<?xml version="1.0" encoding="Windows-1252"?>

<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="StartupList">
<title>StartupList</title>
<link>http://www.castlecops.com/StartupList.html</link>
<description>CastleCops - Paul Collins StartupList</description>
<dc:language>en-us</dc:language>
<dc:creator>Paul Laudanski (mailto:paul@computercops.biz)</dc:creator>
<dc:rights>Copyright &#169; 2002-2006 CastleCops&amp;reg;</dc:rights>
<dc:date>2008-09-07T07:13:15-05:00</dc:date>
<sy:updatePeriod>daily</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2003-01-01T12:00-05:00</sy:updateBase>
<admin:generatorAgent rdf:resource="http://www.castlecops.com/" />

<item>
<name></name>
<status>X</status>
<command>MSPF.EXE</command>
<description>Added by a variant of the http://vil.nai.com/vil/content/v_100454.htm SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
</description>
<infourl>http://www.castlecops.com/startuplist-15264.html</infourl>
</item>
<item>
<name></name>
<status>X</status>
<command>svchost.exe</command>
<description>Added by the http://www.sophos.com/virusinfo/analyses/trojdelfux.html DELF-UX TROJAN! Note - this is not the legitimate http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/ svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
</description>
<infourl>http://www.castlecops.com/startuplist-15265.html</infourl>
</item>
<item>
<name></name>
<status>X</status>
<command>mstdmc.exe</command>
<description>Added by Trojan-Downloader.Win32.Banload.cil, http://www.bleepingcomputer.com/startups/mstdmc.exe-19557.html MALWARE! [red]Note:[/red] Located in \%WINDIR%\System32\ [red]The startup name is empty[/red] This will make sure that it's start at startup.</description>
<infourl>http://www.castlecops.com/startuplist-15649.html</infourl>
</item>
<item>
<name></name>
<status>X</status>
<command>msmapiax32.exe</command>
<description>Identified as a variant of the Rootkit.Win32.Agent.uj, http://www.bleepingcomputer.com/startups/msmapiax32.exe-21900.html rootkit. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision. </description>
<infourl>http://www.castlecops.com/startuplist-16339.html</infourl>
</item>
<item>
<name></name>
<status>X</status>
<command>msmapibx32.exe</command>
<description>Identified as a variant of the Rootkit.Win32.Agent.uj, http://www.bleepingcomputer.com/startups/msmapiax32.exe-21900.html rootkit. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-16340.html</infourl>
</item>
<item>
<name></name>
<status></status>
<command></command>
<description>Added by the W32/Sdbot-DHY,http://www.sophos.com/security/analyses/viruses-and-spyware/w32sdbotdhy.html Worm! [red]Read the link, allows remote access[/red] [red]Note:[/red] located in \%WINDIR%\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17011.html</infourl>
</item>
<item>
<name> hamachi</name>
<status>U</status>
<command>hamachi.exe</command>
<description>Related to hamachi, https://secure.logmein.com/ Instantly connect multiple computers in a VPN from LogMeIn Inc. [red]Note:[/red] Located in \%Program Files%\Hamachi\</description>
<infourl>http://www.castlecops.com/startuplist-15594.html</infourl>
</item>
<item>
<name> Security Patch</name>
<status>X</status>
<command>scmss.exe</command>
<description>Added by the W32/RBOT-ZW, http://www.sophos.com/virusinfo/analyses/w32rbotzw.html WORM! [red]Read the link, keylogger/password stealing trojan(s) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-7614.html</infourl>
</item>
<item>
<name> WinCheck</name>
<status>X</status>
<command>services.exe</command>
<description>Added by the W32.Sober.V, http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.v@mm.html
 WORM!
 [red] Note:[/red] This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder.</description>
<infourl>http://www.castlecops.com/startuplist-12044.html</infourl>
</item>
<item>
<name> Windows</name>
<status>X</status>
<command>services.exe</command>
<description>Added by the W32.Sober.X, http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.x@mm.html
 WORM!
 [red] Note:[/red] This is not the legitimate Windows process services.exe (Which is always found in the System32 folder.)  This worm file is found in the Windows\WinSecurity or Winnt\WinSecurity folder.
</description>
<infourl>http://www.castlecops.com/startuplist-12164.html</infourl>
</item>
<item>
<name>!1_pgaccount</name>
<status>Y</status>
<command>pgaccount.exe</command>
<description>DiamondCS ProcessGuard, http://www.diamondcs.com.au/processguard/ security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system,  and this is essential for PG to work properly</description>
<infourl>http://www.castlecops.com/startuplist-6352.html</infourl>
</item>
<item>
<name>!1_ProcessGuard_Startup</name>
<status>Y</status>
<command>procguard.exe</command>
<description>DiamondCS ProcessGuard, http://www.diamondcs.com.au/processguard/ security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks.</description>
<infourl>http://www.castlecops.com/startuplist-6353.html</infourl>
</item>
<item>
<name>!AVG Anti-Spyware</name>
<status>U</status>
<command>avgas.exe</command>
<description>Related to AVG_Anti-Spyware, http://www.grisoft.com/doc/1 from Grisoft. [red]Note:[/red] Located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\</description>
<infourl>http://www.castlecops.com/startuplist-13378.html</infourl>
</item>
<item>
<name>!ewido</name>
<status>U</status>
<command>ewido.exe</command>
<description>Part of http://www.ewido.net/en/ Ewido anti-spyware
</description>
<infourl>http://www.castlecops.com/startuplist-12965.html</infourl>
</item>
<item>
<name>!NoLoad</name>
<status>U</status>
<command>winrecon.exe</command>
<description>Winrecon, http://www.symantec.com/avcenter/venc/data/spyware.winrecon.html. [red]Read the link, keylogger/password stealing trojan(s) involved.[/red] - Commercial Keylogger</description>
<infourl>http://www.castlecops.com/startuplist-1.html</infourl>
</item>
<item>
<name>$EnterNet</name>
<status>U</status>
<command>Enternet.exe</command>
<description>Connection manager for the EnterNet ISP. You can also use &lt;a href=&quot;http://user.cs.tu-berlin.de/~normanb/&quot; target=&quot;_blank&quot;&gt;RASPPOE&lt;/a&gt;</description>
<infourl>http://www.castlecops.com/startuplist-2.html</infourl>
</item>
<item>
<name>$sys$cmp</name>
<status>X</status>
<command>$sys$xp.exe</command>
<description>Added by the Backdoor.Ryknos.B, http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ryknos.b.html
 TROJAN!  Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
 [red]Read the link, rootkit type stealth involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-12041.html</infourl>
</item>
<item>
<name>$sys$crash</name>
<status>X</status>
<command>$sys$WeLoveMcCOL.exe</command>
<description>Added by the Welomoch, http://securityresponse.symantec.com/avcenter/venc/data/trojan.welomoch.html
 TROJAN!
 [red] Note:[/red] This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
 [red]Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY![/red]</description>
<infourl>http://www.castlecops.com/startuplist-12331.html</infourl>
</item>
<item>
<name>$sys$crash</name>
<status>X</status>
<command>$sys$sonyTimer.exe</command>
<description>Added by the Welomoch, http://securityresponse.symantec.com/avcenter/venc/data/trojan.welomoch.html
 TROJAN!
 [red] Note:[/red] This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
 [red]Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY![/red]</description>
<infourl>http://www.castlecops.com/startuplist-12332.html</infourl>
</item>
<item>
<name>$sys$crash</name>
<status>X</status>
<command>$sys$sos$sys$.exe</command>
<description>Added by the Welomoch, http://securityresponse.symantec.com/avcenter/venc/data/trojan.welomoch.html
 TROJAN!
 [red] Note:[/red] This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
 [red]Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY![/red]</description>
<infourl>http://www.castlecops.com/startuplist-12333.html</infourl>
</item>
<item>
<name>$sys$drv</name>
<status>X</status>
<command>$sys$drv.exe</command>
<description>Added by the Backdoor.Ryknos, http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ryknos.html
 TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
 [red]Read the link, rootkit type stealth involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-12040.html</infourl>
</item>
<item>
<name>$Volumouse$</name>
<status>U</status>
<command>volumouse.exe</command>
<description>Related to Volumouse, http://www.nirsoft.net/utils/volumouse.html from Nirsoft. Provides you a quick and easy way to control the sound volume on your system. [red]Note:[/red] Located in C:\Program Files\Volumouse\</description>
<infourl>http://www.castlecops.com/startuplist-13161.html</infourl>
</item>
<item>
<name>$WindowsRegKey%update</name>
<status>X</status>
<command>IEXPLORE.EXE</command>
<description>Added as result of a W32/Rbot-EZ, http://www.sophos.com/virusinfo/analyses/w32rbotez.html WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/iexplore  process, it should not appear in Msconfig/Startup unless you add it manually!</description>
<infourl>http://www.castlecops.com/startuplist-5336.html</infourl>
</item>
<item>
<name>%cmpmixtitle%</name>
<status>?</status>
<command>%cmpmixstr%</command>
<description>&lt;font color=&quot;#FF0000&quot;&gt;Possibly related to C-Media Mixer Control panel?&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-3.html</infourl>
</item>
<item>
<name>%FP%012-L2TP fts.exe</name>
<status>?</status>
<command>fts.exe</command>
<description>012.Net ISP software - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-6262.html</infourl>
</item>
<item>
<name>%FP%012-L2TP FWPortal.exe</name>
<status>?</status>
<command>FWPortal.exe</command>
<description>012.Net ISP software - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-6263.html</infourl>
</item>
<item>
<name>%FP%1776 Internet fts.exe</name>
<status>?</status>
<command>fts.exe</command>
<description>1776 Internet ISP software - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-6265.html</infourl>
</item>
<item>
<name>%FP%1776 Internet FWPortal.exe</name>
<status>?</status>
<command>FWPortal.exe</command>
<description>1776 Internet ISP software - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-6264.html</infourl>
</item>
<item>
<name>%FP%AIRTEL fts.exe</name>
<status>U</status>
<command>fts.exe</command>
<description>Related to AIRTEL-Broadband, http://www.airtel.in/level2_t12.aspx?path=1/9 Part of the Friendly technologies PPPOE DSL Driver. This is customized for use with the AIRTEL-Broadband ISP. [red]Note:[/red] Located in \%Program Files%\AIRTEL\AIRTEL-Broadband\</description>
<infourl>http://www.castlecops.com/startuplist-15929.html</infourl>
</item>
<item>
<name>%FP%Barak013 fts.exe</name>
<status>?</status>
<command>fts.exe</command>
<description> Barak013 ISP software - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-6260.html</infourl>
</item>
<item>
<name>%FP%Barak013 FWPortal.exe</name>
<status>?</status>
<command>FWPortal.exe</command>
<description> Barak013 ISP software - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-6261.html</infourl>
</item>
<item>
<name>%FP%Friendly fts.exe</name>
<status>?</status>
<command>fts.exe</command>
<description>Friendly ISP software - [red]what does it do and is it required?[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-7167.html</infourl>
</item>
<item>
<name>(*)API Machine</name>
<status>X</status>
<command>winSOCKS.exe</command>
<description>Homepage hijacker, see &lt;a href=&quot;http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi?s=3e991177279cffff;act=ST;f=6;t=2598;hl=new&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; (* = any digit)</description>
<infourl>http://www.castlecops.com/startuplist-9.html</infourl>
</item>
<item>
<name>(*)Run</name>
<status>X</status>
<command>win32API.exe</command>
<description>Homepage hijacker, see &lt;a href=&quot;http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi?s=3e991177279cffff;act=ST;f=6;t=2598;hl=new&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; (* = any digit)</description>
<infourl>http://www.castlecops.com/startuplist-10.html</infourl>
</item>
<item>
<name>(default)</name>
<status>X</status>
<command>(random filename).exe</command>
<description>Added as a result of the &lt;a href=\&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.blackmal@mm.html\&quot; target=\&quot;_blank\&quot;&gt;BLACKMAL&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-14.html</infourl>
</item>
<item>
<name>(Default)</name>
<status>X</status>
<command>Systrsy.exe
</command>
<description>Added by the Trojan.Cdtray, http://securityresponse.symantec.com/avcenter/venc/data/trojan.cdtray.html
 TROJAN!
 [red]Note:[/red] This trojan file is found in the Internet Explorer folder.</description>
<infourl>http://www.castlecops.com/startuplist-11140.html</infourl>
</item>
<item>
<name>(default)</name>
<status>X</status>
<command>llsass.exe</command>
<description>Added by the TROJ/PROXY-GG, http://www.sophos.com/virusinfo/analyses/trojproxygg.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-11994.html</infourl>
</item>
<item>
<name>(Default)</name>
<status>X</status>
<command>webcam.exe</command>
<description>Added by the Troj/Monad-A, http://www.sophos.com/virusinfo/analyses/trojmonada.html
 TROJAN!
 [red] Note:[/red] This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
</description>
<infourl>http://www.castlecops.com/startuplist-12223.html</infourl>
</item>
<item>
<name>(Default)</name>
<status>X</status>
<command>syspol.exe</command>
<description>Added by the Dremm.b, http://www.symantec.com/avcenter/venc/data/trojan.dremn.b.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-12334.html</infourl>
</item>
<item>
<name>(default)</name>
<status>X</status>
<command>rundll32.exe (path to) Zykheptd.dll</command>
<description>Added by the Backdoor.Hesive.B, http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hesive.b.html
 TROJAN!
 [red]Read the link, rootkit type stealth involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-12663.html</infourl>
</item>
<item>
<name>(Default)</name>
<status>X</status>
<command>5640.exe</command>
<description>Troj/DownLd-ABF, http://www.sophos.com/security/analyses/trojdownldabf.html</description>
<infourl>http://www.castlecops.com/startuplist-14640.html</infourl>
</item>
<item>
<name>(Entry name)</name>
<status>X</status>
<command>System.exe</command>
<description>Added by the Troj/Nethief-N, http://www.sophos.com/virusinfo/analyses/trojnethiefn.html
 Trojan!
</description>
<infourl>http://www.castlecops.com/startuplist-9301.html</infourl>
</item>
<item>
<name>(Global Startup)</name>
<status>X</status>
<command>Skunk.exe</command>
<description>Added by the W32/Sunk-A, http://www.sophos.com/virusinfo/analyses/w32sunka.html
 WORM!
