Spybot Search'n'Destroy process data | 2005-05-31 | 1.7 MB | 43,191 lines
Text Truncated. Only the first 1MB is shown below. Download the file for the complete contents.
[]
Confirmed=X
Filename=system32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotku.html" target=_blank>AGOBOT-KU</a> WORM! Note - has a blank entry under the Startup Item/Name field
Source=Paul Collins Startup list
[!1_pgaccount]
Confirmed=Y
Filename=pgaccount.exe
Description=DiamondCS <a href="http://www.diamondcs.com.au/processguard/" target=_blank>ProcessGuard</a> security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
Source=Paul Collins Startup list
[!1_ProcessGuard_Startup]
Confirmed=Y
Filename=procguard.exe
Description=DiamondCS <a href="http://www.diamondcs.com.au/processguard/" target=_blank>ProcessGuard</a> security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks
Source=Paul Collins Startup list
[!NoLoad]
Confirmed=N
Filename=winrecon.exe
Description=<a href="http://www.winrecon.com/" target="_blank">WinRecon</a> - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Source=Paul Collins Startup list
[$EnterNet]
Confirmed=?
Filename=Enternet.exe
Description=Connection manager for the EnterNet ISP. You can also use <a href="http://user.cs.tu-berlin.de/~normanb/" target="_blank">RASPPOE</a>
Source=Paul Collins Startup list
[$WindowsRegKey%update]
Confirmed=X
Filename=IEXPLORE.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotez.html" target="_blank">RBOT-EZ</a> WORM! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[%cmpmixtitle%]
Confirmed=N
Filename=%cmpmixstr%
Description=<font color="#FF0000">Possibly related to C-Media Mixer Control panel?</font>
Source=Paul Collins Startup list
[%FP%012-L2TP fts.exe]
Confirmed=?
Filename=fts.exe
Description=012.Net ISP software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[%FP%012-L2TP FWPortal.exe]
Confirmed=?
Filename=FWPortal.exe
Description=012.Net ISP software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[%FP%1776 Internet fts.exe]
Confirmed=?
Filename=fts.exe
Description=1776 Internet ISP software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[%FP%1776 Internet FWPortal.exe]
Confirmed=?
Filename=FWPortal.exe
Description=1776 Internet ISP software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[%FP%Barak013 fts.exe]
Confirmed=?
Filename=fts.exe
Description=Barak013 ISP software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[%FP%Barak013 FWPortal.exe]
Confirmed=?
Filename=FWPortal.exe
Description=Barak013 ISP software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[(*)API Machine]
Confirmed=X
Filename=winSOCKS.exe
Description=Homepage hijacker, see <a href="http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi?s=3e991177279cffff;act=ST;f=6;t=2598;hl=new" target="_blank">here</a> (* = any digit)
Source=Paul Collins Startup list
[(*)Run]
Confirmed=X
Filename=win32API.exe
Description=Homepage hijacker, see <a href="http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi?s=3e991177279cffff;act=ST;f=6;t=2598;hl=new" target="_blank">here</a> (* = any digit)
Source=Paul Collins Startup list
[(Default)]
Confirmed=X
Filename=media_driver.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.tupeg.html" target="_blank">TUPEG</a> VIRUS!
Source=Paul Collins Startup list
[(Default)]
Confirmed=X
Filename=Shania.vbs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.shania.html" target="_blank">SHANIA</a> TROJAN!
Source=Paul Collins Startup list
[(Default)]
Confirmed=X
Filename=NOTEPAD.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.rusty@m.html" target="_blank">RUSTY</a> WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor
Source=Paul Collins Startup list
[(default)]
Confirmed=X
Filename=[random filename].exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blackmal@mm.html" target="_blank">BLACKMAL</a> WORM!
Source=Paul Collins Startup list
[(default)]
Confirmed=X
Filename=twunk_32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blackmal.c@mm.html" target="_blank">BLACKMAL.C</a> WORM!
Source=Paul Collins Startup list
[(default)]
Confirmed=X
Filename=winhelp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blackmal.c@mm.html" target="_blank">BLACKMAL.C</a> WORM!
Source=Paul Collins Startup list
[*JanisRuckenbrodII]
Confirmed=X
Filename=janis.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.pops.html" target="_blank">POPS</a> WORM!
Source=Paul Collins Startup list
[*StateMgr]
Confirmed=Y
Filename=statemgr.exe
Description=Windows ME default for System Restore. Do NOT disable!
Source=Paul Collins Startup list
[*windows update]
Confirmed=X
Filename=wrauclt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqu.html" target=_blank>RBOT-QU</a> WORM!
Source=Paul Collins Startup list
[*windows update]
Confirmed=X
Filename=wuanclt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpg.html" target=_blank>RBOT-PG</a> WORM!
Source=Paul Collins Startup list
[*windows update]
Confirmed=X
Filename=wuaucrlt.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.spybot.hur.html" target=_blank>SPYBOT.HUR</a> WORM!
Source=Paul Collins Startup list
[*windows update]
Confirmed=X
Filename=wuraclt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpo.html" target=_blank>RBOT-PO</a> WORM!
Source=Paul Collins Startup list
[*WinLogon]
Confirmed=X
Filename=[trojan path] ren time:[random number]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.html" target=_blank>VUNDO</a> TROJAN!
Source=Paul Collins Startup list
[,main drive Loader]
Confirmed=X
Filename=wininfo.exe
Description=Suspected malware as it appears in 3 different registry locations - see <a href="http://forums.techguy.org/t151017/s.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[.mscdr]
Confirmed=X
Filename=lassa.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.c.html" target=_blank>WEBUS.C</a> TROJAN!
Source=Paul Collins Startup list
[.mscdr]
Confirmed=X
Filename=lsvchost.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.d.html" target=_blank>WEBUS.D</a> TROJAN!
Source=Paul Collins Startup list
[.NET config]
Confirmed=?
Filename=sysmon32.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[.norton]
Confirmed=X
Filename=rchost.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojboxeda.html" target=_blank>BOXED-A</a> TROJAN!
Source=Paul Collins Startup list
[.Prog]
Confirmed=X
Filename=services.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html" target="_blank">NEVEG.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[.Prog]
Confirmed=X
Filename=winlogon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[.TEXTCONV]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[.TEXTCONV]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.b.html" target="_blank">WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lsass.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[.WMAudio]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[.WMAudio]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.b.html" target="_blank">WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lsass.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[/l:eng]
Confirmed=N
Filename=N/A
Description=Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
Description=Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
Source=Paul Collins Startup list
[00THotkey]
Confirmed=U
Filename=00THotKey.exe
Description=For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.c.worm.html" target="_blank">KITRO.C</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DANDI.A&VSect=T" target="_blank">DANDI.A</a>) WORM! 123456 can be any random 3 to 6 digit number
Description=HP utility for monitoring when and how many recoveries have been done
Source=Paul Collins Startup list
[1A:MacVisionTrayMonitor]
Confirmed=N
Filename=TrayMonitor.exe
Description=Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
Source=Paul Collins Startup list
[1A:Stardock MCP]
Confirmed=Y
Filename=mcpserver.exe
Description=Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
Source=Paul Collins Startup list
[1A:Stardock TrayMonitor]
Confirmed=Y
Filename=TrayServer.exe
Description=For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
Source=Paul Collins Startup list
[1CmailS]
Confirmed=?
Filename=NETMAIL.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[1on1]
Confirmed=X
Filename=1on1.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[1Srv32]
Confirmed=U
Filename=SpyAgent4.exe
Description=SpyTech <a href="http://www.spytech-web.com/spyagent.shtml" target="_blank">SpyAgent</a> monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
Description=2020Search Toolbar related. Reported to be auto-installed
Source=Paul Collins Startup list
[2thousandbuck]
Confirmed=X
Filename=[path to file]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.l.html" target=_blank>RANKY.L</a> TROJAN!
Source=Paul Collins Startup list
[2wSysTray]
Confirmed=U
Filename=2portalmon.exe
Description=<a target="_blank" href="http://www.2wire.com/home/index.html">2Wire Homeportal</a> user interface
Source=Paul Collins Startup list
[39ELTFH25Z8SKF]
Confirmed=?
Filename=Ezg1q5.exe
Description=<font color="#FF0000">Seems to be associated with software by <a href="http://www.resplendence.com/docs/" target="_blank">Resplendence SP</a> ?</font>
Source=Paul Collins Startup list
[3c1807pd]
Confirmed=Y
Filename=3cmlink.exe 3cpipe-3c1807pd
Description=3Com WinModem driver. See <a href="http://808hi.com/56k/winmodems.asp" target="_blank">here</a> for more WinModem information
Description=For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See <a href="http://808hi.com/56k/winmodems.asp" target="_blank">here</a> for more WinModem information
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.jermy.a.html" target="_blank"> JERMY.A</a> WORM!
Source=Paul Collins Startup list
[3Deep Control Panel]
Confirmed=U
Filename=3DeepCTL.EXE
Description=From <a href="http://www.colorific.com/index.htm" target="_blank">LightSurf Technologies</a> (nee E-Color) - <a href="http://www.colorific.com/d1.htm" target="_blank">3Deep</a> corrects lighting, shading and color for all your 2D and 3D games
Source=Paul Collins Startup list
[3Dfx Acc]
Confirmed=X
Filename=GFXACC.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gibe@mm.html" target="_blank">GIBE</a> WORM!
Source=Paul Collins Startup list
[3dfx Task Manager]
Confirmed=N
Filename=3dfxMan.exe
Description=System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Source=Paul Collins Startup list
[3dfx Tools]
Confirmed=Y
Filename=3dfxCmn.dll
Description=Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
Source=Paul Collins Startup list
[3dfxv2ps.dll]
Confirmed=Y
Filename=3dfxv2ps.dll
Description=Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
Source=Paul Collins Startup list
[3Dlabs Taskbar Display Manager]
Confirmed=?
Filename=3DLman.exe
Description=3DLabs graphics driver related. <font color="#FF0000"> System Tray access to display settings?</font>
Source=Paul Collins Startup list
[3DLabsHelperDemon]
Confirmed=U
Filename=3dldemon.exe
Description=Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
Source=Paul Collins Startup list
[3qdctl.exe]
Confirmed=U
Filename=3qdctl.exe
Description=Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
Source=Paul Collins Startup list
[3ware 3DM]
Confirmed=Y
Filename=3dm.exe
Description=Monitors status of the disk array on 3ware IDE RAID controllers
Source=Paul Collins Startup list
[4wd!!!]
Confirmed=X
Filename=Natal!.pif
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.AI" target="_blank">OPASERV.AI</a> WORM!
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojpipes.html" target=_blank>PIPES</a> TROJAN!
Source=Paul Collins Startup list
[9xHtProtect]
Confirmed=X
Filename=AVprotect9x.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.m@mm.html" target="_blank">NETSKY.M</a> WORM!
Source=Paul Collins Startup list
[;Rundll]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PWSLEGMIR.E" target="_blank">PWSLEGMIR.E</a> TROJAN!
Source=Paul Collins Startup list
[@]
Confirmed=X
Filename=regedit -s ..win.dll
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/js.seeker.k.html" target="_blank">SEEKER.K</a> TROJAN!
Source=Paul Collins Startup list
[@Hoc Toolbar]
Confirmed=N
Filename=AtHoc.exe
Description=One-click activated browsing toolbar used by various web-sites. See <a href="http://siliconvalley.internet.com/news/article.php/3531_479951" target="_blank">here</a> for more info
Source=Paul Collins Startup list
[@loha]
Confirmed=N
Filename=reminder.exe
Description=Registration reminder for <a href="http://www.pcworld.com/downloads/file_description/0,fid,6581,00.asp" target="_blank">@loha@home</a> E-mail utility
Source=Paul Collins Startup list
[@tour_ww]
Confirmed=X
Filename=@tour_ww[1].exe
Description=Adult content dialler
Source=Paul Collins Startup list
[a]
Confirmed=X
Filename=a.exe
Description=Commercials file that registers itself in the system registry and redirects IE to a certain commercial website
Source=Paul Collins Startup list
[a-squared]
Confirmed=U
Filename=a2guard.exe
Description=<a href="http://www.emsisoft.com/en/" target=_blank>a-Squared</a> antitrojan - can be run on demand but necessary in Startup if you prefer the a▓ 'Background Guard' real time protection feature
Source=Paul Collins Startup list
[a-winpoet-service]
Confirmed=Y
Filename=winpppoverethernet.exe
Description=WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read <a href="http://www.finepoint.com/products/winpoet/index.html" target="_blank">here</a>. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
Source=Paul Collins Startup list
[A1000 Settings Utility]
Confirmed=U
Filename=cpqa1000.exe
Description=Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
Source=Paul Collins Startup list
[A4Proxy]
Confirmed=U
Filename=A4Proxy.exe
Description=<a href="http://www.findincontext.com/a4proxy/review.htm" target="_blank">Anonymity 4 Proxy</a> - local proxy server that makes you anonymous when visiting web sites
Source=Paul Collins Startup list
[AAACLEAN]
Confirmed=?
Filename=AAACLEAN.INF
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[AAAKeyboard]
Confirmed=?
Filename=??
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[AAATraySaver]
Confirmed=N
Filename=TraySaver.exe
Description=System Tray management utility from <a href="http://www.mlin.net/" target="_blank">Mike Lin</a> which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
Source=Paul Collins Startup list
[AAK]
Confirmed=U
Filename=aak.exe
Description=<a href="http://www.anti-keylogger.net/" target="_blank">Advanced Anti-Keylogger</a> - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"
Description=Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
Source=Paul Collins Startup list
[ABC]
Confirmed=X
Filename=keylogger.exe
Description=Monitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by <a href="http://www.spycop.com/index.html" target="_blank">SpyCop</a> in their <a href="http://www.spycop.com/faq.htm" target="_top">FAQ</a>
Source=Paul Collins Startup list
[ABIT uGuru]
Confirmed=U
Filename=uGuru.exe
Description=Provides quick access to several Abit motherboard utilities - such as monitoring cpu temperature, fan speeds, overclocking, flashing of BIOS
Source=Paul Collins Startup list
[Absolute Shield]
Confirmed=U
Filename=dseraser.exe
Description=<a href="http://www.absoluteshielderaserinternet.com/" target="_blank">Absolute Shield/Evidence Eliminator</a> - iternet history eraser
Source=Paul Collins Startup list
[Absolute StartUp monitor]
Confirmed=U
Filename=ASMon.exe
Description=<a href="http://www.fgroupsoft.com/Absolutestartup/" target="_blank">Absolute Startup</a> - startup monitor from F-Group Software
Source=Paul Collins Startup list
[ABsr]
Confirmed=X
Filename=absr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.autoupder.html" target="_blank">AUTOUPDER</a> TROJAN!
Source=Paul Collins Startup list
[absr]
Confirmed=X
Filename=mwsvm.exe
Description=SeekSeek search hijacker related - as seen <a href="http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?act=ST&f=32&t=6790&st=0&&#entry34543" target="_blank"> here</a>
Source=Paul Collins Startup list
[abtu]
Confirmed=X
Filename=mp3serch.exe
Description=Loads the executable for <a href="http://www.spywareinfo.com/lop.html" target="_blank">Lop.com</a>. mp3serch.exe is the final version
Source=Paul Collins Startup list
[abtu]
Confirmed=X
Filename=lopsearch.exe
Description=Loads the executable for <a href="http://www.spywareinfo.com/lop.html" target="_blank">Lop.com</a>. lopsearch.exe is the beta version
Source=Paul Collins Startup list
[AbyssWebServer]
Confirmed=U
Filename=abyssws.exe
Description=<a href="http://abyss.sourceforge.net/" target="_blank">Abyss</a> web server
Source=Paul Collins Startup list
[AcBtnMgr_Xxx]
Confirmed=Y
Filename=AcBtnMgr_Xxx.exe
Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
Source=Paul Collins Startup list
[acc]
Confirmed=U
Filename=acc.exe
Description=<a href="http://www.voicecallcentral.com/#advanced_call_center" target="_blank">Advanced Call Center</a> - "full-featured yet easy-to-use answering machine software for your voice modem"
Source=Paul Collins Startup list
[ACCDEFRAGINFO]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32darbyo.html" target=_blank>DARBY-O</a> WORM!
Source=Paul Collins Startup list
[Accelerate]
Confirmed=U
Filename=accelerate.exe
Description=Webroot <a href="http://www.webroot.com/wb/products/accelerate/index.php" target="_blank">Accelerate</a> - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
Source=Paul Collins Startup list
[Access Ramp Monitor]
Confirmed=N
Filename=armon32.exe
Description=Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again
Source=Paul Collins Startup list
[AccessRamp Monitor01]
Confirmed=N
Filename=ARMon32a.exe
Description=From a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
Source=Paul Collins Startup list
[AccessRampLAN01]
Confirmed=N
Filename=ARUpld32.exe
Description=Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
Source=Paul Collins Startup list
[AcctMgr]
Confirmed=U
Filename=AcctMgr.exe
Description=NortonÖ Password Manager - part of <a href="http://www.symantec.com/sabu/sysworks/basic/" target="_blank">Norton SystemWorks 2004</a> - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activitiesùall from the safety of your own PC
Source=Paul Collins Startup list
[AccuWeather.com« Desktop]
Confirmed=N
Filename=??
Description=Desktop weather from <a href="http://wwwa.accuweather.com/adcbin/public/index.asp?partner=accuweather" target="_blank">AccuWeather.com</a>
Source=Paul Collins Startup list
[Ace bows]
Confirmed=?
Filename=Ace bows.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[AceGain LiveUpdate]
Confirmed=N
Filename=LiveUpdate.exe
Description=<a href="http://gameone.acegain.com/" target="_blank">AceGain_LiveUpdate</a>. "AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences."
Source=Paul Collins Startup list
[AcerNotebookManager]
Confirmed=U
Filename=almxptray.exe
Description=System Tray access on some Acer Notebooks to give faster access to system settings
Source=Paul Collins Startup list
[AcerPowerkey]
Confirmed=U
Filename=Powerkey.exe
Description=PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
Source=Paul Collins Startup list
[Acme.PCHButton]
Confirmed=N
Filename=pchbutton.exe
Description=Used by HP Instant Support
Source=Paul Collins Startup list
[ACMonitor_Xxx]
Confirmed=Y
Filename=ACMonitor_Xxx.exe
Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
Source=Paul Collins Startup list
[acocash]
Confirmed=X
Filename=fastdown.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[acocash]
Confirmed=X
Filename=fastdown.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Acombo3dmouse]
Confirmed=U
Filename=Acombo3d.exe
Description=Mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Aconti]
Confirmed=X
Filename=aconti.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[acoustic]
Confirmed=U
Filename=acoustic.exe
Description=Control panel program for Philips <a href="http://www.consumer.philips.com/global/b2c/ce/catalog/product.jhtml;jsessionid=5ZTUCSVZIGCWUCRQNFJRX1YKGBUEWHAW?divId=0&groupId=PCSTUFF&catId=&subCatId=SOUNDCARDS&productId=PSC706_05" target="_blank"> Acoustic Edge</a> soundcard. Not required unless changed settings aren't retained
Source=Paul Collins Startup list
[acpart]
Confirmed=N
Filename=agpart11.exe
Description=Program for finding trucks on-line
Source=Paul Collins Startup list
[Acrobat Assistant]
Confirmed=U
Filename=ACROTRAY.EXE
Description=Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation
Source=Paul Collins Startup list
[Acronis Scheduler2 Service]
Confirmed=U
Filename=schedhlp.exe
Description=Part of <a href="http://www.acronis.com/products/trueimage/" target="_blank">Acronis True Image</a> - backup software. Co-operates with the "schedul2.exe" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images
Source=Paul Collins Startup list
[Acronis TrueImage Monitor]
Confirmed=N
Filename=TrueImageMonitor.exe
Description=Part of <a href="http://www.acronis.com/products/trueimage/" target="_blank">Acronis True Image</a> - backup software. Can be disabled without affecting TrueImage
Source=Paul Collins Startup list
[Action Manager 32]
Confirmed=N
Filename=am32.exe
Description=Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[ActionAgent]
Confirmed=?
Filename=actionagent.exe
Description="A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[Activation]
Confirmed=N
Filename=Activation.exe
Description=Part of Microsoft Money
Source=Paul Collins Startup list
[Activboard]
Confirmed=U
Filename=MMKeybd.exe
Description=Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys
Source=Paul Collins Startup list
[Active shield]
Confirmed=U
Filename=Activeshield.exe
Description=<a href="http://www.securitystronghold.com/" target=_blank>Active Shield</a> is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses"
Source=Paul Collins Startup list
[ActiveDesktop]
Confirmed=X
Filename=systray32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.daboom@mm.html" target="_blank">DABOOM</a> WORM!
Source=Paul Collins Startup list
[ACTIVEDS]
Confirmed=X
Filename=ACTIVEDS.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
Source=Paul Collins Startup list
[ActiveEyes]
Confirmed=N
Filename=ActiveEyes.exe
Description=<a href="http://www.tfi-technology.com/products.htm#ActiveEyes" target="_blank">ActiveEyes</a> from TFI Technology
Source=Paul Collins Startup list
[ActiveMenu]
Confirmed=U
Filename=ActiveMenu.exe
Description=<a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=company_art&artid=art20030925_A" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
Description=McAfee VirusScan On-line. See also the McAgentExe entry
Source=Paul Collins Startup list
[ActivSurf]
Confirmed=N
Filename=backweb*****.exe
Description=Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
Source=Paul Collins Startup list
[ActMaker]
Confirmed=U
Filename=ActMak25.exe
Description="<a href="http://www.789987.com/products.htm" target=_blank>ActMaker</a> mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer"
Source=Paul Collins Startup list
[ACU]
Confirmed=U
Filename=ACU.exe
Description=<a href="http://www.nus.edu.sg/winzone/atheros/" target=_blank>Atheros</a> wireless Client Utility For HP Compaq
Source=Paul Collins Startup list
[Ad Blocker]
Confirmed=U
Filename=blocker.exe
Description=<a href="http://www.cdkm.com/" target="_blank">Ad Blocker</a> - blocks popups, and also removes banners, image ads and flash ads
Source=Paul Collins Startup list
[Ad Blocker Pro]
Confirmed=U
Filename=Ad Blocker Pro.exe
Description=Ad Away popup and banner remover
Source=Paul Collins Startup list
[Ad Online Guide]
Confirmed=?
Filename=adonlineguide.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Ad-aware]
Confirmed=N
Filename=Ad-aware.exe
Description=<a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware</a> from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
Source=Paul Collins Startup list
[Ad-Muncher]
Confirmed=U
Filename=ADMUNCH.EXE
Description=<a href="http://www.admuncher.com/" target="_blank">Ad Muncher</a> removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
Source=Paul Collins Startup list
[Ad-watch]
Confirmed=U
Filename=Ad-watch.exe
Description=Part of Lavasoft <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware Plus</a> - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
Source=Paul Collins Startup list
[AD2KClient]
Confirmed=U
Filename=AD2KClient.exe
Description=Executable for <a href="http://www.iomega-activedisk.com/index.jsp" target="_blank">Active Disk</a> from Iomega disk - allows software applications to be run directly from an Iomega Zip« disk. Required if you wish the applications to launch on insertion of a disk
Source=Paul Collins Startup list
[Adaptec DirectCD]
Confirmed=N
Filename=Directcd.exe
Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
Source=Paul Collins Startup list
[AdaptecDirectCD]
Confirmed=N
Filename=Directcd.exe
Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
Source=Paul Collins Startup list
[Adaware Bootup]
Confirmed=N
Filename=ad-aware.exe
Description=<a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware</a> from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
Source=Paul Collins Startup list
[Adaware lptt01]
Confirmed=X
Filename=adaware.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Adaware" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not the valid Lavasoft Adaware
Source=Paul Collins Startup list
[Adaware ml097e]
Confirmed=X
Filename=adaware.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.f.html" target="_blank">STARTPAGE.F</a> TROJAN!
Source=Paul Collins Startup list
[AdDelete]
Confirmed=U
Filename=AdDelete.exe
Description=Banner advertisment blocker
Source=Paul Collins Startup list
[AdDestroyer]
Confirmed=X
Filename=AdDestroyer.exe
Description=Like VirtualBouncer, malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the malware it claims to remove/prevent, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code
Description=Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Source=Paul Collins Startup list
[Adiras]
Confirmed=Y
Filename=Adiras.exe
Description=ADSL USB modem related
Source=Paul Collins Startup list
[ADM Library Loader]
Confirmed=X
Filename=admlib32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJAN!
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Adobe]
Confirmed=X
Filename=sysconfig.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[adobe]
Confirmed=X
Filename=gam.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Adobe]
Confirmed=X
Filename=sysbat32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_LOWZONES.T" target=_blank>LOWZONES.T</a> TROJAN!
Source=Paul Collins Startup list
[Adobe Filter Platform]
Confirmed=X
Filename=afilterplatform.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotop.html" target=_blank>RBOT-OP</a> WORM!
Source=Paul Collins Startup list
[Adobe Gamma Loader]
Confirmed=U
Filename=Adobe Gamma Loader.exe
Description=Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
Source=Paul Collins Startup list
[Adobe Reader Speed Launch]
Confirmed=N
Filename=reader_sl.exe
Description=Speeds up the time it takes to load the <a href="http://www.adobe.com/products/acrobat/readermain.html" target=_blank>Adobe Reader</a> application. Your choice, but not required for Adobe Reader to function properly
Source=Paul Collins Startup list
[AdobeA]
Confirmed=X
Filename=adobes.exe
Description=Added by the <a href="http://vil.nai.com/vil/content/v_100373.htm" target="_blank">FLOOD.BA</a> TROJAN!
Source=Paul Collins Startup list
[AdobeFonts]
Confirmed=X
Filename=fonts.hta
Description=Browser hijacker - redirecting to Hugesearch.net
Source=Paul Collins Startup list
[AdobeVersionCue]
Confirmed=N
Filename=VersionCueTray.exe
Description="An exclusive feature of the Adobe« Creative Suite, <a href="http://www.adobe.com/products/creativesuite/versioncue.html" target=_blank>Version CueÖ</a> helps you find files fast, track multiple versions of your files, and share your files for creative collaboration"
Source=Paul Collins Startup list
[Adope File Manager]
Confirmed=X
Filename=lsasv.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[adp]
Confirmed=X
Filename=adp.exe
Description=Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc
Source=Paul Collins Startup list
[ADQuickAccess]
Confirmed=N
Filename=Adtray.exe
Description=After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
Description=<a href="http://www.giantcompany.com/antispyware/research/spyware/spyware-AdRotator.aspx" target=_blank>AdRotator</a> adware. Note - this is not the valid Client Server Runtime Subsystem <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target=_blank>csrss.exe</a> process, which provides text window support, shutdown, and hard-error handling
Source=Paul Collins Startup list
[ADService]
Confirmed=U
Filename=ADService.exe
Description=Part of Iomega's <a href="http://www.iomega-activedisk.com/index.jsp" target="_blank">Active Disk</a> - allows software applications to be run directly from an Iomega Zip« disk. Required if you wish the applications to launch on insertion of a disk
Description=System tray access to ADSL modem diagnostic tools. Available via Start -> Programs
Source=Paul Collins Startup list
[AdslTaskBar]
Confirmed=Y
Filename=rundll32.exe stmctrl.dll, TaskBar
Description=ISP software, initializes DSL modem
Source=Paul Collins Startup list
[ADSL_A2]
Confirmed=?
Filename=A2Installed
Description=Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[ADSS]
Confirmed=Y
Filename=ADSS.exe
Description=ADSS is part of <a href="http://www.johnru.com/" target="_blank">Access Denied</a> security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied
Description=<a href="http://www.adsubtract.com/" target="_blank">AdSubtract</a> blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs
Source=Paul Collins Startup list
[AdultX]
Confirmed=X
Filename=AdultX.exe
Description=Adult content dialler and hijacker
Source=Paul Collins Startup list
[Adult_Chat]
Confirmed=X
Filename=Adult_Chat.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Adult_Chat1]
Confirmed=X
Filename=Adult_Chat1.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[ADUserMon]
Confirmed=U
Filename=ADUserMon.exe
Description=Part of Iomega's <a href="http://www.iomega-activedisk.com/index.jsp" target="_blank">Active Disk</a> - allows software applications to be run directly from an Iomega Zip« disk. Required if you wish the applications to launch on insertion of a disk
Source=Paul Collins Startup list
[Advanced Internet Protocol]
Confirmed=X
Filename=cerf.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Advanced Tools Check]
Confirmed=N
Filename=ADVCHK.EXE
Description=Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
Source=Paul Collins Startup list
[Advapi]
Confirmed=X
Filename=Advapi.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_NETDEVIL.12" target="_blank">NETDEVIL.12</a> WORM!
Source=Paul Collins Startup list
[ADVCHK]
Confirmed=N
Filename=ADVCHK.EXE
Description=Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
Description=Bogus adware remover, see this <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">list</a> of Rogue/Suspect Anti-Spyware Products & Web Sites
Source=Paul Collins Startup list
[Aeiwlsta.exe]
Confirmed=?
Filename=Aeiwlsta.exe
Description=IBM High Rate Wireless LAN Adapter driver.<font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[AELaunch]
Confirmed=N
Filename=AELaunch.exe
Description=Audio Applications Launcher for the Philips <a href="http://www.consumer.philips.com/global/b2c/ce/catalog/product.jhtml;jsessionid=5ZTUCSVZIGCWUCRQNFJRX1YKGBUEWHAW?divId=0&groupId=PCSTUFF&catId=&subCatId=SOUNDCARDS&productId=PSC706_05" target="_blank"> Acoustic Edge</a> soundcard
Source=Paul Collins Startup list
[AeXSWDUsr]
Confirmed=?
Filename=AeXSWDUsr.exe
Description=<a href="http://www.altiris.com/" target="_blank">Altiris</a> Express NS Client Manager software. <font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[AEZBProc]
Confirmed=U
Filename=aptezbp.exe
Description=IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions
Source=Paul Collins Startup list
[AFAFilter]
Confirmed=U
Filename=windefault.exe
Description=<a href="http://www.afafilter.com/" target="_blank">AFAFilter</a> - internet filter software
Source=Paul Collins Startup list
[Agent]
Confirmed=N
Filename=Agent.exe
Description=<a href="http://www.cyberlink.com" target="_blank">Cyberlink Power VCR II 3.0</a> is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs
Source=Paul Collins Startup list
[Agente]
Confirmed=?
Filename=Remupd.exe
Description=Part of <a href="http://www.pandasoftware.com/products/titanium/" target="_blank">Panda Antivirus Titanium</a>. <font color="#FF0000">Is this an update reminder (guess because of the name), virus definition update reminder or something similar?</font>
Source=Paul Collins Startup list
[AgfaCLnk]
Confirmed=U
Filename=AgfaCLnk.exe
Description=For Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
Source=Paul Collins Startup list
[agp]
Confirmed=X
Filename=agp32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.sy.html" target="_blank">GAOBOT.SY</a> WORM!
Source=Paul Collins Startup list
[AGRSMMSG]
Confirmed=Y
Filename=AGRSMMSG.exe
Description=IBM AMR modem driver
Source=Paul Collins Startup list
[AGSatellite]
Confirmed=N
Filename=AGSatellite.exe
Description=Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
Source=Paul Collins Startup list
[ahfp]
Confirmed=U
Filename=ahfp.exe
Description=<a href="http://www.softbe.com/" target="_blank">Advanced Hide Folders</a> - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
Source=Paul Collins Startup list
[ahfprog]
Confirmed=U
Filename=ahfp.exe
Description=<a href="http://www.softbe.com/" target="_blank">Advanced Hide Folders</a> - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
Source=Paul Collins Startup list
[AHNSD]
Confirmed=U
Filename=AhnSD.exe
Description=<a href="http://home.ahnlab.com/english/product/01_1.html" target="_blank">AhnLab</a> V3 antivirus updater - leave enabled unless you manually update on a regular basis
Source=Paul Collins Startup list
[AHNUE]
Confirmed=?
Filename=AHNUE.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[AHQInit]
Confirmed=N
Filename=ahqinit.exe
Description=Part of <a href="#AudioHQ">AudioHQ</a> for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
Description=AOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs
Source=Paul Collins Startup list
[AIM reminder]
Confirmed=X
Filename=AIM reminder.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BUDDY.E" target="_blank">BUDDY</a> TROJAN!
Source=Paul Collins Startup list
[aimaol lptt01]
Confirmed=X
Filename=aimaol.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[aimaol ml097e]
Confirmed=X
Filename=aimaol.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[AimingClick]
Confirmed=N
Filename=AimingClick.exe
Description=<a href="http://www.aimingtech.com/aimingclick/home.htm" target="_blank">AimingClick</a> from AimingTech. Web searching tool. Available via Start -> Programs
Source=Paul Collins Startup list
[AIMster]
Confirmed=N
Filename=??
Description=Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
Source=Paul Collins Startup list
[AIMWDInstall]
Confirmed=N
Filename=AIMWDInstall.exe
Description=Version of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=company_art&artid=art20030925_A" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[Aiptek Graphics Tablet (USB)]
Confirmed=Y
Filename=atwtusb.exe
Description=USB interface for Aiptek Graphics Tablet (USB)
Source=Paul Collins Startup list
[AKEYNAME]
Confirmed=X
Filename=WinServ.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.evilbot.c.html" target="_blank">EVILBOT.C</a> TROJAN!
Description=Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop
Source=Paul Collins Startup list
[AlarmWatcher]
Confirmed=?
Filename=AlarmWatcher.exe
Description=<font color="#FF0000">Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?</font>
Source=Paul Collins Startup list
[Album Fast Start]
Confirmed=N
Filename=ABMTSR.EXE
Description=Scanner software, not required for scanner to work
Description=Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers
Description=RealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one
Source=Paul Collins Startup list
[AlcxMonitor]
Confirmed=X
Filename=Alcxmntr.exe
Description=Realtek AC97 Audio - Event Monitor. Sypware file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but is being used by Realtek to gather data about customers
Source=Paul Collins Startup list
[Alevir]
Confirmed=X
Filename=Alevir.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32opaserva.html" target="_blank">OPASERV.A</a> or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.F" target="_blank">OPASERV.F</a> or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.G" target="_blank">OPASERV.G</a> WORMS!
Source=Paul Collins Startup list
[AlevirOld]
Confirmed=X
Filename=[worm filename]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.G" target="_blank">OPASERV.G</a> WORM!
Source=Paul Collins Startup list
[Alexa]
Confirmed=N
Filename=Alexa.exe?
Description=<a href="http://download.alexa.com/alexa65/startpage.html?p=Dest_W_g_40_L1" target="_blank">Alexa Toolbar</a> "is a downloadable toolbar that helps you navigate the Internet as you surf, by instantly providing you with related information about the site you're viewing". Available via Start -> Programs
Source=Paul Collins Startup list
[ALFY Accellerator]
Confirmed=?
Filename=AlfyAC~1.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Alias SketchBook Snapshot]
Confirmed=N
Filename=ALIASS~2.EXE
Description=Screen-capture utility for Alias Sketchbook
Source=Paul Collins Startup list
[AlienAutopsy]
Confirmed=N
Filename=Test_BS.exe
Description=<a href="http://www.alienware.com/" target="_blank">Alienware</a> computer technical support software
Source=Paul Collins Startup list
[ALiSndMgr]
Confirmed=Y
Filename=ALiSndMg.exe
Description=ALi AC97 Sound driver
Source=Paul Collins Startup list
[AliUSBfix]
Confirmed=?
Filename=GREENMK.exe
Description=<font color="#FF0000">May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?</font>
Source=Paul Collins Startup list
[alkasr]
Confirmed=X
Filename=╬Σ╥φ╤.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.balkart.html" target="_blank">BALKART</a> TROJAN!
Source=Paul Collins Startup list
[All Aboard Status]
Confirmed=U
Filename=stswin.exe
Description=<a target="_blank" href="http://yippee.i4free.co.nz/html/win/internet/title6724.htm">All Aboard! Internet Connection Sharing</a> status icon
Source=Paul Collins Startup list
[All Sea screen saver]
Confirmed=X
Filename=TaskTray.exe
Description="Free screensaver", installs lots of foistware. See <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=10&t=5833&hl=&s=" target="_blank">here</a>. Get rid of it
Source=Paul Collins Startup list
[All Sea web link]
Confirmed=X
Filename=FWLink.exe
Description="Free screensaver", installs lots of foistware. See <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=10&t=5833&hl=&s=" target="_blank">here</a>. Get rid of it
Source=Paul Collins Startup list
[allSnap]
Confirmed=U
Filename=allSnap.exe
Description="<a href="http://members.rogers.com/ivanheckman/index.html" target="_blank">allSnap</a> is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"
Source=Paul Collins Startup list
[Alogserv]
Confirmed=U
Filename=Alogserv.exe
Description=From McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up
Source=Paul Collins Startup list
[Alps Electric USB Server]
Confirmed=Y
Filename=Monserv.exe
Description=Alps Electric USB Server - required according to <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;200692" target="_blank">this</a> article
Source=Paul Collins Startup list
[AlpsPoint]
Confirmed=U
Filename=Apoint.exe
Description=Touchpad software for laptop PC's. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
Source=Paul Collins Startup list
[ALServ]
Confirmed=?
Filename=ALServ.exe
Description=Altec Lansing AMS speaker related.<font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[Altnet]
Confirmed=N
Filename=points manager.exe
Description=<a href="http://www.altnet.com/faq/" target="_blank">Altnet Points Manager</a> - manages the new Kazaa Plus scheme for awarding you points if you share music files on your machine with others rather than simply getting files and not sharing their own. Start manually when required
Source=Paul Collins Startup list
[AltnetPointsManager]
Confirmed=N
Filename=points manager.exe
Description=<a href="http://www.altnet.com/faq/" target="_blank">Altnet Points Manager</a> - manages the new Kazaa Plus scheme for awarding you points if you share music files on your machine with others rather than simply getting files and not sharing their own. Start manually when required
Source=Paul Collins Startup list
[AltoMB_service]
Confirmed=U
Filename=AltoMBsrv.exe
Description=Alto Memory Booster from <a href="http://www.altosoftware.com/" target="_blank">Alto Software</a> - boost the computers performance via more intelligent and efficient memory management
Source=Paul Collins Startup list
[ALUAlert]
Confirmed=U
Filename=ALUNotify.exe
Description=Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
Source=Paul Collins Startup list
[AlwaysOnTopMaker]
Confirmed=U
Filename=AlwaysOnTopMaker.exe
Description=<a href="http://www.fadsoft.com/AlwaysOnTopMaker.htm" target="_blank">Always On Top Maker</a> - utilty to enable an application to always be displayed "on top" of others on the desktop
Source=Paul Collins Startup list
[AmazingTens]
Confirmed=X
Filename=AmazingTens.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[America Online *.* Tray Icon]
Confirmed=N
Filename=aoltray.exe
Description=Puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs
Source=Paul Collins Startup list
[AME_CSA]
Confirmed=N
Filename=rundll32 amecsa.cpl, RUN_DLL
Description=Loads ADSL modem Control Panel applet
Source=Paul Collins Startup list
[Amon]
Confirmed=Y
Filename=AMON.EXE
Description=Monitoring part of Eset's <a href="http://www.nod32.com/home/home.htm" target="_blank">NOD32</a> virus-scanner
Source=Paul Collins Startup list
[Amonitor]
Confirmed=Y
Filename=amon.exe
Description=<a href="http://www.tinysoftware.com/home/tiny2?la=EN" target="_blank">Tiny Personal Firewall</a>
Source=Paul Collins Startup list
[anbv32]
Confirmed=X
Filename=nabv32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.titog.c.worm.html" target="_blank">TITOG.C</a> WORM!
Source=Paul Collins Startup list
[ANIWZCSService]
Confirmed=?
Filename=WZCSLDR.exe
Description=D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
Source=Paul Collins Startup list
[AnnotateCheck]
Confirmed=?
Filename=AnnCheck.exe
Description=Genius Wizard Pen Tablet driver related. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[Announcements]
Confirmed=N
Filename=Annclist.exe
Description=MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
Source=Paul Collins Startup list
[Anntext]
Confirmed=N
Filename=Anntext.exe
Description=Caere Pagekeeper text annotation server
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.sinkin.html" target="_blank">SINKIN</a> TROJAN! Resets IE start page to realphx.com
Source=Paul Collins Startup list
[Antivirus]
Confirmed=X
Filename=maja.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.h@mm.html" target="_blank">NETSKY.H</a> WORM!
Source=Paul Collins Startup list
[Antivirus]
Confirmed=X
Filename=iexpl0res.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[AntiVirusProtection]
Confirmed=?
Filename=qumk.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[AntiWindowsMessenger]
Confirmed=U
Filename=AntiMsMsg.exe
Description=<a href="http://fileforum.betanews.com/detail/1069500643/1" target="_blank">Anti-Windows_Messenger</a> is a small application that prevents Windows Messenger from remaining resident in memory
Source=Paul Collins Startup list
[AnVir]
Confirmed=Y
Filename=AnVir.exe
Description=<a href="http://anvir.com/taskmanager/" target="_blank">AnVir Task Manager</a> - protects computer against viruses and manages running processes and startup files
Source=Paul Collins Startup list
[AnVir Task Manager]
Confirmed=Y
Filename=AnVir.exe
Description=<a href="http://anvir.com/taskmanager/" target="_blank">AnVir Task Manager</a> - protects computer against viruses and manages running processes and startup files
Source=Paul Collins Startup list
[anvshell]
Confirmed=U
Filename=anvshell.exe
Description=System Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
Source=Paul Collins Startup list
[anycom bluetooth]
Confirmed=?
Filename=ftflauncher.exe
Description=Associated with an Anycom bluetooth wireless card. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[AnyDVD]
Confirmed=N
Filename=AnyDVD.exe
Description="<a href="http://www.slysoft.com/en/anydvd.html" target="_blank">AnyDVD</a> is a driver, which descrambles DVD-Movies automatically in the background. This DVD appears unprotected and region code free for all applications and the Windows operating system as well"
Source=Paul Collins Startup list
[AO Tray]
Confirmed=N
Filename=AOTray.Exe
Description=System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[AOL Broadband Check-Up]
Confirmed=U
Filename=matcli.exe
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[AOL Companion]
Confirmed=N
Filename=companion.exe
Description=Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use
Source=Paul Collins Startup list
[AOL Instant Messenger]
Confirmed=?
Filename=AlM.EXE
Description=That is an L between the A and M, the start up location is wrong for AIM. <font color="#FF0000">What does this relate to?</font>
Source=Paul Collins Startup list
[AOL Messenger]
Confirmed=X
Filename=[random filename]
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[AOL Messenger]
Confirmed=X
Filename=aolmsngr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotjf.html" target=_blank>SDBOT-JF</a> WORM!
Source=Paul Collins Startup list
[AOL Spyware Protection]
Confirmed=U
Filename=AOLSP Scheduler.exe
Description=AOL's spyware protection program
Source=Paul Collins Startup list
[AolAcsDaemon1]
Confirmed=Y
Filename=Acsd.exe
Description=AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
Source=Paul Collins Startup list
[AolAcsDaemon1]
Confirmed=Y
Filename=AOLACSD.EXE
Description=AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
Source=Paul Collins Startup list
[AolCon]
Confirmed=X
Filename=config.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.taplak.html" target="_blank">TAPLAK</a> WORM!
Source=Paul Collins Startup list
[AOLDialer]
Confirmed=N
Filename=AOLDial.exe
Description=AOL ISP software dialer - can be activated through a desktop shortcut
Source=Paul Collins Startup list
[AolFix]
Confirmed=N
Filename=AolFix.exe
Description=Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL to run correctly. Not seen much any more and should only run once
Source=Paul Collins Startup list
[Aornum]
Confirmed=X
Filename=aornum.exe
Description=Installed along with <a href="http://www.iwon.com/home/prizes/pm3_overview/0,21311,,00.html?PG=home?SEC=fnstf">iWon Prize Machine</a>. Based upon their <a href="http://www.iwon.com/home/companyinfo/privacy/privacy_overview/0,11882,,00.html#1">privacy</a> statement this can be regarded as spyware
Source=Paul Collins Startup list
[AOTray]
Confirmed=N
Filename=AOTray.Exe
Description=System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[APC UPS Status]
Confirmed=Y
Filename=Display.exe
Description=<a href="http://www.apcc.com/products/family/index.cfm?id=129&web_displayed=" target="_blank">APC PowerChute Personal Edition</a> status icon
Source=Paul Collins Startup list
[APC_SERVICE]
Confirmed=U
Filename=mainserv.exe
Description=<a href="http://www.apcc.com/tools/download/software_comp.cfm?sw_sku=SDW75" target="_blank">PowerChute« Personal Edition</a> - "safe system shutdown software with sophisticated power management functions"
Source=Paul Collins Startup list
[apc_tray]
Confirmed=Y
Filename=apc_tray.exe
Description=Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
Source=Paul Collins Startup list
[API32]
Confirmed=X
Filename=api32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojircbotb.html" target=_blank>IRCBOT-B</a> TROJAN!
Source=Paul Collins Startup list
[APIMon]
Confirmed=X
Filename=apimonx.exe
Description=Added by the TIBSER.A downloader TROJAN!
Source=Paul Collins Startup list
[APIMon]
Confirmed=X
Filename=winapix.exe
Description=Added by a variant of the TIBSER.A downloader TROJAN!
Source=Paul Collins Startup list
[Apmsrv9x]
Confirmed=?
Filename=APMSRV9X.EXE
Description=Intel AnyPoint Wireless II Home Network related. <font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[Apoint]
Confirmed=U
Filename=Apoint.exe
Description=Touchpad software for laptop PC's. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
Source=Paul Collins Startup list
[App.EXEName]
Confirmed=X
Filename=[path to worm]\.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.bodiru.html" target="_blank">BODIRU</a> WORM!
Source=Paul Collins Startup list
[Appcon]
Confirmed=U
Filename=vAppCon.exe
Description=Vital Application Console - part of <a href="http://www.pos-partner.com/Product.htm" target="_blank">POS-partner 2000</a> point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established
Source=Paul Collins Startup list
[appconn]
Confirmed=X
Filename=appconn.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.cargao.html" target="_blank">CARGAO</a> WORM!
Source=Paul Collins Startup list
[AppExtender]
Confirmed=U
Filename=AppExtCB.exe
Description=Loads the <a href="http://www.confimax.com/?PHPSESSID=aefc68296846f048b5b7ae96e48d854f" target="_blank">Confimax</a> add-in for popular E-mail programs to confirm E-mails have been sent and received
Source=Paul Collins Startup list
[appis.exe]
Confirmed=X
Filename=appis.exe
Description=Added by the <a href="http://pestpatrol.com/PestInfo/t/trojandownloader_win32_agent_bc.asp" target=_blank>AGENT-BC</a> TROJAN!
Source=Paul Collins Startup list
[Application]
Confirmed=Y
Filename=mdmsetsp.exe
Description=Aztech Labs modem driver
Source=Paul Collins Startup list
[Application Explorer]
Confirmed=U
Filename=Naldesk.exe
Description=Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."
Source=Paul Collins Startup list
[AppPlus]
Confirmed=U
Filename=AppPlus.exe
Description=<a href="http://www.appplusonline.com/" target="_blank">AppPlus</a> - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)"
Source=Paul Collins Startup list
[Apvxd]
Confirmed=Y
Filename=APVXDWIN.EXE
Description=Part of <a href="http://www.pandasoftware.com/" target="_blank">Panda Anti-Virus</a>. Required to enable permanent virus protection
Source=Paul Collins Startup list
[Apvxdwin]
Confirmed=Y
Filename=APVXDWIN.EXE
Description=Part of <a href="http://www.pandasoftware.com/" target="_blank">Panda Anti-Virus</a>. Required to enable permanent virus protection
Source=Paul Collins Startup list
[Apwheel]
Confirmed=Y
Filename=Apwheel.exe
Description=Wheel support for an Alps mouse
Source=Paul Collins Startup list
[aqadcup.exe]
Confirmed=X
Filename=aqadcup.exe
Description=Added by the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/aqadcup/" target="_blank">AGENT.BG</a> WORM!
Source=Paul Collins Startup list
[ara-key]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.antinny.html" target="_blank">ANTINNY</a> WORM!
Source=Paul Collins Startup list
[ARCSolo Recovery]
Confirmed=N
Filename=N/A
Description=Backup software by Computer Associates - no longer supported
Source=Paul Collins Startup list
[ares]
Confirmed=N
Filename=ares.exe
Description=<a href="http://www.aresgalaxy.org/download.html" target="_blank">Ares</a> is "a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download"
Source=Paul Collins Startup list
[areslite]
Confirmed=N
Filename=AresLite.exe
Description=<a href="http://www.aresgalaxy.org/download.html" target="_blank">Ares</a> Lite Edition is "a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download"
Source=Paul Collins Startup list
[Aritima]
Confirmed=X
Filename=aritima.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.aritim.html" target="_blank">ARITIM</a> WORM!
Source=Paul Collins Startup list
[Artera]
Confirmed=U
Filename=arteraui.exe
Description=<a href="http://www.arteraturbo.com/" target="_blank">Artera Turbo Internet Accelerator</a> - "surf faster, boost download speed". Only required if you find it helps improve your performance
Source=Paul Collins Startup list
[asdx]
Confirmed=X
Filename=xwinrpc32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.VO" target="_blank">AGOBOT.VO</a> WORM!
Source=Paul Collins Startup list
[ASE Scheduler]
Confirmed=N
Filename=ASE Scheduler.exe
Description=Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see <a href="http://www.boston.com/business/technology/articles/2004/11/06/spyware_killer_displays_its_own_ads/" target=_blank>here</a> and <a href="http://netrn.net/spywareblog/archives/2004/11/06/aluria-confused/" target=_blank>here</a>
Source=Paul Collins Startup list
[Ashampoo PopUpBlocker]
Confirmed=U
Filename=PopUpKiller.exe
Description=Ashampoo popup blocker, part of Privacy Protector Plus - see <a href="http://www.ashampoo.com/frontend/products/php/product.php?idstring=0204&session_langid=2ñcy_id=-1" target=_blank>here</a>
Source=Paul Collins Startup list
[ASHLT]
Confirmed=X
Filename=Ashlt.exe
Description=Adware - leads back to an ad server
Source=Paul Collins Startup list
[ashMaiSv]
Confirmed=Y
Filename=ashmaisv.exe
Description=Part of <a href="http://www.alwil.com/en/default.asp" target=_blank>Avast!</a> anti-virus software - E-mail scanner
Source=Paul Collins Startup list
[AsioReg]
Confirmed=U
Filename=regsvr32.exe ctasio.dll
Description=<a href="http://www.soundblaster.com/resources/read.asp?articleid=60&cat=2" target="_blank">ASIO</a> (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
Source=Paul Collins Startup list
[asp4tray]
Confirmed=N
Filename=asp4tray.exe
Description=System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[AspireTimeMachine]
Confirmed=Y
Filename=acertmb.exe
Description=System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry
Source=Paul Collins Startup list
[assistse]
Confirmed=X
Filename=ASSISTSE.EXE
Description=CnsMin (<a href="http://www.pestpatrol.com/PestInfo/C/CnsMin.asp" target="_blank">Chinese_Keywords</a>) related
Source=Paul Collins Startup list
[AST]
Confirmed=X
Filename=AST
Description=Added by the TROJANDOWNLOADER.WIN32.VB.AH VIRUS!
Source=Paul Collins Startup list
[AST]
Confirmed=X
Filename=AST
Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453068322" target=_blank>VB.AH</a> TROJAN!
Source=Paul Collins Startup list
[ASTART]
Confirmed=U
Filename=astart.exe
Description=ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
Source=Paul Collins Startup list
[AStart]
Confirmed=X
Filename=AStart
Description=Added by the <a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453068322" target=_blank>VB.AH</a> TROJAN!
Source=Paul Collins Startup list
[asTray]
Confirmed=N
Filename=Astray.exe
Description=Voyetra Audio Station - part of Voyetra's <a href="http://www.voyetra.com/site/products/ump3/" target="_blank"> Ultimate MP3 & CD Manager</a>. MP3 and digital music jukebox/organizer
Source=Paul Collins Startup list
[Astro]
Confirmed=N
Filename=Astro.exe
Description=Checks for updates to Quicken on a system reboot
Source=Paul Collins Startup list
[ASUS Probe]
Confirmed=N
Filename=AsusProb.exe
Description=ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
Source=Paul Collins Startup list
[ASUS SmartDoctor]
Confirmed=U
Filename=VGAProbe.exe
Description=ASUS video card fan/thermal monitor
Source=Paul Collins Startup list
[ASUS TweakEnable]
Confirmed=U
Filename=astart.exe
Description=Restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
Source=Paul Collins Startup list
[ASUSKey]
Confirmed=N
Filename=V38SHELL.EXE
Description=System tray Icon for quickly changing video modes
Source=Paul Collins Startup list
[ASWDP]
Confirmed=N
Filename=ASWDP.exe
Description=<a href="http://www.stevejacksonre.com/mls_pulse_sign_up.htm" target="_blank">MLS Pulse</a> - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market
Source=Paul Collins Startup list
[ASWnk]
Confirmed=X
Filename=aswnk.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[AT-Watch]
Confirmed=U
Filename=ATWatch.exe
Description=Anti-Trojan Watch - trojan detector
Source=Paul Collins Startup list
[Athan]
Confirmed=U
Filename=Athan.exe
Description=<a href="http://www.islamasoft.co.uk/products/athan/athansoftware.html" target=_blank>Athan</a> - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world
Source=Paul Collins Startup list
[ATI CATALYST System Tray]
Confirmed=N
Filename=CLI.exe SystemTray
Description=System Tray access to ATI's CATALYSTÖ CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop
Source=Paul Collins Startup list
[ATI DeviceDetect]
Confirmed=N
Filename=ATIDtct.EXE
Description=Utility meant for future use of the ATI TV WONDERÖ USB 2.0 video driver and can be disabled
Source=Paul Collins Startup list
[ATI GART Set-up Utility]
Confirmed=N
Filename=Atigart.exe
Description=Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed
Source=Paul Collins Startup list
[ATI Launchpad]
Confirmed=U
Filename=launchpd.exe
Description=Convenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu
Source=Paul Collins Startup list
[ATI Remote Control]
Confirmed=Y
Filename=ATIRW.exe
Description=Driver for the <a href="http://www.ati.com/products/home-office.html" target=_blank>ATI REMOTE WONDERÖ</a> RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
Source=Paul Collins Startup list
[ATI Scheduler]
Confirmed=N
Filename=Atisched.exe
Description=Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
Source=Paul Collins Startup list
[ATI Task Application]
Confirmed=N
Filename=Atitkad.exe
Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
Source=Paul Collins Startup list
[ATI Task Application (Atikey)]
Confirmed=N
Filename=Atitask.exe
Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
Source=Paul Collins Startup list
[ATI VIDEO REGKEY]
Confirmed=X
Filename=ati2vid.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.UR" target="_blank">SDBOT.UR</a> WORM!
Source=Paul Collins Startup list
[Ati2cwxx]
Confirmed=?
Filename=Ati2cwxx.exe
Description=<font color="#FF0000">For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it </font>
Source=Paul Collins Startup list
[Ati2mdxx]
Confirmed=N
Filename=Ati2mdxx.exe
Description=For ATI video cards. System Tray access to display mode changing
Source=Paul Collins Startup list
[ATICCC]
Confirmed=U
Filename=cli.exe runtime
Description=ATI's CATALYSTÖ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. If not you can start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime
Source=Paul Collins Startup list
[AtiCwd]
Confirmed=U
Filename=AtiCwd.exe
Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
Source=Paul Collins Startup list
[AtiCwd]
Confirmed=U
Filename=AtiCwd32.exe
Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
Source=Paul Collins Startup list
[AtiCwd]
Confirmed=U
Filename=Ati2cwad.exe
Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
Source=Paul Collins Startup list
[AtiCwd32]
Confirmed=U
Filename=AtiCwd.exe
Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
Source=Paul Collins Startup list
[AtiCwd32]
Confirmed=U
Filename=AtiCwd32.exe
Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
Source=Paul Collins Startup list
[AtiCwd32]
Confirmed=U
Filename=Ati2cwad.exe
Description=This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
Source=Paul Collins Startup list
[AtiKey]
Confirmed=N
Filename=AtiKey32.exe
Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
Source=Paul Collins Startup list
[AtiKey]
Confirmed=?
Filename=atiptkad.exe
Description=System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
Source=Paul Collins Startup list
[ATIModeChange]
Confirmed=U
Filename=Ati2mdxx.exe
Description=System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
Source=Paul Collins Startup list
[ATIPOLAB]
Confirmed=U
Filename=ati2evxx.exe
Description=ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
Source=Paul Collins Startup list
[ATIPOLL]
Confirmed=U
Filename=ati2evxx.exe
Description=ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
Source=Paul Collins Startup list
[AtiPTA]
Confirmed=U
Filename=Ati2ptxx.exe
Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Source=Paul Collins Startup list
[AtiPTA]
Confirmed=U
Filename=Atiptaxx.exe
Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Source=Paul Collins Startup list
[AtiPTAAA]
Confirmed=U
Filename=Ati2ptxx.exe
Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Source=Paul Collins Startup list
[AtiPTAAA]
Confirmed=U
Filename=Atiptaxx.exe
Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Source=Paul Collins Startup list
[atiptaxx]
Confirmed=U
Filename=Ati2ptxx.exe
Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Source=Paul Collins Startup list
[atiptaxx]
Confirmed=U
Filename=Atiptaxx.exe
Description=Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Source=Paul Collins Startup list
[AtiQiPcl]
Confirmed=U
Filename=AtiQiPcl.exe
Description=Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
Source=Paul Collins Startup list
[ATISmart]
Confirmed=U
Filename=ati2s9ag.exe
Description=ATI's "SMARTGART", which is included with the "<a href="http://mirror.ati.com/products/pc/catalyst/index.html" target="_blank">Catalyst</a>" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings
Source=Paul Collins Startup list
[atisrc2]
Confirmed=X
Filename=windfind.exe
Description=Adult content dialler - see <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=11&t=7756&hl=&s=" target="_blank">here</a>. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM32.EXE), otherwise they return
Source=Paul Collins Startup list
[atitray]
Confirmed=U
Filename=atitray.exe
Description=ATI Tray Tools - allows quick access to ATI graphics card settings
Source=Paul Collins Startup list
[AtiTrayTools]
Confirmed=U
Filename=atitray.exe
Description=ATI Tray Tools - allows quick access to ATI graphics card settings
Source=Paul Collins Startup list
[atiupdate]
Confirmed=X
Filename=ATIUPDATE5.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS_DEBESKI.A" target="_blank">DEBESKI.A</a> TROJAN!
Source=Paul Collins Startup list
[atiupdate]
Confirmed=X
Filename=msshed32.exe
Description=Added by the DELF.EP downloader TROJAN!
Source=Paul Collins Startup list
[ativopen]
Confirmed=X
Filename=ativopen.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[ATIX10]
Confirmed=U
Filename=atix10.exe
Description=ATI <a href="http://www.ati.com/products/pc/remotewonder/" target="_blank">Remote Wonder</a> - PC wireless remote control
Source=Paul Collins Startup list
[ATM Control]
Confirmed=X
Filename=adpn.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MMS.A&VSect=T" target="_blank">MMS.A</a> WORM!
Source=Paul Collins Startup list
[ATnotes]
Confirmed=N
Filename=atnotes.exe
Description=Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
Source=Paul Collins Startup list
[Atomic.exe]
Confirmed=U
Filename=Atomic.exe
Description=<a href="http://www.worldtimeserver.com/atomic-clock/" target=_blank>Atomic Clock Sync</a> - synchronizes your computer's time with the NIST time server
Source=Paul Collins Startup list
[Atomica]
Confirmed=N
Filename=atomica.exe
Description=<a href="http://www.atomica.com/" target="_blank">Atomica</a> runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key
Source=Paul Collins Startup list
[AtomicTime]
Confirmed=U
Filename=ATOMICTIME.EXE
Description=<a href="http://schmail.com/atomictime/" target="_blank">AtomicTime</a> - utility that synchronizes your PC clock to an atomic clock
Source=Paul Collins Startup list
[Atrack]
Confirmed=U
Filename=atrack.exe
Description=New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert
Source=Paul Collins Startup list
[Atray]
Confirmed=U
Filename=Atray.exe
Description=<a href="http://www.divcomsoft.com/atray/" target="_blank">Active Tray</a> is a utility which lets you configure the system tray. You can also create your own tray icons
Source=Paul Collins Startup list
[ATTBroadbandUpdate]
Confirmed=U
Filename=SAUpdate.exe
Description=<a href="http://bb4.com/" target="_blank">Big Brother</a> from Quest Software. System and network monitor
Source=Paul Collins Startup list
[ATTRedUpdate]
Confirmed=U
Filename=AutoUpdate.exe
Description=Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
Source=Paul Collins Startup list
[AttuneClientEngine]
Confirmed=X
Filename=attune_ce.exe
Description=Spyware - part of an automated helpdesk software called Aveo Attune
Source=Paul Collins Startup list
[AttuneContentUpdater]
Confirmed=X
Filename=attune_cu.exe
Description=Spyware - part of an automated helpdesk software called Aveo Attune
Source=Paul Collins Startup list
[AttuneDiscovery]
Confirmed=X
Filename=attune_di.exe
Description=Spyware - part of an automated helpdesk software called Aveo Attune
Source=Paul Collins Startup list
[Attunel]
Confirmed=X
Filename=Attunel.exe
Description=Spyware - part of an automated helpdesk software called Aveo Attune
Source=Paul Collins Startup list
[AttuneSystray]
Confirmed=X
Filename=attune_st.exe
Description=Spyware - part of an automated helpdesk software called Aveo Attune
Source=Paul Collins Startup list
[aTuner]
Confirmed=N
Filename=atuner.exe
Description=<a href="http://www.3dcenter.de/atuner/index_e.php" target="_blank">aTuner</a> - tweak tool for GeForce based graphics cards
Source=Paul Collins Startup list
[atwtusb]
Confirmed=Y
Filename=atwtusb.exe
Description=USB interface for Aiptek Graphics Tablet (USB)
Source=Paul Collins Startup list
[AU Agent]
Confirmed=U
Filename=AUagent.exe
Description=<a href="http://www.zilab.com/Products/Au/index_2.shtml" target="_blank">Au Agent</a> from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon
Source=Paul Collins Startup list
[au.exe]
Confirmed=X
Filename=au.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.b@mm.html" target="_blank">BEAGLE.B</a> WORM!
Source=Paul Collins Startup list
[AUCBPNP]
Confirmed=Y
Filename=aucbnpn.exe
Description=Adaptec USB CardBus Safe-Eject - driver for the <a href="http://www.adaptec.com/worldwide/product/proddetail.html?sess=no&language=English+US&prodkey=AUA-1420&cat=%2fTechnology%2fUSB%2fUSB+Adapters" target="_blank">Adaptec USB 2.0 CardBus</a> which provides USB 2.0 ports for laptop users via a PCMCIA card slot
Source=Paul Collins Startup list
[Aucompat]
Confirmed=X
Filename=Aucompat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[AudCtrl]
Confirmed=?
Filename=RunDll32 AudCtrl.dll, RCMonitor
Description=<font color="#FF0000">Audio control panel?</font>
Source=Paul Collins Startup list
[Audiocntl]
Confirmed=X
Filename=audiocntl.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[AudioHQ]
Confirmed=N
Filename=Ahqtb.exe
Description=For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
Source=Paul Collins Startup list
[audioinf]
Confirmed=X
Filename=audioinf.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[Aureal A3D Interactive Audio]
Confirmed=Y
Filename=sa3dsrv.exe
Description=For Aureal based 3D soundcards. A3D sound features won't work with this disabled
Source=Paul Collins Startup list
[Aureal A3D Interactive Audio Init]
Confirmed=Y
Filename=A3dInit.exe
Description=For Aureal based 3D soundcards. A3D sound features won't work with this disabled
Source=Paul Collins Startup list
[ausvc]
Confirmed=X
Filename=ausvc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.autoupder.html" target="_blank">AUTOUPDER</a> TROJAN!
Source=Paul Collins Startup list
[authz]
Confirmed=X
Filename=authz.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[auto repair system]
Confirmed=X
Filename=qualityx.exe
Description=Added by an unidentified WORM or TROJAN - probably a <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> variant
Source=Paul Collins Startup list
[Auto T Bar]
Confirmed=N
Filename=autotbar.exe
Description=If you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled
Source=Paul Collins Startup list
[Auto updat]
Confirmed=X
Filename=crsrs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotak.html" target="_blank">FORBOT-AK</a> WORM!
Source=Paul Collins Startup list
[Auto Updat]
Confirmed=X
Filename=WindowsSys32.exe
Description=Added by a variant of the <a href="http://sophos.com.au/virusinfo/analyses/w32forbotgen.html" target=_blank>FORBOT</a> WORM!
Source=Paul Collins Startup list
[Auto Update]
Confirmed=X
Filename=AUP.exe
Description=Added by an unididentified WORM or TROJAN!
Source=Paul Collins Startup list
[Autobar]
Confirmed=U
Filename=autobar.exe
Description=Connect buttons on the keyboard for internet direct access, etc. on HP computers
Source=Paul Collins Startup list
[AutoEA]
Confirmed=N
Filename=Ahqrun.exe
Description=For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
Description=Task scheduler for <a href="http://www.unisyn.com/" target="_blank">Unisyn Automate 4</a> task automation/macro running software. Available via a desktop shortcut or Start -> Programs
Source=Paul Collins Startup list
[Automatic Microsoft Windows Updater]
Confirmed=X
Filename=suchost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rboteq.html" target=_blank>RBOT-EQ</a> WORM!
Source=Paul Collins Startup list
[Automatic Windows Updater]
Confirmed=X
Filename=Update.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Automatically launches the United Devices Agent when you start your computer]
Confirmed=N
Filename=UD.EXE
Description=The <a href="http://members.ud.com/download/gold/" target="_blank">United Devices Agent</a> can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
Source=Paul Collins Startup list
[AUTOPROP]
Confirmed=N
Filename=REGPROP.EXE WMPADDIN.DLL
Description=Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension
Source=Paul Collins Startup list
[AutoShutdown]
Confirmed=?
Filename=pssvc.exe
Description=<font color="#FF0000">Utility to fix vCard Export in MS Outlook 2000 - although why are these together?</font>
Source=Paul Collins Startup list
[AutoSizer]
Confirmed=U
Filename=AUTOSIZER.EXE
Description=<a href="http://www.southbaypc.com/AutoSizer/" target="_blank">AutoSizer</a> - utility that automatically maximizes windows when they're opened
Description=If you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled
Source=Paul Collins Startup list
[AutoTKit]
Confirmed=N
Filename=AUTOTKIT.EXE
Description=On HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled
Source=Paul Collins Startup list
[autoupd]
Confirmed=N
Filename=autoupd.exe
Description=<a href="http://www.raxco.com/support/windows/kb_details.cfm?kbid=46" target="_blank">Raxco Software Auto Update</a> utility."Used to keep your software up-to-date"
Source=Paul Collins Startup list
[autoupd]
Confirmed=X
Filename=autoupd.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name
Description=Part of <a href="http://www.alwil.com/en/default.asp" target=_blank>Avast!</a> anti-virus software
Source=Paul Collins Startup list
[Avast32]
Confirmed=Y
Filename=Astart32.exe
Description=Part of <a href="http://www.alwil.com/en/default.asp" target=_blank>Avast!</a> anti-virus software
Source=Paul Collins Startup list
[avc]
Confirmed=X
Filename=avmon.exe
Description=Added by an unidentified TROJAN!
Source=Paul Collins Startup list
[AvconsoleEXE]
Confirmed=U
Filename=Avconsol.exe
Description=From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
Source=Paul Collins Startup list
[AveoAttune]
Confirmed=X
Filename=atmdlusr.exe
Description=Spyware - part of an automated helpdesk software
Source=Paul Collins Startup list
[AVG Grisoft Updater]
Confirmed=X
Filename=updater.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotot.html" target=_blank>AGOBOT-OT</a> WORM!
Source=Paul Collins Startup list
[AVG7_AMSVR]
Confirmed=Y
Filename=Avgamsvr.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> antivirus related
Source=Paul Collins Startup list
[AVG7_CC]
Confirmed=Y
Filename=AVGCC.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
Source=Paul Collins Startup list
[AVG7_EMC]
Confirmed=Y
Filename=AVGEMC.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
Source=Paul Collins Startup list
[AVG7_Run]
Confirmed=Y
Filename=avgw.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 related
Source=Paul Collins Startup list
[avgamsvr.exe]
Confirmed=Y
Filename=Avgamsvr.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> antivirus related
Source=Paul Collins Startup list
[avgcc32]
Confirmed=Y
Filename=avgcc32.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
Source=Paul Collins Startup list
[AVGCtrl]
Confirmed=Y
Filename=AVGCTRL.EXE
Description=Background task of the <a target="_blank" href="http://www.hbedv.com/">AntiVir</a> antivirus program which scans files transparently in the background
Source=Paul Collins Startup list
[avgmsvr.exe]
Confirmed=Y
Filename=avgmsvr.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 related
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
Source=Paul Collins Startup list
[AVG_EMC]
Confirmed=Y
Filename=AVGEMC.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
Source=Paul Collins Startup list
[AVG_RegCleaner]
Confirmed=Y
Filename=AVGREGCL.exe
Description=<a href="http://www.grisoft.com/" target=_blank>AVG</a> Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems
Source=Paul Collins Startup list
[Avimgt]
Confirmed=X
Filename=Avimgt.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Avimgt32]
Confirmed=X
Filename=Avimgt32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[AvMaiSrv]
Confirmed=Y
Filename=Avmaisrv.exe
Description=Part of <a href="http://www.alwil.com/en/default.asp" target=_blank>Avast!</a> anti-virus software - E-mail scanner
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.mydoom.af@mm.html" target=_blank>MYDOOM.AF</a> WORM!
Source=Paul Collins Startup list
[Avril Lavigne - Muse]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32avrila.html" target="_blank">AVRIL-A</a> WORM!
Source=Paul Collins Startup list
[AVSCHED32]
Confirmed=Y
Filename=AVSched32.exe
Description=<a href="http://www.hbedv.com/" target="_blank">AntiVir</a> anti-virus from H+BDEV
Source=Paul Collins Startup list
[avserve.exe]
Confirmed=X
Filename=avserve.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html" target="_blank">SASSER</a> WORM!
Source=Paul Collins Startup list
[avserve2.exe]
Confirmed=X
Filename=avserve2.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html" target="_blank">SASSER.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.c.worm.html" target="_blank">SASSER.C</a> WORMS!
Source=Paul Collins Startup list
[avserve3.exe]
Confirmed=X
Filename=avserve3.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.g.html" target="_blank">SASSER.G</a> WORM!
Description=PRISM Status Tray Applet - <font color="#FF0000">but what is it for and is it required?</font>
Source=Paul Collins Startup list
[AVWUpd32]
Confirmed=U
Filename=AVWUPD32.EXE
Description=<a href="http://www.hbedv.com/" target="_blank">AntiVir</a> updater. Useful, but can be run manually
Source=Paul Collins Startup list
[avx communicator]
Confirmed=Y
Filename=xcommsur.exe
Description=Anti-virus part of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
Source=Paul Collins Startup list
[Avxlive]
Confirmed=Y
Filename=avxlive.exe
Description=<a href="http://www.bullguard.com/" target="_blank">Bullguard</a> or <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> antivirus
Source=Paul Collins Startup list
[avxlni]
Confirmed=Y
Filename=avxinit.exe
Description=Anti-virus part of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
Source=Paul Collins Startup list
[Avxnews]
Confirmed=?
Filename=??
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Awatch]
Confirmed=X
Filename=Awatch.exe
Description=<a href="http://www.avm.de/de/Service/AVM_Service_Portale/FRITZCard_DSL/index.php3" target=_blank>Fritz!_DSL</a> ISP software related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[awhost32]
Confirmed=N
Filename=awhost32.exe
Description=Part of Symantec's <a href="http://enterprisesecurity.symantec.com/products/products.cfm?productID=2">pcAnywhere</a> remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended
Source=Paul Collins Startup list
[AWMON]
Confirmed=U
Filename=Ad-Watch.exe
Description=Part of Lavasoft <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware Plus</a> - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
Source=Paul Collins Startup list
[AxFilter]
Confirmed=?
Filename=Rundll32 AXFILTER.DLL, Rundll32
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[a_vpd]
Confirmed=?
Filename=vpd.exe
Description=Located in the IBMTOOLS\VPD sub-directory. <font color="#FF0000">What does it do and is it required?"
Source=Paul Collins Startup list
[a▓]
Confirmed=U
Filename=a2guard.exe
Description=<a href="http://www.emsisoft.com/en/" target=_blank>a-Squared</a> antitrojan - can be run on demand but necessary in Startup if you prefer the a▓ 'Background Guard' real time protection feature
Source=Paul Collins Startup list
[B'sCLiP]
Confirmed=N
Filename=BSCLIP.exe
Description=CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
Source=Paul Collins Startup list
[B.Reader]
Confirmed=N
Filename=remin.exe
Description=<a href="http://www.harshal.da.ru/" target="_blank">Birthday Reminder 5.0</a> - as the name implies
Source=Paul Collins Startup list
[b3d]
Confirmed=X
Filename=BDEsecureinstall.exe
Description=<a href="http://www.kazaa.com/en/privacy/bundles.htm" target="_blank">B3d Projector</a> foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\\Windows\\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
Source=Paul Collins Startup list
[b3dUpdate]
Confirmed=X
Filename=Zupdate.exe
Description=<a href="http://www.kazaa.com/en/privacy/bundles.htm" target="_blank">B3d Projector</a> foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\\Windows\\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
Source=Paul Collins Startup list
[b9]
Confirmed=U
Filename=B9.exe
Description=<a href="http://www.firetrust.com/products/benign/?PHPSESSID=b60bb4b6eb22115639c465d6f606b788" target="_blank">FireTrust Benign</a> - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"
Description=<a href="http://www.commonname.com/english/ug/toolbar/default.asp?idx=1" target="_blank">CommonName Toolbar</a> spyware. To uninstall see <a href="http://www.commonname.com/english/ug/toolbar/default.asp?idx=10#4">here</a>
Source=Paul Collins Startup list
[Babylon Translator]
Confirmed=N
Filename=Babylon.exe
Description="<a href="http://www.babylon.com/" target="_blank">Babylon-Pro</a> is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
Source=Paul Collins Startup list
[BackgroundSwitcher]
Confirmed=U
Filename=bgswitch.exe
Description=Background Switcher Powertoy. Included with the last beta version of the XP Powertoys. Whenever a user right clicked his desktop and chose properties he could see a new tab which allowed him to enable a "Desktop Slide Show." This would automatically change the Windows Desktop at an interval specified by the user. Available <a href="http://shellcity.net/content4.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[Backpack UDF]
Confirmed=N
Filename=bpudfmon.exe
Description=<a href="http://www.nero.com/" target="_blank">Backpack UDF</a> packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk
Source=Paul Collins Startup list
[BackupExecScheduler]
Confirmed=U
Filename=besch.exe
Description=Veritas "Back Up My PC" software
Source=Paul Collins Startup list
[BackupNotify]
Confirmed=?
