home *** CD-ROM | disk | FTP | other *** search
/ PC World Komputer 2010 April / PCWorld0410.iso / redakcyjne / programy / SpyBot Search Destroy 1.6.1.38 Beta / spybotsd-1.6.1.38.exe / {app} / Includes / Startup.tnfo < prev    next >
Encoding:
Spybot Search'n'Destroy process data  |  2007-09-19  |  3.7 MB  |  100,995 lines

Text Truncated. Only the first 1MB is shown below. Download the file for the complete contents.
  1. []
  2. Number=1
  3. Confirmed=X
  4. Filename=system32.exe
  5. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotku.html" target=_blank>AGOBOT-KU</a> WORM! Note - has a blank entry under the Startup Item/Name field
  6. Source=Paul Collins Startup list
  7.  
  8. []
  9. Number=2
  10. Confirmed=X
  11. Filename=pathex.exe
  12. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmkmoosea.html" target="_blank">MKMOOSE-A</a> WORM! Note - has a blank entry under the Startup Item/Name field
  13. Source=Paul Collins Startup list
  14.  
  15. []
  16. Number=3
  17. Confirmed=X
  18. Filename=svchost.exe
  19. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelfux.html" target="_blank">DELF-UX</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
  20. Source=Paul Collins Startup list
  21.  
  22. []
  23. Number=4
  24. Confirmed=X
  25. Filename=MSPF.EXE
  26. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
  27. Source=Paul Collins Startup list
  28.  
  29. []
  30. Number=5
  31. Confirmed=X
  32. Filename=dllvirtual.exe
  33. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdadobraiw.html" target="_blank">DADOBRA-IW</a> TROJAN! Note - has a blank entry under the Startup Item/Name field
  34. Source=Paul Collins Startup list
  35.  
  36. []
  37. Number=6
  38. Confirmed=X
  39. Filename=dllvirtual.dll
  40. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdadobraiw.html" target="_blank">DADOBRA-IW</a> TROJAN! Note - has a blank entry under the Startup Item/Name field
  41. Source=Paul Collins Startup list
  42.  
  43. []
  44. Number=7
  45. Confirmed=X
  46. Filename=dllvirtual.js
  47. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdadobraiw.html" target="_blank">DADOBRA-IW</a> TROJAN! Note - has a blank entry under the Startup Item/Name field
  48. Source=Paul Collins Startup list
  49.  
  50. [ SystemBoot]
  51. Number=8
  52. Confirmed=X
  53. Filename=services.exe
  54. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsoberq.html" target="_blank">SOBER-Q</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Help\Help subfolder of the Windows or Winnt folder
  55. Source=Paul Collins Startup list
  56.  
  57. [ WinCheck]
  58. Number=9
  59. Confirmed=X
  60. Filename=services.exe
  61. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sobers.html" target=_blank>SOBER-S</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatus\Microsoft" subfolder of the Windows or Winnt folder
  62. Source=Paul Collins Startup list
  63.  
  64. [ Windows]
  65. Number=10
  66. Confirmed=X
  67. Filename=services.exe
  68. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-111915-0848-99" target=_blank>SOBER.X</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder
  69. Source=Paul Collins Startup list
  70.  
  71. [ WinStart]
  72. Number=11
  73. Confirmed=X
  74. Filename=services.exe
  75. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050210-2339-99" target="_blank">SOBER.O</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection Wizard\Status subfolder of the Windows or Winnt folder
  76. Source=Paul Collins Startup list
  77.  
  78. [ winsystem.sys]
  79. Number=12
  80. Confirmed=X
  81. Filename=smss.exe
  82. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022023-0454-99" target=_blank>SOBER.K</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/smss/" target=_blank>smss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagent\win32 subfolder of the Winnt or Windows folder
  83. Source=Paul Collins Startup list
  84.  
  85. [!1_pgaccount]
  86. Number=13
  87. Confirmed=Y
  88. Filename=pgaccount.exe
  89. Description=DiamondCS <a href="http://www.diamondcs.com.au/processguard/" target=_blank>ProcessGuard</a> security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
  90. Source=Paul Collins Startup list
  91.  
  92. [!1_ProcessGuard_Startup]
  93. Number=14
  94. Confirmed=Y
  95. Filename=procguard.exe
  96. Description=DiamondCS <a href="http://www.diamondcs.com.au/processguard/" target=_blank>ProcessGuard</a> security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks
  97. Source=Paul Collins Startup list
  98.  
  99. [!AVG Anti-Spyware]
  100. Number=15
  101. Confirmed=U
  102. Filename=avgas.exe
  103. Description=Part of <a href="http://www3.grisoft.com/doc/products-avg-anti-spyware/us/crp/0" target="_blank">AVG Anti-Spyware</a> from Grisoft
  104. Source=Paul Collins Startup list
  105.  
  106. [!ewido]
  107. Number=16
  108. Confirmed=U
  109. Filename=ewido.exe
  110. Description=Part of <a href="http://www.ewido.net/en/" target="_blank">Ewido</a> anti-spyware
  111. Source=Paul Collins Startup list
  112.  
  113. [!NoLoad]
  114. Number=17
  115. Confirmed=N
  116. Filename=winrecon.exe
  117. Description=<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winrecon/" target="_blank">WinRecon</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  118. Source=Paul Collins Startup list
  119.  
  120. [$EnterNet]
  121. Number=18
  122. Confirmed=?
  123. Filename=Enternet.exe
  124. Description=Connection manager for the EnterNet ISP. You can also use <a href="http://user.cs.tu-berlin.de/~normanb/" target="_blank">RASPPOE</a>
  125. Source=Paul Collins Startup list
  126.  
  127. [$sys$cmp]
  128. Number=19
  129. Confirmed=X
  130. Filename=$sys$xp.exe
  131. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-111015-0804-99" target=_blank>RYKNOS.B</a> TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
  132. Source=Paul Collins Startup list
  133.  
  134. [$sys$crash]
  135. Number=20
  136. Confirmed=X
  137. Filename=$sys$sonyTimer.exe
  138. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  139. Source=Paul Collins Startup list
  140.  
  141. [$sys$crash]
  142. Number=21
  143. Confirmed=X
  144. Filename=$sys$sos$sys$.exe
  145. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  146. Source=Paul Collins Startup list
  147.  
  148. [$sys$crash]
  149. Number=22
  150. Confirmed=X
  151. Filename=$sys$WeLoveMcCOL.exe
  152. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  153. Source=Paul Collins Startup list
  154.  
  155. [$sys$drv]
  156. Number=23
  157. Confirmed=X
  158. Filename=$sys$drv.exe
  159. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-111012-2048-99" target=_blank>RYKNOS</a> TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
  160. Source=Paul Collins Startup list
  161.  
  162. [$sys$momomomochin]
  163. Number=24
  164. Confirmed=X
  165. Filename=$sys$sonyTimer.exe
  166. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  167. Source=Paul Collins Startup list
  168.  
  169. [$sys$momomomochin]
  170. Number=25
  171. Confirmed=X
  172. Filename=$sys$sos$sys$.exe
  173. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  174. Source=Paul Collins Startup list
  175.  
  176. [$sys$momomomochin]
  177. Number=26
  178. Confirmed=X
  179. Filename=$sys$WeLoveMcCOL.exe
  180. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  181. Source=Paul Collins Startup list
  182.  
  183. [$sys$umaiyo]
  184. Number=27
  185. Confirmed=X
  186. Filename=$sys$sonyTimer.exe
  187. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  188. Source=Paul Collins Startup list
  189.  
  190. [$sys$umaiyo]
  191. Number=28
  192. Confirmed=X
  193. Filename=$sys$sos$sys$.exe
  194. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  195. Source=Paul Collins Startup list
  196.  
  197. [$sys$umaiyo]
  198. Number=29
  199. Confirmed=X
  200. Filename=$sys$WeLoveMcCOL.exe
  201. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120709-5703-99" target=_blank>WELOMOCH</a> TROJAN!
  202. Source=Paul Collins Startup list
  203.  
  204. [$Volumouse$]
  205. Number=30
  206. Confirmed=U
  207. Filename=volumouse.exe
  208. Description=<a href="http://www.nirsoft.net/utils/volumouse.html" target="_blank">Volumouse</a> from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"
  209. Source=Paul Collins Startup list
  210.  
  211. [$WindowsRegKey%update]
  212. Number=31
  213. Confirmed=X
  214. Filename=IEXPLORE.EXE
  215. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotez.html" target=_blank>RBOT-EZ</a> WORM! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  216. Source=Paul Collins Startup list
  217.  
  218. [%cmpmixtitle%]
  219. Number=32
  220. Confirmed=N
  221. Filename=%cmpmixstr%
  222. Description=<font color="#FF0000">Possibly related to C-Media Mixer Control panel?</font>
  223. Source=Paul Collins Startup list
  224.  
  225. [%FP%012-L2TP fts.exe]
  226. Number=33
  227. Confirmed=N
  228. Filename=fts.exe
  229. Description=012.Net.il Israeli ISP software front-end
  230. Source=Paul Collins Startup list
  231.  
  232. [%FP%012-L2TP FWPortal.exe]
  233. Number=34
  234. Confirmed=U
  235. Filename=FWPortal.exe
  236. Description=012.Net.il Israeli ISP dial-up software
  237. Source=Paul Collins Startup list
  238.  
  239. [%FP%1776 Internet fts.exe]
  240. Number=35
  241. Confirmed=N
  242. Filename=fts.exe
  243. Description=1776 Internet US ISP software ISP software front-end
  244. Source=Paul Collins Startup list
  245.  
  246. [%FP%1776 Internet FWPortal.exe]
  247. Number=36
  248. Confirmed=U
  249. Filename=FWPortal.exe
  250. Description=1776 Internet US ISP dial-up software
  251. Source=Paul Collins Startup list
  252.  
  253. [%FP%Barak013 fts.exe]
  254. Number=37
  255. Confirmed=N
  256. Filename=fts.exe
  257. Description=Barak013 Israeli ISP software front-end
  258. Source=Paul Collins Startup list
  259.  
  260. [%FP%Barak013 FWPortal.exe]
  261. Number=38
  262. Confirmed=U
  263. Filename=FWPortal.exe
  264. Description=Barak013 Israeli ISP dial-up software
  265. Source=Paul Collins Startup list
  266.  
  267. [%FP%Friendly fts.exe]
  268. Number=39
  269. Confirmed=N
  270. Filename=fts.exe
  271. Description=Friendly ISP software front-end
  272. Source=Paul Collins Startup list
  273.  
  274. [(*)API Machine]
  275. Number=40
  276. Confirmed=X
  277. Filename=winSOCKS.exe
  278. Description=Homepage hijacker, see <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winsocks/" target="_blank">here</a> (* = any digit)
  279. Source=Paul Collins Startup list
  280.  
  281. [(*)Run]
  282. Number=41
  283. Confirmed=X
  284. Filename=win32API.exe
  285. Description=Homepage hijacker, see <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/win32api/" target="_blank">here</a> (* = any digit)
  286. Source=Paul Collins Startup list
  287.  
  288. [(default)]
  289. Number=42
  290. Confirmed=X
  291. Filename=[random filename].exe
  292. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-032319-2209-99" target="_blank">BLACKMAL</a> WORM!
  293. Source=Paul Collins Startup list
  294.  
  295. [(default)]
  296. Number=43
  297. Confirmed=X
  298. Filename=rundll32.exe [path] Zykheptd.dll
  299. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-022116-5404-99" target=_blank>HESIVE.B</a> TROJAN!
  300. Source=Paul Collins Startup list
  301.  
  302. [(L4r1$$4) (4nt1) (V1ruz)]
  303. Number=44
  304. Confirmed=X
  305. Filename=SP00Lsv32.pif
  306. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030222-1459-99" target=_blank>ASSIRAL.B</a> WORM!
  307. Source=Paul Collins Startup list
  308.  
  309. [*JanisRuckenbrodII]
  310. Number=45
  311. Confirmed=X
  312. Filename=janis.com
  313. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-012114-5256-99" target="_blank">POPS</a> WORM!
  314. Source=Paul Collins Startup list
  315.  
  316. [*Microsoft Update]
  317. Number=46
  318. Confirmed=X
  319. Filename=ctxma.exe
  320. Description=Added by the <a href="http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml" target="_blank">STMU</a> TROJAN!
  321. Source=Paul Collins Startup list
  322.  
  323. [*Microsoft Update]
  324. Number=47
  325. Confirmed=X
  326. Filename=cxma.exe
  327. Description=Added by the <a href="http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml" target="_blank">STMU</a> TROJAN!
  328. Source=Paul Collins Startup list
  329.  
  330. [*Microsoft Update]
  331. Number=48
  332. Confirmed=X
  333. Filename=wstcl.exe
  334. Description=Added by the <a href="http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml" target="_blank">STMU</a> TROJAN!
  335. Source=Paul Collins Startup list
  336.  
  337. [*Microsoft Update]
  338. Number=49
  339. Confirmed=X
  340. Filename=wucxt.exe
  341. Description=Added by the <a href="http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml" target="_blank">STMU</a> TROJAN!
  342. Source=Paul Collins Startup list
  343.  
  344. [*Microsoft Update]
  345. Number=50
  346. Confirmed=X
  347. Filename=wuytc.exe
  348. Description=Added by the <a href="http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml" target="_blank">STMU</a> TROJAN!
  349. Source=Paul Collins Startup list
  350.  
  351. [*MS Setup]
  352. Number=51
  353. Confirmed=X
  354. Filename=[random filename]
  355. Description=Virtumondo adware, also known as the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99" target=_blank>VUNDO</a> TROJAN!
  356. Source=Paul Collins Startup list
  357.  
  358. [*Security Center]
  359. Number=52
  360. Confirmed=X
  361. Filename=secctr.exe
  362. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BRO&VSect=P" target=_blank>SDBOT.BRO</a> WORM!
  363. Source=Paul Collins Startup list
  364.  
  365. [*StateMgr]
  366. Number=53
  367. Confirmed=Y
  368. Filename=statemgr.exe
  369. Description=Windows ME default for System Restore. Do NOT disable!
  370. Source=Paul Collins Startup list
  371.  
  372. [*windows update]
  373. Number=54
  374. Confirmed=X
  375. Filename=wrauclt.exe
  376. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqu.html" target=_blank>RBOT-QU</a> WORM!
  377. Source=Paul Collins Startup list
  378.  
  379. [*windows update]
  380. Number=55
  381. Confirmed=X
  382. Filename=wuanclt.exe
  383. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpg.html" target=_blank>RBOT-PG</a> WORM!
  384. Source=Paul Collins Startup list
  385.  
  386. [*windows update]
  387. Number=56
  388. Confirmed=X
  389. Filename=wuaucrlt.exe
  390. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-010714-2915-99" target=_blank>SPYBOT.HUR</a> WORM!
  391. Source=Paul Collins Startup list
  392.  
  393. [*windows update]
  394. Number=57
  395. Confirmed=X
  396. Filename=wuraclt.exe
  397. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpo.html" target=_blank>RBOT-PO</a> WORM!
  398. Source=Paul Collins Startup list
  399.  
  400. [*windows update]
  401. Number=58
  402. Confirmed=X
  403. Filename=wurauclt.exe
  404. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotsy.html" target=_blank>RBOT-SY</a> WORM!
  405. Source=Paul Collins Startup list
  406.  
  407. [*windows update]
  408. Number=59
  409. Confirmed=X
  410. Filename=wsctl.exe
  411. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.PR" target="_blank">SPYBOT.PR</a> WORM!
  412. Source=Paul Collins Startup list
  413.  
  414. [*windows update]
  415. Number=60
  416. Confirmed=X
  417. Filename=wkmst.exe
  418. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.AVD" target="_blank">SDBOT.AVD</a> WORM!
  419. Source=Paul Collins Startup list
  420.  
  421. [*windows update]
  422. Number=61
  423. Confirmed=X
  424. Filename=wscxt.exe
  425. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AOS&VSect=P" target=_blank>RBOT.AOS</a> WORM!
  426. Source=Paul Collins Startup list
  427.  
  428. [*windows update]
  429. Number=62
  430. Confirmed=X
  431. Filename=waurclt.exe
  432. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  433. Source=Paul Collins Startup list
  434.  
  435. [*Windows [filename] Checker]
  436. Number=63
  437. Confirmed=X
  438. Filename=[filename]
  439. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32kedebeb.html" target=_blank>KEDEBE-B</a> WORM!
  440. Source=Paul Collins Startup list
  441.  
  442. [*WindowsAudio]
  443. Number=64
  444. Confirmed=X
  445. Filename=systemupd.exe
  446. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentth.html" target=_blank>AGENT-TH</a> WORM!
  447. Source=Paul Collins Startup list
  448.  
  449. [*WinLogon]
  450. Number=65
  451. Confirmed=X
  452. Filename=[trojan path] ren time:[random number]
  453. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99" target=_blank>VUNDO</a> TROJAN!
  454. Source=Paul Collins Startup list
  455.  
  456. [*winstats]
  457. Number=66
  458. Confirmed=X
  459. Filename=winstats.exe
  460. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-090216-3057-99" target=_blank>GARGAFX</a> TROJAN!
  461. Source=Paul Collins Startup list
  462.  
  463. [*wuauclt.exe]
  464. Number=67
  465. Confirmed=X
  466. Filename=w****.exe [* = random char]
  467. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotug.html" target="_blank">RBOT-UG</a> WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
  468. Source=Paul Collins Startup list
  469.  
  470. [,main drive Loader]
  471. Number=68
  472. Confirmed=X
  473. Filename=wininfo.exe
  474. Description=Suspected malware as it appears in 3 different registry locations - see <a href="http://forums.techguy.org/t151017/s.html" target="_blank"> here</a>
  475. Source=Paul Collins Startup list
  476.  
  477. [..]
  478. Number=69
  479. Confirmed=X
  480. Filename=ABC2007.exe
  481. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadrash.html" target="_blank">DLOADR-ASH</a> TROJAN!
  482. Source=Paul Collins Startup list
  483.  
  484. [.mscdr]
  485. Number=70
  486. Confirmed=X
  487. Filename=lassa.exe
  488. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-101212-0903-99" target=_blank>WEBUS.C</a> TROJAN!
  489.  
  490. Source=Paul Collins Startup list
  491.  
  492. [.mscdr]
  493. Number=71
  494. Confirmed=X
  495. Filename=lsvchost.exe
  496. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-111216-2213-99" target=_blank>WEBUS.D</a> TROJAN!
  497. Source=Paul Collins Startup list
  498.  
  499. [.mscdsr]
  500. Number=72
  501. Confirmed=X
  502. Filename=lsvchost.exe
  503. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorcr.html" target=_blank>CR</a> TROJAN!
  504. Source=Paul Collins Startup list
  505.  
  506. [.mscsbl]
  507. Number=73
  508. Confirmed=X
  509. Filename=svhost.exe
  510. Description=Added by the <a href="http://vil.mcafeesecurity.com/vil/content/v_130850.htm" target=_blank>CMQ</a> TROJAN!
  511. Source=Paul Collins Startup list
  512.  
  513. [.msfupdate]
  514. Number=74
  515. Confirmed=X
  516. Filename=msveup.exe
  517. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040411-1529-99" target=_blank>ALLOCUP.A</a> WORM!
  518. Source=Paul Collins Startup list
  519.  
  520. [.mssecure]
  521. Number=75
  522. Confirmed=X
  523. Filename=mssecure.exe
  524. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=DDOS_BOXED.X&VSect=P" target=_blank>DDOS_BOXED.X</a> TROJAN!
  525. Source=Paul Collins Startup list
  526.  
  527. [.NET config]
  528. Number=76
  529. Confirmed=?
  530. Filename=sysmon32.exe
  531. Description=<font color="#FF0000">??</font>
  532. Source=Paul Collins Startup list
  533.  
  534. [.norton]
  535. Number=77
  536. Confirmed=X
  537. Filename=rchost.exe
  538. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojboxeda.html" target=_blank>BOXED-A</a> TROJAN!
  539. Source=Paul Collins Startup list
  540.  
  541. [.nvsvc]
  542. Number=78
  543. Confirmed=X
  544. Filename=smss.exe
  545. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbotfp.html" target=_blank>IRCBOT-FP</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/smss/" target=_blank>smss.exe</a> process which should not normally figure in Msconfig/Startup!
  546.  
  547. Source=Paul Collins Startup list
  548.  
  549. [.nvsvcb]
  550. Number=79
  551. Confirmed=X
  552. Filename=smssb.exe
  553. Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=57167" target="_blank">BOXED.CG</a> TROJAN!
  554. Source=Paul Collins Startup list
  555.  
  556. [.Prog]
  557. Number=80
  558. Confirmed=X
  559. Filename=services.exe
  560. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081700-2526-99" target="_blank">NEVEG.B</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081614-3605-99" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
  561. Source=Paul Collins Startup list
  562.  
  563. [.Prog]
  564. Number=81
  565. Confirmed=X
  566. Filename=winlogon.exe
  567. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081623-4258-99" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
  568. Source=Paul Collins Startup list
  569.  
  570. [.protected]
  571. Number=82
  572. Confirmed=X
  573. Filename=N/A
  574. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094215" target="_blank">Smitfraud</a> variant
  575. Source=Paul Collins Startup list
  576.  
  577. [.svchost]
  578. Number=83
  579. Confirmed=X
  580. Filename=CSRSS.EXE
  581. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051709-5609-99" target=_blank>WEBUS.F</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
  582. Source=Paul Collins Startup list
  583.  
  584. [.TEXTCONV]
  585. Number=84
  586. Confirmed=X
  587. Filename=csrss.exe
  588. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091409-4900-99" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  589. Source=Paul Collins Startup list
  590.  
  591. [.TEXTCONV]
  592. Number=85
  593. Confirmed=X
  594. Filename=lsass.exe
  595. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100519-0947-99" target=_blank>WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
  596. Source=Paul Collins Startup list
  597.  
  598. [.WMAudio]
  599. Number=86
  600. Confirmed=X
  601. Filename=csrss.exe
  602. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091409-4900-99" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  603. Source=Paul Collins Startup list
  604.  
  605. [.WMAudio]
  606. Number=87
  607. Confirmed=X
  608. Filename=lsass.exe
  609. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100519-0947-99" target=_blank>WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
  610. Source=Paul Collins Startup list
  611.  
  612. [/l:eng]
  613. Number=88
  614. Confirmed=N
  615. Filename=N/A
  616. Description=Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
  617. Source=Paul Collins Startup list
  618.  
  619. [000]
  620. Number=89
  621. Confirmed=U
  622. Filename=pit.exe
  623. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061617-2707-99" target="_blank">PrivateEye</a> surveillance software. Uninstall this software unless you put it there yourself
  624. Source=Paul Collins Startup list
  625.  
  626. [000hpdllhos]
  627. Number=90
  628. Confirmed=X
  629. Filename=hpdllhost.exe
  630. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target="_blank">LZIO.com</a> adware downloader
  631. Source=Paul Collins Startup list
  632.  
  633. [000StTHK]
  634. Number=91
  635. Confirmed=U
  636. Filename=000StTHK.exe
  637. Description=Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
  638. Source=Paul Collins Startup list
  639.  
  640. [0050726-007-i32-1]
  641. Number=92
  642. Confirmed=X
  643. Filename=0050726-007-i32-1.exe
  644. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanec.html" target=_blank>BANCBAN-EC</a> TROJAN!
  645. Source=Paul Collins Startup list
  646.  
  647. [00DSKSVR00]
  648. Number=93
  649. Confirmed=?
  650. Filename=desksaver.exe
  651. Description=Related to <a href="http://www.softstack.com/deskshield.html" target=_blank>Advanced Desktop Shield</a>
  652. Source=Paul Collins Startup list
  653.  
  654. [00DSKSVR01]
  655. Number=94
  656. Confirmed=?
  657. Filename=desksaver.exe
  658. Description=Related to <a href="http://www.softstack.com/deskshield.html" target=_blank>Advanced Desktop Shield</a>
  659. Source=Paul Collins Startup list
  660.  
  661. [00TCrdMain]
  662. Number=95
  663. Confirmed=Y
  664. Filename=TCrdMain.exe
  665. Description=Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
  666. Source=Paul Collins Startup list
  667.  
  668. [00THotkey]
  669. Number=96
  670. Confirmed=U
  671. Filename=00THotKey.exe
  672. Description=For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
  673. Source=Paul Collins Startup list
  674.  
  675. [0190 Warner]
  676. Number=97
  677. Confirmed=U
  678. Filename=WARN0190.EXE
  679. Description=Anti-dialer <a href="http://www.wt-rate.com/" target=_blank>program</a> (Germany)
  680. Source=Paul Collins Startup list
  681.  
  682. [0900 Warner]
  683. Number=98
  684. Confirmed=U
  685. Filename=WARN0900.EXE
  686. Description=Anti-dialer <a href="http://www.wt-rate.com/" target=_blank>program</a> (Germany)
  687. Source=Paul Collins Startup list
  688.  
  689. [0mcamcap]
  690. Number=99
  691. Confirmed=X
  692. Filename=0mcamcap.exe
  693. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcosiamh.html" target=_blank>COSIAM-H</a> TROJAN!
  694.  
  695. Source=Paul Collins Startup list
  696.  
  697. [0utlook Express]
  698. Number=100
  699. Confirmed=X
  700. Filename=*****.exe [* = random char]
  701. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotcc.html" target=_blank>RBOT-CC</a> WORM! Note the first letter is actually the digit "0" and not a capital "o"
  702. Source=Paul Collins Startup list
  703.  
  704. [1]
  705. Number=101
  706. Confirmed=X
  707. Filename=1.exe
  708. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-041515-1002-99" target=_blank>ESTEEMS</a> TROJAN!
  709. Source=Paul Collins Startup list
  710.  
  711. [1]
  712. Number=102
  713. Confirmed=X
  714. Filename=lsass.scr
  715. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-052411-0618-99" target=_blank>BANCOS.V</a> TROJAN!
  716.  
  717. Source=Paul Collins Startup list
  718.  
  719. [1]
  720. Number=103
  721. Confirmed=X
  722. Filename=svchost.scr
  723. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-052515-4611-99" target=_blank>BANCOS.X</a> TROJAN!
  724. Source=Paul Collins Startup list
  725.  
  726. [1111swapmgr.exe]
  727. Number=104
  728. Confirmed=X
  729. Filename=1111swapmgr.exe
  730. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdooric.html" target=_blank>IC</a> TROJAN!
  731. Source=Paul Collins Startup list
  732.  
  733. [123456]
  734. Number=105
  735. Confirmed=X
  736. Filename=rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl
  737. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-070209-4033-99" target="_blank">KITRO.C</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DANDI.A&VSect=T" target="_blank">DANDI.A</a>) WORM! 123456 can be any random 3 to 6 digit number
  738. Source=Paul Collins Startup list
  739.  
  740. [12Ghosts Popup-Killer]
  741. Number=106
  742. Confirmed=U
  743. Filename=12popup.exe
  744. Description=<a href="http://12ghosts.com/ghosts/popup.htm" target="_blank">12Ghosts Popup-Killer</a>
  745. Source=Paul Collins Startup list
  746.  
  747. [17779Proj2002]
  748. Number=107
  749. Confirmed=?
  750. Filename=N/A
  751. Description=<font color="#FF0000">??</font>
  752. Source=Paul Collins Startup list
  753.  
  754. [180adsolution]
  755. Number=108
  756. Confirmed=X
  757. Filename=180adsolution.exe
  758. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=180solutions.NCase&threatid=8869" target="_blank">NCase</a> adware
  759. Source=Paul Collins Startup list
  760.  
  761. [180ax]
  762. Number=109
  763. Confirmed=X
  764. Filename=180ax.exe
  765. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=180solutions.NCase&threatid=8869" target="_blank">NCase</a> adware
  766. Source=Paul Collins Startup list
  767.  
  768. [180ClientStubInstall]
  769. Number=110
  770. Confirmed=X
  771. Filename=stubinstaller****.exe [* = digit]
  772. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677" target="_blank">180Solutions</a> adware related
  773. Source=Paul Collins Startup list
  774.  
  775. [180ClientStubInstall]
  776. Number=111
  777. Confirmed=X
  778. Filename=[path to trojan]
  779. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677" target="_blank">180Solutions</a> adware related
  780. Source=Paul Collins Startup list
  781.  
  782. [180ClientStubInstall]
  783. Number=112
  784. Confirmed=X
  785. Filename=******.tmp [* = random digit/char]
  786. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677" target="_blank">180Solutions</a> adware related
  787. Source=Paul Collins Startup list
  788.  
  789. [196_150_ni]
  790. Number=113
  791. Confirmed=X
  792. Filename=196_150_ni.exe
  793. Description=WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see <a href="http://www.superadblocker.com/1/196_150_NI.EXE-5442.html" target="_blank">here</a>
  794. Source=Paul Collins Startup list
  795.  
  796. [197_150_ni_3]
  797. Number=114
  798. Confirmed=X
  799. Filename=197_150_ni_3.exe
  800. Description=WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see <a href="http://www.superadblocker.com/1/196_150_NI.EXE-5442.html" target="_blank">here</a>
  801. Source=Paul Collins Startup list
  802.  
  803. [1:]
  804. Number=115
  805. Confirmed=N
  806. Filename=hpdrv.exe
  807. Description=HP utility for monitoring when and how many recoveries have been done
  808. Source=Paul Collins Startup list
  809.  
  810. [1A:MacVisionTrayMonitor]
  811. Number=116
  812. Confirmed=N
  813. Filename=TrayMonitor.exe
  814. Description=Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
  815. Source=Paul Collins Startup list
  816.  
  817. [1A:Stardock MCP]
  818. Number=117
  819. Confirmed=Y
  820. Filename=mcpserver.exe
  821. Description=Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
  822. Source=Paul Collins Startup list
  823.  
  824. [1A:Stardock TrayMonitor]
  825. Number=118
  826. Confirmed=Y
  827. Filename=TrayServer.exe
  828. Description=For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
  829. Source=Paul Collins Startup list
  830.  
  831. [1CmailS]
  832. Number=119
  833. Confirmed=?
  834. Filename=NETMAIL.EXE
  835. Description=<font color="#FF0000">??</font>
  836. Source=Paul Collins Startup list
  837.  
  838. [1on1]
  839. Number=120
  840. Confirmed=X
  841. Filename=1on1.exe
  842. Description=Adult content dialler
  843. Source=Paul Collins Startup list
  844.  
  845. [1Srv32]
  846. Number=121
  847. Confirmed=U
  848. Filename=SpyAgent4.exe
  849. Description=SpyTech <a href="http://www.spytech-web.com/spyagent.shtml" target="_blank">SpyAgent</a> monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
  850. Source=Paul Collins Startup list
  851.  
  852. [1u7]
  853. Number=122
  854. Confirmed=X
  855. Filename=1u7.exe
  856. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmurbaca.html" target="_blank">MURBAC-A</a> TROJAN!
  857. Source=Paul Collins Startup list
  858.  
  859. [1Win32Cfg]
  860. Number=123
  861. Confirmed=U
  862. Filename=SpyBuddy.exe
  863. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-062611-4548-99" target=_blank>SpyBuddy</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  864. Source=Paul Collins Startup list
  865.  
  866. [1Win32Cfg]
  867. Number=124
  868. Confirmed=U
  869. Filename=Keyloggerpro.exe
  870. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-120711-4013-99" target=_blank>Keyloggerpro</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  871. Source=Paul Collins Startup list
  872.  
  873. [1WinCfg32]
  874. Number=125
  875. Confirmed=X
  876. Filename=WebMailSpy.exe
  877. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-062918-0745-99" target=_blank>WebMailSpy</a> spyware
  878. Source=Paul Collins Startup list
  879.  
  880. [2020Downloader]
  881. Number=126
  882. Confirmed=X
  883. Filename=mssvr.exe
  884. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=2020Search&threatid=13811" target="_blank">2020Search</a> Toolbar
  885. Source=Paul Collins Startup list
  886.  
  887. [252]
  888. Number=127
  889. Confirmed=X
  890. Filename=winmgr.exe
  891. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlegmirat.html" target=_blank>LEGMIR-AT</a> TROJAN!
  892. Source=Paul Collins Startup list
  893.  
  894. [27]
  895. Number=128
  896. Confirmed=X
  897. Filename=slsorve.exe
  898. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojslsorvea.html" target="_blank">SLSORVE-A</a> TROJAN!
  899. Source=Paul Collins Startup list
  900.  
  901. [27]
  902. Number=129
  903. Confirmed=X
  904. Filename=csrss32.exe
  905. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojslsorved.html" target=_blank>SLSORVE-D</a> TROJAN!
  906. Source=Paul Collins Startup list
  907.  
  908. [27]
  909. Number=130
  910. Confirmed=X
  911. Filename=msm32.exe
  912. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojslsorvee.html" target=_blank>SLSORVE-E</a> TROJAN!
  913. Source=Paul Collins Startup list
  914.  
  915. [2Search]
  916. Number=131
  917. Confirmed=X
  918. Filename=main.exe
  919. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-080302-3232-99" target="_blank">2Search</a> adware
  920. Source=Paul Collins Startup list
  921.  
  922. [2thousandbuck]
  923. Number=132
  924. Confirmed=X
  925. Filename=[path to file]
  926. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-110410-0039-99" target=_blank>RANKY.L</a> TROJAN!
  927. Source=Paul Collins Startup list
  928.  
  929. [2wSysTray]
  930. Number=133
  931. Confirmed=U
  932. Filename=2portalmon.exe
  933. Description=<a target="_blank" href="http://www.2wire.com/">2Wire</a> Homeportal user interface
  934. Source=Paul Collins Startup list
  935.  
  936. [32-bit Thunking service]
  937. Number=134
  938. Confirmed=X
  939. Filename=thunk32.exe
  940. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-021712-1032-99" target=_blank>DERDERO.A</a> WORM!
  941. Source=Paul Collins Startup list
  942.  
  943. [333]
  944. Number=135
  945. Confirmed=X
  946. Filename=svchost.exe
  947. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojjda.html" target="_blank">JD-A</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory
  948. Source=Paul Collins Startup list
  949.  
  950. [39ELTFH25Z8SKF]
  951. Number=136
  952. Confirmed=?
  953. Filename=Ezg1q5.exe
  954. Description=<font color="#FF0000">Seems to be associated with software by <a href="http://www.resplendence.com/docs/" target="_blank">Resplendence SP</a> ?</font>
  955. Source=Paul Collins Startup list
  956.  
  957. [3c1807pd]
  958. Number=137
  959. Confirmed=Y
  960. Filename=3cmlink.exe 3cpipe-3c1807pd
  961. Description=3Com WinModem driver. See <a href="http://modemsite.com/56k/winmodems.asp" target="_blank">here</a> for more WinModem information
  962. Source=Paul Collins Startup list
  963.  
  964. [3capplnk]
  965. Number=138
  966. Confirmed=Y
  967. Filename=3capplnk.exe
  968. Description=US Robotics Modem driver
  969. Source=Paul Collins Startup list
  970.  
  971. [3cdminic]
  972. Number=139
  973. Confirmed=N
  974. Filename=3CDMINIC.EXE
  975. Description=3Com DMI (DynamicAccess <u>D</u>esktop <u>M</u>anagement <u>I</u>nterface) Agent associated with 3Com network cards
  976. Source=Paul Collins Startup list
  977.  
  978. [3CM Link]
  979. Number=140
  980. Confirmed=Y
  981. Filename=3cmcnkw.exe
  982. Description=Required for a US Robotics WinModem as it provides the link to Windows - won't work without it
  983. Source=Paul Collins Startup list
  984.  
  985. [3Cmlink]
  986. Number=141
  987. Confirmed=Y
  988. Filename=3CmlinkW.exe
  989. Description=For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See <a href="http://modemsite.com/56k/winmodems.asp" target="_blank">here</a> for more WinModem information
  990. Source=Paul Collins Startup list
  991.  
  992. [3ComDMIAgent]
  993. Number=142
  994. Confirmed=N
  995. Filename=3CDMINIC.EXE
  996. Description=3Com DMI (DynamicAccess <u>D</u>esktop <u>M</u>anagement <u>I</u>nterface) Agent associated with 3Com network cards
  997. Source=Paul Collins Startup list
  998.  
  999. [3cpipe-USRpdA]
  1000. Number=143
  1001. Confirmed=Y
  1002. Filename=USRmlnkA.exe
  1003. Description=Modem driver files from US Robotics
  1004. Source=Paul Collins Startup list
  1005.  
  1006. [3D Text]
  1007. Number=144
  1008. Confirmed=X
  1009. Filename=3D Text.scr
  1010. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102412-2855-99" target="_blank"> JERMY.A</a> WORM!
  1011. Source=Paul Collins Startup list
  1012.  
  1013. [3Deep Control Panel]
  1014. Number=145
  1015. Confirmed=U
  1016. Filename=3DeepCTL.EXE
  1017. Description=Now superseeded by <a href="http://www.colorwizzard.com/" target="_blank">ColorWizzard</a> - 3Deep corrected lighting, shading and color for all your 2D and 3D games
  1018. Source=Paul Collins Startup list
  1019.  
  1020. [3Dfx Acc]
  1021. Number=146
  1022. Confirmed=X
  1023. Filename=GFXACC.EXE
  1024. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-030413-4714-99" target="_blank">GIBE</a> WORM!
  1025.  
  1026. Source=Paul Collins Startup list
  1027.  
  1028. [3dfx Task Manager]
  1029. Number=147
  1030. Confirmed=N
  1031. Filename=3dfxMan.exe
  1032. Description=System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
  1033. Source=Paul Collins Startup list
  1034.  
  1035. [3dfx Tools]
  1036. Number=148
  1037. Confirmed=Y
  1038. Filename=3dfxCmn.dll
  1039. Description=Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
  1040. Source=Paul Collins Startup list
  1041.  
  1042. [3dfxv2ps.dll]
  1043. Number=149
  1044. Confirmed=Y
  1045. Filename=3dfxv2ps.dll
  1046. Description=Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
  1047. Source=Paul Collins Startup list
  1048.  
  1049. [3Dlabs Taskbar Display Manager]
  1050. Number=150
  1051. Confirmed=?
  1052. Filename=3DLman.exe
  1053. Description=3DLabs graphics driver related. <font color="#FF0000"> System Tray access to display settings?</font>
  1054. Source=Paul Collins Startup list
  1055.  
  1056. [3DLabsHelperDemon]
  1057. Number=151
  1058. Confirmed=U
  1059. Filename=3dldemon.exe
  1060. Description=Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
  1061. Source=Paul Collins Startup list
  1062.  
  1063. [3DMouse.EXE]
  1064. Number=152
  1065. Confirmed=Y
  1066. Filename=3DMouse.EXE
  1067. Description=Dritek System Inc. 3D Mouse driver
  1068. Source=Paul Collins Startup list
  1069.  
  1070. [3d_sound]
  1071. Number=153
  1072. Confirmed=X
  1073. Filename=3d_sound.exe
  1074. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojriadosa.html" target=_blank>RIADOS-A</a> TROJAN!
  1075. Source=Paul Collins Startup list
  1076.  
  1077. [3qdctl.exe]
  1078. Number=154
  1079. Confirmed=U
  1080. Filename=3qdctl.exe
  1081. Description=Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
  1082. Source=Paul Collins Startup list
  1083.  
  1084. [3ware 3DM]
  1085. Number=155
  1086. Confirmed=Y
  1087. Filename=3dm.exe
  1088. Description=Monitors status of the disk array on 3ware IDE RAID controllers
  1089. Source=Paul Collins Startup list
  1090.  
  1091. [456655]
  1092. Number=156
  1093. Confirmed=X
  1094. Filename=explorer.exe
  1095. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbifrosede.html" target=_blank>BIFROSE-DE</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder
  1096. Source=Paul Collins Startup list
  1097.  
  1098. [4da92ad5.exe]
  1099. Number=157
  1100. Confirmed=X
  1101. Filename=4da92ad5.exe
  1102. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadrwz.html" target="_blank">DLOADR-WZ</a> TROJAN!
  1103. Source=Paul Collins Startup list
  1104.  
  1105. [4wd!!!]
  1106. Number=158
  1107. Confirmed=X
  1108. Filename=Natal!.pif
  1109. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.AI" target="_blank">OPASERV.AI</a> WORM!
  1110. Source=Paul Collins Startup list
  1111.  
  1112. [5-1-61-96]
  1113. Number=159
  1114. Confirmed=X
  1115. Filename=members-area.exe
  1116. Description=Adult content dialler
  1117. Source=Paul Collins Startup list
  1118.  
  1119. [5-2-46-112]
  1120. Number=160
  1121. Confirmed=X
  1122. Filename=5-2-46-112.exe
  1123. Description=Adult content pop-up dialler. Removal instructions <a href="http://groups.google.com/group/microsoft.public.windowsxp.general/browse_frm/thread/eb788b5ae71219be/b143744d5a592352?hl=en&lr=&ie=UTF-8&oe=UTF8&safe=off&rnum=9&prev=/groups%3Fq%3D5-2-46-112.exe%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF8%26safe%3Doff%26selm%3D1e10cd61.0203201743.78f51cfa%40posting.google.com%26rnum%3D9#b143744d5a592352" target="_blank">here</a>
  1124. Source=Paul Collins Startup list
  1125.  
  1126. [55278]
  1127. Number=161
  1128. Confirmed=X
  1129. Filename=grepclient1.exe
  1130. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlineages.html" target=_blank>LINEAGE-S</a> TROJAN!
  1131. Source=Paul Collins Startup list
  1132.  
  1133. [5p4m]
  1134. Number=162
  1135. Confirmed=X
  1136. Filename=[path to trojan]
  1137. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlitebotc.html" target=_blank>LITEBOT-C</a> TROJAN!
  1138. Source=Paul Collins Startup list
  1139.  
  1140. [5whgue21]
  1141. Number=163
  1142. Confirmed=X
  1143. Filename=5whgue21.exe
  1144. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  1145. Source=Paul Collins Startup list
  1146.  
  1147. [666]
  1148. Number=164
  1149. Confirmed=X
  1150. Filename=Ska.exe
  1151. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpipes.html" target=_blank>PIPES</a> TROJAN!
  1152. Source=Paul Collins Startup list
  1153.  
  1154. [678]
  1155. Number=165
  1156. Confirmed=X
  1157. Filename=lsas32.exe
  1158. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojslsorveb.html" target=_blank>SLSORVE-B</a> TROJAN!
  1159. Source=Paul Collins Startup list
  1160.  
  1161. [98D0CE0C16B1]
  1162. Number=166
  1163. Confirmed=X
  1164. Filename=rundll32.exe D0CE0C16B1, D0CE0C16B1
  1165. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BrowserAid&threatid=3342" target="_blank">BrowserAid/BrowserPal</a> foistware
  1166. Source=Paul Collins Startup list
  1167.  
  1168. [9m]
  1169. Number=167
  1170. Confirmed=X
  1171. Filename=winlog0n.exe
  1172. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlegmiraqk.html" target="_blank">LEGMIR-AQK</a> TROJAN!
  1173. Source=Paul Collins Startup list
  1174.  
  1175. [9xadiras]
  1176. Number=168
  1177. Confirmed=Y
  1178. Filename=9xadiras.exe
  1179. Description=<a href="http://www.alliedtelesyn.co.uk/en-gb/" target=_blank>Allied Telesyn</a> AT series router/modem related - apparently required
  1180. Source=Paul Collins Startup list
  1181.  
  1182. [9xHtProtect]
  1183. Number=169
  1184. Confirmed=X
  1185. Filename=AVprotect9x.exe
  1186. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031015-0018-99" target="_blank">NETSKY.M</a> WORM!
  1187. Source=Paul Collins Startup list
  1188.  
  1189. [;Rundll]
  1190. Number=170
  1191. Confirmed=X
  1192. Filename=[filename]
  1193. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PWSLEGMIR.E" target="_blank">PWSLEGMIR.E</a> TROJAN!
  1194. Source=Paul Collins Startup list
  1195.  
  1196. [?ekio Startups]
  1197. Number=171
  1198. Confirmed=X
  1199. Filename=?nksvc32.exe
  1200. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotov.html" target=_blank>AGOBOT-OV</a> WORM where ? is a random character
  1201.  
  1202. Source=Paul Collins Startup list
  1203.  
  1204. [@]
  1205. Number=172
  1206. Confirmed=X
  1207. Filename=regedit -s ..win.dll
  1208. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-100111-0931-99" target="_blank">SEEKER.K</a> TROJAN!
  1209. Source=Paul Collins Startup list
  1210.  
  1211. [@Hoc Toolbar]
  1212. Number=173
  1213. Confirmed=N
  1214. Filename=AtHoc.exe
  1215. Description=One-click activated browsing toolbar used by various web-sites. See <a href="http://siliconvalley.internet.com/news/article.php/3531_479951" target="_blank">here</a> for more info
  1216. Source=Paul Collins Startup list
  1217.  
  1218. [@loha]
  1219. Number=174
  1220. Confirmed=N
  1221. Filename=reminder.exe
  1222. Description=Registration reminder for <a href="http://www.pcworld.com/downloads/file_description/0,fid,6581,00.asp" target="_blank">@loha@home</a> E-mail utility
  1223. Source=Paul Collins Startup list
  1224.  
  1225. [@tour_ww]
  1226. Number=175
  1227. Confirmed=X
  1228. Filename=@tour_ww[1].exe
  1229. Description=Adult content dialler
  1230. Source=Paul Collins Startup list
  1231.  
  1232. [a]
  1233. Number=176
  1234. Confirmed=X
  1235. Filename=a.exe
  1236. Description=Commercials file that registers itself in the system registry and redirects IE to a certain commercial website
  1237. Source=Paul Collins Startup list
  1238.  
  1239. [a]
  1240. Number=177
  1241. Confirmed=X
  1242. Filename=jesse.exe
  1243. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32meloa.html" target=_blank>MELO-A</a> WORM!
  1244. Source=Paul Collins Startup list
  1245.  
  1246. [A New Windows Updater]
  1247. Number=178
  1248. Confirmed=X
  1249. Filename=w32NTupdt.exe
  1250. Description=Added by <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042420-4303-99" target="_blank">MYTOB.BM</a> WORM!
  1251. Source=Paul Collins Startup list
  1252.  
  1253. [A Verizon App]
  1254. Number=179
  1255. Confirmed=U
  1256. Filename=VERIZO~1.EXE
  1257. Description=Part of <a href="http://www22.verizon.com/" target="_blank">Verizon</a> Online Support Manager
  1258. Source=Paul Collins Startup list
  1259.  
  1260. [a-squared]
  1261. Number=180
  1262. Confirmed=U
  1263. Filename=a2guard.exe
  1264. Description=<a href="http://www.emsisoft.com/en/" target=_blank>a-Squared</a> antitrojan - can be run on demand but necessary in Startup if you prefer the aâ–“ 'Background Guard' real time protection feature
  1265. Source=Paul Collins Startup list
  1266.  
  1267. [a-winpoet-service]
  1268. Number=181
  1269. Confirmed=Y
  1270. Filename=winpppoverethernet.exe
  1271. Description=WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read <a href="http://www.finepoint.com/winpoet.html" target="_blank">here</a>. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
  1272. Source=Paul Collins Startup list
  1273.  
  1274. [A1000 Settings Utility]
  1275. Number=182
  1276. Confirmed=U
  1277. Filename=cpqa1000.exe
  1278. Description=Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
  1279. Source=Paul Collins Startup list
  1280.  
  1281. [A4Proxy]
  1282. Number=183
  1283. Confirmed=U
  1284. Filename=A4Proxy.exe
  1285. Description=<a href="http://www.findincontext.com/a4proxy/review.htm" target="_blank">Anonymity 4 Proxy</a> - local proxy server that makes you anonymous when visiting web sites
  1286. Source=Paul Collins Startup list
  1287.  
  1288. [AAACLEAN]
  1289. Number=184
  1290. Confirmed=?
  1291. Filename=AAACLEAN.INF
  1292. Description=<font color="#FF0000">??</font>
  1293. Source=Paul Collins Startup list
  1294.  
  1295. [AAAKeyboard]
  1296. Number=185
  1297. Confirmed=?
  1298. Filename=??
  1299. Description=<font color="#FF0000">??</font>
  1300. Source=Paul Collins Startup list
  1301.  
  1302. [AAATraySaver]
  1303. Number=186
  1304. Confirmed=N
  1305. Filename=TraySaver.exe
  1306. Description=System Tray management utility from <a href="http://www.mlin.net/" target="_blank">Mike Lin</a> which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
  1307. Source=Paul Collins Startup list
  1308.  
  1309. [AAK]
  1310. Number=187
  1311. Confirmed=U
  1312. Filename=aak.exe
  1313. Description=<a href="http://www.anti-keylogger.net/" target="_blank">Advanced Anti-Keylogger</a> - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"
  1314. Source=Paul Collins Startup list
  1315.  
  1316. [Aaou]
  1317. Number=188
  1318. Confirmed=X
  1319. Filename=amee.exe
  1320. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  1321. Source=Paul Collins Startup list
  1322.  
  1323. [Aapp]
  1324. Number=189
  1325. Confirmed=X
  1326. Filename=adprot.exe
  1327. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051216-4630-99" target=_blank>AdBlaster</a> adware
  1328. Source=Paul Collins Startup list
  1329.  
  1330. [aauclient]
  1331. Number=190
  1332. Confirmed=?
  1333. Filename=ACNUpdater.exe
  1334. Description=Appears to be related to software from <a href="http://www.accenture.com/home/default.htm?viewType=Flash" target=_blank>Accenture.com</a>
  1335. Source=Paul Collins Startup list
  1336.  
  1337. [ab EazyScheduler]
  1338. Number=191
  1339. Confirmed=?
  1340. Filename=ezsched.exe
  1341. Description=<font color="#FF0000">??</font>
  1342. Source=Paul Collins Startup list
  1343.  
  1344. [ABBYY Community Agent]
  1345. Number=192
  1346. Confirmed=N
  1347. Filename=CAGENT.EXE
  1348. Description=Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
  1349. Source=Paul Collins Startup list
  1350.  
  1351. [ABC]
  1352. Number=193
  1353. Confirmed=U
  1354. Filename=keylogger.exe
  1355. Description=Keystroke logger/monitoring program - remove unless you installed it yourself!
  1356.  
  1357. Source=Paul Collins Startup list
  1358.  
  1359. [abcdefgh]
  1360. Number=194
  1361. Confirmed=X
  1362. Filename=abcdefgh.exe
  1363. Description=<a href="http://www.securitystronghold.com/gates/spyware-adware-solutions/abcdefgh_abcdefgh.exe_solution.htm" target=_blank>EPJ</a> TROJAN! 
  1364.  
  1365. Source=Paul Collins Startup list
  1366.  
  1367. [ABIT uGuru]
  1368. Number=195
  1369. Confirmed=U
  1370. Filename=uGuru.exe
  1371. Description=<a href="http://www2.abit.com.tw/page/en/news/newspop.php?pDOCNO=en_0309184" target=_blank>ABIT â•¡Guru</a> - on motherboards incorporating the â•¡Guru processor this provides quick access to "hardware monitoring, overclocking, BIOS flashing and audio tweakin
  1372. Source=Paul Collins Startup list
  1373.  
  1374. [ABITEQ]
  1375. Number=196
  1376. Confirmed=N
  1377. Filename=abiteq.exe
  1378. Description=Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds
  1379. Source=Paul Collins Startup list
  1380.  
  1381. [Abrada WIN32]
  1382. Number=197
  1383. Confirmed=X
  1384. Filename=abrada.exe
  1385. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdermong.html" target=_blank>DERMON-G</a> TROJAN!
  1386.  
  1387. Source=Paul Collins Startup list
  1388.  
  1389. [Absolute Shield]
  1390. Number=198
  1391. Confirmed=U
  1392. Filename=dseraser.exe
  1393. Description=<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/dseraser/" target=_blank>Absolute Shield Evidence Eliminator</a> - internet history eraser
  1394.  
  1395. Source=Paul Collins Startup list
  1396.  
  1397. [Absolute StartUp monitor]
  1398. Number=199
  1399. Confirmed=U
  1400. Filename=ASMon.exe
  1401. Description=<a href="http://www.fgroupsoft.com/Absolutestartup/" target="_blank">Absolute Startup</a> - startup monitor from F-Group Software
  1402. Source=Paul Collins Startup list
  1403.  
  1404. [AbsoluteShield Internet Eraser]
  1405. Number=200
  1406. Confirmed=U
  1407. Filename=cseraser.exe
  1408. Description=<a href="http://www.internet-track-eraser.com/" target=_blank>AbsoluteShield Internet Eraser</a> - "protects your privacy by cleaning up all the tracks of your Internet and computer activities"
  1409.  
  1410. Source=Paul Collins Startup list
  1411.  
  1412. [ABsr]
  1413. Number=201
  1414. Confirmed=X
  1415. Filename=absr.exe
  1416. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-042320-3206-99" target="_blank">AUTOUPDER</a> TROJAN!
  1417. Source=Paul Collins Startup list
  1418.  
  1419. [absr]
  1420. Number=202
  1421. Confirmed=X
  1422. Filename=mwsvm.exe
  1423. Description=SeekSeek search hijacker related - see <a href="http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_SECTHOUGHT.A&VSect=Sn" target=_blank>here</a>
  1424.  
  1425. Source=Paul Collins Startup list
  1426.  
  1427. [abtu]
  1428. Number=203
  1429. Confirmed=X
  1430. Filename=mp3serch.exe
  1431. Description=Loads the executable for <a href="http://www.spywareinfo.com/lop.html" target="_blank">Lop.com</a>. mp3serch.exe is the final version
  1432. Source=Paul Collins Startup list
  1433.  
  1434. [abtu]
  1435. Number=204
  1436. Confirmed=X
  1437. Filename=lopsearch.exe
  1438. Description=Loads the executable for <a href="http://www.spywareinfo.com/articles/lop/" target="_blank">Lop.com</a>. lopsearch.exe is the beta version
  1439. Source=Paul Collins Startup list
  1440.  
  1441. [AbyssWebServer]
  1442. Number=205
  1443. Confirmed=U
  1444. Filename=abyssws.exe
  1445. Description=<a href="http://abyss.sourceforge.net/" target="_blank">Abyss</a> web server
  1446. Source=Paul Collins Startup list
  1447.  
  1448. [AcBtnMgr_Xxx]
  1449. Number=206
  1450. Confirmed=Y
  1451. Filename=AcBtnMgr_Xxx.exe
  1452. Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
  1453. Source=Paul Collins Startup list
  1454.  
  1455. [acc]
  1456. Number=207
  1457. Confirmed=U
  1458. Filename=acc.exe
  1459. Description=<a href="http://www.voicecallcentral.com/#advanced_call_center" target="_blank">Advanced Call Center</a> - "full-featured yet easy-to-use answering machine software for your voice modem"
  1460. Source=Paul Collins Startup list
  1461.  
  1462. [ACCDEFRAGINFO]
  1463. Number=208
  1464. Confirmed=X
  1465. Filename=[path to worm]
  1466. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32darbyo.html" target=_blank>DARBY-O</a> WORM!
  1467. Source=Paul Collins Startup list
  1468.  
  1469. [Accelerate]
  1470. Number=209
  1471. Confirmed=U
  1472. Filename=accelerate.exe
  1473. Description=Webroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
  1474. Source=Paul Collins Startup list
  1475.  
  1476. [Access Ramp Monitor]
  1477. Number=210
  1478. Confirmed=N
  1479. Filename=armon32.exe
  1480. Description=Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again
  1481. Source=Paul Collins Startup list
  1482.  
  1483. [Access WebControl]
  1484. Number=211
  1485. Confirmed=X
  1486. Filename=[path to file]
  1487. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojppdoorm.html" target=_blank>PPDOOR-M</a> TROJAN!
  1488. Source=Paul Collins Startup list
  1489.  
  1490. [AccessManager]
  1491. Number=212
  1492. Confirmed=U
  1493. Filename=AccessMgr.exe
  1494. Description=Part of SmartPipes <a href="http://www.smartpipes.com/SecureSite.htm" target=_blank>SecureSite</a> software. "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management"
  1495. Source=Paul Collins Startup list
  1496.  
  1497. [AccessMedia P2P Loader]
  1498. Number=213
  1499. Confirmed=X
  1500. Filename=amp2pl.exe
  1501. Description=My AccessMedia toolbar related, stealth installed!
  1502. Source=Paul Collins Startup list
  1503.  
  1504. [AccessoriesPlus]
  1505. Number=214
  1506. Confirmed=U
  1507. Filename=clockplus.exe
  1508. Description=Clock Plus, part of <a href="http://simplypowerful.com/software/accessoriesplus.html" target=_blank>Accessories Plus</a> allows you to select from dozens of alternatives for the Windows clock
  1509. Source=Paul Collins Startup list
  1510.  
  1511. [AccessRamp Monitor01]
  1512. Number=215
  1513. Confirmed=N
  1514. Filename=ARMon32a.exe
  1515. Description=From a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
  1516. Source=Paul Collins Startup list
  1517.  
  1518. [AccessRampLAN01]
  1519. Number=216
  1520. Confirmed=N
  1521. Filename=ARUpld32.exe
  1522. Description=Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
  1523. Source=Paul Collins Startup list
  1524.  
  1525. [AcctMgr]
  1526. Number=217
  1527. Confirmed=U
  1528. Filename=AcctMgr.exe
  1529. Description=NortonÖ Password Manager - part of <a href="http://www.symantec.com/sabu/sysworks/basic/" target="_blank">Norton SystemWorks 2004</a> - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities - all from the safety of your own PC
  1530. Source=Paul Collins Startup list
  1531.  
  1532. [AccuWeather.com« Desktop]
  1533. Number=218
  1534. Confirmed=N
  1535. Filename=AccuWeatherDesktop.exe
  1536. Description=Desktop weather from <a href="http://home.accuweather.com/index.asp?partner=accuweather" target="_blank">AccuWeather</a>
  1537. Source=Paul Collins Startup list
  1538.  
  1539. [accwizz.exe]
  1540. Number=219
  1541. Confirmed=X
  1542. Filename=accwizz.exe
  1543. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-082312-1953-99" target=_blank>RULAND.A</a> WORM!
  1544. Source=Paul Collins Startup list
  1545.  
  1546. [accwizzz.exe]
  1547. Number=220
  1548. Confirmed=X
  1549. Filename=accwizzz.exe
  1550. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-082312-1953-99" target=_blank>RULAND.A</a> WORM!
  1551. Source=Paul Collins Startup list
  1552.  
  1553. [acdllib3]
  1554. Number=221
  1555. Confirmed=X
  1556. Filename=bcdlmem.exe
  1557. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmailbotba.html" target="_blank">MAILBOT-BA</a> TROJAN!
  1558. Source=Paul Collins Startup list
  1559.  
  1560. [ACDSee]
  1561. Number=222
  1562. Confirmed=N
  1563. Filename=ACDSee8Pro.exe
  1564. Description=<a href="http://www.acdsee.com/" target="_blank">ACDSee</a> 8 photo software. Organize, manage, enhance, and share all your valued photo memories
  1565. Source=Paul Collins Startup list
  1566.  
  1567. [Ace bows]
  1568. Number=223
  1569. Confirmed=?
  1570. Filename=Ace bows.exe
  1571. Description=<font color="#FF0000">??</font>
  1572. Source=Paul Collins Startup list
  1573.  
  1574. [AceGain LiveUpdate]
  1575. Number=224
  1576. Confirmed=N
  1577. Filename=LiveUpdate.exe
  1578. Description="<a href="http://www.acegain.com/products_lu.htm" target="_blank">AceGain LiveUpdate</a> can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates, driver updates or full product updates and automatically download and install them according to user configuration"
  1579. Source=Paul Collins Startup list
  1580.  
  1581. [Acer ePower Management]
  1582. Number=225
  1583. Confirmed=U
  1584. Filename=Acer ePower Management.exe
  1585. Description=Part of Acer Empowering Technology. "<a href="http://www.acer-euro.com/et/en/notebooks01.htm#7" target="_blank">Acer ePower Management</a> is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"
  1586. Source=Paul Collins Startup list
  1587.  
  1588. [AcerGoto]
  1589. Number=226
  1590. Confirmed=U
  1591. Filename=AcerGoto.exe
  1592. Description=Acer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer
  1593. Source=Paul Collins Startup list
  1594.  
  1595. [AcerNotebookManager]
  1596. Number=227
  1597. Confirmed=U
  1598. Filename=almxptray.exe
  1599. Description=System Tray access on some Acer Notebooks to give faster access to system settings
  1600. Source=Paul Collins Startup list
  1601.  
  1602. [AcerPowerkey]
  1603. Number=228
  1604. Confirmed=U
  1605. Filename=Powerkey.exe
  1606. Description=PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
  1607. Source=Paul Collins Startup list
  1608.  
  1609. [Aceu]
  1610. Number=229
  1611. Confirmed=X
  1612. Filename=[random filename]
  1613. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  1614. Source=Paul Collins Startup list
  1615.  
  1616. [AClntUsr]
  1617. Number=230
  1618. Confirmed=U
  1619. Filename=AClntUsr.exe
  1620. Description=Altiris <a href="http://www.cdg-group.com/go.exe?prodid=299" target="_blank">AClient</a> Service Windows Tray Icon
  1621. Source=Paul Collins Startup list
  1622.  
  1623. [Acme.PCHButton]
  1624. Number=231
  1625. Confirmed=N
  1626. Filename=pchbutton.exe
  1627. Description=Used by HP Instant Support
  1628. Source=Paul Collins Startup list
  1629.  
  1630. [ACMonitor_Xxx]
  1631. Number=232
  1632. Confirmed=Y
  1633. Filename=ACMonitor_Xxx.exe
  1634. Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
  1635. Source=Paul Collins Startup list
  1636.  
  1637. [acocash]
  1638. Number=233
  1639. Confirmed=X
  1640. Filename=fastdown.exe
  1641. Description=Adult content dialler
  1642. Source=Paul Collins Startup list
  1643.  
  1644. [acocash]
  1645. Number=234
  1646. Confirmed=X
  1647. Filename=fastdown.exe
  1648. Description=Adult content dialler
  1649. Source=Paul Collins Startup list
  1650.  
  1651. [Acombo3dmouse]
  1652. Number=235
  1653. Confirmed=U
  1654. Filename=Acombo3d.exe
  1655. Description=Mouse driver - required if you use non-standard Windows driver features
  1656. Source=Paul Collins Startup list
  1657.  
  1658. [Aconti]
  1659. Number=236
  1660. Confirmed=X
  1661. Filename=aconti.exe
  1662. Description=Adult content dialler
  1663. Source=Paul Collins Startup list
  1664.  
  1665. [acoustic]
  1666. Number=237
  1667. Confirmed=U
  1668. Filename=acoustic.exe
  1669. Description=Control panel program for Philips <a href="http://www.digit-life.com/articles/philipsae/index.html" target="_blank">Acoustic Edge</a> soundcard. Not required unless changed settings aren't retained
  1670. Source=Paul Collins Startup list
  1671.  
  1672. [acpart]
  1673. Number=238
  1674. Confirmed=N
  1675. Filename=agpart11.exe
  1676. Description=Program for finding trucks on-line
  1677. Source=Paul Collins Startup list
  1678.  
  1679. [Acrobat]
  1680. Number=239
  1681. Confirmed=X
  1682. Filename=acrmon32.exe
  1683. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmallect.html" target="_blank">SMALL-ECT</a> TROJAN!
  1684. Source=Paul Collins Startup list
  1685.  
  1686. [Acrobat Assistant *.*]
  1687. Number=240
  1688. Confirmed=U
  1689. Filename=ACROTRAY.EXE
  1690. Description=Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation. *.* represents the version
  1691. Source=Paul Collins Startup list
  1692.  
  1693. [Acrobat Read]
  1694. Number=241
  1695. Confirmed=X
  1696. Filename=acroup32.exe
  1697. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvanbotbq.html" target="_blank">VANBOT-BQ</a> TROJAN!
  1698. Source=Paul Collins Startup list
  1699.  
  1700. [Acronis Popup Blocker]
  1701. Number=242
  1702. Confirmed=U
  1703. Filename=RunDll32.exe [path] Blocker.dll, Run
  1704. Description=Part of <a href="http://www.acronis.com/homecomputing/products/privacyexpert/" target=_blank>Acronis Privacy Expert</a> - anti-spyware and security suite
  1705.  
  1706. Source=Paul Collins Startup list
  1707.  
  1708. [Acronis Scheduler2 Service]
  1709. Number=243
  1710. Confirmed=U
  1711. Filename=schedhlp.exe
  1712. Description=Part of <a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank">Acronis True Image</a> - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images
  1713. Source=Paul Collins Startup list
  1714.  
  1715. [Acronis True Image]
  1716. Number=244
  1717. Confirmed=U
  1718. Filename=TimounterMonitor.exe
  1719. Description=Part of <a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank">Acronis True Image</a> backup software. Monitor for the backup archive explorer for moving and viewing files within an archive
  1720. Source=Paul Collins Startup list
  1721.  
  1722. [Acronis True Image Monitor]
  1723. Number=245
  1724. Confirmed=N
  1725. Filename=TrueImageMonitor.exe
  1726. Description=Part of <a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank">Acronis True Image</a> - backup software. Can be disabled without affecting TrueImage
  1727. Source=Paul Collins Startup list
  1728.  
  1729. [Acronis TrueImage Monitor]
  1730. Number=246
  1731. Confirmed=N
  1732. Filename=TrueImageMonitor.exe
  1733. Description=Part of <a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank">Acronis True Image</a> - backup software. Can be disabled without affecting TrueImage
  1734. Source=Paul Collins Startup list
  1735.  
  1736. [AcronisTimounterMonitor]
  1737. Number=247
  1738. Confirmed=U
  1739. Filename=TimounterMonitor.exe
  1740. Description=Part of <a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank">Acronis True Image</a> backup software. Monitor for the backup archive explorer for moving and viewing files within an archive
  1741. Source=Paul Collins Startup list
  1742.  
  1743. [AcronisTrueImage Monitor]
  1744. Number=248
  1745. Confirmed=N
  1746. Filename=TrueImageMonitor.exe
  1747. Description=Part of <a href="http://www.acronis.com/homecomputing/products/trueimage/" target="_blank">Acronis True Image</a> - backup software. Can be disabled without affecting TrueImage
  1748. Source=Paul Collins Startup list
  1749.  
  1750. [Act! Preloader]
  1751. Number=249
  1752. Confirmed=U
  1753. Filename=Act8.exe
  1754. Description=Sage Software's <a href="http://www.act.com/products/index.cfm" target="_blank">ACT!</a> "enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships"
  1755. Source=Paul Collins Startup list
  1756.  
  1757. [Action Manager 32]
  1758. Number=250
  1759. Confirmed=N
  1760. Filename=am32.exe
  1761. Description=Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
  1762. Source=Paul Collins Startup list
  1763.  
  1764. [ActionAgent]
  1765. Number=251
  1766. Confirmed=?
  1767. Filename=actionagent.exe
  1768. Description="A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". <font color="#FF0000">Is it required?</font>
  1769. Source=Paul Collins Startup list
  1770.  
  1771. [Activation]
  1772. Number=252
  1773. Confirmed=N
  1774. Filename=Activation.exe
  1775. Description=Part of Microsoft Money
  1776. Source=Paul Collins Startup list
  1777.  
  1778. [Activboard]
  1779. Number=253
  1780. Confirmed=U
  1781. Filename=MMKeybd.exe
  1782. Description=Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys
  1783. Source=Paul Collins Startup list
  1784.  
  1785. [Active Bit Station]
  1786. Number=254
  1787. Confirmed=X
  1788. Filename=abs.exe
  1789. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050615-3728-99" target="_blank">MYTOB.BZ</a> WORM!
  1790. Source=Paul Collins Startup list
  1791.  
  1792. [Active Email Monitor]
  1793. Number=255
  1794. Confirmed=U
  1795. Filename=aem25.exe
  1796. Description=<a href="http://www.vicman.net/emailmon/" target="_blank">Active Email Monitor</a> checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email
  1797. Source=Paul Collins Startup list
  1798.  
  1799. [Active shield]
  1800. Number=256
  1801. Confirmed=U
  1802. Filename=Activeshield.exe
  1803. Description=<a href="http://www.securitystronghold.com/" target=_blank>Active Shield</a> is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses"
  1804. Source=Paul Collins Startup list
  1805.  
  1806. [ActiveDesktop]
  1807. Number=257
  1808. Confirmed=X
  1809. Filename=systray32.exe
  1810. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-030717-0234-99" target="_blank">DABOOM</a> WORM!
  1811. Source=Paul Collins Startup list
  1812.  
  1813. [ACTIVEDS]
  1814. Number=258
  1815. Confirmed=X
  1816. Filename=ACTIVEDS.EXE
  1817. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
  1818. Source=Paul Collins Startup list
  1819.  
  1820. [ActiveEyes]
  1821. Number=259
  1822. Confirmed=N
  1823. Filename=ActiveEyes.exe
  1824. Description=ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small, it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs, create your own shortcut
  1825. Source=Paul Collins Startup list
  1826.  
  1827. [ActiveKeys.AAB635BD7D054a37A576]
  1828. Number=260
  1829. Confirmed=U
  1830. Filename=akeys.exe
  1831. Description="<a href="http://softarium.com/activekeys/" target="_blank">Active Keys</a> is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"
  1832. Source=Paul Collins Startup list
  1833.  
  1834. [ActiveMenu]
  1835. Number=261
  1836. Confirmed=U
  1837. Filename=ActiveMenu.exe
  1838. Description=Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
  1839. Source=Paul Collins Startup list
  1840.  
  1841. [ActivePlus]
  1842. Number=262
  1843. Confirmed=U
  1844. Filename=activeplus.exe
  1845. Description=Interactive Agents Plugin for <a href="http://www.patchou.com/msgplus/" target="_blank">Messenger Plus!</a> (MSN Messenger add-on)
  1846. Source=Paul Collins Startup list
  1847.  
  1848. [ActiveScan Antivirus]
  1849. Number=263
  1850. Confirmed=X
  1851. Filename=ActiveScan.exe
  1852. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfkq.html" target="_blank">RBOT-FKQ</a> WORM!
  1853. Source=Paul Collins Startup list
  1854.  
  1855. [ActiveShield]
  1856. Number=264
  1857. Confirmed=Y
  1858. Filename=MCVSSHLD.EXE
  1859. Description=McAfee VirusScan On-line. See also the McAgentExe entry
  1860. Source=Paul Collins Startup list
  1861.  
  1862. [ActiveSpeed]
  1863. Number=265
  1864. Confirmed=U
  1865. Filename=AS.exe
  1866. Description=Ascentive <a href="http://www.barelyaverage.com/portfolio/html_emails/ascentive/activespeed_biplane/biplane_anim.html" target=_blank>ActiveSpeed</a> Internet Optimizer
  1867. Source=Paul Collins Startup list
  1868.  
  1869. [ActiveSync]
  1870. Number=266
  1871. Confirmed=X
  1872. Filename=wcescom32.exe
  1873. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmancsyne.html" target="_blank">MANCSYN-E</a> TROJAN!
  1874. Source=Paul Collins Startup list
  1875.  
  1876. [ActiveWords]
  1877. Number=267
  1878. Confirmed=N
  1879. Filename=AWMonitor.exe
  1880. Description=<a href="http://www.activewords.com" target="_blank">ActiveWords</a> from ActiveWord Systems, Inc. Like macro programs, ActiveWords sits in the background and watches as you type. When it recognizes that youÆve typed an ActiveWord, it takes the associated action, such as replacing your keystrokes with the text youÆve defined
  1881. Source=Paul Collins Startup list
  1882.  
  1883. [ActiveX Streamer]
  1884. Number=268
  1885. Confirmed=X
  1886. Filename=msgfix.exe
  1887. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.NQ" target="_blank">SDBOT.NQ</a> WORM!
  1888. Source=Paul Collins Startup list
  1889.  
  1890. [ActiveXUpdate]
  1891. Number=269
  1892. Confirmed=X
  1893. Filename=svcss.exe
  1894. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojdedlerc.html" target=_blank>DEDLER.C</a> TROJAN!
  1895. Source=Paul Collins Startup list
  1896.  
  1897. [Activity]
  1898. Number=270
  1899. Confirmed=U
  1900. Filename=actik.exe
  1901. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-032917-5224-99" target="_blank">ActivityKey</a> Keystroke logger/monitoring program - remove unless you installed it yourself!
  1902. Source=Paul Collins Startup list
  1903.  
  1904. [ActivSurf]
  1905. Number=271
  1906. Confirmed=N
  1907. Filename=backweb*****.exe
  1908. Description=Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
  1909. Source=Paul Collins Startup list
  1910.  
  1911. [ActMaker]
  1912. Number=272
  1913. Confirmed=U
  1914. Filename=ActMak25.exe
  1915. Description="<a href="http://www.789987.com/products.htm" target=_blank>ActMaker</a> mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer"
  1916. Source=Paul Collins Startup list
  1917.  
  1918. [ActMaker]
  1919. Number=273
  1920. Confirmed=U
  1921. Filename=ActMaker25.exe
  1922. Description=<a href="http://www.789987.com/products.htm" target=_blank>ActMaker</a> mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload
  1923.  
  1924. Source=Paul Collins Startup list
  1925.  
  1926. [ACTray]
  1927. Number=274
  1928. Confirmed=U
  1929. Filename=ACTray.exe
  1930. Description=System Tray icon for <a href="http://www.pc.ibm.com/us/think/thinkvantagetech/accessconnections.html" target="_blank">ThinkVantage Access Connections</a> - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically"
  1931. Source=Paul Collins Startup list
  1932.  
  1933. [Actual Window Minimizer]
  1934. Number=275
  1935. Confirmed=U
  1936. Filename=ActualWindowMinimizerCenter.exe
  1937. Description=<a href="http://www.actualtools.com/windowminimizer/" target=_blank>Actual Window Minimizer</a> - "allows minimizing any window to task tray notification area or to the edge of the screen"
  1938.  
  1939. Source=Paul Collins Startup list
  1940.  
  1941. [ACTX1]
  1942. Number=276
  1943. Confirmed=X
  1944. Filename=v1201.exe
  1945. Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097395" target="_blank">VB.IS</a> TROJAN!
  1946. Source=Paul Collins Startup list
  1947.  
  1948. [ACU]
  1949. Number=277
  1950. Confirmed=U
  1951. Filename=ACU.exe
  1952. Description=<a href="http://www.atheros.com/" target="_blank">Atheros</a> wireless Client Utility
  1953. Source=Paul Collins Startup list
  1954.  
  1955. [ACU_QSB]
  1956. Number=278
  1957. Confirmed=U
  1958. Filename=ACU.exe
  1959. Description=<a href="http://www.atheros.com/" target="_blank">Atheros</a> wireless Client Utility
  1960. Source=Paul Collins Startup list
  1961.  
  1962. [ACWLIcon]
  1963. Number=279
  1964. Confirmed=U
  1965. Filename=ACWLIcon.exe
  1966. Description=Related to IBM ThinkVantage Connectivity Solution
  1967.  
  1968. Source=Paul Collins Startup list
  1969.  
  1970. [Ad Blocker]
  1971. Number=280
  1972. Confirmed=U
  1973. Filename=blocker.exe
  1974. Description=<a href="http://www.cdkm.com/" target="_blank">Ad Blocker</a> - blocks popups, and also removes banners, image ads and flash ads
  1975. Source=Paul Collins Startup list
  1976.  
  1977. [Ad Blocker Pro]
  1978. Number=281
  1979. Confirmed=U
  1980. Filename=Ad Blocker Pro.exe
  1981. Description=Ad Away popup and banner remover
  1982. Source=Paul Collins Startup list
  1983.  
  1984. [Ad Muncher]
  1985. Number=282
  1986. Confirmed=U
  1987. Filename=AdMunch.exe
  1988. Description=<a href="http://www.admuncher.com/" target="_blank">Ad Muncher</a> removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
  1989. Source=Paul Collins Startup list
  1990.  
  1991. [Ad Online Guide]
  1992. Number=283
  1993. Confirmed=?
  1994. Filename=adonlineguide.exe
  1995. Description=<font color="#FF0000">??</font>
  1996. Source=Paul Collins Startup list
  1997.  
  1998. [Ad-aware]
  1999. Number=284
  2000. Confirmed=N
  2001. Filename=Ad-aware.exe
  2002. Description=<a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware</a> from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
  2003. Source=Paul Collins Startup list
  2004.  
  2005. [Ad-Aware]
  2006. Number=285
  2007. Confirmed=X
  2008. Filename=Ad-Aware.exe
  2009. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotadj.html" target=_blank>RBOT-ADJ</a> WORM! Note - this is not the popular <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware</a> spware/adware removal tool and is located in the Winnt\System32 or Windows\System32 directory
  2010. Source=Paul Collins Startup list
  2011.  
  2012. [Ad-Eliminator]
  2013. Number=286
  2014. Confirmed=N
  2015. Filename=ad-eliminator.exe
  2016. Description=Spyware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target=_blank>here</a>
  2017. Source=Paul Collins Startup list
  2018.  
  2019. [Ad-Muncher]
  2020. Number=287
  2021. Confirmed=U
  2022. Filename=ADMUNCH.EXE
  2023. Description=<a href="http://www.admuncher.com/" target="_blank">Ad Muncher</a> removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
  2024. Source=Paul Collins Startup list
  2025.  
  2026. [Ad-Protect]
  2027. Number=288
  2028. Confirmed=U
  2029. Filename=ad-protect.exe
  2030. Description=<a href="http://www.adprotectplus.com/" target=_blank>Ad-Protect</a> spyware and spam monitoring tool
  2031.  
  2032. Source=Paul Collins Startup list
  2033.  
  2034. [Ad-watch]
  2035. Number=289
  2036. Confirmed=U
  2037. Filename=Ad-watch.exe
  2038. Description=Part of Lavasoft <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware Plus</a> - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
  2039. Source=Paul Collins Startup list
  2040.  
  2041. [AD2KClient]
  2042. Number=290
  2043. Confirmed=U
  2044. Filename=AD2KClient.exe
  2045. Description=Executable for <a href="http://www.iomega-activedisk.com/index.jsp" target="_blank">Active Disk</a> from Iomega disk - allows software applications to be run directly from an Iomega Zip« disk. Required if you wish the applications to launch on insertion of a disk
  2046. Source=Paul Collins Startup list
  2047.  
  2048. [Adaptec DirectCD]
  2049. Number=291
  2050. Confirmed=N
  2051. Filename=Directcd.exe
  2052. Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
  2053.  
  2054. Source=Paul Collins Startup list
  2055.  
  2056. [AdaptecDirectCD]
  2057. Number=292
  2058. Confirmed=N
  2059. Filename=Directcd.exe
  2060. Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
  2061. Source=Paul Collins Startup list
  2062.  
  2063. [AdAware]
  2064. Number=293
  2065. Confirmed=X
  2066. Filename=wini.exe
  2067. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotxn.html" target="_blank">RBOT-XN</a> WORM!
  2068. Source=Paul Collins Startup list
  2069.  
  2070. [Adaware Bootup]
  2071. Number=294
  2072. Confirmed=N
  2073. Filename=ad-aware.exe
  2074. Description=<a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware</a> from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
  2075. Source=Paul Collins Startup list
  2076.  
  2077. [Adaware lptt01]
  2078. Number=295
  2079. Confirmed=X
  2080. Filename=adaware.exe
  2081. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>. Note - this is not the valid Lavasoft Adaware
  2082. Source=Paul Collins Startup list
  2083.  
  2084. [Adaware ml097e]
  2085. Number=296
  2086. Confirmed=X
  2087. Filename=adaware.exe
  2088. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>. Note - this is not the valid Lavasoft Adaware
  2089. Source=Paul Collins Startup list
  2090.  
  2091. [Add**.exe [* = random char]]
  2092. Number=297
  2093. Confirmed=X
  2094. Filename=Add**.exe [* = random char]
  2095. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  2096. Source=Paul Collins Startup list
  2097.  
  2098. [Add**32.exe [* = random char]]
  2099. Number=298
  2100. Confirmed=X
  2101. Filename=Add**32.exe [* = random char]
  2102. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  2103. Source=Paul Collins Startup list
  2104.  
  2105. [AddClass]
  2106. Number=299
  2107. Confirmed=X
  2108. Filename=AddClass.exe
  2109. Description=CoolWebSearch <a href="http://cwshredder.net/cwshredder/cwschronicles.html#addclass" target=_blank>Addclass</a> parasite variant
  2110. Source=Paul Collins Startup list
  2111.  
  2112. [AddClass]
  2113. Number=300
  2114. Confirmed=X
  2115. Filename=[Installation_Path]
  2116. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-080815-4711-99" target=_blank>STARTPAGE.F</a> hijacker
  2117. Source=Paul Collins Startup list
  2118.  
  2119. [AddClass]
  2120. Number=301
  2121. Confirmed=X
  2122. Filename=[path to trojan]
  2123. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsecdla.html" target=_blank>SECDL-A</a> TROJAN!
  2124. Source=Paul Collins Startup list
  2125.  
  2126. [AdDelete]
  2127. Number=302
  2128. Confirmed=U
  2129. Filename=AdDelete.exe
  2130. Description=Banner advertisment blocker
  2131. Source=Paul Collins Startup list
  2132.  
  2133. [AdDestroyer]
  2134. Number=303
  2135. Confirmed=X
  2136. Filename=AdDestroyer.exe
  2137. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Virtual%20Bouncer&threatid=12432" target="_blank">Virtual Bouncer</a> - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see <a href="http://groups.google.com/group/alt.sports.hockey.nhl.vanc-canucks/msg/dec91d1aa1e0d9dd?hl=en&lr=&ie=UTF-8&oe=UTF-8" target="_blank">here</a>
  2138. Source=Paul Collins Startup list
  2139.  
  2140. [addproxy]
  2141. Number=304
  2142. Confirmed=?
  2143. Filename=addproxy.exe
  2144. Description=Related to Adobe Photoshop
  2145. Source=Paul Collins Startup list
  2146.  
  2147. [ADG]
  2148. Number=305
  2149. Confirmed=?
  2150. Filename=ADG.exe
  2151. Description=<font color="#FF0000"> SoundBlaster Audigy related?</font>
  2152. Source=Paul Collins Startup list
  2153.  
  2154. [ADGJdet]
  2155. Number=306
  2156. Confirmed=N
  2157. Filename=ADGJDet.exe
  2158. Description=Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
  2159. Source=Paul Collins Startup list
  2160.  
  2161. [aDir]
  2162. Number=307
  2163. Confirmed=X
  2164. Filename=adirss.exe
  2165. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojspamsrve.html" target="_blank">SPAMSRV-E</a> TROJAN!
  2166. Source=Paul Collins Startup list
  2167.  
  2168. [Adiras]
  2169. Number=308
  2170. Confirmed=Y
  2171. Filename=Adiras.exe
  2172. Description=ADSL USB modem related
  2173. Source=Paul Collins Startup list
  2174.  
  2175. [adirka]
  2176. Number=309
  2177. Confirmed=X
  2178. Filename=adirka.exe
  2179. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtibsqt.html" target="_blank">TIBS-QT</a> TROJAN!
  2180. Source=Paul Collins Startup list
  2181.  
  2182. [AdKiller]
  2183. Number=310
  2184. Confirmed=U
  2185. Filename=AD Defender.exe
  2186. Description=Part of <a href="http://www.evonsoft.com/Advanced-Spyware-Remover.htm" target="_blank">Advanced Spyware Remover</a> anti-spyware tool
  2187. Source=Paul Collins Startup list
  2188.  
  2189. [ADM Library Loader]
  2190. Number=311
  2191. Confirmed=X
  2192. Filename=admlib32.exe
  2193. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJAN!
  2194. Source=Paul Collins Startup list
  2195.  
  2196. [Admanager Controller]
  2197. Number=312
  2198. Confirmed=X
  2199. Filename=AdManCtl.exe
  2200. Description=Adware, probably a Windupdates variant
  2201. Source=Paul Collins Startup list
  2202.  
  2203. [Admilli Service]
  2204. Number=313
  2205. Confirmed=X
  2206. Filename=AdmilliServ.exe
  2207. Description=Windupdates adware variant
  2208. Source=Paul Collins Startup list
  2209.  
  2210. [Administrator]
  2211. Number=314
  2212. Confirmed=X
  2213. Filename=svchost.scr
  2214. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-092910-5215-99" target=_blank>NOVACAL</a> TROJAN!
  2215. Source=Paul Collins Startup list
  2216.  
  2217. [AdminSoft]
  2218. Number=315
  2219. Confirmed=X
  2220. Filename=sysfile.vbs
  2221. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/vbsstargruba.html" target="_blank">STARGRUB-A</a> WORM!
  2222. Source=Paul Collins Startup list
  2223.  
  2224. [admtray.exe]
  2225. Number=316
  2226. Confirmed=U
  2227. Filename=admtray.exe
  2228. Description=Related to <a href="http://global.acer.com/" target=_blank>Acer</a> Inc. destop tray
  2229. Source=Paul Collins Startup list
  2230.  
  2231. [Adobe]
  2232. Number=317
  2233. Confirmed=X
  2234. Filename=Adobe.exe
  2235. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  2236. Source=Paul Collins Startup list
  2237.  
  2238. [Adobe]
  2239. Number=318
  2240. Confirmed=X
  2241. Filename=sysconfig.exe
  2242. Description=Added by an unidentified WORM or TROJAN!
  2243. Source=Paul Collins Startup list
  2244.  
  2245. [adobe]
  2246. Number=319
  2247. Confirmed=X
  2248. Filename=gam.exe
  2249. Description=Added by an unidentified WORM or TROJAN!
  2250. Source=Paul Collins Startup list
  2251.  
  2252. [Adobe]
  2253. Number=320
  2254. Confirmed=X
  2255. Filename=sysbat32.exe
  2256. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_LOWZONES.T" target=_blank>LOWZONES.T</a> TROJAN!
  2257. Source=Paul Collins Startup list
  2258.  
  2259. [Adobe]
  2260. Number=321
  2261. Confirmed=X
  2262. Filename=zteam.exe
  2263. Description=Added by an unidentified TROJAN!
  2264. Source=Paul Collins Startup list
  2265.  
  2266. [Adobe Acrobat]
  2267. Number=322
  2268. Confirmed=N
  2269. Filename=READER~1.EXE
  2270. Description=Speeds up the time it takes to load the <a href="http://www.adobe.com/products/acrobat/readermain.html" target="_blank">Adobe Reader</a> application. Your choice, but not required for Adobe Reader to function properly
  2271. Source=Paul Collins Startup list
  2272.  
  2273. [Adobe Acrobat Distiller Application]
  2274. Number=323
  2275. Confirmed=X
  2276. Filename=acrotray.exe
  2277. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040512-3029-99" target=_blank>RANDEX.DFJ</a> WORM!
  2278. Source=Paul Collins Startup list
  2279.  
  2280. [Adobe Acrobat Reader CFG]
  2281. Number=324
  2282. Confirmed=X
  2283. Filename=[random filename]
  2284. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  2285. Source=Paul Collins Startup list
  2286.  
  2287. [Adobe Filter Platform]
  2288. Number=325
  2289. Confirmed=X
  2290. Filename=afilterplatform.exe
  2291. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotop.html" target=_blank>RBOT-OP</a> WORM!
  2292. Source=Paul Collins Startup list
  2293.  
  2294. [Adobe Gamma Loader]
  2295. Number=326
  2296. Confirmed=U
  2297. Filename=Adobe Gamma Loader.exe
  2298. Description=Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
  2299. Source=Paul Collins Startup list
  2300.  
  2301. [Adobe Photo Downloader]
  2302. Number=327
  2303. Confirmed=N
  2304. Filename=apdproxy.exe
  2305. Description=Part of <a href="http://www.adobe.com/" target=_blank>Adobe's</a> Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see <a href="http://www.adobe.com/support/techdocs/332361.html" target=_blank>here</a>)
  2306. Source=Paul Collins Startup list
  2307.  
  2308. [Adobe Reader Speed Lauch]
  2309. Number=328
  2310. Confirmed=N
  2311. Filename=reader_sl.exe
  2312. Description=Speeds up the launch of Adobe (Acrobat) Reader 7
  2313. Source=Paul Collins Startup list
  2314.  
  2315. [Adobe Reader Speed Launch]
  2316. Number=329
  2317. Confirmed=N
  2318. Filename=reader_sl.exe
  2319. Description=Speeds up the time it takes to load the <a href="http://www.adobe.com/products/acrobat/readermain.html" target=_blank>Adobe Reader</a> application. Your choice, but not required for Adobe Reader to function properly
  2320. Source=Paul Collins Startup list
  2321.  
  2322. [Adobe Reader Speed Launch]
  2323. Number=330
  2324. Confirmed=N
  2325. Filename=READER~1.EXE
  2326. Description=Speeds up the time it takes to load the <a href="http://www.adobe.com/products/acrobat/readermain.html" target="_blank">Adobe Reader</a> application. Your choice, but not required for Adobe Reader to function properly
  2327. Source=Paul Collins Startup list
  2328.  
  2329. [Adobe Version Cue CS2]
  2330. Number=331
  2331. Confirmed=U
  2332. Filename=VersionCueCS2Tray.exe
  2333. Description=File manager that's part of <a href="http://www.adobe.com/products/creativesuite/index.html?c=us" target="_blank">Adobe Creative Suite 2</a> - "find files fast, track versions across applications, link files together, and share them in creative collaboration without fear of overwriting someone else's work"
  2334. Source=Paul Collins Startup list
  2335.  
  2336. [AdobeA]
  2337. Number=332
  2338. Confirmed=X
  2339. Filename=adobes.exe
  2340. Description=Added by the <a href="http://vil.nai.com/vil/content/v_100373.htm" target="_blank">FLOOD.BA</a> TROJAN!
  2341. Source=Paul Collins Startup list
  2342.  
  2343. [AdobeFonts]
  2344. Number=333
  2345. Confirmed=X
  2346. Filename=fonts.hta
  2347. Description=Browser hijacker - redirecting to Hugesearch.net
  2348. Source=Paul Collins Startup list
  2349.  
  2350. [adobemgr]
  2351. Number=334
  2352. Confirmed=X
  2353. Filename=adobemgr.exe
  2354. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-091214-5754-99" target=_blank>ADCLICKER</a> TROJAN!
  2355. Source=Paul Collins Startup list
  2356.  
  2357. [AdobeReader]
  2358. Number=335
  2359. Confirmed=X
  2360. Filename=msni.exe
  2361. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.DAO" target="_blank">RBOT.DAO</a> TROJAN!
  2362. Source=Paul Collins Startup list
  2363.  
  2364. [AdobeReaderPro]
  2365. Number=336
  2366. Confirmed=X
  2367. Filename=msnxpsp.exe
  2368. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotask.html" target=_blank>RBOT-ASK</a> or <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaus.html" target=_blank>RBOT-AUS</a> WORMS!
  2369. Source=Paul Collins Startup list
  2370.  
  2371. [AdobeReaderPro]
  2372. Number=337
  2373. Confirmed=X
  2374. Filename=ntkernell32.exe
  2375. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaty.html" target=_blank>RBOT-ATY</a> WORM!
  2376. Source=Paul Collins Startup list
  2377.  
  2378. [AdobeReaderPro]
  2379. Number=338
  2380. Confirmed=X
  2381. Filename=msnserve.exe
  2382. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotakh.html" target="_blank">SDBOT-AKH</a> WORM!
  2383. Source=Paul Collins Startup list
  2384.  
  2385. [AdobeReaderPro]
  2386. Number=339
  2387. Confirmed=X
  2388. Filename=updt.exe
  2389. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32ircbotvq.html" target="_blank">IRCBOT-VQ</a> WORM!
  2390. Source=Paul Collins Startup list
  2391.  
  2392. [AdobeReaderProfessional]
  2393. Number=340
  2394. Confirmed=X
  2395. Filename=msx64.exe
  2396. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgat.html" target="_blank">RBOT-GAT</a> WORM!
  2397. Source=Paul Collins Startup list
  2398.  
  2399. [AdobeReaderPros]
  2400. Number=341
  2401. Confirmed=X
  2402. Filename=sysmsn.exe
  2403. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotbgh.html" target="_blank">RBOT-BGH</a> WORM!
  2404. Source=Paul Collins Startup list
  2405.  
  2406. [AdobeVersionCue]
  2407. Number=342
  2408. Confirmed=N
  2409. Filename=VersionCueTray.exe
  2410. Description="An exclusive feature of the Adobe« Creative Suite, <a href="http://www.adobe.com/products/creativesuite/versioncue.html" target=_blank>Version CueÖ</a> helps you find files fast, track multiple versions of your files, and share your files for creative collaboration"
  2411. Source=Paul Collins Startup list
  2412.  
  2413. [Adope File Manager]
  2414. Number=343
  2415. Confirmed=X
  2416. Filename=lsasv.exe
  2417. Description=Added by an unidentified WORM or TROJAN!
  2418. Source=Paul Collins Startup list
  2419.  
  2420. [adp]
  2421. Number=344
  2422. Confirmed=X
  2423. Filename=adp.exe
  2424. Description=Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc
  2425. Source=Paul Collins Startup list
  2426.  
  2427. [AdPopup]
  2428. Number=345
  2429. Confirmed=X
  2430. Filename=dcf5678.exe
  2431. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentfz.html" target=_blank>AGENT-FZ</a> TROJAN!
  2432. Source=Paul Collins Startup list
  2433.  
  2434. [adprot]
  2435. Number=346
  2436. Confirmed=X
  2437. Filename=adprot.exe
  2438. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051216-4630-99" target=_blank>AdBlaster</a> adware
  2439. Source=Paul Collins Startup list
  2440.  
  2441. [ADQuickAccess]
  2442. Number=347
  2443. Confirmed=N
  2444. Filename=Adtray.exe
  2445. Description=After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
  2446. Source=Paul Collins Startup list
  2447.  
  2448. [ADriver]
  2449. Number=348
  2450. Confirmed=X
  2451. Filename=windrv.exe
  2452. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DELF.WG" target="_blank">DELF.WG</a> TROJAN!
  2453. Source=Paul Collins Startup list
  2454.  
  2455. [AdRoarUpdate]
  2456. Number=349
  2457. Confirmed=X
  2458. Filename=ARUpdate.exe
  2459. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-120211-0649-99" target="_blank">AdRoar</a> adware updater
  2460. Source=Paul Collins Startup list
  2461.  
  2462. [AdRotator.Application]
  2463. Number=350
  2464. Confirmed=X
  2465. Filename=[path to csrss.exe]
  2466. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmallaq.html" target=_blank>SMALL-AQ</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
  2467. Source=Paul Collins Startup list
  2468.  
  2469. [AdRotator.Application]
  2470. Number=351
  2471. Confirmed=X
  2472. Filename=services.exe
  2473. Description=Added by <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-080316-2013-99&tabid=1" target=_blank>FakeMessage/AdRotator</a> adware. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder
  2474. Source=Paul Collins Startup list
  2475.  
  2476. [ADS Adware Remover]
  2477. Number=352
  2478. Confirmed=N
  2479. Filename=ADS Adware Remover.exe
  2480. Description=Adware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  2481. Source=Paul Collins Startup list
  2482.  
  2483. [AdsBlocker]
  2484. Number=353
  2485. Confirmed=X
  2486. Filename=stopAds.exe
  2487. Description=Reported as DILAER.DW by <a href="http://www.eset.com/products/index.php" target="_blank">NOD32</a>
  2488. Source=Paul Collins Startup list
  2489.  
  2490. [ADService]
  2491. Number=354
  2492. Confirmed=U
  2493. Filename=ADService.exe
  2494. Description=Part of Iomega's <a href="http://www.iomega-activedisk.com/index.jsp" target="_blank">Active Disk</a> - allows software applications to be run directly from an Iomega Zip« disk. Required if you wish the applications to launch on insertion of a disk
  2495. Source=Paul Collins Startup list
  2496.  
  2497. [AdsGone]
  2498. Number=355
  2499. Confirmed=U
  2500. Filename=Adsgone.exe
  2501. Description=<a href="http://www.adsgone.com/" target="_blank">AdsGone</a> - pop-up stopper
  2502. Source=Paul Collins Startup list
  2503.  
  2504. [ADSL Diagnostic Tools]
  2505. Number=356
  2506. Confirmed=N
  2507. Filename=mapiicon.exe
  2508. Description=System tray access to ADSL modem diagnostic tools. Available via Start -> Programs
  2509. Source=Paul Collins Startup list
  2510.  
  2511. [ADSLSYSTEMTRAY]
  2512. Number=357
  2513. Confirmed=?
  2514. Filename=SystemtrayV100B.exe
  2515. Description=Apparently Annex A ADSL modem related. <font color="#FF0000">What does it do and is it required?</font>
  2516. Source=Paul Collins Startup list
  2517.  
  2518. [AdslTaskBar]
  2519. Number=358
  2520. Confirmed=Y
  2521. Filename=rundll32.exe stmctrl.dll, TaskBar
  2522. Description=ISP software, initializes DSL modem
  2523. Source=Paul Collins Startup list
  2524.  
  2525. [AdslTaskBars]
  2526. Number=359
  2527. Confirmed=X
  2528. Filename=taskmng.exe
  2529. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaxz.html" target=_blank>RBOT-AXZ</a> WORM!
  2530. Source=Paul Collins Startup list
  2531.  
  2532. [ADSL_A2]
  2533. Number=360
  2534. Confirmed=?
  2535. Filename=A2Installed
  2536. Description=Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. <font color="#FF0000">What does it do and is it required?</font>
  2537. Source=Paul Collins Startup list
  2538.  
  2539. [ADSS]
  2540. Number=361
  2541. Confirmed=Y
  2542. Filename=ADSS.exe
  2543. Description=ADSS is part of <a href="http://www.johnru.com/" target="_blank">Access Denied</a> security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied
  2544. Source=Paul Collins Startup list
  2545.  
  2546. [adstartup]
  2547. Number=362
  2548. Confirmed=X
  2549. Filename=automove.exe
  2550. Description=<a href="http://www.spywareguide.com/product_show.php?id=791" target="_blank">Adlogix</a> adware variant
  2551. Source=Paul Collins Startup list
  2552.  
  2553. [adstartup]
  2554. Number=363
  2555. Confirmed=X
  2556. Filename=Adstartup.exe
  2557. Description=<a href="http://www.spywareguide.com/product_show.php?id=791" target=_blank>Adlogix</a> adware variant
  2558. Source=Paul Collins Startup list
  2559.  
  2560. [AdStatus Service]
  2561. Number=364
  2562. Confirmed=X
  2563. Filename=AdStatServ.exe
  2564. Description=WindUpdates <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094113" target="_blank">AdStatus Service</a> adware
  2565. Source=Paul Collins Startup list
  2566.  
  2567. [AdSubtract]
  2568. Number=365
  2569. Confirmed=U
  2570. Filename=adsub.exe
  2571. Description=AdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs. Now superseeded by <a href="http://www.trendmicro.com/en/products/desktop/as/evaluate/overview.htm" target="_blank">Trend Micro AntiSpyware</a>
  2572. Source=Paul Collins Startup list
  2573.  
  2574. [adtech2005]
  2575. Number=366
  2576. Confirmed=X
  2577. Filename=adtech2005.exe
  2578. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan.Win32.StartPage.aw
  2579. Source=Paul Collins Startup list
  2580.  
  2581. [adtech2006]
  2582. Number=367
  2583. Confirmed=X
  2584. Filename=adtech2006.exe
  2585. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Clicker.Win32.VB.kc
  2586. Source=Paul Collins Startup list
  2587.  
  2588. [Adtools Service]
  2589. Number=368
  2590. Confirmed=X
  2591. Filename=AdTools.exe
  2592. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082798" target="_blank">Windupdates</a> Adware
  2593. Source=Paul Collins Startup list
  2594.  
  2595. [ADU]
  2596. Number=369
  2597. Confirmed=?
  2598. Filename=adu.exe
  2599. Description=Related to <a href="http://www.cisco.com/" target="_blank">Cisco</a> Aironet wireless products. <font color="#FF0000">What does it do and is it required?</font>
  2600. Source=Paul Collins Startup list
  2601.  
  2602. [AdultX]
  2603. Number=370
  2604. Confirmed=X
  2605. Filename=AdultX.exe
  2606. Description=Adult content dialler and hijacker
  2607. Source=Paul Collins Startup list
  2608.  
  2609. [Adult_Chat]
  2610. Number=371
  2611. Confirmed=X
  2612. Filename=Adult_Chat.exe
  2613. Description=Adult content dialler
  2614. Source=Paul Collins Startup list
  2615.  
  2616. [Adult_Chat1]
  2617. Number=372
  2618. Confirmed=X
  2619. Filename=Adult_Chat1.exe
  2620. Description=Adult content dialler
  2621. Source=Paul Collins Startup list
  2622.  
  2623. [AdUpdater]
  2624. Number=373
  2625. Confirmed=X
  2626. Filename=sysupudt.exe
  2627. Description=Unidentified adware downloader/updater
  2628. Source=Paul Collins Startup list
  2629.  
  2630. [ADUserMon]
  2631. Number=374
  2632. Confirmed=U
  2633. Filename=ADUserMon.exe
  2634. Description=Part of Iomega's <a href="http://www.iomega-activedisk.com/index.jsp" target="_blank">Active Disk</a> - allows software applications to be run directly from an Iomega Zip« disk. Required if you wish the applications to launch on insertion of a disk
  2635. Source=Paul Collins Startup list
  2636.  
  2637. [Advanced DHTML Enable]
  2638. Number=375
  2639. Confirmed=X
  2640. Filename=exo32.exe
  2641. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojranckfi.html" target="_blank">RANCK-FI</a> TROJAN!
  2642. Source=Paul Collins Startup list
  2643.  
  2644. [Advanced Internet Protocol]
  2645. Number=376
  2646. Confirmed=X
  2647. Filename=cerf.exe
  2648. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-053013-5943-99" target="_blank">SPYBOT</a> WORM!
  2649. Source=Paul Collins Startup list
  2650.  
  2651. [Advanced Protection System]
  2652. Number=377
  2653. Confirmed=X
  2654. Filename=advpsys.exe
  2655. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  2656. Source=Paul Collins Startup list
  2657.  
  2658. [Advanced Spyware Remover]
  2659. Number=378
  2660. Confirmed=U
  2661. Filename=Asr.exe
  2662. Description=<a href="http://www.evonsoft.com/" target=_blank>Advanced Spyware Remover</a> anti spyware tool
  2663.  
  2664. Source=Paul Collins Startup list
  2665.  
  2666. [Advanced Tool Checks]
  2667. Number=379
  2668. Confirmed=X
  2669. Filename=advchks.exe
  2670. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  2671. Source=Paul Collins Startup list
  2672.  
  2673. [Advanced Tools Check]
  2674. Number=380
  2675. Confirmed=N
  2676. Filename=ADVCHK.EXE
  2677. Description=Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
  2678. Source=Paul Collins Startup list
  2679.  
  2680. [Advanced Uninstaller PRO Installation Monitor]
  2681. Number=381
  2682. Confirmed=U
  2683. Filename=monitor.exe
  2684. Description=Innovative Solutions <a href="http://www.innovative-sol.com/products.htm#uninstaller" target=_blank>Advanced Uninstaller PRO</a> - "easy-to-use suite for uninstalling applications and keeping your computer fast, clean, and in its best shape"
  2685. Source=Paul Collins Startup list
  2686.  
  2687. [Advapi]
  2688. Number=382
  2689. Confirmed=X
  2690. Filename=Advapi.exe
  2691. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_NETDEVIL.12" target="_blank">NETDEVIL.12</a> WORM!
  2692. Source=Paul Collins Startup list
  2693.  
  2694. [ADVCHK]
  2695. Number=383
  2696. Confirmed=N
  2697. Filename=ADVCHK.EXE
  2698. Description=Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
  2699. Source=Paul Collins Startup list
  2700.  
  2701. [Advertising Killer]
  2702. Number=384
  2703. Confirmed=U
  2704. Filename=Akiller.exe
  2705. Description=<a href="http://sourceforge.net/projects/akiller/" target="_blank">Advertising Killer</a> - popup stopper
  2706. Source=Paul Collins Startup list
  2707.  
  2708. [advmon32]
  2709. Number=385
  2710. Confirmed=X
  2711. Filename=advmon32.exe
  2712. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  2713. Source=Paul Collins Startup list
  2714.  
  2715. [Adware Agent]
  2716. Number=386
  2717. Confirmed=U
  2718. Filename=adware agent.exe
  2719. Description=<a href="http://www.topshareware.com/Adware-Agent-download-4866.htm" target="_blank">Adware Agent</a> popup blocker
  2720. Source=Paul Collins Startup list
  2721.  
  2722. [Adware Spy]
  2723. Number=387
  2724. Confirmed=N
  2725. Filename=AdwareSpy.exe
  2726. Description=Adware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  2727. Source=Paul Collins Startup list
  2728.  
  2729. [AdwareAlert]
  2730. Number=388
  2731. Confirmed=U
  2732. Filename=AdwareAlert.Exe
  2733. Description=Adware program, previously not recommended (see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#adw-alert_note" target=_blank>here</a>). It has now been delisted, so make sure you have the latest version
  2734. Source=Paul Collins Startup list
  2735.  
  2736. [AdwareDelete]
  2737. Number=389
  2738. Confirmed=N
  2739. Filename=adwaredelete.exe
  2740. Description=Adware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target=_blank>here</a>
  2741. Source=Paul Collins Startup list
  2742.  
  2743. [Aeiwlsta.exe]
  2744. Number=390
  2745. Confirmed=?
  2746. Filename=Aeiwlsta.exe
  2747. Description=IBM High Rate Wireless LAN Adapter driver.<font color="#FF0000"> Is it required?</font>
  2748. Source=Paul Collins Startup list
  2749.  
  2750. [AELaunch]
  2751. Number=391
  2752. Confirmed=N
  2753. Filename=AELaunch.exe
  2754. Description=Audio Applications Launcher for the Philips <a href="http://www.digit-life.com/articles/philipsae/index.html" target="_blank">Acoustic Edge</a> soundcard
  2755. Source=Paul Collins Startup list
  2756.  
  2757. [AERVICESN]
  2758. Number=392
  2759. Confirmed=X
  2760. Filename=AERVICESN.exe
  2761. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32randonao.html" target=_blank>RANDON-AO</a> WORM!
  2762. Source=Paul Collins Startup list
  2763.  
  2764. [AeXAgentLogon]
  2765. Number=393
  2766. Confirmed=N
  2767. Filename=AeXAgentActivate.exe
  2768. Description=<a href="http://www.altiris.com" target=_blank>Altiris</a> Agent transmits information about your machine for the purpose of asset management and deployment
  2769. Source=Paul Collins Startup list
  2770.  
  2771. [AeXSWDUsr]
  2772. Number=394
  2773. Confirmed=?
  2774. Filename=AeXSWDUsr.exe
  2775. Description=<a href="http://www.altiris.com/" target="_blank">Altiris</a> Express NS Client Manager software. <font color="#FF0000"> Is it required?</font>
  2776. Source=Paul Collins Startup list
  2777.  
  2778. [AEZBProc]
  2779. Number=395
  2780. Confirmed=U
  2781. Filename=aptezbp.exe
  2782. Description=IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions
  2783. Source=Paul Collins Startup list
  2784.  
  2785. [AFAFilter]
  2786. Number=396
  2787. Confirmed=U
  2788. Filename=windefault.exe
  2789. Description=<a href="http://www.afafilter.com/" target="_blank">AFAFilter</a> - internet filter software
  2790. Source=Paul Collins Startup list
  2791.  
  2792. [Agent]
  2793. Number=397
  2794. Confirmed=N
  2795. Filename=Agent.exe
  2796. Description=<a href="http://www.cyberlink.com/" target=_blank>Cyberlink's</a> Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs
  2797.  
  2798. Source=Paul Collins Startup list
  2799.  
  2800. [Agent]
  2801. Number=398
  2802. Confirmed=X
  2803. Filename=alsys.exe
  2804. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32drefv.html" target="_blank">DREF-V</a> VIRUS!
  2805. Source=Paul Collins Startup list
  2806.  
  2807. [agent]
  2808. Number=399
  2809. Confirmed=X
  2810. Filename=ppl.exe
  2811. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32drefu.html" target="_blank">DREF-U</a> VIRUS!
  2812. Source=Paul Collins Startup list
  2813.  
  2814. [Agent Browser]
  2815. Number=400
  2816. Confirmed=X
  2817. Filename=[random filename]
  2818. Description=Added by the PPdoor.M-bdr backdoor TROJAN!
  2819. Source=Paul Collins Startup list
  2820.  
  2821. [Agent Explorer]
  2822. Number=401
  2823. Confirmed=X
  2824. Filename=[random filename]
  2825. Description=Unidentified adware
  2826. Source=Paul Collins Startup list
  2827.  
  2828. [Agente]
  2829. Number=402
  2830. Confirmed=?
  2831. Filename=Remupd.exe
  2832. Description=Part of <a href="http://www.pandasoftware.com/home/particulares/default" target="_blank">Panda Antivirus </a>. <font color="#FF0000">Is this an update reminder (guess because of the name), virus definition update reminder or something similar?</font>
  2833. Source=Paul Collins Startup list
  2834.  
  2835. [agentsvr]
  2836. Number=403
  2837. Confirmed=X
  2838. Filename=agentsvr.exe
  2839. Description=Malware, detected by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as AdWare.Monker.a. NOTE: do NOT confuse with the Microsoft Agent Server application of the same name as described  <a href="http://www.microsoft.com/msagent/default.asp" target=_blank>here</a> - the legitimate file will always be located in the Windows\Msagent folder
  2840. Source=Paul Collins Startup list
  2841.  
  2842. [AgfaCLnk]
  2843. Number=404
  2844. Confirmed=U
  2845. Filename=AgfaCLnk.exe
  2846. Description=For Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
  2847. Source=Paul Collins Startup list
  2848.  
  2849. [agp]
  2850. Number=405
  2851. Confirmed=X
  2852. Filename=agp32.exe
  2853. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040112-0028-99" target="_blank">GAOBOT.SY</a> WORM!
  2854. Source=Paul Collins Startup list
  2855.  
  2856. [AGRSMMSG]
  2857. Number=406
  2858. Confirmed=Y
  2859. Filename=AGRSMMSG.exe
  2860. Description=IBM AMR modem driver
  2861. Source=Paul Collins Startup list
  2862.  
  2863. [AGSatellite]
  2864. Number=407
  2865. Confirmed=N
  2866. Filename=AGSatellite.exe
  2867. Description=Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
  2868. Source=Paul Collins Startup list
  2869.  
  2870. [ahfp]
  2871. Number=408
  2872. Confirmed=U
  2873. Filename=ahfp.exe
  2874. Description=<a href="http://www.softbe.com/" target="_blank">Advanced Hide Folders</a> - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
  2875. Source=Paul Collins Startup list
  2876.  
  2877. [ahfprog]
  2878. Number=409
  2879. Confirmed=U
  2880. Filename=ahfp.exe
  2881. Description=<a href="http://www.softbe.com/" target="_blank">Advanced Hide Folders</a> - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
  2882. Source=Paul Collins Startup list
  2883.  
  2884. [AHNSD]
  2885. Number=410
  2886. Confirmed=Y
  2887. Filename=AhnSD.exe
  2888. Description=<a href="http://global.ahnlab.com/" target="_blank">AhnLab</a> V3 antivirus updater - leave enabled unless you manually update on a regular basis
  2889. Source=Paul Collins Startup list
  2890.  
  2891. [AHNUE]
  2892. Number=411
  2893. Confirmed=?
  2894. Filename=AHNUE.exe
  2895. Description=<font color="#FF0000">??</font>
  2896. Source=Paul Collins Startup list
  2897.  
  2898. [ahost]
  2899. Number=412
  2900. Confirmed=X
  2901. Filename=ahost.exe
  2902. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  2903. Source=Paul Collins Startup list
  2904.  
  2905. [AHQInit]
  2906. Number=413
  2907. Confirmed=N
  2908. Filename=ahqinit.exe
  2909. Description=Part of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
  2910. Source=Paul Collins Startup list
  2911.  
  2912. [Ahst]
  2913. Number=414
  2914. Confirmed=X
  2915. Filename=iebs.exe
  2916. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  2917. Source=Paul Collins Startup list
  2918.  
  2919. [AHU]
  2920. Number=415
  2921. Confirmed=X
  2922. Filename=[path to worm]
  2923. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32anaconb.html" target=_blank>ANACON-B</a> WORM!
  2924. Source=Paul Collins Startup list
  2925.  
  2926. [ahui32.exe]
  2927. Number=416
  2928. Confirmed=X
  2929. Filename=ahui32.exe
  2930. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcertifm.html" target=_blank>CERTIF-M</a> TROJAN!
  2931. Source=Paul Collins Startup list
  2932.  
  2933. [Aica]
  2934. Number=417
  2935. Confirmed=X
  2936. Filename=tuaa.exe
  2937. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  2938. Source=Paul Collins Startup list
  2939.  
  2940. [Aida]
  2941. Number=418
  2942. Confirmed=X
  2943. Filename=ttuh.exe
  2944. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  2945. Source=Paul Collins Startup list
  2946.  
  2947. [Aida]
  2948. Number=419
  2949. Confirmed=X
  2950. Filename=eetu.exe
  2951. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target=_blank>PurityScan/Clickspring</a> adware
  2952. Source=Paul Collins Startup list
  2953.  
  2954. [aiepk]
  2955. Number=420
  2956. Confirmed=U
  2957. Filename=aiepk2.exe
  2958. Description=<a href="http://www.fadsoft.net/Another%20IE%20Popup%20Killer.htm" target="_blank">Another IE Popup Killer</a> - pop-up stopper
  2959. Source=Paul Collins Startup list
  2960.  
  2961. [AIM]
  2962. Number=421
  2963. Confirmed=N
  2964. Filename=aim.exe
  2965. Description=AOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs
  2966. Source=Paul Collins Startup list
  2967.  
  2968. [AIM]
  2969. Number=422
  2970. Confirmed=U
  2971. Filename=AIM+.exe
  2972. Description=AIM plus - a free add-on to AOL's Instant Messenger for Windows from Big-O Software
  2973. Source=Paul Collins Startup list
  2974.  
  2975. [AIM Instant Message Cookies]
  2976. Number=423
  2977. Confirmed=X
  2978. Filename=[random filename]
  2979. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotafv.html" target=_blank>RBOT-AFV</a> WORM!
  2980. Source=Paul Collins Startup list
  2981.  
  2982. [Aim Plugin]
  2983. Number=424
  2984. Confirmed=X
  2985. Filename=aimplugin.exe
  2986. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32guapf.html" target=_blank>GUAP-F</a> WORM!
  2987. Source=Paul Collins Startup list
  2988.  
  2989. [AIM reminder]
  2990. Number=425
  2991. Confirmed=X
  2992. Filename=AIM reminder.exe
  2993. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BUDDY.E" target="_blank">BUDDY</a> TROJAN!
  2994. Source=Paul Collins Startup list
  2995.  
  2996. [Aim6]
  2997. Number=426
  2998. Confirmed=N
  2999. Filename=AOLLaunch.exe
  3000. Description=<a href="http://www.aim.com/" target="_blank">AOL Instant Messenger</a> - start it when you want to use it
  3001. Source=Paul Collins Startup list
  3002.  
  3003. [AIM95 Startup]
  3004. Number=427
  3005. Confirmed=X
  3006. Filename=aim95.exe
  3007. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.AEE" target=_blank>AGOBOT.AEE</a> WORM!
  3008. Source=Paul Collins Startup list
  3009.  
  3010. [aimaol lptt01]
  3011. Number=428
  3012. Confirmed=X
  3013. Filename=aimaol.exe
  3014. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Aimaol" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  3015. Source=Paul Collins Startup list
  3016.  
  3017. [aimaol ml097e]
  3018. Number=429
  3019. Confirmed=X
  3020. Filename=aimaol.exe
  3021. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Aimaol" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  3022. Source=Paul Collins Startup list
  3023.  
  3024. [aimb.exe]
  3025. Number=430
  3026. Confirmed=U
  3027. Filename=aimb.exe
  3028. Description=<a href="http://sarc.com/avcenter/venc/data/spyware.imsurfsentinel.html" target=_blank>IMSufSentinel</a> is a spy program which can record IM conversations, log keystrokes, record URLs visited, and take screenshots. If you didn't install this yourself remove it
  3029. Source=Paul Collins Startup list
  3030.  
  3031. [AimingClick]
  3032. Number=431
  3033. Confirmed=N
  3034. Filename=AimingClick.exe
  3035. Description=<a href="http://www.aimingtech.com/aimingclick/" target="_blank">AimingClick</a> from AimingTech. Web searching tool. Available via Start -> Programs
  3036. Source=Paul Collins Startup list
  3037.  
  3038. [AIMPro]
  3039. Number=432
  3040. Confirmed=U
  3041. Filename=aimpro.exe
  3042. Description=<a href="http://aimpro.premiumservices.aol.com/" target="_blank">AIM Pro</a> - secure instant messaging, video conferencing, on-line meetings and desktop and file sharing
  3043. Source=Paul Collins Startup list
  3044.  
  3045. [AIMster]
  3046. Number=433
  3047. Confirmed=N
  3048. Filename=??
  3049. Description=Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
  3050. Source=Paul Collins Startup list
  3051.  
  3052. [AIMWDInstall]
  3053. Number=434
  3054. Confirmed=N
  3055. Filename=AIMWDInstall.exe
  3056. Description=Version of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=company_art&artid=art20030925_A" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
  3057. Source=Paul Collins Startup list
  3058.  
  3059. [Aiptek Graphics Tablet (USB)]
  3060. Number=435
  3061. Confirmed=Y
  3062. Filename=atwtusb.exe
  3063. Description=USB interface for Aiptek Graphics Tablet (USB)
  3064. Source=Paul Collins Startup list
  3065.  
  3066. [aircity]
  3067. Number=436
  3068. Confirmed=X
  3069. Filename=aircity.exe
  3070. Description=Related to "Prutect" malware from <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-102614-1006-99" target=_blank>e2Give</a>
  3071. Source=Paul Collins Startup list
  3072.  
  3073. [AKEYNAME]
  3074. Number=437
  3075. Confirmed=X
  3076. Filename=WinServ.exe
  3077. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-101912-0427-99" target="_blank">EVILBOT.C</a> TROJAN!
  3078. Source=Paul Collins Startup list
  3079.  
  3080. [akeys]
  3081. Number=438
  3082. Confirmed=U
  3083. Filename=akeys.exe
  3084. Description="<a href="http://softarium.com/activekeys/" target="_blank">Active Keys</a> is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"
  3085. Source=Paul Collins Startup list
  3086.  
  3087. [AKiller]
  3088. Number=439
  3089. Confirmed=U
  3090. Filename=akiller.exe
  3091. Description=<a href="http://sourceforge.net/projects/akiller/" target="_blank">Advertising Killer</a> - popup stopper
  3092. Source=Paul Collins Startup list
  3093.  
  3094. [ala.exe]
  3095. Number=440
  3096. Confirmed=X
  3097. Filename=ala.exe
  3098. Description=<a href="http://www.softheap.com/lock.html" target=_blank>Access Lock</a> is a system-tray security utility you can use to secure your desktop when you are away from your computer
  3099. Source=Paul Collins Startup list
  3100.  
  3101. [Alarm Manager]
  3102. Number=441
  3103. Confirmed=U
  3104. Filename=Alarm.app.exe
  3105. Description=Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop
  3106. Source=Paul Collins Startup list
  3107.  
  3108. [AlarmWatcher]
  3109. Number=442
  3110. Confirmed=?
  3111. Filename=AlarmWatcher.exe
  3112. Description=<font color="#FF0000">Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?</font>
  3113. Source=Paul Collins Startup list
  3114.  
  3115. [Album Fast Start]
  3116. Number=443
  3117. Confirmed=N
  3118. Filename=ABMTSR.EXE
  3119. Description=Scanner software, not required for scanner to work
  3120. Source=Paul Collins Startup list
  3121.  
  3122. [AlcFDMonitor]
  3123. Number=444
  3124. Confirmed=?
  3125. Filename=ALCFDRTM.EXE
  3126. Description=RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - <font color="#FF0000">is it required in startup?</font>
  3127. Source=Paul Collins Startup list
  3128.  
  3129. [ALCFDRTM16]
  3130. Number=445
  3131. Confirmed=?
  3132. Filename=ALCFDRTM16.com
  3133. Description=RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - <font color="#FF0000">is it required in startup?</font>
  3134. Source=Paul Collins Startup list
  3135.  
  3136. [Alchem]
  3137. Number=446
  3138. Confirmed=X
  3139. Filename=Alchem.exe
  3140. Description=<a href="http://www.symantec.com/security_response/print_writeup.jsp?docid=2004-050512-4801-99" target="_blank">ClickAlchemy</a> adware
  3141. Source=Paul Collins Startup list
  3142.  
  3143. [Alcmtr]
  3144. Number=447
  3145. Confirmed=U
  3146. Filename=Alcmtr.exe
  3147. Description=Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to data about the customer. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation
  3148. Source=Paul Collins Startup list
  3149.  
  3150. [Alcohol]
  3151. Number=448
  3152. Confirmed=U
  3153. Filename=Alcohol.exe
  3154. Description=<a href="http://www.alcohol-software.com/index.php" target="_blank">Alcohol 120%</a> - CD/DVD emulation/writing/copying software 
  3155. Source=Paul Collins Startup list
  3156.  
  3157. [Alcohol Autorun]
  3158. Number=449
  3159. Confirmed=U
  3160. Filename=Alcohol.exe
  3161. Description=<a href="http://www.alcohol-software.com/index.php" target="_blank">Alcohol 120%</a> - CD/DVD emulation/writing/copying software
  3162. Source=Paul Collins Startup list
  3163.  
  3164. [Alcom PCL Capture]
  3165. Number=450
  3166. Confirmed=?
  3167. Filename=FMW_PCAP.EXE
  3168. Description=<font color="#FF0000">??</font>
  3169. Source=Paul Collins Startup list
  3170.  
  3171. [AlcWzrd]
  3172. Number=451
  3173. Confirmed=N
  3174. Filename=ALCWZRD.EXE
  3175. Description=RealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one
  3176. Source=Paul Collins Startup list
  3177.  
  3178. [AlcxMonitor]
  3179. Number=452
  3180. Confirmed=U
  3181. Filename=Alcxmntr.exe
  3182. Description=Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation
  3183. Source=Paul Collins Startup list
  3184.  
  3185. [aldefr ere service]
  3186. Number=453
  3187. Confirmed=X
  3188. Filename=tay0x.exe
  3189. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotxs.html" target=_blank>RBOT-XS</a> WORM!
  3190. Source=Paul Collins Startup list
  3191.  
  3192. [Alevir]
  3193. Number=454
  3194. Confirmed=X
  3195. Filename=Alevir.exe
  3196. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32opaserva.html" target=_blank>OPASERV-A</a> WORM!
  3197.  
  3198. Source=Paul Collins Startup list
  3199.  
  3200. [AlevirOld]
  3201. Number=455
  3202. Confirmed=X
  3203. Filename=[worm filename]
  3204. Description=Added by the <a href="http://www.bullguard.com/virus/default.aspx?id=24" target=_blank>OPASERV</a> WORM!
  3205.  
  3206. Source=Paul Collins Startup list
  3207.  
  3208. [Alexa]
  3209. Number=456
  3210. Confirmed=N
  3211. Filename=alexa.exe
  3212. Description=Related to Alexa. Note - collects and stores information about the web pages you view, the data you enter in online forms and search programs and, with versions 5.0 and higher, the products you purchase online whilst using the toolbar. Although Alexa state's they do not attempt to analyze the data it may collect about you to determine who you are, some of your information collected by the software is personally identifiable. Please read the <a href="http://www.alexa.com/site/help/privacy" target="_blank">Privacy Policy</a>. Not Recommended
  3213. Source=Paul Collins Startup list
  3214.  
  3215. [AlexaToolbar]
  3216. Number=457
  3217. Confirmed=X
  3218. Filename=alt.exe
  3219. Description=Reported as the DELF.EB hijacker by <a href="http://www.ewido.net/en/" target=_blank>Ewido Security Suite</a>
  3220. Source=Paul Collins Startup list
  3221.  
  3222. [AlfaCleaner]
  3223. Number=458
  3224. Confirmed=X
  3225. Filename=AlfaCleaner.exe
  3226. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=AlfaCleaner&threatid=44118" target="_blank">AlphaCleaner</a> is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware 
  3227.  
  3228. Source=Paul Collins Startup list
  3229.  
  3230. [AlfaClock Classic]
  3231. Number=459
  3232. Confirmed=U
  3233. Filename=AlfaClock.exe
  3234. Description=<a href="http://www.alfasoftweb.com/" target=_blank>AlfaClock</a> from AlfaSoft Research Labs - "enhances your taskbar clock (tray clock) with fully customizable clock display, alarms, time synchronization and more"
  3235.  
  3236. Source=Paul Collins Startup list
  3237.  
  3238. [ALFY Accellerator]
  3239. Number=460
  3240. Confirmed=?
  3241. Filename=AlfyAC~1.exe
  3242. Description=<font color="#FF0000">??</font>
  3243. Source=Paul Collins Startup list
  3244.  
  3245. [ALG.EXE]
  3246. Number=461
  3247. Confirmed=X
  3248. Filename=iexplorer .exe
  3249. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32demotryb.html" target=_blank>DEMOTRY-B</a> WORM!
  3250. Source=Paul Collins Startup list
  3251.  
  3252. [ALG32]
  3253. Number=462
  3254. Confirmed=X
  3255. Filename=ALG32.EXE
  3256. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031109-3305-99" target=_blank>STARTPAGE.K</a> hijacker
  3257. Source=Paul Collins Startup list
  3258.  
  3259. [ALGU]
  3260. Number=463
  3261. Confirmed=X
  3262. Filename=ALGU.EXE
  3263. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcwsi.html" target=_blank>CWS-I</a> TROJAN!
  3264. Source=Paul Collins Startup list
  3265.  
  3266. [ALi5289]
  3267. Number=464
  3268. Confirmed=U
  3269. Filename=ALi5289.exe
  3270. Description=Related to <a href="http://www.uli.com.tw/" target="_blank">Uli Integrated Drivers</a> from Uli Electronics Inc
  3271. Source=Paul Collins Startup list
  3272.  
  3273. [Alias SketchBook Snapshot]
  3274. Number=465
  3275. Confirmed=N
  3276. Filename=ALIASS~2.EXE
  3277. Description=Screen-capture utility for Alias Sketchbook
  3278. Source=Paul Collins Startup list
  3279.  
  3280. [AlienAutopsy]
  3281. Number=466
  3282. Confirmed=N
  3283. Filename=Test_BS.exe
  3284. Description=<a href="http://www.alienware.com/" target="_blank">Alienware</a> computer technical support software
  3285. Source=Paul Collins Startup list
  3286.  
  3287. [ALiSndMgr]
  3288. Number=467
  3289. Confirmed=Y
  3290. Filename=ALiSndMg.exe
  3291. Description=ALi AC97 Sound driver
  3292. Source=Paul Collins Startup list
  3293.  
  3294. [AliUSBfix]
  3295. Number=468
  3296. Confirmed=?
  3297. Filename=GREENMK.exe
  3298. Description=<font color="#FF0000">May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?</font>
  3299. Source=Paul Collins Startup list
  3300.  
  3301. [Alive SYstem]
  3302. Number=469
  3303. Confirmed=X
  3304. Filename=scchost.exe
  3305. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtofdropb.html" target=_blank>TOFDROP-B</a> TROJAN!
  3306. Source=Paul Collins Startup list
  3307.  
  3308. [Alive SYstem]
  3309. Number=470
  3310. Confirmed=X
  3311. Filename=scchostc.exe
  3312. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtofdropb.html" target=_blank>TOFDROP-B</a> TROJAN!
  3313. Source=Paul Collins Startup list
  3314.  
  3315. [alkasr]
  3316. Number=471
  3317. Confirmed=X
  3318. Filename=╬Σ╥φ╤.exe
  3319. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-090212-3607-99" target="_blank">BALKART</a> TROJAN!
  3320. Source=Paul Collins Startup list
  3321.  
  3322. [All Aboard Status]
  3323. Number=472
  3324. Confirmed=U
  3325. Filename=stswin.exe
  3326. Description=<a target="_blank" href="http://yippee.i4free.co.nz/html/win/internet/title6724.htm">All Aboard! Internet Connection Sharing</a> status icon
  3327. Source=Paul Collins Startup list
  3328.  
  3329. [All Sea screen saver]
  3330. Number=473
  3331. Confirmed=X
  3332. Filename=TaskTray.exe
  3333. Description="Free screensaver", installs lots of foistware. See <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=10&t=5833&hl=&s=" target="_blank">here</a>. Get rid of it
  3334. Source=Paul Collins Startup list
  3335.  
  3336. [All Sea web link]
  3337. Number=474
  3338. Confirmed=X
  3339. Filename=FWLink.exe
  3340. Description="Free screensaver", installs lots of foistware. See <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=10&t=5833&hl=&s=" target="_blank">here</a>. Get rid of it
  3341. Source=Paul Collins Startup list
  3342.  
  3343. [AllerCalc]
  3344. Number=475
  3345. Confirmed=N
  3346. Filename=AllerCalc.exe
  3347. Description=<a href="http://www.allersoft.com/allercalc.htm" target=_blank>AllerCalc</a> is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually
  3348. Source=Paul Collins Startup list
  3349.  
  3350. [Allopassw]
  3351. Number=476
  3352. Confirmed=X
  3353. Filename=[path to trojan]
  3354. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_RANKY.CU" target="_blank">RANKY.CU</a> TROJAN!
  3355. Source=Paul Collins Startup list
  3356.  
  3357. [AllSeeingEye]
  3358. Number=477
  3359. Confirmed=U
  3360. Filename=ase.exe
  3361. Description=<a href="http://www.fortego.com/en/ase.html" target=_blank>All-Seeing_Eye</a> security software - "monitors everything that takes place on your computer, and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening, providing the user with alternatives for possible actions"
  3362. Source=Paul Collins Startup list
  3363.  
  3364. [allSnap]
  3365. Number=478
  3366. Confirmed=U
  3367. Filename=allSnap.exe
  3368. Description="<a href="http://ca.geocities.com/ivanheckman@rogers.com/" target="_blank">allSnap</a> is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"
  3369. Source=Paul Collins Startup list
  3370.  
  3371. [AllToTray]
  3372. Number=479
  3373. Confirmed=U
  3374. Filename=ALLTOTRAY.EXE
  3375. Description=<a href="http://www.dntsoft.com/" target=_blank>AlltoTray</a> from DNTSoft - minimize any program to your System Tray
  3376.  
  3377. Source=Paul Collins Startup list
  3378.  
  3379. [Alogrithm Link Queue]
  3380. Number=480
  3381. Confirmed=X
  3382. Filename=alq.exe
  3383. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  3384. Source=Paul Collins Startup list
  3385.  
  3386. [Alogserv]
  3387. Number=481
  3388. Confirmed=U
  3389. Filename=Alogserv.exe
  3390. Description=From McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up
  3391. Source=Paul Collins Startup list
  3392.  
  3393. [ALPass]
  3394. Number=482
  3395. Confirmed=U
  3396. Filename=ALPass.exe
  3397. Description=<a href="http://www.altools.net/Default.aspx?tabid=62" target=_blank>ALPass</a> password manager
  3398. Source=Paul Collins Startup list
  3399.  
  3400. [Alps Electric USB Server]
  3401. Number=483
  3402. Confirmed=Y
  3403. Filename=Monserv.exe
  3404. Description=Alps Electric USB Server - required according to <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;200692" target="_blank">this</a> article
  3405.  
  3406.  
  3407. Source=Paul Collins Startup list
  3408.  
  3409. [AlpsPoint]
  3410. Number=484
  3411. Confirmed=U
  3412. Filename=Apoint.exe
  3413. Description=Touchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
  3414. Source=Paul Collins Startup list
  3415.  
  3416. [ALServ]
  3417. Number=485
  3418. Confirmed=?
  3419. Filename=ALServ.exe
  3420. Description=Altec Lansing AMS speaker related.<font color="#FF0000"> What does it do and is it required?</font>
  3421. Source=Paul Collins Startup list
  3422.  
  3423. [Altnet]
  3424. Number=486
  3425. Confirmed=X
  3426. Filename=points manager.exe
  3427. Description=Altnet <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080415-0053-99" target=_blank>TopSearch</a> adware
  3428. Source=Paul Collins Startup list
  3429.  
  3430. [AltnetPointsManager]
  3431. Number=487
  3432. Confirmed=X
  3433. Filename=points manager.exe
  3434. Description=Altnet <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080415-0053-99" target=_blank>TopSearch</a> adware
  3435. Source=Paul Collins Startup list
  3436.  
  3437. [AltoMB_service]
  3438. Number=488
  3439. Confirmed=U
  3440. Filename=AltoMBsrv.exe
  3441. Description=Alto Memory Booster from <a href="http://www.altosoftware.com/" target="_blank">Alto Software</a> - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See <a href="http://aumha.org/win4/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
  3442. Source=Paul Collins Startup list
  3443.  
  3444. [ALTOOLS]
  3445. Number=489
  3446. Confirmed=U
  3447. Filename=AccessL.exe
  3448. Description=<a href="http://www.altools.net/" target=_blank>ALTools</a> family of PC utilities
  3449.  
  3450. Source=Paul Collins Startup list
  3451.  
  3452. [AltPayments]
  3453. Number=490
  3454. Confirmed=X
  3455. Filename=AltPayments.exe
  3456. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-053116-5734-99" target="_blank">WeirdOnTheWeb</a> adware
  3457. Source=Paul Collins Startup list
  3458.  
