[Microsoft Management Console]
Confirmed=X
Filename=lssas.exe
Description=EasySearch adware
Source=Paul Collins Startup list
[Microsoft media]
Confirmed=X
Filename=winmplayers.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft media services]
Confirmed=X
Filename=Iassd.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Microsoft media services]
Confirmed=X
Filename=winmplayer.exe
Description=Added by the RBOT.ZO WORM!
Source=Paul Collins Startup list
[Microsoft Movie Maker]
Confirmed=X
Filename=Mmaker.exe
Description=Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program
Source=Paul Collins Startup list
[Microsoft MSGPLUS32 Protocol]
Confirmed=X
Filename=msgplus32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft MSNGR32 Protocol]
Confirmed=X
Filename=msngr32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft MsnST]
Confirmed=X
Filename=msnst32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft MSUPDATE]
Confirmed=X
Filename=SpoolSvc.exe
Description=Added by the SXTB-A TROJAN!
Source=Paul Collins Startup list
[Microsoft NetMeeting Associates, Inc.]
Confirmed=X
Filename=NetMeeting.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Microsoft Netview]
Confirmed=X
Filename=gesfm32.exe
Description=Added by the RANDEX.C WORM!
Source=Paul Collins Startup list
[Microsoft Netview]
Confirmed=X
Filename=mssvc32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Netview Component v5.1]
Confirmed=X
Filename=msnv32.exe
Description=Added by the RANDEX.F WORM!
Source=Paul Collins Startup list
[Microsoft Network]
Confirmed=X
Filename=msnet.exe
Description=Added by the MOCKBOT.A WORM!
Source=Paul Collins Startup list
[Microsoft Network Daemon for Win32]
Confirmed=X
Filename=Netd32.exe
Description=Added by the SDBOT.R TROJAN!
Source=Paul Collins Startup list
[Microsoft NT Update]
Confirmed=X
Filename=winexec32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=N
Filename=Osa.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=N
Filename=Msoffice.exe
Description=Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=X
Filename=MSMSGR.exe
Description=Added by the GAOBOT.BB WORM!
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=N
Filename=Osa9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=X
Filename=lserv.exe
Description=Added by the SDBOT.MH WORM!
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=X
Filename=Microsoft Office.hta
Description=HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
Source=Paul Collins Startup list
[Microsoft Office Fast Cache]
Confirmed=N
Filename=Fastboot.exe
Description=Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled
Source=Paul Collins Startup list
[Microsoft Office OneNote 2003 Quick Launch]
Confirmed=U
Filename=ONENOTEM.EXE
Description=ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work
Source=Paul Collins Startup list
[Microsoft Office Shortcut Bar]
Confirmed=N
Filename=Msoffice.exe
Description=Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
Source=Paul Collins Startup list
[Microsoft Office Start]
Confirmed=X
Filename=winupdates.exe
Description=Added by the GAOBOT.BC WORM!
Source=Paul Collins Startup list
[Microsoft Office Startup]
Confirmed=N
Filename=Osa.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Office Startup]
Confirmed=N
Filename=Osa9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Personal Firewalls]
Confirmed=X
Filename=bakw.exe
Description=Added by the RBOT-KS WORM!
Source=Paul Collins Startup list
[Microsoft RDLL]
Confirmed=X
Filename=sysconf32.exe
Description=Added by a variant of the SDBOT TROJAN!
Source=Paul Collins Startup list
[Microsoft Registry]
Confirmed=X
Filename=csrse.exe
Description=Added by the RBOT-PC WORM!
Source=Paul Collins Startup list
[Microsoft Restore]
Confirmed=X
Filename=scrgrd.exe
Description=Added by the SPYBOT.BR WORM!
Source=Paul Collins Startup list
[Microsoft Runtime]
Confirmed=X
Filename=CfgDll32.exe
Description=Added by the RANDEX.BD WORM!
Source=Paul Collins Startup list
[Microsoft Scanreg]
Confirmed=X
Filename=microsoftscanreg.exe
Description=Added by the FRANRIV.A WORM!
Source=Paul Collins Startup list
[Microsoft SCVHOST32 Protocol]
Confirmed=X
Filename=scvhost32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Secure Messenger.NET Service]
Confirmed=X
Filename=securitychk.exe
Description=Added by the SDBOT.VT WORM!
Source=Paul Collins Startup list
[Microsoft Security Hot Fix Update]
Confirmed=X
Filename=mshotfix.exe
Description=Affilred adware
Source=Paul Collins Startup list
[Microsoft Security Management]
Confirmed=X
Filename=winnt.exe
Description=Added by the RBOT-MQ WORM!
Source=Paul Collins Startup list
[Microsoft Security Management]
Confirmed=X
Filename=winserv.exe
Description=Added by the RBOT-MJ WORM!
Source=Paul Collins Startup list
[Microsoft Server Application]
Confirmed=X
Filename=Sound.exe
Description=Added by the RBOT-NE WORM!
Source=Paul Collins Startup list
[Microsoft Service]
Confirmed=X
Filename=microhost.exe
Description=Added by the RBOT-LC WORM!
Source=Paul Collins Startup list
[Microsoft Service]
Confirmed=X
Filename=winsvc.exe
Description=Added by the SPYBOT-DB WORM!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=lsserv.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=lssrv.exe
Description=Added by the RBOT.CW WORM!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=services.exe
Description=Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=lsrv.exe
Description=Added by the RBOT-BK WORM!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=svshost.exe
Description=Added by the ALETS.B TROJAN!
Source=Paul Collins Startup list
[Microsoft Sidewinder Game Controller Software]
Confirmed=N
Filename=SWTRAY.EXE
Description=MS SideWinder game controller system tray icon. Available via Start -> Programs
Source=Paul Collins Startup list
[Microsoft Software]
Confirmed=X
Filename=sysinfo33.exe
Description=Added by the RBOT.LS WORM!
Source=Paul Collins Startup list
[microsoft software]
Confirmed=X
Filename=****.exe E255 [* = random char]
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft software]
Confirmed=X
Filename=cdaccess.exe
Description=Added by the RBOT.ABK WORM!
Source=Paul Collins Startup list
[Microsoft Software Update]
Confirmed=X
Filename=nmon.exe
Description=Added by the RBOT.HZ WORM!
Source=Paul Collins Startup list
[Microsoft Sound Driver]
Confirmed=X
Filename=sound32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Sound Volume Tool]
Confirmed=N
Filename=mssvol.exe
Description=This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Microsoft SourceSafe]
Confirmed=X
Filename=csrss.exe
Description=Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Microsoft Spool Server for Win32]
Confirmed=X
Filename=spoolsrv.exe
Description=Added by the RANDEX.H WORM!
Source=Paul Collins Startup list
[Microsoft SSISVRI32 Protocol]
Confirmed=X
Filename=ssisvri.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=asgard.exe
Description=Added by the SDBOT.PH WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=bot.exe
Description=Added by the SDBOT.IH WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=netscape.exe
Description=Added by the RANDEX.AE WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=slhost.exe
Description=Added by the SDBOT.YH WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=svhost.exe
Description=Added by the SDBOT-PY WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=WinLoginnn.exe
Description=Added by the SPYBOT.FO WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=winupdate.exe
Description=Added by the SDBOT.ER WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=xXx.exe
Description=Added by the SDBOT-KZ WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=___synmgr.exe
Description=Added by the MASLAN.A or MASLAN.C WORMS!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=al.exe
Description=Added by the OPTXPRO.132 TROJAN!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=win.exe
Description=Added by the SDBOT.AK WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=Cool.exe
Description=Added by the DONK.B WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=Wnetlib.exe
Description=Added by the DONK.C WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=dbnetlib.exe
Description=Added by the DONK.L WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=Keymgr.exe
Description=Added by the DONK.M WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=inetman.exe
Description=Added by the DONK.O WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=ntsysmgr.exe
Description=Added by the DONK.S WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=ntsysman.exe
Description=Added by the SDBOT-QW WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=libsysmgr.exe
Description=Added by the SDBOT-CAF WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=sysmgr.exe
Description=Added by the SDBOT-OO TROJAN!
Source=Paul Collins Startup list
[Microsoft System Restore Configuration]
Confirmed=X
Filename=CBRSS.EXE
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft System32 Update]
Confirmed=X
Filename=cmsrg.exe
Description=Added by the RBOT-GN WORM!
Source=Paul Collins Startup list
[Microsoft Time Manager]
Confirmed=X
Filename=dveldr.exe
Description=Added by the RBOT-HQ WORM!
Source=Paul Collins Startup list
[Microsoft Transfer File Server]
Confirmed=X
Filename=mtfs.exe
Description=Added by the RBOT.AFE WORM!
Source=Paul Collins Startup list
[Microsoft Tray]
Confirmed=X
Filename=[random filename]
Description=Added by the DELF.BZ TROJAN!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Microsoft.exe
Description=Added by the GAOBOT.AFJ WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=mssmgrd.exe
Description=Added by the SDBOT.JT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=mvsc.exe
Description=Added by the SPYBOT.DAZ WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=ascdl.exe
Description=Added by the GAOBOT.SY WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Isac.exe
Description=Added by the RBOT-AU WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=automgr32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=mediap.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Microsoftx.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=msconfg.exe
Description=Added by the RBOT.H WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Mslti32.exe
Description=Added by the RBOT-LX WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=muamgrd.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=navmgrd.exe
Description=Added by the SDBOT.DP TROJAN!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Smss32.exe
Description=Added by the RBOT.CB WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=sys32cfg.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=VPC32.EXE
Description=Added by the AGOBOT.XM WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=winsys32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the RBOT-LK WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuammgr32.exe
Description=Added by the RBOT-AW WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wudmate.exe
Description=Added by the RBOT.AP WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=msawindows.exe
Description=Added by the GAOBOT.AFJ WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=msiwin84.exe
Description=Added by the GAOBOT.AFJ WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuamgrd32.exe
Description=Added by the RBOT.ZB WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=NAV.exe
Description=Added by the RBOT-IV WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=systemi32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=xpupdate.exe
Description=Added by the RBOT-QE WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=webm.exe
Description=Added by the SDBOT.WK WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuagrd.exe
Description=Added by the RBOT-FK WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=aaupdt.exe
Description=Added by the RBOT-RQ WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=lsac.exe
Description=Added by the GAOBOT.XW WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Mupdate.exe
Description=Added by the RBOT-AG WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=prowind32.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=snlogsvc.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=svhost.exe
Description=Added by the RBOT-PI WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wauguard.exe
Description=Added by the RBOT.AEE WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=winscv.exe
Description=Added by the RBOT-BH WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=winsys.exe
Description=Added by the RBOT-GV WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wserv32.exe
Description=Added by the RBOT.AF WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wtm32.exe
Description=Added by the RBOT-AQ WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wumgrd.exe
Description=Added by the SDBOT-KY WORM!
Source=Paul Collins Startup list
[Microsoft Update 32]
Confirmed=X
Filename=explore32.exe
Description=Added by the SPYBOT.CYM WORM!
Source=Paul Collins Startup list
[Microsoft Update 32]
Confirmed=X
Filename=MSupdate32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[MICROSOFT UPDATE CONFIGURATION]
Confirmed=X
Filename=WIN32SNC.EXE
Description=Added by the RBOT-AI WORM!
Source=Paul Collins Startup list
[Microsoft Update Emulator]
Confirmed=X
Filename=kern-mxe.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Loader]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=expl0rer.exe
Description=Added by the SDBOT.OK WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=rxhost.exe
Description=Added by the RBOT.FC WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=servicz.exe
Description=Added by the RBOT-HU WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=SP2.exe
Description=Added by the SPYBOT.FP WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winini.exe
Description=Added by the RBOT-KV WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=xvshost.exe
Description=Added by the RBOT.QP WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=memstat.exe
Description=Added by the RBOT-OM WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=ntce.exe
Description=Added by the RBOT-FA WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=system03.exe
Description=Added by the RBOT-NM WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuawx.exe
Description=Added by the RBOT-CE WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=zonealarm.exe
Description=Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=systemll.exe
Description=Added by the RBOT-JT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winupdt.exe
Description=Added by the RBOT-FP WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=svshost.exe
Description=Added by the RBOT.AK WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuamgd.exe
Description=Added by the SDBOT.HQ WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wupdt32x.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=linux.exe
Description=Added by the RBOT-IM WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=lmrss.exe
Description=Added by the RBOT-DY WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=windowsu.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wininigo.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winmgr.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=Winmsixp32.exe
Description=Added by the RBOT.DN WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=Winregs32.exe
Description=Added by the RBOT.DN WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winxpini.exe
Description=Added by the RBOT-OB WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the RBOT-HE WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuagrd.exe
Description=Added by the RBOT-GF WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=LANWAKE.EXE
Description=Added by the RBOT-QZ WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=scvhost.exe
Description=Added by the RBOT-GS WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winhost.exe
Description=Added by the RBOT-GK WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winss.exe
Description=Added by the RBOT.JU WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=WUAMGRDXS.EXE
Description=Added by the RBOT-GL WORM!
Source=Paul Collins Startup list
[Microsoft Update Manager]
Confirmed=X
Filename=WINRLS.EXE
Description=Added by the RBOT-AF WORM!
Source=Paul Collins Startup list
[Microsoft Update Mechene]
Confirmed=X
Filename=Updatez.exe
Description=Added by the RBOT-GI WORM!
Source=Paul Collins Startup list
[Microsoft Update Module]
Confirmed=X
Filename=rundll24.exe
Description=Added by the RBOT-PS WORM!
Source=Paul Collins Startup list
[Microsoft Update Security Patch]
Confirmed=X
Filename=mssecurityupdatepatch.exe
Description=Added by the AGENT.EF TROJAN!
Source=Paul Collins Startup list
[Microsoft Update Server]
Confirmed=X
Filename=mssrv.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Update Service]
Confirmed=X
Filename=csrss32.exe
Description=Added by the AGOBOT-HC WORM!
Source=Paul Collins Startup list
[Microsoft Update Service]
Confirmed=X
Filename=mswin32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft update service]
Confirmed=X
Filename=systemm.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Microsoft Update Time]
Confirmed=X
Filename=wuam.exe
Description=Added by the RBOT-M WORM!
Source=Paul Collins Startup list
[Microsoft Update Win32a]
Confirmed=X
Filename=winupdate32a.exe
Description=Added by the RBOT-LO WORM!
Source=Paul Collins Startup list
[Microsoft UPDATER32]
Confirmed=X
Filename=lsass.exe
Description=Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[Microsoft Updaters Pros]
Confirmed=X
Filename=WINDLL32XP.EXE
Description=Added by the SPYBOTTER.GEN VIRUS!
Source=Paul Collins Startup list
[Microsoft Updates]
Confirmed=X
Filename=systemc32.exe
Description=Added by the RBOT-GR WORM!
Source=Paul Collins Startup list
[Microsoft Updates Resources]
Confirmed=X
Filename=WinFixIDs.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft upnp Update]
Confirmed=X
Filename=msie.exe
Description=Added by the RBOT-LQ WORM!
Source=Paul Collins Startup list
[Microsoft Utility Startup]
Confirmed=N
Filename=OSA9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Video Controls]
Confirmed=X
Filename=tskmsgr.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Virual Machine]
Confirmed=X
Filename=sms.exe
Description=Added by the RBOT-SP WORM!
Source=Paul Collins Startup list
[Microsoft Visual SourceSafe]
Confirmed=X
Filename=services.exe
Description=Added by the NEVEG.B or NEVEG.C WORMS!. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program
Source=Paul Collins Startup list
[Microsoft Visual SourceSafe]
Confirmed=X
Filename=winlogon.exe
Description=Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program
Source=Paul Collins Startup list
[Microsoft Visual Studio VSA]
Confirmed=X
Filename=varpc32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Webserver]
Confirmed=U
Filename=svctrl.exe
Description=Personal web server program which enables you to create and host a web server from your computer. Not required for most people
Source=Paul Collins Startup list
[Microsoft Windows]
Confirmed=X
Filename=mstask0.exe
Description=Added by the SDBOT.FQ WORM!
Source=Paul Collins Startup list
[Microsoft Windows 2000]
Confirmed=X
Filename=Winupdsdgm.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Microsoft Windows Control]
Confirmed=X
Filename=mswctl32.exe
Description=Added by the RBOT.JP WORM!
Source=Paul Collins Startup list
[Microsoft Windows DHCP]
Confirmed=X
Filename=___r.exe
Description=Added by the MASLAN.A or MASLAN.C WORMS!
Source=Paul Collins Startup list
[Microsoft Windows DLLHandler]
Confirmed=X
Filename=bitpaint.exe
Description=Added by the SDBOT.AHG WORM!
Source=Paul Collins Startup list
[Microsoft Windows GUI]
Confirmed=X
Filename=Windowz.exe
Description=Added by the RANDEX.AEV WORM!
Source=Paul Collins Startup list
[Microsoft Windows GUI]
Confirmed=X
Filename=msmonk32.exe
Description=Added by the SDBOT-PE WORM!
Source=Paul Collins Startup list
[Microsoft Windows Kernel Services]
Confirmed=X
Filename=winkrnl386.exe
Description=Added by the ZEBROXY TROJAN!
Source=Paul Collins Startup list
[Microsoft Windows Loader]
Confirmed=X
Filename=wloader.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Microsoft Windows Media Player]
Confirmed=X
Filename=mediaplayer.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Windows Media Player]
Confirmed=X
Filename=wimp.exe
Description=Added by the RBOT-FN WORM!
Source=Paul Collins Startup list
[Microsoft Windows Secure Server]
Confirmed=X
Filename=rpcxWindows.exe
Description=Added by the RBOT-LL WORM!
Source=Paul Collins Startup list
[Microsoft Windows Securety]
Confirmed=X
Filename=wurguar.exe
Description=Added by the RBOT-KY WORM!
Source=Paul Collins Startup list
[Microsoft Windows Security]
Confirmed=X
Filename=spvsper.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Microsoft Windows Task Manger]
Confirmed=X
Filename=Mstosk.exe
Description=Added by the SDBOT-WW WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=rundlls.exe
Description=Added by the HABRACK WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=msoffice2.exe
Description=Added by the RBOT-GB WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=spools.exe
Description=Added by the SDBOT.TD WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svchos.exe
Description=Added by the SDBOT.AC WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svcshost.exe
Description=Added by the FORBOT-CF WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svmhost.exe
Description=Added by the FORBOT-CH WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svshost.exe
Description=Added by the WOOTBOT.CJ WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=msnmessenger.exe
Description=Added by the SDBOT.AJ WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=msnwun.exe
Description=Added by the SDBOT-RM WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=scvvhost.exe
Description=Added by the FORBOT-DH WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update Service]
Confirmed=X
Filename=wupdmgr32.exe
Description=Added by the DOS.AUTOCAT TROJAN!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=winupdgm.exe
Description=Added by the GAOBOT.BI WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=svchostz.exe
Description=Added by the DAEMONI-E TROJAN!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=WINIUPDATES.EXE
Description=Added by the RBOT-KK WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=WINUPDATE.EXE
Description=Added by the SDBOT-PU WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=TMNTSrv.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=win32upd.exe
Description=Added by the RBOT-EC WORM!
Source=Paul Collins Startup list
[Microsoft Windows updaterD]
Confirmed=X
Filename=log32zx.exe
Description=Added by the MYDOOM.W WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updates]
Confirmed=X
Filename=explorer32.exe
Description=Added by the SDBOT.VQ WORM!
Source=Paul Collins Startup list
[Microsoft Windows W32 Services]
Confirmed=X
Filename=mssw32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft Winsock Wrapper]
Confirmed=X
Filename=ws2_32s.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=mntcgf032.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=svh0st.exe
Description=Added by the SPYBOT.DL WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=syslx32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=syswin32.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdates]
Confirmed=X
Filename=serm32.exe
Description=Added by the RBOT.GE WORM!
Source=Paul Collins Startup list
[Microsoft Word]
Confirmed=X
Filename=BootSector.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Microsoft Works Calendar Reminders]
Confirmed=N
Filename=wkcalrem.exe
Description=Produces a pop-up reminder of events scheduled using the MS Works Calendar
Source=Paul Collins Startup list
[Microsoft Works Portfolio]
Confirmed=N
Filename=WksSb.exe
Description=The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
Source=Paul Collins Startup list
[Microsoft Works Update Detection ]
Confirmed=N
Filename=wkdetect.exe
Description=Checks for updates to MS Works
Source=Paul Collins Startup list
[Microsoft World Service]
Confirmed=X
Filename=winworld.exe
Description=Added by an unidentified IRC worm with backdoor capability!
Source=Paul Collins Startup list
[Microsoft Wxdate]
Confirmed=X
Filename=Syswu32.exe
Description=Added by the SPYBOT.HZ WORM!
Source=Paul Collins Startup list
[microsoft xdaemon 2.0]
Confirmed=X
Filename=xdaemon.exe
Description=Added by the DELF.D TROJAN!
Source=Paul Collins Startup list
[Microsoft XML Service]
Confirmed=X
Filename=msxmlx.exe
Description=Added by the RBOT.KS WORM!
Source=Paul Collins Startup list
[Microsoft--Updates]
Confirmed=X
Filename=sxvhost.exe
Description=Added by the RBOT-FH WORM!
Source=Paul Collins Startup list
[Microsoft-Update]
Confirmed=X
Filename=wngard.exe
Description=Added by the RBOT-JV WORM!
Source=Paul Collins Startup list
[Microsoft-Updates]
Confirmed=X
Filename=svxhost.exe
Description=Added by the RBOT-CT WORM!
Source=Paul Collins Startup list
[microsoft420]
Confirmed=X
Filename=microsoft420.exe
Description=Added by the MENACE.B WORM!
Source=Paul Collins Startup list
[Microsoftkeysd]
Confirmed=X
Filename=systemproc.exe
Description=Added by the FORBOT-BI WORM!
Source=Paul Collins Startup list
[Microsoftkeysd]
Confirmed=X
Filename=systemwin32s.exe
Description=Added by the WOOTBOT.CO WORM!
Source=Paul Collins Startup list
[Microsoftmsn32.exe]
Confirmed=X
Filename=microsoftmsn32.exe
Description=Added by the CERTIF-C TROJAN!
Source=Paul Collins Startup list
[MicrosoftMultimediaTask]
Confirmed=X
Filename=Mmtask.exe
Description=Adware downloader - not the valid MusicMatch Jukebox which shares the same filename
Source=Paul Collins Startup list
[MicrosoftNetwork Daemon for Win32]
Confirmed=X
Filename=NETD32.EXE
Description=Added by the RANDEX.F WORM!
Source=Paul Collins Startup list
[MicrosoftOEM]
Confirmed=X
Filename=smvss.exe
Description=Added by the DEDLER-G TROJAN!
Source=Paul Collins Startup list
[Microsofts media]
Confirmed=X
Filename=winmplayd.exe
Description=Added by an undidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Microsofts Security Manager]
Confirmed=X
Filename=****.exe [**** = random char]
Description=Added by the RBOT-WH TROJAN!
Source=Paul Collins Startup list
[Microsofts Updatez]
Confirmed=X
Filename=cmsssr.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=mstask32.exe
Description=Added by the YAHA.P WORM!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=Wintsk32.exe
Description=Added by the YAHA.U WORM!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=EXPLORERE.EXE
Description=Added by the YAHA.AB WORM!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=msupdat.exe
Description=Added by the YAHA.AA WORM!
Source=Paul Collins Startup list
[MicrosoftSourceSafe]
Confirmed=X
Filename=lsass.exe
Description=Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[MicrosoftUpdate]
Confirmed=X
Filename=syshelper.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MicrosoftUpdate]
Confirmed=X
Filename=WinUp32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MicrosoftValue]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Microsoftvirus]
Confirmed=X
Filename=sysoverload.exe
Description=Added by the FORBOT-AL WORM!
Source=Paul Collins Startup list
[MicrosoftWindows]
Confirmed=X
Filename=[various filenames]
Description=MagicSearch - a CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Microsoft© PID Lex]
Confirmed=X
Filename=PIDLex.exe
Description=Added by the NIOVADOOR TROJAN!
Source=Paul Collins Startup list
[Microsoft® System Mapper]
Confirmed=X
Filename=SysMap.exe
Description=Added by the MAPSY TROJAN!
Source=Paul Collins Startup list
[Microszoft Update Mach1nezs]
Confirmed=X
Filename=svchst.exe
Description=Added by the RBOT-ED WORM!
Source=Paul Collins Startup list
[Microzoft_Ofiz]
Confirmed=X
Filename=KdzEregli.exe
Description=Added by the AMUS.A WORM!
Source=Paul Collins Startup list
[Micrsoft Driver]
Confirmed=X
Filename=windrive.exe
Description=Added by the SDBOT.AF TROJAN!
Source=Paul Collins Startup list
[MightyFAX Controller]
Confirmed=N
Filename=MFNTCTL.EXE
Description=Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software"
Source=Paul Collins Startup list
[MigrationVendorSetupCaller]
Confirmed=?
Filename=rundll32.exe migrate.dll, CallVendorSetupDlls
Description=??
Source=Paul Collins Startup list
[MimBoot]
Confirmed=N
Filename=mimboot.exe
Description=Starts Musicmatch Jukebox at bootup - can be started manually
Source=Paul Collins Startup list
[MINIBUG]
Confirmed=X
Filename=MINIBUG.EXE
Description=Displays ads inside Weatherbug - see here
Source=Paul Collins Startup list
[MINIFERT.EXE]
Confirmed=N
Filename=MINIFERT.EXE
Description=Part of Backweb
Source=Paul Collins Startup list
[minilog]
Confirmed=U
Filename=MINILOG.EXE
Description=If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use
Source=Paul Collins Startup list
[MiniMavis]
Confirmed=N
Filename=MiniMavis.exe
Description=Mavis Beacon typing tutor
Source=Paul Collins Startup list
[MiniNote]
Confirmed=N
Filename=MININOTE.EXE
Description=Mini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software
Source=Paul Collins Startup list
[Miniphone]
Confirmed=?
Filename=glophone.exe
Description=VoiceGlo Glophone Voice over Internet Protocol (VOIP) communications software - "an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer" - is it required in startup?
Source=Paul Collins Startup list
[MinMaxExtender]
Confirmed=U
Filename=Mmext.exe
Description=MinMaxExtender - window handling tool
Source=Paul Collins Startup list
[Miosf Update]
Confirmed=X
Filename=wimsqaad.exe
Description=Added by the SDBOT.AG TROJAN!
Source=Paul Collins Startup list
[Mirabilis ICQ]
Confirmed=N
Filename=NDetect.exe
Description=If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Source=Paul Collins Startup list
[Mirabilis ICQ]
Confirmed=N
Filename=icq.exe
Description=If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Source=Paul Collins Startup list
[Mirabilis ICQ]
Confirmed=N
Filename=ICQNet.exe
Description=If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Source=Paul Collins Startup list
[Miramar Systems, Inc.]
Confirmed=U
Filename=atmsg.exe
Description=Miramar PC/Mac networking software
Source=Paul Collins Startup list
[Mirate Sp 2 Information]
Confirmed=X
Filename=miratesp2.exe
Description=Added by the RBOT.QH WORM!
Source=Paul Collins Startup list
[miroVIDEO Tray Tool]
Confirmed=N
Filename=misitray.exe
Description=Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions
Source=Paul Collins Startup list
[MirrorFolderShell]
Confirmed=U
Filename=mrfshl.exe
Description=MirrorFolder backup software
Source=Paul Collins Startup list
[misiCTRL]
Confirmed=?
Filename=misiCTRL.exe
Description=Miro video driver related. Is it required?
Source=Paul Collins Startup list
[misiTRAY]
Confirmed=?
Filename=misiTRAY.exe
Description=Miro video driver related. Is it required?
Source=Paul Collins Startup list
[Mixer]
Confirmed=N
Filename=Mixer.exe
Description=C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
Source=Paul Collins Startup list
[Mixghost]
Confirmed=N
Filename=mixghost.exe
Description=Management software for Altec Lansing speakers. If a change is needed, the user can launch it from the Start menu
Source=Paul Collins Startup list
[mload]
Confirmed=X
Filename=lxmstart.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MM Install]
Confirmed=?
Filename=setup.exe
Description=Possibly Money Manager from Moneysoft?
Source=Paul Collins Startup list
[mmcndmgr]
Confirmed=X
Filename=mmcndmgr.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MMCWINMGMT]
Confirmed=N
Filename=winmgmt.exe
Description=Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
Source=Paul Collins Startup list
[MMERefresh]
Confirmed=U
Filename=MMERefresh.exe
Description=Part of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R
Source=Paul Collins Startup list
[Mmgsvc]
Confirmed=X
Filename=mmgsvc.exe
Description=Mmgsvc spyware
Source=Paul Collins Startup list
[MMhid]
Confirmed=U
Filename=mmhid.dll
Description=This is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP
Source=Paul Collins Startup list
[MMHK]
Confirmed=?
Filename=mmhk.exe
Description=A driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys?
Source=Paul Collins Startup list
[MMHotKey]
Confirmed=N
Filename=MMHotKey.exe
Description=Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
Source=Paul Collins Startup list
[MMKeybd]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[mmod]
Confirmed=X
Filename=mmod.exe
Description=Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information
Source=Paul Collins Startup list
[mmpti]
Confirmed=N
Filename=m1mmpti.exe
Description=Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards
Source=Paul Collins Startup list
[MMRun]
Confirmed=?
Filename=mmrun.exe
Description=??
Source=Paul Collins Startup list
[mmsys]
Confirmed=?
Filename=recover.exe
Description=??
Source=Paul Collins Startup list
[MMSystem]
Confirmed=X
Filename=RunDll32
Description=Added by the FUNNER-A WORM!
Source=Paul Collins Startup list
[MMTASK]
Confirmed=Y
Filename=mmtask.tsk
Description=A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc
Source=Paul Collins Startup list
[mmtask]
Confirmed=N
Filename=mmtask.exe
Description=Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator
Source=Paul Collins Startup list
[MMtask Service]
Confirmed=X
Filename=mmtask.exe
Description=Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename
Source=Paul Collins Startup list
[MMTray]
Confirmed=N
Filename=mm_tray.exe
Description=MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator
Source=Paul Collins Startup list
[MMTray]
Confirmed=N
Filename=MMTray.exe
Description=Part of Morgan Multimedia Codecs. Only required when the codecs are used
Source=Paul Collins Startup list
[MMTray2K]
Confirmed=N
Filename=MMTray2K.exe
Description=Part of Morgan Multimedia Codecs. Only required when the codecs are used
Source=Paul Collins Startup list
[MMTrayLSI]
Confirmed=N
Filename=MMTrayLSI.exe
Description=Part of Morgan Multimedia Codecs. Only required when the codecs are used
Source=Paul Collins Startup list
[mmusrstp]
Confirmed=?
Filename=procrun.exe
Description=??
Source=Paul Collins Startup list
[mmxrun]
Confirmed=X
Filename=msosa.exe
Description=Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return
Source=Paul Collins Startup list
[MNPol]
Confirmed=X
Filename=mnpol.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[MNS]
Confirmed=U
Filename=MNS.exe
Description=Mobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more
Source=Paul Collins Startup list
[mnsvc]
Confirmed=X
Filename=mnsvc.exe
Description=Added by the AUTOUPDER TROJAN!
Source=Paul Collins Startup list
[mnsvcsp]
Confirmed=X
Filename=mnsvcsp.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[mobsync]
Confirmed=N
Filename=mobsync.exe
Description=MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages
Source=Paul Collins Startup list
[MOBSYNC32.EXE]
Confirmed=X
Filename=mobsync32.exe
Description=Added by the FINERO TROJAN!
Source=Paul Collins Startup list
[MOD]
Confirmed=N
Filename=muamger.exe
Description=MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them
Source=Paul Collins Startup list
[Modem]
Confirmed=X
Filename=locatesvc.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[MODEMBTR]
Confirmed=U
Filename=MODEMBTR.EXE
Description=Modem Booster from inKline Global to improve ISP connections
Source=Paul Collins Startup list
[Modeminf]
Confirmed=X
Filename=Modeminf.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[ModemOnHold]
Confirmed=U
Filename=MOH.EXE
Description=NetWaiting Modem-on-Hold Application
Source=Paul Collins Startup list
[ModemUtility]
Confirmed=N
Filename=mdmsetpe.exe
Description=System Tray configuration icon for Aztech modems
Source=Paul Collins Startup list
[ModularConfig]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Module Call initialize]
Confirmed=X
Filename=RUNDLL32.EXE reg.dll, ondll_reg
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Money Express]
Confirmed=N
Filename=moneyexpress.exe
Description=Part of MS Money. Available via Start -> Programs
Source=Paul Collins Startup list
[MoneyAgent]
Confirmed=N
Filename=money express.exe
Description=Part of MS Money. Available via Start -> Programs
Source=Paul Collins Startup list
[MoneyAgent]
Confirmed=N
Filename=mnyexpr.exe
Description=Microsoft Money
Source=Paul Collins Startup list
[MoneyStartUp]
Confirmed=N
Filename=Money Startup.exe
Description=Microsoft Money
Source=Paul Collins Startup list
[MoneyStartUp10.0]
Confirmed=N
Filename=Activation.exe
Description=Part of MS Money 2002. Available via Start -> Programs
Source=Paul Collins Startup list
[Monitor Apache Servers]
Confirmed=U
Filename=ApacheMonitor.exe
Description=Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
Source=Paul Collins Startup list
[Monitoring Service]
Confirmed=X
Filename=svchost.exe
Description=Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Monitormgt]
Confirmed=X
Filename=Monitormgt.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Monstersoundtray]
Confirmed=N
Filename=Freectrl.exe
Description=Diamond Multimedia sound card control panel
Source=Paul Collins Startup list
[MonTest]
Confirmed=X
Filename=vccxzq.exe
Description=Added by the SDBOT-EA WORM!
Source=Paul Collins Startup list
[MoodBook]
Confirmed=U
Filename=mb.exe
Description=MoodBook is a free Windows utility that brings art to your desktop
Source=Paul Collins Startup list
[moon phase]
Confirmed=N
Filename=moon.exe
Description=Moon Phase - tray icon that indicates the phases of the moon
Source=Paul Collins Startup list
[Morpheus]
Confirmed=N
Filename=morpheus.exe
Description=MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it"
Source=Paul Collins Startup list
[mosearch]
Confirmed=X
Filename=mosearch.exe
Description=Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here
Source=Paul Collins Startup list
[Motive SmartBridge]
Confirmed=N
Filename=mpbtn.exe
Description=System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[Motive SmartBridge]
Confirmed=N
Filename=MotiveSB.exe
Description=System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[MotiveMonitor]
Confirmed=U
Filename=motmon.exe
Description=Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required
Source=Paul Collins Startup list
[MotiveSB]
Confirmed=N
Filename=MotiveSB.exe
Description=System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[MotMon]
Confirmed=U
Filename=motmon.exe
Description=Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required
Source=Paul Collins Startup list
[Mount Safe & Sound]
Confirmed=U
Filename=Fbmount.exe
Description=From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
Source=Paul Collins Startup list
[Mouse 32A]
Confirmed=N
Filename=Mouse32A.exe
Description=Mouse driver to control mouse functions from Azona. Available via Start -> Programs
Source=Paul Collins Startup list
[Mouse Suite 98 Daemon]
Confirmed=N
Filename=pelmiced.exe
Description=Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
Source=Paul Collins Startup list
[mousebut]
Confirmed=X
Filename=mousebut.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[Mousecntl]
Confirmed=X
Filename=mousecntl.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[MouseCount]
Confirmed=N
Filename=MC.exe
Description=MouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required
Source=Paul Collins Startup list
[mousedrv]
Confirmed=X
Filename=mousedrv.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[mouseElf]
Confirmed=U
Filename=MC.exe
Description=Genius NetScroll mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[mouseElf]
Confirmed=U
Filename=mouseElf.exe
Description=System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[MouseImp]
Confirmed=U
Filename=MImpHost.exe
Description=MouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device"
Source=Paul Collins Startup list
[Mousinfo]
Confirmed=U
Filename=mousinfo.exe
Description=MS mouse information tool - for troubleshooting mouse problems
Source=Paul Collins Startup list
[Movielink Manager Uninstall]
Confirmed=N
Filename=msvcmm32.exe
Description=Auto-update for Movielink - internet movie rental System Tray access
Source=Paul Collins Startup list
[MovieNetworks]
Confirmed=X
Filename=MovieNetworks.exe
Description=MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:\Program Files\MovieNetworks directory
Source=Paul Collins Startup list
[Movieplace]
Confirmed=X
Filename=Movieplace.exe
Description=MoviePlace malware
Source=Paul Collins Startup list
[Mozilla Quick Launch]
Confirmed=N
Filename=Netscp6.exe
Description=Netscape 6 and Mozilla browsers
Source=Paul Collins Startup list
[Mozilla Quick Launch]
Confirmed=N
Filename=Mozilla.exe
Description=Netscape 6 and Mozilla browsers
Source=Paul Collins Startup list
[MP Tcloaxs]
Confirmed=X
Filename=mptcloaxs.exe
Description=Added by the RANDEX.CT WORM!
Source=Paul Collins Startup list
[MPEO]
Confirmed=U
Filename=Csinsm32.exe
Description=Automatic logging of installs from Norton CleanSweep - available via Start -> Programs
Source=Paul Collins Startup list
[MPFExe]
Confirmed=Y
Filename=mpf.exe
Description=McAfee Personal Firewall
Source=Paul Collins Startup list
[MPFExe]
Confirmed=Y
Filename=MpfTray.exe
Description=McAfee Personal Firewall
Source=Paul Collins Startup list
[MPL32 driver]
Confirmed=X
Filename=MPL32.exe
Description=Added by the LOONY-M TROJAN!
Source=Paul Collins Startup list
[MplSetup]
Confirmed=U
Filename=MplSetup.exe
Description=Used by Ricoh network printers to enable network printing from the client
Source=Paul Collins Startup list
[MPower]
Confirmed=U
Filename=MPower.exe
Description=MPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read this article and make up your own mind
Source=Paul Collins Startup list
[MPREXE]
Confirmed=X
Filename=MPREXE.EXE
Description=Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file
Source=Paul Collins Startup list
[MPREXE.exe]
Confirmed=Y
Filename=mprexe.exe
Description=WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus
Source=Paul Collins Startup list
[MprHTML]
Confirmed=X
Filename=MprHTML.exe
Description=Added by a variant of the VAGRNOCKER TROJAN!
Source=Paul Collins Startup list
[MPSExe]
Confirmed=U
Filename=mscifapp.exe
Description=McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
Source=Paul Collins Startup list
[MPT]
Confirmed=?
Filename=MPT.exe
Description=??
Source=Paul Collins Startup list
[MPtask Services]
Confirmed=X
Filename=mptask.exe
Description=Added by the LALA or AOT TROJANS!
Source=Paul Collins Startup list
[MPTBox]
Confirmed=N
Filename=MPTBOX.EXE
Description=Cannon Multi-Pass toolbox - a button bar
Source=Paul Collins Startup list
[MPXTray]
Confirmed=N
Filename=mpxptray.exe
Description=Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc
Source=Paul Collins Startup list
[MP_STATUS_MONITOR]
Confirmed=?
Filename=monitr32.exe
Description=Related to Cannon Multi-Pass
Source=Paul Collins Startup list
[mqbkup]
Confirmed=X
Filename=mqbkup.exe
Description=Added by the OPASERV.K WORM!
Source=Paul Collins Startup list
[mrtMngr]
Confirmed=N
Filename=mrtMngr.exe
Description=Maintenance Release Task Manager for Intuit’s QuickBooks or Quicken
Source=Paul Collins Startup list
[MRU-Blaster Scheduler]
Confirmed=U
Filename=scheduler.exe
Description=MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer
Source=Paul Collins Startup list
[MRU-Blaster Silent Clean]
Confirmed=N
Filename=mrublaster.exe
Description=MRU-Blaster - performs silent cleaning of MRU lists at boot
Source=Paul Collins Startup list
[MS Config Loader]
Confirmed=X
Filename=svchos1.exe
Description=Added by the AGOBOT.R WORM!
Source=Paul Collins Startup list
[MS Config Loader]
Confirmed=X
Filename=MSWin32bck.exe
Description=Added by the GAOBOT.AA WORM!
Source=Paul Collins Startup list
[MS Config Service]
Confirmed=X
Filename=Msloader32.exe
Description=Added by the RBOT-KJ WORM!
Source=Paul Collins Startup list
[MS Configuration]
Confirmed=X
Filename=MSFramer.exe
Description=Added by the RANDEX.OL WORM!
Source=Paul Collins Startup list
[MS Decryption Software]
Confirmed=X
Filename=active.exe
Description=MediaTickets adware variant
Source=Paul Collins Startup list
[MS Explorer]
Confirmed=X
Filename=mexplore.exe
Description=Added by the YAHA.AE WORM!
Source=Paul Collins Startup list
[MS FIREWALL]
Confirmed=X
Filename=msfrewall.exe
Description=Added by the SDBOT-PU WORM!
Source=Paul Collins Startup list
[MS FIREWALL]
Confirmed=X
Filename=msfirewall.exe
Description=Added by the SDBOT-QH WORM!
Source=Paul Collins Startup list
[MS HTML]
Confirmed=X
Filename=msHtml.exe
Description=Added by the PESTDOOR.31 TROJAN!
Source=Paul Collins Startup list
[MS HTML]
Confirmed=X
Filename=mslat.exe
Description=Added by the LATINUS.SVR TROJAN!
Source=Paul Collins Startup list
[MS lsass Startup]
Confirmed=X
Filename=lsass135.exe
Description=Added by the RBOT.WM WORM!
Source=Paul Collins Startup list
[MS management console]
Confirmed=?
Filename=mms.exe
Description=Suspicious as the Microsoft Management Console is "mmc.exe" and doesn't normally run at startup
Source=Paul Collins Startup list
[MS Network Control]
Confirmed=X
Filename=mswin.exe
Description=Added by the DUMBA TROJAN!
Source=Paul Collins Startup list
[MS Remote Procedure Call]
Confirmed=X
Filename=msrpc32.exe
Description=Added by the RBOT-QL WORM!
Source=Paul Collins Startup list
[MS Security Hotfix]
Confirmed=X
Filename=service5.exe
Description=Added by the GAOBOT.AG WORM!
Source=Paul Collins Startup list
[MS Sound Config 16bit]
Confirmed=X
Filename=sndcfg16.exe
Description=Added by the SDBOT.MB TROJAN!
Source=Paul Collins Startup list
[Ms Spool32]
Confirmed=X
Filename=MS SPOOL32.EXE
Description=Added by the ASASSIN TROJAN!
Source=Paul Collins Startup list
[MS SyS Restore]
Confirmed=X
Filename=sysrestore.exe
Description=Added by the RBOT.XM WORM!
Source=Paul Collins Startup list
[MS Update]
Confirmed=X
Filename=syshost.exe
Description=Added by the EVAMAN-F WORM!
Source=Paul Collins Startup list
[MS Updates]
Confirmed=X
Filename=mscache.exe
Description=Spyware web downloader
Source=Paul Collins Startup list
[MS Updates]
Confirmed=X
Filename=syshosts.exe
Description=Added by the MYDOOM.Y WORM!
Source=Paul Collins Startup list
[MS Updates]
Confirmed=X
Filename=aupd.exe
Description=Spyware web downloader
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=arr.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=cdm.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=game.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=msite18.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=web.exe
Description=Adult content dialler - see here
Source=Paul Collins Startup list
[MS-HTML]
Confirmed=X
Filename=[random filename]
Description=Added by the LATINUS.15 TROJAN!
Source=Paul Collins Startup list
[MS-RunKey]
Confirmed=X
Filename=arr.exe
Description=MS-Connect dialler/hijacker
Source=Paul Collins Startup list
[MS7531]
Confirmed=X
Filename=ms7531.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[MSACM]
Confirmed=X
Filename=msacm.exe
Description=Added by the OPASERV-O WORM!
Source=Paul Collins Startup list
[msadcheck]
Confirmed=X
Filename=msadcheck32.exe
Description=Browser hijacker, redirecting to search-system.com
Source=Paul Collins Startup list
[MSAdmin]
Confirmed=X
Filename=jdbgmrg.exe
Description=Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
Source=Paul Collins Startup list
[MSAgent]
Confirmed=X
Filename=mshtm.exe
Description=Browser hijacker - redirecting to buldog-search.com
Source=Paul Collins Startup list
[MSBB]
Confirmed=X
Filename=msbb.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[MSChoExE]
Confirmed=X
Filename=suge.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[msci]
Confirmed=?
Filename=mcinfo.exe
Description=McAfee Internet Security related. What does it do and is it required?
Source=Paul Collins Startup list
[mscman]
Confirmed=X
Filename=mscman.exe
Description=Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
Source=Paul Collins Startup list
[mscn]
Confirmed=U
Filename=mscn.exe
Description=Part of the SafeChildNet internet filtering program - required if you use it
Source=Paul Collins Startup list
[Mscnt]
Confirmed=X
Filename=mscnt.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Mscolour]
Confirmed=X
Filename=mscolour.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[MSCommX]
Confirmed=X
Filename=mscommx.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[MSCONFG32.EXE]
Confirmed=X
Filename=MSCONFG32.EXE
Description=Added by the OPTIX.04.C TROJAN!
Source=Paul Collins Startup list
[MSConfig]
Confirmed=N
Filename=msconfig.exe
Description=Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
Source=Paul Collins Startup list
[MSConfig]
Confirmed=X
Filename=MSCONFIG32.EXE
Description=Unidentified adware, spyware or virus
Source=Paul Collins Startup list
[msconfig]
Confirmed=X
Filename=msconfig.exe
Description=CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
Source=Paul Collins Startup list
[Msconfig]
Confirmed=X
Filename=msconfig.exe
Description=Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:\winrun\
Source=Paul Collins Startup list
[msconfig]
Confirmed=X
Filename=wins.exe
Description=Added by an unidentified IRC WORM with backdoor trojan capabilities!
Source=Paul Collins Startup list
[Msconfig lptt01]
Confirmed=X
Filename=msconfig.exe
Description=Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name
Source=Paul Collins Startup list
[MSConfig Manager]
Confirmed=X
Filename=msupdate.exe
Description=CoolWebSearch parasite related
Source=Paul Collins Startup list
[Msconfig ml097e]
Confirmed=X
Filename=msconfig.exe
Description=Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name
Source=Paul Collins Startup list
[msconfig service]
Confirmed=X
Filename=MSupdate32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[msconfig.exe]
Confirmed=X
Filename=proxy.exe
Description=Added by a variant of the AGENT.AH downloader TROJAN!
Source=Paul Collins Startup list
[msconfig.exe]
Confirmed=X
Filename=uline.exe
Description=Added by a variant of the AGENT.AH downloader TROJAN!
Source=Paul Collins Startup list
[MSConfig45]
Confirmed=X
Filename=MSConfig45.exe
Description=Added by the SDBOT.OJ TROJAN!
Source=Paul Collins Startup list
[MSConfigr]
Confirmed=X
Filename=jdbgmrg.exe
Description=Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
Source=Paul Collins Startup list
[MSConfigReminder]
Confirmed=N
Filename=msconfig.exe
Description=Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
Source=Paul Collins Startup list
[MSCORE]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Mscsgs]
Confirmed=X
Filename=MSCSGS.EXE
Description=Added by the ZEZER WORM!
Source=Paul Collins Startup list
[Mscsgs32]
Confirmed=X
Filename=MSCSGS32.EXE
Description=Added by the ZEZER WORM!
Source=Paul Collins Startup list
[Msctrl32]
Confirmed=X
Filename=Msctrl32.scr
Description=Added by the REDIST WORM!
Source=Paul Collins Startup list
[MSCVT]
Confirmed=X
Filename=MSCVT.exe
Description=Added by the SLIDESHOW WORM!
Source=Paul Collins Startup list
[msdev]
Confirmed=X
Filename=msdev.exe
Description=Added by the FORBOT-CR WORM!
Source=Paul Collins Startup list
[msdev]
Confirmed=X
Filename=msconfig.exe
Description=Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
Source=Paul Collins Startup list
[MSDLL]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Msdmxm]
Confirmed=X
Filename=msdmxm.exe
Description=Adult premium rate dialler
Source=Paul Collins Startup list
[Msdos32]
Confirmed=X
Filename=Msdos32.pif
Description=Added by the RECORY WORM!
Source=Paul Collins Startup list
[msdos423]
Confirmed=X
Filename=msdos423.exe
Description=Added by the MENACE.A WORM!
Source=Paul Collins Startup list
[MSDosdrv]
Confirmed=N
Filename=msdosdrv.exe
Description=Added by the BACROS WORM!
Source=Paul Collins Startup list
[MSDTC]
Confirmed=N
Filename=msdtc.exe
Description=MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
Source=Paul Collins Startup list
[Msemu32]
Confirmed=X
Filename=Msemu32.exe
Description=Unidentified spyware/adware/hijacker
Source=Paul Collins Startup list
[Msfind]
Confirmed=X
Filename=Msfind.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[MSFind32]
Confirmed=X
Filename=msfind32.exe
Description=Added by the CAYAM WORM!
Source=Paul Collins Startup list
[msfindosa.exe]
Confirmed=X
Filename=msfindosa.exe
Description=Added by the DOWNLOADER-BS TROJAN!
Source=Paul Collins Startup list
[Msg Fixage]
Confirmed=X
Filename=msgfixed.exe
Description=Added by the SDBOT.ZD WORM!
Source=Paul Collins Startup list
[MsgApi]
Confirmed=X
Filename=[path to file]
Description=Added by the DEDLER-D TROJAN!
Source=Paul Collins Startup list
[msgb1]
Confirmed=X
Filename=msgb1.exe
Description=Added by the DLUCA.GEN TROJAN!
Source=Paul Collins Startup list
[Msgmgr]
Confirmed=X
Filename=[path to worm]
Description=Added by the BABYBEAR WORM!
Source=Paul Collins Startup list
[msgserv_]
Confirmed=X
Filename=Syss.exe
Description=Added by the FANTA TROJAN!
Source=Paul Collins Startup list
[Msgsrv16]
Confirmed=X
Filename=Msgsrv16.exe
Description=Added by the DELF family of TROJANS!
Source=Paul Collins Startup list
[MSGSRV32.exe]
Confirmed=Y
Filename=msgsrv32.exe
Description=Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background
Source=Paul Collins Startup list
[msgsvr32]
Confirmed=X
Filename=msgsvr32.exe
Description=Added by the DEADHAT.B WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:\Windows\System) on a Win9x/Me machine
Source=Paul Collins Startup list
[Msgtray]
Confirmed=X
Filename=sys16.exe
Description=Added by an unknown VIRUS!
Source=Paul Collins Startup list
[MSHT@]
Confirmed=X
Filename=MSHT@.EXE
Description=Added by the MAGISTR.A VIRUS!
Source=Paul Collins Startup list
[msidle]
Confirmed=X
Filename=msidle.exe
Description=Added by the OPASERV-O WORM!
Source=Paul Collins Startup list
[MSIdll]
Confirmed=X
Filename=winmp.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[MSIEXEC]
Confirmed=X
Filename=MSIEXEC32.exe
Description=Added by the AINESEY.A WORM!
Source=Paul Collins Startup list
[MSIN]
Confirmed=?
Filename=MSin.exe
Description=??
Source=Paul Collins Startup list
[MSInfo]
Confirmed=X
Filename=msinfo.exe
Description=Added by the ALADINZ.M TROJAN!
Source=Paul Collins Startup list
[MSInfo]
Confirmed=X
Filename=AVBgle.exe
Description=Added by the NETSKY.O WORM!
Source=Paul Collins Startup list
[MSInstall]
Confirmed=X
Filename=smvss.exe
Description=Added by the DEDLER-G TROJAN!
Source=Paul Collins Startup list
[msjava service]
Confirmed=X
Filename=xpcd.exe
Description=Added by the SDBOT.VM WORM!
Source=Paul Collins Startup list
[MSKAGENTEXE]
Confirmed=U
Filename=MskAgent.exe
Description=Part of McAfee Spamkiller
Source=Paul Collins Startup list
[MSKCES32]
Confirmed=X
Filename=[random filename]
Description=Added by the CLONER TROJAN!
Source=Paul Collins Startup list
[MSKDetectorExe]
Confirmed=U
Filename=MSKDetct.exe
Description=Part of McAfee Spamkiller
Source=Paul Collins Startup list
[MSKernel32]
Confirmed=X
Filename=MSKernel32.vbs
Description=Added by the LOVELETTER (I LOVE YOU) VIRUS!
Source=Paul Collins Startup list
[MSkernel32]
Confirmed=X
Filename=System.exe 4820
Description=Added by the TUXDER TROJAN!
Source=Paul Collins Startup list
[MSKExe]
Confirmed=U
Filename=spamkiller.exe
Description=McAfee SpamKiller
Source=Paul Collins Startup list
[MSKServerExe]
Confirmed=U
Filename=MSKSrvr.exe
Description=Part of McAfee Spamkiller
Source=Paul Collins Startup list
[mslagent]
Confirmed=X
Filename=mslagent.exe
Description=Added by SIMCSS.B adware!
Source=Paul Collins Startup list
[MSLIB32]
Confirmed=?
Filename=mswatch32.exe
Description=??
Source=Paul Collins Startup list
[Mslogon lptt01]
Confirmed=X
Filename=mslogon.exe
Description=Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Mslogon ml097e]
Confirmed=X
Filename=mslogon.exe
Description=Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[MsManager]
Confirmed=X
Filename=msmgr32.exe
Description=Added by the YAHA.AF WORM!
Source=Paul Collins Startup list
[msmanager32]
Confirmed=X
Filename=msmngr32.exe
Description=Added by the RANDON-R (or WOMANIZ.A) WORM!
Source=Paul Collins Startup list
[msmc]
Confirmed=X
Filename=mscpbo.exe
Description=ClientMan parasite variant
Source=Paul Collins Startup list
[msmc]
Confirmed=X
Filename=msgdmf.exe
Description=ClientMan parasite variant
Source=Paul Collins Startup list
[msmc]
Confirmed=X
Filename=msongn.exe
Description=ClientMan parasite variant
Source=Paul Collins Startup list
[msmc]
Confirmed=X
Filename=msmc.exe
Description=ClientMan parasite variant
Source=Paul Collins Startup list
[MSMcAfeee]
Confirmed=X
Filename=Avsynmgr32e.exe
Description=Added by the FRAMAR TROJAN!
Source=Paul Collins Startup list
[MSMcAfeeh]
Confirmed=X
Filename=Avsynmgr32h.exe
Description=Added by the FRANGO TROJAN!
Source=Paul Collins Startup list
[MSMcAfeeS]
Confirmed=X
Filename=Avsynmgr32S.exe
Description=Added by the VOLAC or VOLAC.DR TROJANS!
Source=Paul Collins Startup list
[msmgr]
Confirmed=?
Filename=msmgr.exe
Description=??
Source=Paul Collins Startup list
[Msmgt]
Confirmed=X
Filename=msmgt.exe
Description=Total Velocity adware/hijacker
Source=Paul Collins Startup list
[msmon]
Confirmed=X
Filename=msmon.exe
Description=Added by a variant of the GEMA.D TROJAN!
Source=Paul Collins Startup list
[MsmqIntCert]
Confirmed=?
Filename=regsvr32 /s mqrt.dll
Description=Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?
Source=Paul Collins Startup list
[MSMSGS]
Confirmed=U
Filename=msmsgs.exe
Description=Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts"
Source=Paul Collins Startup list
[MSMsgSvc]
Confirmed=X
Filename=MSMSGSVC.exe
Description=Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
Source=Paul Collins Startup list
[msn]
Confirmed=X
Filename=system32.exe
Description=Added by the KITRO.A WORM!
Source=Paul Collins Startup list
[msn]
Confirmed=X
Filename=msnmsg.exe
Description=Added by the RBOT-GO WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=msnmsgs.exe
Description=Added by the RBOT-KL WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=ctfmoons.exe
Description=Added by the SPYBOT.HI WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=msnmesengers.exe
Description=Added by the RBOT-ME WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=MSN.exe
Description=Added by the MINIT WORM!
Source=Paul Collins Startup list
[MSN ang]
Confirmed=X
Filename=cssrss.exe
Description=Added by the FORBOT-CE WORM!
Source=Paul Collins Startup list
[Msn Config]
Confirmed=X
Filename=msngf.exe
Description=Added by the RBOT-QG WORM!
Source=Paul Collins Startup list
[MSN Internet Access]
Confirmed=N
Filename=trayclnt.exe
Description=Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards
Source=Paul Collins Startup list
[MSN Manager]
Confirmed=X
Filename=cvss.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[MSN Manager]
Confirmed=X
Filename=mscmgr.exe
Description=Unidentified malware - causes multiple browser windows to open
Source=Paul Collins Startup list
[MSN Messanger]
Confirmed=X
Filename=msnmsng.exe
Description=Added by the SDBOT.XN WORM!
Source=Paul Collins Startup list
[MSN messenger]
Confirmed=X
Filename=messenger.exe
Description=Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread
Source=Paul Collins Startup list
[Msn Messenger]
Confirmed=X
Filename=msnmsgs.exe
Description=Added by the LOONY-P TROJAN!
Source=Paul Collins Startup list
[MSN messenger service]
Confirmed=X
Filename=mssgs.exe
Description=Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread
Source=Paul Collins Startup list
[Msn Messengers]
Confirmed=X
Filename=MSNMSGR.EXE
Description=Added by the RBOT.KX WORM!
Source=Paul Collins Startup list
[Msn Patch]
Confirmed=X
Filename=msndp.exe
Description=Added by the RBOT.AAI WORM!
Source=Paul Collins Startup list
[Msn Patches]
Confirmed=X
Filename=msndr.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Msn Plus Updater]
Confirmed=X
Filename=msnplus.exe
Description=Added by the RBOT-MU WORM!
Source=Paul Collins Startup list
[MSN Quick View]
Confirmed=N
Filename=Msndc.exe
Description=Quick way to connect to MSN internet service
Source=Paul Collins Startup list
[MSN Start]
Confirmed=X
Filename=msnmsgr7.exe
Description=Added by the RBOT-PH WORM!
Source=Paul Collins Startup list
[MSN Update]
Confirmed=X
Filename=mscon.exe
Description=Added by the RBOT-QA WORM!
Source=Paul Collins Startup list
[Msn Update Manager (Sp2)]
Confirmed=X
Filename=MSMSGS.EXE
Description=Added by the AGOBOT-NL WORM!
Source=Paul Collins Startup list
[MSN Updater]
Confirmed=X
Filename=msnms.exe
Description=Added by the FORBOT-CG WORM!
Source=Paul Collins Startup list
[Msn Updater]
Confirmed=X
Filename=msnplugins.exe
Description=Added by the RBOT-HS WORM!
Source=Paul Collins Startup list
[MSN UPDATERS]
Confirmed=X
Filename=virtualmemory.exe
Description=Added by the RBOT-JK WORM!
Source=Paul Collins Startup list
[msnappau]
Confirmed=N
Filename=msnappau.exe
Description=Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar
Source=Paul Collins Startup list
[Msnarrator]
Confirmed=X
Filename=msnarrator.exe
Description=Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware
Source=Paul Collins Startup list
[MSNET]
Confirmed=X
Filename=msnet.exe
Description=Added by the BOA WORM!
Source=Paul Collins Startup list
[MsnFixer]
Confirmed=?
Filename=msnfixjs.js
Description=Located in the HPbinmsnfix directory of a HP PC
Source=Paul Collins Startup list
[MSNGrabber]
Confirmed=X
Filename=MSNgrabber.exe
Description=Added by the ENVID.A WORM!
Source=Paul Collins Startup list
[MSNIA]
Confirmed=N
Filename=MSNIASVC.EXE
Description=Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG
Source=Paul Collins Startup list
[msnload32.exe]
Confirmed=X
Filename=msnload32.exe
Description=Added by the BANCOS.M TROJAN!
Source=Paul Collins Startup list
[MSNMESENGER]
Confirmed=X
Filename=Main.exe
Description=Added by the PRORAT TROJAN!
Source=Paul Collins Startup list
[msnmsg.exe]
Confirmed=X
Filename=mscmd32.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[msnmsgr]
Confirmed=N
Filename=msnmsgr.exe
Description=MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts"
Source=Paul Collins Startup list
[MsnMsgr]
Confirmed=X
Filename=MsnMsgrs.exe
Description=Added by the NETSKY-AD WORM!
Source=Paul Collins Startup list
[msnmsgr32-.exe]
Confirmed=X
Filename=msnmsgr-.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[MSNMSGR5]
Confirmed=X
Filename=MSNMSGR5.exe
Description=Added by the RBOT.PQ WORM!
Source=Paul Collins Startup list
[MSNMSGRE]
Confirmed=X
Filename=swef.bat
Description=IRC backdoor TROJAN or WORM!
Source=Paul Collins Startup list
[MSNMSGRR]
Confirmed=X
Filename=swin.bat
Description=IRC backdoor TROJAN or WORM!
Source=Paul Collins Startup list
[MSNMSGRS1]
Confirmed=X
Filename=swed.bat
Description=IRC backdoor TROJAN or WORM!
Source=Paul Collins Startup list
[msnmsgsgs]
Confirmed=X
Filename=msnmsgsgs.exe
Description=Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
Source=Paul Collins Startup list
[MSNService]
Confirmed=X
Filename=MSNService.exe
Description=Added by the CARPET.C WORM!
Source=Paul Collins Startup list
[MSNSysRestore]
Confirmed=X
Filename=pc32.exe
Description=Added by a variant of the MASTAK VIRUS!
Source=Paul Collins Startup list
[MSObject32]
Confirmed=X
Filename=MSObject32.js
Description=Added by the PUN TROJAN!
Source=Paul Collins Startup list
[Msoffice]
Confirmed=X
Filename=msoffice.hta
Description=Hijacker - redirecting to Searchdot.net
Source=Paul Collins Startup list
[MSOffice]
Confirmed=X
Filename=services.exe
Description=Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[MSOleath32]
Confirmed=X
Filename=winss.exe
Description=Added by the KATHER TROJAN!
Source=Paul Collins Startup list
[MSOOBD]
Confirmed=X
Filename=MSOOBD.EXE
Description=Added by the MAGISTR.A VIRUS!
Source=Paul Collins Startup list
[mspaint.exe]
Confirmed=X
Filename=check32.exe
Description=Added by the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[Mspatch69]
Confirmed=X
Filename=[path to trojan]
Description=Added by the MPROX TROJAN!
Source=Paul Collins Startup list
[Mspatch89]
Confirmed=X
Filename=cnqmax.exe
Description=Added by the RANDEX.P WORM!
Source=Paul Collins Startup list
[MSPQFile]
Confirmed=X
Filename=MSA****.TMP
Description=Homepage hijacker. See here for more information. **** can be anything
Source=Paul Collins Startup list
[MSprotect.exe]
Confirmed=X
Filename=MSprotect.exe
Description=Added by the DABYREV.A VIRUS!
Source=Paul Collins Startup list
[mspwr]
Confirmed=U
Filename=pupstman.exe
Description="Transparent icon background" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)
Source=Paul Collins Startup list
[MSPY2002]
Confirmed=N
Filename=ImScInst.exe
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[MSR]
Confirmed=X
Filename=msr.exe
Description=Added by the AGOBOT.RT WORM!
Source=Paul Collins Startup list
[Msrc]
Confirmed=X
Filename=Msrc.exe
Description=Added by the KRYPTONIC GHOST TROJAN!
Source=Paul Collins Startup list
[msreg.exe]
Confirmed=X
Filename=msrege.exe
Description=Added by the ZINX TROJAN!
Source=Paul Collins Startup list
[msReg32 Loader]
Confirmed=X
Filename=msreg32.exe
Description=Added by the AGOBOT.IU WORM!
Source=Paul Collins Startup list
[MSREGIT]
Confirmed=X
Filename=Msgp.exe
Description=Added by the KRYPGHOS.13 TROJAN!
Source=Paul Collins Startup list
[MSRegSvc]
Confirmed=X
Filename=regsvc32.exe
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[msrunocx32]
Confirmed=X
Filename=msrunocx32.exe
Description=Added by the SKUS WORM!
Source=Paul Collins Startup list
[msservice]
Confirmed=X
Filename=msserv.exe
Description=Added by the HYD WORM!
Source=Paul Collins Startup list
[MSSGisg]
Confirmed=X
Filename=[path to file]
Description=Added by the RANKY.N TROJAN!
Source=Paul Collins Startup list
[MSSHVC]
Confirmed=X
Filename=MSSHVC.exe
Description=Added by the NUFFY.A WORM!
Source=Paul Collins Startup list
[mssoul]
Confirmed=X
Filename=msmscc2.exe
Description=Added by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!)
Source=Paul Collins Startup list
[MSSQL]
Confirmed=X
Filename=Mssql.exe
Description=Added by the SDBOT TROJAN!
Source=Paul Collins Startup list
[Msstart]
Confirmed=X
Filename=msstart.exe
Description=Added by the LIVUP.C TROJAN!
Source=Paul Collins Startup list
[MSStartOptimizer]
Confirmed=X
Filename=Iexpres.exe
Description=Added by the POLDO.B TROJAN!
Source=Paul Collins Startup list
[MSStartOptimizer]
Confirmed=X
Filename=WINUPD.EXE
Description=Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
Source=Paul Collins Startup list
[msstask]
Confirmed=X
Filename=msstask.exe
Description=Added by the MYPARTY WORM!
Source=Paul Collins Startup list
[mssurfer lptt01]
Confirmed=X
Filename=mssurfer.exe
Description=Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[mssurfer ml097e]
Confirmed=X
Filename=mssurfer.exe
Description=Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[mssvc]
Confirmed=X
Filename=[path to trojan]
Description=Added by the PSK TROJAN!
Source=Paul Collins Startup list
[MSSVC]
Confirmed=X
Filename=svcsys.exe
Description=Added by the FATOOS-C TROJAN!
Source=Paul Collins Startup list
[MSSVC.EXE]
Confirmed=Y
Filename=MSSVC.EXE
Description=Stealthdisk - hides folders, files and applications. Will also encrypt them for better protection
Source=Paul Collins Startup list
[mssvc32]
Confirmed=X
Filename=mssvc32.exe
Description=Added by the AGOBOT-ME WORM!
Source=Paul Collins Startup list
[mssys]
Confirmed=X
Filename=mssys.exe
Description=Added by the MYSS.B TROJAN!
Source=Paul Collins Startup list
[mssysint]
Confirmed=X
Filename=Iexplore .exe
Description=Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[mssyslanhelper]
Confirmed=X
Filename=msmsgri32.exe
Description=Added by the RANDEX.D WORM!
Source=Paul Collins Startup list
[MsSystem]
Confirmed=X
Filename=msdos.exe
Description=Adult content downloader - see here
Source=Paul Collins Startup list
[MsSystem]
Confirmed=X
Filename=mssys.exe
Description=Added by the VANTA.A TROJAN!
Source=Paul Collins Startup list
[MSSYSTEM]
Confirmed=X
Filename=svcsys.exe
Description=Added by the FATOOS-C TROJAN!
Source=Paul Collins Startup list
[Mstapi]
Confirmed=X
Filename=Mstapi.exe
Description=Keylogger trojan
Source=Paul Collins Startup list
[Mstask]
Confirmed=X
Filename=mstask.exe
Description=Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in C:\Windows or C:\WINNT
Source=Paul Collins Startup list
[mstask]
Confirmed=X
Filename=mstask.exe
Description=Browser hijacker - redirecting to find-more.net. Note - this is not the legitimate mstask.exe system file
Source=Paul Collins Startup list
[mstasks]
Confirmed=X
Filename=mstasks.exe
Description=Added by the MULTIDR-AY TROJAN!