Filename=backupnotify.exe
Description=HP Digital Imaging related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[BackWeb]
Confirmed=N
Filename=backweb.exe
Description=Automatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
Description=Known as "PowerKey" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray
Source=Paul Collins Startup list
[BacsTray]
Confirmed=N
Filename=BacsTray.exe
Description=Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
Source=Paul Collins Startup list
[BADDATE]
Confirmed=X
Filename=BADDATE.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[BagleAV]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.ab@mm.html" target="_blank">NETSKY.AB</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Bakra]
Confirmed=X
Filename=IEHost.EXE
Description=IEDriver adware variant
Source=Paul Collins Startup list
[Band-Aid]
Confirmed=X
Filename=[path to file]
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.ranky.o.html" target=_blank>RANKY.O</a> TROJAN!
Description=<font color="#FF0000">Related to <a href="http://www.peoplepc.com/" target="_blank"> PeoplePC ISP</a>. May be a dialler for dial-up accounts?</font>
Source=Paul Collins Startup list
[bascstray]
Confirmed=N
Filename=BascsTray.exe
Description=Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
Source=Paul Collins Startup list
[Bat]
Confirmed=X
Filename=secure2.bat
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.zcrew.c.html" target="_blank">ZCREW.C</a> TROJAN!
Source=Paul Collins Startup list
[Batchreg1]
Confirmed=N
Filename=N/A
Description=Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See <a href="http://www.vanwijk.com/-=%20Bookz%20=-/Special%20Edition%20Using%20Windows%2098/ch10/ch10.htm#Heading24" target="_blank">here</a>
Source=Paul Collins Startup list
[BatInfEx]
Confirmed=U
Filename=rundll32.exe
Description=Displays battery status information on an IBM Thinkpad
Source=Paul Collins Startup list
[Battery Scope]
Confirmed=U
Filename=batmgr.exe
Description=Monitors battery levels on a notebook/laptop PC
Source=Paul Collins Startup list
[BatteryBar]
Confirmed=U
Filename=batterybar.exe
Description=<a href="http://www.nistech.com/BatteryBar/Default.htm" target="_blank">BatteryBar</a> - displays battery usage, and the current percentage of battery power left
Source=Paul Collins Startup list
[BatzBack]
Confirmed=X
Filename=BatzBack.scr
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.backzat.worm.html" target="_blank">BACKZAT</a> WORM!
Source=Paul Collins Startup list
[BAUSB]
Confirmed=U
Filename=BAUSB.exe
Description=Boston Acoustics Audio, USB driver
Source=Paul Collins Startup list
[bawindo]
Confirmed=X
Filename=bawindo.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ar@mm.html" target="_blank">BEAGLE.AR</a> or <a href="http://www.symantec.com/avcenter/venc/data/w32.beagle.au@mm.html" target=_blank>BEAGLE.AU</a> WORMS!
Source=Paul Collins Startup list
[BayMgr]
Confirmed=U
Filename=DockApp.exe
Description=Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices
Source=Paul Collins Startup list
[Bayswap]
Confirmed=U
Filename=bayswap.exe
Description=Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
Source=Paul Collins Startup list
[Bayswap2]
Confirmed=U
Filename=TbUpdate.exe
Description=Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
Source=Paul Collins Startup list
[BBDial]
Confirmed=?
Filename=BT Broadband.exe
Description=<font color="#FF0000">Part of BT Broandband - is it required?</font>
Source=Paul Collins Startup list
[bbSysTray]
Confirmed=N
Filename=bbSysTray.exe
Description=Philips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"
Source=Paul Collins Startup list
[bbui]
Confirmed=U
Filename=bbui.exe
Description=AOL DSL status monitor displaying a red/green icon indicating if you have a connection
Description=Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
Source=Paul Collins Startup list
[BCMDMMSG]
Confirmed=Y
Filename=bcmdmmsg.exe
Description=BCM voicemodem driver. Required for dial-up if you have one of these modems
Source=Paul Collins Startup list
[BCMHal]
Confirmed=U
Filename=rundll32.exe bcmhal9x.dll, bcinit
Description=BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
Source=Paul Collins Startup list
[BCMSMMSG]
Confirmed=Y
Filename=BCMSMMSG.exe
Description=BCM voicemodem driver. Required for dial-up if you have one of these modems
Description=<a href="http://www.weatherbug.com/aws/index.asp" target="_blank">AWS Weatherbug</a> related. <font color="#FF0000">What does it do?</font>
Description=BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
Source=Paul Collins Startup list
[Bcvsrv32]
Confirmed=N
Filename=bcvsrv32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.bqj.html" target=_blank>GAOBOT.BQJ</a> WORM!
Source=Paul Collins Startup list
[BCWipeTM]
Confirmed=N
Filename=bcwipetm.exe
Description=<a href="http://www.jetico.com/" target="_blank">BCWipe</a> Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed
Description=<a href="http://www.bitdefender.com/bd/site/products.php?p_id=25" target="_blank">Bitdefender</a> 8 antivirus and firewall
Source=Paul Collins Startup list
[BDSwitchAgent]
Confirmed=Y
Filename=bdswitch.exe
Description=<a href="http://www.bitdefender.com/bd/site/products.php?p_id=25" target="_blank">Bitdefender</a> 8 antivirus and firewall
Source=Paul Collins Startup list
[BearShare]
Confirmed=N
Filename=bearshare.exe
Description=<a href="http://www.bearshare.com/" target="_blank">BearShare</a> file sharing client. Versions known to include spyware - see <a href="http://www.cexx.org/adware.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[BEEI]
Confirmed=?
Filename=beei.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[BEHL]
Confirmed=?
Filename=BEHL.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[BEHLO]
Confirmed=?
Filename=BEHLO.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Belkin PCMCIA WLAN Monitor]
Confirmed=N
Filename=monitorbk.exe
Description=Belkin USB Network Adapter Management utility - can be started manually
Source=Paul Collins Startup list
[BelNotify]
Confirmed=U
Filename=[path] NPBelv32.dll, RunDll32_BelNotify
Description="<a href="http://www.belarc.com/BelTech.html" target=_blank>BelTech</a> enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service"
Source=Paul Collins Startup list
[BELORVBI]
Confirmed=?
Filename=BELORVBI.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Belsta.exe]
Confirmed=?
Filename=Belsta.exe
Description=Configuration tool for Belkin wireless network cards. Required to change the cardÆs configuration.<font color="#FF0000"> Is it required for correct operation once the confuiguration is changed?</font>
Description=Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
Source=Paul Collins Startup list
[BestPopUpKiller]
Confirmed=N
Filename=BestPopupKiller.exe
Description=Popup killer of dubious repute by SwankSoft.com. For more info about the company, do a search for 'SwankSoft' on <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm" target="_blank">this</a> web page on "Rogue/Suspect Anti-Spyware Products & Web Sites"
Source=Paul Collins Startup list
[bg]
Confirmed=Y
Filename=bullguard.exe
Description=<a href="http://www.bullguard.com/" target="_blank">Bullguard</a> antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster
Source=Paul Collins Startup list
[BGInfo]
Confirmed=U
Filename=Bginfo.exe
Description=<a href="http://www.sysinternals.com/ntw2k/freeware/bginfo.shtml" target="_blank">BGinfo</a> automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more
Description=Printer driver to generate PDF files from any program
Source=Paul Collins Startup list
[BHOCop]
Confirmed=N
Filename=BHOCop.exe
Description=ZDNet's <a href="http://www.zdnet.com/products/stories/reviews/0,4161,2760348-9,00.html" target="_blank">BHO Cop</a> that lets you see what browser helper objects are installed. Useful for detecting spyware
Source=Paul Collins Startup list
[BHODemon 2.0]
Confirmed=U
Filename=BHODemon.exe
Description=BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!". If you prefer forgoing resident protection, the application can also be run on demand
Description=<a href="http://www.bigfix.com/website/index.html" target="_blank">BigFix</a> can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet« Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog
Source=Paul Collins Startup list
[BigPond Toolbar]
Confirmed=U
Filename=bpumTray.exe
Description=<a href="http://www.bigpond.com/helpcentre/toolbar/" target="_blank">Telstra BigPond Toolbar</a> - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"
Source=Paul Collins Startup list
[BigPondCable]
Confirmed=N
Filename=bpcable.exe
Description=Telstra Bigpond Cable login software - can be started manually
Source=Paul Collins Startup list
[Billminder]
Confirmed=N
Filename=Billmind.exe
Description=Can be setup in Quicken to remind user of due payments. Available via Start -> Programs
Description=<a href="http://www.bitdefender.com/html/bd_msn_messenger.php" target="_blank">Bitdefender</a> anti-virus for MSN Messenger. Unless you have MSN Messenger running all the time start it manually
Source=Paul Collins Startup list
[BitDefender for Yahoo! Messenger]
Confirmed=U
Filename=yahmon.exe
Description=<a href="http://www.bitdefender.com/bd/site/products.php?p_id=18" target="_blank">BitDefender Antivirus for Yahoo! Messenger</a> - free AV add-on for Yahoo! Messenger
Description=Main program of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
Source=Paul Collins Startup list
[BitDefender_P2P_Startup]
Confirmed=U
Filename=BitDefender_P2P_Startup.exe
Description=<a href="http://www.bitdefender.com/html/bd_msn_messenger.php" target="_blank">Bitdefender</a> anti-virus for file transfers via internet messaging clients such as ICQ and MSN Messenger. Unless you have these running all the time start it manually
Description=Canon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
Source=Paul Collins Startup list
[bjcfd]
Confirmed=N
Filename=cdf.exe
Description=<a href="http://www.broadjump.com/" target="_blank">BroadJump</a> Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
Source=Paul Collins Startup list
[BlackICE PC Protection]
Confirmed=N
Filename=blackice.exe
Description=Loads the user interface for the <a href="http://blackice.iss.net/product_pc_protection.php" target="_blank">BlackICE PC Protection</a> (was Defender) firewall program. From the <a href="http://www.networkice.com/" target="_blank">parent site</a> - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD
Source=Paul Collins Startup list
[BlackIce Utility]
Confirmed=N
Filename=blackice.exe
Description=Loads the user interface for the <a href="http://blackice.iss.net/product_pc_protection.php" target="_blank">BlackICE PC Protection</a> (was Defender) firewall program. From the <a href="http://www.networkice.com/" target="_blank">parent site</a> - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD
Source=Paul Collins Startup list
[blads]
Confirmed=U
Filename=blads.exe
Description=A <a href="http://www.totalidea.com/frameset-tweakxp.htm" target=_blank>Tweak-XP</a> component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
Source=Paul Collins Startup list
[blah service]
Confirmed=X
Filename=winupdate.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.bia.html" target="_blank">GAOBOT.BIA</a> WORM!
Source=Paul Collins Startup list
[blah service]
Confirmed=X
Filename=winsysengine.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotki.html" target="_blank">RBOT-KI</a> WORM!
Source=Paul Collins Startup list
[blah service]
Confirmed=X
Filename=internet.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[blah service]
Confirmed=X
Filename=smnp.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.IZ" target=_blank>RBOT.IZ</a> WORM!
Source=Paul Collins Startup list
[blah service]
Confirmed=X
Filename=msnmsgrr.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.PZ&VSect=T" target=_blank>RBOT.PZ</a> WORM!
Source=Paul Collins Startup list
[blah service]
Confirmed=X
Filename=tazkmgr.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.UA" target=_blank>RBOT.UA</a> WORM!
Source=Paul Collins Startup list
[BlazeChanger]
Confirmed=N
Filename=FBZPaper.exe
Description=<a href="http://www.firehand.com/Ember/" target="_blank">Ember</a> graphic file viewer, manager, and touch-up system
Source=Paul Collins Startup list
[bldbubg]
Confirmed=?
Filename=bldbubg.exe
Description=<font color="#FF0000">Found on a Dell machine??</font>
Description=A <a href="http://www.totalidea.com/frameset-tweakxp.htm" target=_blank>Tweak-XP</a> component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
Source=Paul Collins Startup list
[BlockTracker]
Confirmed=N
Filename=BlockTracker.exe
Description=If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
Source=Paul Collins Startup list
[blss]
Confirmed=X
Filename=blss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.blarul.html" target=_blank>BLARUL</a> TROJAN!
Source=Paul Collins Startup list
[BLSTAPP]
Confirmed=N
Filename=blstapp.exe
Description=Puts access to Creative's BlasterControl in the System Tray
Description=Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click <a href="http://www.winbookcorp.com/_technote/WBTA20000912.htm" target=_blank>here</a> here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
Description=Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click <a href="http://www.winbookcorp.com/_technote/WBTA20000912.htm" target=_blank>here</a> for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig
Source=Paul Collins Startup list
[Blueyonder Instant Support Tool]
Confirmed=U
Filename=matcli.exe
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[BMail Installation]
Confirmed=N
Filename=FTP_back.exe
Description=Part of <a href="http://www.imesh.com" target="_blank">iMesh</a> - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not
Source=Paul Collins Startup list
[BMMGAG]
Confirmed=U
Filename=Rundll32 PWRMONIT.DLL, StartPwrMonitor
Description=Displays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window
Source=Paul Collins Startup list
[BMMLREF]
Confirmed=U
Filename=BMMLREF.EXE
Description=Battery Manager for IBM ThinkPad laptops
Description=IBM Thinkpad related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[BMO MasterCard Wallet]
Confirmed=U
Filename=EWALLET.EXE
Description=The wallet conveniently stores billing, shipping and payment information on your PC
Source=Paul Collins Startup list
[BMupdate]
Confirmed=N
Filename=BMupdate.exe
Description=Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install
Description=Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
Source=Paul Collins Startup list
[Bonzi Buddy]
Confirmed=X
Filename=??
Description=Spyware - read <a href="http://www.safersite.com/pestinfo/B/BonziBuddy_Adware.asp" target="_blank">here</a> for information and <a href="http://www.pchell.com/support/bonzibuddy.shtml" target="_blank">here</a> for removal instructions
Source=Paul Collins Startup list
[BookedSpace]
Confirmed=X
Filename=bs2.dll,DllRun
Description=Adware, related to the <a href="http://www.doxdesk.com/parasite/Remanent.html" target="_blank"> Remanent</a> parasite
Source=Paul Collins Startup list
[BookmarkCentral]
Confirmed=N
Filename=BMLauncher.exe
Description=<a href="http://www.bookmarkexpress.com/" target="_blank">Bookmark Express</a> - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use"
Source=Paul Collins Startup list
[BookMarkSink]
Confirmed=N
Filename=syncit.exe
Description=Bookmark synchronization utility
Source=Paul Collins Startup list
[BookMarkSync]
Confirmed=N
Filename=syncit.exe
Description=Bookmark synchronization utility
Source=Paul Collins Startup list
[BookMarkSync2It]
Confirmed=N
Filename=sync2it.exe
Description=<a href="http://www.sync2it.com/" target=_blank>Sync2IT BookMarkSync</a> - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser"
Source=Paul Collins Startup list
[Boost XP Service]
Confirmed=U
Filename=bxservice.exe
Description=<a href="http://www.systweak.com/boostxp/boostxp.htm" target="_blank">Boost XP</a> from Systweak - WinXP tweaking utility
Source=Paul Collins Startup list
[boot]
Confirmed=X
Filename=boot.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.elem.trojan.html" target="_blank">ELEM</a> TROJAN!
Source=Paul Collins Startup list
[Boot Manager]
Confirmed=X
Filename=Njgal.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.kilo.html" target="_blank">KILO</a> TROJAN!
Source=Paul Collins Startup list
[BootLoader]
Confirmed=X
Filename=BootLoader.exe.vbs
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/vbs.waterworks.worm.html" target="_blank">WATERWORKS</a> WORM!
Source=Paul Collins Startup list
[BootStatus]
Confirmed=U
Filename=BOOTST~1.EXE
Description=Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it, it has no more effect on resources
Source=Paul Collins Startup list
[BootWarn]
Confirmed=U
Filename=BootWarn.exe
Description=From <a href="http://www.answersthatwork.com/Tasklist_pages/tasklist_b.htm" target=_blank>here</a>: "Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from ôStart \ Programs \ Norton AntiVirusö. If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab û it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages"
Source=Paul Collins Startup list
[Bose Wave/PC Monitor]
Confirmed=N
Filename=wavepcmonitor.exe
Description=System Tray access for this system (more info on the system <a href="http://www.bose.com/home_audio/interactive_systems/wave_pc/index.shtml" target="_blank">here</a>). Available via Start -> Programs
Source=Paul Collins Startup list
[Boston]
Confirmed=?
Filename=Boston.exe
Description=Part of the Boston Acoustics USB speaker systems. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[Bouncer RunStartup]
Confirmed=X
Filename=bouncer.exe
Description=<a href="http://www.pestpatrol.com/PestInfo/v/virtualbouncer_2_0.asp" target=_blank>VIrtualBouncer</a> malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs
Source=Paul Collins Startup list
[Bouncer RunStartup]
Confirmed=X
Filename=LiveUpdate.exe
Description=<a href="http://www.pestpatrol.com/PestInfo/v/virtualbouncer_2_0.asp" target=_blank>VIrtualBouncer</a> malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs
Source=Paul Collins Startup list
[bpcpost.exe]
Confirmed=U
Filename=bpcpost.exe
Description=MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
Source=Paul Collins Startup list
[BPK]
Confirmed=U
Filename=bpk.exe
Description=Blazing Tools <a href="http://www.blazingtools.com/bpk.html" target="_blank"> Perfect Keylogger</a> (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
Description=System Tray access to <a href="http://www.burnquick.com/" target="_blank"> BurnQuick</a> CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
Source=Paul Collins Startup list
[Brasil]
Confirmed=X
Filename=Brasil.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.E" target="_blank">OPASERV.E</a> WORM!
Source=Paul Collins Startup list
[Brasil]
Confirmed=X
Filename=BRASIL.PIF
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.E" target="_blank">OPASERV.E</a> WORM!
Source=Paul Collins Startup list
[BrasilOld]
Confirmed=X
Filename=[worm filename]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.P" target="_blank">OPASERV.P</a> WORM!
Source=Paul Collins Startup list
[Break_Reminder]
Confirmed=U
Filename=BREAK REMINDER.exe
Description=Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See <a href="http://www.cheqsoft.com/break.html" target="_blank">here</a>
Description=Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from <a href="http://www.brindys.com/" target="_blank">Brindys Software</a>). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired
Source=Paul Collins Startup list
[Broadband Wizard]
Confirmed=N
Filename=bbwiz.exe
Description=Starts <a href="http://www.broadbandwizard.net/" target="_blank">Broadband Wizard</a> so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs
Source=Paul Collins Startup list
[BrowseProxy]
Confirmed=N
Filename=FindService.exe
Description=<a href="http://actualnames.com/index.php?cont=products" target="_blank">Actual Names</a> - "It is now possible to enter a particular word or keyword phrase that is associated with your business, and immediately be directed to YOUR WEBSITE! The Actual Names technology can do this for you"
Description=<a href="http://www.wilderssecurity.com/bhblaster.html" target="_blank">Browser Hijack Blaster</a> - protects your system from browser hijackers and spyware that alters your IE settings
Source=Paul Collins Startup list
[Browser Launcher]
Confirmed=U
Filename=Commandr.exe
Description=Logitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
Description=Browser Sentinel. Notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page. See <a href="http://www.unhsolutions.net/Browser-Sentinel/index.shtml" target="_blank">here</a>
Source=Paul Collins Startup list
[BrowserWebCheck]
Confirmed=N
Filename=loadwc.exe
Description=Checks to make sure that IE is still your default browser
Source=Paul Collins Startup list
[Bsoft lppt01]
Confirmed=X
Filename=Bsoft.exe
Description=New variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "BelmontSoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[btinst]
Confirmed=?
Filename=btinst.exe
Description=Associated with an Anycom bluetooth wireless card. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[BtStart]
Confirmed=U
Filename=btstart.exe
Description=<a href="http://www.widcomm.com/Partners/index.asp" target="_blank">Broadcorp</a> (formerly WIDCOMM) Bluetooth Connectivity Software
Source=Paul Collins Startup list
[bttray]
Confirmed=U
Filename=bttray.exe
Description=System tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device
Source=Paul Collins Startup list
[BTUSRBDGF]
Confirmed=Y
Filename=BtUsrBdg.exe
Description=Used with a <a href="http://www.mitsumi.de/index4.html" target="_blank">Mitsumi USB Bluetooth</a> adaptor
Description=Part of the <a href="#AIMster">AIMster</a> Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
Source=Paul Collins Startup list
[bugwatcher service]
Confirmed=U
Filename=bugwatcher.exe
Description=<a href="http://www.bugtoaster.com/" target="_blank">Bugtoaster</a> is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures
Source=Paul Collins Startup list
[BuildBU]
Confirmed=?
Filename=bldbubg.exe
Description=<font color="#FF0000">Found on a Dell machine??</font>
Source=Paul Collins Startup list
[BuildLab]
Confirmed=X
Filename=services.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html" target="_blank">NEVEG.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[BuildLab]
Confirmed=X
Filename=winlogon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[BuildLabs]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Bulldog Service]
Confirmed=U
Filename=upsd.exe
Description=Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
Source=Paul Collins Startup list
[BullGuard]
Confirmed=Y
Filename=mgui.exe
Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
Source=Paul Collins Startup list
[BullGuard Update]
Confirmed=U
Filename=avxlive.exe
Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus. Leave enabled unless you manually update virus definitions
Source=Paul Collins Startup list
[BullGuard XComm]
Confirmed=Y
Filename=XCOMMSVR.EXE
Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
Source=Paul Collins Startup list
[BullGuardInit]
Confirmed=Y
Filename=AVXINIT.EXE
Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
Source=Paul Collins Startup list
[BullguardoptIn]
Confirmed=Y
Filename=bulldownload.exe
Description=Part of <a href="http://www.bullguard.com/" target="_blank"> Bullguard</a> antivirus
Description=<a href="http://www.intelliseek.com/prod/bullseye/bullseye.htm" target="_blank">Bullseye</a> - intelligent research assistant
Source=Paul Collins Startup list
[BurnQuick Queue]
Confirmed=N
Filename=BQTray.exe
Description=System Tray access to <a href="http://www.burnquick.com/" target="_blank">BurnQuick</a> CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
Source=Paul Collins Startup list
[Button Server]
Confirmed=U
Filename=bttnserv.exe
Description=Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required
Source=Paul Collins Startup list
[ButtonKey]
Confirmed=N
Filename=ButtonKey.exe
Description=CyberView TWAIN driver for the <a href="http://www.scanace.com/en/product/product.php" target="_blank">Pacific Image</a> range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut
Source=Paul Collins Startup list
[Buzme]
Confirmed=N
Filename=Bmui.exe
Description=<a href="http://www.buzme.com/buzme/default.asp" target="_blank">Buzme</a> by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
Source=Paul Collins Startup list
[Buzof.exe]
Confirmed=U
Filename=buzof.exe
Description=<a href="http://www.basta.com/ProdBuzof.htm" target="_blank">Buzof</a> from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes"
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.bymer.html" target="_blank">BYMER</a> WORM!
Source=Paul Collins Startup list
[Bymer.Scanner]
Confirmed=X
Filename=Msinit.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.bymer.html" target="_blank">BYMER</a> WORM!
Source=Paul Collins Startup list
[c]
Confirmed=X
Filename=c:\archiv~1\win.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.cuydoc.html" target="_blank">CUYDOC</a> TROJAN!
Source=Paul Collins Startup list
[C-Media Echo Control]
Confirmed=U
Filename=EchoCtrl.exe
Description=C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
Source=Paul Collins Startup list
[C-Media Mixer]
Confirmed=N
Filename=Mixer.exe
Description=C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
Source=Paul Collins Startup list
[C2K]
Confirmed=U
Filename=CYB2K.EXE
Description=CYBERsitter 2000 or 2001 - anti-porn filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
Source=Paul Collins Startup list
[CA-AMAgent]
Confirmed=U
Filename=amagent.exe
Description=<a href="http://www3.ca.com/Solutions/Product.asp?ID=194" target=_blank>Unicenter Asset Management</a> is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting
Source=Paul Collins Startup list
[Cabchk]
Confirmed=X
Filename=Cabchk.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Cabchk32]
Confirmed=X
Filename=Cabchk32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Description=<a href="http://www.systweak.com/cacheboost/" target="_blank">CacheBoost</a> "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost"
Source=Paul Collins Startup list
[Cacheman]
Confirmed=N
Filename=Cacheman.exe
Description=Freeware disk cache tweaker from <a href="http://www.outertech.com/">Outer Technologies</a>. Should only be run once and not loaded at start-up
Description=<a href="http://www.caddais.com/BackupOnDemand.shtml" target="_blank">Caddais BackupOnDemand</a> - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location"
Source=Paul Collins Startup list
[CADS]
Confirmed=U
Filename=cads.exe
Description=<a href="http://www.securitysoft.com/new601/cs_home.htm" target="_blank">Cyber Sentinel</a> internet filtering software
Source=Paul Collins Startup list
[CAgent]
Confirmed=N
Filename=CAgent.exe
Description=<a href="http://www.fine-reader.com/" target="_blank">Abbyy Fine Reader</a> OCR (Optical Character Recognition) software for scanning and converting documents
Source=Paul Collins Startup list
[cAgOu]
Confirmed=X
Filename=[filename].hta
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/wscript.kakworm.html" target="_blank">KAKWORM</a> WORM!
Source=Paul Collins Startup list
[CahootWebcard]
Confirmed=N
Filename=CahootWebcard.exe
Description="The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when needed
Source=Paul Collins Startup list
[CAISafe]
Confirmed=Y
Filename=isafe.exe
Description=Part of Computer Associates <a href="http://www1.my-etrust.com/products/Antivirus.cfm?" target="_blank">eTrus EZ Antivirus</a>
Source=Paul Collins Startup list
[Cal Reminder Shortcut]
Confirmed=N
Filename=calrem.exe
Description=Produces a pop-up reminder of events scheduled using the MS Office Calendar
Source=Paul Collins Startup list
[Calendar 200X Reminder]
Confirmed=N
Filename=calendar.exe
Description=<a href="http://www.jgraff.addr.com/cal.htm" target="_blank">Calendar 200X</a> - shows holidays, reminders of various anniversaries,tasks etc
Source=Paul Collins Startup list
[CallBumping]
Confirmed=?
Filename=cbpopw.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[CallControl]
Confirmed=N
Filename=ftctrl32.exe
Description=FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows
Source=Paul Collins Startup list
[CamCheck]
Confirmed=N
Filename=CamCheck.exe
Description=<a href="http://www.nucam.com.tw/index1.htm" target="_blank">NuCam</a> camera software related
Source=Paul Collins Startup list
[Camera Detector]
Confirmed=N
Filename=CAMDET~*.EXE
Description=<a href="http://www.acdsystems.com/english/products/acdsee/overview?LAN=englishX70" target="_blank">ACDSee</a> Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
Source=Paul Collins Startup list
[Camera Detector]
Confirmed=N
Filename=Camdetect.exe
Description=<a href="http://www.acdsystems.com/english/products/acdsee/overview?LAN=englishX70" target="_blank">ACDSee</a> Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically
Source=Paul Collins Startup list
[Camio Viewer x]
Confirmed=N
Filename=IXApplet.exe
Description=Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
Source=Paul Collins Startup list
[CamMonitor]
Confirmed=?
Filename=hpqcmon.exe
Description=<font color="#FF0000">From HP and related to digital imaging</font>
Source=Paul Collins Startup list
[Canada]
Confirmed=N
Filename=Canada.exe
Description=<font color="#FF0000">Known to be a dialler - but is it maliscous or clean?</font>
Source=Paul Collins Startup list
[Canary]
Confirmed=N
Filename=canary-std.exe
Description=Canary monitoring program. Keylogger, monitors all computer activity
Source=Paul Collins Startup list
[candy]
Confirmed=X
Filename=command32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlv.html" target="_blank">RBOT-LV</a> WORM!
Source=Paul Collins Startup list
[candynet]
Confirmed=X
Filename=Taskmsg.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotna.html" target=_blank>RBOT-NA</a> WORM!
Source=Paul Collins Startup list
[Canon PC1200 iC D600 iR1200G Status Window]
Confirmed=N
Filename=CAPM1LAK.EXE
Description=Canon P1200 printer status
Source=Paul Collins Startup list
[Canon Printer Monitor BJCxxx]
Confirmed=N
Filename=Cjstlst.exe
Description=Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankeran.html" target=_blank>BANKER-AN</a> TROJAN!
Source=Paul Collins Startup list
[CARPservice]
Confirmed=U
Filename=carpserv.exe
Description=Associated with <a href="http://www.zoltrix.com/" target="_blank"> Zoltrix</a> modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
Source=Paul Collins Startup list
[CasAgnt]
Confirmed=U
Filename=CasAgnt.exe
Description=Program by Extended Systems which allows you to sync your Casio PDA with your PC
Source=Paul Collins Startup list
[Casdvqwa]
Confirmed=X
Filename=bmqnzkg.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.be.html" target="_blank">RANDEX.BE</a> WORM!
Source=Paul Collins Startup list
[caseyvideo]
Confirmed=X
Filename=CaseyVideo.exe
Description=Malware causing p0rn popups
Source=Paul Collins Startup list
[caseyvideo]
Confirmed=X
Filename=caseyvideo[*].exe [* = digit]
Description=Malware causing p0rn popups
Source=Paul Collins Startup list
[CashBack]
Confirmed=X
Filename=cashback.exe
Description=Part of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch
Source=Paul Collins Startup list
[Cashsurfers Cashbar Navigator]
Confirmed=N
Filename=Cashbar.Exe
Description=Cashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"
Description=CashToolbar <a href="http://vil.nai.com/vil/content/v_126801.htm" target="_blank">Downloader-MY</a> adware. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.cazno.html" target="_blank">CAZNO</a> TROJAN!
Source=Paul Collins Startup list
[CBWAttn]
Confirmed=U
Filename=CBWAttn.exe
Description=Required for <a href="http://www.accpac.com/products/communication/bitware/" target="_blank"> Bitware</a> to answer incoming faxes, can cause sleep mode problems
Source=Paul Collins Startup list
[CBWHost]
Confirmed=U
Filename=CBWHost.exe
Description=Required for <a href="http://www.accpac.com/products/communication/bitware/" target="_blank"> Bitware</a> to answer incoming faxes, can cause sleep mode problems
Source=Paul Collins Startup list
[CBWUser]
Confirmed=?
Filename=CBWDial.exe
Description=Associated with <a href="http://www.accpac.com/products/communication/bitware/" target="_blank"> Bitware</a> that integrates fax, voice, pager, and data communications on your desktop
Source=Paul Collins Startup list
[CC2KUI]
Confirmed=X
Filename=comet.exe
Description=Comet Cursor - displays different mouse pointers dependent upon the site your visiting. Malware because it automatically installs. See <a href="http://www.accs-net.com/smallfish/comet.htm" target="_blank">here</a> for more information and for the uninstall procedure
Source=Paul Collins Startup list
[ccApp]
Confirmed=Y
Filename=ccApp.exe
Description=Part of <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> Norton AntiVirus 2003</a>. Auto-protect and E-mail check will not function without this
Source=Paul Collins Startup list
[ccApp]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.obsorb.html" target="_blank">OBSORB</a> TROJAN! Note the random filename compared to the valid Norton AntiVirus
Source=Paul Collins Startup list
[ccApp]
Confirmed=X
Filename=WMADZ.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlj.html" target="_blank">RBOT-LJ</a> WORM!
Source=Paul Collins Startup list
[ccAppr]
Confirmed=X
Filename=svcrhost.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[ccApps]
Confirmed=X
Filename=services.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html" target="_blank">NEVEG.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[ccApps]
Confirmed=X
Filename=winlogon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[CCD Manager]
Confirmed=U
Filename=DDS.EXE
Description=Project Labs <a href="http://www.centurycdna.com/" target="_blank">Century CD</a> manager for their CD/DVD storage device
Description=Part of the closed caption decdoder/MS VBI codec. Should only run once
Source=Paul Collins Startup list
[CCDoctorLogonTesting]
Confirmed=Y
Filename=ccdoctor.exe
Description=Checks your system to make sure it's configured properly for running <a href="http://www.rational.com/products/clearcase/index.jsp" target="_blank">Rational ClearCase</a>, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product
Description=Part of <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> Norton AntiVirus 2003</a>.<font color="#FF0000"> </font>Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and was not required as a seperate entry but a recent update changed this
Source=Paul Collins Startup list
[ccpApps]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[ccpApps]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.b.html" target="_blank">WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lsass.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[ccProxy]
Confirmed=U
Filename=CCPROXY.EXE
Description=Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage
Source=Paul Collins Startup list
[CcPxySvc]
Confirmed=Y
Filename=CCPXYSVC.exe
Description=Part of Norton's <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> AntiVirus 2003</a>, <a href="http://www.symantec.com/sabu/nis/nis_pe/" target="_blank"> Internet Security</a> and <a href="http://www.symantec.com/sabu/nis/npf/" target="_blank"> Firewall</a> products. E-mail proxy service - required for E-mail scanning and the firewall
Source=Paul Collins Startup list
[ccreg]
Confirmed=X
Filename=explorer.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.irc.zcrew.html" target="_blank">ZCREW</a> TROJAN! Note - the valid "explorer.exe" is located in C:\Windows or C:\Winnt whereas this one is located in a C:\Windows\System or C:\Winnt\System subdirectory
Source=Paul Collins Startup list
[CcRegVfy]
Confirmed=Y
Filename=ccRegVfy.exe
Description=Part of <a href="http://www.symantec.com/nav/nav_9xnt/" target="_blank"> Norton AntiVirus 2003</a>. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"
Source=Paul Collins Startup list
[ccSetMgr]
Confirmed=Y
Filename=ccSetMgr.exe
Description=Part of Norton AntiVirus 2004. <font color="#FF0000"> What does it do?</font>
Source=Paul Collins Startup list
[ccUpdate]
Confirmed=X
Filename=ccUpdate.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_AGOBOT.YS&VSect=T" target=_blank>AGOBOT.YS</a> WORM!
Source=Paul Collins Startup list
[ccWasher]
Confirmed=U
Filename=aolwasher.exe
Description=Webroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL
Source=Paul Collins Startup list
[CCWC7a]
Confirmed=U
Filename=ac.exe
Description=<a href="http://www.moleculesoft.se/index2b.html" target=_blank>Moleculesoft</a> Cache, Cookie & Windows Cleaner Ver. 7 - auto clean
Source=Paul Collins Startup list
[CCWC7I]
Confirmed=U
Filename=idxl.exe
Description=<a href="http://www.moleculesoft.se/index2b.html" target=_blank>Moleculesoft</a> Cache, Cookie & Windows Cleaner Ver. 7 - auto clean
Source=Paul Collins Startup list
[CCWC7s]
Confirmed=U
Filename=stealth.exe
Description=<a href="http://www.moleculesoft.se/index2b.html" target=_blank>Moleculesoft</a> Cache, Cookie & Windows Cleaner Ver. 7
Source=Paul Collins Startup list
[cd1]
Confirmed=X
Filename=cd1.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[CDANTSRV]
Confirmed=N
Filename=CDANTSRV.exe
Description=C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually
Source=Paul Collins Startup list
[Cdcompat]
Confirmed=X
Filename=Cdcompat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[cddrv32]
Confirmed=X
Filename=cddrv32.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[CDInterceptor]
Confirmed=N
Filename=cdi.exe
Description=CD indexer for measuring the speed of CD players
Source=Paul Collins Startup list
[CDTray]
Confirmed=N
Filename=CDTray.exe
Description=On HP PCs, this is the small CD icon next to the time
Source=Paul Collins Startup list
[CeEKEY]
Confirmed=?
Filename=CeEKey.exe
Description=<font color="#FF0000">Toshiba Satellite E-Key related. Is it required?</font>
Source=Paul Collins Startup list
[CeEPOWER]
Confirmed=U
Filename=cepmtray.exe
Description=Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times
Source=Paul Collins Startup list
[Ceic]
Confirmed=?
Filename=Ceic.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Cekirge]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kergez.a@mm.html" target="_blank">KERGEZ.A</a> WORM!
Source=Paul Collins Startup list
[center]
Confirmed=X
Filename=[random name]32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.bofra.a@mm.html" target=_blank>BOFRA.A</a> WORM!
Source=Paul Collins Startup list
[CentralProcessor]
Confirmed=X
Filename=taskimgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.j.html" target="_blank">BANCOS.J</a> TROJAN!
Source=Paul Collins Startup list
[CEPA]
Confirmed=?
Filename=wsot.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[cesmain.dll]
Confirmed=X
Filename=cmail.dll, Rundll32
Description=CnsMin "<a href="http://217.115.153.73/parasite/CnsMin.html" target="_blank">Chinese Keywords</a>" hijacker related
Source=Paul Collins Startup list
[CFD]
Confirmed=N
Filename=CFD.exe
Description=<a href="http://www.broadjump.com/" target="_blank">BroadJump</a> Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
Description=Configuration Interpreter - part of <a href="http://www.tinysoftware.com/home/tiny2?la=EN" target="_blank">Tiny Personal Firewall</a> V4
Source=Paul Collins Startup list
[cfgwiz]
Confirmed=N
Filename=cfgwiz.exe
Description=Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
Source=Paul Collins Startup list
[cFosDNT]
Confirmed=?
Filename=cFosDNT.exe
Description=<a href="http://www.cfos.de/index2_e.htm" target="_blank">cFos</a> DSL Modem driver related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[cFosInst_Check]
Confirmed=?
Filename=cfosinst.exe
Description=<a href="http://www.cfos.de/index2_e.htm" target="_blank">cFos</a> DSL Modem driver related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[cftmon32]
Confirmed=X
Filename=taskmgr*.exe [* = number]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sowsat.c@mm.html" target="_blank">SOWSAT.C</a> and <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sowsat.j@mm.html" target="_blank">SOWSAT.J</a> WORMS!
Source=Paul Collins Startup list
[CGServer]
Confirmed=U
Filename=cgserver.exe
Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs
Source=Paul Collins Startup list
[Cgtask Services]
Confirmed=X
Filename=cgtask.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lala.b.html" target="_blank">LALA.B</a> TROJAN!
Source=Paul Collins Startup list
[ChamClock]
Confirmed=U
Filename=ChamClock.exe
Description=<a href="http://www.softshape.com/cham/" target="_blank">Chameleon Clock</a> - system tray clock replacement
Source=Paul Collins Startup list
[change-me-now]
Confirmed=X
Filename=msgfix1.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.ZD" target=_blank>SDBOT.ZD</a> WORM!
Source=Paul Collins Startup list
[ChangeLines]
Confirmed=?
Filename=chngline.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Chatango]
Confirmed=N
Filename=Chatango.exe
Description=<a href="http://www.chatango.com/" target=_blank>Chatango</a> - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately
Source=Paul Collins Startup list
[Chcenter]
Confirmed=N
Filename=chcenter.exe
Description=IMSI <a href="http://www.imsisoft.com/prodinfo.asp?t=1&mcid=100" target="_blank">HiJaak</a> - "the easiest way to convert, capture, and manage all your graphic files"
Source=Paul Collins Startup list
[Cheatle]
Confirmed=X
Filename=GigaByte.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllp.shodi.b.html" target="_blank">SHODI.B</a> VIRUS!
Source=Paul Collins Startup list
[Check for One Touch Update]
Confirmed=N
Filename=wiseupdt.exe
Description=Checks for updates for Visioneer OneTouch scanners
Source=Paul Collins Startup list
[Check Messenger]
Confirmed=U
Filename=cmesseng.exe
Description=<a href="http://www.qchex.com/messenger.asp" target="_blank">Check Messenger</a> from Qchex.com - program that helps you manage the activity of your Qchex account
Source=Paul Collins Startup list
[CheckIt]
Confirmed=U
Filename=ToolBox.exe
Description=CheckIt Toolbox from <a href="http://cssvc.pcworld.compuserve.com/computing/cis/article/0,aid,15497,00.asp" target="_blank">WinCheckIt Diagnostic Software</a>. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify
Source=Paul Collins Startup list
[CheckMsgPlus]
Confirmed=Y
Filename=MsgPlusH.dll, VerifyInstallation
Description=Added by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see <a href="http://www.patchou.com/msgplus/faq.htm#stopconnect" target="_blank">here</a> for more info.
Source=Paul Collins Startup list
[checktime]
Confirmed=?
Filename=ct.exe
Description=<font color="#FF0000">Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required?</font>
Source=Paul Collins Startup list
[CherryKeyMan]
Confirmed=U
Filename=KeyMan.exe
Description=Multimedia keyboard manager for the <a href="http://www.cherrycorp.com/english/" target="_blank">Cherry</a> keyboard series. Only required if you use any of the special keys
Source=Paul Collins Startup list
[ChineseStar]
Confirmed=U
Filename=cstar.exe
Description=Chinese language support software
Source=Paul Collins Startup list
[CHKADMIN]
Confirmed=N
Filename=CHKADMIN.EXE
Description=Compaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability"
Source=Paul Collins Startup list
[chkdsk]
Confirmed=X
Filename=c:\autoexec.bat
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.anpes@mm.html" target=_blank>ANPES</a> WORM!
Source=Paul Collins Startup list
[Choke]
Confirmed=X
Filename=Choke.exe-blahh
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.choke.worm.html" target="_blank">CHOKE</a> WORM!
Source=Paul Collins Startup list
[chostsv]
Confirmed=X
Filename=chostsv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.banpaes.c.html" target="_blank">BANPAES.C</a> TROJAN!
Source=Paul Collins Startup list
[CHotKey]
Confirmed=U
Filename=mhotkey.exe
Description=Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features
Source=Paul Collins Startup list
[CHotKey]
Confirmed=U
Filename=MK9805.EXE
Description=Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features
Source=Paul Collins Startup list
[CHotKey]
Confirmed=U
Filename=zHotkey.exe
Description=Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features
Source=Paul Collins Startup list
[Christmas Music Player]
Confirmed=N
Filename=TTEST6.EXE
Description=<I>"</I>Christmas Music Player<I> </I>brings the music of the Christmas Holiday to your desktop"
Source=Paul Collins Startup list
[ChromeMark]
Confirmed=?
Filename=keysh.exe
Description=<font color="#FF0000">Related to <a href="http://chromium.com/chromemark.html" target="_blank">this</a>. Don't know what keysh.exe does though and if it's required</font>
Source=Paul Collins Startup list
[ChronitelInitTV]
Confirmed=?
Filename=CHTVINIT.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[CiaBackdoor]
Confirmed=X
Filename=msldr.com
Description=Added by a VIRUS!
Source=Paul Collins Startup list
[cihost.exe]
Confirmed=X
Filename=cihost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.linst.html" target="_blank">LINST</a> TROJAN!
Source=Paul Collins Startup list
[CIJxP2PSERVER]
Confirmed=N
Filename=CIJxP2PS.EXE
Description=Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7
Source=Paul Collins Startup list
[Cisco Systems VPN Client]
Confirmed=U
Filename=ipsecdialer.exe
Description=Cisco <a href="http://www.cisco.com/en/US/products/sw/secursw/ps2308/" target=_blank>VPN Client</a> - lets local users gain Administrator privileges on the operating system
Source=Paul Collins Startup list
[Cisco Systems VPN Client]
Confirmed=N
Filename=vpngui.exe
Description=Sets up IPSec communications for Cisco's <a href="http://www.cisco.com/en/US/products/sw/secursw/ps2308/" target=_blank>VPN Client</a>
Source=Paul Collins Startup list
[CISrvr Program]
Confirmed=N
Filename=CISRVR.EXE
Description=Related to internet setup on Compaq PC's
Source=Paul Collins Startup list
[Cissi]
Confirmed=X
Filename=Cissi.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.cissi.a@mm.html" target="_blank">CISSI.A</a> WORM!
Source=Paul Collins Startup list
[CitiVAN]
Confirmed=N
Filename=CitiVAN.exe
Description=Option from <a href="http://www.citibank.com/" target="_blank">Citibank</a> to change a credit card number in a random fashion for each purchase. The number will only be used once and never again
Source=Paul Collins Startup list
[Cjstcom]
Confirmed=Y
Filename=Cjstcom.exe
Description=Canon printer BJ status language monitor
Description=Automatic logging of installs from Norton CleanSweep - available via Start -> Programs
Source=Paul Collins Startup list
[CleanSweep Useage Watch]
Confirmed=N
Filename=CSUSEM32.EXE
Description=Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Source=Paul Collins Startup list
[CleanTemp]
Confirmed=U
Filename=CLEANT~1.EXEB
Description=<a href="http://www.html2exe.com/mnu/dl/dl.shtml#free" target="_blank">CleanTemp</a> - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
Source=Paul Collins Startup list
[CleanTemp]
Confirmed=U
Filename=CleanTemp.exe
Description=<a href="http://www.html2exe.com/mnu/dl/dl.shtml#free" target="_blank">CleanTemp</a> - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
Source=Paul Collins Startup list
[Cleanup]
Confirmed=N
Filename=ONICTASK.EXE
Description=<a href="http://www.aladdinsys.com/internetcleanup/" target="_blank">Internet Cleanup</a> from Aladdin Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet
Source=Paul Collins Startup list
[CleanupProgram]
Confirmed=?
Filename=cleanup.exe
Description=<font color="#FF0000">In a C:\Sony\sys folder - Sony Vaio related?</font>
Source=Paul Collins Startup list
[Click Radio Tuner]
Confirmed=N
Filename=clickr~1.exe
Description=<a href="http://www.clickradio.com/home.html" target="_blank">ClickRadio</a> - subscription service playing radio music via the internet
Source=Paul Collins Startup list
[Click Tray Calendar]
Confirmed=N
Filename=ClickT~1.EXE
Description=<a href="http://waseo.de/en/Freeware2/ClickTrayE/clicktraye.html" target="_blank">ClickTray Calendar</a> - shows holidays, reminders of various anniversaries,tasks etc
Description=ClickTheButton <a href="http://vil.nai.com/vil/content/v_126801.htm" target="_blank">Downloader-MY</a> adware. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
Source=Paul Collins Startup list
[Client Access Check Version]
Confirmed=N
Filename=cwbckver.exe
Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
Source=Paul Collins Startup list
[Client Access Express Welcome]
Confirmed=?
Filename=cwbwlwiz.exe
Description=Welcome wizard launcher - Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[Client Access Help Update]
Confirmed=N
Filename=cwbinhlp.exe
Description=Client Access Help Registry Update Function - part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
Source=Paul Collins Startup list
[Client Access Service]
Confirmed=N
Filename=CwbSvStr.Exe
Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
Source=Paul Collins Startup list
[Client agent for ARCserve]
Confirmed=?
Filename=W95AGENT.EXE
Description=Part of <a href="http://www3.ca.com/Solutions/ProductFamily.asp?ID=115" target="_blank">Brightstor ARCserve Backup</a> from Computer Associates. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[Client Server Runtime Process]
Confirmed=X
Filename=csrsss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotld.html" target=_blank>SDBOT-LD</a> WORM!
Source=Paul Collins Startup list
[ClientMan1]
Confirmed=X
Filename=mscman.exe
Description=Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
Source=Paul Collins Startup list
[Clik Status Monitor]
Confirmed=N
Filename=toolsclickstat.exe
Description=Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
Source=Paul Collins Startup list
[Clipbook Service]
Confirmed=N
Filename=Clipsrv.exe
Description=Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
Source=Paul Collins Startup list
[ClipMate5x]
Confirmed=N
Filename=ClipMt5x.exe
Description=<a href="http://www.thornsoft.com/ProductOverview.asp" target="_blank">Clip Mate 5.x</a> by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
Source=Paul Collins Startup list
[Clipmate6]
Confirmed=N
Filename=CLIPMT60.EXE
Description=<a href="http://www.thornsoft.com/new_60.htm" target="_blank">Clip Mate 6</a> by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
Source=Paul Collins Startup list
[Clipomatic]
Confirmed=N
Filename=Clipomatic.exe
Description=Mike Lin's <a href="http://www.mlin.net/Clipomatic.shtml" target="_blank">Clipomatic</a> is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data
Source=Paul Collins Startup list
[Clipsrv]
Confirmed=N
Filename=Clipsrv.exe
Description=Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
Description=System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost
Description=<a href="http://www.clock-sync.com/" target="_blank">ClockSynck</a> - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available
Source=Paul Collins Startup list
[ClockWise]
Confirmed=U
Filename=CLOCKWISE.EXE
Description=<a href="http://www.rjsoftware.com/ClockWise/" target="_blank">ClockWise</a> - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync
Source=Paul Collins Startup list
[CloneCD]
Confirmed=U
Filename=CloneCDTray.exe
Description=System tray for <a href="http://www.elby.org/CloneCD/english/" target="_blank">CloneCD</a> - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
Source=Paul Collins Startup list
[CloneCDElbyCDFL]
Confirmed=U
Filename=ElbyCheck.exe
Description=From <a href="http://www.elby.org/english/corp/index.htm" target="_blank">Elaborate Bytes</a> who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
Source=Paul Collins Startup list
[CloneCDTray]
Confirmed=U
Filename=CloneCDTray.exe
Description=System tray for <a href="http://www.elby.org/CloneCD/english/" target="_blank">CloneCD</a> - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
Source=Paul Collins Startup list
[Clotusorgreg0]
Confirmed=?
Filename=prtStart.exe Orgprt.exe
Description=Lotus <a href="http://www.lotus.com/products/smrtsuite.nsf/wPages/smartsuite?OpenDocument" target="_blank"> SmartSuite</a> related. In a LotusOrgReg folder. <font color="#FF0000"> Unclear what exactly it does?</font>
Source=Paul Collins Startup list
[ClrSchLoader]
Confirmed=X
Filename=Loader.exe
Description=Clearsearch variant of <a href="http://www.igetnet.com/iGetNet_Home.asp" target="_blank"> IGetNet</a>
Source=Paul Collins Startup list
[CLSID]
Confirmed=X
Filename=com.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[CLSID]
Confirmed=X
Filename=dll.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[CLSID]
Confirmed=X
Filename=msgplus.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[CLSID]
Confirmed=X
Filename=plugin.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[CLSID]
Confirmed=X
Filename=sed.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[CLSID]
Confirmed=X
Filename=msgplus.exe
Description=Premium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
Source=Paul Collins Startup list
[CM-SmWizard]
Confirmed=?
Filename=SmWizard.exe
Description=SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[cma]
Confirmed=U
Filename=cma.exe
Description=<a href="http://www.desksitemusic.com/" target="_blank">DeskSite CMA siftware</a> - "retrieves new content from the DeskSite Data Center"
Source=Paul Collins Startup list
[Cmaudio]
Confirmed=N
Filename=Rundll32 cmicnfg.cpl, CMICtrlWnd
Description=System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Cmd]
Confirmed=X
Filename=cmd32.exe
Description=Added by the <a href="http://www.viruslibrary.com/virusinfo/Worm.P2P.Tanked.htm" target="_blank">TANKED</a> WORM!
Source=Paul Collins Startup list
[cmdcon]
Confirmed=X
Filename=cmdcon.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[CME]
Confirmed=X
Filename=cme.exe
Description=Part of <a href="http://www.thiefware.com/info/data.gator.shtml" target="_blank"> Gator</a> advertising spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions
Source=Paul Collins Startup list
[CmeSYS]
Confirmed=X
Filename=CMEsys.exe
Description=Part of <a href="http://www.thiefware.com/info/data.gator.shtml" target="_blank"> Gator</a> advertising spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions
Source=Paul Collins Startup list
[CmeUPD]
Confirmed=X
Filename=CMEupd.exe
Description=Part of <a href="http://www.thiefware.com/info/data.gator.shtml" target="_blank"> Gator</a> advertising spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions
Source=Paul Collins Startup list
[CMGrdian]
Confirmed=?
Filename=CMGrdian.exe
Description=One of the McAfee shared components. <font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[Cmmon32Sys]
Confirmed=X
Filename=cmmon32.exe
Description=Added by the SMALL.CL TROJAN!
Source=Paul Collins Startup list
[CMPDPSRV]
Confirmed=U
Filename=CMPDPSRV.EXE
Description=<a href="http://www.viewahead.com/PDP.htm" target="_blank">Printer Driver Plus</a> from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more." Installed with some Compaq and Lexmark printers
Source=Paul Collins Startup list
[cmsound]
Confirmed=X
Filename=vcpdll.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtcxmedid.html" target=_blank>TCXMEDI-D</a> downloader TROJAN!
Source=Paul Collins Startup list
[cmsound]
Confirmed=X
Filename=vcsystem.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojtcxmedid.html" target=_blank>TCXMEDI-D</a> downloader TROJAN!
Source=Paul Collins Startup list
[cmssSystemProcess]
Confirmed=X
Filename=csmss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentco.html" target=_blank>AGENT-CO</a> TROJAN!
Source=Paul Collins Startup list
[cmssSystemProcess]
Confirmed=X
Filename=mcsmss.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.EI&VSect=T" target=_blank>AGENT.EI</a> TROJAN!
Source=Paul Collins Startup list
[cmt101]
Confirmed=X
Filename=cmt101.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[cmx32]
Confirmed=X
Filename=cmx32.exe
Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=40493" target=_blank>GEMA.D</a> TROJAN!
Source=Paul Collins Startup list
[Cn323]
Confirmed=X
Filename=cnfrm33.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.g@mm.html" target=_blank>MIMAIL.G</a> WORM!
Source=Paul Collins Startup list
[CNBABE]
Confirmed=X
Filename=CNBABE.EXE
Description=Appears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing
Source=Paul Collins Startup list
[cnet]
Confirmed=N
Filename=kontiki.exe
Description=<a href="http://help.kontiki.com/enduser/group.jsp;jsessionid=2C47C896EA1784C5321FD3E6845E8157?node=2846" target="_blank">Kontiki Delivery Manager</a> - Windows-based client software that enables secure delivery of content to users' desktops
Source=Paul Collins Startup list
[Cnfrm32]
Confirmed=X
Filename=cnfrm.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.d@mm.html" target=_blank>MIMAIL.D</a> WORM!
Source=Paul Collins Startup list
[CnsMax]
Confirmed=X
Filename=Internat.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.pointex.html" target="_blank">POINTEX</a> TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
Source=Paul Collins Startup list
[CnsMin]
Confirmed=X
Filename=Rundll32.exe CNSMIN.DLL, Rundll32
Description=CnsMin "<a href="http://217.115.153.73/parasite/CnsMin.html" target="_blank">Chinese Keywords</a>" hijacker related
Source=Paul Collins Startup list
[CnxDslTaskBar]
Confirmed=N
Filename=CnxDslTb.exe
Description=Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
Source=Paul Collins Startup list
[Codename Dashboard]
Confirmed=U
Filename=dashboard.exe
Description=<a href="http://www.downlinx.com/proghtml/415/41557.htm" target="_blank">Codename: Dashboard</a> - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time"
Source=Paul Collins Startup list
[Coldlife -icmp]
Confirmed=X
Filename=Systray.exe
Description=Added by the <a href="http://vil.nai.com/vil/content/Print100363.htm" target="_blank">FLOOD.AV</a> TROJAN! Note - this is not the legitimate SysTray.exe
Source=Paul Collins Startup list
[coloreal]
Confirmed=U
Filename=coloreal.exe
Description=Makes colours sharper and brighter, but will only work with coloreal capable monitors
Source=Paul Collins Startup list
[Colorific Control Panel]
Confirmed=N
Filename=Hgcctl95.exe
Description=From E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor
Source=Paul Collins Startup list
[COM Service]
Confirmed=X
Filename=mscom32.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.h.html" target="_blank">BEASTY.H</a> TROJAN!
Source=Paul Collins Startup list
[COM Service]
Confirmed=X
Filename=msynvr.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.g.html" target="_blank">BEASTY.G</a> TROJAN!
Source=Paul Collins Startup list
[COM Service]
Confirmed=X
Filename=msjclh.com
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.plux.html" target="_blank">PLUX</a> TROJAN!
Source=Paul Collins Startup list
[COM Service]
Confirmed=X
Filename=msdrce.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.beasty.i.html" target="_blank">BEASTY.I</a> TROJAN!
Source=Paul Collins Startup list
[COM+ Event System]
Confirmed=X
Filename=DRWTSN16.EXE
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Com+ Sys]
Confirmed=X
Filename=csrs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbt.html" target=_blank>FORBOT-BT</a> WORM!
Source=Paul Collins Startup list
[COM+ System Applications]
Confirmed=X
Filename=lsas.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.SE" target=_blank>AGOBOT.SE</a> WORM!
Source=Paul Collins Startup list
[COM++ System]
Confirmed=X
Filename=exploier.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32lovgatef.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[COM++ System]
Confirmed=X
Filename=suchost.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32lovgatef.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[COM++ System]
Confirmed=X
Filename=svchost.exe...
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32lovgatef.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[COM-IP]
Confirmed=N
Filename=COMIP.EXE
Description=COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
Description=Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
Source=Paul Collins Startup list
[COMCFG]
Confirmed=X
Filename=comcfg.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_TOADCOM.A" target="_blank">TOADCOM.A</a> TROJAN!
Source=Paul Collins Startup list
[comctl32]
Confirmed=X
Filename=comctl32.exe
Description=Adware - recognized by <a href="http://www.kaspersky.com/personalpro" target=_blank>Kaspersky</a> antivirus and others as TrojanDownloader.Win32.Agent.am
Source=Paul Collins Startup list
[COMDRV32]
Confirmed=U
Filename=svdhost.exe
Description=<a href="http://www.protectcom.com/" target="_blank">Orvell Monitoring 2003</a> - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/
Source=Paul Collins Startup list
[Comm Driver]
Confirmed=U
Filename=commh32.exe
Description=G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see <a href="http://www.chip.de/artikel/c_artikel_8806643.html" target=_blank>here</a>. Disable/remove if you didn't install it yourself!
Source=Paul Collins Startup list
[Command]
Confirmed=X
Filename=system.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_GATECRASH.A" target="_blank">GATECRASH.A</a> or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_GATECRASH.B" target="_blank">GATECRASH.B</a> TROJANS!
Source=Paul Collins Startup list
[Command]
Confirmed=X
Filename=Gotit.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.titog.worm.html" target="_blank">TITOG</a> WORM!
Source=Paul Collins Startup list
[COMMAND]
Confirmed=X
Filename=command.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.pws.qqpass.e.html" target="_blank">QQPASS.E</a> TROJAN!
Source=Paul Collins Startup list
[CommCtr]
Confirmed=N
Filename=commctr.exe
Description="<a href="http://commcenter.net2phone.com/GLPPublish.asp?idpage=features" target="_blank">Net2Phone CommCenter</a> is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available via Start -> Programs
Source=Paul Collins Startup list
[Compaq Alerter]
Confirmed=U
Filename=CPQAlert.exe
Description=Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See <a href="http://www.compaq.com/products/servers/management/cim-description.html" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[Compaq Computer Corp SCCenter Module]
Confirmed=N
Filename=SCCENTER.EXE
Description=For Compaq PC's. Part of Backweb
Source=Paul Collins Startup list
[Compaq Computer Security]
Confirmed=?
Filename=Rundll32.exe SECURE32.CPL, Service
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Compaq DMI]
Confirmed=N
Filename=cpqdmi.exe
Description=Compaq version of the Desktop Management Interface
Source=Paul Collins Startup list
[Compaq Internet Setup]
Confirmed=N
Filename=inetwizard.exe
Description=For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
Source=Paul Collins Startup list
[Compaq Knowledge Center]
Confirmed=U
Filename=silent.exe & matcli.exe
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide
Source=Paul Collins Startup list
[Compaq Message Server]
Confirmed=N
Filename=COMPAQ-RBA.EXE
Description=Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the "advanced" tab. Not required and can cause problems
Source=Paul Collins Startup list
[Compaq PK Daemon]
Confirmed=U
Filename=cpqkl.exe
Description=For Compaq laptops for programming user configurable keys. Not required unless you use them
Source=Paul Collins Startup list
[Compaq Video CD Watcher]
Confirmed=N
Filename=??
Description=For Compaq PC's. MPEG viewer
Source=Paul Collins Startup list
[CompaqHW Comp Manager]
Confirmed=?
Filename=cpqhcm.exe
Description=<font color="#FF0000">Running on a Compaq laptop - any ideas?</font>
Source=Paul Collins Startup list
[CompaqPrinTray]
Confirmed=N
Filename=printray.exe
Description=Puts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
Source=Paul Collins Startup list
[CompaqSystray]
Confirmed=N
Filename=cpqpscp.exe
Description=Compaq System Tray icon
Source=Paul Collins Startup list
[Compatibility Service Process]
Confirmed=X
Filename=regsvs.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.yn.html" target="_blank">GAOBOT.YN</a> WORM!
Source=Paul Collins Startup list
[COMSMDEXE]
Confirmed=N
Filename=comsmd.exe
Description=3Com tray icon
Source=Paul Collins Startup list
[ComTry Web Searcher]
Confirmed=X
Filename=wstray.exe
Description=Comtry MP3 Downloader related - spyware
Source=Paul Collins Startup list
[comxt]
Confirmed=X
Filename=comxt.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.comxt.html" target="_blank">COMXT</a> TROJAN!
Source=Paul Collins Startup list
[Config]
Confirmed=X
Filename=service.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.israz.b@mm.html" target="_blank">ISRAZ.B</a> WORM!
Source=Paul Collins Startup list
[Config Loadation]
Confirmed=X
Filename=iEEexplore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.h.html" target="_blank">SDBOT.H</a> TROJAN!
Source=Paul Collins Startup list
[Config Loadatiorin]
Confirmed=X
Filename=I3Explorer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.h.html" target="_blank">SDBOT.H</a> TROJAN!
Source=Paul Collins Startup list
[Config Loader]
Confirmed=X
Filename=svchosl.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.gaobot.p.html" target="_blank">GAOBOT.P</a> WORM!
Source=Paul Collins Startup list
[Config Loader]
Confirmed=X
Filename=sysldr32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.html" target="_blank">GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Config Loader]
Confirmed=X
Filename=scvhost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ae.html" target="_blank">GAOBOT.AE</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORMS!
Source=Paul Collins Startup list
[Config Loader for Microsoft Windows]
Confirmed=X
Filename=mwincfg32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.BD" target="_blank">AGOBOT.BD</a> WORM!
Source=Paul Collins Startup list
[Config Loader2]
Confirmed=X
Filename=explores.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bt.html" target="_blank">GAOBOT.BT</a> WORM!
Source=Paul Collins Startup list
[Config Loadr]
Confirmed=X
Filename=winsys32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobothn.html" target=_blank>AGOBOT-HN</a> WORM!
Source=Paul Collins Startup list
[Config33.exe]
Confirmed=X
Filename=Config33.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.T" target=_blank>SDBOT.T</a> TROJAN!
Source=Paul Collins Startup list
[ConfiggLoader]
Confirmed=X
Filename=cart322.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.dj.html" target="_blank">GAOBOT.DJ</a> WORM!
Source=Paul Collins Startup list
[ConfigSafe]
Confirmed=U
Filename=CFGSAFE.EXE
Description=<a href="http://www.imaginelan.com/configsafe/index.html" target="_blank">ConfigSafe</a> - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
Source=Paul Collins Startup list
[ConfigSafe]
Confirmed=U
Filename=AUTOCHK.EXE
Description=<a href="http://www.imaginelan.com/configsafe/index.html" target="_blank">ConfigSafe</a> - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
Source=Paul Collins Startup list
[ConfigServices]
Confirmed=N
Filename=Config.exe
Description=Part of initial setup on a Compaq PC
Source=Paul Collins Startup list
[Configuration]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotml.html" target=_blank>SDBOT-ML</a> WORM!
Source=Paul Collins Startup list
[Configuration Default]
Confirmed=X
Filename=Wuxat.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotca.html" target=_blank>SPYBOT-CA</a> WORM!
Source=Paul Collins Startup list
[Configuration File]
Confirmed=X
Filename=Winset32.exe
Description=Added by the FLUX.101 TROJAN!
Source=Paul Collins Startup list
[Configuration Loaded]
Confirmed=X
Filename=wupdated.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.moega.html" target="_blank">MOEGA</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.moega.ag.html" target="_blank">MOEGA.AG</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.moega.ap.html" target="_blank">MOEGA.AP</a> WORMS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=aim95.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJANS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=cmd32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJANS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=service5.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.af.html" target="_blank">GAOBOT.AF</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=?
Filename=lfass.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=sycfg34.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.an.html" target="_blank">GAOBOT.AN</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=wincrt32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bh.html" target="_blank">GAOBOT.BF</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=windex.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bz.html" target="_blank">GAOBOT.BZ</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=dosrun32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=Service.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=Servicess.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=sw32.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_AGOBOT.BQ" target="_blank">AGOBOT.BQ</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=System.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=Winreg.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=sysinfo.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.fq.html" target="_blank">GAOBOT.FQ</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=microsoft.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.jb.html" target="_blank">GAOBOT.JB</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=confgldr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.polybot.html" target="_blank">POLYBOT</a> WORM!
Source=Paul Collins Startup list
[configuration loader]
Confirmed=X
Filename=winicfg32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.gen!poly.html" target="_blank">GAOBOT.GEN!POLY</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=svhst.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.yc.html" target="_blank">GAOBOT.YC</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=msgfix.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.aus.html" target="_blank">GAOBOT.AUS</a> or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.J" target="_blank">SDBOT.J</a> or <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotqg.html" target=_blank>SDBOT-QG</a> WORMS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=msnss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.aus.html" target="_blank">GAOBOT.AUS</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=IEXPL0RE.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJANS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=loadcfg32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJANS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=MSTasks.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LOADCFG.A" target="_blank"> LOADCFG</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJANS!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=systemry.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=ccSort.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=WORM_AGOBOT.SR" target=_blank>AGOBOT.SR</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=smss32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.MB" target=_blank>AGOBOT.MB</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader]
Confirmed=X
Filename=wincffg.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.A3&VSect=T" target=_blank>AGOBOT.A3</a> WORM!
Source=Paul Collins Startup list
[Configuration Loader ]
Confirmed=X
Filename=syscfg32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.b.html" target="_blank">SDBOT.B</a> TROJAN!
Source=Paul Collins Startup list
[Configuration Loading]
Confirmed=X
Filename=svchos1.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.dk.html" target="_blank">GAOBOT.DK</a> WORM!
Source=Paul Collins Startup list
[Configuration Loading]
Confirmed=X
Filename=configldr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotec.html" target="_blank">AGOBOT-EC</a> WORM!
Source=Paul Collins Startup list
[Configuration Manager]
Confirmed=X
Filename=CNFGLD32.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank"> SDBOT</a> TROJAN!
Source=Paul Collins Startup list
[Configuration Manager]
Confirmed=X
Filename=Cnfgldr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank"> SDBOT</a> TROJAN!
Source=Paul Collins Startup list
[Configuration Service]
Confirmed=X
Filename=suchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.treb.html" target="_blank">TREB</a> TROJAN!
Source=Paul Collins Startup list
[Configuration Utility]
Confirmed=N
Filename=CONFIG.EXE
Description=Controls linksys wireless connection. Available from the Desktop
Source=Paul Collins Startup list
[Configuration Utility]
Confirmed=U
Filename=wlanutil.exe
Description=<a href="http://www.netgear.com/index.php" target="_blank">NetGear</a> Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
Source=Paul Collins Startup list
[Configuration Wizard]
Confirmed=X
Filename=Cfgwiz32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_HCKTCK.2K.C" target="_blank">HACKTACK</a> TROJAN! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe)
Source=Paul Collins Startup list
[ConfLoader]
Confirmed=X
Filename=sysconf16.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsdbotfb.html" target=_blank>SDBOT-FB</a> TROJAN!
Source=Paul Collins Startup list
[Conmgr]
Confirmed=N
Filename=conmgr.exe
Description=Starts Winfax pro at startup
Source=Paul Collins Startup list
[ConMgr.exe]
Confirmed=U
Filename=conmgr.exe
Description=Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
Source=Paul Collins Startup list
[Connect2Party]
Confirmed=X
Filename=connect2party.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Connection Manager]
Confirmed=N
Filename=CManager.exe
Description=SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
Source=Paul Collins Startup list
[Cons]
Confirmed=X
Filename=consol32.exe
Description=Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed
Description=System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
Source=Paul Collins Startup list
[Control Panel]
Confirmed=X
Filename=System.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.dani.html" target="_blank">DANI</a> TROJAN!
Source=Paul Collins Startup list
[ControlCenter2.0]
Confirmed=N
Filename=brctrcen.exe
Description=Brother scanner 'Control Center' application - can be started manually
Source=Paul Collins Startup list
[ControlCentreTray]
Confirmed=N
Filename=XWCTray.exe
Description=System Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc
Source=Paul Collins Startup list
[Controlled Resource System Service]
Confirmed=X
Filename=crss.exe
Description=Added by the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/crss/" target=_blank>AGOBOT.GH</a> WORM!
Source=Paul Collins Startup list
[Controller]
Confirmed=N
Filename=WFXCTL32.EXE
Description=From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Description=Added by a vairant of the <a href="http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=65504&VName=TROJ_DELF.DW&VSect=T" target=_blank>DELF.DW</a> TROJAN!
Description=<a href="http://www.pcmag.com/article/0,2997,a=20844,00.asp" target="_blank">Cookie Cop 2</a> from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
Source=Paul Collins Startup list
[Cookie Pal]
Confirmed=U
Filename=CPBRWTCH.EXE
Description=Kookaburra Softwares <a href="http://www.pcmag.com/article/0,2997,s=1626&a=12703,00.asp" target="_blank">Cookie Pal</a> cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
Source=Paul Collins Startup list
[CookieJar]
Confirmed=U
Filename=Cookiejar.exe
Description=<a href="http://www.jasons-toolbox.com/cookiejar.asp" target="_blank">Cookie Jar</a> cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
Description=<a href="http://www.analogx.com/contents/download/network/cookie.htm" target="_blank">CookieWall</a> from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
Source=Paul Collins Startup list
[Cool Desk]
Confirmed=U
Filename=cdesk.exe
Description=<a href="http://www.shelltoys.com/" target="_blank">Cool Desk</a> is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you
Source=Paul Collins Startup list
[CoolDownloads]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=<a href="http://www.doxdesk.com/parasite/MatrixDialer.html" target="_blank">MatrixDialer</a> related
Source=Paul Collins Startup list
[CoolMP3]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=<a href="http://www.doxdesk.com/parasite/MatrixDialer.html" target="_blank">MatrixDialer</a> related
Source=Paul Collins Startup list
[CoolSwitch]
Confirmed=U
Filename=taskswitch.exe
Description=ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
Source=Paul Collins Startup list
[Coolwallpaper]
Confirmed=N
Filename=cwm_tray.exe
Description=<a href="http://coolwallpaper.com/download/index2.html" target=_blank>Cool Wallpaper</a> software allows you to manage high quality photos as desktop wallpaper and screen savers
Description=Copernic <a href="http://www.copernic.com/en/products/desktop-search/index.html" target=_blank>Desktop Search</a> - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures"
Source=Paul Collins Startup list
[CopernicPerUserTaskMgr]
Confirmed=U
Filename=CopernicPerUserTaskMgr.exe
Description=Automatic tasking feature of Copernic Pro multi-search engine tool
Source=Paul Collins Startup list
[Copyright]
Confirmed=N
Filename=mwcpyrt.exe
Description=Displays copyright information on IBM ThinkPads
Source=Paul Collins Startup list
[CoreCenter]
Confirmed=U
Filename=CoreCenter.exe
Description=MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking
Source=Paul Collins Startup list
[CoreCenter]
Confirmed=U
Filename=CORECE~1.EXE
Description=MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking
Source=Paul Collins Startup list
[Corel Colleagues & Contacts Reminders]
Confirmed=N
Filename=cffrem.exe
Description=<a href="http://www.corel.com/printoffice_v1/ccc.htm" target="_blank">Corel Colleagues & Contracts</a> - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of Corel Print Office
Source=Paul Collins Startup list
[Corel Desktop Application Director]
Confirmed=N
Filename=dadx.exe
Description=The Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
Source=Paul Collins Startup list
[Corel Family & Friends reminders]
Confirmed=N
Filename=CFFREM.EXE
Description=<a href="http://www.corel.com/products/graphicsandpublishing/phmagic/CFF.htm" target="_blank">Corel Family & Friends</a> - all-in-one calender, address book and list manager. Part of Corel Print House Magic
Source=Paul Collins Startup list
[Corel Registration]
Confirmed=N
Filename=Remind32.exe
Description=If you don't want to register Corel products and be reminded about it every 2 weeks disable it
Source=Paul Collins Startup list
[Corel Registration Reminder]
Confirmed=N
Filename=Remind32.exe
Description=If you don't want to register Corel products and be reminded about it every 2 weeks disable it
Source=Paul Collins Startup list
[Corel Reminder]
Confirmed=N
Filename=NAVBROWSER.EXE
Description=If you don't want to register Corel products and be reminded about it every 2 weeks disable it
Source=Paul Collins Startup list
[CorelCENTRAL 10]
Confirmed=N
Filename=I_26dadCC.exe
Description=<a href="http://www3.corel.com/cgi-bin/gx.cgi/AppLogic+FTContentServer?pagename=Corel/Product/Feature&fid=CC1ZX1WPOP4" target="_blank">CorelCENTRAL 10</a> - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs
Source=Paul Collins Startup list
[CorelMedia FoldersIndexer8]
Confirmed=N
Filename=MFindexer.exe
Description=Part of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
Source=Paul Collins Startup list
[CorelMedia FoldersIndexer8]
Confirmed=N
Filename=MFINDE~1.EXE
Description=Part of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
Source=Paul Collins Startup list
[CoreSrv]
Confirmed=X
Filename=coresrv.exe
Description=Some IRC trojans/worms use this - see <a href="http://lockdowncorp.com/bots/" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[CORESYS]
Confirmed=?
Filename=coresys.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[CorrectConnect]
Confirmed=N
Filename=CConnect.exe
Description=Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
Source=Paul Collins Startup list
[cosine]
Confirmed=X
Filename=cosine.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotsw.html" target=_blank>RBOT-SW</a> WORM!
Description=Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required
Source=Paul Collins Startup list
[CountrySelection]
Confirmed=N
Filename=pctptt.exe
Description=Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required
Source=Paul Collins Startup list
[Coupon Offers]
Confirmed=?
Filename=??
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[couponica]
Confirmed=X
Filename=couponica.exe
Description=Adware - see <a href="http://vil.nai.com/vil/content/v_100077.htm#top" target="_blank">here</a>
Source=Paul Collins Startup list
[CP32NOT]
Confirmed=U
Filename=CP32BTN.EXE
Description=For the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
Source=Paul Collins Startup list
[CPA9P2PSERVER]
Confirmed=?