  3459. [ALU Scheduler Service]
  3460. Number=491
  3461. Confirmed=N
  3462. Filename=ALUSchedulerSvc.exe
  3463. Description=Symantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
  3464. Source=Paul Collins Startup list
  3465.  
  3466. [ALUAlert]
  3467. Number=492
  3468. Confirmed=U
  3469. Filename=ALUNotify.exe
  3470. Description=Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
  3471. Source=Paul Collins Startup list
  3472.  
  3473. [Aluria Security Center]
  3474. Number=493
  3475. Confirmed=N
  3476. Filename=SecurityCenter.exe
  3477. Description=Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see <a href="http://netrn.net/spywareblog/archives/2004/11/06/aluria-confused/" target="_blank">here</a>
  3478. Source=Paul Collins Startup list
  3479.  
  3480. [Aluria's Pop-Up Stopper]
  3481. Number=494
  3482. Confirmed=U
  3483. Filename=eps.exe
  3484. Description=Aluria Pop-Stopper
  3485. Source=Paul Collins Startup list
  3486.  
  3487. [Aluria's Spyware Eliminator]
  3488. Number=495
  3489. Confirmed=N
  3490. Filename=ASE.exe
  3491. Description=Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see <a href="http://netrn.net/spywareblog/archives/2004/11/06/aluria-confused/" target="_blank">here</a>
  3492. Source=Paul Collins Startup list
  3493.  
  3494. [AlwaysOnTopMaker]
  3495. Number=496
  3496. Confirmed=U
  3497. Filename=AlwaysOnTopMaker.exe
  3498. Description=<a href="http://www.fadsoft.net/AlwaysOnTopMaker.htm" target="_blank">Always On Top Maker</a> - utilty to enable an application to always be displayed "on top" of others on the desktop
  3499. Source=Paul Collins Startup list
  3500.  
  3501. [AlwaysReady Power Message APP]
  3502. Number=497
  3503. Confirmed=N
  3504. Filename=ARPWRMSG.EXE
  3505. Description=Related to HP and Compaq Desktop PCs. Read <a href="http://h10025.www1.hp.com:80/ewfrf/wc/genericDocument?docname=bph07149&cc=us&lc=en&dlc=en&dlc=en&lang=en" target="_blank">this</a> article
  3506. Source=Paul Collins Startup list
  3507.  
  3508. [AmazingTens]
  3509. Number=498
  3510. Confirmed=X
  3511. Filename=AmazingTens.exe
  3512. Description=Premium rate adult content dialler
  3513. Source=Paul Collins Startup list
  3514.  
  3515. [AMD PowerNow!]
  3516. Number=499
  3517. Confirmed=U
  3518. Filename=GemBack.exe
  3519. Description=<a href="http://www.amd.com/us-en/0,,3715_13530_1260_1204^964,00.html" target="_blank">AMD PowerNow!</a> - "an innovative solution available on all AMD mobile processor-based notebooks that can effectively increase notebook battery life, while delivering performance on demand"
  3520. Source=Paul Collins Startup list
  3521.  
  3522. [amd_dc_opt]
  3523. Number=500
  3524. Confirmed=Y
  3525. Filename=amd_dc_opt.exe
  3526. Description=<a href="http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_9706,00.html" target="_blank">AMD Dual-Core Optimizer</a> - "can help improve some PC gaming video performance by compensating for those applications that bypass the Windows API for timing by directly using the RDTSC (Read Time Stamp Counter) instruction"
  3527. Source=Paul Collins Startup list
  3528.  
  3529. [America Online *.* Tray Icon]
  3530. Number=501
  3531. Confirmed=N
  3532. Filename=aoltray.exe
  3533. Description=Puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs
  3534. Source=Paul Collins Startup list
  3535.  
  3536. [AME_CSA]
  3537. Number=502
  3538. Confirmed=N
  3539. Filename=rundll32 amecsa.cpl, RUN_DLL
  3540. Description=Loads ADSL modem Control Panel applet
  3541. Source=Paul Collins Startup list
  3542.  
  3543. [AModemLockDown]
  3544. Number=503
  3545. Confirmed=U
  3546. Filename=ModemLockDown.exe
  3547. Description=<a href="http://modemlockdown.techconz.com/index.html" target=_blank>ModemLockDown</a> - allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etc
  3548. Source=Paul Collins Startup list
  3549.  
  3550. [Amon]
  3551. Number=504
  3552. Confirmed=Y
  3553. Filename=AMON.EXE
  3554. Description=Monitoring part of Eset's <a href="http://www.eset.com/products/index.php" target="_blank">NOD32</a> virus-scanner
  3555. Source=Paul Collins Startup list
  3556.  
  3557. [Amonitor]
  3558. Number=505
  3559. Confirmed=Y
  3560. Filename=amon.exe
  3561. Description=<a href="http://www.tinysoftware.com/home/tiny2?la=EN" target="_blank">Tiny Personal Firewall</a>
  3562. Source=Paul Collins Startup list
  3563.  
  3564. [AMP WinOFF]
  3565. Number=506
  3566. Confirmed=U
  3567. Filename=winoff.exe
  3568. Description=<a href="http://www.ampsoft.net/utilities/WinOFF.php" target=_blank>WinOFF</a> is " a utility designed to shut down Windows computers automatically, in a fully configurable way"
  3569. Source=Paul Collins Startup list
  3570.  
  3571. [AMSG]
  3572. Number=507
  3573. Confirmed=U
  3574. Filename=Amsg.exe
  3575. Description=Part of the IBM <a href="http://www.pc.ibm.com/us/think/thinkvantagetech/productivity_ctr.html" target="_blank">ThinkVantage Productivity Center</a>. "The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"
  3576. Source=Paul Collins Startup list
  3577.  
  3578. [AMSN]
  3579. Number=508
  3580. Confirmed=N
  3581. Filename=amsn.exe
  3582. Description=<a href="http://sourceforge.net/projects/amsn/" target="_blank">aMSN Messenger</a> is a multiplatform MSN messenger clone
  3583. Source=Paul Collins Startup list
  3584.  
  3585. [amsn]
  3586. Number=509
  3587. Confirmed=X
  3588. Filename=amsn.exe
  3589. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerbnz.html" target="_blank">BANKER-BNZ</a> TROJAN!
  3590. Source=Paul Collins Startup list
  3591.  
  3592. [Anapod Manager]
  3593. Number=510
  3594. Confirmed=N
  3595. Filename=anamgr.exe
  3596. Description=<a href="http://www.redchairsoftware.com/anapod/" target="_blank">Anapod Explorer</a> "is the most advanced Windows iPod software available, offering iPod management through full Windows Explorer integration under My Computer"
  3597. Source=Paul Collins Startup list
  3598.  
  3599. [anbv32]
  3600. Number=511
  3601. Confirmed=X
  3602. Filename=nabv32.exe
  3603. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091209-3011-99" target="_blank">TITOG.C</a> WORM!
  3604. Source=Paul Collins Startup list
  3605.  
  3606. [ANIWZCS2Service]
  3607. Number=512
  3608. Confirmed=Y
  3609. Filename=WZCSLDR2.exe
  3610. Description=<a href="http://www.alphanetworks.com/" target=_blank>ALPHA Networks</a> wireless driver
  3611. Source=Paul Collins Startup list
  3612.  
  3613. [ANIWZCSService]
  3614. Number=513
  3615. Confirmed=?
  3616. Filename=WZCSLDR.exe
  3617. Description=D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
  3618. Source=Paul Collins Startup list
  3619.  
  3620. [AnnotateCheck]
  3621. Number=514
  3622. Confirmed=?
  3623. Filename=AnnCheck.exe
  3624. Description=Genius Wizard Pen Tablet driver related. <font color="#FF0000">Is it required?</font>
  3625. Source=Paul Collins Startup list
  3626.  
  3627. [Announcements]
  3628. Number=515
  3629. Confirmed=N
  3630. Filename=Annclist.exe
  3631. Description=MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
  3632. Source=Paul Collins Startup list
  3633.  
  3634. [Anntext]
  3635. Number=516
  3636. Confirmed=N
  3637. Filename=Anntext.exe
  3638. Description=Caere Pagekeeper text annotation server
  3639. Source=Paul Collins Startup list
  3640.  
  3641. [Anonymizer Total Net Shield]
  3642. Number=517
  3643. Confirmed=U
  3644. Filename=AnonTns.exe
  3645. Description=Anonymizer <a href="http://www.anonymizer.com/consumer/products/total_net_shield/" target="_blank">Total Net Shield</a> - ID protection and privacy software
  3646. Source=Paul Collins Startup list
  3647.  
  3648. [ANONYMIZER_SPYWAREKILLER]
  3649. Number=518
  3650. Confirmed=U
  3651. Filename=SpyWareKiller.exe
  3652. Description=Anonymizer Spyware Killer - now <a href="http://www.anonymizer.com/consumer/products/anti_spyware/" target="_blank">Anti-Spyware</a>
  3653. Source=Paul Collins Startup list
  3654.  
  3655. [ANONYMIZER_SPYWAREKILLER]
  3656. Number=519
  3657. Confirmed=U
  3658. Filename=AnonAntiSpyware.exe
  3659. Description=Anonymizer Spyware Killer - now <a href="http://www.anonymizer.com/consumer/products/anti_spyware/" target="_blank">Anti-Spyware</a>
  3660. Source=Paul Collins Startup list
  3661.  
  3662. [Another Internet Explorer Popup Killer]
  3663. Number=520
  3664. Confirmed=U
  3665. Filename=aiepk2.exe
  3666. Description=<a href="http://www.fadsoft.net/Another%20IE%20Popup%20Killer.htm" target="_blank">Another IE Popup Killer</a> - pop-up stopper
  3667. Source=Paul Collins Startup list
  3668.  
  3669. [ansjava]
  3670. Number=521
  3671. Confirmed=X
  3672. Filename=[path to worm]
  3673. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32randonan.html" target=_blank>RANDON-AN</a> WORM!
  3674. Source=Paul Collins Startup list
  3675.  
  3676. [Anskya]
  3677. Number=522
  3678. Confirmed=X
  3679. Filename=PYSKY.NET.exe
  3680. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadermw.html" target="_blank">DLOADER-MW</a> TROJAN!
  3681. Source=Paul Collins Startup list
  3682.  
  3683. [Answer Problem]
  3684. Number=523
  3685. Confirmed=X
  3686. Filename=dSAFsqs.exe
  3687. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotsc.html" target="_blank">SDBOT-SC</a> WORM!
  3688. Source=Paul Collins Startup list
  3689.  
  3690. [AnswerTool]
  3691. Number=524
  3692. Confirmed=U
  3693. Filename=AnswerTool.exe
  3694. Description=<a href="http://www.answertool.com/" target=_blank>AnswerTool</a> - save your E-mail replies in AnswerTool, then reuse them again and again
  3695.  
  3696. Source=Paul Collins Startup list
  3697.  
  3698. [Anti Spam Service]
  3699. Number=525
  3700. Confirmed=X
  3701. Filename=spamsvc.exe
  3702. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobbk.html" target=_blank>MYTOB-BK</a> WORM!
  3703. Source=Paul Collins Startup list
  3704.  
  3705. [Anti-Blaxx Manager]
  3706. Number=526
  3707. Confirmed=N
  3708. Filename=Anti-Blaxx.exe
  3709. Description=<a href="http://www.antiblaxx.com/" target=_blank>Anti-Blaxx</a> - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives
  3710.  
  3711. Source=Paul Collins Startup list
  3712.  
  3713. [Anti-keylogger check]
  3714. Number=527
  3715. Confirmed=U
  3716. Filename=antikey.exe
  3717. Description=<a href="http://www.anti-keyloggers.com/" target="_blank">Anti-keylogger</a> - protects against keylogger programs monitoring your keystrokes
  3718. Source=Paul Collins Startup list
  3719.  
  3720. [Anti-Trojan-Watch]
  3721. Number=528
  3722. Confirmed=U
  3723. Filename=ATWatch.exe
  3724. Description=Anti-Trojan Watch - trojan detector
  3725. Source=Paul Collins Startup list
  3726.  
  3727. [Anti-Virus]
  3728. Number=529
  3729. Confirmed=X
  3730. Filename=vpms.exe
  3731. Description=Added by the <a href="http://www.scanspyware.net/info/Sdbot.GV.htm" target="_blank">SDBOT.GV</a> WORM!
  3732. Source=Paul Collins Startup list
  3733.  
  3734. [Anti-Virus]
  3735. Number=530
  3736. Confirmed=X
  3737. Filename=[random filename].exe
  3738. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcaprobada.html" target="_blank">CAPROBAD-A</a> TROJAN!
  3739. Source=Paul Collins Startup list
  3740.  
  3741. [Anti-Virus Product Sync]
  3742. Number=531
  3743. Confirmed=X
  3744. Filename=[unprintable character][3 characters]log.exe
  3745. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061311-1623-99" target=_blank>KEDEBE.D</a> WORM!
  3746. Source=Paul Collins Startup list
  3747.  
  3748. [Anti-Virus Update Scheduler]
  3749. Number=532
  3750. Confirmed=X
  3751. Filename=[path to trojan]
  3752. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojspammita.html" target=_blank>SPAMMIT-A</a> TROJAN!
  3753. Source=Paul Collins Startup list
  3754.  
  3755. [Anti-Virus Update Scheduler]
  3756. Number=533
  3757. Confirmed=X
  3758. Filename=winsp3.exe
  3759. Description=Malware - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other systems via the compromised system
  3760. Source=Paul Collins Startup list
  3761.  
  3762. [Anti-Virus Update Scheduler V1.39.12R]
  3763. Number=534
  3764. Confirmed=X
  3765. Filename=[path to trojan]
  3766. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050122-5053-99" target="_blank">HEPLANE</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050215-0935-99" target="_blank">STAPREW.B</a> TROJANS! - different filenames have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more...
  3767. Source=Paul Collins Startup list
  3768.  
  3769. [AntiClicker]
  3770. Number=535
  3771. Confirmed=X
  3772. Filename=SVCHST32.EXE
  3773. Description=Added by the <a href="http://vil.nai.com/vil/content/v_100928.htm" target="_blank">CBH</a> TROJAN!
  3774. Source=Paul Collins Startup list
  3775.  
  3776. [antidialer.co.uk]
  3777. Number=536
  3778. Confirmed=U
  3779. Filename=Dialer_Watcher.exe
  3780. Description=<a href="http://freespace.virgin.net/glenn.fletcher/index2.htm" target="_blank">Dialer_Watcher</a> is an application that allows you to detect <a href="http://www.mcgill.ca/ncs/products/security/threatsdangers/virus/dialers/" target="_blank">dialers</a> on your computer
  3781. Source=Paul Collins Startup list
  3782.  
  3783. [AntiPopUp]
  3784. Number=537
  3785. Confirmed=U
  3786. Filename=AntiPopUp.exe
  3787. Description=<a href="http://www.webknacks.com/antipopup.htm" target="_blank">AntiPopUp for IE</a> - pop-up stopper
  3788. Source=Paul Collins Startup list
  3789.  
  3790. [AntiVerminser]
  3791. Number=538
  3792. Confirmed=N
  3793. Filename=AntiVerminser.exe
  3794. Description=Spyware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  3795. Source=Paul Collins Startup list
  3796.  
  3797. [Antivir]
  3798. Number=539
  3799. Confirmed=X
  3800. Filename=svchst.exe
  3801. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojragruka.html" target=_blank>RAGRUK-A</a> TROJAN!
  3802. Source=Paul Collins Startup list
  3803.  
  3804. [AntiVir]
  3805. Number=540
  3806. Confirmed=X
  3807. Filename=scvhost.exe
  3808. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentdsf.html" target="_blank">AGENT-DSF</a> TROJAN!
  3809. Source=Paul Collins Startup list
  3810.  
  3811. [AntiVir]
  3812. Number=541
  3813. Confirmed=X
  3814. Filename=winlog.exe
  3815. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbottj.html" target="_blank">IRCBOT-TJ</a> TROJAN!
  3816. Source=Paul Collins Startup list
  3817.  
  3818. [AntiVir XP]
  3819. Number=542
  3820. Confirmed=Y
  3821. Filename=AVwin.exe
  3822. Description=<a href="http://www.free-av.com/" target=_blank>AntiVir« PersonalEdition Classic</a> - antivirus
  3823.  
  3824. Source=Paul Collins Startup list
  3825.  
  3826. [Antivirus]
  3827. Number=543
  3828. Confirmed=X
  3829. Filename=av.exe
  3830. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-101417-5541-99" target="_blank">SINKIN</a> TROJAN! Resets IE start page to realphx.com
  3831. Source=Paul Collins Startup list
  3832.  
  3833. [Antivirus]
  3834. Number=544
  3835. Confirmed=X
  3836. Filename=maja.exe
  3837. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-030509-1444-99" target="_blank">NETSKY.H</a> WORM!
  3838. Source=Paul Collins Startup list
  3839.  
  3840. [Antivirus]
  3841. Number=545
  3842. Confirmed=X
  3843. Filename=iexpl0res.exe
  3844. Description=Added by an unidentified WORM or TROJAN!
  3845. Source=Paul Collins Startup list
  3846.  
  3847. [AntiVirus]
  3848. Number=546
  3849. Confirmed=X
  3850. Filename=kaspery.exe
  3851. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  3852. Source=Paul Collins Startup list
  3853.  
  3854. [Antivirus Installer]
  3855. Number=547
  3856. Confirmed=X
  3857. Filename=[path to trojan]
  3858. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbadgenta.html" target=_blank>BADGENT-A</a> TROJAN!
  3859. Source=Paul Collins Startup list
  3860.  
  3861. [Antivirus-Golden]
  3862. Number=548
  3863. Confirmed=N
  3864. Filename=Antivirus-Golden.exe
  3865. Description=Spyware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  3866. Source=Paul Collins Startup list
  3867.  
  3868. [antivirus32]
  3869. Number=549
  3870. Confirmed=X
  3871. Filename=antivirus.exe
  3872. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022323-4358-99" target=_blank>SPYBOT.KAI</a> WORM!
  3873. Source=Paul Collins Startup list
  3874.  
  3875. [AntivirusGold]
  3876. Number=550
  3877. Confirmed=X
  3878. Filename=AntivirusGold.exe
  3879. Description=<a href="http://www3.ca.com/securityadvisor/pest/Pest.aspx?id=453094194" target="_blank">AntivirusGold</a> malware
  3880. Source=Paul Collins Startup list
  3881.  
  3882. [AntiVirusProtection]
  3883. Number=551
  3884. Confirmed=?
  3885. Filename=qumk.exe
  3886. Description=<font color="#FF0000">??</font>
  3887. Source=Paul Collins Startup list
  3888.  
  3889. [antiware]
  3890. Number=552
  3891. Confirmed=X
  3892. Filename=elite***32.exe [*** = random char]
  3893. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderhw.html" target=_blank>DLOADER-HW</a> TROJAN!
  3894. Source=Paul Collins Startup list
  3895.  
  3896. [AntiWindowsMessenger]
  3897. Number=553
  3898. Confirmed=U
  3899. Filename=AntiMsMsg.exe
  3900. Description=<a href="http://fileforum.betanews.com/detail/1069500643/1" target="_blank">Anti-Windows_Messenger</a> is a small application that prevents Windows Messenger from remaining resident in memory
  3901. Source=Paul Collins Startup list
  3902.  
  3903. [anti_troj]
  3904. Number=554
  3905. Confirmed=X
  3906. Filename=anti_troj.exe
  3907. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-112315-1052-99" target=_blank>LODEAR.D</a> TROJAN!
  3908. Source=Paul Collins Startup list
  3909.  
  3910. [AnVir]
  3911. Number=555
  3912. Confirmed=Y
  3913. Filename=AnVir.exe
  3914. Description=<a href="http://anvir.com/taskmanager/" target="_blank">AnVir Task Manager</a> - protects computer against viruses and manages running processes and startup files
  3915. Source=Paul Collins Startup list
  3916.  
  3917. [AnVir Task Manager]
  3918. Number=556
  3919. Confirmed=Y
  3920. Filename=AnVir.exe
  3921. Description=<a href="http://anvir.com/taskmanager/" target="_blank">AnVir Task Manager</a> - protects computer against viruses and manages running processes and startup files
  3922. Source=Paul Collins Startup list
  3923.  
  3924. [anvshell]
  3925. Number=557
  3926. Confirmed=U
  3927. Filename=anvshell.exe
  3928. Description=System Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
  3929. Source=Paul Collins Startup list
  3930.  
  3931. [Any To-Do List]
  3932. Number=558
  3933. Confirmed=U
  3934. Filename=anytodo.exe
  3935. Description=<a href="http://www.anyutils.com/anytodo.htm" target=_blank>Any To-Do List</a> "the ultimate software solution to keep yourself organized and reminded"
  3936.  
  3937. Source=Paul Collins Startup list
  3938.  
  3939. [anycom bluetooth]
  3940. Number=559
  3941. Confirmed=?
  3942. Filename=ftflauncher.exe
  3943. Description=Associated with an Anycom bluetooth wireless card. <font color="#FF0000">What does it do and is it required?</font>
  3944. Source=Paul Collins Startup list
  3945.  
  3946. [AnyDVD]
  3947. Number=560
  3948. Confirmed=U
  3949. Filename=AnyDVD.exe
  3950. Description=<a href="http://www.slysoft.com/en/anydvd.html" target="_blank">AnyDVD</a> - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the "U" recommendation
  3951. Source=Paul Collins Startup list
  3952.  
  3953. [AO Tray]
  3954. Number=561
  3955. Confirmed=N
  3956. Filename=AOTray.Exe
  3957. Description=System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
  3958. Source=Paul Collins Startup list
  3959.  
  3960. [aol]
  3961. Number=562
  3962. Confirmed=Y
  3963. Filename=avp.exe
  3964. Description=AOL's <a href="http://www.securitycadets.com/2006/08/aols-active-virus-shield-in-a-nutshell/" target="_blank">Active Virus Shield</a>
  3965. Source=Paul Collins Startup list
  3966.  
  3967. [AOL 9.0 Optimized]
  3968. Number=563
  3969. Confirmed=X
  3970. Filename=AOLClient.exe
  3971. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-021517-4127-99" target=_blank>SPYBOTER.A</a> TROJAN!
  3972. Source=Paul Collins Startup list
  3973.  
  3974. [AOL Broadband Check-Up]
  3975. Number=564
  3976. Confirmed=U
  3977. Filename=matcli.exe
  3978. Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
  3979. Source=Paul Collins Startup list
  3980.  
  3981. [AOL Companion]
  3982. Number=565
  3983. Confirmed=N
  3984. Filename=companion.exe
  3985. Description=Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use
  3986.  
  3987. Source=Paul Collins Startup list
  3988.  
  3989. [Aol Configuration Loader]
  3990. Number=566
  3991. Confirmed=X
  3992. Filename=aimsng.exe
  3993. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxe.html" target=_blank>SDBOT-XE</a> WORM!
  3994. Source=Paul Collins Startup list
  3995.  
  3996. [AOL Fast Start]
  3997. Number=567
  3998. Confirmed=?
  3999. Filename=AOL.exe
  4000. Description=AOL ISP software related. <font color="#FF0000">What does it do and is it required?</font>
  4001. Source=Paul Collins Startup list
  4002.  
  4003. [AOL Instant Messanger]
  4004. Number=568
  4005. Confirmed=X
  4006. Filename=aim.exe
  4007. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotyt.html" target=_blank>SDBOT-YT</a> WORM!
  4008. Source=Paul Collins Startup list
  4009.  
  4010. [AOL Instant Messengar]
  4011. Number=569
  4012. Confirmed=X
  4013. Filename=aol.exe
  4014. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotfn.html" target="_blank">AGOBOT-FN</a> WORM!
  4015. Source=Paul Collins Startup list
  4016.  
  4017. [AOL Instant Messenger]
  4018. Number=570
  4019. Confirmed=?
  4020. Filename=AlM.EXE
  4021. Description=That is an L between the A and M, the start up location is wrong for AIM. <font color="#FF0000">What does this relate to?</font>
  4022. Source=Paul Collins Startup list
  4023.  
  4024. [Aol Instant Messenger]
  4025. Number=571
  4026. Confirmed=X
  4027. Filename=aolmsg.exe
  4028. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042300-3701-99" target="_blank">KELVIR.AL</a> WORM!
  4029. Source=Paul Collins Startup list
  4030.  
  4031. [AOL Instant Messenger 7.213]
  4032. Number=572
  4033. Confirmed=X
  4034. Filename=aim9283.exe
  4035. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotzf.html" target=_blank>SDBOT-ZF</a> WORM!
  4036. Source=Paul Collins Startup list
  4037.  
  4038. [Aol Instant Messenger Fix]
  4039. Number=573
  4040. Confirmed=X
  4041. Filename=aolfix.exe
  4042. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotabj.html" target=_blank>SDBOT-ABJ</a> WORM!
  4043. Source=Paul Collins Startup list
  4044.  
  4045. [AOL Messenger]
  4046. Number=574
  4047. Confirmed=X
  4048. Filename=[random filename]
  4049. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  4050. Source=Paul Collins Startup list
  4051.  
  4052. [AOL Messenger]
  4053. Number=575
  4054. Confirmed=X
  4055. Filename=aolmsngr.exe
  4056. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotjf.html" target=_blank>SDBOT-JF</a> WORM!
  4057. Source=Paul Collins Startup list
  4058.  
  4059. [AOL Messenger Optimized]
  4060. Number=576
  4061. Confirmed=X
  4062. Filename=AOLOpt.exe
  4063. Description=Added by the <a href="http://www.superadblocker.com/definition/aolopt/" target=_blank>AOLOPT</a> TROJAN! 
  4064.  
  4065. Source=Paul Collins Startup list
  4066.  
  4067. [AOL Services Hosts]
  4068. Number=577
  4069. Confirmed=X
  4070. Filename=aolserviceshosts.exe
  4071. Description=Added by an unidentified WORM or TROJAN!
  4072. Source=Paul Collins Startup list
  4073.  
  4074. [AOL Spyware Protection]
  4075. Number=578
  4076. Confirmed=U
  4077. Filename=AOLSP Scheduler.exe
  4078. Description=AOL's spyware protection program
  4079. Source=Paul Collins Startup list
  4080.  
  4081. [AOL TopSpeedMonitor]
  4082. Number=579
  4083. Confirmed=U
  4084. Filename=aoltsmon.exe
  4085. Description=AOL's <a href="http://site.aol.com/price_plans/bfsdialup.adp" target=_blank>TopSpeed</a> web acceleration technology supposedly helps to make web browsing faster. Most important for those users who still access AOL via dial-up
  4086. Source=Paul Collins Startup list
  4087.  
  4088. [AolAcsDaemon1]
  4089. Number=580
  4090. Confirmed=Y
  4091. Filename=Acsd.exe
  4092. Description=AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
  4093. Source=Paul Collins Startup list
  4094.  
  4095. [AolAcsDaemon1]
  4096. Number=581
  4097. Confirmed=Y
  4098. Filename=AOLACSD.EXE
  4099. Description=AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
  4100. Source=Paul Collins Startup list
  4101.  
  4102. [AOLCC]
  4103. Number=582
  4104. Confirmed=?
  4105. Filename=ACCAgnt.exe
  4106. Description=AOL ISP software related, file located in a "AOL Computer Check-Up" folder. <font color="#FF0000">What does it do and is it required?</font>
  4107. Source=Paul Collins Startup list
  4108.  
  4109. [AolCon]
  4110. Number=583
  4111. Confirmed=X
  4112. Filename=config.com
  4113. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-112012-0423-99" target="_blank">TAPLAK</a> WORM!
  4114. Source=Paul Collins Startup list
  4115.  
  4116. [AOLDialer]
  4117. Number=584
  4118. Confirmed=N
  4119. Filename=AOLDial.exe
  4120. Description=AOL ISP software dialer - can be activated through a desktop shortcut
  4121. Source=Paul Collins Startup list
  4122.  
  4123. [AolFix]
  4124. Number=585
  4125. Confirmed=N
  4126. Filename=AolFix.exe
  4127. Description=Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL  to run correctly. Not seen much any more and should only run once
  4128. Source=Paul Collins Startup list
  4129.  
  4130. [AOLRegKey32]
  4131. Number=586
  4132. Confirmed=X
  4133. Filename=AOREGSVR512.EXE
  4134. Description=Unidentified malware - see <a href="http://fileinfo.prevx.com/QQ2cb317153874-AORE13820788/AOREGSVR512.EXE.html" target=_blank>here</a>
  4135.  
  4136. Source=Paul Collins Startup list
  4137.  
  4138. [AOLStart]
  4139. Number=587
  4140. Confirmed=X
  4141. Filename=AOLStart.exe
  4142. Description=Added by the <a href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=41605" target="_blank">KRAIMER.12</a> TROJAN!
  4143. Source=Paul Collins Startup list
  4144.  
  4145. [Aornum]
  4146. Number=588
  4147. Confirmed=X
  4148. Filename=aornum.exe
  4149. Description=Installed along with <a href="http://www.iwon.com/home/prizes/pm3_overview/0,21311,,00.html?PG=home?SEC=fnstf">iWon Prize Machine</a>. Based upon their <a href="http://www.iwon.com/home/companyinfo/privacy/privacy_overview/0,11882,,00.html#1">privacy</a> statement this can be regarded as spyware
  4150. Source=Paul Collins Startup list
  4151.  
  4152. [AOTray]
  4153. Number=589
  4154. Confirmed=N
  4155. Filename=AOTray.Exe
  4156. Description=System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
  4157. Source=Paul Collins Startup list
  4158.  
  4159. [APC UPS Status]
  4160. Number=590
  4161. Confirmed=Y
  4162. Filename=Display.exe
  4163. Description=<a href="http://www.apcc.com/products/family/index.cfm?id=129&web_displayed=" target="_blank">APC PowerChute Personal Edition</a> status icon
  4164. Source=Paul Collins Startup list
  4165.  
  4166. [APC_SERVICE]
  4167. Number=591
  4168. Confirmed=U
  4169. Filename=mainserv.exe
  4170. Description=<a href="http://www.apcc.com/tools/download/software_comp.cfm?sw_sku=SDW75" target="_blank">PowerChute« Personal Edition</a> - "safe system shutdown software with sophisticated power management functions"
  4171. Source=Paul Collins Startup list
  4172.  
  4173. [apc_tray]
  4174. Number=592
  4175. Confirmed=Y
  4176. Filename=apc_tray.exe
  4177. Description=Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
  4178. Source=Paul Collins Startup list
  4179.  
  4180. [APD123]
  4181. Number=593
  4182. Confirmed=X
  4183. Filename=APD123.exe
  4184. Description=<a href="http://www.benedelman.org/spyware/installations/pacerd/" target=_blank>PacerD Media/Pacimedia.com</a> adware
  4185. Source=Paul Collins Startup list
  4186.  
  4187. [Api**.exe [* = random char]]
  4188. Number=594
  4189. Confirmed=X
  4190. Filename=Api**.exe [* = random char]
  4191. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  4192. Source=Paul Collins Startup list
  4193.  
  4194. [Api**32.exe [* = random char]]
  4195. Number=595
  4196. Confirmed=X
  4197. Filename=Api**32.exe [* = random char]
  4198. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  4199. Source=Paul Collins Startup list
  4200.  
  4201. [API32]
  4202. Number=596
  4203. Confirmed=X
  4204. Filename=api32.exe
  4205. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbotb.html" target=_blank>IRCBOT-B</a> TROJAN!
  4206. Source=Paul Collins Startup list
  4207.  
  4208. [APIClass]
  4209. Number=597
  4210. Confirmed=X
  4211. Filename=lexplore_.exe
  4212. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmsnopta.html" target=_blank>MSNOPT-A</a> TROJAN!
  4213. Source=Paul Collins Startup list
  4214.  
  4215. [APIMon]
  4216. Number=598
  4217. Confirmed=X
  4218. Filename=apimonx.exe
  4219. Description=Added by the TIBSER.A downloader TROJAN!
  4220. Source=Paul Collins Startup list
  4221.  
  4222. [APIMon]
  4223. Number=599
  4224. Confirmed=X
  4225. Filename=winapix.exe
  4226. Description=Added by a variant of the TIBSER.A downloader TROJAN!
  4227. Source=Paul Collins Startup list
  4228.  
  4229. [APIMon]
  4230. Number=600
  4231. Confirmed=X
  4232. Filename=msreg.exe
  4233. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DROPPER.Z" target="_blank">DROPPER.Z</a> TROJAN!
  4234. Source=Paul Collins Startup list
  4235.  
  4236. [apisvc.exe]
  4237. Number=601
  4238. Confirmed=X
  4239. Filename=apisvc.exe
  4240. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_116121.htm" target=_blank>LAMEBOT</a> TROJAN!
  4241. Source=Paul Collins Startup list
  4242.  
  4243. [APL]
  4244. Number=602
  4245. Confirmed=U
  4246. Filename=APL.exe
  4247. Description=Sage Software's <a href="http://www.act.com/products/index.cfm" target="_blank">ACT!</a> The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application
  4248. Source=Paul Collins Startup list
  4249.  
  4250. [Apmsrv9x]
  4251. Number=603
  4252. Confirmed=?
  4253. Filename=APMSRV9X.EXE
  4254. Description=<a target="_blank" href="http://www.intel.com/support/network/anypoint/">Intel AnyPoint</a> Wireless II Home Network related. Now discontinued. <font color="#FF0000">What does it do and is it required?</font>
  4255. Source=Paul Collins Startup list
  4256.  
  4257. [Apoint]
  4258. Number=604
  4259. Confirmed=U
  4260. Filename=Apoint.exe
  4261. Description=Touchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
  4262. Source=Paul Collins Startup list
  4263.  
  4264. [App**32.exe [* = random char]]
  4265. Number=605
  4266. Confirmed=X
  4267. Filename=App**32.exe [* = random char]
  4268. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  4269. Source=Paul Collins Startup list
  4270.  
  4271. [App.EXEName]
  4272. Number=606
  4273. Confirmed=X
  4274. Filename=[path to worm]\.exe
  4275. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-120812-3452-99" target="_blank">BODIRU</a> WORM!
  4276. Source=Paul Collins Startup list
  4277.  
  4278. [Appcon]
  4279. Number=607
  4280. Confirmed=U
  4281. Filename=vAppCon.exe
  4282. Description=Vital Application Console - part of <a href="http://www.pos-partner.com/Product.htm" target="_blank">POS-partner 2000</a> point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established
  4283. Source=Paul Collins Startup list
  4284.  
  4285. [appconn]
  4286. Number=608
  4287. Confirmed=X
  4288. Filename=appconn.exe
  4289. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-071414-1355-99" target="_blank">CARGAO</a> WORM!
  4290. Source=Paul Collins Startup list
  4291.  
  4292. [AppExtender]
  4293. Number=609
  4294. Confirmed=U
  4295. Filename=AppExtCB.exe
  4296. Description=Loads the <a href="http://www.confimax.com/?PHPSESSID=aefc68296846f048b5b7ae96e48d854f" target="_blank">Confimax</a> add-in for popular E-mail programs to confirm E-mails have been sent and received
  4297. Source=Paul Collins Startup list
  4298.  
  4299. [appis.exe]
  4300. Number=610
  4301. Confirmed=X
  4302. Filename=appis.exe
  4303. Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088191" target="_blank">AGENT-BC</a> TROJAN!
  4304. Source=Paul Collins Startup list
  4305.  
  4306. [Application]
  4307. Number=611
  4308. Confirmed=Y
  4309. Filename=mdmsetsp.exe
  4310. Description=<a href="http://www.aztech.com/" target=_blank>Aztech Labs</a> modem driver
  4311. Source=Paul Collins Startup list
  4312.  
  4313. [Application Explorer]
  4314. Number=612
  4315. Confirmed=U
  4316. Filename=Naldesk.exe
  4317. Description=Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components." 
  4318. Source=Paul Collins Startup list
  4319.  
  4320. [Application Explorer]
  4321. Number=613
  4322. Confirmed=U
  4323. Filename=NalView.exe
  4324. Description=<a href="http://www.novell.com/documentation/zdfs/index.html?page=/documentation/zdfs/zdfsadmn/data/acpsmx1.html" target="_blank">Application Explorer</a> - file manager type access to Novell Application Launcher for installing and updating network residing applications
  4325. Source=Paul Collins Startup list
  4326.  
  4327. [Application Layer Gateway Service]
  4328. Number=614
  4329. Confirmed=X
  4330. Filename=algs.exe
  4331. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-052109-2651-99" target=_blank>LINKBOT.M</a> WORM!
  4332. Source=Paul Collins Startup list
  4333.  
  4334. [ApplicationProtocolRun]
  4335. Number=615
  4336. Confirmed=X
  4337. Filename=smsbvl32.exe
  4338. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbotcx.html" target="_blank">IRCBOT-CX</a> TROJAN!
  4339. Source=Paul Collins Startup list
  4340.  
  4341. [AppPlus]
  4342. Number=616
  4343. Confirmed=U
  4344. Filename=AppPlus.exe
  4345. Description=<a href="http://www.appplusonline.com/" target="_blank">AppPlus</a> - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)"
  4346. Source=Paul Collins Startup list
  4347.  
  4348. [Apvxd]
  4349. Number=617
  4350. Confirmed=Y
  4351. Filename=APVXDWIN.EXE
  4352. Description=Part of <a href="http://www.pandasoftware.com/home/particulares/default" target="_blank">Panda Antivirus </a>. Required to enable permanent virus protection
  4353. Source=Paul Collins Startup list
  4354.  
  4355. [Apvxdwin]
  4356. Number=618
  4357. Confirmed=Y
  4358. Filename=APVXDWIN.EXE
  4359. Description=Part of <a href="http://www.pandasoftware.com/home/particulares/default" target="_blank">Panda Antivirus </a>. Required to enable permanent virus protection
  4360. Source=Paul Collins Startup list
  4361.  
  4362. [Apwheel]
  4363. Number=619
  4364. Confirmed=Y
  4365. Filename=Apwheel.exe
  4366. Description=Wheel support for an Alps mouse 
  4367. Source=Paul Collins Startup list
  4368.  
  4369. [apyginapygin]
  4370. Number=620
  4371. Confirmed=X
  4372. Filename=simenu.exe
  4373. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BTR&VSect=P" target=_blank>SDBOT.BTR</a> WORM!
  4374. Source=Paul Collins Startup list
  4375.  
  4376. [AQ3HelperStartUp]
  4377. Number=621
  4378. Confirmed=U
  4379. Filename=AQ3HEL~1.EXE
  4380. Description=ScreenScenes "Aquatica Water Worlds" screensaver. The freeware version comes with <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.GAIN.CommonElements&threatid=5605" target="_blank">GAIN</a> branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  4381. Source=Paul Collins Startup list
  4382.  
  4383. [aqadcup.exe]
  4384. Number=622
  4385. Confirmed=X
  4386. Filename=aqadcup.exe
  4387. Description=Added by the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/aqadcup/" target="_blank">AGENT.BG</a> WORM!
  4388. Source=Paul Collins Startup list
  4389.  
  4390. [Aqujyjax]
  4391. Number=623
  4392. Confirmed=X
  4393. Filename=[path to file]
  4394. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojranckcq.html" target="_blank">RANCK-CQ</a> TROJAN!
  4395. Source=Paul Collins Startup list
  4396.  
  4397. [Aqujyjax]
  4398. Number=624
  4399. Confirmed=X
  4400. Filename=aqujyjax.exe
  4401. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotyc.html" target="_blank">SDBOT-YC</a> WORM!
  4402. Source=Paul Collins Startup list
  4403.  
  4404. [ara-key]
  4405. Number=625
  4406. Confirmed=X
  4407. Filename=[random filename]
  4408. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080817-4045-99" target="_blank">ANTINNY</a> WORM!
  4409. Source=Paul Collins Startup list
  4410.  
  4411. [arcaderockstar]
  4412. Number=626
  4413. Confirmed=X
  4414. Filename=arcaderockstar32.exe
  4415. Description=Arcade Rockstar (now <a href="http://www.gamevance.com/" target="_blank">Gamevance</a>) - free arcade games and prize tournaments. The program itself is clean, but the TOS and privacy statement say that you agree to allow the program to track/report your surfing and put popup advertising on your computer
  4416. Source=Paul Collins Startup list
  4417.  
  4418. [Archive]
  4419. Number=627
  4420. Confirmed=X
  4421. Filename=archive.exe
  4422. Description=Adware - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan-Downloader.Centim.a
  4423. Source=Paul Collins Startup list
  4424.  
  4425. [ARCHIVE CONTROL]
  4426. Number=628
  4427. Confirmed=X
  4428. Filename=fixupdattr.exe
  4429. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-070712-1709-99" target=_blank>MYTOB.GU</a> WORM!
  4430. Source=Paul Collins Startup list
  4431.  
  4432. [ARCSolo Recovery]
  4433. Number=629
  4434. Confirmed=N
  4435. Filename=N/A
  4436. Description=Backup software by Computer Associates - no longer supported
  4437. Source=Paul Collins Startup list
  4438.  
  4439. [Ardamax Keylogger]
  4440. Number=630
  4441. Confirmed=U
  4442. Filename=akl.exe
  4443. Description=<a href="http://www.bleepingcomputer.com/startups/akl.exe-10964.html" target=_blank>Ardakey B</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  4444.  
  4445. Source=Paul Collins Startup list
  4446.  
  4447. [ares]
  4448. Number=631
  4449. Confirmed=N
  4450. Filename=ares.exe
  4451. Description="<a href="http://aresgalaxy.sourceforge.net/" target="_blank">Ares</a> is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc"
  4452. Source=Paul Collins Startup list
  4453.  
  4454. [areslite]
  4455. Number=632
  4456. Confirmed=N
  4457. Filename=AresLite.exe
  4458. Description="<a href="http://aresgalaxy.sourceforge.net/" target="_blank">Ares</a> is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc"
  4459. Source=Paul Collins Startup list
  4460.  
  4461. [Argentum Backup]
  4462. Number=633
  4463. Confirmed=U
  4464. Filename=ab.exe
  4465. Description=<a href="http://www.argentuma.com/backup.html" target="_blank">Argentum Backup</a> - a small backup program that lets you easily back up your documents and folders
  4466. Source=Paul Collins Startup list
  4467.  
  4468. [Aritima]
  4469. Number=634
  4470. Confirmed=X
  4471. Filename=aritima.exe
  4472. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-081915-4836-99" target="_blank">ARITIM</a> WORM!
  4473. Source=Paul Collins Startup list
  4474.  
  4475. [ARMOR2NET]
  4476. Number=635
  4477. Confirmed=N
  4478. Filename=Armor2net.exe
  4479. Description=Related to Armor2net personal firewall (possibly contains or is related to an anti-spyware product known as ArmorWall, which is a spyware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target=_blank>here</a>
  4480. Source=Paul Collins Startup list
  4481.  
  4482. [ARPWRMSG]
  4483. Number=636
  4484. Confirmed=N
  4485. Filename=ARPWRMSG.EXE
  4486. Description=Related to HP and Compaq Desktop PCs. Read <a href="http://h10025.www1.hp.com:80/ewfrf/wc/genericDocument?docname=bph07149&cc=us&lc=en&dlc=en&dlc=en&lang=en" target="_blank">this</a> article
  4487. Source=Paul Collins Startup list
  4488.  
  4489. [Artera]
  4490. Number=637
  4491. Confirmed=U
  4492. Filename=arteraui.exe
  4493. Description=<a href="http://www.arteraturbo.com/" target="_blank">Artera Turbo Internet Accelerator</a> - "surf faster, boost download speed". Only required if you find it helps improve your performance
  4494. Source=Paul Collins Startup list
  4495.  
  4496. [AS00 Gear511]
  4497. Number=638
  4498. Confirmed=?
  4499. Filename=Gear511.exe
  4500. Description=Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. <font color="#FF0000">Is it at all required?</font>
  4501. Source=Paul Collins Startup list
  4502.  
  4503. [AS00_WN511B]
  4504. Number=639
  4505. Confirmed=U
  4506. Filename=WN511B.exe
  4507. Description=Netgear <a href="http://www.netgear.com/Products/Adapters/RangeMaxNextWirelessAdapters/WN511B.aspx" target="_blank">RangeMax NEXT</a> wireless adapter configuration utility
  4508. Source=Paul Collins Startup list
  4509.  
  4510. [AS00_WPN511]
  4511. Number=640
  4512. Confirmed=?
  4513. Filename=WPN511.exe
  4514. Description=NetgearRev MFC Application - software for Netgear wireless network cards - <font color="#FF0000">what does it do and is it required in startup?</font>
  4515. Source=Paul Collins Startup list
  4516.  
  4517. [ASDPLUGIN]
  4518. Number=641
  4519. Confirmed=X
  4520. Filename=dsldbaccess.exe
  4521. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4522. Source=Paul Collins Startup list
  4523.  
  4524. [ASDPLUGIN]
  4525. Number=642
  4526. Confirmed=X
  4527. Filename=canada.exe
  4528. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4529. Source=Paul Collins Startup list
  4530.  
  4531. [ASDPLUGIN]
  4532. Number=643
  4533. Confirmed=X
  4534. Filename=france.exe
  4535. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4536. Source=Paul Collins Startup list
  4537.  
  4538. [ASDPLUGIN]
  4539. Number=644
  4540. Confirmed=X
  4541. Filename=fullgames.exe
  4542. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4543. Source=Paul Collins Startup list
  4544.  
  4545. [ASDPLUGIN]
  4546. Number=645
  4547. Confirmed=X
  4548. Filename=100171be.exe
  4549. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4550. Source=Paul Collins Startup list
  4551.  
  4552. [ASDPLUGIN]
  4553. Number=646
  4554. Confirmed=X
  4555. Filename=100176br.exe
  4556. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4557. Source=Paul Collins Startup list
  4558.  
  4559. [ASDPLUGIN]
  4560. Number=647
  4561. Confirmed=X
  4562. Filename=adult1.exe
  4563. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4564. Source=Paul Collins Startup list
  4565.  
  4566. [ASDPLUGIN]
  4567. Number=648
  4568. Confirmed=X
  4569. Filename=Austria.exe
  4570. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4571. Source=Paul Collins Startup list
  4572.  
  4573. [ASDPLUGIN]
  4574. Number=649
  4575. Confirmed=X
  4576. Filename=belgium nm.exe
  4577. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4578. Source=Paul Collins Startup list
  4579.  
  4580. [ASDPLUGIN]
  4581. Number=650
  4582. Confirmed=X
  4583. Filename=czech.exe
  4584. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4585. Source=Paul Collins Startup list
  4586.  
  4587. [ASDPLUGIN]
  4588. Number=651
  4589. Confirmed=X
  4590. Filename=dbaccess.exe
  4591. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4592. Source=Paul Collins Startup list
  4593.  
  4594. [ASDPLUGIN]
  4595. Number=652
  4596. Confirmed=X
  4597. Filename=dslgeaccess.exe
  4598. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4599. Source=Paul Collins Startup list
  4600.  
  4601. [ASDPLUGIN]
  4602. Number=653
  4603. Confirmed=X
  4604. Filename=Finland.exe
  4605. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4606. Source=Paul Collins Startup list
  4607.  
  4608. [ASDPLUGIN]
  4609. Number=654
  4610. Confirmed=X
  4611. Filename=geaccess.exe
  4612. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4613. Source=Paul Collins Startup list
  4614.  
  4615. [ASDPLUGIN]
  4616. Number=655
  4617. Confirmed=X
  4618. Filename=mexico.exe
  4619. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4620. Source=Paul Collins Startup list
  4621.  
  4622. [ASDPLUGIN]
  4623. Number=656
  4624. Confirmed=X
  4625. Filename=netherlands.exe
  4626. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4627. Source=Paul Collins Startup list
  4628.  
  4629. [ASDPLUGIN]
  4630. Number=657
  4631. Confirmed=X
  4632. Filename=turkey.exe
  4633. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4634. Source=Paul Collins Startup list
  4635.  
  4636. [ASDPLUGIN]
  4637. Number=658
  4638. Confirmed=X
  4639. Filename=uk nm.exe
  4640. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4641. Source=Paul Collins Startup list
  4642.  
  4643. [ASDPLUGIN]
  4644. Number=659
  4645. Confirmed=X
  4646. Filename=Xadult1.exe
  4647. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4648. Source=Paul Collins Startup list
  4649.  
  4650. [ASDPLUGIN]
  4651. Number=660
  4652. Confirmed=X
  4653. Filename=temp532.exe
  4654. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  4655. Source=Paul Collins Startup list
  4656.  
  4657. [asdx]
  4658. Number=661
  4659. Confirmed=X
  4660. Filename=xwinrpc32.exe
  4661. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.VO" target="_blank">AGOBOT.VO</a> WORM!
  4662. Source=Paul Collins Startup list
  4663.  
  4664. [ASE Scheduler]
  4665. Number=662
  4666. Confirmed=N
  4667. Filename=ASE Scheduler.exe
  4668. Description=Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see <a href="http://www.boston.com/business/technology/articles/2004/11/06/spyware_killer_displays_its_own_ads/" target=_blank>here</a> and <a href="http://netrn.net/spywareblog/archives/2004/11/06/aluria-confused/" target=_blank>here</a>
  4669. Source=Paul Collins Startup list
  4670.  
  4671. [Ashampoo PopUpBlocker]
  4672. Number=663
  4673. Confirmed=U
  4674. Filename=PopUpKiller.exe
  4675. Description=<a href="http://www.ashampoo.com/frontend/homepage/php/index.php?session_langid=2" target="_blank">Ashampoo</a> popup blocker, part of Magical Security (was Privacy Protector Plus)
  4676. Source=Paul Collins Startup list
  4677.  
  4678. [ashAvast]
  4679. Number=664
  4680. Confirmed=Y
  4681. Filename=ashAvast.exe
  4682. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast</a> antivirus
  4683. Source=Paul Collins Startup list
  4684.  
  4685. [ASHLT]
  4686. Number=665
  4687. Confirmed=X
  4688. Filename=Ashlt.exe
  4689. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100811-0814-99" target="_blank">Ashlt</a> adware
  4690. Source=Paul Collins Startup list
  4691.  
  4692. [ashMaiSv]
  4693. Number=666
  4694. Confirmed=Y
  4695. Filename=ashmaisv.exe
  4696. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast!</a> anti-virus software - E-mail scanner
  4697. Source=Paul Collins Startup list
  4698.  
  4699. [AsioReg]
  4700. Number=667
  4701. Confirmed=U
  4702. Filename=regsvr32.exe ctasio.dll
  4703. Description=<a href="http://www.soundblaster.com/resources/read.asp?articleid=53937&page=1&cat=2" target="_blank">ASIO</a> (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
  4704. Source=Paul Collins Startup list
  4705.  
  4706. [ASK]
  4707. Number=668
  4708. Confirmed=U
  4709. Filename=rundll32.exe [path] ASK.dll rdl
  4710. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-071816-1110-99" target=_blank>Stealth Keylogger</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  4711. Source=Paul Collins Startup list
  4712.  
  4713. [asl]
  4714. Number=669
  4715. Confirmed=X
  4716. Filename=Aslru.exe
  4717. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancoscu.html" target=_blank>BANCOS-CU</a> TROJAN!
  4718. Source=Paul Collins Startup list
  4719.  
  4720. [Asmw Soft Popups Burner]
  4721. Number=670
  4722. Confirmed=U
  4723. Filename=popups burner.exe
  4724. Description=Popup blocker, part of Asmw Soft <a href="http://www.asmwsoft.com/products/002.htm" target= blank>PC Optimizer</a>
  4725. Source=Paul Collins Startup list
  4726.  
  4727. [asnconsole]
  4728. Number=671
  4729. Confirmed=X
  4730. Filename=msasn.exe
  4731. Description=Added by the <a href="https://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=53404" target="_blank">RBOT.EVU</a> TROJAN!
  4732. Source=Paul Collins Startup list
  4733.  
  4734. [ASocksrv]
  4735. Number=672
  4736. Confirmed=X
  4737. Filename=SocksA.exe
  4738. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_VB.CBW" target="_blank">VB.CBW</a> WORM!
  4739. Source=Paul Collins Startup list
  4740.  
  4741. [ASP.NET State Service]
  4742. Number=673
  4743. Confirmed=X
  4744. Filename=csrss.exe
  4745. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderqi.html" target=_blank>DLOADER-QI</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
  4746. Source=Paul Collins Startup list
  4747.  
  4748. [ASP.NET State Service]
  4749. Number=674
  4750. Confirmed=X
  4751. Filename=crsass.exe
  4752. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbanloadm.html" target=_blank>BANLOAD-M</a> TROJAN!
  4753. Source=Paul Collins Startup list
  4754.  
  4755. [ASP.NET State Service]
  4756. Number=675
  4757. Confirmed=X
  4758. Filename=servicos..exe
  4759. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdadobrai.html" target=_blank>DADOBRA-I</a> TROJAN!
  4760. Source=Paul Collins Startup list
  4761.  
  4762. [asp4tray]
  4763. Number=676
  4764. Confirmed=N
  4765. Filename=asp4tray.exe
  4766. Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
  4767. Source=Paul Collins Startup list
  4768.  
  4769. [AspireTimeMachine]
  4770. Number=677
  4771. Confirmed=Y
  4772. Filename=acertmb.exe
  4773. Description=System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry
  4774. Source=Paul Collins Startup list
  4775.  
  4776. [asrupdate.exe]
  4777. Number=678
  4778. Confirmed=X
  4779. Filename=asrupdate.exe
  4780. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Win32.VB.atz&threatid=90801" target="_blank">VB.ATZ</a> TROJAN!
  4781. Source=Paul Collins Startup list
  4782.  
  4783. [assistse]
  4784. Number=679
  4785. Confirmed=X
  4786. Filename=ASSISTSE.EXE
  4787. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=3721%20Chinese%20Keywords%20(CNSMin)&threatid=3678" target="_blank">CnsMin</a> (Chinese Keywords) hijacker related
  4788. Source=Paul Collins Startup list
  4789.  
  4790. [AST]
  4791. Number=680
  4792. Confirmed=X
  4793. Filename=AST
  4794. Description=Added by the TROJANDOWNLOADER.WIN32.VB.AH VIRUS!
  4795. Source=Paul Collins Startup list
  4796.  
  4797. [AST]
  4798. Number=681
  4799. Confirmed=X
  4800. Filename=AST
  4801. Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453068322" target=_blank>VB.AH</a> TROJAN!
  4802. Source=Paul Collins Startup list
  4803.  
  4804. [AST]
  4805. Number=682
  4806. Confirmed=X
  4807. Filename=AST.exe
  4808. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082809" target=_blank>AutoStarter</a> parasite
  4809.  
  4810. Source=Paul Collins Startup list
  4811.  
  4812. [ASTART]
  4813. Number=683
  4814. Confirmed=U
  4815. Filename=astart.exe
  4816. Description=ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
  4817. Source=Paul Collins Startup list
  4818.  
  4819. [AStart]
  4820. Number=684
  4821. Confirmed=X
  4822. Filename=AStart
  4823. Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453068322" target=_blank>VB.AH</a> TROJAN!
  4824. Source=Paul Collins Startup list
  4825.  
  4826. [asTray]
  4827. Number=685
  4828. Confirmed=N
  4829. Filename=Astray.exe
  4830. Description=Voyetra Audio Station - part of <a href="http://www.voyetra.com/site/default.asp" target="_blank">Voyetra's</a> Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer
  4831. Source=Paul Collins Startup list
  4832.  
  4833. [Astro]
  4834. Number=686
  4835. Confirmed=N
  4836. Filename=Astro.exe
  4837. Description=Checks for updates to Quicken on a system reboot
  4838. Source=Paul Collins Startup list
  4839.  
  4840. [ASUS Live Update]
  4841. Number=687
  4842. Confirmed=N
  4843. Filename=ALU.exe
  4844. Description=ASUS Live Update utility for their motherboards
  4845. Source=Paul Collins Startup list
  4846.  
  4847. [ASUS Probe]
  4848. Number=688
  4849. Confirmed=N
  4850. Filename=AsusProb.exe
  4851. Description=ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
  4852. Source=Paul Collins Startup list
  4853.  
  4854. [ASUS SmartDoctor]
  4855. Number=689
  4856. Confirmed=U
  4857. Filename=VGAProbe.exe
  4858. Description=ASUS video card fan/thermal monitor
  4859. Source=Paul Collins Startup list
  4860.  
  4861. [ASUS TweakEnable]
  4862. Number=690
  4863. Confirmed=U
  4864. Filename=astart.exe
  4865. Description=Restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
  4866. Source=Paul Collins Startup list
  4867.  
  4868. [ASUSKey]
  4869. Number=691
  4870. Confirmed=N
  4871. Filename=V38SHELL.EXE
  4872. Description=System tray Icon for quickly changing video modes
  4873. Source=Paul Collins Startup list
  4874.  
  4875. [asustweakenable]
  4876. Number=692
  4877. Confirmed=U
  4878. Filename=ATweak.exe
  4879. Description=Asus tweaking utility - for fine tuning the settings of your ASUS display card
  4880. Source=Paul Collins Startup list
  4881.  
  4882. [ASWDP]
  4883. Number=693
  4884. Confirmed=N
  4885. Filename=ASWDP.exe
  4886. Description=<a href="http://www.mlspulse.com/login.jsp" target="_blank">MLS Pulse</a> - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market
  4887. Source=Paul Collins Startup list
  4888.  
  4889. [ASWnk]
  4890. Number=694
  4891. Confirmed=X
  4892. Filename=aswnk.exe
  4893. Description=Adult content dialler
  4894. Source=Paul Collins Startup list
  4895.  
  4896. [AT-Watch]
  4897. Number=695
  4898. Confirmed=U
  4899. Filename=ATWatch.exe
  4900. Description=Anti-Trojan Watch - trojan detector
  4901. Source=Paul Collins Startup list
  4902.  
  4903. [atapidrv]
  4904. Number=696
  4905. Confirmed=X
  4906. Filename=atapidrv.exe
  4907. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotsl.html" target=_blank>AGOBOT-SL</a> WORM!
  4908. Source=Paul Collins Startup list
  4909.  
  4910. [Athan]
  4911. Number=697
  4912. Confirmed=U
  4913. Filename=Athan.exe
  4914. Description=<a href="http://www.islamasoft.co.uk/products/athan/athansoftware.html" target=_blank>Athan</a> - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world
  4915. Source=Paul Collins Startup list
  4916.  
  4917. [ATI Active Graphics Card Monitor]
  4918. Number=698
  4919. Confirmed=X
  4920. Filename=atievx.exe
  4921. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32ircbottl.html" target="_blank">IRCBOT-TL</a> WORM!
  4922. Source=Paul Collins Startup list
  4923.  
  4924. [ATI AS Filter]
  4925. Number=699
  4926. Confirmed=X
  4927. Filename=msnse.exe
  4928. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotccy.html" target="_blank">RBOT-CCY</a> WORM! Note - modifies the HOSTS file by appending numerous lines, preventing access to the virus cleaning websites
  4929. Source=Paul Collins Startup list
  4930.  
  4931. [ATI CATALYST System Tray]
  4932. Number=700
  4933. Confirmed=N
  4934. Filename=CLI.exe SystemTray
  4935. Description=System Tray access to ATI's CATALYSTÖ CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop
  4936. Source=Paul Collins Startup list
  4937.  
  4938. [ATI DeviceDetect]
  4939. Number=701
  4940. Confirmed=N
  4941. Filename=ATIDtct.EXE
  4942. Description=Utility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
  4943. Source=Paul Collins Startup list
  4944.  
  4945. [ATI Display Driver]
  4946. Number=702
  4947. Confirmed=X
  4948. Filename=atixd.exe
  4949. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfov.html" target="_blank">RBOT-FOV</a> WORM!
  4950. Source=Paul Collins Startup list
  4951.  
  4952. [Ati Display Settings]
  4953. Number=703
  4954. Confirmed=X
  4955. Filename=atividx.exe
  4956. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgas.html" target="_blank">RBOT-GAS</a> WORM!
  4957. Source=Paul Collins Startup list
  4958.  
  4959. [ATI GART Set-up Utility]
  4960. Number=704
  4961. Confirmed=N
  4962. Filename=Atigart.exe
  4963. Description=Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed
  4964. Source=Paul Collins Startup list
  4965.  
  4966. [ATI Launchpad]
  4967. Number=705
  4968. Confirmed=U
  4969. Filename=launchpd.exe
  4970. Description=Convenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu
  4971. Source=Paul Collins Startup list
  4972.  
  4973. [ATI Rage3d Pro]
  4974. Number=706
  4975. Confirmed=X
  4976. Filename=AtiRage4dPro.exe
  4977. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotog.html" target=_blank>AGOBOT-OG</a> WORM!
  4978. Source=Paul Collins Startup list
  4979.  
  4980. [ATI Remote Control]
  4981. Number=707
  4982. Confirmed=Y
  4983. Filename=ATIRW.exe
  4984. Description=Driver for the <a href="http://www.ati.com/products/home-office.html" target=_blank>ATI REMOTE WONDERÖ</a> RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
  4985. Source=Paul Collins Startup list
  4986.  
  4987. [ATI Remote Control]
  4988. Number=708
  4989. Confirmed=Y
  4990. Filename=ATIX10.exe
  4991. Description=ATI <a href="http://www.ati.com/products/pc/remotewonder/" target="_blank">Remote WonderÖ</a> - PC wireless remote control driver. Required if you use it
  4992. Source=Paul Collins Startup list
  4993.  
  4994. [ATI Scheduler]
  4995. Number=709
  4996. Confirmed=N
  4997. Filename=Atisched.exe
  4998. Description=Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
  4999. Source=Paul Collins Startup list
  5000.  
  5001. [ATI Task Application]
  5002. Number=710
  5003. Confirmed=N
  5004. Filename=Atitkad.exe
  5005. Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
  5006. Source=Paul Collins Startup list
  5007.  
  5008. [ATI Task Application (Atikey)]
  5009. Number=711
  5010. Confirmed=N
  5011. Filename=Atitask.exe
  5012. Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
  5013. Source=Paul Collins Startup list
  5014.  
  5015. [ATI Technology Startup]
  5016. Number=712
  5017. Confirmed=X
  5018. Filename=techstart.exe
  5019. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaeu.html" target=_blank>RBOT-AEU</a> WORM!
  5020. Source=Paul Collins Startup list
  5021.  
  5022. [ATI Video Driver Control]
  5023. Number=713
  5024. Confirmed=X
  5025. Filename=atigfx.exe
  5026. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfwl.html" target="_blank">RBOT-FWL</a> WORM!
  5027. Source=Paul Collins Startup list
  5028.  
  5029. [ATI VIDEO REGKEY]
  5030. Number=714
  5031. Confirmed=X
  5032. Filename=ati2vid.exe
  5033. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.UR" target="_blank">SDBOT.UR</a> WORM!
  5034. Source=Paul Collins Startup list
  5035.  
  5036. [Ati2cwxx]
  5037. Number=715
  5038. Confirmed=?
  5039. Filename=Ati2cwxx.exe
  5040. Description=<font color="#FF0000">For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it </font>
  5041. Source=Paul Collins Startup list
  5042.  
  5043. [Ati2mdxx]
  5044. Number=716
  5045. Confirmed=U
  5046. Filename=Ati2mdxx.exe
  5047. Description=System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
  5048. Source=Paul Collins Startup list
  5049.  
  5050. [ATICCC]
  5051. Number=717
  5052. Confirmed=N
  5053. Filename=cli.exe runtime
  5054. Description=ATI's CATALYSTÖ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. Recommend that start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime as it can casue problems when starting Windows
  5055. Source=Paul Collins Startup list
  5056.  
  5057. [ATICCC]
  5058. Number=718
  5059. Confirmed=N
  5060. Filename=CLIStart.exe
  5061. Description=Puts the ATI CatalystÖ Control Center Icon/Shortcut on the System Tray - available via Start -> Programs
  5062. Source=Paul Collins Startup list
  5063.  
  5064. [aticpaxx.exe]
  5065. Number=719
  5066. Confirmed=X
  5067. Filename=aticpaxx.exe
  5068. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotxp.html" target= blank>RBOT-XP</a> WORM!
  5069. Source=Paul Collins Startup list
  5070.  
  5071. [AtiCwd]
  5072. Number=720
  5073. Confirmed=U
  5074. Filename=AtiCwd.exe
  5075. Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
  5076. Source=Paul Collins Startup list
  5077.  
  5078. [AtiCwd]
  5079. Number=721
  5080. Confirmed=U
  5081. Filename=AtiCwd32.exe
  5082. Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
  5083. Source=Paul Collins Startup list
  5084.  
  5085. [AtiCwd]
  5086. Number=722
  5087. Confirmed=U
  5088. Filename=Ati2cwad.exe
  5089. Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
  5090. Source=Paul Collins Startup list
  5091.  
  5092. [AtiCwd32]
  5093. Number=723
  5094. Confirmed=U
  5095. Filename=AtiCwd.exe
  5096. Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
  5097. Source=Paul Collins Startup list
  5098.  
  5099. [AtiCwd32]
  5100. Number=724
  5101. Confirmed=U
  5102. Filename=AtiCwd32.exe
  5103. Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
  5104. Source=Paul Collins Startup list
  5105.  
  5106. [AtiCwd32]
  5107. Number=725
  5108. Confirmed=U
  5109. Filename=Ati2cwad.exe
  5110. Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
  5111. Source=Paul Collins Startup list
  5112.  
  5113. [AtiDisplayDrv]
  5114. Number=726
  5115. Confirmed=X
  5116. Filename=atidrvxx.exe
  5117. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotvz.html" target= blank>RBOT-VZ</a> WORM!
  5118. Source=Paul Collins Startup list
  5119.  
  5120. [atidriver]
  5121. Number=727
  5122. Confirmed=X
  5123. Filename=reaIplayer.exe
  5124. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32warpigse.html" target=_blank>WARPIGS-E</a> WORM! Note the uppercase "I" in the filename, rather than a lower case "L"
  5125. Source=Paul Collins Startup list
  5126.  
  5127. [AtiKey]
  5128. Number=728
  5129. Confirmed=N
  5130. Filename=AtiKey32.exe
  5131. Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
  5132. Source=Paul Collins Startup list
  5133.  
  5134. [AtiKey]
  5135. Number=729
  5136. Confirmed=?
  5137. Filename=atiptkad.exe
  5138. Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
  5139. Source=Paul Collins Startup list
  5140.  
  5141. [Atikey]
  5142. Number=730
  5143. Confirmed=N
  5144. Filename=Atitask.exe
  5145. Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
  5146. Source=Paul Collins Startup list
  5147.  
  5148. [ATIMACE]
  5149. Number=731
  5150. Confirmed=U
  5151. Filename=MACE.exe
  5152. Description=ATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst Environment (MACE) component
  5153.  
  5154. Source=Paul Collins Startup list
  5155.  
  5156. [ATIModeChange]
  5157. Number=732
  5158. Confirmed=U
  5159. Filename=Ati2mdxx.exe
  5160. Description=System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
  5161. Source=Paul Collins Startup list
  5162.  
  5163. [AtiPanel]
  5164. Number=733
  5165. Confirmed=X
  5166. Filename=atip.exe
  5167. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.U</a> TROJAN!
  5168. Source=Paul Collins Startup list
  5169.  
  5170. [atipatxx]
  5171. Number=734
  5172. Confirmed=X
  5173. Filename=atipatxx.exe
  5174. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmalled.html" target=_blank>SMALL-ED</a> TROJAN!
  5175. Source=Paul Collins Startup list
  5176.  
  5177. [ATIPOLAB]
  5178. Number=735
  5179. Confirmed=U
  5180. Filename=ati2evxx.exe
  5181. Description=ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces  on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
  5182. Source=Paul Collins Startup list
  5183.  
  5184. [ATIPOLAB]
  5185. Number=736
  5186. Confirmed=U
  5187. Filename=ati2evae.exe
  5188. Description=ATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
  5189. Source=Paul Collins Startup list
  5190.  
  5191. [ATIPOLL]
  5192. Number=737
  5193. Confirmed=U
  5194. Filename=ati2evxx.exe
  5195. Description=ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces  on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
  5196. Source=Paul Collins Startup list
  5197.  
  5198. [AtiPTA]
  5199. Number=738
  5200. Confirmed=U
  5201. Filename=Ati2ptxx.exe
  5202. Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
  5203. Source=Paul Collins Startup list
  5204.  
  5205. [AtiPTA]
  5206. Number=739
  5207. Confirmed=U
  5208. Filename=Atiptaxx.exe
  5209. Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
  5210. Source=Paul Collins Startup list
  5211.  
  5212. [AtiPTAAA]
  5213. Number=740
  5214. Confirmed=U
  5215. Filename=Ati2ptxx.exe
  5216. Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
  5217. Source=Paul Collins Startup list
  5218.  
  5219. [AtiPTAAA]
  5220. Number=741
  5221. Confirmed=U
  5222. Filename=Atiptaxx.exe
  5223. Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
  5224. Source=Paul Collins Startup list
  5225.  
  5226. [atiptaxx]
  5227. Number=742
  5228. Confirmed=U
  5229. Filename=Ati2ptxx.exe
  5230. Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
  5231. Source=Paul Collins Startup list
  5232.  
  5233. [atiptaxx]
  5234. Number=743
  5235. Confirmed=U
  5236. Filename=Atiptaxx.exe
  5237. Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
  5238. Source=Paul Collins Startup list
  5239.  
  5240. [atiptext]
  5241. Number=744
  5242. Confirmed=X
  5243. Filename=atiptext.exe
  5244. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcosiama.html" target= blank>COSIAM-A</a> TROJAN!
  5245. Source=Paul Collins Startup list
  5246.  
  5247. [AtiQiPcl]
  5248. Number=745
  5249. Confirmed=U
  5250. Filename=AtiQiPcl.exe
  5251. Description=Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
  5252. Source=Paul Collins Startup list
  5253.  
  5254. [ATISmart]
  5255. Number=746
  5256. Confirmed=U
  5257. Filename=ati2s9ag.exe
  5258. Description=ATI's "SMARTGART", which is included with the "<a href="http://mirror.ati.com/products/pc/catalyst/index.html" target="_blank">Catalyst</a>" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings
  5259. Source=Paul Collins Startup list
  5260.  
  5261. [AtiSound]
  5262. Number=747
  5263. Confirmed=U
  5264. Filename=csrss.exe
  5265. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-110711-5846-99" target="_blank">WinSpy</a> surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "ComRoot" subfolder
  5266. Source=Paul Collins Startup list
  5267.  
  5268. [atisrc2]
  5269. Number=748
  5270. Confirmed=X
  5271. Filename=windfind.exe
  5272. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojwindfinda.html" target=_blank>WINDFIND-A</a> TROJAN!
  5273.  
  5274. Source=Paul Collins Startup list
  5275.  
  5276. [ATITech]
  5277. Number=749
  5278. Confirmed=X
  5279. Filename=Active.exe
  5280. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojroamera.html" target=_blank>ROAMER-A</a> TROJAN!
  5281. Source=Paul Collins Startup list
  5282.  
  5283. [atitray]
  5284. Number=750
  5285. Confirmed=U
  5286. Filename=atitray.exe
  5287. Description=ATI Tray Tools - allows quick access to ATI graphics card settings
  5288. Source=Paul Collins Startup list
  5289.  
  5290. [AtiTrayTools]
  5291. Number=751
  5292. Confirmed=U
  5293. Filename=atitray.exe
  5294. Description=ATI Tray Tools - allows quick access to ATI graphics card settings
  5295. Source=Paul Collins Startup list
  5296.  
  5297. [atiupdate]
  5298. Number=752
  5299. Confirmed=X
  5300. Filename=ATIUPDATE5.EXE
  5301. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS_DEBESKI.A" target="_blank">DEBESKI.A</a> TROJAN!
  5302. Source=Paul Collins Startup list
  5303.  
  5304. [atiupdate]
  5305. Number=753
  5306. Confirmed=X
  5307. Filename=msshed32.exe
  5308. Description=Added by the DELF.EP downloader TROJAN!
  5309. Source=Paul Collins Startup list
  5310.  
  5311. [ATIUpdater]
  5312. Number=754
  5313. Confirmed=X
  5314. Filename=atiupdxx.exe
  5315. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotabx.html" target= blank>RBOT-ABX</a> WORM!
  5316. Source=Paul Collins Startup list
  5317.  
  5318. [Atiupdpl]
  5319. Number=755
  5320. Confirmed=X
  5321. Filename=atiupdpl.exe
  5322. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_SMALL.AOS" target="_blank">SMALL.AOS</a> TROJAN!
  5323. Source=Paul Collins Startup list
  5324.  
  5325. [ativopen]
  5326. Number=756
  5327. Confirmed=X
  5328. Filename=ativopen.exe
  5329. Description=Premium rate adult content dialler
  5330. Source=Paul Collins Startup list
  5331.  
  5332. [ATIX10]
  5333. Number=757
  5334. Confirmed=Y
  5335. Filename=atix10.exe
  5336. Description=ATI <a href="http://www.ati.com/products/pc/remotewonder/" target="_blank">Remote WonderÖ</a> - PC wireless remote control driver. Required if you use it
  5337. Source=Paul Collins Startup list
  5338.  
  5339. [Atl**.exe [* = random char]]
  5340. Number=758
  5341. Confirmed=X
  5342. Filename=Atl**.exe [* = random char]
  5343. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  5344. Source=Paul Collins Startup list
  5345.  
  5346. [Atl**32.exe [* = random char]]
  5347. Number=759
  5348. Confirmed=X
  5349. Filename=Atl**32.exe [* = random char]
  5350. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  5351. Source=Paul Collins Startup list
  5352.  
  5353. [ATM Control]
  5354. Number=760
  5355. Confirmed=X
  5356. Filename=adpn.exe
  5357. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MMS.A&VSect=T" target="_blank">MMS.A</a> WORM!
  5358. Source=Paul Collins Startup list
  5359.  
  5360. [ATnotes]
  5361. Number=761
  5362. Confirmed=N
  5363. Filename=atnotes.exe
  5364. Description=Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
  5365. Source=Paul Collins Startup list
  5366.  
  5367. [Atomic Time Synchronizer]
  5368. Number=762
  5369. Confirmed=U
  5370. Filename=TimeSync.exe
  5371. Description=<a href="http://www.spdialer.com/timesync/" target="_blank">TimeSync</a> - lets you synchronize your computer's clock with any internet atomic clock
  5372. Source=Paul Collins Startup list
  5373.  
  5374. [Atomic-x27]
  5375. Number=763
  5376. Confirmed=X
  5377. Filename=Atomic-x27.exe
  5378. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32katomika.html" target=_blank>KATOMIK-A</a> WORM!
  5379. Source=Paul Collins Startup list
  5380.  
  5381. [Atomic-x27C]
  5382. Number=764
  5383. Confirmed=X
  5384. Filename=AtomicpartC.exe
  5385. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32katomika.html" target=_blank>KATOMIK-A</a> WORM!
  5386. Source=Paul Collins Startup list
  5387.  
  5388. [Atomic.exe]
  5389. Number=765
  5390. Confirmed=U
  5391. Filename=Atomic.exe
  5392. Description=<a href="http://www.worldtimeserver.com/atomic-clock/" target=_blank>Atomic Clock Sync</a> - synchronizes your computer's time with the NIST time server
  5393. Source=Paul Collins Startup list
  5394.  
  5395. [Atomica]
  5396. Number=766
  5397. Confirmed=N
  5398. Filename=atomica.exe
  5399. Description=<a href="http://www.atomica.com/" target="_blank">Atomica</a> runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key
  5400. Source=Paul Collins Startup list
  5401.  
  5402. [AtomicTime]
  5403. Number=767
  5404. Confirmed=U
  5405. Filename=ATOMICTIME.EXE
  5406. Description=<a href="http://schmail.com/atomictime/" target="_blank">AtomicTime</a> - utility that synchronizes your PC clock to an atomic clock
  5407. Source=Paul Collins Startup list
  5408.  
  5409. [Atrack]
  5410. Number=768
  5411. Confirmed=U
  5412. Filename=atrack.exe
  5413. Description=New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert
  5414. Source=Paul Collins Startup list
  5415.  
  5416. [Atray]
  5417. Number=769
  5418. Confirmed=U
  5419. Filename=Atray.exe
  5420. Description=<a href="http://www.activetray.com/" target="_blank">Active Tray</a> is a utility which lets you configure the system tray. You can also create your own tray icons
  5421. Source=Paul Collins Startup list
  5422.  
  5423. [ATSpooler]
  5424. Number=770
  5425. Confirmed=U
  5426. Filename=AppsTraka.exe
  5427. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-062416-0348-99" target= blank>DeskTopScout</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  5428. Source=Paul Collins Startup list
  5429.  
  5430. [ATTBroadbandUpdate]
  5431. Number=771
  5432. Confirmed=U
  5433. Filename=SAUpdate.exe
  5434. Description=<a href="http://bb4.com/" target="_blank">Big Brother</a> from Quest Software. System and network monitor
  5435. Source=Paul Collins Startup list
  5436.  
  5437. [ATTRedUpdate]
  5438. Number=772
  5439. Confirmed=U
  5440. Filename=AutoUpdate.exe
  5441. Description=Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
  5442. Source=Paul Collins Startup list
  5443.  
  5444. [AttuneClientEngine]
  5445. Number=773
  5446. Confirmed=X
  5447. Filename=attune_ce.exe
  5448. Description=Spyware - part of an automated helpdesk software called Aveo Attune
  5449. Source=Paul Collins Startup list
  5450.  
  5451. [AttuneContentUpdater]
  5452. Number=774
  5453. Confirmed=X
  5454. Filename=attune_cu.exe
  5455. Description=Spyware - part of an automated helpdesk software called Aveo Attune
  5456. Source=Paul Collins Startup list
  5457.  
  5458. [AttuneDiscovery]
  5459. Number=775
  5460. Confirmed=X
  5461. Filename=attune_di.exe
  5462. Description=Spyware - part of an automated helpdesk software called Aveo Attune
  5463. Source=Paul Collins Startup list
  5464.  
  5465. [Attunel]
  5466. Number=776
  5467. Confirmed=X
  5468. Filename=Attunel.exe
  5469. Description=Spyware - part of an automated helpdesk software called Aveo Attune
  5470. Source=Paul Collins Startup list
  5471.  
  5472. [AttuneSystray]
  5473. Number=777
  5474. Confirmed=X
  5475. Filename=attune_st.exe
  5476. Description=Spyware - part of an automated helpdesk software called Aveo Attune
  5477. Source=Paul Collins Startup list
  5478.  
  5479. [aTuner]
  5480. Number=778
  5481. Confirmed=N
  5482. Filename=atuner.exe
  5483. Description=<a href="http://www.3dcenter.de/atuner/index_e.php" target="_blank">aTuner</a> - tweak tool for GeForce based graphics cards
  5484. Source=Paul Collins Startup list
  5485.  
  5486. [atwtusb]
  5487. Number=779
  5488. Confirmed=Y
  5489. Filename=atwtusb.exe
  5490. Description=USB interface for Aiptek Graphics Tablet (USB)
  5491. Source=Paul Collins Startup list
  5492.  
  5493. [AtxBrw]
  5494. Number=780
  5495. Confirmed=X
  5496. Filename=Iexplor.exe
  5497. Description="Pop Marketing" adware
  5498. Source=Paul Collins Startup list
  5499.  
  5500. [au]
  5501. Number=781
  5502. Confirmed=U
  5503. Filename=DealioAu.exe
  5504. Description=<a href="http://www.dealio.com/toolbar/index.html" target="_blank">Dealio Toolbar</a> is a free shopping comparison toolbar that allows users to search for a wide range of consumer products
  5505. Source=Paul Collins Startup list
  5506.  
  5507. [AU Agent]
  5508. Number=782
  5509. Confirmed=U
  5510. Filename=AUagent.exe
  5511. Description=<a href="http://www.zilab.com/Products/Au/index_2.shtml" target="_blank">Au Agent</a> from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon
  5512. Source=Paul Collins Startup list
  5513.  
  5514. [au.exe]
  5515. Number=783
  5516. Confirmed=X
  5517. Filename=au.exe
  5518. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021713-3625-99" target="_blank">BEAGLE.B</a> WORM!
  5519. Source=Paul Collins Startup list
  5520.  
  5521. [AUCBPNP]
  5522. Number=784
  5523. Confirmed=Y
  5524. Filename=aucbnpn.exe
  5525. Description=Adaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
  5526. Source=Paul Collins Startup list
  5527.  
  5528. [Aucompat]
  5529. Number=785
  5530. Confirmed=X
  5531. Filename=Aucompat.exe
  5532. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  5533. Source=Paul Collins Startup list
  5534.  
  5535. [Audcntr]
  5536. Number=786
  5537. Confirmed=X
  5538. Filename=audcntr.exe
  5539. Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=40574" target=_blank>GEMA</a> TROJAN!
  5540. Source=Paul Collins Startup list
  5541.  
  5542. [AudCtrl]
  5543. Number=787
  5544. Confirmed=?
  5545. Filename=RunDll32 AudCtrl.dll, RCMonitor
  5546. Description=<font color="#FF0000">Audio control panel?</font>
  5547. Source=Paul Collins Startup list
  5548.  
  5549. [audi32]
  5550. Number=788
  5551. Confirmed=X
  5552. Filename=audi32.exe
  5553. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojranckfl.html" target="_blank">RANCK-FL</a> TROJAN!
  5554. Source=Paul Collins Startup list
  5555.  
  5556. [AUDIO]
  5557. Number=789
  5558. Confirmed=X
  5559. Filename=SOUND.exe
  5560. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/dialployba.html" target=_blank>PLOYB-A</a> TROJAN!
  5561. Source=Paul Collins Startup list
  5562.  
  5563. [audiocfg.exe]
  5564. Number=790
  5565. Confirmed=X
  5566. Filename=audiocfg.exe
  5567. Description=Added by the VB.ATE WORM!
  5568. Source=Paul Collins Startup list
  5569.  
  5570. [Audiocntl]
  5571. Number=791
  5572. Confirmed=X
  5573. Filename=audiocntl.exe
  5574. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  5575. Source=Paul Collins Startup list
  5576.  
  5577. [AudioDeck]
  5578. Number=792
  5579. Confirmed=N
  5580. Filename=ADeck.exe
  5581. Description=ADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items
  5582. Source=Paul Collins Startup list
  5583.  
  5584. [Audiodrv]
  5585. Number=793
  5586. Confirmed=X
  5587. Filename=audiodrv.exe
  5588. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target= blank>CRYPTER-C</a> TROJAN!
  5589. Source=Paul Collins Startup list
  5590.  
  5591. [AudioDrvEmulator]
  5592. Number=794
  5593. Confirmed=U
  5594. Filename=DLLML.exe AudDrvEm.dll
  5595. Description=Related to <a href="http://www.creative.com/" target=_blank>Creative</a> DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems
  5596. Source=Paul Collins Startup list
  5597.  
  5598. [AudioHQ]
  5599. Number=795
  5600. Confirmed=N
  5601. Filename=Ahqtb.exe
  5602. Description=For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
  5603. Source=Paul Collins Startup list
  5604.  
  5605. [AudioHQU]
  5606. Number=796
  5607. Confirmed=N
  5608. Filename=AHQTBU.EXE
  5609. Description=System Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start -> Programs
  5610.  
  5611. Source=Paul Collins Startup list
  5612.  
  5613. [audioinf]
  5614. Number=797
  5615. Confirmed=X
  5616. Filename=audioinf.exe
  5617. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  5618. Source=Paul Collins Startup list
  5619.  
  5620. [auloadplx]
  5621. Number=798
  5622. Confirmed=X
  5623. Filename=mplprogsm.exe
  5624. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Proxy.Win32.Slaper.k&threatid=102648" target="_blank">SLAPER.K</a> TROJAN!
  5625. Source=Paul Collins Startup list
  5626.  
  5627. [AUNPS2]
  5628. Number=799
  5629. Confirmed=X
  5630. Filename=RUNDLL32 AUNPS2.DLL, _Run@16
  5631. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-062019-0029-99" target="_blank">AUNPS</a> adware
  5632. Source=Paul Collins Startup list
  5633.  
  5634. [aupd]
  5635. Number=800
  5636. Confirmed=X
  5637. Filename=symcsvc.exe
  5638. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-072614-3940-99" target=_blank>ABWIZ.D</a> TROJAN!
  5639. Source=Paul Collins Startup list
  5640.  
  5641. [aupd]
  5642. Number=801
  5643. Confirmed=X
  5644. Filename=sysvcs.exe
  5645. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-072216-2140-99" target=_blank>ABWIZ.C</a> TROJAN!
  5646. Source=Paul Collins Startup list
  5647.  
  5648. [aupd]
  5649. Number=802
  5650. Confirmed=X
  5651. Filename=sywsvcs.exe
  5652. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojorsem.html" target=_blank>ORSE-M</a> TROJAN!
  5653. Source=Paul Collins Startup list
  5654.  
  5655. [Aureal A3D Interactive Audio]
  5656. Number=803
  5657. Confirmed=Y
  5658. Filename=sa3dsrv.exe
  5659. Description=For Aureal based 3D soundcards. A3D sound features won't work with this disabled
  5660. Source=Paul Collins Startup list
  5661.  
  5662. [Aureal A3D Interactive Audio Init]
  5663. Number=804
  5664. Confirmed=Y
  5665. Filename=A3dInit.exe
  5666. Description=For Aureal based 3D soundcards. A3D sound features won't work with this disabled
  5667. Source=Paul Collins Startup list
  5668.  
  5669. [ausvc]
  5670. Number=805
  5671. Confirmed=X
  5672. Filename=ausvc.exe
  5673. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-042320-3206-99" target="_blank">AUTOUPDER</a> TROJAN!
  5674. Source=Paul Collins Startup list
  5675.  
  5676. [Auth Starter Ident]
  5677. Number=806
  5678. Confirmed=X
  5679. Filename=startauth.exe
  5680. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotwp.html" target= blank>RBOT-WP</a> WORM!
  5681. Source=Paul Collins Startup list
  5682.  
  5683. [authz]
  5684. Number=807
  5685. Confirmed=X
  5686. Filename=authz.exe
  5687. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  5688. Source=Paul Collins Startup list
  5689.  
  5690. [Auto CD-ROM Startup]
  5691. Number=808
  5692. Confirmed=X
  5693. Filename=cdaccess.exe
  5694. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.BLA&VSect=P" target=_blank>SPYBOT.BLA</a> WORM!
  5695. Source=Paul Collins Startup list
  5696.  
  5697. [Auto EPSON Stylus CX6400 on DDLS1Z11]
  5698. Number=809
  5699. Confirmed=U
  5700. Filename=E_S4I2L1.EXE
  5701. Description=Related to Epson Stylus CX6400 Series printer
  5702.  
  5703. Source=Paul Collins Startup list
  5704.  
  5705. [auto repair system]
  5706. Number=810
  5707. Confirmed=X
  5708. Filename=qualityx.exe
  5709. Description=Added by an unidentified WORM or TROJAN - probably a <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-053013-5943-99" target="_blank">SPYBOT</a> variant
  5710. Source=Paul Collins Startup list
  5711.  
  5712. [Auto Switch]
  5713. Number=811
  5714. Confirmed=U
  5715. Filename=TASKBAR.exe
  5716. Description=Related to 2-port Bitronics AutoSwitch kit from Belkin
  5717. Source=Paul Collins Startup list
  5718.  
  5719. [Auto T Bar]
  5720. Number=812
  5721. Confirmed=N
  5722. Filename=autotbar.exe
  5723. Description=If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
  5724. Source=Paul Collins Startup list
  5725.  
  5726. [Auto Updat]
  5727. Number=813
  5728. Confirmed=X
  5729. Filename=WindowsSys32.exe
  5730. Description=Added by a variant of the <a href="http://sophos.com.au/virusinfo/analyses/w32forbotgen.html" target=_blank>FORBOT</a> WORM!
  5731. Source=Paul Collins Startup list
  5732.  
  5733. [Auto updat]
  5734. Number=814
  5735. Confirmed=X
  5736. Filename=crcss.exe
  5737. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.AAG&VSect=T" target=_blank>SDBOT.AAG</a> WORM!
  5738. Source=Paul Collins Startup list
  5739.  
  5740. [Auto Update]
  5741. Number=815
  5742. Confirmed=X
  5743. Filename=AUP.exe
  5744. Description=Added by an unididentified WORM or TROJAN!
  5745. Source=Paul Collins Startup list
  5746.  
  5747. [Auto Update]
  5748. Number=816
  5749. Confirmed=X
  5750. Filename=dma.exe
  5751. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotavo.html" target=_blank>RBOT-AVO</a> WORM!
  5752. Source=Paul Collins Startup list
  5753.  
  5754. [Auto Update]
  5755. Number=817
  5756. Confirmed=X
  5757. Filename=svchost.exe
  5758. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdumardla.html" target=_blank>DUMARDI-A</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  5759. Source=Paul Collins Startup list
  5760.  
  5761. [Auto Updates]
  5762. Number=818
  5763. Confirmed=X
  5764. Filename=svchost.exe
  5765. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcheukoa.html" target=_blank>CHEUKO-A</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  5766. Source=Paul Collins Startup list
  5767.  
  5768. [Auto WinUpdate]
  5769. Number=819
  5770. Confirmed=X
  5771. Filename=taskmrg.exe
  5772. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotafa.html" target=_blank>RBOT-AFA</a> WORM!
  5773. Source=Paul Collins Startup list
  5774.  
  5775. [Autobar]
  5776. Number=820
  5777. Confirmed=U
  5778. Filename=autobar.exe
  5779. Description=Connect buttons on the keyboard for internet direct access, etc. on HP computers
  5780. Source=Paul Collins Startup list
  5781.  
  5782. [AutoCAD Startup Accelerator]
  5783. Number=821
  5784. Confirmed=U
  5785. Filename=acstart16.exe
  5786. Description=Preloads some libraries that are used by <a href="http://usa.autodesk.com/adsk/servlet/index?siteID=123112&id=5127213" target=_blank>AutoCAD</a> in order to make the software load faster
  5787. Source=Paul Collins Startup list
  5788.  
  5789. [autoclk]
  5790. Number=822
  5791. Confirmed=U
  5792. Filename=autoclk.exe
  5793. Description=<a href="http://autoclik.8m.com/" target=_blank>Autoclik</a> is a Windows utility "that allows you to perform all mouse activity with absolutely no clicking"
  5794. Source=Paul Collins Startup list
  5795.  
  5796. [AutoEA]
  5797. Number=823
  5798. Confirmed=N
  5799. Filename=Ahqrun.exe
  5800. Description=For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
  5801. Source=Paul Collins Startup list
  5802.  
  5803. [AUTOEXE]
  5804. Number=824
  5805. Confirmed=X
  5806. Filename=AUTOEXE.exe
  5807. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32semapia.html" target= blank>SEMAPI-A</a> WORM!
  5808. Source=Paul Collins Startup list
  5809.  
  5810. [Autoloaderaproposclient]
  5811. Number=825
  5812. Confirmed=X
  5813. Filename=Apropos_Client_Loader.exe
  5814. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=AproposMedia&threatid=14978" target="_blank">AproposMedia</a> adware
  5815. Source=Paul Collins Startup list
  5816.  
  5817. [Autoloaderaproposclient]
  5818. Number=826
  5819. Confirmed=X
  5820. Filename=cxtpls_loader.exe
  5821. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=AproposMedia&threatid=14978" target="_blank">AproposMedia</a> adware
  5822. Source=Paul Collins Startup list
  5823.  
  5824. [AutoLoaderEnvoloAutoUpdater]
  5825. Number=827
  5826. Confirmed=X
  5827. Filename=auto_update_loader.exe
  5828. Description=<a href="http://www.securemost.com/articles/trou_3_remove_aproposmedia.htm" target=_blank>Envolo/AproposMedia</a> adware updater
  5829. Source=Paul Collins Startup list
  5830.  
  5831. [AutoMate Task Service ]
  5832. Number=828
  5833. Confirmed=N
  5834. Filename=automate.exe
  5835. Description=Task scheduler for <a href="http://www.unisyn.com/" target="_blank">Unisyn Automate 4</a> task automation/macro running software. Available via a desktop shortcut or Start -> Programs
  5836. Source=Paul Collins Startup list
  5837.  
  5838. [AutoMate5]
  5839. Number=829
  5840. Confirmed=U
  5841. Filename=Am5HkWnd.exe
  5842. Description="<a href="http://www.networkautomation.com/automate/index.htm" target="_blank">Automate</a> is the Leading Software for Automation of front and back-office business processes.It provides all the tools necessary to completely automate business processes, regardless of their complexity"
  5843. Source=Paul Collins Startup list
  5844.  
  5845. [Automatic Defrag Manager]
  5846. Number=830
  5847. Confirmed=X
  5848. Filename=defrag.exe
  5849. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotake.html" target=_blank>RBOT-AKE</a> WORM!
  5850. Source=Paul Collins Startup list
  5851.  
  5852. [Automatic Microsoft Windows Updater]
  5853. Number=831
  5854. Confirmed=X
  5855. Filename=suchost.exe
  5856. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rboteq.html" target=_blank>RBOT-EQ</a> WORM!
  5857.  
  5858. Source=Paul Collins Startup list
  5859.  
  5860. [Automatic Windows Updater]
  5861. Number=832
  5862. Confirmed=X
  5863. Filename=Update.exe
  5864. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  5865. Source=Paul Collins Startup list
  5866.  
  5867. [Automatically launches the United Devices Agent when you start your computer]
  5868. Number=833
  5869. Confirmed=N
  5870. Filename=UD.EXE
  5871. Description=The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
  5872. Source=Paul Collins Startup list
  5873.  
  5874. [Autopdate]
  5875. Number=834
  5876. Confirmed=X
  5877. Filename=Autopdate.exe
  5878. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotagl.html" target=_blank>RBOT-AGL</a> WORM!
  5879. Source=Paul Collins Startup list
  5880.  
  5881. [AUTOPROP]
  5882. Number=835
  5883. Confirmed=N
  5884. Filename=REGPROP.EXE WMPADDIN.DLL
  5885. Description=Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension
  5886. Source=Paul Collins Startup list
  5887.  
  5888. [AUTOPROTECTU]
  5889. Number=836
  5890. Confirmed=X
  5891. Filename=navapq32.exe
  5892. Description=Added by an unidentified WORM or TROJAN!
  5893. Source=Paul Collins Startup list
  5894.  
  5895. [autorepair]
  5896. Number=837
  5897. Confirmed=X
  5898. Filename=dexs.exe
  5899. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  5900. Source=Paul Collins Startup list
  5901.  
  5902. [Autoroute SMTP]
  5903. Number=838
  5904. Confirmed=U
  5905. Filename=AutoSmtp.exe
  5906. Description=<a href="http://www.mailutilities.com/ars/" target="_blank">Autoroute SMTP</a> - "automatic switching between SMTP servers depending on what network you are currently working in." You need to have two Internet service providers
  5907. Source=Paul Collins Startup list
  5908.  
  5909. [autorun]
  5910. Number=839
  5911. Confirmed=X
  5912. Filename=autorun.exe
  5913. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/vbsautomb.html" target="_blank">AUTOM-B</a> WORM!
  5914. Source=Paul Collins Startup list
  5915.  
  5916. [AutoShutdown]
  5917. Number=840
  5918. Confirmed=?
  5919. Filename=pssvc.exe
  5920. Description=<font color="#FF0000">Utility to fix vCard Export in MS Outlook 2000 - although why are these together?</font>
  5921. Source=Paul Collins Startup list
  5922.  
  5923. [AutoSizer]
  5924. Number=841
  5925. Confirmed=U
  5926. Filename=AUTOSIZER.EXE
  5927. Description=<a href="http://www.southbaypc.com/AutoSizer/" target="_blank">AutoSizer</a> - utility that automatically maximizes windows when they're opened
  5928. Source=Paul Collins Startup list
  5929.  
  5930. [AutoSpell]
  5931. Number=842
  5932. Confirmed=N
  5933. Filename=autospel.exe
  5934. Description=<a href="http://www.spellchecker.com/" target="_blank">AutoSpell</a> - spell checker (version 6.*)
  5935. Source=Paul Collins Startup list
  5936.  
  5937. [AutoSpell 5]
  5938. Number=843
  5939. Confirmed=N
  5940. Filename=ASWATC32.EXE
  5941. Description=<a href="http://www.spellchecker.com/" target="_blank">AutoSpell</a> - spell checker
  5942. Source=Paul Collins Startup list
  5943.  
  5944. [AutoSys]
  5945. Number=844
  5946. Confirmed=U
  5947. Filename=autosys.exe
  5948. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Winguardian&threatid=40587" target="_blank">Winguardian</a> surveillance software. Uninstall this software unless you put it there yourself
  5949. Source=Paul Collins Startup list
  5950.  
  5951. [autotbar]
  5952. Number=845
  5953. Confirmed=N
  5954. Filename=autotbar.exe
  5955. Description=If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
  5956. Source=Paul Collins Startup list
  5957.  
  5958. [AutoTKit]
  5959. Number=846
  5960. Confirmed=N
  5961. Filename=AUTOTKIT.EXE
  5962. Description=On HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled
  5963. Source=Paul Collins Startup list
  5964.  
  5965. [autoupd]
  5966. Number=847
  5967. Confirmed=N
  5968. Filename=autoupd.exe
  5969. Description=<a href="http://www.raxco.com/support/windows/kb_details.cfm?kbid=46" target="_blank">Raxco Software Auto Update</a> utility."Used to keep your software up-to-date"
  5970. Source=Paul Collins Startup list
  5971.  
  5972. [autoupd]
  5973. Number=848
  5974. Confirmed=X
  5975. Filename=autoupd.exe
  5976. Description=Added by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name
  5977. Source=Paul Collins Startup list
  5978.  
  5979. [autoupdate]
  5980. Number=849
  5981. Confirmed=X
  5982. Filename=WINUP2DATE.DLL, SHStart
  5983. Description=Unidentified adware - detected by <a href="http://www.pandasoftware.com/" target="_blank">Panda</a> antivirus as the CLICKER.CY TROJAN!
  5984. Source=Paul Collins Startup list
  5985.  
  5986. [autoupdate]
  5987. Number=850
  5988. Confirmed=X
  5989. Filename=rundll32 [path] DATADX.DLL, SHStart
  5990. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43264" target=_blank>QOOLOGIC</a> TROJAN!
  5991. Source=Paul Collins Startup list
  5992.  
  5993. [autoupdate]
  5994. Number=851
  5995. Confirmed=X
  5996. Filename=rundll32 [path] SUPDATE.DLL, SHStart
  5997. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43264" target="_blank">QOOLOGIC</a> TROJAN!
  5998. Source=Paul Collins Startup list
  5999.  
  6000. [Autoupdate Service]
  6001. Number=852
  6002. Confirmed=X
  6003. Filename=kaka.exe
  6004. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsympeb.html" target=_blank>SYMPE-B</a> TROJAN!
  6005. Source=Paul Collins Startup list
  6006.  
  6007. [AutoUpdater]
  6008. Number=853
  6009. Confirmed=X
  6010. Filename=aupdate.exe
  6011. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=TinyBar&threatid=13064&search=Tinybar" target="_blank">Tinybar</a> variant
  6012. Source=Paul Collins Startup list
  6013.  
  6014. [AutoUpdater]
  6015. Number=854
  6016. Confirmed=X
  6017. Filename=AutoUpdate.exe
  6018. Description=<a href="http://www.pchell.com/support/peopleonpage.shtml" target="_blank">PeopleonPage</a> foistware
  6019. Source=Paul Collins Startup list
  6020.  
  6021. [autoupdatev2]
  6022. Number=855
  6023. Confirmed=X
  6024. Filename=[path to file]
  6025. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdropperbm.html" target=_blank>DROPPER-BM</a> TROJAN!
  6026. Source=Paul Collins Startup list
  6027.  
  6028. [autoupdatev2]
  6029. Number=856
  6030. Confirmed=X
  6031. Filename=autoupdatev2.exe
  6032. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Clicker.Win32.Agent.fq
  6033. Source=Paul Collins Startup list
  6034.  
  6035. [AutoVirusProtection]
  6036. Number=857
  6037. Confirmed=X
  6038. Filename=ciscv.exe
  6039. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  6040. Source=Paul Collins Startup list
  6041.  
  6042. [auto__antiav__key]
  6043. Number=858
  6044. Confirmed=X
  6045. Filename=antiav_exe.exe
  6046. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbagledlaa.html" target=_blank>BAGLEDI-AA</a> TROJAN!
  6047. Source=Paul Collins Startup list
  6048.  
  6049. [auto__hloader__key]
  6050. Number=859
  6051. Confirmed=X
  6052. Filename=hloader_exe.exe
  6053. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BAGLE.AB&VSect=P" target=_blank>BAGLE.AB</a> TROJAN!
  6054. Source=Paul Collins Startup list
  6055.  
  6056. [aux.exe]
  6057. Number=860
  6058. Confirmed=X
  6059. Filename=aux.exe
  6060. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-010115-5424-99" target=_blank>ZINS</a> TROJAN!
  6061. Source=Paul Collins Startup list
  6062.  
  6063. [auxAudioDevice]
  6064. Number=861
  6065. Confirmed=X
  6066. Filename=aux32.exe
  6067. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091017-5519-99" target="_blank">AIZU</a> WORM!
  6068. Source=Paul Collins Startup list
  6069.  
  6070. [AUXXTRAY]
  6071. Number=862
  6072. Confirmed=N
  6073. Filename=au30setp.exe
  6074. Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
  6075. Source=Paul Collins Startup list
  6076.  
  6077. [AV]
  6078. Number=863
  6079. Confirmed=X
  6080. Filename=UPDATE-28062004.exe[25 blank spaces].vbs
  6081. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-110809-1153-99" target=_blank>MIDFIN</a> WORM!
  6082. Source=Paul Collins Startup list
  6083.  
  6084. [AV Client]
  6085. Number=864
  6086. Confirmed=X
  6087. Filename=patch31345.exe
  6088. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100413-3115-99" target=_blank>MYDOOM.AD</a> WORM!
  6089. Source=Paul Collins Startup list
  6090.  
  6091. [AV Industry]
  6092. Number=865
  6093. Confirmed=X
  6094. Filename=patch31345.exe
  6095. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100413-3115-99" target=_blank>MYDOOM.AD</a> WORM!
  6096. Source=Paul Collins Startup list
  6097.  
  6098. [AV UpDate]
  6099. Number=866
  6100. Confirmed=X
  6101. Filename=Update.exe
  6102. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojfuroota.html" target= blank>FUROOT-A</a> TROJAN!
  6103. Source=Paul Collins Startup list
  6104.  
  6105. [AvaFind]
  6106. Number=867
  6107. Confirmed=N
  6108. Filename=AvaFind.exe
  6109. Description=<a href="http://www.think-less-do-more.com/avafind/" target="_blank">AvaFind</a> file search utility
  6110. Source=Paul Collins Startup list
  6111.  
  6112. [AVantivirus]
  6113. Number=868
  6114. Confirmed=X
  6115. Filename=Avconsol.exe
  6116. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32msnvbd.html" target="_blank">MSNVB-D</a> WORM!
  6117. Source=Paul Collins Startup list
  6118.  
  6119. [Avast!]
  6120. Number=869
  6121. Confirmed=Y
  6122. Filename=ashserv.exe
  6123. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast!</a> anti-virus software
  6124. Source=Paul Collins Startup list
  6125.  
  6126. [avast!]
  6127. Number=870
  6128. Confirmed=Y
  6129. Filename=ashDisp.exe
  6130. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast!</a> anti-virus software
  6131. Source=Paul Collins Startup list
  6132.  
  6133. [avast! Web Scanner]
  6134. Number=871
  6135. Confirmed=Y
  6136. Filename=Ashwebsv.exe
  6137. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast!</a> anti-virus software
  6138. Source=Paul Collins Startup list
  6139.  
  6140. [Avast32]
  6141. Number=872
  6142. Confirmed=Y
  6143. Filename=Astart32.exe
  6144. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast!</a> anti-virus software
  6145. Source=Paul Collins Startup list
  6146.  
  6147. [avc]
  6148. Number=873
  6149. Confirmed=X
  6150. Filename=avmon.exe
  6151. Description=Added by an unidentified TROJAN!
  6152. Source=Paul Collins Startup list
  6153.  
  6154. [AvconsoleEXE]
  6155. Number=874
  6156. Confirmed=U
  6157. Filename=Avconsol.exe
  6158. Description=From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
  6159. Source=Paul Collins Startup list
  6160.  
  6161. [AveoAttune]
  6162. Number=875
  6163. Confirmed=X
  6164. Filename=atmdlusr.exe
  6165. Description=Spyware - part of an automated helpdesk software
  6166. Source=Paul Collins Startup list
  6167.  
  6168. [AVFX Engine]
  6169. Number=876
  6170. Confirmed=U
  6171. Filename=StartFX.exe
  6172. Description=<a href="http://www.creative.com/products/webcams/avfx/" target="_blank">Advanced Video FX</a> - supported by a number of Creative Web Cameras. "Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"
  6173. Source=Paul Collins Startup list
  6174.  
  6175. [AvG]
  6176. Number=877
  6177. Confirmed=X
  6178. Filename=svchost323.exe
  6179. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotza.html" target= blank>RBOT-ZA</a> WORM!
  6180. Source=Paul Collins Startup list
  6181.  
  6182. [AVG Anti-Virus system]
  6183. Number=878
  6184. Confirmed=Y
  6185. Filename=avgcc.exe
  6186. Description=<a href="http://www.grisoft.com/" target="_blank">AVG</a> Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
  6187. Source=Paul Collins Startup list
  6188.  
  6189. [Avg Antivirus]
  6190. Number=879
  6191. Confirmed=X
  6192. Filename=icpldrvx.exe
  6193. Description=Added by the <a href="http://www.quickheal.co.in/public/alerts/banker_byu.asp" target="_blank">BANKER.BYU</a> TROJAN!
  6194. Source=Paul Collins Startup list
  6195.  
  6196. [AVG Grisoft Updater]
  6197. Number=880
  6198. Confirmed=X
  6199. Filename=updater.exe
  6200. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotot.html" target=_blank>AGOBOT-OT</a> WORM!
  6201. Source=Paul Collins Startup list
  6202.  
  6203. [AVG7_AMSVR]
  6204. Number=881
  6205. Confirmed=Y
  6206. Filename=Avgamsvr.exe
  6207. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> antivirus related
  6208. Source=Paul Collins Startup list
  6209.  
  6210. [AVG7_CC]
  6211. Number=882
  6212. Confirmed=Y
  6213. Filename=AVGCC.exe
  6214. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
  6215. Source=Paul Collins Startup list
  6216.  
  6217. [AVG7_CC]
  6218. Number=883
  6219. Confirmed=Y
  6220. Filename=avgcc.exe
  6221. Description=<a href="http://www.grisoft.com/" target="_blank">AVG</a> Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
  6222. Source=Paul Collins Startup list
  6223.  
  6224. [AVG7_EMC]
  6225. Number=884
  6226. Confirmed=Y
  6227. Filename=AVGEMC.exe
  6228. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
  6229. Source=Paul Collins Startup list
  6230.  
  6231. [AVG7_Run]
  6232. Number=885
  6233. Confirmed=Y
  6234. Filename=avgw.exe
  6235. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 related
  6236. Source=Paul Collins Startup list
  6237.  
  6238. [avgamsvr.exe]
  6239. Number=886
  6240. Confirmed=Y
  6241. Filename=Avgamsvr.exe
  6242. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> antivirus related
  6243. Source=Paul Collins Startup list
  6244.  
  6245. [avgcc32]
  6246. Number=887
  6247. Confirmed=Y
  6248. Filename=avgcc32.exe
  6249. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
  6250. Source=Paul Collins Startup list
  6251.  
  6252. [AVGCtrl]
  6253. Number=888
  6254. Confirmed=Y
  6255. Filename=AVGCtrl.exe
  6256. Description=Part of <a href="http://www.free-av.com/" target=_blank>AntiVir« PersonalEdition Classic</a> antivirus
  6257. Source=Paul Collins Startup list
  6258.  
  6259. [avgfwsrv]
  6260. Number=889
  6261. Confirmed=Y
  6262. Filename=AVGFWSRV.EXE
  6263. Description=Firewall part of the <a href="http://www.grisoft.com/doc/31/us/crp/4?prd=afw" target="_blank">AVG Plus Firewall Edition</a>
  6264. Source=Paul Collins Startup list
  6265.  
  6266. [avgmsvr.exe]
  6267. Number=890
  6268. Confirmed=Y
  6269. Filename=avgmsvr.exe
  6270. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 related
  6271. Source=Paul Collins Startup list
  6272.  
  6273. [AVGnt]
  6274. Number=891
  6275. Confirmed=Y
  6276. Filename=AVGnt.exe
  6277. Description=<a href="http://www.free-av.com/" target=_blank>AntiVir« PersonalEdition Classic</a> antivirus. System Tray icon and control program
  6278.  
  6279. Source=Paul Collins Startup list
  6280.  
  6281. [Avgserv9.exe]
  6282. Number=892
  6283. Confirmed=Y
  6284. Filename=Avgserv9.exe
  6285. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> antivirus background monitoring
  6286. Source=Paul Collins Startup list
  6287.  
  6288. [AVGuard]
  6289. Number=893
  6290. Confirmed=Y
  6291. Filename=AVGuard.exe
  6292. Description=<a href="http://www.free-av.com/" target=_blank>AntiVir« PersonalEdition Classic</a> antivirus. Background task which scans files transparently
  6293.  
  6294. Source=Paul Collins Startup list
  6295.  
  6296. [AVG_CC]
  6297. Number=894
  6298. Confirmed=Y
  6299. Filename=avgcc32.exe
  6300. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
  6301. Source=Paul Collins Startup list
  6302.  
  6303. [AVG_EMC]
  6304. Number=895
  6305. Confirmed=Y
  6306. Filename=AVGEMC.exe
  6307. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
  6308. Source=Paul Collins Startup list
  6309.  
  6310. [AVG_RegCleaner]
  6311. Number=896
  6312. Confirmed=Y
  6313. Filename=AVGREGCL.exe
  6314. Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems
  6315. Source=Paul Collins Startup list
  6316.  
  6317. [avidrv]
  6318. Number=897
  6319. Confirmed=X
  6320. Filename=drvsc.exe
  6321. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan-Downloader.Win32.Agent.ph
  6322. Source=Paul Collins Startup list
  6323.  
  6324. [Avimgt]
  6325. Number=898
  6326. Confirmed=X
  6327. Filename=Avimgt.exe
  6328. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  6329. Source=Paul Collins Startup list
  6330.  
  6331. [Avimgt32]
  6332. Number=899
  6333. Confirmed=X
  6334. Filename=Avimgt32.exe
  6335. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  6336. Source=Paul Collins Startup list
  6337.  
  6338. [avinit]
  6339. Number=900
  6340. Confirmed=Y
  6341. Filename=AVINIT9X.EXE
  6342. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> related
  6343. Source=Paul Collins Startup list
  6344.  
  6345. [AVK Mail Checker]
  6346. Number=901
  6347. Confirmed=Y
  6348. Filename=AVKPop.exe
  6349. Description=<a href="http://www.boomerangsoftware.com/Products/AntiVirus/AVKProInfo.htm" target=_blank>eXtendia</a> AVK AntiVirus email checker 
  6350. Source=Paul Collins Startup list
  6351.  
  6352. [AVKBar]
  6353. Number=902
  6354. Confirmed=Y
  6355. Filename=AVKBar.exe
  6356. Description=GData <a href="http://www.gdata.de/trade/productview/488/16/" target=_blank>AntiVirusKit</a> Anti-virus
  6357. Source=Paul Collins Startup list
  6358.  
  6359. [AvMaiSrv]
  6360. Number=903
  6361. Confirmed=Y
  6362. Filename=Avmaisrv.exe
  6363. Description=Part of <a href="http://www.avast.com/" target="_blank">Avast!</a> anti-virus software - E-mail scanner
  6364. Source=Paul Collins Startup list
  6365.  
  6366. [avnort]
  6367. Number=904
  6368. Confirmed=X
  6369. Filename=formatsys.exe
  6370. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030709-3841-99" target=_blank>SERFLOG.A</a> WORM!
  6371. Source=Paul Collins Startup list
  6372.  
  6373. [avnort]
  6374. Number=905
  6375. Confirmed=X
  6376. Filename=msmbw.exe
  6377. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030709-3841-99" target=_blank>SERFLOG.A</a> WORM!
  6378. Source=Paul Collins Startup list
  6379.  
  6380. [avnort]
  6381. Number=906
  6382. Confirmed=X
  6383. Filename=serbw.exe
  6384. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030709-3841-99" target=_blank>SERFLOG.A</a> WORM!
  6385. Source=Paul Collins Startup list
  6386.  
  6387. [avp]
  6388. Number=907
  6389. Confirmed=Y
  6390. Filename=avp.exe
  6391. Description=AOL's <a href="http://www.securitycadets.com/2006/08/aols-active-virus-shield-in-a-nutshell/" target="_blank">Active Virus Shield</a>
  6392. Source=Paul Collins Startup list
  6393.  
  6394. [AVP]
  6395. Number=908
  6396. Confirmed=X
  6397. Filename=[path to trojan]
  6398. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmutboa.html" target=_blank>MUTBO-A</a> TROJAN!
  6399. Source=Paul Collins Startup list
  6400.  
  6401. [AVP-SE]
  6402. Number=909
  6403. Confirmed=X
  6404. Filename=avp-32.exe
  6405. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.FS" target="_blank">AGOBOT.FS</a> WORM!
  6406. Source=Paul Collins Startup list
  6407.  
  6408. [avpcc]
  6409. Number=910
  6410. Confirmed=Y
  6411. Filename=avpcc.exe
  6412. Description=<a href="http://www.kaspersky.com/" target="_blank">Kaspersky Labs</a> anti-virus
  6413. Source=Paul Collins Startup list
  6414.  
  6415. [avpm]
  6416. Number=911
  6417. Confirmed=Y
  6418. Filename=avpm.exe
  6419. Description=<a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> anti-virus
  6420. Source=Paul Collins Startup list
  6421.  
  6422. [Avpr]
  6423. Number=912
  6424. Confirmed=X
  6425. Filename=avpr.exe
  6426. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-101709-2151-99" target=_blank>MYDOOM.AF</a> WORM!
  6427. Source=Paul Collins Startup list
  6428.  
  6429. [avptask]
  6430. Number=913
  6431. Confirmed=X
  6432. Filename=[path to trojan]
  6433. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojnofereg.html" target="_blank">NOFERE-G</a> TROJAN!
  6434. Source=Paul Collins Startup list
  6435.  
  6436. [avptask]
  6437. Number=914
  6438. Confirmed=X
  6439. Filename=expl0rer.exe
  6440. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.JJO" target="_blank">AGENT.JJO</a> TROJAN!
  6441. Source=Paul Collins Startup list
  6442.  
  6443. [Avptask]
  6444. Number=915
  6445. Confirmed=X
  6446. Filename=rund1132.exe
  6447. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.PKZ" target="_blank">AGENT.PKZ</a> TROJAN!
  6448. Source=Paul Collins Startup list
  6449.  
  6450. [Avril Lavigne - Muse]
  6451. Number=916
  6452. Confirmed=X
  6453. Filename=[random filename]
  6454. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32avrila.html" target="_blank">AVRIL-A</a> WORM!
  6455. Source=Paul Collins Startup list
  6456.  
  6457. [AVSCHED32]
  6458. Number=917
  6459. Confirmed=Y
  6460. Filename=AVSched32.exe
  6461. Description=<a href="http://www.free-av.com/" target=_blank>AntiVir« PersonalEdition Classic</a> - antivirus
  6462.  
  6463. Source=Paul Collins Startup list
  6464.  
  6465. [AVSchedScan]
  6466. Number=918
  6467. Confirmed=Y
  6468. Filename=SCHSC9X.EXE
  6469. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> related
  6470. Source=Paul Collins Startup list
  6471.  
  6472. [AvSer]
  6473. Number=919
  6474. Confirmed=X
  6475. Filename=dsm.exe
  6476. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  6477. Source=Paul Collins Startup list
  6478.  
  6479. [AvSer]
  6480. Number=920
  6481. Confirmed=X
  6482. Filename=msmpatch.exe
  6483. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  6484. Source=Paul Collins Startup list
  6485.  
  6486. [AvSer]
  6487. Number=921
  6488. Confirmed=X
  6489. Filename=svosm.exe
  6490. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  6491. Source=Paul Collins Startup list
  6492.  
  6493. [AvSer]
  6494. Number=922
  6495. Confirmed=X
  6496. Filename=sysup.exe
  6497. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  6498. Source=Paul Collins Startup list
  6499.  
  6500. [avserve.exe]
  6501. Number=923
  6502. Confirmed=X
  6503. Filename=avserve.exe
  6504. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-050116-1831-99" target="_blank">SASSER</a> WORM!
  6505. Source=Paul Collins Startup list
  6506.  
  6507. [avserve2.exe]
  6508. Number=924
  6509. Confirmed=X
  6510. Filename=avserve2.exe
  6511. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-050114-1001-99" target="_blank">SASSER.B</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-050216-3656-99" target="_blank">SASSER.C</a> WORMS!
  6512. Source=Paul Collins Startup list
  6513.  
  6514. [avserve3.exe]
  6515. Number=925
  6516. Confirmed=X
  6517. Filename=avserve3.exe
  6518. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-082413-3637-99" target="_blank">SASSER.G</a> WORM!
  6519. Source=Paul Collins Startup list
  6520.  
  6521. [AVStation premium]
  6522. Number=926
  6523. Confirmed=U
  6524. Filename=AVStation agent.exe
  6525. Description=Related to <a href="http://www.samsung.com/in/products/notepc/notepc/leaflets/X20.pdf" target=_blank>Samsung AV Station</a> - instant playback of music, photos, videos
  6526. Source=Paul Collins Startup list
  6527.  
  6528. [Avtray]
  6529. Number=927
  6530. Confirmed=N
  6531. Filename=Avtray.exe
  6532. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> tray icon
  6533. Source=Paul Collins Startup list
  6534.  
  6535. [AVWLPSTA]
  6536. Number=928
  6537. Confirmed=?
  6538. Filename=AVWLPSTA.exe
  6539. Description=PRISM Status Tray Applet - <font color="#FF0000">but what is it for and is it required?</font>
  6540. Source=Paul Collins Startup list
  6541.  
  6542. [AVWUpd32]
  6543. Number=929
  6544. Confirmed=Y
  6545. Filename=AVWUPD32.EXE
  6546. Description=<a href="http://www.free-av.com/" target=_blank>AntiVir« PersonalEdition Classic</a> - updater
  6547.  
  6548. Source=Paul Collins Startup list
  6549.  
  6550. [avx communicator]
  6551. Number=930
  6552. Confirmed=Y
  6553. Filename=xcommsur.exe
  6554. Description=Anti-virus part of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
  6555. Source=Paul Collins Startup list
  6556.  
  6557. [Avxlive]
  6558. Number=931
  6559. Confirmed=Y
  6560. Filename=avxlive.exe
  6561. Description=<a href="http://www.bullguard.com/" target="_blank">Bullguard</a> or <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  6562. Source=Paul Collins Startup list
  6563.  
  6564. [avxlni]
  6565. Number=932
  6566. Confirmed=Y
  6567. Filename=avxinit.exe
  6568. Description=Anti-virus part of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
  6569. Source=Paul Collins Startup list
  6570.  
  6571. [Avxnews]
  6572. Number=933
  6573. Confirmed=?
  6574. Filename=??
  6575. Description=<font color="#FF0000">??</font>
  6576. Source=Paul Collins Startup list
  6577.  
  6578. [Awatch]
  6579. Number=934
  6580. Confirmed=U
  6581. Filename=Awatch.exe
  6582. Description=Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products
  6583. Source=Paul Collins Startup list
  6584.  
  6585. [AwaySch]
  6586. Number=935
  6587. Confirmed=U
  6588. Filename=AwaySch.EXE
  6589. Description=Part of the IBM <a href="http://www.pc.ibm.com/us/think/thinkvantagetech/productivity_ctr.html" target="_blank">ThinkVantage Productivity Center</a>. "The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"
  6590. Source=Paul Collins Startup list
  6591.  
  6592. [awhost32]
  6593. Number=936
  6594. Confirmed=N
  6595. Filename=awhost32.exe
  6596. Description=Part of Symantec's <a href="http://www.symantec.com/home_homeoffice/products/overview.jsp?pcid=pf&pvid=pca12" target="_blank">pcAnywhere</a> remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended
  6597. Source=Paul Collins Startup list
  6598.  
  6599. [AWMON]
  6600. Number=937
  6601. Confirmed=U
  6602. Filename=Ad-Watch.exe
  6603. Description=Part of Lavasoft <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware Plus</a> - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
  6604. Source=Paul Collins Startup list
  6605.  
  6606. [AWMON]
  6607. Number=938
  6608. Confirmed=U
  6609. Filename=Ad-Monitor.exe
  6610. Description=<a href="http://www.f-secure.com/" target="_blank">F-Secure</a> Anti-Spyware
  6611. Source=Paul Collins Startup list
  6612.  
  6613. [AWUSGSTA]
  6614. Number=939
  6615. Confirmed=?
  6616. Filename=AWUSGSTA.exe
  6617. Description=Reportedly related to a USB Wifi Adapter - <font color="#FF0000">is it required at startup?</font>
  6618.  
  6619. Source=Paul Collins Startup list
  6620.  
  6621. [awxDTools]
  6622. Number=940
  6623. Confirmed=U
  6624. Filename=awxDTools.dll, awxRegisterDll
  6625. Description=<a href="http://www.hbreitner.de/awxdtools/" target= blank>AwxDTools</a> related - a Windows Shell-Extension for the Daemon-Tools. It extends the context-menu of ImageFiles supported by Daemon-Tools (i.e.: *.cue, *.iso, *.ccd ...)
  6626. Source=Paul Collins Startup list
  6627.  
  6628. [AxFilter]
  6629. Number=941
  6630. Confirmed=?
  6631. Filename=Rundll32 AXFILTER.DLL, Rundll32
  6632. Description=<font color="#FF0000">??</font>
  6633. Source=Paul Collins Startup list
  6634.  
  6635. [AXVenore]
  6636. Number=942
  6637. Confirmed=X
  6638. Filename=AXVenore.exe
  6639. Description=<a href="http://fileinfo.prevx.com/QQb33919476991-AXVE15381588/AXVENORE.EXE.html" target=_blank>Identified</a> as a TROJAN!
  6640.  
  6641. Source=Paul Collins Startup list
  6642.  
  6643. [AzMixerSel]
  6644. Number=943
  6645. Confirmed=U
  6646. Filename=AzMixerSel.exe
  6647. Description=Related to <a href="http://www.realtek.com.tw/" target="_blank">Realtek_Azalia</a> Mixer Selector
  6648. Source=Paul Collins Startup list
  6649.  
  6650. [azmodem]
  6651. Number=944
  6652. Confirmed=Y
  6653. Filename=azexe.exe
  6654. Description=<a href="http://www.aztech.com/" target=_blank>Aztech Labs</a> modem driver
  6655. Source=Paul Collins Startup list
  6656.  
  6657. [a_vpd]
  6658. Number=945
  6659. Confirmed=?
  6660. Filename=vpd.exe
  6661. Description=Located in the IBMTOOLS\VPD sub-directory. <font color="#FF0000">What does it do and is it required?</font>
  6662. Source=Paul Collins Startup list
  6663.  
  6664. [aâ–“]
  6665. Number=946
  6666. Confirmed=U
  6667. Filename=a2guard.exe
  6668. Description=<a href="http://www.emsisoft.com/en/" target=_blank>a-Squared</a> antitrojan - can be run on demand but necessary in Startup if you prefer the aâ–“ 'Background Guard' real time protection feature
  6669. Source=Paul Collins Startup list
  6670.  
  6671. [B'sCLiP]
  6672. Number=947
  6673. Confirmed=N
  6674. Filename=BSCLIP.exe
  6675. Description=CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
  6676. Source=Paul Collins Startup list
  6677.  
  6678. [b.exe]
  6679. Number=948
  6680. Confirmed=X
  6681. Filename=b.exe
  6682. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BND&VSect=T" target=_blank>SDBOT.BND</a> WORM!
  6683. Source=Paul Collins Startup list
  6684.  
  6685. [B.Reader]
  6686. Number=949
  6687. Confirmed=N
  6688. Filename=remin.exe
  6689. Description=<a href="http://www.harshal.da.ru/" target="_blank">Birthday Reminder 5.0</a> - as the name implies
  6690. Source=Paul Collins Startup list
  6691.  
  6692. [b3d]
  6693. Number=950
  6694. Confirmed=X
  6695. Filename=BDEsecureinstall.exe
  6696. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BrilliantDigital&threatid=3334" target="_blank">B3d Projector</a> foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the "System" directory. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
  6697. Source=Paul Collins Startup list
  6698.  
  6699. [b3dUpdate]
  6700. Number=951
  6701. Confirmed=X
  6702. Filename=Zupdate.exe
  6703. Description=Associated with <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BrilliantDigital&threatid=3334" target="_blank">B3d Projector</a> foistware - see <a href="http://www.greatis.com/appdata/u/z/zupdate.exe.htm" target="_blank">here</a>
  6704. Source=Paul Collins Startup list
  6705.  
  6706. [b9]
  6707. Number=952
  6708. Confirmed=U
  6709. Filename=B9.exe
  6710. Description=<a href="http://www.firetrust.com/firetrustbenign.html" target="_blank">FireTrust Benign</a> - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"
  6711. Source=Paul Collins Startup list
  6712.  
  6713. [b99]
  6714. Number=953
  6715. Confirmed=X
  6716. Filename=msmm.exe
  6717. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClientMan&threatid=3754" target=_blank>ClientMan</a> parasite variant
  6718. Source=Paul Collins Startup list
  6719.  
  6720. [bab]
  6721. Number=954
  6722. Confirmed=X
  6723. Filename=svchst32.exe
  6724. Description=Added by the <a href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=41035" target="_blank">AGENT.Q</a> TROJAN!
  6725. Source=Paul Collins Startup list
  6726.  
  6727. [babeie]
  6728. Number=955
  6729. Confirmed=X
  6730. Filename=rundll32 cnbabe.dll, dllstartup
  6731. Description=<a href="http://www.commonname.com/english/ug/toolbar/default.asp?idx=1" target="_blank">CommonName Toolbar</a> spyware. To uninstall see <a href="http://www.commonname.com/english/ug/toolbar/default.asp?idx=10#4">here</a>
  6732. Source=Paul Collins Startup list
  6733.  
  6734. [Babylon Client]
  6735. Number=956
  6736. Confirmed=N
  6737. Filename=Babylon.exe
  6738. Description=<a href="http://www.babylon.com/" target="_blank">Babylon-Pro</a> is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
  6739. Source=Paul Collins Startup list
  6740.  
  6741. [Babylon Translator]
  6742. Number=957
  6743. Confirmed=N
  6744. Filename=Babylon.exe
  6745. Description="<a href="http://www.babylon.com/" target="_blank">Babylon-Pro</a> is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
  6746. Source=Paul Collins Startup list
  6747.  
  6748. [Back Updates]
  6749. Number=958
  6750. Confirmed=X
  6751. Filename=Uninstall.log.vbs
  6752. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040911-2617-99" target=_blank>YPSAN.D</a> WORM!
  6753. Source=Paul Collins Startup list
  6754.  
  6755. [Backdoor.NuAgent]
  6756. Number=959
  6757. Confirmed=X
  6758. Filename=agent.exe
  6759. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentdp.html" target=_blank>AGENT-DP</a> TROJAN!
  6760. Source=Paul Collins Startup list
  6761.  
  6762. [Background Intelligent Transfer Service]
  6763. Number=960
  6764. Confirmed=X
  6765. Filename=rundll32.exe
  6766. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvbzd.html" target=_blank>VB-ZD</a> TROJAN! Note - this file is located in the C:\Windows\help folder, and is not to be confused with the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/rundll32/" target=_blank>rundll32.exe</a> file!
  6767. Source=Paul Collins Startup list
  6768.  
  6769. [BackgroundSwitcher]
  6770. Number=961
  6771. Confirmed=U
  6772. Filename=bgswitch.exe
  6773. Description=Originally included with Microsoft's XP PowerToys (but now withdrawn - see <a href="http://www.aumha.org/a/powertoy.php" target="_blank">here</a>, Background Switcher allows your desktop background to periodically change
  6774. Source=Paul Collins Startup list
  6775.  
  6776. [Backpack UDF]
  6777. Number=962
  6778. Confirmed=N
  6779. Filename=bpudfmon.exe
  6780. Description=<a href="http://www.nero.com/" target="_blank">Backpack UDF</a> packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk
  6781. Source=Paul Collins Startup list
  6782.  
  6783. [backup]
  6784. Number=963
  6785. Confirmed=X
  6786. Filename=[path to worm]
  6787. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agoboth.html" target="_blank">AGOBOT-H</a> WORM!
  6788. Source=Paul Collins Startup list
  6789.  
  6790. [Backup Service]
  6791. Number=964
  6792. Confirmed=X
  6793. Filename=backup.svc
  6794. Description=Unidentified adware
  6795. Source=Paul Collins Startup list
  6796.  
  6797. [Backup4all OTB Agent]
  6798. Number=965
  6799. Confirmed=U
  6800. Filename=B4AOTB.exe
  6801. Description="<a href="http://www.backup4all.com/backup4all.php" target="_blank">Backup4all</a> is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space"
  6802. Source=Paul Collins Startup list
  6803.  
  6804. [BackupExecScheduler]
  6805. Number=966
  6806. Confirmed=U
  6807. Filename=besch.exe
  6808. Description=Veritas "Back Up My PC" software
  6809. Source=Paul Collins Startup list
  6810.  
  6811. [BackupNotify]
  6812. Number=967
  6813. Confirmed=?
  6814. Filename=backupnotify.exe
  6815. Description=HP Digital Imaging related. <font color="#FF0000">What does it do and is it required?</font>
  6816. Source=Paul Collins Startup list
  6817.  
  6818. [BackWeb]
  6819. Number=968
  6820. Confirmed=N
  6821. Filename=backweb.exe
  6822. Description=Automatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
  6823. Source=Paul Collins Startup list
  6824.  
  6825. [Backwork]
  6826. Number=969
  6827. Confirmed=N
  6828. Filename=Backwork.exe
  6829. Description=<a href="http://www.pcadvisor.co.uk/downloads/index.cfm?categoryID=1505&itemID=6930" target="_blank">Backwork</a> trojan detector
  6830. Source=Paul Collins Startup list
  6831.  
  6832. [BACPI10]
  6833. Number=970
  6834. Confirmed=U
  6835. Filename=bacpi10a.exe
  6836. Description=Known as "PowerKey" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray
  6837. Source=Paul Collins Startup list
  6838.  
  6839. [BacsTray]
  6840. Number=971
  6841. Confirmed=N
  6842. Filename=BacsTray.exe
  6843. Description=Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
  6844. Source=Paul Collins Startup list
  6845.  
  6846. [BADDATE]
  6847. Number=972
  6848. Confirmed=X
  6849. Filename=BADDATE.EXE
  6850. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  6851. Source=Paul Collins Startup list
  6852.  
  6853. [BagleAV]
  6854. Number=973
  6855. Confirmed=X
  6856. Filename=csrss.exe
  6857. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042814-2354-99" target=_blank>NETSKY.AB</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
  6858. Source=Paul Collins Startup list
  6859.  
  6860. [Bakra]
  6861. Number=974
  6862. Confirmed=X
  6863. Filename=IEHost.EXE
  6864. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmultidrah.html" target=_blank>MULTIDR-AH</a> TROJAN!
  6865. Source=Paul Collins Startup list
  6866.  
  6867. [bal]
  6868. Number=975
  6869. Confirmed=X
  6870. Filename=SYSMONMS.EXE
  6871. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.FakeAlert&threatid=43521" target="_blank">FAKEALERT</a> TROJAN!
  6872. Source=Paul Collins Startup list
  6873.  
  6874. [Band-Aid]
  6875. Number=976
  6876. Confirmed=X
  6877. Filename=[path to file]
  6878. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-122417-2948-99" target=_blank>RANKY.O</a> TROJAN!
  6879. Source=Paul Collins Startup list
  6880.  
  6881. [Bandook]
  6882. Number=977
  6883. Confirmed=X
  6884. Filename=ali.exe
  6885. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojexemasb.html" target=_blank>EXEMAS-B</a> TROJAN!
  6886. Source=Paul Collins Startup list
  6887.  
  6888. [Bandwidth Monitor Pro]
  6889. Number=978
  6890. Confirmed=U
  6891. Filename=Bandwidth Monitor Pro.exe
  6892. Description=<a href="http://www.bandwidthmonitorpro.com/" target=_blank>Bandwidth Monitor Pro</a> - utililty to track your current download/upload limit that may be set by your ISP
  6893.  
  6894. Source=Paul Collins Startup list
  6895.  
  6896. [Banpopup by Pratik]
  6897. Number=979
  6898. Confirmed=U
  6899. Filename=Banpopup.exe
  6900. Description=Banpopup - popup killer
  6901. Source=Paul Collins Startup list
  6902.  
  6903. [Bar Ding lolt]
  6904. Number=980
  6905. Confirmed=X
  6906. Filename=Analiz.exe
  6907. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotrp.html" target=_blank>RBOT-RP</a> WORM!
  6908. Source=Paul Collins Startup list
  6909.  