Source=Paul Collins Startup list
[Mstcgww]
Confirmed=?
Filename=MSTCGWW.EXE
Description=??
Source=Paul Collins Startup list
[MSTMON_Q]
Confirmed=N
Filename=MSTMON_Q.exe
Description=Generates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready
Source=Paul Collins Startup list
[Mstng32]
Confirmed=X
Filename=MSTng32.exe
Description=Added by the TANG WORM!
Source=Paul Collins Startup list
[MSUpdate]
Confirmed=X
Filename=wupd.exe
Description=Added by the ALADINZ.M TROJAN!
Source=Paul Collins Startup list
[MSUpdate]
Confirmed=X
Filename=svchosthlp.exe
Description=Added by the BLASTER.T WORM!
Source=Paul Collins Startup list
[msupdate]
Confirmed=X
Filename=msupdate.exe
Description=Added by the RBOT-MZ WORM!
Source=Paul Collins Startup list
[MSUpdate]
Confirmed=X
Filename=criticalUpdate.exe
Description=Affilred adware
Source=Paul Collins Startup list
[MSupdate.exe]
Confirmed=X
Filename=N/A
Description=CoolWebSearch parasite related - resets home page to an adult content site
Source=Paul Collins Startup list
[MSupdater.exe]
Confirmed=X
Filename=N/A
Description=CoolWebSearch parasite related. Installs the Winshow.dll browser plugin
Source=Paul Collins Startup list
[msupdates]
Confirmed=X
Filename=msupdt.exe
Description=Added by the RBOT-JO WORM!
Source=Paul Collins Startup list
[MSUpdSrv]
Confirmed=X
Filename=msupdsrv.exe
Description=Browser hijacker, redirecting to a porn site
Source=Paul Collins Startup list
[msurl]
Confirmed=X
Filename=msurl32.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[msuser32.exe]
Confirmed=X
Filename=msuser32.exe
Description=Added by the ANDROV TROJAN!
Source=Paul Collins Startup list
[msvc32]
Confirmed=X
Filename=msvc32.exe
Description=ClientMan parasite variant
Source=Paul Collins Startup list
[msvcc]
Confirmed=X
Filename=msvchost.exe
Description=Added by the XOMBE TROJAN!
Source=Paul Collins Startup list
[MSVersion]
Confirmed=X
Filename=INTERNETFEATURES.exe
Description=Added by the POPMON.A TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[MSVersion]
Confirmed=X
Filename=clrschp038.exe
Description=Added by the POPMON.A TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[msvsc32]
Confirmed=X
Filename=msdev.exe
Description=Added by the RBOT-GJ WORM!
Source=Paul Collins Startup list
[MSVSync]
Confirmed=X
Filename=videosync.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[MSVXD]
Confirmed=X
Filename=MSVXD.EXE
Description=Added by the DATOM.A WORM!
Source=Paul Collins Startup list
[mswave]
Confirmed=X
Filename=mswave.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[Mswavedll]
Confirmed=X
Filename=mswavedll.exe
Description=Added by the CRYPTER-C TROJAN!
Source=Paul Collins Startup list
[MSwheel]
Confirmed=U
Filename=mswheel.exe
Description=Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Mswincfg]
Confirmed=X
Filename=Mswincfg32.exe
Description=Added by the CYBRSPY.D TROJAN!
Source=Paul Collins Startup list
[MsWindows SysDate]
Confirmed=X
Filename=sysmsvc.exe
Description=Added by the SPYBOT.FCD WORM!
Source=Paul Collins Startup list
[Mswinpid32]
Confirmed=X
Filename=mswinpid32.exe
Description=Added by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
Source=Paul Collins Startup list
[MSWinSrv]
Confirmed=X
Filename=MSWinSrv.exe
Description=Added by the MTRON TROJAN!
Source=Paul Collins Startup list
[MSWinSrv32]
Confirmed=X
Filename=MSWinSrv32.exe
Description=Added by the MTRON-B TROJAN!
Source=Paul Collins Startup list
[mswspl]
Confirmed=X
Filename=[random filename]
Description=Added by the SMALL.IQ TROJAN!
Source=Paul Collins Startup list
[mswspl]
Confirmed=X
Filename=searchbarcash.exe
Description=SearchBarCash adware
Source=Paul Collins Startup list
[msys lptt01]
Confirmed=X
Filename=msys.exe
Description=New variant of the RapidBlaster parasite (in a "Msyss" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Msys32]
Confirmed=X
Filename=morfitwebentrance.exe
Description=Morfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage
Source=Paul Collins Startup list
[MS_NETD_WIN32]
Confirmed=X
Filename=netd32.EXE
Description=Added by the RANDEX.F WORM!
Source=Paul Collins Startup list
[MS_SETUP.EXE]
Confirmed=X
Filename=MS_SETUP.EXE
Description=Added by the CHARGE TROJAN!
Source=Paul Collins Startup list
[Mtr2]
Confirmed=X
Filename=mtr2.exe
Description=Added by the KRYPTONIC GHOST TROJAN!
Source=Paul Collins Startup list
[MUAL]
Confirmed=U
Filename=mual.exe
Description=Millesky video mail updater and launcher
Source=Paul Collins Startup list
[muamgr]
Confirmed=U
Filename=muamgr.exe
Description=Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs
Source=Paul Collins Startup list
[Mufix]
Confirmed=?
Filename=mufix.exe
Description=Part of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - what does it do and is it required
Source=Paul Collins Startup list
[Multi-function keyboard]
Confirmed=U
Filename=GWHotkey.exe
Description=Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)
Source=Paul Collins Startup list
[MultiCAM Initializer]
Confirmed=U
Filename=MCamBoot.exe
Description=The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled
Source=Paul Collins Startup list
[Multimedia Codecs]
Confirmed=X
Filename=mcc.exe
Description=Added by the MCC TROJAN!
Source=Paul Collins Startup list
[Multimedia extensions]
Confirmed=X
Filename=mservice.exe
Description=EasySearch adware
Source=Paul Collins Startup list
[Multimedia KBD]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[MULTIMEDIA KEYBOARD]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[MultiRes]
Confirmed=U
Filename=MultiRes.exe
Description=MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP
Source=Paul Collins Startup list
[MUPS]
Confirmed=U
Filename=MUPS.exe
Description=Lauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions
Source=Paul Collins Startup list
[murphy shield]
Confirmed=Y
Filename=lmgui.exe
Description=Firewall part of BitDefender virus scanner/firewall
Source=Paul Collins Startup list
[Music01 Server]
Confirmed=N
Filename=Music01 Server.exe
Description=J River Media Jukebox
Source=Paul Collins Startup list
[MusIRC (irc.music.com) client]
Confirmed=X
Filename=musirc4.71.exe
Description=Added by the RANDEX.Q WORM!
Source=Paul Collins Startup list
[MutexServiceEx]
Confirmed=N
Filename=Sys32Smm.exe
Description=Webroot Sofware's discontinued "Privacy Master"
Source=Paul Collins Startup list
[mwavscan]
Confirmed=U
Filename=mwavscan.com
Description=MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive
Source=Paul Collins Startup list
[MWProEng]
Confirmed=N
Filename=MWProEng.exe
Description=Logitech Mouseware Pro software - only required when using special functions
Source=Paul Collins Startup list
[MWSnap]
Confirmed=N
Filename=MWSnap.exe
Description=MWSnap - screen capture utility. Start manually when required
Source=Paul Collins Startup list
[mwsoemon]
Confirmed=X
Filename=mwsoemon.exe
Description="My Web Search" malware
Source=Paul Collins Startup list
[Mwsvm]
Confirmed=X
Filename=mwsvm.exe
Description=SeekSeek search hijacker related - as seen here
Source=Paul Collins Startup list
[MxHLp32]
Confirmed=X
Filename=MxHLp32.exe
Description=Added by a variant of the VAGRNOCKER TROJAN!
Source=Paul Collins Startup list
[MXO Auto Loader]
Confirmed=U
Filename=MXOaldr.exe
Description=Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
Source=Paul Collins Startup list
[MxRunner]
Confirmed=U
Filename=MxRunner.exe
Description=EasyUninstall from Aladdin Systems (formerly by Ontrack)
Source=Paul Collins Startup list
[My Agent]
Confirmed=X
Filename=msagent.exe
Description=Added by the NEGASMS.A TROJAN!
Source=Paul Collins Startup list
[My App]
Confirmed=X
Filename=SMSSvc.exe
Description=Added by the NEGASMS.A TROJAN!
Source=Paul Collins Startup list
[My Search Bar Eq]
Confirmed=X
Filename=S4BAREQ.EXE
Description=MySearch bar parasite
Source=Paul Collins Startup list
[MyAgtTry]
Confirmed=U
Filename=MyAgtTry.exe
Description=System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications
Source=Paul Collins Startup list
[Myapp]
Confirmed=X
Filename=[filename]
Description=Added by the FATEE.B WORM!
Source=Paul Collins Startup list
[Myapp]
Confirmed=X
Filename=service.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[MyAV]
Confirmed=X
Filename=avpguard.exe
Description=Added by the NETSKY.J WORM!
Source=Paul Collins Startup list
[MyCIO Agent Service]
Confirmed=Y
Filename=myagtsvc.exe
Description=McAfee VirusScan ASaP Agent service
Source=Paul Collins Startup list
[myCIO.com ASaP]
Confirmed=U
Filename=MyAgtTry.exe
Description=System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications
Source=Paul Collins Startup list
[myCIO.com Splash]
Confirmed=N
Filename=Splash.exe
Description=Splash screen for McAfee VirusScan ASaP on-line scanner
Source=Paul Collins Startup list
[MyCometCursor]
Confirmed=X
Filename=MYCOME~1.EXE
Description=Comet Cursor adware
Source=Paul Collins Startup list
[MyDailyHoroscope]
Confirmed=X
Filename=MYDAIL~1.EXE
Description=MyDailyHoroscope foistware
Source=Paul Collins Startup list
[MyDailyHoroscope]
Confirmed=X
Filename=MyDailyHoroscope.exe
Description=MyDailyHoroscope foistware
Source=Paul Collins Startup list
[MyFastAccess]
Confirmed=N
Filename=myfastupdate.exe
Description=My-Fast-Access toolbar updater
Source=Paul Collins Startup list
[MyLife]
Confirmed=X
Filename=CmdServ.exe
Description=Added by the HOLAR.A WORM!
Source=Paul Collins Startup list
[myNetWatchman]
Confirmed=U
Filename=nwclient.exe
Description=Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running
Source=Paul Collins Startup list
[MyPointsPointAlert]
Confirmed=X
Filename=wjview ...MyPointsPointAlertrun.exe
Description="With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy
Source=Paul Collins Startup list
[myprint mileage]
Confirmed=U
Filename=mpm.exe
Description=Reports battery status on a portable printer
Source=Paul Collins Startup list
[mysoft]
Confirmed=X
Filename=winexplor.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[MySoftware NewsFlash]
Confirmed=?
Filename=Newsflsh.exe
Description=??
Source=Paul Collins Startup list
[MytekSystrayExePath]
Confirmed=U
Filename=MyTekSystray.exe
Description=MyTek system tray - web site providing computer tech support in Australia
Source=Paul Collins Startup list
[MyTotalSearch Email Plugin]
Confirmed=X
Filename=mtsoemon.exe
Description=MyTotalSearchBar adware
Source=Paul Collins Startup list
[MyVirt.exe]
Confirmed=X
Filename=MyVirt.exe
Description=Added by the REMADM-C TROJAN!
Source=Paul Collins Startup list
[MyVitalAgent]
Confirmed=U
Filename=VtlAgent.exe
Description=MyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs
Source=Paul Collins Startup list
[MyWebSearch Email Plugin]
Confirmed=X
Filename=mwsoemon.exe
Description="My Web Search" malware
Source=Paul Collins Startup list
[N2PTray]
Confirmed=U
Filename=Net2fone.exe
Description=An Internet telephony application. Needed only if you have an account at Net2Phone, Inc
Source=Paul Collins Startup list
[NADaemon]
Confirmed=N
Filename=NADAEMON.EXE
Description=Program by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required
Source=Paul Collins Startup list
[Naggerrunkey]
Confirmed=N
Filename=nagger.exe
Description=Packard Bell Free Internet Signup screen
Source=Paul Collins Startup list
[Naimagent_service]
Confirmed=Y
Filename=EPOAgentnaimas32.exe
Description=Networked version of McAfee VirusScan. Installs, configures and updates the software and DAT (virus definition) files on local computers from a network server. A resource hog but required for DAT updates and if disabled can also cause random freezes and error messages
Source=Paul Collins Startup list
[Naimagent_UI]
Confirmed=Y
Filename=EPOAgentnaimag32.exe
Description=Workstation background program for Network Associates’ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
Source=Paul Collins Startup list
[Naimagent_UI]
Confirmed=Y
Filename=naimag32.exe
Description=Workstation background program for Network Associates’ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
Source=Paul Collins Startup list
[Name]
Confirmed=X
Filename=Iexplorer0.exe
Description=Added by the THREADSYS TROJAN!
Source=Paul Collins Startup list
[Narrator]
Confirmed=X
Filename=******.exe [* = random char]
Description=Transponder/VX2 related adware
Source=Paul Collins Startup list
[Natal]
Confirmed=X
Filename=Natal.scr
Description=Added by the OPASERV.AE WORM!
Source=Paul Collins Startup list
[NAV]
Confirmed=X
Filename=RuxDLL32.exe
Description=Added by the MAPSON.D WORM!
Source=Paul Collins Startup list
[NAV Agent]
Confirmed=Y
Filename=navapw32.exe
Description=Norton Anti-Virus's background scanning process
Source=Paul Collins Startup list
[nAv AGENT]
Confirmed=X
Filename=N/A
Description=Added by the RIOSYS MACRO! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes
Source=Paul Collins Startup list
[NAV Agent]
Confirmed=X
Filename=systems.exe
Description=Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name
Source=Paul Collins Startup list
[NAV Agent]
Confirmed=X
Filename=winsnav.vbs
Description=Added by the ANPES WORM!
Source=Paul Collins Startup list
[NAV Auto Update]
Confirmed=X
Filename=Navautoupdate.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[NAV CfgWiz]
Confirmed=N
Filename=cfgwiz.exe
Description=Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
Source=Paul Collins Startup list
[NAV Configuration Wizard]
Confirmed=N
Filename=cfgwiz.exe
Description=Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
Source=Paul Collins Startup list
[NAV DefAlert]
Confirmed=U
Filename=DefAlert.exe
Description=Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
Source=Paul Collins Startup list
[NAV Live Update]
Confirmed=X
Filename=[path to worm]
Description=Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec
Source=Paul Collins Startup list
[NAV Scan Service]
Confirmed=X
Filename=NAVSCAN32.EXE
Description=Added by the SDBOT.VG WORM!
Source=Paul Collins Startup list
[NavAgent32]
Confirmed=X
Filename=lasvr32.exe
Description=Added by the FEMOT.D WORM!
Source=Paul Collins Startup list
[NavAgent32]
Confirmed=X
Filename=SCardSvr32.Exe
Description=Added by the MOFEI.B WORM!
Source=Paul Collins Startup list
[navapp]
Confirmed=X
Filename=navapp.exe
Description=NavExcel adware variant
Source=Paul Collins Startup list
[navapw32]
Confirmed=Y
Filename=navapw32.exe
Description=Norton Anti-Virus's background scanning process
Source=Paul Collins Startup list
[Naviscope]
Confirmed=U
Filename=naviscope.exe
Description=Naviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more
Source=Paul Collins Startup list
[NaviSearch]
Confirmed=X
Filename=nls.exe
Description=NaviSearch, eXact Advertising variant
Source=Paul Collins Startup list
[navman_20]
Confirmed=X
Filename=sysnav32.exe
Description=Hijacker, possibly a CoolWebSearch variant
Source=Paul Collins Startup list
[navp.exe]
Confirmed=X
Filename=navp.exe
Description=Added by the AGOBOT-OE WORM!
Source=Paul Collins Startup list
[NavPass]
Confirmed=X
Filename=NavPass.exe
Description=Free system for gaining access to and downloading from adult content web-sites
Source=Paul Collins Startup list
[NavScan]
Confirmed=X
Filename=[filename]
Description=Added by the OBSORB TROJAN!
Source=Paul Collins Startup list
[NAVSCANNER32]
Confirmed=X
Filename=NAVSCANNER32.EXE
Description=Added by the RBOT.QC WORM!
Source=Paul Collins Startup list
[NAVUpd]
Confirmed=X
Filename=rundll32.exe navupd.dll, Startup
Description=Added by the NAVU TROJAN!
Source=Paul Collins Startup list
[NB Common Dialog Enhancements]
Confirmed=N
Filename=COMDLGEX.EXE
Description=Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs
Source=Paul Collins Startup list
[NB Start Menu]
Confirmed=N
Filename=STARTM.EXE
Description=Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B
Source=Paul Collins Startup list
[NB Windows Patterns]
Confirmed=N
Filename=WINDBKGND.EXE
Description=Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows
Source=Paul Collins Startup list
[NBJ]
Confirmed=U
Filename=NBJ.exe
Description=Ahead Nero BackItUp backup program. Only required for if you have scheduled back-ups
Source=Paul Collins Startup list
[NbkCtrl]
Confirmed=U
Filename=NbkCtrl.exe
Description=Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
Source=Paul Collins Startup list
[NBT System alias]
Confirmed=X
Filename=[path] repcale.exe [path] beird.exe
Description=Added by a variant of the RANDON.AN WORM!
Source=Paul Collins Startup list
[NCClient]
Confirmed=?
Filename=N/A
Description=??
Source=Paul Collins Startup list
[NCD]
Confirmed=N
Filename=ncd.exe
Description=Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path
Source=Paul Collins Startup list
[NCLAUNCH]
Confirmed=?
Filename=NCLAUNCH.Exe
Description=Part of SWF Studio from Northcode Inc - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XP. Is it required?
Source=Paul Collins Startup list
[NCS_SS]
Confirmed=N
Filename=Csinsm32.exe
Description=Same as CleanSweep Smart Sweep-Internet Sweep
Source=Paul Collins Startup list
[NDDEAGNT]
Confirmed=?
Filename=NDDEAGNT.EXE
Description=WinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE services
Source=Paul Collins Startup list
[NDIS Adapter]
Confirmed=X
Filename=ndis.exe
Description=Added by the SDBOT.VF WORM!
Source=Paul Collins Startup list
[NDIS Adapter]
Confirmed=X
Filename=windows.exe
Description=Added by the FORBOT-BR WORM!
Source=Paul Collins Startup list
[NDIS Adapter]
Confirmed=X
Filename=lsass2.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[NDplDeamon]
Confirmed=X
Filename=nstask32.exe
Description=Added by the RANDEX.E WORM!
Source=Paul Collins Startup list
[NDplDeamon]
Confirmed=X
Filename=winlogin.exe
Description=Added by the RANDEX.E WORM!
Source=Paul Collins Startup list
[NDPS]
Confirmed=U
Filename=DPMW32.EXE
Description=Novell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this feature
Source=Paul Collins Startup list
[NDrv]
Confirmed=X
Filename=NDrv.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[NDSTray]
Confirmed=U
Filename=NDSTray.exe
Description=ConfigFreeT Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have
Source=Paul Collins Startup list
[Necbar]
Confirmed=N
Filename=Necbar.exe
Description=Nec Assistant; Ark's Navigator, a graphical interface for NEC computers
Source=Paul Collins Startup list
[NECMFK]
Confirmed=Y
Filename=necmfk.exe
Description=NEC wireless keyboard driver
Source=Paul Collins Startup list
[Necutray]
Confirmed=U
Filename=Necutray.exe
Description=Driver for external USB storage devices (hard drives, flsh disks, etc)
Source=Paul Collins Startup list
[neqprvfy.exe]
Confirmed=?
Filename=neqprvfy.exe
Description=Appears to be related to the downloading of some application - possibly verifying updates?
Source=Paul Collins Startup list
[Nero.ma]
Confirmed=X
Filename=***.exe [*** = 2 to 3 digits]
Description=Added by the JONBARR.D WORM!
Source=Paul Collins Startup list
[NeroAutoStartClient]
Confirmed=X
Filename=NeroASM.exe
Description=Added by the AGOBOT.VG WORM!
Source=Paul Collins Startup list
[NeroCheck]
Confirmed=U
Filename=nerocheck.exe
Description=Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
Source=Paul Collins Startup list
[NeroCheck]
Confirmed=X
Filename=regedit.exe
Description=Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)
Source=Paul Collins Startup list
[NeroFilterCheck]
Confirmed=U
Filename=NeroCheck.exe
Description=Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
Source=Paul Collins Startup list
[NeroNETTrayIcon]
Confirmed=N
Filename=NNServiceCtrl.exe
Description=System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network
Source=Paul Collins Startup list
[Net]
Confirmed=X
Filename=WINREG.EXE
Description=Added by the ASSASIN.D TROJAN!
Source=Paul Collins Startup list
[Net Accelerator]
Confirmed=U
Filename=NetAccelerator.exe
Description=Rizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance
Source=Paul Collins Startup list
[Net Activity Diagram]
Confirmed=U
Filename=nad.exe
Description=Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs
Source=Paul Collins Startup list
[Net-It Launcher]
Confirmed=N
Filename=NILaunch.exe
Description=Net-It - web publishing software
Source=Paul Collins Startup list
[NetAccelerator]
Confirmed=U
Filename=NetAccel.exe
Description=NetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance
Source=Paul Collins Startup list
[NetAdm7]
Confirmed=X
Filename=NETADM7.EXE
Description=Added by the BANCOS.F TROJAN!
Source=Paul Collins Startup list
[Netapi]
Confirmed=X
Filename=Netapi.exe
Description=Added by the NETDEVIL.14 TROJAN!
Source=Paul Collins Startup list
[NetApp]
Confirmed=X
Filename=winserv.exe
Description=Added by the SHADOWTHIEF TROJAN!
Source=Paul Collins Startup list
[netconfig]
Confirmed=X
Filename=netconfig.exe
Description=Added by the NETCONF TROJAN!
Source=Paul Collins Startup list
[NetCruiser Dialer]
Confirmed=U
Filename=NCDialer.exe
Description=NetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"
Source=Paul Collins Startup list
[netdaemon]
Confirmed=X
Filename=netdaemon /v
Description=Malware designed to "kill" a number of antispyware applications (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)
Source=Paul Collins Startup list
[netdll32]
Confirmed=X
Filename=netdll32.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[netdllex]
Confirmed=X
Filename=netdllex.Exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[NetDy]
Confirmed=X
Filename=VisualGuard.exe
Description=Added by the NETSKY.N or NETSKY.W WORMS!
Source=Paul Collins Startup list
[NETFP32.EXE]
Confirmed=X
Filename=NETFP32.EXE
Description=Added by the AGENT.CD TROJAN!
Source=Paul Collins Startup list
[netfxupdate]
Confirmed=?
Filename=netfxupdate.exe
Description=Would appear to be a valid Microsoft .NET file (see here) but this suggest's it's a trojan?
Source=Paul Collins Startup list
[NetFxUpdate_v1.0.3705]
Confirmed=?
Filename=netfxupdate.exe
Description=Would appear to be a valid Microsoft .NET file (see here) but this suggest's it's a trojan?
Source=Paul Collins Startup list
[NetGuard]
Confirmed=U
Filename=NetGuard.exe
Description=FBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor
Source=Paul Collins Startup list
[Netlimiter]
Confirmed=U
Filename=Netlimiter.exe
Description=Netlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."
Source=Paul Collins Startup list
[Netline User]
Confirmed=N
Filename=netchk.exe
Description=Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example
Source=Paul Collins Startup list
[NetLink]
Confirmed=X
Filename=netlink32.exe
Description=Added by the GAOBOT.WO WORM!
Source=Paul Collins Startup list
[NetLogon]
Confirmed=X
Filename=userint.exe
Description=Added by the SDBOT-BC WORM!
Source=Paul Collins Startup list
[NetManagerService]
Confirmed=X
Filename=ntss.exe
Description=Added by the BESTPICS.A TROJAN!
Source=Paul Collins Startup list
[NetMeter]
Confirmed=X
Filename=NetMeter.exe
Description=NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
Source=Paul Collins Startup list
[NetMon]
Confirmed=X
Filename=netmon.exe
Description=Added by the MIMAIL.M WORM!
Source=Paul Collins Startup list
[netmsg]
Confirmed=U
Filename=netmsg.exe
Description=Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well
Source=Paul Collins Startup list
[NetPatrol]
Confirmed=U
Filename=winclient.exe
Description=NetPatrol network monitoring software
Source=Paul Collins Startup list
[netpc32.exe]
Confirmed=X
Filename=netpc32.exe
Description=Malware, probably CoolWebSearch parasite related
Source=Paul Collins Startup list
[NetPerSec]
Confirmed=N
Filename=NetPerSec.exe
Description=NetPerSec - measures the real-time speed of your Internet connection
Source=Paul Collins Startup list
[NetPumper]
Confirmed=N
Filename=NetPumperIEProxy.exe
Description=NetPumper download manager - bundles Cydoor and SaveNow adware, see here
Source=Paul Collins Startup list
[NetReach]
Confirmed=X
Filename=nrcheck.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Netropa Internet Receiver]
Confirmed=X
Filename=Netropa.exe
Description=Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
Source=Paul Collins Startup list
[NetRun]
Confirmed=U
Filename=NetRun.exe
Description=NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost
Source=Paul Collins Startup list
[Netscape Messenger]
Confirmed=N
Filename=NETSCAPE.EXE
Description=In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed
Source=Paul Collins Startup list
[Netscp6]
Confirmed=N
Filename=Netscp6.exe
Description=Netscape 6
Source=Paul Collins Startup list
[netservices]
Confirmed=X
Filename=recall.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[NetShow Powerpoint Helper]
Confirmed=U
Filename=NSPPTHLP.EXE
Description=If disabled, user created fonts can no longer be seen by other programs
Source=Paul Collins Startup list
[NetStat Live]
Confirmed=N
Filename=Nsl.exe
Description=AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data
Source=Paul Collins Startup list
[netsv32]
Confirmed=X
Filename=netsv32.exe
Description=Added by the SDBOT-PX WORM!
Source=Paul Collins Startup list
[NetTime]
Confirmed=U
Filename=NETTIME.EXE
Description=From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."
Source=Paul Collins Startup list
[NetTurbo]
Confirmed=U
Filename=netturbo.exe
Description=NetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled
Source=Paul Collins Startup list
[Netunit32]
Confirmed=X
Filename=wunit32.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[NetWatch32]
Confirmed=X
Filename=netwatch.exe
Description=Added by the MIMAIL.C WORM!
Source=Paul Collins Startup list
[Netword Agent]
Confirmed=N
Filename=nwant33.exe
Description=An interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs
Source=Paul Collins Startup list
[NetWork]
Confirmed=X
Filename=csrs.exe
Description=Added by the AGOBOT.JJ WORM!
Source=Paul Collins Startup list
[Network Administration]
Confirmed=X
Filename=NAS.exe
Description=Added by the ANTILAM.20.Q TROJAN!
Source=Paul Collins Startup list
[Network Administration Service]
Confirmed=X
Filename=rsvc32.exe
Description=Added by the RBOT.ABH WORM!
Source=Paul Collins Startup list
[Network Associates Error Reporting Service]
Confirmed=U
Filename=TBMon.exe
Description=Network Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
Source=Paul Collins Startup list
[NetWork Device Switch]
Confirmed=U
Filename=NetDevSW.exe
Description=Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
Source=Paul Collins Startup list
[Network Host Controller]
Confirmed=X
Filename=[path to trojan]
Description=Added by the WHISPER TROJAN!
Source=Paul Collins Startup list
[Network Protocol Service]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the RBOT.EA WORM!
Source=Paul Collins Startup list
[Network protocol service]
Confirmed=X
Filename=wintcp.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Network Security Guard]
Confirmed=X
Filename=**********.exe [* = random char]
Description=CoolWebSearch parasite related
Source=Paul Collins Startup list
[Network Service]
Confirmed=X
Filename=svchost.exe
Description=CoolWebSearch parasite related. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Network Service Manager]
Confirmed=X
Filename=netsvc.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Network Service Manager]
Confirmed=X
Filename=netsvc.exe
Description=Added by a variant of the GAOBOT/AGOBOT WORM!
Source=Paul Collins Startup list
[NetworkAssociates Inc]
Confirmed=X
Filename=internet.exe
Description=Added by the LOVGATE WORM!
Source=Paul Collins Startup list
[NetworkClient]
Confirmed=X
Filename=NetworkClient.exe
Description=Added by the LEMUR WORM!
Source=Paul Collins Startup list
[Networks Configurator]
Confirmed=X
Filename=NetConfs.exe
Description=Added by the RBOT-OX WORM!
Source=Paul Collins Startup list
[Networks Controler]
Confirmed=X
Filename=Netsis.exe
Description=Added by the RBOT-NG WORM!
Source=Paul Collins Startup list
[NetworkSetup]
Confirmed=N
Filename=dlink.exe
Description=D-Link System Tray icon
Source=Paul Collins Startup list
[Netzip Smart Downloader]
Confirmed=X
Filename=npnzdad.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[NetZIPFolders]
Confirmed=N
Filename=nzfprop.exe
Description=Netzip Classic zip file manager
Source=Paul Collins Startup list
[NeuroMedia(IESpeaker)]
Confirmed=X
Filename=NeuroMedia.exe
Description=Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available
Source=Paul Collins Startup list
[NeuroSpeech OESpeaker]
Confirmed=N
Filename=OEMonitor.exe
Description=Part of OESpeaker - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not
Source=Paul Collins Startup list
[New.net]
Confirmed=X
Filename=rundll32.exe NewDotNetStartup Newdot~2.exe
Description=NewDotNet foistware
Source=Paul Collins Startup list
[New.net Startup]
Confirmed=X
Filename=rundll32 [path], NewDotNetStartup -s
Description=NewDotNet foistware
Source=Paul Collins Startup list
[NEWDOT~1]
Confirmed=X
Filename=rundll32.exe NewDotNetStartup Newdot~2.exe
Description=NewDotNet foistware
Source=Paul Collins Startup list
[News Service]
Confirmed=?
Filename=ispnews.exe
Description=F-Secure antivirus related. However, is this particular item required?
Source=Paul Collins Startup list
[Newsalrt]
Confirmed=N
Filename=NEWSALRT.EXE
Description=MSNBC News system tray utility to alert you to new news
Source=Paul Collins Startup list
[Newsgroup lptt01]
Confirmed=X
Filename=newsgroup.exe
Description=Variant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Newsgroup ml097e]
Confirmed=X
Filename=newsgroup.exe
Description=Variant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[NewsUpd]
Confirmed=N
Filename=newsupd.exe
Description=For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here.
Source=Paul Collins Startup list
[NewtonKnowsUpd]
Confirmed=X
Filename=NewtKnow.exe ...NewtnUpd.dll, runkey
Description=NewtonKnow hijacker
Source=Paul Collins Startup list
[NFM Service]
Confirmed=U
Filename=NPDOR9x.exe
Description=Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
Source=Paul Collins Startup list
[nForce Tray Options]
Confirmed=N
Filename=sstray.exe
Description=nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
Source=Paul Collins Startup list
[NGClient]
Confirmed=U
Filename=ngctw32.exe
Description=Symantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manually
Source=Paul Collins Startup list
[NGServer]
Confirmed=N
Filename=ngserver.exe
Description=Symantec/Norton Ghost Console service
Source=Paul Collins Startup list
[NiceDownloads]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=MatrixDialer related
Source=Paul Collins Startup list
[Nielsen NetRatings]
Confirmed=N
Filename=insight.exe
Description=Nielsen NetRatings - "Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site’s audience and your customers". Is it required?
Source=Paul Collins Startup list
[nikLaus]
Confirmed=X
Filename=nikLaus.exe
Description=Added by the NIKLAS WORM!
Source=Paul Collins Startup list
[NInit]
Confirmed=N
Filename=NInit.exe
Description=Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
Source=Paul Collins Startup list
[nisserv]
Confirmed=Y
Filename=NISSERV.EXE
Description=Norton Personal Firewall
Source=Paul Collins Startup list
[Nisum]
Confirmed=Y
Filename=NISUM.EXE
Description=Norton Personal Firewall
Source=Paul Collins Startup list
[NJG40]
Confirmed=X
Filename=NJG40.EXE
Description=Added by the BANCOS.D TROJAN!
Source=Paul Collins Startup list
[NkvMon.exe]
Confirmed=N
Filename=NkvMon.exe
Description=Nikon View 5 - for transferring pictures from Nikon digital cameras
Source=Paul Collins Startup list
[NkVwMon.exe]
Confirmed=N
Filename=NkVwMon.exe
Description=Nikon View - for transferring pictures from Nikon digital cameras
Source=Paul Collins Startup list
[NLS Keyboard]
Confirmed=X
Filename=keyboard.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[NMSSvc]
Confirmed=?
Filename=NMSSVC.EXE
Description=NIC Management Service - diagnostics program for Intel Pro family network cards
Source=Paul Collins Startup list
[NMSVC]
Confirmed=Y
Filename=nmSvc.exe
Description=Covenant Eyes - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it
Source=Paul Collins Startup list
[NNSvc]
Confirmed=U
Filename=nnsvc.exe
Description=NetNanny internet filter
Source=Paul Collins Startup list
[No Credit Card]
Confirmed=X
Filename=plugin-[random].exe
Description=Adult content pop-up dialler
Source=Paul Collins Startup list
[No-IP DUC]
Confirmed=U
Filename=DUC20.exe
Description=Part of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available
Source=Paul Collins Startup list
[NoAds]
Confirmed=U
Filename=NoAds.exe
Description=Blocks advertisement banners in Internet Explorer
Source=Paul Collins Startup list
[NoAdware]
Confirmed=N
Filename=NoAdware.exe
Description=Adware/spyware remover - not particularly recommended, see here
Source=Paul Collins Startup list
[Nocana]
Confirmed=X
Filename=[path to worm]
Description=Added by the ANACON-B WORM!
Source=Paul Collins Startup list
[Nod32CC]
Confirmed=U
Filename=nod32cc.exe
Description=Control Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button
Source=Paul Collins Startup list
[NOD32kernel]
Confirmed=Y
Filename=Nod32krn.exe
Description=Nod32 Antivirus Version 2
Source=Paul Collins Startup list
[nod32kui]
Confirmed=Y
Filename=nod32kui.exe
Description=Nod32 Antivirus Version 2
Source=Paul Collins Startup list
[NOD32POP3]
Confirmed=Y
Filename=Pop3scan.exe
Description=POP3 E-mail part of Eset's NOD32 virus-scanner
Source=Paul Collins Startup list
[NodeMnger]
Confirmed=?
Filename=Nodemngr.exe
Description=Part of the Dell OpenManage Client installation - to allow Dell representatives to remote logon?
Source=Paul Collins Startup list
[nodriver]
Confirmed=X
Filename=AUEKXRZ.EXE
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Noha]
Confirmed=X
Filename=aasd.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[Nokia Connection Monitor]
Confirmed=N
Filename=NclConf.exe
Description=Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[Nokia Tray Application]
Confirmed=U
Filename=NclTray.exe
Description=Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
Source=Paul Collins Startup list
[NOMAD Detector]
Confirmed=U
Filename=ctmnrun.exe
Description=Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
Source=Paul Collins Startup list
[NomdCheck]
Confirmed=N
Filename=nomdchek.exe
Description=Part of Intel's Native Audio
Source=Paul Collins Startup list
[nomtray]
Confirmed=U
Filename=nomtray.exe
Description=System Tray access to NetMotion Wireless options - including connectivity status (see here)
Source=Paul Collins Startup list
[Norman ZANDA]
Confirmed=U
Filename=ZLH.EXE
Description=System Tray icon for Norman Antivirus
Source=Paul Collins Startup list
[Norton Antivirus AV]
Confirmed=X
Filename=FVProtect.exe
Description=Added by the NETSKY.P WORM! Note - this is not the popular AV software!
Source=Paul Collins Startup list
[Norton AntiVirus Sys]
Confirmed=X
Filename=NAVsys32.exe
Description=Added by a variant of the WOOTBOT WORM!
Source=Paul Collins Startup list
[Norton Auto Protect]
Confirmed=X
Filename=nava.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Norton Auto-Protect]
Confirmed=Y
Filename=navapw32.exe
Description=Norton Anti-Virus's background scanning process
Source=Paul Collins Startup list
[Norton AV Preload]
Confirmed=?
Filename=Premend.exe
Description=Norton Antivirus related. What does it do and is it required
Source=Paul Collins Startup list
[Norton Crashguard Monitor]
Confirmed=N
Filename=cgmenu.exe
Description=Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
Source=Paul Collins Startup list
[Norton Disk Doctor]
Confirmed=N
Filename=Ndd32.exe
Description=Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
Source=Paul Collins Startup list
[Norton eMail Protect]
Confirmed=Y
Filename=POPROXY.EXE
Description=Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it
Source=Paul Collins Startup list
[Norton Guard 32]
Confirmed=X
Filename=ntguard32.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Norton Live Update Server]
Confirmed=X
Filename=cpsdv.exe
Description=Added by the AGOBOT.EW TROJAN!
Source=Paul Collins Startup list
[Norton Live Updater]
Confirmed=X
Filename=Cavapsvc.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Norton Live Updater]
Confirmed=X
Filename=Sochost.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Norton Navigator Loader]
Confirmed=N
Filename=nnloader.exe
Description=An older Norton utility for file management under Windows 95. More information here
Source=Paul Collins Startup list
[Norton Program Scheduler]
Confirmed=U
Filename=nsched32.exe
Description=Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
Source=Paul Collins Startup list
[Norton Program Scheduler]
Confirmed=U
Filename=NPSsvc.exe
Description=Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
Source=Paul Collins Startup list
[Norton Program Scheduler Event Checker]
Confirmed=?
Filename=npscheck.exe
Description=Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker
Source=Paul Collins Startup list
[Norton Service Process]
Confirmed=X
Filename=navapvc.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Norton SpySweeper AutoUpdate]
Confirmed=X
Filename=navsw.exe
Description=Added by the FORBOT-AS WORM!
Source=Paul Collins Startup list
[Norton System Doctor]
Confirmed=N
Filename=Sysdoc32.exe
Description=Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
Source=Paul Collins Startup list
[Norton SystemWorks]
Confirmed=N
Filename=cfgwiz.exe
Description=Norton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it
Source=Paul Collins Startup list
[Norton Update]
Confirmed=X
Filename=ccUpdate.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Norton Updater]
Confirmed=X
Filename=winset.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Norton Wizzard]
Confirmed=X
Filename=nwiz.exe
Description=Added by the GAOBOT.ZX or GAOBOT.ADV WORMS! Note - this is not the valid nVidia application that shares the same name
Source=Paul Collins Startup list
[norton32]
Confirmed=X
Filename=norton32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[NortonAV]
Confirmed=X
Filename=norton_antivirus.exe
Description=Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program
Source=Paul Collins Startup list
[nortonsantivirus]
Confirmed=X
Filename=ccEvtMngr.exe
Description=Added by the HZDOOR-A TROJAN!
Source=Paul Collins Startup list
[Notebook Maximizer]
Confirmed=U
Filename=maximizer_startup.exe
Description=Toshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency
Source=Paul Collins Startup list
[NotebookManager]
Confirmed=?
Filename=nbm.exe
Description=Associated with Acer notebook PCs. What does it do and is it required?
Source=Paul Collins Startup list
[Notepad lptt01]
Confirmed=X
Filename=notepad.exe
Description=Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name
Source=Paul Collins Startup list
[Notepad ml097e]
Confirmed=X
Filename=notepad.exe
Description=Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name
Source=Paul Collins Startup list
[notepad.exe]
Confirmed=X
Filename=upx.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[Notn]
Confirmed=X
Filename=Eber.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[NovaBackup * Tray Control]
Confirmed=U
Filename=NbkCtrl.exe
Description=Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number
Source=Paul Collins Startup list
[NovaPortal Single User Service]
Confirmed=?
Filename=NPSU.exe
Description=??
Source=Paul Collins Startup list
[NovastorSchedulerd]
Confirmed=U
Filename=SCHENGD.EXE
Description=NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
Source=Paul Collins Startup list
[NPFMonitor]
Confirmed=?
Filename=NPFMntor.exe
Description=Norton AntiVirus Firewall Install Monitor. What does it do and is it required?
Source=Paul Collins Startup list
[NPROTECT]
Confirmed=U
Filename=nprotect.exe
Description=Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see here
Source=Paul Collins Startup list
[NPS Event Checker]
Confirmed=?
Filename=npscheck.exe
Description=Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker
Source=Paul Collins Startup list
[NS]
Confirmed=X
Filename=ns.exe
Description=Added by the AGOBOT-HS WORM!
Source=Paul Collins Startup list
[NSCheck]
Confirmed=X
Filename=NSCHECK.EXE
Description=NetSetter/Marketscore foistware
Source=Paul Collins Startup list
[nscntrl]
Confirmed=X
Filename=nscntrl.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[nsdlua]
Confirmed=X
Filename=nsdlua.exe
Description=All-In-One Telcom - adult content dialler
Source=Paul Collins Startup list
[nsdriver]
Confirmed=X
Filename=nssys32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[nse]
Confirmed=X
Filename=nse.exe
Description=Added by the AGOBOT-ML WORM!
Source=Paul Collins Startup list
[Nsengine]
Confirmed=U
Filename=Nsengine.exe
Description=Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
Source=Paul Collins Startup list
[NSHelper]
Confirmed=U
Filename=aexnsinstallhelper.exe
Description=Altiris Express Notification Server Install helper - monitors integrity of the installation
Source=Paul Collins Startup list
[nssysconf]
Confirmed=X
Filename=[random filename]
Description=Added by the VIVIA.A TROJAN!
Source=Paul Collins Startup list
[nstat]
Confirmed=X
Filename=netstat.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[NSupdate]
Confirmed=X
Filename=NSupdate.exe
Description=Adult content dialer
Source=Paul Collins Startup list
[Nsvdr]
Confirmed=X
Filename=nsvdr.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[NSystemMonitor]
Confirmed=N
Filename=Symmon.exe
Description=Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
Source=Paul Collins Startup list
[NT Kernel Patch]
Confirmed=N
Filename=ntkrnlpt.exe
Description=FaxServe network fax software
Source=Paul Collins Startup list
[NT Logging Service]
Confirmed=X
Filename=Syslog32.exe
Description=Added by the DONK.B or DONK.C or DONK.L or DONK.M or DONK.O WORMS!
Source=Paul Collins Startup list
[NT Services]
Confirmed=X
Filename=ntsvc.exe
Description=Added by the AGOBOT.VJ WORM!
Source=Paul Collins Startup list
[ntdll]
Confirmed=X
Filename=ntdll.exe
Description=Added by the BIONET.404 TROJAN!
Source=Paul Collins Startup list
[NTDLM]
Confirmed=X
Filename=csrss.exe
Description=Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Ntech.patchs]
Confirmed=X
Filename=[trojan filename]
Description=Added by the LEMIR.G TROJAN!
Source=Paul Collins Startup list
[NTFS16]
Confirmed=X
Filename=ntfs16.exe
Description=Added by the RBOT-LY WORM!
Source=Paul Collins Startup list
[NTFSCLUP]
Confirmed=Y
Filename=NTFSCLUP.EXE
Description=Part of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"
Source=Paul Collins Startup list
[ntldr]
Confirmed=X
Filename=ntldr.exe
Description=Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: C:\WINDOWS\SYSTEM\ntldr.exe, C:\m.exe, C:\WINDOWS\Search-For-You.url, C:\n.bat, C:\q.exe, C:\r.bat
Source=Paul Collins Startup list
[ntlfreedom]
Confirmed=N
Filename=RyDial.dll, QuickStart
Description=NTL Freedom ISP software - reportedly not required
Source=Paul Collins Startup list
[NTP Server]
Confirmed=X
Filename=[path to trojan]
Description=Added by the RANKY.F TROJAN!
Source=Paul Collins Startup list
[NTrtc]
Confirmed=N
Filename=ntrtc.exe
Description=Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here
Source=Paul Collins Startup list
[NTsocket]
Confirmed=X
Filename=NoeWinnt.exe
Description=Added by the ATAKA-E TROJAN!
Source=Paul Collins Startup list
[NTsrv.exe]
Confirmed=X
Filename=NTsrv.exe
Description=Added by a variant of the SERVU-O TROJAN!
Source=Paul Collins Startup list
[ntupdate]
Confirmed=X
Filename=dnsvc.exe
Description=Added by the SDBOT-TC WORM!
Source=Paul Collins Startup list
[NTVDM]
Confirmed=U
Filename=NTVDM.EXE
Description=Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM here
Source=Paul Collins Startup list
[ntvdscm]
Confirmed=X
Filename=ntvdscm.exe
Description=Added by the SCKEYLOG.O TROJAN!
Source=Paul Collins Startup list
[NuTCSetupEnviron]
Confirmed=Y
Filename=ncoeenv.exe
Description=Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone
Source=Paul Collins Startup list
[NvClipRsv]
Confirmed=X
Filename=svchost.exe
Description=Added by the DUMARU-AK WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[NvClipRsv]
Confirmed=X
Filename=swchost.exe
Description=Added by the DUMARU-AK WORM!
Source=Paul Collins Startup list
[NVCLOCK]
Confirmed=?
Filename=rundll32 nvclock.dll, fnNvclock
Description=Overclocking utility for nVidia based graphics cards?
Source=Paul Collins Startup list
[NvColorInit]
Confirmed=?
Filename=rundll32.exe NvQtwk.dll, NvColorInit
Description=Associated with Nvidia based graphics cards
Source=Paul Collins Startup list
[NvCpl]
Confirmed=U
Filename=rundll32.exe NvCpl.dll, NvStartup
Description=Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
Source=Paul Collins Startup list
[NvCpl]
Confirmed=X
Filename=NvCpl.EXE
Description=Added by the YANZ.B WORM!
Source=Paul Collins Startup list
[NvCpl]
Confirmed=U
Filename=NvCpl.EXE
Description=Added by the YANZ.B WORM!
Source=Paul Collins Startup list
[NvCplD]
Confirmed=X
Filename=m2gr32.exe
Description="Switch" premium rate adult content dialler
Source=Paul Collins Startup list
[NvCplD]
Confirmed=X
Filename=ntcpl.exe
Description=Switch adult content dialler
Source=Paul Collins Startup list
[NvCplDaemon]
Confirmed=N
Filename=rundll32.exe NvQtwk.dll, NvCplDaemon
Description=System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
Source=Paul Collins Startup list
[NvCplDaemon]
Confirmed=U
Filename=rundll32.exe NvCpl.dll, NvStartup
Description=Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
Source=Paul Collins Startup list
[NvCplDmn]
Confirmed=X
Filename=NAVSVC.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[NvCplScan]
Confirmed=X
Filename=nvsc32.exe
Description=Added by a variant of the IRC.BOT TROJAN!
Source=Paul Collins Startup list
[NvCplScan]
Confirmed=X
Filename=msc32.exe
Description=Added by the FORBOT-DD WORM!
Source=Paul Collins Startup list
[nvd32 lptt01]
Confirmed=X
Filename=nvd32.exe
Description=Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[nvd32 ml097e]
Confirmed=X
Filename=nvd32.exe
Description=Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Nvid]
Confirmed=X
Filename=[8 random charachters]
Description=Unidentified adware
Source=Paul Collins Startup list
[Nvid32]
Confirmed=X
Filename=Nvid32.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Nvidex32]
Confirmed=X
Filename=Nvidex32.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Nvidia Control Panel]
Confirmed=X
Filename=ncsvc32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[NVIDIA Driver]
Confirmed=X
Filename=MSPMSPSU.EXE
Description=Added by the WOOTBOT.Y WORM!
Source=Paul Collins Startup list
[NVIDIA nForce APU1 Utilities]
Confirmed=N
Filename=NVATray.exe
Description=nVidia's nForce Audio Processing Unit (APU)- "provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time"
Source=Paul Collins Startup list
[NVIDIA Video drivers]
Confirmed=X
Filename=video_32D.exe
Description=Added by the AGOBOT.KV WORM!
Source=Paul Collins Startup list
[Nvidia32]
Confirmed=X
Filename=nvidia32.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[NvidiaQuickTweak]
Confirmed=N
Filename=rundll32.exe NvQtwk.dll, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NVIEW]
Confirmed=U
Filename=rundll32.exe nview.dll, nViewLoadHook
Description=This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers
Source=Paul Collins Startup list
[NvInitialize]
Confirmed=N
Filename=rundll32.exe NvQtwk.dll, NvXTInit
Description=Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled
Source=Paul Collins Startup list
[NVmax]
Confirmed=Y
Filename=NVmax.exe
Description=NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card
Source=Paul Collins Startup list
[NVMCTRAY]
Confirmed=N
Filename=RUNDLL32.EXE ...NVMCTRAY.DLL, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NvMediaCenter]
Confirmed=U
Filename=RunDLL32.exe NvMCTray.dll, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NVMixerTray]
Confirmed=N
Filename=NVMixerTray.exe
Description=System Tray access to audio controls from nVidia's motherboard ForceWare software
Source=Paul Collins Startup list
[NVQuickTweak]
Confirmed=N
Filename=rundll32.exe NvQtwk.dll, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NVRT]
Confirmed=N
Filename=nvrt.exe
Description=NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
Source=Paul Collins Startup list
[NVRTClk]
Confirmed=?
Filename=NVRTClk.exe
Description=Related to a Gigabyte video card. What does it do, and is it required?
Source=Paul Collins Startup list
[nvsv32.exe]
Confirmed=X
Filename=nvsv32.exe
Description=Added by the FORBOT-DI WORM!
Source=Paul Collins Startup list
[NvSvc]
Confirmed=N
Filename=nvsvc.exe
Description=NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that
Source=Paul Collins Startup list
[NVSystem32]
Confirmed=X
Filename=nvscv32.exe
Description=Added by the AGOBOT-NO WORM!
Source=Paul Collins Startup list
[NvXplDeamon]
Confirmed=X
Filename=xstyles.exe
Description=Added by the SMALL.AJ VIRUS!
Source=Paul Collins Startup list
[NWEReboot]
Confirmed=?
Filename=dummy.exe
Description=??
Source=Paul Collins Startup list
[nwiz]
Confirmed=N
Filename=nwiz.exe
Description=Associated with the newer versions of nVidia graphics cards drivers. Allows you to immensely improve desktop layouts by setting preferences and optimizations. However, this isn't necessary for the operation of your system
Source=Paul Collins Startup list
[Nwpopup]
Confirmed=Y
Filename=Nwpopup.exe
Description=Broadcast message handler part of Novell Netware that displays server, printer and other messages
Source=Paul Collins Startup list
[nwrecmsg]
Confirmed=U
Filename=nwrecmsg.exe
Description=Broadcast message handler part of Novell Netware that displays server, printer and other messages - can cause crashes
Source=Paul Collins Startup list
[NWTRAY]
Confirmed=Y
Filename=nwtray.exe
Description=Novell Netware. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the client
Source=Paul Collins Startup list
[oadaemon]
Confirmed=?
Filename=oadaemon.exe
Description=Background process that establishes connection with a C3-1000 scanner and watch general status of the device and for scanner button presses. Can it be started manually?
Source=Paul Collins Startup list
[oahstifr]
Confirmed=Y
Filename=oahstifr.exe
Description=Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."
Source=Paul Collins Startup list
[OAKSTART]
Confirmed=U
Filename=OAKSTART.EXE
Description=Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
Source=Paul Collins Startup list
[OAKTASK]
Confirmed=N
Filename=OAKTASK.EXE
Description=Taskbar utility for a "control panel" for a CD-RW
Source=Paul Collins Startup list
[Object Store Server]
Confirmed=Y
Filename=osserver.exe
Description=Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."
Source=Paul Collins Startup list
[objtjprx]
Confirmed=?
Filename=objtjprx.exe
Description=??
Source=Paul Collins Startup list
[obsver]
Confirmed=?
Filename=obsver.exe
Description=Part of LingoWare translating software - what does it do and is it required?
Source=Paul Collins Startup list
[OCAudioIni]
Confirmed=N
Filename=OCAudioIni.exe
Description=One-click Audio Converter - allows you to convert files of multiple audio formats right from Windows Explorer
Source=Paul Collins Startup list
[ocraware]
Confirmed=N
Filename=ocraware.exe
Description=Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[ocx32]
Confirmed=X
Filename=ocx32.exe
Description=Added by the ASTEF or RESPAN WORMS!
Source=Paul Collins Startup list
[OD]
Confirmed=X
Filename=SYSCNTR.EXE
Description=HotVideo dialler
Source=Paul Collins Startup list
[od-matrxx]
Confirmed=X
Filename=od-matrxx.exe
Description=Adult dialler - xx can be any number
Source=Paul Collins Startup list
[od-stndxx]
Confirmed=X
Filename=od-stndxx.exe
Description=Adult dialler - xx can be any number
Source=Paul Collins Startup list
[od-teenxx]
Confirmed=X
Filename=od-teenxx.exe
Description=Adult dialler - xx can be any number
Source=Paul Collins Startup list
[ODBC BackUp]
Confirmed=U
Filename=fdxxl.exe
Description=G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself!
Source=Paul Collins Startup list
[Odometer]
Confirmed=N
Filename=Odometer.EXE
Description=Mouse odometer - tracks how far your pointer/arrow has traveled on the screen. Shortcut available
Source=Paul Collins Startup list
[Oeloader]
Confirmed=X
Filename=Oeloader.exe
Description=Xupiter OrbitExplorer toolbar related, drive-by foistware
Source=Paul Collins Startup list
[OEM Tools 32]
Confirmed=X
Filename=tres32.exe
Description=Added by the RBOT.QB WORM!
Source=Paul Collins Startup list
[OEM32 Tools]
Confirmed=X
Filename=sres32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[OEMCLEANUP]
Confirmed=N
Filename=oemreset.exe
Description=Resets OEM installation settings at bootup. Not required unless you're new to PC's
Source=Paul Collins Startup list
[OEMRESET]
Confirmed=U
Filename=oemreset.exe
Description=Resets OEM installation settings at bootup. Not required unless you're new to PC's
Source=Paul Collins Startup list
[OEPowerPlugs]
Confirmed=?
Filename=winoeinit.exe
Description=??
Source=Paul Collins Startup list
[OEXCheck]
Confirmed=N
Filename=EA2Check.exe
Description=Express Assist from AJSystems.com. Utility for use with Outlook Express to backup, restore, synchronize amongst others
Source=Paul Collins Startup list
[Offer Companion]
Confirmed=X
Filename=offers.exe
Description=Adware
Source=Paul Collins Startup list
[Offers]
Confirmed=X
Filename=offers.exe
Description=Adware
Source=Paul Collins Startup list
[Office Startup]
Confirmed=N
Filename=Osa.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Office Startup]
Confirmed=X
Filename=Exploer.exe
Description=Added by the GAOBOT.BV WORM! Note the different filename to the valid MS Office entries
Source=Paul Collins Startup list
[Office Startup]
Confirmed=N
Filename=Osa9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[OfficeGuard RegChecker]
Confirmed=Y
Filename=ogrc.exe
Description=Kaspersky Labs anti-virus
Source=Paul Collins Startup list
[officejet 6100]
Confirmed=?
Filename=hposol08.exe
Description=Associated with a HP PSC2110 (and maybe others) all-in-one machine
Source=Paul Collins Startup list
[OfficeScan95]
Confirmed=Y
Filename=pccwin97.exe
Description=Trend Micro antivirus OfficeScan
Source=Paul Collins Startup list
[OfficeScanNT Monitor]
Confirmed=Y
Filename=pccntmon.exe
Description=Trend Micro OfficeScan Antivirus real-time scan monitor
Source=Paul Collins Startup list
[OfotoNow USB Detection]
Confirmed=N
Filename=Rundll32.exe OFUSBS.DLL, WatchForConnection OfotoNow
Description=Autodetects when a digital camera is attached to a USB port and launches OfotoNow image software. Available via Start -> Programs
Source=Paul Collins Startup list
[ogrc]
Confirmed=Y
Filename=ogrc.exe
Description=Kaspersky Labs anti-virus
Source=Paul Collins Startup list
[Oil Change]
Confirmed=N
Filename=OCTray32.exe
Description=From CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs
Source=Paul Collins Startup list
[OIM]
Confirmed=?
Filename=oim.exe
Description=Related to the O2 (was "genie") mobile phone service. What does it do and is it required?
Source=Paul Collins Startup list
[OLE]
Confirmed=X
Filename=[filename]
Description=Added by the STAWIN or TARNO.D TROJANS!
Source=Paul Collins Startup list
[OLE Automation Server]
Confirmed=X
Filename=ole32aut.vbe
Description=CoolWebSearch parasite related
Source=Paul Collins Startup list
[Olehelp]
Confirmed=X
Filename=Olehelp.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[olehelp]
Confirmed=X
Filename=olehelp.exe
Description=Added by the BOOKMARKER.D or BOOKMARKER.G TROJANS!
Source=Paul Collins Startup list
[Olive System]
Confirmed=X
Filename=Szchost.exe
Description=Added by the MERCURYCAS.A TROJAN!
Source=Paul Collins Startup list
[Omf4]
Confirmed=X
Filename=OMF4.EXE
Description=Added by the FREEMEGA TROJAN!
Source=Paul Collins Startup list
[OmgStartup]
Confirmed=N
Filename=omgstartup.exe
Description=Sony program called OpenMG Jukebox - player and music organizer
Source=Paul Collins Startup list
[OmniHTTPd]
Confirmed=U
Filename=ohttpd.exe
Description=OmniHTTPd web server from Omnicron
Source=Paul Collins Startup list
[OmniPage]
Confirmed=N
Filename=Opware32.exe
Description=Part of OmniPage Pro from Scansoft (was Caere) - "the fastest, easiest way to turn paper documents into digital files you can edit." Opware32.exe links Word, via OLE, with OmniPage. If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs
Source=Paul Collins Startup list
[OmniPass]
Confirmed=U
Filename=scureapp.exe
Description=OmniPass from Softex Inc. - secure password management software
Source=Paul Collins Startup list
[On Screen Display]
Confirmed=U
Filename=OSD.EXE
Description=By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don't adjust things regularly - can also freeze
Source=Paul Collins Startup list
[One Touch Monitor]
Confirmed=N
Filename=OneTouchMonitor.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[One Touch Monitor]
Confirmed=N
Filename=1tou~2.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[One Touch Monitor]
Confirmed=N
Filename=ONETOU~2.EXE
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouch Monitor]
Confirmed=N
Filename=OneTouchMon.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouchMonitor]
Confirmed=N
Filename=OneTouchMonitor.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouchMonitor]
Confirmed=N
Filename=1tou~2.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouchMonitor]
Confirmed=N
Filename=ONETOU~2.EXE
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[ONETOU~2]
Confirmed=N
Filename=OneTouchMonitor.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[ONETOU~2]
Confirmed=N
Filename=1tou~2.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[ONETOU~2]
Confirmed=N
Filename=ONETOU~2.EXE
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[Onflow]
Confirmed=X
Filename=onflow.exe
Description=Onflow is a internet company that offers an online advertising program. Not required - uninstall
Source=Paul Collins Startup list
[online cdrom]
Confirmed=?
Filename=Active acid.exe
Description=??
Source=Paul Collins Startup list
[Online Service]
Confirmed=X
Filename=svchost.exe
Description=Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[OnlinePCfix SmoothSurfer]
Confirmed=U
Filename=SS.exe
Description=Smooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists
Source=Paul Collins Startup list
[OnlineTime]
Confirmed=N
Filename=onlinetime.exe
Description=OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs
Source=Paul Collins Startup list
[online_party]
Confirmed=X
Filename=online_party.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[OnSrvr]
Confirmed=X
Filename=OnSrvr.exe
Description=OnWebMedia adware
Source=Paul Collins Startup list
[oo4]
Confirmed=X
Filename=RunDLL32.EXE oo4.dll, DllRun
Description=BookedSpace parasite variant
Source=Paul Collins Startup list
[OOLHELPT]
Confirmed=?
Filename=OOLHELPT.exe
Description=??
Source=Paul Collins Startup list
[OP12 Reminder]
Confirmed=N
Filename=Ereg.exe
Description=Registration reminder for OmniPage Pro 12 from ScanSoft
Source=Paul Collins Startup list
[Open Site]
Confirmed=X
Filename=opnste.exe
Description=Adware - see here
Source=Paul Collins Startup list
[Open2Enter]
Confirmed=X
Filename=runme.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Open2Enter]
Confirmed=X
Filename=runme2.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[OpenMstart]
Confirmed=X
Filename=mcmgr32.exe
Description="Switch" adult content dialler
Source=Paul Collins Startup list
[OpenMstart]
Confirmed=X
Filename=mmgr32.exe
Description="Switch" adult content dialler
Source=Paul Collins Startup list
[OpenOffice.org x]
Confirmed=N
Filename=QUICKS~1.EXE
Description=Displays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). "x" represents the version number
Source=Paul Collins Startup list
[Openwares LiveUpdate]
Confirmed=U
Filename=LiveUpdate.exe
Description=Web-update utility as used by various types of software - see here
Source=Paul Collins Startup list
[Operator]
Confirmed=N
Filename=??
Description=Media Pilot operator, in Win.ini. Locks port open
Source=Paul Collins Startup list
[Operator]
Confirmed=U
Filename=xtmop.exe
Description=Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported
Source=Paul Collins Startup list
[OpiStat]
Confirmed=N
Filename=OPISTAT.EXE
Description=OpiStat is a European Research Institute whose goal is to understand consumer needs and opinions better
Source=Paul Collins Startup list
[OPQFile]
Confirmed=X
Filename=regedit.exe /s ...rad03FA6.tmp
Description=Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
Source=Paul Collins Startup list
[OPTIMIZER]
Confirmed=X
Filename=iexplore.exe
Description=Added by the EVIVINC TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Optimum Online]
Confirmed=N
Filename=Netsurf.exe
Description=Optimum Online ISP software. Not required, just window dressing & advertising from Optimum
Source=Paul Collins Startup list
[Optus Cable Data Monitor]
Confirmed=U
Filename=datamonitor.exe
Description=Allows Optus customers to monitor their actual data usage against Optus' "data allowance limits"
Source=Paul Collins Startup list
[OptusNetUsage]
Confirmed=U
Filename=OptusNet Usage Meter.exe
Description=Designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit, and how far over your suggested limit you should be
Source=Paul Collins Startup list
[Opware12]
Confirmed=N
Filename=Opware12.exe
Description=OmniPage Pro 12 from ScanSoft
Source=Paul Collins Startup list
[OrbitUpdate]
Confirmed=X
Filename=update.exe
Description=Xupiter OrbitExplorer toolbar, drive-by foistware
Source=Paul Collins Startup list
[OrbitView]
Confirmed=X
Filename=view.exe
Description=Xupiter OrbitExplorer toolbar, drive-by foistware
Source=Paul Collins Startup list
[org5.exe]
Confirmed=?
Filename=org5.exe
Description=Lotus Organizer 5 application file, Lotus Organizer software. What does it do and is it required?
Source=Paul Collins Startup list
[OrgyCam]
Confirmed=X
Filename=OrgyCam.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[OrigRage128Tweaker]
Confirmed=U
Filename=RAGE128TWEAK.EXE
Description=Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com
Source=Paul Collins Startup list
[ORiNOCO]
Confirmed=U
Filename=Cmluc.exe
Description=Client Manager software for an ORiNOCO wireless LAN card
Source=Paul Collins Startup list
[Osa32]
Confirmed=X
Filename=NTOSA32.exe
Description=Added by the ANIG WORM!
Source=Paul Collins Startup list
[OSD]
Confirmed=U
Filename=OSD.exe
Description=By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don't adjust things regularly - can also freeze
Source=Paul Collins Startup list
[OSS]
Confirmed=X
Filename=ossproxy.exe
Description=NetSetter/Marketscore foistware
Source=Paul Collins Startup list
[OSS]
Confirmed=X
Filename=rk.exe
Description=RelevantKnowledge, NetSetter/Marketscore foistware variant
Source=Paul Collins Startup list
[OSSProxy]
Confirmed=X
Filename=OSSPROXY.EXE
Description=NetSetter/Marketscore foistware
Source=Paul Collins Startup list
[OStivityInvAgt]
Confirmed=U
Filename=ostivity.exe
Description=OStivity - "a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network, a complete inventory (software and hardware) is taken of the system"
Source=Paul Collins Startup list
[Osus]
Confirmed=X
Filename=acao.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[otcx]
Confirmed=X
Filename=otcxxh.exe
Description=Added by the CAROOL TROJAN!
Source=Paul Collins Startup list
[outlook]
Confirmed=X
Filename=outlook.exe
Description=Added by the SDBOT-RU WORM!
Source=Paul Collins Startup list
[Outpost Firewall]
Confirmed=Y
Filename=outpost.exe
Description=Outpost personal firewall
Source=Paul Collins Startup list
[Outwar]
Confirmed=X
Filename=syslaunch.exe
Description=Outwar adware downloader
Source=Paul Collins Startup list
[OVCJ]
Confirmed=?
Filename=ovcj.exe
Description=??
Source=Paul Collins Startup list
[Overnet]
Confirmed=N
Filename=Overnet.exe
Description=Overnet peer-to-peer (P2P) file sharing program
Source=Paul Collins Startup list
[OWCCardbusTray]
Confirmed=U
Filename=ocbtray.exe
Description=Icon in the system tray for safely removing PCMCIA cards. Only required if you have a laptop or desktop which includes a PCMCIA card interface
Source=Paul Collins Startup list
[OWCWebCamDV]
Confirmed=U
Filename=wcdvtray.exe
Description=WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam
Source=Paul Collins Startup list
[OWMngr]
Confirmed=X
Filename=OWMngr.exe
Description=OnWebMedia advertising foistware - see here for exactly what to look for
Source=Paul Collins Startup list
[oz2]
Confirmed=X
Filename=oz2.exe
Description=Added by the MYDOOM.W WORM!
Source=Paul Collins Startup list
[P17Helper]
Confirmed=?
Filename=Rundll32 P17.dll, P17Helper
Description=ASIO driver for the Sound Blaster Audigy & Audigy 2 series sound card - is it required in startup?
Source=Paul Collins Startup list
[P2P NETWORKING]
Confirmed=N
Filename=P2P Networking.exe
Description=Peer to Peer (P2P) sharing of files on the internet
Source=Paul Collins Startup list
[P2P Networking3]
Confirmed=N
Filename=P2P Networking3.exe
Description=P2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required - see here
Source=Paul Collins Startup list
[P3p4chk]
Confirmed=X
Filename=P3p4chk.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[p4mx4]
Confirmed=X
Filename=p4mx4.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[Packard Bell EverSafe Tray Control]
Confirmed=?
Filename=TrayControl.exe
Description=Packard Bell EverSafe software. What does it do, and is it required?
Source=Paul Collins Startup list
[PadTouch]
Confirmed=N
Filename=PadExe.exe
Description=Toshiba Touch and Launch - offers easy movement and freedom of programs navigation with TouchPad
Source=Paul Collins Startup list
[Pagekeeper Jobs]
Confirmed=U
Filename=pkjobs.exe
Description=PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc
Source=Paul Collins Startup list
[Pagekeeper Lite]
Confirmed=U
Filename=pkjobs.exe
Description=PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc
Source=Paul Collins Startup list
[PAgent]
Confirmed=X
Filename=PAgent.exe
Description=Scans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local filesystem for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is found. See here for more info
Source=Paul Collins Startup list
[Pagis Scheduler]
Confirmed=N
Filename=Monitor.exe
Description=Scheduler for the Pagis scanning suite from Scansoft.