Filename=CPA9P2PS.exe
Description=<font color="#FF0000">Found on a Compaq Presario but what is it?</font>
Source=Paul Collins Startup list
[CPATR10]
Confirmed=U
Filename=CPATR10.EXE
Description=Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast
Source=Paul Collins Startup list
[CPBrWtch]
Confirmed=U
Filename=CPBrWtch.exe
Description=Kookaburra Softwares <a href="http://www.pcmag.com/article/0,2997,s=1626&a=12703,00.asp" target="_blank">Cookie Pal</a> cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
Source=Paul Collins Startup list
[CPD_EXE]
Confirmed=Y
Filename=CPD.EXE
Description=Firewall bundled with McAfee VirusScan 6.*
Description=<font color="#FF0000">CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?</font>
Source=Paul Collins Startup list
[CPQAcDc]
Confirmed=Y
Filename=CPQAcDc.exe
Description=Compaq PowerCon power management software for laptops
Source=Paul Collins Startup list
[CPQAlert]
Confirmed=U
Filename=CPQAlert.exe
Description=Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See <a href="http://www.compaq.com/products/servers/management/cim-description.html" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[CPQBootPerfDB]
Confirmed=N
Filename=CPQBootPerfDB.EXE
Description=See the entry for Compaq Message Server
Source=Paul Collins Startup list
[CPQCalib]
Confirmed=Y
Filename=CPQCalib.exe
Description=Compaq PowerCon power management software for laptops
Source=Paul Collins Startup list
[CPQDFWAG]
Confirmed=N
Filename=CpqDfwAg.exe
Description=For Compaq PC's. Runs Compaq diagnostics on every boot
Source=Paul Collins Startup list
[CPQEASYACC]
Confirmed=U
Filename=cpqeadm.exe
Description=For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Source=Paul Collins Startup list
[cpqeaui]
Confirmed=U
Filename=cpqeaui.exe
Description=For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Source=Paul Collins Startup list
[cpqek]
Confirmed=U
Filename=kcpqek.exe
Description=For Compaq PC's. <a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank"> Easy Access</a> button support for the keyboard
Source=Paul Collins Startup list
[CPQInet Runtime Service]
Confirmed=U
Filename=CpqInet.exe
Description=For Compaq PC's. Allows AOL and Compuserve to use the <a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank"> Easy Access</a> buttons for the internet. Is not required if you don't use the ISP providers
Source=Paul Collins Startup list
[CPQINKAGENT]
Confirmed=N
Filename=cpqinkag.exe
Description=That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)
Source=Paul Collins Startup list
[cpqns]
Confirmed=U
Filename=cpqnpcss.exe
Description=Related to Compaq.Net - not required if you don't use that
Source=Paul Collins Startup list
[Cpqset]
Confirmed=N
Filename=Cpqset.exe
Description=Default settings software in Hewlett Packard notebook
Source=Paul Collins Startup list
[CPQSTUTFIX]
Confirmed=Y
Filename=stutfix.exe
Description=For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it <a href="files/StutFix.exe">here</a>. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton
Source=Paul Collins Startup list
[cpr]
Confirmed=X
Filename=cpr
Description=Adroar.com adware downloader
Source=Paul Collins Startup list
[CPU Manager]
Confirmed=X
Filename=cpumgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.pandem.b.worm.html" target="_blank">PANDEM.B</a> WORM!
Source=Paul Collins Startup list
[CPUcool]
Confirmed=U
Filename=Cpucool.exe
Description=Program to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Cpusave]
Confirmed=X
Filename=Cpusave.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Cpusave32]
Confirmed=X
Filename=Cpusave32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[cqlyg]
Confirmed=X
Filename=world_cup_.bat
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BAT_WCUP.A" target="_blank">WCUP.A</a> WORM!
Source=Paul Collins Startup list
[CQSCP2P SERVER]
Confirmed=?
Filename=??
Description=<font color="#FF0000">"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed</font>
Source=Paul Collins Startup list
[CQSCP2PS]
Confirmed=?
Filename=??
Description=<font color="#FF0000">"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed</font>
Description=<a href="http://www.reallusion.com/crazytalk/default.asp" target="_blank">CrazyTalk</a> from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS
Source=Paul Collins Startup list
[CRC Value Verifier]
Confirmed=X
Filename=crsss32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[CRC Value Verifier]
Confirmed=X
Filename=Crsss64.exe
Description=Added by the <a href="http://www.sophos.com.au/virusinfo/analyses/w32rbotny.html" target=_blank>RBOT-NY</a> WORM!
Source=Paul Collins Startup list
[CRC Value Verifier]
Confirmed=X
Filename=svchost32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotoa.html" target=_blank>RBOT-OA</a> WORM!
Source=Paul Collins Startup list
[Creata Mail]
Confirmed=U
Filename=JMSrvr.exe
Description=<a href="http://www.bluemountain.com/mail/index.pd" target=_blank>Creata_Mail</a>. Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express
Source=Paul Collins Startup list
[Create A Monster]
Confirmed=X
Filename=createAMonster.exe
Description=Kudd.com CreateAMonster. Reportedly stealth installed and <a href="http://sarc.com/avcenter/venc/data/adware.look2me.html" target=_blank>Look2Me</a> adware related
Source=Paul Collins Startup list
[CreateCD]
Confirmed=N
Filename=Createcd.exe
Description=Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
Source=Paul Collins Startup list
[CreateCD50]
Confirmed=N
Filename=Createcd50.exe
Description=Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
Source=Paul Collins Startup list
[Creative AGP Wizard]
Confirmed=N
Filename=agpwiz.exe
Description=Part of Creative's BlasterControl
Source=Paul Collins Startup list
[Creative Launcher]
Confirmed=N
Filename=CTLauncher.exe
Description=For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
Source=Paul Collins Startup list
[Creative MediaSource Go]
Confirmed=N
Filename=CTCMSGo.exe
Description="Creative <a href="http://www.soundblaster.com/mediasource/" target="_blank"> MediaSource</a> playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats"
Source=Paul Collins Startup list
[Creative PCI Audio Configuration Utility]
Confirmed=N
Filename=starter.exe
Description=System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on <a href="http://www.pacs-portal.co.uk/startup_pages/starter_exe.htm" target="_blank">this</a> special page. Similar to EnsoniqMixer
Source=Paul Collins Startup list
[Creative Service for CDROM Access]
Confirmed=N
Filename=Ctsvccda.exe
Description=Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs
Source=Paul Collins Startup list
[Creative WebCam Tray]
Confirmed=N
Filename=Camtray.exe
Description=Creative WebCam tray control - can be started manually
Source=Paul Collins Startup list
[Creative.exe]
Confirmed=X
Filename=Creative.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.prolin.worm.html" target="_blank">PROLIN</a> WORM!
Source=Paul Collins Startup list
[CreativeDiscNotifier]
Confirmed=N
Filename=CTNOTIFY.EXE
Description=For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[CreativeMixer]
Confirmed=U
Filename=CTMIX32.EXE
Description=Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon
Source=Paul Collins Startup list
[CriticalUpdate]
Confirmed=N
Filename=Wucrtupd.exe
Description=MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
Source=Paul Collins Startup list
[cronos]
Confirmed=X
Filename=MARCO!.SCR
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.G" target="_blank">OPASERV.G</a> WORM!
Source=Paul Collins Startup list
[Crusty]
Confirmed=X
Filename=dmcpl.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.rusty@m.html" target="_blank">RUSTY</a> WORM!
Source=Paul Collins Startup list
[Cryptographic Service]
Confirmed=X
Filename=******.exe [* = random char]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.w.html" target="_blank">KORGO.W</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.x.html" target="_blank">KORGO.X</a> or <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39581" target="_blank">KORGO.AB</a> WORMS!
Source=Paul Collins Startup list
[Crystal 3D Audio Control]
Confirmed=?
Filename=CWD3DSND.EXE
Description=Crystal 3D Audio sound driver. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[csaRem]
Confirmed=N
Filename=spqmdmui.exe
Description=Compaq modem country selection
Source=Paul Collins Startup list
[CSAV_CheckViruses]
Confirmed=Y
Filename=vchk.exe.exe
Description=Part of <a href="http://www.authentium.com/solutions/products/commandantivirus.cfm" target="_blank">Command AntiVirus</a>
Source=Paul Collins Startup list
[csc]
Confirmed=?
Filename=csc.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[CSINJECT.EXE]
Confirmed=U
Filename=CSINJECT.EXE
Description=Part of Quarterdeck/Norton CleanSweep. For a full description see <a href="http://service1.symantec.com/SUPPORT/cleansweep.nsf/docid/1999022413295728" target="_blank">here</a>. An excerpt - "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes."
Source=Paul Collins Startup list
[csrsc]
Confirmed=X
Filename=csrsc.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[CSRSS]
Confirmed=X
Filename=CSRSS.EXE
Description=Search page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the valid Client Server Runtime Subsystem (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a>) process, which provides text window support, shutdown, and hard-error handling
Source=Paul Collins Startup list
[CSRSS Loader]
Confirmed=X
Filename=csrsss.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.TX" target=_blank>AGOBOT.TX</a> WORM!
Source=Paul Collins Startup list
[CSRSWIN]
Confirmed=X
Filename=[trojan filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.winshell.50.html" target="_blank">WINSHELL.50</a> TROJAN!
Source=Paul Collins Startup list
[CSRSX]
Confirmed=X
Filename=[trojan filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.winshell.50.b.html" target="_blank">WINSHELL.50.B</a> TROJAN!
Source=Paul Collins Startup list
[CSScheduleCheck]
Confirmed=Y
Filename=SCHWIZEX.EXE
Description=Part of <a href="http://www.imaginelan.com/configsafe/index.html" target="_blank"> ConfigSafe</a> - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
Source=Paul Collins Startup list
[csss]
Confirmed=X
Filename=Csss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.balick.trojan.html" target="_blank">BALICK</a> TROJAN!
Source=Paul Collins Startup list
[CSS_Central]
Confirmed=U
Filename=CSS_1631.EXE
Description=CSS Communication Agent (95 Host) from <a href="http://www.commandcom.com/enterprise/csscntrl.html" target="_blank">Command Software Systems</a> "CSS CentralÖ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console."
Source=Paul Collins Startup list
[CSV10P70]
Confirmed=X
Filename=CSv10P070.exe
Description=<a href="http://doxdesk.com/parasite/ClearSearch.html" target=_blank>ClearSearch</a> adware related
Source=Paul Collins Startup list
[CSV7P26]
Confirmed=X
Filename=CSV7P26.exe
Description=<a href="http://doxdesk.com/parasite/ClearSearch.html" target=_blank>ClearSearch</a> adware related
Source=Paul Collins Startup list
[CSV7P70]
Confirmed=X
Filename=CSV7P070.exe
Description=<a href="http://doxdesk.com/parasite/ClearSearch.html" target=_blank>ClearSearch</a> adware related
Source=Paul Collins Startup list
[CSV7P91]
Confirmed=X
Filename=CSV7P91.exe
Description=<a href="http://doxdesk.com/parasite/ClearSearch.html" target=_blank>ClearSearch</a> adware related
Source=Paul Collins Startup list
[ct]
Confirmed=Y
Filename=ct.exe
Description=ct.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it
Source=Paul Collins Startup list
[CTAVTray]
Confirmed=N
Filename=CTAvTray.exe
Description=For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
Source=Paul Collins Startup list
[CTDVDDet]
Confirmed=N
Filename=CTDVDDet.exe
Description=Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
Source=Paul Collins Startup list
[CTDVDDet]
Confirmed=N
Filename=CTDetect.exe
Description=Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
Source=Paul Collins Startup list
[ctfmon]
Confirmed=U
Filename=ctfmon.exe
Description=CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;282599">here</a
Source=Paul Collins Startup list
[ctfmon]
Confirmed=X
Filename=taskmgr32*.exe [* = number]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.sowsat.b@mm.html" target="_blank">SOWSAT.B</a> WORM!
Source=Paul Collins Startup list
[Ctfmon.exe]
Confirmed=X
Filename=ctfmon32.exe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related - hijacking to Slawsearch.com
Source=Paul Collins Startup list
[CTHELPER]
Confirmed=U
Filename=CTHELPER.EXE
Description=CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with CreativeÆs sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
Source=Paul Collins Startup list
[CTime]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.httpdos.html" target="_blank">HTTPDOS</a> TROJAN!
Source=Paul Collins Startup list
[CTin10]
Confirmed=X
Filename=CTin10.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.e.html" target="_blank">BANCOS.E</a> TROJAN!
Source=Paul Collins Startup list
[CTPDPSRV]
Confirmed=?
Filename=CTPDPSRV.EXE
Description=Printer driver (in the WINDOWSSystem32spoolDRIVERSW32X86 folder).<font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[CTRegRun]
Confirmed=N
Filename=CTRegRun.exe
Description=For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
Source=Paul Collins Startup list
[CtrlVol]
Confirmed=U
Filename=CtrlVol.exe
Description=Acer's on screen volume control using the Fn key
Source=Paul Collins Startup list
[CTStartup]
Confirmed=N
Filename=CTEaxSpl.exe
Description=Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
Source=Paul Collins Startup list
[CTsysVol]
Confirmed=U
Filename=CTSYSVOL.exe
Description=Creative sound card volume controls
Source=Paul Collins Startup list
[cttdpsrv]
Confirmed=?
Filename=cttdpsrv.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[cuagentExe]
Confirmed=Y
Filename=Cuagent.exe
Description=<a href="http://www.command.co.uk/html/products/csav/index.cfm">Command Antivirus</a> related
Source=Paul Collins Startup list
[cuo]
Confirmed=X
Filename=cuo.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BUGBEAR.A" target="_blank">BUGBEAR.A</a> WORM!
Source=Paul Collins Startup list
[cursor]
Confirmed=N
Filename=Screendragon_VS_Taskbar.exe
Description=<a href="http://www.screendragon.com/" target="_blank">ScreenDragon</a> video player
Source=Paul Collins Startup list
[CursorXP]
Confirmed=N
Filename=CursorXP.exe
Description=<a href="http://www.stardock.com/products/cursorxp/" target="_blank">CursorXP</a> from Stardock - tool for creating mouse cursors
Source=Paul Collins Startup list
[Customizer2000]
Confirmed=U
Filename=logon.exe
Description=Automatic logon feature of <a href="http://www.hot-shareware.com/utilities/customizer-2000/" target="_blank">Customizer 2000</a> - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes"
Source=Paul Collins Startup list
[CuteMX]
Confirmed=N
Filename=CuteMX.EXE
Description=File sharing utility
Source=Paul Collins Startup list
[cvmonitor.exe]
Confirmed=X
Filename=cvmonitor.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BV" target="_blank">SDBOT.BV</a> WORM!
Source=Paul Collins Startup list
[CVPND]
Confirmed=Y
Filename=cvpnd.exe
Description=Sub-system used by Cisco VPN client for making a connection to a remote IPSec server
Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
Source=Paul Collins Startup list
[cwbinhlp]
Confirmed=N
Filename=cwbinhlp.exe
Description=Client Access Help Registry Update Function - part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
Source=Paul Collins Startup list
[cwbsvstr]
Confirmed=N
Filename=cwbsvstr.exe
Description=Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
Source=Paul Collins Startup list
[cwbwlwiz]
Confirmed=?
Filename=cwbwlwiz.exe
Description=Welcome wizard launcher - Part of IBM's <a href="http://www-1.ibm.com/servers/eserver/iseries/access/" target="_blank">iSeries</a> (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. <font color="#FF0000">What does it do and is it required?</font>
Description=Autodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
Source=Paul Collins Startup list
[Cyber]
Confirmed=N
Filename=cyberchk.exe
Description=Part of Belkins "Multimedia Cleaning Kit" and is
automatically installed when you run their optical disk drive cleaning utility - to remind
you to clean your drive after "x" amount of time has passed
Source=Paul Collins Startup list
[Cyber Trio]
Confirmed=U
Filename=showmode.exe
Description=From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs
Description=<a href="http://www.cyberlat.com/ramcleaner/" target="_blank">CyberLat RAM Cleaner</a> is a program that Frees, Optimizes and Defrags your system's wasted memory (RAM). Some users swear by programs such as this but I suggest you read <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[CyberMedia Agent]
Confirmed=N
Filename=CMAGENT.EXE
Description=Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled
Source=Paul Collins Startup list
[CyberWolf]
Confirmed=X
Filename=CyberWolf.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.kickin.a@mm.html" target="_blank"> KICKIN.A</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_CYDOG.C" target="_blank">CYDOG.C</a>) WORM!
Source=Paul Collins Startup list
[CyDoor]
Confirmed=X
Filename=CD_Load.exe
Description=Adware. Check <a href="http://www.cexx.org/cydoor.htm" target="_blank">here</a> for information about Cy-Door and <a href="http://www.lavasoft.de/software/adaware/" target="_blank">here</a> for a program that can remove it
Source=Paul Collins Startup list
[CydoorUpdate]
Confirmed=X
Filename=CD_Load.exe
Description=Adware. Check <a href="http://www.cexx.org/cydoor.htm" target="_blank">here</a> for information about Cy-Door and <a href="http://www.lavasoft.de/software/adaware/" target="_blank">here</a> for a program that can remove it
Description=D-Link Air Plus Wireless PC modem connection monitor
Source=Paul Collins Startup list
[D066UUtility]
Confirmed=N
Filename=D066UUTY.EXE
Description=TWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
Source=Paul Collins Startup list
[d3dupdate.exe]
Confirmed=X
Filename=bbeagle.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.a@mm.html" target="_blank">BEAGLE.A</a> WORM!
Source=Paul Collins Startup list
[D4]
Confirmed=U
Filename=D4.exe
Description=<a href="http://www.thinkman.com/dimension4/index.html" target="_blank">Dimension 4</a> - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
Source=Paul Collins Startup list
[DACONFIGEXE]
Confirmed=N
Filename=daconfig.exe
Description=3Com NIC Diagnostics. Available via Start -> Programs
Source=Paul Collins Startup list
[DadApp]
Confirmed=Y
Filename=dadapp.exe
Description="DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from Dell
Source=Paul Collins Startup list
[Daemon]
Confirmed=N
Filename=DAEMON32.EXE
Description=Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
Source=Paul Collins Startup list
[Daemon]
Confirmed=U
Filename=Daemon.exe
Description=<a href="http://www.daemon-tools.net/main.htm" target="_blank">Daemon Tools</a> - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
Source=Paul Collins Startup list
[DAEMON Tools-1033]
Confirmed=U
Filename=Daemon.exe
Description=<a href="http://www.daemon-tools.net/main.htm" target="_blank">Daemon Tools</a> - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
Source=Paul Collins Startup list
[Daily Planner]
Confirmed=N
Filename=dayplan.exe
Description=Daily Planner - discontinued, and now part of <a href="http://www.kmcsonline.com/index.html" target="_blank">KMCS Deluxe System Suite</a>. Tool to plan your days, and check activities off as you complete them
Source=Paul Collins Startup list
[Danton*]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.danton.html" target="_blank">DANTON</a> TROJAN! where * = random number
Source=Paul Collins Startup list
[Dap]
Confirmed=N
Filename=DAP.exe
Description=<a href="http://www.speedbit.com/DAPDL.asp?" target="_blank">Download Accelerator Plus</a> from SpeedBit - download manager/accelerator
Source=Paul Collins Startup list
[DarkDevil.Grasiele.BR]
Confirmed=X
Filename=Grasiele.VBS
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.lembra@mm.html" target="_blank">LEMBRA</a> WORM!
Source=Paul Collins Startup list
[DashIE]
Confirmed=?
Filename=N/A
Description=<font color="#FF0000">Could be related to "Dash Power Shopping" tool bar in IE?</font>
Source=Paul Collins Startup list
[dasxdads]
Confirmed=X
Filename=fsdqd.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.biq.html" target="_blank">GAOBOT.BIQ</a> WORM!
Source=Paul Collins Startup list
[Data]
Confirmed=X
Filename=System.dat.vbs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.biscuit.a@mm.html" target="_blank">BISCUIT.A</a> WORM!
Source=Paul Collins Startup list
[Data LifeGuard]
Confirmed=N
Filename=BACKWE~1.EXE
Description=Data LifeGuard diagnostic tools for Western Digital's series of hard drives
Source=Paul Collins Startup list
[Data LifeGuard LifeLine Lite installer]
Confirmed=N
Filename=DLGLI.EXE
Description=Backweb installer - see <a href="http://www.cexx.org/dlgli.htm" target="_blank"> here</a>
Source=Paul Collins Startup list
[Data789]
Confirmed=X
Filename=Regedit.exe ....data789.tmp
Description=Homepage hijacker
Source=Paul Collins Startup list
[DATABASE MySql]
Confirmed=X
Filename=[path] repcale.exe [path] beird.exe
Description=Added by a variant of the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RANDON.AN" target=_blank>RANDON.AN</a> WORM!
Source=Paul Collins Startup list
[DataCaching]
Confirmed=N
Filename=FlashKsk.exe
Description=<a href="http://www.smartdisk.com" target="_blank">SmartMedia Card</a> management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon
Source=Paul Collins Startup list
[DataLayer]
Confirmed=U
Filename=DataLayer.exe
Description=Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
Source=Paul Collins Startup list
[DataViz Messenger]
Confirmed=N
Filename=DvzMsgr.exe
Description=<a href="http://www.dataviz.com/products/documentstogo/" target="_blank">DataViz Documents to Go</a> - "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"
Source=Paul Collins Startup list
[Datcheck]
Confirmed=X
Filename=datcheck.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/keypanic.trojan.html" target="_blank">KEYPANIC</a> TROJAN!
Source=Paul Collins Startup list
[Date Manager]
Confirmed=X
Filename=datemanager.exe
Description=<a href="http://www.date-manager.com/" target="_blank">Date Manager</a> - calender program. Spyware/adware based provided by The Gator Corporation
Source=Paul Collins Startup list
[Datechecker]
Confirmed=?
Filename=N/A
Description=<font color="#FF0000">Could be related to <a href="http://www.simtel.net/pub/pd/9379.html" target="_blank">this</a>?</font>
Source=Paul Collins Startup list
[DateMakerIntl]
Confirmed=X
Filename=DateMakerIntl.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[DAupdate]
Confirmed=X
Filename=DAupdate.exe
Description=NavEnhance adware
Source=Paul Collins Startup list
[DAW9532.exe]
Confirmed=?
Filename=DAW9532.EXE
Description=Loaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[DayToday]
Confirmed=U
Filename=DAYTODAY.EXE
Description=<a href="http://www.locutuscodeware.com/daytoday.htm" target="_blank">DayToday</a> from RoboMagic Software Corp. Displays the date on the taskbar
Source=Paul Collins Startup list
[DAZEL Delivery Agent]
Confirmed=U
Filename=DcDaemon.exe
Description=Control and send documents, etc, to any destination - see <a href="http://www.clickly.com/ISSVDO4Z/EN/user/proddet.html?P=888" target="_blank">here</a>
Source=Paul Collins Startup list
[dbserv]
Confirmed=N
Filename=dbserv.exe
Description=Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
Source=Paul Collins Startup list
[DCE Manager]
Confirmed=X
Filename=dcemgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.tumag.html" target="_blank">TUMAG</a> TROJAN!
Source=Paul Collins Startup list
[DCfssvc]
Confirmed=U
Filename=dcfssvc.exe
Description=Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
Source=Paul Collins Startup list
[dcfssve]
Confirmed=U
Filename=dcfssvc.exe
Description=Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
Source=Paul Collins Startup list
[DDCActiveMenu]
Confirmed=N
Filename=DDCActiveMenu.exe
Description=Digital Distribution Channel - formally part of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games delivery service. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=company_art&artid=art20030925_A" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[DDCM]
Confirmed=N
Filename=DDCMan.exe
Description=Digital Distribution Channel - formally part of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games delivery service. Note that WildTanget's <a href="Digital Distribution Channel - formally part of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games delivery service. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=privacy" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[DDCMan]
Confirmed=N
Filename=DDCMan.exe
Description=Digital Distribution Channel - formally part of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games delivery service. Note that WildTanget's <a href="Digital Distribution Channel - formally part of the <a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> on-line games delivery service. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=privacy" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gutta.html" target="_blank">GUBED</a> TROJAN Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[deejay]
Confirmed=X
Filename=forboo.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotay.html" target="_blank">FORBOT-AY</a> WORM!
Source=Paul Collins Startup list
[Default System Research]
Confirmed=X
Filename=vhchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.i.html" target="_blank">TARNO.I</a> TROJAN!
Source=Paul Collins Startup list
[Default web browser]
Confirmed=X
Filename=IexpIore.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojoblivionb.html" target="_blank">OBLIVION.B</a> TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L"
Description=Detects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
Source=Paul Collins Startup list
[Delay]
Confirmed=U
Filename=delayrun.exe
Description=On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
Source=Paul Collins Startup list
[Delayrun]
Confirmed=U
Filename=delayrun.exe
Description=On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
Source=Paul Collins Startup list
[delcab]
Confirmed=?
Filename=deltreew.exe C:\cabs
Description=<font color="#FF0000">??<font>
Source=Paul Collins Startup list
[Delete Me]
Confirmed=X
Filename=worm.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.doomhunter.html" target="_blank">DOOMHUNTER</a> WORM!
Source=Paul Collins Startup list
[Dell AIO Printer A***]
Confirmed=N
Filename=dlbabmgr.exe
Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
Source=Paul Collins Startup list
[Dell AIO Printer A***]
Confirmed=N
Filename=dlbfbmgr.exe
Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
Source=Paul Collins Startup list
[Dell AIO Printer A***]
Confirmed=N
Filename=dlbkbmgr.exe
Description=Dell AIO Printer A*** related (*** = model). Not Required at Startup
Source=Paul Collins Startup list
[Dell Alert]
Confirmed=N
Filename=DAMon.exe
Description="Dell Alert" utility, that's supposed to make interaction with Support easier
Source=Paul Collins Startup list
[DellDMI]
Confirmed=?
Filename=delldmi.exe
Description=<font color="#FF0000">Possibly part of <a href="http://docs.us.dell.com/docs/software/smcliins/cli60/en/ug/intro.htm" target="_blank">Dell OpenManage Client Instrumentation</a> - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?</font>
Source=Paul Collins Startup list
[DELLMMKB]
Confirmed=U
Filename=DELLMMKB.EXE
Description=Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
Source=Paul Collins Startup list
[DellSC]
Confirmed=N
Filename=dellsc.exe
Description=Dell Solution Center - web-based troubleshooting tools and educational offerings
Source=Paul Collins Startup list
[DellTouch]
Confirmed=U
Filename=MMKeybd.exe
Description=Dell multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[DellTouch]
Confirmed=U
Filename=DELLMMKB.EXE
Description=Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
Description=Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. <font color="#FF0000">Deletes temporary files once an installation is complete?</font>
Source=Paul Collins Startup list
[DeltTray]
Confirmed=N
Filename=deltray.exe
Description=System Tray access to the control panel for the M-Audio <a href="http://www.midiman.net/products/m-audio/delta44.php" target="_blank">Delta 44</a> PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[demon]
Confirmed=?
Filename=demon.exe
Description=Part of the French Wanadoo ADSL extense pack. <font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[DepFrez]
Confirmed=U
Filename=frzstate.exe
Description=<a href="http://www.winselect.com/pages/deepfreeze/dpfrz_info.htm?B13=More+Info" target="_blank">Deep Freeze</a> from Hyper Technologies. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example
Source=Paul Collins Startup list
[Description of Shortcuts]
Confirmed=?
Filename=*.exe
Description=<font color="#FF0000">* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e., 4EBD23F5 is actually Works Calender Reminder (found via a registry search)</font>
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.bookmarker.html" target="_blank">BOOKMARKER</a> TROJAN!
Source=Paul Collins Startup list
[desktop]
Confirmed=X
Filename=desktop.exe
Description=Added by the <a href="http://www.f-secure.com/v-descs/sdbot_md.shtml" target=_blank>SDBOT.MD</a> WORM!
Source=Paul Collins Startup list
[Desktop Architect]
Confirmed=N
Filename=DATRAY.EXE
Description=Desktop theme manager available <a href="http://download.com.com/3000-2326-5630015.html?tag=list" target="_blank">here</a> - for managing the desktop appearance, fonts, sounds, etc
Source=Paul Collins Startup list
[Desktop Plant]
Confirmed=N
Filename=AZARE10S.PLT
Description=Vritual plant from <a href="http://www.desksoft.com/DesktopPlant.htm" target="_blank">here</a> - this version is an Azalea, there are others so the filename may be different
Source=Paul Collins Startup list
[Desktop Search]
Confirmed=X
Filename=desktop.exe
Description=iSearch "Desktop Search" hijacker
Source=Paul Collins Startup list
[Desktop Service Centre]
Confirmed=?
Filename=DSC.exe
Description=OptusNet DSL or Dial-Up connection software - <font color="#FF0000">is it required?</font>
Source=Paul Collins Startup list
[Desktop Weather]
Confirmed=N
Filename=THE WEATHER CHANNEL.exe
Description=<a href="http://www.weather.com/services/desktop.html?from=tutorial" target="_blank">Desktop Weather</a> by The Weather Channel - provides current temperature, conditions, alerts, etc
Source=Paul Collins Startup list
[Desktop Weather 3]
Confirmed=N
Filename=THE WEATHER CHANNEL.exe
Description=<a href="http://www.weather.com/services/desktop.html" target="_blank">Desktop Weather 3</a> by The Weather Channel - provides current temperature, conditions, alerts, etc
Source=Paul Collins Startup list
[Desktop Weather 3]
Confirmed=N
Filename=THEWEA~1.EXE
Description=<a href="http://www.weather.com/services/desktop.html" target="_blank">Desktop Weather 3</a> by The Weather Channel - provides current temperature, conditions, alerts, etc
Source=Paul Collins Startup list
[desktopmgr]
Confirmed=N
Filename=desktopmgr.exe
Description=Synchronisation manager for the cradles for the <a href="http://www.rim.net/products/index.shtml" target="_blank">Research In Motion</a> range of wireless handhelds, including the "Blackberry"
Source=Paul Collins Startup list
[DesktopX]
Confirmed=U
Filename=DESKTOPX.EXE
Description=A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking
Source=Paul Collins Startup list
[deskup]
Confirmed=N
Filename=deskup.exe
Description=Adds Iomega Zip drive icons to the desktop
Source=Paul Collins Startup list
[detect]
Confirmed=U
Filename=idetect.exe
Description=<a href="http://www.clasys.com/internet_turbo.html" target="_blank">iNTERNET Turbo</a> from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled
Source=Paul Collins Startup list
[detect]
Confirmed=?
Filename=turbodetect.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Detector]
Confirmed=N
Filename=detector.exe
Description=USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software
Source=Paul Collins Startup list
[DEventAgent]
Confirmed=U
Filename=eventagt.exe
Description=DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
Source=Paul Collins Startup list
[Device Configuration Loader]
Confirmed=X
Filename=msdvc32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Device Detector]
Confirmed=U
Filename=DevDetect.exe
Description=Watches for external digital imaging products being connected from <a href="http://www.acdsystems.com/English/index.htm" target="_blank">ACD Systems</a>
Source=Paul Collins Startup list
[DeviceDiscovery]
Confirmed=U
Filename=hpotdd01.exe
Description=Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
Source=Paul Collins Startup list
[DevicePath]
Confirmed=X
Filename=Proyecto1.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gruel@mm.html" target="_blank">GRUEL</a> WORM!
Source=Paul Collins Startup list
[DevicePath]
Confirmed=X
Filename=Root.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gruel@mm.html" target="_blank">GRUEL</a> WORM!
Source=Paul Collins Startup list
[Devices]
Confirmed=U
Filename=olesvr.exe
Description=Salfeld <a href="http://www.salfeld.com/parental_control_overwiew.htm" target="_blank">Child Control 2003</a> - parental control software
Source=Paul Collins Startup list
[devldr16]
Confirmed=U
Filename=devldr16.exe
Description=Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Source=Paul Collins Startup list
[Devlog]
Confirmed=?
Filename=??
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Devlog]
Confirmed=?
Filename=devlog.exe
Description=Apparently mainboard/chipset related, by a French company called AS Media - <font color="#FF0000"> what exactly is it, and is it required</font>
Source=Paul Collins Startup list
[DGJM]
Confirmed=?
Filename=DGJM.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[dguard]
Confirmed=N
Filename=dguard.exe
Description=eAcceleration Stop-Sign related - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">note</a>
Source=Paul Collins Startup list
[DHCP Server]
Confirmed=X
Filename=regsvr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpr.html" target=_blank>RBOT-PR</a> WORM!
Source=Paul Collins Startup list
[dhcpagnt]
Confirmed=Y
Filename=dhcpagnt.exe
Description=Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
Source=Paul Collins Startup list
[DHNUXB]
Confirmed=?
Filename=DHNUXB.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[diagent]
Confirmed=N
Filename=diagent.exe
Description=System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
Source=Paul Collins Startup list
[Dial22]
Confirmed=X
Filename=dlm.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Dial33]
Confirmed=X
Filename=dlm.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Dialer]
Confirmed=X
Filename=rundll32.exe msa32chk.dll
Description=Unidentfied malware
Source=Paul Collins Startup list
[Dialer Control]
Confirmed=U
Filename=dc.exe
Description=<a href="http://www.dialer-control.de/" target="_blank">Dialer-Control</a>. Detects and protects from premium rate p0rn diallers
Source=Paul Collins Startup list
[Dialer Detect]
Confirmed=U
Filename=dd.exe
Description=<a href="http://www.dialerdetect.nl/english/main.htm" target=_blank>DialerDetect</a> detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing it
Source=Paul Collins Startup list
[Dialgo SDK]
Confirmed=U
Filename=PhoneAnswer.exe
Description=Dialgo Wave Modem ActiveX - "Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis"
Source=Paul Collins Startup list
[DialNet]
Confirmed=X
Filename=mxt32.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Dialog Box Assistant]
Confirmed=N
Filename=OSDEx.exe
Description=<a href="http://www.dualitysoft.com/osdex/" target="_blank">Dialog Box Assistant</a> from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders
Source=Paul Collins Startup list
[Dialog Helper]
Confirmed=N
Filename=PDDLGHLP.EXE
Description=Dialog Helper from <a href="http://www.ontrack.com/powerdesk/">PowerDesk Pro</a> by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs
Source=Paul Collins Startup list
[DIECOX]
Confirmed=X
Filename=csrss.exe
Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100826.htm" target="_blank">ATM.GEN</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[DietK]
Confirmed=U
Filename=DietK.exe
Description=<a href="http://www.dietk.com/" target="_blank">DietK</a> - add-on for Kazaa Media Desktop; "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results"
Source=Paul Collins Startup list
[DigiCell]
Confirmed=U
Filename=DigiCell.exe
Description=MSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center"
Source=Paul Collins Startup list
[DigiD]
Confirmed=X
Filename=DigitalSound.exe
Description=Adware downloader
Source=Paul Collins Startup list
[DigiGuide]
Confirmed=N
Filename=CLIENT.EXE
Description=TV guide and reminder
Source=Paul Collins Startup list
[DigiGuide]
Confirmed=N
Filename=client01.exe
Description=TV guide and reminder
Source=Paul Collins Startup list
[Digital Dashboard]
Confirmed=N
Filename=devgulp.exe
Description=For Compaq PC's. Loads Digital Dashboard options
Source=Paul Collins Startup list
[Digital Line Detect]
Confirmed=N
Filename=DLG.exe
Description=Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
Source=Paul Collins Startup list
[Digital River eBot]
Confirmed=N
Filename=downlo~1.exe
Description=Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more <a href="http://groups.google.com/groups?hl=en&threadm=39727D1B.3754C1D1%40concentric.net&rnum=3&prev=/groups%3Fq%3DDigital%2BRiver%2BeBot%26btnG%3DGoogle%2BSearch%26hl%3Den" target="_blank">here</a>
Description=InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
Source=Paul Collins Startup list
[DigitalWizard Monitor]
Confirmed=N
Filename=dwMon.exe
Description=InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
Source=Paul Collins Startup list
[DIGStream]
Confirmed=N
Filename=digstream.exe
Description=DIGStream Cache Manager - part of <a href="http://espn.go.com/motion/download.html" target="_blank">ESPN Motion</a> and <a href="http://disney.go.com/guestservices/disneymotion/about.html" target="_blank"> Disney Motion</a> that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
Source=Paul Collins Startup list
[Dimension]
Confirmed=U
Filename=Dimension.exe
Description=Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol
Source=Paul Collins Startup list
[Dimension4]
Confirmed=U
Filename=d4.exe
Description=<a href="http://www.thinkman.com/dimension4/index.html" target="_blank">Dimension 4</a> - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
Source=Paul Collins Startup list
[Dino3]
Confirmed=X
Filename=dino3.exe
Description=Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
Source=Paul Collins Startup list
[Dir1]
Confirmed=X
Filename=caKe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.cake.html" target="_blank">CAKE</a> WORM!
Source=Paul Collins Startup list
[Direct settings]
Confirmed=X
Filename=sdchost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdaemonii.html" target=_blank>DAEMONI-I</a> TROJAN!
Source=Paul Collins Startup list
[Direct Update]
Confirmed=U
Filename=DUControl.exe
Description=<a href="http://www.directupdate.net/" target="_blank">DirectUpdate</a> dynamic DNS updater
Source=Paul Collins Startup list
[Direct X Direct3D]
Confirmed=X
Filename=dxd3d.exe
Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[Direct X Opengl]
Confirmed=X
Filename=dxopengl.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotcj.html" target=_blank>RBOT-CJ</a> WORM!
Source=Paul Collins Startup list
[DirectCD]
Confirmed=N
Filename=DirectCD.exe
Description=DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
Source=Paul Collins Startup list
[directs.exe]
Confirmed=X
Filename=directs.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.o@mm.html" target="_blank">BEAGLE.O</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.r@mm.html" target="_blank">BEAGLE.R</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.s@mm.html" target="_blank">BEAGLE.S</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.t@mm.html" target="_blank">BEAGLE.T</a> WORMS!
Source=Paul Collins Startup list
[DIRECTVDSL]
Confirmed=U
Filename=Directvdsl.exe
Description=Starts DirectTV DSL modem at boot up. Can also be started manually
Source=Paul Collins Startup list
[DirectX]
Confirmed=X
Filename=ddhelp32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_BIONET.318" target="_blank">BIONET.318</a> TROJAN! Note - not the DirectX helper which is ddhelp.exe
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=Directx.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.d.html" target="_blank">SDBOT.D</a> TROJAN!
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=Sqlexploit.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.d.html" target="_blank">SDBOT.D</a> TROJAN!
Source=Paul Collins Startup list
[DirectX]
Confirmed=X
Filename=DirectX.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.blaxe.html" target="_blank">BLAXE</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.logpole.html" target="_blank"> LOGPOLE</a> WORMS!
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=NTCmd.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.d.html" target="_blank">SDBOT.D</a> TROJAN!
Source=Paul Collins Startup list
[directx]
Confirmed=X
Filename=PipeCmd.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.d.html" target="_blank">SDBOT.D</a> TROJAN!
Source=Paul Collins Startup list
[DirectX For Microsoft Windows]
Confirmed=X
Filename=dtxservice.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.progent.html" target="_blank">PROGENT</a> TROJAN!
Source=Paul Collins Startup list
[DirectX for Microsoft Windows]
Confirmed=X
Filename=Fservice.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.prorat.html" target="_blank">PRORAT</a> TROJAN!
Source=Paul Collins Startup list
[DirectX for Microsoft Windows]
Confirmed=X
Filename=Sservice.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.prorat.html" target="_blank">PRORAT</a> TROJAN!
Source=Paul Collins Startup list
[DirectX Video Driver]
Confirmed=X
Filename=dxterm5.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32wilaba.html" target=_blank>WILAB-A</a> TROJAN!
Source=Paul Collins Startup list
[DirectX64]
Confirmed=X
Filename=DirectXset.exe
Description=Added by the <a href="http://vil.nai.com/vil/content/v_100098.htm" target="_blank">BROWNEY.A</a> WORM!
Source=Paul Collins Startup list
[Dirkey]
Confirmed=U
Filename=Dirkey.exe
Description=<a href="http://www.protonfx.com/dirkey/" target="_blank">Dirkey</a> - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders
Source=Paul Collins Startup list
[Disable EHCI]
Confirmed=?
Filename=nousb20.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Disc Detector]
Confirmed=N
Filename=CtNotify.exe
Description=For Creative sound cards. Detects when you insert a CD, DVD, etc
Source=Paul Collins Startup list
[disc detector]
Confirmed=?
Filename=qnetquestnotifty.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[discoveg]
Confirmed=?
Filename=discoveg.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[DiscoverDeskshop]
Confirmed=N
Filename=Deskshop.exe
Description=<a href="http://www.dealchecker.com/doc.cfm?OID=1091" target="_blank">Discover Deskshop</a> - single use "virtual" credit card
Source=Paul Collins Startup list
[Disk Master]
Confirmed=X
Filename=[trojan name]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.dister.html" target="_blank">DISTER</a> TROJAN! - a spam relayer
Source=Paul Collins Startup list
[DiskeeperSystray]
Confirmed=N
Filename=DkIcon.exe
Description=<a href="http://www.executive.com/defrag/defrag.asp" target=_blank>DisKeeper</a> defragmentation software - can be started manually
Source=Paul Collins Startup list
[diskinf]
Confirmed=X
Filename=diskinf.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[DISKMON.EXE]
Confirmed=?
Filename=DISKMON.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Disknag]
Confirmed=N
Filename=disknag.exe
Description=Dell program that reminds you to make your backup diskettes
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=Code.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=cat.exe
Description=MS-Connect dialler
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=hit.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Diskstart]
Confirmed=X
Filename=Snt.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Disk_Monitor]
Confirmed=U
Filename=Disk_Monitor.exe
Description=Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader
Source=Paul Collins Startup list
[Display Drivers]
Confirmed=X
Filename=cssrs.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.FX" target="_blank">AGOBOT.FX</a> WORM!
Source=Paul Collins Startup list
[Display Settings]
Confirmed=N
Filename=hptasks.exe
Description=Allows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers
Source=Paul Collins Startup list
[DisplayTrayIcon]
Confirmed=N
Filename=TrayIcon.exe
Description=System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display
Source=Paul Collins Startup list
[Distiller Assistant 3.01]
Confirmed=N
Filename=DISTASST.EXE
Description=From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
Source=Paul Collins Startup list
[Distributed File System]
Confirmed=X
Filename=Dfsvc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.myfip.a.html" target=_blank>MYFIP.A</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.myfip.k.html" target=_blank>MYFIP.K</a> WORMS!
Source=Paul Collins Startup list
[Distributed File System]
Confirmed=X
Filename=kernel32dll.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32myfipc.html" target=_blank>MYFIP-C</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.myfip.k.html" target=_blank>MYFIP.K</a> WORMS!
Source=Paul Collins Startup list
[distributed.net client]
Confirmed=U
Filename=DNETC.EXE
Description=Dsitributed computing projects client from <a href="http://distributed.net/" target="_blank">Distributed.net</a> where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by <a href="http://distributed.net/trojans.html.en" target="_blank">viruses</a>
Source=Paul Collins Startup list
[Dit]
Confirmed=Y
Filename=dit.exe
Description="Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found
Source=Paul Collins Startup list
[DiTask.exe]
Confirmed=N
Filename=DiTask.exe
Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs
Source=Paul Collins Startup list
[Divamon.exe]
Confirmed=?
Filename=Divamon.exe
Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target=_blank>Eicon Networks</a> Diva ISDN or ADSL modem - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[DivX MediaPlayer 7.0]
Confirmed=X
Filename=Dr.DivX.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.g.html" target="_blank">ALADINZ.G</a> TROJAN!
Source=Paul Collins Startup list
[DivX Player]
Confirmed=X
Filename=DivXPlayer.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[DivX Updater]
Confirmed=X
Filename=DivX.Exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.naldem.html" target="_blank">NALDEM</a> TROJAN or MASTAK VIRUS!
Source=Paul Collins Startup list
[Divx4 codec]
Confirmed=X
Filename=devldr32.exe
Description=Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/devldr32/F412" target=_blank>devldr32.exe</a> file
Source=Paul Collins Startup list
[DJREGFIX]
Confirmed=N
Filename=regedit /s c:\hpdjregfix.reg
Description=DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers
Source=Paul Collins Startup list
[DkService]
Confirmed=Y
Filename=DkService.exe
Description=From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled, otherwise you could have problems starting it manually.
Source=Paul Collins Startup list
[DKTime]
Confirmed=X
Filename=dktime.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/downloader.lunii.html" target="_blank">LUNII</a> TROJAN!
Source=Paul Collins Startup list
[Dkware lptt01]
Confirmed=X
Filename=dkware.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[Dkware ml097e]
Confirmed=X
Filename=dkware.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[dkzzixm]
Confirmed=?
Filename=dkzzixm.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[dla]
Confirmed=Y
Filename=tfswctrl.exe
Description=Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
Source=Paul Collins Startup list
[DlaTray]
Confirmed=N
Filename=Dlatray.exe
Description=System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
Source=Paul Collins Startup list
[dlder]
Confirmed=X
Filename=dlder.exe
Description=Advertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dlder.html" target="_blank">here</a>). Reported in the past as a virus
Source=Paul Collins Startup list
[DlDir1]
Confirmed=X
Filename=caKe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.cake.html" target="_blank">CAKE</a> WORM!
Source=Paul Collins Startup list
[DLForcerExe]
Confirmed=?
Filename=DLForcerEXE.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[DLF_00000B00]
Confirmed=N
Filename=Vcdlf.exe
Description=Known to cause problems with "Out of memory" errors (see <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;q303045" target="_blank">here</a>).<font color="#FF0000"> Otherwise, it's purpose is unknown</font>
Source=Paul Collins Startup list
[DLG]
Confirmed=N
Filename=DLGCHBW.exe
Description=Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
Source=Paul Collins Startup list
[DLHelperEXE]
Confirmed=N
Filename=WATCH.exe
Description=Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
Source=Paul Collins Startup list
[DLHelperEXE.exe]
Confirmed=X
Filename=N/A
Description=Downloader for Microgaming/Casino software - stealth installed
Source=Paul Collins Startup list
[Dlite]
Confirmed=X
Filename=dllmanager.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_WOOTBOT.DN" target=_blank>WOOTBOT.DN</a> WORM!
Source=Paul Collins Startup list
[DLL Service Manager]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.rpcbot.f.html" target="_blank">RPCBOT.F</a> TROJAN!
Source=Paul Collins Startup list
[DLL32]
Confirmed=X
Filename=dllmem32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.kwbot.e.worm.html" target="_blank">KWBOT.E</a> WORM!
Source=Paul Collins Startup list
[DllCacherv2]
Confirmed=X
Filename=dllcachev2.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lateda.html" target=_blank>LATEDA</a> TROJAN!
Source=Paul Collins Startup list
[dlldmt]
Confirmed=X
Filename=dlldmt.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[dllhelp]
Confirmed=X
Filename=dllhelp.exe
Description=Added by the <a href="http://www.hacksoft.com.pe/virus/w32_startpage_dq.htm" target="_blank">STARTPAGE.DQ</a> hijacker
Source=Paul Collins Startup list
[dllhelp]
Confirmed=X
Filename=dllhlp.exe
Description=Added by the <a href="http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=123155" target=_blank>Downloader-HI</a> TROJAN!
Source=Paul Collins Startup list
[dllhostxp.exe]
Confirmed=X
Filename=dllhostxp.exe
Description=Browser hijacker and adware downloader
Source=Paul Collins Startup list
[dllreg]
Confirmed=X
Filename=dllreg.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[DLLService32]
Confirmed=X
Filename=dllsvc32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.VX" target=_blank>AGOBOT.VX</a> WORM!
Source=Paul Collins Startup list
[DLT]
Confirmed=?
Filename=dlt.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[dluca]
Confirmed=X
Filename=dluca.exe
Description=Adult content dialler - see <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=11&t=6465&st=15&" target="_blank"> here</a>
Source=Paul Collins Startup list
[dluca]
Confirmed=X
Filename=dluca.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/downloader.dluca.c.html" target="_blank">DLUCA.C</a> TROJAN!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/downloader.dluca.d.html" target="_blank">DLUCA.D</a> TROJAN!
Source=Paul Collins Startup list
[DM mgr]
Confirmed=X
Filename=dm_mgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.jittar.html" target="_blank">JITTAR</a> TROJAN!
Source=Paul Collins Startup list
[DMILDR]
Confirmed=N
Filename=dmildr.exe
Description=Part of <a href="http://docs.us.dell.com/docs/software/smcliins/cli60/en/ug/intro.htm" target="_blank">Dell OpenManage Client Instrumentation</a> - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs
Source=Paul Collins Startup list
[DMISL]
Confirmed=N
Filename=DMISL.EXE
Description=DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See <a href="http://support.intel.com/support/tokenexpress/pro/11601.htm" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[DMISLAPP]
Confirmed=N
Filename=DMISLAPP.exe
Description=DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See <a href="http://support.intel.com/support/tokenexpress/pro/11601.htm" target=_blank>here</a> for more information
Source=Paul Collins Startup list
[Dmsvc32]
Confirmed=X
Filename=Dmsvc32.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_AGOBOT.ABU&VSect=T" target=_blank>AGOBOT.ABU</a> WORM!
Source=Paul Collins Startup list
[dmtdll]
Confirmed=X
Filename=dmtdll.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Description=Unknown, except that it is not necessary. Tends to phone home a lot. DMI related - see <a href="http://www.spywareinfo.com/yabbse/index.php?board=10;action=display;threadid=1137;start=0" target="_blank">here</a>
Source=Paul Collins Startup list
[DNE Binding Watchdog]
Confirmed=Y
Filename=rundll dnes.dll, DnDneCheckBindings
Description=Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
Source=Paul Collins Startup list
[DNE DUN Watchdog]
Confirmed=Y
Filename=rundll dnes.dll, DnDneCheckDUN13
Description=Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
Source=Paul Collins Startup list
[DNS Service]
Confirmed=X
Filename=dnsresolver.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpq.html" target=_blank>RBOT-PQ</a> WORM!
Source=Paul Collins Startup list
[DNS2GoClient]
Confirmed=?
Filename=dns2goclient.exe
Description=<a href="http://dns2go.deerfield.com/" target="_blank">DNS2Go</a> is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[DNXVC]
Confirmed=?
Filename=dnxvc.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[DocTor]
Confirmed=X
Filename=Doctor.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOTOR.A" target="_blank">DOTOR.A</a> WORM!
Source=Paul Collins Startup list
[DocuMagix Init]
Confirmed=N
Filename=PWATCH.EXE
Description=<a href="http://www.documagix.com/" target="_blank">PaperMaster</a> is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed
Source=Paul Collins Startup list
[DOGStart]
Confirmed=X
Filename=GSDOGST.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
Source=Paul Collins Startup list
[Doing]
Confirmed=?
Filename=doing.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Don't Panic]
Confirmed=U
Filename=dontpanicdemodp.exe
Description=30-day trial version of <a href="http://www.panicware.com/product_dp.html" target="_blank">Don't Panic</a> privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite."
Source=Paul Collins Startup list
[Don't Panic Pop-Up Stopper]
Confirmed=U
Filename=dpps2.exe
Description=<a href="http://www.panicware.com/product_companion.html" target="_blank">Pop-Up Stopper Companion</a> from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Source=Paul Collins Startup list
[dos]
Confirmed=X
Filename=dos64.exe
Description=Adware downloader trojan
Source=Paul Collins Startup list
[Dosbat]
Confirmed=?
Filename=??
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[DoUWantIt]
Confirmed=N
Filename=duwi.exe
Description=DoUWantIt - online shopping assistant. Start it manually
Source=Paul Collins Startup list
[Download Accelerator Plus 5.0]
Confirmed=N
Filename=DAP.exe
Description=<a href="http://www.speedbit.com/" target="_blank">Download Accelerator Plus</a> from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is "adware" based
Description=<a href="http://www.forty.com/" target="_blank">Download Wonder</a> from Forty Software. Download manager for resuming downloads, amongst other features
Source=Paul Collins Startup list
[DownloadLegalMusic]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=<a href="http://www.doxdesk.com/parasite/MatrixDialer.html" target="_blank">MatrixDialer</a> related
Source=Paul Collins Startup list
[DownloadWare]
Confirmed=X
Filename=dw.exe
Description=<a href="http://downloadware.net/" target="_blank">DownloadWare</a> - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see <a href="http://and.doxdesk.com/parasite/DownloadWare.html" target="_blank">here</a>). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as <a href="#MovieNetworks">MovieNetworks</a>, <a href="#MediaLoads">Medialoads</a> and <a href="#PAgent">PAgent</a>
Source=Paul Collins Startup list
[DownloadWare Engine]
Confirmed=X
Filename=Dwe.exe
Description=<a href="http://downloadware.net/" target="_blank">DownloadWare</a> - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see <a href="http://and.doxdesk.com/parasite/DownloadWare.html" target="_blank">here</a>). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as <a href="#MovieNetworks">MovieNetworks</a>, <a href="#MediaLoads">Medialoads</a> and <a href="#PAgent">PAgent</a>
Source=Paul Collins Startup list
[Downxz]
Confirmed=X
Filename=Downxz.bat
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.w@mm.html" target="_blank">MYDOOM.W</a> WORM
Description=<a href="http://www.professionalsatellite.com/html/direcway_dw4000_features.html" target="_blank">DirecWay</a> from DirectTV satellite based high-speed internet access
Source=Paul Collins Startup list
[dpcproxy]
Confirmed=X
Filename=dpcproxy.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojgoldenpa.html" target="_blank">GOLDENP-A</a> TROJAN!
Source=Paul Collins Startup list
[DPCProxyLoadOnStartup]
Confirmed=Y
Filename=dpcstart.exe
Description=<a href="http://www.professionalsatellite.com/html/direcway_dw4000_features.html" target="_blank">DirecWay</a> from DirectTV satellite based high-speed internet access
Source=Paul Collins Startup list
[Dpcstart]
Confirmed=Y
Filename=dpcstart.exe
Description=<a href="http://www.professionalsatellite.com/html/direcway_dw4000_features.html" target="_blank">DirecWay</a> from DirectTV satellite based high-speed internet access. Proxy software
Source=Paul Collins Startup list
[Dpcstart]
Confirmed=U
Filename=dpcstart.exe
Description=Startup program for Direcway 2-way satellite internet service. Loads DirecWay's Navigator, tray icon, etc
Source=Paul Collins Startup list
[dpi]
Confirmed=X
Filename=dpi.exe
Description=<a href="http://www.spywareguide.com/product_show.php?id=727" target=_blank>Delfin Media Viewer</a> or "Promulgate" adware
Source=Paul Collins Startup list
[dpps2]
Confirmed=U
Filename=dpps2.exe
Description=<a href="http://www.panicware.com/product_companion.html" target="_blank">Pop-Up Stopper Companion</a> from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Source=Paul Collins Startup list
[dps]
Confirmed=X
Filename=dps.exe
Description=scumware-remover.org foistware, bogus adware/spyware remover, is in fact itself a browser hijacker, redirecting to smartestsearch.com
Description=Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
Source=Paul Collins Startup list
[dried.exe]
Confirmed=?
Filename=dried.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[DriveLED]
Confirmed=N
Filename=OODLed.exe
Description=<a href="http://www.oosoft.de/english/products/oodl/" target="_blank">O&O DriveLED</a> - displays your HDD LED on your monitor. Start manually
Source=Paul Collins Startup list
[Driver]
Confirmed=X
Filename=gbot.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_JUNTADOR.K" target="_blank">JUNTADOR.K</a> TROJAN!
Source=Paul Collins Startup list
[Driver32]
Confirmed=X
Filename=Scam32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html" target="_blank"> SIRCAM</a> WORM!
Source=Paul Collins Startup list
[DriveSelect]
Confirmed=N
Filename=driveselect.exe
Description=DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
Source=Paul Collins Startup list
[dRMON SmartAgent]
Confirmed=U
Filename=SmartAgt.exe
Description=Part of the network monitoring program group for 3Com NIC cards. See <a href="http://support.3com.com/infodeli/tools/netmgt/rmonprob/product/drmon/chap1.htm" target="_blank">here</a> for more info
Source=Paul Collins Startup list
[drmu]
Confirmed=X
Filename=W95Mm.exe
Description=Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this <a href="http://www.lavasoft.nu/cgi-bin/forums/ikonboard.cgi?s=3d69d34f399dffff;act=ST;f=14;t=304;st=0" target="_blank">thread</a>
Source=Paul Collins Startup list
[drocher]
Confirmed=X
Filename=d.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[drvddll.exe]
Confirmed=X
Filename=drvddll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ap@mm.html" target="_blank">BEAGLE.AP</a> WORM!
Source=Paul Collins Startup list
[Drvddll_exe]
Confirmed=X
Filename=drvddll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.x@mm.html" target="_blank">BEAGLE.X</a> WORM!
Source=Paul Collins Startup list
[DrvListnr]
Confirmed=?
Filename=DrvListnr.exe
Description=Analog Devices SoundMAX soundcard related.<font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[drvlsnr]
Confirmed=U
Filename=drvlsnr.exe
Description=Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
Source=Paul Collins Startup list
[drvr32h]
Confirmed=X
Filename=drvr32h.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[drvrmanager]
Confirmed=X
Filename=drvrquery32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/bat.boohoo.worm.html" target="_blank">BOOHOO</a> WORM!
Source=Paul Collins Startup list
[drvsys.exe]
Confirmed=X
Filename=drvsys.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.w@mm.html" target="_blank">BEAGLE.W</a> WORM!
Source=Paul Collins Startup list
[drvupd]
Confirmed=X
Filename=rundll32 ..drvupd.inf
Description=Hijacker - drvupd.inf file installs a "searchforge.com" hijack
Source=Paul Collins Startup list
[Drwebscheduler]
Confirmed=Y
Filename=Drwebscd.exe
Description=<a href="http://www.sald.com/" target="_blank">Dr. Web</a> antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem
Description=Digital desktop clock including synchronization with atomic servers - see <a href="http://www.dualitysoft.com/dsclock/" target="_blank">here</a>
Source=Paul Collins Startup list
[dsa]
Confirmed=X
Filename=dsa.exe
Description=Homepage hijacker - redirecting to downseek.com
Source=Paul Collins Startup list
[DSAcass]
Confirmed=X
Filename=[path to file]
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.ranky.m.html" target=_blank>RANKY.M</a> TROJAN!
Description=Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
Source=Paul Collins Startup list
[Dsi]
Confirmed=X
Filename=dp-******.exe
Description=Added by an unidentified adware where ****** are random characters
Source=Paul Collins Startup list
[Dskcompat]
Confirmed=X
Filename=Dskcompat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[DSL Monitor]
Confirmed=N
Filename=spdstrm.exe
Description=Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
Source=Paul Collins Startup list
[DSLagentexe]
Confirmed=Y
Filename=DSLagent.exe
Description=Used in conjunction with USB connected ADSL modems from <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection
Source=Paul Collins Startup list
[dslmon]
Confirmed=Y
Filename=dslmon.exe
Description=Sagem DSL modem related. Apparently needed to detect the modem
Source=Paul Collins Startup list
[DSLSTATEXE]
Confirmed=U
Filename=dslstat.exe
Description=System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
Source=Paul Collins Startup list
[DSS]
Confirmed=X
Filename=dssagent.exe
Description=DSSAgent by Br°derbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See <a href="http://cexx.org/dssagent.htm" target="_blank">here</a> for more info
Source=Paul Collins Startup list
[DSSSGENS]
Confirmed=?
Filename=dssagens.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[DU Meter]
Confirmed=N
Filename=DUMETER.EXE
Description=<a href="http://www.dumeter.com/main.php" target="_blank">Hagel Technologies</a> internet bandwidth monitor
Source=Paul Collins Startup list
[dumprep 0 -k]
Confirmed=N
Filename=dumprep 0 -k
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[dumprep 0 -u]
Confirmed=U
Filename=dumprep 0 -u
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[dvd43]
Confirmed=N
Filename=DVD43_Tray.exe
Description=<a href="http://www.dvdidle.com/dvd43.htm" target="_blank">DVD43</a> is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"
Source=Paul Collins Startup list
[dvd98]
Confirmed=X
Filename=windvd98.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.cult.p@mm.html" target="_blank">CULT.P</a> WORM!
Source=Paul Collins Startup list
[DVDBitSet]
Confirmed=U
Filename=DVDBitSet.exe
Description=DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
Source=Paul Collins Startup list
[Dvdcompat]
Confirmed=X
Filename=Dvdcompat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[DVDLauncher]
Confirmed=N
Filename=DVDLauncher.exe
Description=A process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use
Source=Paul Collins Startup list
[DVDSentry]
Confirmed=N
Filename=DSentry.exe
Description=Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
Source=Paul Collins Startup list
[DVDTray]
Confirmed=?
Filename=DVDTray.exe
Description=HP CD/DVD Tray icon. <font color="#FF0000">What does it do, and is it required</font>
Source=Paul Collins Startup list
[DVDUpgrade]
Confirmed=?
Filename=DVDUpgrd.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Dvp95]
Confirmed=Y
Filename=Dvp95.exe
Description=Scan engine for <a href="http://www.f-secure.com/index.shtml" target="_blank">F-Secure</a> and Command antivirus software based on the <a href="http://www.f-prot.com" target="_blank">F-Prot AntiVirus</a> engine
Source=Paul Collins Startup list
[dvpapi9x]
Confirmed=Y
Filename=DVPAPI9X.exe
Description=Command AntiVirus for Windows 95/98/Me
Source=Paul Collins Startup list
[DvpInitExe]
Confirmed=Y
Filename=Dvpinit.exe
Description=<a href="http://www.command.co.uk/html/products/csav/index.cfm">Command Antivirus</a> related
Source=Paul Collins Startup list
[dvprpt]
Confirmed=Y
Filename=Dvprpt.exe
Description=<a href="http://www.command.co.uk/html/products/csav/index.cfm">Command Antivirus</a> real time protection
Source=Paul Collins Startup list
[dvraudio]
Confirmed=X
Filename=dvraudio.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[dvsfss]
Confirmed=X
Filename=fbsfsdrs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotqa.html" target="_blank">SDBOT-QA</a> WORM!
Source=Paul Collins Startup list
[DVSync]
Confirmed=U
Filename=dvsync.exe
Description=DVSync is the program that allows you to synchronize your daVinciÆs PDA's data with your Personal Information Manager on the PC
Source=Paul Collins Startup list
[Dvx]
Confirmed=X
Filename=wsxsvc.exe
Description=<a href="http://www.spywareguide.com/product_show.php?id=727" target=_blank>Delfin Media Viewer</a> or "Promulgate" adware variant
Source=Paul Collins Startup list
[dw]
Confirmed=X
Filename=dw.exe
Description=<a href="http://downloadware.net/" target="_blank">DownloadWare</a> - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see <a href="http://and.doxdesk.com/parasite/DownloadWare.html" target="_blank">here</a>). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as <a href="#MovieNetworks">MovieNetworks</a>, <a href="#MediaLoads">Medialoads</a> and <a href="#PAgent">PAgent</a>
Source=Paul Collins Startup list
[DWHeartbeatMonitor]
Confirmed=U
Filename=DWHeartbeatMonitor.exe
Description=DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
Source=Paul Collins Startup list
[DwlClient]
Confirmed=N
Filename=support.exe
Description=Download manager for Dell support alerts
Source=Paul Collins Startup list
[Dx]
Confirmed=X
Filename=sys*.exe [* = random number]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DEXTER.A" target="_blank">DEXTER.A</a> WORM!
Source=Paul Collins Startup list
[Dx8compat]
Confirmed=X
Filename=Dx8compat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[DXDllRegExe]
Confirmed=N
Filename=dxdllreg.exe
Description=Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it
Source=Paul Collins Startup list
[DxLoad]
Confirmed=X
Filename=DX3DRndr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gibe.b@mm.html" target="_blank">GIBE.B</a> WORM!
Source=Paul Collins Startup list
[DXM6Patch_981116]
Confirmed=N
Filename=p_981116.exe
Description=Win32 cabinet self extractor. More info <a href="http://groups.google.com/groups?hl=en&threadm=OpHhSjpd%24GA.249%40cppssbbsa04&rnum=18&prev=/groups%3Fq%3DP_981116.exe%26hl%3Den%26start%3D10%26sa%3DN" target="_blank">here</a>
Source=Paul Collins Startup list
[Dxsty]
Confirmed=X
Filename=Dxsty.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Dxupdate.exe]
Confirmed=X
Filename=Dxupdate.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mafeg.html" target="_blank">MAFEG</a> WORM!
Source=Paul Collins Startup list
[DyFuCA]
Confirmed=X
Filename=optimize.exe
Description=Adult content dialler - see <a href="http://www.sophos.com/virusinfo/analyses/dialdyfucaa.html" target="_blank">here</a>
Source=Paul Collins Startup list
[DyFuCA Active Alert]
Confirmed=X
Filename=actalert.exe
Description=Adult content dialler - see <a href="http://www.sophos.com/virusinfo/analyses/dialdyfucaa.html" target="_blank">here</a>
Source=Paul Collins Startup list
[DynDNS-Updater Traytool]
Confirmed=N
Filename=ddutray.exe
Description=<a href="http://www.dyndns.org/services/dyndns/" target="_blank">DynDNS</a> updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually
Source=Paul Collins Startup list
[Dynu Basic Client]
Confirmed=U
Filename=dynubas.exe
Description=<a href="http://www.dynu.com/" target=_blank>Dynu</a> online dynamic IP update client. Useful when using a dial up modem
Source=Paul Collins Startup list
[DZKillMe]
Confirmed=?
Filename=DZSAVEME.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[E-Card]
Confirmed=X
Filename=ecard.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.yodi.html" target="_blank">YODI</a> WORM!
Source=Paul Collins Startup list
[E-color]
Confirmed=U
Filename=IconMgr.Exe
Description=Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
Source=Paul Collins Startup list
[E6TaskPanel]
Confirmed=N
Filename=TaskPanl.exe
Description=Earthlink Task Panel - part of <a href="http://www.earthlink.net/home/software/" target="_blank">Earthlink TotalAccess 2003</a> internet access software. Quick access to internet, E-mail and web-space
Source=Paul Collins Startup list
[eabconfg.cpl]
Confirmed=U
Filename=EabServr.exe
Description=Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
Description=For Compaq PC's. <a href="http://h18000.www1.hp.com/support/techpubs/whitepapers/13W1-1200a-wwen.html" target="_blank"> Easy Access</a> button support for the keyboard
Source=Paul Collins Startup list
[Eac_Cnry]
Confirmed=X
Filename=canary.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcanary.html" target="_blank"> CANARY</a> TROJAN!
Source=Paul Collins Startup list
[Eac_rnvdl]
Confirmed=?
Filename=ANTIVIRUS_INSTALL.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[EanthologyApp]
Confirmed=X
Filename=EANTHO~1.EXE
Description=<a href="http://www.stop-sign.com/" target="_blank">Stop-Sign</a> from eAccelerration. Detects spyware, malware, viruses and keyloggers and stops popups. Spyware itself - read their privacy statement <a href="http://www.eacceleration.com/privacy/" target="_blank">here</a>
Source=Paul Collins Startup list
[eanth_critical_update_alert]
Confirmed=X
Filename=sys_alert.exe
Description=Stop-Sign from eAcceleration. Purports to detect spyware, malware, viruses and keyloggers, but is in fact spyware itself - read their privacy statement <a href="http://www.eacceleration.com/privacy/" target="_blank">here</a>
Source=Paul Collins Startup list
[eanth_system_patcher]
Confirmed=N
Filename=sys_alert.exe
Description=eAcceleration Stop-Sign related - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">note</a>
Source=Paul Collins Startup list
[Eapcisetup]
Confirmed=N
Filename=sbsetup.exe
Description=Rockwell RipTide soundcard application software. Sound works without it
Source=Paul Collins Startup list
[EAPCISETUP]
Confirmed=N
Filename=wizard.exe
Description=Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
Source=Paul Collins Startup list
[EarthLink ToolBar 5.0]
Confirmed=N
Filename=etoolbar.exe
Description=EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time
Source=Paul Collins Startup list
[Easy Key]
Confirmed=U
Filename=easykey.exe
Description=For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
Source=Paul Collins Startup list
[Easy Start Button]
Confirmed=N
Filename=esb.exe
Description=Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
Source=Paul Collins Startup list
[EasyAV]
Confirmed=X
Filename=EasyAV.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.s@mm.html" target="_blank">NETSKY.S</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.t@mm.html" target="_blank">NETSKY.T</a> WORMS!
Source=Paul Collins Startup list
[EasyDates]
Confirmed=X
Filename=EasyDates.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[EasyDates_nl]
Confirmed=X
Filename=EasyDates_nl.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[EasyKey]
Confirmed=U
Filename=easykey.exe
Description=For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
Source=Paul Collins Startup list
[EasyMessage]
Confirmed=U
Filename=em2.exe
Description=Easy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See <a href="http://www.easymessage.net/" target="_blank">here</a>
Source=Paul Collins Startup list
[EasySearchBar]
Confirmed=X
Filename=ESBUpdate.exe
Description=EasySearchBar adware downloader
Source=Paul Collins Startup list
[easyServ]
Confirmed=X
Filename=Server.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.easyserv.html" target="_blank">EASYSERV</a> TROJAN!
Source=Paul Collins Startup list
[EasySync Pro]
Confirmed=U
Filename=XCPCMenu.exe
Description=<a href="http://www.lotus.com/products/easysyncpro.nsf" target="_blank">EasySync Pro</a> is a Lotus program for synchronizing a PDA with Lotus Notes
Source=Paul Collins Startup list
[EasyTuneIII]
Confirmed=U
Filename=EasyTune.exe
Description=Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
Source=Paul Collins Startup list
[EasyTuneIV]
Confirmed=U
Filename=ET4Tray.exe
Description=Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
Source=Paul Collins Startup list
[easywww]
Confirmed=X
Filename=easywww2.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Description=<a href="http://pages.ebay.com/ebay_toolbar/" target="_blank">eBay Toolbar</a> - reportes as spyware as it "phones home"
Source=Paul Collins Startup list
[eBoard]
Confirmed=U
Filename=Eboard.exe
Description=eMachines multimedia keyboard manager. Required if you use the extra keys
Source=Paul Collins Startup list
[eBot]
Confirmed=N
Filename=DownloadWizard.exe
Description=<a href="http://www.ebot.com/index.html" target="_blank">eBot</a> from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs
Source=Paul Collins Startup list
[ecpe]
Confirmed=?
Filename=ECPE.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[edexter]
Confirmed=?
Filename=edexter.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[editpad]
Confirmed=X
Filename=editpad.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojconsperb.html" target="_blank">CONSPER-B</a> TROJAN!
Source=Paul Collins Startup list
[EDLoader]
Confirmed=N
Filename=DTLoader.exe
Description=Effective Desktop from MiniStars Software - desktop management software no longer being supported
Source=Paul Collins Startup list
[EDRestore]
Confirmed=U
Filename=??
Description=<a href="http://www.easydesksoftware.com/spoint.htm" target="_blank">Set Point</a> from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP"
Source=Paul Collins Startup list
[educational writer]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlz.html" target="_blank">RBOT-LZ</a> WORM!
Source=Paul Collins Startup list
[Edwizard]
Confirmed=U
Filename=Edwizard.exe
Description=<a href="http://www.ediport.hu/_sgeasy.html" target="_blank">SafeGuard Easy</a> - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
Source=Paul Collins Startup list
[eFax.com Tray Menu]
Confirmed=N
Filename=HotTray.exe
Description=eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available <a href="http://www.efax.com/help/index.asp" target="_blank">here</a>
Source=Paul Collins Startup list
[efaxs lptt01]
Confirmed=X
Filename=efaxs.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[efaxs ml097e]
Confirmed=X
Filename=efaxs.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[Efpap.exe]
Confirmed=U
Filename=Efpap.exe
Description=<a href="http://www.softstack.com/fileprotpro.html" target="_blank">Easy File & Folder Protector</a>. Deny access to certain files and folders, or to hide them securely from viewing and searching
Source=Paul Collins Startup list
[ehTray]
Confirmed=?
Filename=ehtray.exe
Description=<font color="#FF0000">eHome <a href="http://www.microsoft.com/windowsxp/mediacenter/evaluation/hardware.asp" target="_blank">Media Center</a> PC related - what does it do and is it required?</font>
Source=Paul Collins Startup list
[ei10.exe]
Confirmed=X
Filename=ei10.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotnk.html" target=_blank>AGOBOT-NK</a> WORM!
Source=Paul Collins Startup list
[Eicon NetworksLAN_DAEMON]
Confirmed=U
Filename=watch.exe
Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Source=Paul Collins Startup list
[Eicon TechnologyLAN_DAEMON]
Confirmed=U
Filename=watch.exe
Description=Associated with an <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Source=Paul Collins Startup list
[eixfi]
Confirmed=X
Filename=china.bat
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BAT_WCUP.A" target="_blank">WCUP.A</a> WORM!
Source=Paul Collins Startup list
[Elbycheck]
Confirmed=U
Filename=ElbyCheck.exe
Description=From <a href="http://www.elby.org/english/corp/index.htm" target="_blank">Elaborate Bytes</a> who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
Source=Paul Collins Startup list
[Electron Microscope]
Confirmed=U
Filename=EMIII.exe
Description=Electron Microscope or <a href="http://www.em-dc.com/" target=_blank>EM</a> - is a program used to track Stanford's distributed computing program client called Folding at Home, <a href="http://folding.stanford.edu/" target=_blank>FAH</a>. It will monitor up to 50 clients and give you the details about each client's progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues
Source=Paul Collins Startup list
[Element]
Confirmed=X
Filename=Element.txt
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.elem.trojan.html" target="_blank">ELEM</a> TROJAN!
Source=Paul Collins Startup list
[elm]
Confirmed=N
Filename=Elmenv.exe
Description=ViaTech eLicense for securing, distributing and selling music online
Source=Paul Collins Startup list
[ELSA WINman Suite]
Confirmed=U
Filename=Winmsuit.exe
Description=Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU
Source=Paul Collins Startup list
[ElsaCapiCtl]
Confirmed=Y
Filename=Rcapi.exe
Description=Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem
Source=Paul Collins Startup list
[ELSAChipGuard]
Confirmed=U
Filename=elsavect.exe
Description=ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking
Source=Paul Collins Startup list
[EMA.exe]
Confirmed=N
Filename=EMA.EXE
Description=Time management system which helps you to manage your time and appointments
Source=Paul Collins Startup list
[eMachines eBoard]
Confirmed=U
Filename=Eboard.exe
Description=eMachines multimedia keyboard manager. Required if you use the extra keys
Source=Paul Collins Startup list
[emsw.exe]
Confirmed=X
Filename=emsw.exe
Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www.c-squad.org/hxdl.html" target="_blank">here</a>
Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
Source=Paul Collins Startup list
[EN4060C Taskbar]
Confirmed=N
Filename=en4060ct.exe
Description=Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
Source=Paul Collins Startup list
[encapsulated command tool]
Confirmed=?
