| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
154 results found for Y
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| xpsystem | X | y.exe | CoolWebSearch parasite variant | No |
| USBGuard | X | Y0tninam.exe | Added by the AUTORUN-BHQ WORM! | No |
| 4z4p | X | y9ce8p.exe | Added by the VB-FND TROJAN! | No |
| YACC | U | YACC.exe | YACC (Yet Another Atomic Clock) from Tools&More - freeware utility that synchronizes your PC clock to a high precision atomic time clock | No |
| YAMAHA AC-XG Power Utility | ? | yacpower.exe | YAMAHA AC-XG Power Utility. What does it do and is it required? | No |
| Microsoft Driver Setup | X | yadrive32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %Windir% | No |
| yaemu.exe | X | yaemu.exe | Added by the WIN32.DNSCHANGER.S TROJAN! | No |
| s5r4etygs54rety | X | yagtser56j.exe | Detected by Dr.Web as Trojan.DownLoader7.8222 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| HAO567 | X | YAHD.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.YH. The file is located in %CommonFiles% | No |
| BitDefender for Yahoo! Messenger | U | yahmon.exe | Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website | No |
| 09fe2b66fa61cf510cd157f5fab34c41 | X | Yahoo Mesenger.exe | Detected by Dr.Web as Trojan.DownLoader7.23754 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| a3f3ce52c6b752619b1e6ed73ef85eae | X | Yahoo! Messenger.exe | Detected by McAfee as Trojan-FAUE!76AE25775E3D and by Malwarebytes Anti-Malware as Trojan.Ransom. Note - this is not the legitimate Yahoo! Messenger (YahooMessenger.exe) | No |
| 8f411d229e3193cfd4882e987d3dc984 | X | Yahoo!Messenger.exe | Detected by Dr.Web as Trojan.DownLoader8.21362 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| 361c5445242f9f7af5395145cc636e43 | X | YAHOO.exe | Detected by McAfee as Trojan-FAUE!753CCFCB7AD8 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| 8ef6e5fbcf93c20a9c240921a52d8776 | X | yahoo.exe | Detected by Dr.Web as Trojan.DownLoader7.3359 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Task Manager | X | yahoo.exe | Added by the QUATIM.A WORM! | No |
| Winhost | X | yahoo.exe | Detected by Sophos as Troj/Delf-KM | No |
| Winhost1 | X | yahoo.exe | Detected by Sophos as Troj/Delf-KM and by Malwarebytes Anti-Malware as Trojan.Clicker | No |
| Winhost2 | X | yahoo.exe | Detected by Sophos as Troj/Delf-KM and by Malwarebytes Anti-Malware as Trojan.Clicker | No |
| Winhost3 | X | yahoo.exe | Detected by Sophos as Troj/Delf-KM and by Malwarebytes Anti-Malware as Trojan.Clicker | No |
| Winhost4 | X | yahoo.exe | Detected by Sophos as Troj/Delf-KM and by Malwarebytes Anti-Malware as Trojan.Clicker | No |
| Yahoo Update | X | Yahoo.exe | Added by the YAHOO! TROJAN! | No |
| Yahoo!MessengerForVista | N | Yahoo.Messenger.YmApp.exe | Version of Yahoo! Messenger released specifically for Vista users - but now superseded | No |
| YCentral | U | YahooCentral.exe | Yahoo! Central - "alerts you if your default home page, search, or email is changed or if updates are available for your Yahoo! software. You can manage your default Internet settings and get updates to your software from Yahoo!" | No |
| Yahoo! Friend | N | YahooFriend.exe | Yahoo!_Friend - plug-in for Yahoo! Messenger that add lots of emoticons and windows effects | No |
| WINTASK | X | yahooicons.exe | Added by the MYTOB-HM WORM! | No |
| Messenger (Yahoo!) | N | YahooMessenger.exe | System Tray access to the Yahoo! Messenger instant messenger | Yes |
| WINDOWSYAHOO | X | YahooMessenger.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.YM | No |
| Yahoo! Messenger | N | YahooMessenger.exe | System Tray access to the Yahoo! Messenger instant messenger | Yes |
| Yahoo! Pager | N | YahooMessenger.exe | System tray access to an older version of the Yahoo! Messenger instant messenger | Yes |