Source=Paul Collins Startup list
[pagmstart]
Confirmed=?
Filename=client.exe
Description=Possibly related to this?
Source=Paul Collins Startup list
[Pagoo]
Confirmed=N
Filename=PAGOO.EXE
Description=Pagoo - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
Source=Paul Collins Startup list
[Palm MultiUser Config]
Confirmed=?
Filename=Configtool.exe
Description=MultiUser configuration for a Palm PDA device?. Is it required?
Source=Paul Collins Startup list
[Palm.exe]
Confirmed=N
Filename=Palm.exe
Description=Palm Desktop Software for use with Palm handheld devices. Available via Start -> Programs
Source=Paul Collins Startup list
[PalNetaware]
Confirmed=X
Filename=pnetaware.exe
Description=PalTalk adware - as included in Morpheus, see here towards the bottom of the page
Source=Paul Collins Startup list
[PaltalkNetaware.exe]
Confirmed=N
Filename=PALNETAW~1.EXE
Description=Voice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start -> Programs. Delete the shortcut in Start -> Programs -> StartUp as well otherwise it will be reinstated
Source=Paul Collins Startup list
[Panda Scheduler]
Confirmed=U
Filename=pavsched.exe
Description=Panda Antivirus scan scheduler. Required if this is your virus scanner program and you have scans scheduled on a regular basis. I recommend that you scan manually so you don't need this but if you tend to forget then leave it
Source=Paul Collins Startup list
[PandaAVEngine]
Confirmed=X
Filename=PandaAVEngine.exe
Description=Added by the NETSKY.R WORM!
Source=Paul Collins Startup list
[Paperport]
Confirmed=N
Filename=runppdrv.exe
Description=Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here
Source=Paul Collins Startup list
[PaperPort PTD]
Confirmed=N
Filename=pptd40nt.exe
Description="PaperPort" software associated with scanners
Source=Paul Collins Startup list
[PaperQuote System Tray Icon]
Confirmed=N
Filename=PQTRAY.EXE
Description=PaperQuote is a "wallpaper" changer with daily quotes that are either for inspiration or motivation
Source=Paul Collins Startup list
[Parallel Tasking]
Confirmed=X
Filename=ptask.exe
Description=Added by unidentified adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.adg
Source=Paul Collins Startup list
[PartSeal]
Confirmed=U
Filename=PartSeal.exe
Description=System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
Source=Paul Collins Startup list
[Password Door Loader]
Confirmed=U
Filename=PDMonitor.exe
Description=Password Door - password protection software
Source=Paul Collins Startup list
[PasteLister]
Confirmed=N
Filename=plister.exe
Description=PasteLister - clipboard extender. Start manually when required
Source=Paul Collins Startup list
[Patch]
Confirmed=X
Filename=patch.exe
Description=Added by the NETBUS WORM!
Source=Paul Collins Startup list
[Patches Value]
Confirmed=X
Filename=WinGamed.exe
Description=Added by the SDBOT.BR WORM!
Source=Paul Collins Startup list
[Path]
Confirmed=?
Filename=lide.exe
Description=??
Source=Paul Collins Startup list
[PAV.EXE]
Confirmed=X
Filename=%Number%
Description=Added by the KITRO.D (or ARGEN.A) WORM! %Number% can be any number
Source=Paul Collins Startup list
[PAV.EXE]
Confirmed=Y
Filename=PAV.EXE
Description=PER Antivirus
Source=Paul Collins Startup list
[PAVFIRES]
Confirmed=Y
Filename=PavFires.exe
Description=Panda Antivirus
Source=Paul Collins Startup list
[PAVFNSVR]
Confirmed=Y
Filename=PavFnSvr.exe
Description=Panda Titanium Antivirus
Source=Paul Collins Startup list
[PavProc]
Confirmed=Y
Filename=PavPrS9x.exe
Description=Panda Titanium Antivirus
Source=Paul Collins Startup list
[PavProt]
Confirmed=Y
Filename=PavProt.exe
Description=Panda Titanium Antivirus
Source=Paul Collins Startup list
[PC Alert III]
Confirmed=U
Filename=alert.exe
Description=MSI PC Alert III - allows you to view your system and cpu temperature, fan rpm and more. Only required if you overclock
Source=Paul Collins Startup list
[PC Booster]
Confirmed=U
Filename=pcbooster.exe
Description=PC Booster from inKline Global - "easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition"
Source=Paul Collins Startup list
[PC-Config32]
Confirmed=X
Filename=corona.exe
Description=Added by the CORONEX.A WORM!
Source=Paul Collins Startup list
[PCBG]
Confirmed=Y
Filename=PCBODYGUARD.EXE
Description=PC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc
Source=Paul Collins Startup list
[PCBODYGUARD]
Confirmed=Y
Filename=PCBODYGUARD.EXE
Description=PC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc
Source=Paul Collins Startup list
[PCCClient.exe]
Confirmed=Y
Filename=PCCClient.exe
Description=PC-Cillin 2002 antivirus software
Source=Paul Collins Startup list
[pccguide.exe]
Confirmed=Y
Filename=pccguide.exe
Description=PC-Cillin 2002 antivirus software
Source=Paul Collins Startup list
[PCCIOMON.EXE]
Confirmed=Y
Filename=PCCIOMON.EXE
Description=PC-Cillin 2000 antivirus software. This is the actual virus-scanner
Source=Paul Collins Startup list
[PCClient.exe]
Confirmed=Y
Filename=PCClient.exe
Description=Trend Micro PC-Cillin Internet Security
Source=Paul Collins Startup list
[PccPfw]
Confirmed=Y
Filename=PccPfw.exe
Description=PC Cillin 2003 personal firewall
Source=Paul Collins Startup list
[PcCtlCom]
Confirmed=Y
Filename=Pcctlcom.exe
Description=Trend Micro PC-cillin Internet Security
Source=Paul Collins Startup list
[PCDRealtime]
Confirmed=N
Filename=realtime.exe
Description=Apparently the monitoring device for PC Doctor Online. It provides a "free" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to "order" the fee-based fixes from its web site
Source=Paul Collins Startup list
[PcEXPLODE]
Confirmed=X
Filename=specialfile.exe
Description=Added by the RBOT.RH WORM!
Source=Paul Collins Startup list
[PCHbutton]
Confirmed=N
Filename=PCHbutton.exe
Description=Used by HP Instant Support
Source=Paul Collins Startup list
[PCHealth]
Confirmed=N
Filename=pchschd.exe
Description=This is a "scheduler" and does not turn off PC Health. For more information refer here
Source=Paul Collins Startup list
[PCHEasySearch]
Confirmed=X
Filename=STUpdate.exe
Description=PCH EasySearch bar
Source=Paul Collins Startup list
[PCIMODEM]
Confirmed=?
Filename=pcimodem.exe
Description=Associated with Lucent based Aztech MDP7800-U PCI modems. Is it required?
Source=Paul Collins Startup list
[PCLEPCI]
Confirmed=U
Filename=ppe.exe
Description=Pinnacle Systems PCI Performance Enhancer. "This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards."
Source=Paul Collins Startup list
[PCMService]
Confirmed=?
Filename=PCMService.exe
Description=In a DellMedia Experience sub-directory
Source=Paul Collins Startup list
[PCRecSA]
Confirmed=U
Filename=PCRecSA.exe
Description=Part of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a "clean" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need to
Source=Paul Collins Startup list
[PCShield]
Confirmed=X
Filename=regsvr32 /s [path] sfg_****.dll [* = random char]
Description=SafeguardProtect/Veevo malware
Source=Paul Collins Startup list
[PCStart]
Confirmed=N
Filename=Pcm25.exe
Description=Runs as part of PCMonitor which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big
Source=Paul Collins Startup list
[PCSuiteTrayApplication]
Confirmed=N
Filename=TrayApplication.exe
Description=System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu
Source=Paul Collins Startup list
[Pcsv]
Confirmed=N
Filename=pcsvc.exe
Description=Delfin Media Viewer or "Promulgate" adware
Source=Paul Collins Startup list
[PcSync]
Confirmed=N
Filename=PcSync.exe
Description=If a Nokia phone has been connected, synchronises the phone with MS Outlook or other organiser software. It is installed by the Nokia PC Suite, and the tray icon shows if a phone has been connected. Available via a desktop shortcut or Start -> Programs
Source=Paul Collins Startup list
[pctspk]
Confirmed=U
Filename=pctspk.exe
Description=Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
Source=Paul Collins Startup list
[PCTVOICE]
Confirmed=U
Filename=pctvoice.exe
Description=The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. It’s better to leave it
Source=Paul Collins Startup list
[PDEngine]
Confirmed=U
Filename=PDEngine.exe
Description=PerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot
Source=Paul Collins Startup list
[pdexplo]
Confirmed=N
Filename=PDEXPLO.EXE
Description=PowerDesk Pro by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs
Source=Paul Collins Startup list
[PDF Converter Registry Controller]
Confirmed=?
Filename=RegistryController.exe
Description=ScanSoft PDF_Converter related - what does it do and is it required?
Source=Paul Collins Startup list
[pdfFactory Pro Dispatcher v1]
Confirmed=N
Filename=fppdis1.exe
Description="With pdfFactory you can create PDF documents from any program printing to the virtual PDF printer". Available via a desktop shortcut or Start -> Programs
Source=Paul Collins Startup list
[pdfSaver3]
Confirmed=N
Filename=pdfSaver3.exe
Description=PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher etc
Source=Paul Collins Startup list
[PDirect]
Confirmed=N
Filename=PDirect.exe
Description=IBM Presentation Director software
Source=Paul Collins Startup list
[pdp Server]
Confirmed=U
Filename=ctpdpsrvr.exe
Description=Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
Source=Paul Collins Startup list
[PDVDServ]
Confirmed=U
Filename=PDVDServ.exe
Description=Remote Control background application for CyberLink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Source=Paul Collins Startup list
[Pe2ckfnt SE]
Confirmed=N
Filename=chkfont.exe
Description=Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu
Source=Paul Collins Startup list
[Peeramid]
Confirmed=?
Filename=PService.exe
Description=In a "Koptimizer" folder in Program Files. What does it do and is it required?
Source=Paul Collins Startup list
[PeerGuardian]
Confirmed=N
Filename=PeerGuardian_1.99b_pr14.exe
Description=PeerGuardian "is a tiny firewall program especially designed for P2P software users, but also for anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections"
Source=Paul Collins Startup list
[Pent@VALUE 3.2]
Confirmed=U
Filename=Pent@VALUE.exe
Description=Pent@VALUE Digital Satellite Internet PC Receiver
Source=Paul Collins Startup list
[PeqBL100]
Confirmed=X
Filename=PEQBL100.exe
Description=Added by the ENVID.D WORM!
Source=Paul Collins Startup list
[PER Email Protection]
Confirmed=Y
Filename=pavmail.exe
Description=PER Antivirus
Source=Paul Collins Startup list
[PerfectPrint]
Confirmed=N
Filename=pfppop70.exe
Description=Print engine used by Corel WordPerfect 7 and Presentations 7
Source=Paul Collins Startup list
[PersFw]
Confirmed=Y
Filename=PersFw.exe
Description=Kerio or Tiny Personal Firewall
Source=Paul Collins Startup list
[Personal Firwall]
Confirmed=X
Filename=ptmedsrv.exe
Description=Added by the SDBOT.XY WORM!
Source=Paul Collins Startup list
[Pervasive.SQL Workgroup Engine]
Confirmed=U
Filename=W3dbsmgr.exe
Description=Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
Source=Paul Collins Startup list
[PestPatrol Control Center]
Confirmed=U
Filename=PPControl.exe
Description=PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
Source=Paul Collins Startup list
[PestPatrolCL]
Confirmed=?
Filename=PestPatrolCL.exe
Description=Associated with PestPatrol anti-malware software. What does this part do and is it required?
Source=Paul Collins Startup list
[Petit Larousse 2001]
Confirmed=U
Filename=HIPL2000Popup.exe
Description=Popup dictionary tool
Source=Paul Collins Startup list
[PFW_CfgEngine]
Confirmed=?
Filename=PFWCFG~1.EXE
Description=Personal Firewall related?
Source=Paul Collins Startup list
[PFW_PullSrv]
Confirmed=?
Filename=PULL.EXE
Description=Personal Firewall related?
Source=Paul Collins Startup list
[PgMonitr]
Confirmed=X
Filename=PgMonitr.exe
Description=Delfin Promulgate adware variant
Source=Paul Collins Startup list
[PGPSDKSVC]
Confirmed=Y
Filename=pgpsdkserv.exe
Description=PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionality
Source=Paul Collins Startup list
[PGPSERVICE]
Confirmed=U
Filename=pgpservice.exe
Description=PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a "fall-back" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big difference
Source=Paul Collins Startup list
[PGPtray]
Confirmed=N
Filename=pgptray.exe
Description=PGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start -> Programs
Source=Paul Collins Startup list
[PGStub.exe]
Confirmed=X
Filename=[various filenames]
Description=Unidentified adware
Source=Paul Collins Startup list
[pgtaff]
Confirmed=X
Filename=pgtaff.exe
Description=AdRotator adware variant
Source=Paul Collins Startup list
[Phime2002a]
Confirmed=N
Filename=TINTSETP.EXE
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[PHIME2002ASync]
Confirmed=N
Filename=TINTSETP.EXE
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[PhoneFree version 6.2]
Confirmed=U
Filename=PHONEF??.EXE
Description=An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here
Source=Paul Collins Startup list
[Photo Express Calendar Checker SE]
Confirmed=N
Filename=CALCHECK.EXE
Description=If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly
Source=Paul Collins Startup list
[Photo Loader supervisory]
Confirmed=N
Filename=Plauto.exe
Description=Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your pictures
Source=Paul Collins Startup list
[PhotoWise QuickLink]
Confirmed=N
Filename=quicklnk.exe
Description=Agfa PhotoWise - "PhotoWise QuickLinkTM lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more."
Source=Paul Collins Startup list
[Picasa Media Detector]
Confirmed=N
Filename=PicasaMediaDetector.exe
Description=Media detector for Picasa's automatic photo organizer
Source=Paul Collins Startup list
[PicasaNet]
Confirmed=N
Filename=Hello.exe
Description=Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs, or blogs
Source=Paul Collins Startup list
[Pickatag]
Confirmed=N
Filename=pickatag.exe
Description=Pick-a-tag - "Freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages"
Source=Paul Collins Startup list
[PICPRTR]
Confirmed=N
Filename=PICPRTR.EXE
Description=Program for viewing and measuring a variety of 3D CAD data formats
Source=Paul Collins Startup list
[pictureBUZZTray]
Confirmed=N
Filename=swtray.exe
Description=System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually
Source=Paul Collins Startup list
[PiDunHK]
Confirmed=U
Filename=PIDUNHK.EXE
Description=Part of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happens
Source=Paul Collins Startup list
[piiserviceOE]
Confirmed=U
Filename=N/A
Description=Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE
Source=Paul Collins Startup list
[pilif]
Confirmed=X
Filename=pilif.exe
Description=Added by the FILI WORM!
Source=Paul Collins Startup list
[Pinger]
Confirmed=N
Filename=pinger.exe
Description=Pinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification
Source=Paul Collins Startup list
[PinnacleDriverCheck]
Confirmed=Y
Filename=PSDrvCheck.exe
Description=Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled
Source=Paul Collins Startup list
[Piolet]
Confirmed=N
Filename=piolet.exe
Description=Piolet - peer-to-peer file sharing client
Source=Paul Collins Startup list
[Piracy]
Confirmed=N
Filename=SysUtil.exe
Description=Software Piracy Alert feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: "The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users"
Source=Paul Collins Startup list
[PivotSoftware]
Confirmed=N
Filename=wpctrl.exe
Description=PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
Source=Paul Collins Startup list
[Pixel32]
Confirmed=X
Filename=Pixel32.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Pixelpwr32]
Confirmed=X
Filename=Pixelpwr32.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Pixelsvr]
Confirmed=X
Filename=Pixelsvr.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[pjWebCam]
Confirmed=U
Filename=pjWebCam.exe
Description=Webcam automation software that saves regular photos from webcam and can also act as HTTP server
Source=Paul Collins Startup list
[PK Services]
Confirmed=X
Filename=pksvc.exe
Description=Added by the FORBOT-BW WORM!
Source=Paul Collins Startup list
[PktAnything]
Confirmed=U
Filename=PocketCompanion.exe
Description=PocketAnything lets you save anything on your computer to your mobile, with one click
Source=Paul Collins Startup list
[PLEAPCPUCPL]
Confirmed=U
Filename=pleapu.exe
Description=CPU Control Panel for the Powerleap CPU upgrade
Source=Paul Collins Startup list
[PLFFAP]
Confirmed=?
Filename=HotfixQ0306270.exe
Description=Prolific Technology Inc. USB Flash Disk driver - is it required in startup?
Source=Paul Collins Startup list
[Plguni]
Confirmed=N
Filename=Plguni.exe
Description=McAfee QuickClean 3.0 - removes internet clutter and unwanted programs
Source=Paul Collins Startup list
[plmg.exe]
Confirmed=U
Filename=plmg.exe
Description=Paragon Last Minute Bidder - auction assistant software
Source=Paul Collins Startup list
[PLoader]
Confirmed=?
Filename=umsd.exe
Description=USB Mass Storage Disk related tray icon. Is it required?
Source=Paul Collins Startup list
[Plob]
Confirmed=X
Filename=kernel.com
Description=Added by the OPTIXPRO.12 TROJAN!
Source=Paul Collins Startup list
[Pluck Tray]
Confirmed=U
Filename=PluckTray.exe
Description=RSS (XML TAGS) reader program
Source=Paul Collins Startup list
[Plug And Play]
Confirmed=X
Filename=msnmsg.exe
Description=Added by the RBOT-ID WORM!
Source=Paul Collins Startup list
[PLXSTART]
Confirmed=U
Filename=PLXSTART.EXE
Description=Sets the spindown timeout and access speeds at startup and displays the "Plextor Manager 2000" splash screen for Plextor CD-RW.
Source=Paul Collins Startup list
[PLXTASK]
Confirmed=N
Filename=PLXTASK.EXE
Description=Taskbar utility for a "control panel" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files)
Source=Paul Collins Startup list
[pm32ctrl]
Confirmed=X
Filename=pwr32crtl.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[pm32info]
Confirmed=X
Filename=pm32info.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[pmc]
Confirmed=X
Filename=764.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[PMedia]
Confirmed=X
Filename=winsrvc.exe
Description=Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!
Source=Paul Collins Startup list
[PmProxy]
Confirmed=?
Filename=PmProxy.exe
Description=Associated with Analog Devices "SoundMAX" audio chipset - often built-in to motherboards. What does it do and is it required?
Source=Paul Collins Startup list
[pmr]
Confirmed=X
Filename=pmr.exe
Description=Powerstrip foistware variant
Source=Paul Collins Startup list
[PMTSHOOT]
Confirmed=N
Filename=pmtshoot.exe
Description=MS tool for troubleshooting power management problems
Source=Paul Collins Startup list
[PMXInit]
Confirmed=U
Filename=pmxinit.exe
Description=Restores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gamma
Source=Paul Collins Startup list
[PNAgent]
Confirmed=N
Filename=PNAgent.exe
Description=PhatNoise Music Manager - manages WMA, MP3, WAV, etc music files
Source=Paul Collins Startup list
[Pnpchk]
Confirmed=U
Filename=Pnpchk.exe
Description=Aztech Labs Sound 3 PnP driver
Source=Paul Collins Startup list
[pnpsvc_lock]
Confirmed=X
Filename=******.exe [* = random digit]
Description=Browser hijacker
Source=Paul Collins Startup list
[pnpsvc_lock]
Confirmed=X
Filename=startsvs.exe
Description=Browser hijacker
Source=Paul Collins Startup list
[PNSetup]
Confirmed=U
Filename=PNSetup.exe
Description=PopNot - pop-up killer
Source=Paul Collins Startup list
[PNtask Services]
Confirmed=X
Filename=pntask.exe
Description=Added by the LALA.C TROJAN!
Source=Paul Collins Startup list
[Pocket Sheet Sync]
Confirmed=U
Filename=PSXLTRAY.EXE
Description=Casio Pocket Sheet synchronization software
Source=Paul Collins Startup list
[Poet]
Confirmed=X
Filename=Poet.exe
Description=Added by the DOEP.A WORM!
Source=Paul Collins Startup list
[Pofatch]
Confirmed=X
Filename=nstrue.exe
Description=Added by the RANDEX.Z WORM!
Source=Paul Collins Startup list
[point32]
Confirmed=U
Filename=point32.exe
Description=Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[POINTER]
Confirmed=U
Filename=point32.exe
Description=Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Points Manager]
Confirmed=N
Filename=points manager.exe
Description=Altnet Points Manager - manages the new Kazaa Plus scheme for awarding you points if you share music files on your machine with others rather than simply getting files and not sharing their own. Start manually when required
Source=Paul Collins Startup list
[POP]
Confirmed=X
Filename=PopSrv***.exe
Description=PeopleonPage foistware, bundled with Grokster where *** are random digits
Source=Paul Collins Startup list
[Pop-Up Smasher]
Confirmed=U
Filename=PopupSmasher.exe
Description=Pop-Up Smasher - pop-up killer
Source=Paul Collins Startup list
[Pop-Up Stopper]
Confirmed=U
Filename=dpps2.exe
Description=Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Source=Paul Collins Startup list
[Pop-Up_Blocker]
Confirmed=U
Filename=Popup.exe
Description=A Tweak-XP component, blocks advertisement pop-up windows in Internet Explorer. Can be enabled/disabled via Tweak-XP -> Internet Tweaks
Source=Paul Collins Startup list
[Pop-Up_Scanner]
Confirmed=U
Filename=Popupscn.exe
Description=Panicware popup blocker
Source=Paul Collins Startup list
[pop3trap.exe]
Confirmed=Y
Filename=pop3trap.exe
Description=PC-Cillin 2000 antivirus software -> E-mail scanner
Source=Paul Collins Startup list
[PopNot]
Confirmed=U
Filename=PopNot.exe
Description=PopNot - pop-up killer
Source=Paul Collins Startup list
[PopOops]
Confirmed=U
Filename=PopOops.exe
Description=PopOops - pop-up killer
Source=Paul Collins Startup list
[Popopen]
Confirmed=U
Filename=popopen.exe
Description=PopOpen makes your windows spring open with animation effects
Source=Paul Collins Startup list
[Poproxy]
Confirmed=Y
Filename=POPROXY.EXE
Description=Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it
Source=Paul Collins Startup list
[popsrv146]
Confirmed=X
Filename=popsrv146.exe
Description=PeopleOnPage online dating browser enhancement - also adware and privacy issues, see here. For removal instructions see here
Source=Paul Collins Startup list
[PopSubtract]
Confirmed=U
Filename=PopSub.exe
Description=PopSubtract - pop-up killer
Source=Paul Collins Startup list
[Popup Ad Filter]
Confirmed=U
Filename=PopFilter.exe
Description=Popup Ad Filter - pop-up killer
Source=Paul Collins Startup list
[Popup Blocker Updater]
Confirmed=X
Filename=regsvr32 veev****.dll [**** = random char]
Description=SafeguardProtect/Veevo hijacker
Source=Paul Collins Startup list
[Popup Defence Updater]
Confirmed=X
Filename=regsvr32 /s [path] pdf****.dll [* = random char/digit]
Description=SafeguardProtect/Veevo hijacker
Source=Paul Collins Startup list
[Popup Defender]
Confirmed=U
Filename=PD.exe
Description=Popup Defender - pop-up killer
Source=Paul Collins Startup list
[Popup Terminator]
Confirmed=U
Filename=GLADManager.exe
Description=Popup Terminator - pop-up killer
Source=Paul Collins Startup list
[PopupEliminator]
Confirmed=U
Filename=Popup Eliminator.exe
Description=Popup Eliminator - pop-up killer
Source=Paul Collins Startup list
[PopUpKiller]
Confirmed=U
Filename=PopUpKiller.exe
Description=PopUpKiller - pop-up killer
Source=Paul Collins Startup list
[PopUpStopperCompanion]
Confirmed=U
Filename=PSComp.exe
Description=PopupStopper Companion popup blocker
Source=Paul Collins Startup list
[PopUpStopperFreeEdition]
Confirmed=U
Filename=PSFREE.EXE
Description=Panicware's Pop-Up Stopper - free limited features version
Source=Paul Collins Startup list
[PopUpStopperProfessional]
Confirmed=U
Filename=PopUpStopperProfessional.exe
Description=Panicware's Pop-Up Stopper - paid for version
Source=Paul Collins Startup list
[PopupVanish]
Confirmed=U
Filename=PopupVanish.exe
Description=Pop-up blocker
Source=Paul Collins Startup list
[PopUpWasher]
Confirmed=U
Filename=PopUpWasher.exe
Description=PopUpWasher pop-up killer
Source=Paul Collins Startup list
[PopUpWatch]
Confirmed=U
Filename=PopUpWatch.exe
Description=Part of BPS Trace Remover - made by the folks who "developed" BPS Spyware Remover which reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!
Source=Paul Collins Startup list
[POS-Partnerbatchprocessor]
Confirmed=?
Filename=BATCH.EXE
Description=VISA credit card batch processing related to Appcon. Is it needed or can it be started manually via Start -> Programs or a manually created shortcut?
Source=Paul Collins Startup list
[Post-It(r) Software]
Confirmed=N
Filename=Psnotes.exe
Description=Pop-up "yellow" notes on screen. Available via Start -> Programs
Source=Paul Collins Startup list
[POW!]
Confirmed=U
Filename=pow.exe
Description=Pop-up killer
Source=Paul Collins Startup list
[Power Scan]
Confirmed=X
Filename=powerscan.exe
Description=Foistware by Integrated Search Technologies - the people behind the ISTbar parasite
Source=Paul Collins Startup list
[PowerBar]
Confirmed=N
Filename=Powerbar.exe
Description=Part of CyberLink's PowerDVD software. Not sure what exactly it does, but not required in startup
Source=Paul Collins Startup list
[PowerChute]
Confirmed=Y
Filename=Pwrchute.exe
Description="During a power outage, if you're not available to save your files & close down Windows....PowerChute will do that for you. PowerChute will save your application files, close your applications and shut down your computer just like you would...otherwise, the APC UPS (Uninterruptible Power Supply) unit would go to battery until it wore down, then your computer would shutoff"
Source=Paul Collins Startup list
[PowerDOCSAPIHost]
Confirmed=U
Filename=papihost.exe
Description=Hummingbird PowerDOCS - "delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"
Source=Paul Collins Startup list
[PowerDVD]
Confirmed=N
Filename=PowerDVD.exe
Description=Launches Cyberlink's PowerDVD software and creates a system tray icon. If enabled, PowerDVD will open automatically when a DVD movie is inserted. Launch manually
Source=Paul Collins Startup list
[PowerKey]
Confirmed=U
Filename=PowerKey.exe
Description=Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[PowerManagement]
Confirmed=X
Filename=Rundlll.exe
Description=Added by the SURDUX TROJAN!
Source=Paul Collins Startup list
[PowerManager]
Confirmed=X
Filename=Svchost.exe
Description=Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[PowerPanel]
Confirmed=Y
Filename=POWPANEL.EXE
Description=Power management utility on notebooks/laptops - automatically switches modes when running on battery
Source=Paul Collins Startup list
[PowerPrifile]
Confirmed=X
Filename=rundl132 kenel.dll, PowerProfileEnable
Description=Added by the INMOTA WORM!
Source=Paul Collins Startup list
[PowerPro]
Confirmed=U
Filename=powerpro.exe
Description=Part of the power professional program that loads the floating menu bar. Can be accessed from Start -> Programs, but I'd leave it alone if you use this program
Source=Paul Collins Startup list
[PowerProf]
Confirmed=X
Filename=PowerProf.exe
Description=Added by the LOREX.B TROJAN!
Source=Paul Collins Startup list
[PowerQuest Startup Utility]
Confirmed=N
Filename=PQINIT.EXE
Description=From a visitor - "This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up, it does nothing (except waste bytes and cycles). I disabled it using msconfig.exe with no problems"
Source=Paul Collins Startup list
[PowerReg Scheduler]
Confirmed=N
Filename=PowerReg Scheduler.exe
Description=PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others
Source=Paul Collins Startup list
[PowerReg SchedulerV2]
Confirmed=N
Filename=PowerReg SchedulerV2.exe
Description=PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others
Source=Paul Collins Startup list
[PowerReg SchedulerV3]
Confirmed=N
Filename=PowerReg SchedulerV3.exe
Description=PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others
Source=Paul Collins Startup list
[POWERR~1]
Confirmed=?
Filename=POWERR~1.exe
Description=Power monitoring?
Source=Paul Collins Startup list
[PowerS]
Confirmed=?
Filename=PowerS.exe
Description=ProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required?
Source=Paul Collins Startup list
[PowerSet]
Confirmed=?
Filename=Regedit.exe /s ...PowerSet_8100_CU.REG
Description=Appears to be Toshiba power management related
Source=Paul Collins Startup list
[PowerStrip]
Confirmed=N
Filename=powerstrip.exe
Description=PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings
Source=Paul Collins Startup list
[PowerStrip]
Confirmed=N
Filename=PSTRIP.EXE
Description=PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings
Source=Paul Collins Startup list
[PowerTools Tray Icon]
Confirmed=U
Filename=pttray.exe
Description=PowerTools - add-on for AOL
Source=Paul Collins Startup list
[Powertweak]
Confirmed=U
Filename=PT2.EXE
Description="Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured." This item is added to startup if 'Use predefined settings' is enabled in the programs options
Source=Paul Collins Startup list
[Powertweak]
Confirmed=U
Filename=PTCTRL.EXE
Description="Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured." This item is added to startup if 'Configure system at logon' is enabled in the programs options
Source=Paul Collins Startup list
[Power_Gear]
Confirmed=U
Filename=BatteryLife.exe
Description=Power management for all Asus notebook. Useful but not critical
Source=Paul Collins Startup list
[PP****usb]
Confirmed=N
Filename=FBDirect.exe
Description=Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[PP2000 Instaupdate]
Confirmed=U
Filename=PPInupdt.exe
Description=Protector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
Source=Paul Collins Startup list
[PP2000 Real Time Scan]
Confirmed=Y
Filename=PPVstop.exe
Description=Protector Plus anti-virus software - real time scanner
Source=Paul Collins Startup list
[PP2000 Taskbar Control]
Confirmed=Y
Filename=PPTbc.exe
Description=Protector Plus anti-virus software - system tray access
Source=Paul Collins Startup list
[PP3100b]
Confirmed=N
Filename=flatbed.exe
Description=Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop
Source=Paul Collins Startup list
[ppass]
Confirmed=U
Filename=Antispy.exe
Description=AntiSpy firewall - "program designed to combat against various types of intrusion and monitoring programs currently in use or presently being developed worldwide"
Source=Paul Collins Startup list
[PPControl]
Confirmed=U
Filename=PPControl.exe
Description=PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
Source=Paul Collins Startup list
[PPK Setup(Server)]
Confirmed=U
Filename=SEServe.exe
Description=Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended"
Source=Paul Collins Startup list
[PPMemCheck]
Confirmed=U
Filename=ppmemcheck.exe
Description=PPMemCheck - "extends PestPatrol's power so that the most dangerous Pests -- those that are about to execute -- are found, terminated, and cleaned from a user's system"
Source=Paul Collins Startup list
[PProTray]
Confirmed=N
Filename=pprotray.exe
Description=Part of the power professional program. Loads the System Tray control
Source=Paul Collins Startup list
[pptd40nt]
Confirmed=N
Filename=pptd40nt.exe
Description="PaperPort" software associated with scanners
Source=Paul Collins Startup list
[PPUpdate]
Confirmed=U
Filename=ppupdater.exe
Description=PPUpdater - "is the update program that ships with PestPatrol. It is able to update licensed and evaluation versions, and presents a visual display of what it is doing". Run manually unless you think you'll forget to check for updates on a regular basis
Source=Paul Collins Startup list
[PPWWebCap]
Confirmed=N
Filename=PPWebCap.exe
Description="PaperPort" software associated with scanners
Source=Paul Collins Startup list
[pqhelper]
Confirmed=X
Filename=pqhelper.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[PractiSearch]
Confirmed=U
Filename=PSearch.exe
Description=PractiSearch web search software
Source=Paul Collins Startup list
[Praize Messenger]
Confirmed=U
Filename=itLoad.exe
Description=Praize IM Christian chat instant messenger
Source=Paul Collins Startup list
[Prayer]
Confirmed=U
Filename=PTW.EXE
Description=Islamic Adhan program (call fpr daily prayers)
Source=Paul Collins Startup list
[prdtect]
Confirmed=X
Filename=prdtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[PreAnnotate]
Confirmed=?
Filename=PreAnntt.exe
Description=Genius Wizard Pen Tablet driver related. Is it required?
Source=Paul Collins Startup list
[Precision Time Clock Checker]
Confirmed=N
Filename=PrecisionTime.exe
Description=Precision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time
Source=Paul Collins Startup list
[precpop2]
Confirmed=X
Filename=starter.exe
Description=PrecisionPop adware
Source=Paul Collins Startup list
[Prein]
Confirmed=X
Filename=APP****.tmp [* = random char or digit]
Description=Unidentified adware
Source=Paul Collins Startup list
[Preload]
Confirmed=Y
Filename=Preload.exe
Description=Millenium Multi-Function Keyboard driver
Source=Paul Collins Startup list
[PreloadApp]
Confirmed=?
Filename=hphprld.exe
Description=HP Printer driver related?
Source=Paul Collins Startup list
[Premeter]
Confirmed=X
Filename=nrpr.exe
Description=NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
Source=Paul Collins Startup list
[Premeter]
Confirmed=X
Filename=prmt.exe
Description=NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
Source=Paul Collins Startup list
[PrevxHome]
Confirmed=Y
Filename=SAGUI.exe
Description=PrevX Home intrusion prevention software
Source=Paul Collins Startup list
[prgtect]
Confirmed=X
Filename=prgtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth!
Source=Paul Collins Startup list
[Price Patrol]
Confirmed=N
Filename=neo.exe
Description=Price Patrol by Half.com - internet shopping companion for finding the best on-line prices
Source=Paul Collins Startup list
[PrimaLauncher]
Confirmed=?
Filename=Launcher.exe
Description=Associated with PrimaScan scanners. Is it required?
Source=Paul Collins Startup list
[Primax 3D Mouse]
Confirmed=U
Filename=3dmoused.exe
Description=Enables the scroll button on the Primax 3-D Scroll mouse
Source=Paul Collins Startup list
[Primsta]
Confirmed=?
Filename=Primsta.exe
Description=Linksys Wireless CompactFlash Card driver related. Is it required?
Source=Paul Collins Startup list
[Print Driver Helper Service]
Confirmed=X
Filename=crsrr.exe
Description=Added by the AGENT-BC TROJAN!
Source=Paul Collins Startup list
[Print Master Event Reminder]
Confirmed=N
Filename=PMremind.exe
Description=Print Master Gold - calander feature that pops up reminders, such as birthdays
Source=Paul Collins Startup list
[Print Screen Deluxe]
Confirmed=N
Filename=psdeluxe.exe
Description=Utility allows "Print Scrn" or "Print Screen" key to capture, print or save the current window
Source=Paul Collins Startup list
[print sharing]
Confirmed=X
Filename=start.bat
Description=Added by the ZCREW TROJAN!
Source=Paul Collins Startup list
[print sharing]
Confirmed=X
Filename=[path] hidden32.exe [path] explorer.exe
Description=Added by the ZCREW.B TROJAN! Note - this is not the valid Windows Explorer (explorer.exe)
Source=Paul Collins Startup list
[Print Spooler]
Confirmed=X
Filename=Spoolsv.exe
Description=Added by the CIADOOR.B TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
Source=Paul Collins Startup list
[Print Spooler]
Confirmed=X
Filename=spoolsvc32.exe
Description=Added by the SDBOT.BB TROJAN!
Source=Paul Collins Startup list
[Print Spooler]
Confirmed=X
Filename=spools.exe
Description=Added by the RBOT-LD WORM!
Source=Paul Collins Startup list
[Printer]
Confirmed=X
Filename=Spyassault.exe
Description=Dubious "spyware killer" - see here. To be avoided
Source=Paul Collins Startup list
[Printer]
Confirmed=N
Filename=[path to file]
Description=Added by the LOWTAPER TROJAN!
Source=Paul Collins Startup list
[Printer]
Confirmed=X
Filename=dipset.exe
Description=Added by a variant of the FBSR TROJAN!
Source=Paul Collins Startup list
[Printer spool Service]
Confirmed=X
Filename=spool.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Printer Update]
Confirmed=?
Filename=CFGREG.EXE
Description=Maybe a registration reminder or automatically updates drivers or application software for a printer?
Source=Paul Collins Startup list
[PrinterSpool]
Confirmed=X
Filename=[path] RESTORE.EXE [path] SPOOL.EXE
Description=Added by the ALADINZ.K TROJAN!
Source=Paul Collins Startup list
[Printkey2000]
Confirmed=N
Filename=printkey2000.exe
Description=Screen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
Source=Paul Collins Startup list
[printnow]
Confirmed=N
Filename=printnow.exe
Description=PrintNow - a utility that primarily allows "Print Srceen" or "Alt+Print Screen" screenshots to be sent directly to a printer
Source=Paul Collins Startup list
[PrinTray]
Confirmed=N
Filename=Printray.exe
Description=Lexmark/Compaq printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. See also LexmarkPrintray and CompaqPrinTray
Source=Paul Collins Startup list
[PrintScreen]
Confirmed=N
Filename=UNWISE.EXE
Description=Gadwin PrintScreen - utility to capture, print or save the current window
Source=Paul Collins Startup list
[Printscreen 95]
Confirmed=N
Filename=PRT95MIN.EXE
Description=Printscreen 95 - utility to capture, print or save the current window
Source=Paul Collins Startup list
[PrintSpoolSv]
Confirmed=X
Filename=System.exe
Description=Added by the BDOOR-S TROJAN!
Source=Paul Collins Startup list
[PRISMSTA.EXE]
Confirmed=U
Filename=PRISMSTA.EXE
Description=Creates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
Source=Paul Collins Startup list
[Privacy Eraser Pro]
Confirmed=N
Filename=PrivacyEraser.exe
Description=Privacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities
Source=Paul Collins Startup list
[PrivacyScanner]
Confirmed=X
Filename=pscan.exe
Description=Privacy Champion, a stealth installed 'Privacy Scanner'. It purportedly scans your PC for links to porn websites, and then offers to "clean" them. Produces loads of False Positives as goad to purchase
Source=Paul Collins Startup list
[PrivateNet]
Confirmed=X
Filename=[various filenames]
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[Privoxy]
Confirmed=U
Filename=privoxy.exe
Description=Privoxy - web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk
Source=Paul Collins Startup list
[PrizeSurfer]
Confirmed=X
Filename=prizesurfer.exe
Description="PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware
Source=Paul Collins Startup list
[prjtect]
Confirmed=X
Filename=prjtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prktect]
Confirmed=X
Filename=prktect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prltect]
Confirmed=X
Filename=prltect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prmt]
Confirmed=X
Filename=prmt.exe
Description=NetRatings software by Opistat. "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
Source=Paul Collins Startup list
[prmtect]
Confirmed=X
Filename=prmtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth!
Source=Paul Collins Startup list
[PrnSys Executable]
Confirmed=U
Filename=PrnSys.exe
Description=Print screen utility bundled with some HP printer software - not required, but your choice if you like that feature
Source=Paul Collins Startup list
[Pro PCL Status Monitor]
Confirmed=U
Filename=PENGSS.EXE
Description=Xerox printer/fax/copier status monitor (PCL = printer control language)
Source=Paul Collins Startup list
[ProArt]
Confirmed=?
Filename=ProArt.exe
Description=??
Source=Paul Collins Startup list
[ProcessGovernor]
Confirmed=U
Filename=processgovernor.exe
Description=Process Supervisor "is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions"
Source=Paul Collins Startup list
[ProcessSupervisorGUI]
Confirmed=U
Filename=ProcessSupervisor.exe
Description=Process Supervisor "is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions"
Source=Paul Collins Startup list
[procmon]
Confirmed=X
Filename=procmon.exe
Description=Added by the BIONET.40A TROJAN!
Source=Paul Collins Startup list
[ProdikeysAutorun]
Confirmed=N
Filename=Prodload.exe
Description=Creative Prodikeys software. "an interactive music entertainment device which not only functions as a full-featured, ergonomic “QWERTY” keyboard but also comes equipped with 37 touch-sensitive music keys and accessible music controls for endless entertainment at your desktop. Coupled with the Sound Blaster audio card, you can explore a wide array of realistic instrument sounds and have non-stop fun making music right at your desktop"
Source=Paul Collins Startup list
[ProDsl]
Confirmed=N
Filename=ProDsl.exe
Description=Intel Pro/DSL 2100 modem connection manager. Available via Start -> Programs
Source=Paul Collins Startup list
[Profile]
Confirmed=X
Filename=Profile.vbs
Description=Added by the WHITEHO VIRUS or TRAPPY WORM!
Source=Paul Collins Startup list
[Profiler]
Confirmed=N
Filename=Profiler.exe
Description=Enables the "Profiler" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs
Source=Paul Collins Startup list
[Prog]
Confirmed=X
Filename=csrss.exe
Description=Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Prog]
Confirmed=X
Filename=lsass.exe
Description=Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Program File]
Confirmed=X
Filename=Progmon.exe
Description=Added by the PEEPER TROJAN!
Source=Paul Collins Startup list
[Program in Windows]
Confirmed=X
Filename=iexplore.exe
Description=Added by a variant of the LOVGATE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[ProgramWindow]
Confirmed=?
Filename=more comp.exe
Description=??
Source=Paul Collins Startup list
[projselector]
Confirmed=N
Filename=projselector.exe
Description=Roxio Project Selector - can be started manually
Source=Paul Collins Startup list
[Promon.exe]
Confirmed=N
Filename=promon.exe
Description=System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
Source=Paul Collins Startup list
[PromulGate]
Confirmed=X
Filename=PgMonitr.exe
Description=Delfin Promulgate adware variant
Source=Paul Collins Startup list
[PRONoMgr.exe]
Confirmed=N
Filename=PRONoMgr.exe
Description=System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
Source=Paul Collins Startup list
[PRONoMgrWired]
Confirmed=U
Filename=PRONoMgr.exe
Description=Intel’s Pro 100 Ethernet card manager
Source=Paul Collins Startup list
[Propel Accelerator]
Confirmed=U
Filename=PropelAC.exe
Description=Propel Internet Accelerator
Source=Paul Collins Startup list
[ProPort Startup]
Confirmed=U
Filename=ProPort.exe
Description=Proport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill, and IP resolving
Source=Paul Collins Startup list
[Protected Storage]
Confirmed=X
Filename=RUNDLL32.EXE MSSIGN30.DLL ondll_reg
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Protection]
Confirmed=X
Filename=[path] runtask.exe [path] protection.exe
Description=Added by a variant of the AGENT.3.AU TROJAN!
Source=Paul Collins Startup list
[Protection]
Confirmed=X
Filename=Protection.exe
Description=Added by the FEBELNECK-A WORM!
Source=Paul Collins Startup list
[PROXOMITRON]
Confirmed=N
Filename=PROXOMITRON.EXE
Description=HTML proxy
Source=Paul Collins Startup list
[PROXOMITRON]
Confirmed=N
Filename=PROXOM~1.EXE
Description=HTML proxy
Source=Paul Collins Startup list
[PRPCMonitor]
Confirmed=U
Filename=PRPCUI.exe
Description=Intel® SpeedStep™ interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power, SpeedStep scales the processor clock frequency and voltage to reduce the power it needs by 40%
Source=Paul Collins Startup list
[prrtect]
Confirmed=X
Filename=prrtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prstect]
Confirmed=X
Filename=prstect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prtcct]
Confirmed=X
Filename=prtcct.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prttect]
Confirmed=X
Filename=prttect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth!
Source=Paul Collins Startup list
[prutcct]
Confirmed=X
Filename=prutcct.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prutdct]
Confirmed=X
Filename=prutdct.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prutgct]
Confirmed=X
Filename=prutgct.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[pruthct]
Confirmed=X
Filename=pruthct.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prutict]
Confirmed=X
Filename=prutict.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prvtect]
Confirmed=X
Filename=prvtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[prxtect]
Confirmed=X
Filename=prxtect.exe
Description=Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
Source=Paul Collins Startup list
[PS2]
Confirmed=U
Filename=ps2.exe
Description=Multimedia Keyboard companion on HP computers. If this is prevented from starting, then some keyboard functionality will be lost.
Source=Paul Collins Startup list
[PSD Tools Channel]
Confirmed=X
Filename=ChannelUp.exe
Description=BuddyLinks adware
Source=Paul Collins Startup list
[PSDrvCheck]
Confirmed=Y
Filename=PSDrvCheck.exe
Description=Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled
Source=Paul Collins Startup list
[PSFree]
Confirmed=U
Filename=PSFree.exe
Description=Pop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Source=Paul Collins Startup list
[PSIMSVC]
Confirmed=Y
Filename=PSIMSVC.exe
Description=Panda Titanium Antivirus
Source=Paul Collins Startup list
[PSIWin2.3 Connection Server]
Confirmed=N
Filename=Psconsv.exe
Description=Allows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
Source=Paul Collins Startup list
[PsMFCard]
Confirmed=U
Filename=PsMFCard.exe
Description=Component of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue, the user can select from 3 PCMCIA power options - On, Auto1 and Auto2. Disabling this item has no adverse effects, except disabling the ability to reduce power consumption by powering-down the PCMCIA slots when not in use
Source=Paul Collins Startup list
[PSNotify]
Confirmed=Y
Filename=psnotify.exe
Description=Pharos SignUp Vx - "PC reservation and management application that addresses the PC scheduling needs of public libraries and higher education labs and libraries"
Source=Paul Collins Startup list
[PsPCCard]
Confirmed=Y
Filename=PsPCCard.EXE
Description=Background Power Saving task found on Toshiba laptops and which handles turning Power Saving ON and OFF on any inserted PC Card (PCMCIA card). Only ever disable if you do not use any power saving or hibernation settings (ie: they are all OFF)
Source=Paul Collins Startup list
[PspContr]
Confirmed=U
Filename=pspcontr.exe
Description=Driver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driver
Source=Paul Collins Startup list
[PsSound]
Confirmed=U
Filename=PsSound.exe
Description=On a Toshiba laptop. Operates your sound in one of 4 modes, off, on , on only with powerr, same as #3 but longer delay
Source=Paul Collins Startup list
[PSTORES]
Confirmed=?
Filename=PSTORES.EXE
Description=Part of Windows Services Protected Storage?
Source=Paul Collins Startup list
[ptfb]
Confirmed=N
Filename=ptfb.exe
Description=Push the Freakin' Button - "When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future"
Source=Paul Collins Startup list
[ptrun32]
Confirmed=U
Filename=ptrun32.exe
Description=Parent Tools for AIM
Source=Paul Collins Startup list
[Ptsnoop]
Confirmed=N
Filename=Ptsnoop.exe
Description=These descriptions I've come across - all valid as far as I can see :- (1) Program installed with some modems that monitors the COM ports for the modem driver. Not required from what I've read - may need a registry edit to get rid of it (2) Backdoor trojan virus that copies itself as PTSNOOP.EXE -see here for more info(3) Apparently the people who put it out claim it's a driver for a Voice modems (don't know who they are though - Ed) Note: If using AOL and you disable this you may lose your connection or lock up (4) Can also be an older Logitech scanner program. Remove from the Win.ini tab under Load='path'PTSNOOP and the System.ini tab under drivers='path'ptrtkr.drb. Can cause parallel port conflicts big time dragging system resources way down when a conflict exists (5) Allows audio monitoring of modem phone dialling tones and can be useful if you have connection problems (6) Karen Kenworthy's Snooper - "logs the start and stop time of all programs run under Windows"
Source=Paul Collins Startup list
[pttrun]
Confirmed=U
Filename=pttrun.exe
Description=Transmeta Crusoe processor related. Reduces application launch times and makes the computer "more responsive"
Source=Paul Collins Startup list
[PtUDFApp]
Confirmed=N
Filename=PtUDFApp.exe
Description=Sony abCD program, included on the CD Xtreme install CD, used to format CD-RWs for packet writing (similar to DirectCD). Available via Start -> Programs. Note that you must add a /T switch to the command line to get it to load to the taskbar
Source=Paul Collins Startup list
[Pure Networks Port Magic]
Confirmed=N
Filename=PortAOL.exe
Description=Pure Networks Port Magic, as available in the latest version of the AOL® 9.0 Optimized SE software; automatically configures most in-home Internet gateways, improving access and performance for applications such as instant messaging, online gaming, and streaming music and video. See here
Source=Paul Collins Startup list
[Purgative]
Confirmed=U
Filename=PURGATIVE100.EXE
Description=AIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
Source=Paul Collins Startup list
[Push Client]
Confirmed=N
Filename=pull.exe
Description=Client software from Interwise that MS use for their webcasts
Source=Paul Collins Startup list
[Push The Freakin' Button]
Confirmed=N
Filename=ptfb.exe
Description=Push the Freakin' Button - "When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future"
Source=Paul Collins Startup list
[PUSH6599]
Confirmed=N
Filename=PUSH6599.EXE
Description=Scan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning software
Source=Paul Collins Startup list
[PutA!!]
Confirmed=X
Filename=PutA!!.exe
Description=Added by the OPASERV.L WORM!
Source=Paul Collins Startup list
[PutAS!]
Confirmed=X
Filename=PutA!!.com
Description=Added by the OPASERV.Z WORM!
Source=Paul Collins Startup list
[putil]
Confirmed=X
Filename=[filename]
Description=Added by the LDPINCH TROJAN!
Source=Paul Collins Startup list
[PVR]
Confirmed=N
Filename=PVR.exe
Description=Pocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound card
Source=Paul Collins Startup list
[Pwr32ctr]
Confirmed=X
Filename=Pwr32ctr.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Pwr32ctrl]
Confirmed=X
Filename=Pwr32ctrl.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Pwr32mgt]
Confirmed=X
Filename=Pwr32mgt.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Pwrmonit]
Confirmed=Y
Filename=Rundll32 PwrMonit.dll
Description=IBM's proprietary 'battery maximiser' and power monitoring software for laptops
Source=Paul Collins Startup list
[Pwroff]
Confirmed=X
Filename=Pwroff.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Pwrsave]
Confirmed=U
Filename=Pwrsave.exe
Description=Toshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
Source=Paul Collins Startup list
[Pwruplogin]
Confirmed=?
Filename=pulogin.exe
Description=??
Source=Paul Collins Startup list
[PwrupTweakMe]
Confirmed=U
Filename=PUPXPTWK.EXE
Description="Ashampoo PowerUp XP is a convenient tool for fine-tuning your Windows® NT4, 2000 and XP configuration to suit your precise needs and wishes. It gives you direct access to many frequently-required settings and parameters, enabling you to make your operating system behave the way you want." Boot-up options won't work if disabled
Source=Paul Collins Startup list
[PWS Tray]
Confirmed=U
Filename=PwsTray.exe
Description=Microsoft's Personal Web Server, an application which allows PCs to behave as web servers (allows you to test your .asp pages on your own PC without having to load them onto the internet). Available via Start -> Programs
Source=Paul Collins Startup list
[p_981116]
Confirmed=N
Filename=p_981116.exe
Description=Win32 cabinet self extractor. More info here
Source=Paul Collins Startup list
[Q152404]
Confirmed=N
Filename=wsript.exe Q152404.VBS
Description=Appears to run Scandisk at bootup on NEC PCs
Source=Paul Collins Startup list
[q36i36O]
Confirmed=X
Filename=lms2cenu.exe
Description=Added by the SECONDTHOUGHT VIRUS!
Source=Paul Collins Startup list
[QAGENT]
Confirmed=N
Filename=qagent.exe
Description=Quicken program is controlled by a separate utility program called the Quicken Download Manager (also known as Qagent). When Quicken Download Manager option is enabled, background downloading takes advantage of unused bandwidth to download current financial information anytime your computer is connected to the Internet
Source=Paul Collins Startup list
[qappsrvc32.exe]
Confirmed=X
Filename=qappsrvc32.exe
Description=Added by a Proxy Trojan variant - identified by Kaspersky antivirus as Trojan-Proxy.Win32.Webber.m
Source=Paul Collins Startup list
[QBCD autorun]
Confirmed=N
Filename=autorun.exe
Description=Quick Books CD
Source=Paul Collins Startup list
[qbkupdbs]
Confirmed=X
Filename=mqbkup.exe
Description=Added by the OPASERV.K WORM!
Source=Paul Collins Startup list
[qbotd]
Confirmed=X
Filename=[random filename]
Description=Added by the BOTTEN TROJAN!
Source=Paul Collins Startup list
[qBrowse]
Confirmed=?
Filename=qbrowse.exe
Description=??
Source=Paul Collins Startup list
[QBRSR]
Confirmed=X
Filename=QuickBrowser.exe
Description=top-banners.com adware
Source=Paul Collins Startup list
[QCTRAY]
Confirmed=U
Filename=Qctray.exe
Description=System Tray icon providing access to the "IBM Access Connections" wizard on ThinkPad laptops and also allows to change the network environment. Not the same as QCWLIcon, which is pertinent only to the Wireless LAN
Source=Paul Collins Startup list
[QCWLICON]
Confirmed=U
Filename=Qcwlicon.exe
Description=Used by IBM Thinkpad laptops with built-in wireless card (802.11). System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off
Source=Paul Collins Startup list
[QD FastAndSafe]
Confirmed=N
Filename=QDCSFS.exe
Description=Automatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
Source=Paul Collins Startup list
[QDM]
Confirmed=U
Filename=QdmStart.exe
Description=QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc
Source=Paul Collins Startup list
[QDMStart]
Confirmed=U
Filename=QdmStart.exe
Description=QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc
Source=Paul Collins Startup list
[Qdsafe]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[Qexplo]
Confirmed=?
Filename=Qexplo.exe
Description=??
Source=Paul Collins Startup list
[QMusic]
Confirmed=?
Filename=QMAgent.exe
Description=??
Source=Paul Collins Startup list
[QNPlus]
Confirmed=N
Filename=QNPlus.exe
Description=Quick Notes Plus by Conceptworld - sticky notes tool
Source=Paul Collins Startup list
[Qoeloader]
Confirmed=U
Filename=Qoeloader.exe
Description=Qurb 2.0 anti-spam tool for Outlook/Outlook Express. Required when supporting OE but not for Outlook. Shortcut available via Start -> Programs
Source=Paul Collins Startup list
[QQ]
Confirmed=X
Filename=sendmess.exe
Description=Added by the SEMES TROJAN!
Source=Paul Collins Startup list
[QSort2000]
Confirmed=N
Filename=QSORT.EXE
Description=Utility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name"
Source=Paul Collins Startup list
[QT4HPOT]
Confirmed=U
Filename=OneTouch.exe
Description=Hewlett Packard One Touch keyboard driver. Required if you use the additional keys
Source=Paul Collins Startup list
[QTaskStartup]
Confirmed=U
Filename=qtask.exe
Description=Feature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly, it is only required for the Desktop Alerts feature
Source=Paul Collins Startup list
[QTSTUB.EXE]
Confirmed=N
Filename=Qtstub.exe
Description=Part of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders
Source=Paul Collins Startup list
[QTSvc]
Confirmed=X
Filename=msocfg.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[QTSvc]
Confirmed=X
Filename=navchk.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[QTSvc]
Confirmed=X
Filename=shman.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[QTSvc]
Confirmed=X
Filename=ssvr.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[qttask]
Confirmed=N
Filename=Qttask.exe
Description=System Tray access to Apple's "Quick Time" viewer from version 5 onwards
Source=Paul Collins Startup list
[QUBCity]
Confirmed=?
Filename=qtp.exe
Description=??
Source=Paul Collins Startup list
[Queensla]
Confirmed=?
Filename=Queensla.exe
Description=??
Source=Paul Collins Startup list
[Quick Controls]
Confirmed=U
Filename=Astrotoolbar.exe
Description=Gateway Astro Screen and Sound Controls tray icon
Source=Paul Collins Startup list
[Quick Heal On-Line Protection]
Confirmed=Y
Filename=Cateye.exe
Description=Quick Heal - virus scanner
Source=Paul Collins Startup list
[Quick Heal Startup Scan]
Confirmed=Y
Filename=QHSTRT32.EXE
Description=Quick Heal - virus scanner
Source=Paul Collins Startup list
[Quick Shelf xx]
Confirmed=N
Filename=qushelfxx.exe
Description=Places an icon in the system tray for launching MS Bookshelf. Available via Start -> Programs"xx" represents the version number - ie, 98, 99
Source=Paul Collins Startup list
[Quick Startup]
Confirmed=Y
Filename=Fquick32.exe
Description=For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
Source=Paul Collins Startup list
[Quick View Plus]
Confirmed=N
Filename=QVP32.EXE
Description=Quick View Plus from Inso Corporation. Multiple file type viewer. Available via Start -> Programs
Source=Paul Collins Startup list
[QuickBooks Delivery Agent]
Confirmed=N
Filename=QBDAGENT.EXE
Description=As far QAGENT but for QuickBooks. Can also have the version number in the name
Source=Paul Collins Startup list
[Quickbooks Update Agent]
Confirmed=N
Filename=qbupdate.exe
Description=Associated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
Source=Paul Collins Startup list
[QuickCamPro]
Confirmed=U
Filename=QuickCamPro.exe
Description=System Tray for Picture Capture utility that can run unattended. Pictures every 30 seconds for example, auto FTP Upload, etc
Source=Paul Collins Startup list
[quicken]
Confirmed=X
Filename=quicken.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[quicken]
Confirmed=X
Filename=Winrar.exe
Description=CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!
Source=Paul Collins Startup list
[quicken]
Confirmed=X
Filename=Waol.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Quicken Scheduled Updates]
Confirmed=N
Filename=bagent.exe
Description=Quicken background downloading module
Source=Paul Collins Startup list
[Quicken Startup]
Confirmed=N
Filename=QWDLLS.EXE
Description=Quicken option to load DLLs at startup
Source=Paul Collins Startup list
[QuickenSEMessage]
Confirmed=N
Filename=Qsemsg.exe
Description=Quicken option
Source=Paul Collins Startup list
[QuickFinder Scheduler]
Confirmed=N
Filename=QFSCHD100.exe
Description=Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
Source=Paul Collins Startup list
[QuickFinder Scheduler]
Confirmed=N
Filename=QFSched.exe
Description=Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
Source=Paul Collins Startup list
[QuickLaunchEr]
Confirmed=Y
Filename=QuickLaunchEr.Exe
Description=QuickLaunchEr - allows you to quickly launch programs from an icon in the system tray
Source=Paul Collins Startup list
[Quicklink III]
Confirmed=N
Filename=QL.EXE
Description=HP fax program and only needs to be in the start-up group if you allow your phone to automatically answer your phone in fax mode, that is, to receive faxes after a certain number of rings. Available via Start -> Programs
Source=Paul Collins Startup list
[Quicknote]
Confirmed=N
Filename=quicknote.exe
Description=JC&MB Quicknote Virtual Scrapbook
Source=Paul Collins Startup list
[QuickPassword]
Confirmed=U
Filename=agquickp.exe
Description=Smart card-based authentication and digital signature client software
Source=Paul Collins Startup list
[QuickRes]
Confirmed=N
Filename=QUICKRES.EXE
Description=Utility to quickly change desktop resolution - left over from Win95 Power Toys. In Win98 and above incorporated via Control Panel -> Display. Not required unless you have to change resolutions on a regular basis
Source=Paul Collins Startup list
[quickset]
Confirmed=N
Filename=quickset.exe
Description=Dell taskbar icon allowing you to quickly change settings
Source=Paul Collins Startup list
[Quicktime Mediaplayer]
Confirmed=X
Filename=winmplyer32.exe
Description=Added by the RBOT-PM WORM!
Source=Paul Collins Startup list
[Quicktime Pro 3.0]
Confirmed=X
Filename=winuodps.exe
Description=Added by the GAOBOT.BH WORM!
Source=Paul Collins Startup list
[QuickTime Task]
Confirmed=N
Filename=Qttask.exe
Description=System Tray access to Apple's "Quick Time" viewer from version 5 onwards
Source=Paul Collins Startup list
[QuickTime Task]
Confirmed=X
Filename=qttasks.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[QuickTime Update Completion x]
Confirmed=N
Filename=quicktimeupdatehelper.exe
Description=Different numbers caused by number of launches. So if 3 updates are made separately, 3 would appear (in theory)
Source=Paul Collins Startup list
[QuicktimeMngr]
Confirmed=X
Filename=QUICKTIMEMNGR.EXE
Description=Added by the WOOTBOT.AW WORM!
Source=Paul Collins Startup list
[Quicktlme]
Confirmed=X
Filename=ru.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[QuickTV]
Confirmed=U
Filename=QuickTV.exe
Description=Infra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control
Source=Paul Collins Startup list
[Quickzip]
Confirmed=X
Filename=Ls.exe
Description=MsConnect browser hijacker and dialler
Source=Paul Collins Startup list
[QuickZip]
Confirmed=X
Filename=lu.exe
Description=MsConnect browser hijacker and dialler
Source=Paul Collins Startup list
[QuikShield]
Confirmed=N
Filename=qkshield.exe
Description=QuikShield popup blocker - reportedly stealth installed, see here
Source=Paul Collins Startup list
[QuikSync]
Confirmed=N
Filename=QUIKSYNC.EXE
Description=Used by Iomega drives. Available via Start -> Programs
Source=Paul Collins Startup list
[QWERTY]
Confirmed=?
Filename=qwerty.exe
Description=Possibly adult content related adware
Source=Paul Collins Startup list
[QWS3270 Sessions]
Confirmed=U
Filename=sessions.exe
Description=QWS3270 Secure terminal emulation software
Source=Paul Collins Startup list
[RA Server]
Confirmed=X
Filename=Slave.exe
Description=Added by the RA TROJAN!
Source=Paul Collins Startup list
[RabbitWannaHome]
Confirmed=X
Filename=rabbit.exe
Description=Added by the MIMAIL.S WORM!
Source=Paul Collins Startup list
[Rabo Session Monitor]
Confirmed=Y
Filename=RaboSessionMon.exe
Description=Related to RaboBank electronic banking software
Source=Paul Collins Startup list
[RadarSync]
Confirmed=N
Filename=RadarSync.exe
Description=Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically
Source=Paul Collins Startup list
[RadBoot]
Confirmed=U
Filename=RadBoot.exe
Description=RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings
Source=Paul Collins Startup list
[RadioSvr]
Confirmed=U
Filename=RadioSvr.EXE
Description=Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network
Source=Paul Collins Startup list
[RAMASST]
Confirmed=U
Filename=RAMASST.exe
Description=Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs
Source=Paul Collins Startup list
[RamBooster2]
Confirmed=X
Filename=rb.exe
Description=Added by the AKAK TROJAN!
Source=Paul Collins Startup list
[RAMDef]
Confirmed=U
Filename=ramdef.exe
Description=Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind
Source=Paul Collins Startup list
[RamIdle]
Confirmed=U
Filename=ramidle.exe
Description=RAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." Some users swear by programs such as this but I suggest you read this article and make up your own mind
Source=Paul Collins Startup list
[RAMpage]
Confirmed=U
Filename=RAMpage.exe
Description=Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source
Source=Paul Collins Startup list
[Randex virus built for IRBMe]
Confirmed=X
Filename=irbme.exe
Description=Added by the RANDEX.RH WORM!
Source=Paul Collins Startup list
[RandomWin32]
Confirmed=X
Filename=mgnwin32.exe
Description=Added by the SDBOT-DV WORM!
Source=Paul Collins Startup list
[RapApp]
Confirmed=Y
Filename=RAPAPP.EXE
Description=Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch
Source=Paul Collins Startup list
[Rapid Restore]
Confirmed=U
Filename=rrpcsb.exe
Description=XPoint "Rapid Restore PC" - a "Managed Recovery™ solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user"
Source=Paul Collins Startup list
[RapidBlaster]
Confirmed=X
Filename=rb32.exe
Description=Homepage hijacker (adult content) - see this newsgroup thread
Source=Paul Collins Startup list
[Raptor Mobile]
Confirmed=Y
Filename=vpnservices.exe
Description=Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking
Source=Paul Collins Startup list
[RasCon Remote Access Service Manager]
Confirmed=X
Filename=rasmngr.exe
Description=Added by the SPYBOT.EM WORM!
Source=Paul Collins Startup list
[Rase]
Confirmed=X
Filename=boln.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[rate.exe]
Confirmed=X
Filename=i11r54n4.exe
Description=Added by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS!
Source=Paul Collins Startup list
[rate.exe]
Confirmed=X
Filename=********.exe [* = random char]
Description=Unidentified adware
Source=Paul Collins Startup list
[RAV8Tray]
Confirmed=Y
Filename=ravtray8.exe
Description=RAV anti-virus related
Source=Paul Collins Startup list
[RAVEN_VLZS.EXE]
Confirmed=X
Filename=RAVEN_VLZS.EXE
Description=Another eAcceleration program - spyware. Read their privacy statement here
Source=Paul Collins Startup list
[RavMon]
Confirmed=Y
Filename=RavMon.exe
Description=RAV AntiVirus
Source=Paul Collins Startup list
[RavTime]
Confirmed=X
Filename=Mstray.exe
Description=Added by the WUKILL.A WORM!
Source=Paul Collins Startup list
[RavTimer]
Confirmed=X
Filename=RavTimer.exe
Description=RAV AntiVirus
Source=Paul Collins Startup list
[RavTimeXP]
Confirmed=X
Filename=[worm filename]
Description=Added by the WULLIK.B WORM!
Source=Paul Collins Startup list
[RavTimXP]
Confirmed=X
Filename=[worm filename]
Description=Added by the WULLIK.B WORM!
Source=Paul Collins Startup list
[rav_temp.exe]
Confirmed=?
Filename=rav_temp.exe
Description=??
Source=Paul Collins Startup list
[Ray Process Killer]
Confirmed=N
Filename=Prkill.exe
Description=Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead
Source=Paul Collins Startup list
[rb32 lptt01]
Confirmed=X
Filename=rb32.exe
Description=Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[rb32 ml097e]
Confirmed=X
Filename=rb32.exe
Description=Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[rbenh ml***e]
Confirmed=X
Filename=rbenh.exe
Description=Variant of the RapidBlaster parasite (in a "RBEnhance" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Rcf Driver]
Confirmed=X
Filename=rcf.exe
Description=Added by the RANDEX.BLD WORM!
Source=Paul Collins Startup list
[RCScheduleCheck]
Confirmed=U
Filename=RCSCHED.EXE
Description=Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"
Source=Paul Collins Startup list
[RCSync]
Confirmed=X
Filename=RCSync.exe
Description=PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware
Source=Paul Collins Startup list
[RDClient]
Confirmed=U
Filename=RDCLIENT.EXE
Description=Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection
Source=Paul Collins Startup list
[RDLL]
Confirmed=X
Filename=RunDll16.exe
Description=Added by the SDBOT.F TROJAN!