  6910. [bargains]
  6911. Number=981
  6912. Confirmed=X
  6913. Filename=bargains.exe
  6914. Description=<a href="http://sarc.com/avcenter/venc/data/adware.bargainbuddy.html" target="_blank">BargainBuddy</a> foistware
  6915. Source=Paul Collins Startup list
  6916.  
  6917. [bargains]
  6918. Number=982
  6919. Confirmed=X
  6920. Filename=bargainbuddy.exe
  6921. Description=<a href="http://sarc.com/avcenter/venc/data/adware.bargainbuddy.html" target="_blank">BargainBuddy</a> foistware
  6922. Source=Paul Collins Startup list
  6923.  
  6924. [Bart Station]
  6925. Number=983
  6926. Confirmed=?
  6927. Filename=station.sbrt
  6928. Description=<font color="#FF0000">Related to <a href="http://www.peoplepc.com/" target="_blank"> PeoplePC ISP</a>. May be a dialler for dial-up accounts?</font>
  6929. Source=Paul Collins Startup list
  6930.  
  6931. [Bart Station]
  6932. Number=984
  6933. Confirmed=U
  6934. Filename=PPCOLink.exe
  6935. Description=Dialer for PeoplePC ISP
  6936. Source=Paul Collins Startup list
  6937.  
  6938. [BarTheme]
  6939. Number=985
  6940. Confirmed=X
  6941. Filename=bartent32.exe
  6942. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotug.html" target=_blank>AGOBOT-UG</a> WORM!
  6943. Source=Paul Collins Startup list
  6944.  
  6945. [bascstray]
  6946. Number=986
  6947. Confirmed=N
  6948. Filename=BascsTray.exe
  6949. Description=Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
  6950. Source=Paul Collins Startup list
  6951.  
  6952. [Bat]
  6953. Number=987
  6954. Confirmed=X
  6955. Filename=secure2.bat
  6956. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-041517-5616-99" target="_blank">ZCREW.C</a> TROJAN!
  6957. Source=Paul Collins Startup list
  6958.  
  6959. [Batchreg1]
  6960. Number=988
  6961. Confirmed=N
  6962. Filename=N/A
  6963. Description=Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See <a href="http://www.vanwijk.com/-=%20Bookz%20=-/Special%20Edition%20Using%20Windows%2098/ch10/ch10.htm#Heading24" target="_blank">here</a>
  6964. Source=Paul Collins Startup list
  6965.  
  6966. [BatInfEx]
  6967. Number=989
  6968. Confirmed=U
  6969. Filename=rundll32.exe
  6970. Description=Displays battery status information on an IBM Thinkpad
  6971. Source=Paul Collins Startup list
  6972.  
  6973. [BatSrv]
  6974. Number=990
  6975. Confirmed=X
  6976. Filename=batserv2.exe
  6977. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as the Win32.Locksky.m WORM!
  6978. Source=Paul Collins Startup list
  6979.  
  6980. [Battery Scope]
  6981. Number=991
  6982. Confirmed=U
  6983. Filename=batmgr.exe
  6984. Description=Monitors battery levels on a notebook/laptop PC
  6985. Source=Paul Collins Startup list
  6986.  
  6987. [BatteryBar]
  6988. Number=992
  6989. Confirmed=U
  6990. Filename=batterybar.exe
  6991. Description=<a href="http://www.nistech.com/BatteryBar/Default.htm" target="_blank">BatteryBar</a> - displays battery usage, and the current percentage of battery power left
  6992. Source=Paul Collins Startup list
  6993.  
  6994. [BatzBack]
  6995. Number=993
  6996. Confirmed=X
  6997. Filename=BatzBack.scr
  6998. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-122517-5425-99" target="_blank">BACKZAT</a> WORM!
  6999. Source=Paul Collins Startup list
  7000.  
  7001. [BAUSB]
  7002. Number=994
  7003. Confirmed=U
  7004. Filename=BAUSB.exe
  7005. Description=Boston Acoustics Audio, USB driver
  7006. Source=Paul Collins Startup list
  7007.  
  7008. [bawindo]
  7009. Number=995
  7010. Confirmed=X
  7011. Filename=bawindo.exe
  7012. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-092811-5825-99" target="_blank">BEAGLE.AR</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-102909-4007-99" target=_blank>BEAGLE.AU</a> WORMS!
  7013. Source=Paul Collins Startup list
  7014.  
  7015. [BayMgr]
  7016. Number=996
  7017. Confirmed=U
  7018. Filename=DockApp.exe
  7019. Description=Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices 
  7020. Source=Paul Collins Startup list
  7021.  
  7022. [Bayswap]
  7023. Number=997
  7024. Confirmed=U
  7025. Filename=bayswap.exe
  7026. Description=Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
  7027. Source=Paul Collins Startup list
  7028.  
  7029. [Bayswap2]
  7030. Number=998
  7031. Confirmed=U
  7032. Filename=TbUpdate.exe
  7033. Description=Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
  7034. Source=Paul Collins Startup list
  7035.  
  7036. [BBC Alerts]
  7037. Number=999
  7038. Confirmed=N
  7039. Filename=BBC_Alerts.exe
  7040. Description=<a href="http://news.bbc.co.uk/1/hi/help/4735697.stm" target="_blank">BBC Alerts</a> - "You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"
  7041. Source=Paul Collins Startup list
  7042.  
  7043. [BBC News alerts]
  7044. Number=1000
  7045. Confirmed=U
  7046. Filename=skinkers.exe
  7047. Description=BBC News Desktop Alerts service - see <a href="http://news.bbc.co.uk/2/hi/help/3533099.stm" target= blank>here</a>. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens
  7048. Source=Paul Collins Startup list
  7049.  
  7050. [BBDial]
  7051. Number=1001
  7052. Confirmed=?
  7053. Filename=BT Broadband.exe
  7054. Description=<font color="#FF0000">Part of BT Broandband - is it required?</font>
  7055. Source=Paul Collins Startup list
  7056.  
  7057. [bbSysTray]
  7058. Number=1002
  7059. Confirmed=N
  7060. Filename=bbSysTray.exe
  7061. Description=Philips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"
  7062. Source=Paul Collins Startup list
  7063.  
  7064. [bbui]
  7065. Number=1003
  7066. Confirmed=U
  7067. Filename=bbui.exe
  7068. Description=AOL DSL status monitor displaying a red/green icon indicating if you have a connection
  7069. Source=Paul Collins Startup list
  7070.  
  7071. [bca]
  7072. Number=1004
  7073. Confirmed=U
  7074. Filename=bca.exe
  7075. Description=BeClean Agent - registry, history, temp files, etc cleaner
  7076. Source=Paul Collins Startup list
  7077.  
  7078. [BCDetect]
  7079. Number=1005
  7080. Confirmed=U
  7081. Filename=bcdetect.exe
  7082. Description=Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
  7083. Source=Paul Collins Startup list
  7084.  
  7085. [BCMDMMSG]
  7086. Number=1006
  7087. Confirmed=Y
  7088. Filename=bcmdmmsg.exe
  7089. Description=BCM voicemodem driver. Required for dial-up if you have one of these modems
  7090. Source=Paul Collins Startup list
  7091.  
  7092. [BCMHal]
  7093. Number=1007
  7094. Confirmed=U
  7095. Filename=rundll32.exe bcmhal9x.dll, bcinit
  7096. Description=BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
  7097. Source=Paul Collins Startup list
  7098.  
  7099. [BCMSMMSG]
  7100. Number=1008
  7101. Confirmed=Y
  7102. Filename=BCMSMMSG.exe
  7103. Description=BCM voicemodem driver. Required for dial-up if you have one of these modems
  7104. Source=Paul Collins Startup list
  7105.  
  7106. [bcmwltry]
  7107. Number=1009
  7108. Confirmed=?
  7109. Filename=bcmwltry.exe
  7110. Description=Broadcom Corporation Wireless Network Tray Applet.<font color="#FF0000"> </font><font color="#FF0000">Is it required?</font>
  7111. Source=Paul Collins Startup list
  7112.  
  7113. [BCNT]
  7114. Number=1010
  7115. Confirmed=N
  7116. Filename=bcnt.exe
  7117. Description=<a href="http://www.weatherbug.com/aws/index.asp" target="_blank">AWS Weatherbug</a> related. <font color="#FF0000">What does it do?</font>
  7118. Source=Paul Collins Startup list
  7119.  
  7120. [BCPC]
  7121. Number=1011
  7122. Confirmed=X
  7123. Filename=bcpc.exe
  7124. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  7125. Source=Paul Collins Startup list
  7126.  
  7127. [bcpc_c]
  7128. Number=1012
  7129. Confirmed=X
  7130. Filename=bcpc_c.exe
  7131. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  7132. Source=Paul Collins Startup list
  7133.  
  7134. [BCTweak]
  7135. Number=1013
  7136. Confirmed=U
  7137. Filename=bctweak.exe
  7138. Description=BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
  7139. Source=Paul Collins Startup list
  7140.  
  7141. [Bcvsrv32]
  7142. Number=1014
  7143. Confirmed=X
  7144. Filename=bcvsrv32.exe
  7145. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-110816-5549-99" target=_blank>GAOBOT.BQJ</a> WORM!
  7146. Source=Paul Collins Startup list
  7147.  
  7148. [BCWipeTM]
  7149. Number=1015
  7150. Confirmed=N
  7151. Filename=bcwipetm.exe
  7152. Description=<a href="http://www.jetico.com/" target="_blank">BCWipe</a> Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed
  7153. Source=Paul Collins Startup list
  7154.  
  7155. [BD]
  7156. Number=1016
  7157. Confirmed=X
  7158. Filename=dc.exe
  7159. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojrasdoora.html" target=_blank>RASDOOR-A</a> TROJAN!
  7160. Source=Paul Collins Startup list
  7161.  
  7162. [BDAgent]
  7163. Number=1017
  7164. Confirmed=U
  7165. Filename=bdagent.exe
  7166. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  7167. Source=Paul Collins Startup list
  7168.  
  7169. [BDMCon]
  7170. Number=1018
  7171. Confirmed=Y
  7172. Filename=Bdmcon.exe
  7173. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  7174. Source=Paul Collins Startup list
  7175.  
  7176. [BDNewsAgent]
  7177. Number=1019
  7178. Confirmed=Y
  7179. Filename=bdnagent.exe
  7180. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus - updater
  7181. Source=Paul Collins Startup list
  7182.  
  7183. [BDOESRV]
  7184. Number=1020
  7185. Confirmed=Y
  7186. Filename=bdoesrv.exe
  7187. Description=<a href="http://www.bitdefender.com/" target="_blank">Bitdefender</a> 8 antivirus and firewall
  7188. Source=Paul Collins Startup list
  7189.  
  7190. [BDSwitchAgent]
  7191. Number=1021
  7192. Confirmed=Y
  7193. Filename=bdswitch.exe
  7194. Description=<a href="http://www.bitdefender.com/" target="_blank">Bitdefender</a> 8 antivirus and firewall
  7195. Source=Paul Collins Startup list
  7196.  
  7197. [BearFlix]
  7198. Number=1022
  7199. Confirmed=U
  7200. Filename=BearFlix.exe
  7201. Description=<a href="http://www.bearflix.com/" target="_blank">BearFlix</a> is optimized for the fast download of video files
  7202. Source=Paul Collins Startup list
  7203.  
  7204. [BearShare]
  7205. Number=1023
  7206. Confirmed=N
  7207. Filename=bearshare.exe
  7208. Description=<a href="http://www.bearshare.com/" target="_blank">BearShare</a> file sharing client. Versions known to include spyware - see <a href="http://www.cexx.org/adware.htm" target="_blank">here</a>
  7209. Source=Paul Collins Startup list
  7210.  
  7211. [BeatNik Internet Clock]
  7212. Number=1024
  7213. Confirmed=U
  7214. Filename=BeatNik.exe
  7215. Description=<a href="http://www.somedec.com/" target=_blank>BeatNik Internet Clock</a> is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock
  7216. Source=Paul Collins Startup list
  7217.  
  7218. [Beawver]
  7219. Number=1025
  7220. Confirmed=X
  7221. Filename=saqevre.exe
  7222. Description=Added by the <a href="http://www.scanspyware.net/info/Ranky.AGA.htm" target="_blank">RANKY.AGA</a> TROJAN!
  7223. Source=Paul Collins Startup list
  7224.  
  7225. [Beegees Update]
  7226. Number=1026
  7227. Confirmed=X
  7228. Filename=beegees.exe
  7229. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotadk.html" target=_blank>SDBOT-ADK</a> WORM!
  7230. Source=Paul Collins Startup list
  7231.  
  7232. [BEEI]
  7233. Number=1027
  7234. Confirmed=?
  7235. Filename=beei.exe
  7236. Description=<font color="#FF0000">??</font>
  7237. Source=Paul Collins Startup list
  7238.  
  7239. [BeFaster]
  7240. Number=1028
  7241. Confirmed=U
  7242. Filename=befaster3.exe
  7243. Description=<a href="http://www.ekremdeniz.com/" target= blank>BeFaster</a> internet connection optimization tool
  7244. Source=Paul Collins Startup list
  7245.  
  7246. [BEHL]
  7247. Number=1029
  7248. Confirmed=?
  7249. Filename=BEHL.exe
  7250. Description=<font color="#FF0000">??</font>
  7251. Source=Paul Collins Startup list
  7252.  
  7253. [BEHLO]
  7254. Number=1030
  7255. Confirmed=?
  7256. Filename=BEHLO.exe
  7257. Description=<font color="#FF0000">??</font>
  7258. Source=Paul Collins Startup list
  7259.  
  7260. [Belkin PCMCIA WLAN Monitor]
  7261. Number=1031
  7262. Confirmed=N
  7263. Filename=monitorbk.exe
  7264. Description=Belkin USB Network Adapter Management utility - can be started manually
  7265. Source=Paul Collins Startup list
  7266.  
  7267. [Belkin Wireless Utility]
  7268. Number=1032
  7269. Confirmed=N
  7270. Filename=Belkinwcui.exe
  7271. Description=Wireles configuration utility for some Belkin cards such as the <a href="http://catalog.belkin.com/IWCatProductPage.process?Product_Id=136479" target="_blank">Wireless G Desktop Card</a>
  7272. Source=Paul Collins Startup list
  7273.  
  7274. [BellSouthAlertManager.exe]
  7275. Number=1033
  7276. Confirmed=U
  7277. Filename=BellSouthAlertManager.exe
  7278. Description=Related to <a href="http://pcpitstop.com/spycheck/SWDetail.asp?fn=BellSouthAlertManager.exe" target="_blank">BellSouth Alert Manager</a>
  7279. Source=Paul Collins Startup list
  7280.  
  7281. [BelNotify]
  7282. Number=1034
  7283. Confirmed=U
  7284. Filename=[path] NPBelv32.dll, RunDll32_BelNotify
  7285. Description="BelTech from <a href="http://www.belarc.com/" target=_blank>Belarc</a> enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service"
  7286. Source=Paul Collins Startup list
  7287.  
  7288. [BELORVBI]
  7289. Number=1035
  7290. Confirmed=?
  7291. Filename=BELORVBI.exe
  7292. Description=<font color="#FF0000">??</font>
  7293. Source=Paul Collins Startup list
  7294.  
  7295. [Belsta.exe]
  7296. Number=1036
  7297. Confirmed=?
  7298. Filename=Belsta.exe
  7299. Description=Configuration tool for Belkin wireless network cards. Required to change the card's configuration.<font color="#FF0000"> Is it required for correct operation once the confuiguration is changed?</font>
  7300. Source=Paul Collins Startup list
  7301.  
  7302. [Belt]
  7303. Number=1037
  7304. Confirmed=X
  7305. Filename=Belt.exe
  7306. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=VX2.Transponder&threatid=12517" target=_blank>VX2.Transponder</a> parasite updater/installer related
  7307. Source=Paul Collins Startup list
  7308.  
  7309. [Benadril Alert Tool]
  7310. Number=1038
  7311. Confirmed=X
  7312. Filename=benadrilalert.exe
  7313. Description=Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
  7314. Source=Paul Collins Startup list
  7315.  
  7316. [BestPopUpKiller]
  7317. Number=1039
  7318. Confirmed=N
  7319. Filename=BestPopupKiller.exe
  7320. Description=Popup killer by Swanksoft - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  7321. Source=Paul Collins Startup list
  7322.  
  7323. [BeSys]
  7324. Number=1040
  7325. Confirmed=X
  7326. Filename=[path to file]
  7327. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-052015-1227-99" target="_blank">BeSys</a> adware
  7328. Source=Paul Collins Startup list
  7329.  
  7330. [BF4P]
  7331. Number=1041
  7332. Confirmed=X
  7333. Filename=bf4p.exe
  7334. Description=Added by the <a href="http://fileinfo.prevx.com/QQc81816553925-BF4P13381774/BF4P.EXE.html" target="_blank">IRCBOT.GEN</a> WORM!
  7335. Source=Paul Collins Startup list
  7336.  
  7337. [bg]
  7338. Number=1042
  7339. Confirmed=Y
  7340. Filename=bullguard.exe
  7341. Description=<a href="http://www.bullguard.com/" target="_blank">Bullguard</a> antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster
  7342. Source=Paul Collins Startup list
  7343.  
  7344. [BGInfo]
  7345. Number=1043
  7346. Confirmed=U
  7347. Filename=Bginfo.exe
  7348. Description=<a href="http://www.microsoft.com/technet/sysinternals/utilities/BgInfo.mspx" target="_blank">BGinfo</a> automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more
  7349. Source=Paul Collins Startup list
  7350.  
  7351. [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
  7352. Number=1044
  7353. Confirmed=U
  7354. Filename=NMBgMonitor.exe
  7355. Description=Associated with <a href="http://www.nero.com/nero7/eng/Nero_Scout.html" target="_blank">Nero Scout</a>, added by version 7 of the Nero digital media suite (CD & DVD burning, authoring, etc). Thanks to Help2Go.com, if you feel this is draining more resources that necessary you can disable it by <a href="http://www.help2go.com/Tutorials/Software_Utilities/Disable_Nero_Scout_in_Nero_7.html" target="_blank">clicking here</a>
  7356. Source=Paul Collins Startup list
  7357.  
  7358. [BGNewsAgent]
  7359. Number=1045
  7360. Confirmed=Y
  7361. Filename=bgnewsag.exe
  7362. Description=<a href="http://www.bullguard.com/" target=_blank>BullGuard</a> antivirus updater
  7363.  
  7364. Source=Paul Collins Startup list
  7365.  
  7366. [bgsmsnd]
  7367. Number=1046
  7368. Confirmed=N
  7369. Filename=bgsmsnd.exe
  7370. Description=Printer driver to generate PDF files from any program
  7371. Source=Paul Collins Startup list
  7372.  
  7373. [BHOCop]
  7374. Number=1047
  7375. Confirmed=N
  7376. Filename=BHOCop.exe
  7377. Description=PC Magazine's <a href="http://www.pcmag.com/article2/0,1895,1654861,00.asp" target="_blank">BHO Cop</a> that lets you see what browser helper objects are installed. Useful for detecting spyware
  7378. Source=Paul Collins Startup list
  7379.  
  7380. [BHODemon 2.0]
  7381. Number=1048
  7382. Confirmed=U
  7383. Filename=BHODemon.exe
  7384. Description=BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!". If you prefer forgoing resident protection, the application can also be run on demand
  7385. Source=Paul Collins Startup list
  7386.  
  7387. [BHR]
  7388. Number=1049
  7389. Confirmed=U
  7390. Filename=BHR.exe
  7391. Description=<a href="http://www.zamaansoft.com/products/bhr/" target="_blank">Browser Hijack Retaliator</a> - recovers your browser after it has been hijacked by spyware, adware, etc
  7392. Source=Paul Collins Startup list
  7393.  
  7394. [BI1HelperStartUp]
  7395. Number=1050
  7396. Confirmed=U
  7397. Filename=BI1HEL~1.EXE
  7398. Description=ScreenScenes "Beach Islands" screensaver. The freeware version comes with <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.GAIN.CommonElements&threatid=5605" target="_blank">GAIN</a> branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  7399. Source=Paul Collins Startup list
  7400.  
  7401. [BIE]
  7402. Number=1051
  7403. Confirmed=X
  7404. Filename=Rundll32.exe BDSrHook.dll, Rundll32
  7405. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075264" target="_blank">BDplugin</a> parasite
  7406. Source=Paul Collins Startup list
  7407.  
  7408. [BIG]
  7409. Number=1052
  7410. Confirmed=X
  7411. Filename=biggy.exe
  7412. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotag.html" target="_blank">DELBOT-AG</a> WORM!
  7413. Source=Paul Collins Startup list
  7414.  
  7415. [BigDog303]
  7416. Number=1053
  7417. Confirmed=U
  7418. Filename=VM303_STI.EXE
  7419. Description=Related to <a href="http://www.vimicro.com/english/" target="_blank">VIMICRO USB</a> for PC Camera
  7420. Source=Paul Collins Startup list
  7421.  
  7422. [BigDogPath]
  7423. Number=1054
  7424. Confirmed=?
  7425. Filename=VM_STI.EXE
  7426. Description=Bundled with some software for digital cameras that use a USB connection - <font color="#FF0000">what does it do and is it required?</font>
  7427. Source=Paul Collins Startup list
  7428.  
  7429. [bigfix]
  7430. Number=1055
  7431. Confirmed=N
  7432. Filename=BIGFIX.EXE
  7433. Description=<a href="http://www.bigfix.com/index.html" target="_blank">BigFix</a> can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet« Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog
  7434. Source=Paul Collins Startup list
  7435.  
  7436. [BigPond Toolbar]
  7437. Number=1056
  7438. Confirmed=U
  7439. Filename=bpumTray.exe
  7440. Description=Telstra <a href="http://www.bigpond.com/default.asp" target="_blank">BigPond</a> Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"
  7441. Source=Paul Collins Startup list
  7442.  
  7443. [BigPondCable]
  7444. Number=1057
  7445. Confirmed=N
  7446. Filename=bpcable.exe
  7447. Description=Telstra Bigpond Cable login software - can be started manually
  7448.  
  7449. Source=Paul Collins Startup list
  7450.  
  7451. [bikini]
  7452. Number=1058
  7453. Confirmed=X
  7454. Filename=bikini.exe
  7455. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlowzonecx.html" target="_blank">LOWZONE-CX</a> TROJAN!
  7456. Source=Paul Collins Startup list
  7457.  
  7458. [Billminder]
  7459. Number=1059
  7460. Confirmed=N
  7461. Filename=Billmind.exe
  7462. Description=Can be setup in Quicken to remind user of due payments. Available via Start -> Programs
  7463. Source=Paul Collins Startup list
  7464.  
  7465. [bin32hpu]
  7466. Number=1060
  7467. Confirmed=X
  7468. Filename=ppstub.exe
  7469. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021414-1601-99" target="_blank">PrecisionPop</a> adware
  7470. Source=Paul Collins Startup list
  7471.  
  7472. [bingdian]
  7473. Number=1061
  7474. Confirmed=X
  7475. Filename=Bingdian.vbs
  7476. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-072911-5238-99" target="_blank">BINGD</a> WORM!
  7477. Source=Paul Collins Startup list
  7478.  
  7479. [Bingo Charm]
  7480. Number=1062
  7481. Confirmed=?
  7482. Filename=charms.exe
  7483. Description=<font color="#FF0000">Some kind of screen icon kind of like desk flag, but it gives you a choice of icons?</font>
  7484. Source=Paul Collins Startup list
  7485.  
  7486. [Biomenu]
  7487. Number=1063
  7488. Confirmed=U
  7489. Filename=menusw.exe
  7490. Description=Related to <a href="http://vaio-online.sony.com/prod_info/vgn-bx168gp/solid_security.html" target=_blank>Sony VAIO</a> - passwords, encryption, and a biometric fingerprint sensor
  7491. Source=Paul Collins Startup list
  7492.  
  7493. [Bios]
  7494. Number=1064
  7495. Confirmed=X
  7496. Filename=Bios32.exe
  7497. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  7498. Source=Paul Collins Startup list
  7499.  
  7500. [BIOS XP Loader]
  7501. Number=1065
  7502. Confirmed=X
  7503. Filename=[random filename]
  7504. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotic.html" target=_blank>RBOT-IC</a> WORM!
  7505. Source=Paul Collins Startup list
  7506.  
  7507. [BIOS1]
  7508. Number=1066
  7509. Confirmed=X
  7510. Filename=BIOS1.EXE
  7511. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
  7512. Source=Paul Collins Startup list
  7513.  
  7514. [BIOVCIP]
  7515. Number=1067
  7516. Confirmed=?
  7517. Filename=BIOVCIP.exe
  7518. Description=<font color="#FF0000">??</font>
  7519. Source=Paul Collins Startup list
  7520.  
  7521. [BitComet]
  7522. Number=1068
  7523. Confirmed=N
  7524. Filename=BitComet.exe
  7525. Description=<a href="http://www.bitcomet.com/index.htm" target=_blank>BitComet</a> P2P client - can be launched from Start -> Programs
  7526. Source=Paul Collins Startup list
  7527.  
  7528. [BitDefender Antivirus]
  7529. Number=1069
  7530. Confirmed=X
  7531. Filename=BITDEFENDERX.EXE
  7532. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-053013-5943-99" target="_blank">SPYBOT</a> WORM!
  7533. Source=Paul Collins Startup list
  7534.  
  7535. [BitDefender Communicator]
  7536. Number=1070
  7537. Confirmed=Y
  7538. Filename=xcommsvr.exe
  7539. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  7540. Source=Paul Collins Startup list
  7541.  
  7542. [BitDefender for MSN Messenger]
  7543. Number=1071
  7544. Confirmed=U
  7545. Filename=msnmon.exe
  7546. Description=Bitdefender anti-virus for MSN Messenger - no longer supported at the <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> website
  7547. Source=Paul Collins Startup list
  7548.  
  7549. [BitDefender for Yahoo! Messenger]
  7550. Number=1072
  7551. Confirmed=U
  7552. Filename=yahmon.exe
  7553. Description=Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> website
  7554. Source=Paul Collins Startup list
  7555.  
  7556. [BitDefender Live! Init]
  7557. Number=1073
  7558. Confirmed=Y
  7559. Filename=bdinit.exe
  7560. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  7561. Source=Paul Collins Startup list
  7562.  
  7563. [BitDefender Scan Server]
  7564. Number=1074
  7565. Confirmed=Y
  7566. Filename=bdss.exe
  7567. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  7568. Source=Paul Collins Startup list
  7569.  
  7570. [BitDefender Virus Shield]
  7571. Number=1075
  7572. Confirmed=Y
  7573. Filename=vsserv.exe
  7574. Description=<a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
  7575. Source=Paul Collins Startup list
  7576.  
  7577. [bitdefenderlive]
  7578. Number=1076
  7579. Confirmed=Y
  7580. Filename=avxlive.exe
  7581. Description=Main program of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
  7582. Source=Paul Collins Startup list
  7583.  
  7584. [BitDefender_P2P_Startup]
  7585. Number=1077
  7586. Confirmed=U
  7587. Filename=BitDefender_P2P_Startup.exe
  7588. Description=Bitdefender anti-virus for P2P clients - no longer supported at the <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> website
  7589. Source=Paul Collins Startup list
  7590.  
  7591. [BitWare Print Monitor]
  7592. Number=1078
  7593. Confirmed=N
  7594. Filename=bwprnmon.exe
  7595. Description=<a href="http://www.2point.com/FAXserve/" target="_blank">FaxServe</a> network fax software
  7596. Source=Paul Collins Startup list
  7597.  
  7598. [BJ Printer Status Monitor]
  7599. Number=1079
  7600. Confirmed=N
  7601. Filename=Cjstsr.exe
  7602. Description=Canon BJ printer status monitor
  7603. Source=Paul Collins Startup list
  7604.  
  7605. [BJ Status Monitor 5xx]
  7606. Number=1080
  7607. Confirmed=N
  7608. Filename=CJSTRxx.EXE
  7609. Description=Canon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
  7610. Source=Paul Collins Startup list
  7611.  
  7612. [bjcfd]
  7613. Number=1081
  7614. Confirmed=N
  7615. Filename=cdf.exe
  7616. Description=<a href="http://www.broadjump.com/" target="_blank">BroadJump</a> Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
  7617. Source=Paul Collins Startup list
  7618.  
  7619. [BlackICE PC Protection]
  7620. Number=1082
  7621. Confirmed=N
  7622. Filename=blackice.exe
  7623. Description=Loads the user interface for the <a href="http://blackice.iss.net/product_pc_protection.php" target="_blank">BlackICE PC Protection</a> (was Defender) firewall program. From the <a href="http://www.networkice.com/" target="_blank">parent site</a> - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD
  7624. Source=Paul Collins Startup list
  7625.  
  7626. [BlackIce Utility]
  7627. Number=1083
  7628. Confirmed=N
  7629. Filename=blackice.exe
  7630. Description=Loads the user interface for the <a href="http://blackice.iss.net/product_pc_protection.php" target="_blank">BlackICE PC Protection</a> (was Defender) firewall program. From the <a href="http://www.networkice.com/" target="_blank">parent site</a> - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD
  7631. Source=Paul Collins Startup list
  7632.  
  7633. [blads]
  7634. Number=1084
  7635. Confirmed=U
  7636. Filename=blads.exe
  7637. Description=A <a href="http://www.totalidea.com/frameset-tweakxp.htm" target=_blank>Tweak-XP</a> component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
  7638. Source=Paul Collins Startup list
  7639.  
  7640. [blah service]
  7641. Number=1085
  7642. Confirmed=X
  7643. Filename=winupdate.exe
  7644. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-090709-0941-99" target="_blank">GAOBOT.BIA</a> WORM!
  7645. Source=Paul Collins Startup list
  7646.  
  7647. [blah service]
  7648. Number=1086
  7649. Confirmed=X
  7650. Filename=winsysengine.exe
  7651. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotki.html" target="_blank">RBOT-KI</a> WORM!
  7652. Source=Paul Collins Startup list
  7653.  
  7654. [blah service]
  7655. Number=1087
  7656. Confirmed=X
  7657. Filename=internet.exe
  7658. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  7659.  
  7660. Source=Paul Collins Startup list
  7661.  
  7662. [blah service]
  7663. Number=1088
  7664. Confirmed=X
  7665. Filename=smnp.exe
  7666. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.IZ" target=_blank>RBOT.IZ</a> WORM!
  7667.  
  7668. Source=Paul Collins Startup list
  7669.  
  7670. [blah service]
  7671. Number=1089
  7672. Confirmed=X
  7673. Filename=msnmsgrr.exe
  7674. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.PZ&VSect=T" target=_blank>RBOT.PZ</a> WORM!
  7675. Source=Paul Collins Startup list
  7676.  
  7677. [blah service]
  7678. Number=1090
  7679. Confirmed=X
  7680. Filename=tazkmgr.exe
  7681. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.UA" target=_blank>RBOT.UA</a> WORM!
  7682. Source=Paul Collins Startup list
  7683.  
  7684. [blah service]
  7685. Number=1091
  7686. Confirmed=X
  7687. Filename=FaLeH.exe
  7688. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaes.html" target=_blank>RBOT-AES</a> WORM!
  7689. Source=Paul Collins Startup list
  7690.  
  7691. [blah service]
  7692. Number=1092
  7693. Confirmed=X
  7694. Filename=microsoft.exe
  7695. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  7696. Source=Paul Collins Startup list
  7697.  
  7698. [blah service]
  7699. Number=1093
  7700. Confirmed=X
  7701. Filename=evosys.exe
  7702. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  7703. Source=Paul Collins Startup list
  7704.  
  7705. [blah service]
  7706. Number=1094
  7707. Confirmed=X
  7708. Filename=win32.exe
  7709. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaxo.html" target=_blank>RBOT-AXO</a> WORM!
  7710. Source=Paul Collins Startup list
  7711.  
  7712. [Blah service]
  7713. Number=1095
  7714. Confirmed=X
  7715. Filename=CCAPPS32.EXE
  7716. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.TV" target="_blank">RBOT.TV</a> WORM!
  7717. Source=Paul Collins Startup list
  7718.  
  7719. [blahh service]
  7720. Number=1096
  7721. Confirmed=X
  7722. Filename=msengine.exe
  7723. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target= blank>RBOT</a> WORM!
  7724. Source=Paul Collins Startup list
  7725.  
  7726. [blahx service]
  7727. Number=1097
  7728. Confirmed=X
  7729. Filename=msnjompa.exe
  7730. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.AML" target=_blank>SDBOT.AML</a> WORM!
  7731. Source=Paul Collins Startup list
  7732.  
  7733. [BlazeChanger]
  7734. Number=1098
  7735. Confirmed=N
  7736. Filename=FBZPaper.exe
  7737. Description=<a href="http://www.firehand.com/Ember/" target="_blank">Ember</a> graphic file viewer, manager, and touch-up system
  7738. Source=Paul Collins Startup list
  7739.  
  7740. [bldbubg]
  7741. Number=1099
  7742. Confirmed=N
  7743. Filename=bldbubg.exe
  7744. Description=Part of Dell Alerts which provides customers with an update on latest updates for his/her system
  7745. Source=Paul Collins Startup list
  7746.  
  7747. [BLF]
  7748. Number=1100
  7749. Confirmed=X
  7750. Filename=blf.exe
  7751. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotm.html" target="_blank">DELBOT-M</a> WORM!
  7752. Source=Paul Collins Startup list
  7753.  
  7754. [blinkx]
  7755. Number=1101
  7756. Confirmed=U
  7757. Filename=blinkx.exe
  7758. Description=<a href="http://www.blinkx.com/" target=_blank>Blinkx</a> Desktop "Smart Folders" software
  7759. Source=Paul Collins Startup list
  7760.  
  7761. [BLMessagingIntegration]
  7762. Number=1102
  7763. Confirmed=X
  7764. Filename=blengine.exe
  7765. Description=<a href="http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101007" target="_blank">BuddyLinks</a> adware
  7766. Source=Paul Collins Startup list
  7767.  
  7768. [BlockAds]
  7769. Number=1103
  7770. Confirmed=U
  7771. Filename=blads.exe
  7772. Description=A <a href="http://www.totalidea.com/frameset-tweakxp.htm" target=_blank>Tweak-XP</a> component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
  7773. Source=Paul Collins Startup list
  7774.  
  7775. [BlockChecker]
  7776. Number=1104
  7777. Confirmed=X
  7778. Filename=Block-checker.exe
  7779. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-082521-1906-99" target=_blank>BlockChecker</a> adware
  7780. Source=Paul Collins Startup list
  7781.  
  7782. [Blocker System611 Monitoring]
  7783. Number=1105
  7784. Confirmed=X
  7785. Filename=PopUpBlocker611.exe
  7786. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BLJ&VSect=P" target=_blank>RBOT.BLJ</a> WORM!
  7787. Source=Paul Collins Startup list
  7788.  
  7789. [BlockTracker]
  7790. Number=1106
  7791. Confirmed=N
  7792. Filename=BlockTracker.exe
  7793. Description=If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
  7794. Source=Paul Collins Startup list
  7795.  
  7796. [blsloader]
  7797. Number=1107
  7798. Confirmed=U
  7799. Filename=blsloader.exe
  7800. Description=BellSouth ISP <a href="http://bellsouth.com/consumer/inetsrvcs/inetsrvcs_fa_features.html" target="_blank">Internet Tools</a>
  7801. Source=Paul Collins Startup list
  7802.  
  7803. [blss]
  7804. Number=1108
  7805. Confirmed=X
  7806. Filename=blss.exe
  7807. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-022118-1659-99" target=_blank>BLARUL</a> TROJAN!
  7808. Source=Paul Collins Startup list
  7809.  
  7810. [BLSTAPP]
  7811. Number=1109
  7812. Confirmed=N
  7813. Filename=blstapp.exe
  7814. Description=Puts access to Creative's BlasterControl in the System Tray
  7815. Source=Paul Collins Startup list
  7816.  
  7817. [Blubster]
  7818. Number=1110
  7819. Confirmed=N
  7820. Filename=Blubster.exe
  7821. Description=Related to <a href="http://www.blubster.com/" target=_blank>Blubster</a> Music sharing service
  7822. Source=Paul Collins Startup list
  7823.  
  7824. [Blue Frog]
  7825. Number=1111
  7826. Confirmed=U
  7827. Filename=bluefrog.exe
  7828. Description=<a href="http://en.wikipedia.org/wiki/Blue_Frog" target="_blank">Blue Frog</a> by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive
  7829. Source=Paul Collins Startup list
  7830.  
  7831. [BlueLight_uoltray]
  7832. Number=1112
  7833. Confirmed=?
  7834. Filename=exec.exe
  7835. Description=Related to <a href="http://www.mybluelight.com/" target="_blank">BlueLight Internet</a>. <font color="#FF0000">What does it do and is it required?</a>
  7836. Source=Paul Collins Startup list
  7837.  
  7838. [BlueSoleil]
  7839. Number=1113
  7840. Confirmed=U
  7841. Filename=BLUESO~1.EXE
  7842. Description=<a href="http://www.bluesoleil.com/products/index.asp" target="_blank">BlueSoleil</a> Bluetooth wireless manager from IVT Corporation
  7843. Source=Paul Collins Startup list
  7844.  
  7845. [BlueSpace NE]
  7846. Number=1114
  7847. Confirmed=U
  7848. Filename=BlueSpaceNE.exe
  7849. Description="BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter". Shortcut available via Start -> Programs
  7850. Source=Paul Collins Startup list
  7851.  
  7852. [BlueToothAuthentication Agent]
  7853. Number=1115
  7854. Confirmed=U
  7855. Filename=RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent
  7856. Description=Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click <a href="http://www.winbookcorp.com/_technote/WBTA20000912.htm" target=_blank>here</a> for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
  7857. Source=Paul Collins Startup list
  7858.  
  7859. [Blueyonder Instant Support Tool]
  7860. Number=1116
  7861. Confirmed=U
  7862. Filename=matcli.exe
  7863. Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide
  7864. Source=Paul Collins Startup list
  7865.  
  7866. [BMail Installation]
  7867. Number=1117
  7868. Confirmed=N
  7869. Filename=FTP_back.exe
  7870. Description=Part of <a href="http://www.imesh.com" target="_blank">iMesh</a> - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not
  7871. Source=Paul Collins Startup list
  7872.  
  7873. [Bman]
  7874. Number=1118
  7875. Confirmed=X
  7876. Filename=BMan1.exe
  7877. Description=Abcsearch.com/DealHelper adware variant
  7878. Source=Paul Collins Startup list
  7879.  
  7880. [BMMGAG]
  7881. Number=1119
  7882. Confirmed=U
  7883. Filename=Rundll32 PWRMONIT.DLL, StartPwrMonitor
  7884. Description=Displays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window
  7885. Source=Paul Collins Startup list
  7886.  
  7887. [BMMLREF]
  7888. Number=1120
  7889. Confirmed=U
  7890. Filename=BMMLREF.EXE
  7891. Description=Battery Manager for IBM ThinkPad laptops
  7892. Source=Paul Collins Startup list
  7893.  
  7894. [BMMMONWND]
  7895. Number=1121
  7896. Confirmed=?
  7897. Filename=rundll32.exe [path] BatInfEx.dll, BMMAutonomicMonitor
  7898. Description=IBM Thinkpad related. <font color="#FF0000">What does it do and is it required?</font>
  7899. Source=Paul Collins Startup list
  7900.  
  7901. [BMO MasterCard Wallet]
  7902. Number=1122
  7903. Confirmed=U
  7904. Filename=EWALLET.EXE
  7905. Description=The wallet conveniently stores billing, shipping and payment information on your PC
  7906. Source=Paul Collins Startup list
  7907.  
  7908. [BMupdate]
  7909. Number=1123
  7910. Confirmed=N
  7911. Filename=BMupdate.exe
  7912. Description=Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install
  7913. Source=Paul Collins Startup list
  7914.  
  7915. [BMZ]
  7916. Number=1124
  7917. Confirmed=X
  7918. Filename=bmz.exe
  7919. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=180solutions.NCase&threatid=8869" target=_blank>NCase</a> adware
  7920. Source=Paul Collins Startup list
  7921.  
  7922. [Bndt32]
  7923. Number=1125
  7924. Confirmed=X
  7925. Filename=Bndt32.exe
  7926. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082915-4622-99" target="_blank">LACON</a> WORM!
  7927. Source=Paul Collins Startup list
  7928.  
  7929. [Bnexe]
  7930. Number=1126
  7931. Confirmed=X
  7932. Filename=[random filename]
  7933. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-070414-5310-99" target="_blank"> KITRO.D</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_ARGEN.A&VSect=T" target="_blank">ARGEN.A</a>) WORM!
  7934. Source=Paul Collins Startup list
  7935.  
  7936. [BO1HelperStartUp]
  7937. Number=1127
  7938. Confirmed=U
  7939. Filename=BO1HEL~1.EXE
  7940. Description=ScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.GAIN.CommonElements&threatid=5605" target="_blank">GAIN</a> branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  7941. Source=Paul Collins Startup list
  7942.  
  7943. [BO1HelperStartUp]
  7944. Number=1128
  7945. Confirmed=U
  7946. Filename=Bo1helper.exe
  7947. Description=ScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.GAIN.CommonElements&threatid=5605" target="_blank">GAIN</a> branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  7948. Source=Paul Collins Startup list
  7949.  
  7950. [Boarddata]
  7951. Number=1129
  7952. Confirmed=X
  7953. Filename=[path] repcale.exe [path] palsp.exe
  7954. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDON.AN" target="_blank">RANDON.AN</a> WORM!
  7955. Source=Paul Collins Startup list
  7956.  
  7957. [boby]
  7958. Number=1130
  7959. Confirmed=X
  7960. Filename=csrs.scr
  7961. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanpc.html" target="_blank">BANCBAN-PC</a> TROJAN!
  7962. Source=Paul Collins Startup list
  7963.  
  7964. [BOC412]
  7965. Number=1131
  7966. Confirmed=Y
  7967. Filename=BOC412.exe
  7968. Description=Version 4.12 of NSClean's <a href="http://www.nsclean.com/boclean.html" target=_blank>BOClean</a> anti-trojan software
  7969. Source=Paul Collins Startup list
  7970.  
  7971. [BOCleanautostart]
  7972. Number=1132
  7973. Confirmed=Y
  7974. Filename=Boclean.exe
  7975. Description=NSClean's <a href="http://www.nsclean.com/boclean.html" target="_blank">BOClean</a> anti-trojan software
  7976. Source=Paul Collins Startup list
  7977.  
  7978. [BOINC Manager]
  7979. Number=1133
  7980. Confirmed=U
  7981. Filename=boincmgr.exe
  7982. Description=<a href="http://boinc.berkeley.edu/manager.php" target="_blank">BOINC manager</a> - "controls the use of your computer's disk, network, and processor resources"
  7983. Source=Paul Collins Startup list
  7984.  
  7985. [Boingo Wireless Utility]
  7986. Number=1134
  7987. Confirmed=U
  7988. Filename=Icon###XXX#X#.exe
  7989. Description=Starts the Boingo Wireless utility, used to detect and login into <a href="http://www.boingo.com/" target=blank>Boingo</a> wireless hotspots. The filename may be autogenerated when installing, two different variations along the lines listed here, where # is a number and X is a letter. Shortcut available via Start -> Programs
  7990. Source=Paul Collins Startup list
  7991.  
  7992. [boler.exe]
  7993. Number=1135
  7994. Confirmed=X
  7995. Filename=syser.exe
  7996. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotays.html" target=_blank>RBOT-AYS</a> WORM!
  7997. Source=Paul Collins Startup list
  7998.  
  7999. [bombshel]
  8000. Number=1136
  8001. Confirmed=U
  8002. Filename=BOMB32.EXE
  8003. Description=Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
  8004. Source=Paul Collins Startup list
  8005.  
  8006. [Bonzi Buddy]
  8007. Number=1137
  8008. Confirmed=X
  8009. Filename=??
  8010. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=59256" target="_blank">Bonzi Buddy</a> adware - see <a href="http://www.pchell.com/support/bonzibuddy.shtml" target="_blank">here</a> for removal instructions
  8011. Source=Paul Collins Startup list
  8012.  
  8013. [boo]
  8014. Number=1138
  8015. Confirmed=X
  8016. Filename=boo.exe
  8017. Description=Adware downloader - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as the FAVADD.O TROJAN!
  8018. Source=Paul Collins Startup list
  8019.  
  8020. [BookedSpace]
  8021. Number=1139
  8022. Confirmed=X
  8023. Filename=RunDLL32.EXE [path] bs2.dll, DllRun
  8024. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  8025. Source=Paul Collins Startup list
  8026.  
  8027. [BookmarkCentral]
  8028. Number=1140
  8029. Confirmed=N
  8030. Filename=BMLauncher.exe
  8031. Description=<a href="http://www.bookmarkexpress.com/" target="_blank">Bookmark Express</a> - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use"
  8032. Source=Paul Collins Startup list
  8033.  
  8034. [BookMarkSink]
  8035. Number=1141
  8036. Confirmed=N
  8037. Filename=syncit.exe
  8038. Description=Bookmark synchronization utility
  8039. Source=Paul Collins Startup list
  8040.  
  8041. [BookMarkSync]
  8042. Number=1142
  8043. Confirmed=N
  8044. Filename=syncit.exe
  8045. Description=<a href="http://www.sync2it.com/" target=_blank>Sync2IT BookMarkSync</a> - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing
  8046. Source=Paul Collins Startup list
  8047.  
  8048. [BookMarkSync2It]
  8049. Number=1143
  8050. Confirmed=N
  8051. Filename=sync2it.exe
  8052. Description=<a href="http://www.sync2it.com/" target=_blank>Sync2IT BookMarkSync</a> - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing
  8053. Source=Paul Collins Startup list
  8054.  
  8055. [Boost XP Service]
  8056. Number=1144
  8057. Confirmed=U
  8058. Filename=bxservice.exe
  8059. Description=<a href="http://www.systweak.com/boostxp/" target="_blank">Boost XP</a> from Systweak - WinXP tweaking utility
  8060. Source=Paul Collins Startup list
  8061.  
  8062. [boot]
  8063. Number=1145
  8064. Confirmed=X
  8065. Filename=boot.exe
  8066. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpuppeta.html" target=_blank>PUPPET-A</a> TROJAN! Located in the System (9x/Me) or System32 (NT/2K/XP) folder
  8067. Source=Paul Collins Startup list
  8068.  
  8069. [Boot]
  8070. Number=1146
  8071. Confirmed=U
  8072. Filename=Boot.exe
  8073. Description=Part of Acer Empowering Technology. "<a href="http://www.acer-euro.com/et/en/notebooks01.htm#7" target="_blank">Acer ePower Management</a> is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles". Located in the "Acer\Empowering Technology\ePower" directory
  8074. Source=Paul Collins Startup list
  8075.  
  8076. [Boot Check]
  8077. Number=1147
  8078. Confirmed=X
  8079. Filename=bootchk.exe
  8080. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotab.html" target="_blank">DELBOT-AB</a> WORM!
  8081. Source=Paul Collins Startup list
  8082.  
  8083. [Boot Manager]
  8084. Number=1148
  8085. Confirmed=X
  8086. Filename=Njgal.exe
  8087. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-021319-1815-99" target="_blank">KILO</a> TROJAN!
  8088. Source=Paul Collins Startup list
  8089.  
  8090. [Boot Manager]
  8091. Number=1149
  8092. Confirmed=X
  8093. Filename=bootmng.exe
  8094. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-053013-5943-99" target="_blank">SPYBOT</a> WORM!
  8095. Source=Paul Collins Startup list
  8096.  
  8097. [BootCfg]
  8098. Number=1150
  8099. Confirmed=X
  8100. Filename=Install.log.vbs
  8101. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040911-2617-99" target=_blank>YPSAN.D</a> WORM!
  8102. Source=Paul Collins Startup list
  8103.  
  8104. [BootCTRL]
  8105. Number=1151
  8106. Confirmed=X
  8107. Filename=bootctrl.exe
  8108. Description=Added by an unidentified WORM or TROJAN!
  8109. Source=Paul Collins Startup list
  8110.  
  8111. [BootLoader]
  8112. Number=1152
  8113. Confirmed=X
  8114. Filename=BootLoader.exe.vbs
  8115. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020518-0826-99" target="_blank">WATERWORKS</a> WORM!
  8116. Source=Paul Collins Startup list
  8117.  
  8118. [bootpd.exe]
  8119. Number=1153
  8120. Confirmed=X
  8121. Filename=bootpd.exe
  8122. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentdt.html" target=_blank>AGENT-DT</a> TROJAN!
  8123. Source=Paul Collins Startup list
  8124.  
  8125. [BootsCfg]
  8126. Number=1154
  8127. Confirmed=X
  8128. Filename=Date.POP.vbs
  8129. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040417-1243-99" target=_blank>KUULLIO</a> WORM!
  8130. Source=Paul Collins Startup list
  8131.  
  8132. [BootsCfg]
  8133. Number=1155
  8134. Confirmed=X
  8135. Filename=wscript.exe [path] All Users.vbs
  8136. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050612-1340-99" target= blank>SPILTRON</a> WORM!
  8137. Source=Paul Collins Startup list
  8138.  
  8139. [BootsCfg]
  8140. Number=1156
  8141. Confirmed=X
  8142. Filename=wscript.exe [path] All Users.vbe
  8143. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050612-1340-99" target= blank>SPILTRON</a> WORM!
  8144. Source=Paul Collins Startup list
  8145.  
  8146. [BootsCfg]
  8147. Number=1157
  8148. Confirmed=X
  8149. Filename=wscript.exe [path] Install.log.vbs
  8150. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050715-3159-99" target= blank>YPSAN.E</a> WORM!
  8151. Source=Paul Collins Startup list
  8152.  
  8153. [BootStatus]
  8154. Number=1158
  8155. Confirmed=U
  8156. Filename=BOOTST~1.EXE
  8157. Description=Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day.  Once you exit it, it has no more effect on resources
  8158. Source=Paul Collins Startup list
  8159.  
  8160. [BootWarn]
  8161. Number=1159
  8162. Confirmed=U
  8163. Filename=BootWarn.exe
  8164. Description=From <a href="http://www.answersthatwork.com/Tasklist_pages/tasklist_b.htm" target=_blank>here</a>: "Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from "Start \ Programs \ Norton AntiVirus". If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab - it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages"
  8165. Source=Paul Collins Startup list
  8166.  
  8167. [boot_reg]
  8168. Number=1160
  8169. Confirmed=X
  8170. Filename=[path to file]
  8171. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanca.html" target=_blank>BANCBAN-CA</a> TROJAN!
  8172. Source=Paul Collins Startup list
  8173.  
  8174. [Bose Wave/PC Monitor]
  8175. Number=1161
  8176. Confirmed=N
  8177. Filename=wavepcmonitor.exe
  8178. Description=System Tray access for this system (more info on the system <a href="http://www.bose.com/controller?event=VIEW_PRODUCT_PAGE_EVENT&product=wave_subcategory" target="_blank">here</a>). Available via Start -> Programs
  8179. Source=Paul Collins Startup list
  8180.  
  8181. [BossIdea]
  8182. Number=1162
  8183. Confirmed=X
  8184. Filename=winlogin.exe
  8185. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlineagei.html" target= blank>LINEAGE-I</a> TROJAN!
  8186. Source=Paul Collins Startup list
  8187.  
  8188. [Boston]
  8189. Number=1163
  8190. Confirmed=?
  8191. Filename=Boston.exe
  8192. Description=Part of the Boston Acoustics USB speaker systems. <font color="#FF0000">What does it do and is it required?</font>
  8193. Source=Paul Collins Startup list
  8194.  
  8195. [Bot Loader]
  8196. Number=1164
  8197. Confirmed=X
  8198. Filename=svchostt.exe
  8199. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-052511-0816-99" target=_blank>GAOBOT.ALV</a> WORM!
  8200. Source=Paul Collins Startup list
  8201.  
  8202. [Bouncer RunStartup]
  8203. Number=1165
  8204. Confirmed=X
  8205. Filename=bouncer.exe
  8206. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Virtual%20Bouncer&threatid=12432" target="_blank">Virtual Bouncer</a> - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see <a href="http://groups.google.com/group/alt.sports.hockey.nhl.vanc-canucks/msg/dec91d1aa1e0d9dd?hl=en&lr=&ie=UTF-8&oe=UTF-8" target="_blank">here</a>
  8207. Source=Paul Collins Startup list
  8208.  
  8209. [Bouncer RunStartup]
  8210. Number=1166
  8211. Confirmed=X
  8212. Filename=LiveUpdate.exe
  8213. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Virtual%20Bouncer&threatid=12432" target="_blank">Virtual Bouncer</a> - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see <a href="http://groups.google.com/group/alt.sports.hockey.nhl.vanc-canucks/msg/dec91d1aa1e0d9dd?hl=en&lr=&ie=UTF-8&oe=UTF-8" target="_blank">here</a>
  8214. Source=Paul Collins Startup list
  8215.  
  8216. [boy lovers of bsd]
  8217. Number=1167
  8218. Confirmed=X
  8219. Filename=ilikeboys.exe
  8220. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.LY&VSect=P" target=_blank>MYTOB.LY</a> WORM!
  8221. Source=Paul Collins Startup list
  8222.  
  8223. [bpcpost.exe]
  8224. Number=1168
  8225. Confirmed=U
  8226. Filename=bpcpost.exe
  8227. Description=MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
  8228. Source=Paul Collins Startup list
  8229.  
  8230. [BPCv2 re]
  8231. Number=1169
  8232. Confirmed=X
  8233. Filename=bpc2 re inst.exe
  8234. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  8235. Source=Paul Collins Startup list
  8236.  
  8237. [BPK]
  8238. Number=1170
  8239. Confirmed=U
  8240. Filename=bpk.exe
  8241. Description=Blazing Tools <a href="http://www.blazingtools.com/bpk.html" target=_blank>Perfect Keylogger</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  8242.  
  8243. Source=Paul Collins Startup list
  8244.  
  8245. [BPServer]
  8246. Number=1171
  8247. Confirmed=N
  8248. Filename=G6FTPSrv.exe
  8249. Description=<a href="http://www.bpftpserver.com/?page=home&lang=en" target="_blank">BulletProof FTP Server</a>
  8250. Source=Paul Collins Startup list
  8251.  
  8252. [BQTray.exe]
  8253. Number=1172
  8254. Confirmed=U
  8255. Filename=BQTray.exe
  8256. Description=System Tray access to <a href="http://www.burnquick.com/" target="_blank"> BurnQuick</a> CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
  8257. Source=Paul Collins Startup list
  8258.  
  8259. [Brasil]
  8260. Number=1173
  8261. Confirmed=X
  8262. Filename=Brasil.exe
  8263. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.E" target="_blank">OPASERV.E</a> WORM!
  8264. Source=Paul Collins Startup list
  8265.  
  8266. [Brasil]
  8267. Number=1174
  8268. Confirmed=X
  8269. Filename=BRASIL.PIF
  8270. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.E" target="_blank">OPASERV.E</a> WORM!
  8271. Source=Paul Collins Startup list
  8272.  
  8273. [BrasilOld]
  8274. Number=1175
  8275. Confirmed=X
  8276. Filename=[worm filename]
  8277. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.P" target="_blank">OPASERV.P</a> WORM!
  8278. Source=Paul Collins Startup list
  8279.  
  8280. [BraveSentry]
  8281. Number=1176
  8282. Confirmed=N
  8283. Filename=BraveSentry.exe
  8284. Description=Spyware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  8285. Source=Paul Collins Startup list
  8286.  
  8287. [Brct]
  8288. Number=1177
  8289. Confirmed=X
  8290. Filename=trdb.exe
  8291. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as the PurityScan.y TROJAN!
  8292. Source=Paul Collins Startup list
  8293.  
  8294. [Break_Reminder]
  8295. Number=1178
  8296. Confirmed=U
  8297. Filename=BREAK REMINDER.exe
  8298. Description=Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See <a href="http://www.cheqsoft.com/break.html" target="_blank">here</a>
  8299. Source=Paul Collins Startup list
  8300.  
  8301. [Breg]
  8302. Number=1179
  8303. Confirmed=X
  8304. Filename=bcre.exe
  8305. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  8306. Source=Paul Collins Startup list
  8307.  
  8308. [Breg]
  8309. Number=1180
  8310. Confirmed=X
  8311. Filename=bptre.exe
  8312. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  8313. Source=Paul Collins Startup list
  8314.  
  8315. [Breg]
  8316. Number=1181
  8317. Confirmed=X
  8318. Filename=breg.exe
  8319. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  8320. Source=Paul Collins Startup list
  8321.  
  8322. [Bridge]
  8323. Number=1182
  8324. Confirmed=X
  8325. Filename=rundll32.exe ...Bridge.dll
  8326. Description=Flingstone.com browser hijacker
  8327. Source=Paul Collins Startup list
  8328.  
  8329. [Brindys BriTray]
  8330. Number=1183
  8331. Confirmed=Y
  8332. Filename=BRITRAY.EXE
  8333. Description=Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from <a href="http://www.brindys.com/" target="_blank">Brindys Software</a>). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired
  8334. Source=Paul Collins Startup list
  8335.  
  8336. [BrmfRmPA]
  8337. Number=1184
  8338. Confirmed=U
  8339. Filename=BrmfRmPA.exe
  8340. Description=Brother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
  8341. Source=Paul Collins Startup list
  8342.  
  8343. [Broadband Wizard]
  8344. Number=1185
  8345. Confirmed=N
  8346. Filename=bbwiz.exe
  8347. Description=Starts <a href="http://www.broadbandwizard.net/" target="_blank">Broadband Wizard</a> so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs
  8348. Source=Paul Collins Startup list
  8349.  
  8350. [Broadcom Wireless Manager UI]
  8351. Number=1186
  8352. Confirmed=U
  8353. Filename=bcmntray.exe
  8354. Description=Related to <a href="http://www.broadcom.com/" target=_blank>Broadcom</a> Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems
  8355. Source=Paul Collins Startup list
  8356.  
  8357. [Broadcom Wireless Manager UI]
  8358. Number=1187
  8359. Confirmed=N
  8360. Filename=wltray.exe
  8361. Description=System tray access to wireless LAN card configuration options
  8362.  
  8363. Source=Paul Collins Startup list
  8364.  
  8365. [Bron-Spizaetus]
  8366. Number=1188
  8367. Confirmed=X
  8368. Filename=CVT.exe
  8369. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-092311-2608-99" target=_blank>RONTOKBRO</a> WORM!
  8370. Source=Paul Collins Startup list
  8371.  
  8372. [Bron-Spizaetus]
  8373. Number=1189
  8374. Confirmed=X
  8375. Filename=norBtok.exe
  8376. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RONTOKBRO.B&VSect=P" target=_blank>RONTOKBRO.B</a> WORM!
  8377. Source=Paul Collins Startup list
  8378.  
  8379. [Bron-Spizaetus]
  8380. Number=1190
  8381. Confirmed=X
  8382. Filename=[path to file]
  8383. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontokf.html" target=_blank>BRONTOK-F</a> WORM!
  8384. Source=Paul Collins Startup list
  8385.  
  8386. [Bron-Spizaetus]
  8387. Number=1191
  8388. Confirmed=X
  8389. Filename=bronstab.exe
  8390. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RONTOKBRO.C&VSect=P" target=_blank>RONTOKBRO.C</a> WORM!
  8391. Source=Paul Collins Startup list
  8392.  
  8393. [Bron-Spizaetus]
  8394. Number=1192
  8395. Confirmed=X
  8396. Filename=eksplorasi.exe
  8397. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RONTOKBRO.J&VSect=P" target=_blank>RONTOKBRO.J</a> WORM!
  8398. Source=Paul Collins Startup list
  8399.  
  8400. [Bron-Spizaetus]
  8401. Number=1193
  8402. Confirmed=X
  8403. Filename=ElnorB.exe
  8404. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RONTOKBRO.D&VSect=P" target=_blank>RONTOKBRO.D</a> WORM!
  8405. Source=Paul Collins Startup list
  8406.  
  8407. [Bron-Spizaetus]
  8408. Number=1194
  8409. Confirmed=X
  8410. Filename=sempalong.exe
  8411. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontoke.html" target=_blank>BRONTOK-E</a> WORM!
  8412. Source=Paul Collins Startup list
  8413.  
  8414. [Bron-Spizaetus]
  8415. Number=1195
  8416. Confirmed=X
  8417. Filename=RakyatKelaparan.exe
  8418. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontokj.html" target=_blank>BRONTOK-J</a> or <a href="http://www.sophos.com/virusinfo/analyses/w32brontokl.html" target=_blank>BRONTOK-L</a> WORMS!
  8419. Source=Paul Collins Startup list
  8420.  
  8421. [Bron-Spizaetus-5118REPM]
  8422. Number=1196
  8423. Confirmed=X
  8424. Filename=komodo-6321422.exe
  8425. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontokr.html" target=_blank>BRONTOK-R</a> WORM!
  8426. Source=Paul Collins Startup list
  8427.  
  8428. [Bron-Spizaetus-cfgmktoq]
  8429. Number=1197
  8430. Confirmed=X
  8431. Filename=bbm-qotkmgfc.exe
  8432. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontokm.html" target=_blank>BRONTOK-M</a> WORM!
  8433. Source=Paul Collins Startup list
  8434.  
  8435. [Bron-Spizaetus-cfgmmnru]
  8436. Number=1198
  8437. Confirmed=X
  8438. Filename=bbm-urnmmgfc.exe
  8439. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontokn.html" target=_blank>BRONTOK-N</a> WORM!
  8440. Source=Paul Collins Startup list
  8441.  
  8442. [BrowseProxy]
  8443. Number=1199
  8444. Confirmed=X
  8445. Filename=FindService.exe
  8446. Description=Actual Names <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075255" target="_blank">(AdvSearch)</a> Internet Keywords parasite
  8447. Source=Paul Collins Startup list
  8448.  
  8449. [browser]
  8450. Number=1200
  8451. Confirmed=X
  8452. Filename=msgaol.exe
  8453. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  8454. Source=Paul Collins Startup list
  8455.  
  8456. [browser]
  8457. Number=1201
  8458. Confirmed=X
  8459. Filename=s_menu.exe
  8460. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  8461. Source=Paul Collins Startup list
  8462.  
  8463. [browser]
  8464. Number=1202
  8465. Confirmed=X
  8466. Filename=browse.exe
  8467. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  8468. Source=Paul Collins Startup list
  8469.  
  8470. [browser]
  8471. Number=1203
  8472. Confirmed=X
  8473. Filename=deamon.exe
  8474. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  8475. Source=Paul Collins Startup list
  8476.  
  8477. [browser]
  8478. Number=1204
  8479. Confirmed=X
  8480. Filename=msgaol.exe
  8481. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  8482. Source=Paul Collins Startup list
  8483.  
  8484. [browser aid]
  8485. Number=1205
  8486. Confirmed=X
  8487. Filename=browseraid.exe
  8488. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BrowserAid&threatid=3342" target="_blank">BrowserAid/BrowserPal</a> foistware
  8489. Source=Paul Collins Startup list
  8490.  
  8491. [Browser Help Svc]
  8492. Number=1206
  8493. Confirmed=X
  8494. Filename=BHSV.EXE
  8495. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotavq.html" target=_blank>RBOT-AVQ</a> WORM!
  8496. Source=Paul Collins Startup list
  8497.  
  8498. [Browser Hijack Blaster]
  8499. Number=1207
  8500. Confirmed=Y
  8501. Filename=bhblaster.exe
  8502. Description=Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by <a href="http://javacoolsoftware.com/spywareguard.html" target="_blank">SpywareGuard</a>
  8503. Source=Paul Collins Startup list
  8504.  
  8505. [Browser Launcher]
  8506. Number=1208
  8507. Confirmed=U
  8508. Filename=Commandr.exe
  8509. Description=Logitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
  8510. Source=Paul Collins Startup list
  8511.  
  8512. [Browser Pal]
  8513. Number=1209
  8514. Confirmed=X
  8515. Filename=adblck.exe
  8516. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BrowserAid&threatid=3342" target="_blank">BrowserAid/BrowserPal</a> foistware
  8517. Source=Paul Collins Startup list
  8518.  
  8519. [Browser Sentinel]
  8520. Number=1210
  8521. Confirmed=U
  8522. Filename=BrowserSentinel.exe
  8523. Description=<a href="http://www.browsersentinel.com/" target="_blank">Browser Sentinel</a> - notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page
  8524. Source=Paul Collins Startup list
  8525.  
  8526. [BrowserUpdateSched]
  8527. Number=1211
  8528. Confirmed=X
  8529. Filename=qwinnsap.exe
  8530. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094810" target="_blank">ZenoSearch</a> adware
  8531. Source=Paul Collins Startup list
  8532.  
  8533. [BrowserUpdateSched]
  8534. Number=1212
  8535. Confirmed=X
  8536. Filename=twinorag.exe
  8537. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094810" target="_blank">ZenoSearch</a> adware
  8538. Source=Paul Collins Startup list
  8539.  
  8540. [BrowserWebCheck]
  8541. Number=1213
  8542. Confirmed=N
  8543. Filename=loadwc.exe
  8544. Description=Checks to make sure that IE is still your default browser
  8545. Source=Paul Collins Startup list
  8546.  
  8547. [brwdiag]
  8548. Number=1214
  8549. Confirmed=X
  8550. Filename=[path to worm]
  8551. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32stratiobn.html" target="_blank">STRATIO-BN</a> WORM!
  8552. Source=Paul Collins Startup list
  8553.  
  8554. [BS Player]
  8555. Number=1215
  8556. Confirmed=N
  8557. Filename=bsplayer.exe
  8558. Description=<a href="http://www.bsplayer.org/" target= blank>BSplayer</a> - A video player used to play avi, mpg, wmv and other multimedia files
  8559. Source=Paul Collins Startup list
  8560.  
  8561. [BsCLiP]
  8562. Number=1216
  8563. Confirmed=N
  8564. Filename=BSCLIP.exe
  8565. Description=CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
  8566. Source=Paul Collins Startup list
  8567.  
  8568. [Bsoft lppt01]
  8569. Number=1217
  8570. Confirmed=X
  8571. Filename=Bsoft.exe
  8572. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "BelmontSoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  8573. Source=Paul Collins Startup list
  8574.  
  8575. [bsplayer]
  8576. Number=1218
  8577. Confirmed=N
  8578. Filename=bsplayer.exe
  8579. Description=<a href="http://www.bsplayer.org/" target=_blank>BSplayer</a> - a video player used to play avi, mpg, wmv and other multimedia files
  8580. Source=Paul Collins Startup list
  8581.  
  8582. [BSserver]
  8583. Number=1219
  8584. Confirmed=X
  8585. Filename=FileKan.exe
  8586. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_VB.CBW" target="_blank">VB.CBW</a> WORM!
  8587. Source=Paul Collins Startup list
  8588.  
  8589. [BSVCHOST]
  8590. Number=1220
  8591. Confirmed=X
  8592. Filename=SVCH0ST.EXE
  8593. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-052311-1341-99" target="_blank">VOXOM</a> TROJAN!
  8594. Source=Paul Collins Startup list
  8595.  
  8596. [Bsx3]
  8597. Number=1221
  8598. Confirmed=X
  8599. Filename=RunDLL32.EXE [path] bs3.dll, DllRun
  8600. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  8601. Source=Paul Collins Startup list
  8602.  
  8603. [BT]
  8604. Number=1222
  8605. Confirmed=X
  8606. Filename=[path to trojan]
  8607. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlitebotb.html" target=_blank>LITEBOT-B</a> TROJAN!
  8608. Source=Paul Collins Startup list
  8609.  
  8610. [BT Broadband Help]
  8611. Number=1223
  8612. Confirmed=U
  8613. Filename=matcli.exe
  8614. Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide
  8615. Source=Paul Collins Startup list
  8616.  
  8617. [BT00003*]
  8618. Number=1224
  8619. Confirmed=X
  8620. Filename=abcdefg23.exe
  8621. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvbvt.html" target=_blank>VB-VT</a> TROJAN where * = 5,6 or 7!
  8622. Source=Paul Collins Startup list
  8623.  
  8624. [BT00003*]
  8625. Number=1225
  8626. Confirmed=X
  8627. Filename=hiklmnop27.exe
  8628. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvbvt.html" target=_blank>VB-VT</a> TROJAN where * = 2,3 or 4!
  8629. Source=Paul Collins Startup list
  8630.  
  8631. [btbb_wcm_McciTrayApp]
  8632. Number=1226
  8633. Confirmed=U
  8634. Filename=McciTrayApp.exe
  8635. Description=System tray access to <a href="http://www.motive.com/" target="_blank">Motive's</a> Broadband 2.0 configuration and repair utility
  8636. Source=Paul Collins Startup list
  8637.  
  8638. [btinst]
  8639. Number=1227
  8640. Confirmed=?
  8641. Filename=btinst.exe
  8642. Description=Associated with an Anycom bluetooth wireless card. <font color="#FF0000">What does it do and is it required?</font>
  8643. Source=Paul Collins Startup list
  8644.  
  8645. [BTModemProtection]
  8646. Number=1228
  8647. Confirmed=U
  8648. Filename=BTModemProtection.exe
  8649. Description=BT Privacy Online modem protection software, see <a href="http://www.btmodemprotection.com/" target=_blank>here</a>
  8650. Source=Paul Collins Startup list
  8651.  
  8652. [BTopenworld]
  8653. Number=1229
  8654. Confirmed=U
  8655. Filename=DialBTYahoo.exe
  8656. Description=BT Yahoo! internet connection manager
  8657.  
  8658. Source=Paul Collins Startup list
  8659.  
  8660. [BTSETBOOTKEY]
  8661. Number=1230
  8662. Confirmed=?
  8663. Filename=BTSetBootKey.exe
  8664. Description=Related to a USB Bluetooth adaptor. <font color="#FF0000">What does it do and is it required?</font>
  8665. Source=Paul Collins Startup list
  8666.  
  8667. [BtStart]
  8668. Number=1231
  8669. Confirmed=U
  8670. Filename=btstart.exe
  8671. Description=<a href="http://www.broadcom.com/products/Bluetooth?source=top" target="_blank">Broadcom</a> (formerly WIDCOMM) Bluetooth Connectivity Software
  8672. Source=Paul Collins Startup list
  8673.  
  8674. [bttray]
  8675. Number=1232
  8676. Confirmed=U
  8677. Filename=bttray.exe
  8678. Description=System tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device
  8679. Source=Paul Collins Startup list
  8680.  
  8681. [BTUSRBDG]
  8682. Number=1233
  8683. Confirmed=Y
  8684. Filename=BtUsrBdg.exe
  8685. Description=Used with a <a href="http://www.mitsumi.de/index4.html" target="_blank">Mitsumi USB Bluetooth</a> adaptor (and maybe others)
  8686. Source=Paul Collins Startup list
  8687.  
  8688. [BTUSRBDGF]
  8689. Number=1234
  8690. Confirmed=Y
  8691. Filename=BtUsrBdg.exe
  8692. Description=Used with a <a href="http://www.mitsumi.de/index4.html" target="_blank">Mitsumi USB Bluetooth</a> adaptor (and maybe others)
  8693. Source=Paul Collins Startup list
  8694.  
  8695. [BTV]
  8696. Number=1235
  8697. Confirmed=X
  8698. Filename=btv.exe
  8699. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080114-4631-99" target="_blank">BroadcastPC</a> adware variant
  8700. Source=Paul Collins Startup list
  8701.  
  8702. [Buddyizer]
  8703. Number=1236
  8704. Confirmed=N
  8705. Filename=Buddyizer.exe
  8706. Description=Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
  8707. Source=Paul Collins Startup list
  8708.  
  8709. [BUFFALO Power Save Utility for HD]
  8710. Number=1237
  8711. Confirmed=U
  8712. Filename=HDManage.exe
  8713. Description=Power Save utility for <a href="http://www.buffalotech.com/buffalo-home.php" target="_blank">Buffalo</a> backup hard discs
  8714. Source=Paul Collins Startup list
  8715.  
  8716. [bugwatcher service]
  8717. Number=1238
  8718. Confirmed=U
  8719. Filename=bugwatcher.exe
  8720. Description=<a href="http://www.pcworld.com/downloads/file_description/0,fid,17260,00.asp" target="_blank">Bugtoaster</a> is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures
  8721. Source=Paul Collins Startup list
  8722.  
  8723. [BuildBU]
  8724. Number=1239
  8725. Confirmed=N
  8726. Filename=bldbubg.exe
  8727. Description=Part of Dell Alerts which provides customers with an update on latest updates for his/her system
  8728. Source=Paul Collins Startup list
  8729.  
  8730. [BuildLab]
  8731. Number=1240
  8732. Confirmed=X
  8733. Filename=services.exe
  8734. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081700-2526-99" target="_blank">NEVEG.B</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081614-3605-99" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
  8735. Source=Paul Collins Startup list
  8736.  
  8737. [BuildLab]
  8738. Number=1241
  8739. Confirmed=X
  8740. Filename=winlogon.exe
  8741. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081623-4258-99" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
  8742. Source=Paul Collins Startup list
  8743.  
  8744. [BuildLabs]
  8745. Number=1242
  8746. Confirmed=X
  8747. Filename=csrss.exe
  8748. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091409-4900-99" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  8749. Source=Paul Collins Startup list
  8750.  
  8751. [BuildLabs]
  8752. Number=1243
  8753. Confirmed=X
  8754. Filename=lsass.exe
  8755. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100519-0947-99" target="_blank">WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lsass.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
  8756. Source=Paul Collins Startup list
  8757.  
  8758. [Bulldog Service]
  8759. Number=1244
  8760. Confirmed=U
  8761. Filename=upsd.exe
  8762. Description=Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
  8763. Source=Paul Collins Startup list
  8764.  
  8765. [BulletProof FTP Server]
  8766. Number=1245
  8767. Confirmed=N
  8768. Filename=bpftpserver.exe
  8769. Description=<a href="http://www.bpftpserver.com/?page=home&lang=en" target="_blank">BulletProof FTP Server</a>
  8770. Source=Paul Collins Startup list
  8771.  
  8772. [BullGuard]
  8773. Number=1246
  8774. Confirmed=Y
  8775. Filename=mgui.exe
  8776. Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
  8777. Source=Paul Collins Startup list
  8778.  
  8779. [BullGuard]
  8780. Number=1247
  8781. Confirmed=Y
  8782. Filename=BullGuard.exe
  8783. Description=Part of <a href="http://www.bullguard.com/" target="_blank">BullGuard</a> antivirus
  8784. Source=Paul Collins Startup list
  8785.  
  8786. [BullGuard Update]
  8787. Number=1248
  8788. Confirmed=U
  8789. Filename=avxlive.exe
  8790. Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus. Leave enabled unless you manually update virus definitions
  8791. Source=Paul Collins Startup list
  8792.  
  8793. [BullGuard XComm]
  8794. Number=1249
  8795. Confirmed=Y
  8796. Filename=XCOMMSVR.EXE
  8797. Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
  8798. Source=Paul Collins Startup list
  8799.  
  8800. [BullGuardInit]
  8801. Number=1250
  8802. Confirmed=Y
  8803. Filename=AVXINIT.EXE
  8804. Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
  8805. Source=Paul Collins Startup list
  8806.  
  8807. [BullguardoptIn]
  8808. Number=1251
  8809. Confirmed=Y
  8810. Filename=bulldownload.exe
  8811. Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
  8812. Source=Paul Collins Startup list
  8813.  
  8814. [BullsEye]
  8815. Number=1252
  8816. Confirmed=X
  8817. Filename=bargains.exe
  8818. Description=<a href="http://sarc.com/avcenter/venc/data/adware.bargainbuddy.html" target="_blank">BargainBuddy</a> adware
  8819. Source=Paul Collins Startup list
  8820.  
  8821. [BullsEye Network]
  8822. Number=1253
  8823. Confirmed=X
  8824. Filename=bargains.exe
  8825. Description=<a href="http://sarc.com/avcenter/venc/data/adware.bargainbuddy.html" target="_blank">BargainBuddy</a> adware
  8826. Source=Paul Collins Startup list
  8827.  
  8828. [BullsEye Tracker]
  8829. Number=1254
  8830. Confirmed=?
  8831. Filename=BeTrack.exe
  8832. Description=Bullseye - intelligent research assistant
  8833. Source=Paul Collins Startup list
  8834.  
  8835. [Bunx]
  8836. Number=1255
  8837. Confirmed=X
  8838. Filename=beagle.exe
  8839. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32lebreate.html" target=_blank>LEBREAT-E</a> WORM!
  8840. Source=Paul Collins Startup list
  8841.  
  8842. [BurnQuick Queue]
  8843. Number=1256
  8844. Confirmed=N
  8845. Filename=BQTray.exe
  8846. Description=System Tray access to <a href="http://www.burnquick.com/" target="_blank">BurnQuick</a> CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
  8847. Source=Paul Collins Startup list
  8848.  
  8849. [Button Server]
  8850. Number=1257
  8851. Confirmed=U
  8852. Filename=bttnserv.exe
  8853. Description=Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required
  8854. Source=Paul Collins Startup list
  8855.  
  8856. [ButtonKey]
  8857. Number=1258
  8858. Confirmed=N
  8859. Filename=ButtonKey.exe
  8860. Description=CyberView TWAIN driver for the <a href="http://www.scanace.com/en/product/product.php" target="_blank">Pacific Image</a> range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut
  8861. Source=Paul Collins Startup list
  8862.  
  8863. [Buzme]
  8864. Number=1259
  8865. Confirmed=N
  8866. Filename=Bmui.exe
  8867. Description=<a href="http://www.buzme.com/buzme/default.asp" target="_blank">Buzme</a> by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
  8868. Source=Paul Collins Startup list
  8869.  
  8870. [BuzMe]
  8871. Number=1260
  8872. Confirmed=U
  8873. Filename=RCUI.exe
  8874. Description=Display Client for the <a href="http://www.buzme.com/" target="_blank">BuzMe</a> Internet Call Waiting Service
  8875. Source=Paul Collins Startup list
  8876.  
  8877. [Buzof.exe]
  8878. Number=1261
  8879. Confirmed=U
  8880. Filename=buzof.exe
  8881. Description=<a href="http://www.basta.com/ProdBuzof.htm" target="_blank">Buzof</a> from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes"
  8882. Source=Paul Collins Startup list
  8883.  
  8884. [bxproxy]
  8885. Number=1262
  8886. Confirmed=X
  8887. Filename=bxproxy.exe
  8888. Description=Added by the <a href="http://www.superadblocker.com/definition/bxproxy/" target=_blank>BXPROXY</a> TROJAN!
  8889. Source=Paul Collins Startup list
  8890.  
  8891. [bxsx5]
  8892. Number=1263
  8893. Confirmed=X
  8894. Filename=RunDLL32.EXE [path] bsx5.dll, DllRun
  8895. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  8896. Source=Paul Collins Startup list
  8897.  
  8898. [bxxs5]
  8899. Number=1264
  8900. Confirmed=X
  8901. Filename=RunDLL32.EXE [path] bxxs5.dll, dllrun
  8902. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  8903. Source=Paul Collins Startup list
  8904.  
  8905. [Bymer.Scanner]
  8906. Number=1265
  8907. Confirmed=X
  8908. Filename=Wininit.exe
  8909. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2000-122012-3537-99" target="_blank">BYMER</a> WORM!
  8910. Source=Paul Collins Startup list
  8911.  
  8912. [Bymer.Scanner]
  8913. Number=1266
  8914. Confirmed=X
  8915. Filename=Msinit.exe
  8916. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2000-122012-3537-99" target="_blank">BYMER</a> WORM!
  8917. Source=Paul Collins Startup list
  8918.  
  8919. [c]
  8920. Number=1267
  8921. Confirmed=X
  8922. Filename=c:\archiv~1\win.com
  8923. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-100907-5516-99" target="_blank">CUYDOC</a> TROJAN!
  8924. Source=Paul Collins Startup list
  8925.  
  8926. [C-Media Echo Control]
  8927. Number=1268
  8928. Confirmed=U
  8929. Filename=EchoCtrl.exe
  8930. Description=C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
  8931.  
  8932. Source=Paul Collins Startup list
  8933.  
  8934. [C-Media Mixer]
  8935. Number=1269
  8936. Confirmed=N
  8937. Filename=Mixer.exe
  8938. Description=C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
  8939. Source=Paul Collins Startup list
  8940.  
  8941. [C2K]
  8942. Number=1270
  8943. Confirmed=U
  8944. Filename=CYB2K.EXE
  8945. Description=CYBERsitter 2000 or 2001 - anti-adult content filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
  8946. Source=Paul Collins Startup list
  8947.  
  8948. [c32cs2]
  8949. Number=1271
  8950. Confirmed=U
  8951. Filename=c32cs2.exe
  8952. Description=<a href="http://www.securitysoft.com/myspace_filtering.asp?pageid=82" target="_blank">Cyber Sentinel</a> - internet filtering software
  8953. Source=Paul Collins Startup list
  8954.  
  8955. [C7]
  8956. Number=1272
  8957. Confirmed=X
  8958. Filename=[path to worm]
  8959. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051016-4401-99" target= blank>MEDIAKILL.A</a> WORM!
  8960. Source=Paul Collins Startup list
  8961.  
  8962. [C:\WINDOWS\IEXPLOR.EXE]
  8963. Number=1273
  8964. Confirmed=X
  8965. Filename=IEXPLOR.EXE
  8966. Description="Pop Marketing" adware
  8967. Source=Paul Collins Startup list
  8968.  
  8969. [C:\WINDOWS\WinTask.exe]
  8970. Number=1274
  8971. Confirmed=X
  8972. Filename=WinTask.exe
  8973. Description="Pop Marketing" adware
  8974. Source=Paul Collins Startup list
  8975.  
  8976. [CA-AMAgent]
  8977. Number=1275
  8978. Confirmed=U
  8979. Filename=amagent.exe
  8980. Description=<a href="http://www3.ca.com/Solutions/Product.asp?ID=194" target=_blank>Unicenter Asset Management</a> is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting
  8981. Source=Paul Collins Startup list
  8982.  
  8983. [CaAvTray]
  8984. Number=1276
  8985. Confirmed=Y
  8986. Filename=CAVTray.exe
  8987. Description=eTrustÖ <a href="http://home.ca.com/dr/sat5/ec_Main.Entry17c?SID=35715&SP=10023&PN=1&PID=671589&V1=671589&CID=179788&api1=78&api2=1&api3=&DSP=&CUR=840&PGRP=0&CACHE_ID=179788" target=_blank>EZ Antivirus</a> system tray application from Computer Associates
  8988. Source=Paul Collins Startup list
  8989.  
  8990. [Cabchk]
  8991. Number=1277
  8992. Confirmed=X
  8993. Filename=Cabchk.exe
  8994. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  8995. Source=Paul Collins Startup list
  8996.  
  8997. [Cabchk32]
  8998. Number=1278
  8999. Confirmed=X
  9000. Filename=Cabchk32.exe
  9001. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  9002. Source=Paul Collins Startup list
  9003.  
  9004. [CABCInstall]
  9005. Number=1279
  9006. Confirmed=X
  9007. Filename=CABCInstall.exe
  9008. Description=<a href="http://www.ignitetech.com/" target="_blank">Ignite Technologies</a> (was CABC) content delivery software
  9009. Source=Paul Collins Startup list
  9010.  
  9011. [CacheBoost]
  9012. Number=1280
  9013. Confirmed=U
  9014. Filename=trayicon.exe
  9015. Description=<a href="http://www.systweak.com/cacheboost/" target="_blank">CacheBoost</a> "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost"
  9016. Source=Paul Collins Startup list
  9017.  
  9018. [CacheLoader]
  9019. Number=1281
  9020. Confirmed=X
  9021. Filename=[path to trojan]
  9022. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadernz.html" target=_blank>DLOADER-NZ</a> TROJAN!
  9023. Source=Paul Collins Startup list
  9024.  
  9025. [Cacheman]
  9026. Number=1282
  9027. Confirmed=N
  9028. Filename=Cacheman.exe
  9029. Description=Freeware disk cache tweaker from <a href="http://www.outertech.com/">Outer Technologies</a>. Should only be run once and not loaded at start-up
  9030. Source=Paul Collins Startup list
  9031.  
  9032. [CacheMgr]
  9033. Number=1283
  9034. Confirmed=Y
  9035. Filename=CacheMgr.exe
  9036. Description=<a href="http://www.sophos.com/products/es/endpoint/sav-windows.html" target="_blank">Sophos Antivirus</a> Remote Update
  9037. Source=Paul Collins Startup list
  9038.  
  9039. [CacheSentry Pro]
  9040. Number=1284
  9041. Confirmed=U
  9042. Filename=CacheSentry Pro.exe
  9043. Description="<a href="http://www.enigmaticsoftware.com/cachesentry_pro/index.html" target="_blank">CacheSentry Pro</a> is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"
  9044. Source=Paul Collins Startup list
  9045.  
  9046. [CacheSentry Pro]
  9047. Number=1285
  9048. Confirmed=U
  9049. Filename=CacheSentry Pro.exe
  9050. Description="<a href="http://www.enigmaticsoftware.com/cachesentry_pro/index.html" target="_blank">CacheSentry Pro</a> is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"
  9051. Source=Paul Collins Startup list
  9052.  
  9053. [CACStarter]
  9054. Number=1286
  9055. Confirmed=N
  9056. Filename=cacstart.exe
  9057. Description=Cash A Check - check writing software
  9058. Source=Paul Collins Startup list
  9059.  
  9060. [Caddais BackupOnDemand]
  9061. Number=1287
  9062. Confirmed=U
  9063. Filename=BODMon.exe
  9064. Description=<a href="http://www.caddais.com/BackupOnDemand.shtml" target="_blank">Caddais BackupOnDemand</a> - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location"
  9065. Source=Paul Collins Startup list
  9066.  
  9067. [Cadenza]
  9068. Number=1288
  9069. Confirmed=U
  9070. Filename=CdzSvc.exe
  9071. Description=Cadenza <a href="http://www.sofotex.com/Cadenza-mNotes-Pocket-PC-download_L8061.html" target=_blank>mNotes</a> for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices
  9072. Source=Paul Collins Startup list
  9073.  
  9074. [CADS]
  9075. Number=1289
  9076. Confirmed=U
  9077. Filename=cads.exe
  9078. Description=<a href="http://www.securitysoft.com/myspace_filtering.asp?pageid=82" target="_blank">Cyber Sentinel</a> - internet filtering software
  9079. Source=Paul Collins Startup list
  9080.  
  9081. [CafeStation]
  9082. Number=1290
  9083. Confirmed=U
  9084. Filename=CafeStation.exe
  9085. Description="<a href="http://cafesuite.net/" target=_blank>CafeSuite</a> is the solution for your internet cafe. Our software provides you with ameans to control the workstations, manage customer database, sell products and generate detailed reports and statistics"
  9086.  
  9087. Source=Paul Collins Startup list
  9088.  
  9089. [CAgent]
  9090. Number=1291
  9091. Confirmed=N
  9092. Filename=CAgent.exe
  9093. Description=<a href="http://www.fine-reader.com/" target="_blank">Abbyy Fine Reader</a> OCR (Optical Character Recognition) software for scanning and converting documents
  9094. Source=Paul Collins Startup list
  9095.  
  9096. [cAgOu]
  9097. Number=1292
  9098. Confirmed=X
  9099. Filename=[filename].hta
  9100. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2000-121908-3951-99" target="_blank">KAKWORM</a> WORM!
  9101. Source=Paul Collins Startup list
  9102.  
  9103. [CahootWebcard]
  9104. Number=1293
  9105. Confirmed=N
  9106. Filename=CahootWebcard.exe
  9107. Description="The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when needed
  9108. Source=Paul Collins Startup list
  9109.  
  9110. [caidiysetup]
  9111. Number=1294
  9112. Confirmed=X
  9113. Filename=diynetsetupuni.exe
  9114. Description=<a href="http://www.sophos.com/virusinfo/analyses/diynet.html" target="_blank">DIYNet</a> adware
  9115. Source=Paul Collins Startup list
  9116.  
  9117. [CAISafe]
  9118. Number=1295
  9119. Confirmed=Y
  9120. Filename=isafe.exe
  9121. Description=Part of Computer Associates <a href="http://www1.my-etrust.com/products/Antivirus.cfm?" target="_blank">eTrust EZ Antivirus</a>
  9122. Source=Paul Collins Startup list
  9123.  
  9124. [CaISSDT]
  9125. Number=1296
  9126. Confirmed=U
  9127. Filename=caissdt.exe
  9128. Description=<a href="http://www.ca.com/" target=_blank>Computer Associates</a> Dashboard Tray applet
  9129.  
  9130. Source=Paul Collins Startup list
  9131.  
  9132. [Cal Reminder Shortcut]
  9133. Number=1297
  9134. Confirmed=N
  9135. Filename=calrem.exe
  9136. Description=Produces a pop-up reminder of events scheduled using the MS Office Calendar
  9137. Source=Paul Collins Startup list
  9138.  
  9139. [Calc Microsoft Windows]
  9140. Number=1298
  9141. Confirmed=X
  9142. Filename=wincalc.exe
  9143. Description=Added by an unidentied WORM or TROJAN!
  9144. Source=Paul Collins Startup list
  9145.  
  9146. [CALC32]
  9147. Number=1299
  9148. Confirmed=X
  9149. Filename=CALC32.EXE
  9150. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotec.html" target=_blank>SPYBOT-EC</a> WORM!
  9151. Source=Paul Collins Startup list
  9152.  
  9153. [Calendar 200X Reminder]
  9154. Number=1300
  9155. Confirmed=N
  9156. Filename=calendar.exe
  9157. Description=<a href="http://www.jgraff.addr.com/cal.htm" target="_blank">Calendar 200X</a> - shows holidays, reminders of various anniversaries,tasks etc
  9158. Source=Paul Collins Startup list
  9159.  
  9160. [Calendarscope]
  9161. Number=1301
  9162. Confirmed=U
  9163. Filename=cs.exe
  9164. Description=<a href="http://www.calendarscope.com/" target=_blank>Calendarscope</a> calendar software
  9165. Source=Paul Collins Startup list
  9166.  
  9167. [calk]
  9168. Number=1302
  9169. Confirmed=X
  9170. Filename=calk.exe
  9171. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojstartpafh.html" target= blank>STARTPA-FH</a> TROJAN!
  9172. Source=Paul Collins Startup list
  9173.  
  9174. [Call32]
  9175. Number=1303
  9176. Confirmed=X
  9177. Filename=Call32.exe
  9178. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojspammith.html" target="_blank">SPAMMIT-H</a> TROJAN!
  9179. Source=Paul Collins Startup list
  9180.  
  9181. [CallBumping]
  9182. Number=1304
  9183. Confirmed=Y
  9184. Filename=cbpopw.exe
  9185. Description=Related to the <a href="http://www.bewan.com/bewan/products/isdn/index.php" target="_blank">Gazel</a> 128 PCI ISDN adapter. Required if you use it
  9186. Source=Paul Collins Startup list
  9187.  
  9188. [CallCenter Main Application]
  9189. Number=1305
  9190. Confirmed=U
  9191. Filename=V3calmcp.exe
  9192. Description="V3 Inc. <a href="http://www.v3inc.com/freecc.htm" target=_blank>CallCenter</a> is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications." Main application
  9193. Source=Paul Collins Startup list
  9194.  
  9195. [CallCenter Printer Interface]
  9196. Number=1306
  9197. Confirmed=U
  9198. Filename=V3faxecp.exe
  9199. Description="V3 Inc. <a href="http://www.v3inc.com/freecc.htm" target=_blank>CallCenter</a> is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications." Fax printer
  9200. Source=Paul Collins Startup list
  9201.  
  9202. [CallControl]
  9203. Number=1307
  9204. Confirmed=N
  9205. Filename=ftctrl32.exe
  9206. Description=FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows
  9207. Source=Paul Collins Startup list
  9208.  
  9209. [CamCheck]
  9210. Number=1308
  9211. Confirmed=N
  9212. Filename=CamCheck.exe
  9213. Description=<a href="http://www.nucam.com.tw/index1.htm" target="_blank">NuCam</a> camera software related
  9214. Source=Paul Collins Startup list
  9215.  
  9216. [Cameno]
  9217. Number=1309
  9218. Confirmed=U
  9219. Filename=Cameno.exe
  9220. Description=<a href="http://www.spadeapps.com/cameno/" target=_blank>Cameno</a> is a program which brings tabbed windows to MSN Messenger 6.0 and above
  9221. Source=Paul Collins Startup list
  9222.  
  9223. [Camera Detector]
  9224. Number=1310
  9225. Confirmed=U
  9226. Filename=CAMDET~*.EXE
  9227. Description=<a href="http://www.acdsee.com/" target="_blank">ACDSee</a> Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
  9228. Source=Paul Collins Startup list
  9229.  
  9230. [Camera Detector]
  9231. Number=1311
  9232. Confirmed=U
  9233. Filename=Camdetect.exe
  9234. Description=<a href="http://www.acdsee.com/" target="_blank">ACDSee</a> Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
  9235. Source=Paul Collins Startup list
  9236.  
  9237. [Camera Detector]
  9238. Number=1312
  9239. Confirmed=U
  9240. Filename=DEVDET~*.EXE
  9241. Description=<a href="http://www.acdsee.com/" target="_blank">ACDSee</a> Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
  9242. Source=Paul Collins Startup list
  9243.  
  9244. [Camio Viewer x]
  9245. Number=1313
  9246. Confirmed=N
  9247. Filename=IXApplet.exe
  9248. Description=Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
  9249. Source=Paul Collins Startup list
  9250.  
  9251. [CamMonitor]
  9252. Number=1314
  9253. Confirmed=?
  9254. Filename=hpqcmon.exe
  9255. Description=<font color="#FF0000">From HP and related to digital imaging</font>
  9256. Source=Paul Collins Startup list
  9257.  
  9258. [Canada]
  9259. Number=1315
  9260. Confirmed=N
  9261. Filename=Canada.exe
  9262. Description=<font color="#FF0000">Known to be a dialler - but is it maliscous or clean?</font>
  9263. Source=Paul Collins Startup list
  9264.  
  9265. [Canary]
  9266. Number=1316
  9267. Confirmed=U
  9268. Filename=canary-std.exe
  9269. Description=Canary keystroke logger/monitoring program - remove unless you installed it yourself!
  9270.  
  9271. Source=Paul Collins Startup list
  9272.  
  9273. [candy]
  9274. Number=1317
  9275. Confirmed=X
  9276. Filename=command32.exe
  9277. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlv.html" target="_blank">RBOT-LV</a> WORM!
  9278. Source=Paul Collins Startup list
  9279.  
  9280. [candynet]
  9281. Number=1318
  9282. Confirmed=X
  9283. Filename=Taskmsg.exe
  9284. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotna.html" target=_blank>RBOT-NA</a> WORM!
  9285. Source=Paul Collins Startup list
  9286.  
  9287. [Canon MultiPASS Status Monitor]
  9288. Number=1319
  9289. Confirmed=U
  9290. Filename=monitr32.exe
  9291. Description=Cannon Multi-Pass status monitor - your choice
  9292. Source=Paul Collins Startup list
  9293.  
  9294. [Canon PC1200 iC D600 iR1200G Status Window]
  9295. Number=1320
  9296. Confirmed=?
  9297. Filename=CAPM1LAK.EXE
  9298. Description=Cannon printer related - <font color="#FF0000">is it required in startup?</font>
  9299. Source=Paul Collins Startup list
  9300.  
  9301. [Canon Printer Monitor BJCxxx]
  9302. Number=1321
  9303. Confirmed=N
  9304. Filename=Cjstlst.exe
  9305. Description=Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs
  9306. Source=Paul Collins Startup list
  9307.  
  9308. [CAP3ON]
  9309. Number=1322
  9310. Confirmed=?
  9311. Filename=CAP3ONN.EXE
  9312. Description=Canon driver, purpose unknown. <font color="#FF0000">Is it required in startup?</font>
  9313. Source=Paul Collins Startup list
  9314.  
  9315. [Capfax]
  9316. Number=1323
  9317. Confirmed=N
  9318. Filename=capfax.exe
  9319. Description=<a  href="http://www.bvrp.com/ENG/products/home_fax_telephony.asp" target="_blank">PhoneTools</a> fax software
  9320. Source=Paul Collins Startup list
  9321.  
  9322. [CAPing]
  9323. Number=1324
  9324. Confirmed=U
  9325. Filename=CAPing.exe
  9326. Description=Citibank Citianywhere software
  9327. Source=Paul Collins Startup list
  9328.  
  9329. [Capon]
  9330. Number=1325
  9331. Confirmed=Y
  9332. Filename=Capon.exe
  9333. Description=Canon printer driver
  9334. Source=Paul Collins Startup list
  9335.  
  9336. [Capon]
  9337. Number=1326
  9338. Confirmed=Y
  9339. Filename=Caponn.exe
  9340. Description=Canon printer driver
  9341. Source=Paul Collins Startup list
  9342.  
  9343. [CaptionMgr32]
  9344. Number=1327
  9345. Confirmed=X
  9346. Filename=crssr.exe
  9347. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-011814-5150-99" target=_blank>ZAR.A</a> WORM!
  9348. Source=Paul Collins Startup list
  9349.  
  9350. [capture]
  9351. Number=1328
  9352. Confirmed=X
  9353. Filename=capture.exe
  9354. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtheefb.html" target=_blank>THEEF-B</a> TROJAN!
  9355. Source=Paul Collins Startup list
  9356.  
  9357. [Capture Express 2000]
  9358. Number=1329
  9359. Confirmed=N
  9360. Filename=capexp.exe
  9361. Description=<a href="http://www.captureexpress.com/" target="_blank">Capture Express</a> - screen capture utility
  9362. Source=Paul Collins Startup list
  9363.  
  9364. [Card Monitor]
  9365. Number=1330
  9366. Confirmed=N
  9367. Filename=REGCNT09.exe
  9368. Description=For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
  9369. Source=Paul Collins Startup list
  9370.  
  9371. [Care20]
  9372. Number=1331
  9373. Confirmed=X
  9374. Filename=Care20.exe
  9375. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453059998" target=_blank>TopMoxie</a> adware
  9376. Source=Paul Collins Startup list
  9377.  
  9378. [Care2GTU]
  9379. Number=1332
  9380. Confirmed=U
  9381. Filename=Care2GTU.exe
  9382. Description=Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it, keep it
  9383. Source=Paul Collins Startup list
  9384.  
  9385. [carpserv]
  9386. Number=1333
  9387. Confirmed=U
  9388. Filename=carpserv.exe
  9389. Description=Associated with <a href="http://www.zoltrix.com/" target="_blank"> Zoltrix</a> and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
  9390. Source=Paul Collins Startup list
  9391.  
  9392. [CARPserver]
  9393. Number=1334
  9394. Confirmed=X
  9395. Filename=CARPserver.exe
  9396. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankeran.html" target=_blank>BANKER-AN</a> TROJAN!
  9397. Source=Paul Collins Startup list
  9398.  
  9399. [CARPservice]
  9400. Number=1335
  9401. Confirmed=U
  9402. Filename=carpserv.exe
  9403. Description=Associated with <a href="http://www.zoltrix.com/" target="_blank"> Zoltrix</a> and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
  9404. Source=Paul Collins Startup list
  9405.  
  9406. [cartao]
  9407. Number=1336
  9408. Confirmed=X
  9409. Filename=[path to file]
  9410. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderqd.html" target=_blank>DLOADER-QD</a> TROJAN!
  9411. Source=Paul Collins Startup list
  9412.  
  9413. [cartao]
  9414. Number=1337
  9415. Confirmed=X
  9416. Filename=conflicted.exe
  9417. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdadobradv.html" target="_blank">DADOBRA-DV</a> TROJAN!
  9418. Source=Paul Collins Startup list
  9419.  
  9420. [cartao]
  9421. Number=1338
  9422. Confirmed=X
  9423. Filename=killing.exe
  9424. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderqn.html" target="_blank">DLOADER-QN</a> TROJAN!
  9425. Source=Paul Collins Startup list
  9426.  
  9427. [CAS Client]
  9428. Number=1339
  9429. Confirmed=X
  9430. Filename=casclient.exe
  9431. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061516-2016-99" target=_blank>CasinoClient</a> adware
  9432. Source=Paul Collins Startup list
  9433.  
  9434. [Cas2Stub]
  9435. Number=1340
  9436. Confirmed=X
  9437. Filename=cas2stub.exe
  9438. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061516-2016-99" target="_blank">CasinoClient</a> adware
  9439. Source=Paul Collins Startup list
  9440.  
  9441. [CasAgnt]
  9442. Number=1341
  9443. Confirmed=U
  9444. Filename=CasAgnt.exe
  9445. Description=Program by Extended Systems which allows you to sync your Casio PDA with your PC
  9446. Source=Paul Collins Startup list
  9447.  
  9448. [Casdvqwa]
  9449. Number=1342
  9450. Confirmed=X
  9451. Filename=bmqnzkg.exe
  9452. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121516-1116-99" target="_blank">RANDEX.BE</a> WORM!
  9453. Source=Paul Collins Startup list
  9454.  
  9455. [caseyvideo]
  9456. Number=1343
  9457. Confirmed=X
  9458. Filename=CaseyVideo.exe
  9459. Description=Malware causing p0rn popups
  9460. Source=Paul Collins Startup list
  9461.  
  9462. [caseyvideo]
  9463. Number=1344
  9464. Confirmed=X
  9465. Filename=caseyvideo[*].exe [* = digit]
  9466. Description=Malware causing p0rn popups
  9467. Source=Paul Collins Startup list
  9468.  
  9469. [CashBack]
  9470. Number=1345
  9471. Confirmed=X
  9472. Filename=cashback.exe
  9473. Description=Part of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch
  9474. Source=Paul Collins Startup list
  9475.  
  9476. [CashFiesta]
  9477. Number=1346
  9478. Confirmed=X
  9479. Filename=Cashfiesta.exe
  9480. Description=<a href="http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_CASHFIESTA.A" target=_blank>CASHFIESTA.A</a> pay-per-surf adware
  9481. Source=Paul Collins Startup list
  9482.  
  9483. [Cashsurfers Cashbar Navigator]
  9484. Number=1347
  9485. Confirmed=N
  9486. Filename=Cashbar.Exe
  9487. Description=Cashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"
  9488. Source=Paul Collins Startup list
  9489.  
  9490. [CashToolbar]
  9491. Number=1348
  9492. Confirmed=X
  9493. Filename=CD_Load.exe
  9494. Description=CashToolbar <a href="http://vil.nai.com/vil/content/v_126801.htm" target="_blank">Downloader-MY</a> adware
  9495. Source=Paul Collins Startup list
  9496.  
  9497. [CashToolbar]
  9498. Number=1349
  9499. Confirmed=X
  9500. Filename=svchost.exe
  9501. Description=CashToolbar <a href="http://vil.nai.com/vil/content/v_126801.htm" target="_blank">Downloader-MY</a> adware. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
  9502. Source=Paul Collins Startup list
  9503.  
  9504. [Casino Royale]
  9505. Number=1350
  9506. Confirmed=X
  9507. Filename=jamesbond.exe
  9508. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfzo.html" target="_blank">RBOT-FZO</a> WORM!
  9509. Source=Paul Collins Startup list
  9510.  
  9511. [Cassandra]
  9512. Number=1351
  9513. Confirmed=X
  9514. Filename=[10 to 14 random char]THD.EXE
  9515. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojkrepperai.html" target=_blank>KREPPER-AI</a> TROJAN!
  9516. Source=Paul Collins Startup list
  9517.  
  9518. [Cassandra]
  9519. Number=1352
  9520. Confirmed=X
  9521. Filename=cassandra.exe
  9522. Description=<a href="http://allentech.net/parasite/SuperSpider.html" target=_blank>SuperSpider</a> hijacker - a <a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant. Also detected as a variant of the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453088106" target=_blank>KREPPER</a> TROJAN!
  9523.  
  9524. Source=Paul Collins Startup list
  9525.  
  9526. [CasStub]
  9527. Number=1353
  9528. Confirmed=X
  9529. Filename=casstub.exe
  9530. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcassa.html" target=_blank>CASS-A</a> TROJAN!
  9531. Source=Paul Collins Startup list
  9532.  
  9533. [Catalyst Control Centre]
  9534. Number=1354
  9535. Confirmed=X
  9536. Filename=atixvdm.exe
  9537. Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=47032" target="_blank">RBOT.DMW</a> TROJAN!
  9538. Source=Paul Collins Startup list
  9539.  
  9540. [CAVRID]
  9541. Number=1355
  9542. Confirmed=Y
  9543. Filename=CAVRID.exe
  9544. Description=eTrustÖ <a href="http://home.ca.com/dr/sat5/ec_Main.Entry17c?SID=35715&SP=10023&PN=1&PID=671589&V1=671589&CID=179788&api1=78&api2=1&api3=&DSP=&CUR=840&PGRP=0&CACHE_ID=179788" target=_blank>EZ Antivirus</a> Real Time Infection Report from Computer Associates
  9545. Source=Paul Collins Startup list
  9546.  
  9547. [CAVS]
  9548. Number=1356
  9549. Confirmed=Y
  9550. Filename=CAVS.exe
  9551. Description=Cheyenne (now <a href="http://ca.com/" target=_blank>eTrust</a>) antivirus
  9552. Source=Paul Collins Startup list
  9553.  
  9554. [CAZNOVAS]
  9555. Number=1357
  9556. Confirmed=X
  9557. Filename=CAZNOVAS.exe
  9558. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031919-3602-99" target="_blank">CAZNO</a> TROJAN!
  9559. Source=Paul Collins Startup list
  9560.  
  9561. [CBACK.EXE]
  9562. Number=1358
  9563. Confirmed=X
  9564. Filename=CBACK.EXE
  9565. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpentaa.html" target=_blank>PENTA-A</a> TROJAN!
  9566. Source=Paul Collins Startup list
  9567.  
  9568. [CBWAttn]
  9569. Number=1359
  9570. Confirmed=U
  9571. Filename=CBWAttn.exe
  9572. Description=Required for <a href="http://www.spyfind.com/bitware.html" target="_blank">Bitware</a> to answer incoming faxes, can cause sleep mode problems
  9573. Source=Paul Collins Startup list
  9574.  
  9575. [CBWHost]
  9576. Number=1360
  9577. Confirmed=U
  9578. Filename=CBWHost.exe
  9579. Description=Required for <a href="http://www.spyfind.com/bitware.html" target="_blank">Bitware</a> to answer incoming faxes, can cause sleep mode problems
  9580. Source=Paul Collins Startup list
  9581.  
  9582. [CBWUser]
  9583. Number=1361
  9584. Confirmed=?
  9585. Filename=CBWDial.exe
  9586. Description=Associated with <a href="http://www.spyfind.com/bitware.html" target="_blank">Bitware</a> that integrates fax, voice, pager, and data communications on your desktop
  9587. Source=Paul Collins Startup list
  9588.  
  9589. [CC2KUI]
  9590. Number=1362
  9591. Confirmed=X
  9592. Filename=comet.exe
  9593. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Comet%20Cursor&threatid=29168" target=_blank>Comet Cursor</a> adware
  9594. Source=Paul Collins Startup list
  9595.  
  9596. [Ccao]
  9597. Number=1363
  9598. Confirmed=X
  9599. Filename=regedit.exe
  9600. Description=Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a "mduu" subfolder, which may change
  9601. Source=Paul Collins Startup list
  9602.  
  9603. [ccApp]
  9604. Number=1364
  9605. Confirmed=Y
  9606. Filename=ccApp.exe
  9607. Description=Part of <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank">Norton AntiVirus</a>. Auto-protect and E-mail check will not function without this
  9608. Source=Paul Collins Startup list
  9609.  
  9610. [ccApp]
  9611. Number=1365
  9612. Confirmed=X
  9613. Filename=[random filename]
  9614. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102917-0924-99" target="_blank">OBSORB</a> TROJAN! Note the random filename compared to the valid Norton AntiVirus
  9615. Source=Paul Collins Startup list
  9616.  
  9617. [ccApp]
  9618. Number=1366
  9619. Confirmed=X
  9620. Filename=WMADZ.EXE
  9621. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlj.html" target="_blank">RBOT-LJ</a> WORM!
  9622. Source=Paul Collins Startup list
  9623.  
  9624. [ccApp]
  9625. Number=1367
  9626. Confirmed=X
  9627. Filename=.EXE
  9628. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlj.html" target= blank>RBOT-LJ</a> WORM!
  9629. Source=Paul Collins Startup list
  9630.  
  9631. [ccApp]
  9632. Number=1368
  9633. Confirmed=X
  9634. Filename=gcasServ.exe
  9635. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name
  9636. Source=Paul Collins Startup list
  9637.  
  9638. [ccAppr]
  9639. Number=1369
  9640. Confirmed=X
  9641. Filename=svcrhost.exe
  9642. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9643. Source=Paul Collins Startup list
  9644.  
  9645. [ccAppr]
  9646. Number=1370
  9647. Confirmed=X
  9648. Filename=expIorer.exe
  9649. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9650. Source=Paul Collins Startup list
  9651.  
  9652. [ccAppr]
  9653. Number=1371
  9654. Confirmed=X
  9655. Filename=outIook.exe
  9656. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9657. Source=Paul Collins Startup list
  9658.  
  9659. [ccAppr]
  9660. Number=1372
  9661. Confirmed=X
  9662. Filename=svcshost.exe
  9663. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9664. Source=Paul Collins Startup list
  9665.  
  9666. [ccApps]
  9667. Number=1373
  9668. Confirmed=X
  9669. Filename=services.exe
  9670. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081700-2526-99" target="_blank">NEVEG.B</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081614-3605-99" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
  9671. Source=Paul Collins Startup list
  9672.  
  9673. [ccApps]
  9674. Number=1374
  9675. Confirmed=X
  9676. Filename=winlogon.exe
  9677. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081623-4258-99" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
  9678. Source=Paul Collins Startup list
  9679.  
  9680. [ccApps]
  9681. Number=1375
  9682. Confirmed=X
  9683. Filename=N/A
  9684. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32kangarooa.html" target=_blank>KANGAROO-A</a> TROJAN!
  9685. Source=Paul Collins Startup list
  9686.  
  9687. [ccApps]
  9688. Number=1376
  9689. Confirmed=X
  9690. Filename=ccApps.exe
  9691. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32kangaroob.html" target=_blank>KANGAROO-B</a> WORM!
  9692. Source=Paul Collins Startup list
  9693.  
  9694. [CCD Manager]
  9695. Number=1377
  9696. Confirmed=U
  9697. Filename=DDS.EXE
  9698. Description=Project Labs <a href="http://www.centurycdtech.com/" target="_blank">Century CD</a> manager for their CD/DVD storage device
  9699. Source=Paul Collins Startup list
  9700.  
  9701. [Ccdecode]
  9702. Number=1378
  9703. Confirmed=N
  9704. Filename=rundll32.exe streamci, StreamingDeviceSetup
  9705. Description=Part of the closed caption decdoder/MS VBI codec. Should only run once
  9706. Source=Paul Collins Startup list
  9707.  
  9708. [CCDoctorLogonTesting]
  9709. Number=1379
  9710. Confirmed=Y
  9711. Filename=ccdoctor.exe
  9712. Description=Checks your system to make sure it's configured properly for running <a href="http://www-306.ibm.com/software/awdtools/clearcase/index.html" target="_blank">IBM Rational ClearCase</a>, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product
  9713. Source=Paul Collins Startup list
  9714.  
  9715. [ccenter]
  9716. Number=1380
  9717. Confirmed=Y
  9718. Filename=CCenter.exe
  9719. Description=<a href="http://www.ravantivirus.com/" target=_blank>RAV</a> AntiVirus
  9720.  
  9721. Source=Paul Collins Startup list
  9722.  
  9723. [CcEvtMgr]
  9724. Number=1381
  9725. Confirmed=Y
  9726. Filename=ccEvtMgr.exe
  9727. Description=Part of <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> Norton AntiVirus 2003</a>.<font color="#FF0000"> </font>Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and was not required as a seperate entry but a recent update changed this
  9728. Source=Paul Collins Startup list
  9729.  
  9730. [ccEvtMrg.exe]
  9731. Number=1382
  9732. Confirmed=X
  9733. Filename=ccEvtMrg.exe
  9734. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.GZ&VSect=T" target=_blank>RBOT.GZ</a> WORM!
  9735. Source=Paul Collins Startup list
  9736.  
  9737. [ccExecute]
  9738. Number=1383
  9739. Confirmed=X
  9740. Filename=bootcfg1.exe
  9741. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32nemsib.html" target=_blank>NEMSI-B</a> VIRUS!
  9742. Source=Paul Collins Startup list
  9743.  
  9744. [ccHelp]
  9745. Number=1384
  9746. Confirmed=X
  9747. Filename=ccHelp.hta
  9748. Description=<a href="http://sarc.com/avcenter/venc/data/adware.searchq.html" target= blank>"Searchq"</a> adware
  9749. Source=Paul Collins Startup list
  9750.  
  9751. [ccleaner]
  9752. Number=1385
  9753. Confirmed=U
  9754. Filename=ccleaner.exe
  9755. Description=<a href="http://www.ccleaner.com/" target=_blank>CCleaner</a> - removes unused files from your system
  9756.  
  9757. Source=Paul Collins Startup list
  9758.  
  9759. [ccpApps]
  9760. Number=1386
  9761. Confirmed=X
  9762. Filename=csrss.exe
  9763. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091409-4900-99" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  9764. Source=Paul Collins Startup list
  9765.  
  9766. [ccpApps]
  9767. Number=1387
  9768. Confirmed=X
  9769. Filename=lsass.exe
  9770. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100519-0947-99" target=_blank>WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
  9771. Source=Paul Collins Startup list
  9772.  
  9773. [ccProxy]
  9774. Number=1388
  9775. Confirmed=U
  9776. Filename=CCPROXY.EXE
  9777. Description=Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage
  9778. Source=Paul Collins Startup list
  9779.  
  9780. [ccPrxy.exe]
  9781. Number=1389
  9782. Confirmed=X
  9783. Filename=ccPrxy.exe
  9784. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32shipuph.html" target="_blank">SHIPUP-H</a> WORM!
  9785. Source=Paul Collins Startup list
  9786.  
  9787. [CcPxySvc]
  9788. Number=1390
  9789. Confirmed=Y
  9790. Filename=CCPXYSVC.exe
  9791. Description=Part of Norton's <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> AntiVirus 2003</a>, <a href="http://www.symantec.com/sabu/nis/nis_pe/" target="_blank"> Internet Security</a> and <a href="http://www.symantec.com/sabu/nis/npf/" target="_blank"> Firewall</a> products. E-mail proxy service - required for E-mail scanning and the firewall
  9792. Source=Paul Collins Startup list
  9793.  
  9794. [ccreg]
  9795. Number=1391
  9796. Confirmed=X
  9797. Filename=explorer.exe
  9798. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-021316-5131-99" target=_blank>ZCREW</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System subfolder
  9799. Source=Paul Collins Startup list
  9800.  
  9801. [CcRegVfy]
  9802. Number=1392
  9803. Confirmed=Y
  9804. Filename=ccRegVfy.exe
  9805. Description=Part of <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> Norton AntiVirus 2003</a>. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"
  9806. Source=Paul Collins Startup list
  9807.  
  9808. [ccRegVfY]
  9809. Number=1393
  9810. Confirmed=X
  9811. Filename=expIorer.exe
  9812. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9813. Source=Paul Collins Startup list
  9814.  
  9815. [ccRegVfY]
  9816. Number=1394
  9817. Confirmed=X
  9818. Filename=svcrhost.exe
  9819. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9820. Source=Paul Collins Startup list
  9821.  
  9822. [ccRegVfY]
  9823. Number=1395
  9824. Confirmed=X
  9825. Filename=svcshost.exe
  9826. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN!
  9827. Source=Paul Collins Startup list
  9828.  
  9829. [ccRegVfY]
  9830. Number=1396
  9831. Confirmed=X
  9832. Filename=outIook.exe
  9833. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.A</a> TROJAN!
  9834. Source=Paul Collins Startup list
  9835.  
  9836. [ccSetMgr]
  9837. Number=1397
  9838. Confirmed=Y
  9839. Filename=ccSetMgr.exe
  9840. Description=Part of Norton AntiVirus 2004. <font color="#FF0000"> What does it do?</font>
  9841. Source=Paul Collins Startup list
  9842.  
  9843. [ccsvit.exe]
  9844. Number=1398
  9845. Confirmed=X
  9846. Filename=ccsvit.exe
  9847. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojstartpahp.html" target=_blank>STARTPA-HP</a> TROJAN!
  9848. Source=Paul Collins Startup list
  9849.  
  9850. [cctray]
  9851. Number=1399
  9852. Confirmed=U
  9853. Filename=cctray.exe
  9854. Description=Part of <a href="http://www3.ca.com/Solutions/Product.aspx?ID=3243" target="_blank">CA Internet Security Suite</a>
  9855. Source=Paul Collins Startup list
  9856.  
  9857. [ccUpdate]
  9858. Number=1400
  9859. Confirmed=X
  9860. Filename=ccUpdate.exe
  9861. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.YS" target="_blank">AGOBOT.YS</a> WORM!
  9862. Source=Paul Collins Startup list
  9863.  
  9864. [ccWasher]
  9865. Number=1401
  9866. Confirmed=U
  9867. Filename=aolwasher.exe
  9868. Description=Webroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL
  9869. Source=Paul Collins Startup list
  9870.  
  9871. [CCWC7a]
  9872. Number=1402
  9873. Confirmed=U
  9874. Filename=ac.exe
  9875. Description=<a href="http://hem.bredband.net/thokha/" target="_blank">Moleculesoft</a> Cache, Cookie & Windows Cleaner. No longer supported but available for free
  9876. Source=Paul Collins Startup list
  9877.  
  9878. [CCWC7I]
  9879. Number=1403
  9880. Confirmed=U
  9881. Filename=idxl.exe
  9882. Description=<a href="http://hem.bredband.net/thokha/" target="_blank">Moleculesoft</a> Cache, Cookie & Windows Cleaner. No longer supported but available for free
  9883. Source=Paul Collins Startup list
  9884.  
  9885. [CCWC7s]
  9886. Number=1404
  9887. Confirmed=U
  9888. Filename=stealth.exe
  9889. Description=<a href="http://hem.bredband.net/thokha/" target="_blank">Moleculesoft</a> Cache, Cookie & Windows Cleaner. No longer supported but available for free
  9890. Source=Paul Collins Startup list
  9891.  
  9892. [CD Storage Master]
  9893. Number=1405
  9894. Confirmed=N
  9895. Filename=cdstorager.exe
  9896. Description=<a href="http://www.cdstorager.com/" target= blank>CD Storage Master</a> - a program designed to catalog CD information, boasts a number of handy features for organizing your collection
  9897. Source=Paul Collins Startup list
  9898.  
  9899. [cd1]
  9900. Number=1406
  9901. Confirmed=X
  9902. Filename=cd1.exe
  9903. Description=Premium rate adult content dialler
  9904. Source=Paul Collins Startup list
  9905.  
  9906. [CDANTSRV]
  9907. Number=1407
  9908. Confirmed=N
  9909. Filename=CDANTSRV.exe
  9910. Description=C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually
  9911. Source=Paul Collins Startup list
  9912.  
  9913. [Cdcompat]
  9914. Number=1408
  9915. Confirmed=X
  9916. Filename=Cdcompat.exe
  9917. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  9918. Source=Paul Collins Startup list
  9919.  
  9920. [cddrv32]
  9921. Number=1409
  9922. Confirmed=X
  9923. Filename=cddrv32.exe
  9924. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  9925. Source=Paul Collins Startup list
  9926.  
  9927. [CDInterceptor]
  9928. Number=1410
  9929. Confirmed=N
  9930. Filename=cdi.exe
  9931. Description=CD indexer for measuring the speed of CD players
  9932. Source=Paul Collins Startup list
  9933.  
  9934. [CdnCtr]
  9935. Number=1411
  9936. Confirmed=X
  9937. Filename=cdnup.exe
  9938. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097703" target="_blank">CNNIC Update</a> pest
  9939. Source=Paul Collins Startup list
  9940.  
  9941. [CDriver]
  9942. Number=1412
  9943. Confirmed=X
  9944. Filename=windrv.exe
  9945. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DELF.WG" target="_blank">DELF.WG</a> TROJAN!
  9946. Source=Paul Collins Startup list
  9947.  
  9948. [Cdrom Controller]
  9949. Number=1413
  9950. Confirmed=X
  9951. Filename=cdromcntrl.exe
  9952. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbattrya.html" target=_blank>BATTRY-A</a> TROJAN!
  9953. Source=Paul Collins Startup list
  9954.  
  9955. [cds]
  9956. Number=1414
  9957. Confirmed=X
  9958. Filename=cds.exe
  9959. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-112514-4016-99" target=_blank>SPYMON</a> TROJAN!
  9960. Source=Paul Collins Startup list
  9961.  
  9962. [CDTray]
  9963. Number=1415
  9964. Confirmed=N
  9965. Filename=CDTray.exe
  9966. Description=On HP PCs, this is the small CD icon next to the time
  9967. Source=Paul Collins Startup list
  9968.  
  9969. [CeEKEY]
  9970. Number=1416
  9971. Confirmed=U
  9972. Filename=CeEKey.exe
  9973. Description=Hot Key utility included on Toshiba Satellite laptops
  9974. Source=Paul Collins Startup list
  9975.  
  9976. [CeEPOWER]
  9977. Number=1417
  9978. Confirmed=U
  9979. Filename=cepmtray.exe
  9980. Description=Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times
  9981. Source=Paul Collins Startup list
  9982.  
  9983. [Ceic]
  9984. Number=1418
  9985. Confirmed=?
  9986. Filename=Ceic.exe
  9987. Description=<font color="#FF0000">??</font>
  9988. Source=Paul Collins Startup list
  9989.  
  9990. [Cekirge]
  9991. Number=1419
  9992. Confirmed=X
  9993. Filename=[path to worm]
  9994. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080513-2747-99" target="_blank">KERGEZ.A</a> WORM!
  9995. Source=Paul Collins Startup list
  9996.  
  9997. [center]
  9998. Number=1420
  9999. Confirmed=X
  10000. Filename=[random name]32.exe
  10001. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-110916-0038-99" target=_blank>BOFRA.A</a> WORM!
  10002. Source=Paul Collins Startup list
  10003.  
  10004. [CentralProcessor]
  10005. Number=1421
  10006. Confirmed=X
  10007. Filename=taskimgr.exe
  10008. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081711-5410-99" target="_blank">BANCOS.J</a> TROJAN!
  10009. Source=Paul Collins Startup list
  10010.  
  10011. [CEPA]
  10012. Number=1422
  10013. Confirmed=?
  10014. Filename=wsot.exe
  10015. Description=<font color="#FF0000">??</font>
  10016. Source=Paul Collins Startup list
  10017.  
  10018. [CertificateRegistration]
  10019. Number=1423
  10020. Confirmed=U
  10021. Filename=SafeSignCertReg.exe
  10022. Description=SafeSign Certificate Registration Utility for Microsoft Crypto applications
  10023. Source=Paul Collins Startup list
  10024.  
  10025. [CertReg]
  10026. Number=1424
  10027. Confirmed=U
  10028. Filename=certreg.exe
  10029. Description=Related to <a href="http://www.gemplus.com/" target=_blank>Gemplus</a> Card Reader
  10030.  
  10031. Source=Paul Collins Startup list
  10032.  
  10033. [CertStoreInit]
  10034. Number=1425
  10035. Confirmed=Y
  10036. Filename=CertStoreInit
  10037. Description=<a href="http://www.aladdin.com/eToken/" target="_blank">Aladdin eToken</a> authentication and password management
  10038. Source=Paul Collins Startup list
  10039.  
  10040. [CesarFTP FTP Server]
  10041. Number=1426
  10042. Confirmed=N
  10043. Filename=server.exe
  10044. Description=<a href="http://www.aclogic.com/" target="_blank">CesarFTPd</a> - FTP server
  10045. Source=Paul Collins Startup list
  10046.  
  10047. [cesmain.dll]
  10048. Number=1427
  10049. Confirmed=X
  10050. Filename=cmail.dll, Rundll32
  10051. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=3721%20Chinese%20Keywords%20(CNSMin)&threatid=3678" target=_blank>CnsMin</a> (Chinese Keywords) hijacker related
  10052. Source=Paul Collins Startup list
  10053.  
  10054. [CEventMgr]
  10055. Number=1428
  10056. Confirmed=X
  10057. Filename=Cell.exe
  10058. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbifroseak.html" target=_blank>BIFROSE-AK</a> TROJAN!
  10059. Source=Paul Collins Startup list
  10060.  
  10061. [CFD]
  10062. Number=1429
  10063. Confirmed=N
  10064. Filename=CFD.exe
  10065. Description=<a href="http://www.broadjump.com/" target="_blank">BroadJump</a> Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
  10066. Source=Paul Collins Startup list
  10067.  
  10068. [CFDStart]
  10069. Number=1430
  10070. Confirmed=X
  10071. Filename=WinMuschi.exe
  10072. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092618-5651-99" target="_blank">WINMUSCHI</a> dialler
  10073. Source=Paul Collins Startup list
  10074.  
  10075. [cfgboost]
  10076. Number=1431
  10077. Confirmed=X
  10078. Filename=cfgboot.exe
  10079. Description=Added by an unidentified WORM or TROJAN!
  10080. Source=Paul Collins Startup list
  10081.  
  10082. [cfgintpr]
  10083. Number=1432
  10084. Confirmed=Y
  10085. Filename=cfgintpr.exe
  10086. Description=Configuration Interpreter - part of <a href="http://www.tinysoftware.com/home/tiny2?la=EN" target="_blank">Tiny Personal Firewall</a> V4
  10087. Source=Paul Collins Startup list
  10088.  
  10089. [cfgmgr51]
  10090. Number=1433
  10091. Confirmed=X
  10092. Filename=RunDLL32.EXE [path] cfgmgr51.dll, DllRun
  10093. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  10094. Source=Paul Collins Startup list
  10095.  
  10096. [cfgmgr52]
  10097. Number=1434
  10098. Confirmed=X
  10099. Filename=RunDLL32.EXE [path] cfgmgr52.dll, DllRun
  10100. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  10101. Source=Paul Collins Startup list
  10102.  
  10103. [cfgwiz]
  10104. Number=1435
  10105. Confirmed=N
  10106. Filename=cfgwiz.exe
  10107. Description=Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
  10108. Source=Paul Collins Startup list
  10109.  
  10110. [cFosDNT]
  10111. Number=1436
  10112. Confirmed=?
  10113. Filename=cFosDNT.exe
  10114. Description=<a href="http://www.cfos.de/index2_e.htm" target="_blank">cFos</a> DSL Modem driver related. <font color="#FF0000">What does it do and is it required?</font>
  10115. Source=Paul Collins Startup list
  10116.  
  10117. [cFosInst_Check]
  10118. Number=1437
  10119. Confirmed=?
  10120. Filename=cfosinst.exe
  10121. Description=<a href="http://www.cfos.de/index2_e.htm" target="_blank">cFos</a> DSL Modem driver related. <font color="#FF0000">What does it do and is it required?</font>
  10122. Source=Paul Collins Startup list
  10123.  
  10124. [cFosSpeed]
  10125. Number=1438
  10126. Confirmed=U
  10127. Filename=cFosSpeed.exe
  10128. Description=<a href="http://www.cfos.de/index2_e.htm" target=_blank>cFos Software</a> Internet acceleration program related. Note - may be necessary for the software to work properly
  10129. Source=Paul Collins Startup list
  10130.  
  10131. [CFSServ.exe]
  10132. Number=1439
  10133. Confirmed=U
  10134. Filename=CFSServ.exe
  10135. Description=Belongs to Toshiba's configfree utility and searches for Wireless Devices
  10136. Source=Paul Collins Startup list
  10137.  
  10138. [cftmon32]
  10139. Number=1440
  10140. Confirmed=X
  10141. Filename=taskmgr*.exe [* = number]
  10142. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080717-1526-99" target="_blank">SOWSAT.C</a> and <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082211-1053-99" target="_blank">SOWSAT.J</a> WORMS!
  10143. Source=Paul Collins Startup list
  10144.  
  10145. [cfy]
  10146. Number=1441
  10147. Confirmed=X
  10148. Filename=cfy.exe
  10149. Description=Surfenhance.com <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-111211-5006-99" target=_blank>SearchForIt</a> adware variant
  10150. Source=Paul Collins Startup list
  10151.  
  10152. [CGI Firewall Script]
  10153. Number=1442
  10154. Confirmed=X
  10155. Filename=CGIAGENT.EXE
  10156. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32bropiau.html" target=_blank>BROPIA-U</a> WORM!
  10157. Source=Paul Collins Startup list
  10158.  
  10159. [CGServer]
  10160. Number=1443
  10161. Confirmed=U
  10162. Filename=cgserver.exe
  10163. Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs
  10164. Source=Paul Collins Startup list
  10165.  
  10166. [Cgtask Services]
  10167. Number=1444
  10168. Confirmed=X
  10169. Filename=cgtask.exe
  10170. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-072809-1932-99" target="_blank">LALA.B</a> TROJAN!
  10171. Source=Paul Collins Startup list
  10172.  
  10173. [Cgywin]
  10174. Number=1445
  10175. Confirmed=X
  10176. Filename=cgywin32.exe
  10177. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaei.html" target=_blank>RBOT-AEI</a> WORM!
  10178. Source=Paul Collins Startup list
  10179.  
  10180. [ChamClock]
  10181. Number=1446
  10182. Confirmed=U
  10183. Filename=ChamClock.exe
  10184. Description=<a href="http://www.softshape.com/cham/" target="_blank">Chameleon Clock</a> - system tray clock replacement
  10185. Source=Paul Collins Startup list
  10186.  
  10187. [change-me-now]
  10188. Number=1447
  10189. Confirmed=X
  10190. Filename=msgfix1.exe
  10191. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.ZD" target=_blank>SDBOT.ZD</a> WORM!
  10192. Source=Paul Collins Startup list
  10193.  
  10194. [ChangeICON]
  10195. Number=1448
  10196. Confirmed=U
  10197. Filename=SPMSMON.EXE
  10198. Description=Card reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
  10199. Source=Paul Collins Startup list
  10200.  
  10201. [ChangeLines]
  10202. Number=1449
  10203. Confirmed=?
  10204. Filename=chngline.exe
  10205. Description=<font color="#FF0000">??</font>
  10206. Source=Paul Collins Startup list
  10207.  
  10208. [Chatango]
  10209. Number=1450
  10210. Confirmed=N
  10211. Filename=Chatango.exe
  10212. Description=<a href="http://www.chatango.com/" target=_blank>Chatango</a> - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately
  10213. Source=Paul Collins Startup list
  10214.  
  10215. [Chcenter]
  10216. Number=1451
  10217. Confirmed=N
  10218. Filename=chcenter.exe
  10219. Description=IMSI <a href="http://www.imsisoft.com/prodinfo.asp?t=1&mcid=100" target="_blank">HiJaak</a> - "the easiest way to convert, capture, and manage all your graphic files"
  10220. Source=Paul Collins Startup list
  10221.  
  10222. [Chckup]
  10223. Number=1452
  10224. Confirmed=X
  10225. Filename=Netverchk.exe
  10226. Description=<a href="http://fileinfo.prevx.com/fileinfo.asp?PXC=e7ee46377171http://fileinfo.prevx.com/fileinfo.asp?PXC=e7ee46377171" target="_blank">Covert Sys Exec</a> malware variant
  10227. Source=Paul Collins Startup list
  10228.  
  10229. [che32]
  10230. Number=1453
  10231. Confirmed=X
  10232. Filename=che.ocx.vbs
  10233. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/wm97adenub.html" target=_blank>ADENU-B</a> VIRUS!
  10234. Source=Paul Collins Startup list
  10235.  
  10236. [Cheatle]
  10237. Number=1454
  10238. Confirmed=X
  10239. Filename=GigaByte.exe
  10240. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042012-2931-99" target="_blank">SHODI.B</a> VIRUS!
  10241. Source=Paul Collins Startup list
  10242.  
  10243. [Check]
  10244. Number=1455
  10245. Confirmed=X
  10246. Filename=Check.exe
  10247. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32vbdrn.html" target="_blank">VB-DRN</a> WORM!
  10248. Source=Paul Collins Startup list
  10249.  
  10250. [Check for One Touch Update]
  10251. Number=1456
  10252. Confirmed=N
  10253. Filename=wiseupdt.exe
  10254. Description=Checks for updates for Visioneer OneTouch scanners
  10255. Source=Paul Collins Startup list
  10256.  
  10257. [Check for TWS Updates]
  10258. Number=1457
  10259. Confirmed=N
  10260. Filename=WiseUpdt.exe
  10261. Description=Interactive Brokers - check for update to their standalone Java-based trading platform
  10262. Source=Paul Collins Startup list
  10263.  
  10264. [Check Messenger]
  10265. Number=1458
  10266. Confirmed=U
  10267. Filename=cmesseng.exe
  10268. Description=Check Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
  10269. Source=Paul Collins Startup list
  10270.  
  10271. [CheckCustomWorksUpdate]
  10272. Number=1459
  10273. Confirmed=N
  10274. Filename=CheckCWupdate.exe
  10275. Description=Update checker, part of <a href="http://www.designersgallerysoftware.com/products/product.asp?Product_ID=EDG-CW" target=_blank>CustomWorks</a> - "customize any embroidery designs to design your own unique creations"
  10276. Source=Paul Collins Startup list
  10277.  
  10278. [Checkdisk]
  10279. Number=1460
  10280. Confirmed=X
  10281. Filename=mscas.exe
  10282. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvagona.html" target=_blank>VAGON-A</a> TROJAN!