Filename=wintr.com
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Encarta Dictionary Quickshelf]
Confirmed=N
Filename=QSHLFED.EXE
Description=<font color="#FF0000">Provides quick access to Encarta's Dictionary features?</font>
Source=Paul Collins Startup list
[ENCMONITOR]
Confirmed=N
Filename=monitor.exe
Description=The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
Source=Paul Collins Startup list
[Encoder Agent]
Confirmed=N
Filename=WMENCAGT.EXE
Description=MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
Source=Paul Collins Startup list
[Encompass_ENCMONTR]
Confirmed=U
Filename=ENCMONTR.EXE
Description=Optional simple browser from Yahoo (Encompass)
Description=Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
Source=Paul Collins Startup list
[Enh Win Updt]
Confirmed=X
Filename=enhupdt.exe
Description=Adware downloader - recognized by <a href="http://www.kaspersky.com/personalpro" target=_blank>Kaspersky</a> antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h
Source=Paul Collins Startup list
[enhance32]
Confirmed=X
Filename=enhance32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[EnigmaPopupStop]
Confirmed=N
Filename=EnigmaPopupStop.exe
Description=SpyHunter - spyware remover of somewhat dubious repute, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#sh_note" target="_blank">note</a>
Source=Paul Collins Startup list
[ENSApServer2_0]
Confirmed=?
Filename=APSERVER.EXE
Description=Intel AnyPoint Wireless II Home Network related. <font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[ENSMIX32.EXE]
Confirmed=?
Filename=ENSMIX32.EXE
Description=Sound card driver. <font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[EnsoniqMixer]
Confirmed=U
Filename=starter.exe
Description=Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on <a href="all/starter_exe.htm" target="_blank">this</a> special page. Similar to Creative PCI Audio Configuration Utility
Source=Paul Collins Startup list
[Enumerate Service]
Confirmed=X
Filename=wsys.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.manifest.trojan.html" target="_blank">MANIFEST</a> TROJAN!
Source=Paul Collins Startup list
[eonemng]
Confirmed=U
Filename=eOneMng.exe
Description=eOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPS]
Confirmed=N
Filename=e_srcv03.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Background Monitor]
Confirmed=N
Filename=STMS.EXE
Description=Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
Source=Paul Collins Startup list
[EPSON CardMonitor]
Confirmed=U
Filename=EPSON CardMonitor1.0.exe
Description=Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check]
Confirmed=N
Filename=e_srcv03.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check]
Confirmed=N
Filename=e_srcv02.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check 2]
Confirmed=N
Filename=e_srcv03.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[EPSON Status Monitor 3 Environment Check 2]
Confirmed=N
Filename=e_srcv02.exe
Description=According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
Source=Paul Collins Startup list
[Epson Stylus C62 Series]
Confirmed=U
Filename=E-S0BIC1.EXE
Description=Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
Source=Paul Collins Startup list
[Epson Stylus C82 Series]
Confirmed=U
Filename=e_s0hic1.EXE
Description=Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
Source=Paul Collins Startup list
[EpsonPhotoStarter]
Confirmed=U
Filename=EPSON_PhotoStarter.exe
Description=Only needed if you want to make full use of the capabilities of an Epson printer that included this
Source=Paul Collins Startup list
[Equipmen]
Confirmed=?
Filename=Equipmen.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[EReg]
Confirmed=N
Filename=reg32.exe
Description=EReg is a software registration tool incorporated on products such as those by Br°derbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it
Source=Paul Collins Startup list
[erm]
Confirmed=?
Filename=erm.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[eros.exe]
Confirmed=X
Filename=eros.exe
Description=Adult content dailler
Source=Paul Collins Startup list
[ErrorGuard]
Confirmed=X
Filename=ErrorGuard.exe
Description=Spyware remover of dubious repute
Source=Paul Collins Startup list
[erthgdr]
Confirmed=X
Filename=windll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ao@mm.html" target="_blank">BEAGLE.AO</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.aq@mm.html" target="_blank">BEAGLE.AQ</a> WORMS!
Source=Paul Collins Startup list
[ERTS0749]
Confirmed=?
Filename=ERTS0749.exe
Description=IBM Warranty Notification - <font color="#FF0000">presumably it's a reminder to either register or that warranty is about to expire?</font>
Source=Paul Collins Startup list
[eSafe Protect]
Confirmed=Y
Filename=ESPWatch.exe
Description=<a href="http://www.esafe.com/esafe/default.asp?cf=tl" target="_blank">eSafe</a> from Aladdin - internet security for gateway and E-mail servers
Source=Paul Collins Startup list
[ESB]
Confirmed=U
Filename=esb.exe
Description=Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
Description=<a href="http://www.mspl.net/antivirus/escan/escan.asp" target="_blank">eScan</a> antivirus updater - allows users to automatically download updates and set the auto time interval for downloads
Source=Paul Collins Startup list
[EScorcher]
Confirmed=X
Filename=escorcher.exe
Description=Part of <a href="http://www.escorcher.com/" target="_blank">eScorcher</a> anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
Source=Paul Collins Startup list
[ESFTP]
Confirmed=N
Filename=esftp.exe
Description=<a href="http://esftp.com/features.html" target="_blank">ESftp</a> - FTP client for transfering files between a local PC and another remote computer
Source=Paul Collins Startup list
[Esoh]
Confirmed=X
Filename=Esoh123.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.FF" target=_blank>AGOBOT.FF</a> WORM!
Source=Paul Collins Startup list
[ESPN BottomLine]
Confirmed=N
Filename=bline.exe
Description=ESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."
Source=Paul Collins Startup list
[ESS Daemon]
Confirmed=?
Filename=Essd.exe
Description=Related to an ESS based soundacard. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[essapm]
Confirmed=?
Filename=essapm.exe
Description=ESS Solo soundcard driver. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[Essdc]
Confirmed=Y
Filename=essdc.exe
Description=Related to an ESS Solo soundcard. Seems as though it's required
Source=Paul Collins Startup list
[ESSNDSYS]
Confirmed=?
Filename=ESSNDSYS.EXE
Description=Related to an ESS based soundacard. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[ESSOLO]
Confirmed=Y
Filename=ESSOLO.exe
Description=Sound card driver that re-instates itself every time it's removed
Source=Paul Collins Startup list
[esspk]
Confirmed=Y
Filename=esspk.exe
Description=ESS Technology modem speaker driver file. Required to get on-line with this modem
Source=Paul Collins Startup list
[EssSpkPhone]
Confirmed=U
Filename=essspk.exe
Description=ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
Source=Paul Collins Startup list
[Ethernet]
Confirmed=N
Filename=tcaudiag.exe
Description=3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Source=Paul Collins Startup list
[Etraffic]
Confirmed=X
Filename=JavaRun.exe
Description=Marketing software from <a href="http://www.etraffic.com/" target="_blank">TopMoxie</a>
Source=Paul Collins Startup list
[eTrust EZ Firewall]
Confirmed=Y
Filename=efpeadm.exe
Description=<a href="http://www1.my-etrust.com/products/Firewall.cfm" target="_blank">eTrust EZ Firewall</a>
Source=Paul Collins Startup list
[eTrust PestPatrol Active Protection]
Confirmed=U
Filename=PPActiveDetection.exe
Description=<a href="http://www.pestpatrol.com/" target=_blank>PestPatrol</a> real-time protection feature. "Stops spyware before it infects your system"
Source=Paul Collins Startup list
[eTrustCIPE]
Confirmed=Y
Filename=ezdsmain.exe
Description=<a href="http://www1.my-etrust.com/products/info/Deskshield/4?CFID=6909348&CFTOKEN=43ce20d%2D0001f1aa%2Df6e5%2D1d77%2Dbe1e%2D2f0eac14303f" target="_blank">eTrust EZ Deskshield</a> from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
Source=Paul Collins Startup list
[EuroGlot]
Confirmed=U
Filename=EuroGlot.exe
Description=<a href="http://www.euroglotonline.nl/en/default.html" target="_blank">Euroglot</a> - "multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian"
Source=Paul Collins Startup list
[Event Log]
Confirmed=?
Filename=eventlog.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Event Planner Reminders]
Confirmed=N
Filename=PLNRnote.exe
Description=Sierra Event Planner tray icon
Source=Paul Collins Startup list
[Event Reminder]
Confirmed=N
Filename=pmremind.exe
Description=A calendar/alarm program that installs with Br°derbund Printmaster
Source=Paul Collins Startup list
[EVENTLISTENER]
Confirmed=U
Filename=EvLstnr.exe
Description=Used with a Nikon digital camera to recognize when the camera is plugged in
Source=Paul Collins Startup list
[eventmgr]
Confirmed=N
Filename=eventmgr.exe
Description=Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
Source=Paul Collins Startup list
[Evidence Eliminator]
Confirmed=N
Filename=ee.exe
Description=<a href="http://www.evidence-eliminator.com/product.shtml" target="_blank">Evidence Eliminator</a> - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis
Source=Paul Collins Startup list
[evntsvc]
Confirmed=N
Filename=evntsc.exe
Description=Application Scheduler installed along with <a href="http://www.real.com/" target="_blank">RealOne Player</a>. Once installed, it runs independently of RealOne Player. Not required - see <a href="http://www.mikescomputerinfo.com/TkBellExe.htm" target="_blank">here</a> for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version
Source=Paul Collins Startup list
[EVOLOSTA]
Confirmed=U
Filename=EVOLOSTA.EXE
Description=Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it
Source=Paul Collins Startup list
[EvtHtm]
Confirmed=X
Filename=evthtm.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[EW Message Server]
Confirmed=U
Filename=msg32.exe
Description=Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
Source=Paul Collins Startup list
[eWare Startup]
Confirmed=N
Filename=iWareStart.exe
Description=<a href="http://www.eware.com/about/index.asp" target="_blank">eWare</a> iWare task bar. Not required
Description=Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
Source=Paul Collins Startup list
[Excite Private Messenger Pipe]
Confirmed=?
Filename=x8impipe.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[ExciteAssistantEXE]
Confirmed=N
Filename=ASSISTANT.EXE
Description=With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[exe ml097e]
Confirmed=X
Filename=exe.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[execfg4]
Confirmed=X
Filename=execfg4.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.electron.html" target="_blank">ELECTRON</a> WORM!
Source=Paul Collins Startup list
[Execute]
Confirmed=?
Filename=delfolders.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[ExeName32]
Confirmed=X
Filename=Warm.scr
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.scold@mm.html" target="_blank">SCOLD</a> WORM!
Source=Paul Collins Startup list
[exgiwsl]
Confirmed=?
Filename=exgiwsl.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Exif Launcher]
Confirmed=U
Filename=Exiflaquickdcr.exe
Description=USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
Source=Paul Collins Startup list
[Exif Launcher]
Confirmed=U
Filename=QuickDCF.exe
Description=USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
Source=Paul Collins Startup list
[ExitKiller]
Confirmed=U
Filename=Ekiller.exe
Description=<a href="http://www.exitkiller.net/" target="_blank">Exit Killer</a> - automatically closes pop-up windows in your browser
Source=Paul Collins Startup list
[exmon]
Confirmed=?
Filename=hpimoniter.exe
Description=<font color="#FF0000">Some kind of hp digital camera maybe or a photo smart connection probe?</font>
Source=Paul Collins Startup list
[Explkw]
Confirmed=X
Filename=expup.exe
Description=Keywords hijacker
Source=Paul Collins Startup list
[explore]
Confirmed=X
Filename=explore.exe
Description=Added by any number of VIRUSES, WORMS or TROJANS!
Source=Paul Collins Startup list
[Explore]
Confirmed=X
Filename=Explorer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.flood.g.html" target="_blank">IRC.FLOOD.G</a> TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
Source=Paul Collins Startup list
[Explore]
Confirmed=X
Filename=explore.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[explore.exe]
Confirmed=X
Filename=Explore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.g.html" target="_blank">GRAYBIRD.G</a> TROJAN!
Source=Paul Collins Startup list
[explorer]
Confirmed=U
Filename=explorer.exe
Description=Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as <a href="http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=PE_BISTRO&VSect=T" target="_blank">PE_BISTRO</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.dvldr.html" target="_blank">DVLDR</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.b@mm.html" target="_blank">MYDOOM.C</a>. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL
Source=Paul Collins Startup list
[explorer]
Confirmed=X
Filename=wscript.exe [filename]
Description=Sneaky way to start any VBS script. Many viruses use VBS files
Source=Paul Collins Startup list
[Explorer]
Confirmed=X
Filename=shellexpl.exe
Description=Added by the <a href="http://www.z-virus.com/Eng-virus-HTM/gpix.htm" target="_blank"> GPIX</a> and <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sheldor.html" target="_blank">SHELDOR</a> VIRUSES!
Source=Paul Collins Startup list
[explorer]
Confirmed=X
Filename=expl32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.ratsou.html" target="_blank">RATSOU</a> TROJAN!
Source=Paul Collins Startup list
[Explorer]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.autex.worm.html" target="_blank">AUTEX</a> WORM!
Source=Paul Collins Startup list
[Explorer]
Confirmed=X
Filename=shellexp.exe
Description=Added by a variant of the <a href="http://www.symantec.nl/avcenter/venc/data/backdoor.sheldor.html" target=_blank>SHELDOR</a> TROJAN!
Source=Paul Collins Startup list
[Explorer lptt01]
Confirmed=X
Filename=explorer.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually!
Source=Paul Collins Startup list
[Explorer ml097e]
Confirmed=X
Filename=explorer.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually!
Source=Paul Collins Startup list
[Explorer Updater]
Confirmed=X
Filename=IEXPLORE.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotwo.html" target="_blank">SDBOT-WO</a> WORM! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Explorer32]
Confirmed=X
Filename=Expl32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_HACKTACK.B" target="_blank">HACKTACK.B</a> TROJAN!
Source=Paul Collins Startup list
[Exshow95]
Confirmed=U
Filename=EXSHOW95.exe
Description=Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
Source=Paul Collins Startup list
[ExtraDNS]
Confirmed=U
Filename=ExtraDNS.exe
Description=<a href="http://www.extratools.com/" target="_blank">ExtraDNS</a> - DNS configuration tool
Description=<a href="http://www.asus.com/products/vga/tvfm/overview.htm" target="_blank">EzVCR</a> recording software for the ASUS TV FM card. Available via Start -> Programs
Source=Paul Collins Startup list
[EZDesk]
Confirmed=N
Filename=EZDESK.EXE
Description=Utility that remembers icon locations for each user and resolution. Available <a href="http://members.aol.com/EzDesk95/" target="_blank">here</a>
Source=Paul Collins Startup list
[EzEjMnAp]
Confirmed=N
Filename=EzEjMnAp.exe
Description=For IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs
Source=Paul Collins Startup list
[eZmmod]
Confirmed=X
Filename=mmod.exe
Description=Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read <a href="http://www.ahfb2000.com/ezula/ezula.php" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[EZNORUN]
Confirmed=?
Filename=EZNORUN.EXE
Description=<font color="#FF0000">Easy Internet related?</font>
Source=Paul Collins Startup list
[ezPS_Px]
Confirmed=Y
Filename=ezSP_PxEngine.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[ezPS_Px]
Confirmed=Y
Filename=ezSP_Px.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[ezShieldProtector for Px]
Confirmed=Y
Filename=ezSP_Px.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[ezShieldProtector for Px]
Confirmed=Y
Filename=ezSP_PxEngine.exe
Description=Engine that allows PrimoDVD from Veritas (was Prassi) and <a href="http://www.easy.co.jp/dd2e/sony/cd/" target="_blank">Drag'n Drop CD</a> from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Source=Paul Collins Startup list
[EZSMART App]
Confirmed=U
Filename=ezsmart.exe
Description=EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
Source=Paul Collins Startup list
[ezula]
Confirmed=X
Filename=eZmmod.exe
Description=Regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read <a href="http://www.ahfb2000.com/ezula/ezula.php" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[eZulaMain]
Confirmed=X
Filename=eZulaMain.exe
Description=Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read <a href="http://www.ahfb2000.com/ezula/ezula.php" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[eZuluMain]
Confirmed=X
Filename=eZuluMain.exe
Description=Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
Description=Epson Stylus printer monitor - for checking ink levels, etc.
Source=Paul Collins Startup list
[E_S23]
Confirmed=U
Filename=E_SICN03.exe
Description=Epson printer status monitor - for checking ink levels, etc.
Source=Paul Collins Startup list
[E_S4I2F1]
Confirmed=N
Filename=E_S4I2F1.exe
Description=Epson Status Monitor 3 for the Epson Stylus Photo R300 (and probably others) printers - monitors the status of a print job spooled to that printer
Source=Paul Collins Startup list
[E_S4I2G1]
Confirmed=?
Filename=E_S4I2G1.EXE
Description=Related to the Epson Stylus CX5400 printer/scanner/copier. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[E_SOEIC1]
Confirmed=U
Filename=E_SOEIC1.exe
Description=Epson Stylus printer monitor - for checking ink levels, etc.
Description=<a href="http://www.f-prot.com">F-Prot</a> anti-virus background scanner by F-Risk Software
Source=Paul Collins Startup list
[f1Tray.exe]
Confirmed=U
Filename=F1TRAY.EXE
Description=System Tray icon for FusionOneÆs <a href="http://www.mightyphone.com/" target=_blank>MightyPhone</a> software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"
Source=Paul Collins Startup list
[f607]
Confirmed=X
Filename=f607.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.urat.b.html" target="_blank">URAT.B</a> TROJAN!
Source=Paul Collins Startup list
[FamilyKeyLogger]
Confirmed=U
Filename=cisvc.exe
Description="<a href="http://www.spyarsenal.com/familykeylogger/" target="_blank">Family Keylogger</a> - is your best choice, if you want to know what other users on your machine are typing". Note! - this is not the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/cisvc/" target="_blank">cisvc.exe</a> service.
Source=Paul Collins Startup list
[fapmon]
Confirmed=?
Filename=fapmon.exe
Description=<a href="http://www.copperhead.cc/fap.html" target="_blank">Fair Access Policy</a> monitor for DirecPC/DirecWay internet access
Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
Description=Added by unidentified adware - recognized by <a href="http://www.kaspersky.com/personalpro" target=_blank>Kaspersky</a> antivirus as Trojan.Win32.Favadd.i
Source=Paul Collins Startup list
[FastCache]
Confirmed=U
Filename=fc.exe
Description=<a href="http://www.analogx.com/contents/download/network/fc.htm" target="_blank">FastCache</a> from AnalogX - speeds up browsing by resolving DNS requests locally
Source=Paul Collins Startup list
[FastTrack Accelerator]
Confirmed=N
Filename=SPEED UP.EXE
Description=<a href="http://www.sharemonkey.com/fta/index.php" target="_blank">FastTrack Accelerator</a> - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus
Source=Paul Collins Startup list
[FastUsr]
Confirmed=N
Filename=fast.exe
Description=Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
Source=Paul Collins Startup list
[FatPipe]
Confirmed=U
Filename=DHCP
Description=Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
Source=Paul Collins Startup list
[Fatpipe Dialer]
Confirmed=U
Filename=fpdialer.exe
Description=Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
Source=Paul Collins Startup list
[FBDirect]
Confirmed=U
Filename=FBDirect.exe
Description=Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[FBI]
Confirmed=?
Filename=FBISM.exe
Description=<font color="#FF0000">Compaq related but what does it do?</font>
Source=Paul Collins Startup list
[fc]
Confirmed=X
Filename=runfc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.campurf@mm.html" target="_blank">CAMPURF</a> WORM!
Source=Paul Collins Startup list
[FD_SAP]
Confirmed=?
Filename=FD.exe
Description=Genicom SAP Printer driver. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[FEELitDeviceManager]
Confirmed=U
Filename=feelitdm.exe
Description=Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
Source=Paul Collins Startup list
[fegoze]
Confirmed=X
Filename=SVCH0ST.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.d.html" target="_blank">GRAYBIRD.D</a> TROJAN!
Source=Paul Collins Startup list
[Fellowes Proxy]
Confirmed=U
Filename=R3proxy.exe
Description=Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
Source=Paul Collins Startup list
[Fen Startups]
Confirmed=X
Filename=fensvc32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.ccf.html" target=_blank>RANDEX.CCF</a> WORM!
Source=Paul Collins Startup list
[FerrariWallPaper]
Confirmed=U
Filename=FerrariWP.exe
Description=Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.j.html" target=_blank>RANKY.J</a> TROJAN!
Source=Paul Collins Startup list
[Fhtisxk]
Confirmed=U
Filename=fhtisxk.exe
Description=XtraKeys - keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove via Spybot S&D (for example)
Source=Paul Collins Startup list
[FieldForms Sync]
Confirmed=U
Filename=SyncService.exe
Description=Resco <a href="http://www.resco-net.com/enterprise/fieldforms/" target="_blank">FieldForms</a>. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well
Source=Paul Collins Startup list
[FiendlyType]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[file indexing service]
Confirmed=?
Filename=msfindfile.exe
Description=<font color="#FF0000">New version of MS FindFast and still a resource hog?</font>
Source=Paul Collins Startup list
[File System Service]
Confirmed=X
Filename=wmiprvsc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagobothz.html" target="_blank">AGOBOT-HZ</a> TROJAN!
Source=Paul Collins Startup list
[FileFreedom_Plugin]
Confirmed=N
Filename=wtm.exe
Description=<a href="http://www.filefreedom.com/" target="_blank">FileFreedom</a> peer-to-peer sharing program
Source=Paul Collins Startup list
[FileManager32]
Confirmed=X
Filename=Wscript.exe ..ChkMgr32.vbs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.notup.a@mm.html" target="_blank">NOTUP.A</a> WORM!
Source=Paul Collins Startup list
[FileSoft]
Confirmed=X
Filename=Wscript.exe UpdataFiles.vbs
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/vbs.sst.b@mm.html" target="_blank">SST.B</a> WORM!
Source=Paul Collins Startup list
[FilterGate]
Confirmed=U
Filename=filtergate.exe
Description=<a href="http://www.filtergate.com/" target="_blank">Filtergate</a> internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items
Source=Paul Collins Startup list
[Filterguard]
Confirmed=U
Filename=Filtrgrd.exe
Description=An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ôshort-cutö to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by ôright-clickingö on the icon
Source=Paul Collins Startup list
[Find Fast]
Confirmed=X
Filename=Findfast.exe
Description=Complete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier
Source=Paul Collins Startup list
[Find Virus Launch Program]
Confirmed=Y
Filename=fvlaunch.exe
Description=Part of <a target="_blank" href="http://www.drsolomon.com/">Dr. Solomon's Antivirus</a>
Source=Paul Collins Startup list
[FinePrint Dispatcher vx]
Confirmed=N
Filename=FPDISPxA.EXE
Description=<a href="http://www.softwarelabs.com/fp/fineprint.htm" target="_blank">FinePrint</a> - virtual printer for use with any printer. Search for "dispatcher" <a href="http://www.softwarelabs.com/fp/fp-faq.htm" target="_blank"> here</a> for more information. If removed, it will re-install when program is run - hence the Y recommendation
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.x@mm.html" target="_blank">NETSKY.X</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.y@mm.html" target="_blank">NETSKY.Y</a> WORMS!
Source=Paul Collins Startup list
[FireWire Driver]
Confirmed=X
Filename=samx.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.sdbot.ae.html" target=_blank>SDBOT.AE</a> WORM!
Description=Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required
Source=Paul Collins Startup list
[Fix-it AV]
Confirmed=Y
Filename=memcheck.exe
Description=Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
Source=Paul Collins Startup list
[fkSysMon]
Confirmed=N
Filename=fksysmon.exe
Description=<a href="http://www.fkware.com/sysmon/index.html" target="_blank">fkWrae SysMon</a> - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more"
Source=Paul Collins Startup list
[FLASH32]
Confirmed=?
Filename=-flash32.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[FlashPath Monitor]
Confirmed=N
Filename=SDSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[FlashPath Monitor]
Confirmed=N
Filename=FLSHSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[FlashPath Status]
Confirmed=N
Filename=SDSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[FlashPath Status]
Confirmed=N
Filename=FLSHSTAT.EXE
Description=System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
Source=Paul Collins Startup list
[Flexicd]
Confirmed=U
Filename=Flexicd.exe
Description=CD player - part of the <a href="http://www.microsoft.com/windows95/downloads/contents/WUToys/W95PwrToysSet/Default.asp" target="_blank">Win95 Power Toys</a>
Source=Paul Collins Startup list
[FLMTRUSTKB]
Confirmed=?
Filename=KbdAp32A.exe
Description=Keyboard utility for a Trust brand keyboard.<font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[FLMTRUSTMOUSE]
Confirmed=?
Filename=mouse32a.exe
Description=Mouse utility for a Trust brand mouse.<font color="#FF0000"> What does it do and is it required?</font>
Source=Paul Collins Startup list
[FLooDNeT]
Confirmed=X
Filename=FLooDeR.exe
Description=Added by of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.endool.html" target="_blank">ENDOOL</a> TROJAN!
Source=Paul Collins Startup list
[Flow Go TV]
Confirmed=?
Filename=flogotv.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[flps]
Confirmed=X
Filename=flps.vbs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.bryon@mm.html" target="_blank">BYRON</a> WORM!
Source=Paul Collins Startup list
[flpycntl]
Confirmed=X
Filename=flpycntl.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[FLSVCI]
Confirmed=?
Filename=FLSVCI.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[FltProcess]
Confirmed=Y
Filename=msinet.exe
Description=Part of <a href="http://www.cyberpatrol.com/">Cyber Patrol</a> internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done
Source=Paul Collins Startup list
[FlyswatDesktop]
Confirmed=X
Filename=flydesk.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[FmctrlTray]
Confirmed=U
Filename=Fmctrl.EXE
Description=Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
Source=Paul Collins Startup list
[fmnwebassist]
Confirmed=X
Filename=fmnwebassist.exe
Description=Adware popup generator
Source=Paul Collins Startup list
[FMStart]
Confirmed=U
Filename=Fmstart.exe
Description=<a href="http://www.gfi.com/faxmaker/" target="_blank">GFI FAXmaker</a> - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop
Source=Paul Collins Startup list
[FMSZ]
Confirmed=X
Filename=fmsz.exe
Description=Added by the <a href="http://www.pestpatrol.com/pestinfo/f/fmsz.asp" target="_blank">FMSZ</a> TROJAN!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.manifest.trojan.html" target="_blank">MANIFEST</a> TROJAN!
Source=Paul Collins Startup list
[Folding@home]
Confirmed=N
Filename=WINFAH.EXE
Description=Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
Source=Paul Collins Startup list
[FoneSyncSystemTray]
Confirmed=N
Filename=FoneSyncSystemTray.exe
Description=System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
Source=Paul Collins Startup list
[FontFix]
Confirmed=X
Filename=fontfix.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[FONTVIEW]
Confirmed=X
Filename=FONTVIEW.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
Source=Paul Collins Startup list
[foobin lptt01]
Confirmed=X
Filename=adaware.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[foobin ml097e]
Confirmed=X
Filename=adaware.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[FoolProof]
Confirmed=Y
Filename=fpwinldr.exe
Description=<a href="http://www.smartstuff.com/fps/fpsinfo.html" target="_blank">FoolProof Security</a> PC security software from SmartStuff
Source=Paul Collins Startup list
[FoolProofSweep]
Confirmed=Y
Filename=??
Description=Part of <a href="http://www.smartstuff.com/fps/fpsinfo.html" target="_blank">FoolProof Security</a> PC security software from SmartStuff
Source=Paul Collins Startup list
[Forbes]
Confirmed=N
Filename=ForbesAlerts.exe
Description=Forbes Business News Alerts - displays business news headlines in a little window on the screen
Source=Paul Collins Startup list
[ForceShow]
Confirmed=X
Filename=rundll32.exe QaBar.dll, ForceShowBar
Description=<a href="http://www.doxdesk.com/parasite/AdultLinks.html" target="_blank">AdultLinks/QAbar</a> parasite related
Source=Paul Collins Startup list
[Forget Me Not]
Confirmed=N
Filename=AGRemind.exe
Description=Calendar reminder part of <font color="#FF0000"><a href="http://www.broderbund.com/SubCategory.asp?CID=107" target="_blank">American Greetings« CreataCard«</a></font>
Source=Paul Collins Startup list
[FotoStation Easy AutoLaunch]
Confirmed=N
Filename=FotoStation Easy AutoLaunch.exe
Description=Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
Source=Paul Collins Startup list
[Foul PX]
Confirmed=U
Filename=FoulPX.exe
Description=Foul PX, Optusnet usage stat checker
Source=Paul Collins Startup list
[FourthDay]
Confirmed=U
Filename=FourthDay.exe
Description=<a href="http://www.starstonesoftware.com/fourthday.htm" target="_blank">The Fourth Day</a> - "astronomical clock and almanac for your system tray"
Source=Paul Collins Startup list
[FP Loader]
Confirmed=Y
Filename=loadfp.exe
Description=<a href="http://www.smartstuff.com/fps/fpsinfo.html" target="_blank">FoolProof Security</a> - PC security software from SmartStuff
Source=Paul Collins Startup list
[FPWGMWZD]
Confirmed=?
Filename=FPWGMWZD.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Fpx]
Confirmed=N
Filename=mnmsrvc.exe
Description=Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
Source=Paul Collins Startup list
[France]
Confirmed=X
Filename=svchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.l@mm.html" target="_blank">MIMAIL.L</a> WORM!. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Fraps]
Confirmed=U
Filename=fraps.exe
Description=Fraps Real-Time Video Capture software
Source=Paul Collins Startup list
[Free Download Manager]
Confirmed=N
Filename=fdm.exe
Description="Free Download Manager" - see <a href="http://www.freedownloadmanager.org/" target="_blank">here</a>
Source=Paul Collins Startup list
[Free Downloads Monitor]
Confirmed=?
Filename=fdcmon.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Freedom]
Confirmed=Y
Filename=Freedom.exe
Description=Zero Knowledge <a href="http://www.freedom.net/" target="_blank">Freedom</a> - Anti-Virus, Personal Firewall and Parental Control, it also blocks ads, safeguards your personal information, encrypts your passwords, and much more
Source=Paul Collins Startup list
[FreeMem Pro]
Confirmed=U
Filename=FMEMPRO.EXE
Description=Some users swear by memory management utilities such as FreeMem Pro but others say you don't need them - especially if you have Win98 or WinME. See <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[FreeMemVn2]
Confirmed=U
Filename=FreeMem.exe
Description=Some users swear by memory management utilities such as FreeMem but others say you don't need them - especially if you have Win98 or WinME. See <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[FreeMP3download]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=<a href="http://www.doxdesk.com/parasite/MatrixDialer.html" target="_blank">MatrixDialer</a> related
Source=Paul Collins Startup list
[FreeRAM XP]
Confirmed=U
Filename=FreeRAM XP Pro x.exe
Description=Some users swear by memory management utilities such as <a href="http://www.yourwaresolutions.com/" target="_blank">FreeRAM XP Pro</a> but others say you don't need them - especially if you have Win98 or WinME. See <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind. "x" indicates the version number
Description=<a href="http://www.softcows.com/fresh_desktop.htm" target=_blank>Fresh Desktop</a> is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals
Source=Paul Collins Startup list
[freshclam]
Confirmed=N
Filename=freshclam.exe
Description=Auto update agent of the open source <a href="http://www.clamwin.com/" target=_blank>Clamwin</a> virus scanner
Source=Paul Collins Startup list
[frguk]
Confirmed=?
Filename=shdrkmck.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[FridaysInHellInstaller]
Confirmed=?
Filename=FridaysInHellInstaller.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[FriendlyType]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.b.html" target="_blank">WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lsass.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[FriendlyTypeName]
Confirmed=X
Filename=services.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html" target="_blank">NEVEG.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html" target="_blank">NEVEG.C</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[FriendlyTypeName]
Confirmed=X
Filename=winlogon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[FriendlyWebQuick-Launch]
Confirmed=N
Filename=SELFCERT.EXE
Description=selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
Source=Paul Collins Startup list
[FRISK FP-Scheduler]
Confirmed=U
Filename=F-Sched.exe
Description=Scheduler for <a href="http://www.f-prot.com/" target="_blank"> F-Prot</a> anitvirus software. Leave enabled unless you scan manually on a regular basis
Source=Paul Collins Startup list
[Fromine WinPopup]
Confirmed=N
Filename=winpopup.exe
Description=Instant Messenger program
Source=Paul Collins Startup list
[Frsk]
Confirmed=X
Filename=frsk.exe
Description=Unidentified adware downloader trojan
Source=Paul Collins Startup list
[FRW_EXE]
Confirmed=Y
Filename=FRW.EXE
Description=<a href="http://www.claymania.com/rate-conseal.html" target="_blank">ConSeal Signal9</a> firewall - now McAfee Personal firewall
Source=Paul Collins Startup list
[frxmxins]
Confirmed=Y
Filename=frxmxins.exe
Description=ATI 3D Studio MAX/VIZ driver
Source=Paul Collins Startup list
[FSCBoss]
Confirmed=N
Filename=FSCBoss.exe
Description=<a href="http://freestorenow.com/dollardriven/makingmoney.html" target=_blank>Free Store Club</a> shop online software
Source=Paul Collins Startup list
[FSDPSRV]
Confirmed=?
Filename=FSDPSRV.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[fsg_4104.exe]
Confirmed=?
Filename=fsg_4104.exe
Description=<font color="#FF0000">Installed with Kazaa and believed to be Gator adware</font><font color="#FF0000">?</font>
Source=Paul Collins Startup list
[fsp]
Confirmed=U
Filename=fsp.exe
Description=<a href="http://www.baxbex.com/foldershield.html" target="_blank">Folder Shield</a> - hide entire directories and thus prevent access by anyone else to your personal files and documents
Source=Paul Collins Startup list
[fspr]
Confirmed=Y
Filename=FolderShield.exe
Description=<a href="http://www.baxbex.de/foldershield.html" target="_blank">Folder Shield</a> - hide personal files and folders
Source=Paul Collins Startup list
[FSScrCtl]
Confirmed=N
Filename=FSScrCtl.exe
Description=Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
Source=Paul Collins Startup list
[fsserv]
Confirmed=U
Filename=fserv.exe
Description=<a target="_blank" href="http://www.bysoft.se/sureshot/farsighter/manual.html">Farsighter Server</a> - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdloaderdt.html" target=_blank>DLOADER-DT</a> TROJAN!
Source=Paul Collins Startup list
[Ftpqueue]
Confirmed=U
Filename=Ftpsched.exe
Description=Part of <a href="http://www.ipswitch.com/Products/WS_FTP/" target="_blank">WS_FTP Pro</a> from Ipswitch. Queueing facility for scheduling FTP transfers
Source=Paul Collins Startup list
[fukerservice]
Confirmed=X
Filename=fukerz.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[fwenc.exe]
Confirmed=Y
Filename=fwenc.exe
Description=<a target="_blank" href="http://www.checkpoint.com/products/protect/vpn-1_srsc.html">Check Point SecuRemote VPN client</a> - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers"
Source=Paul Collins Startup list
[Fwr Command Module]
Confirmed=X
Filename=fwr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpp.html" target="_blank">SDBOT-PP</a> WORM!
Source=Paul Collins Startup list
[fwrastrc]
Confirmed=N
Filename=fwrastrc.exe
Description=Dial-up software for Friendly Technologies/1NationOnLine free ISP
Source=Paul Collins Startup list
[fwservice]
Confirmed=X
Filename=fwservice
Description=eAcceleration Stop-Sign related - not recommended, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note" target="_blank">note</a>
Source=Paul Collins Startup list
[FX]
Confirmed=X
Filename=ieloader.exe
Description=Added by the SMALL.RR TROJAN!
Source=Paul Collins Startup list
[fxredir]
Confirmed=U
Filename=fxredir.exe
Description=Canon MultiPASS fax redirector
Source=Paul Collins Startup list
[f~a]
Confirmed=X
Filename=ra32.exe
Description=Password stealer trojan
Source=Paul Collins Startup list
[G00123]
Confirmed=X
Filename=[worm filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbros@mm.html" target="_blank">BUGBROS</a> WORM!
Source=Paul Collins Startup list
[g3dctl]
Confirmed=?
Filename=g3dctl.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Gadu-Gadu]
Confirmed=N
Filename=gg.exe
Description=Polish language Instant Messaging client
Source=Paul Collins Startup list
[Gadwin PrintScreen]
Confirmed=N
Filename=PrintScreen.exe
Description=Gadwin <a href="http://www.gadwin.com/printscreen/" target="_blank">PrintScreen</a> - utility to capture, print or save the current window
Source=Paul Collins Startup list
[Gainward]
Confirmed=U
Filename=TBPanel.exe
Description=Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Game Device]
Confirmed=N
Filename=JOYUPDRV.EXE
Description=Genius game controller profile activator
Description=<a href="http://help.kontiki.com/enduser/group.jsp;jsessionid=2C47C896EA1784C5321FD3E6845E8157?node=2846" target="_blank">Kontiki Delivery Manager</a> - Windows-based client software that enables secure delivery of content to users' desktops
Source=Paul Collins Startup list
[gameutil.exe]
Confirmed=U
Filename=gameutil.exe
Description=Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
Source=Paul Collins Startup list
[GammaHotKeys]
Confirmed=U
Filename=setgamma.exe
Description=Part of the <a href="http://radeontweaker.sourceforge.net/" target="_blank">RadeonTweaker</a> program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
Source=Paul Collins Startup list
[Gator]
Confirmed=X
Filename=gator.exe
Description=Spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions
Source=Paul Collins Startup list
[Gator eWallet]
Confirmed=X
Filename=gator.exe
Description=<a href="http://www.gator.com/about/" target="_blank">Gator eWallet</a> from The Gator Corporation. Spyware - see <a href="http://www.pchell.com/support/gator.shtml" target="_blank">here</a> for removal instructions
Source=Paul Collins Startup list
[Gay_Sexy_**]
Confirmed=X
Filename=Gay_Sexy_**.exe
Description=Premium rate adult content dialler (where * is a random char)
Source=Paul Collins Startup list
[GazelDisplay]
Confirmed=U
Filename=gsyno.exe
Description=<a href="http://www.bt.com/homehighway/more_info.htm">BT Digital Access USB</a> - Gazel ISDN installation System Tray icon
Source=Paul Collins Startup list
[GBTray]
Confirmed=U
Filename=GBTray.exe
Description=System Tray icon access to Roxio's (nee Adaptec) <a href="http://www.roxio.com/en/products/goback/index.jhtml"> GoBack</a> software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Description=Associated with <a href="http://www.arcamax.com/products/oem/ogccreator.htm" target="_blank">AcraMax Greeting Card Creator</a>. <font color="#FF0000">Is it a registration reminder?</font>
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.k.html" target=_blank>RANKY.K</a> TROJAN!
Source=Paul Collins Startup list
[GDrive]
Confirmed=N
Filename=GDriver.exe
Description=Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
Source=Paul Collins Startup list
[Gearbox]
Confirmed=N
Filename=confsvr.exe
Description=NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available <a href="http://www.ntlworld.com/help/settings.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[GEARsec]
Confirmed=N
Filename=gearsec.exe
Description=Installed by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player
Source=Paul Collins Startup list
[GEDZAC]
Confirmed=X
Filename=GEDZAC.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.gemel.html" target="_blank">GEMEL</a> WORM!
Source=Paul Collins Startup list
[GemStRmW]
Confirmed=N
Filename=GemStRmW.exe
Description=For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually
Source=Paul Collins Startup list
[Gene USB Monitor]
Confirmed=U
Filename=USBMonit.exe
Description=Monitors USB ports for insertion of Sandisk USB flashdrives
Source=Paul Collins Startup list
[general lptt01]
Confirmed=X
Filename=general.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[general ml097e]
Confirmed=X
Filename=general.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[Generic host proccess for windows]
Confirmed=X
Filename=SVCHOSTS.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Generic Host Process]
Confirmed=X
Filename=SCHOST.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotnc.html" target=_blank>RBOT-NC</a> WORM!
Source=Paul Collins Startup list
[Generic Host Process for Win32 Services]
Confirmed=X
Filename=ntspcv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.s.html" target="_blank">SDBOT.S</a> TROJAN!
Source=Paul Collins Startup list
[Generic Host Process for Win32 Services]
Confirmed=X
Filename=intspvc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dinfor.d.worm.html" target="_blank">DINFOR.D</a> WORM!
Source=Paul Collins Startup list
[Generic Host Process for Win32 Services]
Confirmed=X
Filename=winsvc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdboto.html" target="_blank">SDBOT-O</a> WORM!
Source=Paul Collins Startup list
[Generic Host Service]
Confirmed=X
Filename=lshost.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.LU&VSect=T" target="_blank">RBOT.LU</a> WORM!
Source=Paul Collins Startup list
[Generic Service Process]
Confirmed=X
Filename=regsvc32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.uj.html" target="_blank">GAOBOT.UJ</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.ul.html" target="_blank">GAOBOT.UL</a> WORMS!
Source=Paul Collins Startup list
[Generic Services Process]
Confirmed=X
Filename=regsvc32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.sy.html" target="_blank">GAOBOT.SY</a> WORM!
Source=Paul Collins Startup list
[Genie USB Monitor]
Confirmed=Y
Filename=USBmonitor.exe
Description=Port monitor for an external USB hard drive. Required to enable access to the drive
Source=Paul Collins Startup list
[Get Smile]
Confirmed=N
Filename=getsmile.exe
Description=Puts smilie faces in your E-mail. Run manually when required
Source=Paul Collins Startup list
[GetRight Tray Icon]
Confirmed=N
Filename=GETRIGHT.EXE
Description=GetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs
Source=Paul Collins Startup list
[GetTheMusic]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=<a href="http://www.doxdesk.com/parasite/MatrixDialer.html" target="_blank">MatrixDialer</a> related
Source=Paul Collins Startup list
[GhostStartService]
Confirmed=N
Filename=GhostStartService.exe
Description=Required to run the Windows based wizard in <a href="http://www.symantec.com/sabu/ghost/ghost_personal/" target="_blank">Norton Ghost</a> - added from the 2003 version. Will start automatically when you run the wizard
Source=Paul Collins Startup list
[GhostStartTrayApp]
Confirmed=N
Filename=GhostStartTrayApp.exe
Description=System Tray access to <a href="http://www.symantec.com/sabu/ghost/ghost_personal/" target="_blank">Norton Ghost</a> - added from the 2003 version
Source=Paul Collins Startup list
[GhostSurfDelSatellite]
Confirmed=?
Filename=DeleteSatellite.exe
Description=<a href="http://www.tenebril.com/products/ghostsurf/spycatcher.html" target=_blank>SpyCatcher</a> spyware remover related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[gigabit.exe]
Confirmed=X
Filename=gigabit.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.u@mm.html" target="_blank">BEAGLE.U</a> WORM!
Source=Paul Collins Startup list
[GigaByte]
Confirmed=X
Filename=Cheatle.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllp.shodi.b.html" target="_blank">SHODI.B</a> VIRUS!
Source=Paul Collins Startup list
[Gilat SOM Enumerator]
Confirmed=Y
Filename=dllhost.exe
Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Source=Paul Collins Startup list
[GilatFTC]
Confirmed=Y
Filename=ftc.exe
Description=For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Source=Paul Collins Startup list
[GinaDll]
Confirmed=X
Filename=ntgina.dll
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_ANIG.A" target="_blank">ANIG.A</a> WORM!
Source=Paul Collins Startup list
[GisdnLog]
Confirmed=?
Filename=gisdnlog.exe
Description=<a href="http://www.bt.com/homehighway/more_info.htm">BT Digital Access USB</a>
Source=Paul Collins Startup list
[Glass2k]
Confirmed=U
Filename=Glass2k.exe
Description="<a href="http://www.chime.tv/products/glass2k.shtml" target="_blank">Glass2k</a> is a small little program that allows Win2K/XP users to make any window transparent"
Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39482" target="_blank">OPTIX PRO</a> TROJAN!
Source=Paul Collins Startup list
[GLSetIT32]
Confirmed=X
Filename=isass.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39482" target="_blank">OPTIX PRO</a> TROJAN!
Source=Paul Collins Startup list
[GLSetT32]
Confirmed=X
Filename=smsiexec.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojoptixd.html" target=_blank>OPTIX-D</a> TROJAN!
Source=Paul Collins Startup list
[gluon]
Confirmed=?
Filename=gluon.exe
Description=<font color="#FF0000">In a gluon/bin sub-directory</font>
Source=Paul Collins Startup list
[Gmouse]
Confirmed=Y
Filename=Gmouse.exe
Description=Amouse mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Gnetmous]
Confirmed=U
Filename=gnetmous.exe
Description=<a href="http://www.geniusnet.com.tw/product/mouse/netscroll+.htm" target="_blank">Genius NetScroll+</a> mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[gnub]
Confirmed=?
Filename=gnub.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Go!Zilla]
Confirmed=X
Filename=gozilla.exe
Description=Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
Source=Paul Collins Startup list
[Go!Zilla Monster Downloads]
Confirmed=X
Filename=Go.exe
Description=Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
Source=Paul Collins Startup list
[GoBack]
Confirmed=U
Filename=GBMenu.exe
Description=Roxio's (nee Adaptec) <a href="http://www.roxio.com/en/products/goback/index.jhtml"> GoBack</a> software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GoBack]
Confirmed=U
Filename=GBTray.exe
Description=System Tray icon access to Roxio's (nee Adaptec) <a href="http://www.roxio.com/en/products/goback/index.jhtml"> GoBack</a> software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GoBack Polling Service]
Confirmed=U
Filename=GBPoll.exe
Description=Roxio's (nee Adaptec) <a href="http://www.roxio.com/en/products/goback/index.jhtml"> GoBack</a> software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GoBack Tray Icon]
Confirmed=U
Filename=GBTray.exe
Description=System Tray icon access to Roxio's (nee Adaptec) <a href="http://www.roxio.com/en/products/goback/index.jhtml"> GoBack</a> software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
Source=Paul Collins Startup list
[GOG]
Confirmed=X
Filename=GOG.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllp.philis.b.html" target="_blank">PHILIS.B</a> VIRUS!
Source=Paul Collins Startup list
[Goldensoft_MndlSvr]
Confirmed=U
Filename=MndlSvr.exe
Description=Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
Source=Paul Collins Startup list
[golumm]
Confirmed=X
Filename=services.exe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite variant. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Google Desktop Search]
Confirmed=N
Filename=GoogleDesktop.exe
Description=<a href="http://desktop.google.com/about.html" target=_blank>Google Desktop Search</a> - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks"
Source=Paul Collins Startup list
[GoogleDCClient]
Confirmed=N
Filename=GoogleDCC.exe
Description=<a target="_blank" href="http://toolbar.google.com/dc/faq_dc.html#about1">Google Compute Client</a> - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing"
Source=Paul Collins Startup list
[GoToMyPC]
Confirmed=U
Filename=g2svc.exe
Description=<a href="https://www.gotomypc.com/ad/corp/home" target="_blank">ExpertCity GoToMyPc</a> logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser
Source=Paul Collins Startup list
[gouday.exe]
Confirmed=X
Filename=readme.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.c@mm.html" target="_blank">BEAGLE.C</a> WORM!
Source=Paul Collins Startup list
[GRA]
Confirmed=N
Filename=gra.exe
Description=Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility
Source=Paul Collins Startup list
[gramdate]
Confirmed=?
Filename=2Stop.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Gravis Appawareloader]
Confirmed=U
Filename=dbserver.exe
Description=Looks like it's associated with <a href="http://www.gravis.com/" target="_blank"> Gravis</a> game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them
Source=Paul Collins Startup list
[Gravis Xperience Driver Support]
Confirmed=U
Filename=Grxp4exe.exe
Description=Driver for <a href="http://www.gravis.com/" target="_blank">Gravis</a> game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used
Source=Paul Collins Startup list
[GrdSys32]
Confirmed=?
Filename=GrdSys32.exe
Description=X-Stream ISP software. Offers free Net access funded by on-screen ads. <font color="#FF0000">Is it required or can you create your own dial-up networking connection to use on demand?</font>
Source=Paul Collins Startup list
[Greetings Workshop]
Confirmed=N
Filename=GWREMIND.EXE
Description=You really want to be reminded about somebody's birthday at the expense of resources?
Source=Paul Collins Startup list
[gremier]
Confirmed=X
Filename=wscript.exe gpremier.vbs
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/vbs.gpremier@mm.html" target="_blank">GPREMIER</a> WORM!
Source=Paul Collins Startup list
[Gremlin]
Confirmed=X
Filename=intrenat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.doomjuice.html" target="_blank">DOOMJUICE</a> WORM!
Source=Paul Collins Startup list
[Grokster]
Confirmed=N
Filename=Grokster.exe
Description=<a href="http://www.pestpatrol.com/PestInfo/G/Grokster.asp" target=_blank>Grokster</a> Peer-To-Peer File Sharing program
Source=Paul Collins Startup list
[GrpConv]
Confirmed=N
Filename=grpconv.exe
Description=To facilitate the upgrade from Windows 3.1 to Win95/98, an executable file named GRPCONV.EXE is included with Win95/98. This file provides the translation of groups and group items to folders and links unless you need to access Win 3.1 Group files
Source=Paul Collins Startup list
[Gscbc]
Confirmed=?
Filename=Gscbc.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[gshp]
Confirmed=X
Filename=zzgshp.vbs
Description=Homepage hi-jacker
Source=Paul Collins Startup list
[Gsiconexe]
Confirmed=N
Filename=Gsicon.exe
Description=ADSL modem monitor from <a href="http://www.eicon.com/worldwide/default.htm" target="_blank">Eicon Networks</a> (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities
Source=Paul Collins Startup list
[GSOrganizer]
Confirmed=N
Filename=GSOrganizer.exe
Description=<a href="http://www.tgslabs.com/index.php3" target="_blank">GoldenSection Organizer</a> - personal information manager
Description=Gator spyware variant. See <a href="#Gator"> Gator</a>
Source=Paul Collins Startup list
[Gtwatch]
Confirmed=N
Filename=gtwatch.exe
Description=Associated with a Mustec scanner and not required
Source=Paul Collins Startup list
[Guardian]
Confirmed=N
Filename=CMGrdian.exe
Description=McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
Source=Paul Collins Startup list
[GuruNet]
Confirmed=U
Filename=GuruNet.exe
Description=<a href="http://www.gurunet.com/what_tools.jsp" target=_blank>GuruNet</a> lets you click on any word on your screen to get the relevant information you want
Source=Paul Collins Startup list
[GustavVED]
Confirmed=X
Filename=[filename].exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.opaserv.h.worm.html" target="_blank">OPASERV.H</a> WORM!
Source=Paul Collins Startup list
[gvagfxj]
Confirmed=X
Filename=rundll32 ...gvagfxj.dll
Description=Unidentified adware, spyware or virus
Source=Paul Collins Startup list
[gw port controller]
Confirmed=Y
Filename=PORTCT95.EXE
Description=From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by Samsung
Source=Paul Collins Startup list
[GWInkMonitor]
Confirmed=N
Filename=GWInkMonitor.exe
Description=Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!
Source=Paul Collins Startup list
[GWMDMMSG]
Confirmed=N
Filename=GWMDMMSG.exe
Description=Used with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
Source=Paul Collins Startup list
[GWMDMpi]
Confirmed=U
Filename=GWMDMpi.exe
Description=Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See <a href="http://support.gateway.com/support/drivers/moreinfo.asp?readmeURL=ftp%3A//ftp.gateway.com/pub/hardware_support/drivers/win_xp/portable/450sx4/7512994.txt" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[gwum]
Confirmed=U
Filename=gwum.exe
Description=Gigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers"
Description=Active sync for use with Windows CE based palm PC
Source=Paul Collins Startup list
[HalifaxHowardCluster]
Confirmed=U
Filename=skinkers.exe
Description=<a href="http://www.skinkers.com/clients.html" target="_blank">Howard the Weatherman</a> desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages
Source=Paul Collins Startup list
[HaMFrontPanel]
Confirmed=U
Filename=hampanel.exe
Description=Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless
Source=Paul Collins Startup list
[Handy Backup 3.9]
Confirmed=U
Filename=hbagent.exe
Description=<a href="http://www.handybackup.com/" target="_blank">Handy Backup</a> - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers
Source=Paul Collins Startup list
[Hardware Doctor]
Confirmed=U
Filename=Hwdoctor.exe
Description=Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you're concerned about your system temperature - typically for "overclocked" systems
Source=Paul Collins Startup list
[Hardware Profile]
Confirmed=X
Filename=hxdef.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Hardware Profile]
Confirmed=X
Filename=hxdef.exe...
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Hardware Sensors Monitor]
Confirmed=U
Filename=hmonitor.exe
Description=Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
Source=Paul Collins Startup list
[Hare]
Confirmed=U
Filename=hare.exe
Description=<a href="http://www.foxpop.ndirect.co.uk/pc/dachshund_03.htm" target="_blank">Hare</a> - improve and optimize performance of desktop/laptop PCs
Source=Paul Collins Startup list
[HawkEye]
Confirmed=U
Filename=HAWK_95.EXE
Description=Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[HawkEye IV Control Panel]
Confirmed=U
Filename=HAWK_32.EXE
Description=Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[Hbinst]
Confirmed=X
Filename=Hbinst.exe
Description=<a href="http://www.hotbar.com/" target="_blank">Hotbar</a> enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see <a href="http://www.safersite.com/pestinfo/H/HotBar_Adware.asp" target="_blank">here</a>
Source=Paul Collins Startup list
[HC Reminder]
Confirmed=N
Filename=hc.exe
Description=For Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed
Source=Paul Collins Startup list
[HCDetect]
Confirmed=N
Filename=HCDetect.exe
Description=MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem
Source=Paul Collins Startup list
[Hcontrol]
Confirmed=U
Filename=hcontrol.exe
Description=Hotkeys on an ASUS Notebook. Only required if you use the additional keys
Source=Paul Collins Startup list
[HDDHealth]
Confirmed=U
Filename=hddhealth.exe
Description=<a href="http://www.panterasoft.com/" target=_blank>HDD Health</a> is a "full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure"
Source=Paul Collins Startup list
[HDhelp]
Confirmed=?
Filename=tbhdhelp.exe
Description=Associated with Philips <a href="http://www.consumer.philips.com/global/b2c/ce/catalog/subcategory.jhtml;jsessionid=4ORTA0KYTJOWWCRQNFJRX1YKGBUEWHAW?subCatId=SOUNDCARDS&groupId=PCSTUFF&divId=0" target="_blank">Edge</a> series soundcards. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[HDtray]
Confirmed=N
Filename=HDtray.exe
Description=Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips <a href="http://www.consumer.philips.com/global/b2c/ce/catalog/subcategory.jhtml;jsessionid=4ORTA0KYTJOWWCRQNFJRX1YKGBUEWHAW?subCatId=SOUNDCARDS&groupId=PCSTUFF&divId=0" target="_blank">Edge</a> series soundcards. Available via Start -> Settings -> Control Panel
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.yodo@mm.html" target="_blank">YODO</a> WORM!
Source=Paul Collins Startup list
[Help]
Confirmed=?
Filename=helpext.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[helpctl.exe]
Confirmed=X
Filename=helpctl.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gaslide.html" target="_blank">GASLIDE</a> TROJAN!
Source=Paul Collins Startup list
[Helper]
Confirmed=X
Filename=eschlp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.t.worm.html" target="_blank">BLASTER.T</a> WORM!
Source=Paul Collins Startup list
[helper.dll]
Confirmed=X
Filename=helper.dll, Rundll32
Description=CnsMin "<a href="http://217.115.153.73/parasite/CnsMin.html" target="_blank">Chinese Keywords</a>" hijacker related
Source=Paul Collins Startup list
[HelpExp.exe]
Confirmed=X
Filename=HelpExp.exe
Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www.c-squad.org/hxdl.html" target="_blank">here</a>
Source=Paul Collins Startup list
[helpmanager]
Confirmed=X
Filename=spoler.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.j.html" target="_blank">RANDEX.J</a> WORM!
Source=Paul Collins Startup list
[helpw]
Confirmed=X
Filename=helpw.exe
Description=Adware downloader
Source=Paul Collins Startup list
[hen]
Confirmed=X
Filename=[filename].exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.g.html" target="_blank">TARNO.G</a> TROJAN!
Source=Paul Collins Startup list
[hErcUnes]
Confirmed=X
Filename=softhost.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.garroch@mm.html" target=_blank>GARROCH</a> WORM!
Source=Paul Collins Startup list
[Hermes Messenger]
Confirmed=U
Filename=DGDRHE~1.EXE
Description=A LAN messenger alternative to WinPopUp - <a href="http://www.dgdr.com/hermes/" target="_blank">Digital Dreams Software</a>
Source=Paul Collins Startup list
[Hewlett Packard Recorder]
Confirmed=N
Filename=Remind32.exe
Description=HP multifunction registration
Source=Paul Collins Startup list
[Hf]
Confirmed=U
Filename=Hf.exe
Description=<a href="http://www.fspro.net/hf/" target="_blank">Hide Folders</a> - hide your folders so only you can view them
Source=Paul Collins Startup list
[hfxp]
Confirmed=U
Filename=hfxp.exe
Description=<a href="http://www.fspro.net/hfxp/" target=_blank>Hide Folders XP</a> - hide your folders so only you can view them
Source=Paul Collins Startup list
[HGTXPEI]
Confirmed=N
Filename=FirstReboot.exe
Description=Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[HiberMonitor]
Confirmed=?
Filename=HCount.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Hibernation]
Confirmed=U
Filename=hib32.exe
Description=Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly
Source=Paul Collins Startup list
[Hid.exe]
Confirmed=X
Filename=hid.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.ratsou.b.html" target="_blank">RATSOU.B</a> TROJAN!
Source=Paul Collins Startup list
[HideRun.exe]
Confirmed=X
Filename=Hiderun.exe and svhost.exe and pro.gif
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/bat.boohoo.worm.html" target="_blank">BOOHOO</a> WORM!
Source=Paul Collins Startup list
[HideStyle]
Confirmed=X
Filename=Ante Browse Trust.exe
Description=IE toolbar taking you to Lop.com. If the exe is running, end it and remove the "Stupidmore" directory from C:\Program Files
Source=Paul Collins Startup list
[hidserv]
Confirmed=U
Filename=hidserv.exe
Description=This is the <a href="http://www.microsoft.com/hwdev/tech/input/audctrl.asp" target="_blank">Human Interface Device Server</a> for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See <a href="http://www.microsoft.com/hwdev/hid/audctrl.htm" target="_blank">here</a>. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards
Source=Paul Collins Startup list
[High Definition Audio Property Page Shortcut]
Confirmed=N
Filename=HDAudPropShortcut.exe
Description=Realtek audio card related - probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required
Source=Paul Collins Startup list
[HistoryKill]
Confirmed=N
Filename=histkill.exe
Description=HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.hiva.html" target="_blank">HIVA</a> TROJAN!
Source=Paul Collins Startup list
[hkcmd]
Confirmed=U
Filename=hkcmd.exe
Description=Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel
Source=Paul Collins Startup list
[HKLM\Run]
Confirmed=X
Filename=windowsupdate.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbj.html" target=_blank>FORBOT-BJ</a> WORM! (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)
Source=Paul Collins Startup list
[hkserv]
Confirmed=U
Filename=HKserv.exe
Description=Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
Source=Paul Collins Startup list
[hkss]
Confirmed=U
Filename=hkss.exe
Description=Compaq HotKey Support - multimedia keyboard support
Source=Paul Collins Startup list
[HLL Data Parameter]
Confirmed=X
Filename=hllcxpa.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/smb/security_info/virus_encyclopedia.php?s=1&VName=WORM_RBOT.AFG" target=_blank>RBOT.AFG</a> WORM!
Source=Paul Collins Startup list
[Hmonitor]
Confirmed=U
Filename=Hmonitor.exe
Description=Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status
Source=Paul Collins Startup list
[Holiday Lights]
Confirmed=N
Filename=Holiday Lights.exe
Description=<a href="http://www.tigertech.com/hlights.html" target="_blank">Holiday Lights</a> from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs
Source=Paul Collins Startup list
[HomeAlarm]
Confirmed=U
Filename=HomeAlarm.exe
Description=<a href="http://www.softshape.com/cham/" target="_blank">Chameleon Clock</a> - system tray clock replacement
Source=Paul Collins Startup list
[HomeCentre WakeUp]
Confirmed=?
Filename=LGWAKEUP.EXE
Description=<font color="#FF0000">Associated with the no longer supported Xerox HomeCentre printer/scanner</font>
Source=Paul Collins Startup list
[Honor]
Confirmed=?
Filename=honor.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Hook99startup]
Confirmed=U
Filename=hk2re.exe
Description="<a href="http://thunder.prohosting.com/~ladi/e_hook.html" target="_blank">Hook99</a> enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent"
Source=Paul Collins Startup list
[HookSys]
Confirmed=U
Filename=HookSys.exe
Description=<a href="http://www.rocketdownload.com/details/secu/6889.htm" target="_blank">SurfinGuard Pro</a> - protects against all malicious code delivered through executables, scripting files, ActiveX and Java
Source=Paul Collins Startup list
[HorngTech4D]
Confirmed=Y
Filename=bally4d.exe
Description=HorngTech 4D mouse driver
Source=Paul Collins Startup list
[Host]
Confirmed=X
Filename=N/A
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.popdis.html" target="_blank">POPDIS</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.f.html" target="_blank">STARTPAGE.F</a> TROJANS!
Source=Paul Collins Startup list
[HostManager]
Confirmed=?
Filename=AOLHostManager.exe
Description=In a Program Files\Common Files\AOL folder. <font color="#FF0000">What does it do, and is it required?</font>
Source=Paul Collins Startup list
[Hot Corners]
Confirmed=U
Filename=Hotc.exe
Description=<a href="http://www.southbaypc.com/HotCorners/" target="_blank">Hot Corners</a> - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"
Source=Paul Collins Startup list
[Hot Key Kbd 2690 Daemon]
Confirmed=U
Filename=SK9910DM.exe
Description=Multimedia keyboard manager - required if you use any special keys
Source=Paul Collins Startup list
[Hot Key Keybd 9910 Daemon]
Confirmed=U
Filename=SK9910DM.exe
Description=Multimedia keyboard manager - required if you use any special keys
Source=Paul Collins Startup list
[Hot Party 22]
Confirmed=?
Filename=hotpart22.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Hotbar]
Confirmed=X
Filename=Hbinst.exe
Description=<a href="http://www.hotbar.com/" target="_blank">Hotbar</a> enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see <a href="http://www.safersite.com/pestinfo/H/HotBar_Adware.asp" target="_blank">here</a>
Source=Paul Collins Startup list
[Hotfix Updat]
Confirmed=X
Filename=svdhost32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.zw.html" target="_blank">GAOBOT.ZW</a> WORM!
Source=Paul Collins Startup list
[HotIDE]
Confirmed=U
Filename=hotide.exe
Description=HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
Source=Paul Collins Startup list
[HotkeyApp]
Confirmed=U
Filename=HotkeyApp.exe
Description=Part of <a href="http://global.acer.com/" target="_blank">Acer</a> Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[HotKeysCmds]
Confirmed=U
Filename=hkcmd.exe
Description=Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via Control Panel -> Display Properties
Source=Paul Collins Startup list
[HotPix]
Confirmed=X
Filename=hotpix.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[hotplug]
Confirmed=X
Filename=hotplug.exe
Description=Added by the <a href="http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=39574" target="_blank">SILLYDL</a> TROJAN!
Source=Paul Collins Startup list
[HotSync Manager]
Confirmed=N
Filename=hotsync.exe
Description=Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start -> Programs
Source=Paul Collins Startup list
[hotwetlove]
Confirmed=X
Filename=hotwetlove.exe
Description=Adult content dialler. Will not uninstall - components have to be manually deleted
Source=Paul Collins Startup list
[Hot_Kiss]
Confirmed=X
Filename=Hot_Kiss.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Hot_Tarts]
Confirmed=X
Filename=Hot_Tarts.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Hot_Tarts_**]
Confirmed=X
Filename=Hot_Tarts_**.exe
Description=Premium rate adult content dialer (where * is a random char)
Description=HP LaserJet 1000 related. <font color="#FF0000">Is it a driver or automatic firmware update (based upon the filename)?</font>
Source=Paul Collins Startup list
[HP AutoIndexer]
Confirmed=U
Filename=hppautoindexer.exe
Description=Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
Source=Paul Collins Startup list
[HP CD Writer]
Confirmed=N
Filename=hpcdtray.exe
Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
Source=Paul Collins Startup list
[HP CD-DVD]
Confirmed=N
Filename=hpcdtray.exe
Description=System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
Source=Paul Collins Startup list
[hp center]
Confirmed=X
Filename=BACKWEB-137903.exe
Description=Based upon HP's own description from <a href="http://www.hp.com/hpinfo/newsroom/press/12oct01a.htm" target="_blank">here</a> - "With the My <abbr title=Hewlett-Packard>HP</abbr> Center, consumers have access directly from the desktop to Internet sites featuring special offers for <abbr title=Hewlett-Packard>HP</abbr> customers ranging from personal finance and shopping to digital imaging and music" I have classified this as adware. <font color="#FF0000">The number may change - if yours is different let me know</font>
Source=Paul Collins Startup list
[hp center UI]
Confirmed=X
Filename=ShadowBar.exe
Description=User Interface for HP Center
Source=Paul Collins Startup list
[HP Component Manager]
Confirmed=N
Filename=hpcmpmgr.exe
Description=Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
Source=Paul Collins Startup list
[HP Deskjet]
Confirmed=X
Filename=HP_DeskJet_500.exe
Description=Added by the <a href="http://www.sophos.com.au/virusinfo/analyses/w32forbotda.html" target=_blank>FORBOT-DA</a> WORM!
Source=Paul Collins Startup list
[HP Display Settings]
Confirmed=N
Filename=hpdisply.exe
Description=Sets default display settings. Unchecking this item has been reported to cure a "Problem sending command to keyboard" error message
Description=On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
Source=Paul Collins Startup list
[HP Instant Support]
Confirmed=U
Filename=matcli.exe
Description="matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide
Source=Paul Collins Startup list
[HP Internet Center]
Confirmed=N
Filename=SURFBRD.EXE
Description=Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
Source=Paul Collins Startup list
[HP JetDiscovery]
Confirmed=N
Filename=HPJETDSC.EXE
Description=HP JetAdmin software which monitors printing jobs on a network environment
Source=Paul Collins Startup list
[HP JetSpeed Autostart]
Confirmed=N
Filename=AUTOSTART.EXE
Description=Autostart executable for the old multiplayer game HP Jetspeed
Source=Paul Collins Startup list
[HP Laser Jet Director]
Confirmed=U
Filename=hppdirector.exe
Description=System Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc
Source=Paul Collins Startup list
[HP Network Registry Agent]
Confirmed=?
Filename=hpnra.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[HP OfficeJet Series xxx Startup]
Confirmed=?
Filename=HPOSTR03.EXE
Description=xxx represents the series number - such as 700. <font color="#FF0000">What does it do and it it required?</font>
Source=Paul Collins Startup list
[HP OfficeJet Series xxx Startup]
Confirmed=?
Filename=HPOstr05.exe
Description=xxx represents the series number - such as 700. <font color="#FF0000">What does it do and it it required?</font>
Source=Paul Collins Startup list
[HP Parallel Port Test]
Confirmed=N
Filename=hppt.exe
Description=Associated with a HP ScanJet scanner
Source=Paul Collins Startup list
[HP Port Resolver]
Confirmed=?
Filename=hpbpro.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[HP Precision Scan]
Confirmed=N
Filename=hpmdlbwx.exe
Description=HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
Source=Paul Collins Startup list
[HP Presentation Ready]
Confirmed=N
Filename=PresRdy.exe
Description=HP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
Source=Paul Collins Startup list
[hp psc 2000 Series]
Confirmed=U
Filename=hpobnz08.exe
Description=System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
Source=Paul Collins Startup list
[HP RecordNow]
Confirmed=U
Filename=??
Description=From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."
Source=Paul Collins Startup list
[HP ScanPatch]
Confirmed=U
Filename=HPScanFix.exe
Description=Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting
Source=Paul Collins Startup list
[HP ScanPicture]
Confirmed=N
Filename=hpsplmwa.exe
Description=HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
Source=Paul Collins Startup list
[HP SchedIndexer]
Confirmed=U
Filename=hppschedindexer.exe
Description=Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
Description=Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
Source=Paul Collins Startup list
[HP software update]
Confirmed=N
Filename=HPWuSchd2.exe
Description=HP software updates. If a shortcut doesn't exist create your own and run it manually
Source=Paul Collins Startup list
[HP software update]
Confirmed=N
Filename=HPWuSchd.exe
Description=HP software updates. If a shortcut doesn't exist, create your own and run it manually
Source=Paul Collins Startup list
[HP software update]
Confirmed=N
Filename=HPWuSchd2.exe
Description=HP software updates. If a shortcut doesn't exist, create your own and run it manually
Source=Paul Collins Startup list
[HP Status]
Confirmed=N
Filename=hpstatus.exe
Description=HP Printer Status and Alerts
Source=Paul Collins Startup list
[HP Status Server]
Confirmed=?
Filename=hpboid.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[HP Updates]
Confirmed=N
Filename=??
Description=On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
Source=Paul Collins Startup list
[HP Visualize Init]
Confirmed=?
Filename=HpVisIni.exe
Description=HP Visualize software related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[HP-Aio Flight]
Confirmed=N
Filename=Remind32.exe
Description=HP multifunction registration
Source=Paul Collins Startup list
[hpaiodevice]
Confirmed=N
Filename=hpodev07.exe
Description=Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
Source=Paul Collins Startup list
[HPAiODevice(hp psc 900 series) -1]
Confirmed=N
Filename=hpobrt07.exe
Description=Installed with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry
Source=Paul Collins Startup list
[HPAIO_PrintFolderMgr]
Confirmed=N
Filename=hpoopm07.exe
Description=Directly from HP: "This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
Source=Paul Collins Startup list
[hpcmpmgr]
Confirmed=?
Filename=hpcmpmgr.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsbol.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see <a href="http://home.t-online.de/home/Martin.Lottermoser/pcl3.html" target="_blank">here</a> for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsd02.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see <a href="http://home.t-online.de/home/Martin.Lottermoser/pcl3.html" target="_blank">here</a> for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsb04.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see <a href="http://home.t-online.de/home/Martin.Lottermoser/pcl3.html" target="_blank">here</a> for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[HPDJ Taskbar Utility]
Confirmed=U
Filename=hpztsb05.exe
Description=(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see <a href="http://home.t-online.de/home/Martin.Lottermoser/pcl3.html" target="_blank">here</a> for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer
Source=Paul Collins Startup list
[hpfsched]
Confirmed=N
Filename=hpfsched.exe
Description=HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
Source=Paul Collins Startup list
[HPGamesActiveMenu]
Confirmed=U
Filename=ActiveMenu.exe
Description=<a href="http://www.wildtangent.com/default.asp" target="_blank">WildTangent</a> games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's <a href="http://www.wildtangent.com/default.asp?pageID=company_art&artid=art20030925_A" target="_blank">privacy policy</a> used to state that they also collect and share individuals information but this is no longer the case
Source=Paul Collins Startup list
[hpgs2wnd]
Confirmed=N
Filename=hpgs2wnd.exe
Description="HP's exclusive <a href="http://www.hp.com/peripherals2/scanjet_info/share-to-web/index.htm" target="_blank">Share-to-Web</a> software makes it easy to share content with others through our affiliate Internet websites."<font color="#FF0000"> </font>Available via Start -> Programs
Source=Paul Collins Startup list
[HPHAxMON]
Confirmed=U
Filename=HPHAxMON.EXE
Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. "x" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards
Source=Paul Collins Startup list
[HPHmon**]
Confirmed=U
Filename=HPHMON**.EXE
Description=Monitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn't inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don't use the reader
Source=Paul Collins Startup list
[HPHmon04]
Confirmed=U
Filename=hphmon04.exe
Description=Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature
Source=Paul Collins Startup list
[HPHmon05]
Confirmed=?
Filename=hphmon05.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Hphome]
Confirmed=X
Filename=hphome.js
Description=Homepage hijacker
Source=Paul Collins Startup list
[HPHUPD**]
Confirmed=N
Filename=hphupd**.exe
Description=HP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs
Source=Paul Collins Startup list
[HPHUPD05]
Confirmed=?
Filename=hphupd05.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[hpjsiroute]
Confirmed=?
Filename=hpjsira.exe
Description=<font color="#FF0000">Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2"</font>
Source=Paul Collins Startup list
[HpLamp]
Confirmed=Y
Filename=HPLAMP.EXE
Description=HP Scanner Utility that controls your scannerÆs light bulb. Needed if it's switched on. Also refer <a href="http://www.hp.com/cgi-bin/cposupport/get_doc.pl?SNI=hpscanjet320506&LC=scanners&Tfile=nps05042" target="_blank">here</a> for troubleshooting
Source=Paul Collins Startup list
[hplampc]
Confirmed=U
Filename=hplampc.exe
Description=HP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off
Source=Paul Collins Startup list
[HPLJ Config]
Confirmed=Y
Filename=SetConfig.exe
Description=Connects system to networked HP printer.
Source=Paul Collins Startup list
[HPLogiFinder]
Confirmed=U
Filename=hp_finder.exe
Description=HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
Source=Paul Collins Startup list
[HpMmKbd]
Confirmed=U
Filename=HpMmKbd.exe
Description=HPÆs multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
Source=Paul Collins Startup list
[hpodblia]
Confirmed=N
Filename=hpodblia.exe
Description=HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Source=Paul Collins Startup list
[hpoddt01.exe]
Confirmed=N
Filename=N/A
Description=Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started
Source=Paul Collins Startup list
[hpodlb08]
Confirmed=N
Filename=hpodlb08.exe
Description=HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Source=Paul Collins Startup list
[hpotdd01.exe]
Confirmed=Y
Filename=hpotdd01.exe
Description=Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems"
Source=Paul Collins Startup list
[hpppta]
Confirmed=Y
Filename=HPPPTA.exe
Description=HP parallel port driver for certain hardware
Description=Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try <a href="http://www.hp.com">www.hp.com</a>, pick your OS option under the SUPPORT tab, follow the instructions and you will find an updated lamp control patch
Source=Paul Collins Startup list
[hpqcmon]
Confirmed=?
Filename=hpqcmon.exe
Description=<font color="#FF0000">From HP and related to digital imaging</font>
Source=Paul Collins Startup list
[HPSCANMonitor]
Confirmed=U
Filename=hpsjvxd.exe
Description=HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
Description=HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment
Source=Paul Collins Startup list
[HPStart]
Confirmed=N
Filename=hpstart.wsf
Description=This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
Source=Paul Collins Startup list
[hpsysconf1]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the <a href="http://de.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=59209&VName=TROJ_VIVIA.A&VSect=T" target="_blank">VIVIA.A</a> TROJAN!