Source=Paul Collins Startup list
[rdvs]
Confirmed=X
Filename=[worm filename]
Description=Added by the ULTIMAX WORM!
Source=Paul Collins Startup list
[Reactor3]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.A WORM!
Source=Paul Collins Startup list
[Reactor5]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.D WORM!
Source=Paul Collins Startup list
[Reactor6]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.C WORM!
Source=Paul Collins Startup list
[Reactor7]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.B WORM!
Source=Paul Collins Startup list
[Reactor8]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.E WORM!
Source=Paul Collins Startup list
[Reactor9]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.E WORM!
Source=Paul Collins Startup list
[readdb40]
Confirmed=X
Filename=rundll32.exe [path] readdb40.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[Real Internet Player]
Confirmed=X
Filename=Reaiplay.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Real player updater]
Confirmed=X
Filename=realupd.exe
Description=Added by the PARLAY TROJAN!
Source=Paul Collins Startup list
[Real-Tens]
Confirmed=X
Filename=Real-Tens.exe
Description=DownloadWare based advetising spyware
Source=Paul Collins Startup list
[RealAudio]
Confirmed=X
Filename=RealAudio.exe
Description=Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player
Source=Paul Collins Startup list
[RealDownload]
Confirmed=N
Filename=RealPlay.exe
Description=Download manager. Available via Start -> Programs
Source=Paul Collins Startup list
[RealDownload Express]
Confirmed=X
Filename=npnzdad.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[Reality Fusion GameCam SE]
Confirmed=N
Filename=RFTRay.exe
Description=System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs
Source=Paul Collins Startup list
[RealJukeboxSystray]
Confirmed=N
Filename=tsystray.exe
Description=System Tray icon for RealJukebox
Source=Paul Collins Startup list
[realone_nt2003]
Confirmed=X
Filename=moniker.exe
Description=Added by the SNONE.A WORM!
Source=Paul Collins Startup list
[realplay lptt01]
Confirmed=X
Filename=realplay.exe
Description=Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name
Source=Paul Collins Startup list
[realplay ml097e]
Confirmed=X
Filename=realplay.exe
Description=Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name
Source=Paul Collins Startup list
[Realplayer One]
Confirmed=X
Filename=realplay.exe
Description=Added by the RBOT-NK WORM!
Source=Paul Collins Startup list
[Realpopup]
Confirmed=?
Filename=Realpopup.exe
Description=RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor"
Source=Paul Collins Startup list
[Realsched]
Confirmed=N
Filename=realsched.exe
Description=Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry
Source=Paul Collins Startup list
[Realtime Audio Engine]
Confirmed=?
Filename=mmrtkrnl.exe
Description=??
Source=Paul Collins Startup list
[Realtime Monitor]
Confirmed=Y
Filename=realmon.exe
Description=Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates
Source=Paul Collins Startup list
[RealTimeUpdate]
Confirmed=?
Filename=RealTimeUpdate.exe
Description=Product description in properties is "InternetExplorerCommunicationAgent Module" ?
Source=Paul Collins Startup list
[RealTray]
Confirmed=N
Filename=RealPlay.exe
Description=System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
Source=Paul Collins Startup list
[RealUpdater]
Confirmed=X
Filename=realupd.exe
Description=Added by the PARLAY or MITGLIEDER.I TROJANS!
Source=Paul Collins Startup list
[Reboot]
Confirmed=N
Filename=Reboot.exe
Description=MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
Source=Paul Collins Startup list
[Recguard]
Confirmed=Y
Filename=recguard.exe
Description=On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense
Source=Paul Collins Startup list
[Reclip]
Confirmed=N
Filename=reclip.exe
Description=Reclip Popup Clipboard manager
Source=Paul Collins Startup list
[Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}]
Confirmed=X
Filename=RH.DLL
Description=SmartPops adware
Source=Paul Collins Startup list
[Recover]
Confirmed=N
Filename=N/A
Description=Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
Source=Paul Collins Startup list
[RecoverFromReboo]
Confirmed=?
Filename=RECOVE~1.EXE
Description=??
Source=Paul Collins Startup list
[RecoverFromReboo]
Confirmed=?
Filename=RecoverFromReboot.exe
Description=??
Source=Paul Collins Startup list
[RecoverFromReboot]
Confirmed=?
Filename=RECOVE~1.EXE
Description=??
Source=Paul Collins Startup list
[RecoverFromReboot]
Confirmed=?
Filename=RecoverFromReboot.exe
Description=??
Source=Paul Collins Startup list
[RecShe]
Confirmed=N
Filename=RecSche.exe
Description=Recording scheduler for WatchTV Capture Card (TV Tuner card)
Source=Paul Collins Startup list
[RecycleSTR]
Confirmed=X
Filename=msreg32.exe
Description=Added by the RBOT-TC WORM!
Source=Paul Collins Startup list
[Red Flag]
Confirmed=N
Filename=redflag.exe
Description=PMS prediction program with modes for guys and girls - no longer available
Source=Paul Collins Startup list
[Red Swoosh EDN Client]
Confirmed=X
Filename=RSEDNClient.exe
Description=Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network
Source=Paul Collins Startup list
[redirect]
Confirmed=X
Filename=redirect*.exe
Description=Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit
Source=Paul Collins Startup list
[Redline Taskbar]
Confirmed=N
Filename=taskbar.exe
Description=Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
Source=Paul Collins Startup list
[REEGRUN]
Confirmed=X
Filename=[path to file]
Description=Added by the SECDROP.AI TROJAN
Source=Paul Collins Startup list
[Referee]
Confirmed=U
Filename=referee.exe
Description=MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run
Source=Paul Collins Startup list
[Refresh]
Confirmed=N
Filename=Refresh.exe
Description=(Iomega) Refresh - loads the Iomega desktop icons at startup
Source=Paul Collins Startup list
[Reg]
Confirmed=X
Filename=Reg.hta
Description=Homepage hi-jacker. Removal instructions here
Source=Paul Collins Startup list
[Reg Check]
Confirmed=?
Filename=lpt.exe
Description=Related to Supanet ISP software - what does it do and is it required?
Source=Paul Collins Startup list
[Reg Service]
Confirmed=X
Filename=winsy.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Reg Services]
Confirmed=X
Filename=Winboot32.exe
Description=Added by the RBOT.PB WORM!
Source=Paul Collins Startup list
[reg1.reg]
Confirmed=X
Filename=vuamgard.exe
Description=Added by a variant of the IRC.BOT TROJAN!
Source=Paul Collins Startup list
[Reg32]
Confirmed=X
Filename=Reg32.exe
Description=Hijacker - redirecting to only-virgins.com
Source=Paul Collins Startup list
[reg32]
Confirmed=X
Filename=reg32.exe
Description=Added by the NOUPDATE.B TROJAN!
Source=Paul Collins Startup list
[Reg32]
Confirmed=X
Filename=reg33.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Regcheck]
Confirmed=X
Filename=~CAB001.EXE
Description=Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!
Source=Paul Collins Startup list
[RegCleaner]
Confirmed=X
Filename=SYSio32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware
Source=Paul Collins Startup list
[RegCompres]
Confirmed=X
Filename=Regcpm32.exe
Description=Added by the POLDO.B TROJAN!
Source=Paul Collins Startup list
[RegCompres]
Confirmed=X
Filename=REGCPM32.EXE
Description=Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
Source=Paul Collins Startup list
[Regcxn]
Confirmed=X
Filename=Regcxn.exe
Description=Added by the COIBOA-D TROJAN!
Source=Paul Collins Startup list
[RegDone]
Confirmed=X
Filename=services.exe
Description=Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[RegDone]
Confirmed=X
Filename=winlogon.exe
Description=Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[RegDone Ex]
Confirmed=X
Filename=csrss.exe
Description=Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[RegDoneEx]
Confirmed=X
Filename=lsass.exe
Description=Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[regedit]
Confirmed=X
Filename=regedit.exe
Description=Added by the BRID.A WORM! Note - resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). The valid "regedit.exe" resides in C:\Windows (Win9x/Me/XP) or C:\Winnt (WinNT/2K)
Source=Paul Collins Startup list
[REGEDIT]
Confirmed=X
Filename=Regsrv32.com
Description=Added by the SOUTHGHOST WORM!
Source=Paul Collins Startup list
[RegFreeze]
Confirmed=U
Filename=regfreeze.exe
Description=RegFreeze anti-spyware software
Source=Paul Collins Startup list
[reggsdg]
Confirmed=X
Filename=spoolserv.exe
Description=Added by the SDBOT-MS WORM!
Source=Paul Collins Startup list
[reginfo32]
Confirmed=?
Filename=reginfo32.exe
Description=??
Source=Paul Collins Startup list
[Register MediaRing Talk]
Confirmed=N
Filename=register.exe
Description=If you don't want to register MediaRing and be reminded about it every bootup disable it
Source=Paul Collins Startup list
[Register SeqChk]
Confirmed=?
Filename=regsvr32.exe ..csseqchk.dll
Description=??
Source=Paul Collins Startup list
[RegisterDropHandler]
Confirmed=U
Filename=REGIST~1.EXE
Description=Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
Source=Paul Collins Startup list
[Registration-Studio 8]
Confirmed=N
Filename=RegTool.exe
Description=Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems
Source=Paul Collins Startup list
[Registry]
Confirmed=X
Filename=wscript.exe
Description=Added by the VBSWG.AQ WORM!
Source=Paul Collins Startup list
[Registry Checkup]
Confirmed=X
Filename=winreg.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Registry Loader]
Confirmed=X
Filename=regloadr.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Registry Loader]
Confirmed=X
Filename=winhlpp32.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Registry Scanner]
Confirmed=X
Filename=regscanr.exe
Description=Added by a variant of the OPTIX TROJAN!
Source=Paul Collins Startup list
[Registry Server]
Confirmed=X
Filename=regsrv32.exe
Description=Added by the RBOT-GM WORM!
Source=Paul Collins Startup list
[Registry Services]
Confirmed=X
Filename=Registry.exe
Description=Added by the DOWNLOADER.CILE TROJAN!
Source=Paul Collins Startup list
[Registry System16 Checkup Monitor]
Confirmed=X
Filename=SystemReg16.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[RegistryChk]
Confirmed=X
Filename=winbackup.exe
Description=Added by the MERTIAN WORM!
Source=Paul Collins Startup list
[RegistryMechanic]
Confirmed=U
Filename=RegMech.exe
Description=Registry Mechanic for Windows - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages"
Source=Paul Collins Startup list
[RegistryMonitor]
Confirmed=X
Filename=registry.pif
Description=Affilred adware
Source=Paul Collins Startup list
[RegProt]
Confirmed=Y
Filename=Regprot.exe
Description=RegistryProt from Diamond Computer Systems - protects the system registry against changes
Source=Paul Collins Startup list
[RegRun]
Confirmed=X
Filename=mActiveX.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Regrun2]
Confirmed=Y
Filename=WatchDog.exe
Description=Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc
Source=Paul Collins Startup list
[regservices.exe]
Confirmed=X
Filename=regservices.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[RegShave]
Confirmed=N
Filename=regshave.exe
Description=Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly
Source=Paul Collins Startup list
[regsrv]
Confirmed=X
Filename=regsrv.exe
Description=Added by the OPTIXPRO.11 TROJAN!
Source=Paul Collins Startup list
[Regsv]
Confirmed=X
Filename=regsv.exe
Description=Search hijacker - redirecting to scheo.com
Source=Paul Collins Startup list
[regsvc32]
Confirmed=X
Filename=regsvc32.exe
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[regsvr]
Confirmed=X
Filename=regsvr.exe
Description=Added by the WEBMONEY-G TROJAN!
Source=Paul Collins Startup list
[REGSVR32]
Confirmed=U
Filename=regsvr32.exe ctasio.dll
Description=ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
Source=Paul Collins Startup list
[regtmlp]
Confirmed=?
Filename=N/A
Description=??
Source=Paul Collins Startup list
[RegTweak]
Confirmed=U
Filename=RegTwk.exe
Description=Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface
Source=Paul Collins Startup list
[RegVer]
Confirmed=X
Filename=REGVER.EXE
Description=Added by the LATINUS.16 TROJAN!
Source=Paul Collins Startup list
[RegWrite]
Confirmed=X
Filename=csrss.exe
Description=Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Regx10EXE]
Confirmed=U
Filename=atix10.exe
Description=ATI Remote Wonder - PC wireless remote control
Source=Paul Collins Startup list
[reg_key]
Confirmed=X
Filename=FUKULAMER.exe
Description=Added by the BEAGLE.AH WORM!
Source=Paul Collins Startup list
[reg_key]
Confirmed=X
Filename=loader_name.exe
Description=Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!
Source=Paul Collins Startup list
[Reg_WFT]
Confirmed=X
Filename=Regsysw.com
Description=Added by the WILSEF VIRUS!
Source=Paul Collins Startup list
[ReleaseRAM]
Confirmed=U
Filename=RRAM.exe
Description="Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". Some users swear by programs such as this but I suggest you read this article and make up your own mind
Source=Paul Collins Startup list
[reload]
Confirmed=X
Filename=reload.vbs
Description=Added by the LOVELETTER.AS VIRUS!
Source=Paul Collins Startup list
[RemHelp]
Confirmed=N
Filename=Remhelp.exe
Description=BT Voyager ADSL Modem Help related
Source=Paul Collins Startup list
[Reminder]
Confirmed=N
Filename=reminder.exe
Description=From MS Money. Reminds you of your bills
Source=Paul Collins Startup list
[Reminder]
Confirmed=N
Filename=Remind_XP.exe
Description=HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
Source=Paul Collins Startup list
[Reminder-cpqXXXXX]
Confirmed=N
Filename=remind32.exe
Description=Compaq printer Registration
Source=Paul Collins Startup list
[Reminder-hpcXXXXX]
Confirmed=N
Filename=remind32.exe
Description=HP CD-Writer Registration
Source=Paul Collins Startup list
[Reminder-ranXXXXX]
Confirmed=N
Filename=remind32.exe
Description=Registration reminder widget for Rand Mcnally maps
Source=Paul Collins Startup list
[reminder-ScanSoft Product Registration]
Confirmed=N
Filename=remind32.exe
Description=Registration reminder for ScanSoft products such as PaperPort
Source=Paul Collins Startup list
[RemindMe]
Confirmed=U
Filename=RemindMe.exe
Description=Remind-Me - calendar software
Source=Paul Collins Startup list
[Remind_XP]
Confirmed=N
Filename=Remind_XP.exe
Description=HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
Source=Paul Collins Startup list
[Remndr]
Confirmed=X
Filename=CsRemnd.exe
Description=CasinoOnline foistware
Source=Paul Collins Startup list
[Remote Access]
Confirmed=U
Filename=rnaapp.exe
Description=Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed
Source=Paul Collins Startup list
[Remote Access Slave]
Confirmed=X
Filename=Synchost.exe
Description=Added by the RIPJAC TROJAN!
Source=Paul Collins Startup list
[Remote Control]
Confirmed=N
Filename=Rc.exe
Description=Hinet Hi-Five ISP software
Source=Paul Collins Startup list
[Remote Desktop Computing]
Confirmed=U
Filename=marspc.exe
Description=Marspc Remote Desktop Computing
Source=Paul Collins Startup list
[Remote Management Agent]
Confirmed=U
Filename=zenrc32.exe
Description=Part of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation
Source=Paul Collins Startup list
[remote master]
Confirmed=U
Filename=remote master.exe
Description=Required if you want your ASUS Remote control to work at all. Available via Start -> Programs
Source=Paul Collins Startup list
[Remote Procedure Call]
Confirmed=X
Filename=winrpc.exe
Description=Added by the RBOT-KM WORM!
Source=Paul Collins Startup list
[Remote Procedure Call]
Confirmed=X
Filename=winsysrpc.exe
Description=Added by the SDBOT-PS WORM!
Source=Paul Collins Startup list
[Remote Procedure Call For Windows 32bit]
Confirmed=X
Filename=rpc.exe
Description=Added by the RBOT-MD WORM!
Source=Paul Collins Startup list
[Remote Procedure Call Locator]
Confirmed=X
Filename=RUNDLL32.EXE reg678.dll ondll_reg
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[Remote Procedure Calls]
Confirmed=X
Filename=mswinrpc.exe
Description=Added by the RBOT.KJ WORM!
Source=Paul Collins Startup list
[Remote Procedure Calls]
Confirmed=X
Filename=mswinc.exe
Description=Added by the RBOT-IT WORM!
Source=Paul Collins Startup list
[Remote Procedure Calls]
Confirmed=X
Filename=win.exe
Description=Added by the SDBOT-QI WORM!
Source=Paul Collins Startup list
[Remote Update Monitor]
Confirmed=Y
Filename=imonitor.exe
Description=Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer
Source=Paul Collins Startup list
[RemoteAgent]
Confirmed=Y
Filename=RAUAgent.exe
Description=Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates"
Source=Paul Collins Startup list
[RemoteCenter]
Confirmed=U
Filename=RcMan.exe
Description=Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats
Source=Paul Collins Startup list
[RemoteControl]
Confirmed=U
Filename=rmctrl.exe
Description=Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Source=Paul Collins Startup list
[RemoteControl]
Confirmed=U
Filename=PDVDServ.exe
Description=Remote Control background application for CyberLink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Source=Paul Collins Startup list
[Remote_Agent]
Confirmed=N
Filename=RemoteAgent.exe
Description=Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings, you will need this, otherwise can be disabled. Available via Start -> Programs
Source=Paul Collins Startup list
[Removecpl]
Confirmed=N
Filename=Removecpl.exe
Description=Related to a Belkin 54Mbps Wireless Utility Control Panel applet
Source=Paul Collins Startup list
[Removed.exe]
Confirmed=X
Filename=Removed.exe
Description=GatorCheat - adware downloader
Source=Paul Collins Startup list
[RemStart]
Confirmed=?
Filename=remstart.exe
Description=Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required?
Source=Paul Collins Startup list
[RenolB]
Confirmed=?
Filename=ib.exe
Description=??
Source=Paul Collins Startup list
[RepliGo Assistant]
Confirmed=U
Filename=RepliGoMon.exe
Description=Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device"
Source=Paul Collins Startup list
[ReproPRD]
Confirmed=U
Filename=PrdUsb.exe
Description=Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work
Source=Paul Collins Startup list
[requester]
Confirmed=X
Filename=requester.5.exe
Description=Adware downloader, identified as TrojanProxy.Win32.Delf.h
Source=Paul Collins Startup list
[requester]
Confirmed=X
Filename=requester.5.exe
Description=Added by the MUQUEST.A TROJAN!
Source=Paul Collins Startup list
[requester]
Confirmed=X
Filename=requester.6.exe
Description=Added by a variant of the MUQUEST.A TROJAN!
Source=Paul Collins Startup list
[requester]
Confirmed=X
Filename=requester.8.exe
Description=Added by a variant of the MUQUEST.A TROJAN!
Source=Paul Collins Startup list
[Resolution Assistant]
Confirmed=N
Filename=matcli.exe
Description=Dell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[Resource Meter]
Confirmed=N
Filename=rsrcmtr.exe
Description=Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes
Source=Paul Collins Startup list
[Restart Watch]
Confirmed=?
Filename=Watch.exe
Description=Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required?
Source=Paul Collins Startup list
[Restart WSC Setting]
Confirmed=U
Filename=wscrestp.exe
Description=WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes
Source=Paul Collins Startup list
[Restart_VS]
Confirmed=?
Filename=Viewsonic.exe
Description=Could be a left-over from the installation of a Viewsonic flat panel display
Source=Paul Collins Startup list
[RestoreIT!]
Confirmed=Y
Filename=VBPTASK.EXE
Description=RestoreIT! from FarStone "allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure."
Source=Paul Collins Startup list
[restory]
Confirmed=X
Filename=restory.exe
Description=Added by the RETSAM TROJAN!
Source=Paul Collins Startup list
[Resume Copy]
Confirmed=U
Filename=copyfstq.exe
Description=Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function
Source=Paul Collins Startup list
[ResumeFixClocks]
Confirmed=U
Filename=resumefix.exe
Description=Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards
Source=Paul Collins Startup list
[retime]
Confirmed=X
Filename=retime.exe
Description=Added by the GIPMA TROJAN!
Source=Paul Collins Startup list
[RetrieverScheduler]
Confirmed=U
Filename=retrieverscheduler.exe
Description=80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available
Source=Paul Collins Startup list
[RevoTaskbarApp]
Confirmed=U
Filename=RevoTask.exe
Description=Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available
Source=Paul Collins Startup list
[RexSyMon]
Confirmed=N
Filename=rexsymon.exe
Description=Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC
Source=Paul Collins Startup list
[rfagent]
Confirmed=U
Filename=rfagent.exe
Description=Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders
Source=Paul Collins Startup list
[RFTray]
Confirmed=X
Filename=RFTRay.exe
Description=Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
Source=Paul Collins Startup list
[rfw]
Confirmed=Y
Filename=Rfw.exe
Description=RAV AntiVirus
Source=Paul Collins Startup list
[rfwydg]
Confirmed=?
Filename=rfwydg.exe
Description=??
Source=Paul Collins Startup list
[RFX_auto_upgrade]
Confirmed=N
Filename=rundll32.exe npvpg005.dll
Description=A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade
Source=Paul Collins Startup list
[RH]
Confirmed=U
Filename=rh32.exe
Description=EuroFonts - adds Euro symbols to pre-Euro computers
Source=Paul Collins Startup list
[Rhino]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the BOFRA.A WORM!
Source=Paul Collins Startup list
[RhinoBlocker]
Confirmed=U
Filename=RhinoBlocker.exe
Description=RhinoBlocker - pop-up stopper
Source=Paul Collins Startup list
[RHSI SHS]
Confirmed=N
Filename=SHS.exe
Description=Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash"
Source=Paul Collins Startup list
[Ring Central Fax]
Confirmed=U
Filename=rcenterrll.exe
Description=Only needed if you want a PC to answer faxes automatically
Source=Paul Collins Startup list
[rIOphosIs]
Confirmed=X
Filename=rIOPHosIs.vBS
Description=Added by the RIOSYS MACRO!
Source=Paul Collins Startup list
[RivaTuner]
Confirmed=U
Filename=RivaTuner.exe
Description=RivaTuner for tweaking nVidia graphics cards. Required if you make any changes
Source=Paul Collins Startup list
[RivaTunerStartupDaemon]
Confirmed=U
Filename=RivaTuner.exe
Description=RivaTuner for tweaking nVidia graphics cards. Required if you make any changes
Source=Paul Collins Startup list
[RjLyraInstaller]
Confirmed=?
Filename=setup.exe
Description=??
Source=Paul Collins Startup list
[rmctrl]
Confirmed=U
Filename=rmctrl.exe
Description=Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Source=Paul Collins Startup list
[rmmon]
Confirmed=N
Filename=mprmmon.exe
Description=Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card
Source=Paul Collins Startup list
[RMremote]
Confirmed=?
Filename=RmRemote.exe
Description=Remote control driver for REALmagic Xcard. Is it required?
Source=Paul Collins Startup list
[rn4d]
Confirmed=X
Filename=dirote.exe
Description=Added by the BKDR_MAROON.A TROJAN!
Source=Paul Collins Startup list
[RNBOStart]
Confirmed=U
Filename=sentstrt.exe
Description=Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
Source=Paul Collins Startup list
[rndll2]
Confirmed=?
Filename=rndll2.exe
Description=May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within?
Source=Paul Collins Startup list
[rngmf]
Confirmed=X
Filename=[path to trojan]
Description=Added by the RANKY.C TROJAN!
Source=Paul Collins Startup list
[RoboForm]
Confirmed=N
Filename=RoboTaskBarIcon.exe
Description=Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin
Source=Paul Collins Startup list
[RoboFormWatcher]
Confirmed=N
Filename=RoboFormWatcher.exe
Description=AI Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs
Source=Paul Collins Startup list
[Rocket.Time]
Confirmed=U
Filename=RocketTime.exe
Description=Time synchronization software from Rocket Software
Source=Paul Collins Startup list
[roketpipe]
Confirmed=?
Filename=rpclient.exe
Description=??
Source=Paul Collins Startup list
[romahere]
Confirmed=X
Filename=matrixhere.exe
Description=SuperSpider hijacker - a CoolWebSearch parasite variant
Source=Paul Collins Startup list
[romahere2]
Confirmed=U
Filename=************.exe [* = random char]
Description=SuperSpider hijacker - a CoolWebSearch parasite variant
Source=Paul Collins Startup list
[romahere3]
Confirmed=X
Filename=************.exe [* = random char]
Description=SuperSpider hijacker - a CoolWebSearch parasite variant
Source=Paul Collins Startup list
[ROUTD]
Confirmed=?
Filename=ROUTD.exe
Description=??
Source=Paul Collins Startup list
[RoxAssist]
Confirmed=N
Filename=RoxAssist.exe
Description=Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel"). Can be run manually
Source=Paul Collins Startup list
[Roxio Engine]
Confirmed=?
Filename=MSMNGR32.EXE
Description=Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!
Source=Paul Collins Startup list
[RoxioAudioCentral]
Confirmed=N
Filename=RxMon.exe
Description=Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly.
Source=Paul Collins Startup list
[RoxioDragToDisc]
Confirmed=N
Filename=DrgToDsc.exe
Description=Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
Source=Paul Collins Startup list
[RoxioEngineUtility]
Confirmed=Y
Filename=EngUtil.exe
Description=Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
Source=Paul Collins Startup list
[RP32]
Confirmed=U
Filename=rp32.exe
Description=ControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems.
Source=Paul Collins Startup list
[RPC]
Confirmed=X
Filename=MSschost.exe
Description=Added by a variant of the GAOBOT/AGOBOT WORM!
Source=Paul Collins Startup list
[RPC Patcher]
Confirmed=X
Filename=[path to worm]
Description=Added by the BOLGI WORM!
Source=Paul Collins Startup list
[RPCSS.exe]
Confirmed=Y
Filename=rpcss.exe
Description=Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here
Source=Paul Collins Startup list
[RRMedic]
Confirmed=X
Filename=rrmedic.exe
Description=Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection
Source=Paul Collins Startup list
[rscmpt]
Confirmed=U
Filename=rscmpt.exe
Description=Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status
Source=Paul Collins Startup list
[rsMenu]
Confirmed=U
Filename=rsMenu.exe
Description=Synchronizes a Casio PDA with MS Outlook
Source=Paul Collins Startup list
[RSPC Driver]
Confirmed=X
Filename=[random filename].exe
Description=Added by the RBOT-SN WORM!
Source=Paul Collins Startup list
[RSPC Driver D]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[RSRCMTZ]
Confirmed=?
Filename=RSRCMTZ.exe
Description=??
Source=Paul Collins Startup list
[RSS]
Confirmed=X
Filename=rundll32 RSSToolbar.dll, DllRunMain
Description="Related Sites" toolbar - SearchAndClick hijacker variant
Source=Paul Collins Startup list
[RtlMon.exe]
Confirmed=N
Filename=RtlMon.exe
Description=Monitor for RealTek network card
Source=Paul Collins Startup list
[RTMonitor]
Confirmed=Y
Filename=RTMonitor.exe
Description=Cheyenne (now eTrust) antivirus
Source=Paul Collins Startup list
[rtos]
Confirmed=X
Filename=rtos.exe
Description=IRC trojan
Source=Paul Collins Startup list
[RTStartMute]
Confirmed=?
Filename=N/A
Description=??
Source=Paul Collins Startup list
[rtvscn95]
Confirmed=Y
Filename=RTVSCN95.EXE
Description=Real-time virus scanner component of Norton Anti-Virus Corporate Edition
Source=Paul Collins Startup list
[Ruby13]
Confirmed=X
Filename=Ruby13.exe
Description=Added by the MEXER.E WORM!
Source=Paul Collins Startup list
[Ruby14]
Confirmed=X
Filename=Ruby14.exe
Description=Added by the FIGHTRUB-A WORM!
Source=Paul Collins Startup list
[RuLaunch]
Confirmed=U
Filename=RuLaunch.exe
Description=Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
Source=Paul Collins Startup list
[Run MSupdt32]
Confirmed=X
Filename=wscript MSupdt32.vbs
Description=Added by the CASER WORM!
Source=Paul Collins Startup list
[Run POPFile in background]
Confirmed=U
Filename=perl.exe
Description=POPFile - E-mail spam blocker
Source=Paul Collins Startup list
[Run POPFile in background]
Confirmed=U
Filename=wperl.exe
Description=POPFile - E-mail spam blocker
Source=Paul Collins Startup list
[Run StartupMonitor]
Confirmed=U
Filename=StartupMonitor.exe
Description=Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
Source=Paul Collins Startup list
[Run TaskMrg]
Confirmed=X
Filename=csrss.exe
Description=Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Run XP Service Pack]
Confirmed=X
Filename=xpservicepack.exe
Description=Added by the SDBOT.AQA WORM!
Source=Paul Collins Startup list
[run32dll]
Confirmed=X
Filename=WINClock.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[run32dll]
Confirmed=X
Filename=task32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Run32dll]
Confirmed=X
Filename=ocxdll.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[run=]
Confirmed=N
Filename=cmmpu.exe
Description=MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)
Source=Paul Collins Startup list
[run=]
Confirmed=N
Filename=hpfsched
Description=HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
Source=Paul Collins Startup list
[run=]
Confirmed=N
Filename=lxdboxcp.exe
Description=Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS
Source=Paul Collins Startup list
[run=]
Confirmed=N
Filename=pcfix2k.exe
Description=pcfix2k splash screen
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=ptlseq.cpl
Description=PhoenixNet BIOS adware. See here
Source=Paul Collins Startup list
[run=]
Confirmed=U
Filename=ramsys.exe
Description=Advanced Startup Manager from Rays Lab
Source=Paul Collins Startup list
[run=]
Confirmed=?
Filename=wallflip.exe
Description=Desktop wallpaper changer?
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=svcinit.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=fntldr.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[run=]
Confirmed=Y
Filename=smsrun16.exe
Description=Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs
Source=Paul Collins Startup list
[run=]
Confirmed=?
Filename=win.ini
Description=??
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=RAVMOND.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=real.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=dec25.exe
Description=Added by the ATAK.F WORM!
Source=Paul Collins Startup list
[run=]
Confirmed=?
Filename=LXBTppls.exe
Description=Reportedly part of Lexmark printer software - what does it do and is it required?
Source=Paul Collins Startup list
[run=]
Confirmed=N
Filename=fmedia.exe
Description=FMedia FaxWorks related - can be run manually
Source=Paul Collins Startup list
[run=]
Confirmed=Y
Filename=wswpd.exe
Description=Used with some models of Panasonic, Epson and NEC printers - required for printer to work
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=cyxid98.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=info32.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=mouse_configurator.win
Description=Added by the GAGGLE.E WORM!
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=RegistryReminder.exe
Description=Added by the APSTROJAN.OB TROJAN!
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=sec5dec.exe
Description=Added by the ATAK.G WORM!
Source=Paul Collins Startup list
[run=]
Confirmed=X
Filename=wmplayer.exe
Description=CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable!
Source=Paul Collins Startup list
[RunAlert]
Confirmed=U
Filename=AService.exe
Description=MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system
Source=Paul Collins Startup list
[runAP]
Confirmed=N
Filename=runAP.exe
Description=Not required but what is it?
Source=Paul Collins Startup list
[Runapp32]
Confirmed=X
Filename=Runapp32.exe
Description=Added by the NEODURK TROJAN!
Source=Paul Collins Startup list
[Rund1l32]
Confirmed=X
Filename=Winfi1e32.exe
Description=Added by the MERTIAN WORM!
Source=Paul Collins Startup list
[rundl332]
Confirmed=X
Filename=math.exe ...pluged.exe
Description=Added by the DOOMJUICE WORM!
Source=Paul Collins Startup list
[rundli32]
Confirmed=X
Filename=rundli32.exe
Description=Added by the LADE WORM!
Source=Paul Collins Startup list
[RunDLL]
Confirmed=X
Filename=rundll32.exe bridge.dll, Load
Description=Flingstone.com browser hijacker
Source=Paul Collins Startup list
[rundll***]
Confirmed=X
Filename=die.exe [path] mdll.exe
Description=Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
Source=Paul Collins Startup list
[rundll***]
Confirmed=X
Filename=die.exe [path] secure.bat
Description=Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
Source=Paul Collins Startup list
[rundll***]
Confirmed=X
Filename=die.exe [path] secure.exe
Description=Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
Source=Paul Collins Startup list
[rundll***]
Confirmed=X
Filename=die.exe [path] ttg.exe
Description=Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
Source=Paul Collins Startup list
[Rundll16]
Confirmed=X
Filename=Rundll16.exe
Description=Added by a number of VIRUSES, WORMS and TROJANS!
Source=Paul Collins Startup list
[Rundll32]
Confirmed=X
Filename=Rundll32.exe
Description=Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the Windows\Fonts directory
Source=Paul Collins Startup list
[RUNDLL32]
Confirmed=N
Filename=RUNDLL32.EXE NvQtwk, NvCplDaemon
Description=System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
Source=Paul Collins Startup list
[RunDLL32]
Confirmed=N
Filename=RunDLL32.exe NvMCTray.dll, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[rundll32]
Confirmed=U
Filename=Rundll32.exe Wf2kcpl.dll DllLoadDefaultSettings
Description=Loads default settings for Leadtek Winfast graphics cards
Source=Paul Collins Startup list
[RunDLL32]
Confirmed=X
Filename=winupdate.exe
Description=Added by an unidentified TROJAN! - possibly a BMBOT variant
Source=Paul Collins Startup list
[Rundll32]
Confirmed=X
Filename=Windows.exe
Description=Added by the QQPASS.E TROJAN!
Source=Paul Collins Startup list
[Rundll32]
Confirmed=X
Filename=Rundll32.exe ptipbm.dll, SetWriteBack
Description=Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required?
Source=Paul Collins Startup list
[rundll32]
Confirmed=X
Filename=[path to worm]
Description=Added by the AUTEX WORM!
Source=Paul Collins Startup list
[rundll32]
Confirmed=?
Filename=rundll32.exe ptipbmf.dll, SetWriteCacheMode
Description=Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller
Source=Paul Collins Startup list
[rundll32]
Confirmed=X
Filename=rundll32.exe
Description=Added by the SANKER WORM! Note that the valid "rundll32.exe" resides in C:\Windows\System32 wheras this version resides in C:\Windows
Source=Paul Collins Startup list
[rundll32]
Confirmed=X
Filename=csrss.exe
Description=Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[rundll32]
Confirmed=U
Filename=RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent
Description=Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
Source=Paul Collins Startup list
[Rundll32 cmicnfg]
Confirmed=N
Filename=Rundll32 cmicnfg.cpl, CMICtrlWnd
Description=System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Rundll32.exe]
Confirmed=X
Filename=Proyecto1.exe
Description=Added by the GRUEL WORM!
Source=Paul Collins Startup list
[Rundll32.exe]
Confirmed=X
Filename=Root.exe
Description=Added by the GRUEL WORM!
Source=Paul Collins Startup list
[Rundll32_7]
Confirmed=X
Filename=rundll32.exe MSIEFR40.DLL, DllRunServer
Description=BrowserAid "Featured Results" hijacker variant
Source=Paul Collins Startup list
[Rundll32_8]
Confirmed=X
Filename=rundll32.exe inetp60.dll, DllRunServer
Description=BrowserAid parasite variant
Source=Paul Collins Startup list
[rundll64]
Confirmed=X
Filename=[path to worm]
Description=Added by the AUTEX WORM!
Source=Paul Collins Startup list
[RundllSvr]
Confirmed=X
Filename=Rundll.exe
Description=Added by the HUAYU WORM!
Source=Paul Collins Startup list
[Rundllsystem32]
Confirmed=X
Filename=Rundllsystem32.exe
Description=Added by the NETDEVIL.B TROJAN!
Source=Paul Collins Startup list
[Rundnm]
Confirmed=X
Filename=Rundnm.exe
Description=Added by the DELF-HA TROJAN!
Source=Paul Collins Startup list
[RunOnce]
Confirmed=U
Filename=RUNONCE.EXE
Description=Part of MS Data Access Components - only required if you use these
Source=Paul Collins Startup list
[RunProg]
Confirmed=X
Filename=Server.exe
Description=Added by the OPTIX.04.A TROJAN!
Source=Paul Collins Startup list
[RunProg]
Confirmed=X
Filename=wini.exe
Description=Added by the OPTIX.04.D TROJAN!
Source=Paul Collins Startup list
[runreper]
Confirmed=X
Filename=viewer.exe
Description=Added by the REPER.A VIRUS!
Source=Paul Collins Startup list
[RunServices]
Confirmed=X
Filename=runsvc32.exe
Description=Added by the AGOBOT.QJ WORM!
Source=Paul Collins Startup list
[RunSysd32]
Confirmed=U
Filename=RunSysd32.exe
Description=DesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
Source=Paul Collins Startup list
[runwin32]
Confirmed=X
Filename=runwin32.exe
Description=Added by the ESEARCH-A TROJAN!
Source=Paul Collins Startup list
[RunWindowsUpdate]
Confirmed=X
Filename=uptodate.exe
Description=BrowserAid/BrowserPal foistware
Source=Paul Collins Startup list
[Run[0]]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Run_cd]
Confirmed=X
Filename=Run_cd.exe
Description=Added by the GHOST.23 TROJAN!
Source=Paul Collins Startup list
[RUSBHOLoader]
Confirmed=?
Filename=rundll32.exe RUSBHOLoader.dll, AutoRegister
Description=??
Source=Paul Collins Startup list
[rvde]
Confirmed=X
Filename=N/A
Description=Related to li-speed****
Source=Paul Collins Startup list
[RVP]
Confirmed=X
Filename=bpc.exe
Description=Spyware included with the latest version of Grokster. Also see here
Source=Paul Collins Startup list
[RxMon]
Confirmed=N
Filename=rxmon9x.exe
Description=Dell Resolution Assistant
Source=Paul Collins Startup list
[r_server]
Confirmed=Y
Filename=r_server.exe
Description=Radmin - remote admistrator server
Source=Paul Collins Startup list
[S0undMan]
Confirmed=X
Filename=svch0st.exe
Description=Added by the LOVGATE.AB WORM!
Source=Paul Collins Startup list
[S24EvMon]
Confirmed=?
Filename=S24EvMon.exe
Description=Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required?
Source=Paul Collins Startup list
[S3 Internal Chip]
Confirmed=X
Filename=s3serv.exe
Description=Added by the AGOBOT-DD WORM!
Source=Paul Collins Startup list
[S3apphk]
Confirmed=?
Filename=S3apphk.exe
Description=S3 graphics related?
Source=Paul Collins Startup list
[S3Hotkey]
Confirmed=?
Filename=s3hotkey.exe
Description=S3 Video driver related. What does it do and is it required?
Source=Paul Collins Startup list
[S3Mon]
Confirmed=?
Filename=S3Mon.exe
Description=S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required?
Source=Paul Collins Startup list
[S3TRAY]
Confirmed=N
Filename=S3Tray.exe
Description=S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
Source=Paul Collins Startup list
[s3tray2]
Confirmed=?
Filename=s3tray2.exe
Description=Same as the s3tray entry in this table?
Source=Paul Collins Startup list
[S3TRAYHP]
Confirmed=?
Filename=S3trayhp.exe
Description=S3 Video driver related. What does it do and is it required?
Source=Paul Collins Startup list
[S4F]
Confirmed=U
Filename=S4F.exe
Description=S4F internet filtering software
Source=Paul Collins Startup list
[s4helper]
Confirmed=X
Filename=s4helper.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[SA]
Confirmed=?
Filename=Sa3.exe
Description=Logitech QuickCam driver. Is it required?
Source=Paul Collins Startup list
[SA Service]
Confirmed=?
Filename=SAservice.exe
Description=Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?
Source=Paul Collins Startup list
[Sa3dsrv]
Confirmed=N
Filename=Sa3dsrv.exe
Description=3D sound extension for Windows
Source=Paul Collins Startup list
[saap]
Confirmed=X
Filename=saap.exe
Description=180Solutions/N-Case adware variant
Source=Paul Collins Startup list
[Sabreserver]
Confirmed=N
Filename=SABSERV.EXE
Description=Airline reservation software from Sabre. Available via Start -> Programs
Source=Paul Collins Startup list
[SAClient]
Confirmed=N
Filename=RegCon.exe
Description=AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging
Source=Paul Collins Startup list
[Safe]
Confirmed=X
Filename=SafeWin.exe
Description=Added by the FOCOSENHA TROJAN!
Source=Paul Collins Startup list
[SafeGuard Popup Blocker Updater]
Confirmed=X
Filename=regsvr32 [path] sfgupd.dll
Description=SafeguardProtect/Veevo hijacker
Source=Paul Collins Startup list
[SafeGuard Popup Blocker Updater (required)]
Confirmed=X
Filename=regsvr32 [path] sfg****.dll [* = ramdom char/digit]
Description=SafeGuard Protect/Veevo - hijacker
Source=Paul Collins Startup list
[SafeGuard Popup Updater (required)]
Confirmed=X
Filename=regsvr32 [path] sfg****.dll [* = ramdom char/digit]
Description=SafeguardProtect/Veevo hijacker
Source=Paul Collins Startup list
[SafeGuard Popup Updater (required)]
Confirmed=X
Filename=regsvr32 [path] PDF****.dll [* = random char/digit]
Description=SafeguardProtect/Veevo hijacker
Source=Paul Collins Startup list
[SafeInstall.exe]
Confirmed=N
Filename=SAFEIN~1.EXE
Description=Monitors a download and ensures an newer version of a file isn't replaced by an older one
Source=Paul Collins Startup list
[SafeOFF]
Confirmed=N
Filename=SafeOff.exe
Description=Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
Source=Paul Collins Startup list
[SafeSearch]
Confirmed=X
Filename=safesearch.exe
Description=AutoSearch parasite variant
Source=Paul Collins Startup list
[SafeSurfingUpdate]
Confirmed=X
Filename=SSUpdate.exe
Description=DyFuCa/MoneyTree parasite variant
Source=Paul Collins Startup list
[Safeworld]
Confirmed=U
Filename=Freedom.exe
Description=SafeWorld Internet Security
Source=Paul Collins Startup list
[Sagate Security Firewall]
Confirmed=X
Filename=sagate.exe
Description=Added by the GAOBOT.BOW WORM!
Source=Paul Collins Startup list
[SAgent2ExePath]
Confirmed=N
Filename=SAgent2.exe
Description=Seiko Epson printer status agent. Disable if printer is not used often
Source=Paul Collins Startup list
[sagnt]
Confirmed=X
Filename=sagnt.exe
Description=Adware web downloader
Source=Paul Collins Startup list
[SAHagent]
Confirmed=X
Filename=Sahagent.exe
Description=ShopAtHomeSelect parasite
Source=Paul Collins Startup list
[SAHBundle]
Confirmed=X
Filename=bundle.exe
Description=ShopAtHomeSelect parasite related
Source=Paul Collins Startup list
[saie]
Confirmed=X
Filename=saie.exe
Description=180Solutions/N-Case adware variant
Source=Paul Collins Startup list
[SAIMON]
Confirmed=U
Filename=SaiMon.exe
Description=Saitek joystick driver
Source=Paul Collins Startup list
[sain]
Confirmed=X
Filename=sain.exe
Description=180Solutions/N-Case adware variant
Source=Paul Collins Startup list
[sais]
Confirmed=X
Filename=sais.exe
Description=180Solutions/N-Case adware variant
Source=Paul Collins Startup list
[SaiSmart]
Confirmed=?
Filename=SaiSmart.exe
Description="Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button. What does it do and is it required?
Source=Paul Collins Startup list
[SaitekAutoConfigure]
Confirmed=U
Filename=saicnfig.exe
Description=Configuration for Saitek game controllers
Source=Paul Collins Startup list
[salm]
Confirmed=X
Filename=salm.exe
Description=180Search adware
Source=Paul Collins Startup list
[salm]
Confirmed=X
Filename=salm.exe
Description=180Solutions/N-Case adware variant
Source=Paul Collins Startup list
[SAMcal]
Confirmed=U
Filename=SAMcal.exe
Description=SamCal - calendar/reminder program
Source=Paul Collins Startup list
[Sametime Connect]
Confirmed=U
Filename=Connect.exe
Description=IBM Lotus Instant Messaging and Conferencing software
Source=Paul Collins Startup list
[SandIcon]
Confirmed=N
Filename=SandIcon.exe
Description=SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources
Source=Paul Collins Startup list
[sapp]
Confirmed=X
Filename=sapp.exe
Description=180Solutions/N-Case adware variant
Source=Paul Collins Startup list
[saSyncMgr]
Confirmed=X
Filename=rundll32.exe sasync.dll, SyncWait
Description=Browser hijacker - redirecting to Searchant.com
Source=Paul Collins Startup list
[SATARaid]
Confirmed=U
Filename=SATARaid.exe
Description=RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
Source=Paul Collins Startup list
[satmat]
Confirmed=X
Filename=satmat.exe
Description=Transponder parasite updater/installer
Source=Paul Collins Startup list
[SAUpdate]
Confirmed=U
Filename=SAUpdate.exe
Description=Big Brother from Quest Software. System and network monitor
Source=Paul Collins Startup list
[SAVAgent]
Confirmed=Y
Filename=SAVAgent.exe
Description=Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users
Source=Paul Collins Startup list
[Save]
Confirmed=X
Filename=Save.exe
Description=Rebranded version of SaveNow advertising spyware
Source=Paul Collins Startup list
[SaveDate]
Confirmed=X
Filename=SaveStartDate.Exe
Description=Unidentified adware
Source=Paul Collins Startup list
[Savenow]
Confirmed=X
Filename=SaveNow.exe
Description=Advertising spyware. Installed as part of the Kazaa Media Desktop bundle for example
Source=Paul Collins Startup list
[Savenow]
Confirmed=X
Filename=savenow.exe
Description=Added by the SPREDA.B VIRUS!
Source=Paul Collins Startup list
[Say The Time 5.0]
Confirmed=U
Filename=SAYTIME.EXE
Description=This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly
Source=Paul Collins Startup list
[SB]
Confirmed=U
Filename=SB.exe
Description=Acer Soft Button on Acer Tablet PCs
Source=Paul Collins Startup list
[SB Audigy 2 Startup Menu]
Confirmed=N
Filename=/l:eng
Description=Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
Source=Paul Collins Startup list
[SB Watchdog]
Confirmed=X
Filename=SBWatchdog.exe
Description=Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information
Source=Paul Collins Startup list
[SBAutoUpdate]
Confirmed=U
Filename=sbautoupdate.exe
Description=SpywareBlaster auto-updater
Source=Paul Collins Startup list
[SBC Self Support Tool]
Confirmed=U
Filename=matcli.exe
Description=matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file. The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[SBDrvDet]
Confirmed=U
Filename=SBDrv.exe
Description=Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one
Source=Paul Collins Startup list
[SBHC]
Confirmed=X
Filename=sbhc.exe
Description=SuperBar parasite - uninstall available here
Source=Paul Collins Startup list
[SBMX]
Confirmed=N
Filename=sbmx.exe
Description=SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only)
Source=Paul Collins Startup list
[SbUsb AudCtrl]
Confirmed=U
Filename=RunDll32 sbusbdll.dll, RCMonitor
Description=Control for Soundblaster MP3 external (USB) sound card
Source=Paul Collins Startup list
[sc]
Confirmed=N
Filename=scrubxp.exe
Description=ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc
Source=Paul Collins Startup list
[sc]
Confirmed=U
Filename=sc.exe
Description=Watchdog 2.0 Software - monitoring program
Source=Paul Collins Startup list
[sc]
Confirmed=U
Filename=run.exe
Description=All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file
Source=Paul Collins Startup list
[sc23exec]
Confirmed=?
Filename=sc23exec.exe
Description=Possibly related to a digital camera
Source=Paul Collins Startup list
[SC3300CC]
Confirmed=Y
Filename=SC3300CC.exe
Description=SiPix digital camera Twain device driver
Source=Paul Collins Startup list
[scan]
Confirmed=X
Filename=mscman.exe
Description=Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
Source=Paul Collins Startup list
[Scan Detector]
Confirmed=?
Filename=Pmxdetect.exe
Description=Associated with PrimaScan scanners. Is it required?
Source=Paul Collins Startup list
[Scan Wizard]
Confirmed=?
Filename=button.exe
Description=Associated with ScanWizard as supplied with Microtek scanners - see also Scanner Detector or SDetect. What does it do and is it required?
Source=Paul Collins Startup list
[ScanDisk]
Confirmed=X
Filename=ScanDisk.exe
Description=Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker
Source=Paul Collins Startup list
[scands32.exe]
Confirmed=X
Filename=scands32.exe
Description=Added by a variant of the Adclicker TROJAN!
Source=Paul Collins Startup list
[ScanFile]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[ScanInicio]
Confirmed=?
Filename=Inicio.exe
Description=Part of Panda Anti-Virus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active
Source=Paul Collins Startup list
[Scanner Detector]
Confirmed=N
Filename=SDetect.exe
Description=ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
Source=Paul Collins Startup list
[Scanreg]
Confirmed=X
Filename=[filename]
Description=Added by the QQPASS.E TROJAN!
Source=Paul Collins Startup list
[ScanRegistry]
Confirmed=X
Filename=nsrvnt.exe
Description=Added by the NERTE TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe
Source=Paul Collins Startup list
[ScanRegistry]
Confirmed=X
Filename=scanregv.exe
Description=Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe
Source=Paul Collins Startup list
[ScanRegistry]
Confirmed=Y
Filename=Scanregw.exe
Description=Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:\Windows or C:\Winnt)
Source=Paul Collins Startup list
[ScanRegistry]
Confirmed=X
Filename=Scanregw.exe
Description=Added by the STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt). Runs from the registry RunServices key as opposed to the Run key
Source=Paul Collins Startup list
[ScanSpyware v *]
Confirmed=X
Filename=Scanner.exe
Description=Spyware remover (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Source=Paul Collins Startup list
[SCardSvr]
Confirmed=N
Filename=scardsvr.exe
Description=Related to SmartCard readers and sometimes uses lots of system resources
Source=Paul Collins Startup list
[SCardSvr]
Confirmed=X
Filename=SCardSvr32.Exe
Description=Added by the MOFEI.B WORM!
Source=Paul Collins Startup list
[Scheduled Maintenance]
Confirmed=N
Filename=Scheduled_Maintenance.exe
Description=Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs
Source=Paul Collins Startup list
[Scheduling Agent]
Confirmed=X
Filename=Scheduler.exe
Description=Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect
Source=Paul Collins Startup list
[SchedulingAgant]
Confirmed=X
Filename=MMTASK.EXE
Description=Added by the YAB.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename
Source=Paul Collins Startup list
[SchedulingAgent]
Confirmed=U
Filename=mstask.exe
Description=MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans
Source=Paul Collins Startup list
[SchedulingAgent]
Confirmed=U
Filename=mstinit.exe
Description=MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans
Source=Paul Collins Startup list
[Schmaili]
Confirmed=U
Filename=Schmaili.exe
Description=Schmaili - insert animated smilies into your e-mail
Source=Paul Collins Startup list
[SCHWIZEX]
Confirmed=Y
Filename=SCHWIZEX.EXE
Description=Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
Source=Paul Collins Startup list
[ScManager]
Confirmed=X
Filename=scman.exe
Description=Added by the FORBOT-CW WORM!
Source=Paul Collins Startup list
[scopedll]
Confirmed=X
Filename=scopedll.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[Scotia OnLine Recovery]
Confirmed=N
Filename=etdirrcv.exe
Description=Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process
Source=Paul Collins Startup list
[Scotia OnLine Security v*.* Recovery]
Confirmed=N
Filename=etdirrcv.exe
Description=Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process
Source=Paul Collins Startup list
[Scr]
Confirmed=X
Filename=scr.scr
Description=Added by the OPASERV.T WORM!
Source=Paul Collins Startup list
[ScrapPad]
Confirmed=N
Filename=Scrappad.exe
Description=ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper
Source=Paul Collins Startup list
[Screen Calendar]
Confirmed=U
Filename=scrcal.exe
Description=Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler
Source=Paul Collins Startup list
[Screen Guard]
Confirmed=U
Filename=launch.exe
Description=Part of Access Denied security and privacy software
Source=Paul Collins Startup list
[Screen Guard Message Scan]
Confirmed=U
Filename=sgms.exe
Description=Part of Access Denied security and privacy software
Source=Paul Collins Startup list
[Screen Saver Control]
Confirmed=N
Filename=FSScrCtl.exe
Description=Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
Source=Paul Collins Startup list
[ScreenPrint32]
Confirmed=N
Filename=ScreenPrint32.exe
Description=ScreenPrint32 screen capture software - can be launched manually
Source=Paul Collins Startup list
[screxe]
Confirmed=?
Filename=scruser2k.exe
Description=??
Source=Paul Collins Startup list
[script]
Confirmed=?
Filename=script.bat
Description=Maybe associated with DOS on a Win9x machine
Source=Paul Collins Startup list
[ScriptBlocking]
Confirmed=Y
Filename=SBServ.exe
Description=Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information
Source=Paul Collins Startup list
[ScriptSentry]
Confirmed=Y
Filename=Scriptsentry.exe
Description=Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly
Source=Paul Collins Startup list
[Scroll-In-Mouse V2.0]
Confirmed=U
Filename=SCROLL.EXE
Description=Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features
Source=Paul Collins Startup list
[ScrSvr]
Confirmed=X
Filename=ScrSvr.exe
Description=Added by the OPASERV WORM!
Source=Paul Collins Startup list
[ScrSvrOld]
Confirmed=X
Filename=[worm filename]
Description=Added by the OPASERV WORM!
Source=Paul Collins Startup list
[Scsi]
Confirmed=Y
Filename=Scsi.exe
Description=SCSI Miniport driver
Source=Paul Collins Startup list
[scvhost]
Confirmed=X
Filename=svzhost.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[scvhost loader]
Confirmed=X
Filename=ixplore.exe
Description=Added by the SDBOT-CY TROJAN!
Source=Paul Collins Startup list
[scvhost.exe]
Confirmed=X
Filename=scvhost.exe
Description=Added by the LOHAV-N TROJAN!
Source=Paul Collins Startup list
[sd32info]
Confirmed=X
Filename=sd32info.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[SDaemon]
Confirmed=U
Filename=sdaemon.exe
Description=PC Security from Tropical Software. 'PC Security™ 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features'
Source=Paul Collins Startup list
[sdchosts32]
Confirmed=X
Filename=vbdd.exe
Description=Added by the RANKY.AG TROJAN!
Source=Paul Collins Startup list
[SDetect]
Confirmed=N
Filename=SDetect.exe
Description=ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
Source=Paul Collins Startup list
[sdfsdfsdf]
Confirmed=X
Filename=sp2update.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[SDIN Adapter]
Confirmed=X
Filename=sdin.exe
Description=Added by the FORBOT-AP WORM!
Source=Paul Collins Startup list
[SDJobCheck]
Confirmed=?
Filename=triggusr.exe
Description=Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup?
Source=Paul Collins Startup list
[SDPhotoBar.exe]
Confirmed=N
Filename=SDPhotoBar.exe
Description=SmartDraw Photo - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics"
Source=Paul Collins Startup list
[sdrss]
Confirmed=X
Filename=sdrss.exe
Description=Added by the SDBOT-SQ WORM!
Source=Paul Collins Startup list
[sealmon]
Confirmed=U
Filename=sealmon.exe
Description=SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email
Source=Paul Collins Startup list
[Search Hook]
Confirmed=?
Filename=srchhook.exe
Description=??
Source=Paul Collins Startup list
[Search Page]
Confirmed=X
Filename=http://find.naupoint.com
Description=Naupoint browser hijacker
Source=Paul Collins Startup list
[Search-Exe]
Confirmed=X
Filename=SE.exe
Description=Search-Exe hijacker
Source=Paul Collins Startup list
[Search.vbs]
Confirmed=X
Filename=
Description=Hijacker
Source=Paul Collins Startup list
[SearchEnhancement]
Confirmed=X
Filename=scbar.exe
Description=IE search hijacker
Source=Paul Collins Startup list
[searchnav]
Confirmed=X
Filename=searchnav.exe
Description=SearchNav adware - IEFeatures/Popnav variant
Source=Paul Collins Startup list
[SearchNavVersion]
Confirmed=X
Filename=searchnavversion.exe
Description=SearchNav adware - IEFeatures/Popnav variant
Source=Paul Collins Startup list
[SearchSetter]
Confirmed=X
Filename=searchsetter[1].exe
Description=Browser hijacker - redirecting to FindWhateverNow.com
Source=Paul Collins Startup list
[SearchSquire33]
Confirmed=X
Filename=SearchUpdate33.exe
Description=SearchSquire parasite
Source=Paul Collins Startup list
[SearchUpgrader]
Confirmed=X
Filename=SearchUpgrader.exe
Description=Hijacker
Source=Paul Collins Startup list
[SecondChance]
Confirmed=U
Filename=sctray.exe
Description=Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash
Source=Paul Collins Startup list
[Secret-Crush]
Confirmed=X
Filename=start.exe
Description=Hijacker that may reset your browser's home page and/or search settings to point to undesired sites
Source=Paul Collins Startup list
[Secsys]
Confirmed=U
Filename=Secsys.exe
Description=Key Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Source=Paul Collins Startup list
[secure]
Confirmed=X
Filename=secure.exe
Description=DealHelper adware
Source=Paul Collins Startup list
[SecureCleanIEClean]
Confirmed=N
Filename=SCIEClean.exe
Description=SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches
Source=Paul Collins Startup list
[SecureItPro]
Confirmed=U
Filename=Secureitpro470p.exe
Description=SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop
Source=Paul Collins Startup list
[SecureLogin]
Confirmed=X
Filename=Mslg32.exe
Description=Added by the REDZED WORM!
Source=Paul Collins Startup list
[Security Accounts Manager SM]
Confirmed=X
Filename=samsm.exe
Description=Added by the SPYBOT.JE WORM!
Source=Paul Collins Startup list
[Security Agent Manager]
Confirmed=X
Filename=mssams.exe
Description=Added by the RBOT-SV WORM!
Source=Paul Collins Startup list
[Security iGuard]
Confirmed=N
Filename=Security iGuard.exe
Description=Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Source=Paul Collins Startup list
[Security Manager]
Confirmed=U
Filename=SecurityManager.exe
Description=A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private
Source=Paul Collins Startup list
[Security Patches]
Confirmed=X
Filename=msnkn.exe
Description=Added by the RBOT.WW WORM!
Source=Paul Collins Startup list
[security service]
Confirmed=X
Filename=syss.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[SECWIZ98]
Confirmed=Y
Filename=SECWIZ98.EXE
Description=Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here
Source=Paul Collins Startup list
[SelfHostUtil]
Confirmed=?
Filename=slefhost.exe
Description=??
Source=Paul Collins Startup list
[SeMS]
Confirmed=U
Filename=SeMS.exe
Description=PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone
Source=Paul Collins Startup list
[Sensiva]
Confirmed=U
Filename=Sensiva.exe
Description=Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly
Source=Paul Collins Startup list
[SENTRY]
Confirmed=X
Filename=SENTRY.exe
Description=From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it
Source=Paul Collins Startup list
[Sepate Security Firewall]
Confirmed=X
Filename=sepate.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Serials]
Confirmed=X
Filename=serials.exe
Description=Any one of a variety of worms and trojans
Source=Paul Collins Startup list
[serrdctl.exe]
Confirmed=Y
Filename=serrdctl.exe
Description="Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems
Source=Paul Collins Startup list
[Serv-U]
Confirmed=N
Filename=serv-u32.exe
Description=FTP server
Source=Paul Collins Startup list
[Serv-U]
Confirmed=X
Filename=wssdsu.exe
Description=Added by the MANIFEST TROJAN!
Source=Paul Collins Startup list
[server]
Confirmed=X
Filename=server.exe
Description=Added by the DELTAD.A WORM!
Source=Paul Collins Startup list
[SERVER.EXE]
Confirmed=X
Filename=SERVER.EXE
Description=Added by the BUSHTRO122 or SMOKODOOR TROJANS!
Source=Paul Collins Startup list
[serverex]
Confirmed=X
Filename=Server.txt.vbs
Description=Added by the DELTAD.A WORM!
Source=Paul Collins Startup list
[Service]
Confirmed=U
Filename=service.exe
Description=Added by the ALADINZ.H TROJAN!
Source=Paul Collins Startup list
[Service]
Confirmed=X
Filename=services.exe
Description=Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Service]
Confirmed=X
Filename=[trojan filename]
Description=Added by the KAITEX.E TROJAN!
Source=Paul Collins Startup list
[Service Connection]
Confirmed=N
Filename=sccenter.exe
Description=For Compaq PC's. Part of Backweb
Source=Paul Collins Startup list
[Service Connection]
Confirmed=N
Filename=bwtray.exe
Description=For Compaq PC's. Part of Backweb
Source=Paul Collins Startup list
[Service Controller]
Confirmed=X
Filename=Csrrs.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Service Host]
Confirmed=X
Filename=[filename].exe
Description=Added by the TORVEL.B WORM!
Source=Paul Collins Startup list
[Service Host]
Confirmed=X
Filename=spoolxx.exe
Description=Added by the TORVEL WORM!
Source=Paul Collins Startup list
[Service Host ]
Confirmed=X
Filename=svchost.exe
Description=Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Service Host Driver]
Confirmed=X
Filename=svchost.exe
Description=Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Service Manager]
Confirmed=N
Filename=sqlmangr.exe
Description=SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start -> Programs
Source=Paul Collins Startup list
[Service Manager]
Confirmed=X
Filename=dxsound.exe
Description=Added by the PROXY-GRIC TROJAN!
Source=Paul Collins Startup list
[Service Process]
Confirmed=X
Filename=SVCHOST.EXE
Description=Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Service Process]
Confirmed=X
Filename=winset.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[service updaer]
Confirmed=X
Filename=qualityz.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant
Source=Paul Collins Startup list
[Service.exe]
Confirmed=X
Filename=Service.exe
Description="servedby.advertising" popup generator
Source=Paul Collins Startup list
[ServiceConfig]
Confirmed=U
Filename=ispbeg.exe
Description=Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation
Source=Paul Collins Startup list
[ServiceLayer]
Confirmed=Y
Filename=ServiceLayer.exe
Description=Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly
Source=Paul Collins Startup list
[services]
Confirmed=X
Filename=start.bat
Description=Added by the ZCREW TROJAN!
Source=Paul Collins Startup list
[Services]
Confirmed=X
Filename=[path to trojan]
Description=Added by the METEORSHELL TROJAN!
Source=Paul Collins Startup list
[Services]
Confirmed=X
Filename=back32.exe ...service.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe
Source=Paul Collins Startup list
[Services]
Confirmed=X
Filename=services.exe
Description=Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Services]
Confirmed=X
Filename=winread.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Services Controller]
Confirmed=X
Filename=lsassa.exe
Description=Added by the CIADOOR.122 VIRUS!
Source=Paul Collins Startup list
[Services Host]
Confirmed=X
Filename=Scchost.exe
Description=Added by the DONK WORM!
Source=Paul Collins Startup list
[Services Process]
Confirmed=X
Filename=services.exe
Description=Added by unidentified spyware - recognized by Kaspersky antivirus as Small.X TROJAN!
Source=Paul Collins Startup list
[Services.EXE]
Confirmed=X
Filename=services.exe
Description=Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[services.exe]
Confirmed=X
Filename=Services.exe
Description=Added by the CIADOOR-F TROJAN! Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[Services004]
Confirmed=X
Filename=[worm filename]
Description=Added by the BUGBROS WORM!
Source=Paul Collins Startup list
[ServUTrayIcon]
Confirmed=?
Filename=ServUTray.exe
Description=System Tray icon for Serv-U FTP server. Is it required?
Source=Paul Collins Startup list
[SESync]
Confirmed=X
Filename=sed.exe
Description=Downloadware/SED adware downloader
Source=Paul Collins Startup list
[SetDefaultMIDI]
Confirmed=?
Filename=MIDIDef.exe
Description=Related to a Soundblaster Audigy soundcards. What does it do and is it required?
Source=Paul Collins Startup list
[setdefprt]
Confirmed=?
Filename=setdefprt.exe
Description=Related to a Brother printer?
Source=Paul Collins Startup list
[SetecCertUtil]
Confirmed=U
Filename=Certutil.exe
Description=Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV
Source=Paul Collins Startup list
[setFTPBack]
Confirmed=X
Filename=createsw.exe
Description=Added by the FTP_BMAIL TROJAN!
Source=Paul Collins Startup list
[SetHook]
Confirmed=N
Filename=SetHook.exe
Description=Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
Source=Paul Collins Startup list
[SETI@home]
Confirmed=N
Filename=SETI@home.exe
Description=SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
Source=Paul Collins Startup list
[seticlient]
Confirmed=N
Filename=SETI@home.exe
Description=SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
Source=Paul Collins Startup list
[SetIcon]
Confirmed=N
Filename=SetIcon.exe
Description=Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog
Source=Paul Collins Startup list
[SetiQueue]
Confirmed=N
Filename=Setiqu~1.exe
Description=Provides work unit buffering for Seti@Home clients - see here for more details
Source=Paul Collins Startup list
[SetiSpy]
Confirmed=N
Filename=SetiSpy.exe
Description=From the site - 'SETI Spy is a little program I wrote to "spy" on the progress and performance of the SETI@home client. I call it a "spy" because I tried to make it as unobtrusive as possible'
Source=Paul Collins Startup list
[SetRefresh]
Confirmed=?
Filename=SetRefresh.exe
Description=Found on a Compaq PC. Video refresh rate utility? Is it required?
Source=Paul Collins Startup list
[Setting]
Confirmed=X
Filename=sysweb.exe
Description=Added by the SDBOT.GEN TROJAN!
Source=Paul Collins Startup list
[setup]
Confirmed=N
Filename=hphprld.exe ....setup.exe
Description=HP DeskJet Setup - printers function normally without it
Source=Paul Collins Startup list
[Setup experation]
Confirmed=X
Filename=svchost.exe
Description=Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process, which NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[SetupICWDesktop]
Confirmed=N
Filename=icwconn1.exe
Description=Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
Source=Paul Collins Startup list
[setupuser]
Confirmed=X
Filename=regedit.exe setupuser.log
Description=Regfile in disguise - another CoolWebSearch parasite variant
Source=Paul Collins Startup list
[setuzp]
Confirmed=?
Filename=setuzp.exe
Description=??
Source=Paul Collins Startup list
[SetVrc]
Confirmed=X
Filename=setvrc.exe
Description=Added by the HUNTOCX WORM!
Source=Paul Collins Startup list
[Sex Teris]
Confirmed=X
Filename=st01b.exe
Description=Added by the REPAD WORM!
Source=Paul Collins Startup list
[Sexy_sg]
Confirmed=X
Filename=Sexy_sg.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[SFP]
Confirmed=N
Filename=vzSFPWin.EXE
Description=Verizon Online Support Center - prompts for online updates
Source=Paul Collins Startup list
[SFtrb Service]
Confirmed=X
Filename=cftrb32.exe
Description=Added by the SOBIG.D WORM!
Source=Paul Collins Startup list
[SfWinStartInfo]
Confirmed=U
Filename=sfWinStartupInfo.exe
Description=
SFIRM32 Online Banking software
Source=Paul Collins Startup list
[Sgecrypt]
Confirmed=U
Filename=Sgecrypt.exe
Description=SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
Source=Paul Collins Startup list
[Sgeecview]
Confirmed=U
Filename=Ecview.exe
Description=SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
Source=Paul Collins Startup list
[sginst]
Confirmed=N
Filename=sginst.exe
Description=eAcceleration Stop-Sign related - not recommended, see note
Source=Paul Collins Startup list
[SGTBox]
Confirmed=?