[red] Note:[/red] This worm\trojan file is found in the Root folder. (C:\), (D:\),  (E:\) etc, etc.
</description>
<infourl>http://www.castlecops.com/startuplist-12346.html</infourl>
</item>
<item>
<name>(L4r1$$4) (4nt1) (V1ruz)</name>
<status>X</status>
<command>SP00Lsv32.pif</command>
<description>Added by the ASSIRAL.B, http://securityresponse.symantec.com/avcenter/venc/data/w32.assiral.b@mm.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-7168.html</infourl>
</item>
<item>
<name>(original file name)</name>
<status>X</status>
<command>svchost.scr</command>
<description>Added by Troj/Bancban-CX, http://www.sophos.com/virusinfo/analyses/trojbancbancx.html and Troj/Bancban-DA, http://www.sophos.com/virusinfo/analyses/trojbancbanda.html TROJANS! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-9199.html</infourl>
</item>
<item>
<name>(original filename)</name>
<status>X</status>
<command>xphost.scr</command>
<description>Added by the Troj/Bancban-HM, http://www.sophos.com/virusinfo/analyses/trojbancbanhm.html TROJAN! [red]Note:[/red] This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-12129.html</infourl>
</item>
<item>
<name>(Original Trojan Filename)</name>
<status>X</status>
<command>install.exe</command>
<description>Added by the Troj/Bancban-FS, http://www.sophos.com/virusinfo/analyses/trojbancbanfs.html TROJAN! [red]Note:[/red] This trojan file is found in the Windows or Winnt folder. [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-11610.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>actxprxy.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5667.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>avicap32.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5666.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>browser8.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5443.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>avifile5.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5444.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>bootvid4.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5450.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>cdmodem4.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5653.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>acctres8.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5654.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>autodisc.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5966.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>cabview1.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5967.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>atitvo32.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-5968.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>advpack1.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-6313.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>batmeter.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant

</description>
<infourl>http://www.castlecops.com/startuplist-6876.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>bidispl2.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant

</description>
<infourl>http://www.castlecops.com/startuplist-6877.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>asferror.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-7942.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>catsrvps.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-8917.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>audiosrv.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant</description>
<infourl>http://www.castlecops.com/startuplist-9032.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>admparse.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant

</description>
<infourl>http://www.castlecops.com/startuplist-9085.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>bootvid2.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant

</description>
<infourl>http://www.castlecops.com/startuplist-9086.html</infourl>
</item>
<item>
<name>(random 12 digit number)</name>
<status>X</status>
<command>cmpbk321.exe</command>
<description>Adsrv.com/IeDriver, http://sarc.com/avcenter/venc/data/pf/adware.iedriver.html adware variant

</description>
<infourl>http://www.castlecops.com/startuplist-9087.html</infourl>
</item>
<item>
<name>(Random characters)</name>
<status>X</status>
<command>securewinload32x.exe</command>
<description>Added by the Troj/OptixP-N, http://www.sophos.com/virusinfo/analyses/trojoptixpn.html
 TROJAN!
 [red] Note:[/red] This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted.
</description>
<infourl>http://www.castlecops.com/startuplist-12088.html</infourl>
</item>
<item>
<name>(random filename - format **-**-**-**-**)</name>
<status>X</status>
<command>dwdsregt.exe</command>
<description>Added by Adware.ZenoSearch, http://sarc.com/avcenter/venc/data/adware.zenosearch.html ADAWARE!</description>
<infourl>http://www.castlecops.com/startuplist-12545.html</infourl>
</item>
<item>
<name>(random filename - format **-**-**-**-**)</name>
<status>X</status>
<command>qndsregn.exe</command>
<description>Added by ZenoSearch, http://www.symantec.com/avcenter/venc/data/adware.zenosearch.html ADAWARE!</description>
<infourl>http://www.castlecops.com/startuplist-12712.html</infourl>
</item>
<item>
<name>(random filename)</name>
<status>X</status>
<command>slk8x2peu.exe</command>
<description>Added by QuickLinks_Process, http://www.superadblocker.com/definition/slk8x2peu/ ADAWARE!</description>
<infourl>http://www.castlecops.com/startuplist-12735.html</infourl>
</item>
<item>
<name>(random name)</name>
<status>X</status>
<command>iexpl0ra.exe</command>
<description>TROJ_ULPM.BD, http://si.trendmicro-europe.com/consumer/vinfo/encyclopedia.php?LYstr=VMAINDATA&amp;vNav=3&amp;VName=TROJ_ULPM.BD</description>
<infourl>http://www.castlecops.com/startuplist-14217.html</infourl>
</item>
<item>
<name>(Random Name)</name>
<status>X</status>
<command>csrssc.exe</command>
<description>Identified as a variant of the Win32/TrojanDownloader.Small.CYF, http://www.bleepingcomputer.com/startups/csrssc.exe-22097.html malware. [red]Note:[/red] Located in \%Temp%\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-16434.html</infourl>
</item>
<item>
<name>(Random number)</name>
<status>X</status>
<command>explorer.exe</command>
<description>Added by the Troj/Keylog-AN TROJAN! [red]Note:[/red] This trojan file is found in the Windows\service or Winnt\service folder, be sure to check the link for this one, It copies it's self under 9 additional file names, all in the Windows\service or Winnt\service folder. [red]Keylogger/password stealing TROJAN(S) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-9297.html</infourl>
</item>
<item>
<name>(Random number)</name>
<status>X</status>
<command>explorer.exe</command>
<description>Added by the Troj/Keylog-AN, http://www.sophos.com/virusinfo/analyses/trojstartpagl.html TROJAN! [red]Note:[/red] This trojan file is found in the Windows\service or Winnt\service folder, be sure to check the link for this one, It copies it's self under 9 additional file names, all in the Windows\service or Winnt\service folder. [red]Keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-11571.html</infourl>
</item>
<item>
<name>(random)</name>
<status>X</status>
<command>lsass.scr</command>
<description>Added by Troj/Bancban-CW, http://www.sophos.com/virusinfo/analyses/trojbancbancy.html TROJAN! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-9200.html</infourl>
</item>
<item>
<name>(random)</name>
<status>X</status>
<command>svchost.scr</command>
<description>Added by Troj/Bancban-CY, http://www.sophos.com/virusinfo/analyses/trojbancbancy.html Trojan! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-9198.html</infourl>
</item>
<item>
<name>(Random)</name>
<status>X</status>
<command>svshost.exe</command>
<description>Added by the W32/Kelvir-AX, http://www.sophos.com/virusinfo/analyses/w32kelvirax.html
 WORM!
 [red] Note:[/red] This worm\trojan file is found in the System\(random folder name) (95/98/ME) or System32\(random folder name) (NT/2000/XP) folder.</description>
<infourl>http://www.castlecops.com/startuplist-11900.html</infourl>
</item>
<item>
<name>(random)</name>
<status>X</status>
<command>svchost.exe</command>
<description>Added by the Troj/Bancban-JC, http://www.sophos.com/virusinfo/analyses/trojbancbanjc.html TROJAN! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-12304.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_cfg.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10475.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_login.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10476.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_start.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10477.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_config.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10478.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_autorun.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10479.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_loader.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10480.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_env.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10481.html</infourl>
</item>
<item>
<name>(Randomly chosen existing folder name)</name>
<status>X</status>
<command>_setup.exe</command>
<description>Added by the W32/Antinny-L, http://www.sophos.com/virusinfo/analyses/w32antinnyl.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-10482.html</infourl>
</item>
<item>
<name>(Registry Value Name)</name>
<status>X</status>
<command>roses.exe</command>
<description>Added by the W32/Rbot-AFT, http://www.sophos.com/virusinfo/analyses/w32rbotaft.html Worm! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-9572.html</infourl>
</item>
<item>
<name>(unknown)</name>
<status>X</status>
<command>charmapnt.exe</command>
<description>Added by the Troj/Bancos-DR, http://www.sophos.com/virusinfo/analyses/trojbancosdr.html TROJAN! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-10771.html</infourl>
</item>
<item>
<name>(User name) config</name>
<status>X</status>
<command>(Path to Trojan exe)</command>
<description>Added by the Troj/Mosuck-H, http://www.sophos.com/virusinfo/analyses/trojmosuckh.html
 TROJAN!
</description>
<infourl>http://www.castlecops.com/startuplist-10669.html</infourl>
</item>
<item>
<name>(various file names)</name>
<status>X</status>
<command>mediaplayer32.exe</command>
<description>Added by a variant of the WIN32.RBOT, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-5759.html</infourl>
</item>
<item>
<name>(various file names)</name>
<status>X</status>
<command>bling.exe</command>
<description>Added by the W32/RBOT-NI, http://www.sophos.com/virusinfo/analyses/w32rbotni.html WORM! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-5884.html</infourl>
</item>
<item>
<name>(various names)</name>
<status>X</status>
<command>win32snd.exe</command>
<description>Added by the W32/RBOT-DQ, http://www.sophos.com/virusinfo/analyses/w32rbotdq.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-5785.html</infourl>
</item>
<item>
<name>(various names)</name>
<status>X</status>
<command>svchostss.exe</command>
<description>Added by a variant of the WIN32.RBOT, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437 WORM!

</description>
<infourl>http://www.castlecops.com/startuplist-5938.html</infourl>
</item>
<item>
<name>(various names)</name>
<status>X</status>
<command>PasswdMon.exe</command>
<description>Added by Wareout, http://research.sunbelt-software.com/threat_display.cfm?name=Misc.WareOut&amp;threatid=40280&amp;search=wareout Rogue Software</description>
<infourl>http://www.castlecops.com/startuplist-6997.html</infourl>
</item>
<item>
<name>(various names)</name>
<status>X</status>
<command>runload32.exe</command>
<description>Added by Wareout, http://research.sunbelt-software.com/threat_display.cfm?name=Misc.WareOut&amp;threatid=40280&amp;search=wareout Rogue Software</description>
<infourl>http://www.castlecops.com/startuplist-6998.html</infourl>
</item>
<item>
<name>)Start Service</name>
<status>U</status>
<command>upssrv.exe</command>
<description>Cyber Power PowerPanelPlus, http://www.cyberpowersystems.com/ software. &quot;In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner.&quot;</description>
<infourl>http://www.castlecops.com/startuplist-5033.html</infourl>
</item>
<item>
<name>*</name>
<status>X</status>
<command>twain_32.exe</command>
<description>Identified as Trj/Downloader.SV by Panda. TROJAN! [red]Note:[/red] located in \%WINDIR%\</description>
<infourl>http://www.castlecops.com/startuplist-16107.html</infourl>
</item>
<item>
<name>******** (* = random char or digit)</name>
<status>X</status>
<command>rsbmsc.exe</command>
<description>Added by what AntiVir, http://www.avira.com/ antivirus detects as the BDS/Agent.adt TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-13988.html</infourl>
</item>
<item>
<name>*Bandook</name>
<status>X</status>
<command>msdll.exe</command>
<description>Add a variant of the Trojan/Backdoor http://www.greatis.com/appdata/d/m/msdll.exe.htm TROJAN! [red]Note:[/red] Located in \%WINDIR%\System32\</description>
<infourl>http://www.castlecops.com/startuplist-15955.html</infourl>
</item>
<item>
<name>*JanisRuckenbrodII</name>
<status>X</status>
<command>janis.com</command>
<description>Added as a result of the &lt;a href=&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.pops.html&quot; target=&quot;_blank&quot;&gt;POPS&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-15.html</infourl>
</item>
<item>
<name>*Microsoft Update</name>
<status>X</status>
<command>wucxt.exe</command>
<description>Added by the W32.HLLW.STMU, http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-8163.html</infourl>
</item>
<item>
<name>*Microsoft Update</name>
<status>X</status>
<command>wuytc.exe</command>
<description>Added by the W32.HLLW.STMU, http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-8164.html</infourl>
</item>
<item>
<name>*Microsoft Update</name>
<status>X</status>
<command>ctxma.exe</command>
<description>Added by the W32.HLLW.STMU, http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-8165.html</infourl>
</item>
<item>
<name>*Microsoft Update</name>
<status>X</status>
<command>wstcl.exe</command>
<description>Added by the W32.HLLW.STMU, http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-8166.html</infourl>
</item>
<item>
<name>*Microsoft Update</name>
<status>X</status>
<command>cxma.exe</command>
<description>Added by the W32.HLLW.STMU, http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-8167.html</infourl>
</item>
<item>
<name>*microsoft update</name>
<status>X</status>
<command>cxma.exe</command>
<description>Added by the W32.HLLW.STMU, http://www.kephyr.com/spywarescanner/library/w32.hllw.stmu/index.phtml TROJAN</description>
<infourl>http://www.castlecops.com/startuplist-9059.html</infourl>
</item>
<item>
<name>*MS Setup</name>
<status>X</status>
<command>[random file name]</command>
<description>Virtumondo adware,  also known as the VUNDO, http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-9176.html</infourl>
</item>
<item>
<name>*MSConfig32</name>
<status>X</status>
<command>aecache.exe </command>
<description>Detected as Trojan.Win32.Obfuscated.gp by F-secure</description>
<infourl>http://www.castlecops.com/startuplist-15498.html</infourl>
</item>
<item>
<name>*Security Center</name>
<status>X</status>
<command>secctr.exe</command>
<description>Added by the SDBOT.BRO, http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FSDBOT%2EBRO&amp;VSect=P WORM!</description>
<infourl>http://www.castlecops.com/startuplist-10131.html</infourl>
</item>
<item>
<name>*StateMgr</name>
<status>Y</status>
<command>statemgr.exe</command>
<description>Windows ME default for System Restore. Do NOT disable!</description>
<infourl>http://www.castlecops.com/startuplist-16.html</infourl>
</item>
<item>
<name>*WerKernelReporting</name>
<status>N</status>
<command>WerFault.exe</command>
<description>Related to Windows_Error_Reporting, http://www.greatis.com/vista/Utilities/w/werfault.exe.htm technology (WER) on Vista Computers. WER captures software crash and hang data from end-users who agree to report it. [red]Note:[/red] Located in \%WINDIR%\System32\</description>
<infourl>http://www.castlecops.com/startuplist-16969.html</infourl>
</item>
<item>
<name>*windows update</name>
<status>X</status>
<command>wurauclt.exe</command>
<description>Added by the W32/RBOT-SY, http://www.sophos.com/virusinfo/analyses/w32rbotsy.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-6993.html</infourl>
</item>
<item>
<name>*windows update</name>
<status>X</status>
<command>wsctl.exe</command>
<description>Added by the SPYBOT.PR, http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SPYBOT.PR WORM!</description>
<infourl>http://www.castlecops.com/startuplist-7124.html</infourl>
</item>
<item>
<name>*windows update</name>
<status>X</status>
<command>wscxt.exe</command>
<description>Added by the RBOT.AOS, http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FRBOT%2EAOS&amp;VSect=P WORM!</description>
<infourl>http://www.castlecops.com/startuplist-7503.html</infourl>
</item>
<item>
<name>*windows update</name>
<status>X</status>
<command>wkmst.exe</command>
<description>Added by the SDBOT.AVD, http://de.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=86536&amp;VName=WORM_SDBOT.AVD&amp;VSect=O WORM!</description>
<infourl>http://www.castlecops.com/startuplist-7628.html</infourl>
</item>
<item>
<name>*windows update</name>
<status>X</status>
<command>wuaucrlt.exe</command>
<description>Added by the SPYBOT.HUR, http://www.symantec.com/avcenter/venc/data/w32.spybot.hur.html WORM! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-7679.html</infourl>
</item>
<item>
<name>*windows update</name>
<status>X</status>
<command>waurclt.exe</command>
<description>Added by a variant of the WIN32.RBOT, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437 WORM!</description>
<infourl>http://www.castlecops.com/startuplist-9152.html</infourl>
</item>
<item>
<name>*WinLogon</name>
<status>X</status>
<command>[trojan path] ren time:[random number]</command>
<description>Added by the VUNDO, http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.html TROJAN!