Source=Paul Collins Startup list
[hpsysdrv]
Confirmed=U
Filename=hpsysdrv.exe
Description=This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working
Source=Paul Collins Startup list
[HPU]
Confirmed=N
Filename=ProvenTactics.exe
Description=<a href="http://www.proventactics.com/" target="_blank">Proven Internet Marketing</a> software
Source=Paul Collins Startup list
[HPZTS04]
Confirmed=N
Filename=hpzts04.exe
Description=Hewlett Packard printer toolbox shortcut that resides in the system tray
Source=Paul Collins Startup list
[HP_dla]
Confirmed=N
Filename=dlatray.exe
Description=On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD
Source=Paul Collins Startup list
[HREF.OCX]
Confirmed=U
Filename=regsvr32.exe ....HREF.OCX
Description=HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as <a href="http://software.xfx.net/utilities/popupkiller/index.php" target="_blank">PopUpKiller</a>
Source=Paul Collins Startup list
[hsim]
Confirmed=X
Filename=isearch.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[hsim]
Confirmed=X
Filename=sexgame.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[hsim]
Confirmed=X
Filename=toolbar.exe
Description=Unidentified malware
Source=Paul Collins Startup list
[Hti]
Confirmed=U
Filename=npdor.exe
Description=Appears in startup if you have chosen to participate in on survey by <a href="http://www.npdor.com/" target="_blank"> NPD Online Research</a>. Required for the survey to work correctly. Otherwise not required
Source=Paul Collins Startup list
[HTpatch]
Confirmed=U
Filename=htpatch.exe
Description=HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
Source=Paul Collins Startup list
[HtProtect]
Confirmed=X
Filename=AVprotect.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.l@mm.html" target="_blank">NETSKY.L</a> WORM!
Source=Paul Collins Startup list
[httpd]
Confirmed=X
Filename=c_pan.exe
Description=Added by a variant of the DELF-A TROJAN!
Source=Paul Collins Startup list
[https-ssl]
Confirmed=X
Filename=https.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.moega.d.html" target="_blank">MOEGA.D</a> WORM!
Source=Paul Collins Startup list
[huhdir]
Confirmed=?
Filename=huhdir.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[huigezi]
Confirmed=X
Filename=HgzServer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.c.html" target="_blank">GRAYBIRD.C</a> TROJAN!
Source=Paul Collins Startup list
[Hvid]
Confirmed=X
Filename=Hvid.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[HWINFO*]
Confirmed=X
Filename=HWINFO*
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.purol.html" target="_blank"> PUROL</a> WORM! where * is a random character
Source=Paul Collins Startup list
[HWinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[HXDL.EXE]
Confirmed=X
Filename=HXDL.EXE
Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www.c-squad.org/hxdl.html" target="_blank">here</a>
Source=Paul Collins Startup list
[HXIUL.EXE]
Confirmed=X
Filename=HXIUL.EXE
Description=Attune HelpExpress - spyware. Disable and uninstall - see <a href="http://www.c-squad.org/hxdl.html" target="_blank">here</a>
Source=Paul Collins Startup list
[HydarVisionDesktopManager]
Confirmed=U
Filename=desk95.exe
Description=ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as <a href="http://support.microsoft.com/?id=810937" target=_blank>this one</a>. HydraVision can be uninstalled through Add/Remove Programs
Source=Paul Collins Startup list
[HydraVisionDesktopManager]
Confirmed=U
Filename=desk98.exe
Description=ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
Source=Paul Collins Startup list
[HydraVisionViewport]
Confirmed=U
Filename=viewport.exe
Description=ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
Source=Paul Collins Startup list
[Hyper Start]
Confirmed=X
Filename=instantmsgrs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotnh.html" target=_blank>RBOT-NH</a> WORM!
Source=Paul Collins Startup list
[I-Worm.GiGu]
Confirmed=X
Filename=uGiG.eXe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gink.worm.html" target="_blank">GINK</a> WORM!
Source=Paul Collins Startup list
[I386]
Confirmed=X
Filename=I386.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mypower.b@mm.html" target="_blank"> MYPOWER</a> WORM!
Source=Paul Collins Startup list
[I81SHELL]
Confirmed=?
Filename=I81SHELL.exe
Description=<font color="#FF0000">Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard</font>
Source=Paul Collins Startup list
[i8kfangui]
Confirmed=U
Filename=i8kfangui.exe
Description=Graphical interface for fan speed control
Source=Paul Collins Startup list
[IAAnotif]
Confirmed=U
Filename=iaanotif.exe
Description=IAA Event Monitor User Notification Tool - part of <a href="http://www.intel.com/support/chipsets/iaa/" target="_blank"> Intel« Application Accelerator</a> - "a performance software package for desktop PCs using select Intel« chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
Source=Paul Collins Startup list
[iamapp]
Confirmed=Y
Filename=iamapp.exe
Description=AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well
Source=Paul Collins Startup list
[Iamnacho On Irc.MusIrc.com Is a Homosexual!]
Confirmed=X
Filename=XBox64.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.y.html" target="_blank">RANDEX.Y</a> WORM!
Source=Paul Collins Startup list
[Iap]
Confirmed=?
Filename=iap.exe
Description=<font color="#FF0000">Possibly part of <a href="http://docs.us.dell.com/docs/software/smcliins/cli60/en/ug/intro.htm" target="_blank">Dell OpenManage Client Instrumentation</a> - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?</font>
Source=Paul Collins Startup list
[IASHLPR]
Confirmed=X
Filename=IASHLPR.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
Source=Paul Collins Startup list
[IBM Warranty Notification]
Confirmed=?
Filename=ERTS0749.exe
Description=IBM Warranty Notification - <font color="#FF0000">presumably it's a reminder to either register or that warranty is about to expire?</font>
Source=Paul Collins Startup list
[ibmmessages]
Confirmed=N
Filename=ibmmessages.exe
Description=Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"
Source=Paul Collins Startup list
[Ibmmon.exe]
Confirmed=?
Filename=Ibmmon.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Ibmpmsvc]
Confirmed=U
Filename=ibmpmsvc.exe
Description=Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes
Source=Paul Collins Startup list
[IBMUltraBayHotSwapCPLLoader]
Confirmed=U
Filename=IBMBAY2N.EXE
Description=Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
Source=Paul Collins Startup list
[IBMUltraBayHotSwapSound]
Confirmed=?
Filename=IBMBAYSN.EXE
Description=<font color="#FF0000">Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?</font>
Description=Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. <font color="#FF0000">May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices</font>
Source=Paul Collins Startup list
[iClean]
Confirmed=U
Filename=iClean.exe
Description=<a href="http://www.nsclean.com/ieclean.html" target="_blank">IEClean</a> - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"
Source=Paul Collins Startup list
[iCn]
Confirmed=N
Filename=NAG.EXE
Description=<a href="http://www.rocketdownload.com/Details/Inte/4948.htm" target="_blank">iChoose</a> - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist
Source=Paul Collins Startup list
[ICO]
Confirmed=N
Filename=ICO.EXE
Description=Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
Source=Paul Collins Startup list
[Icon Animation]
Confirmed=N
Filename=HDE.EXE
Description=Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
Source=Paul Collins Startup list
[Icon Hearit 95]
Confirmed=N
Filename=hearit95.exe
Description=Audio desktop customization utility from Moon Valley Software. Resource hog
Source=Paul Collins Startup list
[Icon Hearit 98]
Confirmed=N
Filename=hearit98.exe
Description=Audio desktop customization utility from Moon Valley Software. Resource hog
Source=Paul Collins Startup list
[Icon lptt01]
Confirmed=X
Filename=icon.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[Icon ml097e]
Confirmed=X
Filename=icon.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[ICONCLNT]
Confirmed=Y
Filename=iconclnt.exe
Description=APC PowerChute Tray Icon. Associated with the <a href="#UPS"> UPS</a> listing
Source=Paul Collins Startup list
[ICONDESK]
Confirmed=U
Filename=ICONDESK.EXE
Description=Small utility which will allow you the option of hiding or showing your desktop icons
Source=Paul Collins Startup list
[Iconfig.exe]
Confirmed=N
Filename=Iconfig.exe
Description=Icon for LS-120 "Superdisk"
Source=Paul Collins Startup list
[iConfigLoader]
Confirmed=X
Filename=DIIhost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Iconoid]
Confirmed=N
Filename=Iconoid.exe
Description=<a href="http://www.sillysot.com/index.html" target="_blank">Iconoid</a> is a desktop icon manager
Source=Paul Collins Startup list
[Iconsaver]
Confirmed=N
Filename=Iconsaver.exe
Description=<a href="http://www.iconsaver.com/index.html" target="_blank">IconSaver</a> is a desktop icon manager
Source=Paul Collins Startup list
[ICQ Center]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randin.html" target="_blank">RANDIN</a> WORM!
Source=Paul Collins Startup list
[ICQ Hacking Pro]
Confirmed=X
Filename=ICQpro.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_NETSPY" target="_blank">NETSPY</a> TROJAN!
Source=Paul Collins Startup list
[ICQ Lite]
Confirmed=N
Filename=ICQLite.exe
Description=<a target="_blank" href="http://www.icq.com/download/">ICQ Lite</a> - compact version of the popular messaging program
Source=Paul Collins Startup list
[ICQ Lite Messenger]
Confirmed=X
Filename=[random filename]
Description=Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or Winnt\System32 directory
Source=Paul Collins Startup list
[ICQ Net]
Confirmed=X
Filename=winlogon.exe
Description=Added by variants of the NETSKY WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[ICQ Plus]
Confirmed=N
Filename=vplus.exe
Description=<a href="http://www.icqplus.org" target="_blank">ICQ Plus</a> is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs
Source=Paul Collins Startup list
[ICSDCLT]
Confirmed=U
Filename=rundll32.exe Icsdclt.dll, ICSClient
Description=Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
Source=Paul Collins Startup list
[ICServer]
Confirmed=N
Filename=Icserver.exe
Description=Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
Source=Paul Collins Startup list
[ICSMGR]
Confirmed=Y
Filename=ICSMGR.EXE
Description=Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if youÆre sharing the internet on various computers
Source=Paul Collins Startup list
[IC_KEY_3]
Confirmed=N
Filename=spvic.exe
Description=<a href="http://www.instantchess.com/?SN=Z4dMzyutgpE9Pspv&ABT=3" target="_blank">Instant Chess</a> related
Source=Paul Collins Startup list
[ID Commander]
Confirmed=N
Filename=IDCom.exe
Description=Caller ID utility for identifying incoming telephone numbers
Source=Paul Collins Startup list
[ID8525]
Confirmed=X
Filename=ID8525.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ID8525.A" target="_blank">ID8525.A</a> TROJAN!
Source=Paul Collins Startup list
[ID8525]
Confirmed=X
Filename=id85255.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ID8525.A" target="_blank">ID8525.A</a> TROJAN!
Source=Paul Collins Startup list
[IDA]
Confirmed=?
Filename=IDA.EXE
Description=<font color="#FF0000">HP related - in a Program FilesHewlett-PackardPC COE folder</font>
Source=Paul Collins Startup list
[IDE]
Confirmed=X
Filename=ide.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.assasin.f.html" target="_blank">ASSASIN.F</a> TROJAN!
Source=Paul Collins Startup list
[IDE Loader]
Confirmed=X
Filename=IDElibr32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.xilon.trojan.html" target="_blank">XILON</a> TROJAN! Related to the game "Diablo II"
Source=Paul Collins Startup list
[idecntl]
Confirmed=X
Filename=idecntl.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[iDesktop]
Confirmed=U
Filename=idesktop.exe
Description=<a href="http://www.immersion.com/products/ce/generaldownloads.shtml" target="_blank">Immersion TouchWare Desktop</a> software for devices such as the Logitech iFeel Mouse
Description=Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
Source=Paul Collins Startup list
[IE Doctor]
Confirmed=U
Filename=IEDoctor.exe
Description=IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
Description=Integrity checker for <a href="http://www.iconedit2.com/" target="_blank">IconEdit2</a> icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
Source=Paul Collins Startup list
[IECleanAux]
Confirmed=U
Filename=Ieboot6.exe
Description=<a href="http://www.nsclean.com/ieclean.html" target="_blank">IEClean</a> by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
Source=Paul Collins Startup list
[iedll]
Confirmed=X
Filename=iedll.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com
Source=Paul Collins Startup list
[IEDriver]
Confirmed=X
Filename=IEDriver.exe
Description=Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_POPMON.A" target="_blank">POPMON.A</a> TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[IEFeatures]
Confirmed=X
Filename=Internetfeatures.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_POPMON.A" target="_blank">POPMON.A</a> TROJAN! - also known as PopMonster adware
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spex.worm.html" target="_blank"> SPEX</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spex.b.worm.html" target="_blank"> SPEX.B</a> WORMS!
Source=Paul Collins Startup list
[Iesar]
Confirmed=X
Filename=Iesar.exe
Description=Browser hijacker - redirecting to an adult web page
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nemog.c.html" target="_blank">NEMOG.C</a> TROJAN!
Source=Paul Collins Startup list
[ietsr]
Confirmed=N
Filename=ietsr.exe
Description=<a href="http://www.nsclean.com/ieclean.html" target="_blank">IEClean</a> by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
Source=Paul Collins Startup list
[ieupdate]
Confirmed=X
Filename=MCP****.exe [**** = random char]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.asoxy.html" target="_blank">ASOXY</a> TROJAN!
Source=Paul Collins Startup list
[ieupdate]
Confirmed=X
Filename=mcpdll32.exe
Description=Adware downloader trojan
Source=Paul Collins Startup list
[Iexplore]
Confirmed=X
Filename=iexplore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.boxer.html" target="_blank">BOXER</a> TROJAN! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[IEXPLORE]
Confirmed=X
Filename=iexplore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.aphexdoor.html" target="_blank">APHEXDOOR</a> TROJAN! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Iexplore Services]
Confirmed=X
Filename=iexplore.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[iexplorer lptt01]
Confirmed=X
Filename=iexplorer.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[iexplorer ml097e]
Confirmed=X
Filename=iexplorer.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[IFSplash.exe]
Confirmed=U
Filename=IFSplash.exe
Description=I-FORCE driver for force feedback steering wheel
Source=Paul Collins Startup list
[igfxtray]
Confirmed=N
Filename=igfxtray.exe
Description=Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
Description=<a href="http://nn101.virtualave.net/clean.html" target="_blank">System Wiper</a> from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
Source=Paul Collins Startup list
[IJ75P2PSERVER]
Confirmed=Y
Filename=IJ75P2PS.EXE
Description=Printer utility which is required in order to make the printer work correctly
Source=Paul Collins Startup list
[IKE Service 95]
Confirmed=Y
Filename=IKEService.exe
Description=Associated with <a href="http://www.pgpi.org/" target="_blank">PGP</a>. The PGP Tray can be
disabled, but without IKESERVICE you won't be able to de- or encrypt anything
Source=Paul Collins Startup list
[iKeyWorks]
Confirmed=U
Filename=IKEYMAIN.EXE
Description=<a href="http://www.a4tech.com/a4techenglish/index.html" target="_blank">A4Tech</a> wireless keyboard driver and utility
Source=Paul Collins Startup list
[iLLeGaL]
Confirmed=X
Filename=Mplayer.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_HOLAR.C" target="_blank">HOLAR.C</a> (or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.galil@mm.html" target="_blank">GALIL</a>) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
Source=Paul Collins Startup list
[iLLeGaL.exe]
Confirmed=X
Filename=Mplayer.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_HOLAR.C" target="_blank">HOLAR.C</a> (or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.galil@mm.html" target="_blank">GALIL</a>) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
Source=Paul Collins Startup list
[ILO_Office_Manager]
Confirmed=?
Filename=IntEdReg.exe /OFFMAN
Description=<a href="http://www.intense.co.uk/" target="_blank">Intense Educational Ltd</a> - Language Office Software. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[iLyric]
Confirmed=U
Filename=iLyric.exe
Description=<a href="http://www.ilyric.net/winamp.html" target=_blank>iLyric</a> plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
Source=Paul Collins Startup list
[iM Start Center]
Confirmed=N
Filename=iM_Tray.exe
Description=Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
Description=Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run
Description=<a href="http://www.acdsystems.com/English/Products/ImageFox/index.htm?LAN=EnglishX20" target="_blank">ImageFox 2.0</a> is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes
Source=Paul Collins Startup list
[Imagemgt32]
Confirmed=X
Filename=Imagemgt32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[imekrig]
Confirmed=N
Filename=imekrig.exe
Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
Source=Paul Collins Startup list
[IMEKRMIG6.1]
Confirmed=N
Filename=IMEKRMIG.EXE
Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
Source=Paul Collins Startup list
[Imesh]
Confirmed=N
Filename=??
Description=<a href="http://www.imesh.com" target="_blank">Imesh</a> is a file sharing system
Source=Paul Collins Startup list
[Imesh Auto Update]
Confirmed=N
Filename=??
Description=Update check for the <a href="http://www.imesh.com" target=_blank>Imesh</a> file sharing system. Turn the update off under "options"
Source=Paul Collins Startup list
[ImgIcon]
Confirmed=U
Filename=ImgIcon.exe
Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Source=Paul Collins Startup list
[ImgStart]
Confirmed=N
Filename=ImgStart.exe
Description=Used by Iomega drives. Details of its purpose can be found <a href="http://pw2.netcom.com/~deepone/zipjaz/ioware.html#startup" target="_blank">here</a>. Available via Start -> Programs
Source=Paul Collins Startup list
[imjpmig]
Confirmed=N
Filename=IMJPMIG.EXE
Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
Source=Paul Collins Startup list
[Imjpmig8.1]
Confirmed=N
Filename=IMJPMIG.EXE
Description=Part of MS <a href="http://www.microsoft.com/windows/ie/downloads/recommended/ime/default.asp" target="_blank">Input Method Editor</a> which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
Source=Paul Collins Startup list
[immcheck.exe]
Confirmed=?
Filename=immcheck.exe
Description=<font color="#FF0000">Related to I-FORCE driver for force feedback steering wheel?</font>
Source=Paul Collins Startup list
[IMOL]
Confirmed=U
Filename=IMOLApp.exe
Description=IncrediMail for Office <a href="http://www.incredimail.com/english/help/sysadmin.html" target=_blank>Outlook Add-On</a>
Source=Paul Collins Startup list
[Imonitor]
Confirmed=N
Filename=Plguni.exe
Description=<a href="http://www.mcafee.com/myapps/qc3/default.asp" target="_blank">McAfee QuickClean 3.0</a> - removes internet clutter and unwanted programs
Source=Paul Collins Startup list
[IMStart]
Confirmed=U
Filename=IMStart.exe
Description=<a href="http://www.intermute.com/products/index.html" target=_blank>InterMute</a> security software related
Description=<a href="http://www.nero.com/" target="_blank">Ahead InCD</a> packet writing software. Similar to DirectCD. On my system there isn't an entry, on another visitor's there is. Run manually before insert an appropriately formatted CD-RW disk
Source=Paul Collins Startup list
[IncMail]
Confirmed=N
Filename=IncMail.exe
Description="<a href="http://www.incredimail.com/english/index.html" target="_blank">IncrediMail</a> is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
Source=Paul Collins Startup list
[InControl Desktop Manager]
Confirmed=N
Filename=DMHKEY.EXE
Description=For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
Source=Paul Collins Startup list
[Incredimail]
Confirmed=N
Filename=incredimail.exe
Description="<a href="http://www.incredimail.com/english/index.html" target="_blank">IncrediMail</a> is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
Source=Paul Collins Startup list
[IndexSearch]
Confirmed=N
Filename=IndexSearch.exe
Description=Associated with PaperPort scanner software from ScanSoft
Source=Paul Collins Startup list
[Inet DataBase]
Confirmed=X
Filename=Inetdbs.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.qeds@mm.html" target=_blank>QEDS</a> WORM!
Source=Paul Collins Startup list
[Inet Delivery]
Confirmed=X
Filename=Intdel.exe
Description=Spyware
Source=Paul Collins Startup list
[Inet Delivery]
Confirmed=X
Filename=intdel_2.exe
Description=Spyware
Source=Paul Collins Startup list
[Inetapi]
Confirmed=X
Filename=Netapi.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_NETDEVIL.14" target="_blank">NETDEVIL.14</a> TROJAN!
Source=Paul Collins Startup list
[inetcntrl]
Confirmed=U
Filename=inetcntrl.exe
Description=Bsafe Online - internet filter
Source=Paul Collins Startup list
[InetConf]
Confirmed=?
Filename=inetconf.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Inetd]
Confirmed=U
Filename=INETD32.EXE
Description=<a href="http://www.hummingbird.com/products/nc/inetd/index.html" target="_blank">Windows Inet Daemon</a> from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation
Source=Paul Collins Startup list
[inetinfo.exe]
Confirmed=U
Filename=inetinfo.exe
Description=Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more)
Source=Paul Collins Startup list
[inetmgr]
Confirmed=X
Filename=inetmgr.exe
Description=Actual Names <a href="http://www.pestpatrol.com/pestinfo/a/actualnames.asp" target="_blank">(AdvSearch)</a> Internet Keywords parasite
Source=Paul Collins Startup list
[InetMSN]
Confirmed=X
Filename=msnet.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJAN!
Source=Paul Collins Startup list
[Info Select]
Confirmed=U
Filename=is.exe
Description=<a href="http://www.miclog.com/isover.htm" target="_blank">Info Select</a> from Micro Logic - personal information manager
Source=Paul Collins Startup list
[Info32x]
Confirmed=X
Filename=Info32x.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Infoplay.exe]
Confirmed=?
Filename=Infoplay.exe
Description=<font color="#FF0000">Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine <a href="http://www.allyoursearch.com/" target="_blank">websites</a> (which I chose not to). What does it do and is it needed?</font>
Source=Paul Collins Startup list
[Infra-red Monitor]
Confirmed=U
Filename=IRMON.EXE
Description=System Tray access to infra-red devices. Not required unless you use infra-red devices
Source=Paul Collins Startup list
[infus]
Confirmed=X
Filename=infus.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Infuzer]
Confirmed=U
Filename=Infuzer.exe
Description=<a href="http://www.infuzer.com/IDC/features/" target="_blank">Infuzer</a> - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"
Description=Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
Source=Paul Collins Startup list
[Ink Monitor]
Confirmed=N
Filename=InkMonitor.exe
Description=Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
Source=Paul Collins Startup list
[InkWatch]
Confirmed=N
Filename=InkWatch.exe
Description=Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
Source=Paul Collins Startup list
[InoRPC]
Confirmed=Y
Filename=InoRpc.exe
Description=Associated with <a href="http://www1.my-etrust.com/?CFID=6909348&CFTOKEN=43ce20d-0001f1aa-f6e5-1d77-be1e-2f0eac14303f" target="_blank">eTrust Antivirus/InoculateIT</a>
Source=Paul Collins Startup list
[InoRT]
Confirmed=Y
Filename=InoRT9x.exe
Description=Associated with the Realtime Monitor of <a href="http://www1.my-etrust.com/?CFID=6909348&CFTOKEN=43ce20d-0001f1aa-f6e5-1d77-be1e-2f0eac14303f" target="_blank">eTrust Antivirus/InoculateIT</a> version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see <a href="http://support.ca.com/techbases/ilnt/31103.html" target="_blank">here</a>
Source=Paul Collins Startup list
[InoTask]
Confirmed=U
Filename=InoTask.exe
Description=Scheduled scans and signature updates for <a href="http://www1.my-etrust.com/?CFID=6909348&CFTOKEN=43ce20d-0001f1aa-f6e5-1d77-be1e-2f0eac14303f" target="_blank">eTrust Antivirus/InoculateIT</a> version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see <a href="http://support.ca.com/techbases/ilnt/31103.html" target="_blank">here</a>
Source=Paul Collins Startup list
[insCOA5]
Confirmed=?
Filename=insCOA5.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Install Pending Files]
Confirmed=?
Filename=sifxinst.exe
Description=Uninstall program for <a href="http://www.lanovation.com/" target="_blank">Lanovation's</a> Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see <font color="#FF0000"><a href="http://www.lanovation.com/support/docs/General/rollbackfiles_prism.htm" target="_blank">here</a>. Is it required?</font>
Source=Paul Collins Startup list
[InstallAurealDemos]
Confirmed=N
Filename=InstallAurealDemos.js
Description=Used to initialize the Aureal A3D demos InstallShield wizard
Source=Paul Collins Startup list
[InstallBuddy]
Confirmed=U
Filename=Ibtna.exe
Description=<a href="http://www.bluenomad.com/ib/prod_installbuddy_details.html" target="_blank">InstallBuddy</a> - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync
Source=Paul Collins Startup list
[Installed shell32.dll]
Confirmed=X
Filename=Office.exe...
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[InstallNAIProduct]
Confirmed=?
Filename=SETUP.EXE
Description=<font color="#FF0000">Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?</font>
Description=From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG. PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner
Source=Paul Collins Startup list
[Instant Wireless Configuration Utility]
Confirmed=U
Filename=WUSB11cfg.exe
Description=Utility used by the <a href="http://www.linksys.com/default.asp" target="_blank">LINKSYS</a> LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
Source=Paul Collins Startup list
[InstantAccess]
Confirmed=N
Filename=INSTAN~1.EXE
Description=From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
Source=Paul Collins Startup list
[InstantDrive]
Confirmed=U
Filename=InstantDrive.exe
Description=<a href="http://www.pinnaclesys.com" target="_blank">Pinnacle Systems</a> (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computerÆs hard drive. Part of InstantCD/DVD burning software
Source=Paul Collins Startup list
[InstantPleasure]
Confirmed=X
Filename=instantpleasure.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[InstantPleasureXXX]
Confirmed=X
Filename=instantpleasurexxx.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[InstantTray]
Confirmed=N
Filename=PCLETray.exe
Description=<a href="http://www.pinnaclesys.com/ProductPage_n.asp?Product_ID=1431&Langue_ID=7" target=_blank>Pinnacle InstantCD/DVD</a> disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually
Source=Paul Collins Startup list
[instit]
Confirmed=X
Filename=instit.bat
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.opaserv.h.worm.html" target="_blank">OPASERV.H</a> WORM!
Source=Paul Collins Startup list
[instit]
Confirmed=X
Filename=INSTIT.BAT
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.K" target="_blank">OPASERV.K</a> WORM!
Description=System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
Source=Paul Collins Startup list
[Intel File Transfer]
Confirmed=U
Filename=xfr.exe
Description=Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
Source=Paul Collins Startup list
[Intel PDS]
Confirmed=U
Filename=pds.exe
Description=Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
Source=Paul Collins Startup list
[Intel Product Number Utility]
Confirmed=U
Filename=IntelProcNumUtility.exe
Description=Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information <a href="http://www.intel.com/support/processors/pentiumiii/psu.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[Intel PROSet Tray Icon]
Confirmed=N
Filename=promon.exe
Description=System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
Source=Paul Collins Startup list
[Intel system works]
Confirmed=X
Filename=iis.exe
Description=Added by the <a href="http://ae.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.QGA" target=_blank>RBOT.QGA</a> WORM!
Source=Paul Collins Startup list
[InteliSys]
Confirmed=X
Filename=smss.exe
Description=Advertisingvision adware - file is located in C:\Windows or C:\Winnt, and not in it's System32 subdirectory, as is the case with the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/smss/" target="_blank"> Smss.exe</a> system file which would normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[Intellitype]
Confirmed=U
Filename=type32.exe
Description=For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them
Source=Paul Collins Startup list
[IntelMEM]
Confirmed=U
Filename=IntelMEM.exe
Description=Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line
Source=Paul Collins Startup list
[IntelProcNumUtility]
Confirmed=U
Filename=cpunumber.exe
Description=Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information <a href="http://www.intel.com/support/processors/pentiumiii/psu.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[Intel« Common User Interface]
Confirmed=N
Filename=igfxtray.exe
Description=Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Intense Registry Service]
Confirmed=?
Filename=IntEdReg.exe /CHECK
Description=<a href="http://www.intense.co.uk/" target="_blank">Intense Educational Ltd</a> - Language Office Software. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[InterceptedSystem]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32anaconb.html" target=_blank>ANACON-B</a> WORM!
Source=Paul Collins Startup list
[InterCheck Monitor]
Confirmed=Y
Filename=Icmon.exe
Description=Part of <a href="http://www.sophos.com/products/software/" target="_blank">Sophos</a> ant-virus sofware
Source=Paul Collins Startup list
[Interdll]
Confirmed=X
Filename=Interdll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.delf.family.html" target="_blank">DELF</a> family of TROJANS!
Source=Paul Collins Startup list
[Internal]
Confirmed=X
Filename=[trojan filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.smother.html" target="_blank">SMOTHER</a> and <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.translat.html" target="_blank"> TRANSLAT</a> TROJANS!
Source=Paul Collins Startup list
[Internal]
Confirmed=X
Filename=regedit.exe /s %windir%c:\[month number]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/js.fortnight.d.html" target="_blank">FORTNIGHT.D</a> TROJAN!
Source=Paul Collins Startup list
[InternalSystray]
Confirmed=X
Filename=Kazza.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=16106" target="_blank">OPTIX</a> TROJAN! Note - unlike the valid KaZaA executable, this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP)
Source=Paul Collins Startup list
[internat]
Confirmed=X
Filename=internat.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlydraf.html" target=_blank>LYDRA-F</a> TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
Source=Paul Collins Startup list
[Internat]
Confirmed=X
Filename=systray.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.p.html" target="_blank">ALADINZ.P</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/systray/" target="_blank">systray.exe</a> process
Source=Paul Collins Startup list
[Internat Conf]
Confirmed=X
Filename=bootconf.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com; see for example <a href="http://boards.cexx.org/viewtopic.php?p=2464#2464" target="_blank"> here</a>
Source=Paul Collins Startup list
[internat.exe]
Confirmed=N
Filename=internat.exe
Description=Language selection icon in system tray
Source=Paul Collins Startup list
[Internat.exe]
Confirmed=X
Filename=internat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.netsnake.html" target="_blank">NETSNAKE</a> TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon
Source=Paul Collins Startup list
[internct]
Confirmed=X
Filename=WinSocks5.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.f.html" target="_blank">GRAYBIRD.F</a> TROJAN!
Source=Paul Collins Startup list
[Internet Answering Machine]
Confirmed=U
Filename=IAMNET~1.EXE
Description=From <a href="http://www.callwave.com/" target="_blank">Callwave</a>. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
Source=Paul Collins Startup list
[Internet Answering Machine]
Confirmed=U
Filename=IAM.exe
Description=From <a href="http://www.callwave.com/" target=_blank>Callwave</a> - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
Source=Paul Collins Startup list
[Internet Config]
Confirmed=X
Filename=svchosts.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJAN!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.evianc.html" target="_blank">EVIAN.C</a> WORM!
Source=Paul Collins Startup list
[Internet Explorer]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.lorsis.worm.html" target="_blank">LORSIS</a> WORM! Note - the legitimate IE (iexplore.exe) does not figure in Msconfig/Startup unless added manually and this loads from the "RunServices" key
Source=Paul Collins Startup list
[Internet Explorer]
Confirmed=X
Filename=IEXPLORE.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotey.html" target="_blank">RBOT-EY</a> WORM! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Internet Explorer Updater]
Confirmed=X
Filename=lexbac.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/download.trojan.html" target="_blank">DOWNLOAD</a> TROJAN!
Source=Paul Collins Startup list
[Internet Explorer Updater]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.reur.b.html" target="_blank">REUR.B</a> WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Source=Paul Collins Startup list
[Internet History Eraser]
Confirmed=U
Filename=HERASER.exe
Description=<a href="http://www.internet-history-eraser.com/index.html" target="_blank">Internet History Eraser</a> - deletes your browsing tracks
Source=Paul Collins Startup list
[Internet Loader1]
Confirmed=X
Filename=MSInstall61.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbot.b.worm.html" target="_blank">KWBOT.B</a> WORM!
Description=Internet connection optimizer. Leave this enabled if you find it improves your connection
Source=Paul Collins Startup list
[Internet Send]
Confirmed=X
Filename=More log.exe
Description=Unidentfied adware
Source=Paul Collins Startup list
[Internet Service]
Confirmed=X
Filename=intersvc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotde.html" target=_blank>SPYBOT-DE</a> WORM!
Source=Paul Collins Startup list
[internet service]
Confirmed=X
Filename=syscfg32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqs.html" target=_blank>RBOT-QS</a> WORM!
Source=Paul Collins Startup list
[Internet Services]
Confirmed=X
Filename=systemdev.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpw.html" target="_blank">SDBOT-PW</a> WORM!
Source=Paul Collins Startup list
[INTERNET SERVISES]
Confirmed=X
Filename=winz32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbotz.worm.html" target="_blank">KWBOT.Z</a> WORM!
Source=Paul Collins Startup list
[Internet Sharing Server]
Confirmed=Y
Filename=iss_srvr.exe
Description=<a target="_blank" href="http://www.intel.com/products/desk_lap/hm_sm_office/index.htm">Intel AnyPoint</a> internet sharing software
Source=Paul Collins Startup list
[Internet Sweeper]
Confirmed=N
Filename=Sweeper.exe
Description=<a href="http://www.bmesite.com/" target="_blank">Internet Sweeper</a> - removes unnecessart left over files after browsing the internet
Source=Paul Collins Startup list
[Internet Timer]
Confirmed=U
Filename=ITIMER.exe
Description=Shareware dial-up connection call cost calculator from <a href="http://www.ratsoft.freeserve.co.uk/" target="_blank">Ratsoft</a>
Source=Paul Collins Startup list
[Internet Washer Pro]
Confirmed=X
Filename=iw.exe
Description=<a href="http://www.internetwasher.com/" target="_blank">Internet Washer</a> manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
Source=Paul Collins Startup list
[Internet.exe]
Confirmed=X
Filename=Internet.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.magiccall.html" target="_blank">MAGICCALL</a> VIRUS!
Source=Paul Collins Startup list
[InternetWasherPro]
Confirmed=X
Filename=iw.exe
Description=<a href="http://www.internetwasher.com/" target="_blank">Internet Washer</a> manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
Source=Paul Collins Startup list
[INTERNET_SERVISES]
Confirmed=X
Filename=winz32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.q.html" target="_blank">SDBOT.Q</a> TROJAN!
Source=Paul Collins Startup list
[Internt]
Confirmed=X
Filename=Internt.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.peeper.html" target="_blank">PEEPER</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.carufax.a.html" target="_blank">CARUFAX.A</a> TROJANS!
Source=Paul Collins Startup list
[InterTrust Quick Start]
Confirmed=N
Filename=it_cpq~1.exe
Description=<a href="http://www.intertrust.com/index.html" target="_blank">InterTrust</a> offers something known as Digital Rights Management to control legal software download and other E-commerce related business
Source=Paul Collins Startup list
[InterU]
Confirmed=X
Filename=WINDRV.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_IRCINTER.A" target="_blank">IRCINTER.A</a> TROJAN!
Source=Paul Collins Startup list
[Intervideo Win Cinema Manager]
Confirmed=N
Filename=WinCinemaMgr.exe
Description=<a href="http://www.intervideo.com/jsp/WinCinema_Manager_Download.jsp" target="_blank">WinCinema Manager</a> is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo Win Cinema Manager]
Confirmed=N
Filename=WINCIN~1.EXE
Description=<a href="http://www.intervideo.com/jsp/WinCinema_Manager_Download.jsp" target="_blank">WinCinema Manager</a> is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinCinema Manager]
Confirmed=N
Filename=WinCinemaMgr.exe
Description=<a href="http://www.intervideo.com/jsp/WinCinema_Manager_Download.jsp" target="_blank">WinCinema Manager</a> is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinCinema Manager]
Confirmed=N
Filename=WINCIN~1.EXE
Description=<a href="http://www.intervideo.com/jsp/WinCinema_Manager_Download.jsp" target="_blank">WinCinema Manager</a> is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinScheduler]
Confirmed=N
Filename=WinScheduler.exe
Description=<a href="http://www.intervideo.com" target="_blank">WinScheduler</a> is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Source=Paul Collins Startup list
[Intervideo WinScheduler]
Confirmed=N
Filename=SchSvr.exe
Description=<a href="http://www.intervideo.com" target="_blank">WinScheduler</a> is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Source=Paul Collins Startup list
[InterWARN]
Confirmed=U
Filename=interwarn.exe
Description=<a href="http://www.interwarn.com/interwarn.html" target="_blank">InterWARN</a> by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs
Source=Paul Collins Startup list
[Intmgr]
Confirmed=X
Filename=Intmgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Intrenat]
Confirmed=X
Filename=Intrenat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.lemir.e.html" target="_blank">LEMIR.E</a> TROJAN!
Source=Paul Collins Startup list
[Introducing Media Manager]
Confirmed=N
Filename=SPLASHA.EXE
Description=<a href="http://www.frontpageworld.com/frontpagetools/mediamanager/default.htm" target="_blank">MS Media Manager</a> tour. Not required
Source=Paul Collins Startup list
[Introduction-Registration]
Confirmed=N
Filename=??
Description=For Compaq PC's. Should only run first time, PC Introduction & Compaq registration
Source=Paul Collins Startup list
[IntruderAlert]
Confirmed=X
Filename=ia99.exe
Description=<a href="http://www.safersite.com/PestInfo/db/i/internetalert.asp" target="_blank">Intruder Alert '99</a> from Bonzi - spyware
Source=Paul Collins Startup list
[Ioadqm]
Confirmed=X
Filename=Media Player.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hawawi.worm.html" target="_blank">HAWAWI</a> WORM!
Description=<a href="http://www.iomega-europe.com/eu/category.asp?catalog%5Fname=Iomega&category%5Fname=Iomega+Automatic+Backup&Page=1" target="_blank">Iomega Automatic Backup</a> - automatic backups for use with Iomega portable HDD
Source=Paul Collins Startup list
[Iomega Automatic Backup 1.0.1]
Confirmed=U
Filename=ibackup.exe
Description=<a href="http://www.iomega-europe.com/eu/category.asp?catalog%5Fname=Iomega&category%5Fname=Iomega+Automatic+Backup&Page=1" target="_blank">Iomega Automatic Backup</a> - automatic backups for use with Iomega portable HDD
Source=Paul Collins Startup list
[Iomega Backup Scheduler]
Confirmed=N
Filename=dtiom98.exe
Description=Used by Iomega drives. Details of its purpose can be found <a href="http://pw2.netcom.com/~deepone/zipjaz/ioware.html#startup" target="_blank">here</a>. Available via Start -> Programs
Source=Paul Collins Startup list
[Iomega Disk Icons]
Confirmed=U
Filename=IMGICON.EXE
Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Source=Paul Collins Startup list
[Iomega Drive Icons]
Confirmed=U
Filename=IMGICON.EXE
Description=Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Source=Paul Collins Startup list
[Iomega ImIconXP]
Confirmed=U
Filename=imiconxp.exe
Description=Iomega <a href="http://www.iomega.com/software/revsystemsw.html" target=_blank>REV System</a> Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks
Source=Paul Collins Startup list
[Iomega QuickSync]
Confirmed=?
Filename=Quicksync.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Iomega Startup Options]
Confirmed=N
Filename=IMGSTART.EXE
Description=Used by Iomega drives. Details of its purpose can be found <a href="http://pw2.netcom.com/~deepone/zipjaz/ioware.html#startup" target="_blank">here</a>. Available via Start -> Programs
Source=Paul Collins Startup list
[Iomega Watch]
Confirmed=N
Filename=IOWATCH.EXE
Description=Used by Iomega drives. Available via Start -> Programs
Source=Paul Collins Startup list
[IomegaWare]
Confirmed=N
Filename=COMMANDER.EXE
Description=Used by Iomega drives. Details of its purpose can be found <a href="http://pw2.netcom.com/~deepone/zipjaz/ioware.html#startup" target="_blank">here</a>. Available via Start -> Programs
Source=Paul Collins Startup list
[Iomon98.exe]
Confirmed=U
Filename=Iomon98.exe
Description=PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
Source=Paul Collins Startup list
[IP Stack]
Confirmed=X
Filename=ipstack.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.CW" target="_blank">AGOBOT.CW</a> WORM!
Source=Paul Collins Startup list
[iPalm]
Confirmed=N
Filename=mon.exe
Description=Installed with a Panasonic <a href="http://www.panasonic.com/consumer_electronics/digital_cameras/ipalm.asp" target="_blank">iPalm</a> digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded
Source=Paul Collins Startup list
[ipcfg.exe]
Confirmed=X
Filename=ipcfg.exe
Description=Adware - recognized by McAfee antivirus as a variant of the <a href="http://vil.mcafeesecurity.com/vil/content/v_130215.htm" target=_blank>AdClicker-BM</a> trojan
Source=Paul Collins Startup list
[IPConfig]
Confirmed=X
Filename=svcxnv32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.hacarmy.e.html" target=_blank>HACARMY.E</a> TROJAN!
Source=Paul Collins Startup list
[IpCtrl]
Confirmed=X
Filename=ipcon32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[IPInSightLAN 01]
Confirmed=X
Filename=ipclient.exe
Description=Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see <a href="http://www.dslreports.com/faq/1247" target="_blank">here</a> for more information. This one constantly "phones home" and wastes resource - hence the "X" status
Source=Paul Collins Startup list
[IPInSightMonitor 01]
Confirmed=N
Filename=ipmon32.exe
Description=Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see <a href="http://www.dslreports.com/faq/1247" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[IPinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[ipmon.exe]
Confirmed=X
Filename=ipmon.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.recerv.html" target="_blank">RECERV</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.r3c.b.html" target="_blank">R3C.B</a> TROJANS!
Source=Paul Collins Startup list
[iPodManager]
Confirmed=U
Filename=iPodManager.exe
Description=Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods
Source=Paul Collins Startup list
[iPodWatcher]
Confirmed=?
Filename=iPodWatcher.exe
Description=Associated with Apple's iPod MP3 player. <font color="#FF0000">Detects when the iPod is connected?</font>
Source=Paul Collins Startup list
[iProtectYou]
Confirmed=U
Filename=ip.exe
Description=<a href="http://www.softforyou.com/ip-index.html" target="_blank">iProtectYou</a> - internet filtering/parental control and network monitoring software
Source=Paul Collins Startup list
[IPSecMon]
Confirmed=Y
Filename=IPSecMon.exe
Description=<a href="http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/l2tpclient.asp" target="_blank">Microsoft L2TP/IPSec VPN Client</a> for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
Source=Paul Collins Startup list
[IPTable Configuration]
Confirmed=X
Filename=Winipcfgs.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[IPv6 Helper Driver]
Confirmed=X
Filename=csass.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.TC" target=_blank>AGOBOT.TC</a> WORM!
Source=Paul Collins Startup list
[IPv6 STUN Service]
Confirmed=X
Filename=netstun.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.GEN" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[IPW]
Confirmed=?
Filename=IPW.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[IQES.exe]
Confirmed=?
Filename=iqes.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[irc session]
Confirmed=X
Filename=sessionmgr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotace.html" target=_blank>SDBOT-ACE</a> WORM!
Source=Paul Collins Startup list
[IREIKE]
Confirmed=Y
Filename=IreIKE.exe
Description=<a href="http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/l2tpclient.asp" target="_blank">Microsoft L2TP/IPSec VPN Client</a> for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
Source=Paul Collins Startup list
[iRis Active Monitor]
Confirmed=N
Filename=winmon32.exe
Description=Iris Antivirus - discontinued, replace with good alternative
Source=Paul Collins Startup list
[iRiS AntiVirus Active Monitor]
Confirmed=N
Filename=WIMMUN32.exe
Description=Iris Antivirus - discontinued, replace with good alternative
Source=Paul Collins Startup list
[iRiver Updater]
Confirmed=N
Filename=Updater.exe
Description=Updates for the <a href="http://www.iriver.com/" target="_blank">iRiver Music Manager</a> - used with their digital music players
Source=Paul Collins Startup list
[IrMon]
Confirmed=U
Filename=IRMON.EXE
Description=System Tray access to infra-red devices. Not required unless you use infra-red devices
Source=Paul Collins Startup list
[IRPMonitor]
Confirmed=?
Filename=itcnmon.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Irwftp]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=65604&VName=TROJ_BANCOS.CR&VSect=T" target="_blank">BANCOS.CR</a> TROJAN!
Source=Paul Collins Startup list
[irwftp]
Confirmed=X
Filename=iexplorer.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbankeran.html" target=_blank>BANKER-AN</a> TROJAN!
Source=Paul Collins Startup list
[IrXfer]
Confirmed=U
Filename=IrXfer.exe
Description=Microsoft Infrared Transfer application
Source=Paul Collins Startup list
[ir_ftp]
Confirmed=X
Filename=ir_ftp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.irftp.html" target="_blank">IRFTP</a> TROJAN!
Source=Paul Collins Startup list
[ir_ftp]
Confirmed=X
Filename=irwftp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.h.html" target="_blank">BANCOS.H</a> TROJAN!
Source=Paul Collins Startup list
[IS CfgWiz]
Confirmed=N
Filename=cfgwiz.exe
Description=Norton Internet Security configuration wizard
Source=Paul Collins Startup list
[Isass]
Confirmed=X
Filename=Isass.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.futro.html" target=_blank>FUTRO</a> TROJAN!
Source=Paul Collins Startup list
[isdbdc]
Confirmed=N
Filename=isdbdc.exe
Description=For Compaq PC's. May install properties in dial-up networking when you register with an ISP
Source=Paul Collins Startup list
[ISDN Monitor]
Confirmed=N
Filename=Linksts.exe
Description=Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
Source=Paul Collins Startup list
[ISDNwatch]
Confirmed=U
Filename=IWatch.exe
Description=<a href="http://www.avm.de/en/press/announcements/2003/2003_05_19_1.php3" target="_blank">FRITZ!X ISDNWatch</a> - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"
Source=Paul Collins Startup list
[ISLP2STA]
Confirmed=N
Filename=ISLP2STA.EXE
Description=<font color="#FF0000">Possibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though</font>
Source=Paul Collins Startup list
[iSpyNOW]
Confirmed=U
Filename=ispynow.exe
Description=<a href="http://www.ispynow.com/" target="_blank">iSpyNOW</a> - remote monitoring and surveillance software
Source=Paul Collins Startup list
[Israfel]
Confirmed=X
Filename=Israfel.vbs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.gaggle.d.html" target="_blank">GAGGLE.D</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.gaggle.e.html" target="_blank">GAGGLE.E</a> WORMS!
Source=Paul Collins Startup list
[ISStart]
Confirmed=U
Filename=ISStart.exe
Description=LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Description=<a href="http://sarc.com/avcenter/venc/data/adware.istbar.html" target="_blank">ISTBar</a> parasite related
Source=Paul Collins Startup list
[ISUSPM Startup]
Confirmed=N
Filename=ISUSPM.exe
Description=InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so youÆre always working with the most current version
Source=Paul Collins Startup list
[ISUSScheduler]
Confirmed=N
Filename=issch.exe
Description=InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so youÆre always working with the most current version
Source=Paul Collins Startup list
[Itk]
Confirmed=U
Filename=Itk.exe
Description=<a href="http://www.itksoft.com/index.asp" target="_blank">In The Know</a> - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Source=Paul Collins Startup list
[iTouch]
Confirmed=U
Filename=iTouch.exe
Description=iTouch loads the iTouch configuration program for Logitech keyboards. ItÆs needed if your keyboard has shortcut buttons and if you use them. ItÆs also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock
Source=Paul Collins Startup list
[ItsDeductiblePopUp]
Confirmed=N
Filename=ItsDeductible.exe
Description=<a href="http://www.itsdeductible2.com/" target="_blank">ItsDeductible</a> from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip
Source=Paul Collins Startup list
[iTunes Helper]
Confirmed=Y
Filename=iTunesHelper.exe
Description=Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
Source=Paul Collins Startup list
[Iusage]
Confirmed=N
Filename=netdet.exe
Description=<a href="http://members.tripod.com/gauravdhup0/iumos.html" target="_blank">Internet Usage Monitor</a> - utility to calculate the cost and time on the internet via dial-up
Source=Paul Collins Startup list
[IW ControlCenter]
Confirmed=N
Filename=iwctrl.exe
Description=<a href="http://www.pinnaclesys.com/" target="_blank">Pinnacle Systems</a> InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
Source=Paul Collins Startup list
[iwctrl]
Confirmed=U
Filename=iwctrl.exe
Description=<a href="http://www.pinnaclesys.com/" target="_blank">Pinnacle Systems</a> InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
Source=Paul Collins Startup list
[IZE]
Confirmed=?
Filename=N/A
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[j2 Tray Menu]
Confirmed=N
Filename=HotTray.exe
Description=eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available <a href="http://www.efax.com/help/index.asp" target="_blank">here</a>
Source=Paul Collins Startup list
[Jammer]
Confirmed=U
Filename=jammer.exe
Description=<a href="http://www.agnitum.com/products/jammer/" target="_blank">Jammer</a> by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"
Source=Paul Collins Startup list
[Jammer2nd]
Confirmed=X
Filename=Jammer2nd.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.z@mm.html" target="_blank">NETSKY.Z</a> WORM!
Source=Paul Collins Startup list
[Java Runtimes]
Confirmed=X
Filename=iexplore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.killav.b.html" target="_blank">KILLAV.B</a> TROJAN! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[JavaUpdate0.07]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.jupdate.html" target=_blank>JUPDATE</a> TROJAN!
Source=Paul Collins Startup list
[JavaVM]
Confirmed=X
Filename=java.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.m@mm.html" target="_blank">MYDOOM.M</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.n@mm.html" target="_blank">MYDOOM.N</a> WORMS! Note - not to be confused with the valid Windows "java.exe" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt
Source=Paul Collins Startup list
[jawa32]
Confirmed=X
Filename=jawa32.exe
Description=Added by the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/aqadcup/" target="_blank">AGENT.BG</a> WORM!
Source=Paul Collins Startup list
[Jawa322]
Confirmed=X
Filename=jawa32.exe
Description=Added by a variant of the <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/jawa32/" target=_blank>AGENT.BG</a> trojan
Source=Paul Collins Startup list
[JB]
Confirmed=N
Filename=Jiffybar.exe
Description="Get Paid As You surf" application
Source=Paul Collins Startup list
[Jet Detection]
Confirmed=N
Filename=ADGJDet.exe
Description=Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Source=Paul Collins Startup list
[JetAdmin Discovery Indicator]
Confirmed=Y
Filename=HPJETDSC.EXE
Description=HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator
Source=Paul Collins Startup list
[jijbl]
Confirmed=X
Filename=ezlwy.bat
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.reddw@mm.html" target="_blank">REDDW</a> WORM!
Source=Paul Collins Startup list
[JobHisInit]
Confirmed=U
Filename=JobHisInit.exe
Description=Used by Ricoh network printers to enable network printing from the client
Source=Paul Collins Startup list
[Jog Serve]
Confirmed=U
Filename=JogServ2.exe
Description="Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
Source=Paul Collins Startup list
[JogServ2]
Confirmed=U
Filename=JogServ2.exe
Description="Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
Description=Checks with Sun's Java updates site to see if newer Java versions are available. Visit <a href="http://java.sun.com" target="_blank"> http://java.sun.com</a> or just run the Java Plug-In Control Panel
Description=<a href="http://www.vtoy.fi/jv16/shtml/powertools.shtml" target="_blank">jv16 PowerTools</a>' network resident program. Only needed if you are using the program's network features
Source=Paul Collins Startup list
[jvdnlssn]
Confirmed=X
Filename=fljzsshc.exe
Description=Flingstone.com adware - and its Golden Palace Casino program
Source=Paul Collins Startup list
[Jzi16]
Confirmed=?
Filename=jzi16.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[K2ps_full.task]
Confirmed=X
Filename=K2ps_full.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_JUNTADOR.K" target="_blank">JUNTADOR.K</a> TROJAN!
Source=Paul Collins Startup list
[K6CPU.EXE]
Confirmed=N
Filename=K6CPU.EXE
Description=Authenticates CPU as K6 in system properties
Source=Paul Collins Startup list
[kak]
Confirmed=X
Filename=kak.hta
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/wscript.kakworm.html" target="_blank">KAKWORM</a> WORM!
Source=Paul Collins Startup list
[Kalibump]
Confirmed=U
Filename=Kalibump.exe
Description=Used with the now unsupported <a href="http://www.kali.net/" target="_blank">Kali</a> software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy
Description=<a href="http://www.istop.com/~phartana/reminder/" target="_blank">Kana Reminder</a> is a program which can be used to set a reminder to be triggered at a specified time
Source=Paul Collins Startup list
[Kaspersky Antivirus]
Confirmed=X
Filename=KasperskyAV.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[KasperskyAv]
Confirmed=X
Filename=kaspersky.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.t@mm.html" target="_blank">MIMAIL.T</a> WORM! Note - this has nothing to do with the real Kaspersky AntiVirus
Source=Paul Collins Startup list
[KasperskyAVEng]
Confirmed=X
Filename=Kasperskyaveng.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.v@mm.html" target="_blank">NETSKY.V</a> WORM!
Source=Paul Collins Startup list
[KAVPersonal50]
Confirmed=Y
Filename=Kav.exe
Description=<a href="http://www.kaspersky.com/personal" target="_blank">Kaspersky</a> Anti-Virus Personal 5.0
Source=Paul Collins Startup list
[KavRuns]
Confirmed=X
Filename=Windll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.trynoma.html" target="_blank">TRYNOMA</a> TROJAN!
Source=Paul Collins Startup list
[KAVutil]
Confirmed=X
Filename=[worm filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.wintoo.b.worm.html" target="_blank">WINTOO.B</a> WORM!
Source=Paul Collins Startup list
[KAZAA]
Confirmed=N
Filename=kazaa.exe
Description=KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check <a href="http://www.cexx.org/cydoor.htm" target="_blank">here</a> for information about "Cy-door" and <a href="http://www.lavasoft.de/software/adaware/" target="_blank">here</a> for a program that can remove it
Source=Paul Collins Startup list
[Kazaa Download Accelerator Updater (required)]
Confirmed=X
Filename=regsvr32 [path] kdp****.dll [* = random char]
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not the valid KaZaA file sharing program which has the same executable name
Source=Paul Collins Startup list
[Kazaa ml097e]
Confirmed=X
Filename=kazaa.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not the valid KaZaA file sharing program which has the same executable name
Source=Paul Collins Startup list
[KAZAACuf]
Confirmed=X
Filename=9
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.d.worm.html" target="_blank"> KITRO.D</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_ARGEN.A&VSect=T" target="_blank">ARGEN.A</a>) WORM!
Source=Paul Collins Startup list
[kazaalite]
Confirmed=N
Filename=kazaalite.exe
Description=<a href="http://www.webattack.com/get/kazaalite.shtml" target="_blank">Kazaalite</a> is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms
Source=Paul Collins Startup list
[KaZooM]
Confirmed=N
Filename=KaZooM.Exe
Description=KaZoom from <a href="http://www.bluehavenmedia.com/" target="_blank"> Blue Haven Media</a> - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"
Source=Paul Collins Startup list
[KBD]
Confirmed=U
Filename=KBD.EXE
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[KBD MediaCenter]
Confirmed=U
Filename=MEDIACTR.EXE
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[kbddrv32]
Confirmed=X
Filename=kbddrv32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[kbddrvinf]
Confirmed=X
Filename=kbddrvinf.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[KCeasy]
Confirmed=N
Filename=KCeasy.exe
Description=<a href="http://kceasy.com/about/" target=_blank>KCeasy</a> - a Windows peer-to-peer filesharing application which uses <a href="http://www.encyclopedia-online.info/GiFT_P2P" target=_blank>giFT</a> as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella
Source=Paul Collins Startup list
[KClient]
Confirmed=U
Filename=kstatus.exe
Description=KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
Source=Paul Collins Startup list
[kdx]
Confirmed=N
Filename=KHost.exe
Description=KonTiki <a href="http://help.kontiki.com/enduser/group.jsp;jsessionid=445B8C402E10C9AFBC8E053A3BBC395C?node=1829" target="_blank">Secure Delivery Plug In</a> related. "The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers"
Source=Paul Collins Startup list
[KE9801]
Confirmed=U
Filename=DriBat32.exe
Description=<a href="http://www.reset.bg/ke9801.htm" target="_blank">KE-9801</a> multimedia keyboard - required if you use the multimedia keys
Source=Paul Collins Startup list
[Keenvalue]
Confirmed=X
Filename=Keenvalue.exe
Description=<a href="http://www.infobeat.com/infobar/terms.html" target="_blank">Keenvalue</a> spyware - see <a href="http://www.dslreports.com/forum/remark,6752007~root=security,1~mode=flat" target="_blank">here</a>
Source=Paul Collins Startup list
[KEMailKb]
Confirmed=U
Filename=KEMailKb.EXE
Description=Controls the buttons at the top of the <a href="http://www.mic-innovations.com/micro_inv/large_image_pages/kb650i.htm" target="_blank"> Micro Innovations 650i Internet Access Keyboard</a>. If you disable it you cannot use the buttons - like volume control or shut down
Source=Paul Collins Startup list
[Kemet]
Confirmed=?
Filename=kemet.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[kern64dll]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/pwsteal.tarno.j.html" target="_blank">TARNO.J</a> TROJAN!
Source=Paul Collins Startup list
[kernctl32]
Confirmed=X
Filename=rundll32 kctl32.dll, initialize
Description=Added by the AGENT.AT TROJAN!
Source=Paul Collins Startup list
[Kernel]
Confirmed=X
Filename=bboy.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MUMU.B" target="_blank">MUMU.B</a> WORM!
Source=Paul Collins Startup list
[Kernel Loader]
Confirmed=X
Filename=ntkrnl.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.cervivec.a@mm.html" target="_blank">CERVIVEC.A</a> WORM!
Source=Paul Collins Startup list
[kernel system daemon]
Confirmed=X
Filename=ACTIVAT0R.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.aw.html" target="_blank">RANDEX.AW</a> WORM!
Source=Paul Collins Startup list
[kernel32]
Confirmed=X
Filename=kern32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BADTRANS.A" target="_blank">BADTRANS.A</a> WORM!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=Kernel32.exe
Description=Added by a number of VIRUSES, WORMS and TROJANS!
Source=Paul Collins Startup list
[kernel32]
Confirmed=X
Filename=kernel.dli
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.netdevil.b.html" target="_blank">NETDEVIL.B</a> TROJAN!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=Kernel.dll
Description=Added by the <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99476" target="_blank">REDLOF.M</a> VIRUS!
Source=Paul Collins Startup list
[kernel32]
Confirmed=X
Filename=kernel32.dlI
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.netdevil.15.html" target="_blank">NETDEVIL.15</a> TROJAN!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=krnl32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.epon@mm.html" target="_blank">EPON</a> WORM!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=Kernel32.win
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.gaggle.d.html" target="_blank">GAGGLE.D</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.gaggle.e.html" target="_blank">GAGGLE.E</a> WORMS!
Source=Paul Collins Startup list
[Kernel32]
Confirmed=X
Filename=kernel32s.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbckdrcic.html" target=_blank>SDBOT-PU</a> TROJAN!
Source=Paul Collins Startup list
[kernel32dll]
Confirmed=X
Filename=guardpc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotcu.html" target=_blank>FORBOT-CU</a> WORM!
Source=Paul Collins Startup list
[kernelfaultcheck]
Confirmed=N
Filename=dumprep 0 -k
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[kernelfaultcheck]
Confirmed=N
Filename=dumprep 0 -u
Description=Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Source=Paul Collins Startup list
[KernelFaultChk]
Confirmed=X
Filename=sms.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.deadhat.html" target="_blank">DEADHAT</a> WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u"
Source=Paul Collins Startup list
[Kernell]
Confirmed=X
Filename=systems.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.c.html" target="_blank">TARNO.C</a> TROJAN!
Source=Paul Collins Startup list
[Kernell32]
Confirmed=X
Filename=Kernell.dll
Description=Added by the <a href="http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DESTINY.A" target="_blank">DESTINY.A</a> TROJAN!
Source=Paul Collins Startup list
[KernellApps]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbancbanac.html" target=_blank>BANCBAN-AC</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Kernelw]
Confirmed=X
Filename=Kernelw32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.indor.e@mm.html" target="_blank">INDOR.E</a> WORM!
Source=Paul Collins Startup list
[Kernel_check]
Confirmed=X
Filename=wmiprvse.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sonebotb.html" target=_blank>SONEBOT-B</a> WORM!
Source=Paul Collins Startup list
[key]
Confirmed=X
Filename=sysxp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ab@mm.html" target="_blank">BEAGLE.AB</a> WORM!
Source=Paul Collins Startup list
[key]
Confirmed=X
Filename=sys_xp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ac@mm.html" target="_blank">BEAGLE.AC</a> WORM!
Source=Paul Collins Startup list
[key]
Confirmed=X
Filename=winxp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ag@mm.html" target="_blank">BEAGLE.AG</a> WORM!
Source=Paul Collins Startup list
[Key Logger]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.buchon.a@mm.html" target=_blank>BUCHON.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Key Text]
Confirmed=N
Filename=KeyText.exe
Description=<a href="http://www.mjmsoft.com/keytext.htm" target="_blank">Key Text 2000</a> from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs
Source=Paul Collins Startup list
[Key1]
Confirmed=X
Filename=Rlid.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lixy.html" target="_blank">LIXY</a> TROJAN!
Source=Paul Collins Startup list
[Key2]
Confirmed=?
Filename=serve.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[KeyAccess]
Confirmed=Y
Filename=keyacc32.exe
Description=KeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"
Source=Paul Collins Startup list
[Keybdcntl]
Confirmed=X
Filename=keybdcntl.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[Keyboard Manager]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Description=Multimedia keyboard manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[keymap]
Confirmed=U
Filename=keymap.exe
Description=System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
Description=<a href="http://www.pestpatrol.com/KeyPatrol/" target="_blank">KeyPatrol</a> - detects Key Loggers ("keyboard loggers" or "keyloggers") using both behavioral and pattern-matching algorithms
Source=Paul Collins Startup list
[KeyWallet]
Confirmed=U
Filename=KWallet.exe
Description="<a href="http://www.keywallet.com/index.php" target="_blank">KeyWallet</a> is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"
Source=Paul Collins Startup list
[kfienq]
Confirmed=X
Filename=masbl.bat
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kifer.html" target="_blank">KIFER</a> TROJAN!
Source=Paul Collins Startup list
[khooker]
Confirmed=N
Filename=khooker.exe
Description=SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
Source=Paul Collins Startup list
[KICKMON.EXE]
Confirmed=U
Filename=KICKMON.EXE
Description=KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required
Description=<a href="http://www.kinberlin.com/kinberlink/index.asp" target="_blank">Kinberlink</a> network messaging. Available via Start -> Programs
Source=Paul Collins Startup list
[KK Loader]
Confirmed=U
Filename=loadkk.exe
Description=<a href="http://www.keykey.com/index1.html" target="_blank">KeyKey XP Professional</a> from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user."
Source=Paul Collins Startup list
[klp]
Confirmed=U
Filename=run32dll.exe
Description=<a href="http://www.newfreeware.com/internet/480/" target="_blank">PAL PC Spy</a> - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online
Source=Paul Collins Startup list
[KM9801U]
Confirmed=U
Filename=MMHotKey.exe
Description=Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
Source=Paul Collins Startup list
[kmw_run.exe]
Confirmed=U
Filename=kmw_run.exe
Description=Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features
Source=Paul Collins Startup list
[kmw_show.exe]
Confirmed=U
Filename=kmw_show.exe
Description=Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features
Source=Paul Collins Startup list
[Kodak Batch Transfer]
Confirmed=N
Filename=pezdow1.exe
Description=Part of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
Source=Paul Collins Startup list
[Kodak EasyShare software]
Confirmed=U
Filename=EasyShare.exe
Description=Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
Source=Paul Collins Startup list
[Kodak Picture Transfer Software]
Confirmed=N
Filename=pts.exe
Description=Looks for Kodak camera connection and media insertion. Available via Start -> Programs
Source=Paul Collins Startup list
[Kodak Software Updater]
Confirmed=N
Filename=backweb*****.exe
Description=Software updater for <a href="http://www.kodak.com/global/en/digital/easyShare/indexFlash.jhtml" target="_blank">Kodak Easyshare</a> digital cameras
Source=Paul Collins Startup list
[KodakCCS]
Confirmed=Y
Filename=KodakCCS.exe
Description=Kodak DC File System Driver
Source=Paul Collins Startup list
[Konni Symbol Autostart]
Confirmed=N
Filename=KonniSymbol.exe
Description=Gives configuration access to <a href="http://www.besoftware.com/index.html" target="_blank">RagTime Solo</a> professional business publishing software. RagTime Solo is the private user version of RagTime 5
Source=Paul Collins Startup list
[kontiki]
Confirmed=N
Filename=kontiki.exe
Description=<a href="http://help.kontiki.com/enduser/group.jsp;jsessionid=2C47C896EA1784C5321FD3E6845E8157?node=2846" target="_blank">Kontiki Delivery Manager</a> - Windows-based client software that enables secure delivery of content to users' desktops
Source=Paul Collins Startup list
[KREC32]
Confirmed=U
Filename=krec32.exe
Description=StarrCommander Pro Keystroke logging software
Source=Paul Collins Startup list
[Krnlmod]
Confirmed=U
Filename=Krnlmod.exe
Description=Keylogger - see <a href="http://www.pestpatrol.com/PestInfo/W/Windows_Keylogger.asp" target="_blank"> here</a>. Given a "U" recommendation because it depends if you intentionally installed it. If you didn't, treat it as "X" and uninstall or remove via Spybot S&D (for example)
Source=Paul Collins Startup list
[ktchnsnk]
Confirmed=U
Filename=ktchnsnk.exe
Description=HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted
Source=Paul Collins Startup list
[kv3000]
Confirmed=X
Filename=lover.vbe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.zsyang.b@mm.html" target="_blank">ZSYANG.B</a> WORM!
Description=Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards
Source=Paul Collins Startup list
[LanGuard]
Confirmed=X
Filename=languard.exe
Description=Adware downloader
Source=Paul Collins Startup list
[LanSpeed2]
Confirmed=U
Filename=LanSpeed2.exe
Description=Monitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
Source=Paul Collins Startup list
[LapLink scheduler]
Confirmed=U
Filename=Llsched.exe
Description=Utility that automatically performs file transfers as unattended background operations
Source=Paul Collins Startup list
[Lar]
Confirmed=X
Filename=Llass.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojinora.html" target="_blank">INOR-A</a> TROJAN!
Source=Paul Collins Startup list
[lar]
Confirmed=X
Filename=[trojan filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.roxy.c.html" target="_blank">ROXY.C</a> TROJAN!
Source=Paul Collins Startup list
[Lasb]
Confirmed=?
Filename=ewat.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[LAsIAf32]
Confirmed=X
Filename=RePEAtLD.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.repeatld.html" target="_blank">REPEATLD</a> WORM!
Source=Paul Collins Startup list
[LASTinst]
Confirmed=Y
Filename=N/A
Description=For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Source=Paul Collins Startup list
[Later]
Confirmed=?
Filename=later.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[LaunApp]
Confirmed=U
Filename=LaunApp.exe
Description=Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[Launcg]
Confirmed=?
Filename=launcg.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Launch Ai Booster]
Confirmed=U
Filename=OverClk.exe
Description=ASUS <a href="http://www.asuscom.de/pub/ASUS/mb/sock478/p4p800/AIBooster_u.pdf" target=_blank>Ai Booster</a> is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup
Source=Paul Collins Startup list
[Launch YahooPOPs! at Windows startup]
Confirmed=N
Filename=YAHOOPOPS.EXE
Description=<a href="http://yahoopops.sourceforge.net/" target="_blank">YahooPOPs</a> - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs
Source=Paul Collins Startup list
[LaunchAp]
Confirmed=U
Filename=LaunchAp.exe
Description=Part of <a href="http://global.acer.com/" target="_blank">Acer</a> Launch Manager - programmable keys on such laptops as the TravelMate 610
Source=Paul Collins Startup list
[LaunchApp]
Confirmed=U
Filename=Alaunch.exe
Description=<a href="http://global.acer.com/" target="_blank">Acer</a> Launch tool utility on laptops
Source=Paul Collins Startup list
[Launchboard]
Confirmed=U
Filename=lnchbrd.exe
Description="LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions"
Source=Paul Collins Startup list
[Launcher]
Confirmed=X
Filename=launcher.exe
Description=Spyware component related to DownloadWare and found in Program FilesKFH
Source=Paul Collins Startup list
[Launcher]
Confirmed=N
Filename=relaunch.exe
Description=Audio Applications Launcher for the Philips <a href="http://www.consumer.philips.com/global/b2c/ce/catalog/product.jhtml;jsessionid=ONLYIDABKOHRQCRQNE2RYVIKGBUCWHD0?divId=0&groupId=PCSTUFF&catId=&subCatId=SOUNDCARDS&productId=PSC703_05" target="_blank">Rythmiic Edge</a> soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs
Source=Paul Collins Startup list
[Lavasoft Ad-Aware]
Confirmed=X
Filename=Ad-Aware.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotso.html" target=_blank>RBOT-SO</a> WORM! Note - this is not the popular <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware</a> spware/adware removal tool
Source=Paul Collins Startup list
[Lavasoft Adwatch]
Confirmed=U
Filename=Ad-watch.exe
Description=Part of Lavasoft <a href="http://www.lavasoft.de/software/adaware/" target="_blank">Ad-aware Plus</a> - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
Source=Paul Collins Startup list
[laxmsp32.exe]
Confirmed=Y
Filename=laxmsp32.exe
Description=Lexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work
Source=Paul Collins Startup list
[LCDC]
Confirmed=U
Filename=LCDC.exe
Description=<a href="http://www.lcdc.cc/about.htm" target="_blank">LCDC</a> is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins
Source=Paul Collins Startup list
[lcfep]
Confirmed=N
Filename=lcfep.exe
Description=Tivoli æTMEÆ System Tray icon - "'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"
Source=Paul Collins Startup list
[lcvga]
Confirmed=X
Filename=lcvga.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojhostola.html" target=_blank>HOSTOL-A</a> TROJAN!
Source=Paul Collins Startup list
[ld]
Confirmed=X
Filename=ld.exe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related - redirects to fastwebfinder.com
Source=Paul Collins Startup list
[LDM]
Confirmed=N
Filename=backweb-8876480.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[LDM]
Confirmed=N
Filename=ldmconf.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[LED TRAY]
Confirmed=U
Filename=LEDTRAY.EXE
Description=Installs a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work
Description=Lexmark printer button manager. Required for correct operation
Source=Paul Collins Startup list
[Lexmark X5100 Series]
Confirmed=U
Filename=lxbabmgr.exe
Description=System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
Source=Paul Collins Startup list
[Lexmark X74-X75]
Confirmed=U
Filename=lxbabmgr.exe
Description=System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
Source=Paul Collins Startup list
[Lexmark Xxx Button Manager]
Confirmed=Y
Filename=AcBtnMgr_Xxx.exe
Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
Source=Paul Collins Startup list
[Lexmark Xxx Button Monitor]
Confirmed=Y
Filename=ACMonitor_Xxx.exe
Description=Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
Source=Paul Collins Startup list
[LexmarkPrinTray]
Confirmed=N
Filename=printray.exe
Description=Lexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray
Source=Paul Collins Startup list
[lexpps]
Confirmed=N
Filename=lexpps.exe
Description=For Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all". It is known that firewalls can however alert you to "lexpps.exe" requesting server privileges
Source=Paul Collins Startup list
[LexStart]
Confirmed=U
Filename=lexstart.exe
Description=Lexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance
Source=Paul Collins Startup list
[Lfsndmng]
Confirmed=U
Filename=lfsndmng.exe
Description=<a href="http://www.lightningfax.com/products/lightningfax/features.htm" target="_blank">LightningFAX Enterprise Fax Server</a> - "puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents"
Description=<a href="http://www.elicense.com/" target="_blank">eLicense</a>, licensing system incorporated with some software and games
Source=Paul Collins Startup list
[LicCtrl]
Confirmed=U
Filename=rundll32.exe [path] MMFS.DLL, Service
Description=Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
Source=Paul Collins Startup list
[LicCtrl]
Confirmed=U
Filename=runservice.exe
Description=Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
Source=Paul Collins Startup list
[LifeScape Media Detector]
Confirmed=N
Filename=PicasaMediaDetector.exe
Description=Media detector for <a href="http://www.picasa.net/" target="_blank">Picasa</a>'s automatic photo organizer
Source=Paul Collins Startup list
[Lightning Download]
Confirmed=U
Filename=Lightning.exe
Description=<a href="http://www.lightningdownload.com/index.shtml" target=_blank>Lightning Download</a> download manager. Can be launched manually, but will need to start up if you want it to "catch clicks" off Internet Explorer
Source=Paul Collins Startup list
[LimeWire x.x]
Confirmed=N
Filename=LimeWire.exe
Description=<a href="http://www.limewire.com/" target="_blank">LimeWire</a> - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware
Source=Paul Collins Startup list
[Line Speed Meter V3.0]
Confirmed=N
Filename=LineSpeedMeter.exe
Description=<a href="http://www.tcpiq.com/tcpiq/linespeed/Default.asp" target="_blank">LineSpeedMeter</a> - detect the download and upload speed of your internet connection
Source=Paul Collins Startup list
[Linksts]
Confirmed=N
Filename=linksts.exe
Description=Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
Source=Paul Collins Startup list
[Linksts]
Confirmed=X
Filename=linksts.exe
Description=Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
Source=Paul Collins Startup list
[Linux]
Confirmed=X
Filename=Linux.vbs
Description=Added by the <a href="http://vil.nai.com/vil/content/v_98684.htm" target="_blank">LOVELETTER.AS</a> VIRUS!
Source=Paul Collins Startup list
[LiquidView]
Confirmed=U
Filename=lviewj.exe
Description="Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display's native resolution. The software lets you increase the size of items that are hard to read on your monitor"
Source=Paul Collins Startup list
[LIU]
Confirmed=N
Filename=LIU.exe
Description=Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
Source=Paul Collins Startup list
[LIU]
Confirmed=N
Filename=Rubicon.exe
Description=Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
Source=Paul Collins Startup list
[Live Menu]
Confirmed=N
Filename=Dllcmd32.exe
Description=eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available <a href="http://www.efax.com/help/index.asp" target="_blank">here</a>
Source=Paul Collins Startup list
[LiveMonitor]
Confirmed=N
Filename=LMonitor.exe
Description=MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
Source=Paul Collins Startup list
[LiveNote]
Confirmed=N
Filename=Livenote.exe
Description=Asus graphics card driver live update feature
Source=Paul Collins Startup list
[LiveSexCams]
Confirmed=X
Filename=LiveSexCams.exe
Description=Premium rate adult content dialler
Source=Paul Collins Startup list
[LiveUpdate]
Confirmed=U
Filename=LiveUpdate.exe
Description=Web-update utility as used by various types of software - see <a href="http://liveupdate.openwares.org/" target="_blank">here</a>
Source=Paul Collins Startup list
[LiveUpdate]
Confirmed=X
Filename=[Windows username]05.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.lineage.html" target=_blank>LINEAGE</a> TROJAN!