Filename=SGTBox.exe
Description=Canon scanner driver. Is it required?
Source=Paul Collins Startup list
[sgtray]
Confirmed=U
Filename=sgtray.exe
Description=StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
Source=Paul Collins Startup list
[shambl3r]
Confirmed=X
Filename=cnf.bat
Description=Added by the REMABL WORM!
Source=Paul Collins Startup list
[shambl3r*]
Confirmed=X
Filename=shambl3r.exe
Description=Added by the REMABL WORM! where * is 2 to 11
Source=Paul Collins Startup list
[Share-to-Web Namespace Daemon]
Confirmed=N
Filename=hpgs2wnd.exe
Description="HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites." In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs
Source=Paul Collins Startup list
[Shareaza]
Confirmed=N
Filename=Shareaza.exe
Description=Shareaza P2P client
Source=Paul Collins Startup list
[sharedprem]
Confirmed=X
Filename=sharedprem.exe
Description=Added by the MAKECALL TROJAN!
Source=Paul Collins Startup list
[Sharing and Mapping Software]
Confirmed=Y
Filename=DShmap.exe
Description=Intel AnyPoint internet sharing software
Source=Paul Collins Startup list
[SharkEject]
Confirmed=N
Filename=AEJCT32.exe
Description=Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required
Source=Paul Collins Startup list
[Shcenter]
Confirmed=N
Filename=chcenter.exe
Description=IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"
Source=Paul Collins Startup list
[SheduIer]
Confirmed=X
Filename=svchst.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[Shell]
Confirmed=X
Filename=Shell32.exe
Description=Added by the BADSECTOR TROJAN!
Source=Paul Collins Startup list
[Shell]
Confirmed=X
Filename=ray.exe
Description=Homepage hijacker re-directing browsers to adult content websites
Source=Paul Collins Startup list
[Shell]
Confirmed=X
Filename=Tray.exe
Description=Homepage hijacker re-directing browsers to adult content websites
Source=Paul Collins Startup list
[Shell]
Confirmed=X
Filename=wmedia16.exe
Description=Added by the GOLDUN TROJAN!
Source=Paul Collins Startup list
[Shell Extension]
Confirmed=X
Filename=spollsv.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[ShellApi]
Confirmed=X
Filename=SHELLMSN.EXE
Description=Added by the NETDEV.B TROJAN!
Source=Paul Collins Startup list
[Shellapi32]
Confirmed=X
Filename=Shellapi32.exe
Description=Added by the NETDEVIL (or NERTE) TROJAN!
Source=Paul Collins Startup list
[ShellCommand]
Confirmed=X
Filename=[path to file]
Description=Added by the REMCON-A TROJAN!
Source=Paul Collins Startup list
[ShellEx]
Confirmed=X
Filename=ShellEx.exe
Description=Added by the ANAKHA TROJAN!
Source=Paul Collins Startup list
[shellsystem]
Confirmed=X
Filename=shellsystem.exe
Description=Added by the UPCHAN TROJAN!
Source=Paul Collins Startup list
[shicoxp]
Confirmed=N
Filename=shicoxp.exe
Description=Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
Source=Paul Collins Startup list
[Shine]
Confirmed=X
Filename=Shine.exe
Description=Added by the HAPPYLOW (or NISHE-A) VIRUS!
Source=Paul Collins Startup list
[SHINITV]
Confirmed=?
Filename=shinitv.exe
Description=??
Source=Paul Collins Startup list
[Shmgrate.exe]
Confirmed=X
Filename=ibot4.exe
Description=Added by the GASTER TROJAN!
Source=Paul Collins Startup list
[ShockmachineReminder]
Confirmed=N
Filename=SmReminder.exe
Description=Shockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version
Source=Paul Collins Startup list
[Shockwave]
Confirmed=X
Filename=csrss.exe
Description=Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Shockwave Init]
Confirmed=N
Filename=SWINIT.EXE
Description=Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
Source=Paul Collins Startup list
[ShortKeys 99]
Confirmed=N
Filename=SHORTKEY.EXE
Description=ShortKeys from Insight Software Solutions - allows you to program keys with text strings
Source=Paul Collins Startup list
[Showbehind]
Confirmed=X
Filename=SHOWBEHIND.EXE
Description=Advertisement display which can be stopped here
Source=Paul Collins Startup list
[ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051]
Confirmed=?
Filename=shwicon.exe
Description=Card reader for memory cards from digital cameras. Is it required?
Source=Paul Collins Startup list
[SHPC32]
Confirmed=U
Filename=SHPC32.exe
Description=Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
Source=Paul Collins Startup list
[ShStatEXE]
Confirmed=Y
Filename=SHSTAT.EXE
Description=From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs
Source=Paul Collins Startup list
[Shutdownaware]
Confirmed=U
Filename=shutdownaware.exe
Description=Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system
Source=Paul Collins Startup list
[ShutDownPro]
Confirmed=U
Filename=ShutDownPro.exe
Description=ShutDownPro - shutdown, reboot, logoff your System with one mouse click
Source=Paul Collins Startup list
[Si Meter]
Confirmed=?
Filename=SIMETER.EXE
Description=??
Source=Paul Collins Startup list
[si91e44b]
Confirmed=X
Filename=rundll32.exe [path] si91e44b.dll, EnableRunDLL32
Description=LZIO.com adware downloader
Source=Paul Collins Startup list
[Sicom]
Confirmed=X
Filename=Sicom.exe
Description=Added by the NETLIP WORM!
Source=Paul Collins Startup list
[SideACT]
Confirmed=U
Filename=SideACT.exe
Description=SideACT organizer software
Source=Paul Collins Startup list
[Sidebar]
Confirmed=X
Filename=Sidebar.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[SideWinderTrayV4]
Confirmed=N
Filename=SWTrayV4.exe
Description=MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
Source=Paul Collins Startup list
[SigX]
Confirmed=?
Filename=sigx.exe
Description=??
Source=Paul Collins Startup list
[SigXC]
Confirmed=X
Filename=SigX.exe
Description=SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"
Source=Paul Collins Startup list
[Simcast]
Confirmed=N
Filename=SimcastAlerts.exe
Description=Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say
Source=Paul Collins Startup list
[SimpLite-MSN]
Confirmed=U
Filename=SimpLite-MSN.exe
Description=Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
Source=Paul Collins Startup list
[Singapore]
Confirmed=X
Filename=singapore.exe
Description=Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself
Source=Paul Collins Startup list
[SIPPS]
Confirmed=U
Filename=SIPPS\SIPPS.exe
Description=Web.de Internet phone utility
Source=Paul Collins Startup list
[SiS KHooker]
Confirmed=N
Filename=khooker.exe
Description=SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
Source=Paul Collins Startup list
[SiS Tray]
Confirmed=U
Filename=sistray.exe
Description=System Tray icon for SiS based graphics. Note - this resides in C:\Windows\System
Source=Paul Collins Startup list
[SiS Windows KeyHook]
Confirmed=U
Filename=keyhook.exe
Description=SIS graphics cards related: "Super VGA Keyboard Daemon" - hooks into the keyboard processing chain in order to enable hotkey settings
Source=Paul Collins Startup list
[SISAM10M]
Confirmed=?
Filename=SISAM10M.exe
Description=??
Source=Paul Collins Startup list
[SiSAudio]
Confirmed=N
Filename=MP_S3.exe
Description=WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems
Source=Paul Collins Startup list
[siscolor]
Confirmed=U
Filename=color.exe
Description=Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
Source=Paul Collins Startup list
[siService.exe]
Confirmed=U
Filename=siService.exe
Description=Spam Inspector - anti email spam software
Source=Paul Collins Startup list
[SiSSetCDfmt]
Confirmed=?
Filename=SiSSetCDfmt.exe
Description=Related to a Silicon Integrated Systems Corp (SiS) product?
Source=Paul Collins Startup list
[SISSoundman]
Confirmed=?
Filename=Soundman.exe
Description=Related to a Silicon Integrated Systems Corp (SiS) product?
Source=Paul Collins Startup list
[SiSSWLED]
Confirmed=U
Filename=sisswled.exe
Description=System Tray utility for SiS 900 network cards
Source=Paul Collins Startup list
[sistrai.exe]
Confirmed=X
Filename=sistrai.exe
Description=Added by the PROVA TROJAN!
Source=Paul Collins Startup list
[sistray]
Confirmed=X
Filename=sistray.exe
Description=Added by the PROVA TROJAN!
Source=Paul Collins Startup list
[sistray]
Confirmed=U
Filename=sistray.exe
Description=System Tray icon for SiS based graphics. Note - this resides in C:\Windows\System
Source=Paul Collins Startup list
[sistry]
Confirmed=X
Filename=sistry.exe
Description=Added by the CEBE WORM!
Source=Paul Collins Startup list
[SiSUSBRG]
Confirmed=N
Filename=SiSUSBrg.exe
Description=SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
Source=Paul Collins Startup list
[SK9910DM]
Confirmed=U
Filename=SK9910DM.EXE
Description=Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Source=Paul Collins Startup list
[SKDAEMON]
Confirmed=U
Filename=SKDAEMON.EXE
Description=Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Source=Paul Collins Startup list
[skinkers]
Confirmed=U
Filename=skinkers.exe
Description=Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages
Source=Paul Collins Startup list
[SkyBlaster Scheduler]
Confirmed=Y
Filename=SSFSch.exe
Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Source=Paul Collins Startup list
[skynetave.exe]
Confirmed=X
Filename=skynetave.exe
Description=Added by the SASSER.D WORM!
Source=Paul Collins Startup list
[SkynetRevenge]
Confirmed=X
Filename=winlogon.scr
Description=Added by the NETSKY.AA WORM!
Source=Paul Collins Startup list
[Skype]
Confirmed=N
Filename=Skype.exe
Description="Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes"
Source=Paul Collins Startup list
[SkySurfer Management Service]
Confirmed=Y
Filename=SmaServ.exe
Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Source=Paul Collins Startup list
[SleepManager]
Confirmed=N
Filename=SleepMgr.exe
Description=This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode
Source=Paul Collins Startup list
[SlickRun]
Confirmed=U
Filename=sr.exe
Description="SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:\Program Files\Outlook Express\msimn.exe becomes MAIL"
Source=Paul Collins Startup list
[slide]
Confirmed=X
Filename=Iexplore.exe
Description=Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[slimp3]
Confirmed=N
Filename=SliMP3 Server.exe
Description=Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC"
Source=Paul Collins Startup list
[Slingshot]
Confirmed=N
Filename=SLINGS~1.EXE
Description=Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more"
Source=Paul Collins Startup list
[slmss]
Confirmed=X
Filename=slmss.exe
Description=SeekSeek search hijacker related - as seen here
Source=Paul Collins Startup list
[slvchost32]
Confirmed=X
Filename=slvchost32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[SM1BG]
Confirmed=?
Filename=SM1BG.EXE
Description=USB driver for downloading from within Napster to portable MP3 players. Is it required to run at startup or can it be run manually?
Source=Paul Collins Startup list
[Sm56acl]
Confirmed=N
Filename=sm56hlpr.exe
Description=Helper utility for Motorola based SM56 software modems - resides in the System Tray
Source=Paul Collins Startup list
[Smapp]
Confirmed=N
Filename=smtray.exe
Description=System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller
Source=Paul Collins Startup list
[Smart Card Service]
Confirmed=N
Filename=ScardSvr.exe
Description=For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly
Source=Paul Collins Startup list
[Smart Connect Monitor]
Confirmed=U
Filename=SCMon.exe
Description=Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Source=Paul Collins Startup list
[Smart Connect Setup]
Confirmed=U
Filename=SCSetup.exe
Description=Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Source=Paul Collins Startup list
[Smart Label O Server]
Confirmed=N
Filename=ssloserv.exe
Description=Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
Source=Paul Collins Startup list
[Smart Label RFViewer]
Confirmed=N
Filename=SSLFVIEW.EXE
Description=Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
Source=Paul Collins Startup list
[Smart Type Assistant]
Confirmed=N
Filename=sta.exe
Description=Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer
Source=Paul Collins Startup list
[Smartalec]
Confirmed=U
Filename=pcaccel.exe
Description=Smartalec PC Accelerator - system optimization utility
Source=Paul Collins Startup list
[SmartBarXP]
Confirmed=N
Filename=SmartBarXP.exe
Description=SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few
Source=Paul Collins Startup list
[sMaRTcaPs]
Confirmed=N
Filename=SMARTC~1.EXE
Description=sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys
Source=Paul Collins Startup list
[Smarthruengine]
Confirmed=?
Filename=QS.exe
Description=Unknown but disabled without problems
Source=Paul Collins Startup list
[SmartPCXL]
Confirmed=U
Filename=pcaccel.exe
Description=Smartalec PC Accelerator - system optimization utility
Source=Paul Collins Startup list
[SMax4]
Confirmed=N
Filename=SMax4.exe
Description=System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
Source=Paul Collins Startup list
[SMax4PNP]
Confirmed=U
Filename=SMax4PNP.exe
Description=SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
Source=Paul Collins Startup list
[smbdpmi]
Confirmed=?
Filename=smbdpmi.exe
Description=IBM Netfinity Director and Universal Management Services related. What does it do and is it required?
Source=Paul Collins Startup list
[smc]
Confirmed=Y
Filename=smc.exe
Description=Sygate Firewall
Source=Paul Collins Startup list
[smc]
Confirmed=Y
Filename=spfsmc.exe
Description=Sygate Firewall
Source=Paul Collins Startup list
[SMC Service]
Confirmed=Y
Filename=smc.exe
Description=Sygate Firewall
Source=Paul Collins Startup list
[SMC Service]
Confirmed=Y
Filename=spfsmc.exe
Description=Sygate Firewall
Source=Paul Collins Startup list
[smcserv]
Confirmed=X
Filename=winsrv.exe
Description=Added by the AGOBOT-OU WORM!
Source=Paul Collins Startup list
[SmcServices]
Confirmed=Y
Filename=smc.exe
Description=Sygate Firewall
Source=Paul Collins Startup list
[SmcServices]
Confirmed=Y
Filename=spfsmc.exe
Description=Sygate Firewall
Source=Paul Collins Startup list
[Smcsta.exe]
Confirmed=?
Filename=Smcsta.exe
Description=SMC Networks wireless PCI card driver. Is it required?
Source=Paul Collins Startup list
[Smith Micro try]
Confirmed=N
Filename=smiptray.exe
Description=Smith Micro shared files. Comes with D-Link web cam
Source=Paul Collins Startup list
[SMS Application Launcher]
Confirmed=U
Filename=LAUNCH32.EXE
Description=Microsoft Systems Management Server - used to manage computers on a network remotely
Source=Paul Collins Startup list
[SMS Client Service]
Confirmed=U
Filename=clisvc95.exe
Description=When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server)
Source=Paul Collins Startup list
[SMS Win9x Message Agent]
Confirmed=U
Filename=??
Description=This program assigns a user to a Systems Management Server site
Source=Paul Collins Startup list
[SMS Win9x Message Agent]
Confirmed=U
Filename=SMSMsg.exe
Description=This program assigns a user to a Systems Management Server site
Source=Paul Collins Startup list
[Smserial]
Confirmed=Y
Filename=sm56hlpr.exe
Description=Motorola based modem driver
Source=Paul Collins Startup list
[SMSI Loader]
Confirmed=N
Filename=SMLoader.exe
Description=Smith Micro HotFax - fax software
Source=Paul Collins Startup list
[SMSS]
Confirmed=X
Filename=smss.exe
Description=Added by the FLOOD.F TROJAN! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[smss]
Confirmed=X
Filename=[path to smss.exe]
Description=Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[SMSSS]
Confirmed=X
Filename=smsss.exe
Description=Added by the SDBOT.ZD WORM!
Source=Paul Collins Startup list
[SMSSS Loader]
Confirmed=X
Filename=smsss.exe
Description=Added by the AGOBOT.MQ WORM!
Source=Paul Collins Startup list
[smsys]
Confirmed=X
Filename=Explorer.exe
Description=Added by the CLICKER-C TROJAN! Note - the valid "explorer.exe" is located in C:\Windows or C:\Winnt whereas this one is located in a C:\Windows\Template or C:\Winnt\Template subdirectory
Source=Paul Collins Startup list
[smsys]
Confirmed=X
Filename=vi.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[SMToolbar]
Confirmed=N
Filename=SMToolbar.exe
Description=StartMake.com toolbar
Source=Paul Collins Startup list
[SmWizard]
Confirmed=?
Filename=SmWizard.exe
Description=SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
Source=Paul Collins Startup list
[snbr]
Confirmed=?
Filename=snbr.exe
Description=??
Source=Paul Collins Startup list
[sncntr]
Confirmed=X
Filename=sncntr.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Sndcompat]
Confirmed=X
Filename=Sndcompat.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[SNDMon]
Confirmed=U
Filename=SNDMon.exe
Description=Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation
Source=Paul Collins Startup list
[Sndsaver]
Confirmed=X
Filename=Sndsaver.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[sndsrvc]
Confirmed=?
Filename=SNDSRVC.EXE
Description=Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required?
Source=Paul Collins Startup list
[Snsicon]
Confirmed=N
Filename=Snsicon.exe
Description=Launches a screensaver program from Second Nature
Source=Paul Collins Startup list
[SO5 Integrator Pass One]
Confirmed=?
Filename=sointgr.exe
Description=StarOffice 5. See here for more details
Source=Paul Collins Startup list
[SO5 Integrator Pass Two]
Confirmed=?
Filename=sointgr.exe
Description=StarOffice 5. See here for more details
Source=Paul Collins Startup list
[Soar]
Confirmed=X
Filename=Rwon.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[Sock32]
Confirmed=X
Filename=sock32.exe
Description=Added by the SDBOT TROJAN!
Source=Paul Collins Startup list
[SoDA Startup]
Confirmed=Y
Filename=SodaStartup.exe
Description=Used by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software
Source=Paul Collins Startup list
[soffice]
Confirmed=N
Filename=SOFFICE.EXE
Description=Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
Source=Paul Collins Startup list
[Soft Profile Inc]
Confirmed=X
Filename=hxdef.exe...
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[SOFTinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[Software]
Confirmed=X
Filename=software.exe
Description=Added by the CRABTON-B TROJAN!
Source=Paul Collins Startup list
[Solo Sentry]
Confirmed=Y
Filename=Solosent.exe
Description=Solo Antivirus
Source=Paul Collins Startup list
[SoloSchedule]
Confirmed=U
Filename=Solocfg.exe
Description=Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis
Source=Paul Collins Startup list
[SoloSysCheck]
Confirmed=U
Filename=Syscheck.exe
Description=Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors
Source=Paul Collins Startup list
[somatic]
Confirmed=X
Filename=somatic.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[Sonic A3D Control]
Confirmed=N
Filename=vrtxctrl.exe
Description=Sound related options
Source=Paul Collins Startup list
[SoniqueQuickStart]
Confirmed=N
Filename=sqstart.exe
Description=Quickstart for Sonique audio player. Available via Start -> Programs
Source=Paul Collins Startup list
[SonnReg]
Confirmed=?
Filename=SonnReg.exe
Description=Part of E-Color 3Deep for color calibration. Possibly a registration reminder?
Source=Paul Collins Startup list
[Soot]
Confirmed=?
Filename=rcea.exe
Description=??
Source=Paul Collins Startup list
[sophagnt]
Confirmed=?
Filename=sophagnt.exe
Description=Possibly related to Sophocles Screenwriting Software?
Source=Paul Collins Startup list
[SOS]
Confirmed=X
Filename=SOS.exe
Description=Added by the PHILIS VIRUS!
Source=Paul Collins Startup list
[SoSyncMonitor]
Confirmed=?
Filename=SoSyncMonitor.exe
Description=SuperOffice related. What does it do and is it required?
Source=Paul Collins Startup list
[Sound Loader]
Confirmed=X
Filename=sndloader.exe
Description=Added by the AGOBOT-BV WORM!
Source=Paul Collins Startup list
[Sound services]
Confirmed=X
Filename=SOUND32.EXE
Description=Added by the AGOBOT.GG WORM!
Source=Paul Collins Startup list
[Sound System]
Confirmed=X
Filename=WinSound1.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[soundcontrl]
Confirmed=X
Filename=soundcontrl.exe
Description=Added by the GAOBOT.AFJ WORM!
Source=Paul Collins Startup list
[sounddrv]
Confirmed=X
Filename=sndbdrv3104.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[SoundFusion]
Confirmed=?
Filename=rundll32 cwcprops.cpl
Description=Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
Source=Paul Collins Startup list
[SoundFusion]
Confirmed=?
Filename=rundll32 hercplgs.cpl, BootEntryPoint
Description=Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
Source=Paul Collins Startup list
[soundman]
Confirmed=N
Filename=soundman.exe
Description=System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel
Source=Paul Collins Startup list
[SoundMAX]
Confirmed=N
Filename=SMax4.exe
Description=System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
Source=Paul Collins Startup list
[SoundMAXPnP]
Confirmed=U
Filename=SMax4PNP.exe
Description=SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
Source=Paul Collins Startup list
[SoundMixer]
Confirmed=X
Filename=smvss.exe
Description=Added by the DEDLER-G TROJAN!
Source=Paul Collins Startup list
[Soundmx]
Confirmed=X
Filename=Soundmx.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[soundtask]
Confirmed=X
Filename=soundtask.exe
Description=Added by the AGOBOT-MD WORM!
Source=Paul Collins Startup list
[soundtasks]
Confirmed=X
Filename=soundtasks.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[soundtctrls]
Confirmed=X
Filename=soundtctrls.exe
Description=Added by the AGOBOT-ZV WORM!
Source=Paul Collins Startup list
[SoundView]
Confirmed=X
Filename=msdview32.exe
Description=Trojan downloader
Source=Paul Collins Startup list
[sounofts]
Confirmed=X
Filename=sounofts.exe
Description=Added by the AGOBOT-ND WORM!
Source=Paul Collins Startup list
[SourcePath]
Confirmed=N
Filename=gwreg.exe
Description=Used to update Gateway registry settings for System Restoration Kit and Web update programs
Source=Paul Collins Startup list
[sp]
Confirmed=X
Filename=sp.reg
Description=IE search hijacker - changes the default search to http://www.gocybersearch.com/
Source=Paul Collins Startup list
[sp]
Confirmed=X
Filename=regedit-s .... sp.dll
Description=Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix
Source=Paul Collins Startup list
[SP TimeSync]
Confirmed=U
Filename=SP TimeSync.exe
Description=SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server)
Source=Paul Collins Startup list
[SP00LSV]
Confirmed=X
Filename=Sp00lsv.exe
Description=Added by the GRAYBIRD.E TROJAN!
Source=Paul Collins Startup list
[sp2ctr]
Confirmed=X
Filename=sp2ctr.exe
Description=Added by the DLUCA-M TROJAN!
Source=Paul Collins Startup list
[Spam Sleuth]
Confirmed=U
Filename=SpamSleuth.exe
Description=Spam Sleuth E-mail spam detection program
Source=Paul Collins Startup list
[spamihilator]
Confirmed=U
Filename=spamihilator.exe
Description=Spamihilator - spam filter
Source=Paul Collins Startup list
[SpamPal]
Confirmed=U
Filename=spampal.exe
Description=SpamPal - anti-spam tool
Source=Paul Collins Startup list
[SpamSubtract]
Confirmed=U
Filename=SpamSubtract.exe
Description=Intermute SpamSubtract - junk email detection and removal program
Source=Paul Collins Startup list
[spc_w]
Confirmed=N
Filename=hcm.exe
Description=NetZero Search related
Source=Paul Collins Startup list
[Spdstart]
Confirmed=N
Filename=Spdstart.exe
Description=Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel."
Source=Paul Collins Startup list
[Speaking Clock Deluxe]
Confirmed=U
Filename=SpClDlx.exe
Description=Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly
Source=Paul Collins Startup list
[Special Firewall Service]
Confirmed=X
Filename=avguard.exe
Description=Added by the NETSKY.G WORM!
Source=Paul Collins Startup list
[SpecialOffers]
Confirmed=X
Filename=SpecialOffers*.exe [* = digit]
Description=Specialoffersnetworks.com adware. "Special Offers is a state of the art advertising product that delivers to you contextually relevant web offers including discounts and coupons"
Source=Paul Collins Startup list
[SpecialOffers]
Confirmed=X
Filename=SpecialOffers.exe
Description=Specialoffersnetworks.com adware. "Special Offers is a state of the art advertising product that delivers to you contextually relevant web offers including discounts and coupons"
Source=Paul Collins Startup list
[Speed racer]
Confirmed=N
Filename=CTSRReg.exe
Description=Software for a Creative sound card
Source=Paul Collins Startup list
[Speed Tec]
Confirmed=U
Filename=speedtec.exe
Description=Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled
Source=Paul Collins Startup list
[SpeedBoss]
Confirmed=X
Filename=[worm filename]
Description=Added by the OPASERV.AD WORM!
Source=Paul Collins Startup list
[Speedkey]
Confirmed=U
Filename=SPEEDKEY.EXE
Description=Additional keyboard shortcuts on MS programmable keyboard
Source=Paul Collins Startup list
[SpeedMeter]
Confirmed=U
Filename=SpeedMeter.exe
Description=Application measuring upload and download speed
Source=Paul Collins Startup list
[SpeedOptimizer]
Confirmed=U
Filename=spo.exe
Description=SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication
Source=Paul Collins Startup list
[Speedtouch USB Diagnostics]
Confirmed=U
Filename=Dragdiag.exe
Description=For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
Source=Paul Collins Startup list
[Spees1]
Confirmed=X
Filename=speedy.scr
Description=Added by the OPASERV.Y WORM!
Source=Paul Collins Startup list
[Spees2]
Confirmed=X
Filename=Speedy.bat
Description=Added by the OPASERV.AD WORM!
Source=Paul Collins Startup list
[Spees3]
Confirmed=X
Filename=SPEEDY.PIF
Description=Added by the OPASERV.AD WORM!
Source=Paul Collins Startup list
[Spellex Anywhere]
Confirmed=N
Filename=sa.exe
Description=Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used
Source=Paul Collins Startup list
[SpIDerMail]
Confirmed=Y
Filename=spiderml.exe
Description=DrWeb antivirus Spider Mail e-mail scanner
Source=Paul Collins Startup list
[Spinner Plus]
Confirmed=N
Filename=spinner.exe
Description="Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs
Source=Paul Collins Startup list
[SPINX]
Confirmed=X
Filename=Wscript.exe OXNEY.B.VBS
Description=Added by the YENO.B and YENO.C WORMS!
Source=Paul Collins Startup list
[SPnt]
Confirmed=X
Filename=SPnt.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[SpokeSysTray]
Confirmed=U
Filename=SpokeSysTray.exe
Description=Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry"
Source=Paul Collins Startup list
[spoo1sv]
Confirmed=X
Filename=spoo1sv.exe
Description=Added by the SOULJET TROJAN!
Source=Paul Collins Startup list
[Spool]
Confirmed=X
Filename=[path to trojan]
Description=Added by the RANKY.R TROJAN!
Source=Paul Collins Startup list
[SPOOL Configuration]
Confirmed=X
Filename=spoolsvc.exe
Description=Added by the SDBOT-KD WORM!
Source=Paul Collins Startup list
[Spool lptt01]
Confirmed=X
Filename=spool.exe
Description=Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Spool ml097e]
Confirmed=X
Filename=spool.exe
Description=Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Spooler Service]
Confirmed=X
Filename=Spoolsrv.exe
Description=Added by the JOINER.C1 TROJAN!
Source=Paul Collins Startup list
[Spooler Sub System Process]
Confirmed=X
Filename=SPOOL32.EXE
Description=Added by the YAB.A TROJAN!
Source=Paul Collins Startup list
[Spooler Subsytem App]
Confirmed=X
Filename=spoolsvc.exe
Description=Added by the SDBOT-MM WORM!
Source=Paul Collins Startup list
[SpoolerSubSystemProcess]
Confirmed=X
Filename=SpooI32.exe
Description=Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a captial "i" not a lower case "L"
Source=Paul Collins Startup list
[spoolserv]
Confirmed=X
Filename=spoolserv.exe
Description=Added by the SDBOT-PN WORM!
Source=Paul Collins Startup list
[SpoolService]
Confirmed=X
Filename=spolsv.exe
Description=Added by the AGOBOT-CS WORM!
Source=Paul Collins Startup list
[Spoolsv]
Confirmed=X
Filename=Spoolsv.exe
Description=Added by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
Source=Paul Collins Startup list
[spoolsv]
Confirmed=X
Filename=scvhosts.exe
Description=Added by the SMALL-AW TROJAN!
Source=Paul Collins Startup list
[spoolsvr32]
Confirmed=X
Filename=csmss.exe
Description=Added by the AGENT-AU TROJAN!
Source=Paul Collins Startup list
[spoolsvr32]
Confirmed=X
Filename=csmss32.exe
Description=Added by a variant of the AGENT-AU TROJAN!
Source=Paul Collins Startup list
[spoolsvv]
Confirmed=X
Filename=spoolsvv.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[Spore]
Confirmed=X
Filename=MsNews.vbs
Description=Added by the SPORE.A WORM!
Source=Paul Collins Startup list
[Spore.b]
Confirmed=X
Filename=Scmhlpr.vbs
Description=Added by the SPORE.B WORM!
Source=Paul Collins Startup list
[SPP]
Confirmed=?
Filename=run.exe
Description=??
Source=Paul Collins Startup list
[spp]
Confirmed=X
Filename=regedit -s spp.reg
Description=IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/
Source=Paul Collins Startup list
[sppbridge]
Confirmed=?
Filename=sppbridge.exe
Description=Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually?
Source=Paul Collins Startup list
[SprintPort]
Confirmed=?
Filename=SprintPortA.exe
Description=Novatel wireless modem related. What does it do and is it required?
Source=Paul Collins Startup list
[SPSTEALT]
Confirmed=U
Filename=SmartProtectorPro.exe
Description=Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc
Source=Paul Collins Startup list
[spstore]
Confirmed=?
Filename=storesp.exe
Description=Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup
Source=Paul Collins Startup list
[Spy Blocker]
Confirmed=U
Filename=spyblocker.exe
Description=SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all
Source=Paul Collins Startup list
[SpyBlast]
Confirmed=X
Filename=SpyBlast.exe
Description=Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others
Source=Paul Collins Startup list
[SpyBlocs]
Confirmed=X
Filename=SpyBlocs.exe
Description=Rogue anti-spyware program
Source=Paul Collins Startup list
[SpybotSD TeaTimer]
Confirmed=U
Filename=TeaTimer.exe
Description=TeaTimer is a new tool of Spybot S&D - spam filter which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future
Source=Paul Collins Startup list
[SpyBotSnD]
Confirmed=U
Filename=Spybotsd.exe
Description=Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla
Source=Paul Collins Startup list
[Spybott lptt01]
Confirmed=X
Filename=spybott.exe
Description=Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Spybott ml097e]
Confirmed=X
Filename=spybott.exe
Description=Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[SpyCop ScanCheck]
Confirmed=U
Filename=MAIN.EXE
Description=SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
Source=Paul Collins Startup list
[SpyHunter]
Confirmed=N
Filename=SpyHunter.exe
Description=SpyHunter - spyware remover of somewhat dubious repute, see note
Source=Paul Collins Startup list
[Spykiller]
Confirmed=U
Filename=Spykiller.exe
Description=Shareware "Spyware remover" of questionable quality and repute. There are better alternatives that are freeware to boot
Source=Paul Collins Startup list
[SpyNuker]
Confirmed=X
Filename=Spynuker.exe
Description=A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages
Source=Paul Collins Startup list
[SpySpotter]
Confirmed=N
Filename=SpySpotter.exe
Description=Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Source=Paul Collins Startup list
[SpyStopper]
Confirmed=U
Filename=spystopper.exe
Description=SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked
Source=Paul Collins Startup list
[SpySubtract]
Confirmed=U
Filename=SpySub.exe
Description=SpySubtract - multi spyware removal tool
Source=Paul Collins Startup list
[SpySweeper]
Confirmed=U
Filename=SpySweeper.exe
Description=Spy Sweeper - detects and removes spyware
Source=Paul Collins Startup list
[Spyware]
Confirmed=X
Filename=Spyware.exe
Description=
BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!
Source=Paul Collins Startup list
[Spyware Begone]
Confirmed=N
Filename=SpywareBeGone.exe
Description=Spyware BeGone - free spyware removal utility. Not recommended - see note
Source=Paul Collins Startup list
[Spyware Begone]
Confirmed=N
Filename=freescan.exe
Description=Spyware BeGone - free spyware removal utility. Not recommended - see note
Source=Paul Collins Startup list
[Spyware Doctor]
Confirmed=U
Filename=spydoctor.exe
Description=Spyware Doctor spyware remover
Source=Paul Collins Startup list
[Spyware Doctor]
Confirmed=U
Filename=swdoctor.exe
Description=Spyware Doctor spyware remover
Source=Paul Collins Startup list
[Spyware Guard Control Panel]
Confirmed=U
Filename=spywar~1.exe
Description=
"SpywareGuard provides a real-time protection solution against spyware"
Source=Paul Collins Startup list
[Spyware Nuker Installer]
Confirmed=X
Filename=SpywareNukerInstaller.exe
Description=
A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages
Source=Paul Collins Startup list
[Spyware remover]
Confirmed=X
Filename=Remove_spyware.exe
Description=Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related!
Source=Paul Collins Startup list
[Spyware Scanner]
Confirmed=U
Filename=AseScanner.exe
Description=Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
Source=Paul Collins Startup list
[Spyware Slayer]
Confirmed=X
Filename=SpywareSlayer.Exe
Description=Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Source=Paul Collins Startup list
[Spyware Stormer]
Confirmed=N
Filename=SpywareStormer.Exe
Description=SpywareStormer spyware remover. Not recommended - see here
Source=Paul Collins Startup list
[Spyware Vanisher]
Confirmed=X
Filename=FreeScanner.exe
Description=Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Source=Paul Collins Startup list
[SpywareGuard]
Confirmed=U
Filename=sgmain.exe
Description=
"SpywareGuard provides a real-time protection solution against spyware"
Source=Paul Collins Startup list
[SpywareGuard]
Confirmed=X
Filename=winproc32.exe
Description=Startpage adware Trojan
Source=Paul Collins Startup list
[Spywareguard lptt01]
Confirmed=X
Filename=Spywareguard.exe
Description=Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Spywareguard ml097e]
Confirmed=X
Filename=Spywareguard.exe
Description=Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[SpywareGuardPlus]
Confirmed=X
Filename=winmm64.exe
Description=StartPage.ht homepage hijacker
Source=Paul Collins Startup list
[SpywareKilla]
Confirmed=N
Filename=SpywareKilla.exe
Description=Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites"
Source=Paul Collins Startup list
[SPYWATCH]
Confirmed=U
Filename=SpyWatch.exe
Description=
BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!
Source=Paul Collins Startup list
[SQConfigChecker]
Confirmed=X
Filename=cc.exe
Description=Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
Source=Paul Collins Startup list
[SQInstaller]
Confirmed=X
Filename=SQInstaller.exe
Description=Xupiter hijacker
Source=Paul Collins Startup list
[SQL Server]
Confirmed=N
Filename=scm.exe
Description=SQL Server Service Control Manager. Available via Start -> Programs
Source=Paul Collins Startup list
[SQUpdatesChecker]
Confirmed=X
Filename=uc.exe
Description=Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
Source=Paul Collins Startup list
[sqvynikp]
Confirmed=X
Filename=sqvynikp.exe
Description=Free_Scratch_Cards foistware
Source=Paul Collins Startup list
[sr1exe]
Confirmed=?
Filename=updtSup3.exe
Description=Found on a Dell computer, in a Documents and SettingsAll UsersApplication DataDellAlert2 subfolder
Source=Paul Collins Startup list
[sr64]
Confirmed=X
Filename=********. exe
Description=Adware, as yet unidentified
Source=Paul Collins Startup list
[SrchfstUpdate]
Confirmed=X
Filename=srchupdt.exe
Description=SearchFast adware downloader
Source=Paul Collins Startup list
[SRFirstRun]
Confirmed=?
Filename=rundll32 srclient.dll, CreateFirstRunRp
Description=Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup?
Source=Paul Collins Startup list
[Srmclean]
Confirmed=U
Filename=srmclean.exe
Description=Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card"
Source=Paul Collins Startup list
[SRNG]
Confirmed=X
Filename=srng.exe
Description=Search hijacker - see here
Source=Paul Collins Startup list
[SRP Startup]
Confirmed=U
Filename=srrpro.exe
Description=System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features." This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[SRS Applet]
Confirmed=Y
Filename=SrsTray.Exe
Description=S3 Sonic Vibes sound card drivers - if disabled you loose sound
Source=Paul Collins Startup list
[Srv RPCrom]
Confirmed=X
Filename=NClienti386.exe
Description=Added by the WATSOON.A TROJAN!
Source=Paul Collins Startup list
[Srv32]
Confirmed=X
Filename=Srv32.exe
Description=Added by the OPASERV.J WORM!
Source=Paul Collins Startup list
[Srv32]
Confirmed=X
Filename=Srv32.exe
Description=Added by the OPASERV.S WORM!
Source=Paul Collins Startup list
[Srv32 spool service]
Confirmed=X
Filename=runsrv32.exe
Description=Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b
Source=Paul Collins Startup list
[Srv32 spool service]
Confirmed=X
Filename=spoolsrv32.exe
Description=Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b
Source=Paul Collins Startup list
[Srv32Old]
Confirmed=X
Filename=[worm filename].PIF
Description=Added by the OPASERV.J WORM!
Source=Paul Collins Startup list
[Srv32Win]
Confirmed=U
Filename=SpyAgent4.exe
Description=SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Source=Paul Collins Startup list
[Srv32Win]
Confirmed=U
Filename=Svchost.exe
Description=Realtime-Spy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
Source=Paul Collins Startup list
[Srv32Win]
Confirmed=X
Filename=sysdiag.exe
Description=NetVizor keystroke logger
Source=Paul Collins Startup list
[srvexc.exe]
Confirmed=X
Filename=srvexc.exe
Description=Added by the SERVSAX TROJAN!
Source=Paul Collins Startup list
[ssate.exe]
Confirmed=X
Filename=irun4.exe
Description=Added by the BEAGLE.J WORM!
Source=Paul Collins Startup list
[ssate.exe]
Confirmed=X
Filename=winsys.exe
Description=Added by the BEAGLE.K WORM!
Source=Paul Collins Startup list
[SSBkgdUpdate]
Confirmed=N
Filename=SSBkgdupdate.exe
Description=ScanSoft OmniPage auto updater. Can be disabled using the main program's options
Source=Paul Collins Startup list
[SSC_UserPrompt]
Confirmed=?
Filename=UsrPrmpt.exe
Description=Part of Symantec (Norton) Security Centre. What does it do, and is it required?
Source=Paul Collins Startup list
[Ssd]
Confirmed=Y
Filename=Std.exe
Description=Stealthdisk - file and folder hiding/locking utility
Source=Paul Collins Startup list
[ssdiag]
Confirmed=?
Filename=ssdiag.exe
Description=Equinox "Configuration and DOS Diagnostic for DOS and Windows platforms"
Source=Paul Collins Startup list
[SSDPSRV]
Confirmed=N
Filename=ssdpsrv.exe
Description=Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play
Source=Paul Collins Startup list
[ssgrate.exe]
Confirmed=X
Filename=system.exe
Description=Added by the MITGLIEDER.C TROJAN!
Source=Paul Collins Startup list
[ssgrate.exe]
Confirmed=X
Filename=irun.exe
Description=Added by the MITGLIEDER.D TROJAN!
Source=Paul Collins Startup list
[ssgrate.exe]
Confirmed=X
Filename=irun4.exe
Description=Added by the MITGLIEDER.F TROJAN!
Source=Paul Collins Startup list
[ssgrate.exe]
Confirmed=X
Filename=sysdoor.exe
Description=Added by the MITGLIEDER.N TROJAN!
Source=Paul Collins Startup list
[ssgrate.exe]
Confirmed=X
Filename=winerdir.exe
Description=Added by the MITGLIEDER.O TROJAN!
Source=Paul Collins Startup list
[SSK Service]
Confirmed=X
Filename=winssk32.exe
Description=Added by the SOBIG.E WORM!
Source=Paul Collins Startup list
[SSL]
Confirmed=X
Filename=svchost.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[ssmmgr]
Confirmed=U
Filename=ssmmgr.exe
Description=Samsung printer monitor - for checking ink levels, etc.
Source=Paul Collins Startup list
[sstata]
Confirmed=X
Filename=dwdas.exe
Description=Added by the DASDA TROJAN!
Source=Paul Collins Startup list
[SStb.exe]
Confirmed=X
Filename=SStb.exe
Description=Adpowerzone.com "ServerSide" keyword hijacker
Source=Paul Collins Startup list
[sstray]
Confirmed=N
Filename=sstray.exe
Description=nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
Source=Paul Collins Startup list
[SSUpdate]
Confirmed=X
Filename=SSUpdate.exe
Description=DyFuCa/MoneyTree parasite variant
Source=Paul Collins Startup list
[ssvchost]
Confirmed=X
Filename=ssvchost.exe
Description=Added by the HELIOS.B TROJAN!
Source=Paul Collins Startup list
[SSWPlauncher]
Confirmed=X
Filename=comet.exe /app:SSWPlauncher
Description=CometCursor by Comet Systems
Source=Paul Collins Startup list
[Stacmon]
Confirmed=N
Filename=Stacmon.exe
Description=Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
Source=Paul Collins Startup list
[Start]
Confirmed=Y
Filename=Quick95.exe
Description=For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
Source=Paul Collins Startup list
[Start]
Confirmed=X
Filename=windows.vbs
Description=Homepage hijacker
Source=Paul Collins Startup list
[start]
Confirmed=?
Filename=start.exe
Description=??
Source=Paul Collins Startup list
[Start Getright]
Confirmed=N
Filename=getright.exe
Description=See Getright Tray Icon
Source=Paul Collins Startup list
[Start Page]
Confirmed=X
Filename=http://find.naupoint.com
Description=Naupoint browser hijacker
Source=Paul Collins Startup list
[Start RF Wireless Keyboard]
Confirmed=Y
Filename=ktrexe.exe
Description=Yuanxun Electronics RF wireless keyboard driver
Source=Paul Collins Startup list
[Start RF Wireless Mouse]
Confirmed=Y
Filename=cm20.exe
Description=Yuanxun Electronics RF wireless mouse driver
Source=Paul Collins Startup list
[Start Service]
Confirmed=U
Filename=upssrv.exe
Description=Cyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner"
Source=Paul Collins Startup list
[Start Up Cop]
Confirmed=U
Filename=startcop.exe
Description=StartUp Cop - startup manager
Source=Paul Collins Startup list
[start uploading]
Confirmed=X
Filename=smsss.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Start Upping]
Confirmed=X
Filename=taskmrg.exe
Description=Added by the RBOT-MA WORM!
Source=Paul Collins Startup list
[Start Upping]
Confirmed=X
Filename=SVCHOSTES.EXE
Description=Added by the RBOT-NB WORM!
Source=Paul Collins Startup list
[Start Upping]
Confirmed=X
Filename=taksmgr.exe
Description=Added by the RBOT-QK WORM!
Source=Paul Collins Startup list
[Start Uppings]
Confirmed=X
Filename=svcchosts.exe
Description=Added by the SDBOT.VY WORM!
Source=Paul Collins Startup list
[Start Uppings]
Confirmed=X
Filename=mssupdate.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Start Wingman Profiler]
Confirmed=N
Filename=lwtest.exe
Description=Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked
Source=Paul Collins Startup list
[Start Wingman Profiler]
Confirmed=N
Filename=lwemon.exe
Description=Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked
Source=Paul Collins Startup list
[Startacc]
Confirmed=U
Filename=startacc.exe
Description=Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection
Source=Paul Collins Startup list
[StartEAK]
Confirmed=Y
Filename=StartEAK.exe
Description=Easy Access Button Support for Compaq PCs. Required if you use these
Source=Paul Collins Startup list
[starter]
Confirmed=X
Filename=scvhosting.exe
Description=Added by the IRCBOT.E TROJAN!
Source=Paul Collins Startup list
[Starter]
Confirmed=X
Filename=scvhosting.exe
Description=Added by the SDBOT.RU WORM!
Source=Paul Collins Startup list
[startl.exe]
Confirmed=N
Filename=startl.exe
Description=Lingocom LingoWare - translates any application into your language
Source=Paul Collins Startup list
[StartMenu]
Confirmed=X
Filename=s_menu.exe
Description=Added by a variant of the DELF-A TROJAN!
Source=Paul Collins Startup list
[startpage]
Confirmed=X
Filename=startpage.exe
Description=Browser hijacker - redirecting to pages2start.com
Source=Paul Collins Startup list
[STARTPAGE]
Confirmed=U
Filename=start1.exe
Description=NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder
Source=Paul Collins Startup list
[StartStop]
Confirmed=U
Filename=STARTSTOP.EXE
Description=StartStop from TFI Technology - startup manager
Source=Paul Collins Startup list
[StartSurfing]
Confirmed=U
Filename=STARTS.exe
Description=Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs
Source=Paul Collins Startup list
[Startup]
Confirmed=N
Filename=??
Description=Related to an Iomega drive
Source=Paul Collins Startup list
[Startup Launcher GUI]
Confirmed=?
Filename=GUI.exe
Description=Startup manager?
Source=Paul Collins Startup list
[Startup Update]
Confirmed=X
Filename=Cvshost.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[StartupMonitor]
Confirmed=U
Filename=StartupMonitor.exe
Description=Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
Source=Paul Collins Startup list
[startwindowskeyuser]
Confirmed=X
Filename=rundle2.exe
Description=Added by the JAVAKILLER TROJAN!
Source=Paul Collins Startup list
[Stat 'n' Perf]
Confirmed=N
Filename=StatnPerf.exe
Description=Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes
Source=Paul Collins Startup list
[StatBar]
Confirmed=X
Filename=STATBAR.exe
Description=StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 95/98/SE/Me
Source=Paul Collins Startup list
[Status Monitor]
Confirmed=N
Filename=BrMfcWnd.exe
Description=Brother scanner status monitor - can be started manually
Source=Paul Collins Startup list
[Status Monitor XE]
Confirmed=N
Filename=ENGSS.EXE
Description=The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
Source=Paul Collins Startup list
[StatusClient 2.6]
Confirmed=?
Filename=StatusClient.exe
Description=Part of Hewlett Packard network printer drivers.
Source=Paul Collins Startup list
[Stay Connected!]
Confirmed=N
Filename=StayCon.exe
Description=More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs
Source=Paul Collins Startup list
[StayAlive]
Confirmed=U
Filename=sa.exe
Description=StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work."
Source=Paul Collins Startup list
[STBVision]
Confirmed=?
Filename=STBVisn.exe
Description=Related to the STB Velocity graphics card. What does it do and is it required?
Source=Paul Collins Startup list
[STBWEBTV]
Confirmed=N
Filename=STBWEBTV.EXE
Description=Used to display TV on your PC
Source=Paul Collins Startup list
[stcinstaller]
Confirmed=X
Filename=id53.exe
Description=Added by the SCTHOUGHT.L TROJAN!
Source=Paul Collins Startup list
[stcloader]
Confirmed=X
Filename=stcloader.exe
Description=Popup adware by 2ndThought software
Source=Paul Collins Startup list
[stcloader]
Confirmed=X
Filename=STCLOA~1.exe
Description=Popup adware by 2ndThought software
Source=Paul Collins Startup list
[STCLOA~1]
Confirmed=X
Filename=stcloader.exe
Description=Popup adware by 2ndThought software
Source=Paul Collins Startup list
[STCLOA~1]
Confirmed=X
Filename=STCLOA~1.exe
Description=Popup adware by 2ndThought software
Source=Paul Collins Startup list
[STCPO]
Confirmed=Y
Filename=STCPO.exe
Description=Sophos Sweep antivirus software
Source=Paul Collins Startup list
[Stealth Anonymizer 2.5]
Confirmed=U
Filename=stealth25.exe
Description=Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy
Source=Paul Collins Startup list
[Steam]
Confirmed=N
Filename=steam.exe
Description=Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game
Source=Paul Collins Startup list
[Stickies]
Confirmed=N
Filename=STICKIES.EXE
Description=Stickies - utility that allows you to put yellow "Post-It" type messages on your desktop and can be used to set reminders. Available via Start -> Programs
Source=Paul Collins Startup list
[Sticky Notes]
Confirmed=N
Filename=stikynot.exe
Description=Microsoft Sticky Notes - virtual sticky notes tool
Source=Paul Collins Startup list
[StickyNote]
Confirmed=N
Filename=StickyNote.exe
Description=Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
Source=Paul Collins Startup list
[StillImageMonitor]
Confirmed=U
Filename=Stimon.exe
Description=Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners
Source=Paul Collins Startup list
[stlbdist]
Confirmed=X
Filename=rundll32exe stlbdist.DLL, DllRunMain
Description=Hijacker pointing to www.searchandclick.com
Source=Paul Collins Startup list
[stlbupdt]
Confirmed=X
Filename=rundll32.exe stlbupdt.DLL, DllRunMain
Description=BrowserAid/Startium parasite
Source=Paul Collins Startup list
[STManager]
Confirmed=N
Filename=drst.exe
Description=Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here
Source=Paul Collins Startup list
[stmha]
Confirmed=X
Filename=wkfxi.js
Description=Added by the SPETH WORM!
Source=Paul Collins Startup list
[StopSignStatus]
Confirmed=N
Filename=stopsinfo.dll", VerifyStatus
Description=eAcceleration Stop-Sign related - not recommended, see note
Source=Paul Collins Startup list
[STOPzilla]
Confirmed=U
Filename=Stopzilla.exe
Description=StopZilla! - pop-up killer
Source=Paul Collins Startup list
[STOPzilla Service]
Confirmed=U
Filename=SZNTSVC.EXE
Description=StopZilla! - pop-up killer
Source=Paul Collins Startup list
[StorageGuard]
Confirmed=U
Filename=sgtray.exe
Description=StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
Source=Paul Collins Startup list
[STPMGR]
Confirmed=?
Filename=STPMGR.EXE
Description=Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs
Source=Paul Collins Startup list
[Strng32]
Confirmed=X
Filename=strngbox.exe
Description=Added by the STRANO WORM!
Source=Paul Collins Startup list
[StubPath]
Confirmed=X
Filename=Sservice.exe
Description=Added by the PRORAT TROJAN!
Source=Paul Collins Startup list
[StyleXP]
Confirmed=U
Filename=StyleXP.exe
Description=StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it
Source=Paul Collins Startup list
[Subtract the Ads]
Confirmed=N
Filename=AdSub.exe
Description=Removes adverts from web pages. Although useful - not required
Source=Paul Collins Startup list
[Suitcase Startup]
Confirmed=U
Filename=Suitcase.exe
Description=Suitcase. System font manager start up utility. Used for dynamic managment of fonts on your system
Source=Paul Collins Startup list
[SULFNBJ.EXE]
Confirmed=X
Filename=SULFNBJ.EXE
Description=Added by the PE_MAGISTR.DAM VIRUS!
Source=Paul Collins Startup list
[SunJavaUpdate]
Confirmed=X
Filename=smvss.exe
Description=Added by the DEDLER-G TROJAN!
Source=Paul Collins Startup list
[SunJavaUpdateSched]
Confirmed=N
Filename=jusched.exe
Description=Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
Source=Paul Collins Startup list
[Sunkist]
Confirmed=U
Filename=shwicon98.exe
Description=Card reader for memory cards from digital cameras, etc
Source=Paul Collins Startup list
[Sunkist2k]
Confirmed=U
Filename=shwicon2k.exe
Description=Card reader for memory cards from digital cameras, etc
Source=Paul Collins Startup list
[SupaDial]
Confirmed=?
Filename=SupaDial.exe
Description=SupaNet.com modem driver related - is it required?
Source=Paul Collins Startup list
[Supastatus]
Confirmed=N
Filename=status.exe
Description=Supanet ISP software
Source=Paul Collins Startup list
[Super Popup Blocker]
Confirmed=U
Filename=popkill.exe
Description=Saga Super Popup Blocker - pop-up stopper
Source=Paul Collins Startup list
[SuperAdBlocker]
Confirmed=U
Filename=SAdBlock.exe
Description=SuperAdBlocker
Source=Paul Collins Startup list
[Supercleaner]
Confirmed=U
Filename=Supercleaner.exe
Description=Supercleaner - all in one disk cleaner for your computer
Source=Paul Collins Startup list
[SuperCool Compress Backup]
Confirmed=U
Filename=Main.exe
Description="SuperCool Zip Backup software is a data backup,restore and file synchronization program"
Source=Paul Collins Startup list
[Supernova]
Confirmed=X
Filename=[worm filename]
Description=Added by the SURNOVA (or SUPOVA) WORM!
Source=Paul Collins Startup list
[superslut]
Confirmed=X
Filename=msslut32.exe
Description=Added by the SLUTER-A WORM!
Source=Paul Collins Startup list
[SuperSpamKiller Pro]
Confirmed=U
Filename=Ssk.exe
Description=SuperSpamKiller Pro email spam blocker
Source=Paul Collins Startup list
[Supervisor.exe]
Confirmed=X
Filename=Supervisor.exe
Description=Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome
Source=Paul Collins Startup list
[supporter5]
Confirmed=X
Filename=supporter5.exe
Description=Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
Source=Paul Collins Startup list
[SureCleanProfessional]
Confirmed=U
Filename=SRClean.exe
Description=SureClean PC and Internet tracks cleaner
Source=Paul Collins Startup list
[Sureshotpopupkiller]
Confirmed=U
Filename=Stopthepop.exe
Description=Stop-the-Pop-Up popup blocker
Source=Paul Collins Startup list
[SurfBuddy]
Confirmed=X
Filename=rundll32 [path] sbuddy.dll
Description=SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!
Source=Paul Collins Startup list
[SurfChoice]
Confirmed=U
Filename=SCMan.exe
Description=SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa
Source=Paul Collins Startup list
[Surfer lptt01]
Confirmed=X
Filename=surfer.exe
Description=Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Surfer ml097e]
Confirmed=X
Filename=surfer.exe
Description=Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[SurfinGuard Pro]
Confirmed=U
Filename=winsfcm.exe
Description=SurfinGuard Pro - internet protection software
Source=Paul Collins Startup list
[SurfSecret]
Confirmed=U
Filename=ss2-full.exe
Description="House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache"
Source=Paul Collins Startup list
[SurfSideKick 2]
Confirmed=X
Filename=Ssk.exe
Description=SurfSideKick adware
Source=Paul Collins Startup list
[SurfStream]
Confirmed=U
Filename=SurfStream.exe
Description=Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"
Source=Paul Collins Startup list
[Surs]
Confirmed=X
Filename=awab.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[Surveysa]
Confirmed=?
Filename=surveysa.exe
Description=Found in the Sony\Vaio\survey directory on a Sony Vaio PC. What does it do and is it required?
Source=Paul Collins Startup list
[Susp]
Confirmed=X
Filename=Susp.exe
Description=Transponder parasite updater/installer
Source=Paul Collins Startup list
[Sustem]
Confirmed=X
Filename=explorer.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[SustemUpdate]
Confirmed=X
Filename=explorer.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[SVA Player]
Confirmed=X
Filename=SVAplayer.exe
Description=QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it
Source=Paul Collins Startup list
[Svc]
Confirmed=X
Filename=svc.exe
Description=Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND TROJAN!
Source=Paul Collins Startup list
[SVC Service]
Confirmed=X
Filename=svcinit.exe
Description=Added by the SINIT TROJAN!
Source=Paul Collins Startup list
[SVC Service]
Confirmed=X
Filename=svcinit.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[SVC Service]
Confirmed=X
Filename=svcpack.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[SVC Socks]
Confirmed=X
Filename=mstaskm.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Svced]
Confirmed=X
Filename=Svced.exe
Description=Added by the DELF.F TROJAN!
Source=Paul Collins Startup list
[SvcH0st]
Confirmed=X
Filename=msexploren.exe
Description=Added by the BACKDOOR-CGZ TROJAN!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=Svch0st.exe
Description=Added by the GRAYBIRD.B TROJAN!
Source=Paul Collins Startup list
[SVCHOST]
Confirmed=X
Filename=svchost.exe
Description=System1060 homepage hi-jacker. Found in a Windows\System1060 directory. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=svchost.exe
Description=Added by the MORB WORM or TARNO TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[SVCHOST]
Confirmed=X
Filename=mrowyekdc.exe
Description=Added by the GOTORM WORM!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=Svch0st.exe
Description=Added by the GRAYBIRD TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=[path to trojan]
Description=Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=ADMAGIC.EXE
Description=Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Svchost]
Confirmed=X
Filename=winhost.exe
Description=Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Svchost]
Confirmed=X
Filename=svchost.exe
Description=Added by the MOXE-A WORM! This is not the valid svchost.exe as described here
Source=Paul Collins Startup list
[SVCHOST]
Confirmed=X
Filename=var.txt.exe
Description=Added by the LDPINCH.C TROJAN!
Source=Paul Collins Startup list
[Svchost]
Confirmed=X
Filename=svchosl.pif
Description=Added by the INZAE.A or INZAE.B WORMS!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=[path] SETUP.EXE
Description=Added by the SETCLO WORM!
Source=Paul Collins Startup list
[svchost]
Confirmed=X
Filename=[path] SETUP.EXE
Description=Added by the SETCLO WORM!
Source=Paul Collins Startup list
[svchost.exe]
Confirmed=X
Filename=svchost32.exe
Description=CoolWebSearch parasite related. Note - this is not the valid svchost.exe as described here
Source=Paul Collins Startup list
[svchost1]
Confirmed=X
Filename=svchost1.exe
Description=Added by the AGOBOT.ZZ WORM!
Source=Paul Collins Startup list
[SvcHost32]
Confirmed=X
Filename=svchost32.exe
Description=Added by the MIMAIL.I or MIMAIL.J WORMS!
Source=Paul Collins Startup list
[svchost64]
Confirmed=X
Filename=svchost64.exe
Description=Added by the SDBOTER.G VIRUS!
Source=Paul Collins Startup list
[svchostr]
Confirmed=X
Filename=svchostr.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[svcinfo]
Confirmed=X
Filename=svcinfo.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[svcroot]
Confirmed=X
Filename=svcroot.exe
Description=Added by the KEYLOG-AC TROJAN!
Source=Paul Collins Startup list
[svcsys32]
Confirmed=X
Filename=svcsys32.exe
Description=Added by the AGOBOT-LL WORM!
Source=Paul Collins Startup list
[svcwinprocess32]
Confirmed=X
Filename=[path to worm]
Description=Added by the UPERING WORM!
Source=Paul Collins Startup list
[SVHOST]
Confirmed=X
Filename=svhost.exe
Description=Added by the MYDOOM.I WORM!
Source=Paul Collins Startup list
[Svhost Loader]
Confirmed=X
Filename=svshost.exe
Description=Added by the AGOBOT.G WORM!
Source=Paul Collins Startup list
[SVIDC32M]
Confirmed=?
Filename=SVIDC32M.exe
Description=??
Source=Paul Collins Startup list
[SVM Pop]
Confirmed=?
Filename=svmpop.exe
Description=??
Source=Paul Collins Startup list
[svphost.exe]
Confirmed=X
Filename=svphost.exe
Description=Added by the AGENT.CS TROJAN!
Source=Paul Collins Startup list
[svrrun]
Confirmed=X
Filename=svrrun.exe
Description=Adware hailing from Deskwizz.com
Source=Paul Collins Startup list
[svshost]
Confirmed=X
Filename=svshost.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[svshost32]
Confirmed=X
Filename=msgrsv32.exe
Description=Added by the RANKY.AJ TROJAN!
Source=Paul Collins Startup list
[svshostdriver]
Confirmed=X
Filename=svshost.exe
Description=Added by the SDBOT-HN TROJAN!
Source=Paul Collins Startup list
[svwin32]
Confirmed=X
Filename=unninst32.exe
Description=Added by the AGOBOT-NF WORM!
Source=Paul Collins Startup list
[SVX Control Service]
Confirmed=X
Filename=svxhost.exe
Description=Added by the FORBOT-K WORM!
Source=Paul Collins Startup list
[Swap Nut]
Confirmed=N
Filename=javaw.exe
Description=SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network
Source=Paul Collins Startup list
[SWCaller]
Confirmed=X
Filename=SWcaller.exe
Description=Homepage hijacker - see here
Source=Paul Collins Startup list
[SWCaller]
Confirmed=X
Filename=Swcaller2.exe
Description=Homepage hijacker - see here
Source=Paul Collins Startup list
[SWd]
Confirmed=N
Filename=winwd.exe
Description=PC Security from Tropical Software - lock files, password protect, etc
Source=Paul Collins Startup list
[Sweep95]
Confirmed=Y
Filename=ICLOAD95.EXE
Description=Part of Sophos ant-virus sofware
Source=Paul Collins Startup list
[Swf32]
Confirmed=X
Filename=AVupdate.exe
Description=Added by the MERKUR WORM!
Source=Paul Collins Startup list
[Swf32]
Confirmed=X
Filename=_backup.exe
Description=Added by the SYMTEN WORM!
Source=Paul Collins Startup list
[SwimSuitNetwork]
Confirmed=X
Filename=SwimSuitNetwork.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[Switch Off]
Confirmed=U
Filename=swoff.exe
Description=Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc
Source=Paul Collins Startup list
[Switchboard.com Toolbar]
Confirmed=N
Filename=AtHoc.exe
Description=Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com
Source=Paul Collins Startup list
[sws.exe]
Confirmed=X
Filename=[random filename]
Description=Haldex type adult content dialler
Source=Paul Collins Startup list
[SwTray]
Confirmed=N
Filename=SWTRAY.EXE
Description=MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
Source=Paul Collins Startup list
[SWTrayV4]
Confirmed=N
Filename=SWTrayV4.exe
Description=MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
Source=Paul Collins Startup list
[SXGDSENU]
Confirmed=?
Filename=sxgdsenu.exe
Description=Yamaha SXG soundcard driver
Source=Paul Collins Startup list
[SxgTkBar]
Confirmed=?
Filename=sxgtkbar.exe
Description=Yamaha SXG soundcard driver
Source=Paul Collins Startup list
[Sxplog]
Confirmed=?
Filename=sxpstub.exe
Description=Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup?
Source=Paul Collins Startup list
[SYDNEY]
Confirmed=X
Filename=[file path]
Description=Added by the SYNEY WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall]
Confirmed=X
Filename=Win32x.exe
Description=Added by the RBOT-KZ WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall]
Confirmed=X
Filename=system32.exe
Description=Added by the RBOT.VI WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall]
Confirmed=X
Filename=sysgut.exe
Description=Added by the SDBOT.WM WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall]
Confirmed=X
Filename=Sygate.exe
Description=Added by the RBOT-PN WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall]
Confirmed=X
Filename=Mcafeeupdate.exe
Description=Added by the RBOT.YN WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall Start]
Confirmed=X
Filename=services32.exe
Description=Added by the RBOT-MB WORM!
Source=Paul Collins Startup list
[Sygate Personal Firewall Start]
Confirmed=X
Filename=servic.exe
Description=Added by the RBOT-RY WORM!
Source=Paul Collins Startup list
[Sygate Personals Firewalls]
Confirmed=X
Filename=ccsrn.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[SyGateService]
Confirmed=U
Filename=sgserv95.exe
Description=SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs
Source=Paul Collins Startup list
[Symantec Anti Virus]
Confirmed=X
Filename=symantec32.exe
Description=Added by a variant of the WOOTBOT WORM!
Source=Paul Collins Startup list
[Symantec Configuration Loader]
Confirmed=X
Filename=ccApp32.exe
Description=Added by a variant of the GAOBOT WORM!
Source=Paul Collins Startup list
[Symantec Core LC]
Confirmed=Y
Filename=symlcsvc.exe
Description=Part of Norton AntiVirus 2004. What does it do?
Source=Paul Collins Startup list
[Symantec Fax Starter Edition Port]
Confirmed=N
Filename=OLFSNT40.EXE
Description=Offers a virtual printer as a fax machine. Can be run via a desktop shortcut
Source=Paul Collins Startup list
[Symantec NetDriver Monitor]
Confirmed=U
Filename=SNDMon.exe
Description=Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation
Source=Paul Collins Startup list
[Symantec Security]
Confirmed=X
Filename=symantec32.exe
Description=Added by the RANDEX.PR or RANDEX.YR WORMS!
Source=Paul Collins Startup list
[Symantec Security Addon]
Confirmed=X
Filename=nvsvc.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Symantec Security Routine Addon for Microsoft Windows]
Confirmed=X
Filename=navpxaw32.exe
Description=Added by the AGOBOT-GJ TROJAN!
Source=Paul Collins Startup list
[SymAV]
Confirmed=X
Filename=SymAV.exe
Description=Added by the NETSKY.U WORM!
Source=Paul Collins Startup list
[SymKeepAlive]
Confirmed=U
Filename=CKA.exe
Description=Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive
Source=Paul Collins Startup list
[SymTray - Norton SystemWorks]
Confirmed=N
Filename=SYMTRAY.EXE
Description=Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray
Source=Paul Collins Startup list
[Sync Data]
Confirmed=U
Filename=Hndsync.exe
Description=Pocket Real Estate - mobile synchronization manager
Source=Paul Collins Startup list
[Sync Server]
Confirmed=X
Filename=drwatsoon.exe
Description=Added by the WATSOON.A TROJAN!
Source=Paul Collins Startup list
[Sync-It]
Confirmed=U
Filename=Syncit.exe
Description=Sync-It - synchronizes the system clock with time servers on the internet
Source=Paul Collins Startup list
[SyncAgent]
Confirmed=U
Filename=syncagent.exe
Description=Ghost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
Source=Paul Collins Startup list
[Synchronization Manager]
Confirmed=N
Filename=mobsync.exe
Description=Find more information about its use here
Source=Paul Collins Startup list
[SynSetup]
Confirmed=?
Filename=SynTP.tmp RunOnce.exe
Description=Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?
Source=Paul Collins Startup list
[Syntax Script]
Confirmed=X
Filename=systacq.exe
Description=Added by the SDBOT.AI WORM!
Source=Paul Collins Startup list
[SynTPEnh]
Confirmed=U
Filename=syntpenh.exe
Description=Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll
Source=Paul Collins Startup list
[SynTPLpr]
Confirmed=Y
Filename=syntplpr.exe
Description=Synaptics touchpad driver helper. Required for touchpad features to work
Source=Paul Collins Startup list
[sys]
Confirmed=X
Filename=regedit /s sys.reg
Description=Hijacker
Source=Paul Collins Startup list
[sys]
Confirmed=X
Filename=sysdllwm.reg
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Sys Ren]
Confirmed=X
Filename=SysRen.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[Sys29]
Confirmed=X
Filename=win***32.exe [* = random char]
Description=EliteBar adware
Source=Paul Collins Startup list
[sys32]
Confirmed=X
Filename=sys32.exe
Description=Added by the FLUX.E TROJAN!