  10283. Source=Paul Collins Startup list
  10284.  
  10285. [CheckFaultKernel]
  10286. Number=1461
  10287. Confirmed=X
  10288. Filename=mswdm.exe
  10289. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmallcsk.html" target="_blank">SMALL-CSK</a> TROJAN!
  10290. Source=Paul Collins Startup list
  10291.  
  10292. [CheckIt]
  10293. Number=1462
  10294. Confirmed=U
  10295. Filename=ToolBox.exe
  10296. Description=CheckIt Toolbox from <a href="http://cssvc.pcworld.compuserve.com/computing/cis/article/0,aid,15497,00.asp" target="_blank">WinCheckIt Diagnostic Software</a>. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify
  10297. Source=Paul Collins Startup list
  10298.  
  10299. [CheckIt 86]
  10300. Number=1463
  10301. Confirmed=U
  10302. Filename=CheckIt86.exe
  10303. Description=<a href="http://www.smithmicro.com/default.tpl?group=product_full&sku=C86WINEE" target=_blank>CheckIt 86</a> popup blocker
  10304. Source=Paul Collins Startup list
  10305.  
  10306. [CheckMsgPlus]
  10307. Number=1464
  10308. Confirmed=Y
  10309. Filename=MsgPlusH.dll, VerifyInstallation
  10310. Description=Added by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see <a href="http://www.patchou.com/msgplus/faq.htm#stopconnect" target="_blank">here</a> for more info.
  10311. Source=Paul Collins Startup list
  10312.  
  10313. [checkrun]
  10314. Number=1465
  10315. Confirmed=X
  10316. Filename=elite***32.exe [* = random char]
  10317. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-083109-1455-99" target=_blank>EliteBar</a> adware
  10318.  
  10319. Source=Paul Collins Startup list
  10320.  
  10321. [checkrun]
  10322. Number=1466
  10323. Confirmed=X
  10324. Filename=elitelsj32.exe
  10325. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmultidrer.html" target=_blank>MULTIDR-ER</a> TROJAN!
  10326. Source=Paul Collins Startup list
  10327.  
  10328. [CheckScan32]
  10329. Number=1467
  10330. Confirmed=X
  10331. Filename=regload16.exe
  10332. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AEBOT.K&VSect=P" target=_blank>AEBOT.K</a> WORM!
  10333. Source=Paul Collins Startup list
  10334.  
  10335. [checktime]
  10336. Number=1468
  10337. Confirmed=?
  10338. Filename=ct.exe
  10339. Description=<font color="#FF0000">Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required?</font>
  10340. Source=Paul Collins Startup list
  10341.  
  10342. [CheckVCR]
  10343. Number=1469
  10344. Confirmed=Y
  10345. Filename=IOMagic.exe
  10346. Description=Driver for the <a href="http://www.iomagic.com/" target=_blank>I/OMagic</a> Personal Video Recorder (DR-PCTV100)
  10347. Source=Paul Collins Startup list
  10348.  
  10349. [CherryKeyMan]
  10350. Number=1470
  10351. Confirmed=U
  10352. Filename=KeyMan.exe
  10353. Description=Multimedia keyboard manager for the <a href="http://www.cherrycorp.com/index.htm" target="_blank">Cherry</a> keyboard series. Only required if you use any of the special keys
  10354. Source=Paul Collins Startup list
  10355.  
  10356. [china11msn]
  10357. Number=1471
  10358. Confirmed=X
  10359. Filename=CHINA11MSN.EXE
  10360. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040417-2341-99" target=_blank>ENVID.O</a> WORM!
  10361. Source=Paul Collins Startup list
  10362.  
  10363. [ChineseStar]
  10364. Number=1472
  10365. Confirmed=U
  10366. Filename=cstar.exe
  10367. Description=Chinese language support software
  10368. Source=Paul Collins Startup list
  10369.  
  10370. [CHIPDRIVEPinManager]
  10371. Number=1473
  10372. Confirmed=U
  10373. Filename=sokscmpn.exe
  10374. Description=<a href="http://www.chipdrive.de/cgi-bin/edcstore.cgi" target=_blank>ChipDrive</a> Smartcard software
  10375. Source=Paul Collins Startup list
  10376.  
  10377. [CHIPDRIVESmartcardManager]
  10378. Number=1474
  10379. Confirmed=U
  10380. Filename=SCMgr.exe
  10381. Description=<a href="http://www.chipdrive.de/cgi-bin/edcstore.cgi" target=_blank>ChipDrive</a> Smartcard software
  10382. Source=Paul Collins Startup list
  10383.  
  10384. [CHKADMIN]
  10385. Number=1475
  10386. Confirmed=N
  10387. Filename=CHKADMIN.EXE
  10388. Description=Compaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability"
  10389. Source=Paul Collins Startup list
  10390.  
  10391. [chkdsk]
  10392. Number=1476
  10393. Confirmed=X
  10394. Filename=autoexec.bat
  10395. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-102614-0016-99" target=_blank>ANPES</a> WORM!
  10396. Source=Paul Collins Startup list
  10397.  
  10398. [Choke]
  10399. Number=1477
  10400. Confirmed=X
  10401. Filename=Choke.exe-blahh
  10402. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-060615-3930-99" target="_blank">CHOKE</a> WORM!
  10403. Source=Paul Collins Startup list
  10404.  
  10405. [chope]
  10406. Number=1478
  10407. Confirmed=X
  10408. Filename=runlli32.exe
  10409. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojqqpassu.html" target=_blank>QQPASS-U</a> TROJAN!
  10410. Source=Paul Collins Startup list
  10411.  
  10412. [chostsv]
  10413. Number=1479
  10414. Confirmed=X
  10415. Filename=chostsv.exe
  10416. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-030518-3634-99" target="_blank">BANPAES.C</a> TROJAN!
  10417. Source=Paul Collins Startup list
  10418.  
  10419. [CHotKey]
  10420. Number=1480
  10421. Confirmed=U
  10422. Filename=mhotkey.exe
  10423. Description=Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features
  10424. Source=Paul Collins Startup list
  10425.  
  10426. [CHotKey]
  10427. Number=1481
  10428. Confirmed=U
  10429. Filename=MK9805.EXE
  10430. Description=Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features
  10431. Source=Paul Collins Startup list
  10432.  
  10433. [CHotKey]
  10434. Number=1482
  10435. Confirmed=U
  10436. Filename=zHotkey.exe
  10437. Description=Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features
  10438. Source=Paul Collins Startup list
  10439.  
  10440. [Christmas Music Player]
  10441. Number=1483
  10442. Confirmed=N
  10443. Filename=TTEST6.EXE
  10444. Description=<I>"</I>Christmas Music Player<I> </I>brings the music of the Christmas Holiday to your desktop"
  10445. Source=Paul Collins Startup list
  10446.  
  10447. [ChromeMark]
  10448. Number=1484
  10449. Confirmed=?
  10450. Filename=keysh.exe
  10451. Description=<font color="#FF0000">Related to <a href="http://chromium.com/chromemark.html" target="_blank">this</a>. Don't know what keysh.exe does though and if it's required</font>
  10452. Source=Paul Collins Startup list
  10453.  
  10454. [ChronitelInitTV]
  10455. Number=1485
  10456. Confirmed=?
  10457. Filename=CHTVINIT.EXE
  10458. Description=<font color="#FF0000">??</font>
  10459. Source=Paul Collins Startup list
  10460.  
  10461. [chrono]
  10462. Number=1486
  10463. Confirmed=U
  10464. Filename=chrono.exe
  10465. Description=<a href=http://www.altrixsoft.com/en/chrono/" target="_blank">Chronograph</a> is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)." Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered over
  10466. Source=Paul Collins Startup list
  10467.  
  10468. [CiaBackdoor]
  10469. Number=1487
  10470. Confirmed=X
  10471. Filename=msldr.com
  10472. Description=Added by a VIRUS!
  10473. Source=Paul Collins Startup list
  10474.  
  10475. [cihost.exe]
  10476. Number=1488
  10477. Confirmed=X
  10478. Filename=cihost.exe
  10479. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031918-3320-99" target="_blank">LINST</a> TROJAN!
  10480. Source=Paul Collins Startup list
  10481.  
  10482. [CIJxP2PSERVER]
  10483. Number=1489
  10484. Confirmed=N
  10485. Filename=CIJxP2PS.EXE
  10486. Description=Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7
  10487. Source=Paul Collins Startup list
  10488.  
  10489. [Cisco Systems VPN Client]
  10490. Number=1490
  10491. Confirmed=U
  10492. Filename=ipsecdialer.exe
  10493. Description=Cisco <a href="http://www.cisco.com/en/US/products/sw/secursw/ps2308/" target=_blank>VPN Client</a> - lets local users gain Administrator privileges on the operating system
  10494. Source=Paul Collins Startup list
  10495.  
  10496. [Cisco Systems VPN Client]
  10497. Number=1491
  10498. Confirmed=N
  10499. Filename=vpngui.exe
  10500. Description=Sets up IPSec communications for Cisco's <a href="http://www.cisco.com/en/US/products/sw/secursw/ps2308/" target=_blank>VPN Client</a>
  10501. Source=Paul Collins Startup list
  10502.  
  10503. [CISrvr Program]
  10504. Number=1492
  10505. Confirmed=N
  10506. Filename=CISRVR.EXE
  10507. Description=Related to internet setup on Compaq PC's
  10508. Source=Paul Collins Startup list
  10509.  
  10510. [Cissi]
  10511. Number=1493
  10512. Confirmed=X
  10513. Filename=Cissi.exe
  10514. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-122215-2226-99" target="_blank">CISSI.A</a> WORM!
  10515. Source=Paul Collins Startup list
  10516.  
  10517. [CitiUCS]
  10518. Number=1494
  10519. Confirmed=U
  10520. Filename=CitiUCS.exe
  10521. Description=Citibank <a href="http://www.citibank.com/us/cards/tour/cb/shp_van.htm" target=_blank>Virtual Account Numbers</a> - "With this free service for Citi cardmembers, you never have to give out your real credit card number online"
  10522. Source=Paul Collins Startup list
  10523.  
  10524. [CitiVAN]
  10525. Number=1495
  10526. Confirmed=N
  10527. Filename=CitiVAN.exe
  10528. Description=Option from <a href="http://www.citibank.com/us/d.htm" target="_blank">Citibank</a> to change a credit card number in a random fashion for each purchase. The number will only be used once and never again
  10529. Source=Paul Collins Startup list
  10530.  
  10531. [CJET]
  10532. Number=1496
  10533. Confirmed=X
  10534. Filename=CJet.exe
  10535. Description=Added by the <a href="http://www.sarc.com/avcenter/venc/data/adware.fftoolbar.html" target=_blank>Adware.FFToolBar</a> adware toolbar
  10536. Source=Paul Collins Startup list
  10537.  
  10538. [Cjstcom]
  10539. Number=1497
  10540. Confirmed=Y
  10541. Filename=Cjstcom.exe
  10542. Description=Canon printer BJ status language monitor
  10543. Source=Paul Collins Startup list
  10544.  
  10545. [ClamWin]
  10546. Number=1498
  10547. Confirmed=Y
  10548. Filename=ClamTray.exe
  10549. Description=<a href="http://www.clamwin.com/" target=_blank>ClamWin</a> antivirus
  10550. Source=Paul Collins Startup list
  10551.  
  10552. [Classes]
  10553. Number=1499
  10554. Confirmed=X
  10555. Filename=int1.exe
  10556. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10557. Source=Paul Collins Startup list
  10558.  
  10559. [Classes]
  10560. Number=1500
  10561. Confirmed=X
  10562. Filename=intl.exe
  10563. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10564. Source=Paul Collins Startup list
  10565.  
  10566. [Classes]
  10567. Number=1501
  10568. Confirmed=X
  10569. Filename=run_21.exe
  10570. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10571. Source=Paul Collins Startup list
  10572.  
  10573. [Classes]
  10574. Number=1502
  10575. Confirmed=X
  10576. Filename=srv.exe
  10577. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10578. Source=Paul Collins Startup list
  10579.  
  10580. [Classes]
  10581. Number=1503
  10582. Confirmed=X
  10583. Filename=srv2.exe
  10584. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10585. Source=Paul Collins Startup list
  10586.  
  10587. [Classes]
  10588. Number=1504
  10589. Confirmed=X
  10590. Filename=MSTAR2.EXE
  10591. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10592.  
  10593. Source=Paul Collins Startup list
  10594.  
  10595. [Classes]
  10596. Number=1505
  10597. Confirmed=X
  10598. Filename=mstart.exe
  10599. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialswitchb.html" target=_blank>"Switch"</a> adult content dialler
  10600.  
  10601. Source=Paul Collins Startup list
  10602.  
  10603. [clcbt.exe]
  10604. Number=1506
  10605. Confirmed=X
  10606. Filename=clcbt.exe
  10607. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentcba.html" target="_blank">AGENT.CBA</a> TROJAN!
  10608. Source=Paul Collins Startup list
  10609.  
  10610. [CLCLSet]
  10611. Number=1507
  10612. Confirmed=U
  10613. Filename=CLCL.exe
  10614. Description=CLCL clipboard caching utility
  10615. Source=Paul Collins Startup list
  10616.  
  10617. [CleanEasyImg]
  10618. Number=1508
  10619. Confirmed=?
  10620. Filename=cleanall.exe
  10621. Description=<font color="#FF0000">??</font>
  10622. Source=Paul Collins Startup list
  10623.  
  10624. [CleanRegPath]
  10625. Number=1509
  10626. Confirmed=?
  10627. Filename=CleanReg.exe
  10628. Description=Apparently Annex A ADSL modem related. <font color="#FF0000">What does it do and is it required?</font>
  10629. Source=Paul Collins Startup list
  10630.  
  10631. [CleanSweep Smart Sweep- Internet Sweep]
  10632. Number=1510
  10633. Confirmed=U
  10634. Filename=Csinsm32.exe
  10635. Description=Automatic logging of installs from Norton CleanSweep - available via Start -> Programs
  10636. Source=Paul Collins Startup list
  10637.  
  10638. [CleanSweep Useage Watch]
  10639. Number=1511
  10640. Confirmed=N
  10641. Filename=CSUSEM32.EXE
  10642. Description=Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
  10643. Source=Paul Collins Startup list
  10644.  
  10645. [CleanTemp]
  10646. Number=1512
  10647. Confirmed=U
  10648. Filename=CLEANT~1.EXEB
  10649. Description=<a href="http://www.html2exe.com/mnu/dl/dl.shtml#free" target="_blank">CleanTemp</a> - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
  10650. Source=Paul Collins Startup list
  10651.  
  10652. [CleanTemp]
  10653. Number=1513
  10654. Confirmed=U
  10655. Filename=CleanTemp.exe
  10656. Description=<a href="http://www.html2exe.com/mnu/dl/dl.shtml#free" target="_blank">CleanTemp</a> - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
  10657. Source=Paul Collins Startup list
  10658.  
  10659. [Cleanup]
  10660. Number=1514
  10661. Confirmed=N
  10662. Filename=ONICTASK.EXE
  10663. Description=<a href="http://www.allume.com/mac/cleanup/index.html" target="_blank">Internet Cleanup</a> from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet
  10664. Source=Paul Collins Startup list
  10665.  
  10666. [CleanUp]
  10667. Number=1515
  10668. Confirmed=Y
  10669. Filename=mcappins.exe
  10670. Description=Used by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled
  10671. Source=Paul Collins Startup list
  10672.  
  10673. [CleanupProgram]
  10674. Number=1516
  10675. Confirmed=?
  10676. Filename=cleanup.exe
  10677. Description=<font color="#FF0000">In a C:\Sony\sys folder - Sony Vaio related?</font>
  10678. Source=Paul Collins Startup list
  10679.  
  10680. [clean_service]
  10681. Number=1517
  10682. Confirmed=X
  10683. Filename=clean_service.cmd
  10684. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022711-2043-99" target=_blank>REFAZ</a> WORM!
  10685. Source=Paul Collins Startup list
  10686.  
  10687. [clfmon]
  10688. Number=1518
  10689. Confirmed=X
  10690. Filename=clfmon.exe
  10691. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.E</a> TROJAN!
  10692. Source=Paul Collins Startup list
  10693.  
  10694. [clfmon]
  10695. Number=1519
  10696. Confirmed=X
  10697. Filename=nvsvca32.exe
  10698. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.E</a> TROJAN!
  10699. Source=Paul Collins Startup list
  10700.  
  10701. [clfmon.exe]
  10702. Number=1520
  10703. Confirmed=X
  10704. Filename=clfmon.exe
  10705. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentbj.html" target=_blank>AGENT-BJ</a> TROJAN!
  10706. Source=Paul Collins Startup list
  10707.  
  10708. [Click Radio Tuner]
  10709. Number=1521
  10710. Confirmed=N
  10711. Filename=clickr~1.exe
  10712. Description=<a href="http://www.clickmusic.com/radio/" target="_blank">ClickRadio</a> - subscription service playing radio music via the internet
  10713. Source=Paul Collins Startup list
  10714.  
  10715. [Click Tray Calendar]
  10716. Number=1522
  10717. Confirmed=N
  10718. Filename=ClickT~1.EXE
  10719. Description=<a href="http://www.waseo.de/articles.php?lng=en&pg=34" target="_blank">ClickTray Calendar</a> - shows holidays, reminders of various anniversaries,tasks etc
  10720. Source=Paul Collins Startup list
  10721.  
  10722. [ClickMe]
  10723. Number=1523
  10724. Confirmed=N
  10725. Filename=ClickMe.exe
  10726. Description=<a href="http://www.trendmicro.com/vinfo/jokes/jokesDetails.asp?JNAME=JOKE_CLICKME.A" target=_blank>ClickM</a> "JOKE" program
  10727. Source=Paul Collins Startup list
  10728.  
  10729. [Clickoff]
  10730. Number=1524
  10731. Confirmed=U
  10732. Filename=Clickoff.exe
  10733. Description=<a href="http://www.johanneshuebner.com/en/clickoff.shtml" target="_blank">Clickoff</a> automatically dismisses annoying dialog boxes
  10734. Source=Paul Collins Startup list
  10735.  
  10736. [ClickTheButton]
  10737. Number=1525
  10738. Confirmed=X
  10739. Filename=CTB.EXE
  10740. Description=ClickTheButton <a href="http://vil.nai.com/vil/content/v_126801.htm" target="_blank">Downloader-MY</a> adware
  10741. Source=Paul Collins Startup list
  10742.  
  10743. [ClickTheButton]
  10744. Number=1526
  10745. Confirmed=X
  10746. Filename=csrss.exe
  10747. Description=ClickTheButton <a href="http://vil.nai.com/vil/content/v_126801.htm" target=_blank>Downloader-MY</a> adware! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which should not normally figure in Msconfig/Startup!
  10748. Source=Paul Collins Startup list
  10749.  
  10750. [ClickTheButton]
  10751. Number=1527
  10752. Confirmed=X
  10753. Filename=MSCStat.exe
  10754. Description=ClickTheButton <a href="http://vil.nai.com/vil/content/v_126801.htm" target="_blank">Downloader-MY</a> adware
  10755. Source=Paul Collins Startup list
  10756.  
  10757. [CLICONFG]
  10758. Number=1528
  10759. Confirmed=X
  10760. Filename=CLICONFG.EXE
  10761. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
  10762. Source=Paul Collins Startup list
  10763.  
  10764. [Client Access API Daemon]
  10765. Number=1529
  10766. Confirmed=U
  10767. Filename=cwbappcd.exe
  10768. Description=IBM iSeries Client Access, see <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target=_blank>here</a>
  10769. Source=Paul Collins Startup list
  10770.  
  10771. [Client Access Check Version]
  10772. Number=1530
  10773. Confirmed=N
  10774. Filename=cwbckver.exe
  10775. Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
  10776. Source=Paul Collins Startup list
  10777.  
  10778. [Client Access Express Welcome]
  10779. Number=1531
  10780. Confirmed=?
  10781. Filename=cwbwlwiz.exe
  10782. Description=Welcome wizard launcher - Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. <font color="#FF0000">What does it do and is it required?</font>
  10783. Source=Paul Collins Startup list
  10784.  
  10785. [Client Access Help Update]
  10786. Number=1532
  10787. Confirmed=N
  10788. Filename=cwbinhlp.exe
  10789. Description=Client Access Help Registry Update Function - part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
  10790. Source=Paul Collins Startup list
  10791.  
  10792. [Client Access Service]
  10793. Number=1533
  10794. Confirmed=N
  10795. Filename=CwbSvStr.Exe
  10796. Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
  10797. Source=Paul Collins Startup list
  10798.  
  10799. [Client Access Taskbar]
  10800. Number=1534
  10801. Confirmed=U
  10802. Filename=cwbuitsk.exe
  10803. Description=IBM iSeries Client Access taskbar, see <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target=_blank>here</a>
  10804. Source=Paul Collins Startup list
  10805.  
  10806. [Client Agent]
  10807. Number=1535
  10808. Confirmed=X
  10809. Filename=ipxwping.exe
  10810. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojppdoorn.html" target=_blank>PPDOOR-N</a> TROJAN!
  10811. Source=Paul Collins Startup list
  10812.  
  10813. [Client Agent]
  10814. Number=1536
  10815. Confirmed=X
  10816. Filename=photes.exe
  10817. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojppdoorp.html" target=_blank>PPDOOR-P</a> TROJAN!
  10818. Source=Paul Collins Startup list
  10819.  
  10820. [Client Agent]
  10821. Number=1537
  10822. Confirmed=X
  10823. Filename=[path to file]
  10824. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojppdoorj.html" target="_blank">PPDOOR-J</a> TROJAN!
  10825. Source=Paul Collins Startup list
  10826.  
  10827. [Client agent for ARCserve]
  10828. Number=1538
  10829. Confirmed=?
  10830. Filename=W95AGENT.EXE
  10831. Description=Part of <a href="http://www3.ca.com/Solutions/ProductFamily.asp?ID=115" target="_blank">Brightstor ARCserve Backup</a> from Computer Associates. <font color="#FF0000">What does it do and is it required?</font>
  10832. Source=Paul Collins Startup list
  10833.  
  10834. [Client for Microsoft Networks]
  10835. Number=1539
  10836. Confirmed=X
  10837. Filename=msclient32.exe
  10838. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotbxq.html" target=_blank>SDBOT-BXQ</a> WORM!
  10839. Source=Paul Collins Startup list
  10840.  
  10841. [Client Server Control Process]
  10842. Number=1540
  10843. Confirmed=X
  10844. Filename=[path to trojan]
  10845. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagenthr.html" target=_blank>AGENT-HR</a> TROJAN! 
  10846. Source=Paul Collins Startup list
  10847.  
  10848. [Client Server Run Time Proccess]
  10849. Number=1541
  10850. Confirmed=X
  10851. Filename=csrsrv.exe
  10852. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  10853. Source=Paul Collins Startup list
  10854.  
  10855. [Client Server Runtime]
  10856. Number=1542
  10857. Confirmed=X
  10858. Filename=[path to worm]
  10859. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32poebotkr.html" target="_blank">POEBOT-KR</a> WORM!
  10860. Source=Paul Collins Startup list
  10861.  
  10862. [Client Server Runtime Process]
  10863. Number=1543
  10864. Confirmed=X
  10865. Filename=csrsss.exe
  10866. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotld.html" target=_blank>SDBOT-LD</a> WORM!
  10867. Source=Paul Collins Startup list
  10868.  
  10869. [Client Server Runtime Process]
  10870. Number=1544
  10871. Confirmed=X
  10872. Filename=csrs.exe
  10873. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-052109-2651-99" target=_blank>LINKBOT.M</a> WORM!
  10874. Source=Paul Collins Startup list
  10875.  
  10876. [Client Server Runtime Process]
  10877. Number=1545
  10878. Confirmed=X
  10879. Filename=smmss.exe
  10880. Description=Backdoor TROJAN! Possible <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotgen.html" target=_blank>SDBOT-GEN</a> variant
  10881. Source=Paul Collins Startup list
  10882.  
  10883. [Client Update]
  10884. Number=1546
  10885. Confirmed=X
  10886. Filename=wup.exe
  10887. Description=Added by a variant of the <a href="http://www.sophos.com.au/virusinfo/analyses/w32opankia.html" target=_blank>OPANKI-A</a> WORM!
  10888. Source=Paul Collins Startup list
  10889.  
  10890. [ClientMan1]
  10891. Number=1547
  10892. Confirmed=X
  10893. Filename=mscman.exe
  10894. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClientMan&threatid=3754" target=_blank>ClientMan</a> parasite variant
  10895.  
  10896. Source=Paul Collins Startup list
  10897.  
  10898. [Clik Status Monitor]
  10899. Number=1548
  10900. Confirmed=N
  10901. Filename=toolsclickstat.exe
  10902. Description=Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
  10903. Source=Paul Collins Startup list
  10904.  
  10905. [clipboard.exe]
  10906. Number=1549
  10907. Confirmed=X
  10908. Filename=clipboard.exe
  10909. Description=Added by an unidentified WORM or TROJAN!
  10910. Source=Paul Collins Startup list
  10911.  
  10912. [Clipbook Service]
  10913. Number=1550
  10914. Confirmed=N
  10915. Filename=Clipsrv.exe
  10916. Description=Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
  10917. Source=Paul Collins Startup list
  10918.  
  10919. [ClipMate5x]
  10920. Number=1551
  10921. Confirmed=N
  10922. Filename=ClipMt5x.exe
  10923. Description=<a href="http://www.thornsoft.com/ProductOverview.asp" target="_blank">Clip Mate 5.x</a> by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
  10924. Source=Paul Collins Startup list
  10925.  
  10926. [Clipmate6]
  10927. Number=1552
  10928. Confirmed=N
  10929. Filename=CLIPMT60.EXE
  10930. Description=<a href="http://www.thornsoft.com/new_60.htm" target="_blank">Clip Mate 6</a> by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
  10931. Source=Paul Collins Startup list
  10932.  
  10933. [ClipMate7]
  10934. Number=1553
  10935. Confirmed=N
  10936. Filename=ClipMate.exe
  10937. Description=<a href="http://www.thornsoft.com/" target=_blank>Clip Mate 7</a> by Thornsoft - utility that allows you to store more than one item in the clipboard
  10938.  
  10939. Source=Paul Collins Startup list
  10940.  
  10941. [Clipomatic]
  10942. Number=1554
  10943. Confirmed=N
  10944. Filename=Clipomatic.exe
  10945. Description=Mike Lin's <a href="http://www.mlin.net/Clipomatic.shtml" target="_blank">Clipomatic</a> is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data
  10946. Source=Paul Collins Startup list
  10947.  
  10948. [Clipsrv]
  10949. Number=1555
  10950. Confirmed=N
  10951. Filename=Clipsrv.exe
  10952. Description=Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
  10953. Source=Paul Collins Startup list
  10954.  
  10955. [ClipSrv]
  10956. Number=1556
  10957. Confirmed=X
  10958. Filename=clipserv.exe
  10959. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotaav.html" target=_blank>SDBOT-AAV</a> and <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotafe.html" target=_blank>SDBOT-AFE</a> WORMS!
  10960. Source=Paul Collins Startup list
  10961.  
  10962. [ClipSrv]
  10963. Number=1557
  10964. Confirmed=X
  10965. Filename=CLIPBRD3D.EXE
  10966. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mofeid.html" target=_blank>MOFEI-D</a> WORM!
  10967. Source=Paul Collins Startup list
  10968.  
  10969. [ClipTrak]
  10970. Number=1558
  10971. Confirmed=N
  10972. Filename=ClipTrak.exe
  10973. Description=<a href="http://www.pcmag.com/article2/0,4149,114185,00.asp" target="_blank">ClipTrak</a> - clipboard extender
  10974. Source=Paul Collins Startup list
  10975.  
  10976. [ClipTrakker]
  10977. Number=1559
  10978. Confirmed=N
  10979. Filename=ClipTrakker.exe
  10980. Description=<a href="http://www.cliptrakker.com/" target="_blank">Cliptrakker</a> - clipboard extender
  10981. Source=Paul Collins Startup list
  10982.  
  10983. [CLISTART]
  10984. Number=1560
  10985. Confirmed=N
  10986. Filename=CLIStart.exe
  10987. Description=Puts the ATI CatalystÖ Control Center Icon/Shortcut on the System Tray - available via Start -> Programs
  10988. Source=Paul Collins Startup list
  10989.  
  10990. [CLMFrontPanel]
  10991. Number=1561
  10992. Confirmed=U
  10993. Filename=clmpanel.exe
  10994. Description=System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost
  10995. Source=Paul Collins Startup list
  10996.  
  10997. [clnwall]
  10998. Number=1562
  10999. Confirmed=?
  11000. Filename=rundll.exe setupx.dll, InstallHinfSection ..delwall.inf
  11001. Description=<font color="#FF0000">??</font>
  11002. Source=Paul Collins Startup list
  11003.  
  11004. [clock]
  11005. Number=1563
  11006. Confirmed=X
  11007. Filename=[various filenames]
  11008. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-111715-1438-99" target=_blank>LiveChat</a> Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe
  11009. Source=Paul Collins Startup list
  11010.  
  11011. [Clock Manager]
  11012. Number=1564
  11013. Confirmed=X
  11014. Filename=amsngr.exe
  11015. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsdbotxm.html" target= blank>SDBOT-XM</a> TROJAN!
  11016. Source=Paul Collins Startup list
  11017.  
  11018. [ClockSync]
  11019. Number=1565
  11020. Confirmed=X
  11021. Filename=Sync.exe
  11022. Description=<a href="http://www.clock-sync.com/" target="_blank">ClockSync</a> - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available
  11023. Source=Paul Collins Startup list
  11024.  
  11025. [ClockWise]
  11026. Number=1566
  11027. Confirmed=U
  11028. Filename=CLOCKWISE.EXE
  11029. Description=<a href="http://www.rjsoftware.com/ClockWise/" target="_blank">ClockWise</a> - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync
  11030. Source=Paul Collins Startup list
  11031.  
  11032. [ClocX]
  11033. Number=1567
  11034. Confirmed=U
  11035. Filename=ClocX.exe
  11036. Description=<a href="http://clocx.php5.cz/" target="_blank">ClocX</a> - places a clock on the desktop that can be moved and then changed into a calendar plus you can set alarms etcà
  11037. Source=Paul Collins Startup list
  11038.  
  11039. [CloneCD]
  11040. Number=1568
  11041. Confirmed=U
  11042. Filename=CloneCDTray.exe
  11043. Description=System tray for the now discontinued <a href="http://www.elby.org/products/clone_cd/index.html" target="_blank">CloneCD</a>. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
  11044. Source=Paul Collins Startup list
  11045.  
  11046. [CloneCDElbyCDFL]
  11047. Number=1569
  11048. Confirmed=U
  11049. Filename=ElbyCheck.exe
  11050. Description=From <a href="http://www.elby.org/" target="_blank">Elaborate Bytes</a> who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
  11051. Source=Paul Collins Startup list
  11052.  
  11053. [CloneCDTray]
  11054. Number=1570
  11055. Confirmed=U
  11056. Filename=CloneCDTray.exe
  11057. Description=System tray for the now discontinued <a href="http://www.elby.org/products/clone_cd/index.html" target="_blank">CloneCD</a>. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
  11058. Source=Paul Collins Startup list
  11059.  
  11060. [Clotusorgreg0]
  11061. Number=1571
  11062. Confirmed=?
  11063. Filename=prtStart.exe Orgprt.exe
  11064. Description=IBM Lotus <a href="http://www-142.ibm.com/software/sw-lotus/products/product2.nsf/wdocs/sshome" target="_blank">SmartSuite</a> related. In a LotusOrgReg folder. <font color="#FF0000"> Unclear what exactly it does?</font>
  11065. Source=Paul Collins Startup list
  11066.  
  11067. [Clre]
  11068. Number=1572
  11069. Confirmed=X
  11070. Filename=mmdc.exe
  11071. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpurscanai.html" target=_blank>PURSCAN-AI</a> TROJAN!
  11072. Source=Paul Collins Startup list
  11073.  
  11074. [ClrSchLoader]
  11075. Number=1573
  11076. Confirmed=X
  11077. Filename=[path to file]
  11078. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  11079. Source=Paul Collins Startup list
  11080.  
  11081. [CLSID]
  11082. Number=1574
  11083. Confirmed=X
  11084. Filename=com.exe
  11085. Description=Adult content dialler
  11086. Source=Paul Collins Startup list
  11087.  
  11088. [CLSID]
  11089. Number=1575
  11090. Confirmed=X
  11091. Filename=dll.exe
  11092. Description=Adult content dialler
  11093. Source=Paul Collins Startup list
  11094.  
  11095. [CLSID]
  11096. Number=1576
  11097. Confirmed=X
  11098. Filename=msgplus.exe
  11099. Description=Adult content dialler
  11100. Source=Paul Collins Startup list
  11101.  
  11102. [CLSID]
  11103. Number=1577
  11104. Confirmed=X
  11105. Filename=plugin.exe
  11106. Description=Adult content dialler
  11107. Source=Paul Collins Startup list
  11108.  
  11109. [CLSID]
  11110. Number=1578
  11111. Confirmed=X
  11112. Filename=sed.exe
  11113. Description=Adult content dialler
  11114. Source=Paul Collins Startup list
  11115.  
  11116. [CLSID]
  11117. Number=1579
  11118. Confirmed=X
  11119. Filename=msgplus.exe
  11120. Description=Premium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
  11121.  
  11122. Source=Paul Collins Startup list
  11123.  
  11124. [CLSRSS]
  11125. Number=1580
  11126. Confirmed=X
  11127. Filename=LSACS.EXE
  11128. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sillyfdcx.html" target="_blank">SILLYFDC-X</a> WORM!
  11129. Source=Paul Collins Startup list
  11130.  
  11131. [CM-SmWizard]
  11132. Number=1581
  11133. Confirmed=?
  11134. Filename=SmWizard.exe
  11135. Description=SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. <font color="#FF0000">What does it do and is it required?</font>
  11136. Source=Paul Collins Startup list
  11137.  
  11138. [cma]
  11139. Number=1582
  11140. Confirmed=U
  11141. Filename=cma.exe
  11142. Description=DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
  11143. Source=Paul Collins Startup list
  11144.  
  11145. [CMAPP]
  11146. Number=1583
  11147. Confirmed=X
  11148. Filename=cmappclient.exe
  11149. Description=CasClient adware - also detected as the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-081011-2344-99" target=_blank>CMAPP</a> TROJAN!
  11150. Source=Paul Collins Startup list
  11151.  
  11152. [Cmaudio]
  11153. Number=1584
  11154. Confirmed=N
  11155. Filename=Rundll32 cmicnfg.cpl, CMICtrlWnd
  11156. Description=System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
  11157. Source=Paul Collins Startup list
  11158.  
  11159. [Cmd]
  11160. Number=1585
  11161. Confirmed=X
  11162. Filename=cmd32.exe
  11163. Description=Added by the <a href="http://www.viruslibrary.com/virusinfo/Worm.P2P.Tanked.htm" target="_blank">TANKED</a> WORM!
  11164. Source=Paul Collins Startup list
  11165.  
  11166. [cmd32]
  11167. Number=1586
  11168. Confirmed=X
  11169. Filename=configs.exe
  11170. Description=Hijacker, also detected as the <a href="http://vil.nai.com/vil/content/v_126408.htm" target="_blank">QURL-2</a> TROJAN!
  11171. Source=Paul Collins Startup list
  11172.  
  11173. [cmdbcs]
  11174. Number=1587
  11175. Confirmed=X
  11176. Filename=cmdbcs.exe
  11177. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlineaggkw.html" target="_blank">LINEAG-GKW</a> TROJAN!
  11178. Source=Paul Collins Startup list
  11179.  
  11180. [cmdcon]
  11181. Number=1588
  11182. Confirmed=X
  11183. Filename=cmdcon.exe
  11184. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
  11185. Source=Paul Collins Startup list
  11186.  
  11187. [CME]
  11188. Number=1589
  11189. Confirmed=X
  11190. Filename=cme.exe
  11191. Description=Part of <a href="http://www.thiefware.com/info/data.gator.shtml" target="_blank">Gator</a> advertising spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  11192. Source=Paul Collins Startup list
  11193.  
  11194. [CmeSYS]
  11195. Number=1590
  11196. Confirmed=X
  11197. Filename=CMEsys.exe
  11198. Description=Part of <a href="http://www.thiefware.com/info/data.gator.shtml" target="_blank">Gator</a> advertising spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  11199. Source=Paul Collins Startup list
  11200.  
  11201. [CmeUPD]
  11202. Number=1591
  11203. Confirmed=X
  11204. Filename=CMEupd.exe
  11205. Description=Part of <a href="http://www.thiefware.com/info/data.gator.shtml" target="_blank">Gator</a> advertising spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  11206. Source=Paul Collins Startup list
  11207.  
  11208. [CMFibula]
  11209. Number=1592
  11210. Confirmed=X
  11211. Filename=CMFibula.exe
  11212. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ConsumerAlertSystem.CASClient&threatid=40038" target="_blank">CASClient</a> adware
  11213. Source=Paul Collins Startup list
  11214.  
  11215. [CmFlywaveName]
  11216. Number=1593
  11217. Confirmed=N
  11218. Filename=CmFlywav.exe
  11219. Description=Driver for Linksys <a href="http://www.linksys.com/servlet/Satellite?c=L_Product_C2&childpagename=US%2FLayout&cid=1137451822026&pagename=Linksys%2FCommon%2FVisitorWrapper" target=_blank>Wireless-G Music Bridge</a>
  11220.  
  11221. Source=Paul Collins Startup list
  11222.  
  11223. [CMGrdian]
  11224. Number=1594
  11225. Confirmed=?
  11226. Filename=CMGrdian.exe
  11227. Description=One of the McAfee shared components. <font color="#FF0000"> What does it do and is it required?</font>
  11228. Source=Paul Collins Startup list
  11229.  
  11230. [CMMan]
  11231. Number=1595
  11232. Confirmed=X
  11233. Filename=CMMan.exe
  11234. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-081011-2344-99" target=_blank>CMAPP</a> TROJAN!
  11235. Source=Paul Collins Startup list
  11236.  
  11237. [Cmmon32Sys]
  11238. Number=1596
  11239. Confirmed=X
  11240. Filename=cmmon32.exe
  11241. Description=Added by the SMALL.CL TROJAN!
  11242. Source=Paul Collins Startup list
  11243.  
  11244. [cmonitor]
  11245. Number=1597
  11246. Confirmed=N
  11247. Filename=startupmon.exe
  11248. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-062015-2622-99" target="_blank">SystemDoctor</a> is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  11249. Source=Paul Collins Startup list
  11250.  
  11251. [CmPCIaudio]
  11252. Number=1598
  11253. Confirmed=U
  11254. Filename=RunDll32 CMICNFG3.CPL, CMICtrlWnd
  11255. Description=Registers the Control Panel applet for a C-Media PCI sound card
  11256. Source=Paul Collins Startup list
  11257.  
  11258. [CMPDPSRV]
  11259. Number=1599
  11260. Confirmed=U
  11261. Filename=CMPDPSRV.EXE
  11262. Description=Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more". Installed with some Compaq and Lexmark printers
  11263. Source=Paul Collins Startup list
  11264.  
  11265. [Cmpnt]
  11266. Number=1600
  11267. Confirmed=X
  11268. Filename=Devices2.exe
  11269. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtompaid.html" target=_blank>TOMPAI-D</a> TROJAN!
  11270. Source=Paul Collins Startup list
  11271.  
  11272. [Cmpnt]
  11273. Number=1601
  11274. Confirmed=X
  11275. Filename=mainsv.exe
  11276. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtompaic.html" target=_blank>TOMPAI-C</a> TROJAN!
  11277. Source=Paul Collins Startup list
  11278.  
  11279. [cmrss]
  11280. Number=1602
  11281. Confirmed=X
  11282. Filename=cmrss.exe
  11283. Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&vNav=1&VName=TROJ_DELF.DU&highlight=cmrss" target=_blank>DELF.DU</a> TROJAN!
  11284. Source=Paul Collins Startup list
  11285.  
  11286. [cmrss]
  11287. Number=1603
  11288. Confirmed=X
  11289. Filename=crmss.exe
  11290. Description=Added by the <a href="http://sophos.com.au/virusinfo/analyses/trojdloaderek.html" target= blank>DLOADER-EK</a> TROJAN!
  11291. Source=Paul Collins Startup list
  11292.  
  11293. [cmrss]
  11294. Number=1604
  11295. Confirmed=X
  11296. Filename=[path to trojan]
  11297. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderqq.html" target="_blank">DLOADER-QQ</a> TROJAN!
  11298. Source=Paul Collins Startup list
  11299.  
  11300. [cmrst]
  11301. Number=1605
  11302. Confirmed=X
  11303. Filename=cmrst.exe
  11304. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-032117-2614-99" target=_blank>BANCOS.S</a> TROJAN!
  11305. Source=Paul Collins Startup list
  11306.  
  11307. [cmrst]
  11308. Number=1606
  11309. Confirmed=X
  11310. Filename=cmrst.scr
  11311. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderfp.html" target=_blank>DLOADER-FP</a> TROJAN!
  11312. Source=Paul Collins Startup list
  11313.  
  11314. [cms]
  11315. Number=1607
  11316. Confirmed=X
  11317. Filename=iserver.exe
  11318. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderwk.html" target=_blank>DLOADER-WK</a> TROJAN!
  11319. Source=Paul Collins Startup list
  11320.  
  11321. [CMSETTINGS]
  11322. Number=1608
  11323. Confirmed=U
  11324. Filename=ctmn.exe
  11325. Description=Part of NetNanny <a href="http://www.pcmag.com/article2/0,1759,1265307,00.asp" target="_blank">Chat Monitor</a>
  11326. Source=Paul Collins Startup list
  11327.  
  11328. [cmsound]
  11329. Number=1609
  11330. Confirmed=X
  11331. Filename=vcpdll.exe
  11332. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtcxmedid.html" target=_blank>TCXMEDI-D</a> downloader TROJAN!
  11333. Source=Paul Collins Startup list
  11334.  
  11335. [cmsound]
  11336. Number=1610
  11337. Confirmed=X
  11338. Filename=vcsystem.exe
  11339. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtcxmedid.html" target=_blank>TCXMEDI-D</a> downloader TROJAN!
  11340. Source=Paul Collins Startup list
  11341.  
  11342. [cmss]
  11343. Number=1611
  11344. Confirmed=X
  11345. Filename=system.exe
  11346. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  11347. Source=Paul Collins Startup list
  11348.  
  11349. [cmssapp]
  11350. Number=1612
  11351. Confirmed=X
  11352. Filename=iexplore_.exe
  11353. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbancq.html" target=_blank>BANCBAN-CQ</a> TROJAN!
  11354. Source=Paul Collins Startup list
  11355.  
  11356. [cmssapp]
  11357. Number=1613
  11358. Confirmed=X
  11359. Filename=iexplore.exe
  11360. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbangf.html" target=_blank>BANCBAN-GF</a> TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
  11361. Source=Paul Collins Startup list
  11362.  
  11363. [cmssSystemProcess]
  11364. Number=1614
  11365. Confirmed=X
  11366. Filename=csmss.exe
  11367. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentco.html" target=_blank>AGENT-CO</a> TROJAN! 
  11368.  
  11369. Source=Paul Collins Startup list
  11370.  
  11371. [cmssSystemProcess]
  11372. Number=1615
  11373. Confirmed=X
  11374. Filename=mcsmss.exe
  11375. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.EI&VSect=T" target=_blank>AGENT.EI</a> TROJAN!
  11376. Source=Paul Collins Startup list
  11377.  
  11378. [cmssSystemProcess]
  11379. Number=1616
  11380. Confirmed=X
  11381. Filename=csms.exe
  11382. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagenty.html" target= blank>AGENT-Y</a> TROJAN!
  11383. Source=Paul Collins Startup list
  11384.  
  11385. [CMSystem]
  11386. Number=1617
  11387. Confirmed=X
  11388. Filename=CMSystem.exe
  11389. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ConsumerAlertSystem.CASClient&threatid=40038" target="_blank">CASClient</a> adware
  11390. Source=Paul Collins Startup list
  11391.  
  11392. [cmt101]
  11393. Number=1618
  11394. Confirmed=X
  11395. Filename=cmt101.exe
  11396. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  11397. Source=Paul Collins Startup list
  11398.  
  11399. [CmUCRRun]
  11400. Number=1619
  11401. Confirmed=?
  11402. Filename=CmUCReye.exe
  11403. Description=Related to <a href="http://www.medion.de/" target="_blank">Medion</a> Display Information. <font color="#FF0000">What does it do and is it required?</font>
  11404. Source=Paul Collins Startup list
  11405.  
  11406. [cmx32]
  11407. Number=1620
  11408. Confirmed=X
  11409. Filename=cmx32.exe
  11410. Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=40493" target=_blank>GEMA.D</a> TROJAN!
  11411. Source=Paul Collins Startup list
  11412.  
  11413. [Cn323]
  11414. Number=1621
  11415. Confirmed=X
  11416. Filename=cnfrm33.exe
  11417. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-110414-0646-99" target=_blank>MIMAIL.G</a> WORM!
  11418. Source=Paul Collins Startup list
  11419.  
  11420. [Cn911]
  11421. Number=1622
  11422. Confirmed=X
  11423. Filename=ODBCJET.exe
  11424. Description=Added by the <a href="http://www.sophos.com/security/analyses/trojbifrosepr.html" target="_blank">BIFROSE-PR</a> TROJAN!
  11425. Source=Paul Collins Startup list
  11426.  
  11427. [CNBABE]
  11428. Number=1623
  11429. Confirmed=X
  11430. Filename=CNBABE.EXE
  11431. Description=Appears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing
  11432. Source=Paul Collins Startup list
  11433.  
  11434. [cnet]
  11435. Number=1624
  11436. Confirmed=N
  11437. Filename=kontiki.exe
  11438. Description=<a href="http://www.kontiki.com/products/deliverymanager/index.html" target="_blank">Kontiki Delivery Manager</a> - Windows-based client software that enables secure delivery of content to users' desktops
  11439. Source=Paul Collins Startup list
  11440.  
  11441. [Cnfrm32]
  11442. Number=1625
  11443. Confirmed=X
  11444. Filename=cnfrm.exe
  11445. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-110116-0904-99" target=_blank>MIMAIL.D</a> WORM!
  11446. Source=Paul Collins Startup list
  11447.  
  11448. [CnsMax]
  11449. Number=1626
  11450. Confirmed=X
  11451. Filename=Internat.exe
  11452. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-041814-0556-99" target="_blank">POINTEX</a> TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
  11453. Source=Paul Collins Startup list
  11454.  
  11455. [CnsMin]
  11456. Number=1627
  11457. Confirmed=X
  11458. Filename=Rundll32.exe CNSMIN.DLL, Rundll32
  11459. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=3721%20Chinese%20Keywords%20(CNSMin)&threatid=3678" target=_blank>CnsMin</a> (Chinese Keywords) hijacker related
  11460. Source=Paul Collins Startup list
  11461.  
  11462. [CnxAdslL]
  11463. Number=1628
  11464. Confirmed=Y
  11465. Filename=CnxAdslL.exe
  11466. Description=DLink, Zoom, or Conexant modem driver
  11467. Source=Paul Collins Startup list
  11468.  
  11469. [CnxDslTaskBar]
  11470. Number=1629
  11471. Confirmed=N
  11472. Filename=CnxDslTb.exe
  11473. Description=Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
  11474. Source=Paul Collins Startup list
  11475.  
  11476. [Cobian Backup 8 interface]
  11477. Number=1630
  11478. Confirmed=U
  11479. Filename=cbInterface.exe
  11480. Description="<a href="http://sourceforge.net/projects/cobianbackup" target="_blank">Cobian Backup</a> is a backup program that can be executed in 2 ways: as a normal application or as a Windows Service. The program can schedule automatic backups for files and directories locally or to FTP servers and can use compression and encryption"
  11481. Source=Paul Collins Startup list
  11482.  
  11483. [Codename Dashboard]
  11484. Number=1631
  11485. Confirmed=U
  11486. Filename=dashboard.exe
  11487. Description=<a href="http://www.downlinx.com/proghtml/415/41557.htm" target="_blank">Codename: Dashboard</a> - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time"
  11488. Source=Paul Collins Startup list
  11489.  
  11490. [cof.updit]
  11491. Number=1632
  11492. Confirmed=X
  11493. Filename=[random filename]
  11494. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  11495. Source=Paul Collins Startup list
  11496.  
  11497. [CognizanceTS]
  11498. Number=1633
  11499. Confirmed=U
  11500. Filename=rundll32.exe [path] AsTsVcc.dll, RegisterModule
  11501. Description=Cognizance Corp <a href="http://www.cognizancesecurity.com/products/overview.html" target=_blank>Identity And Access Management</a> suite
  11502.  
  11503. Source=Paul Collins Startup list
  11504.  
  11505. [Coldlife -icmp]
  11506. Number=1634
  11507. Confirmed=X
  11508. Filename=Systray.exe
  11509. Description=Added by the <a href="http://vil.nai.com/vil/content/Print100363.htm" target="_blank">FLOOD.AV</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/systray/" target="_blank">systray.exe</a> process
  11510. Source=Paul Collins Startup list
  11511.  
  11512. [coloreal]
  11513. Number=1635
  11514. Confirmed=U
  11515. Filename=coloreal.exe
  11516. Description=Makes colours sharper and brighter, but will only work with coloreal capable monitors
  11517. Source=Paul Collins Startup list
  11518.  
  11519. [Colorific Control Panel]
  11520. Number=1636
  11521. Confirmed=N
  11522. Filename=Hgcctl95.exe
  11523. Description=From E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor
  11524. Source=Paul Collins Startup list
  11525.  
  11526. [COM Service]
  11527. Number=1637
  11528. Confirmed=X
  11529. Filename=mscom32.com
  11530. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-081408-1248-99" target="_blank">BEASTY.H</a> TROJAN!
  11531. Source=Paul Collins Startup list
  11532.  
  11533. [COM Service]
  11534. Number=1638
  11535. Confirmed=X
  11536. Filename=msynvr.com
  11537. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-073114-1034-99" target="_blank">BEASTY.G</a> TROJAN!
  11538. Source=Paul Collins Startup list
  11539.  
  11540. [COM Service]
  11541. Number=1639
  11542. Confirmed=X
  11543. Filename=msjclh.com
  11544. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-030615-4253-99" target="_blank">BEASTY.E</a> TROJAN!
  11545. Source=Paul Collins Startup list
  11546.  
  11547. [COM Service]
  11548. Number=1640
  11549. Confirmed=X
  11550. Filename=msdrce.com
  11551. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081110-1125-99" target="_blank">BEASTY.I</a> TROJAN!
  11552. Source=Paul Collins Startup list
  11553.  
  11554. [COM Service]
  11555. Number=1641
  11556. Confirmed=X
  11557. Filename=msflyx.com
  11558. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbeastdoo.html" target=_blank>BEASTDO-O</a> TROJAN!
  11559. Source=Paul Collins Startup list
  11560.  
  11561. [COM+ Event System]
  11562. Number=1642
  11563. Confirmed=X
  11564. Filename=DRWTSN16.EXE
  11565. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-021916-4352-99" target="_blank">LOVGATE</a> WORM!
  11566. Source=Paul Collins Startup list
  11567.  
  11568. [COM+ EventSystem Services]
  11569. Number=1643
  11570. Confirmed=X
  11571. Filename=ECSERVER.EXE
  11572. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  11573. Source=Paul Collins Startup list
  11574.  
  11575. [Com+ Sys]
  11576. Number=1644
  11577. Confirmed=X
  11578. Filename=csrs.exe
  11579. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbt.html" target=_blank>FORBOT-BT</a> WORM!
  11580.  
  11581. Source=Paul Collins Startup list
  11582.  
  11583. [COM+ System Applications]
  11584. Number=1645
  11585. Confirmed=X
  11586. Filename=lsas.exe
  11587. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.SE" target=_blank>AGOBOT.SE</a> WORM!
  11588. Source=Paul Collins Startup list
  11589.  
  11590. [COM++ System]
  11591. Number=1646
  11592. Confirmed=X
  11593. Filename=exploier.exe
  11594. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32lovgatef.html" target="_blank">LOVGATE</a> WORM!
  11595. Source=Paul Collins Startup list
  11596.  
  11597. [COM++ System]
  11598. Number=1647
  11599. Confirmed=X
  11600. Filename=suchost.exe
  11601. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32lovgatef.html" target="_blank">LOVGATE</a> WORM!
  11602. Source=Paul Collins Startup list
  11603.  
  11604. [COM++ System]
  11605. Number=1648
  11606. Confirmed=X
  11607. Filename=svchost.exe...
  11608. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32lovgatef.html" target="_blank">LOVGATE</a> WORM!
  11609. Source=Paul Collins Startup list
  11610.  
  11611. [COM-IP]
  11612. Number=1649
  11613. Confirmed=N
  11614. Filename=COMIP.EXE
  11615. Description=COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
  11616. Source=Paul Collins Startup list
  11617.  
  11618. [ComAgent]
  11619. Number=1650
  11620. Confirmed=U
  11621. Filename=ComAgent.exe
  11622. Description=ComAgent - <a href="http://www.altn.com/products/default.asp?product_id=MDaemon" target=_blank>MDaemon's</a> instant messaging client
  11623. Source=Paul Collins Startup list
  11624.  
  11625. [combo.exe]
  11626. Number=1651
  11627. Confirmed=X
  11628. Filename=combo.exe
  11629. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojchimoc.html" target=_blank>CHIMO-C</a> TROJAN!
  11630. Source=Paul Collins Startup list
  11631.  
  11632. [combop.exe]
  11633. Number=1652
  11634. Confirmed=X
  11635. Filename=combop.exe
  11636. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbowfeeda.html" target=_blank>BOWFEED-A</a> TROJAN!
  11637. Source=Paul Collins Startup list
  11638.  
  11639. [Comcast Network]
  11640. Number=1653
  11641. Confirmed=X
  11642. Filename=ribiva.exe
  11643. Description=Added by an <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031015-3147-99" target= blank>IRC TROJAN</a> variant!
  11644. Source=Paul Collins Startup list
  11645.  
  11646. [ComcastSUPPORT]
  11647. Number=1654
  11648. Confirmed=X
  11649. Filename=tgkill.exe
  11650. Description=Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
  11651. Source=Paul Collins Startup list
  11652.  
  11653. [COMCFG]
  11654. Number=1655
  11655. Confirmed=X
  11656. Filename=comcfg.exe
  11657. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_TOADCOM.A" target="_blank">TOADCOM.A</a> TROJAN!
  11658. Source=Paul Collins Startup list
  11659.  
  11660. [comctl32]
  11661. Number=1656
  11662. Confirmed=X
  11663. Filename=comctl32.exe
  11664. Description=Adware - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as TrojanDownloader.Win32.Agent.am
  11665. Source=Paul Collins Startup list
  11666.  
  11667. [COMDRV32]
  11668. Number=1657
  11669. Confirmed=U
  11670. Filename=svdhost.exe
  11671. Description=<a href="http://www.protectcom.com/" target="_blank">Orvell Monitoring 2003</a> surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/
  11672. Source=Paul Collins Startup list
  11673.  
  11674. [Comm Driver]
  11675. Number=1658
  11676. Confirmed=U
  11677. Filename=commh32.exe
  11678. Description=G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see <a href="http://archiv.chip.de/artikel/c1_archiv_artikel_17080599.html" target="_blank">here</a>. Disable/remove if you didn't install it yourself!
  11679. Source=Paul Collins Startup list
  11680.  
  11681. [Command]
  11682. Number=1659
  11683. Confirmed=X
  11684. Filename=system.exe
  11685. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_GATECRASH.A" target="_blank">GATECRASH.A</a> or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_GATECRASH.B" target="_blank">GATECRASH.B</a> TROJANS!
  11686.  
  11687. Source=Paul Collins Startup list
  11688.  
  11689. [Command]
  11690. Number=1660
  11691. Confirmed=X
  11692. Filename=Gotit.exe
  11693. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-121712-0428-99" target="_blank">TITOG</a> WORM!
  11694. Source=Paul Collins Startup list
  11695.  
  11696. [COMMAND]
  11697. Number=1661
  11698. Confirmed=X
  11699. Filename=command.exe
  11700. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092815-0339-99" target="_blank">QQPASS.E</a> TROJAN!
  11701. Source=Paul Collins Startup list
  11702.  
  11703. [command]
  11704. Number=1662
  11705. Confirmed=X
  11706. Filename=javaw.exe
  11707. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotlg.html" target=_blank>AGOBOT-LG</a> WORM!
  11708. Source=Paul Collins Startup list
  11709.  
  11710. [Command Prompt32]
  11711. Number=1663
  11712. Confirmed=X
  11713. Filename=CmdPrompt32.pif
  11714. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030222-1459-99" target=_blank>ASSIRAL.B</a> WORM!
  11715. Source=Paul Collins Startup list
  11716.  
  11717. [command32]
  11718. Number=1664
  11719. Confirmed=X
  11720. Filename=command32.exe
  11721. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlineadla.html" target=_blank>LINEADI-A</a> TROJAN!
  11722. Source=Paul Collins Startup list
  11723.  
  11724. [CommCtr]
  11725. Number=1665
  11726. Confirmed=N
  11727. Filename=commctr.exe
  11728. Description="<a href="http://web.net2phone.com/consumer/commcenter/" target="_blank">Net2Phone CommCenter</a> is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available via Start -> Programs
  11729. Source=Paul Collins Startup list
  11730.  
  11731. [Comodo Firewall]
  11732. Number=1666
  11733. Confirmed=U
  11734. Filename=CPF.exe
  11735. Description=<a href="http://www.personalfirewall.comodo.com/" target="_blank">Comodo Firewall</a>
  11736. Source=Paul Collins Startup list
  11737.  
  11738. [CompanionWizard]
  11739. Number=1667
  11740. Confirmed=N
  11741. Filename=compwiz.exe
  11742. Description=WinAntiVirus 2006 virus software - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  11743. Source=Paul Collins Startup list
  11744.  
  11745. [Compaq Alerter]
  11746. Number=1668
  11747. Confirmed=U
  11748. Filename=CPQAlert.exe
  11749. Description=Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See <a href="http://h18000.www1.hp.com/products/servers/management/cim-description.html" target="_blank">here</a> for more information
  11750. Source=Paul Collins Startup list
  11751.  
  11752. [Compaq Computer Corp SCCenter Module]
  11753. Number=1669
  11754. Confirmed=N
  11755. Filename=SCCENTER.EXE
  11756. Description=For Compaq PC's. Part of Backweb
  11757. Source=Paul Collins Startup list
  11758.  
  11759. [Compaq Computer Security]
  11760. Number=1670
  11761. Confirmed=?
  11762. Filename=Rundll32.exe SECURE32.CPL, Service
  11763. Description=<font color="#FF0000">??</font>
  11764. Source=Paul Collins Startup list
  11765.  
  11766. [Compaq Connections]
  11767. Number=1671
  11768. Confirmed=N
  11769. Filename=COMPAQ~1.EXE
  11770. Description=See <a href="http://h10025.www1.hp.com/ewfrf/wc/genericDocument?cc=us&docname=bph05170&lc=en&jumpid=reg_R1002_USEN#bph05170_G5" target="_blank">here</a> - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners"
  11771. Source=Paul Collins Startup list
  11772.  
  11773. [Compaq Connections]
  11774. Number=1672
  11775. Confirmed=N
  11776. Filename=BackWeb-1940576.exe
  11777. Description=See <a href="http://h10025.www1.hp.com/ewfrf/wc/genericDocument?cc=us&docname=bph05170&lc=en&jumpid=reg_R1002_USEN#bph05170_G5" target="_blank">here</a> - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners". * can be any digit
  11778. Source=Paul Collins Startup list
  11779.  
  11780. [Compaq DMI]
  11781. Number=1673
  11782. Confirmed=N
  11783. Filename=cpqdmi.exe
  11784. Description=Compaq version of the Desktop Management Interface
  11785. Source=Paul Collins Startup list
  11786.  
  11787. [Compaq Drivers]
  11788. Number=1674
  11789. Confirmed=X
  11790. Filename=F1rewalls.exe
  11791. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotwd.html" target= blank>SDBOT-WD</a> WORM!
  11792. Source=Paul Collins Startup list
  11793.  
  11794. [Compaq Internet Setup]
  11795. Number=1675
  11796. Confirmed=N
  11797. Filename=inetwizard.exe
  11798. Description=For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
  11799. Source=Paul Collins Startup list
  11800.  
  11801. [Compaq Jes Drivers]
  11802. Number=1676
  11803. Confirmed=X
  11804. Filename=winjes.exe
  11805. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxr.html" target= blank>SDBOT-XR</a> WORM!
  11806. Source=Paul Collins Startup list
  11807.  
  11808. [Compaq Knowledge Center]
  11809. Number=1677
  11810. Confirmed=U
  11811. Filename=silent.exe & matcli.exe
  11812. Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide
  11813. Source=Paul Collins Startup list
  11814.  
  11815. [Compaq Message Server]
  11816. Number=1678
  11817. Confirmed=N
  11818. Filename=COMPAQ-RBA.EXE
  11819. Description=Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the "advanced" tab. Not required and can cause problems
  11820. Source=Paul Collins Startup list
  11821.  
  11822. [Compaq PK Daemon]
  11823. Number=1679
  11824. Confirmed=U
  11825. Filename=cpqkl.exe
  11826. Description=For Compaq laptops for programming user configurable keys. Not required unless you use them
  11827. Source=Paul Collins Startup list
  11828.  
  11829. [Compaq Print Fax]
  11830. Number=1680
  11831. Confirmed=X
  11832. Filename=cpqa1000.exe
  11833. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BCV&VSect=T" target=_blank>SDBOT.BCV</a> WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm
  11834. Source=Paul Collins Startup list
  11835.  
  11836. [Compaq Service Drivers]
  11837. Number=1681
  11838. Confirmed=X
  11839. Filename=systeminfos.exe
  11840. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxc.html" target=_blank>SDBOT-XC</a> WORM!
  11841. Source=Paul Collins Startup list
  11842.  
  11843. [Compaq Service Drivers]
  11844. Number=1682
  11845. Confirmed=X
  11846. Filename=compq.exe
  11847. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  11848. Source=Paul Collins Startup list
  11849.  
  11850. [Compaq Service Drivers]
  11851. Number=1683
  11852. Confirmed=X
  11853. Filename=navapqwa.exe
  11854. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BBQ&VSect=T" target=_blank>SDBOT.BBQ</a> WORM!
  11855. Source=Paul Collins Startup list
  11856.  
  11857. [Compaq Service Drivers]
  11858. Number=1684
  11859. Confirmed=X
  11860. Filename=amsn.exe
  11861. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  11862. Source=Paul Collins Startup list
  11863.  
  11864. [Compaq Service Drivers]
  11865. Number=1685
  11866. Confirmed=X
  11867. Filename=compqs.exe
  11868. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  11869. Source=Paul Collins Startup list
  11870.  
  11871. [Compaq Service Drivers]
  11872. Number=1686
  11873. Confirmed=X
  11874. Filename=msnt.exe
  11875. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.CQL&VSect=T" target=_blank>SDBOT.CQL</a> WORM!
  11876. Source=Paul Collins Startup list
  11877.  
  11878. [Compaq Service Drivers]
  11879. Number=1687
  11880. Confirmed=X
  11881. Filename=NtKernelSystem.exe
  11882. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  11883. Source=Paul Collins Startup list
  11884.  
  11885. [Compaq Service Drivers]
  11886. Number=1688
  11887. Confirmed=X
  11888. Filename=wincmd.exe
  11889. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ATV&VSect=P" target=_blank>RBOT.ATV</a> WORM!
  11890. Source=Paul Collins Startup list
  11891.  
  11892. [Compaq Service Drivers]
  11893. Number=1689
  11894. Confirmed=X
  11895. Filename=wind32.exe
  11896. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  11897. Source=Paul Collins Startup list
  11898.  
  11899. [Compaq Service Drivers]
  11900. Number=1690
  11901. Confirmed=X
  11902. Filename=winmsn.exe
  11903. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  11904. Source=Paul Collins Startup list
  11905.  
  11906. [Compaq Service Drivers]
  11907. Number=1691
  11908. Confirmed=X
  11909. Filename=compaq.exe
  11910. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotafu.html" target=_blank>SDBOT-AFU</a> WORM!
  11911. Source=Paul Collins Startup list
  11912.  
  11913. [Compaq Service Drivers]
  11914. Number=1692
  11915. Confirmed=X
  11916. Filename=msnsvc.exe
  11917. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BKT&VSect=T" target=_blank>RBOT.BKT</a> WORM!
  11918. Source=Paul Collins Startup list
  11919.  
  11920. [Compaq Service Drivers]
  11921. Number=1693
  11922. Confirmed=X
  11923. Filename=ntsys32.exe
  11924. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CIW&VSect=T" target=_blank>RBOT.CIW</a> WORM!
  11925. Source=Paul Collins Startup list
  11926.  
  11927. [Compaq Service Drivers]
  11928. Number=1694
  11929. Confirmed=X
  11930. Filename=winsvc.exe
  11931. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotagd.html" target="_blank">SDBOT-AGD</a> WORM!
  11932. Source=Paul Collins Startup list
  11933.  
  11934. [Compaq Service Drivers 32]
  11935. Number=1695
  11936. Confirmed=X
  11937. Filename=compq32.exe
  11938. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  11939. Source=Paul Collins Startup list
  11940.  
  11941. [Compaq Service Drivrs]
  11942. Number=1696
  11943. Confirmed=X
  11944. Filename=copq.exe
  11945. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target= blank>RBOT</a> WORM!
  11946. Source=Paul Collins Startup list
  11947.  
  11948. [Compaq Services Drivers]
  11949. Number=1697
  11950. Confirmed=X
  11951. Filename=ndt32.exe
  11952. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CQZ&VSect=T" target=_blank>RBOT.CQZ</a> WORM!
  11953. Source=Paul Collins Startup list
  11954.  
  11955. [Compaq Sound Drivers For WINDOWS]
  11956. Number=1698
  11957. Confirmed=X
  11958. Filename=sounddr.exe
  11959. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxg.html" target=_blank>SDBOT-XG</a> WORM!
  11960. Source=Paul Collins Startup list
  11961.  
  11962. [Compaq Video CD Watcher]
  11963. Number=1699
  11964. Confirmed=N
  11965. Filename=??
  11966. Description=For Compaq PC's. MPEG viewer
  11967. Source=Paul Collins Startup list
  11968.  
  11969. [Compaq32 Service Drivers]
  11970. Number=1700
  11971. Confirmed=X
  11972. Filename=ms32.exe
  11973. Description=Added by the <a href="http://bg.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&vNav=3&VName=WORM_SDBOT.BWH" target=_blank>SDBOT.BWH</a> WORM!
  11974. Source=Paul Collins Startup list
  11975.  
  11976. [Compaq32 Service Drivers]
  11977. Number=1701
  11978. Confirmed=X
  11979. Filename=msconfig32.exe
  11980. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotadc.html" target=_blank>SDBOT-ADC</a> WORM!
  11981. Source=Paul Collins Startup list
  11982.  
  11983. [Compaq32 Service Drivers]
  11984. Number=1702
  11985. Confirmed=X
  11986. Filename=msnt32.exe
  11987. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BVF&VSect=T" target=_blank>RBOT.BVF</a> WORM!
  11988. Source=Paul Collins Startup list
  11989.  
  11990. [CompaqHW Comp Manager]
  11991. Number=1703
  11992. Confirmed=?
  11993. Filename=cpqhcm.exe
  11994. Description=<font color="#FF0000">Running on a Compaq laptop - any ideas?</font>
  11995. Source=Paul Collins Startup list
  11996.  
  11997. [CompaqPrinTray]
  11998. Number=1704
  11999. Confirmed=N
  12000. Filename=printray.exe
  12001. Description=Puts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
  12002. Source=Paul Collins Startup list
  12003.  
  12004. [Compaqs Service Driver]
  12005. Number=1705
  12006. Confirmed=X
  12007. Filename=copypad32.exe
  12008. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.CSO&VSect=T" target=_blank>SDBOT.CSO</a> WORM!
  12009. Source=Paul Collins Startup list
  12010.  
  12011. [Compaqs Service Drivers]
  12012. Number=1706
  12013. Confirmed=X
  12014. Filename=compqs.exe
  12015. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  12016. Source=Paul Collins Startup list
  12017.  
  12018. [CompaqSystray]
  12019. Number=1707
  12020. Confirmed=N
  12021. Filename=cpqpscp.exe
  12022. Description=Compaq System Tray icon
  12023. Source=Paul Collins Startup list
  12024.  
  12025. [Compatibility Service Process]
  12026. Number=1708
  12027. Confirmed=X
  12028. Filename=regsvs.exe
  12029. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040817-5940-99" target="_blank">GAOBOT.YN</a> WORM!
  12030. Source=Paul Collins Startup list
  12031.  
  12032. [Compd Service Drivrs]
  12033. Number=1709
  12034. Confirmed=X
  12035. Filename=codq.exe
  12036. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  12037. Source=Paul Collins Startup list
  12038.  
  12039. [ComproRemote]
  12040. Number=1710
  12041. Confirmed=U
  12042. Filename=ComproRemote.exe
  12043. Description=<a href="http://www.comprousa.com/New/en/home.html" target=_blank>VideoMate</a> TV tuner and capture card - remote control driver
  12044.  
  12045. Source=Paul Collins Startup list
  12046.  
  12047. [ComproSchedulerDTV]
  12048. Number=1711
  12049. Confirmed=U
  12050. Filename=ComproSchedulerDTV.exe
  12051. Description=<a href="http://www.comprousa.com/New/en/home.html" target=_blank>VideoMate</a> TV tuner and capture card - scheduler
  12052.  
  12053. Source=Paul Collins Startup list
  12054.  
  12055. [Computing Technologie Firewall]
  12056. Number=1712
  12057. Confirmed=X
  12058. Filename=lsauth.exe
  12059. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotwx.html" target= blank>SDBOT-WX</a> WORM!
  12060. Source=Paul Collins Startup list
  12061.  
  12062. [COMSMDEXE]
  12063. Number=1713
  12064. Confirmed=N
  12065. Filename=comsmd.exe
  12066. Description=3Com tray icon
  12067. Source=Paul Collins Startup list
  12068.  
  12069. [ComStart]
  12070. Number=1714
  12071. Confirmed=N
  12072. Filename=Trojan Guarder.exe
  12073. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-071914-2557-99" target="_blank">TrojanGuarder</a> is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  12074. Source=Paul Collins Startup list
  12075.  
  12076. [ComTry Web Searcher]
  12077. Number=1715
  12078. Confirmed=X
  12079. Filename=wstray.exe
  12080. Description=Comtry MP3 Downloader related - spyware
  12081. Source=Paul Collins Startup list
  12082.  
  12083. [comxt]
  12084. Number=1716
  12085. Confirmed=X
  12086. Filename=comxt.exe
  12087. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100710-2042-99" target="_blank">COMXT</a> TROJAN!
  12088. Source=Paul Collins Startup list
  12089.  
  12090. [con]
  12091. Number=1717
  12092. Confirmed=X
  12093. Filename=[path to trojan]
  12094. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbravea.html" target=_blank>BRAVE-A</a> TROJAN!
  12095.  
  12096. Source=Paul Collins Startup list
  12097.  
  12098. [Config]
  12099. Number=1718
  12100. Confirmed=X
  12101. Filename=service.exe
  12102. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092311-3948-99" target="_blank">ISRAZ.B</a> WORM!
  12103. Source=Paul Collins Startup list
  12104.  
  12105. [Config Loadation]
  12106. Number=1719
  12107. Confirmed=X
  12108. Filename=iEEexplore.exe
  12109. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-041721-2428-99" target="_blank">SDBOT.H</a> TROJAN!
  12110. Source=Paul Collins Startup list
  12111.  
  12112. [Config Loadatiorin]
  12113. Number=1720
  12114. Confirmed=X
  12115. Filename=I3Explorer.exe
  12116. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-041721-2428-99" target="_blank">SDBOT.H</a> TROJAN!
  12117. Source=Paul Collins Startup list
  12118.  
  12119. [Config Loader]
  12120. Number=1721
  12121. Confirmed=X
  12122. Filename=svchosl.exe
  12123. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-040409-1043-99" target="_blank">GAOBOT.P</a> WORM!
  12124. Source=Paul Collins Startup list
  12125.  
  12126. [Config Loader]
  12127. Number=1722
  12128. Confirmed=X
  12129. Filename=sysldr32.exe
  12130. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-102419-1801-99" target="_blank">GAOBOT</a> WORM!
  12131. Source=Paul Collins Startup list
  12132.  
  12133. [Config Loader]
  12134. Number=1723
  12135. Confirmed=X
  12136. Filename=scvhost.exe
  12137. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091111-5223-99" target="_blank">GAOBOT.AE</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORMS!
  12138. Source=Paul Collins Startup list
  12139.  
  12140. [Config Loader]
  12141. Number=1724
  12142. Confirmed=X
  12143. Filename=svhost.exe
  12144. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target="_blank">AGOBOT/GAOBOT</a> WORM!
  12145. Source=Paul Collins Startup list
  12146.  
  12147. [Config Loader for Microsoft Windows]
  12148. Number=1725
  12149. Confirmed=X
  12150. Filename=mwincfg32.exe
  12151. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.BD" target="_blank">AGOBOT.BD</a> WORM!
  12152. Source=Paul Collins Startup list
  12153.  
  12154. [Config Loader2]
  12155. Number=1726
  12156. Confirmed=X
  12157. Filename=explores.exe
  12158. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-103111-3854-99" target="_blank">GAOBOT.BT</a> WORM!
  12159. Source=Paul Collins Startup list
  12160.  
  12161. [Config Loadr]
  12162. Number=1727
  12163. Confirmed=X
  12164. Filename=winsys32.exe
  12165. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobothn.html" target=_blank>AGOBOT-HN</a> WORM!
  12166. Source=Paul Collins Startup list
  12167.  
  12168. [Config33.exe]
  12169. Number=1728
  12170. Confirmed=X
  12171. Filename=Config33.exe
  12172. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.T" target=_blank>SDBOT.T</a> TROJAN!
  12173.  
  12174. Source=Paul Collins Startup list
  12175.  
  12176. [ConfiggLoader]
  12177. Number=1729
  12178. Confirmed=X
  12179. Filename=cart322.exe
  12180. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-112612-5132-99" target="_blank">GAOBOT.DJ</a> WORM!
  12181. Source=Paul Collins Startup list
  12182.  
  12183. [ConfigSafe]
  12184. Number=1730
  12185. Confirmed=U
  12186. Filename=CFGSAFE.EXE
  12187. Description=<a href="http://www.imaginelan.com/configsafe/index.html" target="_blank">ConfigSafe</a> - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
  12188. Source=Paul Collins Startup list
  12189.  
  12190. [ConfigSafe]
  12191. Number=1731
  12192. Confirmed=U
  12193. Filename=AUTOCHK.EXE
  12194. Description=<a href="http://www.imaginelan.com/configsafe/index.html" target="_blank">ConfigSafe</a> - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
  12195. Source=Paul Collins Startup list
  12196.  
  12197. [ConfigServices]
  12198. Number=1732
  12199. Confirmed=N
  12200. Filename=Config.exe
  12201. Description=Part of initial setup on a Compaq PC
  12202. Source=Paul Collins Startup list
  12203.  
  12204. [configsetup]
  12205. Number=1733
  12206. Confirmed=X
  12207. Filename=configsetup32.exe
  12208. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotafp.html" target=_blank>AGOBOT-AFP</a> WORM!
  12209. Source=Paul Collins Startup list
  12210.  
  12211. [Configuration]
  12212. Number=1734
  12213. Confirmed=X
  12214. Filename=explorer32.exe
  12215. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotml.html" target="_blank">SDBOT-ML</a> WORM!
  12216. Source=Paul Collins Startup list
  12217.  
  12218. [Configuration]
  12219. Number=1735
  12220. Confirmed=X
  12221. Filename=[filename]
  12222. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotml.html" target=_blank>SDBOT-ML</a> WORM!
  12223.  
  12224. Source=Paul Collins Startup list
  12225.  
  12226. [configuration]
  12227. Number=1736
  12228. Confirmed=X
  12229. Filename=apphost.exe
  12230. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotvp.html" target= blank>SDBOT-VP</a> WORM!
  12231. Source=Paul Collins Startup list
  12232.  
  12233. [Configuration]
  12234. Number=1737
  12235. Confirmed=X
  12236. Filename=ntsys32.exe
  12237. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotln.html" target= blank>SDBOT-LN</a> WORM!
  12238. Source=Paul Collins Startup list
  12239.  
  12240. [Configuration Default]
  12241. Number=1738
  12242. Confirmed=X
  12243. Filename=Wuxat.exe
  12244. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotca.html" target=_blank>SPYBOT-CA</a> WORM!
  12245.  
  12246. Source=Paul Collins Startup list
  12247.  
  12248. [Configuration File]
  12249. Number=1739
  12250. Confirmed=X
  12251. Filename=Winset32.exe
  12252. Description=Added by the FLUX.101 TROJAN!
  12253.  
  12254. Source=Paul Collins Startup list
  12255.  
  12256. [Configuration Loaded]
  12257. Number=1740
  12258. Confirmed=X
  12259. Filename=wupdated.exe
  12260. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080813-3234-99" target="_blank">MOEGA</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021013-3329-99" target="_blank">MOEGA.AG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-022818-2915-99" target="_blank">MOEGA.AP</a> WORMS!
  12261. Source=Paul Collins Startup list
  12262.  
  12263. [Configuration Loaded]
  12264. Number=1741
  12265. Confirmed=X
  12266. Filename=lssas.exe
  12267. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe</a> process
  12268. Source=Paul Collins Startup list
  12269.  
  12270. [Configuration Loader]
  12271. Number=1742
  12272. Confirmed=X
  12273. Filename=aim95.exe
  12274. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJANS!
  12275. Source=Paul Collins Startup list
  12276.  
  12277. [Configuration Loader]
  12278. Number=1743
  12279. Confirmed=X
  12280. Filename=cmd32.exe
  12281. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJANS!
  12282. Source=Paul Collins Startup list
  12283.  
  12284. [Configuration Loader]
  12285. Number=1744
  12286. Confirmed=X
  12287. Filename=service5.exe
  12288. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091710-1153-99" target="_blank">GAOBOT.AF</a> WORM!
  12289. Source=Paul Collins Startup list
  12290.  
  12291. [Configuration Loader]
  12292. Number=1745
  12293. Confirmed=?
  12294. Filename=lfass.exe
  12295. Description=<font color="#FF0000">??</font>
  12296. Source=Paul Collins Startup list
  12297.  
  12298. [Configuration Loader]
  12299. Number=1746
  12300. Confirmed=X
  12301. Filename=sycfg34.exe
  12302. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092916-3339-99" target="_blank">GAOBOT.AN</a> WORM!
  12303. Source=Paul Collins Startup list
  12304.  
  12305. [Configuration Loader]
  12306. Number=1747
  12307. Confirmed=X
  12308. Filename=wincrt32.exe
  12309. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102714-0859-99" target="_blank">GAOBOT.BF</a> WORM!
  12310. Source=Paul Collins Startup list
  12311.  
  12312. [Configuration Loader]
  12313. Number=1748
  12314. Confirmed=X
  12315. Filename=windex.exe
  12316. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-110115-4341-99" target="_blank">GAOBOT.BZ</a> WORM!
  12317. Source=Paul Collins Startup list
  12318.  
  12319. [Configuration Loader]
  12320. Number=1749
  12321. Confirmed=X
  12322. Filename=dosrun32.exe
  12323. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  12324. Source=Paul Collins Startup list
  12325.  
  12326. [Configuration Loader]
  12327. Number=1750
  12328. Confirmed=X
  12329. Filename=Service.exe
  12330. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  12331. Source=Paul Collins Startup list
  12332.  
  12333. [Configuration Loader]
  12334. Number=1751
  12335. Confirmed=X
  12336. Filename=Servicess.exe
  12337. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  12338. Source=Paul Collins Startup list
  12339.  
  12340. [Configuration Loader]
  12341. Number=1752
  12342. Confirmed=X
  12343. Filename=sw32.exe
  12344. Description=Added by the <a href="http://es.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&VName=WORM_AGOBOT.BQ" target="_blank">AGOBOT.BQ</a> WORM!
  12345. Source=Paul Collins Startup list
  12346.  
  12347. [Configuration Loader]
  12348. Number=1753
  12349. Confirmed=X
  12350. Filename=System.exe
  12351. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  12352. Source=Paul Collins Startup list
  12353.  
  12354. [Configuration Loader]
  12355. Number=1754
  12356. Confirmed=X
  12357. Filename=Winreg.exe
  12358. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  12359. Source=Paul Collins Startup list
  12360.  
  12361. [Configuration Loader]
  12362. Number=1755
  12363. Confirmed=X
  12364. Filename=sysinfo.exe
  12365. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-011214-4249-99" target="_blank">GAOBOT.FQ</a> WORM!
  12366.  
  12367. Source=Paul Collins Startup list
  12368.  
  12369. [Configuration Loader]
  12370. Number=1756
  12371. Confirmed=X
  12372. Filename=microsoft.exe
  12373. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-020416-5105-99" target="_blank">GAOBOT.JB</a> WORM!
  12374. Source=Paul Collins Startup list
  12375.  
  12376. [Configuration Loader]
  12377. Number=1757
  12378. Confirmed=X
  12379. Filename=confgldr.exe
  12380. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031915-3501-99" target="_blank">GAOBOT.GEN!POLY</a> WORM!
  12381. Source=Paul Collins Startup list
  12382.  
  12383. [configuration loader]
  12384. Number=1758
  12385. Confirmed=X
  12386. Filename=winicfg32.exe
  12387. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-032013-3449-99" target="_blank">GAOBOT.RQ</a> WORM!
  12388. Source=Paul Collins Startup list
  12389.  
  12390. [Configuration Loader]
  12391. Number=1759
  12392. Confirmed=X
  12393. Filename=svhst.exe
  12394. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040717-1139-99" target="_blank">GAOBOT.YC</a> WORM!
  12395. Source=Paul Collins Startup list
  12396.  
  12397. [Configuration Loader]
  12398. Number=1760
  12399. Confirmed=X
  12400. Filename=msgfix.exe
  12401. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-062910-1433-99" target="_blank">GAOBOT.AUS</a> or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.J" target="_blank">SDBOT.J</a> or <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotqg.html" target=_blank>SDBOT-QG</a> WORMS!
  12402. Source=Paul Collins Startup list
  12403.  
  12404. [Configuration Loader]
  12405. Number=1761
  12406. Confirmed=X
  12407. Filename=msnss.exe
  12408. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-062910-1433-99" target="_blank">GAOBOT.AUS</a> WORM!
  12409. Source=Paul Collins Startup list
  12410.  
  12411. [Configuration Loader]
  12412. Number=1762
  12413. Confirmed=X
  12414. Filename=IEXPL0RE.EXE
  12415. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJANS!
  12416. Source=Paul Collins Startup list
  12417.  
  12418. [Configuration Loader]
  12419. Number=1763
  12420. Confirmed=X
  12421. Filename=loadcfg32.exe
  12422. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJANS!
  12423. Source=Paul Collins Startup list
  12424.  
  12425. [Configuration Loader]
  12426. Number=1764
  12427. Confirmed=X
  12428. Filename=MSTasks.exe
  12429. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJANS!
  12430. Source=Paul Collins Startup list
  12431.  
  12432. [Configuration Loader]
  12433. Number=1765
  12434. Confirmed=X
  12435. Filename=systemry.exe
  12436. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
  12437. Source=Paul Collins Startup list
  12438.  
  12439. [Configuration Loader]
  12440. Number=1766
  12441. Confirmed=X
  12442. Filename=ccSort.exe
  12443. Description=Added by the <a href="http://uk.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=WORM_AGOBOT.SR" target=_blank>AGOBOT.SR</a> WORM!
  12444. Source=Paul Collins Startup list
  12445.  
  12446. [Configuration Loader]
  12447. Number=1767
  12448. Confirmed=X
  12449. Filename=smss32.exe
  12450. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.MB" target=_blank>AGOBOT.MB</a> WORM!
  12451. Source=Paul Collins Startup list
  12452.  
  12453. [Configuration Loader]
  12454. Number=1768
  12455. Confirmed=X
  12456. Filename=wincffg.exe
  12457. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.A3&VSect=T" target=_blank>AGOBOT.A3</a> WORM!
  12458. Source=Paul Collins Startup list
  12459.  
  12460. [Configuration Loader]
  12461. Number=1769
  12462. Confirmed=X
  12463. Filename=seru32.exe
  12464. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotvr.html" target=_blank>SDBOT-VR</a> WORM!
  12465. Source=Paul Collins Startup list
  12466.  
  12467. [Configuration Loader]
  12468. Number=1770
  12469. Confirmed=X
  12470. Filename=botss.exe
  12471. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxs.html" target= blank>SDBOT-XS</a> WORM!
  12472. Source=Paul Collins Startup list
  12473.  
  12474. [Configuration Loader]
  12475. Number=1771
  12476. Confirmed=X
  12477. Filename=ldasp.exe
  12478. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.BH" target="_blank">AGOBOT.BH</a> WORM!
  12479. Source=Paul Collins Startup list
  12480.  
  12481. [Configuration Loader]
  12482. Number=1772
  12483. Confirmed=X
  12484. Filename=msgcfgsrv.exe
  12485. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target="_blank">AGOBOT/GAOBOT</a> WORM!
  12486. Source=Paul Collins Startup list
  12487.  
  12488. [Configuration Loader]
  12489. Number=1773
  12490. Confirmed=X
  12491. Filename=smsai.exe
  12492. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotye.html" target= blank>SDBOT-YE</a> WORM!
  12493. Source=Paul Collins Startup list
  12494.  
  12495. [Configuration Loader]
  12496. Number=1774
  12497. Confirmed=X
  12498. Filename=svupdate.exe
  12499. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051410-0631-99" target= blank>RANDEX.DXP</a> WORM!
  12500. Source=Paul Collins Startup list
  12501.  
  12502. [Configuration Loader]
  12503. Number=1775
  12504. Confirmed=X
  12505. Filename=crcss.exe
  12506. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.ADG&VSect=T" target=_blank>AGOBOT.ADG</a> WORM!
  12507. Source=Paul Collins Startup list
  12508.  
  12509. [Configuration Loader]
  12510. Number=1776
  12511. Confirmed=X
  12512. Filename=lexplore.exe
  12513. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotagx.html" target=_blank>RBOT-AGX</a> WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
  12514. Source=Paul Collins Startup list
  12515.  
  12516. [Configuration Loader]
  12517. Number=1777
  12518. Confirmed=X
  12519. Filename=scvhost.exe
  12520. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotaae.html" target=_blank>AGOBOT-AAE</a> and <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-060816-2421-99" target=_blank>SDBOT.AR</a> WORMS!
  12521. Source=Paul Collins Startup list
  12522.  
  12523. [Configuration Loader]
  12524. Number=1778
  12525. Confirmed=X
  12526. Filename=svchost.exe
  12527. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32paradropa.html" target=_blank>PARADROP-A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
  12528. Source=Paul Collins Startup list
  12529.  
  12530. [Configuration Loader]
  12531. Number=1779
  12532. Confirmed=X
  12533. Filename=svchost2.exe
  12534. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.JR&VSect=P" target=_blank>AGOBOT.JR</a> WORM!
  12535. Source=Paul Collins Startup list
  12536.  
  12537. [Configuration Loader]
  12538. Number=1780
  12539. Confirmed=X
  12540. Filename=dezi.exe
  12541. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotob.html" target=_blank>SDBOT-OB</a> WORM!
  12542. Source=Paul Collins Startup list
  12543.  
  12544. [Configuration Loader]
  12545. Number=1781
  12546. Confirmed=X
  12547. Filename=mouse.exe
  12548. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
  12549. Source=Paul Collins Startup list
  12550.  
  12551. [Configuration Loader]
  12552. Number=1782
  12553. Confirmed=X
  12554. Filename=msg.exe
  12555. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BT&VSect=P" target=_blank>SDBOT.BT</a> WORM!
  12556. Source=Paul Collins Startup list
  12557.  
  12558. [Configuration Loader]
  12559. Number=1783
  12560. Confirmed=X
  12561. Filename=WinHelper.exe
  12562. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
  12563. Source=Paul Collins Startup list
  12564.  
  12565. [Configuration Loader]
  12566. Number=1784
  12567. Confirmed=X
  12568. Filename=extrac.exe
  12569. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotafp.html" target=_blank>SDBOT-AFP</a> WORM!
  12570. Source=Paul Collins Startup list
  12571.  
  12572. [Configuration Loader]
  12573. Number=1785
  12574. Confirmed=X
  12575. Filename=DVD-Player.exe
  12576. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  12577. Source=Paul Collins Startup list
  12578.  
  12579. [Configuration Loader]
  12580. Number=1786
  12581. Confirmed=X
  12582. Filename=IEXPLORE.EXE
  12583. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotkw.html" target=_blank>SDBOT-KW</a> WORM! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a>) process, which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup unless you add it manually! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  12584. Source=Paul Collins Startup list
  12585.  
  12586. [Configuration Loader]
  12587. Number=1787
  12588. Confirmed=X
  12589. Filename=svchost.exe
  12590. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32paradropa.html" target=_blank>PARADROP-AI</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which should not normally figure in Msconfig/Startup!
  12591. Source=Paul Collins Startup list
  12592.  
  12593. [Configuration Loader]
  12594. Number=1788
  12595. Confirmed=X
  12596. Filename=wincore.exe
  12597. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BHE" target="_blank">SDBOT.BHE</a> WORM!
  12598. Source=Paul Collins Startup list
  12599.  
  12600. [Configuration Loader]
  12601. Number=1789
  12602. Confirmed=X
  12603. Filename=configldr.exe
  12604. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotpp.html" target="_blank">AGOBOT-PP</a> TROJAN!
  12605. Source=Paul Collins Startup list
  12606.  
  12607. [Configuration Loader ]
  12608. Number=1790
  12609. Confirmed=X
  12610. Filename=syscfg32.exe
  12611. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-102319-2939-99" target="_blank">SDBOT.B</a> TROJAN!
  12612. Source=Paul Collins Startup list
  12613.  
  12614. [Configuration Loader Service]
  12615. Number=1791
  12616. Confirmed=X
  12617. Filename=Winsys32.exe
  12618. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotyv.html" target=_blank>RBOT-YV</a> WORM!
  12619. Source=Paul Collins Startup list
  12620.  
  12621. [Configuration Loader Service]
  12622. Number=1792
  12623. Confirmed=X
  12624. Filename=devl32.exe
  12625. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxy.html" target= blank>SDBOT-XY</a> WORM!
  12626. Source=Paul Collins Startup list
  12627.  
  12628. [Configuration Loader10]
  12629. Number=1793
  12630. Confirmed=X
  12631. Filename=ip7.exe
  12632. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotanz.html" target=_blank>AGOBOT-ANZ</a> WORM!
  12633. Source=Paul Collins Startup list
  12634.  
  12635. [Configuration Loading]
  12636. Number=1794
  12637. Confirmed=X
  12638. Filename=svchos1.exe
  12639. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-120514-4926-99" target="_blank">GAOBOT.DK</a> WORM!
  12640. Source=Paul Collins Startup list
  12641.  
  12642. [Configuration Loading]
  12643. Number=1795
  12644. Confirmed=X
  12645. Filename=configldr.exe
  12646. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotec.html" target="_blank">AGOBOT-EC</a> WORM!
  12647. Source=Paul Collins Startup list
  12648.  
  12649. [Configuration Loading Service]
  12650. Number=1796
  12651. Confirmed=X
  12652. Filename=wscel.exe
  12653. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotwj.html" target= blank>SDBOT-WJ</a> WORM!
  12654. Source=Paul Collins Startup list
  12655.  
  12656. [Configuration Loadr]
  12657. Number=1797
  12658. Confirmed=X
  12659. Filename=iexplore.exee
  12660. Description=Added by an unidentified WORM or TROJAN!
  12661. Source=Paul Collins Startup list
  12662.  
  12663. [Configuration Manager]
  12664. Number=1798
  12665. Confirmed=X
  12666. Filename=CNFGLD32.EXE
  12667. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJAN!
  12668. Source=Paul Collins Startup list
  12669.  
  12670. [Configuration Manager]
  12671. Number=1799
  12672. Confirmed=X
  12673. Filename=Cnfgldr.exe
  12674. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-051312-3628-99" target="_blank">SDBOT</a> TROJAN!
  12675. Source=Paul Collins Startup list
  12676.  
  12677. [Configuration Manager]
  12678. Number=1800
  12679. Confirmed=X
  12680. Filename=cfg32.exe
  12681. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BookedSpace&threatid=3275" target=_blank>BookedSpace</a> parasite
  12682. Source=Paul Collins Startup list
  12683.  
  12684. [Configuration Servecie]
  12685. Number=1801
  12686. Confirmed=X
  12687. Filename=sewins.exe
  12688. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotcoh.html" target="_blank">SDBOT-COH</a> WORM!
  12689. Source=Paul Collins Startup list
  12690.  
  12691. [Configuration Service]
  12692. Number=1802
  12693. Confirmed=X
  12694. Filename=suchost.exe
  12695. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081709-4000-99" target="_blank">TREB</a> TROJAN!
  12696. Source=Paul Collins Startup list
  12697.  
  12698. [Configuration Services]
  12699. Number=1803
  12700. Confirmed=X
  12701. Filename=mswords.exe
  12702. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotym.html" target=_blank>SDBOT-YM</a> WORM!
  12703. Source=Paul Collins Startup list
  12704.  
  12705. [Configuration Utility]
  12706. Number=1804
  12707. Confirmed=N
  12708. Filename=CONFIG.EXE
  12709. Description=Controls linksys wireless connection. Available from the Desktop
  12710. Source=Paul Collins Startup list
  12711.  
  12712. [Configuration Utility]
  12713. Number=1805
  12714. Confirmed=U
  12715. Filename=wlanutil.exe
  12716. Description=<a href="http://www.netgear.com/" target="_blank">NetGear</a> Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
  12717. Source=Paul Collins Startup list
  12718.  
  12719. [Configuration Wizard]
  12720. Number=1806
  12721. Confirmed=X
  12722. Filename=Cfgwiz32.exe
  12723. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_HCKTCK.2K.C" target="_blank">HACKTACK</a> TROJAN! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe)
  12724. Source=Paul Collins Startup list
  12725.  
  12726. [Configuration32 Loader32]
  12727. Number=1807
  12728. Confirmed=X
  12729. Filename=winamp32.exe
  12730. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotbic.html" target=_blank>SDBOT-BIC</a> WORM!
  12731. Source=Paul Collins Startup list
  12732.  
  12733. [ConfLoader]
  12734. Number=1808
  12735. Confirmed=X
  12736. Filename=sysconf16.exe
  12737. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsdbotfb.html" target=_blank>SDBOT-FB</a> TROJAN!
  12738. Source=Paul Collins Startup list
  12739.  
  12740. [Conmgr]
  12741. Number=1809
  12742. Confirmed=N
  12743. Filename=conmgr.exe
  12744. Description=Starts Winfax pro at startup
  12745. Source=Paul Collins Startup list
  12746.  
  12747. [ConMgr.exe]
  12748. Number=1810
  12749. Confirmed=U
  12750. Filename=conmgr.exe
  12751. Description=Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut 
  12752. Source=Paul Collins Startup list
  12753.  
  12754. [Connect2Party]
  12755. Number=1811
  12756. Confirmed=X
  12757. Filename=connect2party.exe
  12758. Description=Adult content dialler
  12759. Source=Paul Collins Startup list
  12760.  
  12761. [Connection Keeper]
  12762. Number=1812
  12763. Confirmed=U
  12764. Filename=ConKeepM.exe
  12765. Description="<a href="http://www.gammadyne.com/conkeep.htm" target="_blank">Connection Keeper</a> is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle, thus preventing your ISP from dropping your connection due to inactivity"
  12766. Source=Paul Collins Startup list
  12767.  
  12768. [Connection Manager]
  12769. Number=1813
  12770. Confirmed=N
  12771. Filename=CManager.exe
  12772. Description=SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
  12773. Source=Paul Collins Startup list
  12774.  
  12775. [Connectivity Tool]
  12776. Number=1814
  12777. Confirmed=X
  12778. Filename=[path to trojan]
  12779. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlitebote.html" target=_blank>LITEBOT-E</a> TROJAN!
  12780. Source=Paul Collins Startup list
  12781.  
  12782. [Connector]
  12783. Number=1815
  12784. Confirmed=X
  12785. Filename=SYS.EXE
  12786. Description=Added by the <a href="http://www.sarc.com/avcenter/venc/data/dialer.nunci.html" target=_blank>dialer.Nunci</a> premium dialer
  12787. Source=Paul Collins Startup list
  12788.  
  12789. [Connector]
  12790. Number=1816
  12791. Confirmed=X
  12792. Filename=sms.EXE
  12793. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/dialexdialb.html" target=_blank>ExDial-B</a> premium rate adult content dialer
  12794. Source=Paul Collins Startup list
  12795.  
  12796. [Cons]
  12797. Number=1817
  12798. Confirmed=X
  12799. Filename=consol32.exe
  12800. Description=Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed
  12801. Source=Paul Collins Startup list
  12802.  
  12803. [conscorr]
  12804. Number=1818
  12805. Confirmed=X
  12806. Filename=conscorr.exe
  12807. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=VX2.Transponder&threatid=12517" target=_blank>VX2.Transponder</a> parasite updater/installer related
  12808. Source=Paul Collins Startup list
  12809.  
  12810. [Console de Gerenciamento Microsoft]
  12811. Number=1819
  12812. Confirmed=X
  12813. Filename=csrss.exe
  12814. Description=Unidentified malware! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a System\Level4 subfolder
  12815.  
  12816. Source=Paul Collins Startup list
  12817.  
  12818. [Console de Gerenciamento Microsoft]
  12819. Number=1820
  12820. Confirmed=X
  12821. Filename=csrss.exe
  12822. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanet.html" target=_blank>BANCBAN-ET</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Central de SeguranÏ„a" subfolder
  12823. Source=Paul Collins Startup list
  12824.  
  12825. [Consumer Input]
  12826. Number=1821
  12827. Confirmed=U
  12828. Filename=ConsumerInput.exe
  12829. Description=<a href="http://www.consumerinput.com/" target="_blank">Consumer Input</a> Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ
  12830. Source=Paul Collins Startup list
  12831.  
  12832. [Consumer Input Rewarded with MyPoints, Consumer Input]
  12833. Number=1822
  12834. Confirmed=U
  12835. Filename=ConsumerInputRewardedwithMyPoints, ConsumerInput.exe
  12836. Description=<a href="http://www.consumerinput.com/" target="_blank">Consumer Input</a> Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ
  12837. Source=Paul Collins Startup list
  12838.  
  12839. [Consumer Input Rewarded with MyPoints, Consumer Input Update]
  12840. Number=1823
  12841. Confirmed=U
  12842. Filename=ConsumerInputRewardedwithMyPoints, ConsumerInputUa.exe
  12843. Description=<a href="http://www.consumerinput.com/" target="_blank">Consumer Input</a> Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ
  12844. Source=Paul Collins Startup list
  12845.  
  12846. [Contacte]
  12847. Number=1824
  12848. Confirmed=?
  12849. Filename=contacte.exe
  12850. Description=<font color="#FF0000">Some kind of driver?</font>
  12851. Source=Paul Collins Startup list
  12852.  
  12853. [Content connector]
  12854. Number=1825
  12855. Confirmed=X
  12856. Filename=[random filename].exe
  12857. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdialery.html" target="_blank">DIALER-Y</a> TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder
  12858. Source=Paul Collins Startup list
  12859.  
  12860. [ContentDownload]
  12861. Number=1826
  12862. Confirmed=X
  12863. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  12864. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  12865. Source=Paul Collins Startup list
  12866.  
  12867. [ContentService]
  12868. Number=1827
  12869. Confirmed=X
  12870. Filename=winservn.exe
  12871. Description=Homepage hijacker
  12872. Source=Paul Collins Startup list
  12873.  
  12874. [ContinueInstall]
  12875. Number=1828
  12876. Confirmed=X
  12877. Filename=bpsinstall.exe
  12878. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=BrowserAid&threatid=3342" target="_blank">BrowserAid/BrowserPal</a> foistware
  12879. Source=Paul Collins Startup list
  12880.  
  12881. [Control]
  12882. Number=1829
  12883. Confirmed=X
  12884. Filename=rundll32.exe ctrlpan.dll, Restore ControlPanel
  12885. Description=CoolWebSearch <a href="http://cwshredder.net/cwshredder/cwschronicles.html#msconfd" target=_blank>Msconfd</a> parasite variant
  12886. Source=Paul Collins Startup list
  12887.  
  12888. [Control Center]
  12889. Number=1830
  12890. Confirmed=N
  12891. Filename=Center.exe
  12892. Description=Related to an <a href="http://www.asus.com/" target=_blank>Asus</a> WLAN card
  12893. Source=Paul Collins Startup list
  12894.  
  12895. [Control handler]
  12896. Number=1831
  12897. Confirmed=X
  12898. Filename=***********.exe [* = random char]
  12899. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  12900. Source=Paul Collins Startup list
  12901.  
  12902. [Control handler]
  12903. Number=1832
  12904. Confirmed=X
  12905. Filename=ahjinst.exe
  12906. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  12907. Source=Paul Collins Startup list
  12908.  
  12909. [Control handler]
  12910. Number=1833
  12911. Confirmed=X
  12912. Filename=[10 to 14 random char]THD.EXE
  12913. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojkrepperai.html" target=_blank>KREPPER-AI</a> TROJAN!
  12914. Source=Paul Collins Startup list
  12915.  
  12916. [control panel]
  12917. Number=1834
  12918. Confirmed=N
  12919. Filename=smctrlw.exe
  12920. Description=System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
  12921. Source=Paul Collins Startup list
  12922.  
  12923. [Control Panel]
  12924. Number=1835
  12925. Confirmed=X
  12926. Filename=System.exe
  12927. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020515-1939-99" target="_blank">DANI</a> TROJAN!
  12928. Source=Paul Collins Startup list
  12929.  
  12930. [control panel software service]
  12931. Number=1836
  12932. Confirmed=X
  12933. Filename=cprs.exe
  12934. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfpi.html" target="_blank">RBOT-FPI</a> WORM!
  12935. Source=Paul Collins Startup list
  12936.  
  12937. [Controladores]
  12938. Number=1837
  12939. Confirmed=X
  12940. Filename=[path to trojan]
  12941. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtelefoa.html" target=_blank>TELEFO-A</a> TROJAN!
  12942. Source=Paul Collins Startup list
  12943.  
  12944. [ControlCenter2.0]
  12945. Number=1838
  12946. Confirmed=N
  12947. Filename=brctrcen.exe
  12948. Description=Brother scanner 'Control Center' application - can be started manually
  12949.  
  12950. Source=Paul Collins Startup list
  12951.  
  12952. [ControlCentreTray]
  12953. Number=1839
  12954. Confirmed=N
  12955. Filename=XWCTray.exe
  12956. Description=System Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc
  12957. Source=Paul Collins Startup list
  12958.  
  12959. [Controlled Resource System Service]
  12960. Number=1840
  12961. Confirmed=X
  12962. Filename=crss.exe
  12963. Description=Added by the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/crss/" target=_blank>AGOBOT.GH</a> WORM!
  12964. Source=Paul Collins Startup list
  12965.  
  12966. [Controller]
  12967. Number=1841
  12968. Confirmed=N
  12969. Filename=WFXCTL32.EXE
  12970. Description=From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
  12971. Source=Paul Collins Startup list
  12972.  
  12973. [ControlPanel]
  12974. Number=1842
  12975. Confirmed=X
  12976. Filename=rundll32 internat.dll, LoadKeyboardProfile
  12977. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  12978. Source=Paul Collins Startup list
  12979.  
  12980. [ControlPanel]
  12981. Number=1843
  12982. Confirmed=X
  12983. Filename=host32.exe internat.dll, LoadKeyboardProfile
  12984. Description=Added by a vairant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DELF.DW" target="_blank">DELF.DW</a> TROJAN!
  12985. Source=Paul Collins Startup list
  12986.  
  12987. [ControlPanel]
  12988. Number=1844
  12989. Confirmed=X
  12990. Filename=[path] cmd32.exe internat.dll, LoadKeyboardProfile
  12991. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderhf.html" target="_blank">DLOADER-HF</a> TROJAN!
  12992. Source=Paul Collins Startup list
  12993.  
  12994. [ControlPanel]
  12995. Number=1845
  12996. Confirmed=X
  12997. Filename=systemctrl.exe internet.dll, LoadNetworkProfile
  12998. Description=Browser hijacker, also detected as <a href="http://www.sophos.com/virusinfo/analyses/trojstartpafx.html" target= blank>STARTPA-FX</a>
  12999. Source=Paul Collins Startup list
  13000.  
  13001. [ControlPanel]
  13002. Number=1846
  13003. Confirmed=X
  13004. Filename=internat.dll, LoadKeyboardProfile
  13005. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbizvesa.html" target=_blank>BIZVES-A</a> TROJAN!
  13006. Source=Paul Collins Startup list
  13007.  
  13008. [ControlPanel]
  13009. Number=1847
  13010. Confirmed=X
  13011. Filename=popcorn.exe internat.dll, LoadKeyboardProfile
  13012. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbizvesb.html" target=_blank>BIZVES-B</a> TROJAN!
  13013. Source=Paul Collins Startup list
  13014.  
  13015. [ControlPanel]
  13016. Number=1848
  13017. Confirmed=X
  13018. Filename=popcorn64.exe
  13019. Description=Browser hijacker, redirecting to loadcash.biz
  13020. Source=Paul Collins Startup list
  13021.  
  13022. [ControlPanel]
  13023. Number=1849
  13024. Confirmed=X
  13025. Filename=popcorn64.exe rundll.dll, LoadMouseProfile
  13026. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderoi.html" target=_blank>DLOADER-OI</a> TROJAN!
  13027. Source=Paul Collins Startup list
  13028.  
  13029. [ControlPanel]
  13030. Number=1850
  13031. Confirmed=X
  13032. Filename=popcorn72.exe rundll.dll, LoadMouseProfile
  13033. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderra.html" target=_blank>DLOADER-RA</a> TROJAN!
  13034. Source=Paul Collins Startup list
  13035.  
  13036. [ControlPanel]
  13037. Number=1851
  13038. Confirmed=X
  13039. Filename=svcc.exe
  13040. Description=<a href="http://www.sarc.com/avcenter/venc/data/adware.worldsearch.html" target=_blank>WorldSearch</a> adware
  13041. Source=Paul Collins Startup list
  13042.  
  13043. [ControlPanel]
  13044. Number=1852
  13045. Confirmed=X
  13046. Filename=popcorn320.exe rundll.dll, LoadMouseProfile
  13047. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderra.html" target=_blank>DLOADER-RA</a> TROJAN!
  13048. Source=Paul Collins Startup list
  13049.  
  13050. [ControlPanel]
  13051. Number=1853
  13052. Confirmed=X
  13053. Filename=[path] private.exe internat.dll, LoadMouseCarpetProfile
  13054. Description=Reported by Norman Virus Control as W32/Downloader. Creates the files sdfff, fdsf and zxczxc. In the C:\WINDOWS\SYSTEM32 directory creates the files d.exe, s.exe and r.exe
  13055. Source=Paul Collins Startup list
  13056.  
  13057. [ControlServiceMgr]
  13058. Number=1854
  13059. Confirmed=X
  13060. Filename=csmsv.exe
  13061. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentxc.html" target=_blank>AGENT-XC</a> TROJAN!
  13062. Source=Paul Collins Startup list
  13063.  
  13064. [Cookie Cop 2]
  13065. Number=1855
  13066. Confirmed=U
  13067. Filename=CookieCop.exe
  13068. Description=<a href="http://www.pcmag.com/article2/0,1895,6142,00.asp" target="_blank">Cookie Cop 2</a> from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
  13069. Source=Paul Collins Startup list
  13070.  
  13071. [Cookie Pal]
  13072. Number=1856
  13073. Confirmed=U
  13074. Filename=CPBRWTCH.EXE
  13075. Description=Kookaburra Software's <a href="http://www.kburra.com/cpal.html" target="_blank">Cookie Pal</a> cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
  13076. Source=Paul Collins Startup list
  13077.  
  13078. [CookieJar]
  13079. Number=1857
  13080. Confirmed=U
  13081. Filename=Cookiejar.exe
  13082. Description=<a href="http://www.jasons-toolbox.com/?page_id=14" target="_blank">Cookie Jar</a> cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return. No longer being actively supported
  13083. Source=Paul Collins Startup list
  13084.  
  13085. [CookiePatrol]
  13086. Number=1858
  13087. Confirmed=U
  13088. Filename=CookiePatrol.exe
  13089. Description=CookiePatrol - cookie interceptor stopping spyware cookies that used to be part of <a href="http://www.pestpatrol.com/default.asp" target="_blank">PestPatrol</a> before CA's aquisition
  13090. Source=Paul Collins Startup list
  13091.  
  13092. [CookieWall]
  13093. Number=1859
  13094. Confirmed=U
  13095. Filename=cookie.exe
  13096. Description=<a href="http://www.analogx.com/contents/download/network/cookie.htm" target="_blank">CookieWall</a> from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
  13097. Source=Paul Collins Startup list
  13098.  
  13099. [Cool Desk]
  13100. Number=1860
  13101. Confirmed=U
  13102. Filename=cdesk.exe
  13103. Description=<a href="http://www.shelltoys.com/" target="_blank">Cool Desk</a> is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you
  13104. Source=Paul Collins Startup list
  13105.  
  13106. [CoolDownloads]
  13107. Number=1861
  13108. Confirmed=X
  13109. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  13110. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  13111. Source=Paul Collins Startup list
  13112.  
  13113. [CoolMP3]
  13114. Number=1862
  13115. Confirmed=X
  13116. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  13117. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  13118. Source=Paul Collins Startup list
  13119.  
  13120. [CoolSwitch]
  13121. Number=1863
  13122. Confirmed=U
  13123. Filename=taskswitch.exe
  13124. Description=ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
  13125. Source=Paul Collins Startup list
  13126.  
  13127. [Coolwallpaper]
  13128. Number=1864
  13129. Confirmed=N
  13130. Filename=cwm_tray.exe
  13131. Description=<a href="http://coolwallpaper.com/download/index2.html" target=_blank>Cool Wallpaper</a> software allows you to manage high quality photos as desktop wallpaper and screen savers
  13132. Source=Paul Collins Startup list
  13133.  
  13134. [coolwebprogram]
  13135. Number=1865
  13136. Confirmed=X
  13137. Filename=clrssn.exe
  13138. Description=CoolWebSearch <a href="http://cwshredder.net/cwshredder/cwschronicles.html#smartsearch" target=_blank>Smartsearch</a> parasite variant
  13139. Source=Paul Collins Startup list
  13140.  
  13141. [Copernic Desktop Search]
  13142. Number=1866
  13143. Confirmed=N
  13144. Filename=DesktopSearch.exe
  13145. Description=Copernic <a href="http://www.copernic.com/en/products/desktop-search/index.html" target=_blank>Desktop Search</a> - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures"
  13146. Source=Paul Collins Startup list
  13147.  
  13148. [Copernic Desktop Search 2]
  13149. Number=1867
  13150. Confirmed=U
  13151. Filename=DesktopSearchService.exe
  13152. Description=<a href="http://www.copernic.com/en/products/desktop-search/index.html" target="_blank">Copernic Desktop Search</a> - search agent
  13153. Source=Paul Collins Startup list
  13154.  
  13155. [CopernicPerUserTaskMgr]
  13156. Number=1868
  13157. Confirmed=U
  13158. Filename=CopernicPerUserTaskMgr.exe
  13159. Description=Automatic tasking feature of Copernic Pro multi-search engine tool
  13160. Source=Paul Collins Startup list
  13161.  
  13162. [Copy handler]
  13163. Number=1869
  13164. Confirmed=U
  13165. Filename=Copy Handler.exe
  13166. Description=<a href="http://copyhandler.com/" target= blank>Copy Handler</a> lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processes
  13167. Source=Paul Collins Startup list
  13168.  
  13169. [Copyright]
  13170. Number=1870
  13171. Confirmed=N
  13172. Filename=mwcpyrt.exe
  13173. Description=Displays copyright information on IBM ThinkPads
  13174. Source=Paul Collins Startup list
  13175.  
  13176. [CoreCenter]
  13177. Number=1871
  13178. Confirmed=U
  13179. Filename=CoreCenter.exe
  13180. Description=MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking
  13181. Source=Paul Collins Startup list
  13182.  
  13183. [CoreCenter]
  13184. Number=1872
  13185. Confirmed=U
  13186. Filename=CORECE~1.EXE
  13187. Description=MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking
  13188. Source=Paul Collins Startup list
  13189.  
  13190. [Corel Colleagues & Contacts Reminders]
  13191. Number=1873
  13192. Confirmed=N
  13193. Filename=cffrem.exe
  13194. Description=Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of the now defunct Corel Print Office
  13195. Source=Paul Collins Startup list
  13196.  
  13197. [Corel Desktop Application Director]
  13198. Number=1874
  13199. Confirmed=N
  13200. Filename=dadx.exe
  13201. Description=The Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
  13202. Source=Paul Collins Startup list
  13203.  
  13204. [Corel Family & Friends reminders]
  13205. Number=1875
  13206. Confirmed=N
  13207. Filename=CFFREM.EXE
  13208. Description=Corel Family & Friends - all-in-one calender, address book and list manager. Part of the now defunct Corel Print House Magic
  13209. Source=Paul Collins Startup list
  13210.  
  13211. [Corel Photo Downloader]
  13212. Number=1876
  13213. Confirmed=N
  13214. Filename=MediaDetect.exe
  13215. Description=Related to <a href="http://www.corel.com/servlet/Satellite?pagename=Corel3/Products/Display&pid=1047025470321" target=_blank>Corel Photo Album</a>
  13216.  
  13217. Source=Paul Collins Startup list
  13218.  
  13219. [Corel Registration]
  13220. Number=1877
  13221. Confirmed=N
  13222. Filename=Remind32.exe
  13223. Description=If you don't want to register Corel products and be reminded about it every 2 weeks disable it
  13224. Source=Paul Collins Startup list
  13225.  
  13226. [Corel Registration Reminder]
  13227. Number=1878
  13228. Confirmed=N
  13229. Filename=Remind32.exe
  13230. Description=If you don't want to register Corel products and be reminded about it every 2 weeks disable it
  13231. Source=Paul Collins Startup list
  13232.  
  13233. [Corel Reminder]
  13234. Number=1879
  13235. Confirmed=N
  13236. Filename=NAVBROWSER.EXE
  13237. Description=If you don't want to register Corel products and be reminded about it every 2 weeks disable it
  13238. Source=Paul Collins Startup list
  13239.  
  13240. [Corel Reminder]
  13241. Number=1880
  13242. Confirmed=N
  13243. Filename=NAVBrowser.exe
  13244. Description=Registration reminder for CorelDRAW 10
  13245. Source=Paul Collins Startup list
  13246.  
  13247. [CorelCENTRAL 10]
  13248. Number=1881
  13249. Confirmed=N
  13250. Filename=I_26dadCC.exe
  13251. Description=<a href="http://www3.corel.com/cgi-bin/gx.cgi/AppLogic+FTContentServer?pagename=Corel/Product/Feature&fid=CC1ZX1WPOP4" target="_blank">CorelCENTRAL 10</a> - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs
  13252. Source=Paul Collins Startup list
  13253.  
  13254. [CorelDraw Toolbox]
  13255. Number=1882
  13256. Confirmed=X
  13257. Filename=CorelDraw.exe
  13258. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotvz.html" target= blank>SDBOT-VZ</a> WORM!
  13259. Source=Paul Collins Startup list
  13260.  
  13261. [CorelMedia FoldersIndexer8]
  13262. Number=1883
  13263. Confirmed=N
  13264. Filename=MFindexer.exe
  13265. Description=Part of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
  13266. Source=Paul Collins Startup list
  13267.  
  13268. [CorelMedia FoldersIndexer8]
  13269. Number=1884
  13270. Confirmed=N
  13271. Filename=MFINDE~1.EXE
  13272. Description=Part of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
  13273. Source=Paul Collins Startup list
  13274.  
  13275. [CoreSrv]
  13276. Number=1885
  13277. Confirmed=X
  13278. Filename=coresrv.exe
  13279. Description=Some IRC trojans/worms use this - see <a href="http://lockdowncorp.com/bots/" target="_blank">here</a> for more information
  13280. Source=Paul Collins Startup list
  13281.  
  13282. [CORESYS]
  13283. Number=1886
  13284. Confirmed=?
  13285. Filename=coresys.exe
  13286. Description=<font color="#FF0000">??</font>
  13287. Source=Paul Collins Startup list
  13288.  
  13289. [CorrectConnect]
  13290. Number=1887
  13291. Confirmed=N
  13292. Filename=CConnect.exe
  13293. Description=Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
  13294. Source=Paul Collins Startup list
  13295.  
  13296. [cosine]
  13297. Number=1888
  13298. Confirmed=X
  13299. Filename=cosine.exe
  13300. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotsw.html" target=_blank>RBOT-SW</a> WORM!
  13301. Source=Paul Collins Startup list
  13302.  
  13303. [CostAware]
  13304. Number=1889
  13305. Confirmed=U
  13306. Filename=niIPCApp.exe
  13307. Description=NetInternals <a href="http://www.netinternals.com/default.htm?products" target="_blank">CostAware</a> - download quota measuring tool
  13308. Source=Paul Collins Startup list
  13309.  
  13310. [Country Select]
  13311. Number=1890
  13312. Confirmed=N
  13313. Filename=pctptt.exe
  13314. Description=Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required
  13315. Source=Paul Collins Startup list
  13316.  
  13317. [CountrySelection]
  13318. Number=1891
  13319. Confirmed=N
  13320. Filename=pctptt.exe
  13321. Description=Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required
  13322. Source=Paul Collins Startup list
  13323.  
  13324. [Coupon Offers]
  13325. Number=1892
  13326. Confirmed=?
  13327. Filename=??
  13328. Description=<font color="#FF0000">??</font>
  13329. Source=Paul Collins Startup list
  13330.  
  13331. [couponica]
  13332. Number=1893
  13333. Confirmed=X
  13334. Filename=couponica.exe
  13335. Description=Adware - see <a href="http://vil.nai.com/vil/content/v_100077.htm#top" target="_blank">here</a>
  13336. Source=Paul Collins Startup list
  13337.  
  13338. [CP]
  13339. Number=1894
  13340. Confirmed=?
  13341. Filename=CopyProtectionNotifier.exe
  13342. Description=Related to <a href="http://www.emuzed.com/application.html" target=_blank>Emuzed</a> Systems and Middleware. Comes included with Windows XP Media Edition
  13343. Source=Paul Collins Startup list
  13344.  
  13345. [CP32NOT]
  13346. Number=1895
  13347. Confirmed=U
  13348. Filename=CP32BTN.EXE
  13349. Description=For the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
  13350. Source=Paul Collins Startup list
  13351.  
  13352. [CP4HPOT]
  13353. Number=1896
  13354. Confirmed=U
  13355. Filename=OneTouch.EXE
  13356. Description=One Touch keyboard driver. Required if you use the additional keys
  13357. Source=Paul Collins Startup list
  13358.  
  13359. [CP888M1]
  13360. Number=1897
  13361. Confirmed=N
  13362. Filename=CP888M1.EXE
  13363. Description=Related to EZbutton quick launcher for the Media player app that comes with certain laptops
  13364. Source=Paul Collins Startup list
  13365.  
  13366. [CPA9P2PSERVER]
  13367. Number=1898
  13368. Confirmed=?
  13369. Filename=CPA9P2PS.exe
  13370. Description=<font color="#FF0000">Found on a Compaq Presario but what is it?</font>
  13371. Source=Paul Collins Startup list
  13372.  
  13373. [cpanel]
  13374. Number=1899
  13375. Confirmed=X
  13376. Filename=winlogin32.exe
  13377. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfoy.html" target="_blank">RBOT-FOY</a> WORM!
  13378. Source=Paul Collins Startup list
  13379.  
  13380. [CPATR10]
  13381. Number=1900
  13382. Confirmed=U
  13383. Filename=CPATR10.EXE
  13384. Description=Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast
  13385. Source=Paul Collins Startup list
  13386.  
  13387. [CPBrWtch]
  13388. Number=1901
  13389. Confirmed=U
  13390. Filename=CPBrWtch.exe
  13391. Description=Kookaburra Software's <a href="http://www.kburra.com/cpal.html" target="_blank">Cookie Pal</a> cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
  13392. Source=Paul Collins Startup list
  13393.  
  13394. [CPD_EXE]
  13395. Number=1902
  13396. Confirmed=Y
  13397. Filename=CPD.EXE
  13398. Description=Firewall bundled with McAfee VirusScan 6.*
  13399. Source=Paul Collins Startup list
  13400.  
  13401. [cpl]
  13402. Number=1903
  13403. Confirmed=X
  13404. Filename=deamon.exe
  13405. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  13406. Source=Paul Collins Startup list
  13407.  
  13408. [cpl]
  13409. Number=1904
  13410. Confirmed=X
  13411. Filename=msgaol.exe
  13412. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  13413. Source=Paul Collins Startup list
  13414.  
  13415. [cpl]
  13416. Number=1905
  13417. Confirmed=X
  13418. Filename=s_menu.exe
  13419. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  13420. Source=Paul Collins Startup list
  13421.  
  13422. [cpl]
  13423. Number=1906
  13424. Confirmed=X
  13425. Filename=browse.exe
  13426. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  13427. Source=Paul Collins Startup list
  13428.  
  13429. [cpl]
  13430. Number=1907
  13431. Confirmed=X
  13432. Filename=msgaol.exe
  13433. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  13434. Source=Paul Collins Startup list
  13435.  
  13436. [CplBTQ00]
  13437. Number=1908
  13438. Confirmed=N
  13439. Filename=CplBTQ00.EXE
  13440. Description=Related to EZbutton quick launcher for the Media player app that comes with certain laptops
  13441. Source=Paul Collins Startup list
  13442.  
  13443. [CPLDBL10]
  13444. Number=1909
  13445. Confirmed=N
  13446. Filename=CPLDBL10.exe
  13447. Description=Related to EZbutton quick launcher for the Media player app that comes with certain laptops
  13448. Source=Paul Collins Startup list
  13449.  
  13450. [cpntmgc]
  13451. Number=1910
  13452. Confirmed=X
  13453. Filename=wincomp.exe
  13454. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_WINTRIM.A" target=_blank>WINTRIM_A</a> TROJAN!
  13455. Source=Paul Collins Startup list
  13456.  
  13457. [cpntmgc]
  13458. Number=1911
  13459. Confirmed=X
  13460. Filename=simcss.exe
  13461. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_MAGICON.A" target=_blank>MAGICON.A</a> TROJAN!
  13462. Source=Paul Collins Startup list
  13463.  
  13464. [cpntmgc]
  13465. Number=1912
  13466. Confirmed=X
  13467. Filename=navpmc.exe
  13468. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-112414-3016-99" target=_blank>SIMCSS</a> TROJAN!
  13469. Source=Paul Collins Startup list
  13470.  
  13471. [cpntmgc]
  13472. Number=1913
  13473. Confirmed=X
  13474. Filename=winmgts.exe
  13475. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojwintrimb.html" target=_blank>WINTRIM-B</a> TROJAN!
  13476. Source=Paul Collins Startup list
  13477.  
  13478. [CPortPatch]
  13479. Number=1914
  13480. Confirmed=?
  13481. Filename=cppatch.exe
  13482. Description=<font color="#FF0000">CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?</font>
  13483. Source=Paul Collins Startup list
  13484.  
  13485. [CPQAcDc]
  13486. Number=1915
  13487. Confirmed=Y
  13488. Filename=CPQAcDc.exe
  13489. Description=Compaq PowerCon power management software for laptops
  13490. Source=Paul Collins Startup list
  13491.  
  13492. [CPQAlert]
  13493. Number=1916
  13494. Confirmed=U
  13495. Filename=CPQAlert.exe
  13496. Description=Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See <a href="http://h18000.www1.hp.com/products/servers/management/cim-description.html" target="_blank">here</a> for more information
  13497. Source=Paul Collins Startup list
  13498.  
  13499. [CPQBootPerfDB]
  13500. Number=1917
  13501. Confirmed=N
  13502. Filename=CPQBootPerfDB.EXE
  13503. Description=See the entry for Compaq Message Server
  13504. Source=Paul Collins Startup list
  13505.  
  13506. [CPQCalib]
  13507. Number=1918
  13508. Confirmed=Y
  13509. Filename=CPQCalib.exe
  13510. Description=Compaq PowerCon power management software for laptops
  13511. Source=Paul Collins Startup list
  13512.  
  13513. [CPQDFWAG]
  13514. Number=1919
  13515. Confirmed=N
  13516. Filename=CpqDfwAg.exe
  13517. Description=For Compaq PC's. Runs Compaq diagnostics on every boot
  13518. Source=Paul Collins Startup list
  13519.  
  13520. [CPQEASYACC]
  13521. Number=1920
  13522. Confirmed=U
  13523. Filename=cpqeadm.exe
  13524. Description=For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
  13525. Source=Paul Collins Startup list
  13526.  
  13527. [CPQEASYACC]
  13528. Number=1921
  13529. Confirmed=U
  13530. Filename=StartEAK.exe
  13531. Description=<a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank">Easy Access</a> Button Support for Compaq PCs. Required if you use these
  13532. Source=Paul Collins Startup list
  13533.  
  13534. [cpqeaui]
  13535. Number=1922
  13536. Confirmed=U
  13537. Filename=cpqeaui.exe
  13538. Description=For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
  13539. Source=Paul Collins Startup list
  13540.  
  13541. [cpqek]
  13542. Number=1923
  13543. Confirmed=U
  13544. Filename=kcpqek.exe
  13545. Description=For Compaq PC's. <a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank"> Easy Access</a> button support for the keyboard
  13546. Source=Paul Collins Startup list
  13547.  
  13548. [CPQInet Runtime Service]
  13549. Number=1924
  13550. Confirmed=U
  13551. Filename=CpqInet.exe
  13552. Description=For Compaq PC's. Allows AOL and Compuserve to use the <a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank"> Easy Access</a> buttons for the internet. Is not required if you don't use the ISP providers
  13553. Source=Paul Collins Startup list
  13554.  
  13555. [CPQINKAGENT]
  13556. Number=1925
  13557. Confirmed=N
  13558. Filename=cpqinkag.exe
  13559. Description=That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)
  13560. Source=Paul Collins Startup list
  13561.  
  13562. [cpqns]
  13563. Number=1926
  13564. Confirmed=U
  13565. Filename=cpqnpcss.exe
  13566. Description=Related to Compaq.Net - not required if you don't use that
  13567. Source=Paul Collins Startup list
  13568.  
  13569. [Cpqset]
  13570. Number=1927
  13571. Confirmed=N
  13572. Filename=Cpqset.exe
  13573. Description=Default settings software in Hewlett Packard notebook
  13574. Source=Paul Collins Startup list
  13575.  
  13576. [CPQSTUTFIX]
  13577. Number=1928
  13578. Confirmed=Y
  13579. Filename=stutfix.exe
  13580. Description=For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it <a href="http://www.pacs-portal.co.uk/files/StutFix.exe">here</a>. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton
  13581. Source=Paul Collins Startup list
  13582.  
  13583. [cpr]
  13584. Number=1929
  13585. Confirmed=X
  13586. Filename=cpr
  13587. Description=Adroar.com adware downloader
  13588. Source=Paul Collins Startup list
  13589.  
  13590. [cprocsvc]
  13591. Number=1930
  13592. Confirmed=X
  13593. Filename=cproc.exe
  13594. Description=Added by MSIL.AGENT.C TROJAN!
  13595. Source=Paul Collins Startup list
  13596.  
  13597. [CPU Manager]
  13598. Number=1931
  13599. Confirmed=X
  13600. Filename=cpumgr.exe
  13601. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-081913-3715-99" target="_blank">PANDEM.B</a> WORM!
  13602. Source=Paul Collins Startup list
  13603.  
  13604. [CPU Temp Control]
  13605. Number=1932
  13606. Confirmed=X
  13607. Filename=wuitgurd.exe
  13608. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotahv.html" target=_blank>RBOT-AHV</a> WORM!
  13609. Source=Paul Collins Startup list
  13610.  
  13611. [CPU Watcher]
  13612. Number=1933
  13613. Confirmed=X
  13614. Filename=rundll32.exe [path] cpu.dll,load
  13615. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderlo.html" target=_blank>DLOADER-LO</a> TROJAN!
  13616. Source=Paul Collins Startup list
  13617.  
  13618. [CPU Windows Status]
  13619. Number=1934
  13620. Confirmed=X
  13621. Filename=cpustats.exe
  13622. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  13623. Source=Paul Collins Startup list
  13624.  
  13625. [CPUcool]
  13626. Number=1935
  13627. Confirmed=U
  13628. Filename=Cpucool.exe
  13629. Description=Program to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel
  13630. Source=Paul Collins Startup list
  13631.  
  13632. [Cpusave]
  13633. Number=1936
  13634. Confirmed=X
  13635. Filename=Cpusave.exe
  13636. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  13637. Source=Paul Collins Startup list
  13638.  
  13639. [Cpusave32]
  13640. Number=1937
  13641. Confirmed=X
  13642. Filename=Cpusave32.exe
  13643. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  13644. Source=Paul Collins Startup list
  13645.  
  13646. [CPVHOST Settings]
  13647. Number=1938
  13648. Confirmed=X
  13649. Filename=cpvhost.exe
  13650. Description=Added by the <a href="http://www.scanspyware.net/info/Sdbot.HMW.htm" target="_blank">SDBOT.HMW</a> WORM!
  13651. Source=Paul Collins Startup list
  13652.  
  13653. [cpyt]
  13654. Number=1939
  13655. Confirmed=X
  13656. Filename=hidep.exe
  13657. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmirjacka.html" target=_blank>MIRJACK-A</a> TROJAN!
  13658. Source=Paul Collins Startup list
  13659.  
  13660. [cqlyg]
  13661. Number=1940
  13662. Confirmed=X
  13663. Filename=world_cup_.bat
  13664. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BAT_WCUP.A" target="_blank">WCUP.A</a> WORM!
  13665. Source=Paul Collins Startup list
  13666.  
  13667. [CQSCP2P SERVER]
  13668. Number=1941
  13669. Confirmed=?
  13670. Filename=??
  13671. Description=<font color="#FF0000">"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed</font>
  13672. Source=Paul Collins Startup list
  13673.  
  13674. [CQSCP2PS]
  13675. Number=1942
  13676. Confirmed=?
  13677. Filename=??
  13678. Description=<font color="#FF0000">"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed</font>
  13679. Source=Paul Collins Startup list
  13680.  
  13681. [Cr**.exe [* = random char]]
  13682. Number=1943
  13683. Confirmed=X
  13684. Filename=Cr**.exe [* = random char]
  13685. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  13686. Source=Paul Collins Startup list
  13687.  
  13688. [Cr**.exe [* = random char]]
  13689. Number=1944
  13690. Confirmed=X
  13691. Filename=Cr**.exe [* = random char]
  13692. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  13693. Source=Paul Collins Startup list
  13694.  
  13695. [Cr**32.exe [* = random char]]
  13696. Number=1945
  13697. Confirmed=X
  13698. Filename=Cr**32.exe [* = random char]
  13699. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  13700. Source=Paul Collins Startup list
  13701.  
  13702. [cracked_windows1]
  13703. Number=1946
  13704. Confirmed=U
  13705. Filename=cracked_windows1.exe
  13706. Description=<a href="http://www.angelfire.com/electronic/purplexed/files/crackedwindows.html" target="_blank">Cracked Windows</a> popup killer
  13707. Source=Paul Collins Startup list
  13708.  
  13709. [CrazyTalk Serve]
  13710. Number=1947
  13711. Confirmed=N
  13712. Filename=rundll32.exe CrazyTalk.dll, DIIServeMediaFile
  13713. Description=<a href="http://www.reallusion.com/crazytalk/default.asp" target="_blank">CrazyTalk</a> from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS
  13714. Source=Paul Collins Startup list
  13715.  
  13716. [CRBroadCasting]
  13717. Number=1948
  13718. Confirmed=U
  13719. Filename=CRBroadCasting.exe
  13720. Description=<a href="http://www.otiglobal.com/" target=_blank>CardReader2</a> from On Track Inovations Ltd. USB Card Reader
  13721.  
  13722. Source=Paul Collins Startup list
  13723.  
  13724. [CRC Value Verifier]
  13725. Number=1949
  13726. Confirmed=X
  13727. Filename=crsss32.exe
  13728. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  13729. Source=Paul Collins Startup list
  13730.  
  13731. [CRC Value Verifier]
  13732. Number=1950
  13733. Confirmed=X
  13734. Filename=Crsss64.exe
  13735. Description=Added by the <a href="http://www.sophos.com.au/virusinfo/analyses/w32rbotny.html" target=_blank>RBOT-NY</a> WORM!
  13736.  
  13737. Source=Paul Collins Startup list
  13738.  
  13739. [CRC Value Verifier]
  13740. Number=1951
  13741. Confirmed=X
  13742. Filename=svchost32.exe
  13743. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotoa.html" target=_blank>RBOT-OA</a> WORM!