</description>
<infourl>http://www.castlecops.com/startuplist-6327.html</infourl>
</item>
<item>
<name>*winstats</name>
<status>X</status>
<command>winstats.exe</command>
<description>Added by the Trojan.Gargafx, http://securityresponse.symantec.com/avcenter/venc/data/trojan.gargafx.html
  TROJAN! [red]Note:[/red] This trojan file (winstats.exe) is found in the Windows or Winnt folder. </description>
<infourl>http://www.castlecops.com/startuplist-11175.html</infourl>
</item>
<item>
<name>*wuauclt.exe</name>
<status>X</status>
<command>w****.exe  (* = random char)</command>
<description>Added by a variant of the W32/RBOT-UG, http://www.sophos.com/virusinfo/analyses/w32rbotug.html WORM! - NOTE: * in the file name represents a random char;  variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...</description>
<infourl>http://www.castlecops.com/startuplist-7697.html</infourl>
</item>
<item>
<name>*wuauclt.exe</name>
<status>X</status>
<command>wmsvc.exe</command>
<description>Added by the W32/RBOT-UG, http://www.sophos.com/virusinfo/analyses/w32rbotug.html WORM! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-8701.html</infourl>
</item>
<item>
<name>,main drive Loader</name>
<status>X</status>
<command>wininfo.exe</command>
<description>Suspected malware as it appears in 3 different registry locations - see http://forums.techguy.org/security/151017-no-start-menu-taskbar-w32.html here
</description>
<infourl>http://www.castlecops.com/startuplist-17.html</infourl>
</item>
<item>
<name>-FreedomNeedsReboot</name>
<status>Y</status>
<command>ZkRunOnceR.exe</command>
<description>Related to Internet_Security_Suite, http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&amp;STORY=/www/story/05-05-2005/0003545403&amp;EDATE= used by Internet providers to protect customers against many attacks. [red]Read the article[/red] [red]Note:[/red] Located in \%Program Files%\(Internet provider)\(Internet provider) Internet Security Suite\</description>
<infourl>http://www.castlecops.com/startuplist-15422.html</infourl>
</item>
<item>
<name>..</name>
<status>X</status>
<command>ABC2007.exe</command>
<description>Added by the Troj/Dloadr-ASH, http://www.us.sophos.com/security/analyses/trojdloadrash.html TROJAN! [red]Note:[/red] This worm\trojan is located in  C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)</description>
<infourl>http://www.castlecops.com/startuplist-13886.html</infourl>
</item>
<item>
<name>.mscdr</name>
<status>X</status>
<command>lassa.exe</command>
<description>Added by the WEBUS.C, http://www.symantec.com/avcenter/venc/data/trojan.webus.c.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-5739.html</infourl>
</item>
<item>
<name>.mscdr</name>
<status>X</status>
<command>lsvchost.exe</command>
<description>Added by the WEBUS.D, http://www.symantec.com/avcenter/venc/data/trojan.webus.d.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-6140.html</infourl>
</item>
<item>
<name>.mscdsr</name>
<status>X</status>
<command>lsvchost.exe</command>
<description>Added by the Troj/Bdoor-CR, http://www.sophos.com/virusinfo/analyses/trojbdoorcr.html
 Trojan!
</description>
<infourl>http://www.castlecops.com/startuplist-9255.html</infourl>
</item>
<item>
<name>.mscsbl</name>
<status>X</status>
<command>svhost.exe</command>
<description>Added by the BACKDOOR-CMQ, http://vil.mcafeesecurity.com/vil/content/v_130850.htm TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-7656.html</infourl>
</item>
<item>
<name>.msfupdate</name>
<status>X</status>
<command>msveup.exe</command>
<description>Added by the W32.ALLOCUP.A, http://www.symantec.com/avcenter/venc/data/w32.allocup.a.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-7788.html</infourl>
</item>
<item>
<name>.mssecure</name>
<status>X</status>
<command>mssecure.exe</command>
<description>Added by the DDOS_BOXED.X, http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=DDOS%5FBOXED%2EX&amp;VSect=P TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-7126.html</infourl>
</item>
<item>
<name>.mssecure</name>
<status>X</status>
<command>mssecure.exe</command>
<description>Added by the Troj/Borobot-B, http://www.sophos.com/virusinfo/analyses/trojborobotb.html
 Trojan!
</description>
<infourl>http://www.castlecops.com/startuplist-9493.html</infourl>
</item>
<item>
<name>.NET config</name>
<status>?</status>
<command>sysmon32.exe</command>
<description>&lt;font color=\&quot;#FF0000\&quot;&gt;??&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-18.html</infourl>
</item>
<item>
<name>.NET.</name>
<status>X</status>
<command>msnmgnr.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-16549.html</infourl>
</item>
<item>
<name>.norton</name>
<status>X</status>
<command>rchost.exe</command>
<description>Added by a variant of the BOXED-A, http://www.sophos.com/virusinfo/analyses/trojboxeda.html
 TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-6944.html</infourl>
</item>
<item>
<name>.nvsvc</name>
<status>X</status>
<command>smss.exe</command>
<description>Added by the BackDoor-CXT, http://vil.nai.com/vil/content/v_138575.htm TROJAN! [red]Note[/red]: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System (XP/WinNT/2K) and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file.</description>
<infourl>http://www.castlecops.com/startuplist-12790.html</infourl>
</item>
<item>
<name>.nvsvcb</name>
<status>X</status>
<command>smssb.exe</command>
<description>Added by the Win32/Boxed.CG, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=57167 TROJAN! [red]Note:[/red] This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) [red]Will attempt to disable antivirus, firewall and Windows Update software[/red]</description>
<infourl>http://www.castlecops.com/startuplist-13437.html</infourl>
</item>
<item>
<name>.Prog</name>
<status>X</status>
<command>services.exe</command>
<description>Added as a result of the NEVEG.B, http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html or NEVEG.C, http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html VIRUSES! Note - this is not the valid Windows Service Controller (services.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/services/ ) process</description>
<infourl>http://www.castlecops.com/startuplist-5081.html</infourl>
</item>
<item>
<name>.Prog</name>
<status>X</status>
<command>winlogon.exe</command>
<description>Added by NEVEG.A, http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.a@mm.html WORM! Note - this is not the valid Windows Logon winlogon.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/winlogon/ process</description>
<infourl>http://www.castlecops.com/startuplist-5082.html</infourl>
</item>
<item>
<name>.protected</name>
<status>X</status>
<command>(no name)</command>
<description>Added by a Smithfraud infection.</description>
<infourl>http://www.castlecops.com/startuplist-12976.html</infourl>
</item>
<item>
<name>.svchost</name>
<status>X</status>
<command>CSRSS.EXE</command>
<description>Added by the WEBUS.F, http://www.symantec.com/avcenter/venc/data/trojan.webus.f.html TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder,  and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/ process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder,  and which moreover should NOT figure in Msconfig/Startup!
</description>
<infourl>http://www.castlecops.com/startuplist-8978.html</infourl>
</item>
<item>
<name>.TEXTCONV</name>
<status>X</status>
<command>csrss.exe</command>
<description>Added as a result of the WEBUS, http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html VIRUS! Note - this is not the valid Client Server Runtime Subsystem  csrss.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/ process, which provides text window support, shutdown, and hard-error handling</description>
<infourl>http://www.castlecops.com/startuplist-4929.html</infourl>
</item>
<item>
<name>.WMAudio</name>
<status>X</status>
<command>csrss.exe</command>
<description>Added as a result of the WEBUS, http://securityresponse.symantec.com/avcenter/venc/data/trojan.webus.html VIRUS! Note - this is not the valid Client Server Runtime Subsystem csrss.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/ process&quot; which provides text window support, shutdown, and hard-error handling </description>
<infourl>http://www.castlecops.com/startuplist-4930.html</infourl>
</item>
<item>
<name>.WMAudio</name>
<status>X</status>
<command>lsass.exe</command>
<description>Added as result of a Webus.B, http://www.symantec.com/avcenter/venc/data/trojan.webus.b.html trojan infection.  Note - this is not the legitimate Lsass.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/ system file, which should normally NOT figure in Msconfig/Startup</description>
<infourl>http://www.castlecops.com/startuplist-5483.html</infourl>
</item>
<item>
<name>/l:eng</name>
<status>N</status>
<command>N/A</command>
<description>Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup</description>
<infourl>http://www.castlecops.com/startuplist-19.html</infourl>
</item>
<item>
<name>000</name>
<status>U</status>
<command>pit.exe</command>
<description>Added by the PrivateEye, http://securityresponse.symantec.com/avcenter/venc/data/spyware.privateeye.html SPYWARE! **Note - If you did not intentionally install this remove it.</description>
<infourl>http://www.castlecops.com/startuplist-9652.html</infourl>
</item>
<item>
<name>0006 - C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\HP Internet Connection Center</name>
<status>N</status>
<command>command.com</command>
<description>Related to HP_Internet_Connection_Center, http://www.amazon.com/HP-Deskjet-950c-capacity-Parallel/dp/B00004TDKS provides access to a variety of valuable offers from Internet Service Providers.</description>
<infourl>http://www.castlecops.com/startuplist-15133.html</infourl>
</item>
<item>
<name>0008 - C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\hp deskjet 990c series v3.0</name>
<status>N</status>
<command>command.com</command>
<description>Related to HP_Internet_Connection_Center, http://www.amazon.com/HP-Deskjet-950c-capacity-Parallel/dp/B00004TDKS provides access to a variety of valuable offers from Internet Service Providers. </description>
<infourl>http://www.castlecops.com/startuplist-15134.html</infourl>
</item>
<item>
<name>000hpdllhos</name>
<status>X</status>
<command>hpdllhost.exe</command>
<description>LZIO.com, http://www.spywareguide.com/product_show.php?id=853 adware downloader</description>
<infourl>http://www.castlecops.com/startuplist-5472.html</infourl>
</item>
<item>
<name>000StTHK</name>
<status>U</status>
<command>000StTHK.exe</command>
<description>Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)</description>
<infourl>http://www.castlecops.com/startuplist-20.html</infourl>
</item>
<item>
<name>0050726-007-i32-1</name>
<status>X</status>
<command>0050726-007-i32-1.exe</command>
<description>Added by the Troj/Bancban-EC, http://www.sophos.com/virusinfo/analyses/trojbancbanec.html TROJAN! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-10796.html</infourl>
</item>
<item>
<name>00DSKSVR00</name>
<status>N</status>
<command>desksaver.exe</command>
<description>Related to Advanced_Desktop_Shield, http://www.softstack.com/deskshield.html</description>
<infourl>http://www.castlecops.com/startuplist-11927.html</infourl>
</item>
<item>
<name>00DSKSVR01</name>
<status>N</status>
<command>desksaver.exe</command>
<description>Related to Advanced_Desktop_Shield, http://www.softstack.com/deskshield.html</description>
<infourl>http://www.castlecops.com/startuplist-11929.html</infourl>
</item>
<item>
<name>00ERSRRRNKY</name>
<status>U</status>
<command>eraser.exe</command>
<description>Related to Evidence_Exterminator, http://www.softstack.com/evterminate.html from Softstack.com Allows for complete removal of data from your hard drive. [red]Note:[/red] Located in \%Program Files%\Evidence Exterminator\ [red]More[/red] here, http://www.threatexpert.com/report.aspx?uid=3c7b3986-c071-4ca5-93f0-1994e7ba44b9</description>
<infourl>http://www.castlecops.com/startuplist-16997.html</infourl>
</item>
<item>
<name>00ERSRRRNKY</name>
<status>U</status>
<command>erasrv.exe</command>
<description>Related to Evidence_Exterminator, http://www.softstack.com/evterminate.html from Softstack.com Allows for complete removal of data from your hard drive. [red]Note:[/red] Located in \%Program Files%\Evidence Exterminator\ [red]More[/red] here, http://www.threatexpert.com/report.aspx?uid=3c7b3986-c071-4ca5-93f0-1994e7ba44b9</description>
<infourl>http://www.castlecops.com/startuplist-16998.html</infourl>
</item>
<item>
<name>00PCTFW</name>
<status>Y</status>
<command>FirewallGUI.exe</command>
<description>Related to PC_Tools, http://www.pctools.com/ Firewall. [red]Note:[/red] Located in \%Program Files%\PC Tools Firewall Plus\</description>
<infourl>http://www.castlecops.com/startuplist-15451.html</infourl>