Source=Paul Collins Startup list
[sys32cmd]
Confirmed=U
Filename=sys32win.exe
Description=Active Keylogger monitoring software - also see here. From the Symantec article: "This spyware program must be manually installed. However, there are several known programs that have Spyware.ActiveKeylog within them and that install it as the program itself is installed". Disable/remove if you didn't install it
Source=Paul Collins Startup list
[SysA]
Confirmed=X
Filename=win***32.exe [* = random char]
Description=EliteBar adware
Source=Paul Collins Startup list
[SysAgent]
Confirmed=U
Filename=SysAgent.exe
Description=SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
Source=Paul Collins Startup list
[SysAI]
Confirmed=X
Filename=SysAI.exe
Description=AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located
Source=Paul Collins Startup list
[Sysbot]
Confirmed=U
Filename=sysbot.exe
Description=Spector - spying (or monitoring) software to record internet activity
Source=Paul Collins Startup list
[syscfg]
Confirmed=X
Filename=syscfg32.exe
Description=Added by the KWBOT.S WORM!
Source=Paul Collins Startup list
[syscfg34.exe]
Confirmed=X
Filename=syscfg34.exe
Description=Added by the ELECTRON WORM!
Source=Paul Collins Startup list
[Syscheck]
Confirmed=X
Filename=win.hta
Description=Browser hijacker
Source=Paul Collins Startup list
[syscheck]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the AGENT.DM TROJAN!
Source=Paul Collins Startup list
[syscm]
Confirmed=X
Filename=Syscm.exe
Description=Vanish adware
Source=Paul Collins Startup list
[SysComp]
Confirmed=?
Filename=mssdnl.com
Description=Unknown but suspect as *.com are not usually run at start up and the name isn't recognized
Source=Paul Collins Startup list
[syscon lptt01]
Confirmed=X
Filename=syscon.exe
Description=Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[syscon ml097e]
Confirmed=X
Filename=syscon.exe
Description=Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[sysconfig]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the CULT.C WORM!
Source=Paul Collins Startup list
[SysConfig]
Confirmed=X
Filename=syscfg35.exe
Description=Added by the KAZMOR.C WORM!
Source=Paul Collins Startup list
[sysconfig]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the CULT.H WORM!
Source=Paul Collins Startup list
[SysConfig]
Confirmed=X
Filename=wincfg32.exe
Description=Added by the SDBOT.ZD WORM!
Source=Paul Collins Startup list
[Syscpy]
Confirmed=X
Filename=Syscpy.exe
Description=Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN!
Source=Paul Collins Startup list
[SysCtl]
Confirmed=X
Filename=sysctl.exe
Description=Added by the AOK TROJAN!
Source=Paul Collins Startup list
[Sysctrls]
Confirmed=X
Filename=procdll.exe
Description=Added by the WEEDBOTZ.14 TROJAN!
Source=Paul Collins Startup list
[sysdir]
Confirmed=X
Filename=winrun.exe
Description=Added by the WINBUR.B WORM!
Source=Paul Collins Startup list
[Sysdpt]
Confirmed=X
Filename=sysdpt.exe
Description=Win32.Crypt trojan downloader
Source=Paul Collins Startup list
[sysfiler]
Confirmed=X
Filename=sysfiler.exe
Description=Added by the RETSAM TROJAN!
Source=Paul Collins Startup list
[SYSfit]
Confirmed=X
Filename=SYSfit.exe
Description=AdShooter adware variant
Source=Paul Collins Startup list
[sysflg32]
Confirmed=X
Filename=sysflg32.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[syshelp]
Confirmed=X
Filename=syshelp.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[sysinfo]
Confirmed=X
Filename=sysinfo.exe
Description=Added by the BEDRILL TROJAN!
Source=Paul Collins Startup list
[sysinfo.exe]
Confirmed=X
Filename=sysinfo.exe
Description=Added by the BEAGLE.V WORM!
Source=Paul Collins Startup list
[SysInit]
Confirmed=X
Filename=wininit32.exe
Description=Added by the XABOT WORM!
Source=Paul Collins Startup list
[sysinit]
Confirmed=X
Filename=services.exe
Description=Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Sysino]
Confirmed=X
Filename=lsess.exe
Description=Added by the FORBOT-BF WORM!
Source=Paul Collins Startup list
[sysint16]
Confirmed=X
Filename=sysint16.exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[Syskey]
Confirmed=X
Filename=sysinit.exe
Description=Added by the BEAGLE.AX WORM!
Source=Paul Collins Startup list
[Syslib]
Confirmed=X
Filename=Syslib.exe
Description=Adult content related downloader trojan
Source=Paul Collins Startup list
[Syslog lptt01]
Confirmed=X
Filename=Syslog.exe
Description=Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Syslog ml097e]
Confirmed=X
Filename=Syslog.exe
Description=Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[syslogin.exe]
Confirmed=X
Filename=syslogin.exe
Description=Added by the BAGZ-B WORM!
Source=Paul Collins Startup list
[SysMetrix]
Confirmed=U
Filename=SysMetrix.exe
Description=SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics
Source=Paul Collins Startup list
[sysmon]
Confirmed=X
Filename=sysmon.exe
Description=Added by the BIZEX WORM!
Source=Paul Collins Startup list
[Sysmon]
Confirmed=X
Filename=rpcmon.exe
Description=Added by the RANDEX.ATX WORM!
Source=Paul Collins Startup list
[sysmon]
Confirmed=X
Filename=sysmon44.exe
Description=Added by a variant of the BACKDOOR-CBA TROJAN!
Source=Paul Collins Startup list
[SysMonXP]
Confirmed=X
Filename=SysMonXP.exe
Description=Added by the NETSKY.Q WORM!
Source=Paul Collins Startup list
[sysnate]
Confirmed=X
Filename=sysnate.exe
Description=Added by the MEDIAS TROJAN!
Source=Paul Collins Startup list
[SysOps]
Confirmed=X
Filename=SysOps
Description=Added by the MSNCORRUPT TROJAN!
Source=Paul Collins Startup list
[syspath]
Confirmed=X
Filename=drv.exe
Description=Added by the SOBER WORM!
Source=Paul Collins Startup list
[SysPilot]
Confirmed=U
Filename=fdxxl.exe
Description=G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself!
Source=Paul Collins Startup list
[sysPnP]
Confirmed=X
Filename=bootconf.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com; see for example here
Source=Paul Collins Startup list
[SysPnP]
Confirmed=X
Filename=rundll32 setupapi, InstallHinfSection.... oemsyspnp.inf
Description=Search hijacker - see here
Source=Paul Collins Startup list
[SysPool]
Confirmed=Y
Filename=Mssvc.exe
Description=StealthDisk - hides folders, files and applications. Will also encrypt them for better protection
Source=Paul Collins Startup list
[SysProtect]
Confirmed=X
Filename=System.exe
Description=Added by the NETSPY TROJAN!
Source=Paul Collins Startup list
[SysR]
Confirmed=X
Filename=sysmd.exe
Description=Adult content based "foistware" (adds hidden components to your system)
Source=Paul Collins Startup list
[SysReg]
Confirmed=X
Filename=SysReg.exe
Description=Added by the CHEKIN TROJAN!
Source=Paul Collins Startup list
[SysReg]
Confirmed=X
Filename=SysReg.exe
Description=SearchSeekFind textual marketing foistware
Source=Paul Collins Startup list
[Sysres]
Confirmed=X
Filename=Sysres.exe
Description=Added by the LOGMOD TROJAN!
Source=Paul Collins Startup list
[SysScan]
Confirmed=X
Filename=bvt.exe
Description=Added by the AUTOUPDER TROJAN!
Source=Paul Collins Startup list
[SysSearch]
Confirmed=X
Filename=Regedit.exe -s [path] pcsearch.reg
Description=Added by the StartPage-FN browser hijacker
Source=Paul Collins Startup list
[SysSearch]
Confirmed=X
Filename=REGEDIT.EXE -s [path] sysreg.reg
Description=Added by the STARTPA-ME TROJAN!
Source=Paul Collins Startup list
[sysser]
Confirmed=X
Filename=[path to file]
Description=Added by the RAHACK WORM!
Source=Paul Collins Startup list
[SysService]
Confirmed=X
Filename=SysService.exe
Description=Added by the DELF family of TROJANS!
Source=Paul Collins Startup list
[SysService32]
Confirmed=X
Filename=SysService32.exe
Description=Added by the KINDAL VIRUS!
Source=Paul Collins Startup list
[SysService32]
Confirmed=X
Filename=ln32k.dll
Description=Added by the KINDAL VIRUS!
Source=Paul Collins Startup list
[SysService32l]
Confirmed=X
Filename=systask32l.exe
Description=Added by the THEUG WORM!
Source=Paul Collins Startup list
[SYSsfitb]
Confirmed=X
Filename=SYSsfitb.exe
Description=Searchforit browser hijacker
Source=Paul Collins Startup list
[SysStrt]
Confirmed=X
Filename=systemc.exe
Description=Added by the AGOBOT-QA TROJAN!
Source=Paul Collins Startup list
[System]
Confirmed=X
Filename=run322.exe
Description=Added by the LANFILT TROJAN!
Source=Paul Collins Startup list
[System]
Confirmed=X
Filename=system.exe
Description=Added by various WORMS and TROJANS!
Source=Paul Collins Startup list
[system]
Confirmed=X
Filename=regedit -s system.dll
Description=Homepage hijacker
Source=Paul Collins Startup list
[system]
Confirmed=X
Filename=systemsearch.hta
Description=Jetseeker.com hijacker
Source=Paul Collins Startup list
[System]
Confirmed=X
Filename=dcomx.exe
Description=Added by the CIREBOT TROJAN!
Source=Paul Collins Startup list
[system]
Confirmed=X
Filename=Explorer.exe
Description=Added by the GRAYBIRD TROJAN! Note - this is located in this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) rather than the valid Windows Explorer which is located in C:\Windows or C:\Winnt
Source=Paul Collins Startup list
[System]
Confirmed=X
Filename=YPager.exe
Description=Added by the JUNTADOR.K TROJAN! Note - this is not Yahoo! Messenger
Source=Paul Collins Startup list
[system]
Confirmed=X
Filename=outlook.exe
Description=Added by the MIMAIL.Q WORM! Note that Microsoft's outlook.exe resides in the Program Files sub-directory wheras this resides in C:\Windows or C:\Winnt
Source=Paul Collins Startup list
[System]
Confirmed=X
Filename=Atira.exe
Description=Added by the KOTIRA VIRUS!
Source=Paul Collins Startup list
[SYSTEM]
Confirmed=X
Filename=lsas.exe
Description=Added by the SPYBOT.CJ WORM!
Source=Paul Collins Startup list
[System]
Confirmed=X
Filename=kernels32.exe
Description=Added by the DLOADER-FC TROJAN!
Source=Paul Collins Startup list
[System 64 Driver for Games]
Confirmed=X
Filename=sys64dvr.exe
Description=Added by the SDBOT TROJAN!
Source=Paul Collins Startup list
[System Applications Profile]
Confirmed=X
Filename=sap.exe
Description=Added by the RBOT-QF WORM!
Source=Paul Collins Startup list
[System Backup]
Confirmed=X
Filename=msystem.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[System Cache]
Confirmed=X
Filename=SysCache.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[System Check]
Confirmed=U
Filename=Rundll32.exe SysDll32.dll, SystemCheck
Description=XPCSpy Pro keylogger, surveillance and monitoring software
Source=Paul Collins Startup list
[system check]
Confirmed=X
Filename=updater.exe
Description=Unidentified adware downloader
Source=Paul Collins Startup list
[System Config Manager]
Confirmed=X
Filename=crss.exe
Description=Added by the AGOBOT.GH WORM!
Source=Paul Collins Startup list
[System Configuration]
Confirmed=X
Filename=iexplore.exe
Description=Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[System Diagnostics]
Confirmed=X
Filename=sysdiag32.exe
Description=Added by the SDBOT.GEN TROJAN!
Source=Paul Collins Startup list
[System DLF]
Confirmed=N
Filename=cpqdiaga.exe
Description=Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
Source=Paul Collins Startup list
[System Document Application]
Confirmed=X
Filename=nmod.exe
Description=Added by the SDBOT-ABB WORM!
Source=Paul Collins Startup list
[System driver]
Confirmed=X
Filename=Messenger.exe
Description=Added by a variant of the SMALL.BJ TROJAN!
Source=Paul Collins Startup list
[System Efficiency Monitor]
Confirmed=X
Filename=mscedit32.exe
Description=Added by the SDBOT.P TROJAN!
Source=Paul Collins Startup list
[System Efficiency Monitor]
Confirmed=X
Filename=mscommand.exe
Description=Added by the KWBOT.P WORM!
Source=Paul Collins Startup list
[System Executable DLL Library]
Confirmed=X
Filename=EXECDLL32.exe
Description=Added by the RANDEX.AZ WORM!
Source=Paul Collins Startup list
[System Failure Statistic]
Confirmed=X
Filename=cnstat.exe
Description=Added by the RBOT-LF WORM!
Source=Paul Collins Startup list
[System File Drivers]
Confirmed=X
Filename=nvsysvc32.exe
Description=Added by the AGOBOT.WJ WORM!
Source=Paul Collins Startup list
[System Handler]
Confirmed=X
Filename=LSASS.EXE
Description=Added by the NIMOS WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[System Host Service]
Confirmed=X
Filename=svchost.exe
Description=Added the the CONE.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[System Information Manager]
Confirmed=X
Filename=Navcpe.exe
Description=Added by the SDBOT-QB WORM!
Source=Paul Collins Startup list
[System Information Manager]
Confirmed=X
Filename=Msbb.exe
Description=Added by a variant of the BACKDOOR.IRC.BOT TROJAN!
Source=Paul Collins Startup list
[System Initialization]
Confirmed=X
Filename=msmsgri32.exe
Description=Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!
Source=Paul Collins Startup list
[System Initialization]
Confirmed=X
Filename=payload.dat
Description=Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!
Source=Paul Collins Startup list
[System LifeGuard Scheduler]
Confirmed=U
Filename=Slsched.exe
Description=System LifeGuard scheduler
Source=Paul Collins Startup list
[System Log Event]
Confirmed=X
Filename=csrss32.exe
Description=Added by the AGOBOT-JI WORM!
Source=Paul Collins Startup list
[System Manager]
Confirmed=X
Filename=svchost.exe
Description=Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[system manager]
Confirmed=X
Filename=System.exe
Description=Added by the FORBOT-BO WORM!
Source=Paul Collins Startup list
[System Manager]
Confirmed=X
Filename=winsrv32.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[System Mechanic Popup Stopper]
Confirmed=U
Filename=Popupstopper.exe
Description=Iolo "System Mechanic" popup stopper
Source=Paul Collins Startup list
[System Monitor]
Confirmed=U
Filename=SYSMON.EXE
Description=Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal
Source=Paul Collins Startup list
[System Monitor]
Confirmed=X
Filename=Sysmon16.exe
Description=Added by the SDBOT TROJAN!
Source=Paul Collins Startup list
[System MScvb]
Confirmed=X
Filename=mscvb32.exe
Description=Added by the SOBIG.C WORM!
Source=Paul Collins Startup list
[System Profile]
Confirmed=X
Filename=Regsrv.exe
Description=Added by a variant of the OPTIX TROJAN!
Source=Paul Collins Startup list
[System Restore]
Confirmed=X
Filename=svcnet.exe
Description=Added by the TIBICK WORM!
Source=Paul Collins Startup list
[System Restore Data]
Confirmed=X
Filename=[path] repcale.exe [path] beird.exe
Description=Added by the RANDON.AN WORM!
Source=Paul Collins Startup list
[System Service]
Confirmed=X
Filename=MSREXE.EXE
Description=Added by the AML TROJAN!
Source=Paul Collins Startup list
[system service]
Confirmed=X
Filename=spoolcrv.cpl
Description=Added by the INSPIR.11 TROJAN!
Source=Paul Collins Startup list
[System Service]
Confirmed=X
Filename=systems.exe
Description=Added by the AGOBOT.VZ WORM!
Source=Paul Collins Startup list
[System Soap Pro]
Confirmed=X
Filename=soap.exe
Description=System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided
Source=Paul Collins Startup list
[System startup]
Confirmed=U
Filename=charmapx.exe
Description=Only required if using an oriental language
Source=Paul Collins Startup list
[System Startup]
Confirmed=X
Filename=Voltio.exe
Description=Added by the RBOT.NJ WORM!
Source=Paul Collins Startup list
[System Stats]
Confirmed=X
Filename=SystemStats.exe
Description=Added by a variant of the WOOTBOT WORM!
Source=Paul Collins Startup list
[System Terminal]
Confirmed=X
Filename=SYSTEM2.EXE
Description=Added by the SPYBOT-BZ TROJAN!
Source=Paul Collins Startup list
[System time updator]
Confirmed=X
Filename=CSysTime.exe
Description=Added by the RANDEX.S WORM!
Source=Paul Collins Startup list
[System Toolkit]
Confirmed=X
Filename=Systools.exe
Description=Added by the RONOPER-G WORM!
Source=Paul Collins Startup list
[System Tray]
Confirmed=X
Filename=msccn32.exe
Description=Added by the PALYH.A WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray (SysTray.exe)
Source=Paul Collins Startup list
[System Tray Services]
Confirmed=X
Filename=spooles32.exe
Description=Added by the AGOBOT.ZH WORM!
Source=Paul Collins Startup list
[System Tray32]
Confirmed=X
Filename=SysTray32.exe
Description=Added by the REPAD WORM!
Source=Paul Collins Startup list
[System Update]
Confirmed=X
Filename=[filename].exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[System Update]
Confirmed=X
Filename=[random filename]
Description=Added by the KORGO.W or KORGO.X WORMS!
Source=Paul Collins Startup list
[System Update]
Confirmed=X
Filename=wupdmgr.exe
Description=Added by the SOROMO-A TROJAN!
Source=Paul Collins Startup list
[System Update Service]
Confirmed=X
Filename=wmiprvsa.exe
Description=Added by the AGOBOT-RG TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=explorer.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=services.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=svchost.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=system.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=taskman.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=taskmon.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=update.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=webcheck.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=wininet.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=winlogon.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=winspool.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Update2]
Confirmed=X
Filename=wupdmgr.exe
Description=Added by the AUTOTROJ-C TROJAN!
Source=Paul Collins Startup list
[System Updater Service]
Confirmed=X
Filename=wmiprvsw.exe
Description=Added by the GAOBOT.AFC WORM!
Source=Paul Collins Startup list
[System Uptime Server]
Confirmed=X
Filename=SYSENTRY.EXE
Description=Added by the RBOT.LK WORM!
Source=Paul Collins Startup list
[System Uptime Server]
Confirmed=X
Filename=SYSENTRY32.EXE
Description=Added by the RBOT.LK WORM!
Source=Paul Collins Startup list
[system xp]
Confirmed=X
Filename=acdsee demo.exe
Description=Added by the SALGA.A WORM!
Source=Paul Collins Startup list
[System-Config]
Confirmed=X
Filename=msptmf32.com
Description=Added by the LIOTEN.FA WORM!
Source=Paul Collins Startup list
[System-Service]
Confirmed=X
Filename=EXPLORER.SCR
Description=Added by the BENJAMIN WORM! KaZaA file-sharing users beware!
Source=Paul Collins Startup list
[system.]
Confirmed=X
Filename=system..exe
Description=Added by the OPTIXPRO.13.C TROJAN!
Source=Paul Collins Startup list
[system...]
Confirmed=X
Filename=system...exe
Description=Added by the OPTIXPRO.13.C TROJAN!
Source=Paul Collins Startup list
[System.exe]
Confirmed=X
Filename=System.exe
Description=Added by various WORMS and TROJANS!
Source=Paul Collins Startup list
[System32]
Confirmed=X
Filename=system.exe
Description=Added by the BUSHTRO122 TROJAN!
Source=Paul Collins Startup list
[System32]
Confirmed=X
Filename=System32.exe
Description=Added by any number of WORMS or TROJANS!
Source=Paul Collins Startup list
[System32]
Confirmed=X
Filename=sysdiag.exe
Description=SpyAgent.B spyware
Source=Paul Collins Startup list
[System32]
Confirmed=X
Filename=system32,1.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[system32]
Confirmed=X
Filename=NeT-BoT.exe
Description=Added by the AGOBOT-LJ WORM!
Source=Paul Collins Startup list
[system32.dll]
Confirmed=X
Filename=systeminit.exe
Description=CoolWebSearch hijacker re-directing to your-search.info
Source=Paul Collins Startup list
[system32.dll]
Confirmed=X
Filename=sysdll32.exe
Description=CoolWebSearch parasite related. Redirecting to wholeworldmarket.com, most likely other domains as well
Source=Paul Collins Startup list
[system32.exe]
Confirmed=X
Filename=services32.exe
Description=Added by a variant of the BACKDOOR.IRC.BOT TROJAN!
Source=Paul Collins Startup list
[System32Dll]
Confirmed=X
Filename=DLL32SYS.EXE
Description=Added by the SPYBOT-CZ WORM!
Source=Paul Collins Startup list
[System32Ex]
Confirmed=X
Filename=System32Ex.exe
Description=Added by the IRCCONTACT TROJAN!
Source=Paul Collins Startup list
[System33]
Confirmed=X
Filename=FB_PNU.EXE
Description=Added by the NICHELLO-A WORM!
Source=Paul Collins Startup list
[SystemAdministration]
Confirmed=X
Filename=Wincmp32.exe
Description=Added by the ASYLUM TROJAN!
Source=Paul Collins Startup list
[SystemAgent]
Confirmed=U
Filename=Sage.exe
Description="Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"
Source=Paul Collins Startup list
[SystemBackup]
Confirmed=X
Filename=mtx.exe
Description=Added by the MTX VIRUS/WORM!
Source=Paul Collins Startup list
[SystemBackup]
Confirmed=X
Filename=MicroLog.exe
Description=Added by the MICROLOG.A TROJAN!
Source=Paul Collins Startup list
[SystemBoot]
Confirmed=?
Filename=ladies.htm
Description=Unknown but sounds very suspicious??
Source=Paul Collins Startup list
[SystemBoot]
Confirmed=X
Filename=Mshta.exe ...filename.hta
Description=Adult content dialler
Source=Paul Collins Startup list
[SystemCheck]
Confirmed=X
Filename=Systemcheck.exe
Description=Added by the LAVITS WORM!
Source=Paul Collins Startup list
[SystemChecker]
Confirmed=X
Filename=Syschk.exe
Description=Added by the GALIL.F WORM!
Source=Paul Collins Startup list
[SystemCONF98i]
Confirmed=X
Filename=SystemCONF98i.exe
Description=Added by the GLITCH BOT TROJAN!
Source=Paul Collins Startup list
[SystemDebug]
Confirmed=X
Filename=Sysdeb32.exe
Description=Added by the SYSBUG TROJAN!
Source=Paul Collins Startup list
[SystemDll]
Confirmed=X
Filename=SystemDll.exe
Description=Added by the LOXOSCAM TROJAN!
Source=Paul Collins Startup list
[systemdrv]
Confirmed=X
Filename=ms32sys.exe
Description=Added by an unidentified WORM or TROJAN - most likely GAOBOT variant
Source=Paul Collins Startup list
[SystemEmergency]
Confirmed=X
Filename=[various filenames]
Description=SmartSearch - a CoolWebSearch parasite variant
Source=Paul Collins Startup list
[SystemExplorer]
Confirmed=X
Filename=explore.exe
Description=Homepage hijacker - file located in the "Services" folder in Common Files
Source=Paul Collins Startup list
[SystemFTP]
Confirmed=X
Filename=VSENMB.exe
Description=Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well
Source=Paul Collins Startup list
[SystemInit]
Confirmed=X
Filename=iservc.exe
Description=Added by the FIZZER WORM!
Source=Paul Collins Startup list
[Systemiom Updater]
Confirmed=X
Filename=Systemiom.exe
Description=Added by the SPYBOT.TY WORM!
Source=Paul Collins Startup list
[SystemLoad32]
Confirmed=X
Filename=sysload32.exe
Description=Added by the MIMAIL.E WORM!
Source=Paul Collins Startup list
[SystemManager]
Confirmed=X
Filename=Sysman32.exe
Description=Added by the DOWNLOADER-BW.B TROJAN!
Source=Paul Collins Startup list
[SystemMap32]
Confirmed=X
Filename=Netisp32.vbs
Description=Added by the REDIST.C WORM!
Source=Paul Collins Startup list
[SystemMD]
Confirmed=X
Filename=md.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[SystemMonitor]
Confirmed=X
Filename=Sysmon32.exe
Description=Added by the AIDID.A WORM!
Source=Paul Collins Startup list
[SystemNetwork]
Confirmed=X
Filename=NETSERV.EXE
Description=Added by the NETCONTROL VIRUS!
Source=Paul Collins Startup list
[SystemReg]
Confirmed=?
Filename=PROCES.EXE
Description=??
Source=Paul Collins Startup list
[SystemReg]
Confirmed=X
Filename=svchost.exe
Description=Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[SystemReg]
Confirmed=X
Filename=WINREG.EXE
Description=Added by the DEWIN.A TROJAN!
Source=Paul Collins Startup list
[Systems]
Confirmed=X
Filename=scchost.exe
Description=Added by the DAEMOZ.A TROJAN!
Source=Paul Collins Startup list
[Systems Restart]
Confirmed=X
Filename=slchost.exe
Description=Added by the BANCOS.RF TROJAN!
Source=Paul Collins Startup list
[Systems Restart]
Confirmed=X
Filename=spchost.exe
Description=Added by a variant of the BANCOS.RF TROJAN!
Source=Paul Collins Startup list
[Systems Restart]
Confirmed=X
Filename=Rundll32.exe beem.dll, DllRegisterServer
Description=Browser hijacker - the file serves to register a dll implemented as a browser plugin
Source=Paul Collins Startup list
[Systems.exe]
Confirmed=U
Filename=Systems.exe
Description=Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Source=Paul Collins Startup list
[SystemSafe]
Confirmed=U
Filename=Syssafe.exe
Description=System Safety Monitor - system monitoring tool with additional application firewalling
Source=Paul Collins Startup list
[SYSTEMSars32]
Confirmed=X
Filename=csrss.exe
Description=Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[SystemSAS]
Confirmed=X
Filename=System32.exe
Description=Added by the KWBOT.C WORM!
Source=Paul Collins Startup list
[SystemSearch]
Confirmed=X
Filename=regedit.exe -s c:\ie.reg
Description=Installs a Seachxl.com browser page hijack
Source=Paul Collins Startup list
[SystemSearch]
Confirmed=X
Filename=regedit.exe -s c:\sys.reg
Description=Installs a i--search.com browser page hijack
Source=Paul Collins Startup list
[SystemService]
Confirmed=X
Filename=msocfg.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[SystemService]
Confirmed=X
Filename=navchk.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[SystemService]
Confirmed=X
Filename=qservice.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[SystemService]
Confirmed=X
Filename=shman.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[SystemSettingf]
Confirmed=X
Filename=TRUG.vbs
Description=Added by the TRUG.B MACRO!
Source=Paul Collins Startup list
[SystemSuite Task Manager]
Confirmed=U
Filename=MXTASK.EXE
Description=vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro
Source=Paul Collins Startup list
[SystemTasks]
Confirmed=X
Filename=filez.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[SystemTasks]
Confirmed=X
Filename=sexypicz.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[SystemTasks]
Confirmed=X
Filename=loaded.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Systemtra]
Confirmed=X
Filename=Systra.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[SystemTra]
Confirmed=X
Filename=CDPlay.EXE
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[SystemTray]
Confirmed=U
Filename=SysTray.Exe
Description=SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[SystemTray]
Confirmed=X
Filename=SystemTray.exe
Description=Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray (SysTray.exe)
Source=Paul Collins Startup list
[SystemTray]
Confirmed=X
Filename=SysTray.exe
Description=Added by the ALADINZ.P TROJAN! Note - this is not the valid System Tray (systray.exe) which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP). If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
Source=Paul Collins Startup list
[SystemUpd]
Confirmed=N
Filename=SystemUpd.exe
Description=Updater for Swapoo.com, a kind of Napster for games
Source=Paul Collins Startup list
[SystemWideHook for Windows NT]
Confirmed=X
Filename=%WinHook32.exe
Description=Added by the MYDOOM.AC WORM!
Source=Paul Collins Startup list
[SystemWizard Sniffer]
Confirmed=U
Filename=Sniffer.exe
Description=SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC
Source=Paul Collins Startup list
[systemyom Updater]
Confirmed=X
Filename=systemyom.exe
Description=Added by a variant of the BACKDOOR.IRC.BOT TROJAN!
Source=Paul Collins Startup list
[SYSTEMZ Patch]
Confirmed=X
Filename=SYSZ.exe
Description=Added by the ALADINZ.P TROJAN!
Source=Paul Collins Startup list
[System_Messages]
Confirmed=U
Filename=pprsen.exe
Description=TerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like"
Source=Paul Collins Startup list
[Systesms.exe]
Confirmed=X
Filename=systesms.exe
Description=Added by the RBOT-HI WORM!
Source=Paul Collins Startup list
[Systest]
Confirmed=N
Filename=Systest.exe
Description=Clean Space temp files cleaner
Source=Paul Collins Startup list
[systhread]
Confirmed=X
Filename=winkernal.exe
Description=Added by the LIAMED WORM!
Source=Paul Collins Startup list
[SysTime]
Confirmed=X
Filename=systime.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Systmesy]
Confirmed=X
Filename=Systmesy.exe
Description=Added by the RBOT-KQ WORM!
Source=Paul Collins Startup list
[Systoan32]
Confirmed=X
Filename=systoan.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[systr32]
Confirmed=?
Filename=systr32.exe
Description=??
Source=Paul Collins Startup list
[systrax]
Confirmed=?
Filename=systrax.exe
Description=??
Source=Paul Collins Startup list
[Systray]
Confirmed=X
Filename=Systray_.Exe
Description=Added by the KERGEZ.A WORM!
Source=Paul Collins Startup list
[Systray]
Confirmed=X
Filename=[filename.exe]
Description=Winfavorites adware
Source=Paul Collins Startup list
[SYSTRAY]
Confirmed=X
Filename=UNMT.EXE
Description=Added by the SDBOT WORM!
Source=Paul Collins Startup list
[SysTray]
Confirmed=U
Filename=SysTray.Exe
Description=SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[SysTray]
Confirmed=X
Filename=Snnpapi.exe
Description=Added by an unidentified TROJAN!
Source=Paul Collins Startup list
[Systray driver]
Confirmed=X
Filename=systray.exe
Description=Added by the MUTEBOT TROJAN! Note - this is not the real SystemTray which shares the same filename
Source=Paul Collins Startup list
[SystrayServices]
Confirmed=X
Filename=Msxpw.exe
Description=Added by the CITOR WORM!
Source=Paul Collins Startup list
[systree]
Confirmed=X
Filename=systree
Description=Added by the BANCOS.L TROJAN!
Source=Paul Collins Startup list
[Systry]
Confirmed=X
Filename=[path to worm]
Description=Added by the AUTEX WORM!
Source=Paul Collins Startup list
[SYStry]
Confirmed=X
Filename=spoolsvr.exe
Description=Added by the SDBOT.GN WORM!
Source=Paul Collins Startup list
[Systryt]
Confirmed=X
Filename=[path to worm]
Description=Added by the AUTEX WORM!
Source=Paul Collins Startup list
[sysu]
Confirmed=X
Filename=sysu.exe
Description=Dynamic Desktop Media adware - see here
Source=Paul Collins Startup list
[SysUpd]
Confirmed=X
Filename=Sysupd.exe
Description=VirtuMonde adware
Source=Paul Collins Startup list
[Sysvupex]
Confirmed=X
Filename=Sysvupex.exe
Description=Added by the MEDIAS TROJAN!
Source=Paul Collins Startup list
[SysW8]
Confirmed=U
Filename=csta.exe
Description=Clean Space - privacy and perfomance enhancer
Source=Paul Collins Startup list
[SYSWB6]
Confirmed=U
Filename=SYSWB6.exe
Description=We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content
Source=Paul Collins Startup list
[SysWin]
Confirmed=X
Filename=SysWin.exe
Description=Added by the IRCCONTACT TROJAN!
Source=Paul Collins Startup list
[syswin32]
Confirmed=X
Filename=syswin32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Syswindow]
Confirmed=X
Filename=Syswindow.exe
Description=Added by the COW TROJAN!
Source=Paul Collins Startup list
[SYS_CLEAN]
Confirmed=X
Filename=Service.exe
Description=Added by the FLOPCOPY WORM!
Source=Paul Collins Startup list
[SZMsgSvc.exe]
Confirmed=U
Filename=SZMsgSvc.exe
Description=StopZilla! - pop-up killer
Source=Paul Collins Startup list
[t]
Confirmed=X
Filename=xclean.exe
Description=Flashtrack.B adware
Source=Paul Collins Startup list
[T-DSL SpeedMgr]
Confirmed=N
Filename=speedmgr.exe
Description=T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically
Source=Paul Collins Startup list
[Taba]
Confirmed=X
Filename=stte.exe
Description=Clickspring spyware
Source=Paul Collins Startup list
[Tablet]
Confirmed=N
Filename=Tablet.exe
Description=Loads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL+ALT+DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds)
Source=Paul Collins Startup list
[tablet s]
Confirmed=Y
Filename=tablet s
Description=Starts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful)
Source=Paul Collins Startup list
[TabletTip]
Confirmed=U
Filename=tabtip.exe
Description=The Microsoft Tablet PC Input Panel converts handwriting to text dynamically, and you can make corrections quickly and easily before inserting text
Source=Paul Collins Startup list
[TabUserW]
Confirmed=Y
Filename=TabUserW.exe
Description=Wacom pen tablet driver
Source=Paul Collins Startup list
[Tad]
Confirmed=N
Filename=tad.exe
Description=From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute
Source=Paul Collins Startup list
[TAG]
Confirmed=?
Filename=tag.exe
Description=??
Source=Paul Collins Startup list
[Tahni Deskmate]
Confirmed=N
Filename=Tahni.exe
Description=Tahni Deskmate - "Interactive cartoon character that lives on your Windows desktop"
Source=Paul Collins Startup list
[TalkingReminder]
Confirmed=N
Filename=TALKINGREMINDER.EXE
Description=Talking Reminder from Software River Solutions - talking calendar reminder
Source=Paul Collins Startup list
[talknow]
Confirmed=?
Filename=talknow.exe
Description=Could it be related to this or something similar?
Source=Paul Collins Startup list
[Tango]
Confirmed=?
Filename=Setup.exe
Description=Tango Broadband access software. Is it required?
Source=Paul Collins Startup list
[TangoManager]
Confirmed=?
Filename=TangoManager.exe
Description=Tango Broadband access software. Is it required?
Source=Paul Collins Startup list
[Tapicfg]
Confirmed=X
Filename=Tapicfg.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Tapisys]
Confirmed=X
Filename=tss.exe
Description=Added by the SMALL TROJAN!
Source=Paul Collins Startup list
[TapiTNA]
Confirmed=U
Filename=TapiTNA.exe
Description=Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys
Source=Paul Collins Startup list
[Tardis]
Confirmed=U
Filename=Tardis.exe
Description=Tardis - time synchronization software
Source=Paul Collins Startup list
[Task]
Confirmed=X
Filename=tasker.exe
Description=Added by the MYDOOM.R WORM!
Source=Paul Collins Startup list
[Task Bar]
Confirmed=X
Filename=TASKBAR.EXE
Description=Added by the FRETHEM.J WORM!
Source=Paul Collins Startup list
[Task BarClient]
Confirmed=?
Filename=TaskBarClient.exe
Description=Responsible for creating the System Tray icon and associated display system for the Starband satellite always on internet service
Source=Paul Collins Startup list
[Task BarSvr]
Confirmed=?
Filename=TaskBarSvr.exe
Description=Part of the Starband satellite always on internet service. Not included on the current system. What does it do and is it needed?
Source=Paul Collins Startup list
[Task Manager]
Confirmed=X
Filename=taskmngr.exe
Description=Added by the RBOT.Y WORM!
Source=Paul Collins Startup list
[Task Monitoring Service]
Confirmed=X
Filename=svchost.exe
Description=Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[task service]
Confirmed=X
Filename=taskservices.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Taskbar]
Confirmed=N
Filename=Taskbar.exe
Description=Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
Source=Paul Collins Startup list
[TaskBar]
Confirmed=N
Filename=CTLTask.exe
Description=Creative SoundBlaster Audigy Taskbar - used to choose between different types of EAX Effects, not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base article
Source=Paul Collins Startup list
[Taskbar Display Controls]
Confirmed=N
Filename=RunDLL deskcp16.dll, QUICKRES_RUNDLLENTRY
Description=Only appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel -> Display -> Settings -> Advanced -> General. Also appears if you have Win95 with the QuickRes "Powertoy" installed
Source=Paul Collins Startup list
[Taskbell.exe]
Confirmed=X
Filename=Rund1.exe
Description=Added by the YIPID TROJAN!
Source=Paul Collins Startup list
[TaskMan]
Confirmed=X
Filename=rundll32.exe
Description=Added by the DVLDR TROJAN! Note - this is not the valid "rundll32.exe" as it's in the Windows\Fonts directory
Source=Paul Collins Startup list
[taskmanager]
Confirmed=X
Filename=taskmgr.com
Description=Added by the BEREB WORM!
Source=Paul Collins Startup list
[Taskmgo]
Confirmed=X
Filename=[path to file]
Description=Added by the BANCBAN-T TROJAN!
Source=Paul Collins Startup list
[Taskmgr]
Confirmed=X
Filename=Taskmgr.exe
Description=System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory
Source=Paul Collins Startup list
[Taskmgr]
Confirmed=X
Filename=tskmgr32.exe
Description=Homepage hi-jacker
Source=Paul Collins Startup list
[taskmgr]
Confirmed=X
Filename=taskmgr.exe
Description=Added by the Startpage.G hijacker. Note - this is NOT the Windows Task Manager file!
Source=Paul Collins Startup list
[taskmgr.exe]
Confirmed=N
Filename=taskmgr.exe
Description=Windows Task Manager in Windows XP. If run from the Startup folder, the tray icon will be put to the system tray after boot. Useful to check if XP has finished running the delayed services after boot. Available via a desktop shortcut
Source=Paul Collins Startup list
[taskmgr.exe]
Confirmed=X
Filename=paint.exe
Description=Added by a variant of the AGENT.AH downloader TROJAN!
Source=Paul Collins Startup list
[taskmgr.exe]
Confirmed=X
Filename=mirc.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[taskmgr.exe]
Confirmed=X
Filename=paintms.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[taskmngr lptt01]
Confirmed=X
Filename=taskmngr.exe
Description=Variant of the RapidBlaster parasite (in a "Taskmngr" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[taskmngr ml097e]
Confirmed=X
Filename=taskmngr.exe
Description=Variant of the RapidBlaster parasite (in a "Taskmngr" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[TaskMon]
Confirmed=X
Filename=taskmon.exe
Description=Added by the MYDOOM.A or MYDOOM.J WORMS! Note - this is not the legitimate Win9x/Me file of the same name which resides in C:\Windows as this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). It is not normally on a WinXP system
Source=Paul Collins Startup list
[Taskmon driver]
Confirmed=X
Filename=winampa.exe
Description=Added by the LOONY-I TROJAN!
Source=Paul Collins Startup list
[TaskMonitor]
Confirmed=U
Filename=taskmon.exe
Description=The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)
Source=Paul Collins Startup list
[taskopen.exe]
Confirmed=X
Filename=taskopen.exe
Description=Added by the HIDD.C TROJAN!
Source=Paul Collins Startup list
[TaskPlus]
Confirmed=N
Filename=TASKPLUS0.EXE
Description=Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
Source=Paul Collins Startup list
[TaskPlus]
Confirmed=N
Filename=TASKPL~1.EXE
Description=Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
Source=Paul Collins Startup list
[TaskReg]
Confirmed=X
Filename=[random filename]
Description=Added by the CBLAD WORM!
Source=Paul Collins Startup list
[Taskschd]
Confirmed=X
Filename=TRAYWND.EXE
Description=Added by the LITMUS.002 TROJAN!
Source=Paul Collins Startup list
[taskswitch]
Confirmed=N
Filename=taskswitch.exe
Description=ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
Source=Paul Collins Startup list
[tasksys]
Confirmed=X
Filename=tasksys.vbs
Description=Added by the BYRON WORM!
Source=Paul Collins Startup list
[Tasktray]
Confirmed=N
Filename=CTLTray.exe
Description=Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a systray icon. Also allows you to launch the Taskbar via right-click -> Show Taskbar. The tasktray can be accessed via Start -> Programs -> Creative -> Sound Blaster Audigy -> Taskbar
Source=Paul Collins Startup list
[tat]
Confirmed=X
Filename=tatss.exe
Description=Delfin Promulgate adware variant
Source=Paul Collins Startup list
[Tau monitor]
Confirmed=Y
Filename=Taumon.exe
Description="Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system."
Source=Paul Collins Startup list
[TB2PROEXE]
Confirmed=U
Filename=tb2start.exe
Description=Timbuktu Pro - remote desktop access software
Source=Paul Collins Startup list
[TBC Pro]
Confirmed=U
Filename=tbcpro.exe
Description=TitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus
Source=Paul Collins Startup list
[tbctray]
Confirmed=N
Filename=tbctray.exe
Description=Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[TBLFUNC]
Confirmed=Y
Filename=tblmouse.exe
Description=Aiptek HyperPen driver
Source=Paul Collins Startup list
[TBPanel]
Confirmed=U
Filename=TBPanel.exe
Description=Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[TBPS]
Confirmed=X
Filename=TBPS.exe
Description=WebSearch toolbar, HuntBar parasite variant
Source=Paul Collins Startup list
[TBTray]
Confirmed=N
Filename=tbtray.exe
Description=VLSI/QSound ThunderBird PCI Control Panel. System Tray access to the settings for this and related soundcards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[TB_setup]
Confirmed=?
Filename=TB_ANI~1.EXE
Description=??
Source=Paul Collins Startup list
[TB_setup]
Confirmed=X
Filename=tb_setup.exe
Description=HuntBar parasite toolbar installer
Source=Paul Collins Startup list
[tcactive]
Confirmed=Y
Filename=tca.exe
Description=Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage
Source=Paul Collins Startup list
[TCASUTIEXE]
Confirmed=N
Filename=tcaudiag.exe
Description=3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Source=Paul Collins Startup list
[TCASUTIEXE]
Confirmed=N
Filename=TCASUTI.exe
Description=Associated with the 3COM diagnostic module (3COM NIC Doctor). No further information is available
Source=Paul Collins Startup list
[TCAUDIAG -off]
Confirmed=N
Filename=tcaudiag.exe
Description=3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Source=Paul Collins Startup list
[TCDPbtn]
Confirmed=?
Filename=TCDPbtn.exe
Description=Found on a Toshiba laptop
Source=Paul Collins Startup list
[TCDPlay]
Confirmed=?
Filename=TCDPlay.drv
Description=Found on a Toshiba laptop - sounds like the driver for the CD-ROM but why doesn't it use the standard Windows drivers - any comments?
Source=Paul Collins Startup list
[TClock]
Confirmed=U
Filename=TCLOCK.EXE
Description=Kazubon TClock. Utility that amongst other things synchronizes your system clock with Internet time servers. Available via Start -> Programs
Source=Paul Collins Startup list
[TClockEx]
Confirmed=U
Filename=TCLOCKEX.EXE
Description=Puts a configurable time/date display in the tray (and other features). Freeware by Dale Nurden and is popular on cover disks
Source=Paul Collins Startup list
[tcmonitor]
Confirmed=U
Filename=tcm.exe
Description=Part of The Cleaner from MooSoft - warns of changes to the registry
Source=Paul Collins Startup list
[TCP Monitoring]
Confirmed=X
Filename=LanNSvc.exe
Description=Added by the RANDEX.AAS WORM!
Source=Paul Collins Startup list
[tcupdater]
Confirmed=X
Filename=tcupdater.exe
Description=Topconverting.com/180Search adware updater
Source=Paul Collins Startup list
[TDispVol]
Confirmed=?
Filename=TDispVol.exe
Description=??
Source=Paul Collins Startup list
[TDKSTART]
Confirmed=U
Filename=TDKSTART.EXE
Description=Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
Source=Paul Collins Startup list
[TDKTASK]
Confirmed=N
Filename=TDKTASK.EXE
Description=Taskbar utility for a "control panel" for a CD-RW
Source=Paul Collins Startup list
[TDockNUndock]
Confirmed=?
Filename=N/A
Description=Found on a Toshiba laptop - for use with a docking station?
Source=Paul Collins Startup list
[TDS3]
Confirmed=U
Filename=TDS-3.exe
Description=DiamondCS TDS3 antitrojan. Can be used to scan on demand, but required in startup if you prefer real time protection
Source=Paul Collins Startup list
[TDspOff]
Confirmed=?
Filename=Tdspoff.exe
Description=Found on a Toshiba laptop
Source=Paul Collins Startup list
[Teach In Box]
Confirmed=N
Filename=teachbox.exe
Description=Tutoring program that comes with a SystemAX Computer
Source=Paul Collins Startup list
[Tech-In-A-Box]
Confirmed=Y
Filename=techbox.exe
Description=Tech-in-a-Box "provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running"
Source=Paul Collins Startup list
[Telemeter 3.0]
Confirmed=N
Filename=telemeter3.exe
Description=Internet connection bandwidth meter from a user ISP
Source=Paul Collins Startup list
[Telepath]
Confirmed=Y
Filename=telepath.exe
Description=Drivers for the WinModem versions of the US Robotics "Telepath" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
Source=Paul Collins Startup list
[TELUS Security service]
Confirmed=Y
Filename=freedom.exe
Description=Freedom Internet Security, provided by TELUS Communications Inc
Source=Paul Collins Startup list
[TempCom]
Confirmed=X
Filename=[randomname].com
Description=Added by the TRAXG WORM!
Source=Paul Collins Startup list
[tempx]
Confirmed=X
Filename=tempx.exe
Description=Added by the TEMPEX.A TROJAN!
Source=Paul Collins Startup list
[Tencent QQ]
Confirmed=X
Filename=Rund1132.exe qq.dll, Rundll32
Description=Added by the QQPASS.F TROJAN!
Source=Paul Collins Startup list
[Terminate Popup]
Confirmed=X
Filename=ZPU.exe
Description=Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see here
Source=Paul Collins Startup list
[Terminate Popup]
Confirmed=X
Filename=FPUK.exe
Description=Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see here
Source=Paul Collins Startup list
[TEscKey]
Confirmed=U
Filename=TEscKey.exe
Description=Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function
Source=Paul Collins Startup list
[Tesla]
Confirmed=?
Filename=TESLA.EXE
Description=??
Source=Paul Collins Startup list
[Testing 123]
Confirmed=X
Filename=msdata.dat
Description=Added by the NITS.A WORM!
Source=Paul Collins Startup list
[TExBUtil Registry]
Confirmed=?
Filename=TExBUtil.exe
Description=??
Source=Paul Collins Startup list
[TextAloud]
Confirmed=N
Filename=TextAloudMP3.exe
Description=TextAloud MP3 - convert text into spoken words and MP3s
Source=Paul Collins Startup list
[Textbridge Instant Access OCR]
Confirmed=N
Filename=telepath.exe
Description=TextBridge from Scansoft. OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs
Source=Paul Collins Startup list
[TEXTCONV]
Confirmed=X
Filename=services.exe
Description=Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[TEXTCONV]
Confirmed=X
Filename=winlogon.exe
Description=Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[TFncKy]
Confirmed=U
Filename=TFncky.exe
Description=Deals with the <Fn> - <Function> key combinations on a Toshiba laptop
Source=Paul Collins Startup list
[TFNF5]
Confirmed=U
Filename=TFNF5.exe
Description=Toshiba Hotkey Utility for Display Devices. By pressing <FN> + <F5>, a window appears showing the displays that can be chosen – LCD, LCD + CRT, CRT, TV
Source=Paul Collins Startup list
[tfswctrl]
Confirmed=Y
Filename=tfswctrl.exe
Description=Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
Source=Paul Collins Startup list
[TFTP***]
Confirmed=X
Filename=tftp***
Description=Added by a variant of the SPYBOT WORM! where *** can be any number
Source=Paul Collins Startup list
[TFunckey]
Confirmed=U
Filename=TFuncKey.exe
Description=Deals with the <Fn> - <Function> key combinations on a Toshiba laptop
Source=Paul Collins Startup list
[TgAddServer]
Confirmed=N
Filename=tgfix.exe
Description=Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove, Charter offer some uninstallation instructions involving a registry patch that you may be able to modify for your proivder or try here
Source=Paul Collins Startup list
[tgbcde]
Confirmed=X
Filename=module32.exe
Description=Added by the REIGN.R TROJAN!
Source=Paul Collins Startup list
[Tgcmd]
Confirmed=U
Filename=tgcmd.exe
Description=See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
Source=Paul Collins Startup list
[tgcmdprovidersbc]
Confirmed=U
Filename=tgcmd.exe
Description=See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
Source=Paul Collins Startup list
[TGCMG]
Confirmed=N
Filename=??
Description=Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work
Source=Paul Collins Startup list
[TGDC IE Plugin]
Confirmed=X
Filename=tgdc.exe
Description=ShopForGood spyware - see here
Source=Paul Collins Startup list
[tgkill]
Confirmed=X
Filename=tgkill.exe
Description=Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
Source=Paul Collins Startup list
[Tgsetsite]
Confirmed=U
Filename=tgfix.exe
Description=See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
Source=Paul Collins Startup list
[Thdetrf]
Confirmed=N
Filename=thdetr32.exe
Description=Appears to be related to Lycos advertising
Source=Paul Collins Startup list
[The Easy Bee's Hive]
Confirmed=U
Filename=ATCEgSvr.exe
Description=The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence
Source=Paul Collins Startup list
[TheMainStart]
Confirmed=?
Filename=N/A
Description=??
Source=Paul Collins Startup list
[THGuard]
Confirmed=U
Filename=TH_Guard.exe
Description=Resident memory scanning for TrojanHunter
Source=Paul Collins Startup list
[THGuard]
Confirmed=U
Filename=THGuard.exe
Description=Resident memory scanning for TrojanHunter
Source=Paul Collins Startup list
[This is a virus, please delete it]
Confirmed=X
Filename=bigbadvirus.exe
Description=Added by the RANDEX.F WORM!
Source=Paul Collins Startup list
[THOTKEY]
Confirmed=U
Filename=THotkey.exe
Description=Associated with the Fn+ keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen
Source=Paul Collins Startup list
[Threaded]
Confirmed=X
Filename=intcp32.exe
Description=Added by the RANDEX.UG WORM!
Source=Paul Collins Startup list
[ThrustTSR]
Confirmed=U
Filename=TMTMTSR.exe
Description=Thrustmaster Thrustmapper. "The Thrustmapper - t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"
Source=Paul Collins Startup list
[TiADSL]
Confirmed=U
Filename=tidslmon.exe
Description=Actiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start -> Programs
Source=Paul Collins Startup list
[tibs3]
Confirmed=X
Filename=tibs3.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[Tiger]
Confirmed=X
Filename=Shine.exe
Description=Added by the HAPPYLOW (or NISHE-A) VIRUS!
Source=Paul Collins Startup list
[Time Zone Synchronization]
Confirmed=X
Filename=wscript zshell.js
Description=Added by the NETDEX-A TROJAN!
Source=Paul Collins Startup list
[TimeCalendar]
Confirmed=U
Filename=tc.exe
Description=TimeCalendar digital planner
Source=Paul Collins Startup list
[Timed Backups Manager Startup]
Confirmed=N
Filename=BACKTIME.EXE
Description=Backup Plus - backup software
Source=Paul Collins Startup list
[Timemanager.exe]
Confirmed=N
Filename=Timemanager.exe
Description=Easy to use program for recording how you spend your time, designed to help you in billing multiple clients
Source=Paul Collins Startup list
[TimeOnline]
Confirmed=N
Filename=TIMEONLINE.EXE
Description=Lightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
Source=Paul Collins Startup list
[TIMER]
Confirmed=X
Filename=TIMER.EXE
Description=Added by the TIMESE.AG WORM!
Source=Paul Collins Startup list
[TimeService]
Confirmed=X
Filename=trun.exe
Description=TlfLic-A premium rate adult content dialler
Source=Paul Collins Startup list
[TimeSink Add Client]
Confirmed=X
Filename=TSADBOT.EXE
Description=Advertising spyware
Source=Paul Collins Startup list
[TimeSyncApp]
Confirmed=X
Filename=TimeSynchronize.exe
Description=DealHelper adware
Source=Paul Collins Startup list
[TimeUp]
Confirmed=N
Filename=Timeup.exe
Description=TimeUp - internet online timer
Source=Paul Collins Startup list
[Timezone]
Confirmed=U
Filename=TimeZone.exe
Description=Microsoft Daylight Saving Time Update Utility - see here
Source=Paul Collins Startup list
[TINTSETP]
Confirmed=N
Filename=TINTSETP.EXE
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[Tiny AV]
Confirmed=X
Filename=fooding.exe
Description=Added by the NETSKY.I WORM!
Source=Paul Collins Startup list
[Tiny Personal Firewall]
Confirmed=Y
Filename=persfw.exe
Description=Tiny Personal Firewall
Source=Paul Collins Startup list
[tinySpell]
Confirmed=U
Filename=tinyspell.exe
Description=Tinyspell - "allows you to easily and quickly check the spelling of words in any Windows application. Monitors your typing on the fly, alerts you whenever it detects a misspelled word, and checks the spelling of every word you copy to the clipboard"
Source=Paul Collins Startup list
[TiomanExe]
Confirmed=U
Filename=Tioman.Exe
Description=Agate Tioman - warm and hot swap removable bay device manager for IBM laptops
Source=Paul Collins Startup list
[Tips]
Confirmed=N
Filename=mousetips.exe
Description=Suggests tips on using your mouse
Source=Paul Collins Startup list
[TiTleBarClock]
Confirmed=U
Filename=TiTleBarClock.exe
Description=TitleBarClock displays the day/month/time and free physical RAM on the right hand side of an open window, replacing the system tray clock at startup
Source=Paul Collins Startup list
[Tivoli]
Confirmed=N
Filename=LCFEP.EXE
Description=Tivoli ‘TME’ System Tray icon - "'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"
Source=Paul Collins Startup list
[TizzleTalk]
Confirmed=U
Filename=TizzleTalk.exe
Description=TizzeTalk is a dialect translator for Yahoo, MSN, AOL Instant Messangers
Source=Paul Collins Startup list
[tjstartup]
Confirmed=X
Filename=svchost.exe
Description=Added by the CURDEAL TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[tjstartup]
Confirmed=X
Filename=[path to file]
Description=Added by the TJSERV.C TROJAN!
Source=Paul Collins Startup list
[TkBell.Exe]
Confirmed=N
Filename=evntsvc.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version
Source=Paul Collins Startup list
[TkBell.Exe]
Confirmed=N
Filename=realsched.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it
Source=Paul Collins Startup list
[TkBell.Exe]
Confirmed=N
Filename=tkbell.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
Source=Paul Collins Startup list
[TkBellExe]
Confirmed=N
Filename=evntsvc.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version
Source=Paul Collins Startup list
[TkBellExe]
Confirmed=N
Filename=realsched.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it
Source=Paul Collins Startup list
[TkBellExe]
Confirmed=N
Filename=tkbell.exe
Description=Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
Source=Paul Collins Startup list
[tkonnect]
Confirmed=N
Filename=TKONNECT.EXE
Description=Dialer for the Tiscali internet service provider. Available as a desktop shortcut
Source=Paul Collins Startup list
[tlc]
Confirmed=X
Filename=update911.js
Description=Hijacker installer
Source=Paul Collins Startup list
[TlcR]
Confirmed=?
Filename=avp.exe
Description=??
Source=Paul Collins Startup list
[TLogonPath]
Confirmed=U
Filename=tb2logon.exe
Description=Timbuktu Pro - remote desktop access software
Source=Paul Collins Startup list
[TM Outbreak Agent]
Confirmed=U
Filename=TMOAgent.exe
Description=Trend Micro Internet Security anti-virus software virus outbreak warnings. Notifies users of virus outbreaks and offers to update the scanner
Source=Paul Collins Startup list
[TMA distribution]
Confirmed=U
Filename=cfinst.exe
Description=Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
Source=Paul Collins Startup list
[tmax]
Confirmed=X
Filename=pupdate.exe
Description=Adware pop-up generator
Source=Paul Collins Startup list
[tmchook]
Confirmed=X
Filename=tmchook.exe
Description=Detected by Kaspersky as the TrojanDownloader.Win32.VB.aa VIRUS!
Source=Paul Collins Startup list
[TMEEJME]
Confirmed=?
Filename=TMEEJME.EXE
Description=Found in a ToshibaTME3 directory. Toshiba Mobile Extension related?
Source=Paul Collins Startup list
[TMERzCtl]
Confirmed=?
Filename=TMERzCtl.EXE
Description=Found in a ToshibaTME3 directory. Toshiba Mobile Extension related?
Source=Paul Collins Startup list
[TMESBS]
Confirmed=U
Filename=TMESBS21.exe
Description=Toshiba Mobile Extension Selectable Bay Service for WinXP - support for docking stations. Not required if you don't use a docking station
Source=Paul Collins Startup list
[TMESBS32]
Confirmed=?
Filename=TMESBS32.EXE
Description=Found in a ToshibaTME3 directory. Toshiba Mobile Extension related?
Source=Paul Collins Startup list
[TMESRV31]
Confirmed=U
Filename=TMESRV31.EXE
Description=Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
Source=Paul Collins Startup list
[TMExLogon]
Confirmed=U
Filename=TMESRV.EXE
Description=Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
Source=Paul Collins Startup list
[Tmmkb]
Confirmed=?
Filename=Tmmkysvr.exe
Description=Toshiba multi-media keyboard software - possibly including creating keyboard shortcuts?
Source=Paul Collins Startup list
[TMOUSE]
Confirmed=U
Filename=tmouse.exe
Description=Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL + ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL + SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects, except disabling the scroll/zoom features of the AccuPoint
Source=Paul Collins Startup list
[tmproxy]
Confirmed=Y
Filename=tmproxy.exe
Description=Trend Micro PC-cillin 2003 antivirus software
Source=Paul Collins Startup list
[TMTMTSR]
Confirmed=N
Filename=TMTMTST.exe
Description=Installed with Thrustmaster game controllers. It launches the Thrustmapper utility. Not required if you install the "driver only" from Thrustmaster website
Source=Paul Collins Startup list
[TNTClk]
Confirmed=U
Filename=TNTCLK.exe
Description=Overclocking program for TNT, TNT2, and other graphics cards. This program can overclock the graphics card manually after startup when needed, especially before starting a gaming session. However, for simplicity, it can be left checked to let it run once at startup to automatically overclock the graphics card. In this case, it doesn't even run in the background after doing its job
Source=Paul Collins Startup list
[ToADiMon.exe]
Confirmed=U
Filename=ToADiMon.exe
Description=T-Online ISP software connection assistant
Source=Paul Collins Startup list
[TomcatStartup]
Confirmed=?
Filename=hpbpsttp.exe
Description=Apache Tomcat web server, part of HP LaserJet "Printer Tools" software. What does it do and is it required?
Source=Paul Collins Startup list
[TomcatStartup 2.5]
Confirmed=?
Filename=hpbpsttp.exe
Description=Apache Tomcat web server, part of HP LaserJet "Printer Tools" software. What does it do and is it required?
Source=Paul Collins Startup list
[Tommorrow]
Confirmed=?
Filename=tomorrow.exe
Description=??
Source=Paul Collins Startup list
[ToPassSrv]
Confirmed=?
Filename=Pktopass.exe
Description=Related to Caere Pagekeeper scanning software (now taken over by Scansoft), Disabling is known to cause problems
Source=Paul Collins Startup list
[TopDesk]
Confirmed=U
Filename=TopDesk.exe
Description=TopDesk - puts an icon in your system tray that when clicked upon, opens a pop-up menu that gives instant access to all of your desktop programs without having to minimize, resize, move or close other programs or files
Source=Paul Collins Startup list
[ToPicks Starter]
Confirmed=X
Filename=Idhost.exe
Description=ToPicks parasite related
Source=Paul Collins Startup list
[topmoxie]
Confirmed=X
Filename=JavaRun.exe
Description=Marketing software from TopMoxie
Source=Paul Collins Startup list
[TOSCDSPD]
Confirmed=?
Filename=toscdspd.exe
Description=Toshiba laptop related
Source=Paul Collins Startup list
[Toshiba Fan]
Confirmed=Y
Filename=fan.exe
Description=Toshiba untilty to keep the fan on a laptop running if they fail to detect there is too much heat
Source=Paul Collins Startup list
[Toshiba Key State]
Confirmed=U
Filename=KEYSTATE.EXE
Description=Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g., Toshiba) laptops which do not have a Caps Lock indicator light. Available via Start -> Programs
Source=Paul Collins Startup list
[ToshibaPinger]
Confirmed=N
Filename=pinger.exe
Description=Pinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification. Disabling instructions here
Source=Paul Collins Startup list
[TOSHIBSU]
Confirmed=U
Filename=Toshibsu.exe
Description=Reduces the power consumption when the laptop isn't being used to preserve battery power. Hibernate function doesn't work if this is disabled. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run off battery regularly
Source=Paul Collins Startup list
[TosHKCW]
Confirmed=U
Filename=TosHKCW.exe
Description=Toshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed)
Source=Paul Collins Startup list
[TosMem]
Confirmed=Y
Filename=tosmem.exe
Description=Toshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem
Source=Paul Collins Startup list
[TotRecSched]
Confirmed=U
Filename=TotRecSched.exe
Description=Scheduler for Total Recorder - allows automatic recording of a show at a given time for later playback or you can use the scheduler as an alarm
Source=Paul Collins Startup list
[Touch Manager]
Confirmed=U
Filename=WinLED.exe
Description=Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
Source=Paul Collins Startup list
[TouchED]
Confirmed=U
Filename=TouchED.exe
Description=TouchPad On/Off Utility on a Toshiba laptop
Source=Paul Collins Startup list
[tour]
Confirmed=N
Filename=regedit ..tour.reg
Description=Edits registry values to keep the WinMe tour in Task Scheduler
Source=Paul Collins Startup list
[Tour]
Confirmed=N
Filename=wincool.exe
Description=Component of WinME that's annoying as hell. Pop's up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only
Source=Paul Collins Startup list
[tourpath]
Confirmed=N
Filename=regedit /s [path] tour.reg
Description=Edits registry values to keep the Win 2000 "tour" in Task Scheduler
Source=Paul Collins Startup list
[TP4EX]
Confirmed=U
Filename=tp4ex.exe
Description=Adds accessibility options for an IBM TrackPoint
Source=Paul Collins Startup list
[tp4mon]
Confirmed=?
Filename=tp4mon.exe
Description=May be IBM Thinkpad mouse/trackpoint related, if so is it required?
Source=Paul Collins Startup list
[tp4serv]
Confirmed=U
Filename=tp4serv.exe
Description=Supports the "pointer stick" on Thinkpads in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
Source=Paul Collins Startup list
[TP98TRAY]
Confirmed=?
Filename=TP98TRAY.EXE
Description=IBM Thinkpad related utility. What does it do and is it required?
Source=Paul Collins Startup list
[TP98UTIL]
Confirmed=N
Filename=TP98.EXE
Description=IBM Thinkpad feature setup & configuration utility
Source=Paul Collins Startup list
[tpcupdater]
Confirmed=X
Filename=updatetc.exe
Description=Adware, probably 180Solutions related
Source=Paul Collins Startup list
[TpHotKey]
Confirmed=U
Filename=TPHKMGR.EXE
Description=Activates "ThinkPad Help" when the "Thinkpad key" is pressed on an IBM ThinkPad laptop. Also activates the audio buttons (volume up/down, mute) on models such as the Thinkpad T30
Source=Paul Collins Startup list
[TPKMAPHELPER]
Confirmed=?
Filename=TpKmapAp.exe
Description=IBM ThinkPad related. What does it do, and is it required?
Source=Paul Collins Startup list
[TpKmapMn]
Confirmed=U
Filename=TpKmapMn.exe
Description=Create Keyboard combinations for special Thinkpad buttons when using an external keyboard, e.g. "Ctrl-arrow up" for "volume up". Only required when using an external keyboard. Available via Start -> Programs
Source=Paul Collins Startup list
[tpopservice]
Confirmed=U
Filename=tpopservice.exe
Description=DirecWay two-way satellite internet service enhanced POP proxy server for email
Source=Paul Collins Startup list
[TPP Auto Loader]
Confirmed=U
Filename=Tppaldr.exe
Description=Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD, CD-ROM and CD-RW drives. System tray icon allowing the user to disconnect the external drive without an error message being displayed
Source=Paul Collins Startup list
[Tprtray]
Confirmed=U
Filename=Tprtray.exe
Description=Displays the Power icon in the System Tray on a Toshiba laptop
Source=Paul Collins Startup list
[TpScrLk]
Confirmed=U
Filename=TpScrLk.exe
Description=IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
Source=Paul Collins Startup list
[TpShocks]
Confirmed=Y
Filename=TpShocks.exe
Description=Responsible for controlling the IBM Hard Drive Active Protection system found on newer models of IBM Thinkpads, including T41, T42, X40, R50, and R51. The Hard Drive Active Protection system is based on a technology similar to that used in automobiles to deploy airbags on contact: An accelorometer on the motherboard detects physical acceleration--such as when the notebook falls--and in response the system temporarily parks the hard drive's read/write head until stability returns
Source=Paul Collins Startup list
[TPSmain]
Confirmed=?
Filename=TPSMain.exe
Description=Toshiba related
Source=Paul Collins Startup list
[TPTray]
Confirmed=N
Filename=TPTray.exe
Description=Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[TPTRAY]
Confirmed=?
Filename=TP98TRAY.EXE
Description=IBM Thinkpad related utility. What does it do and is it required?
Source=Paul Collins Startup list
[TPwrMgr]
Confirmed=?
Filename=TPwrMgr.exe
Description=Found on a Toshiba laptop. Related to power management?
Source=Paul Collins Startup list
[TPWRTRAY]
Confirmed=Y
Filename=Tpwrtray.exe
Description=Toshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use
Source=Paul Collins Startup list
[tqrecv]
Confirmed=U
Filename=tqrecv.exe
Description=Tellique satellite broadcast reception software
Source=Paul Collins Startup list
[Traceless]
Confirmed=N
Filename=launch.exe
Description=Traceless 2003 - clear your cookies, temp directories and browser history with a click of a button. It also clears the recent documents and the IE drop down auto complete box
Source=Paul Collins Startup list
[Tracker]
Confirmed=?