  13744. Source=Paul Collins Startup list
  13745.  
  13746. [CRC Value Verifier]
  13747. Number=1952
  13748. Confirmed=X
  13749. Filename=crsss.exe
  13750. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.UK&VSect=P" target=_blank>SPYBOT.UK</a> WORM!
  13751. Source=Paul Collins Startup list
  13752.  
  13753. [Crc32stats Dependencies]
  13754. Number=1953
  13755. Confirmed=X
  13756. Filename=Crc32stats.exe
  13757. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-070615-3252-99" target=_blank>MYTOB.GT</a> WORM!
  13758. Source=Paul Collins Startup list
  13759.  
  13760. [CRCSS]
  13761. Number=1954
  13762. Confirmed=X
  13763. Filename=crcss.exe
  13764. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32ircbotth.html" target="_blank">IRCBOT-TH</a> WORM!
  13765. Source=Paul Collins Startup list
  13766.  
  13767. [Creata Mail]
  13768. Number=1955
  13769. Confirmed=U
  13770. Filename=JMSrvr.exe
  13771. Description=<a href="http://www.bluemountain.com/mail/index.pd" target=_blank>Creata_Mail</a>. Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express
  13772.  
  13773. Source=Paul Collins Startup list
  13774.  
  13775. [Create A Monster]
  13776. Number=1956
  13777. Confirmed=X
  13778. Filename=createAMonster.exe
  13779. Description=Kudd.com CreateAMonster. Reportedly stealth installed and <a href="http://sarc.com/avcenter/venc/data/adware.look2me.html" target=_blank>Look2Me</a> adware related
  13780.  
  13781. Source=Paul Collins Startup list
  13782.  
  13783. [CreateCD]
  13784. Number=1957
  13785. Confirmed=N
  13786. Filename=Createcd.exe
  13787. Description=Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
  13788. Source=Paul Collins Startup list
  13789.  
  13790. [CreateCD50]
  13791. Number=1958
  13792. Confirmed=N
  13793. Filename=Createcd50.exe
  13794. Description=Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
  13795. Source=Paul Collins Startup list
  13796.  
  13797. [Creative AGP Wizard]
  13798. Number=1959
  13799. Confirmed=N
  13800. Filename=agpwiz.exe
  13801. Description=Part of Creative's BlasterControl
  13802. Source=Paul Collins Startup list
  13803.  
  13804. [Creative Audio Drivers]
  13805. Number=1960
  13806. Confirmed=X
  13807. Filename=creative.exe
  13808. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfkr.html" target="_blank">RBOT-FKR</a> WORM!
  13809. Source=Paul Collins Startup list
  13810.  
  13811. [Creative Detector]
  13812. Number=1961
  13813. Confirmed=N
  13814. Filename=CTDetect.exe
  13815. Description=Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
  13816. Source=Paul Collins Startup list
  13817.  
  13818. [Creative Launcher]
  13819. Number=1962
  13820. Confirmed=N
  13821. Filename=CTLauncher.exe
  13822. Description=For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
  13823. Source=Paul Collins Startup list
  13824.  
  13825. [Creative MediaSource Go]
  13826. Number=1963
  13827. Confirmed=N
  13828. Filename=CTCMSGo.exe
  13829. Description="Creative <a href="http://www.soundblaster.com/mediasource/" target="_blank"> MediaSource</a> playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats"
  13830. Source=Paul Collins Startup list
  13831.  
  13832. [Creative PCI Audio Configuration Utility]
  13833. Number=1964
  13834. Confirmed=N
  13835. Filename=starter.exe
  13836. Description=System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on <a href="http://www.pacs-portal.co.uk/startup_pages/starter_exe.htm" target="_blank">this</a> special page. Similar to EnsoniqMixer
  13837. Source=Paul Collins Startup list
  13838.  
  13839. [Creative Service for CDROM Access]
  13840. Number=1965
  13841. Confirmed=N
  13842. Filename=Ctsvccda.exe
  13843. Description=Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs
  13844. Source=Paul Collins Startup list
  13845.  
  13846. [Creative WebCam Tray]
  13847. Number=1966
  13848. Confirmed=N
  13849. Filename=Camtray.exe
  13850. Description=Creative WebCam tray control - can be started manually
  13851.  
  13852. Source=Paul Collins Startup list
  13853.  
  13854. [Creative.exe]
  13855. Number=1967
  13856. Confirmed=X
  13857. Filename=Creative.exe
  13858. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2000-122112-0126-99" target="_blank">PROLIN</a> WORM!
  13859. Source=Paul Collins Startup list
  13860.  
  13861. [CreativeDiscNotifier]
  13862. Number=1968
  13863. Confirmed=N
  13864. Filename=CTNOTIFY.EXE
  13865. Description=For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel
  13866. Source=Paul Collins Startup list
  13867.  
  13868. [CreativeMixer]
  13869. Number=1969
  13870. Confirmed=U
  13871. Filename=CTMIX32.EXE
  13872. Description=Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon
  13873. Source=Paul Collins Startup list
  13874.  
  13875. [CreativeTaskScheduler]
  13876. Number=1970
  13877. Confirmed=?
  13878. Filename=CTSched.exe
  13879. Description=<a href="http://www.creative.com/" target="_blank">Creative</a> Task Scheduler. <font color="#FF0000">What does it do and is it required?</font>
  13880. Source=Paul Collins Startup list
  13881.  
  13882. [Critical Update Check]
  13883. Number=1971
  13884. Confirmed=X
  13885. Filename=battlenet.exe
  13886. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelflb.html" target=_blank>DELF-LB</a> TROJAN!
  13887. Source=Paul Collins Startup list
  13888.  
  13889. [CriticalUpdate]
  13890. Number=1972
  13891. Confirmed=N
  13892. Filename=Wucrtupd.exe
  13893. Description=MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
  13894. Source=Paul Collins Startup list
  13895.  
  13896. [CriticalUpdate]
  13897. Number=1973
  13898. Confirmed=X
  13899. Filename=wucrtupd.exe
  13900. Description=Added by the <a href="http://vil.nai.com/vil/content/v_100790.htm" target=_blank>NOALA.B</a> WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/wucrtupd/" target=_blank>here</a>
  13901. Source=Paul Collins Startup list
  13902.  
  13903. [Crnsava]
  13904. Number=1974
  13905. Confirmed=X
  13906. Filename=scrnsave.pif
  13907. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotzv.html" target=_blank>SDBOT-ZV</a> WORM!
  13908. Source=Paul Collins Startup list
  13909.  
  13910. [cronos]
  13911. Number=1975
  13912. Confirmed=X
  13913. Filename=MARCO!.SCR
  13914. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.G" target="_blank">OPASERV.G</a> WORM!
  13915. Source=Paul Collins Startup list
  13916.  
  13917. [CrossMenu]
  13918. Number=1976
  13919. Confirmed=X
  13920. Filename=CrossMenu
  13921. Description=Toshiba CrossMenu Utility - allows the user to create their own menus
  13922. Source=Paul Collins Startup list
  13923.  
  13924. [CRP386 Networking]
  13925. Number=1977
  13926. Confirmed=X
  13927. Filename=crp386.exe
  13928. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Backdoor.Win32.IRCBot.n&threatid=10896" target="_blank">IRCBOT.N</a> TROJAN!
  13929. Source=Paul Collins Startup list
  13930.  
  13931. [crs]
  13932. Number=1978
  13933. Confirmed=X
  13934. Filename=crs.exe
  13935. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobottj.html" target=_blank>AGOBOT-TJ</a> WORM!
  13936. Source=Paul Collins Startup list
  13937.  
  13938. [CRSSXP SysInfo]
  13939. Number=1979
  13940. Confirmed=X
  13941. Filename=crssxp.exe
  13942. Description=Added by the <a href="http://www.scanspyware.net/info/Sdbot.NHS.htm" target="_blank">SDBOT.NHS</a> WORM!
  13943. Source=Paul Collins Startup list
  13944.  
  13945. [Crusty]
  13946. Number=1980
  13947. Confirmed=X
  13948. Filename=dmcpl.exe
  13949. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021517-4140-99" target="_blank">RUSTY</a> WORM!
  13950. Source=Paul Collins Startup list
  13951.  
  13952. [cryptdlg]
  13953. Number=1981
  13954. Confirmed=X
  13955. Filename=cryptdlg.exe
  13956. Description=Added by an unidentified TROJAN!
  13957. Source=Paul Collins Startup list
  13958.  
  13959. [cryptoexpert]
  13960. Number=1982
  13961. Confirmed=U
  13962. Filename=cexpert.exe
  13963. Description=<a href="http://www.secureaction.com/cryptoexpert/" target="_blank">CryptoExpert</a> from SecureAction Research. Advanced on the fly encryption system
  13964. Source=Paul Collins Startup list
  13965.  
  13966. [Cryptographic Service]
  13967. Number=1983
  13968. Confirmed=X
  13969. Filename=******.exe [* = random char]
  13970. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-070217-1202-99" target="_blank">KORGO.W</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-080213-0953-99" target="_blank">KORGO.X</a> or <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39581" target="_blank">KORGO.AB</a> WORMS!
  13971. Source=Paul Collins Startup list
  13972.  
  13973. [Crystal 3D Audio Control]
  13974. Number=1984
  13975. Confirmed=?
  13976. Filename=CWD3DSND.EXE
  13977. Description=Crystal 3D Audio sound driver. <font color="#FF0000">Is it required?</font>
  13978. Source=Paul Collins Startup list
  13979.  
  13980. [csaRem]
  13981. Number=1985
  13982. Confirmed=N
  13983. Filename=spqmdmui.exe
  13984. Description=Compaq modem country selection 
  13985. Source=Paul Collins Startup list
  13986.  
  13987. [CSAV_CheckViruses]
  13988. Number=1986
  13989. Confirmed=Y
  13990. Filename=vchk.exe
  13991. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> related
  13992. Source=Paul Collins Startup list
  13993.  
  13994. [csc]
  13995. Number=1987
  13996. Confirmed=U
  13997. Filename=csc.exe
  13998. Description=Command line compiler for Microsoft C# it gets installed with the .NET SDK
  13999. Source=Paul Collins Startup list
  14000.  
  14001. [CSCRS Value]
  14002. Number=1988
  14003. Confirmed=X
  14004. Filename=cscrs.exe
  14005. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaaa.html" target=_blank>RBOT-AAA</a> WORM!
  14006. Source=Paul Collins Startup list
  14007.  
  14008. [CSCRS Value Check]
  14009. Number=1989
  14010. Confirmed=X
  14011. Filename=MsPMSPSd.exe
  14012. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  14013. Source=Paul Collins Startup list
  14014.  
  14015. [CSINJECT.EXE]
  14016. Number=1990
  14017. Confirmed=U
  14018. Filename=CSINJECT.EXE
  14019. Description=Part of Quarterdeck/Norton CleanSweep. "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"
  14020. Source=Paul Collins Startup list
  14021.  
  14022. [csm Win Updates]
  14023. Number=1991
  14024. Confirmed=X
  14025. Filename=csm.exe
  14026. Description=Added by the <a href="http://vil.nai.com/vil/content/v_135435.htm" target=_blank>ZOTOB.B</a> WORM!
  14027. Source=Paul Collins Startup list
  14028.  
  14029. [csoftok]
  14030. Number=1992
  14031. Confirmed=X
  14032. Filename=softok.exe
  14033. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050913-5746-99" target= blank>QQPASS.G</a> TROJAN!
  14034. Source=Paul Collins Startup list
  14035.  
  14036. [csrs]
  14037. Number=1993
  14038. Confirmed=X
  14039. Filename=csrs.exe
  14040. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031915-3501-99" target="_blank">GAOBOT.GEN!POLY</a> WORM!
  14041. Source=Paul Collins Startup list
  14042.  
  14043. [csrsc]
  14044. Number=1994
  14045. Confirmed=X
  14046. Filename=csrsc.exe
  14047. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  14048. Source=Paul Collins Startup list
  14049.  
  14050. [CSRSS]
  14051. Number=1995
  14052. Confirmed=X
  14053. Filename=CSRSS.EXE
  14054. Description=Search page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  14055. Source=Paul Collins Startup list
  14056.  
  14057. [Csrss]
  14058. Number=1996
  14059. Confirmed=X
  14060. Filename=csrss.exe
  14061. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031323-3628-99" target="_blank">CHOD</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup and the executeable resides in a random folder name
  14062. Source=Paul Collins Startup list
  14063.  
  14064. [csrss]
  14065. Number=1997
  14066. Confirmed=X
  14067. Filename=csrss.exe
  14068. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojkeylogaq.html" target=_blank>KEYLOG-AQ</a> KEYLOGGER! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
  14069. Source=Paul Collins Startup list
  14070.  
  14071. [csrss]
  14072. Number=1998
  14073. Confirmed=X
  14074. Filename=csrss.exe
  14075. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32chodej.html" target=_blank>CHODE-J</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a random subfolder
  14076. Source=Paul Collins Startup list
  14077.  
  14078. [csrss]
  14079. Number=1999
  14080. Confirmed=X
  14081. Filename=msmsgs.exe
  14082. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32chodej.html" target=_blank>CHODE-J</a> WORM!
  14083. Source=Paul Collins Startup list
  14084.  
  14085. [csrss]
  14086. Number=2000
  14087. Confirmed=X
  14088. Filename=nwiz.exe
  14089. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32chodej.html" target=_blank>CHODE-J</a> WORM!
  14090. Source=Paul Collins Startup list
  14091.  
  14092. [csrss]
  14093. Number=2001
  14094. Confirmed=U
  14095. Filename=csrss.exe
  14096. Description=<a href="http://www.sarc.com/avcenter/venc/data/spyware.beyondkeylog.html" target="_blank">BeyondKeylog</a> surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program Files/Supremtec folder
  14097. Source=Paul Collins Startup list
  14098.  
  14099. [CSRSS Loader]
  14100. Number=2002
  14101. Confirmed=X
  14102. Filename=csrsss.exe
  14103. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.TX" target=_blank>AGOBOT.TX</a> WORM!
  14104. Source=Paul Collins Startup list
  14105.  
  14106. [csrss.exe]
  14107. Number=2003
  14108. Confirmed=X
  14109. Filename=csrss.exe
  14110. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-070603-2351-99" target=_blank>DALBUG</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the Winnt\System32 or Windows\System32 folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  14111. Source=Paul Collins Startup list
  14112.  
  14113. [csrssLevel4]
  14114. Number=2004
  14115. Confirmed=X
  14116. Filename=csrss.exe
  14117. Description=Unidentified malware. Note - this file is placed in a C:\Windows\System\Level4 folder, and should NOT be confused with the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the Winnt\System32 or Windows\System32 folder and should NOT figure in Msconfig/Startup!
  14118. Source=Paul Collins Startup list
  14119.  
  14120. [CSRSSU]
  14121. Number=2005
  14122. Confirmed=X
  14123. Filename=CSRSSU.exe
  14124. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant - hijacking to Slawsearch.com. Also detected as the <a href="http://www.sophos.com/virusinfo/analyses/trojcwse.html" target= blank>CWS-E</a> TROJAN!
  14125. Source=Paul Collins Startup list
  14126.  
  14127. [CSRSSW]
  14128. Number=2006
  14129. Confirmed=X
  14130. Filename=CSRSSW.EXE
  14131. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcwsf.html" target= blank>CWS-F</a> TROJAN!
  14132. Source=Paul Collins Startup list
  14133.  
  14134. [CSRSWIN]
  14135. Number=2007
  14136. Confirmed=X
  14137. Filename=[trojan filename]
  14138. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080611-0047-99" target="_blank">WINSHELL.50</a> TROJAN!
  14139. Source=Paul Collins Startup list
  14140.  
  14141. [CSRSX]
  14142. Number=2008
  14143. Confirmed=X
  14144. Filename=[trojan filename]
  14145. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-081110-5211-99" target="_blank">WINSHELL.50.B</a> TROJAN!
  14146. Source=Paul Collins Startup list
  14147.  
  14148. [CSS Server]
  14149. Number=2009
  14150. Confirmed=U
  14151. Filename=CSSServer.exe
  14152. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-082415-5002-99" target="_blank">ComSpySysSvr</a> surveillance software. Uninstall this software unless you put it there yourself
  14153. Source=Paul Collins Startup list
  14154.  
  14155. [cssauth]
  14156. Number=2010
  14157. Confirmed=U
  14158. Filename=cssauth.exe
  14159. Description=Related to IBM ThinkVantage Client Security Solution
  14160.  
  14161. Source=Paul Collins Startup list
  14162.  
  14163. [CSScheduleCheck]
  14164. Number=2011
  14165. Confirmed=Y
  14166. Filename=SCHWIZEX.EXE
  14167. Description=Part of <a href="http://www.imaginelan.com/configsafe/index.html" target="_blank"> ConfigSafe</a> - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
  14168. Source=Paul Collins Startup list
  14169.  
  14170. [cssrs]
  14171. Number=2012
  14172. Confirmed=X
  14173. Filename=cssrs.exe
  14174. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbandw.html" target="_blank">BANCBAN-DW</a> TROJAN!
  14175. Source=Paul Collins Startup list
  14176.  
  14177. [csss]
  14178. Number=2013
  14179. Confirmed=X
  14180. Filename=Csss.exe
  14181. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-112709-2857-99" target="_blank">BALICK</a> TROJAN!
  14182. Source=Paul Collins Startup list
  14183.  
  14184. [CSS_Central]
  14185. Number=2014
  14186. Confirmed=U
  14187. Filename=CSS_1631.EXE
  14188. Description=CSS Communication Agent (95 Host) from Command Software Systems (now <a href="http://www.commandcom.com/" target="_blank">Authentium</a>). "CSS CentralÖ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"
  14189. Source=Paul Collins Startup list
  14190.  
  14191. [CSV10P1]
  14192. Number=2015
  14193. Confirmed=X
  14194. Filename=CSP001.exe
  14195. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  14196. Source=Paul Collins Startup list
  14197.  
  14198. [CSV10P70]
  14199. Number=2016
  14200. Confirmed=X
  14201. Filename=CSv10P070.exe
  14202. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  14203. Source=Paul Collins Startup list
  14204.  
  14205. [CSV7P26]
  14206. Number=2017
  14207. Confirmed=X
  14208. Filename=CSV7P26.exe
  14209. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  14210. Source=Paul Collins Startup list
  14211.  
  14212. [CSV7P70]
  14213. Number=2018
  14214. Confirmed=X
  14215. Filename=CSV7P070.exe
  14216. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  14217. Source=Paul Collins Startup list
  14218.  
  14219. [CSV7P91]
  14220. Number=2019
  14221. Confirmed=X
  14222. Filename=CSV7P91.exe
  14223. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092410-4648-99" target=_blank>ClearSearch</a> adware
  14224. Source=Paul Collins Startup list
  14225.  
  14226. [csvdea]
  14227. Number=2020
  14228. Confirmed=U
  14229. Filename=csvdea.exe
  14230. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-072112-1717-99" target="_blank">SpyArsenalLog</a> surveillance software. Uninstall this software unless you put it there yourself
  14231. Source=Paul Collins Startup list
  14232.  
  14233. [csvhost.exe]
  14234. Number=2021
  14235. Confirmed=X
  14236. Filename=csvhost.exe
  14237. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcimuzbd.html" target="_blank">CIMUZ-BD</a> TROJAN!
  14238. Source=Paul Collins Startup list
  14239.  
  14240. [ct]
  14241. Number=2022
  14242. Confirmed=Y
  14243. Filename=ct.exe
  14244. Description=ct.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it
  14245. Source=Paul Collins Startup list
  14246.  
  14247. [CT Control Settings]
  14248. Number=2023
  14249. Confirmed=X
  14250. Filename=CTSVCCD.EXE
  14251. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotys.html" target=_blank>RBOT-YS</a> WORM!
  14252. Source=Paul Collins Startup list
  14253.  
  14254. [CTAVTray]
  14255. Number=2024
  14256. Confirmed=N
  14257. Filename=CTAvTray.exe
  14258. Description=For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
  14259. Source=Paul Collins Startup list
  14260.  
  14261. [CTCMonitor]
  14262. Number=2025
  14263. Confirmed=U
  14264. Filename=CTCMonitor.exe
  14265. Description=<a href="http://www.clicktoconvert.com/Features/features.html" target=_blank>Click-to-Convert</a> - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required
  14266. Source=Paul Collins Startup list
  14267.  
  14268. [CTDVDDet]
  14269. Number=2026
  14270. Confirmed=N
  14271. Filename=CTDVDDet.exe
  14272. Description=Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
  14273. Source=Paul Collins Startup list
  14274.  
  14275. [CTDVDDet]
  14276. Number=2027
  14277. Confirmed=N
  14278. Filename=CTDetect.exe
  14279. Description=Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
  14280. Source=Paul Collins Startup list
  14281.  
  14282. [ctflog manager]
  14283. Number=2028
  14284. Confirmed=X
  14285. Filename=ctflog.exe
  14286. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DONBOMB.A&VSect=P" target=_blank>DONBOMB.A</a> TROJAN!
  14287. Source=Paul Collins Startup list
  14288.  
  14289. [CTFM0N.exe]
  14290. Number=2029
  14291. Confirmed=X
  14292. Filename=CTFM0N.exe
  14293. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-070512-2031-99" target=_blank>STARTPAGE.P</a> TROJAN!
  14294. Source=Paul Collins Startup list
  14295.  
  14296. [ctfmon]
  14297. Number=2030
  14298. Confirmed=U
  14299. Filename=ctfmon.exe
  14300. Description=CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;282599" target=_blank>here</a>. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see <a href="http://actualtools.com/forum/read.php?FID=9&TID=63" target=_blank>here</a> for such an example
  14301. Source=Paul Collins Startup list
  14302.  
  14303. [ctfmon]
  14304. Number=2031
  14305. Confirmed=X
  14306. Filename=taskmgr32*.exe [* = number]
  14307. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080617-4010-99" target="_blank">SOWSAT.B</a> WORM!
  14308. Source=Paul Collins Startup list
  14309.  
  14310. [ctfmon]
  14311. Number=2032
  14312. Confirmed=X
  14313. Filename=cftmon.exe
  14314. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelivea.html" target= blank>DELIVE-A</a> TROJAN! Note - this file is found in C:\Windows or C:\Winnt and is not the valid MS Office file of the same name (see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;282599" target= blank>here</a>)
  14315. Source=Paul Collins Startup list
  14316.  
  14317. [ctfmon]
  14318. Number=2033
  14319. Confirmed=X
  14320. Filename=mIRC.dll
  14321. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelbote.html" target=_blank>DELBOT-E</a> TROJAN!
  14322. Source=Paul Collins Startup list
  14323.  
  14324. [ctfmon]
  14325. Number=2034
  14326. Confirmed=X
  14327. Filename=WinConst.exe
  14328. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojassasing.html" target=_blank>ASSASIN-G</a> TROJAN!
  14329. Source=Paul Collins Startup list
  14330.  
  14331. [CTFMon]
  14332. Number=2035
  14333. Confirmed=U
  14334. Filename=ctfmon.exe
  14335. Description=<a href="http://www.spyarsenal.com/familykeylogger/" target=_blank>Family Keylogger</a> is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Keystroke logger/monitoring program - remove unless you installed it yourself! Found in the System\CTF (9x/Me) or System32\CTF (NT/2K/XP) folder
  14336.  
  14337. Source=Paul Collins Startup list
  14338.  
  14339. [ctfmon]
  14340. Number=2036
  14341. Confirmed=X
  14342. Filename=msnmsgr.exe
  14343. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorjv.html" target=_blank>JV</a> TROJAN!
  14344. Source=Paul Collins Startup list
  14345.  
  14346. [Ctfmon.exe]
  14347. Number=2037
  14348. Confirmed=X
  14349. Filename=ctfmon32.exe
  14350. Description=CoolWebSearch <a href="http://cwshredder.net/cwshredder/cwschronicles.html#ctfmon32" target=_blank>Ctfmon32</a> parasite variant
  14351. Source=Paul Collins Startup list
  14352.  
  14353. [ctfmon.exe]
  14354. Number=2038
  14355. Confirmed=X
  14356. Filename=ctfmon.exe
  14357. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-062417-1936-99" target=_blank>RAIDYS</a> TROJAN! Note - this should not be confused with the valid Office XP file, see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;282599" target=_blank>here</a>
  14358. Source=Paul Collins Startup list
  14359.  
  14360. [ctfmon.exe]
  14361. Number=2039
  14362. Confirmed=X
  14363. Filename=msupdate32.exe
  14364. Description=Spy Sheriff/SpywareNO malware, also detected as the <a href="http://www.sophos.com/virusinfo/analyses/trojspyhoaxa.html" target=_blank>SPYHOAX-A</a> TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
  14365. Source=Paul Collins Startup list
  14366.  
  14367. [ctfmon.exe]
  14368. Number=2040
  14369. Confirmed=U
  14370. Filename=ctfmon.exe
  14371. Description=CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;282599" target="_blank">here</a>. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see <a href="http://actualtools.com/forum/read.php?FID=9&TID=63" target="_blank">here</a> for such an example
  14372. Source=Paul Collins Startup list
  14373.  
  14374. [CTFMON32]
  14375. Number=2041
  14376. Confirmed=X
  14377. Filename=CTFMON32.EXE
  14378. Description=CoolWebSearch <a href="http://cwshredder.net/cwshredder/cwschronicles.html#ctfmon32" target=_blank>Ctfmon32</a> parasite variant - also detected as the <a href="http://www.sophos.com/virusinfo/analyses/trojcwse.html" target= blank>CWS-E</a> TROJAN!
  14379. Source=Paul Collins Startup list
  14380.  
  14381. [CTFMONSS]
  14382. Number=2042
  14383. Confirmed=X
  14384. Filename=CTFMONSS.EXE
  14385. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcwsf.html" target= blank>CWS-F</a> TROJAN!
  14386. Source=Paul Collins Startup list
  14387.  
  14388. [ctfnom]
  14389. Number=2043
  14390. Confirmed=X
  14391. Filename=rundIl32.exe
  14392. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlegmiraw.html" target=_blank>LEGMIR-AW</a> TROJAN!
  14393. Source=Paul Collins Startup list
  14394.  
  14395. [ctfnom.exe]
  14396. Number=2044
  14397. Confirmed=X
  14398. Filename=SVOHOST.exe
  14399. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdigidora.html" target=_blank>DIGIDOR-A</a> TROJAN!
  14400. Source=Paul Collins Startup list
  14401.  
  14402. [ctfnom.exe]
  14403. Number=2045
  14404. Confirmed=X
  14405. Filename=OSRSS.exe
  14406. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderuq.html" target=_blank>DLOADER-UQ</a> TROJAN!
  14407. Source=Paul Collins Startup list
  14408.  
  14409. [CTHELPER]
  14410. Number=2046
  14411. Confirmed=U
  14412. Filename=CTHELPER.EXE
  14413. Description=CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
  14414. Source=Paul Collins Startup list
  14415.  
  14416. [CTHelper]
  14417. Number=2047
  14418. Confirmed=X
  14419. Filename=cthelper.exe
  14420. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotxb.html" target= blank>RBOT-XB</a> WORM! Note - do not confuse with the Creative application of the same name described <a href="http://www.sysinfo.org/startuplist.php?filter=cthelper.exe" target= blank>here</a>
  14421. Source=Paul Collins Startup list
  14422.  
  14423. [CTime]
  14424. Number=2048
  14425. Confirmed=X
  14426. Filename=[path to trojan]
  14427. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-012015-3226-99" target="_blank">HTTPDOS</a> TROJAN!
  14428. Source=Paul Collins Startup list
  14429.  
  14430. [CTin10]
  14431. Number=2049
  14432. Confirmed=X
  14433. Filename=CTin10.exe
  14434. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-022710-5851-99" target="_blank">BANCOS.E</a> TROJAN!
  14435. Source=Paul Collins Startup list
  14436.  
  14437. [CtModule]
  14438. Number=2050
  14439. Confirmed=X
  14440. Filename=CtModule.exe
  14441. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojclickereg.html" target="_blank">CLICKER-EG</a> TROJAN!
  14442. Source=Paul Collins Startup list
  14443.  
  14444. [CTNMRUN]
  14445. Number=2051
  14446. Confirmed=U
  14447. Filename=ctnmrun.exe
  14448. Description=Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
  14449. Source=Paul Collins Startup list
  14450.  
  14451. [CTPDPSRV]
  14452. Number=2052
  14453. Confirmed=?
  14454. Filename=CTPDPSRV.EXE
  14455. Description=Printer driver (in the WINDOWS\System32\spool\DRIVERS\W32\X86 folder).<font color="#FF0000"> Is it required?</font>
  14456. Source=Paul Collins Startup list
  14457.  
  14458. [CTPerformanceUtility]
  14459. Number=2053
  14460. Confirmed=N
  14461. Filename=CTPowUti.exe
  14462. Description=Related to <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/ctpowuti/" target="_blank">Creative PowerSysTrayApp</a>. This program is a non-essential process, but should not be terminated unless suspected to be causing problems
  14463. Source=Paul Collins Startup list
  14464.  
  14465. [ctpmon]
  14466. Number=2054
  14467. Confirmed=X
  14468. Filename=ctpmon.exe
  14469. Description=System Registry Cleaner - stealth installed foistware from sysregistry.com
  14470. Source=Paul Collins Startup list
  14471.  
  14472. [CTRegRun]
  14473. Number=2055
  14474. Confirmed=N
  14475. Filename=CTRegRun.exe
  14476. Description=For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
  14477. Source=Paul Collins Startup list
  14478.  
  14479. [CtrlVol]
  14480. Number=2056
  14481. Confirmed=U
  14482. Filename=CtrlVol.exe
  14483. Description=Volume control key on Acer, Fujitsu and other laptops
  14484. Source=Paul Collins Startup list
  14485.  
  14486. [CTSched]
  14487. Number=2057
  14488. Confirmed=?
  14489. Filename=CTSched.exe
  14490. Description=<a href="http://www.creative.com/" target="_blank">Creative</a> Task Scheduler. <font color="#FF0000">What does it do and is it required?</font>
  14491. Source=Paul Collins Startup list
  14492.  
  14493. [CTStartup]
  14494. Number=2058
  14495. Confirmed=N
  14496. Filename=CTEaxSpl.exe
  14497. Description=Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
  14498. Source=Paul Collins Startup list
  14499.  
  14500. [CTSyncU.exe]
  14501. Number=2059
  14502. Confirmed=N
  14503. Filename=CTSyncU.exe
  14504. Description=<a href="http://www.creative.com/" target="_blank">Creative</a> Sync Manager</a> - synchronizes music tracks on your computer with your player
  14505. Source=Paul Collins Startup list
  14506.  
  14507. [CTsysVol]
  14508. Number=2060
  14509. Confirmed=U
  14510. Filename=CTSYSVOL.exe
  14511. Description=Creative sound card volume controls
  14512. Source=Paul Collins Startup list
  14513.  
  14514. [cttdpsrv]
  14515. Number=2061
  14516. Confirmed=?
  14517. Filename=cttdpsrv.exe
  14518. Description=<font color="#FF0000">??</font>
  14519. Source=Paul Collins Startup list
  14520.  
  14521. [CTUpdate]
  14522. Number=2062
  14523. Confirmed=X
  14524. Filename=ctupdclt.exe
  14525. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotabg.html" target= blank>RBOT-ABG</a> WORM!
  14526. Source=Paul Collins Startup list
  14527.  
  14528. [CTxfiHlp]
  14529. Number=2063
  14530. Confirmed=N
  14531. Filename=CTXFIHLP.EXE
  14532. Description=Added by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card
  14533.  
  14534. Source=Paul Collins Startup list
  14535.  
  14536. [CTXFIREG]
  14537. Number=2064
  14538. Confirmed=N
  14539. Filename=CTxfiReg.exe
  14540. Description=Creative Labs sound card driver related. It appears that it isn't required and maybe registration related
  14541. Source=Paul Collins Startup list
  14542.  
  14543. [Ctykd]
  14544. Number=2065
  14545. Confirmed=X
  14546. Filename=[path to file]
  14547. Description=<a href="http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY_SMALL.SN&VSect=Td" target=_blank>SMALL.SN</a> spyware
  14548. Source=Paul Collins Startup list
  14549.  
  14550. [CU1]
  14551. Number=2066
  14552. Confirmed=X
  14553. Filename=VCClient.exe
  14554. Description=Associated with the Surf Sidekick adware and should be removed
  14555. Source=Paul Collins Startup list
  14556.  
  14557. [CU2]
  14558. Number=2067
  14559. Confirmed=X
  14560. Filename=VCMain.exe
  14561. Description=Associated with the Surf Sidekick adware and should be removed
  14562. Source=Paul Collins Startup list
  14563.  
  14564. [cuagentExe]
  14565. Number=2068
  14566. Confirmed=Y
  14567. Filename=Cuagent.exe
  14568. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> related
  14569. Source=Paul Collins Startup list
  14570.  
  14571. [cuo]
  14572. Number=2069
  14573. Confirmed=X
  14574. Filename=cuo.exe
  14575. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BUGBEAR.A" target="_blank">BUGBEAR.A</a> WORM!
  14576. Source=Paul Collins Startup list
  14577.  
  14578. [Current Security Config]
  14579. Number=2070
  14580. Confirmed=X
  14581. Filename=csecure.exe
  14582. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotamo.html" target=_blank>RBOT-AMO</a> WORM!
  14583. Source=Paul Collins Startup list
  14584.  
  14585. [cursor]
  14586. Number=2071
  14587. Confirmed=N
  14588. Filename=Screendragon_VS_Taskbar.exe
  14589. Description=<a href="http://www.screendragon.com/" target="_blank">ScreenDragon</a> video player
  14590. Source=Paul Collins Startup list
  14591.  
  14592. [CursorXP]
  14593. Number=2072
  14594. Confirmed=N
  14595. Filename=CursorXP.exe
  14596. Description=<a href="http://www.stardock.com/products/cursorxp/" target="_blank">CursorXP</a> from Stardock - tool for creating mouse cursors
  14597. Source=Paul Collins Startup list
  14598.  
  14599. [Customizer2000]
  14600. Number=2073
  14601. Confirmed=U
  14602. Filename=logon.exe
  14603. Description=Automatic logon feature of <a href="http://www.hot-shareware.com/utilities/customizer-2000/" target="_blank">Customizer 2000</a> - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes"
  14604. Source=Paul Collins Startup list
  14605.  
  14606. [CuteMX]
  14607. Number=2074
  14608. Confirmed=N
  14609. Filename=CuteMX.EXE
  14610. Description=File sharing utility
  14611. Source=Paul Collins Startup list
  14612.  
  14613. [cvmonitor.exe]
  14614. Number=2075
  14615. Confirmed=X
  14616. Filename=cvmonitor.exe
  14617. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BV" target="_blank">SDBOT.BV</a> WORM!
  14618. Source=Paul Collins Startup list
  14619.  
  14620. [CVPND]
  14621. Number=2076
  14622. Confirmed=Y
  14623. Filename=cvpnd.exe
  14624. Description=Sub-system used by Cisco VPN client for making a connection to a remote IPSec server
  14625. Source=Paul Collins Startup list
  14626.  
  14627. [CW]
  14628. Number=2077
  14629. Confirmed=U
  14630. Filename=cw4.exe
  14631. Description=<a href="http://www.zemericks.com/products/chatwatch/index.asp" target=_blank>Chat Watch</a> "is a monitoring and logging software for online chat and instant messaging programs"
  14632. Source=Paul Collins Startup list
  14633.  
  14634. [CWatch]
  14635. Number=2078
  14636. Confirmed=U
  14637. Filename=cw.exe
  14638. Description=<a href="http://www.zemericks.com/products/chatwatch/index.asp" target="_blank">ChatWatch</a> - chat monitoring tool
  14639. Source=Paul Collins Startup list
  14640.  
  14641. [cwbckver]
  14642. Number=2079
  14643. Confirmed=N
  14644. Filename=cwbckver.exe
  14645. Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
  14646. Source=Paul Collins Startup list
  14647.  
  14648. [cwbinhlp]
  14649. Number=2080
  14650. Confirmed=N
  14651. Filename=cwbinhlp.exe
  14652. Description=Client Access Help Registry Update Function - part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
  14653. Source=Paul Collins Startup list
  14654.  
  14655. [cwbsvstr]
  14656. Number=2081
  14657. Confirmed=N
  14658. Filename=cwbsvstr.exe
  14659. Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
  14660. Source=Paul Collins Startup list
  14661.  
  14662. [cwbwlwiz]
  14663. Number=2082
  14664. Confirmed=?
  14665. Filename=cwbwlwiz.exe
  14666. Description=Welcome wizard launcher - Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. <font color="#FF0000">What does it do and is it required?</font>
  14667. Source=Paul Collins Startup list
  14668.  
  14669. [Cwcdschk.exe]
  14670. Number=2083
  14671. Confirmed=?
  14672. Filename=Cwcdschk.exe
  14673. Description=<font color="#FF0000">IBM Thinkpad related?</font>
  14674. Source=Paul Collins Startup list
  14675.  
  14676. [cwcptray]
  14677. Number=2084
  14678. Confirmed=U
  14679. Filename=cwcptray.exe
  14680. Description=Related to <a href="http://www.contentwatch.com/" target=_blank>ContentWatch</a> Parental Control internet filter
  14681. Source=Paul Collins Startup list
  14682.  
  14683. [cwingllib]
  14684. Number=2085
  14685. Confirmed=X
  14686. Filename=atllsimm.exe
  14687. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  14688. Source=Paul Collins Startup list
  14689.  
  14690. [cwupdate]
  14691. Number=2086
  14692. Confirmed=U
  14693. Filename=cwupdate.exe
  14694. Description=<a href="http://www.contentwatch.com/products/contentprotect.php" target=_blank>ContentProtect</a> from ContentWatch - internet filter
  14695. Source=Paul Collins Startup list
  14696.  
  14697. [CXMon]
  14698. Number=2087
  14699. Confirmed=N
  14700. Filename=Hpi_Monitor.exe
  14701. Description=Autodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
  14702. Source=Paul Collins Startup list
  14703.  
  14704. [Cyber]
  14705. Number=2088
  14706. Confirmed=N
  14707. Filename=cyberchk.exe
  14708. Description=Part of Belkins "Multimedia Cleaning Kit" and is 
  14709. automatically installed when you run their optical disk drive cleaning utility - to remind 
  14710. you to clean your drive after "x" amount of time has passed
  14711. Source=Paul Collins Startup list
  14712.  
  14713. [Cyber Trio]
  14714. Number=2089
  14715. Confirmed=U
  14716. Filename=showmode.exe
  14717. Description=From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs
  14718. Source=Paul Collins Startup list
  14719.  
  14720. [Cyber-Defender 2003]
  14721. Number=2090
  14722. Confirmed=U
  14723. Filename=uwcdsvr.exe
  14724. Description=<a href="http://www.pcworld.com/downloads/file/fid,24815-order,1-page,1-c,alldownloads/description.html" target="_blank">Cyber Defender 2003</a>
  14725. Source=Paul Collins Startup list
  14726.  
  14727. [cyberfree.exe]
  14728. Number=2091
  14729. Confirmed=X
  14730. Filename=****.dat [* = random char]
  14731. Description=Unidentified adware
  14732. Source=Paul Collins Startup list
  14733.  
  14734. [Cyberhawk]
  14735. Number=2092
  14736. Confirmed=U
  14737. Filename=CHTray.exe
  14738. Description=<a href="http://www.novatix.com/" target="_blank">Cyberhawk</a> from Novatix. Protects against viruses, spyware, identity theft
  14739. Source=Paul Collins Startup list
  14740.  
  14741. [CyberLat Ram Cleaner]
  14742. Number=2093
  14743. Confirmed=U
  14744. Filename=CLRamCleaner.exe
  14745. Description=<a href="http://www.cyberlat.com/ramcleaner/" target="_blank">CyberLat RAM Cleaner</a> - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See <a href="http://aumha.org/win4/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
  14746. Source=Paul Collins Startup list
  14747.  
  14748. [CyberMedia Agent]
  14749. Number=2094
  14750. Confirmed=N
  14751. Filename=CMAGENT.EXE
  14752. Description=Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled
  14753. Source=Paul Collins Startup list
  14754.  
  14755. [CyberPatrolNew]
  14756. Number=2095
  14757. Confirmed=U
  14758. Filename=cphq.exe
  14759. Description="<a href="http://www.cyberpatrol.com/Default.aspx?id=85&mnuid=2" target="_blank">CyberPatrol</a> is one of the most powerful and popular client-based, browser independent, Internet safety software solutions for Windows-based standalone PCs available today"
  14760. Source=Paul Collins Startup list
  14761.  
  14762. [CyberWolf]
  14763. Number=2096
  14764. Confirmed=X
  14765. Filename=CyberWolf.exe
  14766. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-050515-4202-99" target="_blank"> KICKIN.A</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_CYDOG.C" target="_blank">CYDOG.C</a>) WORM!
  14767. Source=Paul Collins Startup list
  14768.  
  14769. [CyDoor]
  14770. Number=2097
  14771. Confirmed=X
  14772. Filename=CD_Load.exe
  14773. Description=Adware. Check <a href="http://www.cexx.org/cydoor.htm" target="_blank">here</a> for information about Cy-Door and <a href="http://www.lavasoft.de/software/adaware/" target="_blank">here</a> for a program that can remove it
  14774. Source=Paul Collins Startup list
  14775.  
  14776. [CydoorUpdate]
  14777. Number=2098
  14778. Confirmed=X
  14779. Filename=CD_Load.exe
  14780. Description=Adware. Check <a href="http://www.cexx.org/cydoor.htm" target="_blank">here</a> for information about Cy-Door and <a href="http://www.lavasoft.de/software/adaware/" target="_blank">here</a> for a program that can remove it
  14781. Source=Paul Collins Startup list
  14782.  
  14783. [CYNHKey]
  14784. Number=2099
  14785. Confirmed=?
  14786. Filename=CYNHKey.exe
  14787. Description=<font color="#FF0000">??</font>
  14788. Source=Paul Collins Startup list
  14789.  
  14790. [CyphTray]
  14791. Number=2100
  14792. Confirmed=N
  14793. Filename=CyphTray.exe
  14794. Description=<a href="http://www.cypherus.com/" target="_blank">Cypherus</a> - encryption software
  14795. Source=Paul Collins Startup list
  14796.  
  14797. [CypressLinkMon]
  14798. Number=2101
  14799. Confirmed=U
  14800. Filename=CypressLinkMon.exe
  14801. Description=Related to <a href="http://cardiology.usa.siemens.com/products-and-it-systems/cardiology-products/ultrasound/acuson-cypress-cardiovascular-system/applications-and-software.aspx" target="_blank">CypressViewer</a> from Siemens that "allows ACUSON Cypress cardiovascular system PLUS users to store, view, and analyze Cypress system PLUS studies on a standard Windows PC"
  14802. Source=Paul Collins Startup list
  14803.  
  14804. [D SYSTEM]
  14805. Number=2102
  14806. Confirmed=X
  14807. Filename=dd.exe
  14808. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobfn.html" target=_blank>MYTOB-FN</a> WORM!
  14809. Source=Paul Collins Startup list
  14810.  
  14811. [D-Link Air USB Utility]
  14812. Number=2103
  14813. Confirmed=Y
  14814. Filename=AirCFG.exe
  14815. Description=D-Link wireless PCI adapter related
  14816. Source=Paul Collins Startup list
  14817.  
  14818. [D-Link Air Utility]
  14819. Number=2104
  14820. Confirmed=Y
  14821. Filename=AirCFG.exe
  14822. Description=D-Link wireless PCI adapter related
  14823. Source=Paul Collins Startup list
  14824.  
  14825. [D-Link AirPlus DWL-650+ Utility]
  14826. Number=2105
  14827. Confirmed=N
  14828. Filename=WLANMON.exe
  14829. Description=D-Link Air Plus Wireless PC modem connection monitor
  14830. Source=Paul Collins Startup list
  14831.  
  14832. [D-Link AirPlus G]
  14833. Number=2106
  14834. Confirmed=Y
  14835. Filename=AirGCFG.exe
  14836. Description=D-Link Airplus Wireless Router driver
  14837. Source=Paul Collins Startup list
  14838.  
  14839. [D-Link AirPlus G Wireless Utility]
  14840. Number=2107
  14841. Confirmed=Y
  14842. Filename=AirPlus.exe
  14843. Description=D-Link <a href="http://www.dlink.com/products/category.asp?cid=1&sec=0#cid_75" target="_blank">AirPlus G</a> wireless configuration and monitoring utility
  14844. Source=Paul Collins Startup list
  14845.  
  14846. [D-Link AirPlus XtremeG]
  14847. Number=2108
  14848. Confirmed=U
  14849. Filename=AirPlusCFG.exe
  14850. Description=D-Link AirPlus XtremeG wireless configuration utility
  14851. Source=Paul Collins Startup list
  14852.  
  14853. [D066UUtility]
  14854. Number=2109
  14855. Confirmed=N
  14856. Filename=D066UUTY.EXE
  14857. Description=TWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
  14858. Source=Paul Collins Startup list
  14859.  
  14860. [D3**.exe [* = random char]]
  14861. Number=2110
  14862. Confirmed=X
  14863. Filename=D3**.exe [* = random char]
  14864. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  14865. Source=Paul Collins Startup list
  14866.  
  14867. [D3**32.exe [* = random char]]
  14868. Number=2111
  14869. Confirmed=X
  14870. Filename=D3**32.exe [* = random char]
  14871. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  14872. Source=Paul Collins Startup list
  14873.  
  14874. [d3dupdate.exe]
  14875. Number=2112
  14876. Confirmed=X
  14877. Filename=bbeagle.exe
  14878. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-011815-3332-99" target="_blank">BEAGLE.A</a> WORM!
  14879. Source=Paul Collins Startup list
  14880.  
  14881. [D4]
  14882. Number=2113
  14883. Confirmed=U
  14884. Filename=D4.exe
  14885. Description=<a href="http://www.thinkman.com/dimension4/index.html" target="_blank">Dimension 4</a> - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
  14886. Source=Paul Collins Startup list
  14887.  
  14888. [dabrun]
  14889. Number=2114
  14890. Confirmed=X
  14891. Filename=rundll32.exe [path] dabapi.dll, Rundll32
  14892. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=SinaUpdateCenter&threatid=91264" target="_blank">SinaUpdateCenter</a> adware
  14893. Source=Paul Collins Startup list
  14894.  
  14895. [DACONFIGEXE]
  14896. Number=2115
  14897. Confirmed=N
  14898. Filename=daconfig.exe
  14899. Description=3Com NIC Diagnostics. Available via Start -> Programs
  14900. Source=Paul Collins Startup list
  14901.  
  14902. [DadApp]
  14903. Number=2116
  14904. Confirmed=Y
  14905. Filename=dadapp.exe
  14906. Description="DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from Dell
  14907. Source=Paul Collins Startup list
  14908.  
  14909. [Daemon]
  14910. Number=2117
  14911. Confirmed=N
  14912. Filename=DAEMON32.EXE
  14913. Description=Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
  14914. Source=Paul Collins Startup list
  14915.  
  14916. [Daemon]
  14917. Number=2118
  14918. Confirmed=U
  14919. Filename=Daemon.exe
  14920. Description=<a href="http://www.daemon-tools.net/main.htm" target="_blank">Daemon Tools</a> - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
  14921. Source=Paul Collins Startup list
  14922.  
  14923. [Daemon]
  14924. Number=2119
  14925. Confirmed=X
  14926. Filename=daemon.exe c daemon2.exe
  14927. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031320-4753-99" target=_blank>SELOTIMA.A</a> WORM!
  14928. Source=Paul Collins Startup list
  14929.  
  14930. [DAEMON Tools-1033]
  14931. Number=2120
  14932. Confirmed=U
  14933. Filename=Daemon.exe
  14934. Description=<a href="http://www.daemon-tools.net/main.htm" target="_blank">Daemon Tools</a> - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
  14935. Source=Paul Collins Startup list
  14936.  
  14937. [Daily Planner]
  14938. Number=2121
  14939. Confirmed=N
  14940. Filename=dayplan.exe
  14941. Description=Daily Planner - discontinued, and now part of <a href="http://www.kmcsonline.com/index.html" target="_blank">KMCS Deluxe System Suite</a>. Tool to plan your days, and check activities off as you complete them
  14942. Source=Paul Collins Startup list
  14943.  
  14944. [Daily Weather Forecast]
  14945. Number=2122
  14946. Confirmed=X
  14947. Filename=weather.exe
  14948. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderip.html" target= blank>DLOADER-IP</a> TROJAN!
  14949. Source=Paul Collins Startup list
  14950.  
  14951. [DamedWare Services]
  14952. Number=2123
  14953. Confirmed=X
  14954. Filename=dwdrce.exe
  14955. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaoj.html" target=_blank>RBOT-AOJ</a> WORM!
  14956. Source=Paul Collins Startup list
  14957.  
  14958. [Dancer]
  14959. Number=2124
  14960. Confirmed=U
  14961. Filename=DncLE.exe
  14962. Description=Part of Microsoft Plus! Digital Media Edition - see <a href="http://www.microsoft.com/windows/plus/dme_more/moreupdates.asp" target=_blank>here</a>
  14963. Source=Paul Collins Startup list
  14964.  
  14965. [Danton*]
  14966. Number=2125
  14967. Confirmed=X
  14968. Filename=[random filename]
  14969. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-032114-0525-99" target="_blank">DANTON</a> TROJAN! where * = random number
  14970. Source=Paul Collins Startup list
  14971.  
  14972. [Dap]
  14973. Number=2126
  14974. Confirmed=N
  14975. Filename=DAP.exe
  14976. Description=<a href="http://www.speedbit.com/" target="_blank">Download Accelerator Plus</a> from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
  14977. Source=Paul Collins Startup list
  14978.  
  14979. [dark]
  14980. Number=2127
  14981. Confirmed=X
  14982. Filename=imgst.scr
  14983. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050210-0214-99" target="_blank">BANCOS.U</a> TROJAN!
  14984. Source=Paul Collins Startup list
  14985.  
  14986. [dark]
  14987. Number=2128
  14988. Confirmed=X
  14989. Filename=imgrt.scr
  14990. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanfh.html" target=_blank>BANCBAN-FH</a> TROJAN!
  14991. Source=Paul Collins Startup list
  14992.  
  14993. [dark]
  14994. Number=2129
  14995. Confirmed=X
  14996. Filename=csrs.scr
  14997. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbangt.html" target=_blank>BANCBAN-GT</a> or <a href="http://www.sophos.com/virusinfo/analyses/trojbancbangu.html" target=_blank>BANCBAN-GU</a> TROJANS!
  14998. Source=Paul Collins Startup list
  14999.  
  15000. [DarkDevil.Grasiele.BR]
  15001. Number=2130
  15002. Confirmed=X
  15003. Filename=Grasiele.VBS
  15004. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-081314-3600-99" target="_blank">LEMBRA</a> WORM!
  15005. Source=Paul Collins Startup list
  15006.  
  15007. [DarKNesS LsasS]
  15008. Number=2131
  15009. Confirmed=X
  15010. Filename=LsasS23.exe
  15011. Description=Added by an unidentified WORM or TROJAN!
  15012. Source=Paul Collins Startup list
  15013.  
  15014. [DashIE]
  15015. Number=2132
  15016. Confirmed=?
  15017. Filename=N/A
  15018. Description=<font color="#FF0000">Could be related to "Dash Power Shopping" tool bar in IE?</font>
  15019. Source=Paul Collins Startup list
  15020.  
  15021. [dasxdads]
  15022. Number=2133
  15023. Confirmed=X
  15024. Filename=fsdqd.exe
  15025. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-090917-0113-99" target="_blank">GAOBOT.BIQ</a> WORM!
  15026. Source=Paul Collins Startup list
  15027.  
  15028. [Data]
  15029. Number=2134
  15030. Confirmed=X
  15031. Filename=System.dat.vbs
  15032. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-092517-0351-99" target="_blank">BISCUIT.A</a> WORM!
  15033. Source=Paul Collins Startup list
  15034.  
  15035. [data]
  15036. Number=2135
  15037. Confirmed=X
  15038. Filename=msngs.exe
  15039. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotadq.html" target=_blank>RBOT-ADQ</a> WORM!
  15040. Source=Paul Collins Startup list
  15041.  
  15042. [Data LifeGuard]
  15043. Number=2136
  15044. Confirmed=N
  15045. Filename=BACKWE~1.EXE
  15046. Description=Data LifeGuard diagnostic tools for Western Digital's series of hard drives
  15047. Source=Paul Collins Startup list
  15048.  
  15049. [Data LifeGuard LifeLine Lite installer]
  15050. Number=2137
  15051. Confirmed=N
  15052. Filename=DLGLI.EXE
  15053. Description=Backweb installer - see <a href="http://www.cexx.org/dlgli.htm" target="_blank"> here</a>
  15054. Source=Paul Collins Startup list
  15055.  
  15056. [Data Restore Service]
  15057. Number=2138
  15058. Confirmed=X
  15059. Filename=prq8.exe
  15060. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042215-3749-99" target= blank>KELVIR.AI</a> WORM!
  15061. Source=Paul Collins Startup list
  15062.  
  15063. [Data789]
  15064. Number=2139
  15065. Confirmed=X
  15066. Filename=Regedit.exe ....data789.tmp
  15067. Description=Homepage hijacker
  15068. Source=Paul Collins Startup list
  15069.  
  15070. [DATABASE MySql]
  15071. Number=2140
  15072. Confirmed=X
  15073. Filename=[path] repcale.exe [path] beird.exe
  15074. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDON.AN" target="_blank">RANDON.AN</a> WORM!
  15075. Source=Paul Collins Startup list
  15076.  
  15077. [DataCaching]
  15078. Number=2141
  15079. Confirmed=N
  15080. Filename=FlashKsk.exe
  15081. Description=<a href="http://www.smartdisk.com" target="_blank">SmartMedia Card</a> management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon
  15082. Source=Paul Collins Startup list
  15083.  
  15084. [DataKeeper]
  15085. Number=2142
  15086. Confirmed=U
  15087. Filename=DataKeeper.exe
  15088. Description=PowerQuest DataKeeper (now owned by <a href="http://www.symantec.com/" target="_blank">Symantec</a>) backup software
  15089. Source=Paul Collins Startup list
  15090.  
  15091. [DataLayer]
  15092. Number=2143
  15093. Confirmed=U
  15094. Filename=DataLayer.exe
  15095. Description=Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
  15096. Source=Paul Collins Startup list
  15097.  
  15098. [DataViz Inc Messenger]
  15099. Number=2144
  15100. Confirmed=X
  15101. Filename=DvzIncMsgr.exe
  15102. Description=Installed with <a href="http://www.dataviz.com/products/documentstogo/" target= blank>DataViz</a> "Documents to Go" software
  15103. Source=Paul Collins Startup list
  15104.  
  15105. [DataViz Messenger]
  15106. Number=2145
  15107. Confirmed=N
  15108. Filename=DvzMsgr.exe
  15109. Description=<a href="http://www.dataviz.com/products/documentstogo/" target="_blank">DataViz Documents to Go</a> - "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"
  15110. Source=Paul Collins Startup list
  15111.  
  15112. [Datcheck]
  15113. Number=2146
  15114. Confirmed=X
  15115. Filename=datcheck.exe
  15116. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-010412-0842-99" target="_blank">KEYPANIC</a> TROJAN!
  15117. Source=Paul Collins Startup list
  15118.  
  15119. [Date Manager]
  15120. Number=2147
  15121. Confirmed=X
  15122. Filename=datemanager.exe
  15123. Description=Date Manager - calender program. Spyware/adware based provided by The Gator Corporation. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  15124. Source=Paul Collins Startup list
  15125.  
  15126. [Datechecker]
  15127. Number=2148
  15128. Confirmed=?
  15129. Filename=N/A
  15130. Description=<font color="#FF0000">Could be related to <a href="http://www.simtel.net/pub/pd/9379.html" target="_blank">this</a>?</font>
  15131. Source=Paul Collins Startup list
  15132.  
  15133. [DateMakerIntl]
  15134. Number=2149
  15135. Confirmed=X
  15136. Filename=DateMakerIntl.exe
  15137. Description=Premium rate adult content dialler
  15138. Source=Paul Collins Startup list
  15139.  
  15140. [DAupdate]
  15141. Number=2150
  15142. Confirmed=X
  15143. Filename=DAupdate.exe
  15144. Description=NavEnhance adware
  15145. Source=Paul Collins Startup list
  15146.  
  15147. [DAW9532.exe]
  15148. Number=2151
  15149. Confirmed=?
  15150. Filename=DAW9532.EXE
  15151. Description=Loaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. <font color="#FF0000">Is it required?</font>
  15152. Source=Paul Collins Startup list
  15153.  
  15154. [DayToday]
  15155. Number=2152
  15156. Confirmed=U
  15157. Filename=DAYTODAY.EXE
  15158. Description=<a href="http://www.locutuscodeware.com/daytoday.htm" target="_blank">DayToday</a> from RoboMagic Software Corp. Displays the date on the taskbar
  15159. Source=Paul Collins Startup list
  15160.  
  15161. [DAZEL Delivery Agent]
  15162. Number=2153
  15163. Confirmed=U
  15164. Filename=DcDaemon.exe
  15165. Description=Control and send documents, etc, to any destination. The Dazel Corporation has now been taken over by HP
  15166. Source=Paul Collins Startup list
  15167.  
  15168. [dbserv]
  15169. Number=2154
  15170. Confirmed=N
  15171. Filename=dbserv.exe
  15172. Description=Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
  15173. Source=Paul Collins Startup list
  15174.  
  15175. [DC6_Check]
  15176. Number=2155
  15177. Confirmed=N
  15178. Filename=uwasdc.exe
  15179. Description=WinAntiSpyware 2006 spyware remover - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  15180. Source=Paul Collins Startup list
  15181.  
  15182. [DC6_check]
  15183. Number=2156
  15184. Confirmed=N
  15185. Filename=dc6_startupmon.exe
  15186. Description=WinAntiVirus 2006 virus software - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">here</a>
  15187. Source=Paul Collins Startup list
  15188.  
  15189. [dc6_check]
  15190. Number=2157
  15191. Confirmed=N
  15192. Filename=dcmon.exe
  15193. Description=<a href="http://www.symantec.com/smb/security_response/writeup.jsp?docid=2006-062015-2622-99" target="_blank">SystemDoctor</a> is a Security Risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  15194. Source=Paul Collins Startup list
  15195.  
  15196. [DCE Manager]
  15197. Number=2158
  15198. Confirmed=X
  15199. Filename=dcemgr.exe
  15200. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-032112-1138-99" target="_blank">TUMAG</a> TROJAN!
  15201. Source=Paul Collins Startup list
  15202.  
  15203. [DCfssvc]
  15204. Number=2159
  15205. Confirmed=U
  15206. Filename=dcfssvc.exe
  15207. Description=Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
  15208. Source=Paul Collins Startup list
  15209.  
  15210. [dcfssve]
  15211. Number=2160
  15212. Confirmed=U
  15213. Filename=dcfssvc.exe
  15214. Description=Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
  15215. Source=Paul Collins Startup list
  15216.  
  15217. [Dcom System Patch]
  15218. Number=2161
  15219. Confirmed=X
  15220. Filename=Microsoft.exe
  15221. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDEX.MS&VSect=P" target=_blank>RANDEX.MS</a> WORM!
  15222. Source=Paul Collins Startup list
  15223.  
  15224. [dcsm]
  15225. Number=2162
  15226. Confirmed=N
  15227. Filename=dcsm.exe
  15228. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-062217-0726-99" target="_blank">DriveCleaner</a> is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks
  15229. Source=Paul Collins Startup list
  15230.  
  15231. [DDCActiveMenu]
  15232. Number=2163
  15233. Confirmed=N
  15234. Filename=DDCActiveMenu.exe
  15235. Description=Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
  15236. Source=Paul Collins Startup list
  15237.  
  15238. [DDCM]
  15239. Number=2164
  15240. Confirmed=N
  15241. Filename=DDCMan.exe
  15242. Description=Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
  15243. Source=Paul Collins Startup list
  15244.  
  15245. [DDCMan]
  15246. Number=2165
  15247. Confirmed=N
  15248. Filename=DDCMan.exe
  15249. Description=Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
  15250. Source=Paul Collins Startup list
  15251.  
  15252. [ddeproc]
  15253. Number=2166
  15254. Confirmed=X
  15255. Filename=ddeproc.exe
  15256. Description=Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  15257. Source=Paul Collins Startup list
  15258.  
  15259. [ddhelper]
  15260. Number=2167
  15261. Confirmed=U
  15262. Filename=W815DM.EXE
  15263. Description=Enuff Parental Control Software by <a href="http://www.akrontech.com/" target=_blank>Akrontech</a>
  15264. Source=Paul Collins Startup list
  15265.  
  15266. [DDialler]
  15267. Number=2168
  15268. Confirmed=X
  15269. Filename=DDialler.exe
  15270. Description=Adult content dialler
  15271. Source=Paul Collins Startup list
  15272.  
  15273. [DDriver]
  15274. Number=2169
  15275. Confirmed=X
  15276. Filename=windrv.exe
  15277. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DELF.WG" target="_blank">DELF.WG</a> TROJAN!
  15278. Source=Paul Collins Startup list
  15279.  
  15280. [DDT]
  15281. Number=2170
  15282. Confirmed=?
  15283. Filename=N/A
  15284. Description=<font color="#FF0000">??</font>
  15285. Source=Paul Collins Startup list
  15286.  
  15287. [de32gen]
  15288. Number=2171
  15289. Confirmed=X
  15290. Filename=de32gen.exe
  15291. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  15292. Source=Paul Collins Startup list
  15293.  
  15294. [DeadAIM]
  15295. Number=2172
  15296. Confirmed=N
  15297. Filename=rundll32.exe DeadAIM.ocm, ExportedCheckODLs
  15298. Description=<a href="http://www.jdennis.net/DeadAIM/about.php" target="_blank">DeadAIM</a> - feature enhancing product for AOL's Instant Messenger program
  15299. Source=Paul Collins Startup list
  15300.  
  15301. [DealHelperBrwsr]
  15302. Number=2173
  15303. Confirmed=X
  15304. Filename=dhbrwsr.exe
  15305. Description=<a href="http://sarc.com/avcenter/venc/data/pf/adware.dealhelper.html" target="_blank">DealHelper</a> adware
  15306. Source=Paul Collins Startup list
  15307.  
  15308. [DealHelperDown]
  15309. Number=2174
  15310. Confirmed=X
  15311. Filename=download.exe
  15312. Description=<a href="http://sarc.com/avcenter/venc/data/pf/adware.dealhelper.html" target="_blank">DealHelper</a> adware
  15313. Source=Paul Collins Startup list
  15314.  
  15315. [DealHelperUpdate]
  15316. Number=2175
  15317. Confirmed=X
  15318. Filename=DHUpdt.exe
  15319. Description=<a href="http://sarc.com/avcenter/venc/data/pf/adware.dealhelper.html" target="_blank">DealHelper</a> adware
  15320. Source=Paul Collins Startup list
  15321.  
  15322. [Death.exe]
  15323. Number=2176
  15324. Confirmed=X
  15325. Filename=Death.exe
  15326. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelferw.html" target="_blank">DELF-ERW</a> TROJAN!
  15327. Source=Paul Collins Startup list
  15328.  
  15329. [Debug]
  15330. Number=2177
  15331. Confirmed=X
  15332. Filename=DebugW32.exe
  15333. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-062416-3732-99" target=_blank>GUBED</a> TROJAN!
  15334. Source=Paul Collins Startup list
  15335.  
  15336. [Debugger]
  15337. Number=2178
  15338. Confirmed=X
  15339. Filename=dbg32.exe
  15340. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobfw.html" target=_blank>MYTOB-FW</a> WORM!
  15341. Source=Paul Collins Startup list
  15342.  
  15343. [Debugger]
  15344. Number=2179
  15345. Confirmed=X
  15346. Filename=explorer32dbg.exe
  15347. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcwsm.html" target=_blank>CWS-M</a> TROJAN!
  15348. Source=Paul Collins Startup list
  15349.  
  15350. [Debugger]
  15351. Number=2180
  15352. Confirmed=X
  15353. Filename=iexplore_dbg.exe
  15354. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcwsm.html" target=_blank>CWS-M</a> TROJAN!
  15355. Source=Paul Collins Startup list
  15356.  
  15357. [debugger]
  15358. Number=2181
  15359. Confirmed=X
  15360. Filename=help.pif
  15361. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delfdra.html" target="_blank">DELF-DRA</a> WORM!
  15362. Source=Paul Collins Startup list
  15363.  
  15364. [DebugMonitor]
  15365. Number=2182
  15366. Confirmed=X
  15367. Filename=debugmonitor.exe
  15368. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031923-1433-99" target="_blank">MYDOOM.BG</a> WORM!
  15369. Source=Paul Collins Startup list
  15370.  
  15371. [DeeEnEs]
  15372. Number=2183
  15373. Confirmed=U
  15374. Filename=DeeEnEs.exe
  15375. Description=<a href="http://www.palacio-cristal.com/products/DeeEnEs/" target=_blank>DeeEnEs</a> - automatically updates a dynamic IP address when it changes
  15376. Source=Paul Collins Startup list
  15377.  
  15378. [deejay]
  15379. Number=2184
  15380. Confirmed=X
  15381. Filename=forboo.exe
  15382. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotay.html" target="_blank">FORBOT-AY</a> WORM!
  15383. Source=Paul Collins Startup list
  15384.  
  15385. [Default]
  15386. Number=2185
  15387. Confirmed=X
  15388. Filename=explore.vbs
  15389. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030216-1808-99" target=_blank>ALLEM</a> WORM!
  15390. Source=Paul Collins Startup list
  15391.  
  15392. [Default]
  15393. Number=2186
  15394. Confirmed=X
  15395. Filename=mtask.vbe
  15396. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030216-1808-99" target=_blank>ALLEM</a> WORM!
  15397. Source=Paul Collins Startup list
  15398.  
  15399. [default]
  15400. Number=2187
  15401. Confirmed=X
  15402. Filename=shell32.exe
  15403. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030215-5059-99" target=_blank>BINGHE</a> TROJAN!
  15404. Source=Paul Collins Startup list
  15405.  
  15406. [Default System Research]
  15407. Number=2188
  15408. Confirmed=X
  15409. Filename=vhchost.exe
  15410. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-090114-1936-99" target="_blank">TARNO.I</a> TROJAN!
  15411. Source=Paul Collins Startup list
  15412.  
  15413. [Default web browser]
  15414. Number=2189
  15415. Confirmed=X
  15416. Filename=IexpIore.exe
  15417. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojoblivionb.html" target="_blank">OBLIVION.B</a> TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L"
  15418. Source=Paul Collins Startup list
  15419.  
  15420. [Default_Page_URL]
  15421. Number=2190
  15422. Confirmed=X
  15423. Filename=http://find.naupoint.com
  15424. Description=<a href="http://www.spynet.com/spyware/spyware-NauPoint-Installer.aspx" target=_blank>Naupoint</a> browser hijacker
  15425. Source=Paul Collins Startup list
  15426.  
  15427. [Default_Search_URL]
  15428. Number=2191
  15429. Confirmed=X
  15430. Filename=http://find.naupoint.com
  15431. Description=<a href="http://www.spynet.com/spyware/spyware-NauPoint-Installer.aspx" target=_blank>Naupoint</a> browser hijacker
  15432. Source=Paul Collins Startup list
  15433.  
  15434. [defender]
  15435. Number=2192
  15436. Confirmed=X
  15437. Filename=defender25.exe
  15438. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097507" target="_blank">DollarRevenue</a> adware
  15439. Source=Paul Collins Startup list
  15440.  
  15441. [defender]
  15442. Number=2193
  15443. Confirmed=X
  15444. Filename=dfndref_7.exe
  15445. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=DollarRevenue&threatid=42948" target="_blank">DollarRevenue</a> adware
  15446. Source=Paul Collins Startup list
  15447.  
  15448. [defergui]
  15449. Number=2194
  15450. Confirmed=?
  15451. Filename=defergui.exe
  15452. Description=Related to IBM Standard Software Installer.  <font color="#FF0000">What does it do and is it required?</font>
  15453. Source=Paul Collins Startup list
  15454.  
  15455. [defragm_check]
  15456. Number=2195
  15457. Confirmed=X
  15458. Filename=defragment.exe
  15459. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  15460. Source=Paul Collins Startup list
  15461.  
  15462. [defragsys]
  15463. Number=2196
  15464. Confirmed=X
  15465. Filename=svchost.exe
  15466. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbifroseth.html" target="_blank">BIFROSE-TH</a> TROJAN!  Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  15467. Source=Paul Collins Startup list
  15468.  
  15469. [defwatch]
  15470. Number=2197
  15471. Confirmed=U
  15472. Filename=defwatch.exe
  15473. Description=Detects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
  15474. Source=Paul Collins Startup list
  15475.  
  15476. [Deko550]
  15477. Number=2198
  15478. Confirmed=U
  15479. Filename=Deko550.exe
  15480. Description=Associated with the <a href="http://www.avid.com/products/deko550/" target="_blank">Deko550</a> entry-level SD real-time graphics system from Avid Technology
  15481. Source=Paul Collins Startup list
  15482.  
  15483. [Delay]
  15484. Number=2199
  15485. Confirmed=U
  15486. Filename=delayrun.exe
  15487. Description=On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
  15488. Source=Paul Collins Startup list
  15489.  
  15490. [Delayrun]
  15491. Number=2200
  15492. Confirmed=U
  15493. Filename=delayrun.exe
  15494. Description=On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
  15495. Source=Paul Collins Startup list
  15496.  
  15497. [delcab]
  15498. Number=2201
  15499. Confirmed=?
  15500. Filename=deltreew.exe C:\cabs
  15501. Description=<font color="#FF0000">??<font>
  15502. Source=Paul Collins Startup list
  15503.  
  15504. [Delete Me]
  15505. Number=2202
  15506. Confirmed=X
  15507. Filename=worm.exe
  15508. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021218-1022-99" target="_blank">DOOMHUNTER</a> WORM!
  15509. Source=Paul Collins Startup list
  15510.  
  15511. [DeleteHistoryFree]
  15512. Number=2203
  15513. Confirmed=U
  15514. Filename=dhf.exe
  15515. Description=<a href="http://www.deletehistoryfree.com/" target=_blank>Delete History Free</a> - "Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC"
  15516.  
  15517. Source=Paul Collins Startup list
  15518.  
  15519. [Dell AIO Printer A***]
  15520. Number=2204
  15521. Confirmed=N
  15522. Filename=dlbabmgr.exe
  15523. Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
  15524. Source=Paul Collins Startup list
  15525.  
  15526. [Dell AIO Printer A***]
  15527. Number=2205
  15528. Confirmed=N
  15529. Filename=dlbfbmgr.exe
  15530. Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
  15531. Source=Paul Collins Startup list
  15532.  
  15533. [Dell AIO Printer A***]
  15534. Number=2206
  15535. Confirmed=N
  15536. Filename=dlbkbmgr.exe
  15537. Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
  15538. Source=Paul Collins Startup list
  15539.  
  15540. [Dell Alert]
  15541. Number=2207
  15542. Confirmed=N
  15543. Filename=DAMon.exe
  15544. Description="Dell Alert" utility, that's supposed to make interaction with Support easier
  15545. Source=Paul Collins Startup list
  15546.  
  15547. [Dell Photo AIO Printer 922]
  15548. Number=2208
  15549. Confirmed=?
  15550. Filename=dlbtbmgr.exe
  15551. Description=Dell Photo AIO Printer 922 Device Monitor. <font color="#FF0000">Is it required?</font>
  15552. Source=Paul Collins Startup list
  15553.  
  15554. [Dell Photo AIO Printer 942]
  15555. Number=2209
  15556. Confirmed=?
  15557. Filename=dlbubmgr.exe
  15558. Description=Dell Photo AIO Printer 942 Device Monitor. <font color="#FF0000">Is it required?</font>
  15559. Source=Paul Collins Startup list
  15560.  
  15561. [Dell Photo AIO Printer 962]
  15562. Number=2210
  15563. Confirmed=?
  15564. Filename=dlbxmon.exe
  15565. Description=Dell Photo AIO Printer 962 Device Monitor. <font color="#FF0000">Is it required?</font>
  15566. Source=Paul Collins Startup list
  15567.  
  15568. [Dell QuickSet]
  15569. Number=2211
  15570. Confirmed=N
  15571. Filename=quickset.exe
  15572. Description=Dell taskbar icon allowing you to quickly change settings
  15573. Source=Paul Collins Startup list
  15574.  
  15575. [Dell Wireless Manager UI]
  15576. Number=2212
  15577. Confirmed=U
  15578. Filename=WLTRAY
  15579. Description=Installed alongside Dell Wireless WLAN Card and provides additional configuration options for these devices
  15580. Source=Paul Collins Startup list
  15581.  
  15582. [Dell Wireless Manager UI]
  15583. Number=2213
  15584. Confirmed=N
  15585. Filename=wltray.exe
  15586. Description=System tray access to wireless LAN card configuration options
  15587.  
  15588. Source=Paul Collins Startup list
  15589.  
  15590. [DellDMI]
  15591. Number=2214
  15592. Confirmed=?
  15593. Filename=delldmi.exe
  15594. Description=<font color="#FF0000">Possibly part of <a href="http://docs.us.dell.com/support/edocs/software/smcliins/cli60/en/ug/intro.htm" target="_blank">Dell OpenManage Client Instrumentation</a> - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?</font>
  15595. Source=Paul Collins Startup list
  15596.  
  15597. [DELLMMKB]
  15598. Number=2215
  15599. Confirmed=U
  15600. Filename=DELLMMKB.EXE
  15601. Description=Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
  15602. Source=Paul Collins Startup list
  15603.  
  15604. [DellSC]
  15605. Number=2216
  15606. Confirmed=N
  15607. Filename=dellsc.exe
  15608. Description=Dell Solution Center - web-based troubleshooting tools and educational offerings
  15609. Source=Paul Collins Startup list
  15610.  
  15611. [DellSupport]
  15612. Number=2217
  15613. Confirmed=U
  15614. Filename=DSAgnt.exe
  15615. Description=Dell Support Agent offers additional support and update features for your Dell computer or laptop
  15616. Source=Paul Collins Startup list
  15617.  
  15618. [DellTouch]
  15619. Number=2218
  15620. Confirmed=U
  15621. Filename=MMKeybd.exe
  15622. Description=Dell multimedia keyboard manager. Required if you use the additional keys
  15623. Source=Paul Collins Startup list
  15624.  
  15625. [DellTouch]
  15626. Number=2219
  15627. Confirmed=U
  15628. Filename=DELLMMKB.EXE
  15629. Description=Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
  15630. Source=Paul Collins Startup list
  15631.  
  15632. [delmsbb]
  15633. Number=2220
  15634. Confirmed=X
  15635. Filename=delmsbb.exe
  15636. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=180solutions.NCase&threatid=8869" target="_blank">NCase</a> adware
  15637. Source=Paul Collins Startup list
  15638.  
  15639. [delsaap]
  15640. Number=2221
  15641. Confirmed=X
  15642. Filename=delsaap.exe
  15643. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=180solutions.NCase&threatid=8869" target="_blank">NCase</a> adware
  15644. Source=Paul Collins Startup list
  15645.  
  15646. [delstart]
  15647. Number=2222
  15648. Confirmed=?
  15649. Filename=delstart.exe
  15650. Description=Reportedly part of BT ISP software - <font color="#FF0000">what does it do and is it required in startup?</font>
  15651. Source=Paul Collins Startup list
  15652.  
  15653. [delsubmit]
  15654. Number=2223
  15655. Confirmed=X
  15656. Filename=rundll32.exe advpack.dll, DelNodeRunDLL32 submit.exe
  15657. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  15658. Source=Paul Collins Startup list
  15659.  
  15660. [DelTmp]
  15661. Number=2224
  15662. Confirmed=?
  15663. Filename=DelTemp.exe
  15664. Description=Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. <font color="#FF0000">Deletes temporary files once an installation is complete?</font>
  15665. Source=Paul Collins Startup list
  15666.  
  15667. [DeltTray]
  15668. Number=2225
  15669. Confirmed=N
  15670. Filename=deltray.exe
  15671. Description=System Tray access to the control panel for the M-Audio <a href="http://www.m-audio.com/products/en_us/Delta44-main.html" target="_blank">Delta 44</a> PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel
  15672. Source=Paul Collins Startup list
  15673.  
  15674. [DeluxeCommunications]
  15675. Number=2226
  15676. Confirmed=X
  15677. Filename=Dxc.exe
  15678. Description=Deluxe Communications, a <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112118-0309-99" target="_blank">SurfSideKick</a> adware variant
  15679. Source=Paul Collins Startup list
  15680.  
  15681. [DELXP Protocol]
  15682. Number=2227
  15683. Confirmed=X
  15684. Filename=delxp.exe
  15685. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  15686. Source=Paul Collins Startup list
  15687.  
  15688. [demon]
  15689. Number=2228
  15690. Confirmed=?
  15691. Filename=demon.exe
  15692. Description=Part of the French Wanadoo ADSL extense pack. <font color="#FF0000"> What does it do and is it required?</font>
  15693. Source=Paul Collins Startup list
  15694.  
  15695. [Deneca]
  15696. Number=2229
  15697. Confirmed=X
  15698. Filename=Virus salvado
  15699. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050909-4602-99" target= blank>DELUZ</a> VIRUS!
  15700. Source=Paul Collins Startup list
  15701.  
  15702. [DepFrez]
  15703. Number=2230
  15704. Confirmed=U
  15705. Filename=frzstate.exe
  15706. Description=<a href="http://www.faronics.com/html/deepfreeze.asp" target="_blank">Deep Freeze</a> from Faronics Coporation. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example
  15707. Source=Paul Collins Startup list
  15708.  
  15709. [Description of Shortcuts]
  15710. Number=2231
  15711. Confirmed=?
  15712. Filename=*.exe
  15713. Description=<font color="#FF0000">* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e., 4EBD23F5 is actually Works Calender Reminder (found via a registry search)</font>
  15714. Source=Paul Collins Startup list
  15715.  
  15716. [Desire]
  15717. Number=2232
  15718. Confirmed=X
  15719. Filename=desires.exe
  15720. Description=Adult content dialler
  15721. Source=Paul Collins Startup list
  15722.  
  15723. [desk-top-service]
  15724. Number=2233
  15725. Confirmed=?
  15726. Filename=desk-top-service.exe
  15727. Description=<font color="#FF0000">??</font>
  15728. Source=Paul Collins Startup list
  15729.  
  15730. [DeskAd Service]
  15731. Number=2234
  15732. Confirmed=X
  15733. Filename=DeskAdServ.exe
  15734. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090749" target= blank>DeskAd.Service</a> adware
  15735. Source=Paul Collins Startup list
  15736.  
  15737. [DeskColor]
  15738. Number=2235
  15739. Confirmed=N
  15740. Filename=DESKCOLOR.EXE
  15741. Description=Provides transparent icon text backgrounds and coloured icon text
  15742. Source=Paul Collins Startup list
  15743.  
  15744. [Deskflag]
  15745. Number=2236
  15746. Confirmed=N
  15747. Filename=Deskflag.exe
  15748. Description=<a href="http://www.deskflag.com/" target="_blank">DeskFlag</a> - animated USA flag on the desktop
  15749. Source=Paul Collins Startup list
  15750.  
  15751. [DeskMateAutoUpdate]
  15752. Number=2237
  15753. Confirmed=X
  15754. Filename=DeskMateAutoUpdate.exe
  15755. Description=DeskMates: Virtual scantily clad girls enhance your desktop. <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453068324" target=_blank>BargainBuddy</a> adware related
  15756. Source=Paul Collins Startup list
  15757.  
  15758. [Desksite CMA]
  15759. Number=2238
  15760. Confirmed=U
  15761. Filename=cma.exe
  15762. Description=DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
  15763. Source=Paul Collins Startup list
  15764.  
  15765. [Desktop]
  15766. Number=2239
  15767. Confirmed=X
  15768. Filename=rundll32.exe msconfd.dll, Restore ControlPanel
  15769. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-122014-1527-99" target="_blank">BOOKMARKER</a> TROJAN!
  15770. Source=Paul Collins Startup list
  15771.  
  15772. [desktop]
  15773. Number=2240
  15774. Confirmed=X
  15775. Filename=desktop.exe
  15776. Description=Added by the <a href="http://www.f-secure.com/v-descs/sdbot_md.shtml" target=_blank>SDBOT.MD</a> WORM!
  15777. Source=Paul Collins Startup list
  15778.  
  15779. [Desktop]
  15780. Number=2241
  15781. Confirmed=X
  15782. Filename=Desktop.com
  15783. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32vbdrn.html" target="_blank">VB-DRN</a> WORM!
  15784. Source=Paul Collins Startup list
  15785.  
  15786. [Desktop Architect]
  15787. Number=2242
  15788. Confirmed=N
  15789. Filename=DATRAY.EXE
  15790. Description=Desktop theme manager available <a href="http://www.pcworld.com/downloads/file/fid,6503-order,1-page,1-c,alldownloads/description.html" target="_blank">here</a> - for managing the desktop appearance, fonts, sounds, etc
  15791. Source=Paul Collins Startup list
  15792.  
  15793. [Desktop Plant]
  15794. Number=2243
  15795. Confirmed=N
  15796. Filename=AZARE10S.PLT
  15797. Description=Vritual plant from <a href="http://www.desksoft.com/DesktopPlant.htm" target="_blank">here</a> - this version is an Azalea, there are others so the filename may be different
  15798. Source=Paul Collins Startup list
  15799.  
  15800. [Desktop Search]
  15801. Number=2244
  15802. Confirmed=X
  15803. Filename=desktop.exe
  15804. Description=<a href="http://vil.nai.com/vil/content/v_133320.htm" target="_blank">iSearch</a> "Desktop Search" hijacker
  15805. Source=Paul Collins Startup list
  15806.  
  15807. [Desktop Service Centre]
  15808. Number=2245
  15809. Confirmed=?
  15810. Filename=DSC.exe
  15811. Description=OptusNet DSL or Dial-Up connection software - <font color="#FF0000">is it required?</font>
  15812. Source=Paul Collins Startup list
  15813.  
  15814. [Desktop Weather]
  15815. Number=2246
  15816. Confirmed=N
  15817. Filename=THE WEATHER CHANNEL.exe
  15818. Description=<a href="http://www.weather.com/services/desktop.html?from=tutorial" target="_blank">Desktop Weather</a> by The Weather Channel - provides current temperature, conditions, alerts, etc
  15819. Source=Paul Collins Startup list
  15820.  
  15821. [Desktop Weather 3]
  15822. Number=2247
  15823. Confirmed=N
  15824. Filename=THE WEATHER CHANNEL.exe
  15825. Description=<a href="http://www.weather.com/services/desktop.html" target="_blank">Desktop Weather 3</a> by The Weather Channel - provides current temperature, conditions, alerts, etc
  15826. Source=Paul Collins Startup list
  15827.  
  15828. [Desktop Weather 3]
  15829. Number=2248
  15830. Confirmed=N
  15831. Filename=THEWEA~1.EXE
  15832. Description=<a href="http://www.weather.com/services/desktop.html" target="_blank">Desktop Weather 3</a> by The Weather Channel - provides current temperature, conditions, alerts, etc
  15833. Source=Paul Collins Startup list
  15834.  
  15835. [desktopmgr]
  15836. Number=2249
  15837. Confirmed=N
  15838. Filename=desktopmgr.exe
  15839. Description=Synchronisation manager for the cradles for the <a href="http://www.rim.net/products/index.shtml" target="_blank">Research In Motion</a> range of wireless handhelds, including the "Blackberry"
  15840. Source=Paul Collins Startup list
  15841.  
  15842. [DesktopUpdate]
  15843. Number=2250
  15844. Confirmed=X
  15845. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  15846. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  15847. Source=Paul Collins Startup list
  15848.  
  15849. [DesktopX]
  15850. Number=2251
  15851. Confirmed=U
  15852. Filename=DESKTOPX.EXE
  15853. Description=A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking
  15854. Source=Paul Collins Startup list
  15855.  
  15856. [deskup]
  15857. Number=2252
  15858. Confirmed=N
  15859. Filename=deskup.exe
  15860. Description=Adds Iomega Zip drive icons to the desktop
  15861. Source=Paul Collins Startup list
  15862.  
  15863. [destroyb11]
  15864. Number=2253
  15865. Confirmed=X
  15866. Filename=destroyb11.exe
  15867. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelfko.html" target=_blank>DELF-KO</a> TROJAN!
  15868. Source=Paul Collins Startup list
  15869.  
  15870. [detect]
  15871. Number=2254
  15872. Confirmed=U
  15873. Filename=idetect.exe
  15874. Description=<a href="http://www.clasys.com/internet_turbo.html" target="_blank">iNTERNET Turbo</a> from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled
  15875. Source=Paul Collins Startup list
  15876.  
  15877. [detect]
  15878. Number=2255
  15879. Confirmed=?
  15880. Filename=turbodetect.exe
  15881. Description=<font color="#FF0000">??</font>
  15882. Source=Paul Collins Startup list
  15883.  
  15884. [Detector]
  15885. Number=2256
  15886. Confirmed=N
  15887. Filename=detector.exe
  15888. Description=USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software
  15889. Source=Paul Collins Startup list
  15890.  
  15891. [Development Environment]
  15892. Number=2257
  15893. Confirmed=X
  15894. Filename=devenv.exe
  15895. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotah.html" target="_blank">DELBOT-AH</a> WORM!
  15896. Source=Paul Collins Startup list
  15897.  
  15898. [DEventAgent]
  15899. Number=2258
  15900. Confirmed=U
  15901. Filename=eventagt.exe
  15902. Description=DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
  15903. Source=Paul Collins Startup list
  15904.  
  15905. [Device Configuration Loader]
  15906. Number=2259
  15907. Confirmed=X
  15908. Filename=msdvc32.exe
  15909. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
  15910.  
  15911. Source=Paul Collins Startup list
  15912.  
  15913. [Device Detector]
  15914. Number=2260
  15915. Confirmed=U
  15916. Filename=DevDetect.exe
  15917. Description=<a href="http://www.acdsee.com/" target="_blank">ACDSee</a> Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
  15918. Source=Paul Collins Startup list
  15919.  
  15920. [Device Detector 2]
  15921. Number=2261
  15922. Confirmed=N
  15923. Filename=DevDtct2.exe
  15924. Description=Installed by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resources
  15925. Source=Paul Collins Startup list
  15926.  
  15927. [Device Manager]
  15928. Number=2262
  15929. Confirmed=X
  15930. Filename=wfxmgr.exe
  15931. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Backdoor.Win32.Rbot.aju&threatid=48893" target="_blank">RBOT.AJU</a> WORM!
  15932. Source=Paul Collins Startup list
  15933.  
  15934. [DeviceDiscovery]
  15935. Number=2263
  15936. Confirmed=U
  15937. Filename=hpotdd01.exe
  15938. Description=Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
  15939. Source=Paul Collins Startup list
  15940.  
  15941. [DevicePath]
  15942. Number=2264
  15943. Confirmed=X
  15944. Filename=Proyecto1.exe
  15945. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071316-1355-99" target="_blank">GRUEL</a> WORM!
  15946. Source=Paul Collins Startup list
  15947.  
  15948. [DevicePath]
  15949. Number=2265
  15950. Confirmed=X
  15951. Filename=Root.exe
  15952. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071316-1355-99" target="_blank">GRUEL</a> WORM!
  15953. Source=Paul Collins Startup list
  15954.  
  15955. [Devices]
  15956. Number=2266
  15957. Confirmed=U
  15958. Filename=olesvr.exe
  15959. Description=Salfeld <a href="http://www.salfeld.com/software/childcontrol/index.html" target="_blank">Child Control</a> - parental control software
  15960. Source=Paul Collins Startup list
  15961.  
  15962. [Devicewin]
  15963. Number=2267
  15964. Confirmed=X
  15965. Filename=[path to trojan]
  15966. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankeraev.html" target=_blank>BANKER-AEV</a> TROJAN!
  15967. Source=Paul Collins Startup list
  15968.  
  15969. [devldr16]
  15970. Number=2268
  15971. Confirmed=U
  15972. Filename=devldr16.exe
  15973. Description=Associated with some Creative Labs sound cards.  Provides audio support for DOS applications.  Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
  15974. Source=Paul Collins Startup list
  15975.  
  15976. [devldr16.exe]
  15977. Number=2269
  15978. Confirmed=U
  15979. Filename=devldr16.exe
  15980. Description=Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
  15981. Source=Paul Collins Startup list
  15982.  
  15983. [Devlog]
  15984. Number=2270
  15985. Confirmed=?
  15986. Filename=??
  15987. Description=<font color="#FF0000">??</font>
  15988. Source=Paul Collins Startup list
  15989.  
  15990. [Devlog]
  15991. Number=2271
  15992. Confirmed=?
  15993. Filename=devlog.exe
  15994. Description=Apparently mainboard/chipset related, by a French company called AS Media - <font color="#FF0000"> what exactly is it, and is it required</font>
  15995. Source=Paul Collins Startup list
  15996.  
  15997. [dfgfdgrergd]
  15998. Number=2272
  15999. Confirmed=X
  16000. Filename=[path to trojan]
  16001. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_RANKY.CK" target="_blank">RANKY.CK</a> TROJAN!
  16002. Source=Paul Collins Startup list
  16003.  
  16004. [DGJM]
  16005. Number=2273
  16006. Confirmed=?
  16007. Filename=DGJM.exe
  16008. Description=<font color="#FF0000">??</font>
  16009. Source=Paul Collins Startup list
  16010.  
  16011. [dgtstart]
  16012. Number=2274
  16013. Confirmed=X
  16014. Filename=dgtstart.exe
  16015. Description=<a href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=80885" target=_blank>DigitalNames.g</a> adware
  16016. Source=Paul Collins Startup list
  16017.  
  16018. [dguard]
  16019. Number=2275
  16020. Confirmed=U
  16021. Filename=dguard.exe
  16022. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  16023. Source=Paul Collins Startup list
  16024.  
  16025. [DHCP Server]
  16026. Number=2276
  16027. Confirmed=X
  16028. Filename=regsvr.exe
  16029. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpr.html" target=_blank>RBOT-PR</a> WORM!
  16030. Source=Paul Collins Startup list
  16031.  
  16032. [dhcpagnt]
  16033. Number=2277
  16034. Confirmed=Y
  16035. Filename=dhcpagnt.exe
  16036. Description=Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
  16037. Source=Paul Collins Startup list
  16038.  
  16039. [DHNUXB]
  16040. Number=2278
  16041. Confirmed=?
  16042. Filename=DHNUXB.exe
  16043. Description=<font color="#FF0000">??</font>
  16044. Source=Paul Collins Startup list
  16045.  
  16046. [diagent]
  16047. Number=2279
  16048. Confirmed=N
  16049. Filename=diagent.exe
  16050. Description=System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
  16051. Source=Paul Collins Startup list
  16052.  
  16053. [Diagnostic]
  16054. Number=2280
  16055. Confirmed=X
  16056. Filename=diagnostic.exe
  16057. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojalphac.html" target="_blank">ALPHA-C</a> TROJAN!
  16058. Source=Paul Collins Startup list
  16059.  
  16060. [Dial22]
  16061. Number=2281
  16062. Confirmed=X
  16063. Filename=dlm.exe
  16064. Description=Adult content dialler
  16065. Source=Paul Collins Startup list
  16066.  
  16067. [Dial33]
  16068. Number=2282
  16069. Confirmed=X
  16070. Filename=dlm.exe
  16071. Description=Adult content dialler
  16072. Source=Paul Collins Startup list
  16073.  
  16074. [Dialer]
  16075. Number=2283
  16076. Confirmed=X
  16077. Filename=rundll32.exe msa32chk.dll
  16078. Description=Unidentfied malware
  16079. Source=Paul Collins Startup list
  16080.  
  16081. [Dialer Control]
  16082. Number=2284
  16083. Confirmed=U
  16084. Filename=dc.exe
  16085. Description=<a href="http://www.dialer-control.de/" target="_blank">Dialer-Control</a>. Detects and protects from premium rate p0rn diallers
  16086. Source=Paul Collins Startup list
  16087.  
  16088. [Dialer Detect]
  16089. Number=2285
  16090. Confirmed=U
  16091. Filename=dd.exe
  16092. Description=<a href="http://www.dialerdetect.nl/english/main.htm" target=_blank>DialerDetect</a> detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing it
  16093.  
  16094. Source=Paul Collins Startup list
  16095.  
  16096. [Dialgo SDK]
  16097. Number=2286
  16098. Confirmed=U
  16099. Filename=PhoneAnswer.exe
  16100. Description=Dialgo Wave Modem ActiveX - "Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis"
  16101. Source=Paul Collins Startup list
  16102.  
  16103. [DialNet]
  16104. Number=2287
  16105. Confirmed=X
  16106. Filename=mxt32.exe
  16107. Description=Adult content dialler
  16108. Source=Paul Collins Startup list
  16109.  
  16110. [Dialog Box Assistant]
  16111. Number=2288
  16112. Confirmed=N
  16113. Filename=OSDEx.exe
  16114. Description=<a href="http://www.win-utilities.com/dba/" target="_blank">Dialog Box Assistant</a> from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders
  16115. Source=Paul Collins Startup list
  16116.  
  16117. [Dialog Helper]
  16118. Number=2289
  16119. Confirmed=N
  16120. Filename=PDDLGHLP.EXE
  16121. Description=Dialog Helper from PowerDesk Pro by <a href="http://www.ontrack.com/" target="_blank">Ontrack</a>. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs
  16122. Source=Paul Collins Startup list
  16123.  
  16124. [DialUp Network Application]
  16125. Number=2290
  16126. Confirmed=X
  16127. Filename=Rnaap.exe
  16128. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  16129. Source=Paul Collins Startup list
  16130.  
  16131. [Diamondview]
  16132. Number=2291
  16133. Confirmed=?
  16134. Filename=Diamondview.exe
  16135. Description=Manulife Financial Insurance program. <font color="#FF0000">Is it required at startup?<font>
  16136. Source=Paul Collins Startup list
  16137.  
  16138. [DIECOX]
  16139. Number=2292
  16140. Confirmed=X
  16141. Filename=csrss.exe
  16142. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100826.htm" target="_blank">ATM.GEN</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  16143. Source=Paul Collins Startup list
  16144.  
  16145. [Diesel]
  16146. Number=2293
  16147. Confirmed=X
  16148. Filename=Recalculate.exe
  16149. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022716-1619-99" target=_blank>LAZAR</a> TROJAN!
  16150. Source=Paul Collins Startup list
  16151.  
  16152. [DietK]
  16153. Number=2294
  16154. Confirmed=U
  16155. Filename=DietK.exe
  16156. Description=Diet Kazaa add-on for Kazaa Media Desktop - "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results" 
  16157. Source=Paul Collins Startup list
  16158.  
  16159. [DigiCell]
  16160. Number=2295
  16161. Confirmed=U
  16162. Filename=DigiCell.exe
  16163. Description=MSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center"
  16164. Source=Paul Collins Startup list
  16165.  
  16166. [DigiD]
  16167. Number=2296
  16168. Confirmed=X
  16169. Filename=DigitalSound.exe
  16170. Description=Adware downloader
  16171.  
  16172. Source=Paul Collins Startup list
  16173.  
  16174. [DigiGuide]
  16175. Number=2297
  16176. Confirmed=N
  16177. Filename=CLIENT.EXE
  16178. Description=TV guide and reminder
  16179. Source=Paul Collins Startup list
  16180.  
  16181. [DigiGuide]
  16182. Number=2298
  16183. Confirmed=N
  16184. Filename=client01.exe
  16185. Description=TV guide and reminder
  16186. Source=Paul Collins Startup list
  16187.  
  16188. [Digisoft AntiDialer]
  16189. Number=2299
  16190. Confirmed=U
  16191. Filename=AntiDialer.exe
  16192. Description=Digisoft <a href="http://www.digisoft.cc/antidialer.asp" target="_blank">AntiDialer</a>
  16193. Source=Paul Collins Startup list
  16194.  
  16195. [DigiSrv]
  16196. Number=2300
  16197. Confirmed=U
  16198. Filename=DigiSrv.exe
  16199. Description=Related to camera software from <a href="http://www.digitaldreamco.com/en/index.shtml" target=_blank>DigitalDreams</a>
  16200. Source=Paul Collins Startup list
  16201.  
  16202. [Digital Dashboard]
  16203. Number=2301
  16204. Confirmed=N
  16205. Filename=devgulp.exe
  16206. Description=For Compaq PC's. Loads Digital Dashboard options
  16207. Source=Paul Collins Startup list
  16208.  
  16209. [Digital Line Detect]
  16210. Number=2302
  16211. Confirmed=N
  16212. Filename=DLG.exe
  16213. Description=Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
  16214. Source=Paul Collins Startup list
  16215.  
  16216. [Digital River eBot]
  16217. Number=2303
  16218. Confirmed=N
  16219. Filename=downlo~1.exe
  16220. Description=Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more <a href="http://groups.google.com/group/microsoft.public.win98.setup/browse_frm/thread/b93fc838492e3bba/b2c2f47bc1cc42ed?hl=en&rnum=3&prev=/groups%3Fq%3DDigital%2BRiver%2BeBot%26btnG%3DGoogle%2BSearch%26hl%3Den#b2c2f47bc1cc42ed" target="_blank">here</a>
  16221. Source=Paul Collins Startup list
  16222.  
  16223. [DigitalNames]
  16224. Number=2304
  16225. Confirmed=X
  16226. Filename=DigitalNamesStart.exe
  16227. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-101109-1008-99" target=_blank>DigitalNames</a> spyware variant
  16228. Source=Paul Collins Startup list
  16229.  
  16230. [DigitalWizard]
  16231. Number=2305
  16232. Confirmed=N
  16233. Filename=ISWizard.exe
  16234. Description=InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
  16235. Source=Paul Collins Startup list
  16236.  
  16237. [DigitalWizard Monitor]
  16238. Number=2306
  16239. Confirmed=N
  16240. Filename=dwMon.exe
  16241. Description=InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
  16242. Source=Paul Collins Startup list
  16243.  
  16244. [DIGServices]
  16245. Number=2307
  16246. Confirmed=U
  16247. Filename=DIGServices
  16248. Description=Created by Disney but licensed to ESPN for watching videos
  16249. Source=Paul Collins Startup list
  16250.  
  16251. [DIGStream]
  16252. Number=2308
  16253. Confirmed=N
  16254. Filename=digstream.exe
  16255. Description=DIGStream Cache Manager - part of <a href="http://espn.go.com/motion/download.html" target="_blank">ESPN Motion</a> and <a href="http://disney.go.com/guestservices/disneymotion/about.html" target="_blank"> Disney Motion</a> that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
  16256. Source=Paul Collins Startup list
  16257.  
  16258. [Dimension]
  16259. Number=2309
  16260. Confirmed=U
  16261. Filename=Dimension.exe
  16262. Description=Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol
  16263. Source=Paul Collins Startup list
  16264.  
  16265. [Dimension4]
  16266. Number=2310
  16267. Confirmed=U
  16268. Filename=d4.exe
  16269. Description=<a href="http://www.thinkman.com/dimension4/index.html" target="_blank">Dimension 4</a> - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
  16270. Source=Paul Collins Startup list
  16271.  
  16272. [Dino3]
  16273. Number=2311
  16274. Confirmed=X
  16275. Filename=dino3.exe
  16276. Description=Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
  16277. Source=Paul Collins Startup list
  16278.  
  16279. [Dinst]
  16280. Number=2312
  16281. Confirmed=X
  16282. Filename=dinst.exe
  16283. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080410-4405-99" target=_blank>IMIServer/IEPlugin</a> adware
  16284. Source=Paul Collins Startup list
  16285.  
  16286. [Dir1]
  16287. Number=2313
  16288. Confirmed=X
  16289. Filename=caKe
  16290. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091116-4057-99" target="_blank">CAKE</a> WORM!
  16291. Source=Paul Collins Startup list
  16292.  
  16293. [Direct settings]
  16294. Number=2314
  16295. Confirmed=X
  16296. Filename=sdchost.exe
  16297. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdaemonii.html" target=_blank>DAEMONI-I</a> TROJAN!
  16298. Source=Paul Collins Startup list
  16299.  
  16300. [Direct Update]
  16301. Number=2315
  16302. Confirmed=U
  16303. Filename=DUControl.exe
  16304. Description=<a href="http://www.directupdate.net/" target="_blank">DirectUpdate</a> dynamic DNS updater
  16305. Source=Paul Collins Startup list
  16306.  
  16307. [Direct X Direct3D]
  16308. Number=2316
  16309. Confirmed=X
  16310. Filename=dxd3d.exe
  16311. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  16312.  
  16313. Source=Paul Collins Startup list
  16314.  
  16315. [Direct X Opengl]
  16316. Number=2317
  16317. Confirmed=X
  16318. Filename=dxopengl.exe
  16319. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotcj.html" target=_blank>RBOT-CJ</a> WORM!
  16320.  
  16321. Source=Paul Collins Startup list
  16322.  
  16323. [direct3d.exe]
  16324. Number=2318
  16325. Confirmed=X
  16326. Filename=direct3d.exe
  16327. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcertiff.html" target=_blank>CERTIF-F</a> TROJAN!
  16328. Source=Paul Collins Startup list
  16329.  
  16330. [DirectCD]
  16331. Number=2319
  16332. Confirmed=N
  16333. Filename=DirectCD.exe
  16334. Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
  16335. Source=Paul Collins Startup list
  16336.  
  16337. [directs.exe]
  16338. Number=2320
  16339. Confirmed=X
  16340. Filename=directs.exe
  16341. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031815-4737-99" target="_blank">BEAGLE.O</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031810-0304-99" target="_blank">BEAGLE.R</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031810-4223-99" target="_blank">BEAGLE.S</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031811-2858-99" target="_blank">BEAGLE.T</a> WORMS!
  16342. Source=Paul Collins Startup list
  16343.  
  16344. [DIRECTVDSL]
  16345. Number=2321
  16346. Confirmed=U
  16347. Filename=Directvdsl.exe
  16348. Description=Starts DirectTV DSL modem at boot up. Can also be started manually
  16349. Source=Paul Collins Startup list
  16350.  
  16351. [DirectX]
  16352. Number=2322
  16353. Confirmed=X
  16354. Filename=ddhelp32.exe
  16355. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_BIONET.318" target="_blank">BIONET.318</a> TROJAN! Note - not the DirectX helper which is ddhelp.exe
  16356. Source=Paul Collins Startup list
  16357.  
  16358. [directx]
  16359. Number=2323
  16360. Confirmed=X
  16361. Filename=Directx.exe
  16362. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020517-3752-99" target="_blank">SDBOT.D</a> TROJAN!
  16363. Source=Paul Collins Startup list
  16364.  
  16365. [directx]
  16366. Number=2324
  16367. Confirmed=X
  16368. Filename=Sqlexploit.exe
  16369. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020517-3752-99" target="_blank">SDBOT.D</a> TROJAN!
  16370. Source=Paul Collins Startup list
  16371.  
  16372. [DirectX]
  16373. Number=2325
  16374. Confirmed=X
  16375. Filename=DirectX.exe
  16376. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-083018-2656-99" target="_blank">BLAXE</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-100815-2137-99" target="_blank"> LOGPOLE</a> WORMS!
  16377. Source=Paul Collins Startup list
  16378.  
  16379. [directx]
  16380. Number=2326
  16381. Confirmed=X
  16382. Filename=NTCmd.exe
  16383. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020517-3752-99" target="_blank">SDBOT.D</a> TROJAN!
  16384. Source=Paul Collins Startup list
  16385.  
  16386. [directx]
  16387. Number=2327
  16388. Confirmed=X
  16389. Filename=PipeCmd.exe
  16390. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020517-3752-99" target="_blank">SDBOT.D</a> TROJAN!
  16391. Source=Paul Collins Startup list
  16392.  
  16393. [DirectX 32]
  16394. Number=2328
  16395. Confirmed=X
  16396. Filename=directx32.exe
  16397. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
  16398. Source=Paul Collins Startup list
  16399.  
  16400. [DirectX For Microsoft Windows]
  16401. Number=2329
  16402. Confirmed=X
  16403. Filename=dtxservice.exe
  16404. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-072515-4207-99" target="_blank">PROGENT</a> TROJAN!
  16405. Source=Paul Collins Startup list
  16406.  
  16407. [DirectX for Microsoft Windows]
  16408. Number=2330
  16409. Confirmed=X
  16410. Filename=Fservice.exe
  16411. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-061315-4216-99" target="_blank">PRORAT</a> TROJAN!
  16412. Source=Paul Collins Startup list
  16413.  
  16414. [DirectX for Microsoft Windows]
  16415. Number=2331
  16416. Confirmed=X
  16417. Filename=Sservice.exe
  16418. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-061315-4216-99" target="_blank">PRORAT</a> TROJAN!
  16419. Source=Paul Collins Startup list
  16420.  
  16421. [DirectX For Microsoft« Windows]
  16422. Number=2332
  16423. Confirmed=X
  16424. Filename=fservice.exe
  16425. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojproratp.html" target=_blank>PRORAT-P</a> TROJAN!
  16426. Source=Paul Collins Startup list
  16427.  
  16428. [DirectX shell driver]
  16429. Number=2333
  16430. Confirmed=X
  16431. Filename=[path to trojan]
  16432. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmarktmanb.html" target=_blank>MARKTMAN-B</a> TROJAN!
  16433. Source=Paul Collins Startup list
  16434.  
  16435. [DirectX Video Driver]
  16436. Number=2334
  16437. Confirmed=X
  16438. Filename=dxterm5.exe
  16439. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32wilaba.html" target=_blank>WILAB-A</a> TROJAN!
  16440.  
  16441. Source=Paul Collins Startup list
  16442.  
  16443. [DirectX64]
  16444. Number=2335
  16445. Confirmed=X
  16446. Filename=DirectXset.exe
  16447. Description=Added by the <a href="http://vil.nai.com/vil/content/v_100098.htm" target="_blank">BROWNEY.A</a> WORM!
  16448. Source=Paul Collins Startup list
  16449.  
  16450. [DirectX9 Diag]
  16451. Number=2336
  16452. Confirmed=X
  16453. Filename=dx9diag.exe
  16454. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotalt.html" target=_blank>RBOT-ALT</a> WORM!
  16455. Source=Paul Collins Startup list
  16456.  
  16457. [Dirkey]
  16458. Number=2337
  16459. Confirmed=U
  16460. Filename=Dirkey.exe
  16461. Description=<a href="http://www.protonfx.com/dirkey/" target="_blank">Dirkey</a> - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders 
  16462. Source=Paul Collins Startup list
  16463.  
  16464. [Disable EHCI]
  16465. Number=2338
  16466. Confirmed=?
  16467. Filename=nousb20.exe
  16468. Description=<font color="#FF0000">??</font>
  16469. Source=Paul Collins Startup list
  16470.  
  16471. [Disc Detector]
  16472. Number=2339
  16473. Confirmed=N
  16474. Filename=CtNotify.exe
  16475. Description=For Creative sound cards. Detects when you insert a CD, DVD, etc
  16476. Source=Paul Collins Startup list
  16477.  
  16478. [disc detector]
  16479. Number=2340
  16480. Confirmed=?
  16481. Filename=qnetquestnotifty.exe
  16482. Description=<font color="#FF0000">??</font>
  16483. Source=Paul Collins Startup list
  16484.  
  16485. [discoveg]
  16486. Number=2341
  16487. Confirmed=?
  16488. Filename=discoveg.exe
  16489. Description=<font color="#FF0000">??</font>
  16490. Source=Paul Collins Startup list
  16491.  
  16492. [DISCover]
  16493. Number=2342
  16494. Confirmed=?
  16495. Filename=DISCover.exe
  16496. Description=Related to <a href="http://www.discoverconsole.com/" target="_blank">DISCover Drop</a> from Digital Interactive Systems Corporation. <font color="#FF0000">What does it do and is it required?</font>
  16497. Source=Paul Collins Startup list
  16498.  
  16499. [DiscoverDeskshop]
  16500. Number=2343
  16501. Confirmed=N
  16502. Filename=Deskshop.exe
  16503. Description=<a href="http://www2.discovercard.com/deskshop/main.shtml" target="_blank">Discover Deskshop</a> - single use "virtual" credit card
  16504. Source=Paul Collins Startup list
  16505.  
  16506. [DiscUpdateManager]
  16507. Number=2344
  16508. Confirmed=U
  16509. Filename=DiscUpdMgr.exe
  16510. Description=Disc Update Manager for Digital interactive's <a href="http://www.discoverconsole.com/" target="_blank">DISCover Console</a>. Provider of on-demand video games
  16511. Source=Paul Collins Startup list
  16512.  
  16513. [Disk Keeper]
  16514. Number=2345
  16515. Confirmed=X
  16516. Filename=[path to trojan]
  16517. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmallve.html" target=_blank>SMALL-VE</a> TROJAN!
  16518. Source=Paul Collins Startup list
  16519.  
  16520. [Disk Keeper]
  16521. Number=2346
  16522. Confirmed=X
  16523. Filename=SECURITY.EXE
  16524. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-100409-0013-99" target=_blank>Daosearch</a> adware
  16525. Source=Paul Collins Startup list
  16526.  
  16527. [Disk Manager]
  16528. Number=2347
  16529. Confirmed=X
  16530. Filename=diskver.exe
  16531. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AQT" target=_blank>RBOT.AQT</a> WORM!
  16532. Source=Paul Collins Startup list
  16533.  
  16534. [Disk Master]
  16535. Number=2348
  16536. Confirmed=X
  16537. Filename=[trojan name]
  16538. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-111009-4018-99" target="_blank">DISTER</a> TROJAN! - a spam relayer
  16539. Source=Paul Collins Startup list
  16540.  
  16541. [DiskCheck]
  16542. Number=2349
  16543. Confirmed=X
  16544. Filename=msdarkend.exe
  16545. Description=Added by an unidentified WORM or TROJAN!
  16546. Source=Paul Collins Startup list
  16547.  
  16548. [DiskeeperSystray]
  16549. Number=2350
  16550. Confirmed=N
  16551. Filename=DkIcon.exe
  16552. Description=<a href="http://www.executive.com/defrag/defrag.asp" target=_blank>DisKeeper</a> defragmentation software - can be started manually
  16553. Source=Paul Collins Startup list
  16554.  
  16555. [diskinf]
  16556. Number=2351
  16557. Confirmed=X
  16558. Filename=diskinf.exe
  16559. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
  16560. Source=Paul Collins Startup list
  16561.  
  16562. [DISKMON.EXE]
  16563. Number=2352
  16564. Confirmed=?
  16565. Filename=DISKMON.EXE
  16566. Description=<font color="#FF0000">??</font>
  16567. Source=Paul Collins Startup list
  16568.  
  16569. [Disknag]
  16570. Number=2353
  16571. Confirmed=N
  16572. Filename=disknag.exe
  16573. Description=Dell program that reminds you to make your  backup diskettes
  16574. Source=Paul Collins Startup list
  16575.  
  16576. [Diskstart]
  16577. Number=2354
  16578. Confirmed=X
  16579. Filename=Code.exe
  16580. Description=Adult content dialler
  16581. Source=Paul Collins Startup list
  16582.  
  16583. [Diskstart]
  16584. Number=2355
  16585. Confirmed=X
  16586. Filename=cat.exe
  16587. Description=MS-Connect dialler
  16588. Source=Paul Collins Startup list
  16589.  
  16590. [Diskstart]
  16591. Number=2356
  16592. Confirmed=X
  16593. Filename=hit.exe
  16594. Description=Adult content dialler
  16595. Source=Paul Collins Startup list
  16596.  
  16597. [Diskstart]
  16598. Number=2357
  16599. Confirmed=X
  16600. Filename=Snt.exe
  16601. Description=Adult content dialler
  16602. Source=Paul Collins Startup list
  16603.  
  16604. [Disk_Monitor]
  16605. Number=2358
  16606. Confirmed=U
  16607. Filename=Disk_Monitor.exe
  16608. Description=Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader
  16609. Source=Paul Collins Startup list
  16610.  
  16611. [Dispatcher]
  16612. Number=2359
  16613. Confirmed=X
  16614. Filename=dispatcher.exe
  16615. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadras.html" target="_blank">DLOADR-AS</a> TROJAN!
  16616. Source=Paul Collins Startup list
  16617.  
  16618. [display]
  16619. Number=2360
  16620. Confirmed=U
  16621. Filename=The_Eye.exe
  16622. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-082415-5002-99" target="_blank">ComSpySysSvr</a> surveillance software. Uninstall this software unless you put it there yourself
  16623. Source=Paul Collins Startup list
  16624.  
  16625. [Display Drivers]
  16626. Number=2361
  16627. Confirmed=X
  16628. Filename=cssrs.exe
  16629. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.FX" target="_blank">AGOBOT.FX</a> WORM!
  16630. Source=Paul Collins Startup list
  16631.  
  16632. [Display Settings]
  16633. Number=2362
  16634. Confirmed=N
  16635. Filename=hptasks.exe
  16636. Description=Allows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers
  16637. Source=Paul Collins Startup list
  16638.  
  16639. [DisplayTrayIcon]
  16640. Number=2363
  16641. Confirmed=N
  16642. Filename=TrayIcon.exe
  16643. Description=System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display
  16644. Source=Paul Collins Startup list
  16645.  
  16646. [Disspy]
  16647. Number=2364
  16648. Confirmed=U
  16649. Filename=disspy.exe
  16650. Description=<a href="http://www.h-desk.com/new/Features.13.0.html" target= blank>Disspy</a> spyware detection and removal software
  16651. Source=Paul Collins Startup list
  16652.  
  16653. [Distiller Assistant 3.01]
  16654. Number=2365
  16655. Confirmed=N
  16656. Filename=DISTASST.EXE
  16657. Description=From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
  16658. Source=Paul Collins Startup list
  16659.  
  16660. [Distributed File System]
  16661. Number=2366
  16662. Confirmed=X
  16663. Filename=Dfsvc.exe
  16664. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-080412-0803-99" target=_blank>MYFIP.A</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112612-3710-99" target=_blank>MYFIP.K</a> WORMS!
  16665. Source=Paul Collins Startup list
  16666.  
  16667. [Distributed File System]
  16668. Number=2367
  16669. Confirmed=X
  16670. Filename=kernel32dll.exe
  16671. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32myfipc.html" target=_blank>MYFIP-C</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112612-3710-99" target=_blank>MYFIP.K</a> WORMS!
  16672. Source=Paul Collins Startup list
  16673.  
  16674. [Distributed File System]
  16675. Number=2368
  16676. Confirmed=X
  16677. Filename=blade.exe
  16678. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-041509-5302-99" target=_blank>MYFIP.AC</a> WORM!
  16679. Source=Paul Collins Startup list
  16680.  
  16681. [Distributed File System]
  16682. Number=2369
  16683. Confirmed=U
  16684. Filename=win.exe
  16685. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-040810-5834-99" target=_blank>MYFIP.AB</a> WORM!
  16686. Source=Paul Collins Startup list
  16687.  
  16688. [distributed.net client]
  16689. Number=2370
  16690. Confirmed=U
  16691. Filename=DNETC.EXE
  16692. Description=Dsitributed computing projects client from <a href="http://distributed.net/" target="_blank">Distributed.net</a> where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by <a href="http://www1.distributed.net/trojans.php.en" target="_blank">viruses</a>
  16693. Source=Paul Collins Startup list
  16694.  
  16695. [Dit]
  16696. Number=2371
  16697. Confirmed=Y
  16698. Filename=dit.exe
  16699. Description="Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found
  16700. Source=Paul Collins Startup list
  16701.  
  16702. [Dit]
  16703. Number=2372
  16704. Confirmed=X
  16705. Filename=dit.exe
  16706. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlazara.html" target=_blank>LAZAR-A</a> TROJAN! Note - this is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  16707. Source=Paul Collins Startup list
  16708.  
  16709. [DiTask.exe]
  16710. Number=2373
  16711. Confirmed=N
  16712. Filename=DiTask.exe
  16713. Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs
  16714. Source=Paul Collins Startup list
  16715.  
  16716. [Divamon.exe]
  16717. Number=2374
  16718. Confirmed=?
  16719. Filename=Divamon.exe
  16720. Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target=_blank>Eicon Networks</a> Diva ISDN or ADSL modem - <font color="#FF0000">what does it do and is it required?</font>
  16721. Source=Paul Collins Startup list
  16722.  
  16723. [divx]
  16724. Number=2375
  16725. Confirmed=X
  16726. Filename=divxenc.exe
  16727. Description=Added to the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042210-0112-99" target= blank>SPBOT.B</a> TROJAN!
  16728. Source=Paul Collins Startup list
  16729.  
  16730. [Divx]
  16731. Number=2376
  16732. Confirmed=X
  16733. Filename=codll.exe
  16734. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojgravebota.html" target=_blank>GRAVEBOT-A</a> TROJAN!
  16735. Source=Paul Collins Startup list
  16736.  
  16737. [DivX MediaPlayer 7.0]
  16738. Number=2377
  16739. Confirmed=X
  16740. Filename=Dr.DivX.exe
  16741. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-011518-3235-99" target="_blank">ALADINZ.G</a> TROJAN!
  16742. Source=Paul Collins Startup list
  16743.  
  16744. [DivX Player]
  16745. Number=2378
  16746. Confirmed=X
  16747. Filename=DivXPlayer.exe
  16748. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  16749.  
  16750. Source=Paul Collins Startup list
  16751.  
  16752. [DivX Updater]
  16753. Number=2379
  16754. Confirmed=X
  16755. Filename=DivX.Exe
  16756. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-111114-5143-99" target="_blank">NALDEM</a> TROJAN or MASTAK VIRUS!
  16757. Source=Paul Collins Startup list
  16758.  
  16759. [DIVX Video Player]
  16760. Number=2380
  16761. Confirmed=X
  16762. Filename=DIVXPloyer.exe
  16763. Description=Added by an unidentified WORM or TROJAN!
  16764. Source=Paul Collins Startup list
  16765.  
  16766. [Divx4 codec]
  16767. Number=2381
  16768. Confirmed=X
  16769. Filename=devldr32.exe
  16770. Description=Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/devldr32" target="_blank">devldr32.exe</a> file
  16771. Source=Paul Collins Startup list
  16772.  
  16773. [DJREGFIX]
  16774. Number=2382
  16775. Confirmed=N
  16776. Filename=regedit /s c:\hpdjregfix.reg
  16777. Description=DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers
  16778. Source=Paul Collins Startup list
  16779.  
  16780. [DJSNetCN]
  16781. Number=2383
  16782. Confirmed=?
  16783. Filename=DJSNetCN.exe
  16784. Description="Symantec Licensing Detect Internet Connection", part of Norton Antivirus. <font color="#FF0000">What does it do and is it required?</font>
  16785. Source=Paul Collins Startup list
  16786.  
  16787. [djtopr1150.exe]
  16788. Number=2384
  16789. Confirmed=X
  16790. Filename=djtopr1150.exe
  16791. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112314-5537-99" target="_blank">WebRebates</a> adware
  16792. Source=Paul Collins Startup list
  16793.  
  16794. [dKernel]
  16795. Number=2385
  16796. Confirmed=X
  16797. Filename=dKernel.exe
  16798. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32decoya.html" target=_blank>DECOY-A</a> WORM!
  16799. Source=Paul Collins Startup list
  16800.  
  16801. [DkService]
  16802. Number=2386
  16803. Confirmed=Y
  16804. Filename=DkService.exe
  16805. Description=From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled, otherwise you could have problems starting it manually.
  16806. Source=Paul Collins Startup list
  16807.  
  16808. [DKTime]
  16809. Number=2387
  16810. Confirmed=X
  16811. Filename=dktime.exe
  16812. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100414-1224-99" target="_blank">LUNII</a> TROJAN!
  16813. Source=Paul Collins Startup list
  16814.  
  16815. [Dkware lptt01]
  16816. Number=2388
  16817. Confirmed=X
  16818. Filename=dkware.exe
  16819. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "DonkeySoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  16820. Source=Paul Collins Startup list
  16821.  
  16822. [Dkware ml097e]
  16823. Number=2389
  16824. Confirmed=X
  16825. Filename=dkware.exe
  16826. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "DonkeySoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  16827. Source=Paul Collins Startup list
  16828.  
  16829. [dkzzixm]
  16830. Number=2390
  16831. Confirmed=?
  16832. Filename=dkzzixm.exe
  16833. Description=<font color="#FF0000">??</font>
  16834. Source=Paul Collins Startup list
  16835.  
  16836. [dla]
  16837. Number=2391
  16838. Confirmed=Y
  16839. Filename=tfswctrl.exe
  16840. Description=Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
  16841. Source=Paul Collins Startup list
  16842.  
  16843. [DLA]
  16844. Number=2392
  16845. Confirmed=U
  16846. Filename=DLACTRLW.EXE
  16847. Description=<a href="http://www.sonic.com/" target=_blank>Sonic</a> CD/DVD burning applications
  16848.  
  16849. Source=Paul Collins Startup list
  16850.  
  16851. [DlaTray]
  16852. Number=2393
  16853. Confirmed=N
  16854. Filename=Dlatray.exe
  16855. Description=System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
  16856. Source=Paul Collins Startup list
  16857.  
  16858. [dlbcserv]
  16859. Number=2394
  16860. Confirmed=N
  16861. Filename=dlbcserv.exe
  16862. Description=Related to Dell Photo Printers and provides additional configuration options for these devices
  16863. Source=Paul Collins Startup list
  16864.  
  16865. [DLBUCATS]
  16866. Number=2395
  16867. Confirmed=U
  16868. Filename=DLBUtime.dll, _RunDLLEntry@16
  16869. Description=Related to Dell Photo Printers - drivers
  16870. Source=Paul Collins Startup list
  16871.  
  16872. [dlccmon.exe]
  16873. Number=2396
  16874. Confirmed=?
  16875. Filename=dlccmon.exe
  16876. Description=Dell Photo AIO Printer 924 Device Monitor. <font color="#FF0000">What does it do and is it required?</font>
  16877. Source=Paul Collins Startup list
  16878.  
  16879. [DLCDCATS]
  16880. Number=2397
  16881. Confirmed=?
  16882. Filename=rundll32 [path] DLCDtime.dll, _RunDLLEntry@16
  16883. Description=Related to Dell Photo Printers - <font color="#FF0000">what does it do and is it required in startup?</font>
  16884. Source=Paul Collins Startup list
  16885.  
  16886. [dlcdmon.exe]
  16887. Number=2398
  16888. Confirmed=N
  16889. Filename=dlcdmon.exe
  16890. Description=Related to Dell Photo Printers - required in order to use the scanner of the printer. If disabled, scanning cannot occur because the driver isn't running
  16891. Source=Paul Collins Startup list
  16892.  
  16893. [dlcgmon.exe]
  16894. Number=2399
  16895. Confirmed=U
  16896. Filename=dlcgmon.exe
  16897. Description=Dell 810 AIO phot printer device monitor. <font color="#FF0000">Is it required?</font>
  16898. Source=Paul Collins Startup list
  16899.  
  16900. [dlder]
  16901. Number=2400
  16902. Confirmed=X
  16903. Filename=dlder.exe
  16904. Description=Advertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080811-0118-99" target="_blank">here</a>). Reported in the past as a virus
  16905. Source=Paul Collins Startup list
  16906.  
  16907. [DlDir1]
  16908. Number=2401
  16909. Confirmed=X
  16910. Filename=caKe
  16911. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091116-4057-99" target="_blank">CAKE</a> WORM!
  16912. Source=Paul Collins Startup list
  16913.  
  16914. [DLForcerExe]
  16915. Number=2402
  16916. Confirmed=?
  16917. Filename=DLForcerEXE.exe
  16918. Description=<font color="#FF0000">??</font>
  16919. Source=Paul Collins Startup list
  16920.  
  16921. [DLF_00000B00]
  16922. Number=2403
  16923. Confirmed=N
  16924. Filename=Vcdlf.exe
  16925. Description=Known to cause problems with "Out of memory" errors (see <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;q303045" target="_blank">here</a>).<font color="#FF0000"> Otherwise, it's purpose is unknown</font>
  16926. Source=Paul Collins Startup list
  16927.  
  16928. [DLG]
  16929. Number=2404
  16930. Confirmed=N
  16931. Filename=DLGCHBW.exe
  16932. Description=Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
  16933. Source=Paul Collins Startup list
  16934.  
  16935. [DLHelperEXE]
  16936. Number=2405
  16937. Confirmed=N
  16938. Filename=WATCH.exe
  16939. Description=Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
  16940. Source=Paul Collins Startup list
  16941.  
  16942. [DLHelperEXE.exe]
  16943. Number=2406
  16944. Confirmed=X
  16945. Filename=N/A
  16946. Description=Downloader for Microgaming/Casino software - stealth installed
  16947. Source=Paul Collins Startup list
  16948.  
  16949. [dlhost]
  16950. Number=2407
  16951. Confirmed=X
  16952. Filename=dlhost.exe
  16953. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojexphooka.html" target=_blank>EXPHOOK-A</a> TROJAN!
  16954. Source=Paul Collins Startup list
  16955.  
  16956. [DLINK dfe drivers for Windows NT]
  16957. Number=2408
  16958. Confirmed=X
  16959. Filename=windfe.exe
  16960. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDEX.AK" target="_blank">RANDEX.AK</a> WORM!
  16961. Source=Paul Collins Startup list
  16962.  
  16963. [DLink System Tray]
  16964. Number=2409
  16965. Confirmed=U
  16966. Filename=dlnetst.exe
  16967. Description=Related to <a href="http://www.dlink.com/products/?pid=284" target=_blank>D-Link</a> DGE-530T PCI card for servers and workstations
  16968. Source=Paul Collins Startup list
  16969.  
  16970. [Dlite]
  16971. Number=2410
  16972. Confirmed=X
  16973. Filename=dllmanager.exe
  16974. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.DN" target="_blank">WOOTBOT.DN</a> WORM!
  16975. Source=Paul Collins Startup list
  16976.  
  16977. [Dll Boot Loader on Startup (do not remove this)]
  16978. Number=2411
  16979. Confirmed=X
  16980. Filename=[various filenames]
  16981. Description=Added by an unidentified TROJAN!
  16982. Source=Paul Collins Startup list
  16983.  
  16984. [DLL Manager]
  16985. Number=2412
  16986. Confirmed=X
  16987. Filename=dllmngr32.exe
  16988. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  16989. Source=Paul Collins Startup list
  16990.  
  16991. [DLL Service Manager]
  16992. Number=2413
  16993. Confirmed=X
  16994. Filename=[path to worm]
  16995. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091611-3830-99" target="_blank">RPCBOT.F</a> TROJAN!
  16996. Source=Paul Collins Startup list
  16997.  
  16998. [dll services]
  16999. Number=2414
  17000. Confirmed=X
  17001. Filename=[random filename].exe
  17002. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  17003. Source=Paul Collins Startup list
  17004.  
  17005. [DLL32]
  17006. Number=2415
  17007. Confirmed=X
  17008. Filename=dllmem32.exe
  17009. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-032717-2015-99" target="_blank">KWBOT.E</a> WORM!
  17010. Source=Paul Collins Startup list
  17011.  
  17012. [DLL32]
  17013. Number=2416
  17014. Confirmed=X
  17015. Filename=dllhost.dll
  17016. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-092612-2130-99" target=_blank>SUCLOVE.A</a> WORM!
  17017. Source=Paul Collins Startup list
  17018.  
  17019. [DllCacherv2]
  17020. Number=2417
  17021. Confirmed=X
  17022. Filename=dllcachev2.exe
  17023. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-122016-1748-99" target=_blank>LATEDA</a> TROJAN!
  17024. Source=Paul Collins Startup list
  17025.  
  17026. [dlldmt]
  17027. Number=2418
  17028. Confirmed=X
  17029. Filename=dlldmt.exe
  17030. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  17031. Source=Paul Collins Startup list
  17032.  
  17033. [DllExecutable]
  17034. Number=2419
  17035. Confirmed=X
  17036. Filename=[path to file]
  17037. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32vbsp.html" target= blank>VB-SP</a> WORM!
  17038. Source=Paul Collins Startup list
  17039.  
  17040. [dllhelp]
  17041. Number=2420
  17042. Confirmed=X
  17043. Filename=dllhelp.exe
  17044. Description=Added by the <a href="http://www.hacksoft.com.pe/virus/w32_startpage_dq.htm" target="_blank">STARTPAGE.DQ</a> hijacker
  17045. Source=Paul Collins Startup list
  17046.  
  17047. [dllhelp]
  17048. Number=2421
  17049. Confirmed=X
  17050. Filename=dllhlp.exe
  17051. Description=Added by the <a href="http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=123155" target=_blank>Downloader-HI</a> TROJAN!
  17052.  
  17053. Source=Paul Collins Startup list
  17054.  
  17055. [DLLHost]
  17056. Number=2422
  17057. Confirmed=X
  17058. Filename=dllhst.exe
  17059. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotac.html" target="_blank">DELBOT-AC</a> WORM!
  17060. Source=Paul Collins Startup list
  17061.  
  17062. [dllhostxp.exe]
  17063. Number=2423
  17064. Confirmed=X
  17065. Filename=dllhostxp.exe
  17066. Description=Browser hijacker and adware downloader
  17067. Source=Paul Collins Startup list
  17068.  
  17069. [DllLoader]
  17070. Number=2424
  17071. Confirmed=X
  17072. Filename=lssas.exe
  17073. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorje.html" target=_blank>JE</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe</a> process
  17074. Source=Paul Collins Startup list
  17075.  
  17076. [Dlload]
  17077. Number=2425
  17078. Confirmed=X
  17079. Filename=killer.exe
  17080. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojkillavfk.html" target=_blank>KILLAV-FK</a> TROJAN!
  17081. Source=Paul Collins Startup list
  17082.  
  17083. [dllreg]
  17084. Number=2426
  17085. Confirmed=X
  17086. Filename=dllreg.exe
  17087. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
  17088. Source=Paul Collins Startup list
  17089.  
  17090. [DLLService32]
  17091. Number=2427
  17092. Confirmed=X
  17093. Filename=dllsvc32.exe
  17094. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.VX" target=_blank>AGOBOT.VX</a> WORM!
  17095. Source=Paul Collins Startup list
  17096.  
  17097. [DLM.exe]
  17098. Number=2428
  17099. Confirmed=N
  17100. Filename=DLM.exe
  17101. Description=IGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin, hence Internet Explorer must be installed beforehand and downloads has to be has to be initialized through that browser
  17102. Source=Paul Collins Startup list
  17103.  
  17104. [dlmMgr]
  17105. Number=2429
  17106. Confirmed=N
  17107. Filename=AdobeDownloadManager.exe
  17108. Description=<a href="http://www.adobe.com/products/acrobat/acrrmanager.html" target=_blank>Adobe Download Manager</a> - "can prevent you from having to start from the beginning should your download process be interrupted, and it offers a level of service not possible
  17109. Source=Paul Collins Startup list
  17110.  
  17111. [DLPSP]
  17112. Number=2430
  17113. Confirmed=U
  17114. Filename=DLPSP.EXE
  17115. Description=Dell laser printer status monitor
  17116. Source=Paul Collins Startup list
  17117.  
  17118. [dlsp2mx]
  17119. Number=2431
  17120. Confirmed=X
  17121. Filename=dlsp2mx.exe
  17122. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/dialmpbb.html" target=_blank>MPB-B</a> DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "dlsp2mx"
  17123. Source=Paul Collins Startup list
  17124.  
  17125. [DLT]
  17126. Number=2432
  17127. Confirmed=?
  17128. Filename=dlt.exe
  17129. Description=<font color="#FF0000">??</font>
  17130. Source=Paul Collins Startup list
  17131.  
  17132. [dluca]
  17133. Number=2433
  17134. Confirmed=X
  17135. Filename=dluca.exe
  17136. Description=Adult content dialler - see <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=11&t=6465&st=15&" target="_blank"> here</a>
  17137. Source=Paul Collins Startup list
  17138.  
  17139. [dluca]
  17140. Number=2434
  17141. Confirmed=X
  17142. Filename=dluca.exe
  17143. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-100216-1500-99" target="_blank">DLUCA.C</a> TROJAN!
  17144. Source=Paul Collins Startup list
  17145.  
  17146. [dluxde]
  17147. Number=2435
  17148. Confirmed=X
  17149. Filename=dluxde.exe
  17150. Description=All-In-One-Telcom (adult content dialler) variant
  17151. Source=Paul Collins Startup list
  17152.  
  17153. [Dluxjp]
  17154. Number=2436
  17155. Confirmed=X
  17156. Filename=cnfrm.exe
  17157. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102909-5644-99" target="_blank">DLUCA.D</a> TROJAN!
  17158. Source=Paul Collins Startup list
  17159.  
  17160. [Dm Hr]
  17161. Number=2437
  17162. Confirmed=X
  17163. Filename=lpns.exe
  17164. Description=Added by the <a href="http://kr.ahnlab.com/SecuInfoVirusViewEngNew3.ahn?SEQ_NO=7228" target="_blank">IRCBOT.WORM.61673</a> WORM!
  17165. Source=Paul Collins Startup list
  17166.  
  17167. [DM mgr]
  17168. Number=2438
  17169. Confirmed=X
  17170. Filename=dm_mgr.exe
  17171. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-100316-2418-99" target="_blank">JITTAR</a> TROJAN!
  17172. Source=Paul Collins Startup list
  17173.  