Source=Paul Collins Startup list
[Livre]
Confirmed=X
Filename=Dibane.bat
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w97m.banedi.html" target=_blank>BANEDI</a> VIRUS!
Description=Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
Source=Paul Collins Startup list
[LManager]
Confirmed=U
Filename=QtZpAcer.exe
Description=Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
Source=Paul Collins Startup list
[LMonitor]
Confirmed=N
Filename=LMonitor.exe
Description=MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
Source=Paul Collins Startup list
[lmpdpsrv]
Confirmed=?
Filename=lmpdpsrv.exe
Description=<font color="#FF0000">Related to a Lexmark printer/scanner. Printer sharing server? Is it required?</font>
Source=Paul Collins Startup list
[LMSTATUS]
Confirmed=N
Filename=LMSTATUS.EXE
Description=Lexmark Status Monitor. Checks the current status of Lexmark printers (and other devices?)
Source=Paul Collins Startup list
[lnternet Explorer]
Confirmed=X
Filename=AMSNDMGR.EXE
Description=Added by the <a href="http://http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbot.r.worm.html" target="_blank">KWBOT.R</a> WORM! Note that the "l" is a lower case "L" and not an upper case "I"
Source=Paul Collins Startup list
[LOAD WB]
Confirmed=U
Filename=LOADWB.EXE
Description=Part of Stardock's <a href="http://www.windowblinds.net/" target="_blank">WindowBlinds</a> custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it
Source=Paul Collins Startup list
[Load-Guard]
Confirmed=X
Filename=Wscript.exe LGuarg.exe.vbs
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.yeno.b@mm.html" target=_blank>YENO.B</a> and <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.yeno.c@mm.html" target=_blank>YENO.C</a> WORMS!
Source=Paul Collins Startup list
[LOAD32]
Confirmed=X
Filename=Lorena.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.mapson.c.worm.html" target="_blank">MAPSON.C</a> WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=load32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nibu.html" target="_blank">NIBU</a>, <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.bambo.html" target="_blank">BAMBO</a> TROJANS and <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru@mm.html" target="_blank">DUMARU</a> WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=l32x.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru.z@mm.html" target="_blank">DUMARU.Z</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru.y@mm.html" target="_blank">DUMARU.Y</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru.ad@mm.html" target="_blank">DUMARU.AD</a> WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=1111a.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru.ah@mm.html" target="_blank">DUMARU.AH</a> WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=swchost.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_TURTA.A&VSect=T" target="_blank">TURTA.A</a> WORM!
Source=Paul Collins Startup list
[load32]
Confirmed=X
Filename=netda.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nibu.e.html" target=_blank>NIBU.E</a> TROJAN!
Source=Paul Collins Startup list
[load=]
Confirmed=N
Filename=adw30.exe
Description=After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Source=Paul Collins Startup list
[load=]
Confirmed=U
Filename=asistat.exe
Description=Status monitor for an NEC SuperScript printer
Source=Paul Collins Startup list
[load=]
Confirmed=?
Filename=cfgsys32.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[load=]
Confirmed=U
Filename=esspk.exe
Description=Speakerphone capability through a soundcard for an <a href="http://www.esstech.com/" target="_blank">ESS</a> modem
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=hotkey.exe
Description=Solo 5300 display driver for Win2K on some Gateway laptops
Source=Paul Collins Startup list
[load=]
Confirmed=N
Filename=HPWHRC.EXE
Description=Loads the Status Window software for the HP Laserjet printers
Source=Paul Collins Startup list
[load=]
Confirmed=?
Filename=WPSLOAD.EXE
Description=<font color="#FF0000">Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk</font>
Source=Paul Collins Startup list
[load=]
Confirmed=N
Filename=vi_grm.exe
Description=Monitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
Source=Paul Collins Startup list
[load=]
Confirmed=?
Filename=WINOSCFG.EXE
Description=<font color="#FF0000">Could it be something to do with configuring Windows on a new PC from an OEM supplier?</font>
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=wpshrc.exe
Description=Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others)
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=Bfrecv.exe
Description=Bitware modem driver
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=msater.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.retsam.html" target="_blank">RETSAM</a> TROJAN!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=shambl3r.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.remabl.worm.html" target="_blank">REMABL</a> WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=Spoolsv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ciadoor.b.html" target="_blank">CIADOOR.B</a> TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
Source=Paul Collins Startup list
[Load=]
Confirmed=?
Filename=wtfeat.exe
Description=<font color="#FF0000">Associated with the Wintab Digitizer</font>
Source=Paul Collins Startup list
[load=]
Confirmed=Y
Filename=AICLIENT.EXE
Description=Asset Insight from <a href="http://www.tangram.com/index.htm" target="_blank">Tangram</a> - asset managing software. Required if an organisation is running a centrally administered asset management system
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=hint.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.atak@mm.html" target="_blank">ATAK</a> WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=win32exec.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.bitter.html" target=_blank>BITTER</a> WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=a1g.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.atak.b@mm.html" target=_blank>ATAK.B</a> WORM!
Source=Paul Collins Startup list
[load=]
Confirmed=X
Filename=dapdll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.atak.e@mm.html" target=_blank>ATAK.E</a> WORM!
Source=Paul Collins Startup list
[LoadBlackD]
Confirmed=Y
Filename=blackd.exe
Description=This is the "intrusion detection system" of the <a href="http://blackice.iss.net/product_pc_protection.php" target="_blank">BlackICE PC Protection</a> (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility)
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gibe@mm.html" target="_blank">GIBE</a> WORM!
Source=Paul Collins Startup list
[LoadDvpApi9x]
Confirmed=?
Filename=DVPAPI9X.exe
Description=<font color="#FF0000">Part of Command AntiVirus for Windows 95/98/Me. Is it needed?</font>
Source=Paul Collins Startup list
[loader]
Confirmed=X
Filename=loader.exe
Description=Homepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe
Source=Paul Collins Startup list
[loader]
Confirmed=X
Filename=WMPLAYER.EXE
Description=Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
Source=Paul Collins Startup list
[LoadFonts]
Confirmed=X
Filename=LoadFonts.vbs
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[LoadFonts]
Confirmed=X
Filename=Tahoma.vbs
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[LoadHTML]
Confirmed=X
Filename=rundll32.exe mshtmpre.dll, MShtmpre
Description=Browser hijacker
Source=Paul Collins Startup list
[LoadingAgent]
Confirmed=X
Filename=ZipLoader32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.oblivion.html" target="_blank">OBLIVION</a> TROJAN! This executable is one of the most common but there are more
Source=Paul Collins Startup list
[LoadingAgent]
Confirmed=X
Filename=msload32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.oblivion.html" target="_blank">OBLIVION</a> TROJAN! This executable is one of the most common but there are more
Source=Paul Collins Startup list
[LoadManager]
Confirmed=X
Filename=msload.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM!
Source=Paul Collins Startup list
[LoadMSvcmm]
Confirmed=N
Filename=msvcmm32.exe
Description=Auto-update for <a href="http://www.movielink.com/" target="_blank">Movielink</a> - internet movie rental System Tray access
Source=Paul Collins Startup list
[LoadOrderVerification]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_TRON.A" target="_blank">TRON.A</a> TROJAN!
Source=Paul Collins Startup list
[Loadout Manager]
Confirmed=U
Filename=nost_LM.exe
Description=Manager for the Belkin Nostromo n50 SpeedPad game controller - see <a href="http://catalog.belkin.com/IWCatProductPage.process?Merchant_Id=1&Product_Id=107727" target="_blank"> here</a>
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=ASDAPI.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.cabro.html" target="_blank">CABRO</a> TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=U
Filename=Rundll32.exe powrprof.dll
Description=Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;187611" target="_blank">here</a>. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=Rundll.exe powerprof.dll
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.loxoscam.html" target=_blank>LOXOSCAM</a> TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe"
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=rundl.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.tofazzol.html" target="_blank">TOFAZZOL</a> TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
Source=Paul Collins Startup list
[LoadPowerProfile]
Confirmed=X
Filename=Rundll32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.miroot.worm.html" target="_blank">MIROOT</a> WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line
Source=Paul Collins Startup list
[LoadQM]
Confirmed=U
Filename=loadqm.exe
Description=Installed with MSN Explorer and loads the <a href="http://support.microsoft.com/default.aspx?scid=KB;EN-US;q309418" target="_blank"> MSN Queue Manager</a>. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it
Description=<font color="#FF0000">Reportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct?</font>
Source=Paul Collins Startup list
[LoadWindowsFile]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.delf.b.html" target="_blank">DELF.B</a> TROJAN! where [filename] is the infected file
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotky.html" target=_blank>AGOBOT-KY</a> TROJAN!
Source=Paul Collins Startup list
[Lock My PC]
Confirmed=U
Filename=lockpc.exe
Description=<a href="http://www.fspro.net/lmpc/" target=_blank>Lock_My_PC</a> - a tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse
Source=Paul Collins Startup list
[Login]
Confirmed=U
Filename=winlog.exe
Description=Salfeld <a href="http://www.salfeld.com/parental_control_overwiew.htm" target="_blank">Child Control 2003</a> - parental control software
Source=Paul Collins Startup list
[Login Service]
Confirmed=X
Filename=[path to file]
Description=Added by the <a href="https://www.europe.f-secure.com/v-descs/migmaf.shtml" target="_blank">MIGMAF</a> TROJAN!
Source=Paul Collins Startup list
[LoginPassport]
Confirmed=X
Filename=Lgnpsp32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.redist.c@mm.html" target="_blank">REDIST.C</a> WORM!
Source=Paul Collins Startup list
[Logitech Desktop Messenger]
Confirmed=N
Filename=backweb-8876480.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[Logitech Desktop Messenger]
Confirmed=N
Filename=ldmconf.exe
Description=Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
Source=Paul Collins Startup list
[Logitech Hardware Abstraction Layer]
Confirmed=?
Filename=Khalmnpr.exe
Description=Logitech Bluetooth mouse Hardware Abstraction layer. A "hardware abstraction layer" is an interface that enables adding support for new devices and new ways of connecting devices to the computer, without modifying every application that uses the device. <font color="#FF0000">What does it do, and is it required?</font>
Source=Paul Collins Startup list
[Logitech SetPoint]
Confirmed=U
Filename=KEM.exe
Description=Keyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
Source=Paul Collins Startup list
[Logitech Utility]
Confirmed=U
Filename=Logi_MwX.exe
Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
Source=Paul Collins Startup list
[Logitech Wakeup]
Confirmed=N
Filename=lgwakeup.exe
Description=Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
Source=Paul Collins Startup list
[LogitechGalleryRepair]
Confirmed=U
Filename=ISStart.exe
Description=LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Source=Paul Collins Startup list
[LogitechImageStudioTray]
Confirmed=N
Filename=LogiTray.exe
Description=Logitech Image Studio - installed with Logitech QuickCams
Source=Paul Collins Startup list
[LogitechSoftwareUpdate]
Confirmed=?
Filename=ManifestEngine.exe
Description=Updater, part of Logitech Image Studio - installed with Logitech QuickCam cameras. Probably not required
Source=Paul Collins Startup list
[LogitechVideoRepair]
Confirmed=U
Filename=ISStart.exe
Description=LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Source=Paul Collins Startup list
[LogitechVideoTray]
Confirmed=N
Filename=LogiTray.exe
Description=Logitech Image Studio - installed with Logitech QuickCams
Source=Paul Collins Startup list
[LogiTray]
Confirmed=N
Filename=LogiTray.exe
Description=Logitech Image Studio - installed with Logitech QuickCams
Source=Paul Collins Startup list
[Logi_Mwx]
Confirmed=U
Filename=Logi_MwX.exe
Description=Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
Source=Paul Collins Startup list
[Logon.exe]
Confirmed=X
Filename=logon.exe
Description=Added by the <a href="http://ae.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=BKDR_ZINS.A" target=_blank>ZINS.A</a> TROJAN!
Source=Paul Collins Startup list
[LogonStudio]
Confirmed=U
Filename=logonstudio.exe
Description=WinCustomize <a href="http://www.stardock.com/products/logonstudio/" target="_blank">LogonStudio</a> - "Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users"
Source=Paul Collins Startup list
[LogWatch]
Confirmed=U
Filename=logwat95.exe
Description=Licensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll - see <a href="http://support.ca.com/Download/patches/licenseit/LO51215.html" target="_blank">here</a>. Not required if you already have a newer version or the patch has been applied
Source=Paul Collins Startup list
[Look 'n' Stop]
Confirmed=Y
Filename=looknstop.exe
Description=<a href="http://www.looknstop.com/En/index2.htm">Look 'n' Stop</a> personal firewall
Source=Paul Collins Startup list
[LookNMeet]
Confirmed=N
Filename=Agent.exe
Description=<a href="http://217.22.55.178/rdl/lnm_v4.3/nl/index.html" target=_blank>LooknMeet</a> dating service
Source=Paul Collins Startup list
[Lookup_Sys]
Confirmed=X
Filename=lookupsys.exe
Description=P04n trojan
Source=Paul Collins Startup list
[Lotus Organizer EasyClip]
Confirmed=N
Filename=easyclip.exe
Description="The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page." Available via Start -> Programs
Source=Paul Collins Startup list
[Lotus QuickStart]
Confirmed=N
Filename=smartctr.exe
Description=Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs
Source=Paul Collins Startup list
[Lotus SuiteStart]
Confirmed=U
Filename=suitest.exe
Description=Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs
Source=Paul Collins Startup list
[LowVersionSupport]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lastras.html" target="_blank">LASTRAS</a> TROJAN!
Source=Paul Collins Startup list
[Lpr]
Confirmed=X
Filename=Lpr123.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/spyware.rempsteal.html" target=_blank>REMPSTEAL</a> password stealer TROJAN!
Source=Paul Collins Startup list
[Lpr123]
Confirmed=X
Filename=Lpr123.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/spyware.rempsteal.html" target=_blank>REMPSTEAL</a> password stealer TROJAN!
Source=Paul Collins Startup list
[LPS]
Confirmed=U
Filename=Lps.exe
Description=Local Port Scanner - "With LPS you're able to check your computer for open or listening ports"
Source=Paul Collins Startup list
[LPtask]
Confirmed=U
Filename=lptask.exe
Description=<a href="http://www.sanegroup.com/sanegroup/lppro.html" target="_blank">Program Lock It And Protect Pro</a> - lock and protect your folders from being opened, moved or deleted
Source=Paul Collins Startup list
[LS120 Superdisk]
Confirmed=N
Filename=??
Description=Supposed to accelerate transfer rate on LS-120, contributes to system lockups
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.ratsou.b.html" target="_blank">RATSOU.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank"> Lsass.exe</a> system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=start.bat
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojzcrew.html" target="_blank">ZCREW</a> TROJAN!
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=[path to lsass.exe]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.f.html" target="_blank">ALADINZ.F</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lasss.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[lsass]
Confirmed=X
Filename=lsasrv.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.mydoom.ag@mm.html" target=_blank>MYDOOM.AG</a> WORM!
Source=Paul Collins Startup list
[LSASS Daemon]
Confirmed=X
Filename=LSASSd.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[lsass service]
Confirmed=X
Filename=lsass2.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[lsasss.exe]
Confirmed=X
Filename=lsasss.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SASSER.E" target="_blank">SASSER.E</a> WORM!
Source=Paul Collins Startup list
[LSPFix]
Confirmed=X
Filename=LSPmonitor.exe
Description=eAcceleration Stop-Sign related - foistware. Read their privacy statement <a href="http://www.eacceleration.com/privacy/" target="_blank">here</a>
Source=Paul Collins Startup list
[LSPmonitor]
Confirmed=X
Filename=LSPmonitor.exe
Description=eAcceleration Stop-Sign related - foistware. Read their privacy statement <a href="http://www.eacceleration.com/privacy/" target="_blank">here</a>
Source=Paul Collins Startup list
[lssass]
Confirmed=X
Filename=lssas.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.RL" target=_blank>AGOBOT.RL</a> WORM!
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LITMUS.A&VSect=T" target="_blank">LITMUS.A</a> TROJAN! Note - MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:\Windows\System
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=MPGSRV32.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LITMUS.201" target="_blank">LITMUS.201</a> TROJAN!
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=MSGSRV320.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LITMUS.C" target="_blank">LITMUS.C</a> TROJAN!
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=winupdate.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LITMUS.203">LITMUS.203</a> TROJAN!
Source=Paul Collins Startup list
[LTM2]
Confirmed=X
Filename=bible.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LITMUS.203">LITMUS.203</a> TROJAN!
Source=Paul Collins Startup list
[LtMoh]
Confirmed=U
Filename=Ltmoh.exe
Description=Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
Source=Paul Collins Startup list
[LTMSG]
Confirmed=Y
Filename=ltmsg.exe
Description=One of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See <a href="http://808hi.com/56k/winmodems.asp" target="_blank">here</a> for more WinModem information
Source=Paul Collins Startup list
[LTSMMSG]
Confirmed=N
Filename=LTSMMSG.exe
Description=Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too
Source=Paul Collins Startup list
[LTSMSG]
Confirmed=X
Filename=Shell32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.lemir.b.html" target="_blank">LEMIR.B</a> TROJAN!
Source=Paul Collins Startup list
[LTWinModem1]
Confirmed=Y
Filename=ltmsg.exe
Description=One of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See <a href="http://808hi.com/56k/winmodems.asp" target="_blank">here</a> for more WinModem information
Source=Paul Collins Startup list
[Lusetup]
Confirmed=Y
Filename=LUSetup.exe
Description=Symantec <a href="http://service1.symantec.com/support/sharedtech.nsf/docid/1999051911110813" target=_blank>LiveUpdate installer</a> - required to install a new version of the application. Will only run once, and the entry is automatically deleted after a reboot
Source=Paul Collins Startup list
[LVComs]
Confirmed=U
Filename=lvcoms.exe
Description=Lvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera
Source=Paul Collins Startup list
[LVCOMSX]
Confirmed=?
Filename=LVCOMSX.EXE
Description=Logitech webcam related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[LWBMOUSE]
Confirmed=U
Filename=lwbwheel.exe
Description=Mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[LWBMOUSE]
Confirmed=U
Filename=MOUSE32A.EXE
Description=Mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Lwinst Run Profiler]
Confirmed=N
Filename=lwtest.exe
Description=Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
Source=Paul Collins Startup list
[lxamsp32]
Confirmed=?
Filename=lxamsp32.exe
Description=<font color="#FF0000">Associated with a Lexmark Printer - is it required?</font>
Source=Paul Collins Startup list
[LXbbmgr]
Confirmed=?
Filename=LXbbmgr.exe
Description=<font color="#FF0000">Lexmark printer button manager? Is it required?</font>
Source=Paul Collins Startup list
[LXBLKsk]
Confirmed=?
Filename=LXBLKsk.exe
Description=Lexmark related. <font color="#FF0000">What does it do, and is it required?</font>
Source=Paul Collins Startup list
[lxbrbmgr]
Confirmed=Y
Filename=lxbrbmgr.exe
Description=Lexmark printer button manager. Required for correct operation
Source=Paul Collins Startup list
[LXBRKsk]
Confirmed=?
Filename=LXBRKsk.exe
Description=Lexmark printer related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[LXSUPMON]
Confirmed=N
Filename=LXSUPMON.EXE
Description=Lexmark Printer. The printer should work fine without it
Description=HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
Source=Paul Collins Startup list
[M1cr0s0ft S3rcurity]
Confirmed=X
Filename=systemconfig.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.BKB" target=_blank>RBOT.BKB</a> WORM!
Source=Paul Collins Startup list
[M1cr0s0ft Upd4t4zS]
Confirmed=X
Filename=update32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmi.html" target=_blank>RBOT-MI</a> WORM!
Source=Paul Collins Startup list
[m32info]
Confirmed=X
Filename=m32info.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[M3Tray]
Confirmed=N
Filename=m3tray.exe
Description=<a href="http://www.movielink.com/" target="_blank">Movielink</a> - internet movie rental System Tray access
Source=Paul Collins Startup list
[Macfee Security Patch]
Confirmed=X
Filename=Mpfsheild.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotnp.html" target=_blank>RBOT-NP</a> WORM!
Source=Paul Collins Startup list
[Machine Debug Manager]
Confirmed=U
Filename=mdm.exe
Description=Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;321410" target="_blank"> here</a> to disable
Source=Paul Collins Startup list
[MacLic]
Confirmed=N
Filename=MacLic.exe
Description=Part of <a href="http://www.dataviz.com/products/conversionsplus/index.html" target="_blank">Conversions Plus</a> from DataViz - allowing PC and MAC owners to share disks
Source=Paul Collins Startup list
[MacName]
Confirmed=N
Filename=MacName.exe
Description=Part of <a href="http://www.dataviz.com/products/conversionsplus/index.html" target="_blank">Conversions Plus</a> from DataViz - allowing PC and MAC owners to share disks
Source=Paul Collins Startup list
[MAD.EXE]
Confirmed=Y
Filename=MAD.EXE
Description=MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up?
Source=Paul Collins Startup list
[MadExe]
Confirmed=N
Filename=LaunchRA.exe
Description=Dell Resolution Assistant
Source=Paul Collins Startup list
[MagicDsk]
Confirmed=U
Filename=MAGICDSK.EXE
Description=Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons
Source=Paul Collins Startup list
[Magitime]
Confirmed=N
Filename=Magitime.exe
Description=<a href="http://www.geocities.com/magistone/magitime.htm" target="_blank">Magitime</a> - connection tracking utility which monitors online time, expense, data transfer
Source=Paul Collins Startup list
[Mail.com]
Confirmed=?
Filename=mcalert.exe
Description=<a href="http://mail01.mail.com/" target="_blank">Mail.com</a> - free web-mail service. <font color="#FF0000">Does mcalert.exe notify you when new mail has arrived?</font>
Source=Paul Collins Startup list
[MailBell]
Confirmed=U
Filename=mailbell.exe
Description=<a href="http://www.emtec.com/mailbell/" target="_blank">MailBell</a> e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
Source=Paul Collins Startup list
[Mailbox Verifier]
Confirmed=U
Filename=mboxvrfy.exe
Description=<a href="http://" target="_blank">Mailbox Verifier (MV)</a> is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
Source=Paul Collins Startup list
[MailScan Dispatcher]
Confirmed=Y
Filename=Launch.exe
Description=<a href="http://www.mspl.net/antivirus/mailscan/ms4adv.asp" target="_blank">MailScan</a> Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned
Source=Paul Collins Startup list
[Mail_Check]
Confirmed=X
Filename=Mail_Check.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_PANOIL.C" target="_blank">PANOIL.C</a> WORM!
Source=Paul Collins Startup list
[MAIN]
Confirmed=U
Filename=main.exe
Description=<a href="http://www.spycop.com/" target="_blank">SpyCop</a> surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
Source=Paul Collins Startup list
[Main Executable (HP)]
Confirmed=?
Filename=HP05T0R5.exe
Description=<font color="#FF0000">HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?</font>
Source=Paul Collins Startup list
[main16]
Confirmed=X
Filename=main16.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[main32]
Confirmed=X
Filename=main32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[mainviewex]
Confirmed=X
Filename=mainviewex.exe
Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=40493" target=_blank>GEMA.D</a> TROJAN!
Source=Paul Collins Startup list
[Mania Win Restore]
Confirmed=N
Filename=RESWIN.EXE
Description=Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
Source=Paul Collins Startup list
[Mantis]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mantibe.html" target="_blank">MANTIBE</a> VIRUS!
Source=Paul Collins Startup list
[MapiDrv]
Confirmed=X
Filename=mpisvc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.mipsiv.html" target="_blank">MIPSIV</a> TROJAN!
Source=Paul Collins Startup list
[mapisvc32]
Confirmed=X
Filename=mapisvc32.exe
Description=Added by the KX VIRUS and also recognised by Symantec as <a href="http://securityresponse.symantec.com/avcenter/venc/data/adware.fapi.html" target="_blank"> FPAI</a> adware
Source=Paul Collins Startup list
[masqform.exe]
Confirmed=N
Filename=masqform.exe
Description=PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms
Source=Paul Collins Startup list
[Mass storage check registry]
Confirmed=N
Filename=rundll32.exe MSDServ.dll, check registry
Description=Used with a USB based smartmedia card reader
Source=Paul Collins Startup list
[Master Volume Spy]
Confirmed=U
Filename=MASTERVOLUMESPY.EXE
Description=Volume control for the Gateway Destination "DestiVu" media interface
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.matrixscreen.html" target=_blank>MATRIXSCREEN</a> TROJAN!
Source=Paul Collins Startup list
[MatrixScreenSaver]
Confirmed=X
Filename=mss.exe
Description=Malware, see <a href="http://www.spywareinfo.com/forums/index.php?s=&act=ST&f=11&t=7278" target="_blank"> here</a>
Source=Paul Collins Startup list
[Matrox Color Control]
Confirmed=N
Filename=hgcctl95.exe
Description=For Matrox video cards. Quick access to changing colors
Source=Paul Collins Startup list
[Matrox Control Center]
Confirmed=N
Filename=mgactrl.exe
Description=For Matrox video cards. Quick access to settings
Source=Paul Collins Startup list
[Matrox Diagnostic]
Confirmed=N
Filename=mgadiag.exe
Description=For Matrox video cards. Quick access to diagnostics
Source=Paul Collins Startup list
[Matrox Powerdesk]
Confirmed=N
Filename=PDesk.exe
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[Matrox PowerDesk 8]
Confirmed=N
Filename=Matrox.PowerDesk.exe /silent
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[Matrox QuickDesk]
Confirmed=N
Filename=mgaqdesk.exe
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[MaxAlerts]
Confirmed=X
Filename=max.exe
Description=Bonzi MaxALERT - spyware
Source=Paul Collins Startup list
[MaxtorCombo]
Confirmed=Y
Filename=ComboButton.exe
Description=Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
Source=Paul Collins Startup list
[MaxtorReg]
Confirmed=U
Filename=AUTOREG.EXE
Description=Part of <a href="http://www.netsizzle.net/sysagent.asp" target="_blank">SYSagent</a> - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
Source=Paul Collins Startup list
[MBM 4]
Confirmed=U
Filename=MBM4.exe
Description=Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[MBM 5]
Confirmed=U
Filename=MBM5.exe
Description=<a href="http://mbm.livewiredev.com/" target=_blank>Motherboard Monitor 5</a> - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[MBProbe]
Confirmed=U
Filename=mbrpobe.exe
Description=<a href="http://mbprobe.livewiredev.com/about.html" target="_blank">MBProbe</a> - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
Source=Paul Collins Startup list
[MC]
Confirmed=X
Filename=wintrims.exe
Description=Added by the <a href="http://www.europe.f-secure.com/v-descs/wintrim.shtml" target="_blank">WINTRIM</a> TROJAN!
Source=Paul Collins Startup list
[Mcafee Anti Scan]
Confirmed=X
Filename=NortonScn.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Mcafee Antivirus Monitoring System32mn]
Confirmed=X
Filename=VSStatmn32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[McAfee Firewall]
Confirmed=Y
Filename=CPD.EXE
Description=Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
Source=Paul Collins Startup list
[McAfee Guardian]
Confirmed=N
Filename=CMGRDIAN.EXE
Description=McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
Source=Paul Collins Startup list
[McAfee QuickClean Imonitor]
Confirmed=N
Filename=Plguni.exe
Description=<a href="http://www.mcafee.com/myapps/qc3/default.asp" target=_blank>McAfee QuickClean 3.0</a> - removes internet clutter and unwanted programs
Source=Paul Collins Startup list
[McAfee Winguage]
Confirmed=N
Filename=??
Description=Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
Source=Paul Collins Startup list
[McAfee.InstantUpdate.Monitor]
Confirmed=U
Filename=RuLaunch.exe
Description=Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
Source=Paul Collins Startup list
[McAfeeUpdaterUI]
Confirmed=?
Filename=UpdaterUI.exe
Description=Associated with McAfee Enterprise 7.0.0.<font color="#FF0000"> Updater for McAfee anti-virus and security programs?</font>
Source=Paul Collins Startup list
[McAfeeVirusScanService]
Confirmed=Y
Filename=Avsynmgr.exe
Description=From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application
Source=Paul Collins Startup list
[McAfeeWebscanX]
Confirmed=Y
Filename=WebScanX.exe
Description=From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
Source=Paul Collins Startup list
[Mcaffe Antivirus]
Confirmed=X
Filename=Mcafeescn.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[McAgentExe]
Confirmed=U
Filename=mcagent.exe
Description=From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed
Source=Paul Collins Startup list
[Mcappins.exe]
Confirmed=?
Filename=mcappins.exe
Description=McAfee Application Installer.<font color="#FF0000"> </font><font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[MChanger]
Confirmed=N
Filename=MChanger.exe
Description=Media Changer - utility that allows you to change wallpapers, sounds, themes, etc
Source=Paul Collins Startup list
[McRegWiz]
Confirmed=?
Filename=mcregwiz.exe
Description=McAfee antivirus related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[McUpdateExe]
Confirmed=U
Filename=mcupdate.exe
Description=From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions
Source=Paul Collins Startup list
[McVsRte]
Confirmed=Y
Filename=mcusrt.exe
Description=Part of McAfee's <a href="http://us.mcafee.com/root/product.asp?productid=msc" target="_blank">SecurityCenter</a>. Must remain checked but one user reports Windows glitches with no response from McAfee as to why
Source=Paul Collins Startup list
[mcvsshld]
Confirmed=Y
Filename=mcvsshld.exe
Description=McAfee VirusScan On-line. See also the McAgentExe entry
Source=Paul Collins Startup list
[MD IE Plugin]
Confirmed=X
Filename=md.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[MD IE Plugin]
Confirmed=X
Filename=winy.exe
Description=Adware
Source=Paul Collins Startup list
[mdac_runonce]
Confirmed=N
Filename=runonce.exe
Description=Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe".
Source=Paul Collins Startup list
[mdetect]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.spabot.html" target="_blank">SPABOT</a> TROJAN!
Source=Paul Collins Startup list
[Mdm]
Confirmed=X
Filename=Mdm.vbs
Description=Added by the <a href="http://vil.nai.com/vil/content/v_99145.htm" target="_blank">WHITEHO</a> VIRUS or <a href="http://securityresponse.symantec.com/avcenter/venc/data/vbs.trappy@mm.html" target="_blank">TRAPPY</a> WORM!
Source=Paul Collins Startup list
[mdm]
Confirmed=X
Filename=mdm.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojlydraf.html" target=_blank>LYDRA-F</a> TROJAN! Note - this is not the valid Machine Debug Manager which shares the same filename
Source=Paul Collins Startup list
[MDM7]
Confirmed=U
Filename=mdm.exe
Description=Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;321410" target="_blank"> here</a> to disable
Source=Paul Collins Startup list
[Mdmdll]
Confirmed=X
Filename=mdmdll.exe
Description=Added by the <a href="http://www.pestpatrol.com/PestInfo/t/trojandownloader_win32_crypter.asp" target=_blank>CRYPTER</a> TROJAN!
Source=Paul Collins Startup list
[Mdmdll32]
Confirmed=X
Filename=mdmdll32.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[mdwmdmsp]
Confirmed=X
Filename=mdwmdmsp.exe
Description=Adware - recognized by <a href="http://www.kaspersky.com/personalpro" target=_blank>Kaspersky</a> antivirus and others as TrojanDownloader.Win32.Agent.am
Description=Added by a unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Media Manager Indexer]
Confirmed=U
Filename=AIRSVCU.EXE
Description=Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see <a href="http://www.cug.edu.cn/fwzn/wlzx/wlfw/vid/USINGVID/0-7897/0-7897-0762-4/ch09.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[Media Player]
Confirmed=X
Filename=media.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojfldmediaa.html" target="_blank">FLDMEDIA-A</a> TROJAN!
Source=Paul Collins Startup list
[Media Player]
Confirmed=X
Filename=wmplayer.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotbm.html" target="_blank">AGOBOT-BM</a> WORM!
Source=Paul Collins Startup list
[Media Plug x.1.2]
Confirmed=X
Filename=msdm.exe
Description=Added by the MULDROP.352 VIRUS!
Source=Paul Collins Startup list
[Media Service]
Confirmed=X
Filename=msn64.exe
Description=Added by the <a href="http://hu.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_SPYBOT.EV" target="_blank">SPYBOT.EV</a> WORM!
Source=Paul Collins Startup list
[Media service]
Confirmed=X
Filename=msnmsgxr.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.TF" target="_blank">SDBOT.TF</a> WORM!
Source=Paul Collins Startup list
[Media service]
Confirmed=X
Filename=SYSTEM64.EXE
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=65730&VName=WORM_RBOT.QV&VSect=T" target="_blank">RBOT.QV</a> WORM!
Source=Paul Collins Startup list
[MediaFace Integration]
Confirmed=N
Filename=Sethook.exe
Description=Fellowes NeatoÖ cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
Source=Paul Collins Startup list
[Mediafour Mac Volume Notifications]
Confirmed=U
Filename=Macvntfy.exe
Description=<a href="http://www.mediafour.com/products/xplay/" target="_blank">Mediafour Xplay</a> - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
Source=Paul Collins Startup list
[Mediafour XPlay Tray Notification Icon]
Confirmed=U
Filename=Xptryicn.exe
Description=<a href="http://www.mediafour.com/products/xplay/" target=_blank>Mediafour Xplay</a> - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
Source=Paul Collins Startup list
[MediaKey]
Confirmed=U
Filename=MediaKey.exe
Description=<a href="http://www.futurepowerusa.com/support/kb_911/help/overview.htm" target="_blank">Multimedia keyboard</a> manager. Required if you use the multimedia keys
Source=Paul Collins Startup list
[MediaLoads]
Confirmed=X
Filename=dw.exe
Description=<a href="http://www.medialoads.com/" target="_blank">Medialoads</a> is advertising software - running DownloadWare as its executable. Installed as a bundle with <a href="http://www.kazaa.com/en/privacy/bundles.htm" target="_blank">Kazaa Media Desktop</a>. See <a href="http://and.doxdesk.com/parasite/DownloadWare.html" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[MediaLoads Installer]
Confirmed=X
Filename=dw.exe
Description=<a href="http://www.medialoads.com/" target="_blank">Medialoads</a> is advertising software - running DownloadWare as its executable. Installed as a bundle with <a href="http://www.kazaa.com/en/privacy/bundles.htm" target="_blank">Kazaa Media Desktop</a>. See <a href="http://and.doxdesk.com/parasite/DownloadWare.html" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[MediaMonitor]
Confirmed=N
Filename=Mediam~1.exe
Description=Installed by Smartdisk MVP CD burning software. Software will work fine without it
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gruel@mm.html" target="_blank">GRUEL</a> WORM!
Source=Paul Collins Startup list
[MediaPath]
Confirmed=X
Filename=Root.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gruel@mm.html" target="_blank">GRUEL</a> WORM!
Source=Paul Collins Startup list
[MediaRing Talk]
Confirmed=N
Filename=mrtalk.exe
Description=Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs
Source=Paul Collins Startup list
[media_manager]
Confirmed=X
Filename=mediaman.exe
Description=<a target="_blank" href="http://www.mini-player.com/">Mini-Player</a>, IMESH related foistware, see <a target="_blank" href="http://www.spywareinfo.com/yabbse/index.php?board=10;action=display;threadid=2633;start=0#msg20371">here</a>
Source=Paul Collins Startup list
[media_stub]
Confirmed=X
Filename=stub.exe
Description=<a target="_blank" href="http://www.mini-player.com/">Mini-Player</a>, IMESH related foistware, see <a target="_blank" href="http://www.spywareinfo.com/yabbse/index.php?board=10;action=display;threadid=2633;start=0#msg20371">here</a>
Source=Paul Collins Startup list
[MemConfig]
Confirmed=X
Filename=SetupIE.com
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.taplak.html" target="_blank">TAPLAK</a> WORM!
Source=Paul Collins Startup list
[MemoKit]
Confirmed=U
Filename=MK.EXE
Description=Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[Memory Check]
Confirmed=X
Filename=memore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.killav.c.html" target="_blank">KILLAV.C</a> TROJAN!
Source=Paul Collins Startup list
[Memory Stick Monitor]
Confirmed=N
Filename=MSTAT.exe
Description=Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer
Source=Paul Collins Startup list
[Memory Stick Monitor]
Confirmed=U
Filename=MSstat.exe
Description=Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
Description=Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[MemoryMeter]
Confirmed=X
Filename=MemoryMeter.exe
Description=Autoinstalling spyware by <a href="http://www.totalvelocity.com/" target="_blank">Total Velocity</a>
Source=Paul Collins Startup list
[MemScanner]
Confirmed=N
Filename=MemScanner.exe
Description=SpyHunter - spyware remover of somewhat dubious repute, see <a href="http://www.spywarewarrior.com/rogue_anti-spyware.htm#sh_note" target="_blank">note</a>
Source=Paul Collins Startup list
[MemTurbo]
Confirmed=U
Filename=memturbo.exe
Description=<a href="http://www.memturbo.com/" target="_blank">MemTurbo</a> memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[MenuSnap]
Confirmed=N
Filename=MenuSnap.exe
Description=<a href="http://www.rietta.com/menusnap/" target="_blank">MenuSnap</a> from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe
Source=Paul Collins Startup list
[Message Queuing]
Confirmed=X
Filename=msmqs.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.freefors.html" target="_blank">FREEFORS</a> TROJAN!
Description=<a href="http://www.ograhl.com/en/messageblocker/" target="_blank">Message Blocker</a> - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message"
Source=Paul Collins Startup list
[Messenger]
Confirmed=X
Filename=messenger.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.kutex.html" target="_blank">KUTEX</a> TROJAN!
Source=Paul Collins Startup list
[Messenger Block]
Confirmed=X
Filename=msngrblock.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.patoo@mm.html" target="_blank">PATOO</a> WORM!
Source=Paul Collins Startup list
[Messenger start-up]
Confirmed=X
Filename=Msgran.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gramos.html" target="_blank">GRAMOS</a> WORM!
Source=Paul Collins Startup list
[Messenger6]
Confirmed=X
Filename=command.pif
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.inzae.b@mm.html" target=_blank>INZAE.B</a> WORM!
Source=Paul Collins Startup list
[MessengerDiscovery]
Confirmed=U
Filename=MessengerDiscovery.exe
Description=<a href="http://www.messengerdiscovery.com/" target=_blank>MessengerDiscovery</a> is a MSN Messenger add-on - adding over 70 new features
Source=Paul Collins Startup list
[MessengerPlus]
Confirmed=N
Filename=MsgPlus.exe
Description=<a href="http://www.msgplus.net/" target=_blank>MessengerPlus</a> - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media <a href="http://inetexplorer.mvps.org/data/messenger_plus.htm" target=_blank>LOP</a> adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
Source=Paul Collins Startup list
[MessengerPlus2]
Confirmed=N
Filename=MsgPlus.exe
Description=<a href="http://www.msgplus.net/" target=_blank>MessengerPlus</a> - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media <a href="http://inetexplorer.mvps.org/data/messenger_plus.htm" target=_blank>LOP</a> adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
Source=Paul Collins Startup list
[MessengerPlus3]
Confirmed=N
Filename=MsgPlus.exe
Description=<a href="http://www.msgplus.net/" target=_blank>MessengerPlus</a> - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media <a href="http://inetexplorer.mvps.org/data/messenger_plus.htm" target=_blank>LOP</a> adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!
Source=Paul Collins Startup list
[messnger]
Confirmed=X
Filename=[worm filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.deloder.html" target="_blank">DELODER</a> WORM!
Source=Paul Collins Startup list
[messnger]
Confirmed=X
Filename=Dvldr32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DELODER.A" target="_blank">DELODER.A</a> WORM!
Source=Paul Collins Startup list
[MeTaLRoCk (irc.musirc.com) has sex with printers]
Confirmed=X
Filename=metalrock-is-gay.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDEX.Q" target=_blank>RANDEX.Q</a> WORM!
Description=MATROX Graphics card related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[MGA Quickdesk]
Confirmed=N
Filename=MGAQDESK.EXE
Description=For Matrox video cards. Quick access to tweak your card to your liking
Source=Paul Collins Startup list
[Mgabg]
Confirmed=?
Filename=Mgabg.exe
Description=Matrox BIOS Guard. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[mgavctrl]
Confirmed=Y
Filename=mgavrtcl.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[mgavctrl]
Confirmed=Y
Filename=mgavrte.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[mgavrtclexe]
Confirmed=Y
Filename=mgavrtcl.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[mgavrtclexe]
Confirmed=Y
Filename=mgavrte.exe
Description=McAfee's Virus Scan Online
Source=Paul Collins Startup list
[MGA_CD_Install]
Confirmed=N
Filename=mgasetup.exe
Description=Matrox Millennium video driver. Not required once drivers installed
Source=Paul Collins Startup list
[MHDOGStart]
Confirmed=X
Filename=mhdogst.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS
Source=Paul Collins Startup list
[MHINIT]
Confirmed=N
Filename=MHINIT.EXE
Description=Part of the Cybermedia Clean Sweep package
Source=Paul Collins Startup list
[Mickey Mouse Cereal]
Confirmed=X
Filename=[random filename].exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.q.html" target=_blank>RANKY.Q</a> TROJAN!
Source=Paul Collins Startup list
[Micr Update]
Confirmed=X
Filename=soundblaster.exe
Description=Added by the <a href="http://no.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SDBOT.NP" target="_blank">SDBOT.NP</a> WORM!
Source=Paul Collins Startup list
[Microangelo Desktop]
Confirmed=U
Filename=Muamgr.exe
Description=Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs
Source=Paul Collins Startup list
[microAttuneDownload]
Confirmed=N
Filename=atmdlusr.exe
Description=USR (US Robotics) modem auto updater. May be a sub-set of Attune
Source=Paul Collins Startup list
[MicroDialler]
Confirmed=U
Filename=atdialler1.exe
Description=Part of the <a href="https://www.freeserve.com/time/anytimereg/migration/?redirect=int" target="_blank">Freeserve Connection Kit</a> - changes the dial-up for Freeserve AnyTime if access problems are encountered
Source=Paul Collins Startup list
[Microfinder lptt01]
Confirmed=X
Filename=mcf.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>
Source=Paul Collins Startup list
[Microfinder ml097e]
Confirmed=X
Filename=mcf.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>
Source=Paul Collins Startup list
[MicroLoad]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.darby.html" target="_blank">DARBY</a> WORM!
Source=Paul Collins Startup list
[Microsof Windows Host]
Confirmed=X
Filename=svhost32.exe
Description=Added by the <a href="http://www.trendmicro.co.jp/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ADY" target=_blank>RBOT.ADY</a> WORM!
Source=Paul Collins Startup list
[Microsof Winlog Host]
Confirmed=X
Filename=wilogon32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.XC" target=_blank>RBOT.XC</a> WORM!
Source=Paul Collins Startup list
[Microsofot x386 System Monitor]
Confirmed=X
Filename=system32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.M" target="_blank">WOOTBOT.M</a> WORM!
Source=Paul Collins Startup list
[microsoft]
Confirmed=X
Filename=svchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.astef.html" target="_blank">ASTEF</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.repsan.html" target="_blank">RESPAN</a> WORMS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[microsoft]
Confirmed=X
Filename=microsoft.hta
Description=HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
Source=Paul Collins Startup list
[Microsoft Associates, Inc.]
Confirmed=X
Filename=iexplorer.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Microsoft .NET Confingurator]
Confirmed=X
Filename=msnconf.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft 16Bit Update]
Confirmed=X
Filename=wuapdate16.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CZ" target="_blank">RBOT.CZ</a> WORM!
Source=Paul Collins Startup list
[Microsoft ALG32 Protocol]
Confirmed=X
Filename=alg32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Announcement Listener]
Confirmed=N
Filename=Annclist.exe
Description=MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
Source=Paul Collins Startup list
[Microsoft Ansti Update]
Confirmed=X
Filename=msie.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotle.html" target="_blank">RBOT-LE</a> WORM!
Source=Paul Collins Startup list
[Microsoft AOL32 Protocol]
Confirmed=X
Filename=aol32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Associates, Inc.]
Confirmed=X
Filename=iexplorer.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Microsoft AUT Update]
Confirmed=X
Filename=MSlti32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotx.html" target="_blank">RBOT-X</a> WORM!
Source=Paul Collins Startup list
[Microsoft AUT Update]
Confirmed=X
Filename=MSlti16.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.EB&VSect=T" target=_blank>RBOT.EB</a> WORM!
Source=Paul Collins Startup list
[Microsoft auto update]
Confirmed=X
Filename=winupdate.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.bmbot.html" target="_blank">BMBOT</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft AutoUpdater]
Confirmed=X
Filename=svhost.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_RBOT.QG" target="_blank">RBOT.QG</a> WORM!
Source=Paul Collins Startup list
[Microsoft Conf Ldr]
Confirmed=X
Filename=sysconf.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Config]
Confirmed=X
Filename=msconf.exe
Description=Added by the <a href="http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.PV" target="_blank">RBOT.PV</a> WORM!
Source=Paul Collins Startup list
[Microsoft Config]
Confirmed=X
Filename=MSCONF.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlg.html" target=_blank>RBOT-LG</a> WORM!
Source=Paul Collins Startup list
[Microsoft Config File]
Confirmed=X
Filename=config.exe
Description=Added by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
Source=Paul Collins Startup list
[Microsoft Corporation]
Confirmed=X
Filename=[random filename]
Description=Added by various VIRUSES, WORMS & TROJANS!
Source=Paul Collins Startup list
[Microsoft CSRSS32 Protocol]
Confirmed=X
Filename=csrss32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft CSRSS386 Protocol]
Confirmed=X
Filename=csrss386.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Cvrt]
Confirmed=X
Filename=mscvrt32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Data Helper]
Confirmed=X
Filename=cihost.exe
Description=Malware, possibly a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.linst.html" target="_blank">LINST</a> TROJAN
Source=Paul Collins Startup list
[Microsoft Data Machine]
Confirmed=X
Filename=csdata32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Database Handler]
Confirmed=X
Filename=mssql32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.ax.html" target="_blank">RANDEX.AX</a> WORM!
Source=Paul Collins Startup list
[Microsoft Decryption Technology]
Confirmed=X
Filename=Msfenoe.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotdg.html" target=_blank>SPYBOT-DG</a> WORM!
Source=Paul Collins Startup list
[Microsoft Diagnostic]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www3.ca.com/virusinfo/Virus.asp?ID=11532" target="_blank">ACEBOT</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Digital Clock]
Confirmed=X
Filename=msclock.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32nackbotd.html" target="_blank">NACKBOT-D</a> WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=Spoolserv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.dinfor.worm.html" target="_blank">DINFOR</a> WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=rasmngr.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=PDSched.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.CN&VSect=T" target=_blank>SDBOT.CN</a> WORM!
Source=Paul Collins Startup list
[Microsoft DirectX]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.MY&VSect=T" target=_blank>SDBOT.MY</a> WORM!
Source=Paul Collins Startup list
[Microsoft Dll Management]
Confirmed=X
Filename=windll.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmt.html" target=_blank>RBOT-MT</a> WORM!
Source=Paul Collins Startup list
[Microsoft DNS Query]
Confirmed=X
Filename=msdns.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.GEN" target=_blank>WOOTBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Document]
Confirmed=X
Filename=krisp.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotrq.html" target=_blank>SDBOT-RQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Drivers]
Confirmed=X
Filename=WSconf.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.GEN" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft ErgoPack]
Confirmed=X
Filename=wserb32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotri.html" target=_blank>RBOT-RI</a> WORM!
Source=Paul Collins Startup list
[Microsoft Excell]
Confirmed=X
Filename=wuamngr32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqh.html" target=_blank>RBOT-QH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Executing]
Confirmed=X
Filename=microsoft.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.UV" target=_blank>AGOBOT.UV</a> WORM!
Source=Paul Collins Startup list
[Microsoft EXPLOREXP Protocol]
Confirmed=X
Filename=explorexp.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Features]
Confirmed=X
Filename=ms32cfg.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_RBOT.HO&VSect=T" target="_blank">RBOT.HO</a> WORM!
Source=Paul Collins Startup list
[Microsoft Find Fast]
Confirmed=X
Filename=Findfast.exe
Description=Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier
Source=Paul Collins Startup list
[Microsoft Firewall]
Confirmed=X
Filename=firewallsp2.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmc.html" target="_blank">RBOT-MC</a> WORM!
Source=Paul Collins Startup list
[MICROSOFT FIREWALL CLIENT]
Confirmed=Y
Filename=ISATRAY.EXE
Description=MS Internet Security and Acceleration Server 2000
Source=Paul Collins Startup list
[Microsoft Gina V Encryption]
Confirmed=X
Filename=MSGINAV.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Greetings Reminders]
Confirmed=N
Filename=MHPRMIND.EXE
Description=Microsoft Home Publishing greetings reminder
Source=Paul Collins Startup list
[Microsoft Greetings Workshop Reminder]
Confirmed=N
Filename=Gwremind.exe
Description=You really want to be reminded about somebody's birthday at the expense of resources?
Source=Paul Collins Startup list
[Microsoft Greetings Reminder]
Confirmed=N
Filename=MHPRMINF.EXE
Description=You really want to be reminded about somebody's birthday at the expense of resources?
Source=Paul Collins Startup list
[Microsoft Help SVC]
Confirmed=X
Filename=msnmngr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpq.html" target="_blank">SDBOT-PQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Help System]
Confirmed=X
Filename=mshelp32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft IE]
Confirmed=X
Filename=Iexplore.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotag.html" target="_blank">FORBOT-AG</a> WORM! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Microsoft IE Execute shell]
Confirmed=X
Filename=IEExec.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.n.html" target="_blank">ALADINZ.N</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft IIS]
Confirmed=X
Filename=syshost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.francette.worm.html" target="_blank">FRANCETTE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Inc.]
Confirmed=X
Filename=iexplorer.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Inet Xp..]
Confirmed=X
Filename=teekids.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.c.worm.html" target="_blank">BLASTER.C</a> WORM!
Source=Paul Collins Startup list
[Microsoft Intellitype Pro]
Confirmed=U
Filename=speedkey.exe
Description=Additional keyboard shortcuts on MS programmable keyboard
Source=Paul Collins Startup list
[Microsoft Internet]
Confirmed=X
Filename=expl0rer.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Internet]
Confirmed=X
Filename=windows32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotf.html" target="_blank">SDBOT-F</a> WORM!
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotkx.html" target="_blank">RBOT-KX</a> WORM!
Source=Paul Collins Startup list
[Microsoft Internet Explorer]
Confirmed=X
Filename=iexplore.exe
Description=Downloader trojan. Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Microsoft Internet Firewall Manager]
Confirmed=X
Filename=GMT16.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.at.html" target="_blank">RANDEX.AT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Internet Services]
Confirmed=X
Filename=Smss32.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.MS" target="_blank">RBOT.MS</a> WORM!
Source=Paul Collins Startup list
[Microsoft IPC]
Confirmed=X
Filename=system.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.nullbot.html" target="_blank">NULLBOT</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft IPC]
Confirmed=X
Filename=svshost.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=win64.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.GA" target="_blank">RBOT.GA</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=IEserv.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=msupdate.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=winn43.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=svchsst.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotdh.html" target=_blank>RBOT-DH</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=win43.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotsa.html" target=_blank>RBOT-SA</a> WORM!
Source=Paul Collins Startup list
[Microsoft IT Update]
Confirmed=X
Filename=windows.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotjm.html" target=_blank>RBOT-GL</a> WORM!
Source=Paul Collins Startup list
[Microsoft Java Virtual Machine]
Confirmed=X
Filename=winscr32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.GEN" target=_blank>WOOTBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Java Windows Update]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotdz.html" target=_blank>RBOT-DZ</a> WORM!
Source=Paul Collins Startup list
[Microsoft JavaVM]
Confirmed=X
Filename=msjarun.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotjw.html" target="_blank">RBOT-JW</a> WORM!
Source=Paul Collins Startup list
[Microsoft Kernel]
Confirmed=X
Filename=Windows_kernel32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.ae@mm.html" target=_blank>NETSKY.AE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Lmhosting Service]
Confirmed=X
Filename=lmhosts.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotrc.html" target=_blank>RBOT-RC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Locals 332]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotku.html" target="_blank">RBOT-KU</a> WORM!
Source=Paul Collins Startup list
[Microsoft LSASS386 Protocol]
Confirmed=X
Filename=scvhost32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Macro Protection SubSsy]
Confirmed=X
Filename=msacroprots386.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpn.html" target="_blank">RBOT-KE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Macro Protection Subsystems]
Confirmed=X
Filename=msmacroprotxz.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Macro Protection Subsystems]
Confirmed=X
Filename=Msmacroprot32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.KN" target=_blank>RBOT.KN</a> WORM!
Source=Paul Collins Startup list
[Microsoft Management]
Confirmed=X
Filename=lmas.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotcz.html" target=_blank>FORBOT-CZ</a> WORM!
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft media services]
Confirmed=X
Filename=Iassd.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target="_blank">AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft media services]
Confirmed=X
Filename=winmplayer.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_RBOT.ZO" target="_blank">RBOT.ZO</a> WORM!
Source=Paul Collins Startup list
[Microsoft Movie Maker]
Confirmed=X
Filename=Mmaker.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.ircbot.c.html" target="_blank">IRCBOT.C</a> TROJAN! Note that this is not a valid Microsoft program
Source=Paul Collins Startup list
[Microsoft MSGPLUS32 Protocol]
Confirmed=X
Filename=msgplus32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft MSNGR32 Protocol]
Confirmed=X
Filename=msngr32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft MsnST]
Confirmed=X
Filename=msnst32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft MSUPDATE]
Confirmed=X
Filename=SpoolSvc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojsxtba.html" target="_blank">SXTB-A</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft NetMeeting Associates, Inc.]
Confirmed=X
Filename=NetMeeting.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Netview]
Confirmed=X
Filename=gesfm32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.randex.c.html" target="_blank">RANDEX.C</a> WORM!
Source=Paul Collins Startup list
[Microsoft Netview]
Confirmed=X
Filename=mssvc32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Netview Component v5.1]
Confirmed=X
Filename=msnv32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.f.html" target="_blank">RANDEX.F</a> WORM!
Source=Paul Collins Startup list
[Microsoft Network]
Confirmed=X
Filename=msnet.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mockbot.a.worm.html" target="_blank">MOCKBOT.A</a> WORM!
Source=Paul Collins Startup list
[Microsoft Network Daemon for Win32]
Confirmed=X
Filename=Netd32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.r.html" target="_blank">SDBOT.R</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft NT Update]
Confirmed=X
Filename=winexec32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=N
Filename=Osa.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=N
Filename=Msoffice.exe
Description=Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=X
Filename=MSMSGR.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bb.html" target="_blank">GAOBOT.BB</a> WORM!
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=N
Filename=Osa9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=X
Filename=lserv.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.MH&VSect=T" target=_blank>SDBOT.MH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Office]
Confirmed=X
Filename=Microsoft Office.hta
Description=HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
Source=Paul Collins Startup list
[Microsoft Office Fast Cache]
Confirmed=N
Filename=Fastboot.exe
Description=Part of MS Office 95 (v7.0). According to <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;Q132755" target=_blank>this</a> it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled
Source=Paul Collins Startup list
[Microsoft Office OneNote 2003 Quick Launch]
Confirmed=U
Filename=ONENOTEM.EXE
Description=ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work
Source=Paul Collins Startup list
[Microsoft Office Shortcut Bar]
Confirmed=N
Filename=Msoffice.exe
Description=Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly
Source=Paul Collins Startup list
[Microsoft Office Start]
Confirmed=X
Filename=winupdates.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bc.html" target="_blank">GAOBOT.BC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Office Startup]
Confirmed=N
Filename=Osa.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Office Startup]
Confirmed=N
Filename=Osa9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Personal Firewalls]
Confirmed=X
Filename=bakw.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotks.html" target="_blank">RBOT-KS</a> WORM!
Source=Paul Collins Startup list
[Microsoft RDLL]
Confirmed=X
Filename=sysconf32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Registry]
Confirmed=X
Filename=csrse.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpc.html" target=_blank>RBOT-PC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Restore]
Confirmed=X
Filename=scrgrd.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.BR" target=_blank>SPYBOT.BR</a> WORM!
Source=Paul Collins Startup list
[Microsoft Runtime]
Confirmed=X
Filename=CfgDll32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.bd.html" target="_blank">RANDEX.BD</a> WORM!
Source=Paul Collins Startup list
[Microsoft Scanreg]
Confirmed=X
Filename=microsoftscanreg.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_FRANRIV.A" target="_blank">FRANRIV.A</a> WORM!
Source=Paul Collins Startup list
[Microsoft SCVHOST32 Protocol]
Confirmed=X
Filename=scvhost32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Secure Messenger.NET Service]
Confirmed=X
Filename=securitychk.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_SDBOT.VT" target="_blank">SDBOT.VT</a> WORM!
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmq.html" target=_blank>RBOT-MQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Security Management]
Confirmed=X
Filename=winserv.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmj.html" target=_blank>RBOT-MJ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Server Application]
Confirmed=X
Filename=Sound.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotne.html" target=_blank>RBOT-NE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Service]
Confirmed=X
Filename=microhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlc.html" target="_blank">RBOT-LC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Service]
Confirmed=X
Filename=winsvc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32spybotdb.html" target="_blank">SPYBOT-DB</a> WORM!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=lsserv.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=lssrv.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CW&VSect=T" target="_blank">RBOT.CW</a> WORM!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=services.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.alets.html" target="_blank">ALETS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=lsrv.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotbk.html" target="_blank">RBOT-BK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Services]
Confirmed=X
Filename=svshost.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.alets.b.html" target=_blank>ALETS.B</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Sidewinder Game Controller Software]
Confirmed=N
Filename=SWTRAY.EXE
Description=MS SideWinder game controller system tray icon. Available via Start -> Programs
Source=Paul Collins Startup list
[Microsoft Software]
Confirmed=X
Filename=sysinfo33.exe
Description=Added by the <a href="http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.LS" target="_blank">RBOT.LS</a> WORM!
Source=Paul Collins Startup list
[microsoft software]
Confirmed=X
Filename=****.exe E255 [* = random char]
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft software]
Confirmed=X
Filename=cdaccess.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ABK" target=_blank>RBOT.ABK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Software Update]
Confirmed=X
Filename=nmon.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.HZ" target="_blank">RBOT.HZ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Sound Driver]
Confirmed=X
Filename=sound32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Sound Volume Tool]
Confirmed=N
Filename=mssvol.exe
Description=This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
Source=Paul Collins Startup list
[Microsoft SourceSafe]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html" target="_blank">WEBUS</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Microsoft Spool Server for Win32]
Confirmed=X
Filename=spoolsrv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.h.html" target="_blank">RANDEX.H</a> WORM!
Source=Paul Collins Startup list
[Microsoft SSISVRI32 Protocol]
Confirmed=X
Filename=ssisvri.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=asgard.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.PH" target="_blank">SDBOT.PH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=bot.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.IH" target="_blank">SDBOT.IH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=netscape.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/smb/security_info/virus_encyclopedia.php?s=1&VName=WORM_RANDEX.AE" target="_blank">RANDEX.AE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=slhost.exe
Description=Added by the <a href="http://it.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_SDBOT.YH" target="_blank">SDBOT.YH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=svhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpy.html" target="_blank">SDBOT-PY</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=WinLoginnn.exe
Description=Added by the <a href="http://fr.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=65624&VName=WORM_SPYBOT.FO&VSect=T" target="_blank">SPYBOT.FO</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=winupdate.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.ER" target="_blank">SDBOT.ER</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=xXx.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotkz.html" target="_blank">SDBOT-KZ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=___synmgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.maslan.a@mm.html" target=_blank>MASLAN.A</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.maslan.c@mm.html" target=_blank>MASLAN.C</a> WORMS!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=al.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=BKDR_OPTXPRO.132" target=_blank>OPTXPRO.132</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Synchronization Manager]
Confirmed=X
Filename=win.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.ak.html" target=_blank>SDBOT.AK</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=Cool.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.b.html" target="_blank">DONK.B</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=Wnetlib.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.c.html" target="_blank">DONK.C</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=dbnetlib.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.l.html" target="_blank">DONK.L</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=Keymgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.m.html" target="_blank">DONK.M</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=inetman.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.o.html" target="_blank">DONK.O</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=ntsysmgr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.donk.s.html" target="_blank">DONK.S</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=ntsysman.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotqw.html" target=_blank>SDBOT-QW</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=libsysmgr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotcaf.html" target=_blank>SDBOT-CAF</a> WORM!
Source=Paul Collins Startup list
[Microsoft System Checkup]
Confirmed=X
Filename=sysmgr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotoo.html" target=_blank>SDBOT-OO</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft System Restore Configuration]
Confirmed=X
Filename=CBRSS.EXE
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft System32 Update]
Confirmed=X
Filename=cmsrg.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgn.html" target=_blank>RBOT-GN</a> WORM!
Source=Paul Collins Startup list
[Microsoft Time Manager]
Confirmed=X
Filename=dveldr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbothq.html" target="_blank">RBOT-HQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Transfer File Server]
Confirmed=X
Filename=mtfs.exe
Description=Added by the <a href="http://www.trendmicro-middleeast.com/enterprise/security_info/ve_detail.php?VName=WORM_RBOT.AFE&VSect=T" target=_blank>RBOT.AFE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Tray]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.vsantivirus.com/back-delf-bz.htm" target="_blank">DELF.BZ</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Microsoft.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.afj.html" target="_blank">GAOBOT.AFJ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=mssmgrd.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.JT" target="_blank">SDBOT.JT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=mvsc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.daz.html" target="_blank">SPYBOT.DAZ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=ascdl.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.sy.html" target="_blank">GAOBOT.SY</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Isac.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotau.html" target="_blank">RBOT-AU</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=automgr32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=mediap.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Microsoftx.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=msconfg.exe
Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39662" target=_blank>RBOT.H</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Mslti32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlx.html" target="_blank">RBOT-LX</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=muamgrd.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target="_blank">AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=navmgrd.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.DP" target="_blank">SDBOT.DP</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Smss32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotcb.html" target="_blank">RBOT.CB</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=sys32cfg.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=VPC32.EXE
Description=Added by the <a href="http://it.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_AGOBOT.XM" target="_blank">AGOBOT.XM</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=winsys32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlk.html" target="_blank">RBOT-LK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuammgr32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaw.html" target="_blank">RBOT-AW</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wudmate.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AP" target="_blank">RBOT.AP</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=msawindows.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.afj.html" target="_blank">GAOBOT.AFJ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=msiwin84.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.afj.html" target="_blank">GAOBOT.AFJ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuamgrd32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ZB" target=_blank>RBOT.ZB</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=NAV.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotiv.html" target=_blank>RBOT-IV</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=systemi32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=xpupdate.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqe.html" target=_blank>RBOT-QE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=webm.exe
Description=Added by the <a href="http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SDBOT.WK" target=_blank>SDBOT.WK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wuagrd.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfk.html" target=_blank>RBOT-FK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=aaupdt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotrq.html" target=_blank>RBOT-RQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=lsac.exe
Description=Added by the <a href="http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?lst=det&idvirus=48428" target=_blank>GAOBOT.XW</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=Mupdate.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotag.html" target=_blank>RBOT-AG</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=prowind32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=snlogsvc.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=svhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotpi.html" target=_blank>RBOT-PI</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wauguard.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_RBOT.AEE" target=_blank>RBOT.AEE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=winscv.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotbh.html" target=_blank>RBOT-BH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=winsys.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgv.html" target=_blank>RBOT-GV</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wserv32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AF&VSect=T" target=_blank>RBOT.AF</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wtm32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaq.html" target=_blank>RBOT-AQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update]
Confirmed=X
Filename=wumgrd.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotky.html" target=_blank>SDBOT-KY</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update 32]
Confirmed=X
Filename=explore32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.cym.html" target="_blank">SPYBOT.CYM</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update 32]
Confirmed=X
Filename=MSupdate32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[MICROSOFT UPDATE CONFIGURATION]
Confirmed=X
Filename=WIN32SNC.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotai.html" target=_blank>RBOT-AI</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Emulator]
Confirmed=X
Filename=kern-mxe.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Loader]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=expl0rer.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.OK&VSect=T" target="_blank">SDBOT.OK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=rxhost.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.FC" target="_blank">RBOT.FC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=servicz.exe
Description=Added by the <a href="http://sophos.com/virusinfo/analyses/w32rbothu.html" target="_blank">RBOT-HU</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=SP2.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_SPYBOT.FP" target="_blank">SPYBOT.FP</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winini.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotkv.html" target="_blank">RBOT-KV</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=xvshost.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=65722&VName=WORM_RBOT.QP&VSect=O" target="_blank">RBOT.QP</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=memstat.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotom.html" target=_blank>RBOT-OM</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=ntce.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfa.html" target=_blank>RBOT-FA</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=system03.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotnm.html" target=_blank>RBOT-NM</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuawx.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotce.html" target=_blank>RBOT-CE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=zonealarm.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotbz.html" target=_blank>RBOT-BZ</a> WORM! Note - this is not the valid Zone Labs firewall program!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=systemll.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotjt.html" target=_blank>RBOT-JT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winupdt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfp.html"target=_blank>RBOT-FP</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=svshost.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.AK" target=_blank>RBOT.AK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuamgd.exe
Description=Added by the <a href="http://tr.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SDBOT.HQ" target=_blank>SDBOT.HQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wupdt32x.exe
Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=[random filename]
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=linux.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotim.html" target=_blank>RBOT-IM</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=lmrss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotdy.html" target=_blank>RBOT-DY</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=windowsu.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wininigo.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winmgr.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=Winmsixp32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.DN&VSect=T" target=_blank>RBOT.DN</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=Winregs32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.DN&VSect=T" target=_blank>RBOT.DN</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winxpini.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotob.html" target=_blank>RBOT-OB</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbothe.html" target=_blank>RBOT-HE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=wuagrd.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgf.html" target=_blank>RBOT-GF</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=LANWAKE.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqz.html" target=_blank>RBOT-QZ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=scvhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgs.html" target=_blank>RBOT-GS</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgk.html" target=_blank>RBOT-GK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=winss.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.JU" target=_blank>RBOT.JU</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Machine]
Confirmed=X
Filename=WUAMGRDXS.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgl.html" target=_blank>RBOT-GL</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Manager]
Confirmed=X
Filename=WINRLS.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotaf.html" target=_blank>RBOT-AF</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Mechene]
Confirmed=X
Filename=Updatez.exe
Description=Added by the <a href="http://www.sophos.com.au/virusinfo/analyses/w32rbotgi.html" target=_blank>RBOT-GI</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Module]
Confirmed=X
Filename=rundll24.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotps.html" target=_blank>RBOT-PS</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Security Patch]
Confirmed=X
Filename=mssecurityupdatepatch.exe
Description=Added by the AGENT.EF TROJAN!
Source=Paul Collins Startup list
[Microsoft Update Server]
Confirmed=X
Filename=mssrv.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft Update Service]
Confirmed=X
Filename=csrss32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobothc.html" target="_blank">AGOBOT-HC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Service]
Confirmed=X
Filename=mswin32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft update service]
Confirmed=X
Filename=systemm.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.GEN" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Time]
Confirmed=X
Filename=wuam.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotm.html" target="_blank">RBOT-M</a> WORM!
Source=Paul Collins Startup list
[Microsoft Update Win32a]
Confirmed=X
Filename=winupdate32a.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlo.html" target="_blank">RBOT-LO</a> WORM!
Source=Paul Collins Startup list
[Microsoft UPDATER32]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.ar.html" target="_blank">RANDEX.AR</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">Lsass.exe</a> system file should normally NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[Microsoft Updaters Pros]
Confirmed=X
Filename=WINDLL32XP.EXE
Description=Added by the SPYBOTTER.GEN VIRUS!
Source=Paul Collins Startup list
[Microsoft Updates]
Confirmed=X
Filename=systemc32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgr.html" target=_blank>RBOT-GR</a> WORM!
Source=Paul Collins Startup list
[Microsoft Updates Resources]
Confirmed=X
Filename=WinFixIDs.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft upnp Update]
Confirmed=X
Filename=msie.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotlq.html" target="_blank">RBOT-LQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Utility Startup]
Confirmed=N
Filename=OSA9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Microsoft Video Controls]
Confirmed=X
Filename=tskmsgr.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Virual Machine]
Confirmed=X
Filename=sms.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotsp.html" target=_blank>RBOT-SP</a> WORM!
Source=Paul Collins Startup list
[Microsoft Visual SourceSafe]
Confirmed=X
Filename=services.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html" target="_blank">NEVEG.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html" target="_blank">NEVEG.C</a> WORMS!. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target="_blank">services.exe</a> process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program
Source=Paul Collins Startup list
[Microsoft Visual SourceSafe]
Confirmed=X
Filename=winlogon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html" target="_blank">NEVEG.A</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/" target="_blank">winlogon.exe</a> process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program
Source=Paul Collins Startup list
[Microsoft Visual Studio VSA]
Confirmed=X
Filename=varpc32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Webserver]
Confirmed=U
Filename=svctrl.exe
Description=Personal web server program which enables you to create and host a web server from your computer. Not required for most people
Source=Paul Collins Startup list
[Microsoft Windows]
Confirmed=X
Filename=mstask0.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.FQ" target=_blank>SDBOT.FQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows 2000]
Confirmed=X
Filename=Winupdsdgm.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Control]
Confirmed=X
Filename=mswctl32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.JP" target=_blank>RBOT.JP</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows DHCP]
Confirmed=X
Filename=___r.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.maslan.a@mm.html" target=_blank>MASLAN.A</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.maslan.c@mm.html" target=_blank>MASLAN.C</a> WORMS!
Source=Paul Collins Startup list
[Microsoft Windows DLLHandler]
Confirmed=X
Filename=bitpaint.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=82113&VName=WORM_SDBOT.AHG&VSect=T" target=_blank>SDBOT.AHG</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows GUI]
Confirmed=X
Filename=Windowz.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.aev.html" target="_blank">RANDEX.AEV</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows GUI]
Confirmed=X
Filename=msmonk32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpe.html" target=_blank>SDBOT-PE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Kernel Services]
Confirmed=X
Filename=winkrnl386.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.zebroxy.html" target="_blank">ZEBROXY</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Windows Loader]
Confirmed=X
Filename=wloader.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Media Player]
Confirmed=X
Filename=mediaplayer.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Media Player]
Confirmed=X
Filename=wimp.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfn.html" target=_blank>RBOT-FN</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Secure Server]
Confirmed=X
Filename=rpcxWindows.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotll.html" target="_blank">RBOT-LL</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Securety]
Confirmed=X
Filename=wurguar.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotky.html" target=_blank>RBOT-KY</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Security]
Confirmed=X
Filename=spvsper.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.GEN" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Task Manger]
Confirmed=X
Filename=Mstosk.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotww.html" target="_blank">SDBOT-WW</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=rundlls.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.habrack.html" target="_blank">HABRACK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=msoffice2.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgb.html" target="_blank">RBOT-GB</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=spools.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/virus_encyclopedia.php?VName=WORM_SDBOT.TD" target="_blank">SDBOT.TD</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svchos.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/backdoor.sdbot.ac.html" target="_blank">SDBOT.AC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svcshost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotcf.html" target=_blank>FORBOT-CF</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svmhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotch.html" target=_blank>FORBOT-CH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=svshost.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=66325&VName=WORM_WOOTBOT.CJ&VSect=T" target=_blank>WOOTBOT.CJ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=msnmessenger.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.aj.html" target=_blank>SDBOT.AJ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=msnwun.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotrm.html" target=_blank>SDBOT-RM</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update]
Confirmed=X
Filename=scvvhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotdh.html" target=_blank>FORBOT-DH</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Update Service]
Confirmed=X
Filename=wupdmgr32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/dos.autocat.html" target="_blank">DOS.AUTOCAT</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=winupdgm.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bi.html" target="_blank">GAOBOT.BI</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=svchostz.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdaemonie.html" target="_blank">DAEMONI-E</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=WINIUPDATES.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotkk.html" target="_blank">RBOT-KK</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=WINUPDATE.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotli.html" target=_blank>SDBOT-PU</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=TMNTSrv.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updater]
Confirmed=X
Filename=win32upd.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotec.html" target=_blank>RBOT-EC</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows updaterD]
Confirmed=X
Filename=log32zx.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.w@mm.html" target="_blank">MYDOOM.W</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows Updates]
Confirmed=X
Filename=explorer32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.VQ&VSect=T" target=_blank>SDBOT.VQ</a> WORM!
Source=Paul Collins Startup list
[Microsoft Windows W32 Services]
Confirmed=X
Filename=mssw32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Winsock Wrapper]
Confirmed=X
Filename=ws2_32s.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=mntcgf032.exe
Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=svh0st.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.DL&VSect=T" target="_blank">SPYBOT.DL</a> WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=syslx32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Microsoft WinUpdate]
Confirmed=X
Filename=syswin32.exe
Description=Added by a variant of the <a href="http://vil.nai.com/vil/content/v_100454.htm" target="_blank">SDBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft WinUpdates]
Confirmed=X
Filename=serm32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.GE&VSect=T" target="_blank">RBOT.GE</a> WORM!
Source=Paul Collins Startup list
[Microsoft Word]
Confirmed=X
Filename=BootSector.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Microsoft Works Calendar Reminders]
Confirmed=N
Filename=wkcalrem.exe
Description=Produces a pop-up reminder of events scheduled using the MS Works Calendar
Source=Paul Collins Startup list
[Microsoft Works Portfolio]
Confirmed=N
Filename=WksSb.exe
Description=The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
Source=Paul Collins Startup list
[Microsoft Works Update Detection ]
Confirmed=N
Filename=wkdetect.exe
Description=Checks for updates to MS Works
Source=Paul Collins Startup list
[Microsoft World Service]
Confirmed=X
Filename=winworld.exe
Description=Added by an unidentified IRC worm with backdoor capability!
Source=Paul Collins Startup list
[Microsoft Wxdate]
Confirmed=X
Filename=Syswu32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.HZ&VSect=T" target=_blank>SPYBOT.HZ</a> WORM!
Source=Paul Collins Startup list
[microsoft xdaemon 2.0]
Confirmed=X
Filename=xdaemon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.delf.d.html" target="_blank">DELF.D</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft XML Service]
Confirmed=X
Filename=msxmlx.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.KS" target="_blank">RBOT.KS</a> WORM!
Source=Paul Collins Startup list
[Microsoft--Updates]
Confirmed=X
Filename=sxvhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotfh.html" target="_blank">RBOT-FH</a> WORM!
Source=Paul Collins Startup list
[Microsoft-Update]
Confirmed=X
Filename=wngard.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotjv.html" target="_blank">RBOT-JV</a> WORM!
Source=Paul Collins Startup list
[Microsoft-Updates]
Confirmed=X
Filename=svxhost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotct.html" target="_blank">RBOT-CT</a> WORM!