</item>
<item>
<name>00TCrdMain</name>
<status>Y</status>
<command>TCrdMain.exe</command>
<description>Related to flash_card, http://www.bleepingcomputer.com/startups/00TCrdMain-17106.html slot on the Toshiba laptop. Ending this process will disable access to the flash cards. [red]Note:[/red] located in %ProgramFiles%\TOSHIBA\FlashCards\</description>
<infourl>http://www.castlecops.com/startuplist-14338.html</infourl>
</item>
<item>
<name>00THotkey</name>
<status>U</status>
<command>00THotKey.exe</command>
<description>For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.</description>
<infourl>http://www.castlecops.com/startuplist-21.html</infourl>
</item>
<item>
<name>00THotkey</name>
<status>U</status>
<command>system32THotkey.exe</command>
<description>For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.</description>
<infourl>http://www.castlecops.com/startuplist-15391.html</infourl>
</item>
<item>
<name>0190 Warner</name>
<status>U</status>
<command>WARN0190.EXE</command>
<description>Anti-dialer program, http://www.wt-rate.com/ (Germany)</description>
<infourl>http://www.castlecops.com/startuplist-7047.html</infourl>
</item>
<item>
<name>0900 Warner</name>
<status>U</status>
<command>WARN0900.EXE</command>
<description>Anti-dialer program, http://www.wt-rate.com/ (Germany)</description>
<infourl>http://www.castlecops.com/startuplist-7048.html</infourl>
</item>
<item>
<name>09734482329566253820889118044258</name>
<status>X</status>
<command>av2009.exe</command>
<description>Added by the Antivirus_2009, http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009 rogue anti-spyware program. [red]Note:[/red] Located in \%Program Files%\Antivirus 2009\</description>
<infourl>http://www.castlecops.com/startuplist-17498.html</infourl>
</item>
<item>
<name>0mcamcap</name>
<status>X</status>
<command>0mcamcap.exe</command>
<description>Added by Troj/Cosiam-H, http://www.sophos.com/virusinfo/analyses/trojcosiamh.html TROJAN! Prevx, http://fileinfo.prevx.com/QQ13c818782725-0MCA14900234/0MCAMCAP.EXE.html identifies it has Haxdoor [red]Note[/red]: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)</description>
<infourl>http://www.castlecops.com/startuplist-12829.html</infourl>
</item>
<item>
<name>0utlook Express</name>
<status>X</status>
<command>*****.exe (where * = random char)</command>
<description>Added by the W32/RBOT-CC, http://www.sophos.com/virusinfo/analyses/w32rbotcc.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-7976.html</infourl>
</item>
<item>
<name>1</name>
<status>X</status>
<command>1.exe</command>
<description>Added by the ESTEEMS, http://www.symantec.com/avcenter/venc/data/trojan.esteems.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-7757.html</infourl>
</item>
<item>
<name>1</name>
<status>X</status>
<command>svchost.scr</command>
<description>Added by PWSteal.Bancos.X, http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.x.html Trojan. [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-9203.html</infourl>
</item>
<item>
<name>1</name>
<status>X</status>
<command> lsass.scr</command>
<description>Added by the PWSteal.Bancos.V, http://www.symantec.com/avcenter/venc/data/pwsteal.bancos.v.html TROJAN! [red]Read the link, keylogger/password stealing TROJAN(S) involved.[/red]
</description>
<infourl>http://www.castlecops.com/startuplist-9177.html</infourl>
</item>
<item>
<name>1</name>
<status>X</status>
<command>mrcmgr.exe</command>
<description>Identified as a variant of the Trojan-Banker.Win32.Banker.rqk, http://www.bleepingcomputer.com/startups/mrcmgr.exe-23589.html malware. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17449.html</infourl>
</item>
<item>
<name>1&amp;1 EasyLogin</name>
<status>U</status>
<command>EasyLogin.exe</command>
<description>Related to 1&amp;1_EasyLogin, http://faq.1and1.com/ an Internet Provider. [red]Note:[/red] Located in \%Program Files%\1&amp;1\1&amp;1 EasyLogin\</description>
<infourl>http://www.castlecops.com/startuplist-16023.html</infourl>
</item>
<item>
<name>101Clips</name>
<status>U</status>
<command>101Clips.exe</command>
<description>Related to 101Clips, http://101clips.com/ 101 is the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. [red]Note:[/red] Located in \%Program Files%\101 Clips\</description>
<infourl>http://www.castlecops.com/startuplist-17215.html</infourl>
</item>
<item>
<name>1029BB4B-16A9-4E77-AA3D-96930BD68EEC</name>
<status>X</status>
<command>sysockeu.exe</command>
<description>Added by the SmitFraud, http://siri.geekstogo.com/ChangeLog.php Trojan</description>
<infourl>http://www.castlecops.com/startuplist-16721.html</infourl>
</item>
<item>
<name>108Mbps Wireless LAN Adapte</name>
<status>U</status>
<command>TRENDnet.exe</command>
<description>Related to TRENDnet, http://www.trendnet.com/ Wireless LAN Adapter. [red]Note:[/red] Located in \%Program Files%\TRENDnet\Model number\</description>
<infourl>http://www.castlecops.com/startuplist-16948.html</infourl>
</item>
<item>
<name>11</name>
<status>X</status>
<command>faxcomdos.exe</command>
<description>Added by the Tuimer, http://securityresponse.symantec.com/avcenter/venc/data/backdoor.tuimer.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-7348.html</infourl>
</item>
<item>
<name>1111swapmgr.exe</name>
<status>X</status>
<command>1111swapmgr.exe</command>
<description>Added by the BDOOR-IC, http://www.sophos.com/virusinfo/analyses/trojbdooric.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-9009.html</infourl>
</item>
<item>
<name>123456</name>
<status>X</status>
<command>rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl</command>
<description>Added as a result of the &lt;a href=&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.c.worm.html&quot; target=&quot;_blank&quot;&gt; KITRO.C&lt;/a&gt; (or &lt;a href=&quot;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DANDI.A&amp;amp;VSect=T&quot; target=&quot;_blank&quot;&gt;DANDI.A&lt;/a&gt;) VIRUS! 123456 can be any random 3 to 6 digit number</description>
<infourl>http://www.castlecops.com/startuplist-22.html</infourl>
</item>
<item>
<name>1234567</name>
<status>X</status>
<command>svcost.exe</command>
<description>Added by the Backdoor.Bifrose.YA family of trojan. [red]Note:[/red] This worm\trojan is located in  C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)</description>
<infourl>http://www.castlecops.com/startuplist-14073.html</infourl>
</item>
<item>
<name>1234klsjdc uiar924c af</name>
<status>X</status>
<command>sxgnsvuxct.exe</command>
<description>Added by the Smitfraud, http://siri.geekstogo.com/ChangeLog.php Trojan</description>
<infourl>http://www.castlecops.com/startuplist-17040.html</infourl>
</item>
<item>
<name>1290A33C-85F5-4164-A1BE-7DD299D4986A</name>
<status>U</status>
<command>PBKScheduler.exe</command>
<description>Scheduler for CyberLink PowerBackup, http://www.cyberlink.com/multi/products/main_29_ENU.html  - archiving/backup utility</description>
<infourl>http://www.castlecops.com/startuplist-12592.html</infourl>
</item>
<item>
<name>12EE7A5E-0674-42f9-A76B-000000004D00</name>
<status>X</status>
<command>rundll32.exe stlb2.dll,DllRunMain</command>
<description>BrowserAid/BrowserPal, http://research.sunbelt-software.com/threat_display.cfm?name=BrowserAid&amp;threatid=3342&amp;search=browseraid Foistware</description>
<infourl>http://www.castlecops.com/startuplist-5215.html</infourl>
</item>
<item>
<name>12Ghosts Popup-Killer</name>
<status>U</status>
<command>12popup.exe</command>
<description>&lt;a href=&quot;http://12ghosts.com/ghosts/popup.htm&quot; target=&quot;_blank&quot;&gt;12Ghosts Popup-Killer&lt;/a&gt;</description>
<infourl>http://www.castlecops.com/startuplist-23.html</infourl>
</item>
<item>
<name>12Ghosts ShowTime</name>
<status>U</status>
<command>12showtime.exe</command>
<description>Related to 12Ghosts, http://12ghosts.com/ Power Tools for Windows users. [red]Note:[/red] Located in \%Program Files%\12Ghosts ShowTime\</description>
<infourl>http://www.castlecops.com/startuplist-15445.html</infourl>
</item>
<item>
<name>12Ghosts Synchronize</name>
<status>U</status>
<command>12sync.exe</command>
<description>Related to 12Ghosts, http://12ghosts.com/ Power Tools for Windows users. [red]Note:[/red] Located in \%Program Files%\12Ghosts ShowTime\</description>
<infourl>http://www.castlecops.com/startuplist-15446.html</infourl>
</item>
<item>
<name>17779Proj2002</name>
<status>?</status>
<command>N/A</command>
<description>&lt;font color=&quot;#FF0000&quot;&gt;??&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-24.html</infourl>
</item>
<item>
<name>180adsolution</name>
<status>X</status>
<command>180adsolution.exe</command>
<description>ncase adware, http://research.sunbelt-software.com/threat_display.cfm?name=180solutions.NCase&amp;threatid=8869</description>
<infourl>http://www.castlecops.com/startuplist-5247.html</infourl>
</item>
<item>
<name>180ax</name>
<status>X</status>
<command>180ax.exe</command>
<description>ncase adware, http://research.sunbelt-software.com/threat_display.cfm?name=180solutions.NCase&amp;threatid=8869</description>
<infourl>http://www.castlecops.com/startuplist-5012.html</infourl>
</item>
<item>
<name>180ClientStubInstall</name>
<status>X</status>
<command>stubinstaller****.exe  (* = digit)</command>
<description>180Solutions, http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677 adware related</description>
<infourl>http://www.castlecops.com/startuplist-7944.html</infourl>
</item>
<item>
<name>180ClientStubInstall</name>
<status>X</status>
<command>******.exe (* = random digit/character)</command>
<description>180Solutions, http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677 adware related</description>
<infourl>http://www.castlecops.com/startuplist-9532.html</infourl>
</item>
<item>
<name>180ClientStubInstall</name>
<status>X</status>
<command>******.tmp (* = random digit/character)</command>
<description>180Solutions, http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090677 adware related</description>
<infourl>http://www.castlecops.com/startuplist-10688.html</infourl>
</item>
<item>
<name>1916435341.exe</name>
<status>X</status>
<command>1916435341.exe</command>
<description>Troj/Dloadr-AXU, http://www.sophos.com/security/analyses/trojdloadraxu.html</description>
<infourl>http://www.castlecops.com/startuplist-14550.html</infourl>
</item>
<item>
<name>196_150_ni</name>
<status>X</status>
<command>196_150_ni.exe</command>
<description>Added by WinSoftware/WinFixer.Process, http://www.superadblocker.com/1/196_150_NI.EXE-5442.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-12728.html</infourl>
</item>
<item>
<name>197_150_ni_3</name>
<status>X</status>
<command>197_150_ni_3.exe</command>
<description>A variant, http://www.superadblocker.com/1/196_150_NI.EXE-5442.html  TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-12729.html</infourl>
</item>
<item>
<name>1:</name>
<status>N</status>
<command>hpdrv.exe</command>
<description>HP utility for monitoring when and how many recoveries have been done</description>
<infourl>http://www.castlecops.com/startuplist-25.html</infourl>
</item>
<item>
<name>1A:MacVisionTrayMonitor</name>
<status>N</status>
<command>TrayMonitor.exe</command>
<description>Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock)</description>
<infourl>http://www.castlecops.com/startuplist-26.html</infourl>
</item>
<item>
<name>1A:Stardock MCP</name>
<status>Y</status>
<command>mcpserver.exe</command>
<description>Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications</description>
<infourl>http://www.castlecops.com/startuplist-27.html</infourl>
</item>
<item>
<name>1A:Stardock TrayMonitor</name>
<status>Y</status>
<command>TrayServer.exe</command>
<description>For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX</description>
<infourl>http://www.castlecops.com/startuplist-28.html</infourl>
</item>
<item>
<name>1CmailS</name>
<status>?</status>
<command>NETMAIL.EXE</command>
<description>&lt;font color=&quot;#FF0000&quot;&gt;??&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-29.html</infourl>
</item>
<item>
<name>1on1</name>
<status>X</status>
<command>1on1.exe</command>
<description>Adult content dialler</description>
<infourl>http://www.castlecops.com/startuplist-30.html</infourl>
</item>
<item>
<name>1Srv32</name>
<status>U</status>
<command>SpyAgent4.exe</command>
<description>SpyTech &lt;a href=&quot;http://www.spytech-web.com/spyagent.shtml&quot; target=&quot;_blank&quot;&gt;SpyAgent&lt;/a&gt; monitoring software. &amp;quot;Spy software that allows you to monitor EVERYTHING users do on your PC.&amp;quot;</description>
<infourl>http://www.castlecops.com/startuplist-31.html</infourl>
</item>
<item>
<name>1u7</name>
<status>X</status>
<command>1u7.exe</command>
<description>Added by the Troj/Murbac-A, http://www.sophos.com/security/analyses/trojmurbaca.html TROJAN!