  17174. [dm***.exe [* = random char]]
  17175. Number=2439
  17176. Confirmed=X
  17177. Filename=dm***.exe [* = random char]
  17178. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Misc.WareOut&threatid=40280" target=_blank>Wareout</a> - malware masquerading as a spyware and dialer remover
  17179. Source=Paul Collins Startup list
  17180.  
  17181. [DMAScheduler]
  17182. Number=2440
  17183. Confirmed=N
  17184. Filename=DMAScheduler.exe
  17185. Description=Related to <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/dmascheduler/" target="_blank">DigitalMedia</a> Plus Archiver. This program is non-essential process to the running of the program, but should not be terminated unless suspected to be causing problems
  17186. Source=Paul Collins Startup list
  17187.  
  17188. [DMC]
  17189. Number=2441
  17190. Confirmed=X
  17191. Filename=dmc.exe
  17192. Description=Added by Trojan-Downloader.Win32.Dluca.bv TROJAN!
  17193. Source=Paul Collins Startup list
  17194.  
  17195. [DMHotKey]
  17196. Number=2442
  17197. Confirmed=U
  17198. Filename=DMLoader.exe
  17199. Description=HotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
  17200. Source=Paul Collins Startup list
  17201.  
  17202. [DMILDR]
  17203. Number=2443
  17204. Confirmed=N
  17205. Filename=dmildr.exe
  17206. Description=Part of <a href="http://docs.us.dell.com/support/edocs/software/smcliins/cli60/en/ug/intro.htm" target="_blank">Dell OpenManage Client Instrumentation</a> - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs
  17207. Source=Paul Collins Startup list
  17208.  
  17209. [DMISL]
  17210. Number=2444
  17211. Confirmed=N
  17212. Filename=DMISL.EXE
  17213. Description=DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See <a href="http://www.intel.com/support/tokenexpress/pro/sb/cs-016261.htm" target="_blank">here</a> for more information
  17214. Source=Paul Collins Startup list
  17215.  
  17216. [DMISLAPP]
  17217. Number=2445
  17218. Confirmed=N
  17219. Filename=DMISLAPP.exe
  17220. Description=DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See <a href="http://www.intel.com/support/tokenexpress/pro/sb/cs-016261.htm" target="_blank">here</a> for more information
  17221. Source=Paul Collins Startup list
  17222.  
  17223. [dmjay]
  17224. Number=2446
  17225. Confirmed=?
  17226. Filename=dmjay.exe
  17227. Description=<font color="#FF0000">??</font>
  17228. Source=Paul Collins Startup list
  17229.  
  17230. [dmloader]
  17231. Number=2447
  17232. Confirmed=X
  17233. Filename=dmloader.exe
  17234. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
  17235. Source=Paul Collins Startup list
  17236.  
  17237. [Dmsvc32]
  17238. Number=2448
  17239. Confirmed=X
  17240. Filename=Dmsvc32.exe
  17241. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.ABU" target="_blank">AGOBOT.ABU</a> WORM!
  17242. Source=Paul Collins Startup list
  17243.  
  17244. [dmtdll]
  17245. Number=2449
  17246. Confirmed=X
  17247. Filename=dmtdll.exe
  17248. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  17249. Source=Paul Collins Startup list
  17250.  
  17251. [DMXLauncher]
  17252. Number=2450
  17253. Confirmed=U
  17254. Filename=DMXLauncher.exe
  17255. Description=Part of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files
  17256. Source=Paul Collins Startup list
  17257.  
  17258. [dm[3 random letters].exe]
  17259. Number=2451
  17260. Confirmed=X
  17261. Filename=dm[3 random letters].exe
  17262. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120710-4752-99" target=_blank>RUINDEM</a> TROJAN!
  17263. Source=Paul Collins Startup list
  17264.  
  17265. [DM_server]
  17266. Number=2452
  17267. Confirmed=X
  17268. Filename=dmserver.exe
  17269. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Comet%20Cursor&threatid=29168" target=_blank>Comet Cursor</a> adware
  17270. Source=Paul Collins Startup list
  17271.  
  17272. [dm_service]
  17273. Number=2453
  17274. Confirmed=X
  17275. Filename=[path to file]
  17276. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-041811-4707-99" target=_blank>MITGLIEDER.P</a> TROJAN!
  17277. Source=Paul Collins Startup list
  17278.  
  17279. [dnam]
  17280. Number=2454
  17281. Confirmed=X
  17282. Filename=d140113.a.Stub.EXE
  17283. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.Downloader.Stub.A&threatid=42053" target=_blank>STUB_A</a> TROJAN!
  17284. Source=Paul Collins Startup list
  17285.  
  17286. [Dnar]
  17287. Number=2455
  17288. Confirmed=X
  17289. Filename=Dnar.exe
  17290. Description=Unknown, except that it is not necessary. Tends to phone home a lot. DMI related - see <a href="http://www.spywareinfo.com/yabbse/index.php?board=10;action=display;threadid=1137;start=0" target="_blank">here</a>
  17291. Source=Paul Collins Startup list
  17292.  
  17293. [DNE Binding Watchdog]
  17294. Number=2456
  17295. Confirmed=Y
  17296. Filename=rundll dnes.dll, DnDneCheckBindings
  17297. Description=Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
  17298. Source=Paul Collins Startup list
  17299.  
  17300. [DNE DUN Watchdog]
  17301. Number=2457
  17302. Confirmed=Y
  17303. Filename=rundll dnes.dll, DnDneCheckDUN13
  17304. Description=Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
  17305. Source=Paul Collins Startup list
  17306.  
  17307. [DNHelper32]
  17308. Number=2458
  17309. Confirmed=X
  17310. Filename=DNHlp32.exe
  17311. Description=Added by an unidentified WORM or TROJAN!
  17312. Source=Paul Collins Startup list
  17313.  
  17314. [DNS]
  17315. Number=2459
  17316. Confirmed=X
  17317. Filename=mc-58-12-0000080.exe
  17318. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-060715-4527-99" target=_blank>Shorty</a> adware - also detected as the AGENT.FD TROJAN!
  17319. Source=Paul Collins Startup list
  17320.  
  17321. [DNS]
  17322. Number=2460
  17323. Confirmed=X
  17324. Filename=mc-58-12-0000093.exe
  17325. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-060715-4527-99" target=_blank>Shorty</a> adware - also detected as the AGENT.FD TROJAN!
  17326. Source=Paul Collins Startup list
  17327.  
  17328. [DNS]
  17329. Number=2461
  17330. Confirmed=X
  17331. Filename=mc-110-12-0000079.exe
  17332. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-060715-4527-99" target=_blank>Shorty</a> adware - also detected as the AGENT.FD TROJAN!
  17333. Source=Paul Collins Startup list
  17334.  
  17335. [DNS]
  17336. Number=2462
  17337. Confirmed=X
  17338. Filename=mc-58-12-0000120.exe
  17339. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-060715-4527-99" target=_blank>Shorty</a> adware - also detected as the AGENT.FD TROJAN!
  17340. Source=Paul Collins Startup list
  17341.  
  17342. [DNS]
  17343. Number=2463
  17344. Confirmed=X
  17345. Filename=mc-58-12-0000140.exe
  17346. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-060715-4527-99" target=_blank>Shorty</a> adware - also detected as the AGENT.FD TROJAN!
  17347. Source=Paul Collins Startup list
  17348.  
  17349. [DNS]
  17350. Number=2464
  17351. Confirmed=X
  17352. Filename=[worm filename]
  17353. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32bckdrcqg.html" target=_blank>CQG</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Common Files folder
  17354. Source=Paul Collins Startup list
  17355.  
  17356. [Dns Resolver]
  17357. Number=2465
  17358. Confirmed=X
  17359. Filename=dnsrslve.exe
  17360. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotws.html" target=_blank>RBOT-WS</a> WORM!
  17361. Source=Paul Collins Startup list
  17362.  
  17363. [DNS Service]
  17364. Number=2466
  17365. Confirmed=X
  17366. Filename=dnsresolver.exe
  17367. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpq.html" target=_blank>RBOT-PQ</a> WORM!
  17368. Source=Paul Collins Startup list
  17369.  
  17370. [DNS Service]
  17371. Number=2467
  17372. Confirmed=X
  17373. Filename=dnssvc.exe
  17374. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotz.html" target="_blank">DELBOT-Z</a> WORM!
  17375. Source=Paul Collins Startup list
  17376.  
  17377. [DNS2GoClient]
  17378. Number=2468
  17379. Confirmed=?
  17380. Filename=dns2goclient.exe
  17381. Description=<a href="http://dns2go.deerfield.com/" target="_blank">DNS2Go</a> is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. <font color="#FF0000">Is it required?</font>
  17382. Source=Paul Collins Startup list
  17383.  
  17384. [DNSCacheBoost]
  17385. Number=2469
  17386. Confirmed=X
  17387. Filename=dnsping.exe
  17388. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdnsbusta.html" target= blank>DNSBUST-A</a> TROJAN!
  17389. Source=Paul Collins Startup list
  17390.  
  17391. [dnscleaner]
  17392. Number=2470
  17393. Confirmed=X
  17394. Filename=dnscleaner.exe
  17395. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  17396. Source=Paul Collins Startup list
  17397.  
  17398. [DNXVC]
  17399. Number=2471
  17400. Confirmed=?
  17401. Filename=dnxvc.exe
  17402. Description=<font color="#FF0000">??</font>
  17403. Source=Paul Collins Startup list
  17404.  
  17405. [DocTor]
  17406. Number=2472
  17407. Confirmed=X
  17408. Filename=Doctor.exe
  17409. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOTOR.A" target="_blank">DOTOR.A</a> WORM!
  17410. Source=Paul Collins Startup list
  17411.  
  17412. [DocuMagix Init]
  17413. Number=2473
  17414. Confirmed=N
  17415. Filename=PWATCH.EXE
  17416. Description=<a href="http://www.papermaster.net/pmpro/twa/page/home" target="_blank">PaperMaster</a> is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed
  17417. Source=Paul Collins Startup list
  17418.  
  17419. [Document Manager]
  17420. Number=2474
  17421. Confirmed=U
  17422. Filename=docmgr.exe
  17423. Description=Wave Systems Corp. <a href="http://www.wavesys.com/support/CSC/CustomerService/cssearch.asp" target="_blank">Document Manager</a> - "provides secure storage and management capabilities for file and folder level encryption"
  17424. Source=Paul Collins Startup list
  17425.  
  17426. [Doggy Style]
  17427. Number=2475
  17428. Confirmed=X
  17429. Filename=MsPMSPSd.exe
  17430. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotaap.html" target=_blank>SDBOT-AAP</a> WORM!
  17431. Source=Paul Collins Startup list
  17432.  
  17433. [DOGStart]
  17434. Number=2476
  17435. Confirmed=X
  17436. Filename=GSDOGST.EXE
  17437. Description=Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
  17438. Source=Paul Collins Startup list
  17439.  
  17440. [Doing]
  17441. Number=2477
  17442. Confirmed=?
  17443. Filename=doing.exe
  17444. Description=<font color="#FF0000">??</font>
  17445. Source=Paul Collins Startup list
  17446.  
  17447. [doit.exe]
  17448. Number=2478
  17449. Confirmed=X
  17450. Filename=doit.exe
  17451. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotek.html" target= blank>FORBOT-EK</a> WORM!
  17452. Source=Paul Collins Startup list
  17453.  
  17454. [Domain Name Resolve Service]
  17455. Number=2479
  17456. Confirmed=X
  17457. Filename=dnsresolver.exe
  17458. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-020213-5552-99" target=_blank>KIMAN.A</a> WORM!
  17459. Source=Paul Collins Startup list
  17460.  
  17461. [Don't Panic]
  17462. Number=2480
  17463. Confirmed=U
  17464. Filename=dontpanicdemodp.exe
  17465. Description=30-day trial version of <a href="http://www.panicware.com/product_dp.html" target="_blank">Don't Panic</a> privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite."
  17466. Source=Paul Collins Startup list
  17467.  
  17468. [Don't Panic Pop-Up Stopper]
  17469. Number=2481
  17470. Confirmed=U
  17471. Filename=dpps2.exe
  17472. Description=<a href="http://www.panicware.com/product_companion.html" target="_blank">Pop-Up Stopper Companion</a> from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
  17473. Source=Paul Collins Startup list
  17474.  
  17475. [Don't Panic!]
  17476. Number=2482
  17477. Confirmed=U
  17478. Filename=DP.EXE
  17479. Description=<a href="http://www.panicware.com/product_dp.html" target="_blank">Don't Panic!</a> privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite"
  17480. Source=Paul Collins Startup list
  17481.  
  17482. [Dopus]
  17483. Number=2483
  17484. Confirmed=U
  17485. Filename=dopus.exe
  17486. Description=<a href="http://gpsoft.com.au/Intro.html" target="_blank">Directory Opus</a> - a file manager from GPSoft
  17487. Source=Paul Collins Startup list
  17488.  
  17489. [dos]
  17490. Number=2484
  17491. Confirmed=X
  17492. Filename=dos64.exe
  17493. Description=Adware downloader trojan
  17494. Source=Paul Collins Startup list
  17495.  
  17496. [Dos Prompt Loader]
  17497. Number=2485
  17498. Confirmed=X
  17499. Filename=cygwin.exe
  17500. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotvv.html" target= blank>SDBOT-VV</a> WORM!
  17501. Source=Paul Collins Startup list
  17502.  
  17503. [Dosbat]
  17504. Number=2486
  17505. Confirmed=?
  17506. Filename=??
  17507. Description=<font color="#FF0000">??</font>
  17508. Source=Paul Collins Startup list
  17509.  
  17510. [DoubleDesktop]
  17511. Number=2487
  17512. Confirmed=U
  17513. Filename=dd.exe
  17514. Description="<a href="http://www.fatfreesoft.com/2desk.php" target=_blank>DoubleDesktop</a> is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"
  17515.  
  17516. Source=Paul Collins Startup list
  17517.  
  17518. [DoUWantIt]
  17519. Number=2488
  17520. Confirmed=N
  17521. Filename=duwi.exe
  17522. Description=DoUWantIt - online shopping assistant. Start it manually
  17523. Source=Paul Collins Startup list
  17524.  
  17525. [down]
  17526. Number=2489
  17527. Confirmed=X
  17528. Filename=hlp32.exe
  17529. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?Vname=TROJ_DLOADER.BG" target=_blank>DLOADER.BG</a> TROJAN!
  17530. Source=Paul Collins Startup list
  17531.  
  17532. [down]
  17533. Number=2490
  17534. Confirmed=X
  17535. Filename=[trojan filename]
  17536. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmallqj.html" target=_blank>Small-QJ</a> TROJAN!
  17537. Source=Paul Collins Startup list
  17538.  
  17539. [Down2Home]
  17540. Number=2491
  17541. Confirmed=U
  17542. Filename=Down2Home.exe
  17543. Description=<a href="http://jitserv.coolfreepage.com/" target=_blank>Down2Home</a> - "monitors your ADSL/Cablemodem/Dialup traffic and provides you with usefull statistics about the amount of data your PC has transferred"
  17544.  
  17545. Source=Paul Collins Startup list
  17546.  
  17547. [Download Accelerator Plus 5.0]
  17548. Number=2492
  17549. Confirmed=N
  17550. Filename=DAP.exe
  17551. Description=<a href="http://www.speedbit.com/" target="_blank">Download Accelerator Plus</a> from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
  17552. Source=Paul Collins Startup list
  17553.  
  17554. [Download Plus]
  17555. Number=2493
  17556. Confirmed=X
  17557. Filename=DownloadPlus.exe
  17558. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=DownloadPlus&threatid=4618" target=_blank>DownloadPlus</a> adware
  17559. Source=Paul Collins Startup list
  17560.  
  17561. [Download Wonder]
  17562. Number=2494
  17563. Confirmed=N
  17564. Filename=DownloadWonder.exe
  17565. Description=<a href="http://www.forty.com/" target="_blank">Download Wonder</a> from Forty Software. Download manager for resuming downloads, amongst other features
  17566. Source=Paul Collins Startup list
  17567.  
  17568. [DownloadAccelerator]
  17569. Number=2495
  17570. Confirmed=N
  17571. Filename=DAP.EXE
  17572. Description=<a href="http://www.speedbit.com/" target="_blank">Download Accelerator Plus</a> from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
  17573. Source=Paul Collins Startup list
  17574.  
  17575. [DownloadLegalMusic]
  17576. Number=2496
  17577. Confirmed=X
  17578. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  17579. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  17580. Source=Paul Collins Startup list
  17581.  
  17582. [DownloadWare]
  17583. Number=2497
  17584. Confirmed=X
  17585. Filename=dw.exe
  17586. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=DownloadWare&threatid=4620" target=_blank>DownloadWare</a> adware
  17587. Source=Paul Collins Startup list
  17588.  
  17589. [DownloadWare Engine]
  17590. Number=2498
  17591. Confirmed=X
  17592. Filename=Dwe.exe
  17593. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=DownloadWare&threatid=4620" target=_blank>DownloadWare</a> adware
  17594. Source=Paul Collins Startup list
  17595.  
  17596. [Downxz]
  17597. Number=2499
  17598. Confirmed=X
  17599. Filename=Downxz.bat
  17600. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091411-5523-99" target="_blank">MYDOOM.W</a> WORM
  17601. Source=Paul Collins Startup list
  17602.  
  17603. [DPAgnt]
  17604. Number=2500
  17605. Confirmed=N
  17606. Filename=DPAgnt.exe
  17607. Description=<a href="http://www.digitalpersona.com/" target="_blank">digitalPersona</a> fingerprint scanner
  17608. Source=Paul Collins Startup list
  17609.  
  17610. [DPAS]
  17611. Number=2501
  17612. Confirmed=U
  17613. Filename=DPASNT.exe
  17614. Description=DefenderPro AntiSpy - spyware remover
  17615. Source=Paul Collins Startup list
  17616.  
  17617. [DPASUpdate]
  17618. Number=2502
  17619. Confirmed=U
  17620. Filename=DPASAutUpdate.exe
  17621. Description=Automatic updates for DefenderPro AntiSpy - spyware remover
  17622. Source=Paul Collins Startup list
  17623.  
  17624. [Dpcnav]
  17625. Number=2503
  17626. Confirmed=Y
  17627. Filename=dpcnav.exe
  17628. Description=DirecWay from DirectTV (now <a href="http://go.gethughesnet.com/HUGHES/Rooms/DisplayPages/LayoutInitial?pageid=hughesnetc&Container=com.webridge.entity.Entity[OID[91908CBE85AD4C428CCD8D5CDB016B51]]" target="_blank">HughesNet</a>) - satellite based high-speed internet access
  17629. Source=Paul Collins Startup list
  17630.  
  17631. [DPConfig]
  17632. Number=2504
  17633. Confirmed=N
  17634. Filename=DPConfig.exe
  17635. Description=Compuware DevPartner Studio Configuration Utility, a tool for software developers - System Tray access to configure the utility's analysis. Not required at startup, can be launched from the Start Menu programs group when needed
  17636. Source=Paul Collins Startup list
  17637.  
  17638. [dpcproxy]
  17639. Number=2505
  17640. Confirmed=X
  17641. Filename=dpcproxy.exe
  17642. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojgoldenpa.html" target="_blank">GOLDENP-A</a> TROJAN!
  17643. Source=Paul Collins Startup list
  17644.  
  17645. [DPCProxyLoadOnStartup]
  17646. Number=2506
  17647. Confirmed=Y
  17648. Filename=dpcstart.exe
  17649. Description=DirecWay from DirectTV (now <a href="http://go.gethughesnet.com/HUGHES/Rooms/DisplayPages/LayoutInitial?pageid=hughesnetc&Container=com.webridge.entity.Entity[OID[91908CBE85AD4C428CCD8D5CDB016B51]]" target="_blank">HughesNet</a>) - satellite based high-speed internet access
  17650. Source=Paul Collins Startup list
  17651.  
  17652. [Dpcstart]
  17653. Number=2507
  17654. Confirmed=Y
  17655. Filename=dpcstart.exe
  17656. Description=DirecWay from DirectTV (now <a href="http://go.gethughesnet.com/HUGHES/Rooms/DisplayPages/LayoutInitial?pageid=hughesnetc&Container=com.webridge.entity.Entity[OID[91908CBE85AD4C428CCD8D5CDB016B51]]" target="_blank">HughesNet</a>) - satellite based high-speed internet access
  17657. Source=Paul Collins Startup list
  17658.  
  17659. [dpi]
  17660. Number=2508
  17661. Confirmed=X
  17662. Filename=dpi.exe
  17663. Description=<a href="http://www.spywareguide.com/product_show.php?id=727" target=_blank>Delfin Media Viewer</a> or "Promulgate" adware
  17664. Source=Paul Collins Startup list
  17665.  
  17666. [dpnsvr32]
  17667. Number=2509
  17668. Confirmed=X
  17669. Filename=dpnsvr32.exe
  17670. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojaolpassb.html" target=_blank>AOLPASS-B</a> TROJAN!
  17671. Source=Paul Collins Startup list
  17672.  
  17673. [dpps2]
  17674. Number=2510
  17675. Confirmed=U
  17676. Filename=dpps2.exe
  17677. Description=<a href="http://www.panicware.com/product_companion.html" target="_blank">Pop-Up Stopper Companion</a> from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
  17678. Source=Paul Collins Startup list
  17679.  
  17680. [dps]
  17681. Number=2511
  17682. Confirmed=X
  17683. Filename=dps.exe
  17684. Description=<a href="http://allentech.net/parasite/SmartestSearch.html" target="_blank">SmartestSearch</a> parasite - poses as a foistware, bogus adware/spyware remover called "scumware-remover"
  17685.  
  17686. Source=Paul Collins Startup list
  17687.  
  17688. [dptracker]
  17689. Number=2512
  17690. Confirmed=N
  17691. Filename=dptracker.exe
  17692. Description=<a href="http://www.digitalpeers.com/" target=_blank>CamTrack</a> webcam software that enhances the way people video chat
  17693.  
  17694. Source=Paul Collins Startup list
  17695.  
  17696. [DpUtil]
  17697. Number=2513
  17698. Confirmed=U
  17699. Filename=TEDTray.exe
  17700. Description=Main executable for TOSHIBA <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/tedtray/" target="_blank">DualPoint Utility</a> Main Module. It is a system tray icon program that provides configuration options for dual pointing device
  17701. Source=Paul Collins Startup list
  17702.  
  17703. [Drag'n'Drop_Autolaunch]
  17704. Number=2514
  17705. Confirmed=N
  17706. Filename=Autolaunch.exe
  17707. Description=<a href="http://www.iomega.com/hotburn/hotburn_main.html" target="_blank">Iomega HotBurn</a> - CD-RW burning software
  17708. Source=Paul Collins Startup list
  17709.  
  17710. [DragDrop]
  17711. Number=2515
  17712. Confirmed=?
  17713. Filename=DragDrop.exe
  17714. Description=<font color="#FF0000">??</font>
  17715. Source=Paul Collins Startup list
  17716.  
  17717. [DragnDrop_Autolaunch]
  17718. Number=2516
  17719. Confirmed=N
  17720. Filename=Autolaunch.exe
  17721. Description=<a href="http://www.iomega.com/hotburn/hotburn_main.html" target="_blank">Iomega HotBurn</a> - CD-RW burning software
  17722. Source=Paul Collins Startup list
  17723.  
  17724. [DRam prmaessor]
  17725. Number=2517
  17726. Confirmed=X
  17727. Filename=[random filename]
  17728. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CSG" target="_blank">RBOT.CSG</a> WORM!
  17729. Source=Paul Collins Startup list
  17730.  
  17731. [DRam prosesor]
  17732. Number=2518
  17733. Confirmed=X
  17734. Filename=[random filename]
  17735. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.EE" target="_blank">SPYBOT.EE</a> WORM!
  17736. Source=Paul Collins Startup list
  17737.  
  17738. [DRam prosessor]
  17739. Number=2519
  17740. Confirmed=X
  17741. Filename=[random filename]
  17742. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CSG" target="_blank">RBOT.CSG</a> WORM!
  17743. Source=Paul Collins Startup list
  17744.  
  17745. [DRam prosessor]
  17746. Number=2520
  17747. Confirmed=X
  17748. Filename=plscd.exe
  17749. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CYA" target="_blank">RBOT.CYA</a> WORM!
  17750. Source=Paul Collins Startup list
  17751.  
  17752. [DRam prosessor]
  17753. Number=2521
  17754. Confirmed=X
  17755. Filename=HWAPI.exe
  17756. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM! Note - this is not the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/hwapi/" target="_blank">McAfee HackerWatch</a> process which has the same filename
  17757. Source=Paul Collins Startup list
  17758.  
  17759. [DRan posessor]
  17760. Number=2522
  17761. Confirmed=X
  17762. Filename=DAP.exe
  17763. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  17764. Source=Paul Collins Startup list
  17765.  
  17766. [DrCache]
  17767. Number=2523
  17768. Confirmed=X
  17769. Filename=MSTDC.EXE
  17770. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorjm.html" target=_blank>JM</a> TROJAN!
  17771. Source=Paul Collins Startup list
  17772.  
  17773. [dreams]
  17774. Number=2524
  17775. Confirmed=X
  17776. Filename=server.exe
  17777. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  17778. Source=Paul Collins Startup list
  17779.  
  17780. [DrefIW]
  17781. Number=2525
  17782. Confirmed=X
  17783. Filename=SysDrefIWv2.exe
  17784. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32drefc.html" target=_blank>DREF-C</a> WORM!
  17785. Source=Paul Collins Startup list
  17786.  
  17787. [DrefIW]
  17788. Number=2526
  17789. Confirmed=X
  17790. Filename=SysDref.exe
  17791. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32drefd.html" target=_blank>DREF-D</a> WORM!
  17792. Source=Paul Collins Startup list
  17793.  
  17794. [dregfix]
  17795. Number=2527
  17796. Confirmed=?
  17797. Filename=ph_finder.exe
  17798. Description=<font color="#FF0000">??</font>
  17799. Source=Paul Collins Startup list
  17800.  
  17801. [DrgToDsc]
  17802. Number=2528
  17803. Confirmed=N
  17804. Filename=DrgToDsc.exe
  17805. Description=Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
  17806. Source=Paul Collins Startup list
  17807.  
  17808. [dried.exe]
  17809. Number=2529
  17810. Confirmed=?
  17811. Filename=dried.exe
  17812. Description=<font color="#FF0000">??</font>
  17813. Source=Paul Collins Startup list
  17814.  
  17815. [DriveCleaner 2006 Free]
  17816. Number=2530
  17817. Confirmed=N
  17818. Filename=UDC2006.exe
  17819. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-062217-0726-99" target="_blank">DriveCleaner</a> is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks
  17820. Source=Paul Collins Startup list
  17821.  
  17822. [DriveIcons]
  17823. Number=2531
  17824. Confirmed=U
  17825. Filename=DriveIcon.exe
  17826. Description=<a href="http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=15&PFid=25&Level=4&Conn=3" target="_blank">Drive Icons</a> from Realtek - shows a specific icon for each card type for their card reader controllers
  17827. Source=Paul Collins Startup list
  17828.  
  17829. [DriveLED]
  17830. Number=2532
  17831. Confirmed=U
  17832. Filename=OODLed.exe
  17833. Description=<a href="http://www.oo-software.com/home/en/products/oodriveled/" target="_blank">O&O DriveLED</a> - hard disk monitoring and crash prevention
  17834. Source=Paul Collins Startup list
  17835.  
  17836. [Driver]
  17837. Number=2533
  17838. Confirmed=X
  17839. Filename=gbot.exe
  17840. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_JUNTADOR.K" target="_blank">JUNTADOR.K</a> TROJAN!
  17841. Source=Paul Collins Startup list
  17842.  
  17843. [Driver32]
  17844. Number=2534
  17845. Confirmed=X
  17846. Filename=Scam32.exe
  17847. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-071720-1640-99" target="_blank"> SIRCAM</a> WORM!
  17848. Source=Paul Collins Startup list
  17849.  
  17850. [DriverCheck]
  17851. Number=2535
  17852. Confirmed=X
  17853. Filename=svchost.exe
  17854. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelfkr.html" target=_blank>DELF-KR</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:\DriverLoad folder
  17855. Source=Paul Collins Startup list
  17856.  
  17857. [DriverDB]
  17858. Number=2536
  17859. Confirmed=X
  17860. Filename=svcmdx32.exe
  17861. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-041722-3847-99" target=_blank>BERPI</a> TROJAN!
  17862. Source=Paul Collins Startup list
  17863.  
  17864. [DriverLoad]
  17865. Number=2537
  17866. Confirmed=X
  17867. Filename=svchost.exe
  17868. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelfkr.html" target=_blank>DELF-KR</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:\DriverLoad folder
  17869. Source=Paul Collins Startup list
  17870.  
  17871. [DriverModule]
  17872. Number=2538
  17873. Confirmed=X
  17874. Filename=csrnvrt.exe
  17875. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-013116-4032-99" target=_blank>IRCBOT.I</a> TROJAN!
  17876. Source=Paul Collins Startup list
  17877.  
  17878. [DriverPath]
  17879. Number=2539
  17880. Confirmed=X
  17881. Filename=system32.exe
  17882. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojprorats.html" target=_blank>PRORAT-S</a> TROJAN!
  17883. Source=Paul Collins Startup list
  17884.  
  17885. [Drivers for Internet Explorer]
  17886. Number=2540
  17887. Confirmed=X
  17888. Filename=accesweb.exe
  17889. Description=Added by freewebs.com hijacker!
  17890. Source=Paul Collins Startup list
  17891.  
  17892. [DriveSelect]
  17893. Number=2541
  17894. Confirmed=N
  17895. Filename=driveselect.exe
  17896. Description=<a href="http://www.321studiosinc.com/" target=_blank>DVD X Copy XPress</a> by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
  17897.  
  17898. Source=Paul Collins Startup list
  17899.  
  17900. [drkly16j]
  17901. Number=2542
  17902. Confirmed=U
  17903. Filename=rundll32.exe drkly16j.dll, ServiceCheck
  17904. Description=<a href="http://www.kidswatch.com/" target=_blank>KidsWatch Time Control</a> parental control software
  17905. Source=Paul Collins Startup list
  17906.  
  17907. [dRMON SmartAgent]
  17908. Number=2543
  17909. Confirmed=U
  17910. Filename=SmartAgt.exe
  17911. Description=Part of the network monitoring program group for 3Com NIC cards. See <a href="http://support.3com.com/infodeli/tools/netmgt/rmonprob/product/drmon/chap1.htm" target="_blank">here</a> for more info
  17912. Source=Paul Collins Startup list
  17913.  
  17914. [drmu]
  17915. Number=2544
  17916. Confirmed=X
  17917. Filename=W95Mm.exe
  17918. Description=Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
  17919. Source=Paul Collins Startup list
  17920.  
  17921. [drocher]
  17922. Number=2545
  17923. Confirmed=X
  17924. Filename=d.exe
  17925. Description=Adult content dialler
  17926. Source=Paul Collins Startup list
  17927.  
  17928. [DropSpam Lifestyle]
  17929. Number=2546
  17930. Confirmed=X
  17931. Filename=dslifestyle.exe
  17932. Description=<a href="http://vil.mcafeesecurity.com/vil/content/v_137582.htm" target="_blank">Dropspam</a> adware
  17933. Source=Paul Collins Startup list
  17934.  
  17935. [drvddll.exe]
  17936. Number=2547
  17937. Confirmed=X
  17938. Filename=drvddll.exe
  17939. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081712-1706-99" target="_blank">BEAGLE.AP</a> WORM!
  17940. Source=Paul Collins Startup list
  17941.  
  17942. [Drvddll_exe]
  17943. Number=2548
  17944. Confirmed=X
  17945. Filename=drvddll.exe
  17946. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042815-2313-99" target="_blank">BEAGLE.X</a> WORM!
  17947. Source=Paul Collins Startup list
  17948.  
  17949. [DrvListnr]
  17950. Number=2549
  17951. Confirmed=?
  17952. Filename=DrvListnr.exe
  17953. Description=Analog Devices SoundMAX soundcard related.<font color="#FF0000"> What does it do and is it required?</font>
  17954. Source=Paul Collins Startup list
  17955.  
  17956. [drvlsnr]
  17957. Number=2550
  17958. Confirmed=U
  17959. Filename=drvlsnr.exe
  17960. Description=Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
  17961. Source=Paul Collins Startup list
  17962.  
  17963. [DrvMon.exe]
  17964. Number=2551
  17965. Confirmed=U
  17966. Filename=DrvMon.exe
  17967. Description=<a href="http://www.alcormicro.com/products.php" target="_blank">Alcor</a> drive monitor software
  17968. Source=Paul Collins Startup list
  17969.  
  17970. [drvnetw]
  17971. Number=2552
  17972. Confirmed=X
  17973. Filename=drvnetw.exe
  17974. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbroggerb.html" target=_blank>BROGGER-B</a> TROJAN!
  17975. Source=Paul Collins Startup list
  17976.  
  17977. [drvr32h]
  17978. Number=2553
  17979. Confirmed=X
  17980. Filename=drvr32h.exe
  17981. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  17982. Source=Paul Collins Startup list
  17983.  
  17984. [drvrmanager]
  17985. Number=2554
  17986. Confirmed=X
  17987. Filename=drvrquery32.exe
  17988. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-072806-1847-99" target="_blank">BOOHOO</a> WORM!
  17989. Source=Paul Collins Startup list
  17990.  
  17991. [drvsys.exe]
  17992. Number=2555
  17993. Confirmed=X
  17994. Filename=drvsys.exe
  17995. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042617-0238-99" target="_blank">BEAGLE.W</a> WORM!
  17996. Source=Paul Collins Startup list
  17997.  
  17998. [drvsyskit]
  17999. Number=2556
  18000. Confirmed=X
  18001. Filename=hidr.exe
  18002. Description=Added by the <a href="http://www.f-secure.com/v-descs/email-worm_w32_bagle_hr.shtml" target="_blank">BAGLE.HR</a> WORM!
  18003. Source=Paul Collins Startup list
  18004.  
  18005. [drvupd]
  18006. Number=2557
  18007. Confirmed=X
  18008. Filename=rundll32 ..drvupd.inf
  18009. Description=Hijacker - drvupd.inf file installs a "searchforge.com" hijack
  18010. Source=Paul Collins Startup list
  18011.  
  18012. [drv_st_key]
  18013. Number=2558
  18014. Confirmed=X
  18015. Filename=hidn.exe
  18016. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-062016-4555-99" target="_blank">BEAGLE.FF</a> WORM!
  18017. Source=Paul Collins Startup list
  18018.  
  18019. [DrWatson]
  18020. Number=2559
  18021. Confirmed=X
  18022. Filename=drwatson_.exe
  18023. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlohavs.html" target=_blank>LOHAV-S</a> TROJAN!
  18024. Source=Paul Collins Startup list
  18025.  
  18026. [DrWatson]
  18027. Number=2560
  18028. Confirmed=X
  18029. Filename=drwatson_32.exe
  18030. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlohavs.html" target=_blank>LOHAV-S</a> TROJAN!
  18031. Source=Paul Collins Startup list
  18032.  
  18033. [DrWeb Antivirus]
  18034. Number=2561
  18035. Confirmed=X
  18036. Filename=DRWEBAV.EXE
  18037. Description=Added by an unidentified WORM or TROJAN!
  18038. Source=Paul Collins Startup list
  18039.  
  18040. [Drwebscheduler]
  18041. Number=2562
  18042. Confirmed=Y
  18043. Filename=Drwebscd.exe
  18044. Description=<a href="http://www.drweb.com/" target="_blank">DrWeb</a> antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem
  18045. Source=Paul Collins Startup list
  18046.  
  18047. [DR_S]
  18048. Number=2563
  18049. Confirmed=X
  18050. Filename=DR_S.exe
  18051. Description=<a href="http://sarc.com/avcenter/venc/data/adware.adshooter.html" target="_blank">AdShooter</a> adware
  18052. Source=Paul Collins Startup list
  18053.  
  18054. [ds]
  18055. Number=2564
  18056. Confirmed=X
  18057. Filename=ds.exe
  18058. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-112514-4016-99" target=_blank>SPYMON</a> TROJAN!
  18059. Source=Paul Collins Startup list
  18060.  
  18061. [DS Clock]
  18062. Number=2565
  18063. Confirmed=U
  18064. Filename=dsclock.exe
  18065. Description=Digital desktop clock including synchronization with atomic servers - see <a href="http://www.dualitysoft.com/dsclock/" target="_blank">here</a>
  18066. Source=Paul Collins Startup list
  18067.  
  18068. [dsa]
  18069. Number=2566
  18070. Confirmed=X
  18071. Filename=dsa.exe
  18072. Description=Homepage hijacker - redirecting to downseek.com
  18073. Source=Paul Collins Startup list
  18074.  
  18075. [DSAcass]
  18076. Number=2567
  18077. Confirmed=X
  18078. Filename=[path to file]
  18079. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112615-3900-99" target=_blank>RANKY.M</a> TROJAN!
  18080. Source=Paul Collins Startup list
  18081.  
  18082. [DSB]
  18083. Number=2568
  18084. Confirmed=X
  18085. Filename=DSB.exe
  18086. Description=<a href="http://sarc.com/avcenter/venc/data/pf/adware.energyplugin.html" target="_blank">EnergyPlugin</a> adware
  18087. Source=Paul Collins Startup list
  18088.  
  18089. [dsd]
  18090. Number=2569
  18091. Confirmed=X
  18092. Filename=zz.exe
  18093. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfox.html" target="_blank">RBOT-FOX</a> WORM!
  18094. Source=Paul Collins Startup list
  18095.  
  18096. [DSentry]
  18097. Number=2570
  18098. Confirmed=N
  18099. Filename=DSentry.exe
  18100. Description=Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
  18101. Source=Paul Collins Startup list
  18102.  
  18103. [Dsi]
  18104. Number=2571
  18105. Confirmed=X
  18106. Filename=dp-******.exe
  18107. Description=Added by an unidentified adware where ****** are random characters
  18108. Source=Paul Collins Startup list
  18109.  
  18110. [Dsi]
  18111. Number=2572
  18112. Confirmed=X
  18113. Filename=dp-him.exe
  18114. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmultidrah.html" target=_blank>MULTIDR-AH</a> TROJAN!
  18115. Source=Paul Collins Startup list
  18116.  
  18117. [Dskcompat]
  18118. Number=2573
  18119. Confirmed=X
  18120. Filename=Dskcompat.exe
  18121. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  18122. Source=Paul Collins Startup list
  18123.  
  18124. [DSKEY]
  18125. Number=2574
  18126. Confirmed=U
  18127. Filename=DsKey.exe
  18128. Description=Part of <a href="http://www.pcphonehome.com/" target="_blank">PC PhoneHome</a> - "secretly sends an invisible email message to an email address of your choice containing the physical location of your computer every time you get an Internet connection". Security software from Brigadoon Security Group for tracking down lost/stolen computers
  18129. Source=Paul Collins Startup list
  18130.  
  18131. [DSL Monitor]
  18132. Number=2575
  18133. Confirmed=N
  18134. Filename=spdstrm.exe
  18135. Description=Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
  18136. Source=Paul Collins Startup list
  18137.  
  18138. [DSLagentexe]
  18139. Number=2576
  18140. Confirmed=Y
  18141. Filename=DSLagent.exe
  18142. Description=Used in conjunction with USB connected ADSL modems from <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection
  18143. Source=Paul Collins Startup list
  18144.  
  18145. [dslmon]
  18146. Number=2577
  18147. Confirmed=Y
  18148. Filename=dslmon.exe
  18149. Description=Sagem DSL modem related. Apparently needed to detect the modem
  18150.  
  18151. Source=Paul Collins Startup list
  18152.  
  18153. [DSLSTATEXE]
  18154. Number=2578
  18155. Confirmed=U
  18156. Filename=dslstat.exe
  18157. Description=System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
  18158. Source=Paul Collins Startup list
  18159.  
  18160. [DsmSer]
  18161. Number=2579
  18162. Confirmed=X
  18163. Filename=dsm.exe
  18164. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  18165. Source=Paul Collins Startup list
  18166.  
  18167. [DsmSer]
  18168. Number=2580
  18169. Confirmed=X
  18170. Filename=msmpatch.exe
  18171. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  18172. Source=Paul Collins Startup list
  18173.  
  18174. [DsmSer]
  18175. Number=2581
  18176. Confirmed=X
  18177. Filename=svosm.exe
  18178. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  18179. Source=Paul Collins Startup list
  18180.  
  18181. [DsmSer]
  18182. Number=2582
  18183. Confirmed=X
  18184. Filename=sysup.exe
  18185. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030723-2605-99" target=_blank>SERFLOG.B</a> WORM!
  18186. Source=Paul Collins Startup list
  18187.  
  18188. [DsplObjects]
  18189. Number=2583
  18190. Confirmed=X
  18191. Filename=windspl.exe
  18192. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-020416-2130-99" target=_blank>BEAGLE.DN</a> WORM!
  18193. Source=Paul Collins Startup list
  18194.  
  18195. [DSS]
  18196. Number=2584
  18197. Confirmed=X
  18198. Filename=dssagent.exe
  18199. Description=DSSAgent by Br°derbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See <a href="http://cexx.org/dssagent.htm" target="_blank">here</a> for more info
  18200. Source=Paul Collins Startup list
  18201.  
  18202. [DSS]
  18203. Number=2585
  18204. Confirmed=X
  18205. Filename=[path to trojan]
  18206. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdssdoorc.html" target=_blank>DSSDOOR-C</a> TROJAN!
  18207. Source=Paul Collins Startup list
  18208.  
  18209. [DSService]
  18210. Number=2586
  18211. Confirmed=X
  18212. Filename=dmrss.exe
  18213. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotxx.html" target=_blank>AGOBOT-XX</a> WORM!
  18214. Source=Paul Collins Startup list
  18215.  
  18216. [DSSSGENS]
  18217. Number=2587
  18218. Confirmed=?
  18219. Filename=dssagens.exe
  18220. Description=<font color="#FF0000">??</font>
  18221. Source=Paul Collins Startup list
  18222.  
  18223. [DSystemDriver]
  18224. Number=2588
  18225. Confirmed=X
  18226. Filename=windrv.exe
  18227. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DELF.WG" target="_blank">DELF.WG</a> TROJAN!
  18228. Source=Paul Collins Startup list
  18229.  
  18230. [DU Meter]
  18231. Number=2589
  18232. Confirmed=N
  18233. Filename=DUMETER.EXE
  18234. Description=<a href="http://www.dumeter.com/main.php" target="_blank">Hagel Technologies</a> internet bandwidth monitor
  18235. Source=Paul Collins Startup list
  18236.  
  18237. [duck]
  18238. Number=2590
  18239. Confirmed=X
  18240. Filename=duck.exe
  18241. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotavg.html" target=_blank>AGOBOT-AVG</a> WORM!
  18242. Source=Paul Collins Startup list
  18243.  
  18244. [Dumeter Services]
  18245. Number=2591
  18246. Confirmed=X
  18247. Filename=dumeter.exe
  18248. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotaeq.html" target=_blank>SDBOT-AEQ</a> WORM!
  18249. Source=Paul Collins Startup list
  18250.  
  18251. [dumprep 0 -k]
  18252. Number=2592
  18253. Confirmed=N
  18254. Filename=dumprep 0 -k
  18255. Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
  18256. Source=Paul Collins Startup list
  18257.  
  18258. [dumprep 0 -u]
  18259. Number=2593
  18260. Confirmed=N
  18261. Filename=dumprep 0 -u
  18262. Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
  18263. Source=Paul Collins Startup list
  18264.  
  18265. [DUN_SERVICES3]
  18266. Number=2594
  18267. Confirmed=X
  18268. Filename=dun3.exe
  18269. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-062715-5302-99" target=_blank>SOKIRON</a> TROJAN!
  18270. Source=Paul Collins Startup list
  18271.  
  18272. [Duweculey]
  18273. Number=2595
  18274. Confirmed=X
  18275. Filename=yujixit.exe
  18276. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BRP&VSect=P" target=_blank>SDBOT.BRP</a> WORM!
  18277. Source=Paul Collins Startup list
  18278.  
  18279. [dvd43]
  18280. Number=2596
  18281. Confirmed=N
  18282. Filename=DVD43_Tray.exe
  18283. Description=<a href="http://www.dvdidle.com/dvd43.htm" target="_blank">DVD43</a> is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"
  18284. Source=Paul Collins Startup list
  18285.  
  18286. [DVD43]
  18287. Number=2597
  18288. Confirmed=U
  18289. Filename=DVD43.exe
  18290. Description=<a href="http://www.dvdidle.com/dvd43.htm" target="_blank">DVD43</a>  is a small tool that overrides CSS copy-protection found on DVD movies
  18291. Source=Paul Collins Startup list
  18292.  
  18293. [dvd98]
  18294. Number=2598
  18295. Confirmed=X
  18296. Filename=windvd98.exe
  18297. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-022917-5250-99" target="_blank">CULT.P</a> WORM!
  18298. Source=Paul Collins Startup list
  18299.  
  18300. [DVDBitSet]
  18301. Number=2599
  18302. Confirmed=U
  18303. Filename=DVDBitSet.exe
  18304. Description=DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
  18305. Source=Paul Collins Startup list
  18306.  
  18307. [DVDCheck]
  18308. Number=2600
  18309. Confirmed=?
  18310. Filename=DVDCheck.exe
  18311. Description=Related to an <a href="http://www.intervideo.com/jsp/Home.jsp" target=_blank>Intervideo</a> program. <font color="#FF0000">What does it do and is it required in startup?</font>
  18312. Source=Paul Collins Startup list
  18313.  
  18314. [Dvdcompat]
  18315. Number=2601
  18316. Confirmed=X
  18317. Filename=Dvdcompat.exe
  18318. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  18319. Source=Paul Collins Startup list
  18320.  
  18321. [DVDLauncher]
  18322. Number=2602
  18323. Confirmed=N
  18324. Filename=DVDLauncher.exe
  18325. Description=Part of Cyberlink's <a href="http://www.cyberlink.com/multi/products/main_12_ENU.html" target=_blank>Power Cinema</a> - allows you to play DVDs upon insertion
  18326.  
  18327. Source=Paul Collins Startup list
  18328.  
  18329. [DVDSentry]
  18330. Number=2603
  18331. Confirmed=N
  18332. Filename=DSentry.exe
  18333. Description=Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
  18334. Source=Paul Collins Startup list
  18335.  
  18336. [DVDTray]
  18337. Number=2604
  18338. Confirmed=N
  18339. Filename=DVDTray.exe
  18340. Description=HP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
  18341. Source=Paul Collins Startup list
  18342.  
  18343. [DVDUpgrade]
  18344. Number=2605
  18345. Confirmed=N
  18346. Filename=DVDUpgrd.exe
  18347. Description=Microsoft program to upgrade your DVD decoder program - see <a href="http://support.microsoft.com/default.aspx?scid=kb;en;306331" target=_blank>Q306331</a>. Available via Start -> Programs
  18348. Source=Paul Collins Startup list
  18349.  
  18350. [DVDXGhost]
  18351. Number=2606
  18352. Confirmed=N
  18353. Filename=DVDGhost.EXE
  18354. Description=<a href="http://www.region-free-dvd.com/" target=_blank>DVD Ghost</a> - "utility to make your software DVD players and DVD copy/backup softwares restriction-free, and copy/backup DVD to hard disk"
  18355.  
  18356. Source=Paul Collins Startup list
  18357.  
  18358. [Dvp95]
  18359. Number=2607
  18360. Confirmed=Y
  18361. Filename=Dvp95.exe
  18362. Description=Scan engine for <a href="http://www.f-secure.com/index.shtml" target="_blank">F-Secure</a> and Command antivirus software based on the <a href="http://www.f-prot.com" target="_blank">F-Prot AntiVirus</a> engine
  18363. Source=Paul Collins Startup list
  18364.  
  18365. [dvpapi9x]
  18366. Number=2608
  18367. Confirmed=Y
  18368. Filename=DVPAPI9X.exe
  18369. Description=Command AntiVirus for Windows 95/98/Me
  18370. Source=Paul Collins Startup list
  18371.  
  18372. [DvpInitExe]
  18373. Number=2609
  18374. Confirmed=Y
  18375. Filename=Dvpinit.exe
  18376. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> related
  18377. Source=Paul Collins Startup list
  18378.  
  18379. [dvprpt]
  18380. Number=2610
  18381. Confirmed=Y
  18382. Filename=Dvprpt.exe
  18383. Description=<a href="http://www.authentium.com/command/" target="_blank">Command Antivirus</a> related
  18384. Source=Paul Collins Startup list
  18385.  
  18386. [dvraudio]
  18387. Number=2611
  18388. Confirmed=X
  18389. Filename=dvraudio.exe
  18390. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  18391. Source=Paul Collins Startup list
  18392.  
  18393. [dvsfss]
  18394. Number=2612
  18395. Confirmed=X
  18396. Filename=fbsfsdrs.exe
  18397. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotqa.html" target="_blank">SDBOT-QA</a> WORM!
  18398. Source=Paul Collins Startup list
  18399.  
  18400. [DVSync]
  18401. Number=2613
  18402. Confirmed=U
  18403. Filename=dvsync.exe
  18404. Description=DVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
  18405. Source=Paul Collins Startup list
  18406.  
  18407. [Dvx]
  18408. Number=2614
  18409. Confirmed=X
  18410. Filename=wsxsvc.exe
  18411. Description=<a href="http://www.spywareguide.com/product_show.php?id=727" target=_blank>Delfin Media Viewer</a> or "Promulgate" adware variant
  18412. Source=Paul Collins Startup list
  18413.  
  18414. [dw]
  18415. Number=2615
  18416. Confirmed=X
  18417. Filename=dw.exe
  18418. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=DownloadWare&threatid=4620" target=_blank>DownloadWare</a> adware
  18419. Source=Paul Collins Startup list
  18420.  
  18421. [DW4]
  18422. Number=2616
  18423. Confirmed=N
  18424. Filename=Weather.exe
  18425. Description=<a href="http://www.weather.com/services/desktop.html?from=dt_hugheader&refer=dt_hugheader" target=_blank>Desktop Weather</a>
  18426. Source=Paul Collins Startup list
  18427.  
  18428. [DWHeartbeatMonitor]
  18429. Number=2617
  18430. Confirmed=U
  18431. Filename=DWHeartbeatMonitor.exe
  18432. Description=DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
  18433. Source=Paul Collins Startup list
  18434.  
  18435. [DwlClient]
  18436. Number=2618
  18437. Confirmed=N
  18438. Filename=support.exe
  18439. Description=Download manager for Dell support alerts
  18440. Source=Paul Collins Startup list
  18441.  
  18442. [dwStart]
  18443. Number=2619
  18444. Confirmed=Y
  18445. Filename=FireWall.exe
  18446. Description=<a href="http://www.pcsecurityshield.com/webApp/208.asp" target=_blank>The Shield</a> firewall
  18447. Source=Paul Collins Startup list
  18448.  
  18449. [Dx]
  18450. Number=2620
  18451. Confirmed=X
  18452. Filename=sys*.exe [* = random number]
  18453. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DEXTER.A" target="_blank">DEXTER.A</a> WORM!
  18454. Source=Paul Collins Startup list
  18455.  
  18456. [Dx8compat]
  18457. Number=2621
  18458. Confirmed=X
  18459. Filename=Dx8compat.exe
  18460. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  18461. Source=Paul Collins Startup list
  18462.  
  18463. [dxdiags.exe]
  18464. Number=2622
  18465. Confirmed=X
  18466. Filename=dxdiags.exe
  18467. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcertifg.html" target=_blank>CERTIF-G</a> TROJAN!
  18468. Source=Paul Collins Startup list
  18469.  
  18470. [DxDialog]
  18471. Number=2623
  18472. Confirmed=X
  18473. Filename=dxdlg32.exe
  18474. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvbcxt.html" target="_blank">VB-CXT</a> TROJAN!
  18475. Source=Paul Collins Startup list
  18476.  
  18477. [dxdll32]
  18478. Number=2624
  18479. Confirmed=X
  18480. Filename=ntxdll.exe
  18481. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030115-3820-99" target=_blank>GAOBOT.CPX</a> WORM!
  18482. Source=Paul Collins Startup list
  18483.  
  18484. [DXDllRegExe]
  18485. Number=2625
  18486. Confirmed=N
  18487. Filename=dxdllreg.exe
  18488. Description=Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it
  18489. Source=Paul Collins Startup list
  18490.  
  18491. [DxLoad]
  18492. Number=2626
  18493. Confirmed=X
  18494. Filename=DX3DRndr.exe
  18495. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-022511-4002-99" target="_blank">GIBE.B</a> WORM!
  18496. Source=Paul Collins Startup list
  18497.  
  18498. [DXM6Patch_981116]
  18499. Number=2627
  18500. Confirmed=N
  18501. Filename=p_981116.exe
  18502. Description=Win32 cabinet self extractor. More info <a href="http://groups.google.com/group/microsoft.public.win98.performance/browse_frm/thread/1bb6d199cdad3c95/24366de20a10c5d6?hl=en&rnum=18&prev=/groups%3Fq%3DP_981116.exe%26hl%3Den%26start%3D10%26sa%3DN#24366de20a10c5d6" target="_blank">here</a>
  18503. Source=Paul Collins Startup list
  18504.  
  18505. [dxmsrv]
  18506. Number=2628
  18507. Confirmed=X
  18508. Filename=dxmsrv.exe
  18509. Description=Added by an unidentified WORM or TROJAN!
  18510. Source=Paul Collins Startup list
  18511.  
  18512. [Dxsty]
  18513. Number=2629
  18514. Confirmed=X
  18515. Filename=Dxsty.exe
  18516. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  18517. Source=Paul Collins Startup list
  18518.  
  18519. [Dxupdate.exe]
  18520. Number=2630
  18521. Confirmed=X
  18522. Filename=Dxupdate.exe
  18523. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102010-4632-99" target="_blank">MAFEG</a> WORM!
  18524. Source=Paul Collins Startup list
  18525.  
  18526. [dxvid]
  18527. Number=2631
  18528. Confirmed=X
  18529. Filename=dxvid.exe
  18530. Description=Added by Trojan-Downloader.Win32.Dluca.by TROJAN!
  18531. Source=Paul Collins Startup list
  18532.  
  18533. [DyFuCA]
  18534. Number=2632
  18535. Confirmed=X
  18536. Filename=optimize.exe
  18537. Description=Adult content dialler - see <a href="http://www.sophos.com/virusinfo/analyses/dialdyfucaa.html" target="_blank">here</a>
  18538. Source=Paul Collins Startup list
  18539.  
  18540. [DyFuCA Active Alert]
  18541. Number=2633
  18542. Confirmed=X
  18543. Filename=actalert.exe
  18544. Description=Adult content dialler - see <a href="http://www.sophos.com/virusinfo/analyses/dialdyfucaa.html" target="_blank">here</a>
  18545. Source=Paul Collins Startup list
  18546.  
  18547. [Dynamic DHCP]
  18548. Number=2634
  18549. Confirmed=X
  18550. Filename=dydhcp.exe
  18551. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_RINBOT.B" target="_blank">RINBOT.B</a> TROJAN!
  18552. Source=Paul Collins Startup list
  18553.  
  18554. [Dynamic Dns Binary]
  18555. Number=2635
  18556. Confirmed=X
  18557. Filename=dynitora.exe
  18558. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotwt.html" target=_blank>RBOT-WT</a> WORM!
  18559. Source=Paul Collins Startup list
  18560.  
  18561. [Dynamic Dns Binary]
  18562. Number=2636
  18563. Confirmed=X
  18564. Filename=CMD16.EXE
  18565. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotxm.html" target= blank>RBOT-XM</a> WORM!
  18566. Source=Paul Collins Startup list
  18567.  
  18568. [Dynamic Dns Binary]
  18569. Number=2637
  18570. Confirmed=X
  18571. Filename=winxp34.exe
  18572. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target= blank>RBOT</a> WORM!
  18573. Source=Paul Collins Startup list
  18574.  
  18575. [Dynamic Dns Binary]
  18576. Number=2638
  18577. Confirmed=X
  18578. Filename=WinHelpcfn.exe
  18579. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  18580. Source=Paul Collins Startup list
  18581.  
  18582. [Dynamic Link Library loader]
  18583. Number=2639
  18584. Confirmed=X
  18585. Filename=Loader32.exe
  18586. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-031416-1509-99" target=_blank>KOL</a> TROJAN!
  18587. Source=Paul Collins Startup list
  18588.  
  18589. [DynDNS Updater]
  18590. Number=2640
  18591. Confirmed=U
  18592. Filename=DynDNS.exe
  18593. Description=Dynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.org
  18594. Source=Paul Collins Startup list
  18595.  
  18596. [DynDNS-Updater Traytool]
  18597. Number=2641
  18598. Confirmed=N
  18599. Filename=ddutray.exe
  18600. Description=<a href="http://www.dyndns.com/services/dns/dyndns/" target="_blank">DynDNS</a> updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually
  18601. Source=Paul Collins Startup list
  18602.  
  18603. [DynHttp Dns Binary]
  18604. Number=2642
  18605. Confirmed=X
  18606. Filename=dynizari.exe
  18607. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target= blank>RBOT</a> WORM!
  18608. Source=Paul Collins Startup list
  18609.  
  18610. [DynSite]
  18611. Number=2643
  18612. Confirmed=U
  18613. Filename=DynSite.exe
  18614. Description=<a href="http://noeld.com/download.htm" target=_blank>DynSite</a> - dynamic DNS client, also called an automatic IP updater
  18615. Source=Paul Collins Startup list
  18616.  
  18617. [Dynu Basic Client]
  18618. Number=2644
  18619. Confirmed=U
  18620. Filename=dynubas.exe
  18621. Description=<a href="http://www.dynu.com/" target=_blank>Dynu</a> online dynamic IP update client. Useful when using a dial up modem
  18622.  
  18623. Source=Paul Collins Startup list
  18624.  
  18625. [DZKillMe]
  18626. Number=2645
  18627. Confirmed=?
  18628. Filename=DZSAVEME.EXE
  18629. Description=<font color="#FF0000">??</font>
  18630. Source=Paul Collins Startup list
  18631.  
  18632. [D_V_T]
  18633. Number=2646
  18634. Confirmed=U
  18635. Filename=dvt.exe
  18636. Description=<a href="http://www.medical.philips.com/main/company/connectivity/dvt-tool/DVT.html" target="_blank">DICOM Validation Tool</a> - "DICOM is increasingly being used as the standard communication mechanism when integrating various medical products in a hospital environment"
  18637. Source=Paul Collins Startup list
  18638.  
  18639. [D_V_T]
  18640. Number=2647
  18641. Confirmed=?
  18642. Filename=dvt.exe
  18643. Description=Installation could be a crack/hack to NOD32 <a href="http://www.microsoft.com/communities/newsgroups/en-us/default.aspx?dg=microsoft.public.windowsupdate&tid=bc156de4-638d-4d29-b49f-a9cb9e588a83&p=1" target="_blank">here</a>. Seen and removed in many logs. Investigate it further and if this file is present C:\d_v_t.reg then it should be fixed. Not to be confused with the DICOM entry <a href="http://www.sysinfo.org/startuplist.php?filter=DICOM" target="_blank">here</a>. Both files are located in the Windows/Windir directory
  18644. Source=Paul Collins Startup list
  18645.  
  18646. [E-Card]
  18647. Number=2648
  18648. Confirmed=X
  18649. Filename=ecard.exe
  18650. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082217-3310-99" target="_blank">YODI</a> WORM!
  18651. Source=Paul Collins Startup list
  18652.  
  18653. [E-color]
  18654. Number=2649
  18655. Confirmed=U
  18656. Filename=IconMgr.Exe
  18657. Description=Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
  18658. Source=Paul Collins Startup list
  18659.  
  18660. [E-nrgyPlus]
  18661. Number=2650
  18662. Confirmed=X
  18663. Filename=E-nrgyPlus.exe
  18664. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-030816-3717-99" target=_blank>Energyplus</a> TRACKWARE! Tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site
  18665. Source=Paul Collins Startup list
  18666.  
  18667. [e-Surveiller Station]
  18668. Number=2651
  18669. Confirmed=X
  18670. Filename=estation.exe
  18671. Description=Added by <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-022415-5224-99" target=_blank>ESurveiller</a> spyware. Note - ESurveiller is spyware that monitors and records keystrokes and mouse clicks, instant message conversations, Internet activity and applications used, must be manually installed
  18672. Source=Paul Collins Startup list
  18673.  
  18674. [E06DXLRD_7604703]
  18675. Number=2652
  18676. Confirmed=U
  18677. Filename=EDICT.EXE
  18678. Description=Related to <a href="http://encarta.msn.com/" target=_blank>Microsoft Encarta</a> dictionary functions
  18679. Source=Paul Collins Startup list
  18680.  
  18681. [E6TaskPanel]
  18682. Number=2653
  18683. Confirmed=N
  18684. Filename=TaskPanl.exe
  18685. Description=Earthlink Task Panel - part of <a href="http://www.earthlink.net/home/software/" target="_blank">Earthlink TotalAccess 2003</a> internet access software. Quick access to internet, E-mail and web-space
  18686. Source=Paul Collins Startup list
  18687.  
  18688. [eabconfg.cpl]
  18689. Number=2654
  18690. Confirmed=U
  18691. Filename=EabServr.exe
  18692. Description=Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
  18693. Source=Paul Collins Startup list
  18694.  
  18695. [Eac Download]
  18696. Number=2655
  18697. Confirmed=X
  18698. Filename=download.exe
  18699. Description=Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  18700. Source=Paul Collins Startup list
  18701.  
  18702. [EACLEAN]
  18703. Number=2656
  18704. Confirmed=U
  18705. Filename=eaclean.exe
  18706. Description=For Compaq PC's. <a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank"> Easy Access</a> button support for the keyboard
  18707. Source=Paul Collins Startup list
  18708.  
  18709. [Eac_Cnry]
  18710. Number=2657
  18711. Confirmed=X
  18712. Filename=canary.exe
  18713. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcanary.html" target="_blank"> CANARY</a> TROJAN!
  18714. Source=Paul Collins Startup list
  18715.  
  18716. [Eac_rnvdl]
  18717. Number=2658
  18718. Confirmed=?
  18719. Filename=ANTIVIRUS_INSTALL.EXE
  18720. Description=<font color="#FF0000">??</font>
  18721. Source=Paul Collins Startup list
  18722.  
  18723. [EanthologyApp]
  18724. Number=2659
  18725. Confirmed=U
  18726. Filename=EANTHO~1.EXE
  18727. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  18728. Source=Paul Collins Startup list
  18729.  
  18730. [EanthologyApp]
  18731. Number=2660
  18732. Confirmed=U
  18733. Filename=eanthology.exe
  18734. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  18735. Source=Paul Collins Startup list
  18736.  
  18737. [eanthology_install.exe]
  18738. Number=2661
  18739. Confirmed=U
  18740. Filename=eanthology_install.exe
  18741. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  18742. Source=Paul Collins Startup list
  18743.  
  18744. [eanth_critical_update_alert]
  18745. Number=2662
  18746. Confirmed=U
  18747. Filename=sys_alert.exe
  18748. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  18749. Source=Paul Collins Startup list
  18750.  
  18751. [eanth_system_patcher]
  18752. Number=2663
  18753. Confirmed=U
  18754. Filename=sys_alert.exe
  18755. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  18756. Source=Paul Collins Startup list
  18757.  
  18758. [Eapcisetup]
  18759. Number=2664
  18760. Confirmed=N
  18761. Filename=sbsetup.exe
  18762. Description=Rockwell RipTide soundcard application software. Sound works without it
  18763. Source=Paul Collins Startup list
  18764.  
  18765. [EAPCISETUP]
  18766. Number=2665
  18767. Confirmed=N
  18768. Filename=wizard.exe
  18769. Description=Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
  18770. Source=Paul Collins Startup list
  18771.  
  18772. [Earthlink Protection Control Center]
  18773. Number=2666
  18774. Confirmed=Y
  18775. Filename=elnk_pcc.exe
  18776. Description=EarthLink <a href="http://www.earthlink.net/software/pcc/" target="_blank">Protection Control Center</a> - "powerful, integrated security program makes it easier than ever to protect yourself against viruses, spyware, and hackers-all from one convenient location"
  18777. Source=Paul Collins Startup list
  18778.  
  18779. [EarthLink ToolBar 5.0]
  18780. Number=2667
  18781. Confirmed=N
  18782. Filename=etoolbar.exe
  18783. Description=EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time
  18784. Source=Paul Collins Startup list
  18785.  
  18786. [Easy Key]
  18787. Number=2668
  18788. Confirmed=U
  18789. Filename=easykey.exe
  18790. Description=For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
  18791. Source=Paul Collins Startup list
  18792.  
  18793. [Easy Start Button]
  18794. Number=2669
  18795. Confirmed=N
  18796. Filename=esb.exe
  18797. Description=Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
  18798. Source=Paul Collins Startup list
  18799.  
  18800. [Easy-PrintToolBox]
  18801. Number=2670
  18802. Confirmed=U
  18803. Filename=BJPSMAIN.EXE
  18804. Description=A utility to launch the applications that are bundled with a Canon bubblejet printer
  18805. Source=Paul Collins Startup list
  18806.  
  18807. [EasyAV]
  18808. Number=2671
  18809. Confirmed=X
  18810. Filename=EasyAV.exe
  18811. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040512-2436-99" target="_blank">NETSKY.S</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040616-1824-99" target="_blank">NETSKY.T</a> WORMS!
  18812. Source=Paul Collins Startup list
  18813.  
  18814. [EasyDates]
  18815. Number=2672
  18816. Confirmed=X
  18817. Filename=EasyDates.exe
  18818. Description=Premium rate adult content dialler
  18819.  
  18820. Source=Paul Collins Startup list
  18821.  
  18822. [EasyDates_nl]
  18823. Number=2673
  18824. Confirmed=X
  18825. Filename=EasyDates_nl.exe
  18826. Description=Adult content dialler
  18827. Source=Paul Collins Startup list
  18828.  
  18829. [EasyKey]
  18830. Number=2674
  18831. Confirmed=U
  18832. Filename=easykey.exe
  18833. Description=For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
  18834. Source=Paul Collins Startup list
  18835.  
  18836. [EasyKeyboardLogger]
  18837. Number=2675
  18838. Confirmed=U
  18839. Filename=EasyKeyboardLogger.exe
  18840. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042216-1324-99" target=_blank>EasyKeyLogger</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  18841.  
  18842. Source=Paul Collins Startup list
  18843.  
  18844. [EasyMessage]
  18845. Number=2676
  18846. Confirmed=U
  18847. Filename=em2.exe
  18848. Description=Easy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See <a href="http://www.easymessage.net/" target="_blank">here</a>
  18849. Source=Paul Collins Startup list
  18850.  
  18851. [EasySearchBar]
  18852. Number=2677
  18853. Confirmed=X
  18854. Filename=ESBUpdate.exe
  18855. Description=EasySearchBar adware downloader
  18856. Source=Paul Collins Startup list
  18857.  
  18858. [easyServ]
  18859. Number=2678
  18860. Confirmed=X
  18861. Filename=Server.exe
  18862. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-080619-3837-99" target="_blank">EASYSERV</a> TROJAN!
  18863. Source=Paul Collins Startup list
  18864.  
  18865. [EasySync Pro]
  18866. Number=2679
  18867. Confirmed=U
  18868. Filename=XCPCMenu.exe
  18869. Description=<a href="http://www-142.ibm.com/software/sw-lotus/products/product4.nsf/wdocs/easysyncprohome" target="_blank">EasySync Pro</a> is a Lotus (now owned by IBM) program for synchronizing a PDA with Lotus Notes
  18870. Source=Paul Collins Startup list
  18871.  
  18872. [EasyTuneIII]
  18873. Number=2680
  18874. Confirmed=U
  18875. Filename=EasyTune.exe
  18876. Description=Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
  18877. Source=Paul Collins Startup list
  18878.  
  18879. [EasyTuneIV]
  18880. Number=2681
  18881. Confirmed=U
  18882. Filename=ET4Tray.exe
  18883. Description=Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
  18884. Source=Paul Collins Startup list
  18885.  
  18886. [easywww]
  18887. Number=2682
  18888. Confirmed=X
  18889. Filename=easywww2.exe
  18890. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  18891. Source=Paul Collins Startup list
  18892.  
  18893. [EbatesMoeMoneyMaker]
  18894. Number=2683
  18895. Confirmed=N
  18896. Filename=wjview ...Code
  18897. Description=<a href="http://www.kephyr.com/spywarescanner/library/ebatesmoemoneymaker/index.phtml" target="_blank">Ebates</a> adware
  18898. Source=Paul Collins Startup list
  18899.  
  18900. [EbatesMoeMoneyMaker0]
  18901. Number=2684
  18902. Confirmed=X
  18903. Filename=EbatesMoeMoneyMaker0.exe
  18904. Description=<a href="http://www.kephyr.com/spywarescanner/library/ebatesmoemoneymaker/index.phtml" target="_blank">Ebates</a> adware
  18905. Source=Paul Collins Startup list
  18906.  
  18907. [eBay Toolbar]
  18908. Number=2685
  18909. Confirmed=X
  18910. Filename=EBAYTBAR.EXE
  18911. Description=<a href="http://pages.ebay.com/ebay_toolbar/" target="_blank">eBay Toolbar</a> - reportes as spyware as it "phones home"
  18912. Source=Paul Collins Startup list
  18913.  
  18914. [eBayToolbar]
  18915. Number=2686
  18916. Confirmed=U
  18917. Filename=eBayTBDaemon.exe
  18918. Description=<a href="http://pages.ebay.com/ebay_toolbar/" target=_blank>eBay</a> toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites
  18919. Source=Paul Collins Startup list
  18920.  
  18921. [eBoard]
  18922. Number=2687
  18923. Confirmed=U
  18924. Filename=Eboard.exe
  18925. Description=eMachines multimedia keyboard manager. Required if you use the extra keys
  18926. Source=Paul Collins Startup list
  18927.  
  18928. [eBot]
  18929. Number=2688
  18930. Confirmed=N
  18931. Filename=DownloadWizard.exe
  18932. Description=eBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs
  18933. Source=Paul Collins Startup list
  18934.  
  18935. [EC21]
  18936. Number=2689
  18937. Confirmed=U
  18938. Filename=EZQ.EXE
  18939. Description=Related to EC21. "<a href="http://www.ec21.com/" target="_blank">EC21</a> is the worldÆs largest B2B marketplace to facilitate online trades between exporters and importers from all around the world"
  18940. Source=Paul Collins Startup list
  18941.  
  18942. [ecko]
  18943. Number=2690
  18944. Confirmed=X
  18945. Filename=claro.exe
  18946. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadraqj.html" target="_blank">DLOADR-AQJ</a> TROJAN!
  18947. Source=Paul Collins Startup list
  18948.  
  18949. [ecpe]
  18950. Number=2691
  18951. Confirmed=?
  18952. Filename=ECPE.EXE
  18953. Description=<font color="#FF0000">??</font>
  18954. Source=Paul Collins Startup list
  18955.  
  18956. [eDataSecurity Loader]
  18957. Number=2692
  18958. Confirmed=U
  18959. Filename=eDSloader.exe
  18960. Description=Part of Acer Empowering Technology. "<a href="http://www.acer-euro.com/et/en/notebooks01.htm#1" target="_blank">Acer eDataSecurity Management</a> is a handy file encryption utility that protects files from being accessed by unauthorized persons, using passwords and advanced encryption algorithms"
  18961. Source=Paul Collins Startup list
  18962.  
  18963. [edexter]
  18964. Number=2693
  18965. Confirmed=N
  18966. Filename=edexter.exe
  18967. Description=<a href="http://www.pyrenean.com/edexter.php" target=_blank>eDexter</a> supplements internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser
  18968. Source=Paul Collins Startup list
  18969.  
  18970. [editpad]
  18971. Number=2694
  18972. Confirmed=X
  18973. Filename=editpad.exe
  18974. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojconsperb.html" target="_blank">CONSPER-B</a> TROJAN!
  18975. Source=Paul Collins Startup list
  18976.  
  18977. [EDLoader]
  18978. Number=2695
  18979. Confirmed=N
  18980. Filename=DTLoader.exe
  18981. Description=Effective Desktop from MiniStars Software - desktop management software no longer being supported
  18982. Source=Paul Collins Startup list
  18983.  
  18984. [eDonkey2000]
  18985. Number=2696
  18986. Confirmed=U
  18987. Filename=edonkey2000.exe
  18988. Description=File sharing network - not recommended as the free version of this application should be avoided as it installs, without permission, New.Net, Webhancer, WebSearch Toolbar and WinTools
  18989. Source=Paul Collins Startup list
  18990.  
  18991. [EDRestore]
  18992. Number=2697
  18993. Confirmed=U
  18994. Filename=??
  18995. Description=<a href="http://www.easydesksoftware.com/spoint.htm" target="_blank">Set Point</a> from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP"
  18996. Source=Paul Collins Startup list
  18997.  
  18998. [educational writer]
  18999. Number=2698
  19000. Confirmed=X
  19001. Filename=[random filename]
  19002. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlz.html" target="_blank">RBOT-LZ</a> WORM!
  19003. Source=Paul Collins Startup list
  19004.  
  19005. [Edwizard]
  19006. Number=2699
  19007. Confirmed=U
  19008. Filename=Edwizard.exe
  19009. Description=<a href="http://www.ediport.hu/_sgeasy.html" target="_blank">SafeGuard Easy</a> - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
  19010. Source=Paul Collins Startup list
  19011.  
  19012. [EDxMC110]
  19013. Number=2700
  19014. Confirmed=X
  19015. Filename=Isass.exe
  19016. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32vbnia.html" target="_blank">VB-NIA</a> WORM!
  19017. Source=Paul Collins Startup list
  19018.  
  19019. [EEventManager]
  19020. Number=2701
  19021. Confirmed=N
  19022. Filename=EEventManager.exe
  19023. Description=Part of the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/eeventmanager/" target="_blank">Epson Creativity Suite</a> supplied with their multi-function printer/scanners, Event Manager launches File Manager or PageManager for EPSON automatically when you press the B&W Start or Color Start button on the control panel in Scan mode
  19024. Source=Paul Collins Startup list
  19025.  
  19026. [eFax DllCmd]
  19027. Number=2702
  19028. Confirmed=U
  19029. Filename=J2GDllCmd.exe
  19030. Description=<a href="http://www.efax.com/en/efax/twa/page/download?rqcp=1" target="_blank">eFax Messenger</a> fax software
  19031. Source=Paul Collins Startup list
  19032.  
  19033. [eFax Tray Menu]
  19034. Number=2703
  19035. Confirmed=N
  19036. Filename=HotTray.exe
  19037. Description=eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available <a href="http://home.efax.com/I18N/FAQ/faq_uk.html" target="_blank">here</a>
  19038. Source=Paul Collins Startup list
  19039.  
  19040. [eFax Tray Menu]
  19041. Number=2704
  19042. Confirmed=U
  19043. Filename=J2GTray.exe
  19044. Description=<a href="http://www.efax.com/en/efax/twa/page/download?rqcp=1" target="_blank">eFax Messenger</a> fax software tray menu
  19045. Source=Paul Collins Startup list
  19046.  
  19047. [eFax.com Tray Menu]
  19048. Number=2705
  19049. Confirmed=N
  19050. Filename=HotTray.exe
  19051. Description=eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available <a href="http://home.efax.com/I18N/FAQ/faq_uk.html" target="_blank">here</a>
  19052. Source=Paul Collins Startup list
  19053.  
  19054. [efaxs lptt01]
  19055. Number=2706
  19056. Confirmed=X
  19057. Filename=efaxs.exe
  19058. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "efaxs" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  19059. Source=Paul Collins Startup list
  19060.  
  19061. [efaxs ml097e]
  19062. Number=2707
  19063. Confirmed=X
  19064. Filename=efaxs.exe
  19065. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "efaxs" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  19066. Source=Paul Collins Startup list
  19067.  
  19068. [EFI Job Monitor]
  19069. Number=2708
  19070. Confirmed=U
  19071. Filename=[path] efjm.dll,run
  19072. Description=Ricoh Imagio Printer/Scanner driver status monitor
  19073. Source=Paul Collins Startup list
  19074.  
  19075. [Efpap.exe]
  19076. Number=2709
  19077. Confirmed=U
  19078. Filename=Efpap.exe
  19079. Description=<a href="http://www.softstack.com/fileprotpro.html" target="_blank">Easy File & Folder Protector</a>. Deny access to certain files and folders, or to hide them securely from viewing and searching
  19080. Source=Paul Collins Startup list
  19081.  
  19082. [ehTray]
  19083. Number=2710
  19084. Confirmed=U
  19085. Filename=ehtray.exe
  19086. Description=Enables the user to access Windows Messenger from within <a href="http://msdn.microsoft.com/library/en-us/MedctrSDK/htm/formoreinformation.asp" target="_blank">Windows Media Center Edition</a>
  19087. Source=Paul Collins Startup list
  19088.  
  19089. [ei10.exe]
  19090. Number=2711
  19091. Confirmed=X
  19092. Filename=ei10.exe
  19093. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotnk.html" target=_blank>AGOBOT-NK</a> WORM!
  19094. Source=Paul Collins Startup list
  19095.  
  19096. [Eicon NetworksLAN_DAEMON]
  19097. Number=2712
  19098. Confirmed=U
  19099. Filename=watch.exe
  19100. Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
  19101. Source=Paul Collins Startup list
  19102.  
  19103. [Eicon TechnologyLAN_DAEMON]
  19104. Number=2713
  19105. Confirmed=U
  19106. Filename=watch.exe
  19107. Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
  19108. Source=Paul Collins Startup list
  19109.  
  19110. [eixfi]
  19111. Number=2714
  19112. Confirmed=X
  19113. Filename=china.bat
  19114. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BAT_WCUP.A" target="_blank">WCUP.A</a> WORM!
  19115. Source=Paul Collins Startup list
  19116.  
  19117. [Elbycheck]
  19118. Number=2715
  19119. Confirmed=U
  19120. Filename=ElbyCheck.exe
  19121. Description=From <a href="http://www.elby.org/" target="_blank">Elaborate Bytes</a> who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
  19122. Source=Paul Collins Startup list
  19123.  
  19124. [Electron Microscope]
  19125. Number=2716
  19126. Confirmed=U
  19127. Filename=EMIII.exe
  19128. Description=Electron Microscope or <a href="http://www.em-dc.com/" target=_blank>EM</a> - is a program used to track Stanford's distributed computing program client called Folding at Home, <a href="http://folding.stanford.edu/" target=_blank>FAH</a>. It will monitor up to 50 clients and give you the details about each client's progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues
  19129.  
  19130. Source=Paul Collins Startup list
  19131.  
  19132. [Element]
  19133. Number=2717
  19134. Confirmed=X
  19135. Filename=Element.txt
  19136. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-112112-1947-99" target="_blank">ELEM</a> TROJAN!
  19137. Source=Paul Collins Startup list
  19138.  
  19139. [element furth]
  19140. Number=2718
  19141. Confirmed=X
  19142. Filename=[path] repcale.exe [path] palsp.exe
  19143. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDON.AN" target="_blank">RANDON.AN</a> WORM!
  19144. Source=Paul Collins Startup list
  19145.  
  19146. [elitemedia]
  19147. Number=2719
  19148. Confirmed=X
  19149. Filename=elitemediapop.exe
  19150. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlowzonebb.html" target=_blank>LOWZONE-BB</a> TROJAN! Also known as Elitebar/EliteToolbar/EliteSidebar adware
  19151.  
  19152. Source=Paul Collins Startup list
  19153.  
  19154. [elm]
  19155. Number=2720
  19156. Confirmed=N
  19157. Filename=Elmenv.exe
  19158. Description=ViaTech eLicense for securing, distributing and selling music online
  19159. Source=Paul Collins Startup list
  19160.  
  19161. [ELNKProxy]
  19162. Number=2721
  19163. Confirmed=X
  19164. Filename=smproxy.exe
  19165. Description=<a href="http://www.spyany.com/program/article_spw_rm_Surfmonkey.html" target=_blank>Surfmonkey</a> adware
  19166. Source=Paul Collins Startup list
  19167.  
  19168. [ELSA WINman Suite]
  19169. Number=2722
  19170. Confirmed=U
  19171. Filename=Winmsuit.exe
  19172. Description=Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU
  19173. Source=Paul Collins Startup list
  19174.  
  19175. [ElsaCapiCtl]
  19176. Number=2723
  19177. Confirmed=Y
  19178. Filename=Rcapi.exe
  19179. Description=Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem
  19180. Source=Paul Collins Startup list
  19181.  
  19182. [ELSAChipGuard]
  19183. Number=2724
  19184. Confirmed=U
  19185. Filename=elsavect.exe
  19186. Description=ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking
  19187. Source=Paul Collins Startup list
  19188.  
  19189. [ELSBLaunch]
  19190. Number=2725
  19191. Confirmed=U
  19192. Filename=ELSBLaunch.exe
  19193. Description=EarthLink <a href="http://www.earthlink.net/software/free/spamblocker/" target="_blank">SpamBlocker</a>
  19194. Source=Paul Collins Startup list
  19195.  
  19196. [EMA.exe]
  19197. Number=2726
  19198. Confirmed=N
  19199. Filename=EMA.EXE
  19200. Description=Time management system which helps you to manage your time and appointments
  19201. Source=Paul Collins Startup list
  19202.  
  19203. [eMachines eBoard]
  19204. Number=2727
  19205. Confirmed=U
  19206. Filename=Eboard.exe
  19207. Description=eMachines multimedia keyboard manager. Required if you use the extra keys
  19208. Source=Paul Collins Startup list
  19209.  
  19210. [Email Protection]
  19211. Number=2728
  19212. Confirmed=Y
  19213. Filename=emlproxy.exe
  19214. Description=<a href="http://www.quickheal.co.in/" target="_blank">AntiVirus Quick Heal</a> - E-mail protection
  19215. Source=Paul Collins Startup list
  19216.  
  19217. [EmailScan]
  19218. Number=2729
  19219. Confirmed=Y
  19220. Filename=mcvsescn.exe
  19221. Description=Related to McAfee AntiVirus suite - used to automatically scan incoming e-mails
  19222.  
  19223. Source=Paul Collins Startup list
  19224.  
  19225. [eMakeSV]
  19226. Number=2730
  19227. Confirmed=X
  19228. Filename=EMAKESV.EXE
  19229. Description=<a href="http://www.spywareguide.com/product_show.php?id=1949" target=_blank>Switch</a> premium rate adult content dialler variant
  19230. Source=Paul Collins Startup list
  19231.  
  19232. [eMakeSV]
  19233. Number=2731
  19234. Confirmed=X
  19235. Filename=EMAKE2B.EXE
  19236. Description=<a href="http://www.spywareguide.com/product_show.php?id=1949" target=_blank>Switch</a> premium rate adult content dialer variant
  19237. Source=Paul Collins Startup list
  19238.  
  19239. [EMBASSY Trust Suite Secure Update]
  19240. Number=2732
  19241. Confirmed=U
  19242. Filename=AutoUpdate.exe
  19243. Description=Updates for Wave Systems Corp. <a href="http://www.wavesys.com/products/ets.html" target="_blank">Embassy Trust Suite</a> - "delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"
  19244. Source=Paul Collins Startup list
  19245.  
  19246. [eMCryT Sh3ars Panagers]
  19247. Number=2733
  19248. Confirmed=X
  19249. Filename=[path to worm]
  19250. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotawi.html" target=_blank>RBOT-AWI</a> WORM!
  19251. Source=Paul Collins Startup list
  19252.  
  19253. [EMMeter]
  19254. Number=2734
  19255. Confirmed=U
  19256. Filename=EMMeter.exe
  19257. Description="<a href="http://www.expressmetrix.com/products/em.asp" target="_blank">Express Meter</a> provides detailed information about how your software assets are being used. With Express Meter you can monitor application usage, identify software usage patterns, and control application launchesùall of which can help you make better decisions about your IT investments"
  19258. Source=Paul Collins Startup list
  19259.  
  19260. [emoc0re]
  19261. Number=2735
  19262. Confirmed=X
  19263. Filename=emo.exe
  19264. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotage.html" target= blank>AGOBOT-AGE</a> WORM!
  19265. Source=Paul Collins Startup list
  19266.  
  19267. [empin]
  19268. Number=2736
  19269. Confirmed=X
  19270. Filename=e121307.exe
  19271. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076775" target="_blank">Delfin Media Viewer</a> adware related
  19272. Source=Paul Collins Startup list
  19273.  
  19274. [empin]
  19275. Number=2737
  19276. Confirmed=X
  19277. Filename=e121307.Stub.exe
  19278. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076775" target="_blank">Delfin Media Viewer</a> adware related
  19279. Source=Paul Collins Startup list
  19280.  
  19281. [emsw.exe]
  19282. Number=2738
  19283. Confirmed=X
  19284. Filename=emsw.exe
  19285. Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079" target="_blank">here</a>
  19286. Source=Paul Collins Startup list
  19287.  
  19288. [emule]
  19289. Number=2739
  19290. Confirmed=X
  19291. Filename=emule.exe
  19292. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotalz.html" target=_blank>RBOT-ALZ</a> WORM!
  19293. Source=Paul Collins Startup list
  19294.  
  19295. [eMusicClient Systray]
  19296. Number=2740
  19297. Confirmed=N
  19298. Filename=eMusicClient.exe
  19299. Description=<a href="http://www.emusic.com/about/index.html" target=_blank>eMusic</a> MP3 download software
  19300. Source=Paul Collins Startup list
  19301.  
  19302. [EM_EXEC]
  19303. Number=2741
  19304. Confirmed=U
  19305. Filename=EM_EXEC.EXE
  19306. Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
  19307. Source=Paul Collins Startup list
  19308.  
  19309. [EN4060C Taskbar]
  19310. Number=2742
  19311. Confirmed=N
  19312. Filename=en4060ct.exe
  19313. Description=Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
  19314. Source=Paul Collins Startup list
  19315.  
  19316. [enBrowser]
  19317. Number=2743
  19318. Confirmed=X
  19319. Filename=[name of file]
  19320. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-062915-3210-99" target=_blank>WINBO</a> adware
  19321. Source=Paul Collins Startup list
  19322.  
  19323. [encapsulated command tool]
  19324. Number=2744
  19325. Confirmed=?
  19326. Filename=wintr.com
  19327. Description=<font color="#FF0000">??</font>
  19328. Source=Paul Collins Startup list
  19329.  
  19330. [Encarta Dictionary Quickshelf]
  19331. Number=2745
  19332. Confirmed=N
  19333. Filename=QSHLFED.EXE
  19334. Description=<font color="#FF0000">Provides quick access to Encarta's Dictionary features?</font>
  19335. Source=Paul Collins Startup list
  19336.  
  19337. [ENCMONITOR]
  19338. Number=2746
  19339. Confirmed=N
  19340. Filename=monitor.exe
  19341. Description=The Encompass Monitor. This program is the Connect Direct Program.  It is more trouble than it is worth and few use it
  19342. Source=Paul Collins Startup list
  19343.  
  19344. [Encoder Agent]
  19345. Number=2747
  19346. Confirmed=N
  19347. Filename=WMENCAGT.EXE
  19348. Description=MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
  19349. Source=Paul Collins Startup list
  19350.  
  19351. [Encompass_ENCMONTR]
  19352. Number=2748
  19353. Confirmed=U
  19354. Filename=ENCMONTR.EXE
  19355. Description=Optional simple browser from Yahoo (Encompass)
  19356. Source=Paul Collins Startup list
  19357.  
  19358. [ENCSurf]
  19359. Number=2749
  19360. Confirmed=?
  19361. Filename=surfboard.exe
  19362. Description=<font color="#FF0000">??</font>
  19363. Source=Paul Collins Startup list
  19364.  
  19365. [Energizer FileSaver]
  19366. Number=2750
  19367. Confirmed=N
  19368. Filename=Energizer FileSaver.exe
  19369. Description=<a href="http://www.energizerups.com/productline.asp" target="_blank">Energizer FileSaver</a> - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended
  19370. Source=Paul Collins Startup list
  19371.  
  19372. [EnergyPlugIn]
  19373. Number=2751
  19374. Confirmed=X
  19375. Filename=EnergyPlugin.exe
  19376. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-061315-1440-99" target=_blank>EnergyPlugin</a> adware variant
  19377. Source=Paul Collins Startup list
  19378.  
  19379. [enginecs2]
  19380. Number=2752
  19381. Confirmed=U
  19382. Filename=enginecs2.exe
  19383. Description=<a href="http://www.securitysoft.com/myspace_filtering.asp?pageid=82" target="_blank">Cyber Sentinel</a> - internet filtering software
  19384. Source=Paul Collins Startup list
  19385.  
  19386. [EngUtil]
  19387. Number=2753
  19388. Confirmed=Y
  19389. Filename=EngUtil.exe
  19390. Description=Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
  19391. Source=Paul Collins Startup list
  19392.  
  19393. [Enh Win Updt]
  19394. Number=2754
  19395. Confirmed=X
  19396. Filename=enhupdt.exe
  19397. Description=Adware downloader - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h
  19398. Source=Paul Collins Startup list
  19399.  
  19400. [enhance32]
  19401. Number=2755
  19402. Confirmed=X
  19403. Filename=enhance32.exe
  19404. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
  19405. Source=Paul Collins Startup list
  19406.  
  19407. [EnigmaPopupStop]
  19408. Number=2756
  19409. Confirmed=N
  19410. Filename=EnigmaPopupStop.exe
  19411. Description=Part of Enigma SpyHunter - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#sh_note" target="_blank">note</a>
  19412. Source=Paul Collins Startup list
  19413.  
  19414. [ENSApServer2_0]
  19415. Number=2757
  19416. Confirmed=?
  19417. Filename=APSERVER.EXE
  19418. Description=<a target="_blank" href="http://www.intel.com/support/network/anypoint/">Intel AnyPoint</a> Wireless II Home Network related. Now discontinued. <font color="#FF0000">What does it do and is it required?</font>
  19419. Source=Paul Collins Startup list
  19420.  
  19421. [ENSMIX32.EXE]
  19422. Number=2758
  19423. Confirmed=?
  19424. Filename=ENSMIX32.EXE
  19425. Description=Sound card driver. <font color="#FF0000"> Is it required?</font>
  19426. Source=Paul Collins Startup list
  19427.  
  19428. [EnsoniqMixer]
  19429. Number=2759
  19430. Confirmed=U
  19431. Filename=starter.exe
  19432. Description=Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on <a href="http://www.pacs-portal.co.uk/startup_pages/starter_exe.htm" target=_blank>this</a> special page. Similar to Creative PCI Audio Configuration Utility
  19433. Source=Paul Collins Startup list
  19434.  
  19435. [Entbloess 2]
  19436. Number=2760
  19437. Confirmed=U
  19438. Filename=Entbloess2.exe
  19439. Description=Related to Window-Switcher (now <a href="http://www.reflexvision.net/" target=_blank>Reflex Vision</a>) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's ExposΘ, for Windows 2K/XP
  19440. Source=Paul Collins Startup list
  19441.  
  19442. [Enterra Icon Keeper]
  19443. Number=2761
  19444. Confirmed=U
  19445. Filename=IcnKeepr.exe
  19446. Description=<a href="http://www.enterra-soft.com/" target=_blank>Icon Keeper</a> - "tool to save and restore icon positions on the desktop"
  19447.  
  19448. Source=Paul Collins Startup list
  19449.  
  19450. [Enumerate Service]
  19451. Number=2762
  19452. Confirmed=X
  19453. Filename=wsys.exe
  19454. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-112614-4025-99" target="_blank">MANIFEST</a> TROJAN!
  19455. Source=Paul Collins Startup list
  19456.  
  19457. [EnvyHFCPL]
  19458. Number=2763
  19459. Confirmed=Y
  19460. Filename=EnMixCPL.exe
  19461. Description=VIA <a href="http://www.via.com.tw/en/products/audio/controllers/envy24/" target= blank>Envy24</a> PCI Audio Controller driver
  19462. Source=Paul Collins Startup list
  19463.  
  19464. [eonemng]
  19465. Number=2764
  19466. Confirmed=U
  19467. Filename=eOneMng.exe
  19468. Description=eOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC
  19469. Source=Paul Collins Startup list
  19470.  
  19471. [EOUApp]
  19472. Number=2765
  19473. Confirmed=U
  19474. Filename=EOUWiz.exe
  19475. Description=Intel ProSET Wireless related - provides additional configuration options for these devices
  19476. Source=Paul Collins Startup list
  19477.  
  19478. [EOUWiz]
  19479. Number=2766
  19480. Confirmed=U
  19481. Filename=EOUWiz.exe
  19482. Description=Intel ProSET Wireless related - provides additional configuration options for these devices
  19483. Source=Paul Collins Startup list
  19484.  
  19485. [ePower_DMC]
  19486. Number=2767
  19487. Confirmed=U
  19488. Filename=ePower_DMC.exe
  19489. Description=Part of Acer Empowering Technology. "<a href="http://www.acer-euro.com/et/en/notebooks01.htm#7" target="_blank">Acer ePower Management</a> is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"
  19490. Source=Paul Collins Startup list
  19491.  
  19492. [EPoXUSDM]
  19493. Number=2768
  19494. Confirmed=U
  19495. Filename=USDM.EXE
  19496. Description=<a href="http://www.epox.com.tw/eng/index.php" target=_blank>EPoX</a> Universal Serial Data Monitor - a diagnostics tool that shows Temps, Fan Speeds, Voltages...etc
  19497. Source=Paul Collins Startup list
  19498.  
  19499. [ePrint 3.0 Service]
  19500. Number=2769
  19501. Confirmed=N
  19502. Filename=EPRINT3.EXE
  19503. Description=LEADTOOLS <a href="http://www.eprintdriver.com/" target=_blank>ePrint</a> file conversion software - "convert any file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT, Multi-page TIFF, JPG, GIF, PNG and many more!" Can be started manually
  19504.  
  19505. Source=Paul Collins Startup list
  19506.  
  19507. [ePrint 4.0 Service]
  19508. Number=2770
  19509. Confirmed=N
  19510. Filename=EPRINT4.EXE
  19511. Description=A component of the "LEADTOOLS <a href="http://www.eprintdriver.com/" target=_blank>ePrint</a> File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT , Multi-page TIFF, JPG, GIF, PNG and many more!" Can be started manually
  19512. Source=Paul Collins Startup list
  19513.  
  19514. [ePrompter]
  19515. Number=2771
  19516. Confirmed=U
  19517. Filename=ePrompter.exe
  19518. Description=<a href="http://www.eprompter.com/" target="_blank">ePrompter</a> - E-mail notification software
  19519. Source=Paul Collins Startup list
  19520.  
  19521. [EPS]
  19522. Number=2772
  19523. Confirmed=N
  19524. Filename=e_srcv02.exe
  19525. Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
  19526. Source=Paul Collins Startup list
  19527.  
  19528. [EPS]
  19529. Number=2773
  19530. Confirmed=N
  19531. Filename=e_srcv03.exe
  19532. Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
  19533. Source=Paul Collins Startup list
  19534.  
  19535. [EPSON Background Monitor]
  19536. Number=2774
  19537. Confirmed=N
  19538. Filename=STMS.EXE
  19539. Description=Supposed to keep an Epson printer ready for quick printing.  Users report little difference whether it is on or not
  19540. Source=Paul Collins Startup list
  19541.  
  19542. [EPSON CardMonitor]
  19543. Number=2775
  19544. Confirmed=U
  19545. Filename=EPSON CardMonitor1.0.exe
  19546. Description=Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
  19547. Source=Paul Collins Startup list
  19548.  
  19549. [EPSON Status Monitor 3 Environment Check]
  19550. Number=2776
  19551. Confirmed=N
  19552. Filename=e_srcv03.exe
  19553. Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
  19554. Source=Paul Collins Startup list
  19555.  
  19556. [EPSON Status Monitor 3 Environment Check]
  19557. Number=2777
  19558. Confirmed=N
  19559. Filename=e_srcv02.exe
  19560. Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
  19561. Source=Paul Collins Startup list
  19562.  
  19563. [EPSON Status Monitor 3 Environment Check 2]
  19564. Number=2778
  19565. Confirmed=N
  19566. Filename=e_srcv03.exe
  19567. Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
  19568. Source=Paul Collins Startup list
  19569.  
  19570. [EPSON Status Monitor 3 Environment Check 2]
  19571. Number=2779
  19572. Confirmed=N
  19573. Filename=e_srcv02.exe
  19574. Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
  19575. Source=Paul Collins Startup list
  19576.  
  19577. [EPSON Stylus C44 Series]
  19578. Number=2780
  19579. Confirmed=U
  19580. Filename=E_S10IC2.EXE
  19581. Description=Epson Stylus C44 Series printer monitor - for checking ink levels, etc
  19582. Source=Paul Collins Startup list
  19583.  
  19584. [EPSON Stylus C46 Series]
  19585. Number=2781
  19586. Confirmed=U
  19587. Filename=E_S4I0T1.EXE
  19588. Description=Epson Stylus C46 Series printer monitor - for checking ink levels, etc
  19589. Source=Paul Collins Startup list
  19590.  
  19591. [Epson Stylus C62 Series]
  19592. Number=2782
  19593. Confirmed=U
  19594. Filename=E-S0BIC1.EXE
  19595. Description=Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
  19596. Source=Paul Collins Startup list
  19597.  
  19598. [Epson Stylus C82 Series]
  19599. Number=2783
  19600. Confirmed=U
  19601. Filename=e_s0hic1.EXE
  19602. Description=Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
  19603. Source=Paul Collins Startup list
  19604.  
  19605. [EPSON Stylus DX4800 Series]
  19606. Number=2784
  19607. Confirmed=?
  19608. Filename=E_FATIADE.EXE
  19609. Description=Related to Epson Stylus DX4800 Series printer - <font color="#FF0000">what does it do and is it required in startup?</font>
  19610. Source=Paul Collins Startup list
  19611.  
  19612. [EPSON Stylus Photo R300 Series]
  19613. Number=2785
  19614. Confirmed=U
  19615. Filename=E_S4I2F1.EXE
  19616. Description=Epson Status Monitor 3 for the Epson Stylus Photo R300 (and probably others) printers - monitors the status of ink levels, a print job spooled to that printer, etc
  19617. Source=Paul Collins Startup list
  19618.  
  19619. [EPSON Stylus Photo RX420 Series]
  19620. Number=2786
  19621. Confirmed=U
  19622. Filename=E_FATI9CE.EXE
  19623. Description=Related to the EPSON Stylus Photo RX420 Series printer/scanner/copier
  19624. Source=Paul Collins Startup list
  19625.  
  19626. [EpsonPhotoStarter]
  19627. Number=2787
  19628. Confirmed=U
  19629. Filename=EPSON_PhotoStarter.exe
  19630. Description=Only needed if you want to make full use of the capabilities of an Epson printer that included this 
  19631. Source=Paul Collins Startup list
  19632.  
  19633. [Eptr]
  19634. Number=2788
  19635. Confirmed=X
  19636. Filename=nopdb.exe
  19637. Description=Added by an unidentified WORM or TROJAN!
  19638. Source=Paul Collins Startup list
  19639.  
  19640. [EQAdvice]
  19641. Number=2789
  19642. Confirmed=X
  19643. Filename=EQAdvice.exe
  19644. Description=Added by <a href="http://www.superadblocker.com/definition/eqadvice/" target=_blank>NewAds1</a> ADAWARE!
  19645.  
  19646. Source=Paul Collins Startup list
  19647.  
  19648. [EQArticle]
  19649. Number=2790
  19650. Confirmed=U
  19651. Filename=EQArticle.exe
  19652. Description=<a href="http://www.spyany.com/program/article_adw_rm_EQArticle.html" target="_blank">EQArticle</a> adware
  19653. Source=Paul Collins Startup list
  19654.  
  19655. [Equipmen]
  19656. Number=2791
  19657. Confirmed=?
  19658. Filename=Equipmen.exe
  19659. Description=<font color="#FF0000">??</font>
  19660. Source=Paul Collins Startup list
  19661.  
  19662. [Eraser]
  19663. Number=2792
  19664. Confirmed=U
  19665. Filename=eraser.exe
  19666. Description=<a href="http://www.heidi.ie/eraser/" target=_blank>Eraser</a> allows for complete removal of data from your hard drive
  19667. Source=Paul Collins Startup list
  19668.  
  19669. [eRecoveryService]
  19670. Number=2793
  19671. Confirmed=U
  19672. Filename=check.exe
  19673. Description=Acer Notebook related. Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system integrity
  19674. Source=Paul Collins Startup list
  19675.  
  19676. [eRecoveryService]
  19677. Number=2794
  19678. Confirmed=U
  19679. Filename=Monitor.exe
  19680. Description=Part of Acer Empowering Technology. "<a href="http://www.acer-euro.com/et/en/notebooks01.htm#4" target="_blank">Acer eRecovery Management</a> is a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager"
  19681. Source=Paul Collins Startup list
  19682.  
  19683. [EReg]
  19684. Number=2795
  19685. Confirmed=N
  19686. Filename=reg32.exe
  19687. Description=EReg is a software registration tool incorporated on products such as those by Br°derbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it
  19688. Source=Paul Collins Startup list
  19689.  
  19690. [erfgddfk]
  19691. Number=2796
  19692. Confirmed=X
  19693. Filename=wind2ll2.exe
  19694. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-112515-0448-99" target=_blank>BEAGLE.CQ</a> WORM!
  19695. Source=Paul Collins Startup list
  19696.  
  19697. [erghgjhgdr]
  19698. Number=2797
  19699. Confirmed=X
  19700. Filename=windlhhl.exe
  19701. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030110-5115-99" target=_blank>BEAGLE.BG</a> WORM!
  19702. Source=Paul Collins Startup list
  19703.  
  19704. [erghgjhjgdr]
  19705. Number=2798
  19706. Confirmed=X
  19707. Filename=windlhhl.exe
  19708. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030110-5115-99" target=_blank>BEAGLE.BG</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030113-2829-99" target=_blank>BEAGLE.BH</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030115-3932-99" target=_blank>BEAGLE.BI</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-030115-4032-99" target=_blank>BEAGLE.BJ</a> WORMS!
  19709. Source=Paul Collins Startup list
  19710.  
  19711. [erm]
  19712. Number=2799
  19713. Confirmed=?
  19714. Filename=erm.exe
  19715. Description=<font color="#FF0000">??</font>
  19716. Source=Paul Collins Startup list
  19717.  
  19718. [eros.exe]
  19719. Number=2800
  19720. Confirmed=X
  19721. Filename=eros.exe
  19722. Description=Adult content dailler
  19723. Source=Paul Collins Startup list
  19724.  
  19725. [Error Nuker]
  19726. Number=2801
  19727. Confirmed=N
  19728. Filename=ErrorNuker.exe
  19729. Description=<a href="http://www.errornuker.com/" target= blank>ErrorNuker</a> registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required
  19730. Source=Paul Collins Startup list
  19731.  
  19732. [Error Safe]
  19733. Number=2802
  19734. Confirmed=N
  19735. Filename=ers.exe
  19736. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-012017-0346-99" target="_blank">ErrorSafe</a> security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  19737. Source=Paul Collins Startup list
  19738.  
  19739. [ErrorGuard]
  19740. Number=2803
  19741. Confirmed=X
  19742. Filename=ErrorGuard.exe
  19743. Description=Spyware remover - not recommended, see <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094197" target="_blank">here</a>
  19744. Source=Paul Collins Startup list
  19745.  
  19746. [errorhandler]
  19747. Number=2804
  19748. Confirmed=X
  19749. Filename=errorhandler.exe
  19750. Description=Added by <a href="http://www.fileresearchcenter.com/E/ERRORHANDLER.EXE-7350.html" target=_blank>ErrorHandler</a> ADAWARE!
  19751.  
  19752. Source=Paul Collins Startup list
  19753.  
  19754. [ERS]
  19755. Number=2805
  19756. Confirmed=N
  19757. Filename=ers_startupmon.exe
  19758. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-012017-0346-99" target="_blank">ErrorSafe</a> security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  19759. Source=Paul Collins Startup list
  19760.  
  19761. [erscw]
  19762. Number=2806
  19763. Confirmed=N
  19764. Filename=erscw.exe
  19765. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-012017-0346-99" target="_blank">ErrorSafe</a> security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  19766. Source=Paul Collins Startup list
  19767.  
  19768. [ERS_check]
  19769. Number=2807
  19770. Confirmed=N
  19771. Filename=ers_startupmon.exe
  19772. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-012017-0346-99" target="_blank">ErrorSafe</a> security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
  19773. Source=Paul Collins Startup list
  19774.  
  19775. [erthegdr]
  19776. Number=2808
  19777. Confirmed=X
  19778. Filename=windll2.exe
  19779. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-091216-4524-99" target=_blank>BEAGLE.CG</a> WORM!
  19780. Source=Paul Collins Startup list
  19781.  
  19782. [erthgdr]
  19783. Number=2809
  19784. Confirmed=X
  19785. Filename=windll.exe
  19786. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-080911-3251-99" target="_blank">BEAGLE.AO</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-083115-2542-99" target="_blank">BEAGLE.AQ</a> WORMS!
  19787. Source=Paul Collins Startup list
  19788.  
  19789. [erthgdr]
  19790. Number=2810
  19791. Confirmed=X
  19792. Filename=svc.exe
  19793. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-041600-0244-99" target= blank>BEAGLE.BN</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042115-2906-99" target= blank>BEAGLE.BP</a> WORM!
  19794. Source=Paul Collins Startup list
  19795.  
  19796. [erthgdr2]
  19797. Number=2811
  19798. Confirmed=X
  19799. Filename=svc23.exe
  19800. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BAGLE.CG&VSect=P" target=_blank>BAGLE.CG</a> WORM!
  19801. Source=Paul Collins Startup list
  19802.  
  19803. [ERTS0749]
  19804. Number=2812
  19805. Confirmed=?
  19806. Filename=ERTS0749.exe
  19807. Description=IBM Warranty Notification - <font color="#FF0000">presumably it's a reminder to either register or that warranty is about to expire?</font>
  19808. Source=Paul Collins Startup list
  19809.  
  19810. [ERUNT AutoBackup]
  19811. Number=2813
  19812. Confirmed=U
  19813. Filename=AUTOBACK.EXE
  19814. Description=<a href="http://www.larshederer.homepage.t-online.de/erunt/" target="_blank">ERUNT</a> backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots, resulting in numerous backups that can be restored
  19815. Source=Paul Collins Startup list
  19816.  
  19817. [eSafe Protect]
  19818. Number=2814
  19819. Confirmed=Y
  19820. Filename=ESPWatch.exe
  19821. Description=<a href="http://www.esafe.com/esafe/default.asp?cf=tl" target="_blank">eSafe</a> from Aladdin - internet security for gateway and E-mail servers
  19822. Source=Paul Collins Startup list
  19823.  
  19824. [ESB]
  19825. Number=2815
  19826. Confirmed=U
  19827. Filename=esb.exe
  19828. Description=Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
  19829. Source=Paul Collins Startup list
  19830.  
  19831. [eScan Monitor]
  19832. Number=2816
  19833. Confirmed=Y
  19834. Filename=AVKWCTL9X.EXE
  19835. Description=MicroWorld <a href="http://www.mwti.net/products/escan/escan_antivirus/escanantivirus.asp" target="_blank">eScan</a> antivirus
  19836. Source=Paul Collins Startup list
  19837.  
  19838. [eScan Scheduler]
  19839. Number=2817
  19840. Confirmed=U
  19841. Filename=avkserv.exe
  19842. Description=MicroWorld <a href="http://www.mwti.net/products/escan/escan_antivirus/escanantivirus.asp" target="_blank">eScan</a> antivirus scheduler
  19843. Source=Paul Collins Startup list
  19844.  
  19845. [eScan Updater]
  19846. Number=2818
  19847. Confirmed=U
  19848. Filename=Trayicos.exe
  19849. Description=MicroWorld <a href="http://www.mwti.net/products/escan/escan_antivirus/escanantivirus.asp" target="_blank">eScan</a> antivirus updater - allows users to automatically download updates and set the auto time interval for downloads
  19850. Source=Paul Collins Startup list
  19851.  
  19852. [EScorcher]
  19853. Number=2819
  19854. Confirmed=X
  19855. Filename=escorcher.exe
  19856. Description=Part of <a href="http://www.escorcher.com/" target="_blank">eScorcher</a> anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
  19857. Source=Paul Collins Startup list
  19858.  
  19859. [ESFTP]
  19860. Number=2820
  19861. Confirmed=N
  19862. Filename=esftp.exe
  19863. Description=<a href="http://esftp.com/features.html" target="_blank">ESftp</a> - FTP client for transfering files between a local PC and another remote computer
  19864. Source=Paul Collins Startup list
  19865.  
  19866. [Esoh]
  19867. Number=2821
  19868. Confirmed=X
  19869. Filename=Esoh123.exe
  19870. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.FF" target=_blank>AGOBOT.FF</a> WORM!
  19871.  
  19872. Source=Paul Collins Startup list
  19873.  
  19874. [Especial]
  19875. Number=2822
  19876. Confirmed=X
  19877. Filename=Deneca.bat
  19878. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050909-4602-99" target= blank>DELUZ</a> VIRUS!
  19879. Source=Paul Collins Startup list
  19880.  
  19881. [ESPN BottomLine]
  19882. Number=2823
  19883. Confirmed=N
  19884. Filename=bline.exe
  19885. Description=ESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."
  19886. Source=Paul Collins Startup list
  19887.  
  19888. [ESS Daemon]
  19889. Number=2824
  19890. Confirmed=?
  19891. Filename=Essd.exe
  19892. Description=Related to an ESS based soundacard. <font color="#FF0000">Is it required?</font>
  19893. Source=Paul Collins Startup list
  19894.  
  19895. [essapm]
  19896. Number=2825
  19897. Confirmed=?
  19898. Filename=essapm.exe
  19899. Description=ESS Solo soundcard driver. <font color="#FF0000">Is it required?</font>
  19900. Source=Paul Collins Startup list
  19901.  
  19902. [Essdc]
  19903. Number=2826
  19904. Confirmed=Y
  19905. Filename=essdc.exe
  19906. Description=Related to an ESS Solo soundcard. Seems as though it's required
  19907. Source=Paul Collins Startup list
  19908.  
  19909. [ESSNDSYS]
  19910. Number=2827
  19911. Confirmed=?
  19912. Filename=ESSNDSYS.EXE
  19913. Description=Related to an ESS based soundacard. <font color="#FF0000">Is it required?</font>
  19914. Source=Paul Collins Startup list
  19915.  
  19916. [ESSOLO]
  19917. Number=2828
  19918. Confirmed=Y
  19919. Filename=ESSOLO.exe
  19920. Description=Sound card driver that re-instates itself every time it's removed
  19921. Source=Paul Collins Startup list
  19922.  
  19923. [esspk]
  19924. Number=2829
  19925. Confirmed=Y
  19926. Filename=esspk.exe
  19927. Description=ESS Technology modem speaker driver file. Required to get on-line with this modem
  19928. Source=Paul Collins Startup list
  19929.  
  19930. [EssSpkPhone]
  19931. Number=2830
  19932. Confirmed=U
  19933. Filename=essspk.exe
  19934. Description=ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
  19935. Source=Paul Collins Startup list
  19936.  
  19937. [eSupInit]
  19938. Number=2831
  19939. Confirmed=?
  19940. Filename=eSupCmd.exe
  19941. Description=Related to <a href="http://www.support.com/" target="_blank">SupportSoft</a> (aka Support.com) "Real-Time Service Management software". <font color="#FF0000">What does it do and is it required?</font>
  19942. Source=Paul Collins Startup list
  19943.  
  19944. [ETB Tester]
  19945. Number=2832
  19946. Confirmed=X
  19947. Filename=etbtest.exe
  19948. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotabr.html" target= blank>RBOT-ABR</a> WORM!
  19949. Source=Paul Collins Startup list
  19950.  
  19951. [etbrun]
  19952. Number=2833
  19953. Confirmed=X
  19954. Filename=elit***32.exe [* = random char]
  19955. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-083109-1455-99" target=_blank>EliteBar</a> adware
  19956. Source=Paul Collins Startup list
  19957.  
  19958. [Ethernet]
  19959. Number=2834
  19960. Confirmed=N
  19961. Filename=tcaudiag.exe
  19962. Description=3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
  19963. Source=Paul Collins Startup list
  19964.  
  19965. [ethernet]
  19966. Number=2835
  19967. Confirmed=X
  19968. Filename=airftp.exe
  19969. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  19970. Source=Paul Collins Startup list
  19971.  
  19972. [ethernet]
  19973. Number=2836
  19974. Confirmed=X
  19975. Filename=msnger.exe
  19976. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  19977. Source=Paul Collins Startup list
  19978.  
  19979. [ethernet]
  19980. Number=2837
  19981. Confirmed=X
  19982. Filename=msftp.exe
  19983. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BXJ&VSect=P" target=_blank>SDBOT.BXJ</a> WORM!
  19984. Source=Paul Collins Startup list
  19985.  
  19986. [Ethernet Drivers]
  19987. Number=2838
  19988. Confirmed=X
  19989. Filename=smrrs.exe
  19990. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaak.html" target=_blank>RBOT-AAK</a> WORM!
  19991. Source=Paul Collins Startup list
  19992.  
  19993. [Ethernet Drivers]
  19994. Number=2839
  19995. Confirmed=X
  19996. Filename=ethernet.exe
  19997. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-012609-1021-99" target= blank>GAOBOT.CEZ</a> WORM!
  19998. Source=Paul Collins Startup list
  19999.  
  20000. [Etraffic]
  20001. Number=2840
  20002. Confirmed=X
  20003. Filename=JavaRun.exe
  20004. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453059998" target="_blank">TopMoxie</a> adware
  20005. Source=Paul Collins Startup list
  20006.  
  20007. [eTrust EZ Firewall]
  20008. Number=2841
  20009. Confirmed=Y
  20010. Filename=efpeadm.exe
  20011. Description=<a href="http://www1.my-etrust.com/products/Firewall.cfm" target="_blank">eTrust EZ Firewall</a>
  20012. Source=Paul Collins Startup list
  20013.  
  20014. [eTrust PestPatrol Active Protection]
  20015. Number=2842
  20016. Confirmed=U
  20017. Filename=PPActiveDetection.exe
  20018. Description=<a href="http://www.pestpatrol.com/" target=_blank>PestPatrol</a> real-time protection feature. "Stops spyware before it infects your system"
  20019. Source=Paul Collins Startup list
  20020.  
  20021. [eTrust Realtime Monitor]
  20022. Number=2843
  20023. Confirmed=X
  20024. Filename=realmon.exe
  20025. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_LAZAR.B" target="_blank">LAZAR.B</a> TROJAN!
  20026. Source=Paul Collins Startup list
  20027.  
  20028. [eTrustCIPE]
  20029. Number=2844
  20030. Confirmed=Y
  20031. Filename=ezdsmain.exe
  20032. Description=eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
  20033. Source=Paul Collins Startup list
  20034.  
  20035. [eTunnel]
  20036. Number=2845
  20037. Confirmed=X
  20038. Filename=winfw.exe
  20039. Description=Added by an unidentified TROJAN!
  20040. Source=Paul Collins Startup list
  20041.  
  20042. [EUP Service]
  20043. Number=2846
  20044. Confirmed=X
  20045. Filename=eupsvc.exe
  20046. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delbotq.html" target="_blank">DELBOT-Q</a> WORM!
  20047. Source=Paul Collins Startup list
  20048.  
  20049. [EuroGlot]
  20050. Number=2847
  20051. Confirmed=U
  20052. Filename=EuroGlot.exe
  20053. Description=<a href="http://www.euroglot.nl/en/producten.html?category=over_euroglot" target="_blank">Euroglot</a> - "multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian"
  20054. Source=Paul Collins Startup list
  20055.  
  20056. [Event Log]
  20057. Number=2848
  20058. Confirmed=?
  20059. Filename=eventlog.exe
  20060. Description=<font color="#FF0000">??</font>
  20061. Source=Paul Collins Startup list
  20062.  
  20063. [Event Planner Reminders]
  20064. Number=2849
  20065. Confirmed=N
  20066. Filename=PLNRnote.exe
  20067. Description=Sierra Event Planner tray icon
  20068. Source=Paul Collins Startup list
  20069.  
  20070. [Event Reminder]
  20071. Number=2850
  20072. Confirmed=N
  20073. Filename=pmremind.exe
  20074. Description=A calendar/alarm program that installs with Br°derbund Printmaster
  20075. Source=Paul Collins Startup list
  20076.  
  20077. [EventApplicationCmd]
  20078. Number=2851
  20079. Confirmed=X
  20080. Filename=smschk.exe
  20081. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbotao.html" target=_blank>IRCBOT-AO</a> TROJAN!
  20082. Source=Paul Collins Startup list
  20083.  
  20084. [EVENTLISTENER]
  20085. Number=2852
  20086. Confirmed=U
  20087. Filename=EvLstnr.exe
  20088. Description=Used with a Nikon digital camera to recognize when the camera is plugged in
  20089. Source=Paul Collins Startup list
  20090.  
  20091. [eventmgr]
  20092. Number=2853
  20093. Confirmed=N
  20094. Filename=eventmgr.exe
  20095. Description=Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
  20096. Source=Paul Collins Startup list
  20097.  
  20098. [eventwvr]
  20099. Number=2854
  20100. Confirmed=X
  20101. Filename=eventwvr.exe
  20102. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcosiamg.html" target=_blank>COSIAM_G</a> TROJAN!
  20103.  
  20104. Source=Paul Collins Startup list
  20105.  
  20106. [Evidence Cleaner]
  20107. Number=2855
  20108. Confirmed=U
  20109. Filename=ecleaner.exe
  20110. Description=<a href="http://www.evidence-cleaner.net/" target= blank>Evidence Cleaner</a> cleans up tracks left by your PC and Internet activities
  20111. Source=Paul Collins Startup list
  20112.  
  20113. [Evidence Eliminator]
  20114. Number=2856
  20115. Confirmed=N
  20116. Filename=ee.exe
  20117. Description=<a href="http://www.evidence-eliminator.com/product.d2w" target="_blank">Evidence Eliminator</a> - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis
  20118. Source=Paul Collins Startup list
  20119.  
  20120. [Evil]
  20121. Number=2857
  20122. Confirmed=X
  20123. Filename=Evil.exe
  20124. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-091514-0637-99" target=_blank>MYTOB.JM</a> WORM!
  20125. Source=Paul Collins Startup list
  20126.  
  20127. [evntsvc]
  20128. Number=2858
  20129. Confirmed=N
  20130. Filename=evntsc.exe
  20131. Description=Application Scheduler installed along with <a href="http://www.real.com/" target="_blank">RealOne Player</a>. Once installed, it runs independently of RealOne Player. See <a href="http://www.mikescomputerinfo.com/TkBellExe.htm" target="_blank">here</a> for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
  20132. Source=Paul Collins Startup list
  20133.  
  20134. [EVOLOSTA]
  20135. Number=2859
  20136. Confirmed=U
  20137. Filename=EVOLOSTA.EXE
  20138. Description=Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it
  20139. Source=Paul Collins Startup list
  20140.  
  20141. [Evoluent Mouse Manager]
  20142. Number=2860
  20143. Confirmed=U
  20144. Filename=EvoMouExec.exe
  20145. Description=Mouse manager for Evoluent <a href="http://www.evoluent.com/vmouse2.html" target="_blank">VertcialMouse</a>
  20146. Source=Paul Collins Startup list
  20147.  
  20148. [EvtHtm]
  20149. Number=2861
  20150. Confirmed=X
  20151. Filename=evthtm.exe
  20152. Description=Premium rate adult content dialler
  20153. Source=Paul Collins Startup list
  20154.  
  20155. [EW Message Server]
  20156. Number=2862
  20157. Confirmed=U
  20158. Filename=msg32.exe
  20159. Description=Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
  20160. Source=Paul Collins Startup list
  20161.  
  20162. [eWare Startup]
  20163. Number=2863
  20164. Confirmed=N
  20165. Filename=iWareStart.exe
  20166. Description=<a href="http://www.eware.com/about/index.asp" target="_blank">eWare</a> iWare task bar. Not required
  20167. Source=Paul Collins Startup list
  20168.  
  20169. [ewupdater]
  20170. Number=2864
  20171. Confirmed=X
  20172. Filename=ewupdater.exe
  20173. Description=<a href="http://www.kephyr.com/spywarescanner/library/easywebsearch/index.phtml" target="_blank">EasyWebSearch</a> adware updater
  20174. Source=Paul Collins Startup list
  20175.  
  20176. [example]
  20177. Number=2865
  20178. Confirmed=X
  20179. Filename=[random filename].exe
  20180. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-112915-5158-99" target=_blank>NUCLEAR</a> TROJAN! Note - this trojan file is found in the Windows\NR or Winnt\NR folder
  20181. Source=Paul Collins Startup list
  20182.  
  20183. [Excite Platform]
  20184. Number=2866
  20185. Confirmed=N
  20186. Filename=Exlaunch.exe
  20187. Description=Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
  20188. Source=Paul Collins Startup list
  20189.  
  20190. [Excite Private Messenger Pipe]
  20191. Number=2867
  20192. Confirmed=?
  20193. Filename=x8impipe.exe
  20194. Description=<font color="#FF0000">??</font>
  20195. Source=Paul Collins Startup list
  20196.  
  20197. [ExciteAssistantEXE]
  20198. Number=2868
  20199. Confirmed=N
  20200. Filename=ASSISTANT.EXE
  20201. Description=With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open
  20202. Source=Paul Collins Startup list
  20203.  
  20204. [exdl.exe]
  20205. Number=2869
  20206. Confirmed=X
  20207. Filename=exdl.exe
  20208. Description=<a href="http://sarc.com/avcenter/venc/data/adware.bargainbuddy.html" target="_blank">BargainBuddy</a> foistware
  20209. Source=Paul Collins Startup list
  20210.  
  20211. [exe lptt01]
  20212. Number=2870
  20213. Confirmed=X
  20214. Filename=exe.exe
  20215. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Exe" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  20216. Source=Paul Collins Startup list
  20217.  
  20218. [exe ml097e]
  20219. Number=2871
  20220. Confirmed=X
  20221. Filename=exe.exe
  20222. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Exe" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  20223. Source=Paul Collins Startup list
  20224.  
  20225. [execfg4]
  20226. Number=2872
  20227. Confirmed=X
  20228. Filename=execfg4.exe
  20229. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-081509-0110-99" target="_blank">ELECTRON</a> WORM!
  20230. Source=Paul Collins Startup list
  20231.  
  20232. [ExecUser]
  20233. Number=2873
  20234. Confirmed=X
  20235. Filename=ExecUser.exe
  20236. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  20237.  
  20238. Source=Paul Collins Startup list
  20239.  
  20240. [Execute]
  20241. Number=2874
  20242. Confirmed=?
  20243. Filename=delfolders.exe
  20244. Description=<font color="#FF0000">??</font>
  20245. Source=Paul Collins Startup list
  20246.  
  20247. [ExeName32]
  20248. Number=2875
  20249. Confirmed=X
  20250. Filename=Warm.scr
  20251. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121115-2525-99" target="_blank">SCOLD</a> WORM!
  20252. Source=Paul Collins Startup list
  20253.  
  20254. [ExFilter]
  20255. Number=2876
  20256. Confirmed=X
  20257. Filename=Rundll32.exe [path] cdnspie.dll, ExecFilter
  20258. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097703" target="_blank">CNNIC Update</a> pest
  20259. Source=Paul Collins Startup list
  20260.  
  20261. [exgiwsl]
  20262. Number=2877
  20263. Confirmed=?
  20264. Filename=exgiwsl.exe
  20265. Description=<font color="#FF0000">??</font>
  20266. Source=Paul Collins Startup list
  20267.  
  20268. [Exif Launcher]
  20269. Number=2878
  20270. Confirmed=U
  20271. Filename=Exiflaquickdcr.exe
  20272. Description=USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
  20273. Source=Paul Collins Startup list
  20274.  
  20275. [Exif Launcher]
  20276. Number=2879
  20277. Confirmed=U
  20278. Filename=QuickDCF.exe
  20279. Description=USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
  20280. Source=Paul Collins Startup list
  20281.  
  20282. [ExitKiller]
  20283. Number=2880
  20284. Confirmed=U
  20285. Filename=Ekiller.exe
  20286. Description=<a href="http://www.exitkiller.net/" target="_blank">Exit Killer</a> - automatically closes pop-up windows in your browser
  20287. Source=Paul Collins Startup list
  20288.  
  20289. [exmon]
  20290. Number=2881
  20291. Confirmed=?
  20292. Filename=hpimoniter.exe
  20293. Description=<font color="#FF0000">Some kind of hp digital camera maybe or a photo smart connection probe?</font>
  20294. Source=Paul Collins Startup list
  20295.  
  20296. [Exn]
  20297. Number=2882
  20298. Confirmed=X
  20299. Filename=exn.exe
  20300. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_IRCBOT.RJ" target="_blank">IRCBOT.RJ</a> WORM!
  20301. Source=Paul Collins Startup list
  20302.  
  20303. [EXPL0RE.EXE]
  20304. Number=2883
  20305. Confirmed=X
  20306. Filename=EXPL0RE.EXE
  20307. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpopnoa.html" target=_blank>POPNO-A</a> TROJAN! Note that the filename is spelled using the digit "0" instead of the uppercase letter "o"
  20308. Source=Paul Collins Startup list
  20309.  
  20310. [Expl0rer soft]
  20311. Number=2884
  20312. Confirmed=X
  20313. Filename=expl0rer.pif
  20314. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaqr.html" target=_blank>RBOT-AQR</a> WORM!
  20315. Source=Paul Collins Startup list
  20316.  
  20317. [expler]
  20318. Number=2885
  20319. Confirmed=X
  20320. Filename=Updadv.exe
  20321. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojqqpassn.html" target=_blank>QQPASS-N</a> TROJAN!
  20322. Source=Paul Collins Startup list
  20323.  
  20324. [Explkw]
  20325. Number=2886
  20326. Confirmed=X
  20327. Filename=expup.exe
  20328. Description=Keywords hijacker
  20329. Source=Paul Collins Startup list
  20330.  
  20331. [explore]
  20332. Number=2887
  20333. Confirmed=X
  20334. Filename=explore.exe
  20335. Description=Added by any number of VIRUSES, WORMS or TROJANS!
  20336. Source=Paul Collins Startup list
  20337.  
  20338. [Explore]
  20339. Number=2888
  20340. Confirmed=X
  20341. Filename=Explorer.exe
  20342. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-080713-1333-99" target=_blank>IRC.FLOOD.G</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually!
  20343. Source=Paul Collins Startup list
  20344.  
  20345. [Explore]
  20346. Number=2889
  20347. Confirmed=X
  20348. Filename=explore.exe
  20349. Description=Adult content dialler
  20350. Source=Paul Collins Startup list
  20351.  
  20352. [explore manager]
  20353. Number=2890
  20354. Confirmed=X
  20355. Filename=explore.exe
  20356. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DONBOMB.A&VSect=P" target=_blank>DONBOMB.A</a> TROJAN!
  20357. Source=Paul Collins Startup list
  20358.  
  20359. [explore.exe]
  20360. Number=2891
  20361. Confirmed=X
  20362. Filename=Explore.exe
  20363. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091414-5731-99" target="_blank">GRAYBIRD.G</a> TROJAN!
  20364. Source=Paul Collins Startup list
  20365.  
  20366. [exploreff.exe]
  20367. Number=2892
  20368. Confirmed=X
  20369. Filename=exploreff.exe
  20370. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-102516-5127-99" target=_blank>FINFANSE</a> TROJAN!
  20371. Source=Paul Collins Startup list
  20372.  
  20373. [explorer]
  20374. Number=2893
  20375. Confirmed=U
  20376. Filename=explorer.exe
  20377. Description=Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_BISTRO" target="_blank">PE_BISTRO</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-031016-5849-99" target="_blank">DVLDR</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-012816-3647-99" target="_blank">MYDOOM.C</a>. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL
  20378. Source=Paul Collins Startup list
  20379.  
  20380. [explorer]
  20381. Number=2894
  20382. Confirmed=X
  20383. Filename=wscript.exe [filename]
  20384. Description=Sneaky way to start any VBS script. Many viruses use VBS files
  20385. Source=Paul Collins Startup list
  20386.  
  20387. [Explorer]
  20388. Number=2895
  20389. Confirmed=X
  20390. Filename=shellexpl.exe
  20391. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082915-1318-99" target="_blank">SHELDOR</a> TROJAN!
  20392. Source=Paul Collins Startup list
  20393.  
  20394. [explorer]
  20395. Number=2896
  20396. Confirmed=X
  20397. Filename=expl32.exe
  20398. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-050220-1346-99" target="_blank">RATSOU</a> TROJAN!
  20399. Source=Paul Collins Startup list
  20400.  
  20401. [Explorer]
  20402. Number=2897
  20403. Confirmed=X
  20404. Filename=[path to worm]
  20405. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-111308-1926-99" target="_blank">AUTEX</a> WORM!
  20406. Source=Paul Collins Startup list
  20407.  
  20408. [Explorer]
  20409. Number=2898
  20410. Confirmed=X
  20411. Filename=shellexp.exe
  20412. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082915-1318-99" target=_blank>SHELDOR</a> TROJAN!
  20413.  
  20414. Source=Paul Collins Startup list
  20415.  
  20416. [EXPLORER]
  20417. Number=2899
  20418. Confirmed=X
  20419. Filename=EXPL0RER.EXE
  20420. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbeastdoy.html" target=_blank>BEASTDO-Y</a> TROJAN! Note the "0" in the filename rather than upper case "o"
  20421. Source=Paul Collins Startup list
  20422.  
  20423. [EXPLORER]
  20424. Number=2900
  20425. Confirmed=X
  20426. Filename=sys.exe
  20427. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsillyfdca.html" target=_blank>SILLYFDC-A</a> TROJAN!
  20428. Source=Paul Collins Startup list
  20429.  
  20430. [Explorer]
  20431. Number=2901
  20432. Confirmed=X
  20433. Filename=config_.com
  20434. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32floppyd.html" target=_blank>FLOPPY-D</a> WORM!
  20435. Source=Paul Collins Startup list
  20436.  
  20437. [Explorer]
  20438. Number=2902
  20439. Confirmed=X
  20440. Filename=drv.exe
  20441. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmallfd.html" target=_blank>SMALL-FD</a> TROJAN!
  20442. Source=Paul Collins Startup list
  20443.  
  20444. [explorer]
  20445. Number=2903
  20446. Confirmed=X
  20447. Filename=[path to trojan]
  20448. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagenteu.html" target=_blank>AGENT-EU</a> TROJAN!
  20449. Source=Paul Collins Startup list
  20450.  
  20451. [explorer]
  20452. Number=2904
  20453. Confirmed=X
  20454. Filename=explorer.exe
  20455. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojkeylogak.html" target=_blank>KEYLOG-AK</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "service" subfolder of the System folder
  20456. Source=Paul Collins Startup list
  20457.  
  20458. [EXPLORER]
  20459. Number=2905
  20460. Confirmed=X
  20461. Filename=EXPLORER.exe
  20462. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojnethiefp.html" target=_blank>NETHIEF-P</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "SHELLEXT" subfolder of the System folder
  20463. Source=Paul Collins Startup list
  20464.  
  20465. [explorer]
  20466. Number=2906
  20467. Confirmed=X
  20468. Filename=explorer.exe
  20469. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojblockeya.html" target=_blank>BLOCKEY-A</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "config" subfolder of the System folder
  20470. Source=Paul Collins Startup list
  20471.  
  20472. [explorer]
  20473. Number=2907
  20474. Confirmed=X
  20475. Filename=Yinstall.exe
  20476. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  20477. Source=Paul Collins Startup list
  20478.  
  20479. [Explorer]
  20480. Number=2908
  20481. Confirmed=X
  20482. Filename=Windows Explorer.exe
  20483. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sillyfdci.html" target="_blank">SILLYFDC-I</a> WORM!
  20484. Source=Paul Collins Startup list
  20485.  
  20486. [Explorer Loader]
  20487. Number=2909
  20488. Confirmed=X
  20489. Filename=explr32.exe
  20490. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.N" target= blank>AGOBOT.N</a> WORM!
  20491. Source=Paul Collins Startup list
  20492.  
  20493. [Explorer Loader]
  20494. Number=2910
  20495. Confirmed=X
  20496. Filename=explorerl.exe
  20497. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotadi.html" target=_blank>SDBOT-ADI</a> WORM!
  20498. Source=Paul Collins Startup list
  20499.  
  20500. [Explorer lptt01]
  20501. Number=2911
  20502. Confirmed=X
  20503. Filename=explorer.exe
  20504. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "explorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!
  20505. Source=Paul Collins Startup list
  20506.  
  20507. [EXPLORER MICROSOFT SYSTEM]
  20508. Number=2912
  20509. Confirmed=X
  20510. Filename=explore.exe
  20511. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  20512. Source=Paul Collins Startup list
  20513.  
  20514. [Explorer ml097e]
  20515. Number=2913
  20516. Confirmed=X
  20517. Filename=explorer.exe
  20518. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "explorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!
  20519. Source=Paul Collins Startup list
  20520.  
  20521. [Explorer soft]
  20522. Number=2914
  20523. Confirmed=X
  20524. Filename=explorer.pif
  20525. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotapk.html" target=_blank>RBOT-APK</a> WORM!
  20526. Source=Paul Collins Startup list
  20527.  
  20528. [Explorer soft]
  20529. Number=2915
  20530. Confirmed=X
  20531. Filename=explorer.com
  20532. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotarm.html" target=_blank>RBOT-ARM</a> WORM!