Source=Paul Collins Startup list
[microsoft420]
Confirmed=X
Filename=microsoft420.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MENACE.B" target="_blank">MENACE.B</a> WORM!
Source=Paul Collins Startup list
[Microsoftkeysd]
Confirmed=X
Filename=systemproc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbi.html" target=_blank>FORBOT-BI</a> WORM!
Source=Paul Collins Startup list
[Microsoftkeysd]
Confirmed=X
Filename=systemwin32s.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_WOOTBOT.CO&VSect=T" target=_blank>WOOTBOT.CO</a> WORM!
Source=Paul Collins Startup list
[Microsoftmsn32.exe]
Confirmed=X
Filename=microsoftmsn32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcertifc.html" target=_blank>CERTIF-C</a> TROJAN!
Source=Paul Collins Startup list
[MicrosoftMultimediaTask]
Confirmed=X
Filename=Mmtask.exe
Description=Adware downloader - not the valid MusicMatch Jukebox which shares the same filename
Source=Paul Collins Startup list
[MicrosoftNetwork Daemon for Win32]
Confirmed=X
Filename=NETD32.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.f.html" target="_blank">RANDEX.F</a> WORM!
Source=Paul Collins Startup list
[MicrosoftOEM]
Confirmed=X
Filename=smvss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdedlerg.html" target=_blank>DEDLER-G</a> TROJAN!
Source=Paul Collins Startup list
[Microsofts media]
Confirmed=X
Filename=winmplayd.exe
Description=Added by an undidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Microsofts Security Manager]
Confirmed=X
Filename=****.exe [**** = random char]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotwh.html" target=_blank>RBOT-WH</a> TROJAN!
Source=Paul Collins Startup list
[Microsofts Updatez]
Confirmed=X
Filename=cmsssr.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=mstask32.exe
Description=Added by the <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=100092" target="_blank">YAHA.P</a> WORM!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=Wintsk32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.yaha.u@mm.html" target="_blank">YAHA.U</a> WORM!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=EXPLORERE.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.ab@mm.html" target="_blank">YAHA.AB</a> WORM!
Source=Paul Collins Startup list
[MicrosoftServiceManager]
Confirmed=X
Filename=msupdat.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.aa@mm.html" target="_blank">YAHA.AA</a> WORM!
Source=Paul Collins Startup list
[MicrosoftSourceSafe]
Confirmed=X
Filename=lsass.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/trojan.webus.b.html" target="_blank">WEBUS.B</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target="_blank">lsass.exe</a> process, which should not appear in Msconfig/Startup!
Source=Paul Collins Startup list
[MicrosoftUpdate]
Confirmed=X
Filename=syshelper.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MicrosoftUpdate]
Confirmed=X
Filename=WinUp32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MicrosoftValue]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Microsoftvirus]
Confirmed=X
Filename=sysoverload.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotal.html" target="_blank">FORBOT-AL</a> WORM!
Source=Paul Collins Startup list
[MicrosoftWindows]
Confirmed=X
Filename=[various filenames]
Description=MagicSearch - a <a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite variant
Source=Paul Collins Startup list
[Microsoft⌐ PID Lex]
Confirmed=X
Filename=PIDLex.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.niovadoor.html" target="_blank">NIOVADOOR</a> TROJAN!
Source=Paul Collins Startup list
[Microsoft« System Mapper]
Confirmed=X
Filename=SysMap.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.mapsy.html" target="_blank">MAPSY</a> TROJAN!
Source=Paul Collins Startup list
[Microszoft Update Mach1nezs]
Confirmed=X
Filename=svchst.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rboted.html" target=_blank>RBOT-ED</a> WORM!
Source=Paul Collins Startup list
[Microzoft_Ofiz]
Confirmed=X
Filename=KdzEregli.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.amus.a@mm.html" target="_blank">AMUS.A</a> WORM!
Source=Paul Collins Startup list
[Micrsoft Driver]
Confirmed=X
Filename=windrive.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.af.html" target=_blank>SDBOT.AF</a> TROJAN!
Source=Paul Collins Startup list
[MightyFAX Controller]
Confirmed=N
Filename=MFNTCTL.EXE
Description=<a href="http://www.rkssoftware.com/mightyfax/overview.html" target="_blank">Mighty FAX</a> from RKS Software - "installs a printer driver so that you can fax directly from Windows software"
Description=Starts <a href="http://www.musicmatch.com/" target=_blank>Musicmatch Jukebox</a> at bootup - can be started manually
Source=Paul Collins Startup list
[MINIBUG]
Confirmed=X
Filename=MINIBUG.EXE
Description=Displays ads inside Weatherbug - see <a href="http://spybot.safer-networking.de/index.php?lang=en&page=knowledgebase/threats/spybots-minibug" target="_blank">here</a>
Source=Paul Collins Startup list
[MINIFERT.EXE]
Confirmed=N
Filename=MINIFERT.EXE
Description=Part of Backweb
Source=Paul Collins Startup list
[minilog]
Confirmed=U
Filename=MINILOG.EXE
Description=If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use
Source=Paul Collins Startup list
[MiniMavis]
Confirmed=N
Filename=MiniMavis.exe
Description=Mavis Beacon typing tutor
Source=Paul Collins Startup list
[MiniNote]
Confirmed=N
Filename=MININOTE.EXE
Description=<a href="http://www.fookes.com/software/mininote.htm" target="_blank">Mini NoteTab</a> was the first in the family of "NoteTab" text and HTML editors from Fookes Software
Source=Paul Collins Startup list
[Miniphone]
Confirmed=?
Filename=glophone.exe
Description=<a href="http://www.voiceglo.com/" target=_blank>VoiceGlo</a> Glophone Voice over Internet Protocol (VOIP) communications software - "an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer" - <font color="#FF0000">is it required in startup?</font>
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.ag.html" target=_blank>SDBOT.AG</a> TROJAN!
Source=Paul Collins Startup list
[Mirabilis ICQ]
Confirmed=N
Filename=NDetect.exe
Description=If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Source=Paul Collins Startup list
[Mirabilis ICQ]
Confirmed=N
Filename=icq.exe
Description=If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Source=Paul Collins Startup list
[Mirabilis ICQ]
Confirmed=N
Filename=ICQNet.exe
Description=If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Source=Paul Collins Startup list
[Miramar Systems, Inc.]
Confirmed=U
Filename=atmsg.exe
Description=Miramar PC/Mac networking software
Source=Paul Collins Startup list
[Mirate Sp 2 Information]
Confirmed=X
Filename=miratesp2.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_RBOT.QH" target=_blank>RBOT.QH</a> WORM!
Source=Paul Collins Startup list
[miroVIDEO Tray Tool]
Confirmed=N
Filename=misitray.exe
Description=Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions
Description=<a href="http://www.video-drivers.com/drivers/26/26750.htm" target="_blank">Miro</a> video driver related.<font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[misiTRAY]
Confirmed=?
Filename=misiTRAY.exe
Description=<a href="http://www.video-drivers.com/drivers/26/26750.htm" target="_blank">Miro</a> video driver related.<font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[Mixer]
Confirmed=N
Filename=Mixer.exe
Description=C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
Source=Paul Collins Startup list
[Mixghost]
Confirmed=N
Filename=mixghost.exe
Description=Management software for Altec Lansing speakers. If a change is needed, the user can launch it from the Start menu
Source=Paul Collins Startup list
[mload]
Confirmed=X
Filename=lxmstart.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MM Install]
Confirmed=?
Filename=setup.exe
Description=<font color="#FF0000">Possibly <a href="http://www.moneysoft.co.uk/" target="_blank">Money Manager</a> from Moneysoft?</font>
Source=Paul Collins Startup list
[mmcndmgr]
Confirmed=X
Filename=mmcndmgr.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[MMCWINMGMT]
Confirmed=N
Filename=winmgmt.exe
Description=Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer <a href="http://groups.google.com/groups?q=PCHealth+pchschd.exe&hl=en&selm=eeuEENQ6AHA.1484@tkmsftngp03&rnum=1" target="_blank">here</a>
Source=Paul Collins Startup list
[MMERefresh]
Confirmed=U
Filename=MMERefresh.exe
Description=Part of <a href="http://www.digidesign.com/" target="_blank">Digidesgin</a> Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R
Description=This is the <a href="http://www.microsoft.com/hwdev/tech/input/audctrl.asp" target="_blank">Human Interface Device Server</a> for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See <a href="http://www.microsoft.com/hwdev/hid/audctrl.htm" target="_blank">here</a>. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP
Source=Paul Collins Startup list
[MMHK]
Confirmed=?
Filename=mmhk.exe
Description=<font color="#FF0000">A driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys?</font>
Source=Paul Collins Startup list
[MMHotKey]
Confirmed=N
Filename=MMHotKey.exe
Description=Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
Source=Paul Collins Startup list
[MMKeybd]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[mmod]
Confirmed=X
Filename=mmod.exe
Description=Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read <a href="http://www.ahfb2000.com/ezula/ezula.php" target="_blank">here</a> for more information
Source=Paul Collins Startup list
[mmpti]
Confirmed=N
Filename=m1mmpti.exe
Description=Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards
Source=Paul Collins Startup list
[MMRun]
Confirmed=?
Filename=mmrun.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[mmsys]
Confirmed=?
Filename=recover.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[MMSystem]
Confirmed=X
Filename=RunDll32
Description=Added by the FUNNER-A WORM!
Source=Paul Collins Startup list
[MMTASK]
Confirmed=Y
Filename=mmtask.tsk
Description=A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc
Source=Paul Collins Startup list
[mmtask]
Confirmed=N
Filename=mmtask.exe
Description=Part of <a href="http://www.musicmatch.com/download/plus/jukebox_intro.htm?os=pc&mode=input&BTD=1&DID=" target="_blank"> MusicMatch Jukebox</a> - digital music player / CD burner and ripper / music organizer / playlist creator
Source=Paul Collins Startup list
[MMtask Service]
Confirmed=X
Filename=mmtask.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojbackgata.html" target="_blank">BACKGAT.A</a> TROJAN! Not the valid MusicMatch Jukebox which has the same filename
Source=Paul Collins Startup list
[MMTray]
Confirmed=N
Filename=mm_tray.exe
Description=<a href="http://www.musicmatch.com/download/plus/jukebox_intro.htm?os=pc&mode=input&BTD=1&DID=" target="_blank">MusicMatch Jukebox</a> icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator
Source=Paul Collins Startup list
[MMTray]
Confirmed=N
Filename=MMTray.exe
Description=Part of <a href="http://www.morgan-multimedia.com/" target="_blank"> Morgan Multimedia Codecs</a>. Only required when the codecs are used
Source=Paul Collins Startup list
[MMTray2K]
Confirmed=N
Filename=MMTray2K.exe
Description=Part of <a href="http://www.morgan-multimedia.com/" target="_blank"> Morgan Multimedia Codecs</a>. Only required when the codecs are used
Source=Paul Collins Startup list
[MMTrayLSI]
Confirmed=N
Filename=MMTrayLSI.exe
Description=Part of <a href="http://www.morgan-multimedia.com/" target="_blank"> Morgan Multimedia Codecs</a>. Only required when the codecs are used
Source=Paul Collins Startup list
[mmusrstp]
Confirmed=?
Filename=procrun.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[mmxrun]
Confirmed=X
Filename=msosa.exe
Description=Adult content dialler - see <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=11&t=7756&hl=&s=" target="_blank">here</a>. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return
Source=Paul Collins Startup list
[MNPol]
Confirmed=X
Filename=mnpol.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[MNS]
Confirmed=U
Filename=MNS.exe
Description=<a href="http://www.mobilenetswitch.com/" target=_blank>Mobile Net Switch</a> enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more
Source=Paul Collins Startup list
[mnsvc]
Confirmed=X
Filename=mnsvc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.autoupder.html" target="_blank">AUTOUPDER</a> TROJAN!
Source=Paul Collins Startup list
[mnsvcsp]
Confirmed=X
Filename=mnsvcsp.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[mobsync]
Confirmed=N
Filename=mobsync.exe
Description=MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages
Source=Paul Collins Startup list
[MOBSYNC32.EXE]
Confirmed=X
Filename=mobsync32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.finero.html" target="_blank">FINERO</a> TROJAN!
Source=Paul Collins Startup list
[MOD]
Confirmed=N
Filename=muamger.exe
Description=MicroAngelo On Display from <a href="http://www.impactsoft.com/muangelo/ondisplay/prodinfo.htm" target="_blank">Impact Software</a> lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them
Source=Paul Collins Startup list
[Modem]
Confirmed=X
Filename=locatesvc.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[MODEMBTR]
Confirmed=U
Filename=MODEMBTR.EXE
Description=Modem Booster from <a href="http://inklineglobal.com/" target="_blank">inKline Global</a> to improve ISP connections
Source=Paul Collins Startup list
[Modeminf]
Confirmed=X
Filename=Modeminf.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[ModemOnHold]
Confirmed=U
Filename=MOH.EXE
Description=NetWaiting Modem-on-Hold Application
Source=Paul Collins Startup list
[ModemUtility]
Confirmed=N
Filename=mdmsetpe.exe
Description=System Tray configuration icon for Aztech modems
Source=Paul Collins Startup list
[ModularConfig]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Module Call initialize]
Confirmed=X
Filename=RUNDLL32.EXE reg.dll, ondll_reg
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[Money Express]
Confirmed=N
Filename=moneyexpress.exe
Description=Part of MS Money. Available via Start -> Programs
Source=Paul Collins Startup list
[MoneyAgent]
Confirmed=N
Filename=money express.exe
Description=Part of MS Money. Available via Start -> Programs
Source=Paul Collins Startup list
[MoneyAgent]
Confirmed=N
Filename=mnyexpr.exe
Description=Microsoft Money
Source=Paul Collins Startup list
[MoneyStartUp]
Confirmed=N
Filename=Money Startup.exe
Description=Microsoft Money
Source=Paul Collins Startup list
[MoneyStartUp10.0]
Confirmed=N
Filename=Activation.exe
Description=Part of MS Money 2002. Available via Start -> Programs
Source=Paul Collins Startup list
[Monitor Apache Servers]
Confirmed=U
Filename=ApacheMonitor.exe
Description=Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
Source=Paul Collins Startup list
[Monitoring Service]
Confirmed=X
Filename=svchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.cone.c@mm.html" target="_blank">CONE.C</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Monitormgt]
Confirmed=X
Filename=Monitormgt.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Monstersoundtray]
Confirmed=N
Filename=Freectrl.exe
Description=Diamond Multimedia sound card control panel
Source=Paul Collins Startup list
[MonTest]
Confirmed=X
Filename=vccxzq.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotea.html" target=_blank>SDBOT-EA</a> WORM!
Source=Paul Collins Startup list
[MoodBook]
Confirmed=U
Filename=mb.exe
Description=<a href="http://www.moodbook.com/" target=_blank>MoodBook</a> is a free Windows utility that brings art to your desktop
Source=Paul Collins Startup list
[moon phase]
Confirmed=N
Filename=moon.exe
Description=<a href="http://www.locutuscodeware.com" target="_blank">Moon Phase</a> - tray icon that indicates the phases of the moon
Source=Paul Collins Startup list
[Morpheus]
Confirmed=N
Filename=morpheus.exe
Description=MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it"
Source=Paul Collins Startup list
[mosearch]
Confirmed=X
Filename=mosearch.exe
Description=Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try <a href="http://support.microsoft.com/support/kb/articles/Q282/1/06.asp" target="_blank">here</a>
Source=Paul Collins Startup list
[Motive SmartBridge]
Confirmed=N
Filename=mpbtn.exe
Description=System tray icon for the Virtual Assistant from <a href="http://www.attbi.com/" target="_blank">AT&T Broadband</a>, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[Motive SmartBridge]
Confirmed=N
Filename=MotiveSB.exe
Description=System tray icon for the Virtual Assistant from <a href="http://www.attbi.com/" target="_blank">AT&T Broadband</a>, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[MotiveMonitor]
Confirmed=U
Filename=motmon.exe
Description=Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is usedáthe suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required
Source=Paul Collins Startup list
[MotiveSB]
Confirmed=N
Filename=MotiveSB.exe
Description=System tray icon for the Virtual Assistant from <a href="http://www.attbi.com/" target="_blank">AT&T Broadband</a>, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[MotMon]
Confirmed=U
Filename=motmon.exe
Description=Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is usedáthe suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required
Source=Paul Collins Startup list
[Mount Safe & Sound]
Confirmed=U
Filename=Fbmount.exe
Description=From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
Source=Paul Collins Startup list
[Mouse 32A]
Confirmed=N
Filename=Mouse32A.exe
Description=Mouse driver to control mouse functions from Azona. Available via Start -> Programs
Source=Paul Collins Startup list
[Mouse Suite 98 Daemon]
Confirmed=N
Filename=pelmiced.exe
Description=Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
Source=Paul Collins Startup list
[mousebut]
Confirmed=X
Filename=mousebut.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[Mousecntl]
Confirmed=X
Filename=mousecntl.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER.C</a> TROJAN!
Source=Paul Collins Startup list
[MouseCount]
Confirmed=N
Filename=MC.exe
Description=<a href="http://www.kittyfeet.com/mousecount.htm" target="_blank">MouseCount</a> by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required
Source=Paul Collins Startup list
[mousedrv]
Confirmed=X
Filename=mousedrv.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[mouseElf]
Confirmed=U
Filename=MC.exe
Description=<a href="http://www.geniusnet.com.tw/product/mouse_line.htm" target=_blank>Genius NetScroll</a> mouse driver - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[mouseElf]
Confirmed=U
Filename=mouseElf.exe
Description=System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[MouseImp]
Confirmed=U
Filename=MImpHost.exe
Description=MouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device"
Source=Paul Collins Startup list
[Mousinfo]
Confirmed=U
Filename=mousinfo.exe
Description=MS mouse information tool - for troubleshooting mouse problems
Source=Paul Collins Startup list
[Movielink Manager Uninstall]
Confirmed=N
Filename=msvcmm32.exe
Description=Auto-update for <a href="http://www.movielink.com/" target="_blank">Movielink</a> - internet movie rental System Tray access
Source=Paul Collins Startup list
[MovieNetworks]
Confirmed=X
Filename=MovieNetworks.exe
Description=<a href="http://www.movienetworks.com/" target="_blank">MovieNetworks</a> will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:\Program Files\MovieNetworks directory
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDEX.CT" target="_blank">RANDEX.CT</a> WORM!
Source=Paul Collins Startup list
[MPEO]
Confirmed=U
Filename=Csinsm32.exe
Description=Automatic logging of installs from Norton CleanSweep - available via Start -> Programs
Source=Paul Collins Startup list
[MPFExe]
Confirmed=Y
Filename=mpf.exe
Description=McAfee Personal Firewall
Source=Paul Collins Startup list
[MPFExe]
Confirmed=Y
Filename=MpfTray.exe
Description=McAfee Personal Firewall
Source=Paul Collins Startup list
[MPL32 driver]
Confirmed=X
Filename=MPL32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojloonym.html" target="_blank">LOONY-M</a> TROJAN!
Source=Paul Collins Startup list
[MplSetup]
Confirmed=U
Filename=MplSetup.exe
Description=Used by Ricoh network printers to enable network printing from the client
Source=Paul Collins Startup list
[MPower]
Confirmed=U
Filename=MPower.exe
Description=<a href="http://www.mindbeat.com/" target="_blank">MPower</a> from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read <a href="http://www.aumha.org/a/memmgmt.htm" target="_blank">this</a> article and make up your own mind
Source=Paul Collins Startup list
[MPREXE]
Confirmed=X
Filename=MPREXE.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.T" target="_blank">OPASERV.T</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/mprexe/" target="_blank"> Mprexe.exe</a> system file
Source=Paul Collins Startup list
[MPREXE.exe]
Confirmed=Y
Filename=mprexe.exe
Description=WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see <a href="http://support.microsoft.com/directory/article.asp?ID=KB;EN-US;Q178084" target="_blank">here</a> and <a href="http://www.ohsu.edu/win95/html/mprexe.html" target="_blank">here</a>. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus
Source=Paul Collins Startup list
[MprHTML]
Confirmed=X
Filename=MprHTML.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_VAGRNOCK.12" target="_blank">VAGRNOCKER</a> TROJAN!
Source=Paul Collins Startup list
[MPSExe]
Confirmed=U
Filename=mscifapp.exe
Description=McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
Source=Paul Collins Startup list
[MPT]
Confirmed=?
Filename=MPT.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[MPtask Services]
Confirmed=X
Filename=mptask.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lala.html" target="_blank">LALA</a> or <a href="http://vil.nai.com/vil/content/v_99788.htm" target="_blank">AOT</a> TROJANS!
Source=Paul Collins Startup list
[MPTBox]
Confirmed=N
Filename=MPTBOX.EXE
Description=Cannon Multi-Pass toolbox - a button bar
Source=Paul Collins Startup list
[MPXTray]
Confirmed=N
Filename=mpxptray.exe
Description=Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc
Source=Paul Collins Startup list
[MP_STATUS_MONITOR]
Confirmed=?
Filename=monitr32.exe
Description=<font color="#FF0000">Related to Cannon Multi-Pass</font>
Source=Paul Collins Startup list
[mqbkup]
Confirmed=X
Filename=mqbkup.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.opaserv.k.worm.html" target="_blank">OPASERV.K</a> WORM!
Source=Paul Collins Startup list
[mrtMngr]
Confirmed=N
Filename=mrtMngr.exe
Description=Maintenance Release Task Manager for IntuitÆs QuickBooks or Quicken
Source=Paul Collins Startup list
[MRU-Blaster Scheduler]
Confirmed=U
Filename=scheduler.exe
Description=<a href="http://www.wilderssecurity.com/mrublaster.html" target="_blank">MRU-Blaster</a> scheduler - detects and cleans MRU (most recently used) lists on your computer
Source=Paul Collins Startup list
[MRU-Blaster Silent Clean]
Confirmed=N
Filename=mrublaster.exe
Description=<a href="http://www.wilderssecurity.com/mrublaster.html" target="_blank">MRU-Blaster</a> - performs silent cleaning of MRU lists at boot
Source=Paul Collins Startup list
[MS Config Loader]
Confirmed=X
Filename=svchos1.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.R" target="_blank">AGOBOT.R</a> WORM!
Source=Paul Collins Startup list
[MS Config Loader]
Confirmed=X
Filename=MSWin32bck.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.aa.html" target="_blank">GAOBOT.AA</a> WORM!
Source=Paul Collins Startup list
[MS Config Service]
Confirmed=X
Filename=Msloader32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotkj.html" target="_blank">RBOT-KJ</a> WORM!
Source=Paul Collins Startup list
[MS Configuration]
Confirmed=X
Filename=MSFramer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.ol.html" target="_blank">RANDEX.OL</a> WORM!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.ae@mm.html" target="_blank">YAHA.AE</a> WORM!
Source=Paul Collins Startup list
[MS FIREWALL]
Confirmed=X
Filename=msfrewall.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpu.html" target=_blank>SDBOT-PU</a> WORM!
Source=Paul Collins Startup list
[MS FIREWALL]
Confirmed=X
Filename=msfirewall.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotqh.html" target=_blank>SDBOT-QH</a> WORM!
Source=Paul Collins Startup list
[MS HTML]
Confirmed=X
Filename=msHtml.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_PESTDOOR.31" target="_blank">PESTDOOR.31</a> TROJAN!
Source=Paul Collins Startup list
[MS HTML]
Confirmed=X
Filename=mslat.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LATINUS.SVR" target="_blank">LATINUS.SVR</a> TROJAN!
Source=Paul Collins Startup list
[MS lsass Startup]
Confirmed=X
Filename=lsass135.exe
Description=Added by the <a href="http://ae.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.WM" target=_blank>RBOT.WM</a> WORM!
Source=Paul Collins Startup list
[MS management console]
Confirmed=?
Filename=mms.exe
Description=<font color="#FF0000">Suspicious as the Microsoft Management Console is "mmc.exe" and doesn't normally run at startup</font>
Source=Paul Collins Startup list
[MS Network Control]
Confirmed=X
Filename=mswin.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.dumba.html" target="_blank">DUMBA</a> TROJAN!
Source=Paul Collins Startup list
[MS Remote Procedure Call]
Confirmed=X
Filename=msrpc32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotql.html" target=_blank>RBOT-QL</a> WORM!
Source=Paul Collins Startup list
[MS Security Hotfix]
Confirmed=X
Filename=service5.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ag.html" target="_blank">GAOBOT.AG</a> WORM!
Source=Paul Collins Startup list
[MS Sound Config 16bit]
Confirmed=X
Filename=sndcfg16.exe
Description=Added by the <a href="http://www.f-secure.com/v-descs/sdbot_mb.shtml" target="_blank">SDBOT.MB</a> TROJAN!
Source=Paul Collins Startup list
[Ms Spool32]
Confirmed=X
Filename=MS SPOOL32.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.assasin.html" target="_blank">ASASSIN</a> TROJAN!
Source=Paul Collins Startup list
[MS SyS Restore]
Confirmed=X
Filename=sysrestore.exe
Description=Added by the <a href="http://es.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=66436&VName=WORM_RBOT.XM&VSect=T" target=_blank>RBOT.XM</a> WORM!
Source=Paul Collins Startup list
[MS Update]
Confirmed=X
Filename=syshost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32evamanf.html" target="_blank">EVAMAN-F</a> WORM!
Source=Paul Collins Startup list
[MS Updates]
Confirmed=X
Filename=mscache.exe
Description=Spyware web downloader
Source=Paul Collins Startup list
[MS Updates]
Confirmed=X
Filename=syshosts.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.y" target="_blank">MYDOOM.Y</a> WORM!
Source=Paul Collins Startup list
[MS Updates]
Confirmed=X
Filename=aupd.exe
Description=Spyware web downloader
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=arr.exe
Description=Adult content dialler - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99972" target="_blank">here</a>
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=cdm.exe
Description=Adult content dialler - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99972" target="_blank">here</a>
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=game.exe
Description=Adult content dialler - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99972" target="_blank">here</a>
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=msite18.exe
Description=Adult content dialler - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99972" target="_blank">here</a>
Source=Paul Collins Startup list
[MS-Connect]
Confirmed=X
Filename=web.exe
Description=Adult content dialler - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99972" target="_blank">here</a>
Source=Paul Collins Startup list
[MS-HTML]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_LATINUS.15" target="_blank">LATINUS.15</a> TROJAN!
Source=Paul Collins Startup list
[MS-RunKey]
Confirmed=X
Filename=arr.exe
Description=MS-Connect dialler/hijacker
Source=Paul Collins Startup list
[MS7531]
Confirmed=X
Filename=ms7531.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[MSACM]
Confirmed=X
Filename=msacm.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32opaservo.html" target="_blank">OPASERV-O</a> WORM!
Source=Paul Collins Startup list
[msadcheck]
Confirmed=X
Filename=msadcheck32.exe
Description=Browser hijacker, redirecting to search-system.com
Source=Paul Collins Startup list
[MSAdmin]
Confirmed=X
Filename=jdbgmrg.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DASMIN.A" target="_blank">DASMIN.A</a> TROJAN! Note - this is not the valid JDBGMGR.EXE file - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99436" target="_blank">here</a>
Source=Paul Collins Startup list
[MSAgent]
Confirmed=X
Filename=mshtm.exe
Description=Browser hijacker - redirecting to buldog-search.com
Source=Paul Collins Startup list
[MSBB]
Confirmed=X
Filename=msbb.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[MSChoExE]
Confirmed=X
Filename=suge.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[msci]
Confirmed=?
Filename=mcinfo.exe
Description=McAfee Internet Security related. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[mscman]
Confirmed=X
Filename=mscman.exe
Description=Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
Source=Paul Collins Startup list
[mscn]
Confirmed=U
Filename=mscn.exe
Description=Part of the SafeChildNet internet filtering program - required if you use it
Source=Paul Collins Startup list
[Mscnt]
Confirmed=X
Filename=mscnt.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[Mscolour]
Confirmed=X
Filename=mscolour.exe
Description=Added by the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=40574" target=_blank>GEMA</a> TROJAN!
Source=Paul Collins Startup list
[MSCommX]
Confirmed=X
Filename=mscommx.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">RBOT</a> WORM!
Source=Paul Collins Startup list
[MSCONFG32.EXE]
Confirmed=X
Filename=MSCONFG32.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.optix.04.c.html" target="_blank">OPTIX.04.C</a> TROJAN!
Source=Paul Collins Startup list
[MSConfig]
Confirmed=N
Filename=msconfig.exe
Description=Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
Source=Paul Collins Startup list
[MSConfig]
Confirmed=X
Filename=MSCONFIG32.EXE
Description=Unidentified adware, spyware or virus
Source=Paul Collins Startup list
[msconfig]
Confirmed=X
Filename=msconfig.exe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite related. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/msconfig/" target=_blank>msconfig.exe</a> which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
Source=Paul Collins Startup list
[Msconfig]
Confirmed=X
Filename=msconfig.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.winur.html" target="_blank">WINUR</a> WORM! Note - this is not the real msconfig.exe as it's located in C:\winrun\
Source=Paul Collins Startup list
[msconfig]
Confirmed=X
Filename=wins.exe
Description=Added by an unidentified IRC WORM with backdoor trojan capabilities!
Source=Paul Collins Startup list
[Msconfig lptt01]
Confirmed=X
Filename=msconfig.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>. Note - this is not the valid Windows Msconfig which has the same executable name
Source=Paul Collins Startup list
[MSConfig Manager]
Confirmed=X
Filename=msupdate.exe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target=_blank>CoolWebSearch</a> parasite related
Source=Paul Collins Startup list
[Msconfig ml097e]
Confirmed=X
Filename=msconfig.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>. Note - this is not the valid Windows Msconfig which has the same executable name
Source=Paul Collins Startup list
[msconfig service]
Confirmed=X
Filename=MSupdate32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[msconfig.exe]
Confirmed=X
Filename=proxy.exe
Description=Added by a variant of the AGENT.AH downloader TROJAN!
Source=Paul Collins Startup list
[msconfig.exe]
Confirmed=X
Filename=uline.exe
Description=Added by a variant of the AGENT.AH downloader TROJAN!
Source=Paul Collins Startup list
[MSConfig45]
Confirmed=X
Filename=MSConfig45.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=56539&VName=BKDR_SDBOT.OJ" target="_blank">SDBOT.OJ</a> TROJAN!
Source=Paul Collins Startup list
[MSConfigr]
Confirmed=X
Filename=jdbgmrg.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DASMIN.C" target="_blank">DASMIN.C</a> TROJAN! Note - this is not the valid JDBGMGR.EXE file - see <a href="http://vil.mcafee.com/dispVirus.asp?virus_k=99436" target="_blank">here</a>
Source=Paul Collins Startup list
[MSConfigReminder]
Confirmed=N
Filename=msconfig.exe
Description=Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
Source=Paul Collins Startup list
[MSCORE]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Mscsgs]
Confirmed=X
Filename=MSCSGS.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.zezer.worm.html" target="_blank">ZEZER</a> WORM!
Source=Paul Collins Startup list
[Mscsgs32]
Confirmed=X
Filename=MSCSGS32.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.zezer.worm.html" target="_blank">ZEZER</a> WORM!
Source=Paul Collins Startup list
[Msctrl32]
Confirmed=X
Filename=Msctrl32.scr
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.redist@mm.html" target="_blank">REDIST</a> WORM!
Source=Paul Collins Startup list
[MSCVT]
Confirmed=X
Filename=MSCVT.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.slideshow.html" target="_blank">SLIDESHOW</a> WORM!
Source=Paul Collins Startup list
[msdev]
Confirmed=X
Filename=msdev.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotcr.html" target=_blank>FORBOT-CR</a> WORM!
Source=Paul Collins Startup list
[msdev]
Confirmed=X
Filename=msconfig.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.AAU&VSect=T" target=_blank>AGOBOT.AAU</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/msconfig/" target=_blank>msconfig.exe</a> which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
Source=Paul Collins Startup list
[MSDLL]
Confirmed=X
Filename=syscnfg.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Source=Paul Collins Startup list
[Msdmxm]
Confirmed=X
Filename=msdmxm.exe
Description=Adult premium rate dialler
Source=Paul Collins Startup list
[Msdos32]
Confirmed=X
Filename=Msdos32.pif
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.recory@mm.html" target="_blank">RECORY</a> WORM!
Source=Paul Collins Startup list
[msdos423]
Confirmed=X
Filename=msdos423.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MENACE.A" target="_blank">MENACE.A</a> WORM!
Source=Paul Collins Startup list
[MSDosdrv]
Confirmed=N
Filename=msdosdrv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.bacros.html" target=_blank>BACROS</a> WORM!
Source=Paul Collins Startup list
[MSDTC]
Confirmed=N
Filename=msdtc.exe
Description=MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.cayam@mm.html" target="_blank">CAYAM</a> WORM!
Source=Paul Collins Startup list
[msfindosa.exe]
Confirmed=X
Filename=msfindosa.exe
Description=Added by the <a href="http://vil.nai.com/vil/content/v_99960.htm" target="_blank">DOWNLOADER-BS</a> TROJAN!
Source=Paul Collins Startup list
[Msg Fixage]
Confirmed=X
Filename=msgfixed.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.ZD" target=_blank>SDBOT.ZD</a> WORM!
Source=Paul Collins Startup list
[MsgApi]
Confirmed=X
Filename=[path to file]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdedlerd.html" target="_blank">DEDLER-D</a> TROJAN!
Source=Paul Collins Startup list
[msgb1]
Confirmed=X
Filename=msgb1.exe
Description=Added by the DLUCA.GEN TROJAN!
Source=Paul Collins Startup list
[Msgmgr]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.babybear@mm.html" target="_blank">BABYBEAR</a> WORM!
Source=Paul Collins Startup list
[msgserv_]
Confirmed=X
Filename=Syss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/fanta.trojan.html" target=_blank>FANTA</a> TROJAN!
Source=Paul Collins Startup list
[Msgsrv16]
Confirmed=X
Filename=Msgsrv16.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.delf.family.html" target="_blank">DELF</a> family of TROJANS!
Source=Paul Collins Startup list
[MSGSRV32.exe]
Confirmed=Y
Filename=msgsrv32.exe
Description=Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see <a href="http://support.microsoft.com/support/kb/articles/q138/7/08.asp" target="_blank">here</a>. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background
Source=Paul Collins Startup list
[msgsvr32]
Confirmed=X
Filename=msgsvr32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.deadhat.b.html" target="_blank">DEADHAT.B</a> WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:\Windows\System) on a Win9x/Me machine
Source=Paul Collins Startup list
[Msgtray]
Confirmed=X
Filename=sys16.exe
Description=Added by an unknown VIRUS!
Source=Paul Collins Startup list
[MSHT@]
Confirmed=X
Filename=MSHT@.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_MAGISTR.A" target="_blank">MAGISTR.A</a> VIRUS!
Source=Paul Collins Startup list
[msidle]
Confirmed=X
Filename=msidle.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32opaservo.html" target="_blank">OPASERV-O</a> WORM!
Source=Paul Collins Startup list
[MSIdll]
Confirmed=X
Filename=winmp.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[MSIEXEC]
Confirmed=X
Filename=MSIEXEC32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.ainesey.a@mm.html" target="_blank">AINESEY.A</a> WORM!
Source=Paul Collins Startup list
[MSIN]
Confirmed=?
Filename=MSin.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[MSInfo]
Confirmed=X
Filename=msinfo.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.m.html" target="_blank">ALADINZ.M</a> TROJAN!
Source=Paul Collins Startup list
[MSInfo]
Confirmed=X
Filename=AVBgle.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.o@mm.html" target="_blank">NETSKY.O</a> WORM!
Source=Paul Collins Startup list
[MSInstall]
Confirmed=X
Filename=smvss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojdedlerg.html" target=_blank>DEDLER-G</a> TROJAN!
Source=Paul Collins Startup list
[msjava service]
Confirmed=X
Filename=xpcd.exe
Description=Added by the <a href="http://de.trendmicro-europe.com/consumer/security_info/ve_detail.php?VName=WORM_SDBOT.VM&VSect=T" target="_blank">SDBOT.VM</a> WORM!
Source=Paul Collins Startup list
[MSKAGENTEXE]
Confirmed=U
Filename=MskAgent.exe
Description=Part of <a href="http://us.mcafee.com/root/package.asp?pkgid=156" target="_blank">McAfee Spamkiller</a>
Source=Paul Collins Startup list
[MSKCES32]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.cloner.html" target="_blank">CLONER</a> TROJAN!
Source=Paul Collins Startup list
[MSKDetectorExe]
Confirmed=U
Filename=MSKDetct.exe
Description=Part of <a href="http://us.mcafee.com/root/package.asp?pkgid=156" target="_blank">McAfee Spamkiller</a>
Source=Paul Collins Startup list
[MSKernel32]
Confirmed=X
Filename=MSKernel32.vbs
Description=Added by the <a href="http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=VBS_LOVELETTER" target="_blank"> LOVELETTER</a> (I LOVE YOU) VIRUS!
Source=Paul Collins Startup list
[MSkernel32]
Confirmed=X
Filename=System.exe 4820
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.tuxder.html" target="_blank">TUXDER</a> TROJAN!
Description=Part of McAfee <a href="http://us.mcafee.com/root/package.asp?pkgid=156" target=_blank>Spamkiller</a>
Source=Paul Collins Startup list
[mslagent]
Confirmed=X
Filename=mslagent.exe
Description=Added by <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.simcss.b.html" target="_blank">SIMCSS.B</a> adware!
Source=Paul Collins Startup list
[MSLIB32]
Confirmed=?
Filename=mswatch32.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Mslogon lptt01]
Confirmed=X
Filename=mslogon.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[Mslogon ml097e]
Confirmed=X
Filename=mslogon.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[MsManager]
Confirmed=X
Filename=msmgr32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.af@mm.html" target="_blank">YAHA.AF</a> WORM!
Source=Paul Collins Startup list
[msmanager32]
Confirmed=X
Filename=msmngr32.exe
Description=Added by the <a href="http://www.us.sophos.com/virusinfo/analyses/w32randonr.html" target="_blank">RANDON-R</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_WOMANIZ.A" target="_blank">WOMANIZ.A</a>) WORM!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.framar.html" target="_blank">FRAMAR</a> TROJAN!
Source=Paul Collins Startup list
[MSMcAfeeh]
Confirmed=X
Filename=Avsynmgr32h.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.frango.html" target="_blank">FRANGO</a> TROJAN!
Source=Paul Collins Startup list
[MSMcAfeeS]
Confirmed=X
Filename=Avsynmgr32S.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.volac.html" target="_blank">VOLAC</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.volac.dr.html" target="_blank">VOLAC.DR</a> TROJANS!
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=40493" target=_blank>GEMA.D</a> TROJAN!
Source=Paul Collins Startup list
[MsmqIntCert]
Confirmed=?
Filename=regsvr32 /s mqrt.dll
Description=Microsoft Message Queue Server - Internal Certificate - see <a href="http://www.microsoft.com/msmq/" target="_blank">here</a> for more info and <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;230050" target="_blank">here</a> for a potential problem.<font color="#FF0000"> Is it required?</font>
Source=Paul Collins Startup list
[MSMSGS]
Confirmed=U
Filename=msmsgs.exe
Description=<a href="http://www.microsoft.com/windowsxp/windowsmessenger/default.asp"_blank">Windows Messenger</a> utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts"
Source=Paul Collins Startup list
[MSMsgSvc]
Confirmed=X
Filename=MSMSGSVC.exe
Description=Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
Source=Paul Collins Startup list
[msn]
Confirmed=X
Filename=system32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KITRO.A" target="_blank"> KITRO.A</a> WORM!
Source=Paul Collins Startup list
[msn]
Confirmed=X
Filename=msnmsg.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgo.html" target="_blank">RBOT-GO</a> WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=msnmsgs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotkl.html" target="_blank">RBOT-KL</a> WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=ctfmoons.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SPYBOT.HI" target=_blank>SPYBOT.HI</a> WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=msnmesengers.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotme.html" target=_blank>RBOT-ME</a> WORM!
Source=Paul Collins Startup list
[MSN]
Confirmed=X
Filename=MSN.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.minit.html" target=_blank>MINIT</a> WORM!
Source=Paul Collins Startup list
[MSN ang]
Confirmed=X
Filename=cssrss.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotce.html" target=_blank>FORBOT-CE</a> WORM!
Source=Paul Collins Startup list
[Msn Config]
Confirmed=X
Filename=msngf.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqg.html" target=_blank>RBOT-QG</a> WORM!
Source=Paul Collins Startup list
[MSN Internet Access]
Confirmed=N
Filename=trayclnt.exe
Description=Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards
Source=Paul Collins Startup list
[MSN Manager]
Confirmed=X
Filename=cvss.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[MSN Manager]
Confirmed=X
Filename=mscmgr.exe
Description=Unidentified malware - causes multiple browser windows to open
Source=Paul Collins Startup list
[MSN Messanger]
Confirmed=X
Filename=msnmsng.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_SDBOT.XN" target="_blank">SDBOT.XN</a> WORM!
Source=Paul Collins Startup list
[MSN messenger]
Confirmed=X
Filename=messenger.exe
Description=Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this <a href="http://forums.techguy.org/showthread.php?s=&threadid=109054" target="_blank">thread</a>
Source=Paul Collins Startup list
[Msn Messenger]
Confirmed=X
Filename=msnmsgs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojloonyp.html" target=_blank>LOONY-P</a> TROJAN!
Source=Paul Collins Startup list
[MSN messenger service]
Confirmed=X
Filename=mssgs.exe
Description=Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this <a href="http://forums.techguy.org/showthread.php?s=&threadid=109054" target="_blank">thread</a>
Source=Paul Collins Startup list
[Msn Messengers]
Confirmed=X
Filename=MSNMSGR.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.KX&VSect=T" target="_blank">RBOT.KX</a> WORM!
Source=Paul Collins Startup list
[Msn Patch]
Confirmed=X
Filename=msndp.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=WORM_RBOT.AAI" target=_blank>RBOT.AAI</a> WORM!
Source=Paul Collins Startup list
[Msn Patches]
Confirmed=X
Filename=msndr.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.GEN" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[Msn Plus Updater]
Confirmed=X
Filename=msnplus.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmu.html" target=_blank>RBOT-MU</a> WORM!
Source=Paul Collins Startup list
[MSN Quick View]
Confirmed=N
Filename=Msndc.exe
Description=Quick way to connect to MSN internet service
Source=Paul Collins Startup list
[MSN Start]
Confirmed=X
Filename=msnmsgr7.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotph.html" target=_blank>RBOT-PH</a> WORM!
Source=Paul Collins Startup list
[MSN Update]
Confirmed=X
Filename=mscon.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotqa.html" target=_blank>RBOT-QA</a> WORM!
Source=Paul Collins Startup list
[Msn Update Manager (Sp2)]
Confirmed=X
Filename=MSMSGS.EXE
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotnl.html" target=_blank>AGOBOT-NL</a> WORM!
Source=Paul Collins Startup list
[MSN Updater]
Confirmed=X
Filename=msnms.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotcg.html" target=_blank>FORBOT-CG</a> WORM!
Source=Paul Collins Startup list
[Msn Updater]
Confirmed=X
Filename=msnplugins.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rboths.html" target=_blank>RBOT-HS</a> WORM!
Source=Paul Collins Startup list
[MSN UPDATERS]
Confirmed=X
Filename=virtualmemory.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotjk.html" target="_blank">RBOT-JK</a> WORM!
Source=Paul Collins Startup list
[msnappau]
Confirmed=N
Filename=msnappau.exe
Description=Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar
Source=Paul Collins Startup list
[Msnarrator]
Confirmed=X
Filename=msnarrator.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_NARAT.A" target="_blank">NARAT.A</a> TROJAN! - also identified as <a href="http://securityresponse.symantec.com/avcenter/venc/data/adware.mpgcom.html" target="_blank">MPGCOM Toolbar</a> adware
Source=Paul Collins Startup list
[MSNET]
Confirmed=X
Filename=msnet.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.boa.html" target="_blank">BOA</a> WORM!
Source=Paul Collins Startup list
[MsnFixer]
Confirmed=?
Filename=msnfixjs.js
Description=<font color="#FF0000">Located in the HPbinmsnfix directory of a HP PC</font>
Source=Paul Collins Startup list
[MSNGrabber]
Confirmed=X
Filename=MSNgrabber.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.envid.a@mm.html" target=_blank>ENVID.A</a> WORM!
Source=Paul Collins Startup list
[MSNIA]
Confirmed=N
Filename=MSNIASVC.EXE
Description=Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG
Source=Paul Collins Startup list
[msnload32.exe]
Confirmed=X
Filename=msnload32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.m.html" target="_blank">BANCOS.M</a> TROJAN!
Source=Paul Collins Startup list
[MSNMESENGER]
Confirmed=X
Filename=Main.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.prorat.html" target="_blank">PRORAT</a> TROJAN!
Source=Paul Collins Startup list
[msnmsg.exe]
Confirmed=X
Filename=mscmd32.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Source=Paul Collins Startup list
[msnmsgr]
Confirmed=N
Filename=msnmsgr.exe
Description=<a href="http://messenger.msn.com/" target="_blank">MSN Messenger</a> utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts"
Source=Paul Collins Startup list
[MsnMsgr]
Confirmed=X
Filename=MsnMsgrs.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.netsky.ad@mm.html" target=_blank>NETSKY-AD</a> WORM!
Source=Paul Collins Startup list
[msnmsgr32-.exe]
Confirmed=X
Filename=msnmsgr-.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[MSNMSGR5]
Confirmed=X
Filename=MSNMSGR5.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/virus_encyclopedia.php?s=1&VName=WORM_RBOT.PQ" target="_blank">RBOT.PQ</a> WORM!
Source=Paul Collins Startup list
[MSNMSGRE]
Confirmed=X
Filename=swef.bat
Description=IRC backdoor TROJAN or WORM!
Source=Paul Collins Startup list
[MSNMSGRR]
Confirmed=X
Filename=swin.bat
Description=IRC backdoor TROJAN or WORM!
Source=Paul Collins Startup list
[MSNMSGRS1]
Confirmed=X
Filename=swed.bat
Description=IRC backdoor TROJAN or WORM!
Source=Paul Collins Startup list
[msnmsgsgs]
Confirmed=X
Filename=msnmsgsgs.exe
Description=Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
Source=Paul Collins Startup list
[MSNService]
Confirmed=X
Filename=MSNService.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.carpet.c.html" target="_blank">CARPET.C</a> WORM!
Source=Paul Collins Startup list
[MSNSysRestore]
Confirmed=X
Filename=pc32.exe
Description=Added by a variant of the MASTAK VIRUS!
Source=Paul Collins Startup list
[MSObject32]
Confirmed=X
Filename=MSObject32.js
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/js.pun.trojan.html" target="_blank">PUN</a> TROJAN!
Source=Paul Collins Startup list
[Msoffice]
Confirmed=X
Filename=msoffice.hta
Description=Hijacker - redirecting to Searchdot.net
Source=Paul Collins Startup list
[MSOffice]
Confirmed=X
Filename=services.exe
Description=Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/services/" target=_blank>services.exe</a> process, which should NOT figure in Msconfig/Startup!
Source=Paul Collins Startup list
[MSOleath32]
Confirmed=X
Filename=winss.exe
Description=Added by the <a href="http://vil.nai.com/vil/content/v_100491.htm" target=_blank>KATHER</a> TROJAN!
Source=Paul Collins Startup list
[MSOOBD]
Confirmed=X
Filename=MSOOBD.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_MAGISTR.A" target="_blank">MAGISTR.A</a> VIRUS!
Source=Paul Collins Startup list
[mspaint.exe]
Confirmed=X
Filename=check32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojagentah.html" target=_blank>AGENT.AH</a> TROJAN!
Source=Paul Collins Startup list
[Mspatch69]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.mprox.html" target="_blank">MPROX</a> TROJAN!
Source=Paul Collins Startup list
[Mspatch89]
Confirmed=X
Filename=cnqmax.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.p.html" target="_blank">RANDEX.P</a> WORM!
Source=Paul Collins Startup list
[MSPQFile]
Confirmed=X
Filename=MSA****.TMP
Description=Homepage hijacker. See <a href="http://www.spywareinfo.com/yabbse/index.php?board=11;action=display;threadid=776;start=10" target="_blank">here</a> for more information. **** can be anything
Source=Paul Collins Startup list
[MSprotect.exe]
Confirmed=X
Filename=MSprotect.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_DABYREV.A" target="_blank">DABYREV.A</a> VIRUS!
Source=Paul Collins Startup list
[mspwr]
Confirmed=U
Filename=pupstman.exe
Description="Transparent icon background" feature of Ashampoo's <a href="http://www.ashampoo.com/frontend/products/php/product.php?idstring=0105" target="_blank">PowerUp XP</a> (WinNT/2K/XP) and <a href="http://www.ashampoo.com/frontend/products/php/product.php?idstring=0005" target="_blank">PowerUp Deluxe</a> (Win98/Me)
Source=Paul Collins Startup list
[MSPY2002]
Confirmed=N
Filename=ImScInst.exe
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[MSR]
Confirmed=X
Filename=msr.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_AGOBOT.RT" target=_blank>AGOBOT.RT</a> WORM!
Source=Paul Collins Startup list
[Msrc]
Confirmed=X
Filename=Msrc.exe
Description=Added by the KRYPTONIC GHOST TROJAN!
Source=Paul Collins Startup list
[msreg.exe]
Confirmed=X
Filename=msrege.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.zinx.html" target="_blank">ZINX</a> TROJAN!
Source=Paul Collins Startup list
[msReg32 Loader]
Confirmed=X
Filename=msreg32.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_AGOBOT.IU&VSect=T" target=_blank>AGOBOT.IU</a> WORM!
Source=Paul Collins Startup list
[MSREGIT]
Confirmed=X
Filename=Msgp.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_KRYPGHOS.13" target="_blank">KRYPGHOS.13</a> TROJAN!
Source=Paul Collins Startup list
[MSRegSvc]
Confirmed=X
Filename=regsvc32.exe
Description=Homepage hijacker that changes your homepage to an adult content site
Source=Paul Collins Startup list
[msrunocx32]
Confirmed=X
Filename=msrunocx32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.skus.html" target="_blank">SKUS</a> WORM!
Source=Paul Collins Startup list
[msservice]
Confirmed=X
Filename=msserv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hyd@mm.html" target="_blank">HYD</a> WORM!
Source=Paul Collins Startup list
[MSSGisg]
Confirmed=X
Filename=[path to file]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.n.html" target=_blank>RANKY.N</a> TROJAN!
Source=Paul Collins Startup list
[MSSHVC]
Confirmed=X
Filename=MSSHVC.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.nuffy.a.html" target="_blank">NUFFY.A</a> WORM!
Source=Paul Collins Startup list
[mssoul]
Confirmed=X
Filename=msmscc2.exe
Description=Added by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!)
Source=Paul Collins Startup list
[MSSQL]
Confirmed=X
Filename=Mssql.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html" target="_blank">SDBOT</a> TROJAN!
Source=Paul Collins Startup list
[Msstart]
Confirmed=X
Filename=msstart.exe
Description=Added by the <a href="http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=BKDR_LIVUP.C" target="_blank">LIVUP.C</a> TROJAN!
Source=Paul Collins Startup list
[MSStartOptimizer]
Confirmed=X
Filename=Iexpres.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.poldo.b.html" target="_blank">POLDO.B</a> TROJAN!
Source=Paul Collins Startup list
[MSStartOptimizer]
Confirmed=X
Filename=WINUPD.EXE
Description=Adult content dialler - see <a href="http://www.spywareinfo.com/forums/index.php?act=ST&f=11&t=7756&hl=&s=" target="_blank">here</a>. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
Source=Paul Collins Startup list
[msstask]
Confirmed=X
Filename=msstask.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.myparty@mm.html" target="_blank">MYPARTY</a> WORM!
Source=Paul Collins Startup list
[mssurfer lptt01]
Confirmed=X
Filename=mssurfer.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[mssurfer ml097e]
Confirmed=X
Filename=mssurfer.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[mssvc]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.psk.html" target="_blank">PSK</a> TROJAN!
Source=Paul Collins Startup list
[MSSVC]
Confirmed=X
Filename=svcsys.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojfatoosc.html" target=_blank>FATOOS-C</a> TROJAN!
Source=Paul Collins Startup list
[MSSVC.EXE]
Confirmed=Y
Filename=MSSVC.EXE
Description=<a href="http://www.stealthdisk.com/" target="_blank">Stealthdisk</a> - hides folders, files and applications. Will also encrypt them for better protection
Source=Paul Collins Startup list
[mssvc32]
Confirmed=X
Filename=mssvc32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotme.html" target=_blank>AGOBOT-ME</a> WORM!
Source=Paul Collins Startup list
[mssys]
Confirmed=X
Filename=mssys.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.myss.b.html" target="_blank">MYSS.B</a> TROJAN!
Source=Paul Collins Startup list
[mssysint]
Confirmed=X
Filename=Iexplore .exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/pwsteal.abchlp.html" target="_blank">PWSTEAL.ABCHLP</a> and <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.pspider.310.b.html" target="_blank">PSPIDER.310.B</a> TROJANS! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[mssyslanhelper]
Confirmed=X
Filename=msmsgri32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.d.html" target="_blank">RANDEX.D</a> WORM!
Source=Paul Collins Startup list
[MsSystem]
Confirmed=X
Filename=msdos.exe
Description=Adult content downloader - see <a href="http://vil.nai.com/vil/content/v_100801.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[MsSystem]
Confirmed=X
Filename=mssys.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_VANTA.A" target="_blank">VANTA.A</a> TROJAN!
Source=Paul Collins Startup list
[MSSYSTEM]
Confirmed=X
Filename=svcsys.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojfatoosc.html" target=_blank>FATOOS-C</a> TROJAN!
Source=Paul Collins Startup list
[Mstapi]
Confirmed=X
Filename=Mstapi.exe
Description=Keylogger trojan
Source=Paul Collins Startup list
[Mstask]
Confirmed=X
Filename=mstask.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.N" target="_blank">OPASERV.N</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/mstask/" target="_blank">mstask.exe</a> system file and the executable resides in C:\Windows or C:\WINNT
Source=Paul Collins Startup list
[mstask]
Confirmed=X
Filename=mstask.exe
Description=Browser hijacker - redirecting to find-more.net. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/mstask/" target=_blank>mstask.exe</a> system file
Source=Paul Collins Startup list
[mstasks]
Confirmed=X
Filename=mstasks.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmultidray.html" target=_blank>MULTIDR-AY</a> TROJAN!
Source=Paul Collins Startup list
[Mstcgww]
Confirmed=?
Filename=MSTCGWW.EXE
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[MSTMON_Q]
Confirmed=N
Filename=MSTMON_Q.exe
Description=Generates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready
Source=Paul Collins Startup list
[Mstng32]
Confirmed=X
Filename=MSTng32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.tang@mm.html" target="_blank">TANG</a> WORM!
Source=Paul Collins Startup list
[MSUpdate]
Confirmed=X
Filename=wupd.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.m.html" target="_blank">ALADINZ.M</a> TROJAN!
Source=Paul Collins Startup list
[MSUpdate]
Confirmed=X
Filename=svchosthlp.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.t.worm.html" target="_blank">BLASTER.T</a> WORM!
Source=Paul Collins Startup list
[msupdate]
Confirmed=X
Filename=msupdate.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotmz.html" target=_blank>RBOT-MZ</a> WORM!
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related - resets home page to an adult content site
Source=Paul Collins Startup list
[MSupdater.exe]
Confirmed=X
Filename=N/A
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related. Installs the Winshow.dll browser plugin
Source=Paul Collins Startup list
[msupdates]
Confirmed=X
Filename=msupdt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotjo.html" target="_blank">RBOT-JO</a> WORM!
Source=Paul Collins Startup list
[MSUpdSrv]
Confirmed=X
Filename=msupdsrv.exe
Description=Browser hijacker, redirecting to a porn site
Source=Paul Collins Startup list
[msurl]
Confirmed=X
Filename=msurl32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[msuser32.exe]
Confirmed=X
Filename=msuser32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.androv.html" target="_blank">ANDROV</a> TROJAN!
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.xombe.html" target="_blank">XOMBE</a> TROJAN!
Source=Paul Collins Startup list
[MSVersion]
Confirmed=X
Filename=INTERNETFEATURES.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_POPMON.A" target="_blank">POPMON.A</a> TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[MSVersion]
Confirmed=X
Filename=clrschp038.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_POPMON.A" target="_blank">POPMON.A</a> TROJAN! - also known as PopMonster adware
Source=Paul Collins Startup list
[msvsc32]
Confirmed=X
Filename=msdev.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotgj.html" target=_blank>RBOT-GJ</a> WORM!
Source=Paul Collins Startup list
[MSVSync]
Confirmed=X
Filename=videosync.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[MSVXD]
Confirmed=X
Filename=MSVXD.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DATOM.A" target="_blank">DATOM.A</a> WORM!
Source=Paul Collins Startup list
[mswave]
Confirmed=X
Filename=mswave.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[Mswavedll]
Confirmed=X
Filename=mswavedll.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojcrypterc.html" target="_blank">CRYPTER-C</a> TROJAN!
Source=Paul Collins Startup list
[MSwheel]
Confirmed=U
Filename=mswheel.exe
Description=<a href="http://www.microsoft.com/intellipoint/" target="_blank">Microsoft Intellipoint</a> software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[Mswincfg]
Confirmed=X
Filename=Mswincfg32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_CYBERSPY.D" target="_blank">CYBRSPY.D</a> TROJAN!
Source=Paul Collins Startup list
[MsWindows SysDate]
Confirmed=X
Filename=sysmsvc.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.spybot.fcd.html" target=_blank>SPYBOT.FCD</a> WORM!
Source=Paul Collins Startup list
[Mswinpid32]
Confirmed=X
Filename=mswinpid32.exe
Description=Added by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
Source=Paul Collins Startup list
[MSWinSrv]
Confirmed=X
Filename=MSWinSrv.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.mtron.html" target=_blank>MTRON</a> TROJAN!
Source=Paul Collins Startup list
[MSWinSrv32]
Confirmed=X
Filename=MSWinSrv32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojmtronb.html" target=_blank>MTRON-B</a> TROJAN!
Source=Paul Collins Startup list
[mswspl]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_SMALL.IQ" target="_blank">SMALL.IQ</a> TROJAN!
Source=Paul Collins Startup list
[mswspl]
Confirmed=X
Filename=searchbarcash.exe
Description=SearchBarCash adware
Source=Paul Collins Startup list
[msys lptt01]
Confirmed=X
Filename=msys.exe
Description=New variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "Msyss" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[Msys32]
Confirmed=X
Filename=morfitwebentrance.exe
Description=<a href="http://www.morfit.com/Eng/" target="_blank">Morfit ADjectPager</a> - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage
Source=Paul Collins Startup list
[MS_NETD_WIN32]
Confirmed=X
Filename=netd32.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.f.html" target="_blank">RANDEX.F</a> WORM!
Source=Paul Collins Startup list
[MS_SETUP.EXE]
Confirmed=X
Filename=MS_SETUP.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.charge.html" target="_blank">CHARGE</a> TROJAN!
Source=Paul Collins Startup list
[Mtr2]
Confirmed=X
Filename=mtr2.exe
Description=Added by the KRYPTONIC GHOST TROJAN!
Source=Paul Collins Startup list
[MUAL]
Confirmed=U
Filename=mual.exe
Description=Millesky video mail updater and launcher
Source=Paul Collins Startup list
[muamgr]
Confirmed=U
Filename=muamgr.exe
Description=Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs
Source=Paul Collins Startup list
[Mufix]
Confirmed=?
Filename=mufix.exe
Description=Part of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - <font color="#FF0000">what does it do and is it required</font>
Source=Paul Collins Startup list
[Multi-function keyboard]
Confirmed=U
Filename=GWHotkey.exe
Description=Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)
Source=Paul Collins Startup list
[MultiCAM Initializer]
Confirmed=U
Filename=MCamBoot.exe
Description=The MultiCAM Initializer is part of the MultiCAM software package provided by <a href="http://www.vistaimaging.com/multicam.htm" target="_blank">Vista Imaging</a> in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled
Source=Paul Collins Startup list
[Multimedia Codecs]
Confirmed=X
Filename=mcc.exe
Description=Added by the <a href="http://www.giantcompany.com/antispyware/research/spyware/spyware-Trojan.PornDownloaderMCC.aspx" target="_blank">MCC</a> TROJAN!
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[MULTIMEDIA KEYBOARD]
Confirmed=U
Filename=MMKeybd.exe
Description=Multimedia keyboard manager. Required if you use the additional keys
Source=Paul Collins Startup list
[MultiRes]
Confirmed=U
Filename=MultiRes.exe
Description=<a href="http://www.entechtaiwan.com/" target="_blank">MultiRes</a> - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP
Source=Paul Collins Startup list
[MUPS]
Confirmed=U
Filename=MUPS.exe
Description=Lauches the <a href="http://www.belkin.com/" target="_blank">Belkin</a> Bulldog Plus Service - required if you want to access the UPS advanced functions
Source=Paul Collins Startup list
[murphy shield]
Confirmed=Y
Filename=lmgui.exe
Description=Firewall part of <a href="http://www.bitdefender.com/" target="_blank">BitDefender</a> virus scanner/firewall
Source=Paul Collins Startup list
[Music01 Server]
Confirmed=N
Filename=Music01 Server.exe
Description=J River <a target="_blank" href="http://www.musicex.com/mediajukebox/">Media Jukebox</a>
Source=Paul Collins Startup list
[MusIRC (irc.music.com) client]
Confirmed=X
Filename=musirc4.71.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RANDEX.Q" target=_blank>RANDEX.Q</a> WORM!
Description=MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive
Source=Paul Collins Startup list
[MWProEng]
Confirmed=N
Filename=MWProEng.exe
Description=Logitech Mouseware Pro software - only required when using special functions
Description=SeekSeek search hijacker related - as seen <a href="http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?act=ST&f=32&t=6790&st=0&&#entry34543" target="_blank"> here</a>
Source=Paul Collins Startup list
[MxHLp32]
Confirmed=X
Filename=MxHLp32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_VAGRNOCK.12" target="_blank">VAGRNOCKER</a> TROJAN!
Source=Paul Collins Startup list
[MXO Auto Loader]
Confirmed=U
Filename=MXOaldr.exe
Description=Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
Source=Paul Collins Startup list
[MxRunner]
Confirmed=U
Filename=MxRunner.exe
Description=<a href="http://www.aladdinsys.com/easyuninstall/" target="_blank">EasyUninstall</a> from Aladdin Systems (formerly by Ontrack)
Source=Paul Collins Startup list
[My Agent]
Confirmed=X
Filename=msagent.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_NEGASMS.A" target="_blank">NEGASMS.A</a> TROJAN!
Source=Paul Collins Startup list
[My App]
Confirmed=X
Filename=SMSSvc.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_NEGASMS.A" target="_blank">NEGASMS.A</a> TROJAN!
Description=System tray notification for McAfee <a href="http://www.mcafeeasap.com/content/virusscan_asap/default.asp" target="_blank">VirusScan ASaP</a> on-line scanner. Not required to be protected but you lose notifications
Source=Paul Collins Startup list
[Myapp]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.fatee.b.html" target="_blank">FATEE.B</a> WORM!
Source=Paul Collins Startup list
[Myapp]
Confirmed=X
Filename=service.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[MyAV]
Confirmed=X
Filename=avpguard.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.j@mm.html" target="_blank">NETSKY.J</a> WORM!
Source=Paul Collins Startup list
[MyCIO Agent Service]
Confirmed=Y
Filename=myagtsvc.exe
Description=McAfee <a href="http://www.mcafeeasap.com/content/virusscan_asap/default.asp" target="_blank">VirusScan ASaP</a> Agent service
Source=Paul Collins Startup list
[myCIO.com ASaP]
Confirmed=U
Filename=MyAgtTry.exe
Description=System tray notification for McAfee <a href="http://www.mcafeeasap.com/content/virusscan_asap/default.asp" target="_blank">VirusScan ASaP</a> on-line scanner. Not required to be protected but you lose notifications
Source=Paul Collins Startup list
[myCIO.com Splash]
Confirmed=N
Filename=Splash.exe
Description=Splash screen for McAfee <a href="http://www.mcafeeasap.com/content/virusscan_asap/default.asp" target="_blank">VirusScan ASaP</a> on-line scanner
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_HOLAR.A" target="_blank">HOLAR.A</a> WORM!
Source=Paul Collins Startup list
[myNetWatchman]
Confirmed=U
Filename=nwclient.exe
Description=Sends your firewall alerts to a <a href="http://www.mynetwatchman.com/" target="_blank">website</a>, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running
Source=Paul Collins Startup list
[MyPointsPointAlert]
Confirmed=X
Filename=wjview ...MyPointsPointAlertrun.exe
Description="With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy
Source=Paul Collins Startup list
[myprint mileage]
Confirmed=U
Filename=mpm.exe
Description=Reports battery status on a portable printer
Source=Paul Collins Startup list
[mysoft]
Confirmed=X
Filename=winexplor.exe
Description=Homepage hijacker
Source=Paul Collins Startup list
[MySoftware NewsFlash]
Confirmed=?
Filename=Newsflsh.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[MytekSystrayExePath]
Confirmed=U
Filename=MyTekSystray.exe
Description=<a href="http://www.mytek.com.au/" target="_blank">MyTek</a> system tray - web site providing computer tech support in Australia
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojremadmc.html" target=_blank>REMADM-C</a> TROJAN!
Source=Paul Collins Startup list
[MyVitalAgent]
Confirmed=U
Filename=VtlAgent.exe
Description=<a href="http://www.qip.lucent.com/qip/spectra/invoke.cfm?id=FBAD6307%2D6CCA%2D4CC3%2D851F5D42DB652AB2&Method=DisplayDetails" target="_blank">MyVitalAgent</a> from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs
Source=Paul Collins Startup list
[MyWebSearch Email Plugin]
Confirmed=X
Filename=mwsoemon.exe
Description="My Web Search" malware
Source=Paul Collins Startup list
[N2PTray]
Confirmed=U
Filename=Net2fone.exe
Description=An Internet telephony application. Needed only if you have an account at <a href="http://web.net2phone.com/" target="_blank">Net2Phone, Inc</a>
Source=Paul Collins Startup list
[NADaemon]
Confirmed=N
Filename=NADAEMON.EXE
Description=Program by <a href="http://www.netactive.com/" target="_blank">NetActive</a> which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required
Source=Paul Collins Startup list
[Naggerrunkey]
Confirmed=N
Filename=nagger.exe
Description=Packard Bell Free Internet Signup screen
Source=Paul Collins Startup list
[Naimagent_service]
Confirmed=Y
Filename=EPOAgentnaimas32.exe
Description=Networked version of McAfee VirusScan. Installs, configures and updates the software and DAT (virus definition) files on local computers from a network server. A resource hog but required for DAT updates and if disabled can also cause random freezes and error messages
Source=Paul Collins Startup list
[Naimagent_UI]
Confirmed=Y
Filename=EPOAgentnaimag32.exe
Description=Workstation background program for Network AssociatesÆ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
Source=Paul Collins Startup list
[Naimagent_UI]
Confirmed=Y
Filename=naimag32.exe
Description=Workstation background program for Network AssociatesÆ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
Source=Paul Collins Startup list
[Name]
Confirmed=X
Filename=Iexplorer0.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.threadsys.html" target="_blank">THREADSYS</a> TROJAN!
Source=Paul Collins Startup list
[Narrator]
Confirmed=X
Filename=******.exe [* = random char]
Description=Transponder/VX2 related adware
Source=Paul Collins Startup list
[Natal]
Confirmed=X
Filename=Natal.scr
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.opaserv.ae.worm.html" target="_blank">OPASERV.AE</a> WORM!
Source=Paul Collins Startup list
[NAV]
Confirmed=X
Filename=RuxDLL32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mapson.d.worm.html" target="_blank">MAPSON.D</a> WORM!
Source=Paul Collins Startup list
[NAV Agent]
Confirmed=Y
Filename=navapw32.exe
Description=Norton Anti-Virus's background scanning process
Source=Paul Collins Startup list
[nAv AGENT]
Confirmed=X
Filename=N/A
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w97m.riosys.html" target="_blank">RIOSYS</a> MACRO! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes
Source=Paul Collins Startup list
[NAV Agent]
Confirmed=X
Filename=systems.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.c.html" target="_blank">TARNO.C</a> TROJAN! Note - this is not the valid Norton Antivirus entry of the same name
Source=Paul Collins Startup list
[NAV Agent]
Confirmed=X
Filename=winsnav.vbs
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.anpes@mm.html" target=_blank>ANPES</a> WORM!
Source=Paul Collins Startup list
[NAV Auto Update]
Confirmed=X
Filename=Navautoupdate.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[NAV CfgWiz]
Confirmed=N
Filename=cfgwiz.exe
Description=Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
Source=Paul Collins Startup list
[NAV Configuration Wizard]
Confirmed=N
Filename=cfgwiz.exe
Description=Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
Source=Paul Collins Startup list
[NAV DefAlert]
Confirmed=U
Filename=DefAlert.exe
Description=Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
Source=Paul Collins Startup list
[NAV Live Update]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.hllw.deborms.c.html" target="_blank">DEBORMS.C</a> WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec
Source=Paul Collins Startup list
[NAV Scan Service]
Confirmed=X
Filename=NAVSCAN32.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.VG" target="_blank">SDBOT.VG</a> WORM!
Source=Paul Collins Startup list
[NavAgent32]
Confirmed=X
Filename=lasvr32.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.femot.d.worm.html" target="_blank">FEMOT.D</a> WORM!
Source=Paul Collins Startup list
[NavAgent32]
Confirmed=X
Filename=SCardSvr32.Exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MOFEI.B" target="_blank">MOFEI.B</a> WORM!
Description=Norton Anti-Virus's background scanning process
Source=Paul Collins Startup list
[Naviscope]
Confirmed=U
Filename=naviscope.exe
Description=<a href="http://naviscope.com/" target="_blank">Naviscope</a> is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more
Description=Hijacker, possibly a <a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> variant
Source=Paul Collins Startup list
[navp.exe]
Confirmed=X
Filename=navp.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotoe.html" target=_blank>AGOBOT-OE</a> WORM!
Source=Paul Collins Startup list
[NavPass]
Confirmed=X
Filename=NavPass.exe
Description=Free system for gaining access to and downloading from adult content web-sites
Source=Paul Collins Startup list
[NavScan]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.obsorb.html" target="_blank">OBSORB</a> TROJAN!
Source=Paul Collins Startup list
[NAVSCANNER32]
Confirmed=X
Filename=NAVSCANNER32.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.QC" target="_blank">RBOT.QC</a> WORM!
Source=Paul Collins Startup list
[NAVUpd]
Confirmed=X
Filename=rundll32.exe navupd.dll, Startup
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.navu.html" target="_blank">NAVU</a> TROJAN!
Source=Paul Collins Startup list
[NB Common Dialog Enhancements]
Confirmed=N
Filename=COMDLGEX.EXE
Description=Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs
Source=Paul Collins Startup list
[NB Start Menu]
Confirmed=N
Filename=STARTM.EXE
Description=Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B
Source=Paul Collins Startup list
[NB Windows Patterns]
Confirmed=N
Filename=WINDBKGND.EXE
Description=Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows
Source=Paul Collins Startup list
[NBJ]
Confirmed=U
Filename=NBJ.exe
Description=Ahead Nero <a href="http://www.nero.com/en/631898241464531.html" target="_blank"> BackItUp</a> backup program. Only required for if you have scheduled back-ups
Source=Paul Collins Startup list
[NbkCtrl]
Confirmed=U
Filename=NbkCtrl.exe
Description=Scheduling engine of <a href="http://www.no-panic.com/backup/n_backup.html" target="_blank"> NovaSTOR Backup</a> Service. Only required if scheduling is enabled and wanted - see <a href="http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[NBT System alias]
Confirmed=X
Filename=[path] repcale.exe [path] beird.exe
Description=Added by a variant of the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RANDON.AN" target=_blank>RANDON.AN</a> WORM!
Source=Paul Collins Startup list
[NCClient]
Confirmed=?
Filename=N/A
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[NCD]
Confirmed=N
Filename=ncd.exe
Description=Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path
Source=Paul Collins Startup list
[NCLAUNCH]
Confirmed=?
Filename=NCLAUNCH.Exe
Description=Part of <a href="http://www.northcode.com/products/swfstudio/index.html" target="_blank">SWF Studio</a> from Northcode Inc - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XP. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[NCS_SS]
Confirmed=N
Filename=Csinsm32.exe
Description=Same as CleanSweep Smart Sweep-Internet Sweep
Source=Paul Collins Startup list
[NDDEAGNT]
Confirmed=?
Filename=NDDEAGNT.EXE
Description=WinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE services
Source=Paul Collins Startup list
[NDIS Adapter]
Confirmed=X
Filename=ndis.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.VF&VSect=T" target="_blank">SDBOT.VF</a> WORM!
Source=Paul Collins Startup list
[NDIS Adapter]
Confirmed=X
Filename=windows.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbr.html" target=_blank>FORBOT-BR</a> WORM!
Source=Paul Collins Startup list
[NDIS Adapter]
Confirmed=X
Filename=lsass2.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[NDplDeamon]
Confirmed=X
Filename=nstask32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.e.html" target="_blank">RANDEX.E</a> WORM!
Source=Paul Collins Startup list
[NDplDeamon]
Confirmed=X
Filename=winlogin.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.e.html" target="_blank">RANDEX.E</a> WORM!
Source=Paul Collins Startup list
[NDPS]
Confirmed=U
Filename=DPMW32.EXE
Description=Novell Distributed Printer Services - part of Novell's <a href="http://www.novell.com/products/netware/" target="_blank">Netware</a> Client and <a href="http://www.novell.com/products/groupwise/" target="_blank"> Groupwise</a> products. Not required if you don't use this feature
Description=ConfigFreeT Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have
Source=Paul Collins Startup list
[Necbar]
Confirmed=N
Filename=Necbar.exe
Description=Nec Assistant; Ark's Navigator, a graphical interface for NEC computers
Source=Paul Collins Startup list
[NECMFK]
Confirmed=Y
Filename=necmfk.exe
Description=NEC wireless keyboard driver
Source=Paul Collins Startup list
[Necutray]
Confirmed=U
Filename=Necutray.exe
Description=Driver for external USB storage devices (hard drives, flsh disks, etc)
Source=Paul Collins Startup list
[neqprvfy.exe]
Confirmed=?
Filename=neqprvfy.exe
Description=<font color="#FF0000">Appears to be related to the downloading of some application - possibly verifying updates?</font>
Source=Paul Collins Startup list
[Nero.ma]
Confirmed=X
Filename=***.exe [*** = 2 to 3 digits]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.jonbarr.d@mm.html" target="_blank">JONBARR.D</a> WORM!