[red]Note:[/red] This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)</description>
<infourl>http://www.castlecops.com/startuplist-13602.html</infourl>
</item>
<item>
<name>1Win32Cfg</name>
<status>U</status>
<command>SpyBuddy.exe</command>
<description>SpyBuddy, http://www.symantec.com/avcenter/venc/data/spyware.spybuddy.html  monitoring software. [red]Read the link, keylogger/password stealing trojan(s) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-32.html</infourl>
</item>
<item>
<name>1Win32Cfg</name>
<status>U</status>
<command>Keyloggerpro.exe</command>
<description>Keyloggerpro, http://www.symantec.com/avcenter/venc/data/spyware.keyloggerpro.html monitoring software. [red]Read the link, keylogger/password stealing trojan(s) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-33.html</infourl>
</item>
<item>
<name>1WinCfg32</name>
<status>X</status>
<command>&quot;\WebMailSpy.exe</command>
<description>Added by WebMailSpy, http://securityresponse.symantec.com/avcenter/venc/data/spyware.webmailspy.html SPYWARE!</description>
<infourl>http://www.castlecops.com/startuplist-7097.html</infourl>
</item>
<item>
<name>2020Downloader</name>
<status>X</status>
<command>mssvr.exe</command>
<description>2020Search, http://research.sunbelt-software.com/threat_display.cfm?name=2020Search&amp;threatid=13811 Toolbar </description>
<infourl>http://www.castlecops.com/startuplist-34.html</infourl>
</item>
<item>
<name>2177F056-0AA6-4D6C-A944-13F71F341C29</name>
<status>X</status>
<command>sysokuaw.exe</command>
<description>Added by the SmitFraud, http://siri.geekstogo.com/ChangeLog.php Trojan</description>
<infourl>http://www.castlecops.com/startuplist-16724.html</infourl>
</item>
<item>
<name>24Online Client</name>
<status>U</status>
<command>CyberoamClient.exe</command>
<description>Related to Cyberroam, http://www.elitecore.com/ from Elitecore Technologies Ltd. [red]Note:[/red] Located in \%Program Files%\eLitecore\Cyberoam Client for 24Online\</description>
<infourl>http://www.castlecops.com/startuplist-15918.html</infourl>
</item>
<item>
<name>250</name>
<status>X</status>
<command>winmgr.exe</command>
<description>Added by the Troj/LegMir-AT, http://www.sophos.com/virusinfo/analyses/trojlegmirat.html TROJAN! [red]Read the link, keylogger/password stealing trojan(s) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-11028.html</infourl>
</item>
<item>
<name>27</name>
<status>X</status>
<command>slsorve.exe</command>
<description>Added by the SLSORVE-A, http://www.sophos.com/virusinfo/analyses/trojslsorvea.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-8753.html</infourl>
</item>
<item>
<name>27</name>
<status>X</status>
<command>csrss32.exe</command>
<description>Added by the TROJ/SLSORVE-D, http://www.sophos.com/virusinfo/analyses/trojslsorved.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-10972.html</infourl>
</item>
<item>
<name>27</name>
<status>X</status>
<command>msm32.exe</command>
<description>Added by the TROJ/SLSORVE-E, http://www.sophos.com/virusinfo/analyses/trojslsorvee.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-11479.html</infourl>
</item>
<item>
<name>2CF0B992-5EEB-4143-99C0-5297EF71F444</name>
<status>X</status>
<command>rundll32.exe stlbdist.dll, DllRunMain</command>
<description>BrowserAid/BrowserPal, http://research.sunbelt-software.com/threat_display.cfm?name=BrowserAid&amp;threatid=3342&amp;search=browseraid Foistware</description>
<infourl>http://www.castlecops.com/startuplist-4649.html</infourl>
</item>
<item>
<name>2CF0B992-5EEB-4143-99C2-5297EF71F44B</name>
<status>X</status>
<command>rundll32.exe stlbupdt.DLL, DllRunMain</command>
<description>BrowserAid/BrowserPal, http://research.sunbelt-software.com/threat_display.cfm?name=BrowserAid&amp;threatid=3342&amp;search=browseraid Foistware</description>
<infourl>http://www.castlecops.com/startuplist-4650.html</infourl>
</item>
<item>
<name>2chkdsk</name>
<status>X</status>
<command>******.dll</command>
<description>VirtuMonde/Vundo, http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99 adware variant</description>
<infourl>http://www.castlecops.com/startuplist-14335.html</infourl>
</item>
<item>
<name>2kadiras</name>
<status>Y</status>
<command>2kadiras.exe</command>
<description>Allied_Telesyn, http://www.alliedtelesyn.co.uk/en-gb/ AT series router/modem related - apparently required
</description>
<infourl>http://www.castlecops.com/startuplist-9149.html</infourl>
</item>
<item>
<name>2Search</name>
<status>X</status>
<command>main.exe</command>
<description>Added by Adware.2Search, http://www.symantec.com/avcenter/venc/data/adware.2search.html ADAWARE! [red]Note[/red]: located in C:\Program Files\2search\</description>
<infourl>http://www.castlecops.com/startuplist-12885.html</infourl>
</item>
<item>
<name>2thousandbuck</name>
<status>X</status>
<command>(path to file)</command>
<description>Added by the RANKY.L, http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.l.html TROJAN!
</description>
<infourl>http://www.castlecops.com/startuplist-6186.html</infourl>
</item>
<item>
<name>2wSysTray</name>
<status>U</status>
<command>2portalmon.exe</command>
<description>&lt;a target=&quot;_blank&quot; href=&quot;http://www.2wire.com/home/index.html&quot;&gt;2Wire Homeportal&lt;/a&gt; user interface</description>
<infourl>http://www.castlecops.com/startuplist-35.html</infourl>
</item>
<item>
<name>32-bit Thunking service</name>
<status>X</status>
<command>thunk32.exe</command>
<description>Added by the W32.Derdero.A, http://securityresponse.symantec.com/avcenter/venc/data/w32.derdero.a@mm.html WORM! </description>
<infourl>http://www.castlecops.com/startuplist-7473.html</infourl>
</item>
<item>
<name>333</name>
<status>X</status>
<command>svchost.exe</command>
<description>Troj/JD-A, http://www.sophos.com/security/analyses/trojjda.html [red]Read the link, steals information[/red]</description>
<infourl>http://www.castlecops.com/startuplist-14366.html</infourl>
</item>
<item>
<name>357AA41A-B7A8-4632-A27D-5B980B25CF43</name>
<status>X</status>
<command>[path to svchost.exe]</command>
<description>Added by the SMALL-AQ, http://www.sophos.com/virusinfo/analyses/trojsmallaq.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-7169.html</infourl>
</item>
<item>
<name>357AA41A-B7A8-4632-A27D-5B980B25CF43</name>
<status>X</status>
<command>services.exe</command>
<description>Added by FakeMessage/AdRotator, http://www.symantec.com/avcenter/venc/data/adware.fakemessage.html adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder,  and should NOT be confused with the legitimate Windows services.exe, http://www.liutilities.com/products/wintaskspro/processlibrary/services/ process,   always located in the Winnt\System32 or Windows\System32 folder,  and which moreover should NOT figure in Msconfig/Startup!
</description>
<infourl>http://www.castlecops.com/startuplist-11011.html</infourl>
</item>
<item>
<name>36X Raid Configurer</name>
<status>Y</status>
<command>JMRaidSetup.exe</command>
<description>Related to Raid_Configurer, http://www.redhat.com/docs/manuals/linux/RHL-9-Manual/custom-guide/ch-software-raid.html Disk Partitioning Setup. [red]Note:[/red] Located in \%WINDIR%\System32\</description>
<infourl>http://www.castlecops.com/startuplist-17352.html</infourl>
</item>
<item>
<name>388529725448</name>
<status>X</status>
<command>AutomaticUpdates.exe</command>
<description>W32/Sdbot-DEN, http://www.sophos.com/security/analyses/w32sdbotden.html [red]Read the link, allows remote access[/red]</description>
<infourl>http://www.castlecops.com/startuplist-14817.html</infourl>
</item>
<item>
<name>38921398152773197389309440455459</name>
<status>X</status>
<command>av2009.exe</command>
<description>Added by the Antivirus_2009, http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009 rogue anti-spyware program. [red]Note:[/red] Located in \%Program Files%\Antivirus 2009\ [red]Note:[/red] Use SDFix under supervision. [red]Note:[/red] Random numbers in the Start up name.</description>
<infourl>http://www.castlecops.com/startuplist-17409.html</infourl>
</item>
<item>
<name>3c1807pd</name>
<status>Y</status>
<command>3cmlink.exe 3cpipe-3c1807pd</command>
<description>3Com WinModem driver. See &lt;a href=&quot;http://808hi.com/56k/winmodems.asp&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; for more WinModem information</description>
<infourl>http://www.castlecops.com/startuplist-37.html</infourl>
</item>
<item>
<name>3capplnk</name>
<status>Y</status>
<command>3capplnk.exe</command>
<description>US Robotics Modem driver</description>
<infourl>http://www.castlecops.com/startuplist-38.html</infourl>
</item>
<item>
<name>3cdminic</name>
<status>N</status>
<command>3CDMINIC.EXE</command>
<description>3Com DMI (DynamicAccess &lt;u&gt;D&lt;/u&gt;esktop &lt;u&gt;M&lt;/u&gt;anagement &lt;u&gt;I&lt;/u&gt;nterface) Agent associated with 3Com network cards</description>
<infourl>http://www.castlecops.com/startuplist-39.html</infourl>
</item>
<item>
<name>3CM Link</name>
<status>Y</status>
<command>3cmcnkw.exe</command>
<description>Required for a US Robotics WinModem as it provides the link to Windows - won't work without it.</description>
<infourl>http://www.castlecops.com/startuplist-40.html</infourl>
</item>
<item>
<name>3Cmlink</name>
<status>Y</status>
<command>3CmlinkW.exe</command>
<description>For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See &lt;a href=&quot;http://808hi.com/56k/winmodems.asp&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; for more WinModem information</description>
<infourl>http://www.castlecops.com/startuplist-41.html</infourl>
</item>
<item>
<name>3ComDMIAgent</name>
<status>N</status>
<command>3CDMINIC.EXE</command>
<description>3Com DMI (DynamicAccess &lt;u&gt;D&lt;/u&gt;esktop &lt;u&gt;M&lt;/u&gt;anagement &lt;u&gt;I&lt;/u&gt;nterface) Agent associated with 3Com network cards</description>
<infourl>http://www.castlecops.com/startuplist-42.html</infourl>
</item>
<item>
<name>3D Text</name>
<status>N</status>
<command>3D Text.scr</command>
<description>Added as a result of the &lt;a href=&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.jermy.a.html&quot; target=&quot;_blank&quot;&gt; JERMY.A&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-44.html</infourl>
</item>
<item>
<name>3Deep Control Panel</name>
<status>U</status>
<command>3DeepCTL.EXE</command>
<description>From &lt;a href=&quot;http://www.colorific.com/index.htm&quot; target=&quot;_blank&quot;&gt;LightSurf Technologies&lt;/a&gt; (nee E-Color) - &lt;a href=&quot;http://www.colorific.com/d1.htm&quot; target=&quot;_blank&quot;&gt;3Deep&lt;/a&gt; corrects lighting, shading and color for all your 2D and 3D games</description>
<infourl>http://www.castlecops.com/startuplist-45.html</infourl>
</item>
<item>
<name>3Dfx Acc</name>
<status>X</status>
<command>GFXACC.EXE</command>
<description>Added as a result of the &lt;a href=&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.gibe@mm.html&quot; target=&quot;_blank&quot;&gt; GIBE&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-46.html</infourl>
</item>
<item>
<name>3dfx Task Manager</name>
<status>N</status>
<command>3dfxMan.exe</command>
<description>System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -&amp;gt; Programs</description>
<infourl>http://www.castlecops.com/startuplist-47.html</infourl>
</item>
<item>
<name>3dfx Tools</name>
<status>Y</status>
<command>3dfxCmn.dll</command>
<description>Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards</description>
<infourl>http://www.castlecops.com/startuplist-48.html</infourl>
</item>
<item>
<name>3dfxv2ps.dll</name>
<status>Y</status>
<command>3dfxv2ps.dll</command>
<description>Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards</description>
<infourl>http://www.castlecops.com/startuplist-49.html</infourl>
</item>
<item>
<name>3Dlabs Taskbar Display Manager</name>
<status>?</status>
<command>3DLman.exe</command>
<description>3DLabs graphics driver related. &lt;font color=&quot;#FF0000&quot;&gt; System Tray access to display settings?&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-50.html</infourl>
</item>
<item>
<name>3DLabsHelperDemon</name>
<status>U</status>
<command>3dldemon.exe</command>
<description>Directly from the programs author &amp;quot;It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive.&amp;quot; In most cases it can be safely disabled</description>
<infourl>http://www.castlecops.com/startuplist-51.html</infourl>
</item>
<item>
<name>3DMouse.EXE</name>
<status>Y</status>
<command>3DMouse.EXE</command>
<description>Dritek System Inc. 3D Mouse driver</description>
<infourl>http://www.castlecops.com/startuplist-8340.html</infourl>
</item>
<item>
<name>3d_sound</name>
<status>X</status>
<command>3d_sound.exe</command>
<description>Added by the Troj/Riados-A, http://www.sophos.com/virusinfo/analyses/trojriadosa.html
 TROJAN!