  20533. Source=Paul Collins Startup list
  20534.  
  20535. [Explorer Updater]
  20536. Number=2916
  20537. Confirmed=X
  20538. Filename=IEXPLORE.exe
  20539. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotwo.html" target=_blank>SDBOT-WO</a> WORM! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  20540. Source=Paul Collins Startup list
  20541.  
  20542. [explorer.exe]
  20543. Number=2917
  20544. Confirmed=X
  20545. Filename=explorer.exe
  20546. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentew.html" target="_blank">AGENT-EW</a> or <a href="http://www.sophos.com/virusinfo/analyses/trojpwscy.html" target="_blank">PWS-CY</a> TROJANS! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  20547. Source=Paul Collins Startup list
  20548.  
  20549. [explorer.exe]
  20550. Number=2918
  20551. Confirmed=X
  20552. Filename=explorer.exe
  20553. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdelfacl.html" target="_blank">DELF-ACL</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder
  20554. Source=Paul Collins Startup list
  20555.  
  20556. [Explorer32]
  20557. Number=2919
  20558. Confirmed=X
  20559. Filename=Expl32.exe
  20560. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_HACKTACK.B" target="_blank">HACKTACK.B</a> TROJAN!
  20561. Source=Paul Collins Startup list
  20562.  
  20563. [Explorer32]
  20564. Number=2920
  20565. Confirmed=X
  20566. Filename=explorer6s4.exe
  20567. Description=Added by the Downloader.Win32.Small.biq TROJAN!
  20568. Source=Paul Collins Startup list
  20569.  
  20570. [Explorer32]
  20571. Number=2921
  20572. Confirmed=X
  20573. Filename=efsdfgxg.exe
  20574. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojclickery.html" target=_blank>CLICKER-Y</a> TROJAN!
  20575. Source=Paul Collins Startup list
  20576.  
  20577. [ExploreUpdSched]
  20578. Number=2922
  20579. Confirmed=X
  20580. Filename=[random filename].exe
  20581. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094810" target="_blank">ZenoSearch</a> adware
  20582. Source=Paul Collins Startup list
  20583.  
  20584. [exporet]
  20585. Number=2923
  20586. Confirmed=X
  20587. Filename=winset.exe
  20588. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojqqpassi.html" target=_blank>QQPASS-I</a> TROJAN!
  20589. Source=Paul Collins Startup list
  20590.  
  20591. [Express ClickYes]
  20592. Number=2924
  20593. Confirmed=U
  20594. Filename=ClickYes.exe
  20595. Description="<a href="http://www.contextmagic.com/" target="_blank">Express ClickYes</a> is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt, that asks you to confirm mail sending from third party applications"
  20596. Source=Paul Collins Startup list
  20597.  
  20598. [Exshow95]
  20599. Number=2925
  20600. Confirmed=U
  20601. Filename=EXSHOW95.exe
  20602. Description=Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
  20603. Source=Paul Collins Startup list
  20604.  
  20605. [External Dependencies]
  20606. Number=2926
  20607. Confirmed=X
  20608. Filename=External.exe
  20609. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061101-2338-99" target=_blank>MYTOB.EC</a> WORM!
  20610. Source=Paul Collins Startup list
  20611.  
  20612. [ExtraDNS]
  20613. Number=2927
  20614. Confirmed=U
  20615. Filename=ExtraDNS.exe
  20616. Description=<a href="http://www.extratools.com/" target="_blank">ExtraDNS</a> - DNS configuration tool
  20617. Source=Paul Collins Startup list
  20618.  
  20619. [Extranet AutoDial]
  20620. Number=2928
  20621. Confirmed=?
  20622. Filename=AutoExt.exe
  20623. Description=Nortel Networks Contivity Extranet Switching Software
  20624. Source=Paul Collins Startup list
  20625.  
  20626. [ExxtremeHelperDemon]
  20627. Number=2929
  20628. Confirmed=?
  20629. Filename=exxdemon.exe
  20630. Description=<font color="#FF0000">Creative Exxtreme graphics card related?</font>
  20631. Source=Paul Collins Startup list
  20632.  
  20633. [Eye Tide Launcher]
  20634. Number=2930
  20635. Confirmed=N
  20636. Filename=oneeyetideone.exe
  20637. Description=Nascar wallpaper
  20638. Source=Paul Collins Startup list
  20639.  
  20640. [EZ Firewall]
  20641. Number=2931
  20642. Confirmed=Y
  20643. Filename=ca.exe
  20644. Description=eTrust <a href="http://www3.ca.com/Solutions/Product.asp?ID=3243" target=_blank>EZ Armor</a> Internet Security
  20645. Source=Paul Collins Startup list
  20646.  
  20647. [ezagent]
  20648. Number=2932
  20649. Confirmed=N
  20650. Filename=ezagent.exe
  20651. Description=<a href="http://www.asus.com/products/vga/tvfm/overview.htm" target="_blank">EzVCR</a> recording software for the ASUS TV FM card. Available via Start -> Programs
  20652. Source=Paul Collins Startup list
  20653.  
  20654. [EzButton]
  20655. Number=2933
  20656. Confirmed=N
  20657. Filename=EzButton.EXE
  20658. Description=EZbutton is a quick launcher for the Media player app that comes with certain laptops
  20659. Source=Paul Collins Startup list
  20660.  
  20661. [EZDesk]
  20662. Number=2934
  20663. Confirmed=N
  20664. Filename=EZDESK.EXE
  20665. Description=Utility that remembers icon locations for each user and resolution. Available <a href="http://www.ezwaretech.com/" target="_blank">here</a>
  20666. Source=Paul Collins Startup list
  20667.  
  20668. [EzEjMnAp]
  20669. Number=2935
  20670. Confirmed=N
  20671. Filename=EzEjMnAp.exe
  20672. Description=For IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs
  20673. Source=Paul Collins Startup list
  20674.  
  20675. [eZmmod]
  20676. Number=2936
  20677. Confirmed=X
  20678. Filename=mmod.exe
  20679. Description=eZula <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=eZula.TopText&threatid=5117" target="_blank">TopText</a> adware
  20680. Source=Paul Collins Startup list
  20681.  
  20682. [EZNORUN]
  20683. Number=2937
  20684. Confirmed=?
  20685. Filename=EZNORUN.EXE
  20686. Description=<font color="#FF0000">Easy Internet related?</font>
  20687. Source=Paul Collins Startup list
  20688.  
  20689. [EzPrint]
  20690. Number=2938
  20691. Confirmed=N
  20692. Filename=ezprint.exe
  20693. Description=Configuration options for Lexmark printing devices
  20694.  
  20695. Source=Paul Collins Startup list
  20696.  
  20697. [ezPS_Px]
  20698. Number=2939
  20699. Confirmed=Y
  20700. Filename=ezSP_PxEngine.exe
  20701. Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
  20702. Source=Paul Collins Startup list
  20703.  
  20704. [ezPS_Px]
  20705. Number=2940
  20706. Confirmed=Y
  20707. Filename=ezSP_Px.exe
  20708. Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
  20709. Source=Paul Collins Startup list
  20710.  
  20711. [ezShieldProtector for Px]
  20712. Number=2941
  20713. Confirmed=Y
  20714. Filename=ezSP_Px.exe
  20715. Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
  20716. Source=Paul Collins Startup list
  20717.  
  20718. [ezShieldProtector for Px]
  20719. Number=2942
  20720. Confirmed=Y
  20721. Filename=ezSP_PxEngine.exe
  20722. Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
  20723. Source=Paul Collins Startup list
  20724.  
  20725. [EZSMART App]
  20726. Number=2943
  20727. Confirmed=U
  20728. Filename=ezsmart.exe
  20729. Description=EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
  20730. Source=Paul Collins Startup list
  20731.  
  20732. [ezula]
  20733. Number=2944
  20734. Confirmed=X
  20735. Filename=eZmmod.exe
  20736. Description=eZula <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=eZula.TopText&threatid=5117" target="_blank">TopText</a> adware
  20737. Source=Paul Collins Startup list
  20738.  
  20739. [eZulaMain]
  20740. Number=2945
  20741. Confirmed=X
  20742. Filename=eZulaMain.exe
  20743. Description=eZula <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=eZula.TopText&threatid=5117" target="_blank">TopText</a> adware
  20744. Source=Paul Collins Startup list
  20745.  
  20746. [eZuluMain]
  20747. Number=2946
  20748. Confirmed=X
  20749. Filename=eZuluMain.exe
  20750. Description=Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
  20751. Source=Paul Collins Startup list
  20752.  
  20753. [eZWO]
  20754. Number=2947
  20755. Confirmed=X
  20756. Filename=wo.exe
  20757. Description=eZula <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=eZula.TopText&threatid=5117" target="_blank">TopText</a> adware
  20758. Source=Paul Collins Startup list
  20759.  
  20760. [E_S10IC2]
  20761. Number=2948
  20762. Confirmed=U
  20763. Filename=E_S10IC2.exe
  20764. Description=Epson Stylus C44 Series printer monitor - for checking ink levels, etc
  20765. Source=Paul Collins Startup list
  20766.  
  20767. [E_S23]
  20768. Number=2949
  20769. Confirmed=U
  20770. Filename=E_SICN03.exe
  20771. Description=Epson printer status monitor - for checking ink levels, etc.
  20772. Source=Paul Collins Startup list
  20773.  
  20774. [E_S4I2F1]
  20775. Number=2950
  20776. Confirmed=U
  20777. Filename=E_S4I2F1.exe
  20778. Description=Epson Status Monitor 3 for the Epson Stylus Photo R300 (and probably others) printers - monitors the status of ink levels, a print job spooled to that printer, etc
  20779. Source=Paul Collins Startup list
  20780.  
  20781. [E_S4I2G1]
  20782. Number=2951
  20783. Confirmed=N
  20784. Filename=E_S4I2G1.EXE
  20785. Description=Epson Status Monitor 3 for the Epson Stylus CX5400 printer/scanner/copier (and probably others) - monitors the status of ink levels, a print job spooled to that printer, etc
  20786. Source=Paul Collins Startup list
  20787.  
  20788. [E_SOEIC1]
  20789. Number=2952
  20790. Confirmed=U
  20791. Filename=E_SOEIC1.exe
  20792. Description=Epson Stylus printer monitor - for checking ink levels, etc.
  20793. Source=Paul Collins Startup list
  20794.  
  20795. [F-Secure 2005]
  20796. Number=2953
  20797. Confirmed=X
  20798. Filename=svchost.exe
  20799. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbifrosech.html" target=_blank>BIFROSE-CH</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  20800. Source=Paul Collins Startup list
  20801.  
  20802. [F-Secure 2006]
  20803. Number=2954
  20804. Confirmed=Y
  20805. Filename=fspex.exe
  20806. Description=<a href="http://www.f-secure.com/" target="_blank">F-Secure</a> Anti-Virus automatic updater
  20807. Source=Paul Collins Startup list
  20808.  
  20809. [F-Secure Management Agent]
  20810. Number=2955
  20811. Confirmed=U
  20812. Filename=FSMA32.EXE
  20813. Description=<a href="http://www.f-secure.com/" target="_blank">F-Secure</a> antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products
  20814. Source=Paul Collins Startup list
  20815.  
  20816. [F-Secure Manager]
  20817. Number=2956
  20818. Confirmed=Y
  20819. Filename=FSM32.EXE
  20820. Description=<a href="http://www.f-secure.com/" target="_blank">F-Secure</a> antivirus - carry out scheduled virus scans automatically
  20821. Source=Paul Collins Startup list
  20822.  
  20823. [F-Secure Startup Wizard]
  20824. Number=2957
  20825. Confirmed=Y
  20826. Filename=FSSW.EXE
  20827. Description=<a href="http://www.f-secure.com/" target="_blank">F-Secure</a> antivirus
  20828. Source=Paul Collins Startup list
  20829.  
  20830. [F-Secure TNB]
  20831. Number=2958
  20832. Confirmed=Y
  20833. Filename=TNBUtil.exe
  20834. Description=<a href="http://www.f-secure.com/" target="_blank">F-Secure</a> antivirus
  20835. Source=Paul Collins Startup list
  20836.  
  20837. [F-StopW]
  20838. Number=2959
  20839. Confirmed=Y
  20840. Filename=F-StopW.exe
  20841. Description=<a href="http://www.f-prot.com">F-Prot</a> anti-virus background scanner by F-Risk Software
  20842. Source=Paul Collins Startup list
  20843.  
  20844. [f1Tray.exe]
  20845. Number=2960
  20846. Confirmed=U
  20847. Filename=F1TRAY.EXE
  20848. Description=System Tray icon for FusionOne's <a href="http://www.mightyphone.com/index.php" target="_blank">MightyPhone</a> software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"
  20849. Source=Paul Collins Startup list
  20850.  
  20851. [f607]
  20852. Number=2961
  20853. Confirmed=X
  20854. Filename=f607.exe
  20855. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082712-0129-99" target="_blank">URAT.B</a> TROJAN!
  20856. Source=Paul Collins Startup list
  20857.  
  20858. [f73cdc8ee94e]
  20859. Number=2962
  20860. Confirmed=X
  20861. Filename=btsendto.exe
  20862. Description=Associated with mysearchnow.com/searchbar.html 
  20863. Source=Paul Collins Startup list
  20864.  
  20865. [FamilyKeyLogger]
  20866. Number=2963
  20867. Confirmed=U
  20868. Filename=cisvc.exe
  20869. Description=<a href="http://www.spyarsenal.com/familykeylogger/" target=_blank>Family Keylogger</a> is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Keystroke logger/monitoring program - remove unless you installed it yourself!
  20870.  
  20871. Source=Paul Collins Startup list
  20872.  
  20873. [Fantasia injector]
  20874. Number=2964
  20875. Confirmed=X
  20876. Filename=wincfg.exe
  20877. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.US&VSect=P" target=_blank>AGOBOT.US</a> WORM!
  20878. Source=Paul Collins Startup list
  20879.  
  20880. [fapmon]
  20881. Number=2965
  20882. Confirmed=?
  20883. Filename=fapmon.exe
  20884. Description=<a href="http://www.copperhead.cc/fap.html" target="_blank">Fair Access Policy</a> monitor for DirecPC/DirecWay internet access
  20885. Source=Paul Collins Startup list
  20886.  
  20887. [farmmext]
  20888. Number=2966
  20889. Confirmed=X
  20890. Filename=farmmext.exe
  20891. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=VX2.Transponder&threatid=12517" target=_blank>VX2.Transponder</a> parasite updater/installer related
  20892. Source=Paul Collins Startup list
  20893.  
  20894. [Fash]
  20895. Number=2967
  20896. Confirmed=X
  20897. Filename=Fash.exe
  20898. Description=Unidentified adware
  20899. Source=Paul Collins Startup list
  20900.  
  20901. [fast]
  20902. Number=2968
  20903. Confirmed=N
  20904. Filename=fast.exe
  20905. Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
  20906. Source=Paul Collins Startup list
  20907.  
  20908. [FAST Defrag]
  20909. Number=2969
  20910. Confirmed=N
  20911. Filename=FAST2.EXE
  20912. Description=<a href="http://www.amsn.ro/" target="_blank">FastDefrag</a> defragmenting software
  20913. Source=Paul Collins Startup list
  20914.  
  20915. [Fast Home]
  20916. Number=2970
  20917. Confirmed=X
  20918. Filename=svcnvt.exe
  20919. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan-Downloader.Win32.Delf.ks This file may be found in the System folder on 9x machines, however as of this writing it has only been seen in the System32 folder
  20920. Source=Paul Collins Startup list
  20921.  
  20922. [Fast Search]
  20923. Number=2971
  20924. Confirmed=X
  20925. Filename=svcnv.exe
  20926. Description=Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf
  20927. Source=Paul Collins Startup list
  20928.  
  20929. [Fast start]
  20930. Number=2972
  20931. Confirmed=X
  20932. Filename=Ntut.exe
  20933. Description=Adware - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan.Win32.Favadd.I
  20934. Source=Paul Collins Startup list
  20935.  
  20936. [Fast start]
  20937. Number=2973
  20938. Confirmed=X
  20939. Filename=svcnt.exe
  20940. Description=Adware - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as a variant of the FAVADD TROJAN!
  20941. Source=Paul Collins Startup list
  20942.  
  20943. [FastCache]
  20944. Number=2974
  20945. Confirmed=U
  20946. Filename=fc.exe
  20947. Description=<a href="http://www.analogx.com/contents/download/network/fc.htm" target="_blank">FastCache</a> from AnalogX - speeds up browsing by resolving DNS requests locally
  20948. Source=Paul Collins Startup list
  20949.  
  20950. [FastStart]
  20951. Number=2975
  20952. Confirmed=X
  20953. Filename=ntnut32.exe
  20954. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031511-4645-99" target=_blank>STARTPAGE.L</a> TROJAN!
  20955. Source=Paul Collins Startup list
  20956.  
  20957. [FastStart]
  20958. Number=2976
  20959. Confirmed=X
  20960. Filename=svcnut.exe
  20961. Description=Browser hijacker - a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031511-4645-99" target=_blank>STARTPAGE.L</a> TROJAN!
  20962. Source=Paul Collins Startup list
  20963.  
  20964. [FastStart]
  20965. Number=2977
  20966. Confirmed=X
  20967. Filename=svcnut32.exe
  20968. Description=Browser hijacker - a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031511-4645-99" target=_blank>STARTPAGE.L</a> TROJAN!
  20969. Source=Paul Collins Startup list
  20970.  
  20971. [FastTrack Accelerator]
  20972. Number=2978
  20973. Confirmed=N
  20974. Filename=SPEED UP.EXE
  20975. Description=<a href="http://www.speedup.tk/" target="_blank">FastTrack Accelerator</a> - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus
  20976. Source=Paul Collins Startup list
  20977.  
  20978. [FASTTRACKNETVISION]
  20979. Number=2979
  20980. Confirmed=X
  20981. Filename=NETVISION.exe
  20982. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialdialcarz.html" target="_blank">DialCar-Z</a> premium rate dialer
  20983. Source=Paul Collins Startup list
  20984.  
  20985. [FastUser]
  20986. Number=2980
  20987. Confirmed=N
  20988. Filename=fast.exe
  20989. Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
  20990. Source=Paul Collins Startup list
  20991.  
  20992. [FastUsr]
  20993. Number=2981
  20994. Confirmed=N
  20995. Filename=fast.exe
  20996. Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
  20997. Source=Paul Collins Startup list
  20998.  
  20999. [FatPipe]
  21000. Number=2982
  21001. Confirmed=U
  21002. Filename=DHCP
  21003. Description=Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
  21004. Source=Paul Collins Startup list
  21005.  
  21006. [Fatpipe Dialer]
  21007. Number=2983
  21008. Confirmed=U
  21009. Filename=fpdialer.exe
  21010. Description=Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
  21011. Source=Paul Collins Startup list
  21012.  
  21013. [fatrecov]
  21014. Number=2984
  21015. Confirmed=U
  21016. Filename=fatrecov.exe
  21017. Description=SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
  21018.  
  21019. Source=Paul Collins Startup list
  21020.  
  21021. [FaxCenterServer]
  21022. Number=2985
  21023. Confirmed=U
  21024. Filename=fm3032.exe
  21025. Description=<a href="http://www.data-tech.com/content/fax.aspx" target=_blank>FaxMan</a> integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others
  21026. Source=Paul Collins Startup list
  21027.  
  21028. [FaxCtrl.exe]
  21029. Number=2986
  21030. Confirmed=U
  21031. Filename=ASMediaProxyServer.exe
  21032. Description=Part of Avaya's <a href="http://www.avaya.com/gcm/master-usa/en-us/products/offers/contactcenterexpress.htm" target="_blank">Contact Center Express</a> - "a multi-channel, high-volume software solution from Avaya designed specifically for the intelligent routing and computer telephony integration (CTI) needs of medium-sized contact centers"
  21033. Source=Paul Collins Startup list
  21034.  
  21035. [FaxTalk CallControl 6.0]
  21036. Number=2987
  21037. Confirmed=N
  21038. Filename=FTClCtrl.EXE
  21039. Description=This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
  21040. Source=Paul Collins Startup list
  21041.  
  21042. [FBDirect]
  21043. Number=2988
  21044. Confirmed=U
  21045. Filename=FBDirect.exe
  21046. Description=Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
  21047. Source=Paul Collins Startup list
  21048.  
  21049. [FBI]
  21050. Number=2989
  21051. Confirmed=?
  21052. Filename=FBISM.exe
  21053. Description=<font color="#FF0000">Compaq related but what does it do?</font>
  21054. Source=Paul Collins Startup list
  21055.  
  21056. [fc]
  21057. Number=2990
  21058. Confirmed=X
  21059. Filename=runfc.exe
  21060. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-010216-2213-99" target="_blank">CAMPURF</a> WORM!
  21061. Source=Paul Collins Startup list
  21062.  
  21063. [FCEngine]
  21064. Number=2991
  21065. Confirmed=X
  21066. Filename=FCEngine.exe
  21067. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ConsumerAlertSystem.CASClient&threatid=40038" target="_blank">CASClient</a> adware
  21068. Source=Paul Collins Startup list
  21069.  
  21070. [FCHelp]
  21071. Number=2992
  21072. Confirmed=X
  21073. Filename=FCHelp.exe
  21074. Description=Added by either <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-011109-4115-99" target=_blank>FCHelp</a> adware or a variant of it
  21075. Source=Paul Collins Startup list
  21076.  
  21077. [FCMan]
  21078. Number=2993
  21079. Confirmed=X
  21080. Filename=FCMan.exe
  21081. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-011109-4115-99" target="_blank">FCHelp</a> adware
  21082. Source=Paul Collins Startup list
  21083.  
  21084. [FDD SYSTEM]
  21085. Number=2994
  21086. Confirmed=X
  21087. Filename=Fdd.exe
  21088. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobfo.html" target=_blank>MYTOB-FO</a> WORM!
  21089. Source=Paul Collins Startup list
  21090.  
  21091. [Fdr Command Module]
  21092. Number=2995
  21093. Confirmed=X
  21094. Filename=sp2.exe
  21095. Description=Added by the <a href="http://www.virus-buster.com/en/viruslab/descriptions/sdbot.wp?VBSESSION=aa76c5b7d679e7a1eb5abe8b697fb08e" target=_blank>SDBOT.WP</a> WORM!
  21096. Source=Paul Collins Startup list
  21097.  
  21098. [FDriver]
  21099. Number=2996
  21100. Confirmed=X
  21101. Filename=windrv.exe
  21102. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DELF.WG" target="_blank">DELF.WG</a> TROJAN!
  21103. Source=Paul Collins Startup list
  21104.  
  21105. [FD_SAP]
  21106. Number=2997
  21107. Confirmed=U
  21108. Filename=FD.exe
  21109. Description=Reported to be the autopassword program from the Sony Microvault thumb drive
  21110. Source=Paul Collins Startup list
  21111.  
  21112. [feelalright]
  21113. Number=2998
  21114. Confirmed=X
  21115. Filename=mirc.exe
  21116. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32ircfloodm.html" target=_blank>IRCFLOOD-M</a> WORM!
  21117. Source=Paul Collins Startup list
  21118.  
  21119. [FEELitDeviceManager]
  21120. Number=2999
  21121. Confirmed=U
  21122. Filename=feelitdm.exe
  21123. Description=Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
  21124. Source=Paul Collins Startup list
  21125.  
  21126. [fegoze]
  21127. Number=3000
  21128. Confirmed=X
  21129. Filename=SVCH0ST.EXE
  21130. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-062811-4412-99" target=_blank>GRAYBIRD.D</a> VIRUS! Note - the filename has the digit 0 rather then the uppercase "o"
  21131. Source=Paul Collins Startup list
  21132.  
  21133. [Fellowes Proxy]
  21134. Number=3001
  21135. Confirmed=U
  21136. Filename=R3proxy.exe
  21137. Description=Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
  21138. Source=Paul Collins Startup list
  21139.  
  21140. [Fen Startups]
  21141. Number=3002
  21142. Confirmed=X
  21143. Filename=fensvc32.exe
  21144. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-122117-1029-99" target=_blank>RANDEX.CCF</a> WORM!
  21145. Source=Paul Collins Startup list
  21146.  
  21147. [FerrariWallPaper]
  21148. Number=3003
  21149. Confirmed=U
  21150. Filename=FerrariWP.exe
  21151. Description=Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
  21152. Source=Paul Collins Startup list
  21153.  
  21154. [ffis]
  21155. Number=3004
  21156. Confirmed=X
  21157. Filename=ffisearch.exe
  21158. Description=<a href="http://vil.nai.com/vil/content/v_133320.htm" target="_blank">iSearch</a> "Desktop Search" hijacker
  21159. Source=Paul Collins Startup list
  21160.  
  21161. [FG1_00]
  21162. Number=3005
  21163. Confirmed=U
  21164. Filename=frntgate.exe
  21165. Description=<a href="http://www.presorium.com/en_au/products/fg/index.shtml" target="_blank">FrontGate MX</a> - e-mail spam blocker
  21166. Source=Paul Collins Startup list
  21167.  
  21168. [fGQEGqHOME]
  21169. Number=3006
  21170. Confirmed=X
  21171. Filename=gwwgtp.exe
  21172. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-102813-3829-99" target=_blank>RANKY.J</a> TROJAN!
  21173. Source=Paul Collins Startup list
  21174.  
  21175. [FHPage]
  21176. Number=3007
  21177. Confirmed=X
  21178. Filename=shdochp.exe
  21179. Description=Added by the <a href="http://www.pctools.com/mrc/infections/id/Trojan.Downloader.Delf.KS/" target=_blank>DELF-Ks</a> TROJAN!
  21180. Source=Paul Collins Startup list
  21181.  
  21182. [FHStart]
  21183. Number=3008
  21184. Confirmed=X
  21185. Filename=shdocsvc.exe
  21186. Description=Added by the <a href="http://www.pctools.com/mrc/infections/id/Trojan.Downloader.Delf.KS/" target=_blank>DELF-Ks</a> TROJAN!
  21187. Source=Paul Collins Startup list
  21188.  
  21189. [Fhtisxk]
  21190. Number=3009
  21191. Confirmed=U
  21192. Filename=fhtisxk.exe
  21193. Description=XtraKeys keystroke logger/monitoring program - remove unless you installed it yourself!
  21194.  
  21195. Source=Paul Collins Startup list
  21196.  
  21197. [FieldForms Sync]
  21198. Number=3010
  21199. Confirmed=U
  21200. Filename=SyncService.exe
  21201. Description=Resco <a href="http://www.resco.net/pocketpc/fieldforms/default.asp" target="_blank">FieldForms</a>. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well
  21202. Source=Paul Collins Startup list
  21203.  
  21204. [FiendlyType]
  21205. Number=3011
  21206. Confirmed=X
  21207. Filename=csrss.exe
  21208. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091409-4900-99" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
  21209. Source=Paul Collins Startup list
  21210.  
  21211. [FILE]
  21212. Number=3012
  21213. Confirmed=X
  21214. Filename=abcdefg.exe
  21215. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061416-3817-99" target=_blank>KELVIR.DD</a> WORM!
  21216. Source=Paul Collins Startup list
  21217.  
  21218. [file indexing service]
  21219. Number=3013
  21220. Confirmed=?
  21221. Filename=msfindfile.exe
  21222. Description=<font color="#FF0000">New version of MS FindFast and still a resource hog?</font>
  21223. Source=Paul Collins Startup list
  21224.  
  21225. [file laoder configuration]
  21226. Number=3014
  21227. Confirmed=X
  21228. Filename=rnd32.exe
  21229. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BQJ&VSect=T" target=_blank>RBOT.BQJ</a> WORM!
  21230. Source=Paul Collins Startup list
  21231.  
  21232. [File System]
  21233. Number=3015
  21234. Confirmed=X
  21235. Filename=taskmqrs.exe
  21236. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=41911" target=_blank>TOXBOT/CODBOT</a> WORM!
  21237. Source=Paul Collins Startup list
  21238.  
  21239. [File System]
  21240. Number=3016
  21241. Confirmed=X
  21242. Filename=taskmqr.exe
  21243. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BWQ" target="_blank">RBOT.BWQ</a> WORM!
  21244. Source=Paul Collins Startup list
  21245.  
  21246. [File System Service]
  21247. Number=3017
  21248. Confirmed=X
  21249. Filename=wmiprvsc.exe
  21250. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagobothz.html" target="_blank">AGOBOT-HZ</a> TROJAN!
  21251. Source=Paul Collins Startup list
  21252.  
  21253. [File0_0]
  21254. Number=3018
  21255. Confirmed=X
  21256. Filename=MD1.exe
  21257. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderor.html" target=_blank>DLOADER-OR</a> TROJAN!
  21258. Source=Paul Collins Startup list
  21259.  
  21260. [File1]
  21261. Number=3019
  21262. Confirmed=X
  21263. Filename=Dia Claro.htm
  21264. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderor.html" target=_blank>DLOADER-OR</a> TROJAN!
  21265. Source=Paul Collins Startup list
  21266.  
  21267. [FileFreedom_Plugin]
  21268. Number=3020
  21269. Confirmed=X
  21270. Filename=wtm.exe
  21271. Description=<a href="http://www.filefreedom.com/" target="_blank">FileFreedom</a> peer-to-peer sharing program
  21272. Source=Paul Collins Startup list
  21273.  
  21274. [FileManager32]
  21275. Number=3021
  21276. Confirmed=X
  21277. Filename=Wscript.exe ..ChkMgr32.vbs
  21278. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-101510-3740-99" target="_blank">NOTUP.A</a> WORM!
  21279. Source=Paul Collins Startup list
  21280.  
  21281. [FileSoft]
  21282. Number=3022
  21283. Confirmed=X
  21284. Filename=Wscript.exe UpdataFiles.vbs
  21285. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-033112-4827-99" target="_blank">SST.B</a> WORM!
  21286. Source=Paul Collins Startup list
  21287.  
  21288. [FilmLoop]
  21289. Number=3023
  21290. Confirmed=U
  21291. Filename=FilmLoopService.exe
  21292. Description=Related to <a href="http://www.filmloop.com/" target=_blank>FilmLoop</a> - a photocasting network. Share your pictures with your family and friends
  21293. Source=Paul Collins Startup list
  21294.  
  21295. [FilterGate]
  21296. Number=3024
  21297. Confirmed=U
  21298. Filename=filtergate.exe
  21299. Description=<a href="http://www.filtergate.com/" target="_blank">Filtergate</a> internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items
  21300. Source=Paul Collins Startup list
  21301.  
  21302. [Filterguard]
  21303. Number=3025
  21304. Confirmed=U
  21305. Filename=Filtrgrd.exe
  21306. Description=An icon located in the lower left of the screen and looks like a lifesaver. This icon is a "short-cut" to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by "right-clicking" on the icon
  21307. Source=Paul Collins Startup list
  21308.  
  21309. [Find]
  21310. Number=3026
  21311. Confirmed=X
  21312. Filename=find.exe
  21313. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051810-1834-99" target=_blank>OPANKI</a> WORM!
  21314. Source=Paul Collins Startup list
  21315.  
  21316. [Find Fast]
  21317. Number=3027
  21318. Confirmed=X
  21319. Filename=Findfast.exe
  21320. Description=Complete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier
  21321. Source=Paul Collins Startup list
  21322.  
  21323. [Find Virus Launch Program]
  21324. Number=3028
  21325. Confirmed=Y
  21326. Filename=fvlaunch.exe
  21327. Description=Part of <a target="_blank" href="http://www.drsolomon.com/">Dr. Solomon's Antivirus</a>
  21328. Source=Paul Collins Startup list
  21329.  
  21330. [FindHack]
  21331. Number=3029
  21332. Confirmed=X
  21333. Filename=[path to trojan]
  21334. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32kelvirba.html" target=_blank>KELVIR-BA</a> TROJAN!
  21335. Source=Paul Collins Startup list
  21336.  
  21337. [FinePrint Dispatcher v4]
  21338. Number=3030
  21339. Confirmed=U
  21340. Filename=fpdisp4a.exe
  21341. Description=<a href="http://www.fineprint.com/products/fineprint/index.html" target="_blank">FinePrint</a> Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output"
  21342. Source=Paul Collins Startup list
  21343.  
  21344. [FinePrint Dispatcher v4]
  21345. Number=3031
  21346. Confirmed=U
  21347. Filename=fpdisp4.exe
  21348. Description=<a href="http://www.fineprint.com/products/fineprint/index.html" target="_blank">FinePrint</a> Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output"
  21349. Source=Paul Collins Startup list
  21350.  
  21351. [FinePrint Dispatcher v5]
  21352. Number=3032
  21353. Confirmed=U
  21354. Filename=fpdisp5a.exe
  21355. Description=<a href="http://www.fineprint.com/products/fineprint/index.html" target="_blank">FinePrint</a> Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output"
  21356. Source=Paul Collins Startup list
  21357.  
  21358. [FineReader7NewsReaderPro]
  21359. Number=3033
  21360. Confirmed=N
  21361. Filename=AbbyyNewsReader.exe
  21362. Description=ABBYY <a href="http://www.abbyy.com/finereader8/?param=44890" target="_blank">FineReader</a> OCR software - version 7
  21363. Source=Paul Collins Startup list
  21364.  
  21365. [Fire Wall services]
  21366. Number=3034
  21367. Confirmed=X
  21368. Filename=[random filename]
  21369. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32ircbotqy.html" target="_blank">IRCBOT-QY</a> WORM!
  21370. Source=Paul Collins Startup list
  21371.  
  21372. [FireFox]
  21373. Number=3035
  21374. Confirmed=X
  21375. Filename=firefox.exe
  21376. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotatp.html" target=_blank>RBOT-ATP</a> WORM! Note - this is not the popular <a href="http://www.mozilla.com/firefox/" target=_blank>FireFox</a> web browser and is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  21377. Source=Paul Collins Startup list
  21378.  
  21379. [FireFox Service Drivers]
  21380. Number=3036
  21381. Confirmed=X
  21382. Filename=ssmss.exe
  21383. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  21384. Source=Paul Collins Startup list
  21385.  
  21386. [FireFox Startup Drivers]
  21387. Number=3037
  21388. Confirmed=X
  21389. Filename=wuaclt.exe
  21390. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BYX&VSect=T" target=_blank>RBOT.BYX</a> WORM!
  21391. Source=Paul Collins Startup list
  21392.  
  21393. [firefox.exe]
  21394. Number=3038
  21395. Confirmed=X
  21396. Filename=firefox.exe
  21397. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerebo.html" target="_blank">BANKER-EBO</a> TROJAN! Note - this is not the popular <a href="http://www.mozilla.com/firefox/" target="_blank">FireFox</a> web browser and is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  21398. Source=Paul Collins Startup list
  21399.  
  21400. [Firewall]
  21401. Number=3039
  21402. Confirmed=X
  21403. Filename= wmlaunch .exe
  21404. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022718-0647-99" target= blank>ELIPTER.A</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031010-2242-99" target= blank>ELIPTER.B</a> WORMS!
  21405. Source=Paul Collins Startup list
  21406.  
  21407. [Firewall]
  21408. Number=3040
  21409. Confirmed=X
  21410. Filename=wmlaunch .exe
  21411. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031416-4252-99" target=_blank>ELIPTER.D</a> WORM!
  21412. Source=Paul Collins Startup list
  21413.  
  21414. [Firewall]
  21415. Number=3041
  21416. Confirmed=X
  21417. Filename=SP2 UPDATE.exe
  21418. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-032516-4935-99" target=_blank>ELITPER.E</a> WORM!
  21419. Source=Paul Collins Startup list
  21420.  
  21421. [Firewall]
  21422. Number=3042
  21423. Confirmed=X
  21424. Filename=Firewall.bat
  21425. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-061716-0240-99" target=_blank>YPSAN.G</a> WORM!
  21426. Source=Paul Collins Startup list
  21427.  
  21428. [firewall]
  21429. Number=3043
  21430. Confirmed=X
  21431. Filename=fw_304.exe
  21432. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorjq.html" target=_blank>JQ</a> TROJAN!
  21433. Source=Paul Collins Startup list
  21434.  
  21435. [Firewall auto setup]
  21436. Number=3044
  21437. Confirmed=X
  21438. Filename=winlogon.exe
  21439. Description=Added by a TROJAN - see <a href="http://sandbox.norman.no/live_2.html?logfile=1368956" target="_blank">here</a>. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
  21440. Source=Paul Collins Startup list
  21441.  
  21442. [Firewall Policy]
  21443. Number=3045
  21444. Confirmed=X
  21445. Filename=MidiDef32.exe
  21446. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpiebota.html" target=_blank>PIEBOT-A</a> TROJAN!
  21447. Source=Paul Collins Startup list
  21448.  
  21449. [Firewall Sp2 system]
  21450. Number=3046
  21451. Confirmed=X
  21452. Filename=sys32Conf.exe
  21453. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotabt.html" target= blank>Rbot-ABT</a> WORM!
  21454. Source=Paul Collins Startup list
  21455.  
  21456. [Firewall Update System1]
  21457. Number=3047
  21458. Confirmed=X
  21459. Filename=WinedowsUpdater1.exe
  21460. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaru.html" target=_blank>RBOT-ARU</a> WORM!
  21461. Source=Paul Collins Startup list
  21462.  
  21463. [Firewall Updater]
  21464. Number=3048
  21465. Confirmed=X
  21466. Filename=msnupdateit.exe
  21467. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaaq.html" target=_blank>RBOT-AAQ</a> WORM!
  21468. Source=Paul Collins Startup list
  21469.  
  21470. [Firewall.exe]
  21471. Number=3049
  21472. Confirmed=X
  21473. Filename=Firewall.exe
  21474. Description=Added by the AGENT.AGL WORM!
  21475. Source=Paul Collins Startup list
  21476.  
  21477. [FirewallActivies]
  21478. Number=3050
  21479. Confirmed=X
  21480. Filename=csrss.exe
  21481. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankeraq.html" target=_blank>BANKER-AQ</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "3041" subfolder
  21482. Source=Paul Collins Startup list
  21483.  
  21484. [FirewallStartup]
  21485. Number=3051
  21486. Confirmed=U
  21487. Filename=Firewallstartup.exe
  21488. Description=<a href="http://www.innovative-sol.com/products.htm#firewall" target=_blank>Innovative Startup Firewall</a> - "designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean, fast and in it's best shape"
  21489. Source=Paul Collins Startup list
  21490.  
  21491. [FirewallSvr]
  21492. Number=3052
  21493. Confirmed=X
  21494. Filename=FirewallSvr.exe
  21495. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042010-3056-99" target="_blank">NETSKY.X</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042011-2621-99" target="_blank">NETSKY.Y</a> WORMS!
  21496. Source=Paul Collins Startup list
  21497.  
  21498. [firewall_anti]
  21499. Number=3053
  21500. Confirmed=X
  21501. Filename=firewall_anti.exe
  21502. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojnetdenyb.html" target=_blank>NETDENY-B</a> TROJAN!
  21503. Source=Paul Collins Startup list
  21504.  
  21505. [FireWire Driver]
  21506. Number=3054
  21507. Confirmed=X
  21508. Filename=samx.exe
  21509. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-102512-0820-99" target=_blank>SDBOT.AE</a> WORM!
  21510. Source=Paul Collins Startup list
  21511.  
  21512. [FireWire Service]
  21513. Number=3055
  21514. Confirmed=X
  21515. Filename=nvscv32.exe
  21516. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  21517. Source=Paul Collins Startup list
  21518.  
  21519. [FireWire Services]
  21520. Number=3056
  21521. Confirmed=X
  21522. Filename=nvcsv32.exe
  21523. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-053013-5943-99" target="_blank">SPYBOT</a> WORM!
  21524. Source=Paul Collins Startup list
  21525.  
  21526. [First Home Page]
  21527. Number=3057
  21528. Confirmed=X
  21529. Filename=http://find.naupoint.com
  21530. Description=<a href="http://www.spynet.com/spyware/spyware-NauPoint-Installer.aspx" target=_blank>Naupoint</a> browser hijacker
  21531. Source=Paul Collins Startup list
  21532.  
  21533. [FIX]
  21534. Number=3058
  21535. Confirmed=X
  21536. Filename=WinFIX1.0.vbs
  21537. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/vbsgormleza.html" target=_blank>GORMLEZ-A</a> WORM!
  21538. Source=Paul Collins Startup list
  21539.  
  21540. [Fix-it]
  21541. Number=3059
  21542. Confirmed=Y
  21543. Filename=mxtask.exe
  21544. Description=Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required
  21545. Source=Paul Collins Startup list
  21546.  
  21547. [Fix-it AV]
  21548. Number=3060
  21549. Confirmed=Y
  21550. Filename=memcheck.exe
  21551. Description=Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
  21552. Source=Paul Collins Startup list
  21553.  
  21554. [FjMenu]
  21555. Number=3061
  21556. Confirmed=U
  21557. Filename=FjMenu.exe
  21558. Description=From the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable
  21559. Source=Paul Collins Startup list
  21560.  
  21561. [FJTWAIN Setup]
  21562. Number=3062
  21563. Confirmed=U
  21564. Filename=FjtwSetup.exe
  21565. Description=Fujitsu scanner utility
  21566. Source=Paul Collins Startup list
  21567.  
  21568. [FKS v2.0]
  21569. Number=3063
  21570. Confirmed=X
  21571. Filename=msngr.exe
  21572. Description=Added by an unidentified WORM or TROJAN!
  21573. Source=Paul Collins Startup list
  21574.  
  21575. [fkSysMon]
  21576. Number=3064
  21577. Confirmed=N
  21578. Filename=fksysmon.exe
  21579. Description=<a href="http://www.fkware.com/sysmon/index.html" target="_blank">fkWrae SysMon</a> - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more"
  21580. Source=Paul Collins Startup list
  21581.  
  21582. [FlaCPY]
  21583. Number=3065
  21584. Confirmed=X
  21585. Filename=flacpy.exe
  21586. Description=<a href="http://sarc.com/avcenter/venc/data/adware.flashenhancer.html" target=_blank>FlashEnhancer</a> adware variant
  21587. Source=Paul Collins Startup list
  21588.  
  21589. [FLASH32]
  21590. Number=3066
  21591. Confirmed=?
  21592. Filename=-flash32.exe
  21593. Description=<font color="#FF0000">??</font>
  21594. Source=Paul Collins Startup list
  21595.  
  21596. [FlashEnc]
  21597. Number=3067
  21598. Confirmed=U
  21599. Filename=FlashEnc.exe
  21600. Description=Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission, which is a pain. No need for it if you do not want these features
  21601. Source=Paul Collins Startup list
  21602.  
  21603. [Flashget Download Manager]
  21604. Number=3068
  21605. Confirmed=X
  21606. Filename=Flashget.exe
  21607. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotagz.html" target=_blank>RBOT-AGZ</a> WORM!
  21608. Source=Paul Collins Startup list
  21609.  
  21610. [FlashPath Monitor]
  21611. Number=3069
  21612. Confirmed=N
  21613. Filename=SDSTAT.EXE
  21614. Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
  21615. Source=Paul Collins Startup list
  21616.  
  21617. [FlashPath Monitor]
  21618. Number=3070
  21619. Confirmed=N
  21620. Filename=FLSHSTAT.EXE
  21621. Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
  21622. Source=Paul Collins Startup list
  21623.  
  21624. [FlashPath Status]
  21625. Number=3071
  21626. Confirmed=N
  21627. Filename=SDSTAT.EXE
  21628. Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
  21629. Source=Paul Collins Startup list
  21630.  
  21631. [FlashPath Status]
  21632. Number=3072
  21633. Confirmed=N
  21634. Filename=FLSHSTAT.EXE
  21635. Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
  21636. Source=Paul Collins Startup list
  21637.  
  21638. [Flash_Player_Install]
  21639. Number=3073
  21640. Confirmed=X
  21641. Filename=ying.exe
  21642. Description=<a href="http://fileinfo.prevx.com/fileinfo.asp?PXC=a7c073784121" target="_blank">Constructor VC2000</a> malware
  21643. Source=Paul Collins Startup list
  21644.  
  21645. [FlenCPY]
  21646. Number=3074
  21647. Confirmed=X
  21648. Filename=flencpy.exe
  21649. Description=<a href="http://sarc.com/avcenter/venc/data/adware.flashenhancer.html" target=_blank>FlashEnhancer</a> adware variant
  21650. Source=Paul Collins Startup list
  21651.  
  21652. [Flexicd]
  21653. Number=3075
  21654. Confirmed=U
  21655. Filename=Flexicd.exe
  21656. Description=CD player - part of the <a href="http://www.microsoft.com/windows95/downloads/contents/WUToys/W95PwrToysSet/Default.asp" target="_blank">Win95 Power Toys</a>
  21657. Source=Paul Collins Startup list
  21658.  
  21659. [FLMK08KB]
  21660. Number=3076
  21661. Confirmed=U
  21662. Filename=MMKEYBD.EXE
  21663. Description=Multimedia keyboard manager. Required if you use the additional keys
  21664. Source=Paul Collins Startup list
  21665.  
  21666. [FLMOFFICE4DMOUSE]
  21667. Number=3077
  21668. Confirmed=U
  21669. Filename=moffice.exe
  21670. Description=<a href="http://www.mic-innovations.com/display.cfm?id=Mice" target="_blank">Micro Innovations</a> mouse management
  21671. Source=Paul Collins Startup list
  21672.  
  21673. [FLMOFFICE4DMOUSE]
  21674. Number=3078
  21675. Confirmed=U
  21676. Filename=mouse32a.exe
  21677. Description=<a href="http://www.mic-innovations.com/display.cfm?id=Mice" target="_blank">Micro Innovations</a> mouse management
  21678. Source=Paul Collins Startup list
  21679.  
  21680. [FLMTRUSTKB]
  21681. Number=3079
  21682. Confirmed=?
  21683. Filename=KbdAp32A.exe
  21684. Description=Keyboard utility for a Trust brand keyboard.<font color="#FF0000"> What does it do and is it required?</font>
  21685. Source=Paul Collins Startup list
  21686.  
  21687. [FLMTRUSTMOUSE]
  21688. Number=3080
  21689. Confirmed=U
  21690. Filename=mouse32a.exe
  21691. Description=Mouse utility for a Trust brand mouse
  21692. Source=Paul Collins Startup list
  21693.  
  21694. [FlnCPY]
  21695. Number=3081
  21696. Confirmed=X
  21697. Filename=flncpy.exe
  21698. Description=<a href="http://sarc.com/avcenter/venc/data/adware.flashenhancer.html" target= blank>FlashEnhancer</a> adware variant
  21699. Source=Paul Collins Startup list
  21700.  
  21701. [FLooDNeT]
  21702. Number=3082
  21703. Confirmed=X
  21704. Filename=FLooDeR.exe
  21705. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-110116-4108-99" target="_blank">ENDOOL</a> TROJAN!
  21706. Source=Paul Collins Startup list
  21707.  
  21708. [Floppy Master]
  21709. Number=3083
  21710. Confirmed=X
  21711. Filename=[path to trojan]
  21712. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojzonitf.html" target=_blank>ZONIT-F</a> TROJAN!
  21713. Source=Paul Collins Startup list
  21714.  
  21715. [Flow Go TV]
  21716. Number=3084
  21717. Confirmed=?
  21718. Filename=flogotv.exe
  21719. Description=<font color="#FF0000">??</font>
  21720. Source=Paul Collins Startup list
  21721.  
  21722. [flps]
  21723. Number=3085
  21724. Confirmed=X
  21725. Filename=flps.vbs
  21726. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-111314-3449-99" target="_blank">BYRON</a> WORM!
  21727. Source=Paul Collins Startup list
  21728.  
  21729. [flpycntl]
  21730. Number=3086
  21731. Confirmed=X
  21732. Filename=flpycntl.exe
  21733. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  21734. Source=Paul Collins Startup list
  21735.  
  21736. [FLSVCI]
  21737. Number=3087
  21738. Confirmed=?
  21739. Filename=FLSVCI.exe
  21740. Description=<font color="#FF0000">??</font>
  21741. Source=Paul Collins Startup list
  21742.  
  21743. [FltProcess]
  21744. Number=3088
  21745. Confirmed=Y
  21746. Filename=msinet.exe
  21747. Description=Part of <a href="http://www.cyberpatrol.com/">Cyber Patrol</a> internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done
  21748. Source=Paul Collins Startup list
  21749.  
  21750. [FlyswatDesktop]
  21751. Number=3089
  21752. Confirmed=X
  21753. Filename=flydesk.exe
  21754. Description=Advertising spyware
  21755. Source=Paul Collins Startup list
  21756.  
  21757. [FmctrlTray]
  21758. Number=3090
  21759. Confirmed=U
  21760. Filename=Fmctrl.EXE
  21761. Description=Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
  21762. Source=Paul Collins Startup list
  21763.  
  21764. [fmnwebassist]
  21765. Number=3091
  21766. Confirmed=X
  21767. Filename=fmnwebassist.exe
  21768. Description=Adware popup generator
  21769. Source=Paul Collins Startup list
  21770.  
  21771. [FMStart]
  21772. Number=3092
  21773. Confirmed=U
  21774. Filename=Fmstart.exe
  21775. Description=<a href="http://www.gfi.com/faxmaker/" target="_blank">GFI FAXmaker</a> - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop
  21776. Source=Paul Collins Startup list
  21777.  
  21778. [FMSZ]
  21779. Number=3093
  21780. Confirmed=X
  21781. Filename=fmsz.exe
  21782. Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453079140" target="_blank">FMSZ</a> TROJAN!
  21783. Source=Paul Collins Startup list
  21784.  
  21785. [fnmwebassist]
  21786. Number=3094
  21787. Confirmed=X
  21788. Filename=fnmwebassist.exe
  21789. Description=<a href="http://allentech.net/parasite/WinPL.html" target="_blank">WinPL</a> adware
  21790.  
  21791. Source=Paul Collins Startup list
  21792.  
  21793. [Focus]
  21794. Number=3095
  21795. Confirmed=?
  21796. Filename=Focus.exe
  21797. Description=<font color="#FF0000">ISDN configuration wizard?</font>
  21798. Source=Paul Collins Startup list
  21799.  
  21800. [Folder Service]
  21801. Number=3096
  21802. Confirmed=X
  21803. Filename=wssdtu.exe
  21804. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-112614-4025-99" target="_blank">MANIFEST</a> TROJAN!
  21805. Source=Paul Collins Startup list
  21806.  
  21807. [Folder View]
  21808. Number=3097
  21809. Confirmed=U
  21810. Filename=folderview.exe
  21811. Description=<a href="http://www.folderview.com/folderview/" target=_blank>Folder View</a> enhances the Windows file Explorer by making all folders you need available in a single click
  21812. Source=Paul Collins Startup list
  21813.  
  21814. [FolderClone v*.*.*]
  21815. Number=3098
  21816. Confirmed=U
  21817. Filename=folderclone.exe
  21818. Description=<a href="http://www.folderclone.com/fcinfo.htm" target=_blank>Folderclone</a> backup and synchronization software
  21819. Source=Paul Collins Startup list
  21820.  
  21821. [Folding@home]
  21822. Number=3099
  21823. Confirmed=N
  21824. Filename=WINFAH.EXE
  21825. Description=Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
  21826. Source=Paul Collins Startup list
  21827.  
  21828. [FoneSyncSystemTray]
  21829. Number=3100
  21830. Confirmed=N
  21831. Filename=FoneSyncSystemTray.exe
  21832. Description=System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
  21833. Source=Paul Collins Startup list
  21834.  
  21835. [FontFix]
  21836. Number=3101
  21837. Confirmed=X
  21838. Filename=fontfix.exe
  21839. Description=Added by an unidentified VIRUS, WORM or TROJAN!
  21840. Source=Paul Collins Startup list
  21841.  
  21842. [fontnav]
  21843. Number=3102
  21844. Confirmed=N
  21845. Filename=FontNav.exe
  21846. Description=Font Navigator from <a href="http://www.bitstream.com/" target=_blank>Bitstream Inc.</a> - a font management utility
  21847. Source=Paul Collins Startup list
  21848.  
  21849. [FontsLoader]
  21850. Number=3103
  21851. Confirmed=X
  21852. Filename=ldfnt32.hta
  21853. Description=Unidentified malware
  21854. Source=Paul Collins Startup list
  21855.  
  21856. [FONTVIEW]
  21857. Number=3104
  21858. Confirmed=X
  21859. Filename=FONTVIEW.EXE
  21860. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
  21861. Source=Paul Collins Startup list
  21862.  
  21863. [FooBar 1.0]
  21864. Number=3105
  21865. Confirmed=U
  21866. Filename=FooBar.exe
  21867. Description=<a href="http://matrixsoftware.com/" target="_blank">FooBar</a> - "combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"
  21868. Source=Paul Collins Startup list
  21869.  
  21870. [foobin lptt01]
  21871. Number=3106
  21872. Confirmed=X
  21873. Filename=adaware.exe
  21874. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "foo1" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  21875. Source=Paul Collins Startup list
  21876.  
  21877. [foobin ml097e]
  21878. Number=3107
  21879. Confirmed=X
  21880. Filename=adaware.exe
  21881. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "foo1" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  21882. Source=Paul Collins Startup list
  21883.  
  21884. [FoolProof]
  21885. Number=3108
  21886. Confirmed=Y
  21887. Filename=fpwinldr.exe
  21888. Description=<a href="http://www.smartstuff.com/fps/fpsinfo.html" target="_blank">FoolProof Security</a> PC security software from SmartStuff
  21889. Source=Paul Collins Startup list
  21890.  
  21891. [FoolProofSweep]
  21892. Number=3109
  21893. Confirmed=Y
  21894. Filename=??
  21895. Description=Part of <a href="http://www.smartstuff.com/fps/fpsinfo.html" target="_blank">FoolProof Security</a> PC security software from SmartStuff
  21896. Source=Paul Collins Startup list
  21897.  
  21898. [Forbes]
  21899. Number=3110
  21900. Confirmed=N
  21901. Filename=ForbesAlerts.exe
  21902. Description=Forbes Business News Alerts - displays business news headlines in a little window on the screen
  21903. Source=Paul Collins Startup list
  21904.  
  21905. [ForceShow]
  21906. Number=3111
  21907. Confirmed=X
  21908. Filename=rundll32.exe QaBar.dll, ForceShowBar
  21909. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=AdultLinks.QBar&threatid=10158" target=_blank>AdultLinks.QBar</a> parasite related
  21910. Source=Paul Collins Startup list
  21911.  
  21912. [Forget Me Not]
  21913. Number=3112
  21914. Confirmed=N
  21915. Filename=AGRemind.exe
  21916. Description=Calendar reminder part of <a href="http://www.broderbund.com/SubCategory.asp?CID=107" target="_blank">Broderbund's</a> American Greetings« CreataCard«
  21917. Source=Paul Collins Startup list
  21918.  
  21919. [FortiClient]
  21920. Number=3113
  21921. Confirmed=X
  21922. Filename=FortiClient.exe
  21923. Description=<a href="http://www.fortinet.com/" target="_blank">Fortinet</a> security systems are the new generation of real time network protection systems
  21924. Source=Paul Collins Startup list
  21925.  
  21926. [Fortis Secure Layer Config]
  21927. Number=3114
  21928. Confirmed=U
  21929. Filename=cseinst.exe
  21930. Description=Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
  21931. Source=Paul Collins Startup list
  21932.  
  21933. [FotoStation Easy AutoLaunch]
  21934. Number=3115
  21935. Confirmed=N
  21936. Filename=FotoStation Easy AutoLaunch.exe
  21937. Description=Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
  21938. Source=Paul Collins Startup list
  21939.  
  21940. [Foul PX]
  21941. Number=3116
  21942. Confirmed=U
  21943. Filename=FoulPX.exe
  21944. Description=Foul PX, Optusnet usage stat checker
  21945. Source=Paul Collins Startup list
  21946.  
  21947. [FourthDay]
  21948. Number=3117
  21949. Confirmed=U
  21950. Filename=FourthDay.exe
  21951. Description=<a href="http://www.starstonesoftware.com/fourthday.htm" target="_blank">The Fourth Day</a> - "astronomical clock and almanac for your system tray"
  21952. Source=Paul Collins Startup list
  21953.  
  21954. [foxdh]
  21955. Number=3118
  21956. Confirmed=X
  21957. Filename=foxdhend.exe
  21958. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-063015-2354-99" target=_blank>MENGHUAN</a> TROJAN!
  21959. Source=Paul Collins Startup list
  21960.  
  21961. [foxdh]
  21962. Number=3119
  21963. Confirmed=X
  21964. Filename=foxdh.exe
  21965. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojgwghostq.html" target=_blank>GWGHOST-Q</a> TROJAN!
  21966. Source=Paul Collins Startup list
  21967.  
  21968. [foxrxjh]
  21969. Number=3120
  21970. Confirmed=X
  21971. Filename=foxrxjh.exe
  21972. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojgwghostt.html" target=_blank>GWGHOST-T</a> TROJAN!
  21973. Source=Paul Collins Startup list
  21974.  
  21975. [foxwudy9912]
  21976. Number=3121
  21977. Confirmed=X
  21978. Filename=service.exe
  21979. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancosbt.html" target= blank>BANCOS-BT</a> TROJAN!
  21980. Source=Paul Collins Startup list
  21981.  
  21982. [FP Loader]
  21983. Number=3122
  21984. Confirmed=Y
  21985. Filename=loadfp.exe
  21986. Description=<a href="http://www.smartstuff.com/fps/fpsinfo.html" target="_blank">FoolProof Security</a> - PC security software from SmartStuff
  21987. Source=Paul Collins Startup list
  21988.  
  21989. [FPWGMWZD]
  21990. Number=3123
  21991. Confirmed=?
  21992. Filename=FPWGMWZD.exe
  21993. Description=<font color="#FF0000">??</font>
  21994. Source=Paul Collins Startup list
  21995.  
  21996. [Fpx]
  21997. Number=3124
  21998. Confirmed=N
  21999. Filename=mnmsrvc.exe
  22000. Description=Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
  22001. Source=Paul Collins Startup list
  22002.  
  22003. [fqor]
  22004. Number=3125
  22005. Confirmed=X
  22006. Filename=stub_113_4_0_4_0.exe
  22007. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=TargetSaver&threatid=15121" target=_blank>TargetSaver</a> adware
  22008.  
  22009. Source=Paul Collins Startup list
  22010.  
  22011. [FrameWork 2.5]
  22012. Number=3126
  22013. Confirmed=X
  22014. Filename=FrameWork.exe
  22015. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfmw.html" target="_blank">RBOT-FMW</a> WORM! Note - can terminate AV related processes
  22016. Source=Paul Collins Startup list
  22017.  
  22018. [France]
  22019. Number=3127
  22020. Confirmed=X
  22021. Filename=svchost.exe
  22022. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-120112-2230-99" target=_blank>MIMAIL.L</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  22023. Source=Paul Collins Startup list
  22024.  
  22025. [Fraps]
  22026. Number=3128
  22027. Confirmed=U
  22028. Filename=fraps.exe
  22029. Description=Fraps Real-Time Video Capture software
  22030. Source=Paul Collins Startup list
  22031.  
  22032. [Free Download Manager]
  22033. Number=3129
  22034. Confirmed=N
  22035. Filename=fdm.exe
  22036. Description="Free Download Manager" - see <a href="http://www.freedownloadmanager.org/" target="_blank">here</a>
  22037. Source=Paul Collins Startup list
  22038.  
  22039. [Free Downloads Monitor]
  22040. Number=3130
  22041. Confirmed=?
  22042. Filename=fdcmon.exe
  22043. Description=<font color="#FF0000">??</font>
  22044. Source=Paul Collins Startup list
  22045.  
  22046. [Free Ram Optimizer]
  22047. Number=3131
  22048. Confirmed=U
  22049. Filename=fro.exe
  22050. Description=<a href="http://www.acelogix.com/freeware.html" target=_blank>Free Ram Optimizer</a> monitors your memory, and frees up ram if it falls below a certain minimum. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/ME. See <a href="http://aumha.org/win4/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
  22051. Source=Paul Collins Startup list
  22052.  
  22053. [Freedom]
  22054. Number=3132
  22055. Confirmed=Y
  22056. Filename=Freedom.exe
  22057. Description=<a href="http://www.freedom.net/" target="_blank">Freedom</a> Internet Security & Privacy - anti-virus, personal firewall and parental control. It also blocks ads, safeguards your personal information, encrypts your passwords, and much more. No longer available for sale
  22058. Source=Paul Collins Startup list
  22059.  
  22060. [FreeMem Pro]
  22061. Number=3133
  22062. Confirmed=U
  22063. Filename=FMEMPRO.EXE
  22064. Description=FreeMem Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See <a href="http://aumha.org/win4/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
  22065. Source=Paul Collins Startup list
  22066.  
  22067. [FreeMemVn2]
  22068. Number=3134
  22069. Confirmed=U
  22070. Filename=FreeMem.exe
  22071. Description=FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See <a href="http://aumha.org/win4/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
  22072. Source=Paul Collins Startup list
  22073.  
  22074. [FreeMP3download]
  22075. Number=3135
  22076. Confirmed=X
  22077. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  22078. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  22079. Source=Paul Collins Startup list
  22080.  
  22081. [FreeRAM XP]
  22082. Number=3136
  22083. Confirmed=U
  22084. Filename=FreeRAM XP Pro *.exe
  22085. Description=<a href="http://www.yourwaresolutions.com/software.html#framxpro" target="_blank">FreeRAM XP Pro</a> - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See <a href="http://aumha.org/win4/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
  22086. Source=Paul Collins Startup list
  22087.  
  22088. [freestyle]
  22089. Number=3137
  22090. Confirmed=X
  22091. Filename=lockx.exe
  22092. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotath.html" target=_blank>RBOT-ATH</a> WORM!
  22093. Source=Paul Collins Startup list
  22094.  
  22095. [freesurfer]
  22096. Number=3138
  22097. Confirmed=U
  22098. Filename=fs20.exe
  22099. Description=<a href="http://www.kolumbus.fi/eero.muhonen/FS/" target="_blank">EMS Free Surfer mk II</a> - pop-up stopper
  22100. Source=Paul Collins Startup list
  22101.  
  22102. [freexstyle]
  22103. Number=3139
  22104. Confirmed=X
  22105. Filename=lockbar.exe
  22106. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-010615-2712-99" target=_blank>LOXBOT.D</a> WORM!
  22107. Source=Paul Collins Startup list
  22108.  
  22109. [freexstyle]
  22110. Number=3140
  22111. Confirmed=X
  22112. Filename=lockbr.exe
  22113. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-010515-3159-99" target=_blank>LOXBOT.C</a> WORM!
  22114. Source=Paul Collins Startup list
  22115.  
  22116. [Fresh Desktop]
  22117. Number=3141
  22118. Confirmed=U
  22119. Filename=freshdesktop.exe
  22120. Description=<a href="http://www.softcows.com/fresh_desktop.htm" target=_blank>Fresh Desktop</a> is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals
  22121. Source=Paul Collins Startup list
  22122.  
  22123. [freshclam]
  22124. Number=3142
  22125. Confirmed=N
  22126. Filename=freshclam.exe
  22127. Description=Auto update agent of the open source <a href="http://www.clamwin.com/" target=_blank>Clamwin</a> virus scanner
  22128.  
  22129. Source=Paul Collins Startup list
  22130.  
  22131. [frguk]
  22132. Number=3143
  22133. Confirmed=?
  22134. Filename=shdrkmck.exe
  22135. Description=<font color="#FF0000">??</font>
  22136. Source=Paul Collins Startup list
  22137.  
  22138. [FridaysInHellInstaller]
  22139. Number=3144
  22140. Confirmed=?
  22141. Filename=FridaysInHellInstaller.exe
  22142. Description=<font color="#FF0000">??</font>
  22143. Source=Paul Collins Startup list
  22144.  
  22145. [FriendlyType]
  22146. Number=3145
  22147. Confirmed=X
  22148. Filename=lsass.exe
  22149. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-100519-0947-99" target=_blank>WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
  22150. Source=Paul Collins Startup list
  22151.  
  22152. [FriendlyTypeName]
  22153. Number=3146
  22154. Confirmed=X
  22155. Filename=services.exe
  22156. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081700-2526-99" target="_blank">NEVEG.B</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081614-3605-99" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
  22157. Source=Paul Collins Startup list
  22158.  
  22159. [FriendlyTypeName]
  22160. Number=3147
  22161. Confirmed=X
  22162. Filename=winlogon.exe
  22163. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081623-4258-99" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
  22164. Source=Paul Collins Startup list
  22165.  
  22166. [FriendlyWebQuick-Launch]
  22167. Number=3148
  22168. Confirmed=N
  22169. Filename=SELFCERT.EXE
  22170. Description=selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
  22171. Source=Paul Collins Startup list
  22172.  
  22173. [FRISK FP-Scheduler]
  22174. Number=3149
  22175. Confirmed=U
  22176. Filename=F-Sched.exe
  22177. Description=Scheduler for <a href="http://www.f-prot.com/" target="_blank"> F-Prot</a> anitvirus software. Leave enabled unless you scan manually on a regular basis
  22178. Source=Paul Collins Startup list
  22179.  
  22180. [FRITZ!DSL Startcenter]
  22181. Number=3150
  22182. Confirmed=?
  22183. Filename=StCenter.exe
  22184. Description=FRITZ! ISP software "StartCenter" User interface that allows you to manage, tweak and diagnose many aspects of your internet connection - <font color="#FF0000">is it required?</font>
  22185. Source=Paul Collins Startup list
  22186.  
  22187. [FRITZ!webProtect]
  22188. Number=3151
  22189. Confirmed=U
  22190. Filename=FwebProt.exe
  22191. Description=Firewall included in FRITZ! ISP DSL software
  22192. Source=Paul Collins Startup list
  22193.  
  22194. [Fromine WinPopup]
  22195. Number=3152
  22196. Confirmed=N
  22197. Filename=winpopup.exe
  22198. Description=Instant Messenger program
  22199. Source=Paul Collins Startup list
  22200.  
  22201. [Frsk]
  22202. Number=3153
  22203. Confirmed=X
  22204. Filename=frsk.exe
  22205. Description=Unidentified adware downloader trojan
  22206. Source=Paul Collins Startup list
  22207.  
  22208. [FRW_EXE]
  22209. Number=3154
  22210. Confirmed=Y
  22211. Filename=FRW.EXE
  22212. Description=<a href="http://www.claymania.com/rate-conseal.html" target="_blank">ConSeal Signal9</a> firewall - now McAfee Personal firewall
  22213. Source=Paul Collins Startup list
  22214.  
  22215. [frxmxins]
  22216. Number=3155
  22217. Confirmed=Y
  22218. Filename=frxmxins.exe
  22219. Description=ATI 3D Studio MAX/VIZ driver
  22220. Source=Paul Collins Startup list
  22221.  
  22222. [FS Agent]
  22223. Number=3156
  22224. Confirmed=X
  22225. Filename=fagent.exe
  22226. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojvolverb.html" target=_blank>VOLVER-B</a> TROJAN!
  22227. Source=Paul Collins Startup list
  22228.  
  22229. [FS6519]
  22230. Number=3157
  22231. Confirmed=X
  22232. Filename=FS6519.dll.vbs
  22233. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-022116-1047-99" target="_blank">SOLOW.B</a> WORM!
  22234. Source=Paul Collins Startup list
  22235.  
  22236. [fsaa]
  22237. Number=3158
  22238. Confirmed=Y
  22239. Filename=fsaa.exe
  22240. Description=<a href="http://www.f-secure.com/" target=_blank>F-Secure</a> antivirus Authentication Agent - creates and stores private keys used by a client to access servers
  22241. Source=Paul Collins Startup list
  22242.  
  22243. [FSCBoss]
  22244. Number=3159
  22245. Confirmed=N
  22246. Filename=FSCBoss.exe
  22247. Description=Free Store Club shop online software
  22248. Source=Paul Collins Startup list
  22249.  
  22250. [FSDPSRV]
  22251. Number=3160
  22252. Confirmed=?
  22253. Filename=FSDPSRV.exe
  22254. Description=<font color="#FF0000">??</font>
  22255. Source=Paul Collins Startup list
  22256.  
  22257. [FSH]
  22258. Number=3161
  22259. Confirmed=X
  22260. Filename=svcnva.exe
  22261. Description=Malware, detected by <a href="http://www.ewido.net/en/" target=_blank>Ewido Security Suite</a> as TrojanDownloader.Delf.ks
  22262. Source=Paul Collins Startup list
  22263.  
  22264. [fsp]
  22265. Number=3162
  22266. Confirmed=U
  22267. Filename=fsp.exe
  22268. Description=<a href="http://www.baxbex.com/foldershield.html" target="_blank">Folder Shield</a> - hide entire directories and thus prevent access by anyone else to your personal files and documents
  22269. Source=Paul Collins Startup list
  22270.  
  22271. [fspr]
  22272. Number=3163
  22273. Confirmed=Y
  22274. Filename=FolderShield.exe
  22275. Description=<a href="http://www.baxbex.de/foldershield.html" target="_blank">Folder Shield</a> - hide personal files and folders
  22276. Source=Paul Collins Startup list
  22277.  
  22278. [FSScrCtl]
  22279. Number=3164
  22280. Confirmed=N
  22281. Filename=FSScrCtl.exe
  22282. Description=Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
  22283. Source=Paul Collins Startup list
  22284.  
  22285. [fsserv]
  22286. Number=3165
  22287. Confirmed=U
  22288. Filename=fserv.exe
  22289. Description=<a target="_blank" href="http://www.bysoft.se/sureshot/farsighter/manual.html">Farsighter Server</a> - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time
  22290. Source=Paul Collins Startup list
  22291.  
  22292. [FSW]
  22293. Number=3166
  22294. Confirmed=X
  22295. Filename=FSW.exe
  22296. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=FreeScratchAndWin&threatid=5475" target=_blank>FreeScratchAndWin</a> parasite
  22297. Source=Paul Collins Startup list
  22298.  
  22299. [FSWebServer]
  22300. Number=3167
  22301. Confirmed=U
  22302. Filename=fsws.exe
  22303. Description=<a href="http://www.sharing-file.com/" target=_blank>Easy File Sharing Web Server</a> is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services
  22304. Source=Paul Collins Startup list
  22305.  
  22306. [FtkCPY]
  22307. Number=3168
  22308. Confirmed=X
  22309. Filename=ftkcpy.exe
  22310. Description=<a href="http://sarc.com/avcenter/venc/data/adware.flashenhancer.html" target="_blank">FlashEnhancer</a> adware variant
  22311. Source=Paul Collins Startup list
  22312.  
  22313. [FtLnSOP_setup]
  22314. Number=3169
  22315. Confirmed=U
  22316. Filename=FtLnSOP.exe
  22317. Description=Fujitsu scanner utility
  22318. Source=Paul Collins Startup list
  22319.  
  22320. [FTMSFLT(USB)]
  22321. Number=3170
  22322. Confirmed=U
  22323. Filename=FTMSFLTU.EXE
  22324. Description=Fujitsu's Touch Panel Message Notifier
  22325. Source=Paul Collins Startup list
  22326.  
  22327. [FTP FOR WINDOWS]
  22328. Number=3171
  22329. Confirmed=X
  22330. Filename=ftpwin32.exe
  22331. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  22332. Source=Paul Collins Startup list
  22333.  
  22334. [FTPGraber]
  22335. Number=3172
  22336. Confirmed=X
  22337. Filename=FTPGraber.exe
  22338. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderdt.html" target=_blank>DLOADER-DT</a> TROJAN!
  22339.  
  22340. Source=Paul Collins Startup list
  22341.  
  22342. [FTPManager]
  22343. Number=3173
  22344. Confirmed=N
  22345. Filename=FTPDM.exe
  22346. Description="<a href="http://www.robust.ws/ftpdm.html" target=_blank>Robust FTP</a> is a Windows-based file transfer client application that transfers files between a user's local PC and another, remote computer system connected via a modem and telephone lines or by a local-area network (with upload transfer resume and download transfer resume)". Can be started manually
  22347. Source=Paul Collins Startup list
  22348.  
  22349. [Ftpqueue]
  22350. Number=3174
  22351. Confirmed=U
  22352. Filename=Ftpsched.exe
  22353. Description=Part of <a href="http://www.ipswitch.com/Products/WS_FTP/" target="_blank">WS_FTP Pro</a> from Ipswitch. Queueing facility for scheduling FTP transfers
  22354. Source=Paul Collins Startup list
  22355.  
  22356. [ftutil2]
  22357. Number=3175
  22358. Confirmed=U
  22359. Filename=rundll32.exe [path] ftutil2.dll, SetWriteCacheMode
  22360. Description=Related to Promise Technology's <a href="http://www.promise.com/marketing/datasheet/file/2_FT%20SX4030_4060%20DS.pdf" target="_blank">FastTrak SX4030/4060</a> PCI ATA Raid 5 controller (and possibly others)
  22361. Source=Paul Collins Startup list
  22362.  
  22363. [Fucker]
  22364. Number=3176
  22365. Confirmed=X
  22366. Filename=fucker.vbs
  22367. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32catchera.html" target="_blank">CATCHER-A</a> WORM!
  22368. Source=Paul Collins Startup list
  22369.  
  22370. [Fujitsu Menu]
  22371. Number=3177
  22372. Confirmed=U
  22373. Filename=FjMnuIco.exe
  22374. Description=From the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable
  22375. Source=Paul Collins Startup list
  22376.  
  22377. [fukerservice]
  22378. Number=3178
  22379. Confirmed=X
  22380. Filename=fukerz.exe
  22381. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
  22382. Source=Paul Collins Startup list
  22383.  
  22384. [FUKLBAR]
  22385. Number=3179
  22386. Confirmed=X
  22387. Filename=bar.exe
  22388. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  22389. Source=Paul Collins Startup list
  22390.  
  22391. [FusionHdtvTray]
  22392. Number=3180
  22393. Confirmed=U
  22394. Filename=FusionHdtvTray.exe
  22395. Description=FusionTrayAgent - main executable for <a href="http://www.fusionhdtv.co.kr/eng/" target="_blank">DVICO FusionHDTV</a> software. It adds an icon to system tray that allows you to easily access Fusion HDTV software
  22396. Source=Paul Collins Startup list
  22397.  
  22398. [FusionRC]
  22399. Number=3181
  22400. Confirmed=U
  22401. Filename=FusionRC.exe
  22402. Description=Remote control manager for <a href="http://www.fusionhdtv.co.kr/eng/" target="_blank">DVICO FusionHDTV</a>
  22403. Source=Paul Collins Startup list
  22404.  
  22405. [FusionRemote]
  22406. Number=3182
  22407. Confirmed=U
  22408. Filename=FusionRc.exe
  22409. Description=Remote control manager for <a href="http://www.fusionhdtv.co.kr/eng/" target="_blank">DVICO FusionHDTV</a>
  22410. Source=Paul Collins Startup list
  22411.  
  22412. [FusionTrayAgent]
  22413. Number=3183
  22414. Confirmed=N
  22415. Filename=FusionHdtvTray.exe
  22416. Description=FusionTrayAgent - main executable for <a href="http://www.fusionhdtv.co.kr/eng/" target="_blank">DVICO FusionHDTV</a> software. It adds an icon to system tray that allows you to easily access Fusion HDTV software
  22417. Source=Paul Collins Startup list
  22418.  
  22419. [fvek]
  22420. Number=3184
  22421. Confirmed=X
  22422. Filename=fvek.exe
  22423. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdrivola.html" target=_blank>DRIVOL-A</a> TROJAN!
  22424. Source=Paul Collins Startup list
  22425.  
  22426. [FW Manager]
  22427. Number=3185
  22428. Confirmed=X
  22429. Filename=fwcheck.exe
  22430. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delboth.html" target="_blank">DELBOT-H</a> WORM!
  22431. Source=Paul Collins Startup list
  22432.  
  22433. [FWDMON.EXE]
  22434. Number=3186
  22435. Confirmed=X
  22436. Filename=fwdmon.exe
  22437. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojproxys.html" target=_blank>PROXY-S</a> TROJAN!
  22438. Source=Paul Collins Startup list
  22439.  
  22440. [fwenc.exe]
  22441. Number=3187
  22442. Confirmed=Y
  22443. Filename=fwenc.exe
  22444. Description=<a href="http://www.checkpoint.com/" target="_blank">Check Point</a> SecuRemote VPN client - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers"
  22445. Source=Paul Collins Startup list
  22446.  
  22447. [Fwr Command Module]
  22448. Number=3188
  22449. Confirmed=X
  22450. Filename=fwr.exe
  22451. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpp.html" target="_blank">SDBOT-PP</a> WORM!
  22452. Source=Paul Collins Startup list
  22453.  
  22454. [fwrastrc]
  22455. Number=3189
  22456. Confirmed=N
  22457. Filename=fwrastrc.exe
  22458. Description=Dial-up software for Friendly Technologies/1NationOnLine free ISP
  22459. Source=Paul Collins Startup list
  22460.  
  22461. [fwservice]
  22462. Number=3190
  22463. Confirmed=U
  22464. Filename=fwservice
  22465. Description=eAcceleration Stop-Sign security software related. Previously not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">here</a>
  22466. Source=Paul Collins Startup list
  22467.  
  22468. [FX]
  22469. Number=3191
  22470. Confirmed=X
  22471. Filename=ieloader.exe
  22472. Description=Added by the SMALL.RR TROJAN!
  22473. Source=Paul Collins Startup list
  22474.  
  22475. [fxredir]
  22476. Number=3192
  22477. Confirmed=U
  22478. Filename=fxredir.exe
  22479. Description=Canon MultiPASS fax redirector
  22480. Source=Paul Collins Startup list
  22481.  
  22482. [fzg]
  22483. Number=3193
  22484. Confirmed=X
  22485. Filename=svhost32.exe
  22486. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DLOADER.BDK" target="_blank">DLOADER.BDK</a> TROJAN!
  22487. Source=Paul Collins Startup list
  22488.  
  22489. [f~a]
  22490. Number=3194
  22491. Confirmed=X
  22492. Filename=ra32.exe
  22493. Description=Added by the <a href="http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101037&affid=125" target=_blank>CAY</a> TROJAN!
  22494. Source=Paul Collins Startup list
  22495.  
  22496. [g.exe]
  22497. Number=3195
  22498. Confirmed=X
  22499. Filename=g.exe
  22500. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-091016-5719-99" target=_blank>GRAYBIRD.Q</a> TROJAN!
  22501. Source=Paul Collins Startup list
  22502.  
  22503. [G00123]
  22504. Number=3196
  22505. Confirmed=X
  22506. Filename=[worm filename]
  22507. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-010215-0626-99" target="_blank">BUGBROS</a> WORM!
  22508. Source=Paul Collins Startup list
  22509.  
  22510. [G0mez]
  22511. Number=3197
  22512. Confirmed=X
  22513. Filename=G0mez.vbs
  22514. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/vbsgormleza.html" target=_blank>GORMLEZ-A</a> WORM!
  22515. Source=Paul Collins Startup list
  22516.  
  22517. [G3]
  22518. Number=3198
  22519. Confirmed=X
  22520. Filename=GSMedia3.exe
  22521. Description=Malware downloader - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan.Win32.VB.ux
  22522. Source=Paul Collins Startup list
  22523.  
  22524. [g3dctl]
  22525. Number=3199
  22526. Confirmed=?
  22527. Filename=g3dctl.exe
  22528. Description=<font color="#FF0000">??</font>
  22529. Source=Paul Collins Startup list
  22530.  
  22531. [Gadu-Gadu]
  22532. Number=3200
  22533. Confirmed=N
  22534. Filename=gg.exe
  22535. Description=Polish language Instant Messaging client
  22536. Source=Paul Collins Startup list
  22537.  
  22538. [Gadwin PrintScreen]
  22539. Number=3201
  22540. Confirmed=N
  22541. Filename=PrintScreen.exe
  22542. Description=Gadwin <a href="http://www.gadwin.com/printscreen/" target="_blank">PrintScreen</a> - utility to capture, print or save the current window
  22543. Source=Paul Collins Startup list
  22544.  
  22545. [GAELICUM.EXE]
  22546. Number=3202
  22547. Confirmed=X
  22548. Filename=GAELICUM.EXE
  22549. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpentaa.html" target=_blank>PENTA-A</a> TROJAN!
  22550. Source=Paul Collins Startup list
  22551.  
  22552. [gah95on6]
  22553. Number=3203
  22554. Confirmed=X
  22555. Filename=gah95on6.exe
  22556. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076082" target=_blank>ShopAtHome/SAHagent</a> adware
  22557. Source=Paul Collins Startup list
  22558.  
  22559. [gaim]
  22560. Number=3204
  22561. Confirmed=U
  22562. Filename=gaim.exe
  22563. Description=<a href="http://gaim.sourceforge.net/" target=_blank>Gaim</a> is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks
  22564. Source=Paul Collins Startup list
  22565.  
  22566. [Gainward]
  22567. Number=3205
  22568. Confirmed=U
  22569. Filename=TBPanel.exe
  22570. Description=Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
  22571. Source=Paul Collins Startup list
  22572.  
  22573. [game]
  22574. Number=3206
  22575. Confirmed=X
  22576. Filename=shit.exe
  22577. Description=Added by the Netclap Gold backdoor TROJAN!
  22578. Source=Paul Collins Startup list
  22579.  
  22580. [Game Device]
  22581. Number=3207
  22582. Confirmed=N
  22583. Filename=JOYUPDRV.EXE
  22584. Description=Genius game controller profile activator
  22585. Source=Paul Collins Startup list
  22586.  
  22587. [Game House]
  22588. Number=3208
  22589. Confirmed=X
  22590. Filename=GameHouse.exe
  22591. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32delfdra.html" target="_blank">DELF-DRA</a> WORM!
  22592. Source=Paul Collins Startup list
  22593.  
  22594. [GameDrive]
  22595. Number=3209
  22596. Confirmed=N
  22597. Filename=GDTask.exe
  22598. Description=<a href="http://www.farstone.com/software/gamedrive.htm" target="_blank">GameDrive</a> Virtual Driver from FarStone Technology, Inc. Run PC games without the disc
  22599. Source=Paul Collins Startup list
  22600.  
  22601. [Games Acceleration]
  22602. Number=3210
  22603. Confirmed=X
  22604. Filename=svshost.exe
  22605. Description=<a href="http://sarc.com/avcenter/venc/data/adware.easysearch.html" target=_blank>EasySearch</a> adware
  22606. Source=Paul Collins Startup list
  22607.  
  22608. [Games Acceleration]
  22609. Number=3211
  22610. Confirmed=X
  22611. Filename=[path to trojan]
  22612. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsmutsrcha.html" target=_blank>SMUTSRCH-A</a> TROJAN!
  22613. Source=Paul Collins Startup list
  22614.  
  22615. [Games Acceleration]
  22616. Number=3212
  22617. Confirmed=X
  22618. Filename=svshost1.exe
  22619. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadrawd.html" target="_blank">DLOADR-AWD</a> TROJAN!
  22620. Source=Paul Collins Startup list
  22621.  
  22622. [Games toolbar]
  22623. Number=3213
  22624. Confirmed=X
  22625. Filename=rundll32.exe [path] tbGame.dll, DllShowTB
  22626. Description=Topconverting.com\180Search "Games Toolbar" adware
  22627.  
  22628. Source=Paul Collins Startup list
  22629.  
  22630. [GameSpot]
  22631. Number=3214
  22632. Confirmed=N
  22633. Filename=kontiki.exe
  22634. Description=<a href="http://www.kontiki.com/products/deliverymanager/index.html" target="_blank">Kontiki Delivery Manager</a> - Windows-based client software that enables secure delivery of content to users' desktops
  22635. Source=Paul Collins Startup list
  22636.  
  22637. [gameutil.exe]
  22638. Number=3215
  22639. Confirmed=U
  22640. Filename=gameutil.exe
  22641. Description=Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
  22642. Source=Paul Collins Startup list
  22643.  
  22644. [GammaHotKeys]
  22645. Number=3216
  22646. Confirmed=U
  22647. Filename=setgamma.exe
  22648. Description=Part of the <a href="http://radeontweaker.sourceforge.net/" target="_blank">RadeonTweaker</a> program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
  22649. Source=Paul Collins Startup list
  22650.  
  22651. [gaSrv]
  22652. Number=3217
  22653. Confirmed=X
  22654. Filename=gaSrv.exe
  22655. Description=Adware downloader, identified by <a href="http://www.pandasoftware.com/" target="_blank">Panda</a> antivirus as Trojan.Downloader.ALQ
  22656. Source=Paul Collins Startup list
  22657.  
  22658. [gaSrve]
  22659. Number=3218
  22660. Confirmed=X
  22661. Filename=gaSrve.exe
  22662. Description=Adware downloader, identified by <a href="http://www.pandasoftware.com/" target="_blank">Panda</a> antivirus as Trojan.Downloader.ALQ
  22663. Source=Paul Collins Startup list
  22664.  
  22665. [Gate Personal Firewall]
  22666. Number=3219
  22667. Confirmed=X
  22668. Filename=Systpl.exe
  22669. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ADC&VSect=P" target=_blank>RBOT.ADC</a> WORM
  22670. Source=Paul Collins Startup list
  22671.  
  22672. [Gateway Extended Warranty]
  22673. Number=3220
  22674. Confirmed=N
  22675. Filename=GWCares.exe
  22676. Description=Gateway Extended Warranty reminder
  22677. Source=Paul Collins Startup list
  22678.  
  22679. [Gator]
  22680. Number=3221
  22681. Confirmed=X
  22682. Filename=gator.exe
  22683. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.Gator.eWallet&threatid=3722" target="_blank">Gator eWallet</a> adware. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  22684. Source=Paul Collins Startup list
  22685.  
  22686. [Gator eWallet]
  22687. Number=3222
  22688. Confirmed=X
  22689. Filename=gator.exe
  22690. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.Gator.eWallet&threatid=3722" target="_blank">Gator eWallet</a> adware. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  22691. Source=Paul Collins Startup list
  22692.  
  22693. [Gay_Sexy_**]
  22694. Number=3223
  22695. Confirmed=X
  22696. Filename=Gay_Sexy_**.exe
  22697. Description=Premium rate adult content dialler (where * is a random char)
  22698. Source=Paul Collins Startup list
  22699.  
  22700. [GazelDisplay]
  22701. Number=3224
  22702. Confirmed=U
  22703. Filename=gsyno.exe
  22704. Description=<a href="http://www.bt.com/homehighway/more_info.htm">BT Digital Access USB</a> - Gazel ISDN installation System Tray icon
  22705. Source=Paul Collins Startup list
  22706.  
  22707. [GBSpaceMan]
  22708. Number=3225
  22709. Confirmed=Y
  22710. Filename=SpaceMan.exe
  22711. Description=<a href="http://greenborder.com/" target="_blank">GreenBorder</a> - secure your browsing activities on the internet
  22712. Source=Paul Collins Startup list
  22713.  
  22714. [GBTray]
  22715. Number=3226
  22716. Confirmed=U
  22717. Filename=GBTray.exe
  22718. Description=System Tray icon access to <a href="http://www.roxio.com/enu/default.html" target="_blank">Roxio's</a> (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
  22719. Source=Paul Collins Startup list
  22720.  
  22721. [gCac]
  22722. Number=3227
  22723. Confirmed=X
  22724. Filename=gcac.exe
  22725. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.U</a> TROJAN!
  22726. Source=Paul Collins Startup list
  22727.  
  22728. [gcasDtServ]
  22729. Number=3228
  22730. Confirmed=X
  22731. Filename=gcasDtServ.exe
  22732. Description=Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
  22733. Source=Paul Collins Startup list
  22734.  
  22735. [gcasServ]
  22736. Number=3229
  22737. Confirmed=U
  22738. Filename=gcasServ.exe
  22739. Description=<a href="http://www.giantcompany.com/p_antiSpyware.htm" target=_blank>Giant Antipsyware</a> - now superseeded by <a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx" target=_blank>Microsoft Windows AntiSpyware</a>
  22740. Source=Paul Collins Startup list
  22741.  
  22742. [gcasServ]
  22743. Number=3230
  22744. Confirmed=X
  22745. Filename=realsched.exe
  22746. Description=Added by a variant of the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target= blank>TACTSLAY.A</a> TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
  22747. Source=Paul Collins Startup list
  22748.  
  22749. [GCC Reminder]
  22750. Number=3231
  22751. Confirmed=?
  22752. Filename=gccrem.exe
  22753. Description=Associated with AcraMax Greeting Card Creator. <font color="#FF0000">Is it a registration reminder?</font>
  22754. Source=Paul Collins Startup list
  22755.  
  22756. [GCS]
  22757. Number=3232
  22758. Confirmed=N
  22759. Filename=GrabClipSave.exe
  22760. Description=<a href="http://www.boumchalak.net/Tools/GCS/gcs.html" target="_blank">GrabClipSave</a> screen capture tool
  22761. Source=Paul Collins Startup list
  22762.  
  22763. [GDAX]
  22764. Number=3233
  22765. Confirmed=X
  22766. Filename=[path to backdoor]
  22767. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-102814-0756-99" target=_blank>RANKY.K</a> TROJAN!
  22768. Source=Paul Collins Startup list
  22769.  
  22770. [gdien32]
  22771. Number=3234
  22772. Confirmed=X
  22773. Filename=gdien32.exe
  22774. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsingup.html" target=_blank>SINGU-P</a> TROJAN!
  22775. Source=Paul Collins Startup list
  22776.  
  22777. [gdimx]
  22778. Number=3235
  22779. Confirmed=X
  22780. Filename=gdimx.exe
  22781. Description=<a href="http://www.sophos.com/virusinfo/analyses/dialmpbd.html" target="_blank">MPB-D</a> dialer. Note - provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "gdimx"
  22782. Source=Paul Collins Startup list
  22783.  
  22784. [GDMgr.exe]
  22785. Number=3236
  22786. Confirmed=U
  22787. Filename=gdmgr.exe
  22788. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-052615-2337-99" target="_blank">GuardMon</a> is a commercial surveillance software program designed to monitor all forms of user activity on a computer
  22789. Source=Paul Collins Startup list
  22790.  
  22791. [GDrive]
  22792. Number=3237
  22793. Confirmed=N
  22794. Filename=GDriver.exe
  22795. Description=Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
  22796. Source=Paul Collins Startup list
  22797.  
  22798. [Gearbox]
  22799. Number=3238
  22800. Confirmed=N
  22801. Filename=confsvr.exe
  22802. Description=NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available <a href="http://www.ntlworld.com/help/settings.htm" target="_blank">here</a>
  22803. Source=Paul Collins Startup list
  22804.  
  22805. [GEARsec]
  22806. Number=3239
  22807. Confirmed=N
  22808. Filename=gearsec.exe
  22809. Description=Installed by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player
  22810. Source=Paul Collins Startup list
  22811.  
  22812. [GEDZAC]
  22813. Number=3240
  22814. Confirmed=X
  22815. Filename=GEDZAC.exe
  22816. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020411-4428-99" target="_blank">GEMEL</a> WORM!
  22817.  
  22818. Source=Paul Collins Startup list
  22819.  
  22820. [GemStRmW]
  22821. Number=3241
  22822. Confirmed=N
  22823. Filename=GemStRmW.exe
  22824. Description=For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually
  22825. Source=Paul Collins Startup list
  22826.  
  22827. [Gene USB Monitor]
  22828. Number=3242
  22829. Confirmed=U
  22830. Filename=USBMonit.exe
  22831. Description=Monitors USB ports for insertion of Sandisk USB flashdrives
  22832. Source=Paul Collins Startup list
  22833.  
  22834. [general lptt01]
  22835. Number=3243
  22836. Confirmed=X
  22837. Filename=general.exe
  22838. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  22839. Source=Paul Collins Startup list
  22840.  
  22841. [general ml097e]
  22842. Number=3244
  22843. Confirmed=X
  22844. Filename=general.exe
  22845. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  22846. Source=Paul Collins Startup list
  22847.  
  22848. [Generic host proccess for windows]
  22849. Number=3245
  22850. Confirmed=X
  22851. Filename=SVCHOSTS.EXE
  22852. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotgq.html" target= blank>SPYBOT-GQ</a> WORM!
  22853. Source=Paul Collins Startup list
  22854.  
  22855. [Generic Host Process]
  22856. Number=3246
  22857. Confirmed=X
  22858. Filename=SCHOST.EXE
  22859. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotnc.html" target=_blank>RBOT-NC</a> WORM!
  22860.  
  22861. Source=Paul Collins Startup list
  22862.  
  22863. [Generic Host Process]
  22864. Number=3247
  22865. Confirmed=X
  22866. Filename=svchost.exe
  22867. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadernx.html" target=_blank>DLOADER-NX</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  22868. Source=Paul Collins Startup list
  22869.  
  22870. [Generic Host Process for Win32 Service]
  22871. Number=3248
  22872. Confirmed=X
  22873. Filename=svlhost.exe
  22874. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.EX" target="_blank">WOOTBOT.EX</a> WORM!
  22875. Source=Paul Collins Startup list
  22876.  
  22877. [Generic Host Process for Win32 Service]
  22878. Number=3249
  22879. Confirmed=X
  22880. Filename=svchost.exe
  22881. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.NC" target="_blank">SPYBOT.NC</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  22882. Source=Paul Collins Startup list
  22883.  
  22884. [Generic Host Process for Win32 Services]
  22885. Number=3250
  22886. Confirmed=X
  22887. Filename=ntspcv.exe
  22888. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-010813-5603-99" target="_blank">SDBOT.S</a> TROJAN!
  22889. Source=Paul Collins Startup list
  22890.  
  22891. [Generic Host Process for Win32 Services]
  22892. Number=3251
  22893. Confirmed=X
  22894. Filename=intspvc.exe
  22895. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-031712-4905-99" target="_blank">DINFOR.D</a> WORM!
  22896. Source=Paul Collins Startup list
  22897.  
  22898. [Generic Host Process for Win32 Services]
  22899. Number=3252
  22900. Confirmed=X
  22901. Filename=winsvc.exe
  22902. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdboto.html" target="_blank">SDBOT-O</a> WORM!
  22903. Source=Paul Collins Startup list
  22904.  
  22905. [Generic Host Process for Win32 Services]
  22906. Number=3253
  22907. Confirmed=X
  22908. Filename=bazzi.exe
  22909. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-022311-5800-99" target=_blank>AHKER.E</a> WORM!
  22910. Source=Paul Collins Startup list
  22911.  
  22912. [Generic Host Process for Win32 Services]
  22913. Number=3254
  22914. Confirmed=X
  22915. Filename=winsvc32.exe
  22916. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotp.html" target= blank>SDBOT-P</a> WORM!
  22917. Source=Paul Collins Startup list
  22918.  
  22919. [Generic Host Process for Win32 Services]
  22920. Number=3255
  22921. Confirmed=X
  22922. Filename=lspsvc.exe
  22923. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MUMU.C" target="_blank">MUMU.C</a> WORM!
  22924. Source=Paul Collins Startup list
  22925.  
  22926. [Generic Host Process for Win32 Services]
  22927. Number=3256
  22928. Confirmed=X
  22929. Filename=SPSVC.EXE
  22930. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.DA" target="_blank">SDBOT.DA</a> WORM!
  22931. Source=Paul Collins Startup list
  22932.  
  22933. [Generic Host Process for Win32 Services]
  22934. Number=3257
  22935. Confirmed=X
  22936. Filename=svchost32.exe
  22937. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.ALH" target="_blank">AGOBOT.ALH</a> WORM!
  22938. Source=Paul Collins Startup list
  22939.  
  22940. [Generic Host Process for Win32 Services]
  22941. Number=3258
  22942. Confirmed=X
  22943. Filename=sv±hεst.exe
  22944. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DLOADER.AK" target="_blank">DLOADER.AK</a> TROJAN!
  22945. Source=Paul Collins Startup list
  22946.  
  22947. [Generic Host Process2 System Backup]
  22948. Number=3259
  22949. Confirmed=X
  22950. Filename=scvhost2.exe
  22951. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotbah.html" target=_blank>RBOT-BAH</a> WORM!
  22952. Source=Paul Collins Startup list
  22953.  
  22954. [Generic Host Process326a System Backup]
  22955. Number=3260
  22956. Confirmed=X
  22957. Filename=scvhost326a.exe
  22958. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  22959. Source=Paul Collins Startup list
  22960.  
  22961. [Generic Host Service]
  22962. Number=3261
  22963. Confirmed=X
  22964. Filename=lshost.exe
  22965. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.LU&VSect=T" target="_blank">RBOT.LU</a> WORM!
  22966. Source=Paul Collins Startup list
  22967.  
  22968. [Generic Service Process]
  22969. Number=3262
  22970. Confirmed=X
  22971. Filename=regsvc32.exe
  22972. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040114-5626-99" target="_blank">GAOBOT.UJ</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040212-0834-99" target="_blank">GAOBOT.UL</a> WORMS!
  22973. Source=Paul Collins Startup list
  22974.  
  22975. [Generic Service Process]
  22976. Number=3263
  22977. Confirmed=X
  22978. Filename=serv1ces.exe
  22979. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotjk.html" target=_blank>AGOBOT-JK</a> WORM!
  22980. Source=Paul Collins Startup list
  22981.  
  22982. [Generic Service Process]
  22983. Number=3264
  22984. Confirmed=X
  22985. Filename=nvsvc.exe
  22986. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.BY" target="_blank">AGOBOT.BY</a> WORM! Note - this is not the valid <a href="http://www.sysinfo.org/startuplist.php?filter=NvSvc" target=_blank>NVIDIA Driver Helper Service</a> and is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  22987. Source=Paul Collins Startup list
  22988.  
  22989. [Generic Services Process]
  22990. Number=3265
  22991. Confirmed=X
  22992. Filename=regsvc32.exe
  22993. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040112-0028-99" target="_blank">GAOBOT.SY</a> WORM!
  22994. Source=Paul Collins Startup list
  22995.  
  22996. [GenericHostXP]
  22997. Number=3266
  22998. Confirmed=X
  22999. Filename=WinLoaderXP.exe
  23000. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdooracx.html" target="_blank">BDOOR-ACX</a> TROJAN!
  23001. Source=Paul Collins Startup list
  23002.  
  23003. [Genie USB Monitor]
  23004. Number=3267
  23005. Confirmed=Y
  23006. Filename=USBmonitor.exe
  23007. Description=Port monitor for an external USB hard drive. Required to enable access to the drive
  23008. Source=Paul Collins Startup list
  23009.  
  23010. [Geography TX 1.0 NT]
  23011. Number=3268
  23012. Confirmed=X
  23013. Filename=CompuSpeed.vbs
  23014. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/vbsnewleya.html" target= blank>NEWLEY-A</a> WORM!
  23015. Source=Paul Collins Startup list
  23016.  
  23017. [Gerenciamento de arquivos do Windows]
  23018. Number=3269
  23019. Confirmed=X
  23020. Filename=Winmod32.exe
  23021. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderwg.html" target=_blank>DLOADER-WG</a> TROJAN!
  23022. Source=Paul Collins Startup list
  23023.  
  23024. [german.exe]
  23025. Number=3270
  23026. Confirmed=X
  23027. Filename=winsystems.exe
  23028. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbagledlae.html" target=_blank>BAGLEDl-AE</a> TROJAN!
  23029. Source=Paul Collins Startup list
  23030.  
  23031. [german.exe]
  23032. Number=3271
  23033. Confirmed=X
  23034. Filename=wintems.exe
  23035. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbagleas.html" target=_blank>BAGLE-AS</a> TROJAN!
  23036. Source=Paul Collins Startup list
  23037.  
  23038. [Gestionnaire de disques universel]
  23039. Number=3272
  23040. Confirmed=X
  23041. Filename=sysoobe.exe
  23042. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtoadera.html" target=_blank>TOADER-A</a> TROJAN!
  23043. Source=Paul Collins Startup list
  23044.  
  23045. [Get Smile]
  23046. Number=3273
  23047. Confirmed=N
  23048. Filename=getsmile.exe
  23049. Description=Puts smilie faces in your E-mail. Run manually when required
  23050. Source=Paul Collins Startup list
  23051.  
  23052. [GetRight Tray Icon]
  23053. Number=3274
  23054. Confirmed=N
  23055. Filename=GETRIGHT.EXE
  23056. Description=GetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs
  23057. Source=Paul Collins Startup list
  23058.  
  23059. [GetTheMusic]
  23060. Number=3275
  23061. Confirmed=X
  23062. Filename=rundll32.exe MSA64CHK.dll, DllMostrar
  23063. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=MatrixDialer&threatid=14914" target=_blank>MatrixDialer</a> related
  23064. Source=Paul Collins Startup list
  23065.  
  23066. [getwin]
  23067. Number=3276
  23068. Confirmed=X
  23069. Filename=winB_.exe
  23070. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerhs.html" target=_blank>BANKER-HS</a> TROJAN!
  23071. Source=Paul Collins Startup list
  23072.  
  23073. [GhostSecuritySuite]
  23074. Number=3277
  23075. Confirmed=U
  23076. Filename=gss.exe
  23077. Description=<a href="http://www.ghostsecurity.com/" target=_blank>Ghost Security Suite</a> - protect the registry from unauthorized reading and modification and other tools
  23078.  
  23079. Source=Paul Collins Startup list
  23080.  
  23081. [GhostStartService]
  23082. Number=3278
  23083. Confirmed=N
  23084. Filename=GhostStartService.exe
  23085. Description=Required to run the Windows based wizard in <a href="http://www.symantec.com/sabu/ghost/ghost_personal/" target="_blank">Norton Ghost</a> - added from the 2003 version. Will start automatically when you run the wizard
  23086. Source=Paul Collins Startup list
  23087.  
  23088. [GhostStartTrayApp]
  23089. Number=3279
  23090. Confirmed=N
  23091. Filename=GhostStartTrayApp.exe
  23092. Description=System Tray access to <a href="http://www.symantec.com/sabu/ghost/ghost_personal/" target="_blank">Norton Ghost</a> - added from the 2003 version
  23093. Source=Paul Collins Startup list
  23094.  
  23095. [GhostSurfDelSatellite]
  23096. Number=3280
  23097. Confirmed=?
  23098. Filename=DeleteSatellite.exe
  23099. Description=<a href="http://www.tenebril.com/products/ghostsurf/spycatcher.html" target=_blank>SpyCatcher</a> spyware remover related. <font color="#FF0000">What does it do and is it required?</font>
  23100.  
  23101. Source=Paul Collins Startup list
  23102.  
  23103. [GhostSurfDelSatellite]
  23104. Number=3281
  23105. Confirmed=Y
  23106. Filename=DeleteSatellite.exe
  23107. Description=Part of <a href="http://www.tenebril.com/consumer/spyware/spycatcher.php" target=_blank>SpyCatcher</a> spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning, you'll want to leave this file in place
  23108.  
  23109. Source=Paul Collins Startup list
  23110.  
  23111. [gigabit.exe]
  23112. Number=3282
  23113. Confirmed=X
  23114. Filename=gigabit.exe
  23115. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-032609-0734-99" target="_blank">BEAGLE.U</a> WORM!
  23116. Source=Paul Collins Startup list
  23117.  
  23118. [GigaByte]
  23119. Number=3283
  23120. Confirmed=X
  23121. Filename=Cheatle.exe
  23122. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042012-2931-99" target="_blank">SHODI.B</a> VIRUS!
  23123. Source=Paul Collins Startup list
  23124.  
  23125. [Gilat SOM Enumerator]
  23126. Number=3284
  23127. Confirmed=Y
  23128. Filename=dllhost.exe
  23129. Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
  23130. Source=Paul Collins Startup list
  23131.  
  23132. [GilatFTC]
  23133. Number=3285
  23134. Confirmed=Y
  23135. Filename=ftc.exe
  23136. Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
  23137. Source=Paul Collins Startup list
  23138.  
  23139. [gimmygames]
  23140. Number=3286
  23141. Confirmed=X
  23142. Filename=[path to trojan]
  23143. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadrln.html" target=_blank>DLOADR-LN</a> TROJAN!
  23144. Source=Paul Collins Startup list
  23145.  
  23146. [gimmysmileys]
  23147. Number=3287
  23148. Confirmed=X
  23149. Filename=gimmysmileys.exe
  23150. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=GimmySmileys&threatid=44087" target="_blank">GimmySmileys</a> adware
  23151. Source=Paul Collins Startup list
  23152.  
  23153. [GinaDll]
  23154. Number=3288
  23155. Confirmed=X
  23156. Filename=ntgina.dll
  23157. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_ANIG.A" target="_blank">ANIG.A</a> WORM!
  23158. Source=Paul Collins Startup list
  23159.  
  23160. [GisdnLog]
  23161. Number=3289
  23162. Confirmed=?
  23163. Filename=gisdnlog.exe
  23164. Description=<a href="http://www.bt.com/homehighway/more_info.htm">BT Digital Access USB</a>
  23165. Source=Paul Collins Startup list
  23166.  
  23167. [Glass2k]
  23168. Number=3290
  23169. Confirmed=U
  23170. Filename=Glass2k.exe
  23171. Description="<a href="http://www.chime.tv/products/glass2k.shtml" target="_blank">Glass2k</a> is a small little program that allows Win2K/XP users to make any window transparent"
  23172. Source=Paul Collins Startup list
  23173.  
  23174. [GLF Network Lan Monitor]
  23175. Number=3291
  23176. Confirmed=X
  23177. Filename=NPFMNTOR.exe
  23178. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotagy.html" target=_blank>RBOT-AGY</a> WORM!
  23179. Source=Paul Collins Startup list
  23180.  
  23181. [Glide]
  23182. Number=3292
  23183. Confirmed=Y
  23184. Filename=Glidew32.exe
  23185. Description=<a href="http://www.cirque.com/" target="_blank">Cirque</a> touchpad driver
  23186. Source=Paul Collins Startup list
  23187.  
  23188. [Global Startup]
  23189. Number=3293
  23190. Confirmed=X
  23191. Filename=WinDash.EXE
  23192. Description=Recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as IM-Worm.Win32.VB.q, may be related to the <a href="http://www.sophos.com/virusinfo/analyses/w32attechc.html" target="_blank">ATTECH-C</a> WORM
  23193. Source=Paul Collins Startup list
  23194.  
  23195. [GlobalSCAPE]
  23196. Number=3294
  23197. Confirmed=X
  23198. Filename=[random filename]
  23199. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaym.html" target=_blank>RBOT-AYM</a> WORM!
  23200. Source=Paul Collins Startup list
  23201.  
  23202. [GLSetIT32]
  23203. Number=3295
  23204. Confirmed=X
  23205. Filename=msiexec16.exe
  23206. Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39482" target="_blank">OPTIX PRO</a> TROJAN!
  23207. Source=Paul Collins Startup list
  23208.  
  23209. [GLSetIT32]
  23210. Number=3296
  23211. Confirmed=X
  23212. Filename=isass.exe
  23213. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39482" target="_blank">OPTIX PRO</a> TROJAN!
  23214. Source=Paul Collins Startup list
  23215.  
  23216. [GLSetT32]
  23217. Number=3297
  23218. Confirmed=X
  23219. Filename=smsiexec.exe
  23220. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojoptixd.html" target=_blank>OPTIX-D</a> TROJAN!
  23221. Source=Paul Collins Startup list
  23222.  
  23223. [gluon]
  23224. Number=3298
  23225. Confirmed=?
  23226. Filename=gluon.exe
  23227. Description=<font color="#FF0000">In a gluon/bin sub-directory</font>
  23228. Source=Paul Collins Startup list
  23229.  
  23230. [glv]
  23231. Number=3299
  23232. Confirmed=X
  23233. Filename=glv.exe
  23234. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderng.html" target= blank>DLOADER-NG</a> TROJAN!
  23235. Source=Paul Collins Startup list
  23236.  
  23237. [GMedia2]
  23238. Number=3300
  23239. Confirmed=X
  23240. Filename=GSM2.exe
  23241. Description=Malware downloader - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan.Win32.VB.ux
  23242. Source=Paul Collins Startup list
  23243.  
  23244. [GMedia2]
  23245. Number=3301
  23246. Confirmed=X
  23247. Filename=GSMedia3.exe
  23248. Description=Malware downloader - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan.Win32.VB.ux
  23249. Source=Paul Collins Startup list
  23250.  
  23251. [Gmouse]
  23252. Number=3302
  23253. Confirmed=Y
  23254. Filename=Gmouse.exe
  23255. Description=Amouse mouse driver - required if you use non-standard Windows driver features
  23256. Source=Paul Collins Startup list
  23257.  
  23258. [Gnetmous]
  23259. Number=3303
  23260. Confirmed=U
  23261. Filename=gnetmous.exe
  23262. Description=<a href="http://www.geniusnet.com/" target="_blank">Genius</a> NetScroll+ mouse driver - required if you use non-standard Windows driver features
  23263. Source=Paul Collins Startup list
  23264.  
  23265. [GNETMOUSE]
  23266. Number=3304
  23267. Confirmed=U
  23268. Filename=gnetmouse.exe
  23269. Description=Genius mouse driver - required if you use non-standard Windows driver features
  23270.  
  23271. Source=Paul Collins Startup list
  23272.  
  23273. [GNP Generic Host Process]
  23274. Number=3305
  23275. Confirmed=X
  23276. Filename=svchost.exe
  23277. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojzapchasf.html" target= blank>ZAPCHAS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
  23278. Source=Paul Collins Startup list
  23279.  
  23280. [GNP Generic Host Process]
  23281. Number=3306
  23282. Confirmed=X
  23283. Filename=svchost.exe
  23284. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojzapchasr.html" target=_blank>ZAPCHAS-R</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup and is always located in the System32 folder. This worm file is found in the System folder
  23285. Source=Paul Collins Startup list
  23286.  
  23287. [GNP Generic Host Process]
  23288. Number=3307
  23289. Confirmed=X
  23290. Filename=svchost.exe
  23291. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojzapchasaa.html" target=_blank>ZAPCHAS-AA</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one replaces svchost.exe in the System32 folder with a copy of Mirc on (NT/2K/XP) systems and just adds svchost.exe to the System folder on (9x/Me) systems
  23292. Source=Paul Collins Startup list
  23293.  
  23294. [gnub]
  23295. Number=3308
  23296. Confirmed=?
  23297. Filename=gnub.exe
  23298. Description=<font color="#FF0000">??</font>
  23299. Source=Paul Collins Startup list
  23300.  
  23301. [go]
  23302. Number=3309
  23303. Confirmed=X
  23304. Filename=cvir.exe
  23305. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32silova.html" target="_blank">SILOV-A</a> WORM!
  23306. Source=Paul Collins Startup list
  23307.  
  23308. [Go!Zilla]
  23309. Number=3310
  23310. Confirmed=X
  23311. Filename=gozilla.exe
  23312. Description=Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
  23313. Source=Paul Collins Startup list
  23314.  
  23315. [Go!Zilla Monster Downloads]
  23316. Number=3311
  23317. Confirmed=X
  23318. Filename=Go.exe
  23319. Description=Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
  23320. Source=Paul Collins Startup list
  23321.  
  23322. [GoBack]
  23323. Number=3312
  23324. Confirmed=U
  23325. Filename=GBMenu.exe
  23326. Description=<a href="http://www.roxio.com/enu/default.html" target="_blank">Roxio's</a> (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
  23327. Source=Paul Collins Startup list
  23328.  
  23329. [GoBack]
  23330. Number=3313
  23331. Confirmed=U
  23332. Filename=GBTray.exe
  23333. Description=System Tray icon access to <a href="http://www.roxio.com/enu/default.html" target="_blank">Roxio's</a> (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
  23334. Source=Paul Collins Startup list
  23335.  
  23336. [GoBack Polling Service]
  23337. Number=3314
  23338. Confirmed=U
  23339. Filename=GBPoll.exe
  23340. Description=<a href="http://www.roxio.com/enu/default.html" target="_blank">Roxio's</a> (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
  23341. Source=Paul Collins Startup list
  23342.  
  23343. [GoBack Tray Icon]
  23344. Number=3315
  23345. Confirmed=U
  23346. Filename=GBTray.exe
  23347. Description=<a href="http://www.roxio.com/enu/default.html" target="_blank">Roxio's</a> (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
  23348. Source=Paul Collins Startup list
  23349.  
  23350. [GOG]
  23351. Number=3316
  23352. Confirmed=X
  23353. Filename=GOG.exe
  23354. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-040217-5954-99" target="_blank">PHILIS.B</a> VIRUS!
  23355. Source=Paul Collins Startup list
  23356.  
  23357. [goidr]
  23358. Number=3317
  23359. Confirmed=X
  23360. Filename=goidr.exe
  23361. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-081916-0353-99" target= blank>Goidr</a> adware
  23362. Source=Paul Collins Startup list
  23363.  
  23364. [Goldensoft_MndlSvr]
  23365. Number=3318
  23366. Confirmed=U
  23367. Filename=MndlSvr.exe
  23368. Description=Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
  23369. Source=Paul Collins Startup list
  23370.  
  23371. [Golum]
  23372. Number=3319
  23373. Confirmed=X
  23374. Filename=services.exe
  23375. Description=Added by the GOLUM.A TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
  23376. Source=Paul Collins Startup list
  23377.  
  23378. [golumm]
  23379. Number=3320
  23380. Confirmed=X
  23381. Filename=services.exe
  23382. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderet.html" target=_blank>DLOADER-ET</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "golumm" subfolder
  23383. Source=Paul Collins Startup list
  23384.  
  23385. [good]
  23386. Number=3321
  23387. Confirmed=X
  23388. Filename=badvir.exe
  23389. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32silovb.html" target="_blank">SILOV-B</a> WORM!
  23390. Source=Paul Collins Startup list
  23391.  
  23392. [google]
  23393. Number=3322
  23394. Confirmed=X
  23395. Filename=google.exe
  23396. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotamw.html" target=_blank>RBOT-AMW</a> WORM!
  23397. Source=Paul Collins Startup list
  23398.  
  23399. [Google Desktop]
  23400. Number=3323
  23401. Confirmed=U
  23402. Filename=GoogleDesktop.exe
  23403. Description=<a href="http://desktop.google.com/about.html" target="_blank">Google Desktop Search</a> - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks"
  23404. Source=Paul Collins Startup list
  23405.  
  23406. [Google Desktop Search]
  23407. Number=3324
  23408. Confirmed=N
  23409. Filename=GoogleDesktop.exe
  23410. Description=<a href="http://desktop.google.com/about.html" target="_blank">Google Desktop Search</a> - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks"
  23411. Source=Paul Collins Startup list
  23412.  
  23413. [Google Earth]
  23414. Number=3325
  23415. Confirmed=X
  23416. Filename=[random filename]
  23417. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaxk.html" target=_blank>RBOT-AXK</a> TROJAN!
  23418. Source=Paul Collins Startup list
  23419.  
  23420. [Google Earth Viewer]
  23421. Number=3326
  23422. Confirmed=N
  23423. Filename=GOOGLEMAPS.EXE
  23424. Description=<a href="http://earth.google.com/" target=_blank>Google Earth</a> "combines satellite imagery, maps and the power of Google Search to put the world's geographic information at your fingertips"
  23425. Source=Paul Collins Startup list
  23426.  
  23427. [google Intrenet Explorer]
  23428. Number=3327
  23429. Confirmed=X
  23430. Filename=google.pif
  23431. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotara.html" target=_blank>RBOT-ARA</a> WORM!
  23432. Source=Paul Collins Startup list
  23433.  
  23434. [Google service]
  23435. Number=3328
  23436. Confirmed=X
  23437. Filename=Googlesetup.exe
  23438. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32ircbotrj.html" target="_blank">IRCBOT-RJ</a> WORM!
  23439. Source=Paul Collins Startup list
  23440.  
  23441. [google toolbar]
  23442. Number=3329
  23443. Confirmed=X
  23444. Filename=ggtb32.exe
  23445. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotrr.html" target= blank>AGOBOT-RR</a> WORM!
  23446. Source=Paul Collins Startup list
  23447.  
  23448. [Google Updater]
  23449. Number=3330
  23450. Confirmed=N
  23451. Filename=GOOGLE~1.EXE
  23452. Description=Downloads and installs updates for Google applications (Google Earth, Google Desktop, etc.)
  23453. Source=Paul Collins Startup list
  23454.  
  23455. [GoogleDCClient]
  23456. Number=3331
  23457. Confirmed=N
  23458. Filename=GoogleDCC.exe
  23459. Description=<a href="http://en.wikipedia.org/wiki/Google_Toolbar#Google_Compute" target="_blank">Google Compute Client</a> - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing". No longer supported
  23460. Source=Paul Collins Startup list
  23461.  
  23462. [googletalk]
  23463. Number=3332
  23464. Confirmed=U
  23465. Filename=googletalk.exe
  23466. Description=<a href="http://www.google.com/talk/" target=_blank>Google Talk</a> "enables you to call or send instant messages to your friends for free-anytime, anywhere in the world". Can be launched manually
  23467. Source=Paul Collins Startup list
  23468.  
  23469. [GoToMyPC]
  23470. Number=3333
  23471. Confirmed=U
  23472. Filename=g2svc.exe
  23473. Description=<a href="https://www.gotomypc.com/en_US/entry.tmpl?_sid=143317649%3A2E0C1B936B629C7&Action=rgoto&_sf=2" target="_blank">ExpertCity GoToMyPc</a> logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser
  23474. Source=Paul Collins Startup list
  23475.  
  23476. [GotSmiley]
  23477. Number=3334
  23478. Confirmed=X
  23479. Filename=GotSmiley.exe
  23480. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Claria.GotSmiley&threatid=40046" target="_blank">GotSmiley</a> - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  23481. Source=Paul Collins Startup list
  23482.  
  23483. [gouday.exe]
  23484. Number=3335
  23485. Confirmed=X
  23486. Filename=readme.exe
  23487. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-022715-1724-99" target="_blank">BEAGLE.C</a> WORM!
  23488. Source=Paul Collins Startup list
  23489.  
  23490. [GRA]
  23491. Number=3336
  23492. Confirmed=N
  23493. Filename=gra.exe
  23494. Description=Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility
  23495. Source=Paul Collins Startup list
  23496.  
  23497. [gramdate]
  23498. Number=3337
  23499. Confirmed=?
  23500. Filename=2Stop.exe
  23501. Description=<font color="#FF0000">??</font>
  23502. Source=Paul Collins Startup list
  23503.  
  23504. [Graphic Driver]
  23505. Number=3338
  23506. Confirmed=X
  23507. Filename=smss32.exe
  23508. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  23509. Source=Paul Collins Startup list
  23510.  
  23511. [Graphic Loader]
  23512. Number=3339
  23513. Confirmed=X
  23514. Filename=ntvdm32.exe
  23515. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  23516. Source=Paul Collins Startup list
  23517.  
  23518. [Gravis Appawareloader]
  23519. Number=3340
  23520. Confirmed=U
  23521. Filename=dbserver.exe
  23522. Description=Looks like it's associated with <a href="http://www.gravis.com/" target="_blank"> Gravis</a> game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them
  23523. Source=Paul Collins Startup list
  23524.  
  23525. [Gravis Xperience Driver Support]
  23526. Number=3341
  23527. Confirmed=U
  23528. Filename=Grxp4exe.exe
  23529. Description=Driver for <a href="http://www.gravis.com/" target="_blank">Gravis</a> game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used
  23530. Source=Paul Collins Startup list
  23531.  
  23532. [GrdSys32]
  23533. Number=3342
  23534. Confirmed=?
  23535. Filename=GrdSys32.exe
  23536. Description=X-Stream ISP software. Offers free Net access funded by on-screen ads. <font color="#FF0000">Is it required or can you create your own dial-up networking connection to use on demand?</font>
  23537. Source=Paul Collins Startup list
  23538.  
  23539. [Greetings Workshop]
  23540. Number=3343
  23541. Confirmed=N
  23542. Filename=GWREMIND.EXE
  23543. Description=You really want to be reminded about somebody's birthday at the expense of resources?
  23544. Source=Paul Collins Startup list
  23545.  
  23546. [gremier]
  23547. Number=3344
  23548. Confirmed=X
  23549. Filename=wscript.exe gpremier.vbs
  23550. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-020622-3859-99" target="_blank">GPREMIER</a> WORM!
  23551. Source=Paul Collins Startup list
  23552.  
  23553. [Gremlin]
  23554. Number=3345
  23555. Confirmed=X
  23556. Filename=intrenat.exe
  23557. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-020909-2916-99" target="_blank">DOOMJUICE</a> WORM!
  23558. Source=Paul Collins Startup list
  23559.  
  23560. [Grokster]
  23561. Number=3346
  23562. Confirmed=N
  23563. Filename=Grokster.exe
  23564. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453060425" target="_blank">Grokster</a> Peer-To-Peer File Sharing program
  23565. Source=Paul Collins Startup list
  23566.  
  23567. [GrooveMonitor]
  23568. Number=3347
  23569. Confirmed=Y
  23570. Filename=GrooveMonitor.exe
  23571. Description=Microsoft Office <a href="http://office.microsoft.com/en-us/groove/HA101680011033.aspx" target="_blank">Groove 2007</a> - Groove Folder Sharing synchronization (GFS). If you kill it, your GFS workspaces may not synchronize properly (particularly around unread-marks), and you might experience some nagging discomfort
  23572. Source=Paul Collins Startup list
  23573.  
  23574. [GrpConv]
  23575. Number=3348
  23576. Confirmed=N
  23577. Filename=grpconv.exe
  23578. Description=Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see <a href="http://support.microsoft.com/?kbid=119941" target= blank>this</a> MS Knowledge Base article
  23579. Source=Paul Collins Startup list
  23580.  
  23581. [GsAds]
  23582. Number=3349
  23583. Confirmed=X
  23584. Filename=gms2.exe
  23585. Description=<a href="http://www.benedelman.org/spyware/installations/pacerd/" target=_blank>PacerD_Media/Pacimedia.com</a> adware
  23586. Source=Paul Collins Startup list
  23587.  
  23588. [Gscbc]
  23589. Number=3350
  23590. Confirmed=?
  23591. Filename=Gscbc.exe
  23592. Description=<font color="#FF0000">??</font>
  23593. Source=Paul Collins Startup list
  23594.  
  23595. [gshp]
  23596. Number=3351
  23597. Confirmed=X
  23598. Filename=zzgshp.vbs
  23599. Description=Homepage hi-jacker
  23600. Source=Paul Collins Startup list
  23601.  
  23602. [Gsiconexe]
  23603. Number=3352
  23604. Confirmed=N
  23605. Filename=Gsicon.exe
  23606. Description=ADSL modem monitor from <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities
  23607. Source=Paul Collins Startup list
  23608.  
  23609. [GsiFinal]
  23610. Number=3353
  23611. Confirmed=?
  23612. Filename=rundll32 gspndll.dll, postInstall final
  23613. Description=USB DSL modem related - [what does it do and is it required in startup?</font>
  23614. Source=Paul Collins Startup list
  23615.  
  23616. [GSISETUP]
  23617. Number=3354
  23618. Confirmed=?
  23619. Filename=[path] GsiInst.exe INSTALL [path] V205Res 13
  23620. Description=BT Voyager ADSL modem related - <font color="#FF0000">what does it do and is it required?</font>
  23621. Source=Paul Collins Startup list
  23622.  
  23623. [GSOrganizer]
  23624. Number=3355
  23625. Confirmed=N
  23626. Filename=GSOrganizer.exe
  23627. Description=<a href="http://www.tgslabs.com/en/winorganizer/" target="_blank">GoldenSection Organizer</a> (now WinOrganizer - personal information manager
  23628. Source=Paul Collins Startup list
  23629.  
  23630. [gssomatic]
  23631. Number=3356
  23632. Confirmed=X
  23633. Filename=gssomatic.exe
  23634. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453077927" target="_blank">Searchcentrix</a> hijacker
  23635. Source=Paul Collins Startup list
  23636.  
  23637. [GStartup]
  23638. Number=3357
  23639. Confirmed=X
  23640. Filename=GMT.exe
  23641. Description=Gator spyware component - see <a href="http://www.cexx.org/gator.htm" target="_blank">here</a>. Please note that Claria Corporation no longer support GAIN-Supported software - see <a href="http://www.claria.com/gainexit/" target="_blank">here</a>
  23642. Source=Paul Collins Startup list
  23643.  
  23644. [gsv]
  23645. Number=3358
  23646. Confirmed=X
  23647. Filename=gsv.exe
  23648. Description=Added by the ROBAL 1.0 backdoor TROJAN!
  23649. Source=Paul Collins Startup list
  23650.  
  23651. [GT]
  23652. Number=3359
  23653. Confirmed=X
  23654. Filename=GT.EXE
  23655. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotaj.html" target="_blank">SDBOT-AJ</a> WORM!
  23656. Source=Paul Collins Startup list
  23657.  
  23658. [GTVEpg]
  23659. Number=3360
  23660. Confirmed=U
  23661. Filename=GTVEpg.exe
  23662. Description=Part of <a href="http://www.gallm.com/" target="_blank">Got All Media</a> - control your TV tuner and other utilities from your PC
  23663. Source=Paul Collins Startup list
  23664.  
  23665. [GTVRec]
  23666. Number=3361
  23667. Confirmed=X
  23668. Filename=GTVRec.exe
  23669. Description=Part of <a href="http://www.gallm.com/" target="_blank">Got All Media</a> - control your TV tuner and other utilities from your PC
  23670. Source=Paul Collins Startup list
  23671.  
  23672. [Gtwatch]
  23673. Number=3362
  23674. Confirmed=N
  23675. Filename=gtwatch.exe
  23676. Description=Associated with a Mustec scanner and not required
  23677. Source=Paul Collins Startup list
  23678.  
  23679. [gtydf]
  23680. Number=3363
  23681. Confirmed=X
  23682. Filename=iisca.exe
  23683. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojclaggerbb.html" target="_blank">CLAGGER-BB</a> TROJAN!
  23684. Source=Paul Collins Startup list
  23685.  
  23686. [gtydf]
  23687. Number=3364
  23688. Confirmed=X
  23689. Filename=iscca.exe
  23690. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdwnldrgtk.html" target="_blank">DWNLDR-GTK</a> TROJAN!
  23691. Source=Paul Collins Startup list
  23692.  
  23693. [Guard]
  23694. Number=3365
  23695. Confirmed=U
  23696. Filename=Guard.exe
  23697. Description=Related to <a href="http://www.phoenix.com/" target=_blank>Phoenix Technologies</a> Core Managed Environment (cME) Integration and Certification program
  23698. Source=Paul Collins Startup list
  23699.  
  23700. [Guardian]
  23701. Number=3366
  23702. Confirmed=N
  23703. Filename=CMGrdian.exe
  23704. Description=McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
  23705. Source=Paul Collins Startup list
  23706.  
  23707. [Guardian PC Security Tools]
  23708. Number=3367
  23709. Confirmed=U
  23710. Filename=Pfft.exe
  23711. Description=Boomerang Software's Guardian PC Security Tools - now rebranded as the <a href="http://www.boomerangsoftware.com/Products/Security/eSecurity.htm" target=_blank>eXtendia Security Suite</a>
  23712.  
  23713. Source=Paul Collins Startup list
  23714.  
  23715. [guarnset]
  23716. Number=3368
  23717. Confirmed=X
  23718. Filename=guarnset.exe
  23719. Description=<a href="http://sarc.com/avcenter/venc/data/adware.adlogix.html" target="_blank">Adlogix</a> adware
  23720. Source=Paul Collins Startup list
  23721.  
  23722. [GURL]
  23723. Number=3369
  23724. Confirmed=X
  23725. Filename=gurl.exe
  23726. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-063018-3752-99" target="_blank">GURLWatcher</a> spyware
  23727. Source=Paul Collins Startup list
  23728.  
  23729. [GuruNet]
  23730. Number=3370
  23731. Confirmed=U
  23732. Filename=GuruNet.exe
  23733. Description=<a href="http://www.gurunet.com/what_tools.jsp" target=_blank>GuruNet</a> lets you click on any word on your screen to get the relevant information you want
  23734. Source=Paul Collins Startup list
  23735.  
  23736. [GustavVED]
  23737. Number=3371
  23738. Confirmed=X
  23739. Filename=[filename].exe
  23740. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-111119-3659-99" target="_blank">OPASERV.H</a> WORM!
  23741. Source=Paul Collins Startup list
  23742.  
  23743. [gvagfxj]
  23744. Number=3372
  23745. Confirmed=X
  23746. Filename=rundll32 ...gvagfxj.dll
  23747. Description=Unidentified adware, spyware or virus
  23748. Source=Paul Collins Startup list
  23749.  
  23750. [gw port controller]
  23751. Number=3373
  23752. Confirmed=Y
  23753. Filename=PORTCT95.EXE
  23754. Description=From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by Samsung
  23755. Source=Paul Collins Startup list
  23756.  
  23757. [GWInkMonitor]
  23758. Number=3374
  23759. Confirmed=N
  23760. Filename=GWInkMonitor.exe
  23761. Description=Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!
  23762. Source=Paul Collins Startup list
  23763.  
  23764. [gwiz]
  23765. Number=3375
  23766. Confirmed=X
  23767. Filename=ntsystem.exe
  23768. Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=58686" target="_blank">NITWIZ.A</a> TROJAN!
  23769. Source=Paul Collins Startup list
  23770.  
  23771. [GWMDMMSG]
  23772. Number=3376
  23773. Confirmed=N
  23774. Filename=GWMDMMSG.exe
  23775. Description=Used with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
  23776. Source=Paul Collins Startup list
  23777.  
  23778. [GWMDMpi]
  23779. Number=3377
  23780. Confirmed=U
  23781. Filename=GWMDMpi.exe
  23782. Description=Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See <a href="http://support.gateway.com/support/drivers/moreinfo.asp?readmeURL=ftp%3A//ftp.gateway.com/pub/hardware_support/drivers/win_xp/portable/450sx4/7512994.txt" target="_blank">here</a> for more information
  23783. Source=Paul Collins Startup list
  23784.  
  23785. [gwum]
  23786. Number=3378
  23787. Confirmed=U
  23788. Filename=gwum.exe
  23789. Description=Gigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers"
  23790. Source=Paul Collins Startup list
  23791.  
  23792. [gyy]
  23793. Number=3379
  23794. Confirmed=?
  23795. Filename=gyy.exe
  23796. Description=<font color="#FF0000">Possibly <a href="#Gator">Gator</a> (and therefore spyware) related?</font>
  23797. Source=Paul Collins Startup list
  23798.  
  23799. [G_Server.exe]
  23800. Number=3380
  23801. Confirmed=X
  23802. Filename=G_Server.exe
  23803. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojfeutelc.html" target=_blank>FEUTEL-C</a> TROJAN!
  23804. Source=Paul Collins Startup list
  23805.  
  23806. [G_Server1.2.exe]
  23807. Number=3381
  23808. Confirmed=X
  23809. Filename=G_Server1.2.exe
  23810. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojgraybirdz.html" target=_blank>GRAYBIRD-Z</a> TROJAN!
  23811. Source=Paul Collins Startup list
  23812.  
  23813. [H/PC Connection Agent]
  23814. Number=3382
  23815. Confirmed=U
  23816. Filename=WCESCOMM.EXE
  23817. Description=Active sync for use with Windows CE based palm PC
  23818. Source=Paul Collins Startup list
  23819.  
  23820. [H2OWIBU]
  23821. Number=3383
  23822. Confirmed=U
  23823. Filename=CXWibu.exe
  23824. Description=Related to <a href="http://wibu.com/start.php?lang=en" target="_blank">CodeMeter</a> from WIBU-SYSTEMS AG. Software protection hardware
  23825. Source=Paul Collins Startup list
  23826.  
  23827. [h4te Service Drivers]
  23828. Number=3384
  23829. Confirmed=X
  23830. Filename=h4te.exe
  23831. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
  23832. Source=Paul Collins Startup list
  23833.  
  23834. [hachimitsu-lemon]
  23835. Number=3385
  23836. Confirmed=X
  23837. Filename=hachimitsu-lemon.exe
  23838. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-070812-1520-99" target=_blank>HACHILEM</a> TROJAN!
  23839. Source=Paul Collins Startup list
  23840.  
  23841. [hagent]
  23842. Number=3386
  23843. Confirmed=X
  23844. Filename=avp.exe
  23845. Description=Added by the "Herman Agent" remote access TROJAN!
  23846. Source=Paul Collins Startup list
  23847.  
  23848. [HalifaxHowardCluster]
  23849. Number=3387
  23850. Confirmed=U
  23851. Filename=skinkers.exe
  23852. Description="Howard the Weatherman" desktop client from Halifax by <a href="http://www.skinkers.com/" target="_blank">Skinkers</a> - marketing/messaging tool. Leave enabled if you want to receive messages
  23853. Source=Paul Collins Startup list
  23854.  
  23855. [HaMFrontPanel]
  23856. Number=3388
  23857. Confirmed=U
  23858. Filename=hampanel.exe
  23859. Description=Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless
  23860. Source=Paul Collins Startup list
  23861.  
  23862. [Handy Backup 3.9]
  23863. Number=3389
  23864. Confirmed=U
  23865. Filename=hbagent.exe
  23866. Description=<a href="http://www.handybackup.com/" target="_blank">Handy Backup</a> - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers
  23867. Source=Paul Collins Startup list
  23868.  
  23869. [HanUpdate]
  23870. Number=3390
  23871. Confirmed=X
  23872. Filename=hanz.exe
  23873. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotglj.html" target="_blank">RBOT-GLJ</a> WORM!
  23874. Source=Paul Collins Startup list
  23875.  
  23876. [Hard drive Controller]
  23877. Number=3391
  23878. Confirmed=X
  23879. Filename=hdcontroller.exe
  23880. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-020812-4733-99" target=_blank>KIMAN.B</a> WORM!