| YahooMessenger | N | YahooMessenger.exe | System Tray access to the Yahoo! Messenger instant messenger | Yes |
| 3129e5b0a2b51b8ca183e6296bd71b8b | X | YahooMessiienge.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| YahooMonitor | U | YahooMonitor.exe | Yahoo Messenger Monitor Sniffer surveillance software for the Yahoo! instant messenger. Uninstall this software unless you put it there yourself | No |
| Yahoo Messenger | X | Yahoomsg.exe | Added by an unidentified WORM or TROJAN! | No |
| Yahoo Instant Messengar | X | YahooMsgr.exe | Added by the SDBOT BACKDOOR! | No |
| yahoomsgr | X | Yahoomsngr.exe | Detected by Trend Micro as WORM_AGOBOT.AKZ | No |
| Yahoo! Pager | N | YAHOOM~1.EXE | System tray access to an older version of the Yahoo! Messenger instant messenger | No |
| Launch YahooPOPs! at Windows startup | N | YAHOOPOPS.EXE | YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs | No |
| YahooToolbar | X | YahooToolbar.exe | Detected by Kaspersky as Trojan.Win32.Sasfis.amwv and by Malwarebytes Anti-Malware as Trojan.Ransom.UPL. Note - this is not a legitimate Yahoo! entry and the file is located in %AppData% | No |
| Yahoo! Widget Engine | U | YahooWidgetEngine.exe | Yahoo! Widget Engine lets you run little files called Widgets that can do pretty much whatever you want them to | No |
| Yahoo! Widgets | U | YahooWidgets.exe | Yahoo! Widgets lets you run little files called Widgets that can do pretty much whatever you want them to | No |
| yahoo_toolbar lptt01 | X | yahoo_toolbar.exe | RapidBlaster variant (in a "yahoo_toolbar" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| yahoo_toolbar ml097e | X | yahoo_toolbar.exe | RapidBlaster variant (in a "yahoo_toolbar" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| yaka.exe | X | yaka.exe | Detected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Yankee Clipper III | N | YankClip.exe | Yankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures, Richtext, URLS, etc - any size. Features printing, drag and drop, optional permanent storage of clippings. Familiar "Outlook" interface'. Freeware | No |
| Yapta Tracker | U | YaptaClient.exe | Yapta "make it easy for you to secure the best airfare deals available on the Web. We do this by giving you a tool to "tag" the trips you like while shopping online, then we track prices on these trips and alert you when prices drop" | No |
| Taskman | X | yaptm.exe | Added by the PALEVO-Z WORM! | No |
| Userinit | X | yapxoeg.exe | Detected by McAfee as Generic BackDoor.acx and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| YBrowser | N | ybrwicon.exe | SBC Yahoo! Browser system tray icon | No |
| YCMMirag Application | U | YCMMirage.exe | Part of YouCam from CyberLink - effects software for webcams. From the CyberLink forum: "YCMMirage.exe is a background process which will monitor if any AP is using our virtual driver. Once it is detected, YCMMirage will launch YouCam, and then YouCam will provide and share the webcam video to client APs" | Yes |
| YCMMirage | U | YCMMirage.exe | Part of YouCam from CyberLink - effects software for webcams. From the CyberLink forum: "YCMMirage.exe is a background process which will monitor if any AP is using our virtual driver. Once it is detected, YCMMirage will launch YouCam, and then YouCam will provide and share the webcam video to client APs" | Yes |
| YouCam Mirage | U | YCMMirage.exe | Part of YouCam from CyberLink - effects software for webcams. From the CyberLink forum: "YCMMirage.exe is a background process which will monitor if any AP is using our virtual driver. Once it is detected, YCMMirage will launch YouCam, and then YouCam will provide and share the webcam video to client APs" | Yes |
| YCR Start | X | YCR.exe | Detected by Dr.Web as Trojan.MulDrop2.50130 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| YDTMain.exe | X | YDTMain.exe | 180solutions adware | No |