 [red] Note:[/red] This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
</description>
<infourl>http://www.castlecops.com/startuplist-12053.html</infourl>
</item>
<item>
<name>3P_UDEC</name>
<status>X</status>
<command>AntvrsInstall.exe</command>
<description>Installer for the Antivirus_2008, http://www.bleepingcomputer.com/malware-removal/antivirus-2008 rogue anti-spyware program. [red]Note:[/red] Use Malwarebytes, http://www.malwarebytes.org/rogueremover.php RogueRemover tool.</description>
<infourl>http://www.castlecops.com/startuplist-17138.html</infourl>
</item>
<item>
<name>3qdctl.exe</name>
<status>U</status>
<command>3qdctl.exe</command>
<description>Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ</description>
<infourl>http://www.castlecops.com/startuplist-52.html</infourl>
</item>
<item>
<name>3ware 3DM</name>
<status>Y</status>
<command>3dm.exe</command>
<description>Monitors status of the disk array on 3ware IDE RAID controllers</description>
<infourl>http://www.castlecops.com/startuplist-53.html</infourl>
</item>
<item>
<name>4684735485910</name>
<status>X</status>
<command>netdll32.exe</command>
<description>W32/Sdbot-DEV, http://www.sophos.com/security/analyses/w32sdbotdev.html [red]Read the link, allows remote access[/red]</description>
<infourl>http://www.castlecops.com/startuplist-14816.html</infourl>
</item>
<item>
<name>4da92ad5.exe</name>
<status>X</status>
<command>4da92ad5.exe</command>
<description>Troj/Dloadr-WZ, http://www.sophos.com/security/analyses/trojdloadrwz.html</description>
<infourl>http://www.castlecops.com/startuplist-14184.html</infourl>
</item>
<item>
<name>4oD</name>
<status>U</status>
<command>KHost.exe</command>
<description>Kontiki_Delivery_Manager, http://help.kontiki.com/enduser/search_results.jsp?node=10779&amp;PMSearch=khost.exe - Windows-based client software that enables secure delivery of content to users' desktops</description>
<infourl>http://www.castlecops.com/startuplist-14642.html</infourl>
</item>
<item>
<name>4wd!!!</name>
<status>X</status>
<command>Natal!.pif</command>
<description>Added as a result of the &lt;a href=\&quot;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.AI\&quot; target=\&quot;_blank\&quot;&gt;OPASERV.AI&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-54.html</infourl>
</item>
<item>
<name>5-1-61-96</name>
<status>X</status>
<command>members-area.exe</command>
<description>Adult content dialler</description>
<infourl>http://www.castlecops.com/startuplist-55.html</infourl>
</item>
<item>
<name>5-2-46-112</name>
<status>X</status>
<command>5-2-46-112.exe</command>
<description>Adult content pop-up dialler. Removal instructions &lt;a href=&quot;http://groups.google.com/groups?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF8&amp;safe=off&amp;threadm=1e10cd61.0203201743.78f51cfa%40posting.google.com&amp;rnum=9&amp;prev=/groups%3Fq%3D5-2-46-112.exe%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF8%26safe%3Doff%26selm%3D1e10cd61.0203201743.78f51cfa%40posting.google.com%26rnum%3D9&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;</description>
<infourl>http://www.castlecops.com/startuplist-56.html</infourl>
</item>
<item>
<name>55278</name>
<status>X</status>
<command>grepclient1.exe</command>
<description>Added by the Troj/Lineage-S, http://www.sophos.com/virusinfo/analyses/trojlineages.html Trojan! [red]Read the link, keylogger/password stealing trojan(s) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-9595.html</infourl>
</item>
<item>
<name>5p4m</name>
<status>X</status>
<command>(Path to Trojan)</command>
<description>Added by the Troj/Litebot-C, http://www.sophos.com/virusinfo/analyses/trojlitebotc.html
 TROJAN!
</description>
<infourl>http://www.castlecops.com/startuplist-10914.html</infourl>
</item>
<item>
<name>666</name>
<status>X</status>
<command>Ska.exe</command>
<description>Added by the Troj/Pipes, http://www.sophos.com/virusinfo/analyses/trojpipes.html TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-57.html</infourl>
</item>
<item>
<name>678</name>
<status>X</status>
<command>lsas32.exe</command>
<description>Added by the Troj/Slsorve-C, http://www.sophos.com/virusinfo/analyses/trojslsorvec.html
 TROJAN!
</description>
<infourl>http://www.castlecops.com/startuplist-10302.html</infourl>
</item>
<item>
<name>756349DC-6D9E-4F2A-9B24-269661F073C3</name>
<status>X</status>
<command>sysoghcx.exe</command>
<description>Added by the SmitFraud, http://siri.geekstogo.com/ChangeLog.php Trojan</description>
<infourl>http://www.castlecops.com/startuplist-16723.html</infourl>
</item>
<item>
<name>7f8e</name>
<status>X</status>
<command>z****.exe 9idf</command>
<description>Detected by NOD32 as Win32/TrojanDropper.Small.ALI , [red]Note:[/red] it creates a number of extra z****.dll files in the system32 folder</description>
<infourl>http://www.castlecops.com/startuplist-13931.html</infourl>
</item>
<item>
<name>7v3j</name>
<status>X</status>
<command>z1844.exe gdtgh</command>
<description>Added by an unidentified TROJAN! [red]Note:[/red] of the Win32/Rbot, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437 Family. [red]Note:[/red] This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) The file name is random z(Random Number).exe followed by [red]gdtgh[/red]</description>
<infourl>http://www.castlecops.com/startuplist-13681.html</infourl>
</item>
<item>
<name>802.11b+g USB Wireless LAN Utility</name>
<status>U</status>
<command>ZDWlan.exe</command>
<description>Related to USB_Wifi_device, http://www.file.net/process/zdwlan.exe.html Wireless Lan. [red]Note:[/red] Located in \%Program Files%\WLAN\802.11b+g USB WLAN\</description>
<infourl>http://www.castlecops.com/startuplist-15928.html</infourl>
</item>
<item>
<name>802.11g Wireless Adatper</name>
<status>U</status>
<command>Monitor.exe</command>
<description>Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to &quot;Wireless Connection Status&quot; and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled.</description>
<infourl>http://www.castlecops.com/startuplist-15432.html</infourl>
</item>
<item>
<name>85</name>
<status>X</status>
<command>rundl132.exe</command>
<description>Added by the Troj/Gampass-L, http://www.sophos.com/security/analyses/trojgampassl.html TROJAN! [red]Note:[/red] This worm\trojan is located in C:\%WINDIR%\TEMP\ [red]Monitor user activity and log keystrokes. It also attempts to suppress detection alerts for an anti-virus product[/red] (random key name).</description>
<infourl>http://www.castlecops.com/startuplist-14251.html</infourl>
</item>
<item>
<name>852EBF20-A95D-4F1F-B9C2-B2CD24350F3E</name>
<status>X</status>
<command>sysodkcs.exe</command>
<description>Added by the SmitFraud, http://siri.geekstogo.com/ChangeLog.php Trojan</description>
<infourl>http://www.castlecops.com/startuplist-16722.html</infourl>
</item>
<item>
<name>98D0CE0C16B1</name>
<status>X</status>
<command>rundll32.exe D0CE0C16B1,D0CE0C16B1</command>
<description>BrowserAid/BrowserPal, http://research.sunbelt-software.com/threat_display.cfm?name=BrowserAid&amp;threatid=3342&amp;search=browseraid Foistware</description>
<infourl>http://www.castlecops.com/startuplist-5622.html</infourl>
</item>
<item>
<name>9m</name>
<status>X</status>
<command>winlog0n.exe</command>
<description>Troj/LegMir-AQK, http://www.sophos.com/security/analyses/trojlegmiraqk.html [red]Read the link, steals information[/red]</description>
<infourl>http://www.castlecops.com/startuplist-14326.html</infourl>
</item>
<item>
<name>9xadiras</name>
<status>Y</status>
<command>9xadiras.exe</command>
<description>Allied_Telesyn, http://www.alliedtelesyn.co.uk/en-gb/ AT series router/modem related - apparently required
</description>
<infourl>http://www.castlecops.com/startuplist-9148.html</infourl>
</item>
<item>
<name>9xHtProtect</name>
<status>X</status>
<command>AVprotect9x.exe</command>
<description>Added by the W32.NETSKY.M, http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.m@mm.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-58.html</infourl>
</item>
<item>
<name>;Rundll</name>
<status>X</status>
<command>(random filename)</command>
<description>Added as a result of the &lt;a href=\&quot;http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PWSLEGMIR.E\&quot; target=\&quot;_blank\&quot;&gt;PWSLEGMIR.E&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-59.html</infourl>
</item>
<item>
<name>&lt;executed file name&gt;</name>
<status>X</status>
<command>Regsrv32.com</command>
<description>Added as a result of the &lt;a href=\&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.southghost.html\&quot; target=\&quot;_blank\&quot;&gt;SOUTHGHOST&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-4.html</infourl>
</item>
<item>
<name>&lt;filename&gt;</name>
<status>X</status>
<command>App.exe</command>
<description>Added as a result of the &lt;a href=\&quot;http://securityresponse.symantec.com/avcenter/venc/data/w32.waxpow.worm.html\&quot; target=\&quot;_blank\&quot;&gt;WAXPOW&lt;/a&gt; VIRUS! where &amp;lt;filename&amp;gt; is the executed filename</description>
<infourl>http://www.castlecops.com/startuplist-5.html</infourl>
</item>
<item>
<name>&lt;random filename&gt;</name>
<status>X</status>
<command>wincpu.exe</command>
<description>Added as a result of an unidentified VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-7.html</infourl>
</item>
<item>
<name>&lt;various names&gt;</name>
<status>X</status>
<command>elf.exe</command>
<description>Elf is a hacker program, tied to a trojan server</description>
<infourl>http://www.castlecops.com/startuplist-8.html</infourl>
</item>
<item>
<name>??QQ</name>
<status>?</status>
<command>QQ.exe</command>
<description>Related to QQ_IM, http://im.qq.com/ program popular in China. (It's similar to MSN Messenger.) there are many add-ons created for QQ and of course, some add-ons are malware. If you didn't get his QQ from the official site, or you installed some add-ons it is suggested that you remove it and have install a fresh copy from the official Tencent Inc. site. [red]Note:[/red] Located in \%Program Files%\Tencent\QQ\ </description>
<infourl>http://www.castlecops.com/startuplist-17042.html</infourl>
</item>
<item>
<name>?ekio Startups</name>
<status>X</status>
<command>?nksvc32.exe</command>
<description>Added by the W32/AGOBOT-OV, http://www.sophos.com/virusinfo/analyses/w32agobotov.html WORM! [red]Read the link, keylogger/password stealing trojan(s) involved.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-8511.html</infourl>
</item>
<item>
<name>@</name>
<status>X</status>
<command>regedit -s ..win.dll</command>
<description>Added as a result of the &lt;a href=&quot;http://securityresponse.symantec.com/avcenter/venc/data/js.seeker.k.html&quot; target=&quot;_blank&quot;&gt;SEEKER.K&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-60.html</infourl>
</item>
<item>
<name>@Hoc Toolbar</name>
<status>N</status>
<command>AtHoc.exe</command>
<description>One-click activated browsing toolbar used by various web-sites. See &lt;a href=&quot;http://siliconvalley.internet.com/news/article.php/3531_479951&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; for more info</description>
<infourl>http://www.castlecops.com/startuplist-61.html</infourl>
</item>
<item>
<name>@loha</name>
<status>N</status>
<command>reminder.exe</command>
<description>Registration reminder for &lt;a href=&quot;http://www.pcworld.com/downloads/file_description/0,fid,6581,00.asp&quot; target=&quot;_blank&quot;&gt;@loha@home&lt;/a&gt; E-mail utility</description>
<infourl>http://www.castlecops.com/startuplist-62.html</infourl>
</item>
<item>
<name>@tour_ww</name>
<status>X</status>
<command>@tour_ww[1].exe</command>
<description>Adult content dialler</description>
<infourl>http://www.castlecops.com/startuplist-63.html</infourl>
</item>
<item>
<name>a</name>
<status>X</status>
<command>a.exe</command>
<description>Commercials file that registers itself in the system registry and redirects IE to a certain commercial website</description>
<infourl>http://www.castlecops.com/startuplist-64.html</infourl>
</item>
<item>
<name>a</name>
<status>X</status>
<command>jesse.exe</command>
<description>Added by the W32/Melo-A, http://www.sophos.com/virusinfo/analyses/w32meloa.html
 WORM! 
 [red] Note:[/red] This worm file is found in the system32\drivers\etc folder.