  23881. Source=Paul Collins Startup list
  23882.  
  23883. [Hardware Doctor]
  23884. Number=3392
  23885. Confirmed=U
  23886. Filename=Hwdoctor.exe
  23887. Description=Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you're concerned about your system temperature - typically for "overclocked" systems
  23888. Source=Paul Collins Startup list
  23889.  
  23890. [Hardware Monitor Service]
  23891. Number=3393
  23892. Confirmed=X
  23893. Filename=mshms.exe
  23894. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojwollfa.html" target=_blank>WOLLF-A</a> TROJAN!
  23895. Source=Paul Collins Startup list
  23896.  
  23897. [Hardware Profile]
  23898. Number=3394
  23899. Confirmed=X
  23900. Filename=hxdef.exe
  23901. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-021916-4352-99" target="_blank">LOVGATE</a> WORM!
  23902. Source=Paul Collins Startup list
  23903.  
  23904. [Hardware Profile]
  23905. Number=3395
  23906. Confirmed=X
  23907. Filename=hxdef.exe...
  23908. Description=Added by a variant of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-021916-4352-99" target="_blank">LOVGATE</a> WORM!
  23909. Source=Paul Collins Startup list
  23910.  
  23911. [Hardware Sensors Monitor]
  23912. Number=3396
  23913. Confirmed=U
  23914. Filename=hmonitor.exe
  23915. Description=Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
  23916. Source=Paul Collins Startup list
  23917.  
  23918. [Hardware Shell Detection]
  23919. Number=3397
  23920. Confirmed=X
  23921. Filename=WinHSD.exe
  23922. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
  23923. Source=Paul Collins Startup list
  23924.  
  23925. [Hare]
  23926. Number=3398
  23927. Confirmed=U
  23928. Filename=hare.exe
  23929. Description=<a href="http://www.foxpop.ndirect.co.uk/pc/dachshund_03.htm" target="_blank">Hare</a> - improve and optimize performance of desktop/laptop PCs
  23930. Source=Paul Collins Startup list
  23931.  
  23932. [HATAPE]
  23933. Number=3399
  23934. Confirmed=X
  23935. Filename=[path to trojan]
  23936. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerqf.html" target=_blank>BANKER-QF</a> TROJAN!
  23937. Source=Paul Collins Startup list
  23938.  
  23939. [HawkEye]
  23940. Number=3400
  23941. Confirmed=U
  23942. Filename=HAWK_95.EXE
  23943. Description=Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
  23944. Source=Paul Collins Startup list
  23945.  
  23946. [HawkEye IV Control Panel]
  23947. Number=3401
  23948. Confirmed=U
  23949. Filename=HAWK_32.EXE
  23950. Description=Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
  23951. Source=Paul Collins Startup list
  23952.  
  23953. [Hbinst]
  23954. Number=3402
  23955. Confirmed=X
  23956. Filename=Hbinst.exe
  23957. Description=<a href="http://www.hotbar.com/" target="_blank">Hotbar</a> enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see <a href="http://www.safersite.com/pestinfo/H/HotBar_Adware.asp" target="_blank">here</a>
  23958. Source=Paul Collins Startup list
  23959.  
  23960. [HC Reminder]
  23961. Number=3403
  23962. Confirmed=N
  23963. Filename=hc.exe
  23964. Description=For Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed
  23965. Source=Paul Collins Startup list
  23966.  
  23967. [HCDetect]
  23968. Number=3404
  23969. Confirmed=N
  23970. Filename=HCDetect.exe
  23971. Description=MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem
  23972. Source=Paul Collins Startup list
  23973.  
  23974. [hcenter]
  23975. Number=3405
  23976. Confirmed=U
  23977. Filename=tgcmd.exe
  23978. Description=See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by <a href="http://www.cox.com/policy/#pp_1" target="_blank">Cox</a> Regarded as spyware by <a href="http://www.answersthatwork.com/Tasklist_pages/tasklist_t.htm" target="_blank">some</a> as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
  23979. Source=Paul Collins Startup list
  23980.  
  23981. [hclean32.exe]
  23982. Number=3406
  23983. Confirmed=X
  23984. Filename=hclean32.exe
  23985. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Misc.WareOut&threatid=40280" target=_blank>Wareout</a> - malware masquerading as a spyware and dialer remover
  23986. Source=Paul Collins Startup list
  23987.  
  23988. [Hcontrol]
  23989. Number=3407
  23990. Confirmed=U
  23991. Filename=hcontrol.exe
  23992. Description=Hotkeys on an ASUS Notebook. Only required if you use the additional keys
  23993. Source=Paul Collins Startup list
  23994.  
  23995. [hcsystray]
  23996. Number=3408
  23997. Confirmed=N
  23998. Filename=hc_tray.exe
  23999. Description=<a href="http://www.kumagames.com/help.html#shootout" target="_blank">Kuma Notifier</a> for the <a href="http://www.history.com/minisites/shootout/" target="_blank">Shootout!</a> game from the History Channel. "It lets you know whenever thereÆs a new episode thatÆs been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"
  24000. Source=Paul Collins Startup list
  24001.  
  24002. [HDAShCut]
  24003. Number=3409
  24004. Confirmed=N
  24005. Filename=HDAShCut.exe
  24006. Description=High definition audio page shortcut - not required
  24007. Source=Paul Collins Startup list
  24008.  
  24009. [HDAudio]
  24010. Number=3410
  24011. Confirmed=X
  24012. Filename=hda.exe
  24013. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.U</a> TROJAN!
  24014. Source=Paul Collins Startup list
  24015.  
  24016. [HDAudio Driver 1.0]
  24017. Number=3411
  24018. Confirmed=X
  24019. Filename=[random filename].exe
  24020. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojteadoord.html" target=_blank>TEADOOR-D</a> TROJAN!
  24021. Source=Paul Collins Startup list
  24022.  
  24023. [HDAudio Driver 2.0]
  24024. Number=3412
  24025. Confirmed=X
  24026. Filename=[random filename].exe
  24027. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojteadoore.html" target=_blank>TEADOOR-E</a> TROJAN!
  24028. Source=Paul Collins Startup list
  24029.  
  24030. [HDDHealth]
  24031. Number=3413
  24032. Confirmed=U
  24033. Filename=hddhealth.exe
  24034. Description=<a href="http://www.panterasoft.com/" target=_blank>HDD Health</a> is a "full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure" 
  24035. Source=Paul Collins Startup list
  24036.  
  24037. [HDDlife]
  24038. Number=3414
  24039. Confirmed=U
  24040. Filename=HDDlife.exe
  24041. Description=<a href="http://www.hddlife.com/" target=_blank>HDDlife</a> checks the health of your hard drives at regular intervals and informs you about the results of these checks
  24042. Source=Paul Collins Startup list
  24043.  
  24044. [HDhelp]
  24045. Number=3415
  24046. Confirmed=?
  24047. Filename=tbhdhelp.exe
  24048. Description=Associated with Philips Edge series soundcards. <font color="#FF0000">Is it required?</font>
  24049. Source=Paul Collins Startup list
  24050.  
  24051. [hdlfoe df98ndf]
  24052. Number=3416
  24053. Confirmed=X
  24054. Filename=svchots.exe
  24055. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
  24056. Source=Paul Collins Startup list
  24057.  
  24058. [hdlpscom]
  24059. Number=3417
  24060. Confirmed=X
  24061. Filename=[8 random letters].exe
  24062. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotful.html" target="_blank">RBOT-FUL</a> WORM!
  24063. Source=Paul Collins Startup list
  24064.  
  24065. [HDtray]
  24066. Number=3418
  24067. Confirmed=N
  24068. Filename=HDtray.exe
  24069. Description=Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
  24070. Source=Paul Collins Startup list
  24071.  
  24072. [he3bbcff]
  24073. Number=3419
  24074. Confirmed=X
  24075. Filename=rundll32.exe [path] he3bbcff.dll, EnableRunDLL32
  24076. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target=_blank>LZIO.com</a> adware downloader
  24077. Source=Paul Collins Startup list
  24078.  
  24079. [he3e3fc4]
  24080. Number=3420
  24081. Confirmed=X
  24082. Filename=rundll32.exe [path] he3e3fc4.dll, EnableRunDLL32
  24083. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target="_blank">LZIO.com</a> adware downloader
  24084. Source=Paul Collins Startup list
  24085.  
  24086. [HELLBOT TEST]
  24087. Number=3421
  24088. Confirmed=X
  24089. Filename=1hellbot.exe
  24090. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050803-1959-99" target= blank>MYDOOM.BO</a> WORM!
  24091. Source=Paul Collins Startup list
  24092.  
  24093. [HELLBOT3]
  24094. Number=3422
  24095. Confirmed=X
  24096. Filename=coolbot.exe
  24097. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.AB&VSect=T" target=_blank>MYTOB.AB</a> WORM!
  24098. Source=Paul Collins Startup list
  24099.  
  24100. [hellodolly]
  24101. Number=3423
  24102. Confirmed=X
  24103. Filename=shost.exe
  24104. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082916-1108-99" target="_blank">YODO</a> WORM!
  24105. Source=Paul Collins Startup list
  24106.  
  24107. [helloworld]
  24108. Number=3424
  24109. Confirmed=X
  24110. Filename=nb32ext2.exe
  24111. Description=Added by the <a href="http://vil.nai.com/vil/content/v_135474.htm" target=_blank>MYDOOM.BV</a> WORM!
  24112. Source=Paul Collins Startup list
  24113.  
  24114. [helloworld]
  24115. Number=3425
  24116. Confirmed=X
  24117. Filename=nb32ext3.exe
  24118. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYTOB.JT&VSect=P" target=_blank>MYTOB.JT</a> WORM!
  24119. Source=Paul Collins Startup list
  24120.  
  24121. [Help]
  24122. Number=3426
  24123. Confirmed=?
  24124. Filename=helpext.exe
  24125. Description=<font color="#FF0000">??</font>
  24126. Source=Paul Collins Startup list
  24127.  
  24128. [help]
  24129. Number=3427
  24130. Confirmed=X
  24131. Filename=help.scr
  24132. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancosbbu.html" target="_blank">BANCOS-BBU</a> TROJAN!
  24133. Source=Paul Collins Startup list
  24134.  
  24135. [Help Temp Files]
  24136. Number=3428
  24137. Confirmed=X
  24138. Filename=netreg.exe
  24139. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotem.html" target= blank>FORBOT-EM</a> WORM!
  24140. Source=Paul Collins Startup list
  24141.  
  24142. [helpctl.exe]
  24143. Number=3429
  24144. Confirmed=X
  24145. Filename=helpctl.exe
  24146. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-082609-2823-99" target="_blank">GASLIDE</a> TROJAN!
  24147. Source=Paul Collins Startup list
  24148.  
  24149. [Helper]
  24150. Number=3430
  24151. Confirmed=X
  24152. Filename=eschlp.exe
  24153. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042117-1932-99" target="_blank">BLASTER.T</a> WORM!
  24154. Source=Paul Collins Startup list
  24155.  
  24156. [HELPER]
  24157. Number=3431
  24158. Confirmed=X
  24159. Filename=greece nm.exe
  24160. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  24161.  
  24162. Source=Paul Collins Startup list
  24163.  
  24164. [HELPER]
  24165. Number=3432
  24166. Confirmed=X
  24167. Filename=Netherlands.exe
  24168. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  24169. Source=Paul Collins Startup list
  24170.  
  24171. [HELPER]
  24172. Number=3433
  24173. Confirmed=X
  24174. Filename=new zealand.exe
  24175. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  24176. Source=Paul Collins Startup list
  24177.  
  24178. [HELPER]
  24179. Number=3434
  24180. Confirmed=X
  24181. Filename=sweden.exe
  24182. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  24183. Source=Paul Collins Startup list
  24184.  
  24185. [HELPER]
  24186. Number=3435
  24187. Confirmed=X
  24188. Filename=canada.exe
  24189. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialler variant
  24190. Source=Paul Collins Startup list
  24191.  
  24192. [HELPER]
  24193. Number=3436
  24194. Confirmed=X
  24195. Filename=france.exe
  24196. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialler variant
  24197. Source=Paul Collins Startup list
  24198.  
  24199. [HELPER]
  24200. Number=3437
  24201. Confirmed=X
  24202. Filename=temp532.exe
  24203. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialler variant
  24204. Source=Paul Collins Startup list
  24205.  
  24206. [helper.dll]
  24207. Number=3438
  24208. Confirmed=X
  24209. Filename=[path] rundll32.exe [path] helper.dll
  24210. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=3721%20Chinese%20Keywords%20(CNSMin)&threatid=3678" target=_blank>CnsMin</a> (Chinese Keywords) hijacker related
  24211. Source=Paul Collins Startup list
  24212.  
  24213. [HelpExp.exe]
  24214. Number=3439
  24215. Confirmed=X
  24216. Filename=HelpExp.exe
  24217. Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079" target="_blank">here</a>
  24218. Source=Paul Collins Startup list
  24219.  
  24220. [helpmanager]
  24221. Number=3440
  24222. Confirmed=X
  24223. Filename=spoler.exe
  24224. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-090510-4423-99" target="_blank">RANDEX.J</a> WORM!
  24225. Source=Paul Collins Startup list
  24226.  
  24227. [helpw]
  24228. Number=3441
  24229. Confirmed=X
  24230. Filename=helpw.exe
  24231. Description=Adware downloader
  24232.  
  24233. Source=Paul Collins Startup list
  24234.  
  24235. [hen]
  24236. Number=3442
  24237. Confirmed=X
  24238. Filename=[filename].exe
  24239. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-042617-4204-99" target="_blank">TARNO.G</a> TROJAN!
  24240. Source=Paul Collins Startup list
  24241.  
  24242. [heomstool]
  24243. Number=3443
  24244. Confirmed=X
  24245. Filename=heomstool.exe
  24246. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-110911-5626-99" target=_blank>HEOMS</a> TROJAN!
  24247. Source=Paul Collins Startup list
  24248.  
  24249. [hErcUnes]
  24250. Number=3444
  24251. Confirmed=X
  24252. Filename=softhost.exe
  24253. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112712-4629-99" target=_blank>GARROCH</a> WORM!
  24254. Source=Paul Collins Startup list
  24255.  
  24256. [Hermes Messenger]
  24257. Number=3445
  24258. Confirmed=U
  24259. Filename=DGDRHE~1.EXE
  24260. Description=A LAN messenger alternative to WinPopUp - <a href="http://www.dgdr.com/" target="_blank">Digital Dreams Software</a>
  24261. Source=Paul Collins Startup list
  24262.  
  24263. [Hewlett Packard Manager]
  24264. Number=3446
  24265. Confirmed=X
  24266. Filename=hpmanager.exe
  24267. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-100711-1841-99" target=_blank>MYTOB.KE</a> WORM! Note - this is not a valid Hewlett-Packard program
  24268. Source=Paul Collins Startup list
  24269.  
  24270. [Hewlett Packard Recorder]
  24271. Number=3447
  24272. Confirmed=N
  24273. Filename=Remind32.exe
  24274. Description=HP multifunction registration
  24275. Source=Paul Collins Startup list
  24276.  
  24277. [Hf]
  24278. Number=3448
  24279. Confirmed=U
  24280. Filename=Hf.exe
  24281. Description=<a href="http://www.fspro.net/hide-folders/" target="_blank">Hide Folders</a> - hide your folders so only you can view them
  24282. Source=Paul Collins Startup list
  24283.  
  24284. [HF Security]
  24285. Number=3449
  24286. Confirmed=X
  24287. Filename=hfsecure.exe
  24288. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotti.html" target=_blank>AGOBOT-TI</a> WORM!
  24289. Source=Paul Collins Startup list
  24290.  
  24291. [hffsrv]
  24292. Number=3450
  24293. Confirmed=U
  24294. Filename=hffsrv.exe
  24295. Description=<a href="http://www.softstack.com/hff.html" target=_blank>Hide Files & Folders</a> is a "password-protected security utility working at the Windows kernel level allowing you to password-protect files and folders, or to hide them securely from viewing and searching"
  24296. Source=Paul Collins Startup list
  24297.  
  24298. [hfxp]
  24299. Number=3451
  24300. Confirmed=U
  24301. Filename=hfxp.exe
  24302. Description=<a href="http://www.fspro.net/hide-folders-xp/" target="_blank">Hide Folders XP</a> - hide your folders so only you can view them
  24303. Source=Paul Collins Startup list
  24304.  
  24305. [hgqhp.exe]
  24306. Number=3452
  24307. Confirmed=X
  24308. Filename=hgqhp.exe
  24309. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-091512-3355-99" target=_blank>FLUSH.F</a> TROJAN!
  24310. Source=Paul Collins Startup list
  24311.  
  24312. [HGTXPEI]
  24313. Number=3453
  24314. Confirmed=N
  24315. Filename=FirstReboot.exe
  24316. Description=Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
  24317. Source=Paul Collins Startup list
  24318.  
  24319. [HiberMonitor]
  24320. Number=3454
  24321. Confirmed=?
  24322. Filename=HCount.exe
  24323. Description=<font color="#FF0000">??</font>
  24324. Source=Paul Collins Startup list
  24325.  
  24326. [Hibernation]
  24327. Number=3455
  24328. Confirmed=U
  24329. Filename=hib32.exe
  24330. Description=Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly
  24331. Source=Paul Collins Startup list
  24332.  
  24333. [Hid.exe]
  24334. Number=3456
  24335. Confirmed=X
  24336. Filename=hid.exe
  24337. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-051918-1128-99" target="_blank">RATSOU.B</a> TROJAN!
  24338. Source=Paul Collins Startup list
  24339.  
  24340. [HideOE]
  24341. Number=3457
  24342. Confirmed=U
  24343. Filename=HideOE.exe
  24344. Description=<a href="http://www.r2.com.au/software.php?page=2&show=hideoe&PHPSESSID=2256bb0c52a103fac2bd9a885f0ca787" target=_blank>HideOE</a> - allows you to 'hide' Outlook Express or minimize it to the System Tray
  24345. Source=Paul Collins Startup list
  24346.  
  24347. [HideRun.exe]
  24348. Number=3458
  24349. Confirmed=X
  24350. Filename=Hiderun.exe and svhost.exe and pro.gif
  24351. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-072806-1847-99" target="_blank">BOOHOO</a> WORM!
  24352. Source=Paul Collins Startup list
  24353.  
  24354. [HideStyle]
  24355. Number=3459
  24356. Confirmed=X
  24357. Filename=Ante Browse Trust.exe
  24358. Description=IE toolbar taking you to Lop.com. If the exe is running, end it and remove the "Stupidmore" directory from C:\Program Files
  24359. Source=Paul Collins Startup list
  24360.  
  24361. [hidserv]
  24362. Number=3460
  24363. Confirmed=U
  24364. Filename=hidserv.exe
  24365. Description=This is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See <a href="http://www.microsoft.com/whdc/device/input/audctrl.mspx" target="_blank">here</a>. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards
  24366. Source=Paul Collins Startup list
  24367.  
  24368. [High Definition Audio Property Page Shortcut]
  24369. Number=3461
  24370. Confirmed=N
  24371. Filename=HDAudPropShortcut.exe
  24372. Description=Realtek audio card related - probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required
  24373. Source=Paul Collins Startup list
  24374.  
  24375. [HighPoint ATA RAID Management Software]
  24376. Number=3462
  24377. Confirmed=Y
  24378. Filename=raidman.exe
  24379. Description=<a href="http://www.highpoint-tech.com/" target="_blank">HighPoint</a> RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on <a href="http://data-recovery.lsoft.net/concept_raid.html" target="_blank">RAID</a>
  24380. Source=Paul Collins Startup list
  24381.  
  24382. [HijackThis startup scan]
  24383. Number=3463
  24384. Confirmed=U
  24385. Filename=HijackThis.exe
  24386. Description=<a href="http://www.spywareinfo.com/~merijn/downloads.html" target= blank>HijackThis</a> lists the contents of key areas of the Registry and hard drive areas that are used by both legitimate programmers and hijackers. The program is continually updated to detect and remove new hijacks. It does not target specific programs and URLs, only the methods used by hijackers to force you onto their sites. As a result, false positives are imminent, and unless you're sure about what you're doing, you always should consult with knowledgable folks before deleting anything. Required if you'd like HijackThis to run a scan at startup, and show the results when new items are found (if so, check the appropriate box in the "Config" section")
  24387. Source=Paul Collins Startup list
  24388.  
  24389. [HijSrv32]
  24390. Number=3464
  24391. Confirmed=X
  24392. Filename=hijsrv.exe
  24393. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankgermd.html" target=_blank>BANKGERM-D</a> TROJAN!
  24394. Source=Paul Collins Startup list
  24395.  
  24396. [HistoryKill]
  24397. Number=3465
  24398. Confirmed=N
  24399. Filename=histkill.exe
  24400. Description=HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs
  24401. Source=Paul Collins Startup list
  24402.  
  24403. [Hitman Pro SurfRight Helper]
  24404. Number=3466
  24405. Confirmed=U
  24406. Filename=srhelper.exe
  24407. Description=<a href="http://process.networktechs.com/srhelper.exe.php" target=_blank>Hitman Pro</a> - a utility to start a number of Security Protection software. They can be started individualy
  24408.  
  24409. Source=Paul Collins Startup list
  24410.  
  24411. [HitQ]
  24412. Number=3467
  24413. Confirmed=X
  24414. Filename=HitQ.exe
  24415. Description=Hijacker, for more information see <a href="http://www.talkaboutshareware.com/group/alt.comp.freeware/messages/289755.html" target=_blank>here</a>
  24416. Source=Paul Collins Startup list
  24417.  
  24418. [HitwarePKLite]
  24419. Number=3468
  24420. Confirmed=U
  24421. Filename=HITWAR~1.EXE
  24422. Description=<a href="http://www.rightutilities.com/products/hitwarelite/hitware_lite.htm" target="_blank">Hitware Popup Killer Lite</a>
  24423. Source=Paul Collins Startup list
  24424.  
  24425. [HIV]
  24426. Number=3469
  24427. Confirmed=X
  24428. Filename=HIV.exe
  24429. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-083114-4604-99" target="_blank">HIVA</a> TROJAN!
  24430. Source=Paul Collins Startup list
  24431.  
  24432. [hk]
  24433. Number=3470
  24434. Confirmed=U
  24435. Filename=hk.exe
  24436. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050512-3309-99" target=blank>KeyLoggerExp</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  24437. Source=Paul Collins Startup list
  24438.  
  24439. [hkcmd]
  24440. Number=3471
  24441. Confirmed=U
  24442. Filename=hkcmd.exe
  24443. Description=Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have "HotKey" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel
  24444. Source=Paul Collins Startup list
  24445.  
  24446. [HKEYok]
  24447. Number=3472
  24448. Confirmed=X
  24449. Filename=runlli32.exe
  24450. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojqqpassu.html" target=_blank>QQPASS-U</a> TROJAN!
  24451. Source=Paul Collins Startup list
  24452.  
  24453. [HKLM\Run]
  24454. Number=3473
  24455. Confirmed=X
  24456. Filename=windowsupdate.exe
  24457. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbj.html" target=_blank>FORBOT-BJ</a> WORM! (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)
  24458. Source=Paul Collins Startup list
  24459.  
  24460. [hkserv]
  24461. Number=3474
  24462. Confirmed=U
  24463. Filename=HKserv.exe
  24464. Description=Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
  24465. Source=Paul Collins Startup list
  24466.  
  24467. [hkss]
  24468. Number=3475
  24469. Confirmed=U
  24470. Filename=hkss.exe
  24471. Description=Compaq HotKey Support - multimedia keyboard support
  24472. Source=Paul Collins Startup list
  24473.  
  24474. [HLcleanup]
  24475. Number=3476
  24476. Confirmed=X
  24477. Filename=hlsetup2.exe
  24478. Description=<a href="http://vil.mcafeesecurity.com/vil/content/v_134892.htm" target=_blank>LinkReplacer/FFinder</a> adware
  24479. Source=Paul Collins Startup list
  24480.  
  24481. [hldrrr]
  24482. Number=3477
  24483. Confirmed=X
  24484. Filename=hldrrr.exe
  24485. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32baglekf.html" target="_blank">BAGLE-KF</a> WORM!
  24486. Source=Paul Collins Startup list
  24487.  
  24488. [hlhtxo.exe]
  24489. Number=3478
  24490. Confirmed=X
  24491. Filename=hlhtxo.exe
  24492. Description=Added by the <a href="http://vil.nai.com/vil/content/v_135291.htm" target=_blank>QLOWZONES-27</a> TROJAN!
  24493. Source=Paul Collins Startup list
  24494.  
  24495. [HLL Data Parameter]
  24496. Number=3479
  24497. Confirmed=X
  24498. Filename=hllcxpa.exe
  24499. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AFG" target="_blank">RBOT.AFG</a> WORM!
  24500. Source=Paul Collins Startup list
  24501.  
  24502. [HMI PowerSystem]
  24503. Number=3480
  24504. Confirmed=X
  24505. Filename=hmisvc32.exe
  24506. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-031510-5713-99" target=_blank>RANDEX.CZZ</a> WORM!
  24507. Source=Paul Collins Startup list
  24508.  
  24509. [HML PowerSource]
  24510. Number=3481
  24511. Confirmed=X
  24512. Filename=hmlsvc32.exe
  24513. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxl.html" target= blank>SDBOT-XL</a> WORM!
  24514. Source=Paul Collins Startup list
  24515.  
  24516. [Hmonitor]
  24517. Number=3482
  24518. Confirmed=U
  24519. Filename=Hmonitor.exe
  24520. Description=Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status
  24521. Source=Paul Collins Startup list
  24522.  
  24523. [HMV PowerSource]
  24524. Number=3483
  24525. Confirmed=X
  24526. Filename=hmusvc32.exe
  24527. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotyw.html" target=_blank>SDBOT-YW</a> WORM!
  24528. Source=Paul Collins Startup list
  24529.  
  24530. [ho2stdll.exe]
  24531. Number=3484
  24532. Confirmed=X
  24533. Filename=ho2stdll.exe
  24534. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerho.html" target=_blank>BANKER-HO</a> TROJAN!
  24535. Source=Paul Collins Startup list
  24536.  
  24537. [HOI Services]
  24538. Number=3485
  24539. Confirmed=X
  24540. Filename=holsvc32.exe
  24541. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotsf.html" target= blank>AGOBOT-SF</a> WORM!
  24542. Source=Paul Collins Startup list
  24543.  
  24544. [Holiday Lights]
  24545. Number=3486
  24546. Confirmed=N
  24547. Filename=Holiday Lights.exe
  24548. Description=<a href="http://www.tigertech.com/hlights.html" target="_blank">Holiday Lights</a> from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs
  24549. Source=Paul Collins Startup list
  24550.  
  24551. [Hollaback]
  24552. Number=3487
  24553. Confirmed=X
  24554. Filename=slvhosts.exe
  24555. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BMO&VSect=P" target=_blank>SDBOT.BMO</a> WORM!
  24556. Source=Paul Collins Startup list
  24557.  
  24558. [Home Theater SchSvr]
  24559. Number=3488
  24560. Confirmed=N
  24561. Filename=SchSvr.exe
  24562. Description=<a href="http://www.intervideo.com" target="_blank">WinScheduler</a> is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
  24563. Source=Paul Collins Startup list
  24564.  
  24565. [HomeAlarm]
  24566. Number=3489
  24567. Confirmed=U
  24568. Filename=HomeAlarm.exe
  24569. Description=<a href="http://www.softshape.com/cham/" target="_blank">Chameleon Clock</a> - system tray clock replacement
  24570. Source=Paul Collins Startup list
  24571.  
  24572. [HomeCentre WakeUp]
  24573. Number=3490
  24574. Confirmed=?
  24575. Filename=LGWAKEUP.EXE
  24576. Description=<font color="#FF0000">Associated with the no longer supported Xerox HomeCentre printer/scanner</font>
  24577. Source=Paul Collins Startup list
  24578.  
  24579. [Homeland Network]
  24580. Number=3491
  24581. Confirmed=X
  24582. Filename=HomelandNetwork.exe
  24583. Description=Homeland Network Notifier - pops ads
  24584. Source=Paul Collins Startup list
  24585.  
  24586. [Honor]
  24587. Number=3492
  24588. Confirmed=?
  24589. Filename=honor.exe
  24590. Description=<font color="#FF0000">??</font>
  24591. Source=Paul Collins Startup list
  24592.  
  24593. [Hook99startup]
  24594. Number=3493
  24595. Confirmed=U
  24596. Filename=hk2re.exe
  24597. Description="<a href="http://thunder.prohosting.com/~ladi/e_hook.html" target="_blank">Hook99</a> enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent"
  24598. Source=Paul Collins Startup list
  24599.  
  24600. [HookSys]
  24601. Number=3494
  24602. Confirmed=U
  24603. Filename=HookSys.exe
  24604. Description=SurfinGuard Pro from <a href="http://www.finjan.com/" target="_blank">Finjan</a> - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java
  24605. Source=Paul Collins Startup list
  24606.  
  24607. [HornetMonitor]
  24608. Number=3495
  24609. Confirmed=U
  24610. Filename=MntrHrnt.exe
  24611. Description=<a href="http://www.bvsystems.com/Products/WLAN/Hornet/hornet.htm" target="_blank">Hornet Monitor</a> - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network
  24612. Source=Paul Collins Startup list
  24613.  
  24614. [HorngTech4D]
  24615. Number=3496
  24616. Confirmed=Y
  24617. Filename=bally4d.exe
  24618. Description=HorngTech 4D mouse driver
  24619. Source=Paul Collins Startup list
  24620.  
  24621. [Host]
  24622. Number=3497
  24623. Confirmed=X
  24624. Filename=N/A
  24625. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-041016-4416-99" target="_blank">POPDIS</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-080815-4711-99" target="_blank">STARTPAGE.F</a> TROJANS!
  24626. Source=Paul Collins Startup list
  24627.  
  24628. [host]
  24629. Number=3498
  24630. Confirmed=X
  24631. Filename=help.exe
  24632. Description=Identified as the DELF.LF by <a href="http://www.ewido.net/en/" target=_blank>Ewido Security Suite</a>
  24633. Source=Paul Collins Startup list
  24634.  
  24635. [Host Process]
  24636. Number=3499
  24637. Confirmed=X
  24638. Filename=mame.exe
  24639. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotapo.html" target=_blank>RBOT-APO</a> WORM!
  24640. Source=Paul Collins Startup list
  24641.  
  24642. [hostdll.exe]
  24643. Number=3500
  24644. Confirmed=X
  24645. Filename=hostdll.exe
  24646. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerbo.html" target=_blank>BANKER-BO</a> TROJAN!
  24647. Source=Paul Collins Startup list
  24648.  
  24649. [HostManager]
  24650. Number=3501
  24651. Confirmed=U
  24652. Filename=AOLHostManager.exe
  24653. Description=Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched, increasing lauching time
  24654. Source=Paul Collins Startup list
  24655.  
  24656. [HostManager]
  24657. Number=3502
  24658. Confirmed=N
  24659. Filename=AOLSoftware.exe
  24660. Description=Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system".
  24661. Source=Paul Collins Startup list
  24662.  
  24663. [Hostren.exe]
  24664. Number=3503
  24665. Confirmed=X
  24666. Filename=Hostren.exe
  24667. Description=Added by PWS.BANKER.F, a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerbo.html" target=_blank>BANKER-BO</a> TROJAN!
  24668. Source=Paul Collins Startup list
  24669.  
  24670. [hostserv]
  24671. Number=3504
  24672. Confirmed=X
  24673. Filename=hostserv.exe
  24674. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BPZ&VSect=P" target=_blank>RBOT.BPZ</a> WORM!
  24675. Source=Paul Collins Startup list
  24676.  
  24677. [hostserv]
  24678. Number=3505
  24679. Confirmed=X
  24680. Filename=wiz98.exe
  24681. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  24682. Source=Paul Collins Startup list
  24683.  
  24684. [HostsMan]
  24685. Number=3506
  24686. Confirmed=U
  24687. Filename=hm.exe
  24688. Description="<a href="http://hostsman.abelhadigital.com/" target="_blank">HostsMan</a> is a freeware application that lets you manage your Hosts file with ease". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost, but can also be used to add any other domain/Ip combination that you want to be included in the HOSTS file
  24689. Source=Paul Collins Startup list
  24690.  
  24691. [HostSrv]
  24692. Number=3507
  24693. Confirmed=X
  24694. Filename=sachostx.exe
  24695. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-011812-1823-99" target=_blank>LOOKSKY.H</a> WORM! Drops multiple files in the System (9x/ME) or System32 (NT/2K/XP) folders
  24696. Source=Paul Collins Startup list
  24697.  
  24698. [HostSrv]
  24699. Number=3508
  24700. Confirmed=X
  24701. Filename=sachostx.exe
  24702. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_LOOKSKY.A&VSect=P" target=_blank>LOOKSKY.A</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-010517-1744-99" target=_blank>LOOKSKY.F</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-010815-3955-99" target=_blank>LOOKSKY.G</a> WORMS!
  24703. Source=Paul Collins Startup list
  24704.  
  24705. [HostSrv]
  24706. Number=3509
  24707. Confirmed=X
  24708. Filename=sachostx.exe...
  24709. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120910-5842-99" target=_blank>LOOKSKY.E</a> WORM!
  24710. Source=Paul Collins Startup list
  24711.  
  24712. [HostSVC syse]
  24713. Number=3510
  24714. Confirmed=X
  24715. Filename=HostSVC.exe
  24716. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotanz.html" target=_blank>RBOT-ANZ</a> WORM!
  24717. Source=Paul Collins Startup list
  24718.  
  24719. [Hot Corners]
  24720. Number=3511
  24721. Confirmed=U
  24722. Filename=Hotc.exe
  24723. Description=<a href="http://www.southbaypc.com/HotCorners/" target="_blank">Hot Corners</a> - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"
  24724. Source=Paul Collins Startup list
  24725.  
  24726. [Hot Key Kbd 2690 Daemon]
  24727. Number=3512
  24728. Confirmed=U
  24729. Filename=SK9910DM.exe
  24730. Description=Multimedia keyboard manager - required if you use any special keys
  24731. Source=Paul Collins Startup list
  24732.  
  24733. [Hot Key Keybd 9910 Daemon]
  24734. Number=3513
  24735. Confirmed=U
  24736. Filename=SK9910DM.exe
  24737. Description=Multimedia keyboard manager - required if you use any special keys
  24738. Source=Paul Collins Startup list
  24739.  
  24740. [Hot Party 22]
  24741. Number=3514
  24742. Confirmed=?
  24743. Filename=hotpart22.exe
  24744. Description=<font color="#FF0000">??</font>
  24745. Source=Paul Collins Startup list
  24746.  
  24747. [HotAction_hr]
  24748. Number=3515
  24749. Confirmed=X
  24750. Filename=hotaction_hr.exe
  24751. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/dialsiteiconb.html" target=_blank>SITEICON-B</a> DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "HotAction_hr"
  24752. Source=Paul Collins Startup list
  24753.  
  24754. [Hotbar]
  24755. Number=3516
  24756. Confirmed=X
  24757. Filename=Hbinst.exe
  24758. Description=<a href="http://www.hotbar.com/" target="_blank">Hotbar</a> enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see <a href="http://www.safersite.com/pestinfo/H/HotBar_Adware.asp" target="_blank">here</a>
  24759. Source=Paul Collins Startup list
  24760.  
  24761. [Hotbar]
  24762. Number=3517
  24763. Confirmed=X
  24764. Filename=HbOEAddOn.exe
  24765. Description=<a href="http://www.sarc.com/avcenter/venc/data/adware.hotbar.html" target=_blank>Hotbar</a> adware
  24766. Source=Paul Collins Startup list
  24767.  
  24768. [Hotfix Updat]
  24769. Number=3518
  24770. Confirmed=X
  24771. Filename=svdhost32.exe
  24772. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-041411-2703-99" target="_blank">GAOBOT.ZW</a> WORM!
  24773. Source=Paul Collins Startup list
  24774.  
  24775. [HotIDE]
  24776. Number=3519
  24777. Confirmed=U
  24778. Filename=hotide.exe
  24779. Description=HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
  24780. Source=Paul Collins Startup list
  24781.  
  24782. [HotkeyApp]
  24783. Number=3520
  24784. Confirmed=U
  24785. Filename=HotkeyApp.exe
  24786. Description=Programmable keys on Acer, Fujitsu and other laptops
  24787. Source=Paul Collins Startup list
  24788.  
  24789. [HotKeysCmds]
  24790. Number=3521
  24791. Confirmed=U
  24792. Filename=hkcmd.exe
  24793. Description=Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have "HotKey" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel
  24794. Source=Paul Collins Startup list
  24795.  
  24796. [HotPix]
  24797. Number=3522
  24798. Confirmed=X
  24799. Filename=hotpix.exe
  24800. Description=Adult content dialler
  24801. Source=Paul Collins Startup list
  24802.  
  24803. [hotplug]
  24804. Number=3523
  24805. Confirmed=X
  24806. Filename=hotplug.exe
  24807. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=39574" target="_blank">SILLYDL</a> TROJAN!
  24808. Source=Paul Collins Startup list
  24809.  
  24810. [Hotplug]
  24811. Number=3524
  24812. Confirmed=U
  24813. Filename=hot_plug.exe
  24814. Description=Related to the <a href="http://www.whatsrunning.net/whatsrunning/QueryProductID.aspx?Product=10086" target="_blank">SiS_Hot_Plug_Application</a>. Enables automated driver loading for hotpluggable devices. If this service is stopped, hotplug devices will no longer function
  24815. Source=Paul Collins Startup list
  24816.  
  24817. [HotSync Manager]
  24818. Number=3525
  24819. Confirmed=N
  24820. Filename=hotsync.exe
  24821. Description=Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing.  Available via Start -> Programs
  24822. Source=Paul Collins Startup list
  24823.  
  24824. [hotwetlove]
  24825. Number=3526
  24826. Confirmed=X
  24827. Filename=hotwetlove.exe
  24828. Description=Adult content dialler. Will not uninstall - components have to be manually deleted
  24829. Source=Paul Collins Startup list
  24830.  
  24831. [Hot_Kiss]
  24832. Number=3527
  24833. Confirmed=X
  24834. Filename=Hot_Kiss.exe
  24835. Description=Adult content dialler
  24836. Source=Paul Collins Startup list
  24837.  
  24838. [Hot_Tarts]
  24839. Number=3528
  24840. Confirmed=X
  24841. Filename=Hot_Tarts.exe
  24842. Description=Adult content dialler
  24843. Source=Paul Collins Startup list
  24844.  
  24845. [Hot_Tarts_**]
  24846. Number=3529
  24847. Confirmed=X
  24848. Filename=Hot_Tarts_**.exe
  24849. Description=Premium rate adult content dialer (where * is a random char)
  24850. Source=Paul Collins Startup list
  24851.  
  24852. [Hot_Tarts_Au]
  24853. Number=3530
  24854. Confirmed=X
  24855. Filename=Hot_Tarts_Au.exe
  24856. Description=Premium rate adult content dialler
  24857. Source=Paul Collins Startup list
  24858.  
  24859. [Hot_Tarts_mc]
  24860. Number=3531
  24861. Confirmed=X
  24862. Filename=Hot_Tarts_mc.exe
  24863. Description=<a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453068396" target=_blank>HotTarts</a> adult content dialer
  24864.  
  24865. Source=Paul Collins Startup list
  24866.  
  24867. [HoverDesk]
  24868. Number=3532
  24869. Confirmed=U
  24870. Filename=HoverDesk.exe
  24871. Description=<a href="http://www.hoverdesk.net/" target="_blank">HoverDesk</a> - desktop replacement software
  24872. Source=Paul Collins Startup list
  24873.  
  24874. [hp 1000 firmware]
  24875. Number=3533
  24876. Confirmed=?
  24877. Filename=fwdl.exe
  24878. Description=HP LaserJet 1000 related. <font color="#FF0000">Is it a driver or automatic firmware update (based upon the filename)?</font>
  24879. Source=Paul Collins Startup list
  24880.  
  24881. [HP AutoIndexer]
  24882. Number=3534
  24883. Confirmed=U
  24884. Filename=hppautoindexer.exe
  24885. Description=Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
  24886. Source=Paul Collins Startup list
  24887.  
  24888. [HP CD Writer]
  24889. Number=3535
  24890. Confirmed=N
  24891. Filename=hpcdtray.exe
  24892. Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
  24893. Source=Paul Collins Startup list
  24894.  
  24895. [HP CD-DVD]
  24896. Number=3536
  24897. Confirmed=N
  24898. Filename=hpcdtray.exe
  24899. Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
  24900. Source=Paul Collins Startup list
  24901.  
  24902. [HP CD-Writer]
  24903. Number=3537
  24904. Confirmed=N
  24905. Filename=hpcdtray.exe
  24906. Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
  24907. Source=Paul Collins Startup list
  24908.  
  24909. [hp center]
  24910. Number=3538
  24911. Confirmed=X
  24912. Filename=BACKWEB-*****.exe
  24913. Description=See <a href="http://h10025.www1.hp.com/ewfrf/wc/genericDocument?cc=us&docname=bph05170&lc=en&jumpid=reg_R1002_USEN#bph05170_G5" target="_blank">here</a> - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners". Applies to certain HP Pavilion desktop computers between Fall 2001 and Spring 2003. * can be any digit
  24914. Source=Paul Collins Startup list
  24915.  
  24916. [hp center UI]
  24917. Number=3539
  24918. Confirmed=N
  24919. Filename=ShadowBar.exe
  24920. Description=User Interface for HP Center - see <a href="http://www.sysinfo.org/startuplist.php?filter=BACKWEB-******.exe" target="_blank">here</a>
  24921. Source=Paul Collins Startup list
  24922.  
  24923. [HP Component Manager]
  24924. Number=3540
  24925. Confirmed=N
  24926. Filename=hpcmpmgr.exe
  24927. Description=Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
  24928. Source=Paul Collins Startup list
  24929.  
  24930. [HP Deskjet]
  24931. Number=3541
  24932. Confirmed=X
  24933. Filename=HP_DeskJet_500.exe
  24934. Description=Added by the <a href="http://www.sophos.com.au/virusinfo/analyses/w32forbotda.html" target=_blank>FORBOT-DA</a> WORM!
  24935. Source=Paul Collins Startup list
  24936.  
  24937. [HP Digital Imaging Monitor]
  24938. Number=3542
  24939. Confirmed=U
  24940. Filename=hpqtra08.exe
  24941. Description=System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera, for example
  24942. Source=Paul Collins Startup list
  24943.  
  24944. [HP Display Settings]
  24945. Number=3543
  24946. Confirmed=U
  24947. Filename=hpdisply.exe
  24948. Description=Sets default display settings. Unchecking this item has been reported to cure a "Problem sending command to keyboard" error message
  24949. Source=Paul Collins Startup list
  24950.  
  24951. [HP IDScheduler]
  24952. Number=3544
  24953. Confirmed=?
  24954. Filename=HPIDSCHD.exe
  24955. Description=<font color="#FF0000">HP Instant Delivery Scheduler</font>
  24956. Source=Paul Collins Startup list
  24957.  
  24958. [HP Image Zone Fast Start]
  24959. Number=3545
  24960. Confirmed=N
  24961. Filename=hpqthb08.exe
  24962. Description=Improves the startup time of HP Image Zone. If you disable it, HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time
  24963. Source=Paul Collins Startup list
  24964.  
  24965. [HP Info Express]
  24966. Number=3546
  24967. Confirmed=N
  24968. Filename=??
  24969. Description=On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
  24970. Source=Paul Collins Startup list
  24971.  
  24972. [HP Instant Support]
  24973. Number=3547
  24974. Confirmed=U
  24975. Filename=matcli.exe
  24976. Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide
  24977. Source=Paul Collins Startup list
  24978.  
  24979. [HP Internet Center]
  24980. Number=3548
  24981. Confirmed=N
  24982. Filename=SURFBRD.EXE
  24983. Description=Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
  24984. Source=Paul Collins Startup list
  24985.  
  24986. [HP JetDiscovery]
  24987. Number=3549
  24988. Confirmed=N
  24989. Filename=HPJETDSC.EXE
  24990. Description=HP JetAdmin software which monitors printing jobs on a network environment
  24991. Source=Paul Collins Startup list
  24992.  
  24993. [HP JetSpeed Autostart]
  24994. Number=3550
  24995. Confirmed=N
  24996. Filename=AUTOSTART.EXE
  24997. Description=Autostart executable for the old multiplayer game HP Jetspeed
  24998. Source=Paul Collins Startup list
  24999.  
  25000. [HP Laser Jet Director]
  25001. Number=3551
  25002. Confirmed=U
  25003. Filename=hppdirector.exe
  25004. Description=System Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc
  25005. Source=Paul Collins Startup list
  25006.  
  25007. [HP Network Registry Agent]
  25008. Number=3552
  25009. Confirmed=?
  25010. Filename=hpnra.exe
  25011. Description=<font color="#FF0000">??</font>
  25012. Source=Paul Collins Startup list
  25013.  
  25014. [HP OfficeJet Series xxx Startup]
  25015. Number=3553
  25016. Confirmed=?
  25017. Filename=HPOSTR03.EXE
  25018. Description=xxx represents the series number - such as 700. <font color="#FF0000">What does it do and it it required?</font>
  25019. Source=Paul Collins Startup list
  25020.  
  25021. [HP OfficeJet Series xxx Startup]
  25022. Number=3554
  25023. Confirmed=?
  25024. Filename=HPOstr05.exe
  25025. Description=xxx represents the series number - such as 700. <font color="#FF0000">What does it do and it it required?</font>
  25026. Source=Paul Collins Startup list
  25027.  
  25028. [HP Parallel Port Test]
  25029. Number=3555
  25030. Confirmed=N
  25031. Filename=hppt.exe
  25032. Description=Associated with a HP ScanJet scanner
  25033. Source=Paul Collins Startup list
  25034.  
  25035. [HP Photo Manager]
  25036. Number=3556
  25037. Confirmed=X
  25038. Filename=HPPhotoManager.exe
  25039. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.AXU&VSect=T" target=_blank>SDBOT.AXU</a> WORM!
  25040. Source=Paul Collins Startup list
  25041.  
  25042. [HP Port Resolver]
  25043. Number=3557
  25044. Confirmed=?
  25045. Filename=hpbpro.exe
  25046. Description=<font color="#FF0000">??</font>
  25047. Source=Paul Collins Startup list
  25048.  
  25049. [HP Precision Scan]
  25050. Number=3558
  25051. Confirmed=N
  25052. Filename=hpmdlbwx.exe
  25053. Description=HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
  25054. Source=Paul Collins Startup list
  25055.  
  25056. [HP Presentation Ready]
  25057. Number=3559
  25058. Confirmed=N
  25059. Filename=PresRdy.exe
  25060. Description=HP Omnibook related:  "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
  25061. Source=Paul Collins Startup list
  25062.  
  25063. [hp psc 2000 Series]
  25064. Number=3560
  25065. Confirmed=U
  25066. Filename=hpobnz08.exe
  25067. Description=System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
  25068. Source=Paul Collins Startup list
  25069.  
  25070. [HP RecordNow]
  25071. Number=3561
  25072. Confirmed=U
  25073. Filename=??
  25074. Description=From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."
  25075. Source=Paul Collins Startup list
  25076.  
  25077. [HP ScanPatch]
  25078. Number=3562
  25079. Confirmed=U
  25080. Filename=HPScanFix.exe
  25081. Description=Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting
  25082. Source=Paul Collins Startup list
  25083.  
  25084. [HP ScanPicture]
  25085. Number=3563
  25086. Confirmed=N
  25087. Filename=hpsplmwa.exe
  25088. Description=HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
  25089. Source=Paul Collins Startup list
  25090.  
  25091. [HP SchedIndexer]
  25092. Number=3564
  25093. Confirmed=U
  25094. Filename=hppschedindexer.exe
  25095. Description=Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
  25096. Source=Paul Collins Startup list
  25097.  
  25098. [HP Service Drivers]
  25099. Number=3565
  25100. Confirmed=X
  25101. Filename=hdsys.exe
  25102. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotze.html" target=_blank>SDBOT-ZE</a> WORM!
  25103. Source=Paul Collins Startup list
  25104.  
  25105. [hp Silent Service]
  25106. Number=3566
  25107. Confirmed=?
  25108. Filename=HpSrvUI.exe
  25109. Description=<font color="#FF0000">HP related</font>
  25110. Source=Paul Collins Startup list
  25111.  
  25112. [HP Simple Trax]
  25113. Number=3567
  25114. Confirmed=N
  25115. Filename=Hpcron.exe
  25116. Description=Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
  25117. Source=Paul Collins Startup list
  25118.  
  25119. [HP software update]
  25120. Number=3568
  25121. Confirmed=N
  25122. Filename=HPWuSchd2.exe
  25123. Description=HP software updates. If a shortcut doesn't exist create your own and run it manually
  25124. Source=Paul Collins Startup list
  25125.  
  25126. [HP software update]
  25127. Number=3569
  25128. Confirmed=N
  25129. Filename=HPWuSchd.exe
  25130. Description=HP software updates. If a shortcut doesn't exist, create your own and run it manually
  25131. Source=Paul Collins Startup list
  25132.  
  25133. [HP Status]
  25134. Number=3570
  25135. Confirmed=N
  25136. Filename=hpstatus.exe
  25137. Description=HP Printer Status and Alerts
  25138. Source=Paul Collins Startup list
  25139.  
  25140. [HP Status Server]
  25141. Number=3571
  25142. Confirmed=?
  25143. Filename=hpboid.exe
  25144. Description=Copied during installation of HP Inkjet Printer Drivers in Win2K/XP. <font color="#FF0000">What does it do and is it required?</font>
  25145. Source=Paul Collins Startup list
  25146.  
  25147. [HP TV Now]
  25148. Number=3572
  25149. Confirmed=U
  25150. Filename=HpTvNow.exe
  25151. Description=Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
  25152. Source=Paul Collins Startup list
  25153.  
  25154. [HP Updates]
  25155. Number=3573
  25156. Confirmed=N
  25157. Filename=??
  25158. Description=On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
  25159. Source=Paul Collins Startup list
  25160.  
  25161. [HP Visualize Init]
  25162. Number=3574
  25163. Confirmed=?
  25164. Filename=HpVisIni.exe
  25165. Description=HP Visualize software related. <font color="#FF0000">What does it do and is it required?</font>
  25166. Source=Paul Collins Startup list
  25167.  
  25168. [HP-Aio Flight]
  25169. Number=3575
  25170. Confirmed=N
  25171. Filename=Remind32.exe
  25172. Description=HP multifunction registration
  25173. Source=Paul Collins Startup list
  25174.  
  25175. [hpaiodevice]
  25176. Number=3576
  25177. Confirmed=N
  25178. Filename=hpodev07.exe
  25179. Description=Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
  25180. Source=Paul Collins Startup list
  25181.  
  25182. [HPAiODevice(hp officejet g series)]
  25183. Number=3577
  25184. Confirmed=?
  25185. Filename=hpoavn07.exe
  25186. Description=HP Printer related, reportedly lets file transfers from an HP device pass files through Windows firewall. <font color="#FF0000">Is it required?</font>
  25187. Source=Paul Collins Startup list
  25188.  
  25189. [HPAiODevice(hp psc 900 series) -1]
  25190. Number=3578
  25191. Confirmed=N
  25192. Filename=hpobrt07.exe
  25193. Description=Installed with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry
  25194. Source=Paul Collins Startup list
  25195.  
  25196. [HPAIO_PrintFolderMgr]
  25197. Number=3579
  25198. Confirmed=N
  25199. Filename=hpoopm07.exe
  25200. Description=Directly from HP: "This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
  25201. Source=Paul Collins Startup list
  25202.  
  25203. [HPBootOp]
  25204. Number=3580
  25205. Confirmed=U
  25206. Filename=HPBootOp.exe
  25207. Description="<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/hpbootop/" target="_blank">HP Boot Optimizer</a> intelligently and dynamically launches software during startup, based on available resources, to improve startup performance"
  25208. Source=Paul Collins Startup list
  25209.  
  25210. [hpcmd]
  25211. Number=3581
  25212. Confirmed=X
  25213. Filename=cmd.exe
  25214. Description=Added by the <a href="http://www.sophos.com/security/analyses/trojadclickds.html" target="_blank">ADCLICK-DS</a> TROJAN!
  25215. Source=Paul Collins Startup list
  25216.  
  25217. [hpcmpmgr]
  25218. Number=3582
  25219. Confirmed=N
  25220. Filename=hpcmpmgr.exe
  25221. Description=Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
  25222. Source=Paul Collins Startup list
  25223.  
  25224. [HPDJ Taskbar Utility]
  25225. Number=3583
  25226. Confirmed=U
  25227. Filename=hpztsbol.exe
  25228. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25229. Source=Paul Collins Startup list
  25230.  
  25231. [HPDJ Taskbar Utility]
  25232. Number=3584
  25233. Confirmed=U
  25234. Filename=hpztsd02.exe
  25235. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25236. Source=Paul Collins Startup list
  25237.  
  25238. [HPDJ Taskbar Utility]
  25239. Number=3585
  25240. Confirmed=U
  25241. Filename=hpztsb04.exe
  25242. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25243. Source=Paul Collins Startup list
  25244.  
  25245. [HPDJ Taskbar Utility]
  25246. Number=3586
  25247. Confirmed=U
  25248. Filename=hpztsb05.exe
  25249. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25250. Source=Paul Collins Startup list
  25251.  
  25252. [HPDJ Taskbar Utility]
  25253. Number=3587
  25254. Confirmed=U
  25255. Filename=hpztsb07.exe
  25256. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25257. Source=Paul Collins Startup list
  25258.  
  25259. [HPDJ Taskbar Utility]
  25260. Number=3588
  25261. Confirmed=U
  25262. Filename=hpztsb09.exe
  25263. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25264. Source=Paul Collins Startup list
  25265.  
  25266. [hpfsched]
  25267. Number=3589
  25268. Confirmed=N
  25269. Filename=hpfsched.exe
  25270. Description=HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
  25271. Source=Paul Collins Startup list
  25272.  
  25273. [HPGamesActiveMenu]
  25274. Number=3590
  25275. Confirmed=U
  25276. Filename=ActiveMenu.exe
  25277. Description=Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
  25278. Source=Paul Collins Startup list
  25279.  
  25280. [hpgs2wnd]
  25281. Number=3591
  25282. Confirmed=N
  25283. Filename=hpgs2wnd.exe
  25284. Description="HP's exclusive <a href="http://h10025.www1.hp.com/ewfrf/wc/genericDocument?docname=bps05210&cc=us&dlc=en&lc=en&jumpid=reg_R1002_USEN" target="_blank">Share-to-Web</a> software makes it easy to share content with others through our affiliate Internet websites".<font color="#FF0000"> </font>Available via Start -> Programs
  25285. Source=Paul Collins Startup list
  25286.  
  25287. [Hpha1mon]
  25288. Number=3592
  25289. Confirmed=U
  25290. Filename=Hpha1mon.exe
  25291. Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature
  25292. Source=Paul Collins Startup list
  25293.  
  25294. [HPHAxMON]
  25295. Number=3593
  25296. Confirmed=U
  25297. Filename=HPHAxMON.EXE
  25298. Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. "x" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards
  25299. Source=Paul Collins Startup list
  25300.  
  25301. [HPHmon**]
  25302. Number=3594
  25303. Confirmed=U
  25304. Filename=HPHMON**.EXE
  25305. Description=Monitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn't inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don't use the reader
  25306. Source=Paul Collins Startup list
  25307.  
  25308. [HPHmon03]
  25309. Number=3595
  25310. Confirmed=U
  25311. Filename=hphmon03.exe
  25312. Description=Related to the Hewlett-Packard Photosmart's configuration and diagnostics module
  25313. Source=Paul Collins Startup list
  25314.  
  25315. [HPHmon04]
  25316. Number=3596
  25317. Confirmed=U
  25318. Filename=hphmon04.exe
  25319. Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature
  25320. Source=Paul Collins Startup list
  25321.  
  25322. [HPHmon05]
  25323. Number=3597
  25324. Confirmed=?
  25325. Filename=hphmon05.exe
  25326. Description=<font color="#FF0000">??</font>
  25327. Source=Paul Collins Startup list
  25328.  
  25329. [HPHmon06]
  25330. Number=3598
  25331. Confirmed=U
  25332. Filename=hphmon06.exe
  25333. Description=Related to the Hewlett Packard software HP Photosmart printer, it provides easy access to flash card reading functions. This program is not essential to the running of the system. Your choice
  25334. Source=Paul Collins Startup list
  25335.  
  25336. [Hphome]
  25337. Number=3599
  25338. Confirmed=X
  25339. Filename=hphome.js
  25340. Description=Homepage hijacker
  25341. Source=Paul Collins Startup list
  25342.  
  25343. [HPHUPD**]
  25344. Number=3600
  25345. Confirmed=N
  25346. Filename=hphupd**.exe
  25347. Description=HP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs
  25348. Source=Paul Collins Startup list
  25349.  
  25350. [hpjsiroute]
  25351. Number=3601
  25352. Confirmed=?
  25353. Filename=hpjsira.exe
  25354. Description=<font color="#FF0000">Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2"</font>
  25355. Source=Paul Collins Startup list
  25356.  
  25357. [HPl Services]
  25358. Number=3602
  25359. Confirmed=X
  25360. Filename=hmlsvc32.exe
  25361. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotsi.html" target=_blank>AGOBOT-SI</a> WORM and variants!
  25362. Source=Paul Collins Startup list
  25363.  
  25364. [HpLamp]
  25365. Number=3603
  25366. Confirmed=Y
  25367. Filename=HPLAMP.EXE
  25368. Description=HP Scanner Utility that controls your scanners light bulb. Needed if it's switched on
  25369. Source=Paul Collins Startup list
  25370.  
  25371. [hplampc]
  25372. Number=3604
  25373. Confirmed=U
  25374. Filename=hplampc.exe
  25375. Description=HP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off
  25376. Source=Paul Collins Startup list
  25377.  
  25378. [HPLaptopGamesActiveMenu]
  25379. Number=3605
  25380. Confirmed=U
  25381. Filename=ActiveMenu.exe
  25382. Description=Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
  25383. Source=Paul Collins Startup list
  25384.  
  25385. [HPLJ Config]
  25386. Number=3606
  25387. Confirmed=Y
  25388. Filename=SetConfig.exe
  25389. Description=Connects system to networked HP printer.
  25390. Source=Paul Collins Startup list
  25391.  
  25392. [HPLogiFinder]
  25393. Number=3607
  25394. Confirmed=U
  25395. Filename=hp_finder.exe
  25396. Description=HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
  25397. Source=Paul Collins Startup list
  25398.  
  25399. [HpMmKbd]
  25400. Number=3608
  25401. Confirmed=U
  25402. Filename=HpMmKbd.exe
  25403. Description=HP's multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
  25404. Source=Paul Collins Startup list
  25405.  
  25406. [HPMVTray]
  25407. Number=3609
  25408. Confirmed=U
  25409. Filename=HPMVTray.exe
  25410. Description=<a href="http://h10025.www1.hp.com/ewfrf/wc/document?docname=c00809011&lc=en&cc=id&dlc=en&product=3193065" target="_blank">HP Media Vault</a> Networked Storage Device - System Tray management utility
  25411. Source=Paul Collins Startup list
  25412.  
  25413. [HPNT]
  25414. Number=3610
  25415. Confirmed=X
  25416. Filename=hpdll.exe
  25417. Description=Malware - recognized by <a href="http://www.kaspersky.com/" target="_blank">Kaspersky</a> antivirus as Trojan-Downloader.Win32.VB.ku
  25418. Source=Paul Collins Startup list
  25419.  
  25420. [hpodblia]
  25421. Number=3611
  25422. Confirmed=N
  25423. Filename=hpodblia.exe
  25424. Description=HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
  25425. Source=Paul Collins Startup list
  25426.  
  25427. [hpoddt01.exe]
  25428. Number=3612
  25429. Confirmed=N
  25430. Filename=N/A
  25431. Description=Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started
  25432. Source=Paul Collins Startup list
  25433.  
  25434. [hpodlb08]
  25435. Number=3613
  25436. Confirmed=N
  25437. Filename=hpodlb08.exe
  25438. Description=HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
  25439. Source=Paul Collins Startup list
  25440.  
  25441. [hpotdd01.exe]
  25442. Number=3614
  25443. Confirmed=Y
  25444. Filename=hpotdd01.exe
  25445. Description=Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
  25446. Source=Paul Collins Startup list
  25447.  
  25448. [hpppta]
  25449. Number=3615
  25450. Confirmed=Y
  25451. Filename=HPPPTA.exe
  25452. Description=HP parallel port driver for certain hardware
  25453. Source=Paul Collins Startup list
  25454.  
  25455. [HpPrinter]
  25456. Number=3616
  25457. Confirmed=X
  25458. Filename=hpserver.exe
  25459. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcmjspyw.html" target=_blank>CMJSPY-W</a> TROJAN!
  25460. Source=Paul Collins Startup list
  25461.  
  25462. [HPPROPTY]
  25463. Number=3617
  25464. Confirmed=N
  25465. Filename=HPPROPTY.EXE
  25466. Description=<a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=bpl05860&locale=en_US&docId=35185" target="_blank">HP LaserJet Toolbox</a>
  25467. Source=Paul Collins Startup list
  25468.  
  25469. [HPPWRSAV]
  25470. Number=3618
  25471. Confirmed=U
  25472. Filename=HPPWRSAV.EXE
  25473. Description=Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try <a href="http://www.hp.com">www.hp.com</a>, pick your OS option under the SUPPORT tab, follow the instructions and you will find an updated lamp control patch
  25474. Source=Paul Collins Startup list
  25475.  
  25476. [hpqcmon]
  25477. Number=3619
  25478. Confirmed=?
  25479. Filename=hpqcmon.exe
  25480. Description=<font color="#FF0000">From HP and related to digital imaging</font>
  25481. Source=Paul Collins Startup list
  25482.  
  25483. [HPSCANMonitor]
  25484. Number=3620
  25485. Confirmed=U
  25486. Filename=hpsjvxd.exe
  25487. Description=HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
  25488. Source=Paul Collins Startup list
  25489.  
  25490. [hpScannerFirstBoot]
  25491. Number=3621
  25492. Confirmed=?
  25493. Filename=scannerfb.exe
  25494. Description=<font color="#FF0000">HP scanner related</font>
  25495. Source=Paul Collins Startup list
  25496.  
  25497. [hpsjbmgr]
  25498. Number=3622
  25499. Confirmed=N
  25500. Filename=hpsjbmgr.exe
  25501. Description=HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment
  25502. Source=Paul Collins Startup list
  25503.  
  25504. [HPStart]
  25505. Number=3623
  25506. Confirmed=N
  25507. Filename=hpstart.wsf
  25508. Description=This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
  25509. Source=Paul Collins Startup list
  25510.  
  25511. [hpsysconf1]
  25512. Number=3624
  25513. Confirmed=X
  25514. Filename=[random filename]
  25515. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_VIVIA.A" target="_blank">VIVIA.A</a> TROJAN!
  25516. Source=Paul Collins Startup list
  25517.  
  25518. [hpsysdrv]
  25519. Number=3625
  25520. Confirmed=U
  25521. Filename=hpsysdrv.exe
  25522. Description=This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working
  25523. Source=Paul Collins Startup list
  25524.  
  25525. [hptools]
  25526. Number=3626
  25527. Confirmed=X
  25528. Filename=hptools.exe
  25529. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  25530. Source=Paul Collins Startup list
  25531.  
  25532. [hptools]
  25533. Number=3627
  25534. Confirmed=X
  25535. Filename=microsoft.exe
  25536. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
  25537. Source=Paul Collins Startup list
  25538.  
  25539. [HPU]
  25540. Number=3628
  25541. Confirmed=N
  25542. Filename=ProvenTactics.exe
  25543. Description=<a href="http://www.proventactics.com/" target="_blank">Proven Internet Marketing</a> software
  25544. Source=Paul Collins Startup list
  25545.  
  25546. [hpWirelessAssistant]
  25547. Number=3629
  25548. Confirmed=U
  25549. Filename=HP Wireless Assistant.exe
  25550. Description=The HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
  25551. Source=Paul Collins Startup list
  25552.  
  25553. [HPZTS04]
  25554. Number=3630
  25555. Confirmed=N
  25556. Filename=hpzts04.exe
  25557. Description=Hewlett Packard printer toolbox shortcut that resides in the system tray
  25558. Source=Paul Collins Startup list
  25559.  
  25560. [hpztsb02]
  25561. Number=3631
  25562. Confirmed=U
  25563. Filename=hpztsb02.exe
  25564. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25565. Source=Paul Collins Startup list
  25566.  
  25567. [hpztsb04]
  25568. Number=3632
  25569. Confirmed=U
  25570. Filename=hpztsb04.exe
  25571. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25572. Source=Paul Collins Startup list
  25573.  
  25574. [hpztsb05]
  25575. Number=3633
  25576. Confirmed=U
  25577. Filename=hpztsb05.exe
  25578. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25579. Source=Paul Collins Startup list
  25580.  
  25581. [hpztsb07]
  25582. Number=3634
  25583. Confirmed=U
  25584. Filename=hpztsb07.exe
  25585. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25586.  
  25587. Source=Paul Collins Startup list
  25588.  
  25589. [hpztsb09]
  25590. Number=3635
  25591. Confirmed=U
  25592. Filename=hpztsb09.exe
  25593. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25594. Source=Paul Collins Startup list
  25595.  
  25596. [hpztsbol]
  25597. Number=3636
  25598. Confirmed=U
  25599. Filename=hpztsbol.exe
  25600. Description=HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
  25601. Source=Paul Collins Startup list
  25602.  
  25603. [HP_dla]
  25604. Number=3637
  25605. Confirmed=N
  25606. Filename=dlatray.exe
  25607. Description=On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD
  25608. Source=Paul Collins Startup list
  25609.  
  25610. [HQI Services]
  25611. Number=3638
  25612. Confirmed=X
  25613. Filename=hqisvc32.exe
  25614. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotro.html" target= blank>AGOBOT-RO</a> WORM!
  25615. Source=Paul Collins Startup list
  25616.  
  25617. [HQI Services]
  25618. Number=3639
  25619. Confirmed=X
  25620. Filename=hqlsvc32.exe
  25621. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotrp.html" target= blank>AGOBOT-RP</a> WORM!
  25622. Source=Paul Collins Startup list
  25623.  
  25624. [HR]
  25625. Number=3640
  25626. Confirmed=U
  25627. Filename=Hr.exe
  25628. Description=<a href="http://sarc.com/avcenter/venc/data/spyware.hiddenrecorder.html" target=_blank>HiddenRecorder</a> periodically takes screenshots of the computer. If you didn't install this yourself remove it
  25629. Source=Paul Collins Startup list
  25630.  
  25631. [HREF.OCX]
  25632. Number=3641
  25633. Confirmed=U
  25634. Filename=regsvr32.exe ....HREF.OCX
  25635. Description=HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as <a href="http://software.xfx.net/utilities/popupkiller/index.php" target="_blank">PopUpKiller</a>
  25636. Source=Paul Collins Startup list
  25637.  
  25638. [Hrn_qtv]
  25639. Number=3642
  25640. Confirmed=X
  25641. Filename=hrnsvc32.exe
  25642. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotaet.html" target=_blank>SDBOT-AET</a> WORM!
  25643. Source=Paul Collins Startup list
  25644.  
  25645. [hsim]
  25646. Number=3643
  25647. Confirmed=X
  25648. Filename=isearch.exe
  25649. Description=Unidentified malware
  25650. Source=Paul Collins Startup list
  25651.  
  25652. [hsim]
  25653. Number=3644
  25654. Confirmed=X
  25655. Filename=sexgame.exe
  25656. Description=Unidentified malware
  25657. Source=Paul Collins Startup list
  25658.  
  25659. [hsim]
  25660. Number=3645
  25661. Confirmed=X
  25662. Filename=toolbar.exe
  25663. Description=Unidentified malware
  25664. Source=Paul Collins Startup list
  25665.  
  25666. [HSLAB Logger]
  25667. Number=3646
  25668. Confirmed=U
  25669. Filename=logger.exe
  25670. Description=<a href="http://sarc.com/avcenter/venc/data/spyware.hslablogger.html" target=_blank>HSLABLogger</a> logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it
  25671. Source=Paul Collins Startup list
  25672.  
  25673. [HSTrans]
  25674. Number=3647
  25675. Confirmed=U
  25676. Filename=hstrans.exe
  25677. Description=Homescan Internet Transporter - part of <a href="http://www2.acnielsen.com/products/cps_homescan.shtml" target=_blank>ACNielson Homescan</a>. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen
  25678. Source=Paul Collins Startup list
  25679.  
  25680. [HsuGuiControl]
  25681. Number=3648
  25682. Confirmed=?
  25683. Filename=HsuGuiControl.exe
  25684. Description=Part of the Starband Internet satellite client. <font color="#FF0000">What does it do and is it required?</font>
  25685. Source=Paul Collins Startup list
  25686.  
  25687. [Hti]
  25688. Number=3649
  25689. Confirmed=U
  25690. Filename=npdor.exe
  25691. Description=Appears in startup if you have chosen to participate in on survey by <a href="http://www.npdor.com/" target="_blank"> NPD Online Research</a>. Required for the survey to work correctly. Otherwise not required
  25692. Source=Paul Collins Startup list
  25693.  
  25694. [HTML Help System]
  25695. Number=3650
  25696. Confirmed=X
  25697. Filename=hhs.pif
  25698. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotatb.html" target=_blank>RBOT-ATB</a> WORM!
  25699. Source=Paul Collins Startup list
  25700.  
  25701. [HTML32 Help System]
  25702. Number=3651
  25703. Confirmed=X
  25704. Filename=hhs32.pif
  25705. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotate.html" target=_blank>RBOT-ATE</a> WORM!
  25706. Source=Paul Collins Startup list
  25707.  
  25708. [HTpatch]
  25709. Number=3652
  25710. Confirmed=U
  25711. Filename=htpatch.exe
  25712. Description=HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
  25713. Source=Paul Collins Startup list
  25714.  
  25715. [HtProtect]
  25716. Number=3653
  25717. Confirmed=X
  25718. Filename=AVprotect.exe
  25719. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-030913-1913-99" target="_blank">NETSKY.L</a> WORM!
  25720. Source=Paul Collins Startup list
  25721.  
  25722. [HTTP Tunneling Server]
  25723. Number=3654
  25724. Confirmed=X
  25725. Filename=mstunnel.exe
  25726. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=49612" target="_blank">RBOT.EDL</a> WORM!
  25727. Source=Paul Collins Startup list
  25728.  
  25729. [http://www.lienvandekelder.be]
  25730. Number=3655
  25731. Confirmed=X
  25732. Filename=LienVandeKelder.exe
  25733. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobaz.html" target= blank>MYTOB-AZ</a> WORM!
  25734. Source=Paul Collins Startup list
  25735.  
  25736. [http://www.lienvandekelder.be]
  25737. Number=3656
  25738. Confirmed=X
  25739. Filename=Lien Van de Kelder.exe
  25740. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobap.html" target=_blank>MYTOB-AP</a> WORM and variants!
  25741. Source=Paul Collins Startup list
  25742.  
  25743. [http://www.lienvandekelder.be]
  25744. Number=3657
  25745. Confirmed=X
  25746. Filename=Lien Vande Kelder.exe
  25747. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobaq.html" target=_blank>MYTOB-AQ</a> WORM!
  25748. Source=Paul Collins Startup list
  25749.  
  25750. [http://www.lienvandekelder.be]
  25751. Number=3658
  25752. Confirmed=X
  25753. Filename=Lien vd Kelder.exe
  25754. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobm.html" target=_blank>MYTOB-M</a> WORM!
  25755. Source=Paul Collins Startup list
  25756.  
  25757. [http://www.lienvandekelder.be]
  25758. Number=3659
  25759. Confirmed=X
  25760. Filename=Lien.exe
  25761. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobcz.html" target=_blank>MYTOB-CZ</a> WORM!
  25762. Source=Paul Collins Startup list
  25763.  
  25764. [http://www.lienvandekelder.be]
  25765. Number=3660
  25766. Confirmed=X
  25767. Filename=Lientjeuh.exe
  25768. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobp.html" target=_blank>MYTOB-P</a> WORM!
  25769. Source=Paul Collins Startup list
  25770.  
  25771. [http://www.lienvandekelder.be]
  25772. Number=3661
  25773. Confirmed=X
  25774. Filename=LienVdK.exe
  25775. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobu.html" target=_blank>MYTOB-U</a> WORM!
  25776. Source=Paul Collins Startup list
  25777.  
  25778. [http://www.lienvandekelder.be]
  25779. Number=3662
  25780. Confirmed=X
  25781. Filename=Van de Kelder Lien.exe
  25782. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobbf.html" target=_blank>MYTOB-BF</a> WORM!
  25783. Source=Paul Collins Startup list
  25784.  
  25785. [http://www.lienvandekelder.be]
  25786. Number=3663
  25787. Confirmed=X
  25788. Filename=We Love Lien Van de Kelder.exe
  25789. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobcv.html" target=_blank>MYTOB-CV</a> WORM!
  25790. Source=Paul Collins Startup list
  25791.  
  25792. [http://www.lienvandekelder.com]
  25793. Number=3664
  25794. Confirmed=X
  25795. Filename=Lien Van de Kelder.exe
  25796. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobeq.html" target=_blank>MYTOB-EQ</a> WORM!
  25797. Source=Paul Collins Startup list
  25798.  
  25799. [http://www.lienvandekelder.com/]
  25800. Number=3665
  25801. Confirmed=X
  25802. Filename=LienVandeKelder.exe
  25803. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32mytobeo.html" target=_blank>MYTOB-EO</a> WORM!
  25804. Source=Paul Collins Startup list
  25805.  
  25806. [httpd]
  25807. Number=3666
  25808. Confirmed=X
  25809. Filename=c_pan.exe
  25810. Description=Added by a variant of the DELF-A TROJAN!
  25811. Source=Paul Collins Startup list
  25812.  
  25813. [httpd]
  25814. Number=3667
  25815. Confirmed=X
  25816. Filename=deamon.exe
  25817. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  25818. Source=Paul Collins Startup list
  25819.  
  25820. [httpd]
  25821. Number=3668
  25822. Confirmed=X
  25823. Filename=msgaol.exe
  25824. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  25825. Source=Paul Collins Startup list
  25826.  
  25827. [httpd]
  25828. Number=3669
  25829. Confirmed=X
  25830. Filename=s_menu.exe
  25831. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  25832. Source=Paul Collins Startup list
  25833.  
  25834. [httpd]
  25835. Number=3670
  25836. Confirmed=X
  25837. Filename=browse.exe
  25838. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  25839. Source=Paul Collins Startup list
  25840.  
  25841. [httpd]
  25842. Number=3671
  25843. Confirmed=X
  25844. Filename=deamon.exe
  25845. Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42022" target="_blank">TACTSLAY.C</a> TROJAN!
  25846. Source=Paul Collins Startup list
  25847.  
  25848. [https-ssl]
  25849. Number=3672
  25850. Confirmed=X
  25851. Filename=https.exe
  25852. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-100918-0303-99" target="_blank">MOEGA.D</a> WORM!
  25853. Source=Paul Collins Startup list
  25854.  
  25855. [huhdir]
  25856. Number=3673
  25857. Confirmed=?
  25858. Filename=huhdir.exe
  25859. Description=<font color="#FF0000">??</font>
  25860. Source=Paul Collins Startup list
  25861.  
  25862. [huigezi]
  25863. Number=3674
  25864. Confirmed=X
  25865. Filename=HgzServer.exe
  25866. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-041516-5125-99" target="_blank">GRAYBIRD.C</a> TROJAN!
  25867. Source=Paul Collins Startup list
  25868.  
  25869. [Hvid]
  25870. Number=3675
  25871. Confirmed=X
  25872. Filename=Hvid.exe
  25873. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  25874. Source=Paul Collins Startup list
  25875.  
  25876. [HWINFO*]
  25877. Number=3676
  25878. Confirmed=X
  25879. Filename=HWINFO*
  25880. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-041115-4727-99" target="_blank"> PUROL</a> WORM! where * is a random character
  25881. Source=Paul Collins Startup list
  25882.  
  25883. [HWinst]
  25884. Number=3677
  25885. Confirmed=Y
  25886. Filename=N/A
  25887. Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
  25888. Source=Paul Collins Startup list
  25889.  
  25890. [Hwp]
  25891. Number=3678
  25892. Confirmed=X
  25893. Filename=system_wc.exe
  25894. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-090719-0424-99" target=_blank>Eziin</a> adware
  25895. Source=Paul Collins Startup list
  25896.  
  25897. [hws]
  25898. Number=3679
  25899. Confirmed=X
  25900. Filename=hws.exe
  25901. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojstartpact.html" target=_blank>STARTPA-CT</a> TROJAN!
  25902. Source=Paul Collins Startup list
  25903.  
  25904. [HWSetup]
  25905. Number=3680
  25906. Confirmed=U
  25907. Filename=HWSetup.exe hwSetUP
  25908. Description="Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows." Allows the user to change BIOS, hard disk, memory, boot disk priority and other settings
  25909. Source=Paul Collins Startup list
  25910.  
  25911. [hxadsec]
  25912. Number=3681
  25913. Confirmed=X
  25914. Filename=[path to trojan]
  25915. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojadclickap.html" target=_blank>ADCLICK-AP</a> TROJAN!
  25916. Source=Paul Collins Startup list
  25917.  
  25918. [HXDL.EXE]
  25919. Number=3682
  25920. Confirmed=X
  25921. Filename=HXDL.EXE
  25922. Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079" target="_blank">here</a>
  25923. Source=Paul Collins Startup list
  25924.  
  25925. [HXIUL.EXE]
  25926. Number=3683
  25927. Confirmed=X
  25928. Filename=HXIUL.EXE
  25929. Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453075079" target="_blank">here</a>
  25930. Source=Paul Collins Startup list
  25931.  
  25932. [HydarVisionDesktopManager]
  25933. Number=3684
  25934. Confirmed=U
  25935. Filename=desk95.exe
  25936. Description=ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as <a href="http://support.microsoft.com/?id=810937" target=_blank>this one</a>. HydraVision can be uninstalled through Add/Remove Programs
  25937. Source=Paul Collins Startup list
  25938.  
  25939. [HydraVisionDesktopManager]
  25940. Number=3685
  25941. Confirmed=U
  25942. Filename=desk98.exe
  25943. Description=ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
  25944. Source=Paul Collins Startup list
  25945.  
  25946. [HydraVisionViewport]
  25947. Number=3686
  25948. Confirmed=U
  25949. Filename=viewport.exe
  25950. Description=ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
  25951. Source=Paul Collins Startup list
  25952.  
  25953. [Hyper Start]
  25954. Number=3687
  25955. Confirmed=X
  25956. Filename=instantmsgrs.exe
  25957. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotnh.html" target=_blank>RBOT-NH</a> WORM!
  25958.  
  25959. Source=Paul Collins Startup list
  25960.  
  25961. [I am not Ranky. I am eTunnel!]
  25962. Number=3688
  25963. Confirmed=X
  25964. Filename=msyervice.exe
  25965. Description=Added by an unidentified WORM or TROJAN!
  25966. Source=Paul Collins Startup list
  25967.  
  25968. [I am not Ranky. I am eTunnel!]
  25969. Number=3689
  25970. Confirmed=X
  25971. Filename=winsys.exe
  25972. Description=Added by an unidentified WORM or TROJAN!
  25973. Source=Paul Collins Startup list
  25974.  
  25975. [I am not Ranky. I am eTunnel!]
  25976. Number=3690
  25977. Confirmed=X
  25978. Filename=disney.exe
  25979. Description=Added by an unidentified WORM or TROJAN!
  25980. Source=Paul Collins Startup list
  25981.  
  25982. [I-Worm.GiGu]
  25983. Number=3691
  25984. Confirmed=X
  25985. Filename=uGiG.eXe
  25986. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-083016-1736-99" target="_blank">GINK</a> WORM!
  25987. Source=Paul Collins Startup list
  25988.  
  25989. [I/O Controllers]
  25990. Number=3692
  25991. Confirmed=X
  25992. Filename=svcnet.exe
  25993. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtibikb.html" target=_blank>TIBIK-B</a> TROJAN!
  25994. Source=Paul Collins Startup list
  25995.  
  25996. [I386]
  25997. Number=3693
  25998. Confirmed=X
  25999. Filename=I386.exe
  26000. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-062412-1734-99" target="_blank"> MYPOWER</a> WORM!
  26001. Source=Paul Collins Startup list
  26002.  
  26003. [I81SHELL]
  26004. Number=3694
  26005. Confirmed=?
  26006. Filename=I81SHELL.exe
  26007. Description=<font color="#FF0000">Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard</font>
  26008. Source=Paul Collins Startup list
  26009.  
  26010. [i8kfangui]
  26011. Number=3695
  26012. Confirmed=U
  26013. Filename=i8kfangui.exe
  26014. Description=Graphical interface for fan speed control
  26015. Source=Paul Collins Startup list
  26016.  
  26017. [IAAnotif]
  26018. Number=3696
  26019. Confirmed=U
  26020. Filename=iaanotif.exe
  26021. Description=IAA Event Monitor User Notification Tool - part of <a href="http://www.intel.com/support/chipsets/iaa/" target="_blank">Intel« Application Accelerator</a> - "a performance software package for desktop PCs using select Intel« chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
  26022. Source=Paul Collins Startup list
  26023.  
  26024. [iamapp]
  26025. Number=3697
  26026. Confirmed=Y
  26027. Filename=iamapp.exe
  26028. Description=AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well
  26029. Source=Paul Collins Startup list
  26030.  
  26031. [Iamnacho On Irc.MusIrc.com Is a Homosexual!]
  26032. Number=3698
  26033. Confirmed=X
  26034. Filename=XBox64.exe
  26035. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-110515-2026-99" target="_blank">RANDEX.Y</a> WORM!
  26036. Source=Paul Collins Startup list
  26037.  
  26038. [Iap]
  26039. Number=3699
  26040. Confirmed=?
  26041. Filename=iap.exe
  26042. Description=<font color="#FF0000">Possibly part of <a href="http://docs.us.dell.com/support/edocs/software/smcliins/cli60/en/ug/intro.htm" target="_blank">Dell OpenManage Client Instrumentation</a> - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?</font>
  26043. Source=Paul Collins Startup list
  26044.  
  26045. [ias]
  26046. Number=3700
  26047. Confirmed=U
  26048. Filename=ias.exe
  26049. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-120115-5305-99" target= blank>InvisibleASpy</a> keystroke logger/monitoring program - remove unless you installed it yourself!
  26050. Source=Paul Collins Startup list
  26051.  
  26052. [IASHLPR]
  26053. Number=3701
  26054. Confirmed=X
  26055. Filename=IASHLPR.EXE
  26056. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
  26057. Source=Paul Collins Startup list
  26058.  
  26059. [ibin]
  26060. Number=3702
  26061. Confirmed=X
  26062. Filename=[path to trojan]
  26063. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojperdac.html" target=_blank>PERDA-C</a> TROJAN!
  26064. Source=Paul Collins Startup list
  26065.  
  26066. [ibm]
  26067. Number=3703
  26068. Confirmed=X
  26069. Filename=ibm.exe
  26070. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlegmirah.html" target=_blank>LEGMIR-AH</a> TROJAN!
  26071. Source=Paul Collins Startup list
  26072.  
  26073. [IBM Warranty Notification]
  26074. Number=3704
  26075. Confirmed=?
  26076. Filename=ERTS0749.exe
  26077. Description=IBM Warranty Notification - <font color="#FF0000">presumably it's a reminder to either register or that warranty is about to expire?</font>
  26078. Source=Paul Collins Startup list
  26079.  
  26080. [ibmmessages]
  26081. Number=3705
  26082. Confirmed=N
  26083. Filename=ibmmessages.exe
  26084. Description=Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"
  26085. Source=Paul Collins Startup list
  26086.  
  26087. [Ibmmon.exe]
  26088. Number=3706
  26089. Confirmed=?
  26090. Filename=Ibmmon.exe
  26091. Description=<font color="#FF0000">??</font>
  26092. Source=Paul Collins Startup list
  26093.  
  26094. [Ibmpmsvc]
  26095. Number=3707
  26096. Confirmed=U
  26097. Filename=ibmpmsvc.exe
  26098. Description=Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes
  26099. Source=Paul Collins Startup list
  26100.  
  26101. [IBMPRC]
  26102. Number=3708
  26103. Confirmed=?
  26104. Filename=ibmprc.exe
  26105. Description=IBM application - <font color=#FF0000>what does it do and is it required?</font>
  26106. Source=Paul Collins Startup list
  26107.  
  26108. [IBMUltraBayHotSwapCPLLoader]
  26109. Number=3709
  26110. Confirmed=U
  26111. Filename=IBMBAY2N.EXE
  26112. Description=Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
  26113. Source=Paul Collins Startup list
  26114.  
  26115. [IBMUltraBayHotSwapSound]
  26116. Number=3710
  26117. Confirmed=?
  26118. Filename=IBMBAYSN.EXE
  26119. Description=<font color="#FF0000">Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?</font>
  26120. Source=Paul Collins Startup list
  26121.  
  26122. [IBM_PWMGR]
  26123. Number=3711
  26124. Confirmed=Y
  26125. Filename=pwmgr.exe
  26126. Description=IBM Password Manager
  26127.  
  26128. Source=Paul Collins Startup list
  26129.  
  26130. [IBWin Background process]
  26131. Number=3712
  26132. Confirmed=U
  26133. Filename=IBackground.exe
  26134. Description=<a href="http://www.ibackup.com/ibwin_new.htm" target=_blank>IBackup</a> for Windows
  26135. Source=Paul Collins Startup list
  26136.  
  26137. [IBWin Monitor]
  26138. Number=3713
  26139. Confirmed=U
  26140. Filename=IBMonitor.exe
  26141. Description=<a href="http://www.ibackup.com/ibwin_new.htm" target=_blank>IBackup</a> for Windows
  26142. Source=Paul Collins Startup list
  26143.  
  26144. [IcaBar]
  26145. Number=3714
  26146. Confirmed=Y
  26147. Filename=icabar.exe
  26148. Description=Related to Citrix MetaFrame
  26149. Source=Paul Collins Startup list
  26150.  
  26151. [icasServ]
  26152. Number=3715
  26153. Confirmed=X
  26154. Filename=icasServ.exe
  26155. Description=Browser hijacker, redirecting to Searchforfree.info. Also detected as the <a href="http://www.sophos.com/virusinfo/analyses/trojicaserva.html" target= blank>ICASERV-A</a> TROJAN!
  26156. Source=Paul Collins Startup list
  26157.  
  26158. [ICcontrol]
  26159. Number=3716
  26160. Confirmed=X
  26161. Filename=iccontrol.exe
  26162. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-091412-0643-99" target=_blank>ICcontrol</a> premium rate adult content dialer
  26163. Source=Paul Collins Startup list
  26164.  
  26165. [icdd7ee6]
  26166. Number=3717
  26167. Confirmed=X
  26168. Filename=rundll32.exe [path] icdd7ee6.dll, EnableRunDLL32
  26169. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target="_blank">LZIO.com</a> adware downloader
  26170. Source=Paul Collins Startup list
  26171.  
  26172. [icddefff]
  26173. Number=3718
  26174. Confirmed=X
  26175. Filename=rundll32.exe [path] icddefff.dll, EnableRunDLL32
  26176. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target=_blank>LZIO.com</a> adware downloader
  26177. Source=Paul Collins Startup list
  26178.  
  26179. [ICH Synth]
  26180. Number=3719
  26181. Confirmed=N
  26182. Filename=eusexe.exe
  26183. Description=Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. <font color="#FF0000">May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices</font>
  26184. Source=Paul Collins Startup list
  26185.  
  26186. [icifati]
  26187. Number=3720
  26188. Confirmed=X
  26189. Filename=yujixit.exe
  26190. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.ZZH&VSect=P" target=_blank>SDBOT.ZZH</a> WORM!
  26191. Source=Paul Collins Startup list
  26192.  
  26193. [iClean]
  26194. Number=3721
  26195. Confirmed=U
  26196. Filename=iClean.exe
  26197. Description=<a href="http://www.nsclean.com/ieclean.html" target="_blank">IEClean</a> - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"
  26198. Source=Paul Collins Startup list
  26199.  
  26200. [ICM]
  26201. Number=3722
  26202. Confirmed=U
  26203. Filename=ICM.EXE
  26204. Description=Starts <a href="http://www.infointeractive.com/" target="_blank">Internet Call Manager</a> dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail
  26205. Source=Paul Collins Startup list
  26206.  
  26207. [iCn]
  26208. Number=3723
  26209. Confirmed=N
  26210. Filename=NAG.EXE
  26211. Description=iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist. Not related to the Mac icon program of the same name
  26212. Source=Paul Collins Startup list
  26213.  
  26214. [ICO]
  26215. Number=3724
  26216. Confirmed=N
  26217. Filename=ICO.EXE
  26218. Description=Found on Sony Vaio and IBM Thinkpad (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
  26219. Source=Paul Collins Startup list
  26220.  
  26221. [Icon Animation]
  26222. Number=3725
  26223. Confirmed=N
  26224. Filename=HDE.EXE
  26225. Description=Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
  26226. Source=Paul Collins Startup list
  26227.  
  26228. [Icon Hearit 95]
  26229. Number=3726
  26230. Confirmed=N
  26231. Filename=hearit95.exe
  26232. Description=Audio desktop customization utility from Moon Valley Software. Resource hog
  26233. Source=Paul Collins Startup list
  26234.  
  26235. [Icon Hearit 98]
  26236. Number=3727
  26237. Confirmed=N
  26238. Filename=hearit98.exe
  26239. Description=Audio desktop customization utility from Moon Valley Software. Resource hog
  26240. Source=Paul Collins Startup list
  26241.  
  26242. [Icon lptt01]
  26243. Number=3728
  26244. Confirmed=X
  26245. Filename=icon.exe
  26246. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  26247. Source=Paul Collins Startup list
  26248.  
  26249. [Icon ml097e]
  26250. Number=3729
  26251. Confirmed=X
  26252. Filename=icon.exe
  26253. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  26254. Source=Paul Collins Startup list
  26255.  
  26256. [ICONCLNT]
  26257. Number=3730
  26258. Confirmed=Y
  26259. Filename=iconclnt.exe
  26260. Description=APC PowerChute Tray Icon. Associated with the <a href="#UPS"> UPS</a> listing
  26261. Source=Paul Collins Startup list
  26262.  
  26263. [ICONDESK]
  26264. Number=3731
  26265. Confirmed=U
  26266. Filename=ICONDESK.EXE
  26267. Description=Small utility which will allow you the option of hiding or showing your desktop icons
  26268. Source=Paul Collins Startup list
  26269.  
  26270. [Iconfig.exe]
  26271. Number=3732
  26272. Confirmed=N
  26273. Filename=Iconfig.exe
  26274. Description=Icon for LS-120 "Superdisk"
  26275. Source=Paul Collins Startup list
  26276.  
  26277. [iConfigLoader]
  26278. Number=3733
  26279. Confirmed=X
  26280. Filename=DIIhost.exe
  26281. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-093012-5903-99" target="_blank">GAOBOT.AO</a> WORM!
  26282. Source=Paul Collins Startup list
  26283.  
  26284. [Iconoid]
  26285. Number=3734
  26286. Confirmed=N
  26287. Filename=Iconoid.exe
  26288. Description=<a href="http://www.sillysot.com/index.html" target="_blank">Iconoid</a> is a desktop icon manager
  26289. Source=Paul Collins Startup list
  26290.  
  26291. [Iconsaver]
  26292. Number=3735
  26293. Confirmed=N
  26294. Filename=Iconsaver.exe
  26295. Description=<a href="http://www.iconsaver.com/index.html" target="_blank">IconSaver</a> is a desktop icon manager
  26296. Source=Paul Collins Startup list
  26297.  
  26298. [ICQ]
  26299. Number=3736
  26300. Confirmed=X
  26301. Filename=ICQNET.vbs
  26302. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/vbsgormleza.html" target=_blank>GORMLEZ-A</a> WORM!
  26303. Source=Paul Collins Startup list
  26304.  
  26305. [ICQ Center]
  26306. Number=3737
  26307. Confirmed=X
  26308. Filename=[path to worm]
  26309. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-092114-2153-99" target="_blank">RANDIN</a> WORM!
  26310. Source=Paul Collins Startup list
  26311.  
  26312. [ICQ Chat Service]
  26313. Number=3738
  26314. Confirmed=X
  26315. Filename=icqjdhs.exe
  26316. Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target= blank>RBOT</a> WORM!
  26317. Source=Paul Collins Startup list
  26318.  
  26319. [ICQ Hacking Pro]
  26320. Number=3739
  26321. Confirmed=X
  26322. Filename=ICQpro.exe
  26323. Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_NETSPY" target="_blank">NETSPY</a> TROJAN!
  26324. Source=Paul Collins Startup list
  26325.  
  26326. [ICQ Lite]
  26327. Number=3740
  26328. Confirmed=N
  26329. Filename=ICQLite.exe
  26330. Description=<a target="_blank" href="http://www.icq.com/download/">ICQ Lite</a> - compact version of the popular messaging program
  26331. Source=Paul Collins Startup list
  26332.  
  26333. [icq lite]
  26334. Number=3741
  26335. Confirmed=X
  26336. Filename=scvhost.exe
  26337. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentdsf.html" target="_blank">AGENT-DSF</a> TROJAN!
  26338. Source=Paul Collins Startup list
  26339.  
  26340. [icq lite]
  26341. Number=3742
  26342. Confirmed=X
  26343. Filename=winlog.exe
  26344. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbottj.html" target="_blank">IRCBOT-TJ</a> TROJAN!
  26345. Source=Paul Collins Startup list
  26346.  
  26347. [ICQ Lite Messenger]
  26348. Number=3743
  26349. Confirmed=X
  26350. Filename=[random filename]
  26351. Description=Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or Winnt\System32 directory
  26352. Source=Paul Collins Startup list
  26353.  
  26354. [ICQ Messenger 2002]
  26355. Number=3744
  26356. Confirmed=X
  26357. Filename=ICQ2002.exe
  26358. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotabl.html" target=_blank>SDBOT-ABL</a> WORM!
  26359. Source=Paul Collins Startup list
  26360.  
  26361. [ICQ Net]
  26362. Number=3745
  26363. Confirmed=X
  26364. Filename=winlogon.exe
  26365. Description=Added by variants of the NETSKY WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process which should not appear in Msconfig/Startup!
  26366. Source=Paul Collins Startup list
  26367.  
  26368. [ICQ Plus]
  26369. Number=3746
  26370. Confirmed=N
  26371. Filename=vplus.exe
  26372. Description=<a href="http://www.freedownloadscenter.com/Business/Application_Add-ins/ICQ_Plus.html" target="_blank">ICQ Plus</a> is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs
  26373. Source=Paul Collins Startup list
  26374.  
  26375. [IcqBeta]
  26376. Number=3747
  26377. Confirmed=X
  26378. Filename=webcamupdate.exe
  26379. Description=Added by an unidentified TROJAN!
  26380. Source=Paul Collins Startup list
  26381.  
  26382. [ICQNet]
  26383. Number=3748
  26384. Confirmed=X
  26385. Filename=winlogon.exe
  26386. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32netskyc.html" target=_blank>NETSKY-C</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target=_blank>winlogon.exe</a> process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
  26387. Source=Paul Collins Startup list
  26388.  
  26389. [icrosof Avps32 Control]
  26390. Number=3749
  26391. Confirmed=X
  26392. Filename=av32.pif
  26393. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotavc.html" target=_blank>RBOT-AVC</a> WORM!
  26394. Source=Paul Collins Startup list
  26395.  
  26396. [icrosoft Visual]
  26397. Number=3750
  26398. Confirmed=X
  26399. Filename=plscx.exe
  26400. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotayo.html" target=_blank>RBOT-AYO</a> WORM!
  26401. Source=Paul Collins Startup list
  26402.  
  26403. [icrosoft Visual InterDevc]
  26404. Number=3751
  26405. Confirmed=X
  26406. Filename=zvslmqb.exe
  26407. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotayp.html" target=_blank>RBOT-AYP</a> WORM!
  26408. Source=Paul Collins Startup list
  26409.  
  26410. [icrosoft Windows DLL Services Configuration]
  26411. Number=3752
  26412. Confirmed=X
  26413. Filename=poker3.exe
  26414. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotaer.html" target=_blank>SDBOT-AER</a> WORM!
  26415. Source=Paul Collins Startup list
  26416.  
  26417. [icrosoftf Avpx Control]
  26418. Number=3753
  26419. Confirmed=X
  26420. Filename=avpx.exe
  26421. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotayn.html" target=_blank>RBOT-AYN</a> WORM!
  26422. Source=Paul Collins Startup list
  26423.  
  26424. [ICSDCLT]
  26425. Number=3754
  26426. Confirmed=U
  26427. Filename=rundll32.exe Icsdclt.dll, ICSClient
  26428. Description=Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
  26429. Source=Paul Collins Startup list
  26430.  
  26431. [ICServer]
  26432. Number=3755
  26433. Confirmed=N
  26434. Filename=Icserver.exe
  26435. Description=Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
  26436. Source=Paul Collins Startup list
  26437.  
  26438. [ICSMGR]
  26439. Number=3756
  26440. Confirmed=Y
  26441. Filename=ICSMGR.EXE
  26442. Description=Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
  26443. Source=Paul Collins Startup list
  26444.  
  26445. [IC_KEY_3]
  26446. Number=3757
  26447. Confirmed=N
  26448. Filename=spvic.exe
  26449. Description=<a href="http://www.instantchess.com/?SN=Z4dMzyutgpE9Pspv&ABT=3" target="_blank">Instant Chess</a> related
  26450. Source=Paul Collins Startup list
  26451.  
  26452. [ID Commander]
  26453. Number=3758
  26454. Confirmed=N
  26455. Filename=IDCom.exe
  26456. Description=Caller ID utility for identifying incoming telephone numbers
  26457. Source=Paul Collins Startup list
  26458.  
  26459. [ID8525]
  26460. Number=3759
  26461. Confirmed=X
  26462. Filename=ID8525.exe
  26463. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ID8525.A" target="_blank">ID8525.A</a> TROJAN!
  26464. Source=Paul Collins Startup list
  26465.  
  26466. [ID8525]
  26467. Number=3760
  26468. Confirmed=X
  26469. Filename=id85255.exe
  26470. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ID8525.A" target="_blank">ID8525.A</a> TROJAN!
  26471. Source=Paul Collins Startup list
  26472.  
  26473. [IDA]
  26474. Number=3761
  26475. Confirmed=?
  26476. Filename=IDA.EXE
  26477. Description=<font color="#FF0000">HP related - in a Program FilesHewlett-PackardPC COE folder</font>
  26478. Source=Paul Collins Startup list
  26479.  
  26480. [IDE]
  26481. Number=3762
  26482. Confirmed=X
  26483. Filename=ide.exe
  26484. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-042919-4416-99" target="_blank">ASSASIN.F</a> TROJAN!
  26485. Source=Paul Collins Startup list
  26486.  
  26487. [IDE Loader]
  26488. Number=3763
  26489. Confirmed=X
  26490. Filename=IDElibr32.exe
  26491. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-121812-2137-99" target="_blank">XILON</a> TROJAN! Related to the game "Diablo II"
  26492. Source=Paul Collins Startup list
  26493.  
  26494. [idecntl]
  26495. Number=3764
  26496. Confirmed=X
  26497. Filename=idecntl.exe
  26498. Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
  26499. Source=Paul Collins Startup list
  26500.  
  26501. [iDesktop]
  26502. Number=3765
  26503. Confirmed=U
  26504. Filename=idesktop.exe
  26505. Description=<a href="http://www.immersion.com/products/ce/generaldownloads.shtml" target="_blank">Immersion TouchWare Desktop</a> software for devices such as the Logitech iFeel Mouse
  26506. Source=Paul Collins Startup list
  26507.  
  26508. [IDMan]
  26509. Number=3766
  26510. Confirmed=N
  26511. Filename=IDMan.exe
  26512. Description=<a href="http://www.internetdownloadmanager.com/" target="_blank">Internet Download Manager</a> - download files faster, schedule and resume
  26513. Source=Paul Collins Startup list
  26514.  
  26515. [IDTemplates]
  26516. Number=3767
  26517. Confirmed=X
  26518. Filename=IDTemplate.exe
  26519. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32brontokh.html" target=_blank>BRONTOK-H</a> WORM!
  26520. Source=Paul Collins Startup list
  26521.  
  26522. [IDW Logging Tool]
  26523. Number=3768
  26524. Confirmed=N
  26525. Filename=idwlog.exe
  26526. Description=Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
  26527. Source=Paul Collins Startup list
  26528.  
  26529. [IE configure]
  26530. Number=3769
  26531. Confirmed=X
  26532. Filename=explorer.exe
  26533. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlineagec.html" target="_blank">LINEAGE-C</a> TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!
  26534. Source=Paul Collins Startup list
  26535.  
  26536. [IE Doctor]
  26537. Number=3770
  26538. Confirmed=U
  26539. Filename=IEDoctor.exe
  26540. Description=IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
  26541. Source=Paul Collins Startup list
  26542.  
  26543. [IE Java Update]
  26544. Number=3771
  26545. Confirmed=X
  26546. Filename=iejava.exe
  26547. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagenthd.html" target=_blank>AGENT-HD</a> TROJAN!
  26548. Source=Paul Collins Startup list
  26549.  
  26550. [IE Menu Extension toolbar]
  26551. Number=3772
  26552. Confirmed=X
  26553. Filename=rundll32.exe [path] tbextn.dll DllShowTB
  26554. Description=Topconverting.com\180Search "IEMenuExtension" toolbar
  26555.  
  26556. Source=Paul Collins Startup list
  26557.  
  26558. [IE New Window Maximizer]
  26559. Number=3773
  26560. Confirmed=U
  26561. Filename=iemaximizer.exe
  26562. Description=<a href="http://www.jiisoft.com/iemaximizer/" target=_blank>IE New Window Maximizer</a> - automatically maximize new Internet Explorer and Outlook Express windows
  26563. Source=Paul Collins Startup list
  26564.  
  26565. [IE Runtime]
  26566. Number=3774
  26567. Confirmed=X
  26568. Filename=wini.exe
  26569. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-041813-3041-99" target=_blank>PICRATE.B</a> WORM!
  26570. Source=Paul Collins Startup list
  26571.  
  26572. [IE Runtimes]
  26573. Number=3775
  26574. Confirmed=X
  26575. Filename=winis.exe
  26576. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotadz.html" target="_blank">RBOT-ADZ</a> TROJAN!
  26577. Source=Paul Collins Startup list
  26578.  
  26579. [IE**.exe [* = random char]]
  26580. Number=3776
  26581. Confirmed=X
  26582. Filename=IE**.exe [* = random char]
  26583. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  26584. Source=Paul Collins Startup list
  26585.  
  26586. [IE**32.exe [* = random char]]
  26587. Number=3777
  26588. Confirmed=X
  26589. Filename=IE**32.exe [* = random char]
  26590. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html#homesearch" target="_blank">CoolWebSearch/HomeSearch</a> adware - for examples, see <a href="http://www.castlecops.com/t131351-Possibly_the_dirtiest_HJTLog_youll_ever_see.html" target="_blank">this</a> log
  26591. Source=Paul Collins Startup list
  26592.  
  26593. [IE-Bar]
  26594. Number=3778
  26595. Confirmed=X
  26596. Filename=iebar.exe
  26597. Description=<a href="http://www3.cai.com/securityadvisor/pest/pest.aspx?id=453099723" target="_blank">DesktopMedia</a> adware
  26598. Source=Paul Collins Startup list
  26599.  
  26600. [IE6]
  26601. Number=3779
  26602. Confirmed=X
  26603. Filename=wkstmg.exe
  26604. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  26605. Source=Paul Collins Startup list
  26606.  
  26607. [IE6]
  26608. Number=3780
  26609. Confirmed=X
  26610. Filename=ssmss.exe
  26611. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-082217-1116-99" target=_blank>GAOBOT.DXO</a> WORM!
  26612. Source=Paul Collins Startup list
  26613.  
  26614. [IE6]
  26615. Number=3781
  26616. Confirmed=X
  26617. Filename=porn.pif
  26618. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotatf.html" target=_blank>RBOT-ATF</a> WORM!
  26619. Source=Paul Collins Startup list
  26620.  
  26621. [IEACCESS]
  26622. Number=3782
  26623. Confirmed=X
  26624. Filename=temp532.exe
  26625. Description=<a href="http://www.sarc.com/avcenter/venc/data/dialer.asdplug.html" target=_blank>AsdPlug</a> premium rate adult content dialer variant
  26626. Source=Paul Collins Startup list
  26627.  
  26628. [IEACCESS]
  26629. Number=3783
  26630. Confirmed=X
  26631. Filename=surfya.exe
  26632. Description=<a href="http://www.extremetech.com/article2/0,1697,1125674,00.asp" target=_blank>IEAccess</a> premium rate adult content dialer variant
  26633. Source=Paul Collins Startup list
  26634.  
  26635. [IEAgent update check]
  26636. Number=3784
  26637. Confirmed=X
  26638. Filename=iewatch.exe
  26639. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-012514-0250-99" target=_blank>BOMKA</a> TROJAN!
  26640. Source=Paul Collins Startup list
  26641.  
  26642. [iecheck]
  26643. Number=3785
  26644. Confirmed=N
  26645. Filename=iecheck.exe
  26646. Description=Integrity checker for <a href="http://www.iconedit2.com/" target="_blank">IconEdit2</a> icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
  26647. Source=Paul Collins Startup list
  26648.  
  26649. [IECheck]
  26650. Number=3786
  26651. Confirmed=X
  26652. Filename=MSDTCs.exe
  26653. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32tirbotd.html" target=_blank>TIRBOT-D</a> WORM!
  26654. Source=Paul Collins Startup list
  26655.  
  26656. [IECheck]
  26657. Number=3787
  26658. Confirmed=X
  26659. Filename=xpssl.exe
  26660. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32tirbote.html" target= blank>TIRBOT-E</a> WORM!
  26661. Source=Paul Collins Startup list
  26662.  
  26663. [IECheck]
  26664. Number=3788
  26665. Confirmed=X
  26666. Filename=mssvp.exe
  26667. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32tirbotg.html" target=_blank>TIRBOT-G</a> WORM!
  26668. Source=Paul Collins Startup list
  26669.  
  26670. [IECleanAux]
  26671. Number=3789
  26672. Confirmed=U
  26673. Filename=Ieboot6.exe
  26674. Description=<a href="http://www.nsclean.com/ieclean.html" target="_blank">IEClean</a> by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
  26675. Source=Paul Collins Startup list
  26676.  
  26677. [iedll]
  26678. Number=3790
  26679. Confirmed=X
  26680. Filename=iedll.exe
  26681. Description=Homepage hijacker, redirecting to coolwwwsearch.com
  26682. Source=Paul Collins Startup list
  26683.  
  26684. [IEDriver]
  26685. Number=3791
  26686. Confirmed=X
  26687. Filename=IEDriver.exe
  26688. Description=Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
  26689. Source=Paul Collins Startup list
  26690.  
  26691. [IEDriver]
  26692. Number=3792
  26693. Confirmed=X
  26694. Filename=xplore.exe
  26695. Description=<a href="http://sarc.com/avcenter/venc/data/adware.iedriver.html" target=_blank>IEDriver</a> adware variant
  26696. Source=Paul Collins Startup list
  26697.  
  26698. [IEDriver]
  26699. Number=3793
  26700. Confirmed=X
  26701. Filename=TD.exe
  26702. Description=<a href="http://sarc.com/avcenter/venc/data/adware.iedriver.html" target=_blank>IEDriver</a> adware variant
  26703. Source=Paul Collins Startup list
  26704.  
  26705. [IEengine]
  26706. Number=3794
  26707. Confirmed=X
  26708. Filename=IEeng.exe
  26709. Description=<a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_STARTPAG.AI" target="_blank">STARTPAG.AI</a> hijacker
  26710. Source=Paul Collins Startup list
  26711.  
  26712. [IEFeatures]
  26713. Number=3795
  26714. Confirmed=X
  26715. Filename=IEFeatures.exe
  26716. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_POPMON.A" target="_blank">POPMON.A</a> TROJAN! - also known as PopMonster adware
  26717. Source=Paul Collins Startup list
  26718.  
  26719. [IEFeatures]
  26720. Number=3796
  26721. Confirmed=X
  26722. Filename=Internetfeatures.exe
  26723. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_POPMON.A" target="_blank">POPMON.A</a> TROJAN! - also known as PopMonster adware
  26724. Source=Paul Collins Startup list
  26725.  
  26726. [IefxTray]
  26727. Number=3797
  26728. Confirmed=X
  26729. Filename=IefxTray.exe
  26730. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojrilerh.html" target=_blank>RILER-H</a> TROJAN!
  26731. Source=Paul Collins Startup list
  26732.  
  26733. [ieharv.exe]
  26734. Number=3798
  26735. Confirmed=X
  26736. Filename=ieharv.exe
  26737. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerhh.html" target=_blank>BANKER-HH</a> TROJAN!
  26738. Source=Paul Collins Startup list
  26739.  
  26740. [Iehelper]
  26741. Number=3799
  26742. Confirmed=X
  26743. Filename=syslaunch.exe
  26744. Description=Outwar adware downloader
  26745. Source=Paul Collins Startup list
  26746.  
  26747. [iel2cde8]
  26748. Number=3800
  26749. Confirmed=X
  26750. Filename=rundll32.exe [path] iel2cde8.dll, EnableRunDLL32
  26751. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target="_blank">LZIO.com</a> adware downloader
  26752. Source=Paul Collins Startup list
  26753.  
  26754. [ielcaabe]
  26755. Number=3801
  26756. Confirmed=X
  26757. Filename=rundll32.exe [path] ielcaabe.dll, EnableRunDLL32
  26758. Description=<a href="http://www.spywareguide.com/product_show.php?id=853" target=_blank>LZIO.com</a> adware downloader
  26759. Source=Paul Collins Startup list
  26760.  
  26761. [IELoader32]
  26762. Number=3802
  26763. Confirmed=X
  26764. Filename=iexplore32.exe
  26765. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-070417-1048-99" target="_blank"> SPEX</a> or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-112617-3418-99" target="_blank"> SPEX.B</a> WORMS!
  26766. Source=Paul Collins Startup list
  26767.  
  26768. [Iesar]
  26769. Number=3803
  26770. Confirmed=X
  26771. Filename=Iesar.exe
  26772. Description=Browser hijacker - redirecting to an adult web page
  26773. Source=Paul Collins Startup list
  26774.  
  26775. [Iesearch.exe]
  26776. Number=3804
  26777. Confirmed=X
  26778. Filename=Iesearch.exe
  26779. Description=<a href="http://sarc.com/avcenter/venc/data/pf/adware.looknsearch.html" target="_blank">LookNSearch</a> adware
  26780. Source=Paul Collins Startup list
  26781.  
  26782. [IESet]
  26783. Number=3805
  26784. Confirmed=X
  26785. Filename=IExplorer.dll
  26786. Description=Added by the <a href="http://vil.nai.com/vil/content/v_132935.htm" target="_blank">PWS-BLUEDIT</a> TROJAN!
  26787. Source=Paul Collins Startup list
  26788.  
  26789. [iestart]
  26790. Number=3806
  26791. Confirmed=X
  26792. Filename=iexp1orer.exe
  26793. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-091023-5351-99" target="_blank">NEMOG.C</a> TROJAN!
  26794. Source=Paul Collins Startup list
  26795.  
  26796. [ietsr]
  26797. Number=3807
  26798. Confirmed=N
  26799. Filename=ietsr.exe
  26800. Description=<a href="http://www.nsclean.com/ieclean.html" target="_blank">IEClean</a> by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
  26801. Source=Paul Collins Startup list
  26802.  
  26803. [ieupdate]
  26804. Number=3808
  26805. Confirmed=X
  26806. Filename=MCP****.exe [**** = random char]
  26807. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-112617-0033-99" target="_blank">ASOXY</a> TROJAN!
  26808. Source=Paul Collins Startup list
  26809.  
  26810. [ieupdate]
  26811. Number=3809
  26812. Confirmed=X
  26813. Filename=mcpdll32.exe
  26814. Description=Adware downloader trojan
  26815. Source=Paul Collins Startup list
  26816.  
  26817. [IEXPL0RER]
  26818. Number=3810
  26819. Confirmed=X
  26820. Filename=IEXPL0RER.EXE
  26821. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotql.html" target= blank>AGOBOT-QL</a> WORM!
  26822.  Note the filename has a "0" rather than an upper case "o"
  26823. Source=Paul Collins Startup list
  26824.  
  26825. [iexpl0res]
  26826. Number=3811
  26827. Confirmed=X
  26828. Filename=iexpl0res.exe
  26829. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AEX&VSect=T" target=_blank>RBOT.AEX</a> WORM! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot
  26830. Source=Paul Collins Startup list
  26831.  
  26832. [IExploer]
  26833. Number=3812
  26834. Confirmed=X
  26835. Filename=svshosts.exe
  26836. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_IRCBOT.BT" target="_blank">IRCBOT.BT</a> TROJAN!
  26837. Source=Paul Collins Startup list
  26838.  
  26839. [Iexploit]
  26840. Number=3813
  26841. Confirmed=X
  26842. Filename=Iexploit.html
  26843. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-091412-3836-99" target=_blank>INKER.B</a> WORM!
  26844. Source=Paul Collins Startup list
  26845.  
  26846. [Iexplore]
  26847. Number=3814
  26848. Confirmed=X
  26849. Filename=iexplore.exe
  26850. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-091117-1653-99" target=_blank>BOXER</a> TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  26851. Source=Paul Collins Startup list
  26852.  
  26853. [IEXPLORE]
  26854. Number=3815
  26855. Confirmed=X
  26856. Filename=iexplore.exe
  26857. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-012817-3358-99" target=_blank>APHEXDOOR</a> TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
  26858. Source=Paul Collins Startup list
  26859.  
  26860. [IExplore]
  26861. Number=3816
  26862. Confirmed=X
  26863. Filename=IEXPLORE.EXE
  26864. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderyz.html" target=_blank>DLOADER-YZ</a> TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in a "Custom" subfolder
  26865. Source=Paul Collins Startup list
  26866.  
  26867. [IExplore]
  26868. Number=3817
  26869. Confirmed=X
  26870. Filename=IEXPLORE.exe
  26871. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloadraam.html" target=_blank>DLOADR-AAM</a> TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the "Arquivos de programas\Internet Explorer\Custom" folder
  26872. Source=Paul Collins Startup list
  26873.  
  26874. [IEXPLORE]
  26875. Number=3818
  26876. Confirmed=X
  26877. Filename=IEXPLORE.EXE
  26878. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerbwe.html" target="_blank">BANKER-BWE</a> TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
  26879. Source=Paul Collins Startup list
  26880.  
  26881. [Iexplore Services]
  26882. Number=3819
  26883. Confirmed=X
  26884. Filename=iexplore.exe
  26885. Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target=_blank>iexplore.exe</a> process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup!
  26886. Source=Paul Collins Startup list
  26887.  
  26888. [IEXPLORE.EXE]
  26889. Number=3820
  26890. Confirmed=X
  26891. Filename=[path to trojan]
  26892. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancoscj.html" target=_blank>BANCOS-CJ</a> TROJAN!
  26893. Source=Paul Collins Startup list
  26894.  
  26895. [IEXPLORE.EXE]
  26896. Number=3821
  26897. Confirmed=X
  26898. Filename=goot.exe
  26899. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbifrosec.html" target=_blank>BIFROSE-C</a> TROJAN!
  26900. Source=Paul Collins Startup list
  26901.  
  26902. [IExplorer]
  26903. Number=3822
  26904. Confirmed=X
  26905. Filename=Iexplor32.exe
  26906. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorby.html" target=_blank>BDOOR-BY</a> TROJAN!
  26907. Source=Paul Collins Startup list
  26908.  
  26909. [IExplorer]
  26910. Number=3823
  26911. Confirmed=X
  26912. Filename=IExplorer.EXE
  26913. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancosch.html" target=_blank>BANCOS-CH</a> TROJAN!
  26914. Source=Paul Collins Startup list
  26915.  
  26916. [IEXPLORER]
  26917. Number=3824
  26918. Confirmed=X
  26919. Filename=msiecfg.exe
  26920. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbdoorju.html" target=_blank>JU</a> or <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanip.html" target=_blank>BANCBAN-IP</a> TROJANS!
  26921. Source=Paul Collins Startup list
  26922.  
  26923. [Iexplorer]
  26924. Number=3825
  26925. Confirmed=X
  26926. Filename=explorer.exe
  26927. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojzapchasac.html" target=_blank>ZAPCHAS-AC</a> TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder
  26928. Source=Paul Collins Startup list
  26929.  
  26930. [iexplorer lptt01]
  26931. Number=3826
  26932. Confirmed=X
  26933. Filename=iexplorer.exe
  26934. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  26935. Source=Paul Collins Startup list
  26936.  
  26937. [iexplorer ml097e]
  26938. Number=3827
  26939. Confirmed=X
  26940. Filename=iexplorer.exe
  26941. Description=<a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">RapidBlaster</a> variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see <a href="http://www.castlecops.com/downloads-file-333-details-RapidBlaster_Killer.html" target="_blank">here</a>
  26942. Source=Paul Collins Startup list
  26943.  
  26944. [Iexplorer.exe]
  26945. Number=3828
  26946. Confirmed=X
  26947. Filename=Iexplorer.exe
  26948. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanen.html" target=_blank>BANCBAN-EN</a> TROJAN!
  26949. Source=Paul Collins Startup list
  26950.  
  26951. [IExplorer32 Java Scripting]
  26952. Number=3829
  26953. Confirmed=X
  26954. Filename=IExplore32b.exe
  26955. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ABO&VSect=P" target=_blank>RBOT.ABO</a> WORM!
  26956. Source=Paul Collins Startup list
  26957.  
  26958. [IExplorer32c Java Scripting]
  26959. Number=3830
  26960. Confirmed=X
  26961. Filename=IExplore32cb.exe
  26962. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ABN" target="_blank">RBOT.ABN</a> WORM!
  26963. Source=Paul Collins Startup list
  26964.  
  26965. [IExplorer6 Java Scripting]
  26966. Number=3831
  26967. Confirmed=X
  26968. Filename=IExplore326.exe
  26969. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  26970. Source=Paul Collins Startup list
  26971.  
  26972. [IExplorer7 Java Scripting]
  26973. Number=3832
  26974. Confirmed=X
  26975. Filename=IExplore327.exe
  26976. Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
  26977. Source=Paul Collins Startup list
  26978.  
  26979. [ifp]
  26980. Number=3833
  26981. Confirmed=X
  26982. Filename=ipf.exe
  26983. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojclaggerag.html" target="_blank">CLAGGER-AG</a> TROJAN!
  26984. Source=Paul Collins Startup list
  26985.  
  26986. [IFSplash.exe]
  26987. Number=3834
  26988. Confirmed=U
  26989. Filename=IFSplash.exe
  26990. Description=I-FORCE driver for force feedback steering wheel
  26991. Source=Paul Collins Startup list
  26992.  
  26993. [igamatu]
  26994. Number=3835
  26995. Confirmed=X
  26996. Filename=ekor.exe
  26997. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-051316-2854-99" target= blank>SDBOT.AQ</a> TROJAN!
  26998. Source=Paul Collins Startup list
  26999.  
  27000. [igamatu]
  27001. Number=3836
  27002. Confirmed=X
  27003. Filename=atecaca.exe
  27004. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_IRCBOT.R&VSect=P" target=_blank>IRCBOT.R</a> WORM!
  27005. Source=Paul Collins Startup list
  27006.  
  27007. [igfxtray]
  27008. Number=3837
  27009. Confirmed=U
  27010. Filename=igfxtray.exe
  27011. Description=Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel
  27012. Source=Paul Collins Startup list
  27013.  
  27014. [Iglpbv]
  27015. Number=3838
  27016. Confirmed=?
  27017. Filename=Iglpbv.exe
  27018. Description=<font color="#FF0000">??</font>
  27019. Source=Paul Collins Startup list
  27020.  
  27021. [igndlm.exe]
  27022. Number=3839
  27023. Confirmed=N
  27024. Filename=DLM.exe
  27025. Description=IGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin, hence Internet Explorer must be installed beforehand and downloads has to be initialized through that browser
  27026. Source=Paul Collins Startup list
  27027.  
  27028. [igsex2x]
  27029. Number=3840
  27030. Confirmed=X
  27031. Filename=igsex2x.exe
  27032. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102813-2445-99" target=_blank>NewDial</a> premium rate adult content dialler
  27033. Source=Paul Collins Startup list
  27034.  
  27035. [iHP-100]
  27036. Number=3841
  27037. Confirmed=?
  27038. Filename=iHPDetect.exe
  27039. Description=Drive Letter Searcher, <a href="http://www.redchairsoftware.com/irivium/" target=_blank>iRiver</a> iHP-100 iHP and H Series player related - <font color="#FF0000">does it need to start with Windows every time?</font>
  27040. Source=Paul Collins Startup list
  27041.  
  27042. [iilc]
  27043. Number=3842
  27044. Confirmed=X
  27045. Filename=IILC.EXE
  27046. Description=Homepage hijacker
  27047. Source=Paul Collins Startup list
  27048.  
  27049. [Iinl]
  27050. Number=3843
  27051. Confirmed=X
  27052. Filename=iptl.exe
  27053. Description=<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=ClickSpring.PuritySCAN&threatid=10115" target="_blank">PurityScan/Clickspring</a> adware
  27054. Source=Paul Collins Startup list
  27055.  
  27056. [iisvers]
  27057. Number=3844
  27058. Confirmed=X
  27059. Filename=iisvers.exe
  27060. Description=Added by an unidentified TROJAN or adware
  27061. Source=Paul Collins Startup list
  27062.  
  27063. [iIWiper]
  27064. Number=3845
  27065. Confirmed=N
  27066. Filename=Systemwiper.exe
  27067. Description=<a href="http://iisoftware.net/index.php?clean.html" target="_blank">System Wiper</a> from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
  27068. Source=Paul Collins Startup list
  27069.  
  27070. [IJ75P2PSERVER]
  27071. Number=3846
  27072. Confirmed=Y
  27073. Filename=IJ75P2PS.EXE
  27074. Description=Printer utility which is required in order to make the printer work correctly
  27075. Source=Paul Collins Startup list
  27076.  
  27077. [IKE Service 95]
  27078. Number=3847
  27079. Confirmed=Y
  27080. Filename=IKEService.exe
  27081. Description=Associated with <a href="http://www.pgpi.org/" target="_blank">PGP</a>. The PGP Tray can be
  27082. disabled, but without IKESERVICE you won't be able to de- or encrypt anything
  27083. Source=Paul Collins Startup list
  27084.  
  27085. [iKeyWorks]
  27086. Number=3848
  27087. Confirmed=U
  27088. Filename=IKEYMAIN.EXE
  27089. Description=<a href="http://www.a4tech.com/a4techenglish/index.html" target="_blank">A4Tech</a> wireless keyboard driver and utility
  27090. Source=Paul Collins Startup list
  27091.  
  27092. [iLLeGaL]
  27093. Number=3849
  27094. Confirmed=X
  27095. Filename=Mplayer.exe
  27096. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_HOLAR.C" target="_blank">HOLAR.C</a> (or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-120413-1702-99" target="_blank">GALIL</a>) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
  27097. Source=Paul Collins Startup list
  27098.  
  27099. [iLLeGaL.exe]
  27100. Number=3850
  27101. Confirmed=X
  27102. Filename=Mplayer.exe
  27103. Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_HOLAR.C" target="_blank">HOLAR.C</a> (or <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-120413-1702-99" target="_blank">GALIL</a>) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
  27104. Source=Paul Collins Startup list
  27105.  
  27106. [ILO_Office_Manager]
  27107. Number=3851
  27108. Confirmed=?
  27109. Filename=IntEdReg.exe /OFFMAN
  27110. Description=<a href="http://www.intense.co.uk/" target="_blank">Intense Educational Ltd</a> - Language Office Software. <font color="#FF0000">Is it required?</font>
  27111. Source=Paul Collins Startup list
  27112.  
  27113. [iLyric]
  27114. Number=3852
  27115. Confirmed=U
  27116. Filename=iLyric.exe
  27117. Description=<a href="http://www.ilyric.net/winamp.html" target=_blank>iLyric</a> plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
  27118.  
  27119. Source=Paul Collins Startup list
  27120.  
  27121. [iM Start Center]
  27122. Number=3853
  27123. Confirmed=N
  27124. Filename=iM_Tray.exe
  27125. Description=Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
  27126. Source=Paul Collins Startup list
  27127.  
  27128. [Image]
  27129. Number=3854
  27130. Confirmed=X
  27131. Filename=rundll32 image.dll, Install
  27132. Description=<a href="http://cwshredder.net/cwshredder/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant
  27133. Source=Paul Collins Startup list
  27134.  
  27135. [Image & Restore]
  27136. Number=3855
  27137. Confirmed=Y
  27138. Filename=IMAGE32.exe
  27139. Description=Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run
  27140. Source=Paul Collins Startup list
  27141.  
  27142. [Image Transfer]
  27143. Number=3856
  27144. Confirmed=N
  27145. Filename=SonyTray.exe
  27146. Description=Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
  27147. Source=Paul Collins Startup list
  27148.  
  27149. [ImageDrive-{hex numbers}]
  27150. Number=3857
  27151. Confirmed=U
  27152. Filename=ImageDrive.exe
  27153. Description=<a href="http://www.nero.com/en/631910958042754.html" target="_blank">Nero ImageDrive</a> from Ahead - virtual CD/DVD drive software
  27154. Source=Paul Collins Startup list
  27155.  
  27156. [Imagefox]
  27157. Number=3858
  27158. Confirmed=U
  27159. Filename=imagefox.exe
  27160. Description=ImageFox 2.0 (formerly available from <a href="http://www.acdsee.com/" target="_blank">ACDSee</a>) is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes
  27161. Source=Paul Collins Startup list
  27162.  
  27163. [Imagemgt32]
  27164. Number=3859
  27165. Confirmed=X
  27166. Filename=Imagemgt32.exe
  27167. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-121616-1945-99" target="_blank">GEMA</a> TROJAN!
  27168. Source=Paul Collins Startup list
  27169.  
  27170. [ImagePath]
  27171. Number=3860
  27172. Confirmed=X
  27173. Filename=taskbarmngr.exe
  27174. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotxb.html" target=_blank>SDBOT-XB</a> WORM!
  27175. Source=Paul Collins Startup list
  27176.  
  27177. [IMAPI]
  27178. Number=3861
  27179. Confirmed=X
  27180. Filename=load.exe
  27181. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdowndela.html" target=_blank>DOWNDEL-A</a> TROJAN!
  27182. Source=Paul Collins Startup list
  27183.  
  27184. [iMarkup Client]
  27185. Number=3862
  27186. Confirmed=N
  27187. Filename=iUtil.exe
  27188. Description=Enables the <a href="http://www.imarkup.com/products/imarkup_client.asp" target=blank>iMarkup Client</a> web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs
  27189. Source=Paul Collins Startup list
  27190.  
  27191. [Imatio]
  27192. Number=3863
  27193. Confirmed=U
  27194. Filename=imation.exe
  27195. Description=<a href="http://www.imation.com/products/flash_devices/downloads.html" target="_blank">Imation Disk Manager</a> - enables you to create a password protected area on your Imation USB flash drive
  27196. Source=Paul Collins Startup list
  27197.  
  27198. [IMClass]
  27199. Number=3864
  27200. Confirmed=X
  27201. Filename=Svhosl.exe
  27202. Description=Added by an unidentified WORM or TROJAN!
  27203. Source=Paul Collins Startup list
  27204.  
  27205. [imekrig]
  27206. Number=3865
  27207. Confirmed=N
  27208. Filename=imekrig.exe
  27209. Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
  27210. Source=Paul Collins Startup list
  27211.  
  27212. [IMEKRMIG6.1]
  27213. Number=3866
  27214. Confirmed=N
  27215. Filename=IMEKRMIG.EXE
  27216. Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
  27217. Source=Paul Collins Startup list
  27218.  
  27219. [Imesh]
  27220. Number=3867
  27221. Confirmed=N
  27222. Filename=??
  27223. Description=<a href="http://www.imesh.com" target="_blank">Imesh</a> is a file sharing system
  27224. Source=Paul Collins Startup list
  27225.  
  27226. [Imesh Auto Update]
  27227. Number=3868
  27228. Confirmed=N
  27229. Filename=??
  27230. Description=Update check for the <a href="http://www.imesh.com" target=_blank>Imesh</a> file sharing system. Turn the update off under "options"
  27231. Source=Paul Collins Startup list
  27232.  
  27233. [IMEvtMgr.exe]
  27234. Number=3869
  27235. Confirmed=X
  27236. Filename=IMEvtMgr.exe
  27237. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojkeylogar.html" target=_blank>KEYLOG-AR</a> TROJAN!
  27238. Source=Paul Collins Startup list
  27239.  
  27240. [ImgIcon]
  27241. Number=3870
  27242. Confirmed=U
  27243. Filename=ImgIcon.exe
  27244. Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
  27245. Source=Paul Collins Startup list
  27246.  
  27247. [imgit]
  27248. Number=3871
  27249. Confirmed=X
  27250. Filename=[path to file]
  27251. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankerem.html" target=_blank>BANKER-EM</a> TROJAN!
  27252. Source=Paul Collins Startup list
  27253.  
  27254. [ImgStart]
  27255. Number=3872
  27256. Confirmed=N
  27257. Filename=ImgStart.exe
  27258. Description=Used by Iomega drives. Details of its purpose can be found <a href="http://pw2.netcom.com/~deepone/zipjaz/ioware.html#startup" target="_blank">here</a>. Available via Start -> Programs
  27259. Source=Paul Collins Startup list
  27260.  
  27261. [Imjpmig*.*]
  27262. Number=3873
  27263. Confirmed=N
  27264. Filename=IMJPMIG.EXE
  27265. Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese). *.* represents the version number
  27266. Source=Paul Collins Startup list
  27267.  
  27268. [immcheck.exe]
  27269. Number=3874
  27270. Confirmed=?
  27271. Filename=immcheck.exe
  27272. Description=<font color="#FF0000">Related to I-FORCE driver for force feedback steering wheel?</font>
  27273. Source=Paul Collins Startup list
  27274.  
  27275. [ImMsn]
  27276. Number=3875
  27277. Confirmed=X
  27278. Filename=timed.exe
  27279. Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&vNav=3&VName=BKDR_WEBDOR.AK" target="_blank">WEBDOR.AK</a> TROJAN!
  27280. Source=Paul Collins Startup list
  27281.  
  27282. [IMOL]
  27283. Number=3876
  27284. Confirmed=U
  27285. Filename=IMOLApp.exe
  27286. Description=<a href="http://www.incredimail.com/" target=_blank>IncrediMail</a> for Office Outlook Add-On
  27287. Source=Paul Collins Startup list
  27288.  
  27289. [Imonitor]
  27290. Number=3877
  27291. Confirmed=N
  27292. Filename=Plguni.exe
  27293. Description=<a href="http://www.mcafee.com/myapps/qc3/default.asp" target="_blank">McAfee QuickClean 3.0</a> - removes internet clutter and unwanted programs
  27294. Source=Paul Collins Startup list
  27295.  
  27296. [imonitor]
  27297. Number=3878
  27298. Confirmed=X
  27299. Filename=[path to trojan]
  27300. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojimonia.html" target="_blank">IMONI-A</a> TROJAN!
  27301. Source=Paul Collins Startup list
  27302.  
  27303. [IMONTRAY]
  27304. Number=3879
  27305. Confirmed=U
  27306. Filename=imontray.exe
  27307. Description=System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
  27308. Source=Paul Collins Startup list
  27309.  
  27310. [IMprocess]
  27311. Number=3880
  27312. Confirmed=X
  27313. Filename=IM-svr.EXE
  27314. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-041214-2538-99" target="_blank">IMNames</a> adware
  27315. Source=Paul Collins Startup list
  27316.  
  27317. [IMStart]
  27318. Number=3881
  27319. Confirmed=U
  27320. Filename=IMStart.exe
  27321. Description=<a href="http://www.intermute.com/products/index.html" target=_blank>InterMute</a> security software related
  27322. Source=Paul Collins Startup list
  27323.  
  27324. [imwinsrvc]
  27325. Number=3882
  27326. Confirmed=X
  27327. Filename=acpmonsrv.exe
  27328. Description=Added by the <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Proxy.Win32.Slaper.e&threatid=76053" target="_blank">SLAPER.E</a> TROJAN!
  27329. Source=Paul Collins Startup list
  27330.  
  27331. [IMwire]
  27332. Number=3883
  27333. Confirmed=X
  27334. Filename=imwireup.exe
  27335. Description=<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-050804-2316-99" target=_blank>SafeSurfing</a> adware variant
  27336.  
  27337. Source=Paul Collins Startup list
  27338.  
  27339. [im_autorn]
  27340. Number=3884
  27341. Confirmed=X
  27342. Filename=im_1.exe
  27343. Description=Added by the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-012610-4055-99" target=_blank>IMAV.A</a> WORM!
  27344. Source=Paul Collins Startup list
  27345.  
  27346. [im_autorn]
  27347. Number=3885
  27348. Confirmed=X
  27349. Filename=im_2.exe
  27350. Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbagledlbo.html" target=_blank>BAGLEDL-