Source=Paul Collins Startup list
[NeroAutoStartClient]
Confirmed=X
Filename=NeroASM.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.VG&VSect=T" target=_blank>AGOBOT.VG</a> WORM!
Source=Paul Collins Startup list
[NeroCheck]
Confirmed=U
Filename=nerocheck.exe
Description=Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
Source=Paul Collins Startup list
[NeroCheck]
Confirmed=X
Filename=regedit.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.doomjuice.b.html" target="_blank">DOOMJUICE.B</a> WORM! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)
Source=Paul Collins Startup list
[NeroFilterCheck]
Confirmed=U
Filename=NeroCheck.exe
Description=Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
Source=Paul Collins Startup list
[NeroNETTrayIcon]
Confirmed=N
Filename=NNServiceCtrl.exe
Description=System tray access to <a href="http://www.nero.com/us/631898255953125.html" target="_blank">NeroNET</a> - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network
Source=Paul Collins Startup list
[Net]
Confirmed=X
Filename=WINREG.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.assasin.d.html" target="_blank">ASSASIN.D</a> TROJAN!
Source=Paul Collins Startup list
[Net Accelerator]
Confirmed=U
Filename=NetAccelerator.exe
Description=<a href="http://www.rizalsoftware.com/" target="_blank">Rizal</a> NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance
Source=Paul Collins Startup list
[Net Activity Diagram]
Confirmed=U
Filename=nad.exe
Description=<a href="http://www.metaproducts.com/mp/mpProducts_Detail.asp?id=20" target="_blank">Net Activity Diagram</a> from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs
Source=Paul Collins Startup list
[Net-It Launcher]
Confirmed=N
Filename=NILaunch.exe
Description=<a href="http://www.net-it.com/" target="_blank">Net-It</a> - web publishing software
Source=Paul Collins Startup list
[NetAccelerator]
Confirmed=U
Filename=NetAccel.exe
Description=<a href="http://www.netaccelerator.net/" target="_blank">NetAccelerator</a> is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance
Source=Paul Collins Startup list
[NetAdm7]
Confirmed=X
Filename=NETADM7.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.f.html" target="_blank">BANCOS.F</a> TROJAN!
Source=Paul Collins Startup list
[Netapi]
Confirmed=X
Filename=Netapi.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_NETDEVIL.14" target="_blank">NETDEVIL.14</a> TROJAN!
Source=Paul Collins Startup list
[NetApp]
Confirmed=X
Filename=winserv.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SHADOWTHIEF" target="_blank">SHADOWTHIEF</a> TROJAN!
Source=Paul Collins Startup list
[netconfig]
Confirmed=X
Filename=netconfig.exe
Description=Added by the <a href="http://www.pestpatrol.com/PestInfo/n/netware_trojan_v1_0.asp" target="_blank">NETCONF</a> TROJAN!
Source=Paul Collins Startup list
[NetCruiser Dialer]
Confirmed=U
Filename=NCDialer.exe
Description=<a href="http://www.netcruiser-software.com/products.html" target="_blank">NetCruiser Dialer</a> from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"
Source=Paul Collins Startup list
[netdaemon]
Confirmed=X
Filename=netdaemon /v
Description=Malware designed to "kill" a number of antispyware applications (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)
Source=Paul Collins Startup list
[netdll32]
Confirmed=X
Filename=netdll32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[netdllex]
Confirmed=X
Filename=netdllex.Exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[NetDy]
Confirmed=X
Filename=VisualGuard.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.n@mm.html" target="_blank">NETSKY.N</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.w@mm.html" target="_blank">NETSKY.W</a> WORMS!
Source=Paul Collins Startup list
[NETFP32.EXE]
Confirmed=X
Filename=NETFP32.EXE
Description=Added by the AGENT.CD TROJAN!
Source=Paul Collins Startup list
[netfxupdate]
Confirmed=?
Filename=netfxupdate.exe
Description=<font color="#FF0000">Would appear to be a valid Microsoft .NET file (see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;827801" target="_blank">here</a>) but <a href="http://www.techsupportforum.com/computer/topic/8189-1.html" target="_blank"> this</a> suggest's it's a trojan?</font>
Source=Paul Collins Startup list
[NetFxUpdate_v1.0.3705]
Confirmed=?
Filename=netfxupdate.exe
Description=<font color="#FF0000">Would appear to be a valid Microsoft .NET file (see <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;827801" target="_blank">here</a>) but <a href="http://www.techsupportforum.com/computer/topic/8189-1.html" target="_blank"> this</a> suggest's it's a trojan?</font>
Source=Paul Collins Startup list
[NetGuard]
Confirmed=U
Filename=NetGuard.exe
Description=FBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor
Source=Paul Collins Startup list
[Netlimiter]
Confirmed=U
Filename=Netlimiter.exe
Description=<a href="http://www.netlimiter.com/" target="_blank">Netlimiter</a> - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."
Source=Paul Collins Startup list
[Netline User]
Confirmed=N
Filename=netchk.exe
Description=Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example
Source=Paul Collins Startup list
[NetLink]
Confirmed=X
Filename=netlink32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.wo.html" target="_blank">GAOBOT.WO</a> WORM!
Source=Paul Collins Startup list
[NetLogon]
Confirmed=X
Filename=userint.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotbc.html" target=_blank>SDBOT-BC</a> WORM!
Source=Paul Collins Startup list
[NetManagerService]
Confirmed=X
Filename=ntss.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_BESTPICS.A" target="_blank">BESTPICS.A</a> TROJAN!
Source=Paul Collins Startup list
[NetMeter]
Confirmed=X
Filename=NetMeter.exe
Description=NetRatings software by <a href="http://www.opistat.com/mp/index.html" target=_blank>Opistat</a> . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
Source=Paul Collins Startup list
[NetMon]
Confirmed=X
Filename=netmon.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.m@mm.html" target="_blank">MIMAIL.M</a> WORM!
Source=Paul Collins Startup list
[netmsg]
Confirmed=U
Filename=netmsg.exe
Description=<a href="http://users.pandora.be/Grrrippp/" target=_blank>Net_Message</a> is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well
Description=Malware, probably <a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related
Source=Paul Collins Startup list
[NetPerSec]
Confirmed=N
Filename=NetPerSec.exe
Description=<a href="http://www.pcmag.com/article2/0,4149,1735,00.asp" target="_blank">NetPerSec</a> - measures the real-time speed of your Internet connection
Source=Paul Collins Startup list
[NetPumper]
Confirmed=N
Filename=NetPumperIEProxy.exe
Description=<a href="http://www.netpumper.com/" target=_blank>NetPumper</a> download manager - bundles Cydoor and SaveNow adware, see <a href="http://www.kephyr.com/spywarescanner/library/netpumper/index.phtml" target=_blank>here</a>
Source=Paul Collins Startup list
[NetReach]
Confirmed=X
Filename=nrcheck.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[Netropa Internet Receiver]
Confirmed=X
Filename=Netropa.exe
Description=Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
Source=Paul Collins Startup list
[NetRun]
Confirmed=U
Filename=NetRun.exe
Description=<a href="http://www.czarsoft.shorturl.com/" target="_blank">NetRun</a> - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost
Source=Paul Collins Startup list
[Netscape Messenger]
Confirmed=N
Filename=NETSCAPE.EXE
Description=In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed
Source=Paul Collins Startup list
[Netscp6]
Confirmed=N
Filename=Netscp6.exe
Description=Netscape 6
Source=Paul Collins Startup list
[netservices]
Confirmed=X
Filename=recall.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_SDBOT.GEN" target=_blank>SDBOT</a> WORM!
Source=Paul Collins Startup list
[NetShow Powerpoint Helper]
Confirmed=U
Filename=NSPPTHLP.EXE
Description=If disabled, user created fonts can no longer be seen by other programs
Source=Paul Collins Startup list
[NetStat Live]
Confirmed=N
Filename=Nsl.exe
Description=AnalogX <a href="http://www.analogx.com/contents/download/network/nsl.htm" target="_blank">NetStat Live</a> - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data
Source=Paul Collins Startup list
[netsv32]
Confirmed=X
Filename=netsv32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotpx.html" target="_blank">SDBOT-PX</a> WORM!
Source=Paul Collins Startup list
[NetTime]
Confirmed=U
Filename=NETTIME.EXE
Description=From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."
Source=Paul Collins Startup list
[NetTurbo]
Confirmed=U
Filename=netturbo.exe
Description=<a href="http://www.netturbo.com/" target="_blank">NetTurbo</a> from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled
Source=Paul Collins Startup list
[Netunit32]
Confirmed=X
Filename=wunit32.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[NetWatch32]
Confirmed=X
Filename=netwatch.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.c@mm.html" target="_blank">MIMAIL.C</a> WORM!
Source=Paul Collins Startup list
[Netword Agent]
Confirmed=N
Filename=nwant33.exe
Description=An interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs
Source=Paul Collins Startup list
[NetWork]
Confirmed=X
Filename=csrs.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_AGOBOT.JJ" target="_blank">AGOBOT.JJ</a> WORM!
Source=Paul Collins Startup list
[Network Administration]
Confirmed=X
Filename=NAS.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.antilam.20.q.html" target="_blank">ANTILAM.20.Q</a> TROJAN!
Source=Paul Collins Startup list
[Network Administration Service]
Confirmed=X
Filename=rsvc32.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.ABH" target=_blank>RBOT.ABH</a> WORM!
Source=Paul Collins Startup list
[Network Associates Error Reporting Service]
Confirmed=U
Filename=TBMon.exe
Description=Network Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
Source=Paul Collins Startup list
[NetWork Device Switch]
Confirmed=U
Filename=NetDevSW.exe
Description=Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
Source=Paul Collins Startup list
[Network Host Controller]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.whisper.html" target="_blank">WHISPER</a> TROJAN!
Source=Paul Collins Startup list
[Network Protocol Service]
Confirmed=X
Filename=wuamgrd.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=60289&VName=WORM_RBOT.EA&VSect=T" target="_blank">RBOT.EA</a> WORM!
Source=Paul Collins Startup list
[Network protocol service]
Confirmed=X
Filename=wintcp.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Network Security Guard]
Confirmed=X
Filename=**********.exe [* = random char]
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related
Source=Paul Collins Startup list
[Network Service]
Confirmed=X
Filename=svchost.exe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related. Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Network Service Manager]
Confirmed=X
Filename=netsvc.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target="_blank">AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Network Service Manager]
Confirmed=X
Filename=netsvc.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>GAOBOT/AGOBOT</a> WORM!
Source=Paul Collins Startup list
[NetworkAssociates Inc]
Confirmed=X
Filename=internet.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html" target="_blank">LOVGATE</a> WORM!
Source=Paul Collins Startup list
[NetworkClient]
Confirmed=X
Filename=NetworkClient.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lemur.html" target="_blank">LEMUR</a> WORM!
Source=Paul Collins Startup list
[Networks Configurator]
Confirmed=X
Filename=NetConfs.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotox.html" target=_blank>RBOT-OX</a> WORM!
Source=Paul Collins Startup list
[Networks Controler]
Confirmed=X
Filename=Netsis.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotng.html" target=_blank>RBOT-NG</a> WORM!
Source=Paul Collins Startup list
[NetworkSetup]
Confirmed=N
Filename=dlink.exe
Description=<a href="http://www.dlink.com/tech/faq/dlink-icon.htm" target="_blank">D-Link</a> System Tray icon
Source=Paul Collins Startup list
[Netzip Smart Downloader]
Confirmed=X
Filename=npnzdad.exe
Description=Advertising spyware
Source=Paul Collins Startup list
[NetZIPFolders]
Confirmed=N
Filename=nzfprop.exe
Description=<a href="http://www.netzip.com/products/info_netzip_win.html?src=site,netzip,plugin,nzc" target="_blank">Netzip Classic</a> zip file manager
Source=Paul Collins Startup list
[NeuroMedia(IESpeaker)]
Confirmed=X
Filename=NeuroMedia.exe
Description=Part of an older freeware version of <a href="http://www.iespeaker.com" target="_blank"> IESpeaker</a> - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available
Source=Paul Collins Startup list
[NeuroSpeech OESpeaker]
Confirmed=N
Filename=OEMonitor.exe
Description=Part of <a href="http://www.iespeaker.com" target="_blank"> OESpeaker</a> - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not
Description=<a href="http://www.f-secure.com/solutions/home.shtml" target="_blank">F-Secure</a> antivirus related. <font color="#FF0000" target="_blank">However, is this particular item required?</font>
Source=Paul Collins Startup list
[Newsalrt]
Confirmed=N
Filename=NEWSALRT.EXE
Description=MSNBC News system tray utility to alert you to new news
Source=Paul Collins Startup list
[Newsgroup lptt01]
Confirmed=X
Filename=newsgroup.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>
Source=Paul Collins Startup list
[Newsgroup ml097e]
Confirmed=X
Filename=newsgroup.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>
Source=Paul Collins Startup list
[NewsUpd]
Confirmed=N
Filename=newsupd.exe
Description=For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see <a href="http://cexx.org/newsupd.htm" target="_blank">here</a>.
Description=Appears in startup if you have chosen to participate in on survey by <a href="http://www.npdor.com/" target="_blank"> NPD Online Research</a>. Required for the survey to work correctly. Otherwise not required
Source=Paul Collins Startup list
[nForce Tray Options]
Confirmed=N
Filename=sstray.exe
Description=nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
Source=Paul Collins Startup list
[NGClient]
Confirmed=U
Filename=ngctw32.exe
Description=Symantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manually
Source=Paul Collins Startup list
[NGServer]
Confirmed=N
Filename=ngserver.exe
Description=Symantec/Norton Ghost Console service
Source=Paul Collins Startup list
[NiceDownloads]
Confirmed=X
Filename=rundll32.exe MSA64CHK.dll, DllMostrar
Description=<a href="http://www.doxdesk.com/parasite/MatrixDialer.html" target="_blank">MatrixDialer</a> related
Source=Paul Collins Startup list
[Nielsen NetRatings]
Confirmed=N
Filename=insight.exe
Description=<a href="http://www.nielsen-netratings.com/mktg.jsp?section=ps" target="_blank">Nielsen NetRatings</a> - "Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web siteÆs audience and your customers". <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[nikLaus]
Confirmed=X
Filename=nikLaus.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.niklas.html" target="_blank">NIKLAS</a> WORM!
Source=Paul Collins Startup list
[NInit]
Confirmed=N
Filename=NInit.exe
Description=Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
Source=Paul Collins Startup list
[nisserv]
Confirmed=Y
Filename=NISSERV.EXE
Description=Norton Personal Firewall
Source=Paul Collins Startup list
[Nisum]
Confirmed=Y
Filename=NISUM.EXE
Description=Norton Personal Firewall
Source=Paul Collins Startup list
[NJG40]
Confirmed=X
Filename=NJG40.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.d.html" target="_blank">BANCOS.D</a> TROJAN!
Source=Paul Collins Startup list
[NkvMon.exe]
Confirmed=N
Filename=NkvMon.exe
Description=Nikon View 5 - for transferring pictures from Nikon digital cameras
Source=Paul Collins Startup list
[NkVwMon.exe]
Confirmed=N
Filename=NkVwMon.exe
Description=Nikon View - for transferring pictures from Nikon digital cameras
Source=Paul Collins Startup list
[NLS Keyboard]
Confirmed=X
Filename=keyboard.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[NMSSvc]
Confirmed=?
Filename=NMSSVC.EXE
Description=NIC Management Service - diagnostics program for Intel Pro family network cards
Source=Paul Collins Startup list
[NMSVC]
Confirmed=Y
Filename=nmSvc.exe
Description=<a href="http://www.covenanteyes.com/about.php" target="_blank">Covenant Eyes</a> - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it
Source=Paul Collins Startup list
[NNSvc]
Confirmed=U
Filename=nnsvc.exe
Description=<a href="http://www.netnanny.com/products/netnanny5/index.html" target="_blank">NetNanny</a> internet filter
Source=Paul Collins Startup list
[No Credit Card]
Confirmed=X
Filename=plugin-[random].exe
Description=Adult content pop-up dialler
Source=Paul Collins Startup list
[No-IP DUC]
Confirmed=U
Filename=DUC20.exe
Description=Part of <a href="http://www.no-ip.com" target="_blank">http://www.no-ip.com</a> provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available
Source=Paul Collins Startup list
[NoAds]
Confirmed=U
Filename=NoAds.exe
Description=Blocks advertisement banners in Internet Explorer
Source=Paul Collins Startup list
[NoAdware]
Confirmed=N
Filename=NoAdware.exe
Description=Adware/spyware remover - not particularly recommended, see <a href="http://www.adwarereport.com/mt/archives/000023.html" target=_blank>here</a>
Source=Paul Collins Startup list
[Nocana]
Confirmed=X
Filename=[path to worm]
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32anaconb.html" target=_blank>ANACON-B</a> WORM!
Source=Paul Collins Startup list
[Nod32CC]
Confirmed=U
Filename=nod32cc.exe
Description=Control Center part of Eset's <a href="http://www.nod32.com/home/home.htm" target="_blank">NOD32</a> virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button
Source=Paul Collins Startup list
[NOD32kernel]
Confirmed=Y
Filename=Nod32krn.exe
Description=<a href="http://www.nod32.com/home/home.htm" target="_blank">Nod32</a> Antivirus Version 2
Source=Paul Collins Startup list
[nod32kui]
Confirmed=Y
Filename=nod32kui.exe
Description=<a href="http://www.nod32.com/home/home.htm" target="_blank">Nod32</a> Antivirus Version 2
Source=Paul Collins Startup list
[NOD32POP3]
Confirmed=Y
Filename=Pop3scan.exe
Description=POP3 E-mail part of Eset's <a href="http://www.nod32.com/home/home.htm" target="_blank">NOD32</a> virus-scanner
Source=Paul Collins Startup list
[NodeMnger]
Confirmed=?
Filename=Nodemngr.exe
Description=<font color="#FF0000">Part of the Dell OpenManage Client installation - to allow Dell representatives to remote logon?</font>
Source=Paul Collins Startup list
[nodriver]
Confirmed=X
Filename=AUEKXRZ.EXE
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Description=Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required
Source=Paul Collins Startup list
[Nokia Tray Application]
Confirmed=U
Filename=NclTray.exe
Description=Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
Source=Paul Collins Startup list
[NOMAD Detector]
Confirmed=U
Filename=ctmnrun.exe
Description=Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
Source=Paul Collins Startup list
[NomdCheck]
Confirmed=N
Filename=nomdchek.exe
Description=Part of Intel's Native Audio
Source=Paul Collins Startup list
[nomtray]
Confirmed=U
Filename=nomtray.exe
Description=System Tray access to NetMotion Wireless options - including connectivity status (see <a href="http://www.netmotionwireless.com/support/technotes/2140.asp" target=_blank>here</a>)
Source=Paul Collins Startup list
[Norman ZANDA]
Confirmed=U
Filename=ZLH.EXE
Description=System Tray icon for <a href="http://www.norman.com/" target="_blank">Norman Antivirus</a>
Source=Paul Collins Startup list
[Norton Antivirus AV]
Confirmed=X
Filename=FVProtect.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.p@mm.html" target="_blank">NETSKY.P</a> WORM! Note - this is not the popular AV software!
Source=Paul Collins Startup list
[Norton AntiVirus Sys]
Confirmed=X
Filename=NAVsys32.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.GEN" target=_blank>WOOTBOT</a> WORM!
Source=Paul Collins Startup list
[Norton Auto Protect]
Confirmed=X
Filename=nava.exe
Description=Added by an unidentified WORM or TROJAN!
Source=Paul Collins Startup list
[Norton Auto-Protect]
Confirmed=Y
Filename=navapw32.exe
Description=Norton Anti-Virus's background scanning process
Source=Paul Collins Startup list
[Norton AV Preload]
Confirmed=?
Filename=Premend.exe
Description=Norton Antivirus related. <font color="#FF0000"> What does it do and is it required</font>
Source=Paul Collins Startup list
[Norton Crashguard Monitor]
Confirmed=N
Filename=cgmenu.exe
Description=Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
Source=Paul Collins Startup list
[Norton Disk Doctor]
Confirmed=N
Filename=Ndd32.exe
Description=Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
Source=Paul Collins Startup list
[Norton eMail Protect]
Confirmed=Y
Filename=POPROXY.EXE
Description=Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it
Source=Paul Collins Startup list
[Norton Guard 32]
Confirmed=X
Filename=ntguard32.exe
Description=Added by a variant of the <a href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437" target=_blank>RBOT</a> WORM!
Source=Paul Collins Startup list
[Norton Live Update Server]
Confirmed=X
Filename=cpsdv.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.EW" target="_blank">AGOBOT.EW</a> TROJAN!
Source=Paul Collins Startup list
[Norton Live Updater]
Confirmed=X
Filename=Cavapsvc.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Norton Live Updater]
Confirmed=X
Filename=Sochost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ao.html" target="_blank">GAOBOT.AO</a> WORM!
Source=Paul Collins Startup list
[Norton Navigator Loader]
Confirmed=N
Filename=nnloader.exe
Description=An older Norton utility for file management under Windows 95. More information <a href="http://www.mg.co.za/mg/pc/history/dec10-nortnavigator.html" target="_blank">here</a>
Source=Paul Collins Startup list
[Norton Program Scheduler]
Confirmed=U
Filename=nsched32.exe
Description=Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
Source=Paul Collins Startup list
[Norton Program Scheduler]
Confirmed=U
Filename=NPSsvc.exe
Description=Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
Source=Paul Collins Startup list
[Norton Program Scheduler Event Checker]
Confirmed=?
Filename=npscheck.exe
Description=<font color="#FF0000">Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker</font>
Source=Paul Collins Startup list
[Norton Service Process]
Confirmed=X
Filename=navapvc.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Norton SpySweeper AutoUpdate]
Confirmed=X
Filename=navsw.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotas.html" target="_blank">FORBOT-AS</a> WORM!
Source=Paul Collins Startup list
[Norton System Doctor]
Confirmed=N
Filename=Sysdoc32.exe
Description=Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
Source=Paul Collins Startup list
[Norton SystemWorks]
Confirmed=N
Filename=cfgwiz.exe
Description=Norton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it
Source=Paul Collins Startup list
[Norton Update]
Confirmed=X
Filename=ccUpdate.exe
Description=Added by a variant of the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.GEN" target=_blank>AGOBOT/GAOBOT</a> WORM!
Source=Paul Collins Startup list
[Norton Updater]
Confirmed=X
Filename=winset.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target=_blank>SPYBOT</a> WORM!
Source=Paul Collins Startup list
[Norton Wizzard]
Confirmed=X
Filename=nwiz.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.zx.html" target="_blank">GAOBOT.ZX</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.adv.html" target="_blank">GAOBOT.ADV</a> WORMS! Note - this is not the valid nVidia application that shares the same name
Source=Paul Collins Startup list
[norton32]
Confirmed=X
Filename=norton32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[NortonAV]
Confirmed=X
Filename=norton_antivirus.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.netjoe.html" target=_blank>NETJOE</a> TROJAN! Note - this is not the legitimate Symantec AV program
Source=Paul Collins Startup list
[nortonsantivirus]
Confirmed=X
Filename=ccEvtMngr.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojhzdoora.html" target=_blank>HZDOOR-A</a> TROJAN!
Source=Paul Collins Startup list
[Notebook Maximizer]
Confirmed=U
Filename=maximizer_startup.exe
Description=Toshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency
Source=Paul Collins Startup list
[NotebookManager]
Confirmed=?
Filename=nbm.exe
Description=<font color="#FF0000">Associated with Acer notebook PCs. What does it do and is it required?</font>
Source=Paul Collins Startup list
[Notepad lptt01]
Confirmed=X
Filename=notepad.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not Windows Notepad which has the same executable name
Source=Paul Collins Startup list
[Notepad ml097e]
Confirmed=X
Filename=notepad.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank"> here</a>. Note - this is not Windows Notepad which has the same executable name
Source=Paul Collins Startup list
[notepad.exe]
Confirmed=X
Filename=upx.exe
Description=Added by a variant of the AGENT.AH TROJAN!
Description=Scheduling engine of <a href="http://www.no-panic.com/backup/n_backup.html" target="_blank">NovaSTOR Backup</a> Service. Only required if scheduling is enabled and wanted - see <a href="http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html" target="_blank">here</a>. * represents the version number
Source=Paul Collins Startup list
[NovaPortal Single User Service]
Confirmed=?
Filename=NPSU.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[NovastorSchedulerd]
Confirmed=U
Filename=SCHENGD.EXE
Description=NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
Source=Paul Collins Startup list
[NPFMonitor]
Confirmed=?
Filename=NPFMntor.exe
Description=Norton AntiVirus Firewall Install Monitor. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[NPROTECT]
Confirmed=U
Filename=nprotect.exe
Description=Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see <a href="http://service1.symantec.com/SUPPORT/nunt.nsf/e35d98be79cddc2785256951004d59cd/b6cb75a0d23fd6fb8825662f00734a64?OpenDocument&src=bar_sc" target="_blank"> here</a>
Source=Paul Collins Startup list
[NPS Event Checker]
Confirmed=?
Filename=npscheck.exe
Description=<font color="#FF0000">Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as </font>Norton Program Scheduler Event Checker
Source=Paul Collins Startup list
[NS]
Confirmed=X
Filename=ns.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agoboths.html" target=_blank>AGOBOT-HS</a> WORM!
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[nse]
Confirmed=X
Filename=nse.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotml.html" target=_blank>AGOBOT-ML</a> WORM!
Source=Paul Collins Startup list
[Nsengine]
Confirmed=U
Filename=Nsengine.exe
Description=Scheduling engine of <a href="http://www.no-panic.com/backup/n_backup.html" target="_blank"> NovaSTOR Backup</a> Service. Only required if scheduling is enabled and wanted - see <a href="http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html" target="_blank"> here</a>
Source=Paul Collins Startup list
[NSHelper]
Confirmed=U
Filename=aexnsinstallhelper.exe
Description=Altiris Express Notification Server Install helper - monitors integrity of the installation
Source=Paul Collins Startup list
[nssysconf]
Confirmed=X
Filename=[random filename]
Description=Added by the <a href="http://de.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=59209&VName=TROJ_VIVIA.A&VSect=T" target="_blank">VIVIA.A</a> TROJAN!
Source=Paul Collins Startup list
[nstat]
Confirmed=X
Filename=netstat.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[NSupdate]
Confirmed=X
Filename=NSupdate.exe
Description=Adult content dialer
Source=Paul Collins Startup list
[Nsvdr]
Confirmed=X
Filename=nsvdr.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[NSystemMonitor]
Confirmed=N
Filename=Symmon.exe
Description=Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.b.html" target="_blank">DONK.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.c.html" target="_blank">DONK.C</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.l.html" target="_blank">DONK.L</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.m.html" target="_blank">DONK.M</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.donk.o.html" target="_blank">DONK.O</a> WORMS!
Source=Paul Collins Startup list
[NT Services]
Confirmed=X
Filename=ntsvc.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_AGOBOT.VJ" target="_blank">AGOBOT.VJ</a> WORM!
Source=Paul Collins Startup list
[ntdll]
Confirmed=X
Filename=ntdll.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.bionet.404.html" target="_blank">BIONET.404</a> TROJAN!
Source=Paul Collins Startup list
[NTDLM]
Confirmed=X
Filename=csrss.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hale.html" target="_blank">HALE</a> TROJAN! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/" target="_blank">csrss.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[Ntech.patchs]
Confirmed=X
Filename=[trojan filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.lemir.g.html" target="_blank">LEMIR.G</a> TROJAN!
Source=Paul Collins Startup list
[NTFS16]
Confirmed=X
Filename=ntfs16.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotly.html" target="_blank">RBOT-LY</a> WORM!
Source=Paul Collins Startup list
[NTFSCLUP]
Confirmed=Y
Filename=NTFSCLUP.EXE
Description=Part of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"
Source=Paul Collins Startup list
[ntldr]
Confirmed=X
Filename=ntldr.exe
Description=Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: C:\WINDOWS\SYSTEM\ntldr.exe, C:\m.exe, C:\WINDOWS\Search-For-You.url, C:\n.bat, C:\q.exe, C:\r.bat
Source=Paul Collins Startup list
[ntlfreedom]
Confirmed=N
Filename=RyDial.dll, QuickStart
Description=NTL Freedom ISP software - reportedly not required
Source=Paul Collins Startup list
[NTP Server]
Confirmed=X
Filename=[path to trojan]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.f.html" target="_blank">RANKY.F</a> TROJAN!
Source=Paul Collins Startup list
[NTrtc]
Confirmed=N
Filename=ntrtc.exe
Description=Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see <a href="http://www.euro.dell.com/countries/ae/enu/bsd/topics/y2k_rtctest.htm" target="_blank">here</a>
Source=Paul Collins Startup list
[NTsocket]
Confirmed=X
Filename=NoeWinnt.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/trojatakae.html" target="_blank">ATAKA-E</a> TROJAN!
Source=Paul Collins Startup list
[NTsrv.exe]
Confirmed=X
Filename=NTsrv.exe
Description=Added by a variant of the <a href="http://www.sophos.com/virusinfo/analyses/trojservuo.html" target=_blank>SERVU-O</a> TROJAN!
Source=Paul Collins Startup list
[ntupdate]
Confirmed=X
Filename=dnsvc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbottc.html" target=_blank>SDBOT-TC</a> WORM!
Source=Paul Collins Startup list
[NTVDM]
Confirmed=U
Filename=NTVDM.EXE
Description=Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;Q264320" target="_blank">here</a>
Source=Paul Collins Startup list
[ntvdscm]
Confirmed=X
Filename=ntvdscm.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=66002&VName=TROJ_SCKEYLOG.O&VSect=O" target="_blank">SCKEYLOG.O</a> TROJAN!
Source=Paul Collins Startup list
[NuTCSetupEnviron]
Confirmed=Y
Filename=ncoeenv.exe
Description=Used by the <a href="http://www.mkssoftware.com/products/tk/ds_tkedev.asp" target="_blank">MKS Toolkit for Enterprise Developers</a> product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone
Source=Paul Collins Startup list
[NvClipRsv]
Confirmed=X
Filename=svchost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32dumaruak.html" target=_blank>DUMARU-AK</a> WORM! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target=_blank>svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[NvClipRsv]
Confirmed=X
Filename=swchost.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32dumaruak.html" target=_blank>DUMARU-AK</a> WORM!
Source=Paul Collins Startup list
[NVCLOCK]
Confirmed=?
Filename=rundll32 nvclock.dll, fnNvclock
Description=<font color="#FF0000">Overclocking utility for nVidia based graphics cards?</font>
Source=Paul Collins Startup list
[NvColorInit]
Confirmed=?
Filename=rundll32.exe NvQtwk.dll, NvColorInit
Description=<font color="#FF0000">Associated with Nvidia based graphics cards</font>
Source=Paul Collins Startup list
[NvCpl]
Confirmed=U
Filename=rundll32.exe NvCpl.dll, NvStartup
Description=Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
Source=Paul Collins Startup list
[NvCpl]
Confirmed=X
Filename=NvCpl.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.yanz.b@mm.html" target=_blank>YANZ.B</a> WORM!
Source=Paul Collins Startup list
[NvCpl]
Confirmed=U
Filename=NvCpl.EXE
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.yanz.b@mm.html" target=_blank>YANZ.B</a> WORM!
Description=System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see <a href="http://www.blackviper.com/WinXP/strangeservice.htm" target="_blank">here</a>)
Source=Paul Collins Startup list
[NvCplDaemon]
Confirmed=U
Filename=rundll32.exe NvCpl.dll, NvStartup
Description=Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
Source=Paul Collins Startup list
[NvCplDmn]
Confirmed=X
Filename=NAVSVC.EXE
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[NvCplScan]
Confirmed=X
Filename=nvsc32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.bot.html" target=_blank>IRC.BOT</a> TROJAN!
Source=Paul Collins Startup list
[NvCplScan]
Confirmed=X
Filename=msc32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotdd.html" target=_blank>FORBOT-DD</a> WORM!
Source=Paul Collins Startup list
[nvd32 lptt01]
Confirmed=X
Filename=nvd32.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>
Source=Paul Collins Startup list
[nvd32 ml097e]
Confirmed=X
Filename=nvd32.exe
Description=Variant of the <a href="http://www.doxdesk.com/parasite/RapidBlaster.html" target="_blank"> RapidBlaster</a> parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see <a href="http://www.wilderssecurity.net/specialinfo/rapidblaster.html" target="_blank">here</a>
Source=Paul Collins Startup list
[Nvid]
Confirmed=X
Filename=[8 random charachters]
Description=Unidentified adware
Source=Paul Collins Startup list
[Nvid32]
Confirmed=X
Filename=Nvid32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Nvidex32]
Confirmed=X
Filename=Nvidex32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Nvidia Control Panel]
Confirmed=X
Filename=ncsvc32.exe
Description=Added by an unidentified VIRUS, WORM or TROJAN!
Source=Paul Collins Startup list
[NVIDIA Driver]
Confirmed=X
Filename=MSPMSPSU.EXE
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WOOTBOT.Y" target="_blank">WOOTBOT.Y</a> WORM!
Source=Paul Collins Startup list
[NVIDIA nForce APU1 Utilities]
Confirmed=N
Filename=NVATray.exe
Description=nVidia's nForce Audio Processing Unit (<a href="http://www.nvidia.com/object/apu.html" target="_blank">APU</a>)- "provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time"
Source=Paul Collins Startup list
[NVIDIA Video drivers]
Confirmed=X
Filename=video_32D.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.KV" target="_blank">AGOBOT.KV</a> WORM!
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NVIEW]
Confirmed=U
Filename=rundll32.exe nview.dll, nViewLoadHook
Description=This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers
Source=Paul Collins Startup list
[NvInitialize]
Confirmed=N
Filename=rundll32.exe NvQtwk.dll, NvXTInit
Description=Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled
Source=Paul Collins Startup list
[NVmax]
Confirmed=Y
Filename=NVmax.exe
Description=NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NvMediaCenter]
Confirmed=U
Filename=RunDLL32.exe NvMCTray.dll, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NVMixerTray]
Confirmed=N
Filename=NVMixerTray.exe
Description=System Tray access to audio controls from nVidia's motherboard ForceWare software
Source=Paul Collins Startup list
[NVQuickTweak]
Confirmed=N
Filename=rundll32.exe NvQtwk.dll, NvTaskbarInit
Description=System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Source=Paul Collins Startup list
[NVRT]
Confirmed=N
Filename=nvrt.exe
Description=NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
Source=Paul Collins Startup list
[NVRTClk]
Confirmed=?
Filename=NVRTClk.exe
Description=Related to a Gigabyte video card. <font color="#FF0000">What does it do, and is it required?</font>
Source=Paul Collins Startup list
[nvsv32.exe]
Confirmed=X
Filename=nvsv32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotdi.html" target=_blank>FORBOT-DI</a> WORM!
Source=Paul Collins Startup list
[NvSvc]
Confirmed=N
Filename=nvsvc.exe
Description=NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that
Source=Paul Collins Startup list
[NVSystem32]
Confirmed=X
Filename=nvscv32.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32agobotno.html" target=_blank>AGOBOT-NO</a> WORM!
Source=Paul Collins Startup list
[NvXplDeamon]
Confirmed=X
Filename=xstyles.exe
Description=Added by the SMALL.AJ VIRUS!
Source=Paul Collins Startup list
[NWEReboot]
Confirmed=?
Filename=dummy.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[nwiz]
Confirmed=N
Filename=nwiz.exe
Description=Associated with the newer versions of nVidia graphics cards drivers. Allows you to immensely improve desktop layouts by setting preferences and optimizations. However, this isn't necessary for the operation of your system
Source=Paul Collins Startup list
[Nwpopup]
Confirmed=Y
Filename=Nwpopup.exe
Description=Broadcast message handler part of <a href="http://www.novell.com/products/netware/" target=_blank>Novell Netware</a> that displays server, printer and other messages
Source=Paul Collins Startup list
[nwrecmsg]
Confirmed=U
Filename=nwrecmsg.exe
Description=Broadcast message handler part of <a href="http://www.novell.com/products/netware/" target=_blank>Novell Netware</a> that displays server, printer and other messages - can cause crashes
Source=Paul Collins Startup list
[NWTRAY]
Confirmed=Y
Filename=nwtray.exe
Description=<a href="http://www.novell.com/products/netware/" target="_blank">Novell Netware</a>. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the client
Source=Paul Collins Startup list
[oadaemon]
Confirmed=?
Filename=oadaemon.exe
Description=Background process that establishes connection with a C3-1000 scanner and watch general status of the device and for scanner button presses. <font color="#FF0000">Can it be started manually?</font>
Source=Paul Collins Startup list
[oahstifr]
Confirmed=Y
Filename=oahstifr.exe
Description=Comes with <a href="http://www.hypertextstudio.com" target="_blank">HyperTextStudio</a>. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."
Source=Paul Collins Startup list
[OAKSTART]
Confirmed=U
Filename=OAKSTART.EXE
Description=Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
Source=Paul Collins Startup list
[OAKTASK]
Confirmed=N
Filename=OAKTASK.EXE
Description=Taskbar utility for a "control panel" for a CD-RW
Source=Paul Collins Startup list
[Object Store Server]
Confirmed=Y
Filename=osserver.exe
Description=Comes with <a href="http://www.hypertextstudio.com" target="_blank">HyperTextStudio</a>. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."
Source=Paul Collins Startup list
[objtjprx]
Confirmed=?
Filename=objtjprx.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[obsver]
Confirmed=?
Filename=obsver.exe
Description=Part of <a href="http://www.lingoware.com/english/" target=_blank>LingoWare</a> translating software - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[OCAudioIni]
Confirmed=N
Filename=OCAudioIni.exe
Description=<a href="http://www.streamware-dev.com/products.html" target="_blank">One-click Audio Converter</a> - allows you to convert files of multiple audio formats right from Windows Explorer
Source=Paul Collins Startup list
[ocraware]
Confirmed=N
Filename=ocraware.exe
Description=<u>O</u>ptical <u>C</u>haracter <u>R</u>ecognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. Available via Start -> Programs
Source=Paul Collins Startup list
[ocx32]
Confirmed=X
Filename=ocx32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.astef.html" target="_blank">ASTEF</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.repsan.html" target="_blank">RESPAN</a> WORMS!
Source=Paul Collins Startup list
[OD]
Confirmed=X
Filename=SYSCNTR.EXE
Description=HotVideo dialler
Source=Paul Collins Startup list
[od-matrxx]
Confirmed=X
Filename=od-matrxx.exe
Description=Adult dialler - xx can be any number
Source=Paul Collins Startup list
[od-stndxx]
Confirmed=X
Filename=od-stndxx.exe
Description=Adult dialler - xx can be any number
Source=Paul Collins Startup list
[od-teenxx]
Confirmed=X
Filename=od-teenxx.exe
Description=Adult dialler - xx can be any number
Source=Paul Collins Startup list
[ODBC BackUp]
Confirmed=U
Filename=fdxxl.exe
Description=G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see <a href="http://www.chip.de/artikel/c_artikel_8806643.html" target=_blank>here</a>. Disable/remove if you didn't install it yourself!
Source=Paul Collins Startup list
[Odometer]
Confirmed=N
Filename=Odometer.EXE
Description=Mouse odometer - tracks how far your pointer/arrow has traveled on the screen. Shortcut available
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.QB&VSect=T" target="_blank">RBOT.QB</a> WORM!
Source=Paul Collins Startup list
[OEM32 Tools]
Confirmed=X
Filename=sres32.exe
Description=Added by a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html" target="_blank">SPYBOT</a> WORM!
Source=Paul Collins Startup list
[OEMCLEANUP]
Confirmed=N
Filename=oemreset.exe
Description=Resets OEM installation settings at bootup. Not required unless you're new to PC's
Source=Paul Collins Startup list
[OEMRESET]
Confirmed=U
Filename=oemreset.exe
Description=Resets OEM installation settings at bootup. Not required unless you're new to PC's
Source=Paul Collins Startup list
[OEPowerPlugs]
Confirmed=?
Filename=winoeinit.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[OEXCheck]
Confirmed=N
Filename=EA2Check.exe
Description=<a href="http://www.ajsystems.com/oexhome.html" target="_blank">Express Assist</a> from AJSystems.com. Utility for use with Outlook Express to backup, restore, synchronize amongst others
Source=Paul Collins Startup list
[Offer Companion]
Confirmed=X
Filename=offers.exe
Description=Adware
Source=Paul Collins Startup list
[Offers]
Confirmed=X
Filename=offers.exe
Description=Adware
Source=Paul Collins Startup list
[Office Startup]
Confirmed=N
Filename=Osa.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Source=Paul Collins Startup list
[Office Startup]
Confirmed=X
Filename=Exploer.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bv.html" target="_blank">GAOBOT.BV</a> WORM! Note the different filename to the valid MS Office entries
Source=Paul Collins Startup list
[Office Startup]
Confirmed=N
Filename=Osa9.exe
Description=Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show
Description=Autodetects when a digital camera is attached to a USB port and launches <a href="http://www.ofoto.com/DownloadClient30.jsp?UV=673857175481_20140377403&US=0&c=f_on">OfotoNow</a> image software. Available via Start -> Programs
Description=From CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs
Source=Paul Collins Startup list
[OIM]
Confirmed=?
Filename=oim.exe
Description=<font color="#FF0000">Related to the <a href="http://www.o2.co.uk/about/0,,600,00.html" target="_blank">O2</a> (was "genie") mobile phone service. What does it do and is it required?</font>
Source=Paul Collins Startup list
[OLE]
Confirmed=X
Filename=[filename]
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/keylogger.stawin.html" target="_blank">STAWIN</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.d.html" target="_blank">TARNO.D</a> TROJANS!
Source=Paul Collins Startup list
[OLE Automation Server]
Confirmed=X
Filename=ole32aut.vbe
Description=<a href="http://www.spywareinfo.com/~merijn/cwschronicles.html" target="_blank">CoolWebSearch</a> parasite related
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.bookmarker.d.html" target="_blank">BOOKMARKER.D</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.bookmarker.g.html" target="_blank">BOOKMARKER.G</a> TROJANS!
Source=Paul Collins Startup list
[Olive System]
Confirmed=X
Filename=Szchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.mercurycas.a.html" target="_blank">MERCURYCAS.A</a> TROJAN!
Source=Paul Collins Startup list
[Omf4]
Confirmed=X
Filename=OMF4.EXE
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.freemega.html" target="_blank">FREEMEGA</a> TROJAN!
Source=Paul Collins Startup list
[OmgStartup]
Confirmed=N
Filename=omgstartup.exe
Description=Sony program called OpenMG Jukebox - player and music organizer
Source=Paul Collins Startup list
[OmniHTTPd]
Confirmed=U
Filename=ohttpd.exe
Description=<a href="http://www.omnicron.ca/httpd/" target="_blank">OmniHTTPd</a> web server from Omnicron
Source=Paul Collins Startup list
[OmniPage]
Confirmed=N
Filename=Opware32.exe
Description=Part of <a href="http://www.scansoft.com/omnipage/">OmniPage Pro</a> from Scansoft (was Caere) - "the fastest, easiest way to turn paper documents into digital files you can edit." Opware32.exe links Word, via OLE, with OmniPage. If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs
Description=By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don't adjust things regularly - can also freeze
Source=Paul Collins Startup list
[One Touch Monitor]
Confirmed=N
Filename=OneTouchMonitor.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[One Touch Monitor]
Confirmed=N
Filename=1tou~2.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[One Touch Monitor]
Confirmed=N
Filename=ONETOU~2.EXE
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouch Monitor]
Confirmed=N
Filename=OneTouchMon.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouchMonitor]
Confirmed=N
Filename=OneTouchMonitor.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouchMonitor]
Confirmed=N
Filename=1tou~2.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[OneTouchMonitor]
Confirmed=N
Filename=ONETOU~2.EXE
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[ONETOU~2]
Confirmed=N
Filename=OneTouchMonitor.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[ONETOU~2]
Confirmed=N
Filename=1tou~2.exe
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[ONETOU~2]
Confirmed=N
Filename=ONETOU~2.EXE
Description=For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
Source=Paul Collins Startup list
[Onflow]
Confirmed=X
Filename=onflow.exe
Description=Onflow is a internet company that offers an online advertising program. Not required - uninstall
Source=Paul Collins Startup list
[online cdrom]
Confirmed=?
Filename=Active acid.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Online Service]
Confirmed=X
Filename=svchost.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hostidel.trojan.b.html" target="_blank">HOSTIDEL.B</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hostidel.trojan.c.html" target="_blank">HOSTIDEL.C</a> or <a href="http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.tarno.b.html" target="_blank">TARNO.B</a> TROJANS! Note - this is not the legitimate <a href="http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/" target="_blank">svchost.exe</a> process which should NOT appear in Msconfig/Startup!
Source=Paul Collins Startup list
[OnlinePCfix SmoothSurfer]
Confirmed=U
Filename=SS.exe
Description=<a href="http://www.smooth-surfer.com/" target="_blank">Smooth-Surfer</a> - blocks banners, ads, popups, and cleans MRU and Recent file lists
Source=Paul Collins Startup list
[OnlineTime]
Confirmed=N
Filename=onlinetime.exe
Description=<a target="_blank" href="http://www.freedownloadscenter.com/Network_and_Internet/Online_Timers/OnlineTimer_Pro.html">OnlineTimer</a> - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs
Description=Displays <a href="http://www.openoffice.org/" target="_blank">OpenOffice</a> quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). "x" represents the version number
Source=Paul Collins Startup list
[Openwares LiveUpdate]
Confirmed=U
Filename=LiveUpdate.exe
Description=Web-update utility as used by various types of software - see <a href="http://liveupdate.openwares.org/" target="_blank">here</a>
Source=Paul Collins Startup list
[Operator]
Confirmed=N
Filename=??
Description=Media Pilot operator, in Win.ini. Locks port open
Source=Paul Collins Startup list
[Operator]
Confirmed=U
Filename=xtmop.exe
Description=Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported
Source=Paul Collins Startup list
[OpiStat]
Confirmed=N
Filename=OPISTAT.EXE
Description=<a href="http://www.opistat.com/mp/index.html" target="_blank">OpiStat</a> is a European Research Institute whose goal is to understand consumer needs and opinions better
Source=Paul Collins Startup list
[OPQFile]
Confirmed=X
Filename=regedit.exe /s ...rad03FA6.tmp
Description=Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
Source=Paul Collins Startup list
[OPTIMIZER]
Confirmed=X
Filename=iexplore.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.evivinc.html" target="_blank">EVIVINC</a> TROJAN! Note - this is not the legitimate Internet Explorer (<a href="http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore/" target="_blank">iexplore.exe</a>) process, which should not appear in Msconfig/Startup unless you add it manually!
Source=Paul Collins Startup list
[Optimum Online]
Confirmed=N
Filename=Netsurf.exe
Description=<a href="http://www.optimumonline.com/index.jhtml;jsessionid=5LMI3XSXKRAYYCQLARQCF3QKBMCGCI5G?pageType=what" target="_blank">Optimum Online</a> ISP software. Not required, just window dressing & advertising from Optimum
Source=Paul Collins Startup list
[Optus Cable Data Monitor]
Confirmed=U
Filename=datamonitor.exe
Description=Allows Optus customers to monitor their actual data usage against Optus' "data allowance limits"
Source=Paul Collins Startup list
[OptusNetUsage]
Confirmed=U
Filename=OptusNet Usage Meter.exe
Description=Designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit, and how far over your suggested limit you should be
Source=Paul Collins Startup list
[Opware12]
Confirmed=N
Filename=Opware12.exe
Description=<a href="http://www.scansoft.com/omnipage/" target="_blank">OmniPage Pro 12</a> from ScanSoft
Description=Lotus Organizer 5 application file, Lotus Organizer software. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[OrgyCam]
Confirmed=X
Filename=OrgyCam.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[OrigRage128Tweaker]
Confirmed=U
Filename=RAGE128TWEAK.EXE
Description=Third party tweaker for ATI Rage 128 Video cards from <a href="http://www.rageunderground.com">http://www.rageunderground.com</a>
Source=Paul Collins Startup list
[ORiNOCO]
Confirmed=U
Filename=Cmluc.exe
Description=Client Manager software for an <a href="http://www.orinocowireless.com/" target="_blank">ORiNOCO</a> wireless LAN card
Source=Paul Collins Startup list
[Osa32]
Confirmed=X
Filename=NTOSA32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.anig.html" target="_blank">ANIG</a> WORM!
Source=Paul Collins Startup list
[OSD]
Confirmed=U
Filename=OSD.exe
Description=By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don't adjust things regularly - can also freeze
Description=<a href="http://www.somix.com/products/ostivity.php" target="_blank">OStivity</a> - "a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network, a complete inventory (software and hardware) is taken of the system"
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/backdoor.carool.html" target="_blank">CAROOL</a> TROJAN!
Source=Paul Collins Startup list
[outlook]
Confirmed=X
Filename=outlook.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32sdbotru.html" target=_blank>SDBOT-RU</a> WORM!
Source=Paul Collins Startup list
[Outpost Firewall]
Confirmed=Y
Filename=outpost.exe
Description=<a href="http://www.agnitum.com/products/outpost/" target="_blank">Outpost</a> personal firewall
Source=Paul Collins Startup list
[Outwar]
Confirmed=X
Filename=syslaunch.exe
Description=Outwar adware downloader
Source=Paul Collins Startup list
[OVCJ]
Confirmed=?
Filename=ovcj.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[Overnet]
Confirmed=N
Filename=Overnet.exe
Description=<a href="http://www.overnet.com/" target="_blank">Overnet</a> peer-to-peer (P2P) file sharing program
Source=Paul Collins Startup list
[OWCCardbusTray]
Confirmed=U
Filename=ocbtray.exe
Description=Icon in the system tray for safely removing PCMCIA cards. Only required if you have a laptop or desktop which includes a PCMCIA card interface
Source=Paul Collins Startup list
[OWCWebCamDV]
Confirmed=U
Filename=wcdvtray.exe
Description=<a href="http://www.orangemicro.com/webcamdv.html" target="_blank">WebCamDV</a> from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam
Source=Paul Collins Startup list
[OWMngr]
Confirmed=X
Filename=OWMngr.exe
Description=OnWebMedia advertising foistware - see <a href="http://www.f-secure.com/v-descs/checkin.shtml" target="_blank"> here</a> for exactly what to look for
Source=Paul Collins Startup list
[oz2]
Confirmed=X
Filename=oz2.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.w@mm.html" target="_blank">MYDOOM.W</a> WORM!
Source=Paul Collins Startup list
[P17Helper]
Confirmed=?
Filename=Rundll32 P17.dll, P17Helper
Description=<a href="http://www.soundblaster.com/resources/read.asp?articleid=60&cat=2" target=_blank>ASIO</a> driver for the Sound Blaster Audigy & Audigy 2 series sound card - <font color="#FF0000">is it required in startup?</font>
Source=Paul Collins Startup list
[P2P NETWORKING]
Confirmed=N
Filename=P2P Networking.exe
Description=Peer to Peer (P2P) sharing of files on the internet
Source=Paul Collins Startup list
[P2P Networking3]
Confirmed=N
Filename=P2P Networking3.exe
Description=P2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required - see <a href="http://www.kephyr.com/spywarescanner/library/p2pnetworking/index.phtml" target="_blank">here</a>
Source=Paul Collins Startup list
[P3p4chk]
Confirmed=X
Filename=P3p4chk.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[p4mx4]
Confirmed=X
Filename=p4mx4.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[Packard Bell EverSafe Tray Control]
Confirmed=?
Filename=TrayControl.exe
Description=Packard Bell EverSafe software. <font color="#FF0000">What does it do, and is it required?</font>
Source=Paul Collins Startup list
[PadTouch]
Confirmed=N
Filename=PadExe.exe
Description=Toshiba Touch and Launch - offers easy movement and freedom of programs navigation with TouchPad
Source=Paul Collins Startup list
[Pagekeeper Jobs]
Confirmed=U
Filename=pkjobs.exe
Description=PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc
Source=Paul Collins Startup list
[Pagekeeper Lite]
Confirmed=U
Filename=pkjobs.exe
Description=PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc
Source=Paul Collins Startup list
[PAgent]
Confirmed=X
Filename=PAgent.exe
Description=Scans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local filesystem for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is found. See <a href="http://and.doxdesk.com/parasite/DownloadWare.html" target="_blank">here</a> for more info
Source=Paul Collins Startup list
[Pagis Scheduler]
Confirmed=N
Filename=Monitor.exe
Description=Scheduler for the <a href="http://www.scansoft.com/pagis/" target="_blank">Pagis</a> scanning suite from Scansoft.
Source=Paul Collins Startup list
[pagmstart]
Confirmed=?
Filename=client.exe
Description=<font color="#FF0000">Possibly related to <a href="http://www.pagm.com/default.asp" target="_blank">this</a>?</font>
Source=Paul Collins Startup list
[Pagoo]
Confirmed=N
Filename=PAGOO.EXE
Description=<a href="http://www.pagoo.com/cc.asp" target="_blank">Pagoo</a> - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
Source=Paul Collins Startup list
[Palm MultiUser Config]
Confirmed=?
Filename=Configtool.exe
Description=<font color="#FF0000">MultiUser configuration for a Palm PDA device?. Is it required?</font>
Source=Paul Collins Startup list
[Palm.exe]
Confirmed=N
Filename=Palm.exe
Description=<a href="http://www.palm.com/support/downloads/win_desktop.html" target="_blank">Palm Desktop Software</a> for use with Palm handheld devices. Available via Start -> Programs
Source=Paul Collins Startup list
[PalNetaware]
Confirmed=X
Filename=pnetaware.exe
Description=PalTalk adware - as included in Morpheus, see <a href="http://www.pestpatrol.com/pestinfo/m/morpheus.asp" target="_blank">here</a> towards the bottom of the page
Source=Paul Collins Startup list
[PaltalkNetaware.exe]
Confirmed=N
Filename=PALNETAW~1.EXE
Description=Voice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start -> Programs. Delete the shortcut in Start -> Programs -> StartUp as well otherwise it will be reinstated
Source=Paul Collins Startup list
[Panda Scheduler]
Confirmed=U
Filename=pavsched.exe
Description=<a href="http://www.pandasoftware.com/" target="_blank">Panda Antivirus</a> scan scheduler. Required if this is your virus scanner program and you have scans scheduled on a regular basis. I recommend that you scan manually so you don't need this but if you tend to forget then leave it
Source=Paul Collins Startup list
[PandaAVEngine]
Confirmed=X
Filename=PandaAVEngine.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.r@mm.html" target="_blank">NETSKY.R</a> WORM!
Source=Paul Collins Startup list
[Paperport]
Confirmed=N
Filename=runppdrv.exe
Description=Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see <a href="http://groups.google.com/groups?q=runppdrv.exe&hl=en&rnum=7&selm=6v04nv%24q3l%241%40supernews.com" target="_blank">here</a>
Source=Paul Collins Startup list
[PaperPort PTD]
Confirmed=N
Filename=pptd40nt.exe
Description="PaperPort" software associated with scanners
Source=Paul Collins Startup list
[PaperQuote System Tray Icon]
Confirmed=N
Filename=PQTRAY.EXE
Description=PaperQuote is a "wallpaper" changer with daily quotes that are either for inspiration or motivation
Source=Paul Collins Startup list
[Parallel Tasking]
Confirmed=X
Filename=ptask.exe
Description=Added by unidentified adware - recognized by <a href="http://www.kaspersky.com/personalpro" target=_blank>Kaspersky</a> antivirus as Trojan-Downloader.Win32.Small.adg
Source=Paul Collins Startup list
[PartSeal]
Confirmed=U
Filename=PartSeal.exe
Description=System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
Description=<a href="http://www.progency.com/pastelister.html" target="_blank">PasteLister</a> - clipboard extender. Start manually when required
Source=Paul Collins Startup list
[Patch]
Confirmed=X
Filename=patch.exe
Description=Added by the <a href="http://www.dark-e.com/archive/trojans/netbusworm/index.shtml" target="_blank"> NETBUS</a> WORM!
Source=Paul Collins Startup list
[Patches Value]
Confirmed=X
Filename=WinGamed.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.BR" target="_blank">SDBOT.BR</a> WORM!
Source=Paul Collins Startup list
[Path]
Confirmed=?
Filename=lide.exe
Description=<font color="#FF0000">??</font>
Source=Paul Collins Startup list
[PAV.EXE]
Confirmed=X
Filename=%Number%
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.d.worm.html" target="_blank"> KITRO.D</a> (or <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_ARGEN.A&VSect=T" target="_blank">ARGEN.A</a>) WORM! %Number% can be any number
Description=MSI PC Alert III - allows you to view your system and cpu temperature, fan rpm and more. Only required if you overclock
Source=Paul Collins Startup list
[PC Booster]
Confirmed=U
Filename=pcbooster.exe
Description=<a href="http://www.inklineglobal.net/products/pcb/index.html" target="_blank">PC Booster</a> from inKline Global - "easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition"
Source=Paul Collins Startup list
[PC-Config32]
Confirmed=X
Filename=corona.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32coronexa.html" target="_blank">CORONEX.A</a> WORM!
Source=Paul Collins Startup list
[PCBG]
Confirmed=Y
Filename=PCBODYGUARD.EXE
Description=<a href="http://www.calluna.com/pcbody.html" target="_blank">PC Bodyguard</a> from Calluna - protects system files and settings from being deleted, modified, etc
Source=Paul Collins Startup list
[PCBODYGUARD]
Confirmed=Y
Filename=PCBODYGUARD.EXE
Description=<a href="http://www.calluna.com/pcbody.html" target="_blank">PC Bodyguard</a> from Calluna - protects system files and settings from being deleted, modified, etc
Source=Paul Collins Startup list
[PCCClient.exe]
Confirmed=Y
Filename=PCCClient.exe
Description=PC-Cillin 2002 antivirus software
Source=Paul Collins Startup list
[pccguide.exe]
Confirmed=Y
Filename=pccguide.exe
Description=PC-Cillin 2002 antivirus software
Source=Paul Collins Startup list
[PCCIOMON.EXE]
Confirmed=Y
Filename=PCCIOMON.EXE
Description=PC-Cillin 2000 antivirus software. This is the actual virus-scanner
Source=Paul Collins Startup list
[PCClient.exe]
Confirmed=Y
Filename=PCClient.exe
Description=Trend Micro <a href="http://www.trendmicro.com/en/products/desktop/pc-cillin/evaluate/overview.htm" target="_blank">PC-Cillin</a> Internet Security
Source=Paul Collins Startup list
[PccPfw]
Confirmed=Y
Filename=PccPfw.exe
Description=PC Cillin 2003 personal firewall
Source=Paul Collins Startup list
[PcCtlCom]
Confirmed=Y
Filename=Pcctlcom.exe
Description=Trend Micro <a href="http://www.trendmicro.com/en/products/desktop/pc-cillin/evaluate/overview.htm" target=_blank>PC-cillin</a> Internet Security
Source=Paul Collins Startup list
[PCDRealtime]
Confirmed=N
Filename=realtime.exe
Description=Apparently the monitoring device for PC Doctor Online. It provides a "free" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to "order" the fee-based fixes from its web site
Source=Paul Collins Startup list
[PcEXPLODE]
Confirmed=X
Filename=specialfile.exe
Description=Added by the <a href="http://it.trendmicro-europe.com/consumer/security_info/ve_detail.php?Vname=WORM_RBOT.RH" target="_blank">RBOT.RH</a> WORM!
Source=Paul Collins Startup list
[PCHbutton]
Confirmed=N
Filename=PCHbutton.exe
Description=Used by HP Instant Support
Source=Paul Collins Startup list
[PCHealth]
Confirmed=N
Filename=pchschd.exe
Description=This is a "scheduler" and does not turn off PC Health. For more information refer <a href="http://groups.google.com/groups?q=PCHealth%2Bpchschd.exe&hl=en&selm=eeuEENQ6AHA.1484%40tkmsftngp03&rnum=1" target="_blank">here</a>
Source=Paul Collins Startup list
[PCHEasySearch]
Confirmed=X
Filename=STUpdate.exe
Description=PCH EasySearch bar
Source=Paul Collins Startup list
[PCIMODEM]
Confirmed=?
Filename=pcimodem.exe
Description=Associated with Lucent based Aztech MDP7800-U PCI modems. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[PCLEPCI]
Confirmed=U
Filename=ppe.exe
Description=Pinnacle Systems <a href="http://www.pinnaclesys.com/docsupport1.asp?division_id=1&langue_id=2&product_id=469&product_name=Studio%20version%207&page_id=146" target="_blank">PCI Performance Enhancer</a>. "This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards."
Source=Paul Collins Startup list
[PCMService]
Confirmed=?
Filename=PCMService.exe
Description=<font color="#FF0000">In a DellMedia Experience sub-directory</font>
Source=Paul Collins Startup list
[PCRecSA]
Confirmed=U
Filename=PCRecSA.exe
Description=Part of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a "clean" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need to
Source=Paul Collins Startup list
[PCShield]
Confirmed=X
Filename=regsvr32 /s [path] sfg_****.dll [* = random char]
Description=Runs as part of <a href="http://pcmonitor.com/" target="_blank">PCMonitor</a> which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big
Source=Paul Collins Startup list
[PCSuiteTrayApplication]
Confirmed=N
Filename=TrayApplication.exe
Description=System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu
Source=Paul Collins Startup list
[Pcsv]
Confirmed=N
Filename=pcsvc.exe
Description=<a href="http://www.spywareguide.com/product_show.php?id=727" target=_blank>Delfin Media Viewer</a> or "Promulgate" adware
Source=Paul Collins Startup list
[PcSync]
Confirmed=N
Filename=PcSync.exe
Description=If a Nokia phone has been connected, synchronises the phone with MS Outlook or other organiser software. It is installed by the Nokia PC Suite, and the tray icon shows if a phone has been connected. Available via a desktop shortcut or Start -> Programs
Source=Paul Collins Startup list
[pctspk]
Confirmed=U
Filename=pctspk.exe
Description=Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
Source=Paul Collins Startup list
[PCTVOICE]
Confirmed=U
Filename=pctvoice.exe
Description=The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. ItÆs better to leave it
Source=Paul Collins Startup list
[PDEngine]
Confirmed=U
Filename=PDEngine.exe
Description=<a href="http://www.raxco.com/products/perfectdisk2k/" target="_blank">PerfectDisk</a> from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot
Source=Paul Collins Startup list
[pdexplo]
Confirmed=N
Filename=PDEXPLO.EXE
Description=<a href="http://www.ontrack.com/powerdesk/">PowerDesk Pro</a> by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs
Source=Paul Collins Startup list
[PDF Converter Registry Controller]
Confirmed=?
Filename=RegistryController.exe
Description=ScanSoft <a href="http://www.scansoft.com/pdfconverter/" target=_blank>PDF_Converter</a> related - <font color="#FF0000">what does it do and is it required?</font>
Source=Paul Collins Startup list
[pdfFactory Pro Dispatcher v1]
Confirmed=N
Filename=fppdis1.exe
Description="With <a href="http://www.fineprint.com/software/index.html" target="_blank">pdfFactory</a> you can create PDF documents from any program printing to the virtual PDF printer". Available via a desktop shortcut or Start -> Programs
Source=Paul Collins Startup list
[pdfSaver3]
Confirmed=N
Filename=pdfSaver3.exe
Description=<a href="http://www.docu-track.com/home/prod_user/pdfxchange_pro/" target=_blank>PDF-XChange</a> - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher etc
Source=Paul Collins Startup list
[PDirect]
Confirmed=N
Filename=PDirect.exe
Description=IBM Presentation Director software
Source=Paul Collins Startup list
[pdp Server]
Confirmed=U
Filename=ctpdpsrvr.exe
Description=Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
Source=Paul Collins Startup list
[PDVDServ]
Confirmed=U
Filename=PDVDServ.exe
Description=Remote Control background application for CyberLink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Source=Paul Collins Startup list
[Pe2ckfnt SE]
Confirmed=N
Filename=chkfont.exe
Description=Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu
Source=Paul Collins Startup list
[Peeramid]
Confirmed=?
Filename=PService.exe
Description=In a "Koptimizer" folder in Program Files. <font color="#FF0000">What does it do and is it required?</font>
Source=Paul Collins Startup list
[PeerGuardian]
Confirmed=N
Filename=PeerGuardian_1.99b_pr14.exe
Description=<a href="http://www.afterdawn.com/software/p2p_software/p2p_tools/peerguardian.cfm" target=_blank>PeerGuardian</a> "is a tiny firewall program especially designed for P2P software users, but also for anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections"
Source=Paul Collins Startup list
[Pent@VALUE 3.2]
Confirmed=U
Filename=Pent@VALUE.exe
Description=Pent@VALUE Digital Satellite Internet PC Receiver
Source=Paul Collins Startup list
[PeqBL100]
Confirmed=X
Filename=PEQBL100.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.envid.d@mm.html" target=_blank>ENVID.D</a> WORM!
Description=Print engine used by Corel WordPerfect 7 and Presentations 7
Source=Paul Collins Startup list
[PersFw]
Confirmed=Y
Filename=PersFw.exe
Description=<a href="http://www.kerio.com/us/kpf_home.html" target="_blank">Kerio</a> or <a href="http://www.tinysoftware.com/home/tiny2?la=EN" target="_blank">Tiny</a> Personal Firewall
Source=Paul Collins Startup list
[Personal Firwall]
Confirmed=X
Filename=ptmedsrv.exe
Description=Added by the <a href="http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_SDBOT.XY" target=_blank>SDBOT.XY</a> WORM!
Source=Paul Collins Startup list
[Pervasive.SQL Workgroup Engine]
Confirmed=U
Filename=W3dbsmgr.exe
Description=Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
Source=Paul Collins Startup list
[PestPatrol Control Center]
Confirmed=U
Filename=PPControl.exe
Description=<a href="http://www.pestpatrol.com/PPControl/" target="_blank">PestPatrol Control Terminal</a> - launches <a href="http://www.pestpatrol.com/default.asp" target="_blank">PestPatrol</a> features such as PPMemCheck and CookiePatrol
Source=Paul Collins Startup list
[PestPatrolCL]
Confirmed=?
Filename=PestPatrolCL.exe
Description=Associated with <a href="http://www.pestpatrol.com/" target="_blank">PestPatrol</a> anti-malware software. <font color="#FF0000">What does this part do and is it required?</font>
Description=PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionality
Source=Paul Collins Startup list
[PGPSERVICE]
Confirmed=U
Filename=pgpservice.exe
Description=PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a "fall-back" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big difference
Source=Paul Collins Startup list
[PGPtray]
Confirmed=N
Filename=pgptray.exe
Description=PGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start -> Programs
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[PHIME2002ASync]
Confirmed=N
Filename=TINTSETP.EXE
Description=Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
Source=Paul Collins Startup list
[PhoneFree version 6.2]
Confirmed=U
Filename=PHONEF??.EXE
Description=An Internet telephony application. Complicated registration and ad banners tailored to your profile - see <a href="http://www.phonefree.com/" target="_blank">here</a>
Source=Paul Collins Startup list
[Photo Express Calendar Checker SE]
Confirmed=N
Filename=CALCHECK.EXE
Description=If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly
Source=Paul Collins Startup list
[Photo Loader supervisory]
Confirmed=N
Filename=Plauto.exe
Description=Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your pictures
Source=Paul Collins Startup list
[PhotoWise QuickLink]
Confirmed=N
Filename=quicklnk.exe
Description=Agfa PhotoWise - "PhotoWise QuickLinkTM lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more."
Source=Paul Collins Startup list
[Picasa Media Detector]
Confirmed=N
Filename=PicasaMediaDetector.exe
Description=Media detector for <a href="http://www.picasa.net/" target="_blank">Picasa</a>'s automatic photo organizer
Source=Paul Collins Startup list
[PicasaNet]
Confirmed=N
Filename=Hello.exe
Description=<a href="http://www.hello.com/index.php" target=_blank>Hello</a> is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs, or blogs
Source=Paul Collins Startup list
[Pickatag]
Confirmed=N
Filename=pickatag.exe
Description=<a href="http://home.wanadoo.nl/jeroen/software.html" target="_blank">Pick-a-tag</a> - "Freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages"
Source=Paul Collins Startup list
[PICPRTR]
Confirmed=N
Filename=PICPRTR.EXE
Description=Program for viewing and measuring a variety of 3D CAD data formats
Source=Paul Collins Startup list
[pictureBUZZTray]
Confirmed=N
Filename=swtray.exe
Description=System Tray access to <a href="http://www.picturebuzz.com" target="_blank">PictureBUZZ</a> on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually
Source=Paul Collins Startup list
[PiDunHK]
Confirmed=U
Filename=PIDUNHK.EXE
Description=Part of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happens
Source=Paul Collins Startup list
[piiserviceOE]
Confirmed=U
Filename=N/A
Description=<a href="http://www.giantcompany.com/piOe.aspx" target="_blank">Spam Inspector</a> (nee Postal Inspector) from The Giant Company or <a href="http://www.sunbelt-software.com/product.cfm?id=930" target="_blank">iHateSpam</a> from Sunbelt Software - spam filter add-ons for OE
Source=Paul Collins Startup list
[pilif]
Confirmed=X
Filename=pilif.exe
Description=Added by the <a href="http://www.symantec.com/avcenter/venc/data/w32.fili@mm.html" target="_blank">FILI</a> WORM!
Source=Paul Collins Startup list
[Pinger]
Confirmed=N
Filename=pinger.exe
Description=Pinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification
Source=Paul Collins Startup list
[PinnacleDriverCheck]
Confirmed=Y
Filename=PSDrvCheck.exe
Description=Part of <a href="http://www.pinnaclesys.com/" target="_blank">Pinnacle Systems</a> InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled
Description=Software Piracy Alert feature bundled with <a href="http://www.pgware.com/products/gamegain/" target=_blank>PGWare</a> software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: "The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users"
Source=Paul Collins Startup list
[PivotSoftware]
Confirmed=N
Filename=wpctrl.exe
Description=PivotPro from <a href="http://www.portrait.com/" target="_blank"> Portrait Studios</a> - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
Source=Paul Collins Startup list
[Pixel32]
Confirmed=X
Filename=Pixel32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Pixelpwr32]
Confirmed=X
Filename=Pixelpwr32.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[Pixelsvr]
Confirmed=X
Filename=Pixelsvr.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.gema.html" target="_blank">GEMA</a> TROJAN!
Source=Paul Collins Startup list
[pjWebCam]
Confirmed=U
Filename=pjWebCam.exe
Description=Webcam automation software that saves regular photos from webcam and can also act as HTTP server
Source=Paul Collins Startup list
[PK Services]
Confirmed=X
Filename=pksvc.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32forbotbw.html" target=_blank>FORBOT-BW</a> WORM!
Source=Paul Collins Startup list
[PktAnything]
Confirmed=U
Filename=PocketCompanion.exe
Description=<a href="http://www.o2pocket.com/pocketanythinginfo" target=_blank>PocketAnything</a> lets you save anything on your computer to your mobile, with one click
Source=Paul Collins Startup list
[PLEAPCPUCPL]
Confirmed=U
Filename=pleapu.exe
Description=<a href="http://www.powerleap.com/Products/ccp.htm" target="_blank">CPU Control Panel</a> for the Powerleap CPU upgrade
Source=Paul Collins Startup list
[PLFFAP]
Confirmed=?
Filename=HotfixQ0306270.exe
Description=Prolific Technology Inc. USB Flash Disk driver - <font color="#FF0000">is it required in startup?</font>
Source=Paul Collins Startup list
[Plguni]
Confirmed=N
Filename=Plguni.exe
Description=<a href="http://www.mcafee.com/myapps/qc3/default.asp" target="_blank">McAfee QuickClean 3.0</a> - removes internet clutter and unwanted programs
Source=Paul Collins Startup list
[plmg.exe]
Confirmed=U
Filename=plmg.exe
Description=Paragon Last Minute Bidder - auction assistant software
Source=Paul Collins Startup list
[PLoader]
Confirmed=?
Filename=umsd.exe
Description=USB Mass Storage Disk related tray icon. <font color="#FF0000">Is it required?</font>
Source=Paul Collins Startup list
[Plob]
Confirmed=X
Filename=kernel.com
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_OPTIXPRO.12" target="_blank">OPTIXPRO.12</a> TROJAN!
Source=Paul Collins Startup list
[Pluck Tray]
Confirmed=U
Filename=PluckTray.exe
Description=RSS (XML TAGS) reader program
Source=Paul Collins Startup list
[Plug And Play]
Confirmed=X
Filename=msnmsg.exe
Description=Added by the <a href="http://www.sophos.com/virusinfo/analyses/w32rbotid.html" target=_blank>RBOT-ID</a> WORM!
Source=Paul Collins Startup list
[PLXSTART]
Confirmed=U
Filename=PLXSTART.EXE
Description=Sets the spindown timeout and access speeds at startup and displays the "Plextor Manager 2000" splash screen for Plextor CD-RW.
Source=Paul Collins Startup list
[PLXTASK]
Confirmed=N
Filename=PLXTASK.EXE
Description=Taskbar utility for a "control panel" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files)
Source=Paul Collins Startup list
[pm32ctrl]
Confirmed=X
Filename=pwr32crtl.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[pm32info]
Confirmed=X
Filename=pm32info.exe
Description=Added by the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_CRYPTER.A" target="_blank">CRYPTER.A</a> TROJAN!
Source=Paul Collins Startup list
[pmc]
Confirmed=X
Filename=764.exe
Description=Adult content dialler
Source=Paul Collins Startup list
[PMedia]
Confirmed=X
Filename=winsrvc.exe
Description=Internet marketing sofware from <a href="http://www.pmedia.co.uk/" target="_blank">PMedia</a> as used in E-Card FriendGreetings foistware - see <a href="http://vil.nai.com/vil/content/v_99760.htm" target="_blank">here</a>. Treated by Trend as the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_FRIENDGRT.B" target="_blank"> FRIENDGRT.B</a> WORM!
Source=Paul Collins Startup list
[PmProxy]
Confirmed=?
Filename=PmProxy.exe
Description=Associated with Analog Devices "SoundMAX" audio chipset - often built-in to motherboards. <font color="#FF0000">What does it do and is it required?</font>
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.doep.a.html" target="_blank">DOEP.A</a> WORM!
Source=Paul Collins Startup list
[Pofatch]
Confirmed=X
Filename=nstrue.exe
Description=Added by the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.randexz.html" target="_blank">RANDEX.Z</a> WORM!
Source=Paul Collins Startup list
[point32]
Confirmed=U
Filename=point32.exe
Description=<a href="http://www.microsoft.com/intellipoint/" target="_blank">Microsoft Intellipoint</a> software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Source=Paul Collins Startup list
[POINTER]
Confirmed=U
Filename=point32.exe
Description=<a href="http://www.microsoft.com/intellipoint/" target="_blank">Microsoft Intellipoint</a> software for their Intellimouse series of mice - required if you use non-standard Windows driver features