</description>
<infourl>http://www.castlecops.com/startuplist-11637.html</infourl>
</item>
<item>
<name>A New Windows Updater</name>
<status>X</status>
<command>w32NTupdt.exe</command>
<description>Added by W32.Mytob.BM, http://securityresponse.symantec.com/avcenter/venc/data/w32.mytob.bm@mm.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-8083.html</infourl>
</item>
<item>
<name>A Note</name>
<status>U</status>
<command>A Note.exe</command>
<description>Related to A_Note, http://a-note.sourceforge.net/ A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop. [red]Note:[/red] Located in \%Program Files%\A Note\</description>
<infourl>http://www.castlecops.com/startuplist-16702.html</infourl>
</item>
<item>
<name>A Verizon App</name>
<status>U</status>
<command>VERIZO~1</command>
<description>Related to Verizon_Online, http://www22.verizon.com/ Help support/ [red]Note:[/red] Located in C:\PROGRA~1\VERIZO~1\HELPSU~1\</description>
<infourl>http://www.castlecops.com/startuplist-13789.html</infourl>
</item>
<item>
<name>a-squared</name>
<status>U</status>
<command>a2guard.exe</command>
<description>a-Squared, http://www.emsisoft.com/en/ antitrojan - can be run on demand,  but necessary in Startup,  if you prefer the a˛  'Background Guard'  real time protection feature</description>
<infourl>http://www.castlecops.com/startuplist-6624.html</infourl>
</item>
<item>
<name>a-winpoet-service</name>
<status>Y</status>
<command>winpppoverethernet.exe</command>
<description>WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read &lt;a href=&quot;http://www.finepoint.com/products/winpoet/index.html&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking</description>
<infourl>http://www.castlecops.com/startuplist-65.html</infourl>
</item>
<item>
<name>A1000 Settings Utility</name>
<status>U</status>
<command>cpqa1000.exe</command>
<description>Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features</description>
<infourl>http://www.castlecops.com/startuplist-66.html</infourl>
</item>
<item>
<name>A4Proxy</name>
<status>U</status>
<command>A4Proxy.exe</command>
<description>&lt;a href=&quot;http://www.findincontext.com/a4proxy/review.htm&quot; target=&quot;_blank&quot;&gt;Anonymity 4 Proxy&lt;/a&gt; - local proxy server that makes you anonymous when visiting web sites</description>
<infourl>http://www.castlecops.com/startuplist-67.html</infourl>
</item>
<item>
<name>A70F6A1D-0195-42a2-934C-D8AC0F7C08EB</name>
<status>X</status>
<command>rundll32.exe E6F1873B.DLL,D9EBC318C</command>
<description>BrowserAid/BrowserPal, http://research.sunbelt-software.com/threat_display.cfm?name=BrowserAid&amp;threatid=3342&amp;search=browseraid Foistware</description>
<infourl>http://www.castlecops.com/startuplist-5621.html</infourl>
</item>
<item>
<name>aa bbcc dde effgghh jj</name>
<status>X</status>
<command>update.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17079.html</infourl>
</item>
<item>
<name>AAACLEAN</name>
<status>?</status>
<command>AAACLEAN.INF</command>
<description>&lt;font color=&quot;#FF0000&quot;&gt;??&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-68.html</infourl>
</item>
<item>
<name>AAAKeyboard</name>
<status>?</status>
<command>??</command>
<description>&lt;font color=\&quot;#FF0000\&quot;&gt;??&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-69.html</infourl>
</item>
<item>
<name>AAATraySaver</name>
<status>N</status>
<command>TraySaver.exe</command>
<description>System Tray management utility from &lt;a href=&quot;http://www.mlin.net/&quot; target=&quot;_blank&quot;&gt;Mike Lin&lt;/a&gt; which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray</description>
<infourl>http://www.castlecops.com/startuplist-70.html</infourl>
</item>
<item>
<name>AAK</name>
<status>U</status>
<command>aak.exe</command>
<description>&lt;a href=\&quot;http://www.anti-keylogger.net/\&quot; target=\&quot;_blank\&quot;&gt;Advanced Anti-Keylogger&lt;/a&gt; - \&quot;Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere\&quot;</description>
<infourl>http://www.castlecops.com/startuplist-71.html</infourl>
</item>
<item>
<name>aaLDISCN32</name>
<status>U</status>
<command>LDISCN32.EXE</command>
<description>Related to LANDesk®_Management, http://www.landesk.com/ Agent from LANDesk Software. [red]Note:[/red] Located in \%ROOT%\LDClient\</description>
<infourl>http://www.castlecops.com/startuplist-15921.html</infourl>
</item>
<item>
<name>aaLDTaskCompletion</name>
<status>U</status>
<command>amclient.EXE</command>
<description>Related to LANDesk®_Management, http://www.landesk.com/ Agent from LANDesk Software. [red]Note:[/red] Located in \%ROOT%\LDClient\</description>
<infourl>http://www.castlecops.com/startuplist-15920.html</infourl>
</item>
<item>
<name>AAMSFree702</name>
<status>X</status>
<command>sys.exe</command>
<description>Added by the BackDoor-CPC backdoor TROJAN!</description>
<infourl>http://www.castlecops.com/startuplist-14720.html</infourl>
</item>
<item>
<name>Aaou</name>
<status>X</status>
<command>amee.exe</command>
<description>PurityScan/Clickspring, http://research.sunbelt-software.com/threat_display.cfm?name=ClickSpring.PuritySCAN&amp;threatid=10115 Adware</description>
<infourl>http://www.castlecops.com/startuplist-5217.html</infourl>
</item>
<item>
<name>Aapp</name>
<status>X</status>
<command>adprot</command>
<description>AdBlaster, http://www.symantec.com/avcenter/venc/data/adware.adblaster.html adware</description>
<infourl>http://www.castlecops.com/startuplist-8050.html</infourl>
</item>
<item>
<name>aauclient</name>
<status>?</status>
<command>ACNUpdater.exe</command>
<description>Appears to be related to software from Accenture.com, http://www.accenture.com/xd/xd.asp?it=enweb&amp;xd=index.xml - [red]what does it do and is it required?[/red]</description>
<infourl>http://www.castlecops.com/startuplist-10274.html</infourl>
</item>
<item>
<name>AAW</name>
<status>N</status>
<command>Ad-Aware.exe</command>
<description>Related to Ad-Aware_SE, http://www.lavasoftusa.com/ from Lavasoft. AdAware removal tool. [red]Note:[/red] Located in \%Program Files%\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe</description>
<infourl>http://www.castlecops.com/startuplist-15646.html</infourl>
</item>
<item>
<name>AAWTray</name>
<status>Y</status>
<command>AAWTray.exe</command>
<description>Part of Ad-aware 2007</description>
<infourl>http://www.castlecops.com/startuplist-15468.html</infourl>
</item>
<item>
<name>ab EazyScheduler</name>
<status>?</status>
<command>ezsched.exe</command>
<description>&lt;font color=\&quot;#FF0000\&quot;&gt;??&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-72.html</infourl>
</item>
<item>
<name>abass</name>
<status>X</status>
<command>abass.exe</command>
<description>Added by a variant of the Email-Worm.Win32.Zhelatin, http://www.bleepingcomputer.com/startups/abass.exe-23108.html worm and IRC backdoor. [red]Note:[/red] located in \%WINDIR%\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17091.html</infourl>
</item>
<item>
<name>ABBYY Community Agent</name>
<status>N</status>
<command>CAGENT.EXE</command>
<description>Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the&amp;nbsp;5.0 version of the software</description>
<infourl>http://www.castlecops.com/startuplist-73.html</infourl>
</item>
<item>
<name>ABC</name>
<status>X</status>
<command>keylogger.exe</command>
<description>Monitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by &lt;a href=&quot;http://www.spycop.com/index.html&quot; target=&quot;_blank&quot;&gt;SpyCop&lt;/a&gt; in their &lt;a href=&quot;http://www.spycop.com/faq.htm&quot; target=&quot;_top&quot;&gt;FAQ&lt;/a&gt;</description>
<infourl>http://www.castlecops.com/startuplist-74.html</infourl>
</item>
<item>
<name>abcdefgh</name>
<status>X</status>
<command>abcdefgh.exe</command>
<description>DOWNLOADER.EPJ, http://www.securitystronghold.com/gates/spyware-adware-solutions/abcdefgh_abcdefgh.exe_solution.htm TROJAN! </description>
<infourl>http://www.castlecops.com/startuplist-11641.html</infourl>
</item>
<item>
<name>ABIT uGuru</name>
<status>U</status>
<command>uGuru.exe</command>
<description>Related to ABIT_Computer, http://www.abit-usa.com/  Provides quick access to several Abit motherboard utilities - such as monitoring cpu temperature, fan speeds, overclocking, flashing of BIOS</description>
<infourl>http://www.castlecops.com/startuplist-12613.html</infourl>
</item>
<item>
<name>ABITEQ</name>
<status>N</status>
<command>abiteq.exe</command>
<description>Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds.</description>
<infourl>http://www.castlecops.com/startuplist-7902.html</infourl>
</item>
<item>
<name>Abrada WIN32</name>
<status>X</status>
<command>abrada.exe</command>
<description>Added by the Troj/Dermon-G, http://www.sophos.com/virusinfo/analyses/trojdermong.html TROJAN! [red]Note[/red]: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) [red]Can severely compromise system security, stealth installed.[/red]</description>
<infourl>http://www.castlecops.com/startuplist-12733.html</infourl>
</item>
<item>
<name>ABRegmon</name>
<status>Y</status>
<command>ABregmon.exe</command>
<description>ArcaVir, http://www.arcabit.com/ Antivirus</description>
<infourl>http://www.castlecops.com/startuplist-17405.html</infourl>
</item>
<item>
<name>Absolute Shield</name>
<status>U</status>
<command>dseraser.exe</command>
<description>Absolute Shield/Evidence Eliminator - internet history eraser, http://www.auditmypc.com/process/dseraser.asp</description>
<infourl>http://www.castlecops.com/startuplist-75.html</infourl>
</item>
<item>
<name>Absolute StartUp monitor</name>
<status>U</status>
<command>ASMon.exe</command>
<description>&lt;a href=\&quot;http://www.fgroupsoft.com/Absolutestartup/\&quot; target=\&quot;_blank\&quot;&gt;Absolute Startup&lt;/a&gt; - startup monitor from F-Group Software</description>
<infourl>http://www.castlecops.com/startuplist-76.html</infourl>
</item>
<item>
<name>AbsoluteShield Internet Eraser</name>
<status>Y</status>
<command>cseraser.exe</command>
<description>Related to AbsoluteShield_Internet_Eraser, http://www.spyany.com/files/cseraser_exe.html application. [red]Note[/red]: located in C:\Program Files\SysShield Tools\Internet Eraser\</description>
<infourl>http://www.castlecops.com/startuplist-12857.html</infourl>
</item>
<item>
<name>ABsr</name>
<status>X</status>
<command>absr.exe</command>
<description>Added as a result of the &lt;a href=\&quot;http://securityresponse.symantec.com/avcenter/venc/data/backdoor.autoupder.html\&quot; target=\&quot;_blank\&quot;&gt;AUTOUPDER&lt;/a&gt; VIRUS!</description>
<infourl>http://www.castlecops.com/startuplist-77.html</infourl>
</item>
<item>
<name>absr</name>
<status>X</status>
<command>mwsvm.exe</command>
<description>SeekSeek search hijacker related - See here, http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_SECTHOUGHT.A&amp;VSect=Sn</description>
<infourl>http://www.castlecops.com/startuplist-78.html</infourl>
</item>
<item>
<name>abtu</name>
<status>X</status>
<command>mp3serch.exe</command>
<description>Loads the executable for &lt;a href=&quot;http://www.spywareinfo.com/lop.html&quot; target=&quot;_blank&quot;&gt;Lop.com&lt;/a&gt;. mp3serch.exe is the final version whilst lopsearch.exe is the beta version</description>
<infourl>http://www.castlecops.com/startuplist-79.html</infourl>
</item>
<item>
<name>abtu</name>
<status>X</status>
<command>lopsearch.exe</command>
<description>Loads the executable for LOP, http://www.spywareinfo.com/lop.html adware -  mp3serch.exe is the final version whilst lopsearch.exe is the beta version</description>
<infourl>http://www.castlecops.com/startuplist-6488.html</infourl>
</item>
<item>
<name>AbyssWebServer</name>
<status>U</status>
<command>abyssws.exe</command>
<description>&lt;a href=&quot;http://abyss.sourceforge.net/&quot; target=&quot;_blank&quot;&gt;Abyss&lt;/a&gt; web server</description>
<infourl>http://www.castlecops.com/startuplist-80.html</infourl>
</item>
<item>
<name>Ac97Sound</name>
<status>X</status>
<command>snddrv.exe</command>
<description>Detected as Mal/SillyFDC-A by sophos</description>
<infourl>http://www.castlecops.com/startuplist-14688.html</infourl>
</item>
<item>
<name>AcBtnMgr_Xxx</name>
<status>Y</status>
<command>AcBtnMgr_Xxx.exe</command>
<description>Associated with the Lexmark Xxx (where &amp;quot;xx&amp;quot; is the model) all-in-one printer/scanner/copier. Required for correct operation</description>
<infourl>http://www.castlecops.com/startuplist-81.html</infourl>
</item>
<item>
<name>acc</name>
<status>U</status>
<command>acc.exe</command>
<description>&lt;a href=\&quot;http://www.voicecallcentral.com/#advanced_call_center\&quot; target=\&quot;_blank\&quot;&gt;Advanced Call Center&lt;/a&gt; - \&quot;full-featured yet easy-to-use answering machine software for your voice modem\&quot;</description>
<infourl>http://www.castlecops.com/startuplist-82.html</infourl>
</item>
<item>
<name>ACCDEFRAGINFO</name>
<status>X</status>
<command>(path to file)</command>
<description>Added by the W32/Darby-O, http://www.sophos.com/virusinfo/analyses/w32darbyo.html WORM!</description>
<infourl>http://www.castlecops.com/startuplist-5594.html</infourl>
</item>
<item>
<name>Accelerate</name>
<status>U</status>
<command>accelerate.exe</command>
<description>Webroot &lt;a href=&quot;http://www.webroot.com/wb/products/accelerate/index.php&quot; target=&quot;_blank&quot;&gt;Accelerate&lt;/a&gt; - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection</description>
<infourl>http://www.castlecops.com/startuplist-83.html</infourl>
</item>
<item>
<name>Access Control App</name>
<status>X</status>
<command>winsto.exe</command>
<description>Identified as a variant of the Win32/TrojanDownloader.Small.CYF Trojan. [red]Note:[/red] Located in \%Temp%\</description>
<infourl>http://www.castlecops.com/startuplist-16150.html</infourl>
</item>
<item>
<name>Access Ramp Monitor</name>
<status>N</status>
<command>armon32.exe</command>
<description>Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again</description>
<infourl>http://www.castlecops.com/startuplist-84.html</infourl>
</item>
<item>
<name>Access WebControl</name>
<status>X</status>
<command>[path to file]</command>
<description>Added by the TROJ/PPDOOR-M, http://www.sophos.com/virusinfo/analyses/trojppdoorm.html TROJAN!
</description>
<infourl>http://www.castlecops.com/startuplist-10296.html</infourl>
</item>
<item>
<name>AccessManager</name>
<status>U</status>
<command>AccessMgr.exe</command>
<description>Part of SmartPipes SecureSite, http://www.smartpipes.com/SecureSite.htm software - &quot;SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management&quot; 

</description>
<infourl>http://www.castlecops.com/startuplist-10165.html</infourl>
</item>
<item>
<name>AccessMedia P2P Loader</name>
<status>X</status>
<command>amp2pl.exe</command>
<description>My AccessMedia toolbar related,  stealth installed!</description>
<infourl>http://www.castlecops.com/startuplist-7948.html</infourl>
</item>
<item>
<name>AccessoriesPlus</name>
<status>U</status>
<command>clockplus.exe</command>
<description>&quot;Clock Plus&quot;,  part of Accessories_Plus, http://simplypowerful.com/software/accessoriesplus.html allows you to select from dozens of alternatives for the Windows clock.</description>
<infourl>http://www.castlecops.com/startuplist-11336.html</infourl>
</item>
<item>
<name>AccessRamp Monitor01</name>
<status>N</status>
<command>ARMon32a.exe</command>
<description>From a visitor &amp;quot;Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service.&amp;quot;</description>
<infourl>http://www.castlecops.com/startuplist-85.html</infourl>
</item>
<item>
<name>AccessRampLAN01</name>
<status>N</status>
<command>ARUpld32.exe</command>
<description>Version of the above for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003</description>
<infourl>http://www.castlecops.com/startuplist-86.html</infourl>
</item>
<item>
<name>AcctMgr</name>
<status>U</status>
<command>AcctMgr.exe</command>
<description>Norton™ Password Manager - part of &lt;a href=\&quot;http://www.symantec.com/sabu/sysworks/basic/\&quot; target=\&quot;_blank\&quot;&gt;Norton SystemWorks 2004&lt;/a&gt; - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities—all from the safety of your own PC</description>
<infourl>http://www.castlecops.com/startuplist-87.html</infourl>
</item>
<item>
<name>AccuWeather.com® Desktop</name>
<status>N</status>
<command>AccuWeatherDesktop.exe</command>
<description>Desktop weather from http://home.accuweather.com/index.asp?partner=accuweather AccuWeather
</description>
<infourl>http://www.castlecops.com/startuplist-15336.html</infourl>
</item>
<item>
<name>accwizz.exe</name>
<status>X</status>
<command>accwizz.exe</command>
<description>Added by the W32.Ruland.A, http://securityresponse.symantec.com/avcenter/venc/data/w32.ruland.a@mm.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-11021.html</infourl>
</item>
<item>
<name>accwizzz.exe</name>
<status>X</status>
<command>accwizzz.exe</command>
<description>Added by the W32.Ruland.A, http://securityresponse.symantec.com/avcenter/venc/data/w32.ruland.a@mm.html
 WORM!