Filename=Tracker.exe
Description=Possibly associated with My Deluxe Invoices program
Source=Paul Collins Startup list
[TrackpointSrv]
Confirmed=U
Filename=daemon.exe
Description=Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
Source=Paul Collins Startup list
[TrackpointSrv]
Confirmed=U
Filename=tp4serv.exe
Description=Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
Source=Paul Collins Startup list
[Tracks Eraser]
Confirmed=U
Filename=te.exe
Description=Tracks Eraser from Acesoft - "Erases all tracks of your internet activity"
Source=Paul Collins Startup list
[Tracks Eraser Pro]
Confirmed=U
Filename=te.exe
Description=Tracks Eraser Pro from Acesoft - "Erases all tracks of your internet activity"
Source=Paul Collins Startup list
[tranicon]
Confirmed=U
Filename=tranicon.exe
Description=A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System + File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent
Source=Paul Collins Startup list
[Transparent]
Confirmed=U
Filename=TransparentW.exe
Description=Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here
Source=Paul Collins Startup list
[Transparent]
Confirmed=U
Filename=TransparentD.exe
Description=Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here
Source=Paul Collins Startup list
[Transparent]
Confirmed=U
Filename=TransparentB.exe
Description=Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here
Source=Paul Collins Startup list
[TransparentIcons]
Confirmed=U
Filename=tranicon.exe
Description=A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System + File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent
Source=Paul Collins Startup list
[transtask]
Confirmed=U
Filename=transtask.exe
Description=A Tweak-XP component, makes the taskbar icons transparent
Source=Paul Collins Startup list
[Trashgrd]
Confirmed=U
Filename=TRASHGRD.EXE
Description=Part of McAfee Nuts & Bolts. Protects all the files you delete, even files deleted in DOS or in 16-bit Windows applications, by sending them to the Recycle Bin
Source=Paul Collins Startup list
[Tray Temperature]
Confirmed=N
Filename=Weatherbug.exe
Description=Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
Source=Paul Collins Startup list
[Traybar]
Confirmed=X
Filename=lsass.exe
Description=Added by the MYDOOM.L WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[traydate.exe]
Confirmed=U
Filename=TRAYDATE.EXE
Description=Displays the date as well as the time in the System Tray. Available from TUCOWS
Source=Paul Collins Startup list
[TrayManager]
Confirmed=U
Filename=Trayman.exe
Description=TrayManager hides system tray icons (FreeCell won't work when TrayMan is loaded)
Source=Paul Collins Startup list
[Traymon]
Confirmed=U
Filename=traymon.exe
Description=Netropa Internet Receiver traymonitor. Will only launch the bar if you are connected to the internet and there's new news
Source=Paul Collins Startup list
[TraySantaCruz]
Confirmed=N
Filename=tbctray.exe
Description=Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[TrayServer]
Confirmed=N
Filename=TrayServer.exe
Description=For monitoring tray icons
Source=Paul Collins Startup list
[TrayX]
Confirmed=X
Filename=winppr32.exe
Description=Added by the SOBIG.F WORM!
Source=Paul Collins Startup list
[tray_helper]
Confirmed=N
Filename=tray_helper.exe
Description=Tray Helper is an Email checker with additional tools, including a popup window killer, pinger module to monitor hosts and an event reminder
Source=Paul Collins Startup list
[TrendMicro Antivirus]
Confirmed=Y
Filename=Aveagent.exe
Description=Virus scanner
Source=Paul Collins Startup list
[TrendMicro OfficeScan NT]
Confirmed=Y
Filename=TMLISTEN.EXE
Description=Virus scanner
Source=Paul Collins Startup list
[Trickler]
Confirmed=X
Filename=fsg.exe
Description=Adware
Source=Paul Collins Startup list
[Trickler]
Confirmed=X
Filename=fsg-ag_3102.exe
Description=Adware
Source=Paul Collins Startup list
[Trickler]
Confirmed=X
Filename=gain_trickler_3202.exe
Description=Adware
Source=Paul Collins Startup list
[trickler_bic_GatorDM_4010]
Confirmed=X
Filename=trickler_bic_GatorDM_4010.exe
Description=Adware
Source=Paul Collins Startup list
[TridTray]
Confirmed=?
Filename=TridTray.exe
Description=System Tray access to Trident 4DWave soundcards?
Source=Paul Collins Startup list
[TridTray]
Confirmed=?
Filename=TridTray.exe
Description=System Tray access to Trident 4DWave soundcards?
Source=Paul Collins Startup list
[trirot]
Confirmed=Y
Filename=trirot.exe
Description=Trident Microsystems 3D video driver
Source=Paul Collins Startup list
[TrojanScanner]
Confirmed=U
Filename=Trjscan.exe
Description=Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed
Source=Paul Collins Startup list
[TrojanShield]
Confirmed=U
Filename=Init.exe
Description=TrojanShield
Source=Paul Collins Startup list
[True Internet Color Icon]
Confirmed=U
Filename=internetcolor.exe
Description=Part of Colorific & 3Deep from LightSurf Technologies (nee E-Color). "With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"
Source=Paul Collins Startup list
[TrueFonts]
Confirmed=X
Filename=fonts.hta
Description=Browser hijacker - redirecting to Hugesearch.net
Source=Paul Collins Startup list
[TrueSync Launcher]
Confirmed=N
Filename=tstool.exe
Description=Starfish TrueSync - for synchronization between Windows platforms and popular devices, applications and services
Source=Paul Collins Startup list
[TrueVector]
Confirmed=Y
Filename=VSMON.EXE
Description=Even if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this
Source=Paul Collins Startup list
[tsa]
Confirmed=X
Filename=tsm.exe
Description=Uploader-R adware
Source=Paul Collins Startup list
[Tsa2]
Confirmed=X
Filename=tsm2.exe
Description=Uploader-R adware variant
Source=Paul Collins Startup list
[TsAdbot]
Confirmed=X
Filename=TSADBOT.EXE
Description=TimeSink Add Client - advertising spyware
Source=Paul Collins Startup list
[TSBxLogon]
Confirmed=?
Filename=TMESBS2.EXE
Description=Found on a Toshiba laptop. May be related to TMESBS?
Source=Paul Collins Startup list
[tskdbg]
Confirmed=X
Filename=tskdbg.exe
Description=Added by the FLOOD.E TROJAN!
Source=Paul Collins Startup list
[Tsl]
Confirmed=X
Filename=tsl.exe
Description=Uploader-R adware
Source=Paul Collins Startup list
[TSMsger]
Confirmed=N
Filename=TSMsger.exe
Description=Epson scannner software - required for "one-touch" operation. Can be launched manually
Source=Paul Collins Startup list
[TSPower]
Confirmed=?
Filename=spower.drv
Description=Found on a Toshiba laptop. Related to power management?
Source=Paul Collins Startup list
[TSService]
Confirmed=?
Filename=NSSERVICE.EXE
Description=??
Source=Paul Collins Startup list
[tsyssmon]
Confirmed=?
Filename=tsyssmon.exe
Description=Found in a Toshibasysstability directory
Source=Paul Collins Startup list
[ttasq]
Confirmed=?
Filename=ttasq.exe
Description=??
Source=Paul Collins Startup list
[Tukati]
Confirmed=?
Filename=TukatiRedistributor.exe
Description=Tukati Digital Content Distribution. Is it required?
Source=Paul Collins Startup list
[TuneUp MemOptimizer]
Confirmed=U
Filename=memoptimizer.exe
Description=Part of "TuneUp Utilities", specifically 2003 version. "Monitors and optimizes free memory in the background." Basically, it cleans RAM and also allows you to clear the clipboard
Source=Paul Collins Startup list
[TurboExplorer]
Confirmed=U
Filename=TE.exe
Description=Web accelerator - "TurboExplorer® 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer® 4/5 to achieve a faster and more effective approach to the internet". Only needed if you find it improves web browsing
Source=Paul Collins Startup list
[TurboMemoryCharger]
Confirmed=U
Filename=turbomemorycharger.exe
Description=Some users swear by memory management utilities such as Turbo Memory Charger but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
Source=Paul Collins Startup list
[TurboNote]
Confirmed=N
Filename=tbnote.exe
Description=Post-It's on your desktop. Available via Start -> Programs
Source=Paul Collins Startup list
[TurboTop]
Confirmed=U
Filename=TurboTop.exe
Description=TurboTop - make any window "Always on top"
Source=Paul Collins Startup list
[TV Media]
Confirmed=X
Filename=Tvm.exe
Description=CleverIEHooker hijacker variant
Source=Paul Collins Startup list
[TVMD]
Confirmed=X
Filename=tvmd.exe
Description=Total Velocity - "Secure commerce company that enables the ‘checkout’ process for our customers in order to safely and securely purchase our award winning software". Autointsalling spyware
Source=Paul Collins Startup list
[TvNow]
Confirmed=U
Filename=TvNow.exe
Description=Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
Source=Paul Collins Startup list
[TVTMD]
Confirmed=X
Filename=TVTMD.EXE
Description=Total Velocity variant - autoinstalling spyware
Source=Paul Collins Startup list
[TVWakeup]
Confirmed=N
Filename=tvwakeup.exe
Description=MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
Source=Paul Collins Startup list
[Tvwatch]
Confirmed=?
Filename=tvwatch.exe
Description=Associated with the TV-oOut option on Asus AGP or Intel graphics cards. Is it required?
Source=Paul Collins Startup list
[Twain image]
Confirmed=X
Filename=mmp32.exe
Description=DailyWinner adware related
Source=Paul Collins Startup list
[TWarmBay]
Confirmed=?
Filename=N/A
Description=Found on a Toshiba laptop. Related to hotswap bay management?
Source=Paul Collins Startup list
[TWarnMsg]
Confirmed=U
Filename=twarnmsg.exe
Description=Toshiba System Warning Function for Windows 98, Me, 2000 - provides notification dialog when the cooling fan stops
Source=Paul Collins Startup list
[TWBbtn]
Confirmed=?
Filename=N/A
Description=Found on a Toshiba laptop
Source=Paul Collins Startup list
[TWBrowse]
Confirmed=?
Filename=TWBrowse.drv
Description=Found on a Toshiba laptop. Possibly related to TWAIN drivers (ie, scanners, etc) - see this?
Source=Paul Collins Startup list
[Tweak Manager]
Confirmed=?
Filename=WinManager.Exe
Description=WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?
Source=Paul Collins Startup list
[Tweak UI]
Confirmed=U
Filename=rundll32.exe tweakui.cpl, tweakmeup
Description=Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed
Source=Paul Collins Startup list
[Tweak UI]
Confirmed=U
Filename=rundll32.exe tweakui.cpl, tweaklogon
Description=Automatically logs you on if you have Microsoft's Tweak UI "powertoy" installed
Source=Paul Collins Startup list
[Tweak UI]
Confirmed=X
Filename=RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup
Description=Added by the SUBWOOFER TROJAN! Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup"
Source=Paul Collins Startup list
[Tweak-Me]
Confirmed=U
Filename=TWEAK-ME.exe
Description=3rd party version of Miscrosoft'sTweak UI "powertoy" with many more options and controls (plus full support), designed specifically to take advantage of features in WinMe/2K and above, available from here
Source=Paul Collins Startup list
[Tweak-xp]
Confirmed=U
Filename=Tweak-xp.exe
Description=Main program for Tweak-XP - a WinXP tweaking utility
Source=Paul Collins Startup list
[TweakDUN]
Confirmed=U
Filename=tweakdun.exe
Description=Utility to optimize your Internet Browser Software. TweakDUN promotes faster Internet data transfer rates and faster downloads by eliminating fragmentation of data packets
Source=Paul Collins Startup list
[tweakico]
Confirmed=?
Filename=tweakico.exe
Description=May be a HP program to control their icons?
Source=Paul Collins Startup list
[TwkSCardSrv]
Confirmed=N
Filename=SCardS32.Exe
Description=Used with Towitoko SmartCard Readers for card recognition
Source=Paul Collins Startup list
[Twunk_64]
Confirmed=X
Filename=twunk_64.exe
Description=System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory
Source=Paul Collins Startup list
[type32]
Confirmed=N
Filename=type32.exe
Description=For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings. Not required unless you have changed them
Source=Paul Collins Startup list
[TypingSatellite]
Confirmed=N
Filename=KBOOST.exe
Description=Typing Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs
Source=Paul Collins Startup list
[Uate]
Confirmed=X
Filename=oocs.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[UBSShell]
Confirmed=U
Filename=UBSShell.exe
Description=UBS (United Bank of Switzerland) banking software
Source=Paul Collins Startup list
[UCmore XP - The Search Accelerator]
Confirmed=U
Filename=rundll32.exe UCMTSAIE.dll, DllShowTB
Description=UCmore toolbar - search accelerator
Source=Paul Collins Startup list
[UC_SMB]
Confirmed=N
Filename=ucstart.exe
Description=Part of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed
Source=Paul Collins Startup list
[uc_start]
Confirmed=N
Filename=ucstartup.exe
Description=Auto updater feature for IBM machines that tries to connect to IBM to see if there are any new drivers, patches and etc
Source=Paul Collins Startup list
[UD Agent]
Confirmed=U
Filename=UD.EXE
Description=The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
Source=Paul Collins Startup list
[Ueproc32]
Confirmed=U
Filename=UEPROC32.exe
Description=Part of Norton Utilities - most likely associated with the Unerase Wizard in older versions
Source=Paul Collins Startup list
[ugon]
Confirmed=?
Filename=aockstrs.exe
Description=??
Source=Paul Collins Startup list
[Uidler]
Confirmed=N
Filename=Uidler.exe
Description=Uniloc Titlewave Browser used with some shareware
Source=Paul Collins Startup list
[UIWatcher]
Confirmed=N
Filename=UIWatcher.exe
Description=Ashampoo Uninstaller Suite - installation watcher. Available via Start -> Programs
Source=Paul Collins Startup list
[UKVideo2]
Confirmed=X
Filename=ukvideo2.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Ulead Photo Express x.0 Calendar]
Confirmed=N
Filename=calcheck.exe
Description=Ulead Calendar Checker - part of Ulead Photo Express, where "x" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually. See here for disabling instructions
Source=Paul Collins Startup list
[UltimateZip Quick Start]
Confirmed=N
Filename=uzqkst.exe
Description=UltimateZip - file compression utility
Source=Paul Collins Startup list
[Ultra Hal Assistant 4.5 Startup]
Confirmed=N
Filename=HalAsst.exe
Description=Zabaware Ultra Hal Assistant - artificial intelligence conversation simulator. It is capable of being your digital secretary and companion
Source=Paul Collins Startup list
[Ulubione]
Confirmed=X
Filename=sys****.exe
Description=Search Hijacker, redirecting to maxxxhosters.com - where **** are random characters
Source=Paul Collins Startup list
[UMAX VistaAccess]
Confirmed=N
Filename=vsaccess.exe
Description=VistaAccess gives you quick and easy access to scanning functions right from your desktop
Source=Paul Collins Startup list
[UMonit]
Confirmed=U
Filename=umonit.exe
Description=Alerts when USB device is plugged in
Source=Paul Collins Startup list
[umxagent]
Confirmed=Y
Filename=umxagent.exe
Description=Tiny Personal Firewall V4 - main engine
Source=Paul Collins Startup list
[umxldra]
Confirmed=Y
Filename=umxldra.exe
Description=User mode executive module DLL loader - part of Tiny Personal Firewall V4
Source=Paul Collins Startup list
[UMXLDRW]
Confirmed=Y
Filename=UMXLDRW.exe
Description=Tiny Personal Firewall (pre V4)
Source=Paul Collins Startup list
[un32info]
Confirmed=X
Filename=un32info.Exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[uninstal]
Confirmed=X
Filename=regsvr32 /u /s image.dll
Description=CoolWebSearch parasite related
Source=Paul Collins Startup list
[Uninstall****]
Confirmed=X
Filename=upd.exe
Description=Adult content based screen saver where **** can be any number
Source=Paul Collins Startup list
[UninstallAbility]
Confirmed=N
Filename=uability.exe
Description=UninstallAbility uninstaller
Source=Paul Collins Startup list
[Uninstall_TBPS]
Confirmed=X
Filename=TBuninst.exe /remove
Description=WebSearch toolbar related, HuntBar parasite variant
Source=Paul Collins Startup list
[UniSc]
Confirmed=U
Filename=Unisc.exe
Description=McAfee UnInstaller
Source=Paul Collins Startup list
[uniucu]
Confirmed=?
Filename=uniucu.exe
Description=??
Source=Paul Collins Startup list
[unldr16]
Confirmed=X
Filename=unldr16.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[unldr32]
Confirmed=X
Filename=unldr32.exe
Description=Added by a variant of the CRYPTER.C TROJAN!
Source=Paul Collins Startup list
[untray]
Confirmed=Y
Filename=untray.exe
Description=Part of Command AntiVirus
Source=Paul Collins Startup list
[uoltray]
Confirmed=N
Filename=exec.exe
Description=Netzero free ISP software - not required
Source=Paul Collins Startup list
[UpConfgVer]
Confirmed=N
Filename=UpgConf.exe
Description=Panda Antivirus Platinum. Purpose unclear, but according to Panda Software not required for the AV to function
Source=Paul Collins Startup list
[Update]
Confirmed=X
Filename=[original file path]
Description=Added by the LYNDEGG WORM!
Source=Paul Collins Startup list
[Update]
Confirmed=X
Filename=CDUpdater.exe
Description="Carpe Diem" adult premium rate dialler related
Source=Paul Collins Startup list
[Update]
Confirmed=X
Filename=Sysupd.exe
Description=Added by the SLACKBOT VIRUS!
Source=Paul Collins Startup list
[Update]
Confirmed=X
Filename=Zupdate.exe
Description=B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\\Windows\\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
Source=Paul Collins Startup list
[Update]
Confirmed=X
Filename=mshtm.exe
Description=Browser hijacker - redirecting to buldog-search.com
Source=Paul Collins Startup list
[Update]
Confirmed=X
Filename=UPDATE-28062004.exe[25 blank spaces].vbs
Description=Added by the MIDFIN WORM!
Source=Paul Collins Startup list
[Update for Works]
Confirmed=?
Filename=MSWkstz.exe
Description=Maybe related to later versions of MS Works?
Source=Paul Collins Startup list
[Update Grokster]
Confirmed=N
Filename=WiseUpdt.exe
Description=Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor
Source=Paul Collins Startup list
[Update Install]
Confirmed=X
Filename=Schost.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Update local]
Confirmed=?
Filename=SetCPQLC.exe
Description=Running on a Compaq desktop. Any ideas?
Source=Paul Collins Startup list
[Update Manager]
Confirmed=N
Filename=UpdateManager.exe
Description=Searches for updates for the Rogers Yahoo! Browser - can be run manually
Source=Paul Collins Startup list
[update run dos]
Confirmed=X
Filename=logon.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Update Service]
Confirmed=Y
Filename=Update.exe
Description=Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall
Source=Paul Collins Startup list
[update service]
Confirmed=X
Filename=svxhost.exe
Description=Added by the RBOT-MG WORM!
Source=Paul Collins Startup list
[Update TUT]
Confirmed=?
Filename=WiseUpdt.exe
Description=??
Source=Paul Collins Startup list
[Update ver 1.0]
Confirmed=X
Filename=Swap.exe
Description=Added by the SWAP-C WORM!
Source=Paul Collins Startup list
[UpdateComponent]
Confirmed=X
Filename=CNF UPD.EXE
Description=Added by the SPYBOT.GEN VIRUS!
Source=Paul Collins Startup list
[UpdateFW]
Confirmed=?
Filename=fwdload.exe
Description=Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module?
Source=Paul Collins Startup list
[UPDATEHOOK]
Confirmed=?
Filename=Rundll32.exe
Description=??
Source=Paul Collins Startup list
[UpdateManager]
Confirmed=U
Filename=sgtray.exe
Description=StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
Source=Paul Collins Startup list
[UpdateMedia]
Confirmed=X
Filename=UpdateMedia.exe
Description=MediaUpdate foistware
Source=Paul Collins Startup list
[updatemgr.exe]
Confirmed=N
Filename=updatemgr.exe
Description=Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually
Source=Paul Collins Startup list
[updater]
Confirmed=X
Filename=wupdater.exe
Description=eUniverse KeenValue parasite related
Source=Paul Collins Startup list
[updater]
Confirmed=?
Filename=updater.exe
Description=??
Source=Paul Collins Startup list
[Updater Service Process]
Confirmed=X
Filename=svhost32.exe
Description=Added by the AGOBOT.TY WORM!
Source=Paul Collins Startup list
[updater32]
Confirmed=X
Filename=winload32.exe
Description=Added by the CULT.M WORM!
Source=Paul Collins Startup list
[Updates]
Confirmed=X
Filename=msupdate.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Updates from HP]
Confirmed=N
Filename=backweb*****.exe
Description=Automatically detects an internet connection and downloads any available updates - * is random digit
Source=Paul Collins Startup list
[Updatestats]
Confirmed=N
Filename=Updatestats.exe
Description=Statblaster - "Get officially liscensed MLB pitch-by-pitch real time updates from every stadium around the league. StatBlaster provides live streaming statistics for each fantasy matchup you want tracked either in one league or across all your leagues"
Source=Paul Collins Startup list
[updatev01]
Confirmed=N
Filename=updatev01.exe
Description=Ultra-networks.com software updater/downloader
Source=Paul Collins Startup list
[Updatewiz]
Confirmed=?
Filename=updatewiz.exe
Description=??
Source=Paul Collins Startup list
[UPDATE~1]
Confirmed=N
Filename=updatemgr.exe
Description=Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually
Source=Paul Collins Startup list
[upddateit]
Confirmed=X
Filename=winit.exe
Description=Added by the RBOT-MS WORM!
Source=Paul Collins Startup list
[Updmgr]
Confirmed=X
Filename=updmgr.exe
Description=eUniverse/KeenValue adware variant
Source=Paul Collins Startup list
[UpdReg]
Confirmed=N
Filename=Updreg.exe
Description=Reminder to register Creative Labs SoundBlaster Live! cards
Source=Paul Collins Startup list
[UpdSys]
Confirmed=X
Filename=[random filename]
Description=Added by the BJ TROJAN!
Source=Paul Collins Startup list
[UPERVGAS]
Confirmed=?
Filename=UPERVGAS.exe
Description=??
Source=Paul Collins Startup list
[upme]
Confirmed=X
Filename=[filename]
Description=Added by the MUGLY.F WORM!
Source=Paul Collins Startup list
[UPNPService]
Confirmed=X
Filename=WinSVCservice.exe
Description=Added by the AGOBOT.UN WORM!
Source=Paul Collins Startup list
[UPS]
Confirmed=Y
Filename=ups.exe
Description=PowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon)
Source=Paul Collins Startup list
[UPSentry 2000]
Confirmed=Y
Filename=upsd.exe
Description=Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
Source=Paul Collins Startup list
[UPSlim]
Confirmed=Y
Filename=upsd.exe
Description=Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
Source=Paul Collins Startup list
[UPSUtl]
Confirmed=X
Filename=web.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Uptimer4]
Confirmed=U
Filename=Uptimer4.exe
Description=Uptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things
Source=Paul Collins Startup list
[UpToDate]
Confirmed=X
Filename=uptodate.exe
Description=BrowserAid/BrowserPal foistware
Source=Paul Collins Startup list
[UrlLstCk]
Confirmed=Y
Filename=UrlLstCk.exe
Description=Part of Norton Internet Security. From Symantec - "UrlLstCk.exe is a necessary file that will be present in C:\Program Files\Norton Internet Security. It is a URL Checklist. It should not be disabled"
Source=Paul Collins Startup list
[URLMAP]
Confirmed=N
Filename=Urlmap.exe
Description=Installed by MS Money, and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it
Source=Paul Collins Startup list
[UrtSvcExe]
Confirmed=Y
Filename=Urt95Svc.exe
Description="Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"
Source=Paul Collins Startup list
[Usb]
Confirmed=?
Filename=Usb.exe
Description=HP related - not sure whether it's required
Source=Paul Collins Startup list
[USB 2.1 Driver]
Confirmed=X
Filename=winupdate1.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[USB controller]
Confirmed=X
Filename=Svcmm32.exe
Description=Ouchvideo.com 'n-Lite' spyware
Source=Paul Collins Startup list
[USB Device]
Confirmed=X
Filename=servicelog.exe
Description=Added by the WOOTBOT.CB WORM!
Source=Paul Collins Startup list
[USB Device]
Confirmed=X
Filename=win32usb.exe
Description=Added by the FORBOT-BQ WORM!
Source=Paul Collins Startup list
[USB Hardware Monitoring]
Confirmed=X
Filename=USBhardware.exe
Description=Added by the RBOT-NN WORM!
Source=Paul Collins Startup list
[USB Host Service]
Confirmed=X
Filename=usbsvc.exe
Description=Added by the RBOT-GG WORM!
Source=Paul Collins Startup list
[USB Hub Keyboard Patch]
Confirmed=?
Filename=SKBPATCH.EXE
Description=USB HUB Update
Source=Paul Collins Startup list
[USB SECURITY DEVICE CoInstaller]
Confirmed=Y
Filename=JupitCo.exe
Description=ButterflyMedia USB Flash drive related - required for the password security feature to work
Source=Paul Collins Startup list
[UsbD]
Confirmed=X
Filename=smss32.exe
Description=Adware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj
Source=Paul Collins Startup list
[UsbD]
Confirmed=X
Filename=svhost32.exe
Description=Added by the AGENT.IB TROJAN!
Source=Paul Collins Startup list
[Usbd]
Confirmed=X
Filename=usb_d.exe
Description=Added by the CIDRA-A TROJAN!
Source=Paul Collins Startup list
[USBDetector]
Confirmed=U
Filename=USBDetector.exe
Description=USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
Source=Paul Collins Startup list
[USBDetector]
Confirmed=?
Filename=UDetect.exe
Description=USB detector, apparently for an MP3 player - any further information appreciated!
Source=Paul Collins Startup list
[usbdrv]
Confirmed=X
Filename=servicetask.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[USBMMKBD]
Confirmed=U
Filename=usbmmkbd.exe
Description=USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version (available here) no longer pings a server when on-line wheras the older version did but did not transmit any user information
Source=Paul Collins Startup list
[usbn]
Confirmed=X
Filename=usbn.exe
Description=Adult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa
Source=Paul Collins Startup list
[USBPNP]
Confirmed=Y
Filename=USBPNP.exe
Description=SiPix digital camera Twain USB driver
Source=Paul Collins Startup list
[USBTA]
Confirmed=N
Filename=usbtapnp.exe
Description=System Tray access for the BeWAN Gazel 128 USB ISDN adapter
Source=Paul Collins Startup list
[User Services]
Confirmed=X
Filename=usersvc.exe
Description=Added by the REVCUSS.A TROJAN!
Source=Paul Collins Startup list
[User23.exe]
Confirmed=X
Filename=DIAL.exe
Description=This is a trojan trying to disguise itself as User32.dll
Source=Paul Collins Startup list
[User32]
Confirmed=X
Filename=[filename]
Description=Added by the NETTRASH TROJAN!
Source=Paul Collins Startup list
[UserFaultCheck]
Confirmed=N
Filename=dumprep 0 -u
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[UserSystem]
Confirmed=X
Filename=[filename]
Description=CoolWebSearch SmartSearch variant - also see here
Source=Paul Collins Startup list
[ushli]
Confirmed=X
Filename=sscbltqu.exe
Description=Obtained from an MP3 search list site. Also generates random processes on reboot
Source=Paul Collins Startup list
[usrgtway.exe]
Confirmed=X
Filename=syswrun4x.exe
Description=Added by the MITGLIEDER.E TROJAN!
Source=Paul Collins Startup list
[USRobotics 802.11g Wireless Network Utility]
Confirmed=N
Filename=USRWLANG.exe
Description=USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck "Use Windows to configure my wireless settings" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties
Source=Paul Collins Startup list
[Usrobotics Online Registration]
Confirmed=N
Filename=??
Description=Pop-up reminding customers to register their products online at US Robotics
Source=Paul Collins Startup list
[Usrr]
Confirmed=X
Filename=rncr.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[USRSTA]
Confirmed=?
Filename=USRSTA.exe
Description=Wireless Card controller. What does it do and is it required?
Source=Paul Collins Startup list
[USSShReg]
Confirmed=N
Filename=USSSHREG.EXE
Description=Registration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
Source=Paul Collins Startup list
[Utility Ping]
Confirmed=?
Filename=UTILIT~1.EXE
Description=??
Source=Paul Collins Startup list
[UtilityPro]
Confirmed=N
Filename=UtilityPro.exe
Description=IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions
Source=Paul Collins Startup list
[UTILsInst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[Utopia Angel]
Confirmed=N
Filename=Angel.exe
Description=Calculator for the online Utopia game
Source=Paul Collins Startup list
[uwyrl]
Confirmed=X
Filename=uwyrl.exe
Description=Added by the PHEL.A TROJAN!
Source=Paul Collins Startup list
[V.92 Modem On Hold]
Confirmed=U
Filename=Ltmoh.exe
Description=Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
Source=Paul Collins Startup list
[V128IID]
Confirmed=Y
Filename=Rundll32.exe v128iitw.dll, STB_InitTweak
Description=Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages
Source=Paul Collins Startup list
[V128IITV]
Confirmed=?
Filename=??
Description=Loads drivers for some STB graphics cards. May be related to such a card with a TV out option?
Source=Paul Collins Startup list
[V66SHELL]
Confirmed=?
Filename=V66SHELL.EXE
Description=It looks to be part of the display driver set for ASUS V3800, V6600 and V6800 display adapters. Probably a system tray quick access control?
Source=Paul Collins Startup list
[va10key]
Confirmed=U
Filename=va10key.exe
Description=Only required if you use the 10 kay bay unit with a Sony Vaio laptop
Source=Paul Collins Startup list
[VAGCtrl]
Confirmed=Y
Filename=VAGCTRL.EXE
Description=Vexira Antivirus - virus scanner from Central Command
Source=Paul Collins Startup list
[VAGuard]
Confirmed=Y
Filename=VAGNT.exe
Description=Vexira Antivirus - virus scanner from Central Command
Source=Paul Collins Startup list
[VAIO Action Setup (Server)]
Confirmed=U
Filename=VAServ.exe
Description=Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera, digital still camera, etc. via iLink (FireWire) or USB
Source=Paul Collins Startup list
[VAIO Recovery]
Confirmed=U
Filename=PartSeal.exe
Description=System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
Source=Paul Collins Startup list
[ValidData]
Confirmed=X
Filename=[path to trojan]
Description=Added by the RANKY.H TROJAN!
Source=Paul Collins Startup list
[vb6]
Confirmed=X
Filename=vb6.exe
Description=Added by the MUGLY.D WORM!
Source=Paul Collins Startup list
[VBouncer]
Confirmed=X
Filename=VirtualBouncer.exe
Description=Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here
Source=Paul Collins Startup list
[VbouncerDL]
Confirmed=X
Filename=VbouncerInner****.exe [* = random char]
Description=Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here
Source=Paul Collins Startup list
[VbouncerDL]
Confirmed=X
Filename=VBouncerInner.exe
Description=Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself
Source=Paul Collins Startup list
[VBundleOuterDL]
Confirmed=X
Filename=BundleOuter.EXE
Description=VirtualBouncer 2.0 - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs
Source=Paul Collins Startup list
[VB_run]
Confirmed=X
Filename=comctl_32.exe
Description=Dubious downloader from densmail.com
Source=Paul Collins Startup list
[VC5MediaPlayer]
Confirmed=X
Filename=csmss.exe
Description=Added by the DEDLER-B WORM!
Source=Paul Collins Startup list
[VC5Play]
Confirmed=N
Filename=VC5Play.exe
Description=Virtual CD drive emulator - version 5. Available via Start -> Programs
Source=Paul Collins Startup list
[VCatch]
Confirmed=X
Filename=Vcatch.exe
Description=CommonSearch Vcatch - "antivirus" software which actually bundles spy/adware itself!
Source=Paul Collins Startup list
[VCatch Premium]
Confirmed=X
Filename=VCatchpre.exe
Description=VCatch antivirus. Considered spyware itself - see here
Source=Paul Collins Startup list
[VCDPlayer]
Confirmed=N
Filename=VCDPlayer.exe
Description=Virtual CD drive emulator. Available via Start -> Programs
Source=Paul Collins Startup list
[vcdplayx]
Confirmed=N
Filename=vcdplayx.exe
Description=CD emulation part of GameDrive & VirtualDrive from Farstone. Not required as starting these programs load this automatically
Source=Paul Collins Startup list
[VCDTower]
Confirmed=U
Filename=VCDTower.exe
Description=Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
Source=Paul Collins Startup list
[VCDWATCH]
Confirmed=?
Filename=VCDWATCH.EXE
Description=Confirmed as Voyetra CD Watcher as it was found in a Compaq/Voyetra/AS2 directory but what does it do?
Source=Paul Collins Startup list
[VCSPlayer]
Confirmed=N
Filename=vcsplay.exe
Description=Virtual CD drive emulator. Available via Start -> Programs
Source=Paul Collins Startup list
[VDI Manager (HP)]
Confirmed=?
Filename=HPO0VDX05.exe
Description=HP (Hewlett-Packard) related. Now - what does it do?
Source=Paul Collins Startup list
[vdtask]
Confirmed=N
Filename=vdtask.exe
Description=Program part of GameDrive & VirtualDrive from Farstone. Not required as starting these programs load this automatically
Source=Paul Collins Startup list
[Vegas Palms - Launcher]
Confirmed=N
Filename=Launcher.exe
Description=Vegas Palms on-line cassino
Source=Paul Collins Startup list
[Verizon Control Pad]
Confirmed=N
Filename=cpad.exe
Description=Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience
Source=Paul Collins Startup list
[Verizon Online Support Center]
Confirmed=U
Filename=matcli.exe
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Verizon Online Support Center is required to run with the Help and Support program. If you uncheck Verizon Online Support Center and and then run help and Support it will add another Verizon Online Support Center in the startup menu. If you remove the Verizon Online Support Center in the add/remove program some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[vern16.dll]
Confirmed=X
Filename=regsvr32.exe [path] vernn16.dll
Description=DailyWinner adware
Source=Paul Collins Startup list
[versato]
Confirmed=U
Filename=versato.exe
Description="Hot" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards
Source=Paul Collins Startup list
[Version]
Confirmed=X
Filename=Version.exe
Description=JRAUN adware variant
Source=Paul Collins Startup list
[Version]
Confirmed=X
Filename=manage.exe
Description=JRAUN adware variant
Source=Paul Collins Startup list
[version]
Confirmed=X
Filename=adl_dh.exe
Description=DealHelper adware related
Source=Paul Collins Startup list
[Vet Alert]
Confirmed=Y
Filename=vetmsg9x.exe
Description=Computer Associates "InnoculateIT" and Vet Anti-Virus virus software
Source=Paul Collins Startup list
[Vet Start Up]
Confirmed=Y
Filename=vet98.exe
Description=Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options
Source=Paul Collins Startup list
[Vet Start Up]
Confirmed=Y
Filename=vet32.exe
Description=Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options
Source=Paul Collins Startup list
[VetTray]
Confirmed=U
Filename=vettray.exe
Description=Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. System Tray quicklaunch access, not really necessary but only occupies 36k resources
Source=Paul Collins Startup list
[VFW Encoder/Decoder Settings]
Confirmed=X
Filename=RUNDLL32.exe MSSIGN30.DLL ondll_reg
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[VGAUtil]
Confirmed=U
Filename=G-VGA.exe
Description=Gigabyte VGA Utility - access card options (application needs to be run at startup, but is not system critical)
Source=Paul Collins Startup list
[vid32cntl]
Confirmed=X
Filename=vid32cntl.Exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[vidcntl]
Confirmed=X
Filename=vidcntl.Exe
Description=Added by the CRYPTER.A TROJAN!
Source=Paul Collins Startup list
[Vidcompat]
Confirmed=X
Filename=Vidcompat.exe
Description=Added by the GEMA TROJAN!
Source=Paul Collins Startup list
[Video]
Confirmed=X
Filename=explored.exe
Description=Added by the GAOBOT.RF WORM!
Source=Paul Collins Startup list
[Video]
Confirmed=X
Filename=winamp32.exe
Description=Added by the AGOBOT-NG WORM!
Source=Paul Collins Startup list
[Video Lan Player]
Confirmed=X
Filename=VideoLanPlayer.exe
Description=Added by the RBOT-MY WORM!
Source=Paul Collins Startup list
[Video Manager]
Confirmed=X
Filename=videomgr.exe
Description=Added by the PANDEM.C WORM!
Source=Paul Collins Startup list
[Video Multimedia Driver]
Confirmed=X
Filename=ndrives32.exe
Description=Added by the RBOT-DK WORM!
Source=Paul Collins Startup list
[Video Proces]
Confirmed=X
Filename=winaps.exe
Description=Added by the AGOBOT.HD WORM!
Source=Paul Collins Startup list
[Video Process]
Confirmed=X
Filename=sysconf.exe
Description=Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!
Source=Paul Collins Startup list
[Video Process]
Confirmed=X
Filename=MS32x16.exe
Description=Added by the RBOT.RH WORM!
Source=Paul Collins Startup list
[Video Process]
Confirmed=X
Filename=netsvcs.exe
Description=Added by the AGOBOT.LH WORM!
Source=Paul Collins Startup list
[Video Process]
Confirmed=X
Filename=MSlti64.exe
Description=Added by the AGOBOT.UE WORM!
Source=Paul Collins Startup list
[Video Process]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-LM WORM!
Source=Paul Collins Startup list
[Video Services]
Confirmed=X
Filename=explore.exe
Description=Added by the GAOBOT.GL WORM!
Source=Paul Collins Startup list
[Video Services]
Confirmed=X
Filename=videol_32.exe
Description=Added by the AGOBOT-DM WORM!
Source=Paul Collins Startup list
[Video Services]
Confirmed=X
Filename=sys32.exe
Description=Added by the AGOBOT.PS WORM!
Source=Paul Collins Startup list
[Videocntl]
Confirmed=X
Filename=Videocntl.exe
Description=Added by a variant of the GEMA.D TROJAN!
Source=Paul Collins Startup list
[VideoDriver]
Confirmed=X
Filename=[filename]
Description=Added by the GSPOT20.A TROJAN!
Source=Paul Collins Startup list
[VideoDriver]
Confirmed=X
Filename=videodrv.exe
Description=Added by the MIMAIL.A WORM!
Source=Paul Collins Startup list
[VideoDriver]
Confirmed=X
Filename=gspotbot.exe
Description=Added by the SPIGOT.C TROJAN!
Source=Paul Collins Startup list
[Videool32]
Confirmed=X
Filename=VIDEOL32.EXE
Description=Added by the AGOBOT.EC WORM!
Source=Paul Collins Startup list
[VidSvr]
Confirmed=N
Filename=vidsvr.exe
Description=MS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
Source=Paul Collins Startup list
[vietato.exe]
Confirmed=X
Filename=vietato.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[ViewMgr]
Confirmed=N
Filename=ViewMgr.exe
Description=Viewpoint Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc). Can be run manually via Start -> Settings -> Control Panel by enabling auto-updates temporarily, re-booting and then disabling again
Source=Paul Collins Startup list
[Vinny]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[Virt.exe]
Confirmed=X
Filename=Virt.exe
Description=Added by the REMADM-C TROJAN!
Source=Paul Collins Startup list
[VirtuaGirl]
Confirmed=U
Filename=Vg.exe
Description=VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request...
Source=Paul Collins Startup list
[VirtuaGirl2]
Confirmed=U
Filename=VirtuaGirl2
Description=VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request...
Source=Paul Collins Startup list
[virtual]
Confirmed=X
Filename=winit.exe
Description=Added by the MUGLY.A or MUGLY.B WORMS!
Source=Paul Collins Startup list
[virtual]
Confirmed=X
Filename=winprotect.exe
Description=Added by the MUGLY.C WORM!
Source=Paul Collins Startup list
[Virtual Access Scheduler]
Confirmed=U
Filename=VASCHD32.EXE
Description=The scheduler for mail and usenet tool
Source=Paul Collins Startup list
[Virtual Bouncer]
Confirmed=X
Filename=VirtualBouncer.exe
Description=Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here
Source=Paul Collins Startup list
[VirtualCloneDrive]
Confirmed=N
Filename=VCDDaemon.exe
Description=Virtual Clone Drive, part of CloneCD CD/DVD copying sofware. Discontinued
Source=Paul Collins Startup list
[VirtualDrive]
Confirmed=N
Filename=VDTask.exe
Description=VirtualDrive from Farstone - virtual CD drive emulator. Available via Start -> Programs
Source=Paul Collins Startup list
[VirtuaReminder]
Confirmed=U
Filename=VirtuaReminder.exe
Description=VirtuaReminder is a tool allowing the user to create reminders for such things as important appointments, birthdays, etc
Source=Paul Collins Startup list
[Virus Scan]
Confirmed=X
Filename=virscana.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[VirusCheckII]
Confirmed=X
Filename=AVIRCHK.EXE
Description=Added by the DASMIN TROJAN!
Source=Paul Collins Startup list
[VirusScan Online]
Confirmed=Y
Filename=mcvsshld.exe
Description=McAfee VirusScan On-line. See also the McAgentExe entry
Source=Paul Collins Startup list
[VirusScanMSC]
Confirmed=?
Filename=VsStat.exe
Description=Part of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe), McAfee SecurityCenter integration or something else? Is it required?
Source=Paul Collins Startup list
[Virus_Scanner]
Confirmed=X
Filename=Virus_Cleaner.exe
Description=Added by the PANOL WORM!
Source=Paul Collins Startup list
[visionGS]
Confirmed=N
Filename=VISIONGS.EXE
Description=visionGS webcam software
Source=Paul Collins Startup list
[Vistascan]
Confirmed=N
Filename=vistascan.exe
Description=Included in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users, you'll see a scanner icon in the Windows Tray of the Taskbar. Click this icon and a menu opens
Source=Paul Collins Startup list
[VividGalut]
Confirmed=X
Filename=VividGalut.exe
Description=Adult content related web downloader
Source=Paul Collins Startup list
[VMDFW]
Confirmed=Y
Filename=vmdfw.exe
Description=VirusMD Personal Firewall
Source=Paul Collins Startup list
[Vmmon32]
Confirmed=X
Filename=vmmon32.exe
Description=Browser hijacker
Source=Paul Collins Startup list
[vmsnGraber]
Confirmed=X
Filename=VMSNGRABER.EXE
Description=Added by the ENVID.B WORM!
Source=Paul Collins Startup list
[vmss]
Confirmed=X
Filename=vmss.exe
Description=Delfin Media Viewer or "Promulgate" adware variant
Source=Paul Collins Startup list
[VnCplUpdate]
Confirmed=X
Filename=msdm.exe
Description=Masssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in this advisory
Source=Paul Collins Startup list
[VOBID]
Confirmed=U
Filename=InstantDrive.exe
Description=Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software
Source=Paul Collins Startup list
[VOBRegCheck]
Confirmed=Y
Filename=VOBRegCheck.exe
Description=Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled
Source=Paul Collins Startup list
[Vonage]
Confirmed=U
Filename=click2call.exe
Description=Vonage Voice over IP Internet phone service
Source=Paul Collins Startup list
[VoodooBanshee]
Confirmed=U
Filename=rundll32.exe 3DBBps.dll, BansheeLoadSettings
Description=Loads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not
Source=Paul Collins Startup list
[voowsmcr]
Confirmed=?
Filename=huhdir.exe
Description=??
Source=Paul Collins Startup list
[Vortex Tray]
Confirmed=N
Filename=asp4setp.exe
Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[VortexTray]
Confirmed=N
Filename=au30setp.exe
Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[VortexTray]
Confirmed=N
Filename=asp4tray.exe
Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[VortexTray]
Confirmed=N
Filename=asp4setp.exe
Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[VoyetraTray]
Confirmed=N
Filename=vtray.exe
Description=This provides an abbreviated Control Group for the Turtle Beach Montego II sound functions/associated with AudioStation 3 and 32
Source=Paul Collins Startup list
[Vpop3 Mail Server]
Confirmed=U
Filename=vpop3.exe
Description=Mail server from Paul Smith Computer Services. Runs in system tray to collect mail. Can be run from a shortcut and if it isn't running then it won't get your email!
Source=Paul Collins Startup list
[vptray]
Confirmed=U
Filename=vptray.exe
Description=System Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here
Source=Paul Collins Startup list
[Vrmon]
Confirmed=Y
Filename=vrmonnt.exe
Description=HAURI Anti-Virus
Source=Paul Collins Startup list
[VrSchedule]
Confirmed=Y
Filename=Vrres.exe
Description=HAURI Anti-Virus
Source=Paul Collins Startup list
[VS.VSN]
Confirmed=Y
Filename=
Description=Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added
Source=Paul Collins Startup list
[vscanner]
Confirmed=X
Filename=spooll32.exe
Description=Added by the OPTIXPRO.10 TROJAN!
Source=Paul Collins Startup list
[VsEcomrEXE]
Confirmed=N
Filename=VSECOMR.EXE
Description=From McAfee VirusScan up to version 4.x. This executable is responsible for the periodic "update" prompts
Source=Paul Collins Startup list
[Vshwin32EXE]
Confirmed=Y
Filename=VSHWIN32.EXE
Description=From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
Source=Paul Collins Startup list
[VSN]
Confirmed=N
Filename=VSN.exe
Description=Software to share photographs across the internet
Source=Paul Collins Startup list
[VSOCheckTask]
Confirmed=Y
Filename=MCMNHDLR.EXE
Description=Part of McAfee's SecurityCenter and Virusscan Online. Must be enabled for scanning to work
Source=Paul Collins Startup list
[vspdfprsrv.exe]
Confirmed=N
Filename=vspdfprsrv.exe
Description=Visage PDF Printer
Source=Paul Collins Startup list
[VsStatEXE]
Confirmed=Y
Filename=VSSTAT.EXE
Description=From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
Source=Paul Collins Startup list
[vTPass]
Confirmed=N
Filename=vtpassld.exe
Description=Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs, create your own shortcut for the "vtpass.exe" file
Source=Paul Collins Startup list
[VTPreset]
Confirmed=U
Filename=VTPreset.exe
Description=Savage Pro S3 graphics software
Source=Paul Collins Startup list
[VTTimer]
Confirmed=U
Filename=VTTimer.exe
Description=Driver file for the on-board VIA/S3G KM400/KN400 graphics which enables TV in/out communication
Source=Paul Collins Startup list
[vTunerStartUp]
Confirmed=N
Filename=vTuner.exe
Description=vTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet"
Source=Paul Collins Startup list
[VVSN]
Confirmed=X
Filename=VVSN.exe
Description=WhenU adware
Source=Paul Collins Startup list
[w32]
Confirmed=X
Filename=w32.exe
Description=Added by the SOKEVEN TROJAN!
Source=Paul Collins Startup list
[W32.Scran]
Confirmed=X
Filename=Scran.exe
Description=Added by the NARCS WORM!
Source=Paul Collins Startup list
[w32alanis]
Confirmed=X
Filename=mope.scr
Description=Added by the SINALA WORM!
Source=Paul Collins Startup list
[W32Load]
Confirmed=X
Filename=[random filename].scr
Description=Added by the CASPID WORM!
Source=Paul Collins Startup list
[w32sup]
Confirmed=X
Filename=w32sup.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[W32Tc]
Confirmed=X
Filename=WTC32.scr
Description=Added by the VOTE.D or VOTE.K WORMS!
Source=Paul Collins Startup list
[W3KNetwork]
Confirmed=X
Filename=rundll32.exe w3knet.dll, dllinitrun
Description=Advertising spyware. Check here for more info on this particular one
Source=Paul Collins Startup list
[W75P2PSERVER]
Confirmed=Y
Filename=W75P2PS.EXE
Description=Printer utility which is required in order to make the printer work correctly
Source=Paul Collins Startup list
[W815DM]
Confirmed=?
Filename=W815DM.exe
Description=??
Source=Paul Collins Startup list
[Wanadoo Messenger.exe]
Confirmed=N
Filename=Wanadoo Messenger.exe
Description=Wanadoo ISP instant messenger client
Source=Paul Collins Startup list
[WanMPSvc]
Confirmed=Y
Filename=WanMPSvc.exe
Description=An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help
Source=Paul Collins Startup list
[WAPI]
Confirmed=X
Filename=wts**.exe [* = random char]
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[war-ftpd.exe]
Confirmed=N
Filename=WAR-FTPD.EXE
Description=War FTP Daemon from JGAA's Internet - FTP client
Source=Paul Collins Startup list
[Wardo]
Confirmed=X
Filename=syslaunch.exe
Description=Added by the ADLCICKER.G TROJAN!
Source=Paul Collins Startup list
[WareOut]
Confirmed=X
Filename=WareOut.exe
Description=Malware masquerading as a spyware and dialer remover, see here
Source=Paul Collins Startup list
[warez]
Confirmed=N
Filename=warez.exe
Description=Warez P2P client
Source=Paul Collins Startup list
[Warner]
Confirmed=U
Filename=warner.exe
Description=Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
Source=Paul Collins Startup list
[Warnet]
Confirmed=U
Filename=warnet.exe
Description=Warnet - system cleanup software
Source=Paul Collins Startup list
[Warning: do not remove it!]
Confirmed=U
Filename=fpplock.exe
Description=Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data"
Source=Paul Collins Startup list
[WARSVR]
Confirmed=N
Filename=war-ftpd.exe
Description="War FTP Daemon - the original free FTP server for windows"
Source=Paul Collins Startup list
[WashAndGo - Cleanup of old Backupfiles]
Confirmed=U
Filename=checker.exe
Description=WashAndGo - temp file cleaner
Source=Paul Collins Startup list
[Washer]
Confirmed=U
Filename=washer.exe
Description=Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Source=Paul Collins Startup list
[Washerie.exe]
Confirmed=N
Filename=washerie.exe
Description=Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
Source=Paul Collins Startup list
[washindex]
Confirmed=U
Filename=washidx.exe
Description=Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Source=Paul Collins Startup list
[Wast]
Confirmed=X
Filename=wast.exe
Description=Grokster ads updater
Source=Paul Collins Startup list
[Watch]
Confirmed=N
Filename=watch.exe
Description=Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
Source=Paul Collins Startup list
[Watch]
Confirmed=?
Filename=1200UBWATCH.EXE
Description=??
Source=Paul Collins Startup list
[Watch Dog Program]
Confirmed=N
Filename=watchdog.exe
Description=For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
Source=Paul Collins Startup list
[Watchdog]
Confirmed=N
Filename=Watchdog.exe
Description=Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
Source=Paul Collins Startup list
[WatchDog]
Confirmed=?
Filename=watchdog.exe
Description=Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files
Source=Paul Collins Startup list
[WaveTop Launcher]
Confirmed=N
Filename=WaveTop.exe
Description=WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
Source=Paul Collins Startup list
[WaveTop Receiver 1]
Confirmed=N
Filename=N/A
Description=WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
Source=Paul Collins Startup list
[WaveTop Receiver 2]
Confirmed=N
Filename=N/A
Description=WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
Source=Paul Collins Startup list
[WaveTop Upload Manager]
Confirmed=N
Filename=N/A
Description=WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
Source=Paul Collins Startup list
[Wbiff]
Confirmed=N
Filename=Wbiff.exe
Description=Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
Source=Paul Collins Startup list
[Wbutton]
Confirmed=?
Filename=Wbutton.exe
Description=Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required?
Source=Paul Collins Startup list
[WCESCOMM]
Confirmed=N
Filename=WCESCOMM.EXE
Description=Active sync for use with Windows CE based palm PC
Source=Paul Collins Startup list
[wcmdmgr]
Confirmed=U
Filename=wcmdmgrl.exe
Description=Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[wcmdmgr.exe]
Confirmed=N
Filename=wcmdmgr.exe
Description=Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[wcmdmgrl]
Confirmed=U
Filename=wcmdmgrl.exe
Description=Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[WCOLOREAL]
Confirmed=U
Filename=coloreal.exe
Description=Makes colours sharper and brighter, but will only work with coloreal capable monitors
Source=Paul Collins Startup list
[WCPC]
Confirmed=?
Filename=wintsvcc.exe
Description=??
Source=Paul Collins Startup list
[WCPI]
Confirmed=X
Filename=wintsvit.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[WCPS]
Confirmed=X
Filename=Wint**.exe [* = random char]
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[WCPT]
Confirmed=X
Filename=wintsvtr.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[WD Button Manager]
Confirmed=U
Filename=WDBtnMgr.exe
Description=Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
Source=Paul Collins Startup list
[WDInfo]
Confirmed=X
Filename=wdinfo.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[wdskctl]
Confirmed=X
Filename=wdskctl.exe
Description=IEPlugin spyware
Source=Paul Collins Startup list
[wdwctrl]
Confirmed=X
Filename=wdwctrl.exe
Description=Added by the DLUCA.E TROJAN!
Source=Paul Collins Startup list
[WEATHER]
Confirmed=N
Filename=WEATHER.EXE
Description=Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
Source=Paul Collins Startup list
[WeatherCast]
Confirmed=N
Filename=Weather.exe
Description=Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
Source=Paul Collins Startup list
[WeatherOnTray]
Confirmed=X
Filename=WeatherOnTray.exe
Description=Hotbar's Weather Forecast tool for your desktop - adware
Source=Paul Collins Startup list
[WeatherWatcher]
Confirmed=N
Filename=ww.exe
Description=WeatherWatcher - weather reporting in the System Tray
Source=Paul Collins Startup list
[web]
Confirmed=X
Filename=******.exe [* = random char]
Description=Added by a variant of the EASTO.A TROJAN!
Source=Paul Collins Startup list
[Web Search]
Confirmed=?
Filename=??
Description=??
Source=Paul Collins Startup list
[web3trap]
Confirmed=Y
Filename=web3trap.exe
Description=PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc
Source=Paul Collins Startup list
[webalize]
Confirmed=X
Filename=webalize.exe
Description=Searchcentrix hijacker
Source=Paul Collins Startup list
[WebArmyKnife]
Confirmed=N
Filename=WAK.exe
Description=Web Army Knife - a suite of web site developer's tools
Source=Paul Collins Startup list
[webassist]
Confirmed=X
Filename=webassist.exe
Description=Adware popup generator
Source=Paul Collins Startup list
[Webcam Go Sti Service Application]
Confirmed=?
Filename=wbcgosvc.exe
Description=Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required?
Source=Paul Collins Startup list
[WebcamRT.exe]
Confirmed=N
Filename=WEBCAMRT.exe
Description=For Logitech Web Cams. Not required - camera works fine without it
Source=Paul Collins Startup list
[Webcelerator]
Confirmed=X
Filename=webcel.exe
Description=Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here
Source=Paul Collins Startup list
[WebCheck]
Confirmed=X
Filename=WebCheck.pif
Description=Added by the CONE.C or CONE.F WORMS!
Source=Paul Collins Startup list
[WebCpr0]
Confirmed=X
Filename=WebCpr0.exe
Description=Web_CPR/TopMoxie adware
Source=Paul Collins Startup list
[Webdav.exe]
Confirmed=X
Filename=webdav.exe
Description=IRC DDoS bot which gives the hacker full control over your system
Source=Paul Collins Startup list
[WebHancer Agent]
Confirmed=X
Filename=whagent.exe
Description=System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
Source=Paul Collins Startup list
[webHancer Survey Companion]
Confirmed=X
Filename=whSurvey.exe
Description=WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
Source=Paul Collins Startup list
[WebInstall]
Confirmed=X
Filename=WebInstall.exe
Description=ClipGenie adware downloader
Source=Paul Collins Startup list
[WebInstall2]
Confirmed=X
Filename=WebInstall.exe
Description=ClipGenie adware downloader
Source=Paul Collins Startup list
[WebKey]
Confirmed=N
Filename=WebKey.exe
Description=WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
Source=Paul Collins Startup list
[WebOutfitterTray]
Confirmed=N
Filename=sttray.exe
Description=Intel WebOutfitter service System Tray icon
Source=Paul Collins Startup list
[Webposition Gold 2]
Confirmed=N
Filename=wpsche~1.exe
Description=Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
Source=Paul Collins Startup list
[WebRebates0]
Confirmed=X
Filename=WebRebates0.exe
Description=WebRebates adware
Source=Paul Collins Startup list
[websaverlive]
Confirmed=U
Filename=websaverlive.exe
Description=WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
Source=Paul Collins Startup list
[WebSavingsfromEbates]
Confirmed=X
Filename=WebSavingsfromEbatesrun.exe
Description=Web Savings From Ebates Software, a shopping tool that opens pop-up windows
Source=Paul Collins Startup list
[WebSavingsFromEbates0]
Confirmed=X
Filename=WebSavingsFromEbates0.exe
Description=Web Savings From Ebates Software, a shopping tool that opens pop-up windows
Source=Paul Collins Startup list
[WebScan]
Confirmed=X
Filename=DEFSCANGUI.EXE
Description=Stop-Sign from eAccelerration. Detects spyware, malware, viruses and keyloggers and stops popups. Spyware in itself - see their privacy statement here
Source=Paul Collins Startup list
[webscan]
Confirmed=N
Filename=stopsignav.exe
Description=eAcceleration Stop-Sign related - not recommended, see note
Source=Paul Collins Startup list
[WebScanX]
Confirmed=Y
Filename=WebScanX.exe
Description=From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
Source=Paul Collins Startup list
[websearch]
Confirmed=X
Filename=wjview ...websearch.exe
Description="Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
Source=Paul Collins Startup list
[WebSecureAlert]
Confirmed=X
Filename=WebSecureAlert.exe
Description=WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior
Source=Paul Collins Startup list
[WebServer]
Confirmed=?
Filename=VBI_SE~1.EXE
Description=Related to a Pinnacle sound card. What does it do and is it needed?
Source=Paul Collins Startup list
[Webshots]
Confirmed=N
Filename=Webshots Tray.exe
Description=Screensaver program that automatically downloads from the webshots web site
Source=Paul Collins Startup list
[Webshots]
Confirmed=N
Filename=websho~1.exe
Description=Screensaver program that automatically downloads from the webshots web site
Source=Paul Collins Startup list
[WebSpecials]
Confirmed=X
Filename=rundll32 [path] webspec.dll
Description=WebSpecials spyware
Source=Paul Collins Startup list
[Websx]
Confirmed=X
Filename=Int*****.exe
Description=Adult content dialler - where ***** are random
Source=Paul Collins Startup list
[Webtrap]
Confirmed=Y
Filename=webtrap.exe
Description=Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
Source=Paul Collins Startup list
[WebTrapNT.exe]
Confirmed=Y
Filename=WebTrapNT.exe
Description=Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
Source=Paul Collins Startup list
[WebWasher]
Confirmed=U
Filename=wwasher.exe
Description=Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
Source=Paul Collins Startup list
[Welcome]
Confirmed=N
Filename=Welcome.exe
Description=Launches the Welcome to Windows tutorial on boot up
Source=Paul Collins Startup list
[WEPstat]
Confirmed=?
Filename=Wepstat.exe
Description=Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
Source=Paul Collins Startup list
[wersds]
Confirmed=X
Filename=doriot.exe
Description=Added by the JECT.C TROJAN!
Source=Paul Collins Startup list
[WetSock]
Confirmed=N
Filename=wetsock.exe
Description=RoboMagic Wetsock - weather reporting in the System Tray
Source=Paul Collins Startup list
[WFGStartup]
Confirmed=N
Filename=WFGStartup.exe
Description=World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
Source=Paul Collins Startup list
[wfips]
Confirmed=U
Filename=iphider.exe
Description=ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here
Source=Paul Collins Startup list
[WFXCTL32.EXE]
Confirmed=N
Filename=WFXCTL32.EXE
Description=From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Source=Paul Collins Startup list
[wfxsnt40]
Confirmed=Y
Filename=wfxsnt40.exe
Description=WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
Source=Paul Collins Startup list
[WFXSwtch]
Confirmed=?
Filename=WFXSWTCH.exe
Description=Related to WinFax. What does it do and is it required?
Source=Paul Collins Startup list
[WG511WLU]
Confirmed=Y
Filename=WG511WLU.exe
Description=Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
Source=Paul Collins Startup list
[WGWLocalManager]
Confirmed=U
Filename=WGWLocalManager.exe
Description=Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system
Source=Paul Collins Startup list
[whagent]
Confirmed=X
Filename=whagent.exe
Description=System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
Source=Paul Collins Startup list
[WheelMouse]
Confirmed=U
Filename=4DMAIN.EXE
Description=Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide
Source=Paul Collins Startup list
[WheelMouse]
Confirmed=U
Filename=AMOUMAIN.EXE
Description=A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[WhenUSave]
Confirmed=X
Filename=Save.exe
Description=Rebranded version of SaveNow advertising spyware
Source=Paul Collins Startup list
[WhenUSearch]
Confirmed=X
Filename=Search.exe
Description=WhenUSearch adware
Source=Paul Collins Startup list
[Whvlxd]
Confirmed=X
Filename=Whvlxd.exe
Description=Added by the W32.LXD.MIRC TROJAN!
Source=Paul Collins Startup list
[WIAWizardMenu]
Confirmed=N
Filename=RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu
Description=Still Image Class Installer - installed with a webcam
Source=Paul Collins Startup list
[WildTangent CDA]
Confirmed=?
Filename=RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain
Description=Part of the WildTangent on-line games system. What does it do and is it required?
Source=Paul Collins Startup list
[WildTangent Web Driver updater]
Confirmed=U
Filename=wcmdmgrl.exe
Description=Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[Wildwire Monitor]
Confirmed=N
Filename=WWMon.exe
Description=This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
Source=Paul Collins Startup list
[Willow Road]
Confirmed=N
Filename=WillowRoad.exe
Description=Willow Road Screen Saver
Source=Paul Collins Startup list
[win]
Confirmed=X
Filename=regedit -s ..win.dll
Description=Added by the SEEKER.K TROJAN!
Source=Paul Collins Startup list
[win]
Confirmed=X
Filename=xwinxrpc32.exe
Description=Added by the AGOBOT-MV WORM!
Source=Paul Collins Startup list
[win]
Confirmed=X
Filename=xwinxrpc.exe
Description=Added by the AGOBOT-MV WORM!
Source=Paul Collins Startup list
[Win Chimes]
Confirmed=U
Filename=winchi~1.exe
Description=WinChimes - enhancement software for the system clock that runs in the system tray
Source=Paul Collins Startup list
[Win Comm]
Confirmed=X
Filename=WinComm.exe
Description=WebRebates related adware
Source=Paul Collins Startup list
[Win Command]
Confirmed=X
Filename=command32.exe
Description=Added by the AGOBOT.XQ WORM!
Source=Paul Collins Startup list
[Win Command]
Confirmed=X
Filename=command32.exe
Description=Added by the AGOBOT.XQ WORM!
Source=Paul Collins Startup list
[WIN HOST PROCESS]
Confirmed=X
Filename=WIN HOST PROCESS.EXE
Description=Added by the KEYLOGGER.CLONE TROJAN!
Source=Paul Collins Startup list
[Win l5oahder]
Confirmed=X
Filename=winampa.exe
Description=Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder
Source=Paul Collins Startup list
[win name]
Confirmed=?
Filename=stat.exe
Description=??
Source=Paul Collins Startup list
[Win Patch]
Confirmed=X
Filename=ntldr.exe
Description=Added by the SDBOT-GS WORM!
Source=Paul Collins Startup list
[Win Server]
Confirmed=X
Filename=winserv.exe
Description=Added by the IMISERV.A TROJAN!
Source=Paul Collins Startup list
[Win Server Updt]
Confirmed=X
Filename=wupdt.exe
Description=Added by the IMISERV.A TROJAN!
Source=Paul Collins Startup list
[win update]
Confirmed=X
Filename=wupda32.exe
Description=Added by the SDBOT.J WORM!
Source=Paul Collins Startup list
[WIN USB 2.0]
Confirmed=X
Filename=usbsystem.exe
Description=Added by an unidentified WORM of TROJAN!
Source=Paul Collins Startup list
[Win USB 2.0 USB Driver]
Confirmed=X
Filename=HPPrint.exe
Description=Added by the SPYBOT.DNB WORM!
Source=Paul Collins Startup list
[WIN-BUGSFIX]
Confirmed=X
Filename=WIN-BUGSFIX.EXE
Description=Added by the LOVELETTER (I LOVE YOU) VIRUS!
Source=Paul Collins Startup list
[Win2Drv]
Confirmed=X
Filename=[worm filename]
Description=Added by the WINTOO WORM!
Source=Paul Collins Startup list
[WIN32]
Confirmed=X
Filename=WIN32.EXE
Description=Added by the RATEGA TROJAN!
Source=Paul Collins Startup list
[win32]
Confirmed=X
Filename=Shakira_1997_Part_1_.Mpeg_.scr
Description=Added by the MYLIFE.N WORM!
Source=Paul Collins Startup list
[win32]
Confirmed=X
Filename=Setup_32.exe
Description=Added by the EVILBOT.B TROJAN!
Source=Paul Collins Startup list
[Win32]
Confirmed=X
Filename=Win32.exe
Description=Added by the ISRAZ.A WORM!
Source=Paul Collins Startup list
[win32]
Confirmed=X
Filename=winsrv32.exe
Description=Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
Source=Paul Collins Startup list
[win32]
Confirmed=X
Filename=WinSetup.exe
Description=Added by the EVILBOT.B TROJAN!
Source=Paul Collins Startup list
[Win32 Configuration]
Confirmed=X
Filename=videosd32.exe
Description=Added by the SDBOT.TT WORM!
Source=Paul Collins Startup list
[Win32 Configuration]
Confirmed=X
Filename=dllhelp.exe
Description=Added by the SDBOT.UL WORM!
Source=Paul Collins Startup list
[Win32 Device Loader]
Confirmed=X
Filename=Win32ldr.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Win32 DRK Driver]
Confirmed=X
Filename=wdrk32.exe
Description=Added by the WOOTBOT.CY WORM!
Source=Paul Collins Startup list
[Win32 exe file]
Confirmed=X
Filename=winstr32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Win32 Explorer]
Confirmed=X
Filename=Explorer32.exe
Description=StartPa-MN homepage hijacker
Source=Paul Collins Startup list
[Win32 FRT Driver]
Confirmed=X
Filename=msfr32.exe
Description=Added by a variant of the FORBOT WORM!
Source=Paul Collins Startup list
[Win32 Kernel core component]
Confirmed=X
Filename=Kernel32.pif
Description=Added by the MOKS VIRUS!
Source=Paul Collins Startup list
[Win32 Ms Auto Updater]
Confirmed=X
Filename=AutomsUPD.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Win32 Network Driver]
Confirmed=X
Filename=crss.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Win32 NVIDIA Driver]
Confirmed=X
Filename=MSPMSPSU.EXE
Description=Added by a variant of the WOOTBOT.Y WORM!
Source=Paul Collins Startup list
[win32 regedit]
Confirmed=X
Filename=msn32.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Win32 Rundll Loader]
Confirmed=X
Filename=Rundll32.exe
Description=Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:\Windows directory. The version created by this virus is saved in the C:\Windows\System directory
Source=Paul Collins Startup list
[Win32 Services1]
Confirmed=X
Filename=wuamngr1.exe
Description=Added by the SDBOT-PV WORM!
Source=Paul Collins Startup list
[Win32 Src Service]
Confirmed=X
Filename=win32src.exe
Description=Added by the RBOT-SX WORM!
Source=Paul Collins Startup list
[Win32 SSL Driver]
Confirmed=X
Filename=winssv.exe
Description=Added by the FORBOT-BH WORM!
Source=Paul Collins Startup list
[Win32 System Spool]
Confirmed=X
Filename=spoolsvc.exe
Description=Added by the SDBOT.UK WORM!
Source=Paul Collins Startup list
[Win32 USB Driver]
Confirmed=X
Filename=winxpinit.exe
Description=Added by the SDBOT.AA TROJAN!
Source=Paul Collins Startup list
[Win32 USB Driver]
Confirmed=X
Filename=mvsecn.exe
Description=Added by the FORBOT-BK WORM!
Source=Paul Collins Startup list
[Win32 Usb Driver]
Confirmed=X
Filename=svhosint32.exe
Description=Added by the FORBOT-BE or FORBOT-J WORMS!
Source=Paul Collins Startup list
[Win32 Usb Driver]
Confirmed=X
Filename=usb32.exe
Description=Added by the SDBOT-OV WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=win32usb.exe
Description=Added by the SPYBOT.DHV WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=smsc.exe
Description=Added by the SDBOT.FO WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=svchosting.exe
Description=Added by the FORBOT.J or SDBOT.HU WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=sys32.exe
Description=Added by the WOOTBOT.X WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=sys32snd.exe
Description=Added by the FORBOT-AN WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=wind32.exe
Description=Added by the FORBOT-AH WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=winupdate.exe
Description=Added by the AGOBOT.YE WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=updatemgr.exe
Description=Added by a variant of the FORBOT WORM!