</description>
<infourl>http://www.castlecops.com/startuplist-11022.html</infourl>
</item>
<item>
<name>acdllib3</name>
<status>X</status>
<command>bcdlmem.exe</command>
<description>Added by the Troj/Mailbot-BA, http://www.sophos.com/security/analyses/trojmailbotba.html TROJAN! [red]Note:[/red] This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)</description>
<infourl>http://www.castlecops.com/startuplist-13617.html</infourl>
</item>
<item>
<name>ACDSee</name>
<status>U</status>
<command>ACDSee8Pro.exe</command>
<description>Related to ACDSee, http://www.acdsee.com/ 8 photo software. Organize, manage, enhance, and share all your valued photo memories. [red]Note:[/red] Located in C:\Program Files\ACD Systems\ACDSee\8.0.Pro\</description>
<infourl>http://www.castlecops.com/startuplist-13115.html</infourl>
</item>
<item>
<name>Acecad.Wtxpload</name>
<status>Y</status>
<command>Wtxpload.exe Acecad</command>
<description>driver for an AceCad, http://www.acecad.com.tw/eng/product.htm USB Graphics Tablet</description>
<infourl>http://www.castlecops.com/startuplist-5624.html</infourl>
</item>
<item>
<name>AceGain LiveUpdate</name>
<status>N</status>
<command>LiveUpdate.exe</command>
<description>AceGain_LiveUpdate, http://gameone.acegain.com/ . &quot;AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences.&quot;</description>
<infourl>http://www.castlecops.com/startuplist-5580.html</infourl>
</item>
<item>
<name>Acer ePower Management</name>
<status>U</status>
<command>Acer ePower Management.exe</command>
<description>Related to Acer_ePower, http://global.acer.com/products/et/index.htm Management from Acer Empowering Technology [red]Note:[/red] Located in C:\Acer\Empowering Technology\ePower\</description>
<infourl>http://www.castlecops.com/startuplist-13152.html</infourl>
</item>
<item>
<name>Acer ePresentation HPD</name>
<status>U</status>
<command>ePresentation.exe</command>
<description> Allows you to connect your Acer laptop to a projector.</description>
<infourl>http://www.castlecops.com/startuplist-15654.html</infourl>
</item>
<item>
<name>Acer Product Registration</name>
<status>N</status>
<command>ACE1.exe</command>
<description>Related to Acer_Product_Registration, http://www.acer.com.my/service/warr_register/warr_register.aspx Remove when registration is completed. [red]Note:[/red] Located in \%Program Files%\Acer Registration\</description>
<infourl>http://www.castlecops.com/startuplist-15880.html</infourl>
</item>
<item>
<name>Acer Tour Reminder
</name>
<status>N</status>
<command>Reminder.exe</command>
<description>Popup reminder to take the tour of your new Acer laptop.</description>
<infourl>http://www.castlecops.com/startuplist-16205.html</infourl>
</item>
<item>
<name>AcerGoto</name>
<status>U</status>
<command>AcerGoto.exe</command>
<description>Acer Computer &quot;Goto Drive&quot;  Cold Swap Driver -  a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer.</description>
<infourl>http://www.castlecops.com/startuplist-10403.html</infourl>
</item>
<item>
<name>AcerNotebookManager</name>
<status>U</status>
<command>almxptray.exe</command>
<description>System Tray access on some Acer Notebooks to give faster access to system settings</description>
<infourl>http://www.castlecops.com/startuplist-89.html</infourl>
</item>
<item>
<name>AcerPowerkey</name>
<status>U</status>
<command>Powerkey.exe</command>
<description>PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3</description>
<infourl>http://www.castlecops.com/startuplist-90.html</infourl>
</item>
<item>
<name>Acess2007a</name>
<status>X</status>
<command>access2007a.exe</command>
<description>Added by  a variant of the W32/Gaobot.PQA.worm network worm and IRC backdoor.</description>
<infourl>http://www.castlecops.com/startuplist-15176.html</infourl>
</item>
<item>
<name>Aceu</name>
<status>X</status>
<command>[random file name]</command>
<description>PurityScan/Clickspring, http://research.sunbelt-software.com/threat_display.cfm?name=ClickSpring.PuritySCAN&amp;threatid=10115 Adware</description>
<infourl>http://www.castlecops.com/startuplist-10851.html</infourl>
</item>
<item>
<name>AceUtils</name>
<status>N</status>
<command>au.exe</command>
<description>Related to Ace Utilities from Acelogix_Software, http://www.acelogix.com/aceutils.html
Note:  this is NOT to be confused with the au.exe used by the BEAGLE.B, http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.b@mm.html worm!</description>
<infourl>http://www.castlecops.com/startuplist-12019.html</infourl>
</item>
<item>
<name>acEventServ</name>
<status>Y</status>
<command>acevtsrv.exe</command>
<description>Related to ActivCard, http://www.actividentity.com/ Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. [red]Note:[/red] Located in \%Program Files%\ActivCard\ActivCard Gold\</description>
<infourl>http://www.castlecops.com/startuplist-15395.html</infourl>
</item>
<item>
<name>AClntUsr</name>
<status>U</status>
<command>AClntUsr.exe</command>
<description>Altiris AClient, http://www.cdg-group.com/go.exe?prodid=299 Service Windows Tray Icon </description>
<infourl>http://www.castlecops.com/startuplist-10514.html</infourl>
</item>
<item>
<name>Acme.PCHButton</name>
<status>N</status>
<command>pchbutton.exe</command>
<description>Used by HP Instant Support</description>
<infourl>http://www.castlecops.com/startuplist-4857.html</infourl>
</item>
<item>
<name>ACMonitor_Xxx</name>
<status>Y</status>
<command>ACMonitor_Xxx.exe</command>
<description>Associated with the Lexmark Xxx (where &amp;quot;xx&amp;quot; is the model) all-in-one printer/scanner/copier. Required for correct operation</description>
<infourl>http://www.castlecops.com/startuplist-91.html</infourl>
</item>
<item>
<name>acocash</name>
<status>X</status>
<command>fastdown.exe, fastfown.exe</command>
<description>Adult content dialler</description>
<infourl>http://www.castlecops.com/startuplist-92.html</infourl>
</item>
<item>
<name>Acombo3dmouse</name>
<status>U</status>
<command>Acombo3d.exe</command>
<description>Mouse driver - required if you use non-standard Windows driver features</description>
<infourl>http://www.castlecops.com/startuplist-93.html</infourl>
</item>
<item>
<name>Aconti</name>
<status>X</status>
<command>aconti.exe</command>
<description>Adult content dialler</description>
<infourl>http://www.castlecops.com/startuplist-94.html</infourl>
</item>
<item>
<name>acoustic</name>
<status>U</status>
<command>acoustic.exe</command>
<description>Control panel program for Philips &lt;a href=&quot;http://www.consumer.philips.com/global/b2c/ce/catalog/product.jhtml;jsessionid=5ZTUCSVZIGCWUCRQNFJRX1YKGBUEWHAW?divId=0&amp;amp;groupId=PCSTUFF&amp;amp;catId=&amp;amp;subCatId=SOUNDCARDS&amp;amp;productId=PSC706_05&quot; target=&quot;_blank&quot;&gt; Acoustic Edge&lt;/a&gt; soundcard. Not required unless changed settings aren't retained</description>
<infourl>http://www.castlecops.com/startuplist-95.html</infourl>
</item>
<item>
<name>acpart</name>
<status>N</status>
<command>agpart11.exe</command>
<description>Program for finding trucks on-line</description>
<infourl>http://www.castlecops.com/startuplist-96.html</infourl>
</item>
<item>
<name>Acrobat</name>
<status>X</status>
<command>acrmon32.exe</command>
<description>Added by the Troj/Small-ECT, http://www.sophos.com/security/analyses/trojsmallect.html?_log_from=rss TROJAN! [red]Note:[/red] Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)</description>
<infourl>http://www.castlecops.com/startuplist-14075.html</infourl>
</item>
<item>
<name>Acrobat Assistant</name>
<status>U</status>
<command>ACROTRAY.EXE</command>
<description>Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the \&quot;U\&quot; recommendation</description>
<infourl>http://www.castlecops.com/startuplist-97.html</infourl>
</item>
<item>
<name>Acrobat Assistant 8.0</name>
<status>N</status>
<command>Acrotray.exe</command>
<description>Related to Acrobat_Assistant, http://www.liutilities.com/products/wintaskspro/processlibrary/acrotray/ a process belonging to the Adobe Acrobat Traybar Assistant which provides a shortcut to additional configuration options for Adobe products.
[red]Note:[/red] Located in C:\Program Files\Adobe\Acrobat 8.0\Acrobat\</description>
<infourl>http://www.castlecops.com/startuplist-14983.html</infourl>
</item>
<item>
<name>Acrobat Read</name>
<status>X</status>
<command>acroup32.exe</command>
<description>Troj/VanBot-BQ, http://www.sophos.com/security/analyses/trojvanbotbq.html </description>
<infourl>http://www.castlecops.com/startuplist-14169.html</infourl>
</item>
<item>
<name>ACROMOUSE</name>
<status>U</status>
<command>ACROMAPP.exe</command>
<description>Related to ACROMOUSE, http://www.acroxusa.com/ Laser mouse control. [red]Note:[/red] Located in C:\Program Files\Tech\Office Program Selector\2.0\</description>
<infourl>http://www.castlecops.com/startuplist-14978.html</infourl>
</item>
<item>
<name>Acronis Popup Blocker</name>
<status>U</status>
<command>Blocker.dll,Run</command>
<description>Related to Acronis, http://www.acronis.com/ Privacy Expert - anti-spyware and security suite.</description>
<infourl>http://www.castlecops.com/startuplist-12757.html</infourl>
</item>
<item>
<name>Acronis Scheduler Helper</name>
<status>U</status>
<command>schedhlp.exe</command>
<description>Part of http://www.acronis.com/homecomputing/products/trueimage/ Acronis True Image - backup software. Co-operates with the &quot;schedul2.exe&quot; service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images
</description>
<infourl>http://www.castlecops.com/startuplist-14947.html</infourl>
</item>
<item>
<name>Acronis Scheduler2 Service</name>
<status>U</status>
<command>schedhlp.exe</command>
<description>Part of http://www.acronis.com/homecomputing/products/trueimage/ Acronis True Image - backup software. Co-operates with the &quot;schedul2.exe&quot; servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images
</description>
<infourl>http://www.castlecops.com/startuplist-98.html</infourl>
</item>
<item>
<name>Acronis True Image</name>
<status>Y</status>
<command>TimounterMonitor.exe</command>
<description>Part of Acronis_True_Image, http://www.acronis.com/homecomputing/products/trueimage  backup software. Monitor for the backup archive explorer for moving and viewing files within an archive
</description>
<infourl>http://www.castlecops.com/startuplist-14821.html</infourl>
</item>
<item>
<name>Acronis True Image Monitor</name>
<status>N</status>
<command>TrueImageMonitor.exe</command>
<description>Part of http://www.acronis.com/homecomputing/products/trueimage/ Acronis True Image - backup software. Can be disabled without affecting TrueImage
</description>
<infourl>http://www.castlecops.com/startuplist-7170.html</infourl>
</item>
<item>
<name>Acronis TrueImage Monitor</name>
<status>N</status>
<command>TrueImageMonitor.exe</command>
<description>Part of http://www.acronis.com/homecomputing/products/trueimage/ Acronis True Image - backup software. Can be disabled without affecting TrueImage
</description>
<infourl>http://www.castlecops.com/startuplist-99.html</infourl>
</item>
<item>
<name>AcronisTimounterMonitor</name>
<status>U</status>
<command>TimounterMonitor.exe</command>
<description>Related to Acronis_TrueImage, http://www.acronis.com/ a backup utility by Acronis. [red]Note:[/red] Located in C:\Program Files\Acronis\TrueImageHome\</description>
<infourl>http://www.castlecops.com/startuplist-14242.html</infourl>
</item>
<item>
<name>AcronisTrueImage Monitor</name>
<status>N</status>
<command>TrueImageMonitor.exe</command>
<description>Part of http://www.acronis.com/homecomputing/products/trueimage/ Acronis True Image - backup software. Can be disabled without affecting TrueImage
</description>
<infourl>http://www.castlecops.com/startuplist-7171.html</infourl>
</item>
<item>
<name>Act! Preloader</name>
<status>U</status>
<command>Act8.exe</command>
<description>Sage Software's http://www.act.com/products/index.cfm ACT! &quot;enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships&quot;
</description>
<infourl>http://www.castlecops.com/startuplist-14147.html</infourl>
</item>
<item>
<name>Action Manager 32</name>
<status>N</status>
<command>am32.exe</command>
<description>Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -&amp;gt; Programs</description>
<infourl>http://www.castlecops.com/startuplist-100.html</infourl>
</item>
<item>
<name>ActionAgent</name>
<status>?</status>
<command>actionagent.exe</command>
<description>\&quot;A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client\&quot;. &lt;font color=\&quot;#FF0000\&quot;&gt;Is it required?&lt;/font&gt;</description>
<infourl>http://www.castlecops.com/startuplist-101.html</infourl>
</item>
<item>
<name>Activation</name>
<status>N</status>
<command>Activation.exe</command>
<description>Part of Microsoft Money</description>
<infourl>http://www.castlecops.com/startuplist-102.html</infourl>
</item>
<item>
<name>Activboard</name>
<status>U</status>
<command>MMKeybd.exe</command>
<description>Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the s