Source=Paul Collins Startup list
[Win32 USB2 Driver]
Confirmed=X
Filename=winsnd32.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Win32 USB2.0 Driver]
Confirmed=X
Filename=386.exe
Description=Added by the IRCBOT.D WORM!
Source=Paul Collins Startup list
[Win32 USB2.0 Driver]
Confirmed=X
Filename=rundll16.exe
Description=Added by the WOOTBOT.H WORM!
Source=Paul Collins Startup list
[Win32 USB2.0 Driver]
Confirmed=X
Filename=w32usb2.exe
Description=Added by the SPYBOT.DN WORM!
Source=Paul Collins Startup list
[Win32 USB2.0 Driver]
Confirmed=X
Filename=service.exe
Description=Added by the SDBOT-QF WORM!
Source=Paul Collins Startup list
[Win32 Wmls Driver]
Confirmed=X
Filename=winitr32.exe
Description=Added by the WOOTBOT.B WORM!
Source=Paul Collins Startup list
[win32.exe]
Confirmed=X
Filename=win32.exe
Description=Added by the STARTPAGE TROJAN!
Source=Paul Collins Startup list
[Win32BaseServiceMOD]
Confirmed=X
Filename=Wintask.exe
Description=Added by the NAVIDAD WORM!
Source=Paul Collins Startup list
[win32clf]
Confirmed=X
Filename=win32clf.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Win32DLL]
Confirmed=X
Filename=Win32DLL.vbs
Description=Added by the LOVELETTER (I LOVE YOU) VIRUS!
Source=Paul Collins Startup list
[Win32dll]
Confirmed=X
Filename=Win32dll.exe
Description=Added by the BANPAES TROJAN!
Source=Paul Collins Startup list
[Win32G]
Confirmed=X
Filename=Kernel32.com
Description=Added by the ESTRELLA TROJAN!
Source=Paul Collins Startup list
[Win32G]
Confirmed=X
Filename=Scandisk.com
Description=Added by the ESTRELLA TROJAN
Source=Paul Collins Startup list
[win32gb]
Confirmed=X
Filename=win32gb.exe
Description=All-In-One-Telcom (adult content dialler) variant
Source=Paul Collins Startup list
[win32info]
Confirmed=X
Filename=win32info.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[win32ini]
Confirmed=X
Filename=systroy.exe
Description=Added by the IRC.ALADINZ.C TROJAN!
Source=Paul Collins Startup list
[Win32R]
Confirmed=X
Filename=Server.com
Description=Added by the ESTRELLA TROJAN!
Source=Paul Collins Startup list
[WIN32SL]
Confirmed=Y
Filename=Win32sl.exe
Description=Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
Source=Paul Collins Startup list
[WIN32SNDS]
Confirmed=X
Filename=banc.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Win32system]
Confirmed=X
Filename=[random filename]
Description=Added by the DDV.B WORM!
Source=Paul Collins Startup list
[Win32System]
Confirmed=X
Filename=win32s.exe
Description=Added by the MYDOOM.V WORM!
Source=Paul Collins Startup list
[Win32SystemMonitor]
Confirmed=X
Filename=***.exe [* = random char]
Description=Browser hijacker
Source=Paul Collins Startup list
[win32us]
Confirmed=X
Filename=win32us.exe
Description=All-In-One-Telcom (adult content dialler) variant
Source=Paul Collins Startup list
[win32usbd]
Confirmed=X
Filename=ssrs.exe
Description=Added by the RBOT-RA WORM!
Source=Paul Collins Startup list
[win32_i lptt01]
Confirmed=X
Filename=win32_i.exe
Description=Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[win32_i ml097e]
Confirmed=X
Filename=win32_i.exe
Description=Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Source=Paul Collins Startup list
[Win386]
Confirmed=X
Filename=Win386.exe
Description=Added by the GOSUSUB VIRUS!
Source=Paul Collins Startup list
[Win386]
Confirmed=X
Filename=sp32.dll
Description=Homepage hijacker. Not a dll but a regfile in disguise
Source=Paul Collins Startup list
[WIN3S2SNDS]
Confirmed=X
Filename=winabsmod.exe
Description=Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
Source=Paul Collins Startup list
[WIN3S2SNDS]
Confirmed=X
Filename=winiprtx.exe
Description=Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
Source=Paul Collins Startup list
[Win64 Compatibility Check]
Confirmed=X
Filename=load win64.drv
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[WinAC v4]
Confirmed=X
Filename=klsuicbn.exe
Description=Added by the FORBOT-CS WORM!
Source=Paul Collins Startup list
[winactive]
Confirmed=X
Filename=WINACTIVE.EXE
Description=Active variant of LOP.com hijacker - see here
Source=Paul Collins Startup list
[WinActiveJ]
Confirmed=X
Filename=WinActiveJ.exe
Description=Added by the ROTARRAN VIRUS!
Source=Paul Collins Startup list
[Winad Client]
Confirmed=X
Filename=Winad.exe
Description=WinAd adware by eXact Advertising
Source=Paul Collins Startup list
[winadm]
Confirmed=X
Filename=winadm.exe
Description=Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
Source=Paul Collins Startup list
[Winahlp.exe]
Confirmed=X
Filename=Winahlp.exe
Description=Added by a variant of the VAGRNOCKER TROJAN!
Source=Paul Collins Startup list
[winallap]
Confirmed=X
Filename=winallap.exe
Description=Added by the DELF.E TROJAN!
Source=Paul Collins Startup list
[winallapu]
Confirmed=X
Filename=winallapu.exe
Description=Added by the DELF.E TROJAN!
Source=Paul Collins Startup list
[Winamp]
Confirmed=X
Filename=winamp.hta
Description=Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp
Source=Paul Collins Startup list
[Winamp]
Confirmed=X
Filename=winamp.exe
Description=Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe)
Source=Paul Collins Startup list
[Winamp media player]
Confirmed=X
Filename=winapa.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Winampa]
Confirmed=U
Filename=WINAMPa.exe
Description=Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
Source=Paul Collins Startup list
[Winampa]
Confirmed=X
Filename=winampa.exe
Description=Added by the AGOBOT-GS WORM!
Source=Paul Collins Startup list
[Winampa Agent]
Confirmed=X
Filename=WINAMPA.EXE
Description=Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
Source=Paul Collins Startup list
[WinampAgent]
Confirmed=U
Filename=WINAMPa.exe
Description=Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
Source=Paul Collins Startup list
[WinApi]
Confirmed=X
Filename=winapix.exe
Description=Added by a variant of the TIBSER.A downloader TROJAN!
Source=Paul Collins Startup list
[Winapp]
Confirmed=X
Filename=winpup32.exe
Description=Produces popup ads to adult content sites
Source=Paul Collins Startup list
[WinApp32]
Confirmed=X
Filename=msapp.exe
Description=Added by the RSBOT TROJAN!
Source=Paul Collins Startup list
[WinAuth]
Confirmed=X
Filename=winlogon.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process
Source=Paul Collins Startup list
[WinBackup Scheduler]
Confirmed=U
Filename=Wbsched.exe
Description=LIUtilities WinBackup scheduler - backup software
Source=Paul Collins Startup list
[WinBar]
Confirmed=U
Filename=WinBar.exe
Description="WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
Source=Paul Collins Startup list
[winbas12]
Confirmed=X
Filename=winbas12.exe
Description=Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du
Source=Paul Collins Startup list
[Winbed]
Confirmed=X
Filename=winbed.exe
Description=Hijacker
Source=Paul Collins Startup list
[WinCheck]
Confirmed=X
Filename=WinCheck.exe
Description=Added by the PWS-CY TROJAN!
Source=Paul Collins Startup list
[WINCINEMAMGR]
Confirmed=N
Filename=WINCIN~1.EXE
Description=WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[WinCinemaMgr]
Confirmed=N
Filename=WinCinemaMgr.exe
Description=WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[WinCSRSS]
Confirmed=X
Filename=MSGRT32.EXE
Description=Added by the REWINDO-A TROJAN!
Source=Paul Collins Startup list
[wind.exe]
Confirmed=X
Filename=wind.exe
Description=Added by the MITGLIEDER.BD TROJAN!
Source=Paul Collins Startup list
[WIND0WS]
Confirmed=X
Filename=WIND0WS.exe
Description=Added by the SPYBOT.DQ WORM!
Source=Paul Collins Startup list
[WinDates]
Confirmed=N
Filename=windates.exe
Description=WinDates is a calendar, date organizer and event reminder program from Rockin' Software
Source=Paul Collins Startup list
[windbs]
Confirmed=X
Filename=winxtc.exe
Description=Added by the AGOBOT-WD WORM!
Source=Paul Collins Startup list
[Winde]
Confirmed=X
Filename=winde.exe
Description=Added by the DLUCA TROJAN!
Source=Paul Collins Startup list
[windef]
Confirmed=X
Filename=Win32sp.vbs
Description=Added by the ANPES WORM!
Source=Paul Collins Startup list
[windir]
Confirmed=X
Filename=winrun.exe
Description=Added by the WINBUR.B WORM!
Source=Paul Collins Startup list
[Windll]
Confirmed=X
Filename=Windll.exe
Description=Added by the TRYNOMA TROJAN!
Source=Paul Collins Startup list
[WINDLL]
Confirmed=U
Filename=WSYS.EXE
Description=STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more"
Source=Paul Collins Startup list
[windll]
Confirmed=X
Filename=windll32.exe
Description=Added by the ASTEF or RESPAN WORMS!
Source=Paul Collins Startup list
[Windll.exe]
Confirmed=X
Filename=Windll.exe
Description=Added by the STEALER TROJAN!
Source=Paul Collins Startup list
[Windll32]
Confirmed=X
Filename=Windll32.exe
Description=Added by the MSNPWS TROJAN!
Source=Paul Collins Startup list
[windllsys32.exe]
Confirmed=X
Filename=windllsys32.exe
Description=Added by a variant of the MITGLIEDER.BY TROJAN!
Source=Paul Collins Startup list
[WinDNS]
Confirmed=X
Filename=windns32.exe
Description=Added by the GAOBOT.WX WORM!
Source=Paul Collins Startup list
[Windoes Kernel]
Confirmed=X
Filename=kernel32.exe
Description=Added by the KICKIN.A (or CYDOG.C) WORM!
Source=Paul Collins Startup list
[Window]
Confirmed=X
Filename=explore.exe
Description=Added by the GAOBOT.ADW WORM!
Source=Paul Collins Startup list
[Window Loader]
Confirmed=X
Filename=Dos32.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Window Monitor]
Confirmed=X
Filename=winmon32.exe
Description=Added by the SDBOT.RT WORM!
Source=Paul Collins Startup list
[Window Washer]
Confirmed=U
Filename=wwDisp.exe
Description=Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Source=Paul Collins Startup list
[window.exe]
Confirmed=X
Filename=window.exe
Description=Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
Source=Paul Collins Startup list
[window2]
Confirmed=X
Filename=ssvchost.exe
Description=Added by the IRCBOT.H TROJAN!
Source=Paul Collins Startup list
[WindowBlinds]
Confirmed=U
Filename=wbload.exe
Description=WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
Source=Paul Collins Startup list
[WindowEnhancer]
Confirmed=X
Filename=Winex.exe
Description=SCbar foistware variant
Source=Paul Collins Startup list
[WindowFX]
Confirmed=U
Filename=wfxload.exe
Description=Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
Source=Paul Collins Startup list
[Windows]
Confirmed=X
Filename=Kernel32.exe
Description=Added by the TENDOOLF WORM!
Source=Paul Collins Startup list
[Windows]
Confirmed=X
Filename=msdos98.exe
Description=Added by the PWSTEAL TROJAN!
Source=Paul Collins Startup list
[Windows]
Confirmed=X
Filename=Windows.exe
Description=Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS!
Source=Paul Collins Startup list
[Windows]
Confirmed=X
Filename=explorer.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[windows]
Confirmed=X
Filename=[path to trojan]
Description=Added by the AIMWIN TROJAN!
Source=Paul Collins Startup list
[windows]
Confirmed=X
Filename=hkey.exe
Description=Added by the GAOBOT.AFW WORM!
Source=Paul Collins Startup list
[windows]
Confirmed=X
Filename=system copy.exe
Description=Added by the SALGA.A WORM!
Source=Paul Collins Startup list
[Windows (random character)]
Confirmed=X
Filename=diskcheck.exe
Description=Added by the SINGU.B TROJAN!
Source=Paul Collins Startup list
[Windows Accelerators]
Confirmed=U
Filename=setup.exe
Description=KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
Source=Paul Collins Startup list
[Windows AdControl]
Confirmed=X
Filename=WinAdCtl.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows AdService]
Confirmed=X
Filename=WinAdServ.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows AdTools]
Confirmed=X
Filename=WinAdTools.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows Anti-Virus Built 32]
Confirmed=X
Filename=AntiVirus32.exe
Description=Added by the SDBOT-BG WORM!
Source=Paul Collins Startup list
[windows auto update]
Confirmed=X
Filename=penis32.exe
Description=Added by the BLASTER (or MSBLAST.A) WORM!
Source=Paul Collins Startup list
[Windows Auto Update]
Confirmed=X
Filename=winupdater.exe
Description=Added by the SDBOT.TF WORM!
Source=Paul Collins Startup list
[windows auto update ]
Confirmed=X
Filename=msblast.exe
Description=Added by the BLASTER.B WORM!
Source=Paul Collins Startup list
[Windows Automatic Update]
Confirmed=X
Filename=wuamgrder.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows Automatic Updates]
Confirmed=X
Filename=dvldr.exe
Description=Added by the RBOT.MF WORM!
Source=Paul Collins Startup list
[windows automation]
Confirmed=X
Filename=mslaugh.exe
Description=Added by the BLASTER.E WORM!
Source=Paul Collins Startup list
[Windows Automation]
Confirmed=X
Filename=msdspr.exe
Description=Added by the SOLAME.A WORM!
Source=Paul Collins Startup list
[Windows backup]
Confirmed=X
Filename=systemss.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Backup Configuration]
Confirmed=X
Filename=IEXPLORER.exe
Description=Added by the GAOBOT.AZ WORM!
Source=Paul Collins Startup list
[Windows Baţlangýç Dosyasý]
Confirmed=X
Filename=sistem.exe
Description=Added by the MUZK WORM!
Source=Paul Collins Startup list
[Windows Communicator]
Confirmed=X
Filename=wincomm.exe
Description=Added by the AGOBOT-BH WORM!
Source=Paul Collins Startup list
[Windows Compliant]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-IR WORM!
Source=Paul Collins Startup list
[Windows Config]
Confirmed=X
Filename=SSYS.EXE
Description=Added by the SPYBOT-DA WORM!
Source=Paul Collins Startup list
[Windows Config Loader]
Confirmed=X
Filename=Wincfg32.exe
Description=Added by the SILVERFTP TROJAN!
Source=Paul Collins Startup list
[Windows Configuration]
Confirmed=X
Filename=wsys32.exe
Description=Added by the GAOBOT.FB WORM!
Source=Paul Collins Startup list
[Windows Control]
Confirmed=X
Filename=Control.exe
Description=Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!
Source=Paul Collins Startup list
[Windows ControlAd]
Confirmed=X
Filename=WinCtlAd.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows Data Server]
Confirmed=X
Filename=autodisc.exe
Description=Added by the SPYBOT-CB WORM!
Source=Paul Collins Startup list
[Windows Database]
Confirmed=X
Filename=WinDat.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Windows Dcom2 Fix]
Confirmed=X
Filename=mscom32.exe
Description=Added by the RBOT-QT WORM!
Source=Paul Collins Startup list
[Windows debug logging]
Confirmed=X
Filename=winlogg.exe
Description=Added by the RBOT-OY WORM!
Source=Paul Collins Startup list
[Windows debug logging]
Confirmed=X
Filename=winloggs.exe
Description=Added by the RBOT-QN WORM!
Source=Paul Collins Startup list
[Windows Debugger]
Confirmed=X
Filename=windbg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Windows DLL Loader]
Confirmed=X
Filename=RUNDLL16.EXE
Description=Added by the DOMWIS TROJAN!
Source=Paul Collins Startup list
[Windows DLL Loader]
Confirmed=X
Filename=defragfat32z.exe
Description=Added by the LINKBOT.A WORM!
Source=Paul Collins Startup list
[Windows DLL Loader]
Confirmed=X
Filename=rundll32.exe
Description=Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the Windows\System folder, wheras the legitimate rundll32.exe is located in the C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)
Source=Paul Collins Startup list
[Windows DLL Loader]
Confirmed=X
Filename=defragfat32pi.exe
Description=Added by the RBOT-QQ WORM!
Source=Paul Collins Startup list
[Windows DLL Loader]
Confirmed=X
Filename=defragfat39.exe
Description=Added by the POEBOT-C WORM!
Source=Paul Collins Startup list
[Windows DLL Loader]
Confirmed=X
Filename=defragfatz.exe
Description=Added by the LINKBOT.H WORM!
Source=Paul Collins Startup list
[Windows DNS Daemon]
Confirmed=X
Filename=windnsd.exe
Description=Added by the WOOTBOT.AS WORM!
Source=Paul Collins Startup list
[Windows Drive Compatibility]
Confirmed=X
Filename=System32Driver32.exe
Description=Added by the SUPOVA.Z WORM!
Source=Paul Collins Startup list
[Windows Driver Services]
Confirmed=X
Filename=msdrvs32.exe
Description=Added by the WOOTBOT.L WORM!
Source=Paul Collins Startup list
[Windows Explorer]
Confirmed=X
Filename=[filename].exe
Description=Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[Windows Explorer]
Confirmed=X
Filename=Lsas.exe
Description=Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[Windows Explorer]
Confirmed=X
Filename=olecom32.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Windows Explorer]
Confirmed=X
Filename=EEXPLORER.EXE
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Explorer Shell]
Confirmed=X
Filename=Winexec32.exe
Description=Added by the REDIST.B WORM!
Source=Paul Collins Startup list
[Windows Explorer Update Build 1142]
Confirmed=X
Filename=EXPLORER32.EXE
Description=Added by the KaZaA based KWBOT or KWBOT.Y WORMS!
Source=Paul Collins Startup list
[Windows Explorer-3212]
Confirmed=X
Filename=WINRE16.EXE
Description=Added by the HARDOC WORM!
Source=Paul Collins Startup list
[Windows Eyes]
Confirmed=N
Filename=??
Description=For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs
Source=Paul Collins Startup list
[Windows File Protection]
Confirmed=X
Filename=winprotect.exe
Description=Added by the AGOBOT.JB WORM!
Source=Paul Collins Startup list
[Windows Firewall Manager]
Confirmed=X
Filename=msfw.exe
Description=Added by the RBOT.WR WORM!
Source=Paul Collins Startup list
[Windows Fix]
Confirmed=X
Filename=integator.exe
Description=Added by the SDBOT.ZAB WORM!
Source=Paul Collins Startup list
[Windows Graphics Loaders]
Confirmed=X
Filename=wingraphics.exe
Description=Added by the SPYBOT.JG WORM!
Source=Paul Collins Startup list
[Windows Guardian]
Confirmed=U
Filename=thehel1iawgrd32.exe
Description=Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
Source=Paul Collins Startup list
[Windows Guardian]
Confirmed=U
Filename=Fawgrd32.exe
Description=Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
Source=Paul Collins Startup list
[Windows Help File]
Confirmed=X
Filename=winhelper32.exe
Description=Added by the SDBOT-QK TROJAN!
Source=Paul Collins Startup list
[Windows Help Manager]
Confirmed=X
Filename=svchost32.exe
Description=Added by the RBOT-OZ WORM!
Source=Paul Collins Startup list
[Windows Help Service]
Confirmed=X
Filename=winhelpsv.exe
Description=Added by the RBOT-LP WORM!
Source=Paul Collins Startup list
[Windows Help System]
Confirmed=?
Filename=Help.pif
Description=??
Source=Paul Collins Startup list
[Windows Host Device]
Confirmed=X
Filename=hostsvc.exe
Description=Added by the ZOOTY-A WORM!
Source=Paul Collins Startup list
[Windows HTML file reader]
Confirmed=X
Filename=Sysconf32.exe
Description=Added by the NOOMY.A WORM!
Source=Paul Collins Startup list
[Windows Internet Protocol]
Confirmed=X
Filename=winproc32.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Windows JavaScript Daemon]
Confirmed=X
Filename=Winjsd.exe
Description=Added by the WOOTBOT.AF WORM!
Source=Paul Collins Startup list
[Windows Load]
Confirmed=?
Filename=windows.com
Description=??
Source=Paul Collins Startup list
[Windows Loader]
Confirmed=X
Filename=wstart32.exe
Description=Added by the GAOBOT.CA WORM!
Source=Paul Collins Startup list
[Windows Loader Service]
Confirmed=X
Filename=civsc.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows logging]
Confirmed=X
Filename=winlogd.exe
Description=Added by the RBOT-ON WORM!
Source=Paul Collins Startup list
[Windows Login]
Confirmed=X
Filename=explored.exe
Description=Added by the GAOBOT.SY WORM!
Source=Paul Collins Startup list
[Windows Logon]
Confirmed=X
Filename=winlogin.exe
Description=Added by the SPYBOT-C TROJAN!
Source=Paul Collins Startup list
[Windows Logon Procedure]
Confirmed=X
Filename=Svchoste.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Management Instrumentation]
Confirmed=X
Filename=mwd.exe
Description=Added by the GRAPS WORM!
Source=Paul Collins Startup list
[Windows Manager]
Confirmed=X
Filename=winmants.exe
Description=Added by the MANTAS WORM!
Source=Paul Collins Startup list
[Windows mangement]
Confirmed=X
Filename=winlogonn.exe
Description=Added by the RANDEX.FC WORM!
Source=Paul Collins Startup list
[Windows Media Player]
Confirmed=X
Filename=wmediaplayer.exe
Description=Added by the AGOBOT-NQ WORM!
Source=Paul Collins Startup list
[Windows Media Player]
Confirmed=X
Filename=MediaPIayer.exe
Description=Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !)
Source=Paul Collins Startup list
[Windows Media Player]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows Media Player]
Confirmed=X
Filename=msa.exe
Description=Added by the RBOT-SI WORM!
Source=Paul Collins Startup list
[Windows Media Player Update]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-ET WORM!
Source=Paul Collins Startup list
[Windows Media Powerpoint Helper]
Confirmed=N
Filename=NSPPTHLP.EXE
Description=German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
Source=Paul Collins Startup list
[Windows media service]
Confirmed=X
Filename=crvss.exe
Description=Added by the SDBOT.VP WORM!
Source=Paul Collins Startup list
[Windows media service]
Confirmed=X
Filename=crsss.exe
Description=Added by the RBOT.ACY WORM!
Source=Paul Collins Startup list
[Windows media services]
Confirmed=X
Filename=cvrsss.exe
Description=Added by the RBOT-MW WORM!
Source=Paul Collins Startup list
[Windows Media SP.2.37]
Confirmed=X
Filename=[random filename]
Description=Added by the LEMIR.C TROJAN!
Source=Paul Collins Startup list
[Windows MeTaLRoCk service]
Confirmed=X
Filename=metalrock.exe
Description=Added by the TASTYRED TROJAN!
Source=Paul Collins Startup list
[Windows Monitor]
Confirmed=X
Filename=winmon.exe
Description=Added by the SDBOT.VB WORM!
Source=Paul Collins Startup list
[Windows Monitoring Service]
Confirmed=X
Filename=winmon.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Windows Nets]
Confirmed=X
Filename=WinNET.exe
Description=Added by the RBOT-MO WORM!
Source=Paul Collins Startup list
[Windows Network Controller]
Confirmed=X
Filename=Mqguard.exe
Description=Added by the FORBOT-CL WORM!
Source=Paul Collins Startup list
[Windows Network Service]
Confirmed=X
Filename=winvc32.exe
Description=Added by the RBOT.RY WORM!
Source=Paul Collins Startup list
[Windows Networking]
Confirmed=X
Filename=winsys32.exe
Description=Added by the GAOBOT.FL WORM!
Source=Paul Collins Startup list
[Windows Nivedia Driver]
Confirmed=X
Filename=sysMGT.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows NNT]
Confirmed=X
Filename=[path to trojan]
Description=Added by the RANKY.E TROJAN!
Source=Paul Collins Startup list
[Windows NT 32]
Confirmed=X
Filename=ntlogin32.exe
Description=Added by the RANDEX.BRD WORM!
Source=Paul Collins Startup list
[Windows NT Login]
Confirmed=X
Filename=ntlogin32.exe
Description=Added by the SDBOT.WG WORM!
Source=Paul Collins Startup list
[Windows NT Service Name]
Confirmed=X
Filename=winshock.exe
Description=Added by the RBOT-PK WORM!
Source=Paul Collins Startup list
[Windows NT Update Manager]
Confirmed=X
Filename=WINL0G0N.exe
Description=Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o"
Source=Paul Collins Startup list
[Windows OEM Tools]
Confirmed=X
Filename=winres32.exe
Description=Added by the SPYBOT.FD WORM!
Source=Paul Collins Startup list
[Windows OLE Automation Server]
Confirmed=X
Filename=ole32aut.vbe
Description=CoolWebSearch parasite related browser hijacker
Source=Paul Collins Startup list
[Windows Print Spooler]
Confirmed=?
Filename=SCVHOSTS.EXE
Description=Suspicious due to the similarity to the valid "svchost.exe" file
Source=Paul Collins Startup list
[Windows Print Spooler]
Confirmed=X
Filename=NavAgent32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Windows Print Spooler]
Confirmed=X
Filename=SVEHOST.EXE
Description=Added by the SPYBOT.H WORM!
Source=Paul Collins Startup list
[Windows Registry]
Confirmed=X
Filename=msnmsg.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows Registry Cleaner]
Confirmed=X
Filename=winclean.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Registry Express Loader]
Confirmed=X
Filename=regexpress.exe
Description=Added by the FORBOT-CJ WORM!
Source=Paul Collins Startup list
[Windows Registry Scan]
Confirmed=X
Filename=regscan32.exe
Description=Added by the RBOT.KE WORM!
Source=Paul Collins Startup list
[Windows Registry Scan]
Confirmed=X
Filename=timeupdate.exe
Description=Added by the SPYBOT.JE WORM!
Source=Paul Collins Startup list
[Windows Registry Security]
Confirmed=X
Filename=crss.exe
Description=Added by a variant of the IRC.BOT TROJAN!
Source=Paul Collins Startup list
[Windows Registry Startup]
Confirmed=X
Filename=wind32.exe
Description=Added by the AGOBOT-BZ WORM!
Source=Paul Collins Startup list
[Windows report]
Confirmed=X
Filename=swchost.exe
Description=Added by the SMALL-BD TROJAN!
Source=Paul Collins Startup list
[Windows Runtime Help]
Confirmed=X
Filename=win32hlp.exe
Description=Added by a variant of the AIMVISION TROJAN!
Source=Paul Collins Startup list
[Windows Runtime Help]
Confirmed=X
Filename=WinRunHelp.wrh
Description=Added by a variant of the AIMVISION TROJAN!
Source=Paul Collins Startup list
[Windows SA]
Confirmed=X
Filename=omniscient.exe
Description=BLAZEFIND adware
Source=Paul Collins Startup list
[Windows secure]
Confirmed=X
Filename=setver32.exe
Description=Added by the SPYBOT.EP WORM!
Source=Paul Collins Startup list
[Windows Secure Messaging System]
Confirmed=X
Filename=msnmsgrsrvc.exe
Description=Added by the RBOT-RE WORM!
Source=Paul Collins Startup list
[Windows Security Assistant]
Confirmed=X
Filename=rundll32.vbe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Windows Security Assistant]
Confirmed=X
Filename=winsec.exe
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[Windows Security Module]
Confirmed=X
Filename=module.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows ServeAd]
Confirmed=X
Filename=WinServAd.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows service]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the RBOT-QW WORM!
Source=Paul Collins Startup list
[Windows Service Host]
Confirmed=X
Filename=scvhost.exe
Description=Added by the SDBOT.N TROJAN!
Source=Paul Collins Startup list
[Windows Service Host]
Confirmed=X
Filename=svchost.exe
Description=Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Windows Services]
Confirmed=X
Filename=service.exe
Description=Added by the RANDEX.R WORM!
Source=Paul Collins Startup list
[Windows Services]
Confirmed=X
Filename=svchosts.exe
Description=Added by the AGOBOT-KL TROJAN!
Source=Paul Collins Startup list
[Windows Services Host]
Confirmed=X
Filename=svchost.exe
Description=Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Windows Services Update]
Confirmed=X
Filename=svch0st.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[Windows shell]
Confirmed=?
Filename=win70.exe
Description=??
Source=Paul Collins Startup list
[Windows Shell Library Loader]
Confirmed=X
Filename=load shell.dll /c /set
Description=CoolWebSearch parasite variant
Source=Paul Collins Startup list
[windows shellext.32]
Confirmed=X
Filename=mschost.exe
Description=Added by the BLASTER.K WORM!
Source=Paul Collins Startup list
[Windows Smart Manager]
Confirmed=X
Filename=smart.exe
Description=Added by the RBOT-SL WORM!
Source=Paul Collins Startup list
[Windows Sound Driver]
Confirmed=X
Filename=SndMon32.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Sound Manager]
Confirmed=X
Filename=SndMon32.exe
Description=Added by the FORBOT-BU WORM!
Source=Paul Collins Startup list
[Windows SP2 Update]
Confirmed=X
Filename=Sp2update.exe
Description=Added by the WOOTBOT.BS WORM!
Source=Paul Collins Startup list
[Windows Spooler]
Confirmed=X
Filename=SPOOLSRV.EXE
Description=Added by the SPYBOT.P WORM!
Source=Paul Collins Startup list
[Windows SSL File]
Confirmed=X
Filename=winssv.exe
Description=Added by the WOOTBOT.CA WORM!
Source=Paul Collins Startup list
[Windows Startup]
Confirmed=X
Filename=winsta~1.exe
Description=GoHip foistware
Source=Paul Collins Startup list
[Windows Startup]
Confirmed=X
Filename=winstartup.exe
Description=GoHip foistware
Source=Paul Collins Startup list
[Windows Startup]
Confirmed=X
Filename=Wdrun32.exe
Description=Added by the GAOBOT.AO WORM!
Source=Paul Collins Startup list
[Windows Startup]
Confirmed=X
Filename=services21.exe
Description=Added by the AGOBOT-MX WORM!
Source=Paul Collins Startup list
[Windows Startup 32 Bits]
Confirmed=X
Filename=sysrun32.exe
Description=Added by a variant of the DARKSUN TROJAN!
Source=Paul Collins Startup list
[Windows Streams Server]
Confirmed=X
Filename=localsrv.exe
Description=Added by the SDBOT.LN WORM!
Source=Paul Collins Startup list
[Windows SyncroAd]
Confirmed=X
Filename=SyncroAd.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows System Configuration]
Confirmed=X
Filename=SYSCFG16.EXE
Description=Added by the WISDOOR.Z TROJAN!
Source=Paul Collins Startup list
[Windows System Manager]
Confirmed=X
Filename=winsystem.exe
Description=Added by the RBOT-AN WORM!
Source=Paul Collins Startup list
[Windows System Manager Proc]
Confirmed=X
Filename=winsmc.exe
Description=Added by the RBOT.JH WORM!
Source=Paul Collins Startup list
[Windows System Restore Configuration]
Confirmed=X
Filename=Sblhost.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows System Restorer]
Confirmed=X
Filename=SystemRestorer.exe
Description=Added by the DULOAD.C WORM!
Source=Paul Collins Startup list
[Windows System Security]
Confirmed=X
Filename=winmp.exe
Description=Added by the RBOT.IV WORM!
Source=Paul Collins Startup list
[Windows System Serivce]
Confirmed=X
Filename=winserv.exe
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[windows system service]
Confirmed=X
Filename=winsock.exe
Description=Added by the RBOT-MR WORM!
Source=Paul Collins Startup list
[Windows System Tray]
Confirmed=U
Filename=msni.exe
Description=Iambigbrother monitoring software
Source=Paul Collins Startup list
[Windows System Tray]
Confirmed=X
Filename=swhost.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Windows Task Manager]
Confirmed=X
Filename=ACCOUNT_DETAILS.DOC.exe
Description=Added by the QUATERS.A WORM!
Source=Paul Collins Startup list
[Windows Task Manager]
Confirmed=X
Filename=taskmgn.exe
Description=Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install
Source=Paul Collins Startup list
[Windows TaskAd]
Confirmed=X
Filename=Wintaskad.exe
Description=Windupdates adware variant
Source=Paul Collins Startup list
[Windows Taskbar Manager]
Confirmed=X
Filename=internat.exe
Description=Added by the PROTORIDE-H WORM!
Source=Paul Collins Startup list
[Windows Taskbar Manager]
Confirmed=X
Filename=[path to file]
Description=Added by the PROTORIDE.B WORM!
Source=Paul Collins Startup list
[Windows Taskbar System]
Confirmed=X
Filename=tasksys.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[Windows TCP/IP]
Confirmed=X
Filename=wintcp.exe
Description=Added by the AGOBOT-ZH WORM!
Source=Paul Collins Startup list
[Windows Telnet Server]
Confirmed=X
Filename=wintel.exe
Description=Added by the AGOBOT-MW WORM!
Source=Paul Collins Startup list
[Windows Time Server]
Confirmed=X
Filename=TimeSRV.exe
Description=Added by the SPYBOT.DNC WORM!
Source=Paul Collins Startup list
[Windows Upate]
Confirmed=X
Filename=rundll.exe
Description=Added by the HAKO TROJAN! Note - this is NOT the Windows system file of the same name as described here
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=[filename]
Description=Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=iexplorere.exe
Description=Added by the GAOBOT.AP WORM!
Source=Paul Collins Startup list
[windows update]
Confirmed=X
Filename=uddater.exe
Description=Added by the LEOX TROJAN!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=wudate.exe
Description=Added by the AGOBOT.ML WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=wupdate.exe
Description=Wengs adware
Source=Paul Collins Startup list
[windows update]
Confirmed=X
Filename=sychost.exe
Description=Added by the LEOX.B WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=Wuamgrd.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=inetinf.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=host32.exe
Description=Added by the RBOT-GU WORM!
Source=Paul Collins Startup list
[windows update]
Confirmed=X
Filename=wuraclt.exe
Description=Added by the RBOT-PO WORM!
Source=Paul Collins Startup list
[windows update]
Confirmed=X
Filename=Wuanclt.exe
Description=Added by the RBOT.XZ WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=ebay.exe
Description=Added by the GAOBOT.BUU WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=windows.exe
Description=Added by the RBOT-RB WORM!
Source=Paul Collins Startup list
[windows update]
Confirmed=X
Filename=wuaurlt.exe
Description=Added by the RBOT.ADG WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=Update.exe
Description=Added by the DELF-FN TROJAN!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=winmguard.exe
Description=Added by the RBOT-EM WORM!
Source=Paul Collins Startup list
[Windows Update]
Confirmed=X
Filename=wuampd.exe
Description=Added by the RBOT.UM WORM!
Source=Paul Collins Startup list
[windows update]
Confirmed=X
Filename=wuarclt.exe
Description=Added by the RBOT-OF WORM!
Source=Paul Collins Startup list
[Windows Update AutoUpdate Client Product]
Confirmed=X
Filename=wuauct.exe
Description=Added by the AGOBOT.ACL WORM!
Source=Paul Collins Startup list
[Windows Update Checker]
Confirmed=X
Filename=[random filename]
Description=Adware downloader trojan
Source=Paul Collins Startup list
[Windows Update Client]
Confirmed=X
Filename=wuclient.exe
Description=Added by the SMALL-RN TROJAN!
Source=Paul Collins Startup list
[Windows Update Client Service]
Confirmed=X
Filename=windrvl32.exe
Description=Added by the AGOBOT-MM TROJAN!
Source=Paul Collins Startup list
[Windows update config]
Confirmed=X
Filename=svhost.exe
Description=Added by the SDBOT-PF WORM!
Source=Paul Collins Startup list
[windows update configurator]
Confirmed=X
Filename=svghost.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows Update Files]
Confirmed=X
Filename=dnetc.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update
Source=Paul Collins Startup list
[Windows Update Manager]
Confirmed=X
Filename=wupdmngr.exe
Description=Added by the RANDEX.BTB WORM!
Source=Paul Collins Startup list
[Windows Update Manager]
Confirmed=X
Filename=Winlog0n.exe
Description=Added by the AGENT-BO TROJAN!
Source=Paul Collins Startup list
[Windows Update Manager for NT]
Confirmed=X
Filename=wupdmgr32.exe
Description=Added by the SDBOT.AH WORM!
Source=Paul Collins Startup list
[Windows Update Monitoring Service]
Confirmed=X
Filename=winupdt.exe
Description=Added by the RBOT-PL WORM!
Source=Paul Collins Startup list
[Windows Update Process]
Confirmed=X
Filename=wmiprvsc.exe
Description=Added by the SDBOT-CB WORM!
Source=Paul Collins Startup list
[Windows Update Service]
Confirmed=X
Filename=csrs.exe
Description=Added by the AGOBOT-NI WORM!
Source=Paul Collins Startup list
[Windows Update Service]
Confirmed=X
Filename=smcg.exe
Description=Added by the SDBOT.QY WORM!
Source=Paul Collins Startup list
[Windows Update Service 2004/2005]
Confirmed=X
Filename=systemupdate.exe
Description=Added by the RBOT-JE WORM!
Source=Paul Collins Startup list
[Windows Update V6]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-KT WORM!
Source=Paul Collins Startup list
[Windows Update.exe]
Confirmed=X
Filename=N/A
Description=Homepage hijacker, see here
Source=Paul Collins Startup list
[Windows Updater]
Confirmed=X
Filename=wupdmgr32.exe
Description=Added by a variant of the DOS.AUTOCAT TROJAN!
Source=Paul Collins Startup list
[Windows Version Check]
Confirmed=N
Filename=ver_chk.exe
Description=Version checker for CyberAudioLibrary ("A new way to exchange information through the Internet")
Source=Paul Collins Startup list
[Windows video]
Confirmed=X
Filename=vide_32.exe
Description=Added by a variant of the AGOBOT/GAOBOT WORM!
Source=Paul Collins Startup list
[Windows Video Acquisition (WVA)]
Confirmed=X
Filename=wvsvc.exe
Description=Added by the AGOBOT.YM WORM!
Source=Paul Collins Startup list
[Windows Video Drivers]
Confirmed=X
Filename=videons32.exe
Description=Added by the GAOBOT.AZT WORM!
Source=Paul Collins Startup list
[Windows-System]
Confirmed=X
Filename=System32.exe
Description=Added by the LOGPOLE.C WORM!
Source=Paul Collins Startup list
[Windows-TCP-IP]
Confirmed=X
Filename=rfkampig.exe
Description=Added by the GIPMA TROJAN!
Source=Paul Collins Startup list
[Windows32]
Confirmed=X
Filename=rundll.exe
Description=Added by the AGOBOT-LK or AGOBOT-ND WORMS!
Source=Paul Collins Startup list
[WindowsAgent]
Confirmed=X
Filename=WindowsAgent.exe
Description=Added by the GOP.G WORM!
Source=Paul Collins Startup list
[WindowsAPI.DLL]
Confirmed=X
Filename=Server5.exe
Description=Added by the "Fear and Hope" TROJAN!
Source=Paul Collins Startup list
[WindowsCriticalUpdate]
Confirmed=X
Filename=windows_critical_update.exe
Description=Added by the ASTEF or RESPAN WORMS!
Source=Paul Collins Startup list
[WindowsKeyUpdate]
Confirmed=X
Filename=master.exe
Description=Added by the JOSAM WORM!
Source=Paul Collins Startup list
[WindowsMGM]
Confirmed=X
Filename=Winmgm32.exe
Description=Added by the SOBIG WORM and LALA.C TROJAN!
Source=Paul Collins Startup list
[WindowsReg% update]
Confirmed=X
Filename=[random filename].exe
Description=Added by the RBOT-HH WORM!
Source=Paul Collins Startup list
[WindowsRegistration]
Confirmed=X
Filename=[random filename]
Description=Added by the RBOT-NO WORM!
Source=Paul Collins Startup list
[WindowsRegKey Autoupdate]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[WindowsRegKey upd4te2d4te]
Confirmed=X
Filename=*********.exe [* = random char]
Description=Added by the RBOT.XQ WORM!
Source=Paul Collins Startup list
[WindowsRegKey update]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the RBOT WORM!
Source=Paul Collins Startup list
[WindowsRegKey update]
Confirmed=X
Filename=winupdate.exe
Description=Added by the RBOT-QJ WORM!
Source=Paul Collins Startup list
[WindowsRegKey%$ update]
Confirmed=X
Filename=msi332.exe
Description=Added by the RBOT-IX WORM!
Source=Paul Collins Startup list
[WindowsRegKey%update]
Confirmed=X
Filename=ethernet32m.exe
Description=Added by the RBOT-EN WORM!
Source=Paul Collins Startup list
[WindowsRegKeys update]
Confirmed=X
Filename=winsysi.exe
Description=Added by the SDBOT.WE WORM!
Source=Paul Collins Startup list
[WindowsSetup]
Confirmed=X
Filename=[path to trojan]
Description=Added by the EZBOT TROJAN!
Source=Paul Collins Startup list
[WindowsUpd]
Confirmed=X
Filename=WindowsUpd4.exe
Description=VirtuMonde adware
Source=Paul Collins Startup list
[WindowsUpd1]
Confirmed=X
Filename=WindowsUpd1.exe
Description=VirtuMonde adware
Source=Paul Collins Startup list
[WindowsUpd2]
Confirmed=X
Filename=WindowsUpd2.exe
Description=VirtuMonde adware
Source=Paul Collins Startup list
[WindowsUpdate]
Confirmed=X
Filename=windows_update.exe
Description=Added by the LOFNI WORM!
Source=Paul Collins Startup list
[WindowsUpdate]
Confirmed=X
Filename=svchost.exe
Description=Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[windowsupdate]
Confirmed=X
Filename=RPCX1sQ3.exe
Description=Added by the IRCBOT.B TROJAN!
Source=Paul Collins Startup list
[WindowsUpdate]
Confirmed=X
Filename=USRINIT.EXE
Description=Added by the MADDIS.B WORM!
Source=Paul Collins Startup list
[WindowsUpdate Service]
Confirmed=X
Filename=wuautlc.exe
Description=Added by the RBOT-NR WORM!
Source=Paul Collins Startup list
[WindowsXP Module]
Confirmed=X
Filename=DirectX3D.exe
Description=Malware, reportedly a keylogger - see here
Source=Paul Collins Startup list
[WindowsXP Update]
Confirmed=X
Filename=windowsxpupdate.exe
Description=Added by the RBOT-PB WORM!
Source=Paul Collins Startup list
[Windows_Serivce]
Confirmed=X
Filename=SERVICE.exe
Description=Added by the WOOTBOT.AH WORM!
Source=Paul Collins Startup list
[Windows_Updates]
Confirmed=X
Filename=svthost.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Windows_VXD]
Confirmed=X
Filename=user32.exe
Description=Added by the PWSTEAL.PPORT TROJAN!
Source=Paul Collins Startup list
[Windowz Update V2.0]
Confirmed=X
Filename=Explorer.exe
Description=Added by the YODO WORM! Note - the valid "explorer.exe" is located in C:\Windows or C:\Winnt whereas this one is located in the System32 sub-directory
Source=Paul Collins Startup list
[WinDriv32]
Confirmed=X
Filename=WinDriv32.exe
Description=Added by the SMALL-BA TROJAN!
Source=Paul Collins Startup list
[WinDriver Configuration]
Confirmed=X
Filename=windrvconf.exe
Description=Added by the AGOBOT-LX TROJAN!
Source=Paul Collins Startup list
[windrv]
Confirmed=X
Filename=windrv32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET
Source=Paul Collins Startup list
[WinDrv]
Confirmed=X
Filename=windrvx.exe
Description=Added by a variant of the TIBSER.A downloader TROJAN!
Source=Paul Collins Startup list
[WinDSL MTU-Adjust]
Confirmed=U
Filename=WinDSL_MTU.exe
Description=Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
Source=Paul Collins Startup list
[WinDSL_MTU]
Confirmed=?
Filename=WinDSL_MTU.exe
Description=May be realted to Tiscali broadband, if so is it required?
Source=Paul Collins Startup list
[WinDSNX]
Confirmed=X
Filename=Win????.exe
Description=Added by the DNSX TROJAN!
Source=Paul Collins Startup list
[WindUpdates]
Confirmed=X
Filename=[path to trojan]
Description=Added by the AGENT.BF TROJAN!
Source=Paul Collins Startup list
[WindUpdates]
Confirmed=X
Filename=WinUpdt.exe
Description=Windupdates adware
Source=Paul Collins Startup list
[WINDVDpatch]
Confirmed=U
Filename=CTHELPER.EXE
Description=CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
Source=Paul Collins Startup list
[WinDVR SchSvr]
Confirmed=N
Filename=SchSvr.exe
Description=WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Source=Paul Collins Startup list
[WinDVRCtrl]
Confirmed=N
Filename=WinDVRCtrl.exe
Description=Control center software for an AOpen VA1000 TV tuner card
Source=Paul Collins Startup list
[Windws Configuration Loader]
Confirmed=X
Filename=LEXPLORE.exe
Description=Added by the SODABOT WORM!
Source=Paul Collins Startup list
[WinEssential]
Confirmed=X
Filename=Keyhost.exe
Description=Hijacker - hailing from jraun.com
Source=Paul Collins Startup list
[WinEssential]
Confirmed=X
Filename=keyword.exe
Description=Jraun.com hijacker
Source=Paul Collins Startup list
[WinExec]
Confirmed=X
Filename=Winexec.exe.vbs
Description=Added by the AINESEY.A WORM!
Source=Paul Collins Startup list
[WinExec32]
Confirmed=X
Filename=WinExec32.exe
Description=Added by the KAZWIN WORM!
Source=Paul Collins Startup list
[WinFast Schedule]
Confirmed=U
Filename=Wfwiz.exe
Description=Leadtek WinFast TV tuner scheduler
Source=Paul Collins Startup list
[Winfast2KLoadDefault]
Confirmed=U
Filename=Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings
Description=Loads default settings for Leadtek Winfast graphics cards
Source=Paul Collins Startup list
[Winfast_2K]
Confirmed=U
Filename=WF2k.exe
Description=System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
Source=Paul Collins Startup list
[WinFast_Gamma]
Confirmed=U
Filename=Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings
Description=Loads if you change the gamma settings on Leadtek WinFast graphics cards
Source=Paul Collins Startup list
[WinFast_Taskbar]
Confirmed=U
Filename=rundll32.exe wftask.dll, WFDllLoadDefaultSettings
Description=Loads default settings for Leadtek WinFast graphics cards
Source=Paul Collins Startup list
[WinFavorites]
Confirmed=X
Filename=WinFavorites.exe1
Description=Loudmarketing.com adware downloader
Source=Paul Collins Startup list
[WinFax PRO Controller]
Confirmed=N
Filename=WFXCTL32.EXE
Description=From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Source=Paul Collins Startup list
[WinFaxAppPortStarter]
Confirmed=Y
Filename=wfxsnt40.exe
Description=WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
Source=Paul Collins Startup list
[winfont]
Confirmed=X
Filename=winfont.exe
Description=Added by the DEATH TROJAN!
Source=Paul Collins Startup list
[WinFoxV2]
Confirmed=U
Filename=WF2k.exe
Description=System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
Source=Paul Collins Startup list
[WinFX]
Confirmed=X
Filename=cssrs.exe
Description=Added by the AGOBOT.FX WORM!
Source=Paul Collins Startup list
[WinGate]
Confirmed=X
Filename=WinGate.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[WinGate Engine Monitor]
Confirmed=U
Filename=wgengmon.exe
Description=WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server
Source=Paul Collins Startup list
[WinGate initialize]
Confirmed=X
Filename=WinGate.exe
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[wingo]
Confirmed=X
Filename=wingo.exe
Description=Added by the BEAGLE.AW or BEAGLE.AV WORMS!
Source=Paul Collins Startup list
[wingo]
Confirmed=X
Filename=[various filenames]
Description=Added by the BAGLE-AU WORM!
Source=Paul Collins Startup list
[WinGuage Pro]
Confirmed=N
Filename=WGPRO32.EXE
Description=Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
Source=Paul Collins Startup list
[Winguard]
Confirmed=Y
Filename=WGFE95.EXE
Description=Dr Solomon's Virex antivirus
Source=Paul Collins Startup list
[WinGuard Pro]
Confirmed=U
Filename=wgp.exe
Description=Winguard Pro
Source=Paul Collins Startup list
[WinHacker]
Confirmed=N
Filename=rundll32.exe wh95.dll, HackMe
Description=Tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free
Source=Paul Collins Startup list
[Winhelp]
Confirmed=X
Filename=winhe1p.exe
Description=Added by the QQPASS.E TROJAN!
Source=Paul Collins Startup list
[WinHelp]
Confirmed=X
Filename=WinHelp.exe
Description=Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid "winhelp.exe" resides in C:\Windows or C:\Winnt
Source=Paul Collins Startup list
[WinHelp]
Confirmed=X
Filename=realsched.exe
Description=Added by a variant of the LOVGATE WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
Source=Paul Collins Startup list
[Winhelp]
Confirmed=X
Filename=TkBellExe.exe...
Description=Added by a variant of the LOVGATE WORM!
Source=Paul Collins Startup list
[winhlp3.exe]
Confirmed=X
Filename=winhlp3.exe
Description=Added by a variant of the EASTO.A TROJAN!
Source=Paul Collins Startup list
[Winhlp32]
Confirmed=X
Filename=Wscript.exe ..Msexec32.vbs
Description=Added by the GANT.B WORM!
Source=Paul Collins Startup list
[winhlp32.exe]
Confirmed=X
Filename=winhlp32.exe
Description=Added by a variant of the EASTO.A TROJAN!
Source=Paul Collins Startup list
[winhlpp32.exe]
Confirmed=X
Filename=winhlpp32.exe
Description=Added by the GAOBOT.SY WORM!
Source=Paul Collins Startup list
[Winhost]
Confirmed=X
Filename=wintt.exe
Description=Added by the LOLAWEB.B TROJAN!
Source=Paul Collins Startup list
[Winhost]
Confirmed=X
Filename=win.exe
Description=Added by the DLOADER-AP TROJAN!
Source=Paul Collins Startup list
[winhost32.exe]
Confirmed=X
Filename=winhost32.exe
Description=Added by the TABDIM TROJAN!
Source=Paul Collins Startup list
[wininet32]
Confirmed=X
Filename=wininet32.exe
Description=Added by the RAZNEW-A TROJAN!
Source=Paul Collins Startup list
[wininetd]
Confirmed=X
Filename=wininetd.exe
Description=Added by the WINET TROJAN!
Source=Paul Collins Startup list
[wininit]
Confirmed=X
Filename=wininit.exe
Description=Added by the WOLLF.16 TROJAN!
Source=Paul Collins Startup list
[Wink*.exe]
Confirmed=X
Filename=Wink*.exe [* = random char]
Description=Added by a variant of the KLEZ WORM!
Source=Paul Collins Startup list
[Winkb6]
Confirmed=U
Filename=winkb6.exe
Description=Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed
Source=Paul Collins Startup list
[WinKernel]
Confirmed=X
Filename=WinKer.exe
Description=Added by the MIRAB or SERVIDOR TROJANS!
Source=Paul Collins Startup list
[WinKernel]
Confirmed=X
Filename=[path to worm]
Description=Added by the PLEA VIRUS!
Source=Paul Collins Startup list
[winkernel32]
Confirmed=X
Filename=wWin32.com
Description=Added by the BANSAP TROJAN!
Source=Paul Collins Startup list
[WinKey]
Confirmed=U
Filename=winkey.exe
Description=Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos
Source=Paul Collins Startup list
[winlibs.exe]
Confirmed=X
Filename=winlibs.exe
Description=Added by the EVAMAN.C WORM!
Source=Paul Collins Startup list
[WinLibUpdate]
Confirmed=X
Filename=libupdate.exe
Description=Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310
Source=Paul Collins Startup list
[WinLibUpdate32]
Confirmed=X
Filename=libupdate32.exe
Description=Added by the BIONET.405 TROJAN!
Source=Paul Collins Startup list
[WinLibUpdte]
Confirmed=X
Filename=libupdte.exe
Description=Added by the BIONET.318 TROJAN!
Source=Paul Collins Startup list
[Winlink]
Confirmed=X
Filename=winlink32.exe
Description=Added by the GAOBOT.AAY WORM!
Source=Paul Collins Startup list
[Winlme]
Confirmed=X
Filename=windll.exe
Description=Added by the GOP.F WORM!
Source=Paul Collins Startup list
[WinLoader]
Confirmed=X
Filename=[random filename]
Description=Added by variants of the SUBSEVEN TROJAN!
Source=Paul Collins Startup list
[winlocatorupdate]
Confirmed=X
Filename=updatewinlocator.exe
Description=Locator adult content toolbar related
Source=Paul Collins Startup list
[WinLogin]
Confirmed=X
Filename=winlogin.exe
Description=Added by the AGOBOT-IX WORM!
Source=Paul Collins Startup list
[Winlogin.exe]
Confirmed=X
Filename=log.exe
Description=Added by a variant of the AGENT.AH downloader TROJAN!
Source=Paul Collins Startup list
[winlogin.exe]
Confirmed=X
Filename=logfile.exe
Description=Added by the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[winlogin.exe]
Confirmed=X
Filename=mspaint.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[Winlogin.exe]
Confirmed=X
Filename=steam.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[winlogon]
Confirmed=Y
Filename=winlogon.exe
Description=Windows Logon Process - handles user logons described here
Source=Paul Collins Startup list
[winlogon]
Confirmed=X
Filename=winlogon.exe
Description=Hijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate Windows Logon (winlogon.exe) process
Source=Paul Collins Startup list
[winlogon]
Confirmed=X
Filename=winlogin.exe
Description=Added by the RANDEX.E WORM!
Source=Paul Collins Startup list
[winlogon]
Confirmed=X
Filename=winlogon.exe
Description=Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory
Source=Paul Collins Startup list
[winlogon]
Confirmed=X
Filename=msreg32.exe
Description=Added by the SDBOT.EO WORM!
Source=Paul Collins Startup list
[winlogon service]
Confirmed=X
Filename=urx.exe
Description=Added by the SPYBOT.EN WORM!
Source=Paul Collins Startup list
[Winlogon.exe]
Confirmed=X
Filename=N/A
Description=CoolWebSearch parasite related - resets home page to an adult material site
Source=Paul Collins Startup list
[WinLsass]
Confirmed=X
Filename=servicec.exe
Description=Added by the SCANE WORM!
Source=Paul Collins Startup list
[WinLsass]
Confirmed=X
Filename=[path to trojan]
Description=Added by the SCANE WORM!
Source=Paul Collins Startup list
[winltmpv]
Confirmed=X
Filename=winln.exe
Description=Added by the TCXMEDI-C TROJAN!
Source=Paul Collins Startup list
[winltmpv]
Confirmed=X
Filename=wutop.exe
Description=Added by the TCXMEDI-C TROJAN!
Source=Paul Collins Startup list
[Winmain]
Confirmed=X
Filename=winmain.exe
Description=One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!
Source=Paul Collins Startup list
[WinManager]
Confirmed=?
Filename=schost.exe
Description=??
Source=Paul Collins Startup list
[winmatrix.exe]
Confirmed=U
Filename=WinMatrixXP.exe
Description=WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
Source=Paul Collins Startup list
[WinMem]
Confirmed=U
Filename=WinMem.exe
Description=WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
Source=Paul Collins Startup list
[WinMenssage]
Confirmed=X
Filename=winmax.exe
Description=Added by the BANCOS.B TROJAN!
Source=Paul Collins Startup list
[WinMgmt]
Confirmed=N
Filename=WinMgmt.exe
Description=Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
Source=Paul Collins Startup list
[WinMgr32]
Confirmed=X
Filename=winmgr32.exe
Description=Added by the MIMAIL.P WORM!
Source=Paul Collins Startup list
[WinMine]
Confirmed=X
Filename=D4NG3.vbs
Description=Added by the BISCUIT.A WORM!
Source=Paul Collins Startup list
[winmodem]
Confirmed=Y
Filename=wmexe.exe
Description=Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
Source=Paul Collins Startup list
[WinMsrv32]
Confirmed=X
Filename=WinMsrv32.exe
Description=Added by the GAOBOT.AFJ WORM!
Source=Paul Collins Startup list
[WinMX]
Confirmed=N
Filename=WinMX.exe
Description=WinMX file sharing application
Source=Paul Collins Startup list
[winmysqladmin]
Confirmed=N
Filename=winmysqladmin.exe
Description=Starts the MySQL database admin tool
Source=Paul Collins Startup list
[WinMySQLadmin Tool]
Confirmed=N
Filename=winmysqladmin.exe
Description=Starts the MySQL database admin tool
Source=Paul Collins Startup list
[winnet]
Confirmed=X
Filename=winnet.exe
Description=CommonName Toolbar spyware. To uninstall see here
Source=Paul Collins Startup list
[Winnov Menu]
Confirmed=?
Filename=WnvMenu.Exe
Description=Winnov Video Capture Card related. What does it do and is it required?
Source=Paul Collins Startup list
[Winnov Remote]
Confirmed=?
Filename=WnvRsvr.Exe
Description=Winnov Video Capture Card related. What does it do and is it required?
Source=Paul Collins Startup list
[Winnov Status]
Confirmed=?
Filename=WvStatus.Exe
Description=Winnov Video Capture Card related. What does it do and is it required?
Source=Paul Collins Startup list
[WinNtBB]
Confirmed=X
Filename=WinntBB.exe
Description=Added by the DULOAD.C WORM!
Source=Paul Collins Startup list
[Winnup]
Confirmed=X
Filename=win32nls.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[winocx32]
Confirmed=X
Filename=winocx32.exe
Description=Added by the PROTORIDE.I WORM!
Source=Paul Collins Startup list
[Winpack]
Confirmed=X
Filename=winpack.exe
Description=Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg
Source=Paul Collins Startup list
[WinPatrol]
Confirmed=U
Filename=WinPatrol.exe
Description=WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"
Source=Paul Collins Startup list
[winphonics7536]
Confirmed=X
Filename=vbsystem35.exe setups.exe vb.vb
Description=Added by a variant of the MUTIN-C TROJAN!
Source=Paul Collins Startup list
[winpipe]
Confirmed=X
Filename=winpipe.exe
Description=Browser hijacker redirecting to wow-access.com
Source=Paul Collins Startup list
[WinPoet]
Confirmed=Y
Filename=WinPPPoverEthernet.exe
Description=WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
Source=Paul Collins Startup list
[WinPopup]
Confirmed=N
Filename=WINPOPUP.EXE
Description=Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup
Source=Paul Collins Startup list
[winpopup]
Confirmed=X
Filename=winupie.exe
Description=Adware by Tradeexit.com
Source=Paul Collins Startup list
[WinProfile]
Confirmed=X
Filename=Command.exe
Description=Added by the BUDDY TROJAN!
Source=Paul Collins Startup list
[WinProfile]
Confirmed=X
Filename=sndcfg16.exe
Description=Added by the SNDC.A WORM!
Source=Paul Collins Startup list
[WinProt]
Confirmed=X
Filename=Winprot.exe
Description=Added by the CHUPACABRA TROJAN!
Source=Paul Collins Startup list
[WinProt]
Confirmed=X
Filename=server.exe
Description=Added by the CHUPACABRA TROJAN!
Source=Paul Collins Startup list
[winprotect]
Confirmed=X
Filename=win32.exe
Description=Added by the MUGLY.E WORM!
Source=Paul Collins Startup list
[WinProxy]
Confirmed=U
Filename=WinProxy.EXE
Description="WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP"
Source=Paul Collins Startup list
[winpsd]
Confirmed=X
Filename=winpsd.exe
Description=Added by the MYDOOM.Q WORM!
Source=Paul Collins Startup list
[winrar]
Confirmed=X
Filename=winrar.exe
Description=CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:\Winnt or C:\Windows
Source=Paul Collins Startup list
[winrarshell]
Confirmed=X
Filename=winrarshell32.exe
Description=Added by the SALIRA TROJAN!
Source=Paul Collins Startup list
[winReg]
Confirmed=X
Filename=winReg.exe
Description=Added by the YAHA.H or YAHA.J WORMS!
Source=Paul Collins Startup list
[winregsrv]
Confirmed=X
Filename=winregsrv.exe
Description=Added by the SYNRG TROJAN!
Source=Paul Collins Startup list
[Winres32vis]
Confirmed=X
Filename=[path to worm]
Description=Added by the THRAX.A WORM!
Source=Paul Collins Startup list
[winroute]
Confirmed=N
Filename=winroute.exe
Description=Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k
Source=Paul Collins Startup list
[winrun]
Confirmed=X
Filename=msconfig.exe
Description=Added by the WINUR.A WORM! Note - this is not the real msconfig.exe as it's located in C:\winrun\
Source=Paul Collins Startup list
[winrun]
Confirmed=X
Filename=winrun.exe
Description=Added by the WINBUR.B WORM!
Source=Paul Collins Startup list
[WinRunners]
Confirmed=X
Filename=WinDrivers.exe
Description=Added by the DULOAD.C WORM!
Source=Paul Collins Startup list
[WinSec]
Confirmed=X
Filename=winsec16.exe
Description=Added by the AGOBOT.ZF WORM!
Source=Paul Collins Startup list
[winsecure]
Confirmed=X
Filename=winsecure.exe
Description=Browser hijacker, redirecting to specificsearches.com
Source=Paul Collins Startup list
[WinSecured32]
Confirmed=X
Filename=ssmr.exe
Description=Added by a variant of the FORBOT WORM!
Source=Paul Collins Startup list
[winserver]
Confirmed=X
Filename=Server.txt.vbs
Description=Added by the DELTAD.A WORM!
Source=Paul Collins Startup list
[WinService32]
Confirmed=U
Filename=ssmgr.exe
Description=007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"
Source=Paul Collins Startup list
[WinServices]
Confirmed=X
Filename=WinServices.exe
Description=Added by the YAHA.K or YAHA.M WORMS!
Source=Paul Collins Startup list
[winservn]
Confirmed=X
Filename=winservn.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[winservs]
Confirmed=X
Filename=winservs.exe
Description=PurityScan/Clickspring adware
Source=Paul Collins Startup list
[WinSetBrowse]
Confirmed=X
Filename=BasicUpdate.dll.vbs
Description=Added by the BISCUIT.A WORM!
Source=Paul Collins Startup list
[Winshoe]
Confirmed=?
Filename=wuadfdqr.exe
Description=Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed
Source=Paul Collins Startup list
[WinShowUpdate]
Confirmed=X
Filename=copy C:\WINDOWS\winshow.new C:\WINDOW\Swinshow.dll
Description=Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version
Source=Paul Collins Startup list
[WinSig]
Confirmed=X
Filename=NetXP.exe
Description=Added by the BANKER-FN TROJAN!
Source=Paul Collins Startup list
[winsock]
Confirmed=X
Filename=svch0st.exe
Description=Added by the SAGE-A WORM!
Source=Paul Collins Startup list
[winsock2]
Confirmed=X
Filename=netsvr.exe
Description=Added by the AGOBOT.LY WORM!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=SDJOIJE.EXE
Description=Added by the SPYBOT.DR TROJAN!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=MIRC32.exe
Description=Added by the SPYBUZZ TROJAN!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=kgzgjkpcw.exe
Description=Added by the SDBOT.T TROJAN!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=ZONEALARM.EXE
Description=Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=WINCFG.SCR
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=winupdate.exe
Description=Added by the SPYBOT-BX WORM!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=SPOLSV.EXE
Description=Added by the SPYBOT-CM WORM!
Source=Paul Collins Startup list
[Winsock2 driver]
Confirmed=X
Filename=Zonealarmupdate.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[Winsock2.dll]
Confirmed=X
Filename=WINLODR.SCR
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Winsock32 driver]
Confirmed=X
Filename=Testing.exe
Description=Added by the SPYBOT.B WORM!
Source=Paul Collins Startup list
[Winsock32 driver]
Confirmed=X
Filename=lcd.exe
Description=Added by the SPYBOT.B WORM!
Source=Paul Collins Startup list
[Winsock32 driver]
Confirmed=X
Filename=Sdjoije.exe
Description=Added by the SPYBOT.B WORM!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=win32server.scr
Description=Added by the HACARMY TROJAN!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=sp2XPupdate.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=win32server.exe
Description=Added by the BACKDOOR-AZV TROJAN!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=ZoneAlarmPr0.exe
Description=Added by the HACKARMY-B TROJAN!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=ZoneLockup.exe
Description=Added by the HACARMY.D TROJAN!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=win32server.exe
Description=Added by the HACARMY.F TROJAN!
Source=Paul Collins Startup list
[Winsock32driver]
Confirmed=X
Filename=winXPupdate.exe
Description=Added by the HACKARMY.9728 TROJAN!
Source=Paul Collins Startup list
[winsockdriver]
Confirmed=X
Filename=tskmg.exe
Description=Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!
Source=Paul Collins Startup list
[winsockdriver]
Confirmed=X
Filename=winsock2.2.exe
Description=Added by a variant of the SPYBOT WORM!
Source=Paul Collins Startup list
[WinSocketComponent]
Confirmed=X
Filename=nthost.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[WinSPF]
Confirmed=X
Filename=windrv32.exe
Description=Added by the MYDOOM.T WORM!
Source=Paul Collins Startup list
[WinSPF]
Confirmed=X
Filename=winspf32.exe
Description=Added by the MYDOOM.S WORM!
Source=Paul Collins Startup list
[Winspl]
Confirmed=X
Filename=winsplx.exe
Description=Added by a variant of the TROLL-A TROJAN!
Source=Paul Collins Startup list
[Winspool]
Confirmed=X
Filename=spoolsvr.exe
Description=Added by a variant of the SDBOT WORM!
Source=Paul Collins Startup list
[WinSrv]
Confirmed=X
Filename=kn0x.exe
Description=Added by the HOBBIT.F WORM!
Source=Paul Collins Startup list
[WinSrv]
Confirmed=X
Filename=SHIZZLE.EXE
Description=Added by the HOBBIT.C WORM!
Source=Paul Collins Startup list
[Winsrv]
Confirmed=X
Filename=winsrv.exe
Description=Added by the OPASERV.T WORM!
Source=Paul Collins Startup list
[WinStart]
Confirmed=X
Filename=WinStart.exe
Description=From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
Source=Paul Collins Startup list
[WinStart]
Confirmed=X
Filename=Wscript.exe WinStart.vbs
Description=Added by the CIAN.C WORM!
Source=Paul Collins Startup list
[WinStart]
Confirmed=X
Filename=winstart32.exe
Description=Added by the PUROL WORM!
Source=Paul Collins Startup list
[WinStart]
Confirmed=X
Filename=WinStart.pif
Description=Added by the CONE.E WORM!
Source=Paul Collins Startup list
[WinStart001]
Confirmed=X
Filename=WinStart001.exe
Description=From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
Source=Paul Collins Startup list
[WinStart001.EXE]
Confirmed=X
Filename=WinStart001.exe
Description=From IGetNet
- turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
Source=Paul Collins Startup list
[Winsta~1]
Confirmed=X
Filename=winsta~1.exe
Description=