| MSRegScan | U | YEKPND.exe | EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself | No |
| [random characters] | X | yesbron.com | Added by the BRONTOK-AI WORM and variants! | No |
| Tok-Cirrhatus-1959sarc | X | yesbron.com | Detected by Sophos as W32/Brontok-R | No |
| y1959sar | X | yesbron.com | Added by the BRONTOK-AK WORM and variants! | No |
| YesFile | X | YesFile.exe | Detected by Dr.Web as Trojan.DownLoader7.29662 | No |
| yespopup | X | yespopup.exe | Detected by Malwarebytes Anti-Malware as Adware.YesPopUp. The file is located in %ProgramFiles%\yespopup | No |
| Ecat | X | yetenyve.exe | Detected by Trend Micro as WORM_SDBOT.AXQ | No |
| You've Got Pictures Screensaver | U | ygpsstra.exe | AOL You've Got Pictures Screensaver | No |
| ylbrooht | X | ygtowvqtssd.exe | Added by the AGENT-NFX TROJAN! | No |
| Winamp Update | X | yhn.exe | Added by the SDBOT-ACR WORM! | No |
| Yhsmiles | N | YHsmiles.exe | Emoticons utility for Yahoo! Messenger | No |
| Azixegoira | X | yikylohi.exe | Added by the SDBOT.ASP WORM! | No |
| Flash_Player_Install | X | ying.exe | Constructor VC2000 malware | No |
| svchost | X | ying.exe | Constructor VC2000 malware | No |
| ying | X | ying.exe | Constructor VC2000 malware | No |
| explorer | X | Yinstall.exe | PurityScan/Clickspring adware | No |
| internet.exe | X | yinyin3345.vbs | Added by the YINI MACRO! | No |
| Taskman | X | yjty.exe | Added by the AGENT-OCS TROJAN! | No |
| MSRegScan | U | YKPND.exe | YKPMD surveillance software. Uninstall this software unless you put it there yourself | No |
| Ykwkwi | X | Ykwkwi.exe | Detected by Malwarebytes Anti-Malware as Worm.Dorkbot. The file is located in %AppData%\Microsoft | No |
| YLive.exe | N | Ylive.exe | Yahoo! Assistant (formerly 3721 Internet Assistant) - not recommended | No |
| Yahoo! Mail | U | YMailAdvisor.exe | Yahoo! Mail Advisor - informs you of any changes to your Yahoo! Mail settings (i.e., if your default mail client changes). Bundled with some Yahoo! programs, Toolbar or Messenger | No |
| YMailAdvisor | U | YMailAdvisor.exe | Yahoo! Mail Advisor - informs you of any changes to your Yahoo! Mail settings (i.e., if your default mail client changes). Bundled with some Yahoo! programs, Toolbar or Messenger | No |
| ymetray | N | ymetray.exe | Yahoo! Music system tray icon | No |
| YmEwGJXgpidLPI | X | YmEwGJXgpidLPI.exe | Added by the FAKEAV-CYN TROJAN! | No |
| Windows LoL Layer | X | ymllh.exe | Added by the RBOT-FSU WORM! | No |
| userinit | X | ymovpa.exe | Detected by McAfee as Generic.mfr and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Yahoo! | X | ymsgr_tray.exe | Detected by Trend Micro as BKDR_RARSTONE.A. Note - this is not the legitimate ymsgr_tray.exe process which is normally located in %ProgramFiles%\Yahoo!\Messenger - this one is located in %System% | No |
| YhooUpdates | X | ymsmsgs.exe | Added by the AGENT.AN TROJAN! | No |
| Yahoo! Messanger | X | ymsngr32.exe | Added by the WOOTBOT.HY WORM! Note - this should not be confused with Yahoo! Messenger | No |
| WINDOWS | X | ymssgr.exe | Added by the BCKDR-PS BACKDOOR! Note - deactivates the Microsoft Internet Connection Firewall (ICF) | No |
| YhooUapdates | X | ymssmsgs.exe | Added by a variant of the AGENT.AN TROJAN! | No |
| ynavmrcd.exe | X | ynavmrcd.exe | Added by the DLOADR-AVC TROJAN! | No |
| WIMMUN32 | X | ynjIQV8QvC2.exe | Added by the GBOT-I TROJAN! | No |
| yo | X | yo.exe | Detected by McAfee as Generic PWS.y | No |
| Microsoft Driver Setup | X | yodrive32.exe | Detected by Malwarebytes Anti-Malware as Worm.Palevo. The file is located in %Windir% | No |
| YOP | N | yop.exe | Dashboard Module for SBC Yahoo! Online Protection | No |
| YouCam | N | YouCam.exe | System Tray access to YouCam from CyberLink - effects software for webcams | Yes |
| YouCam Tray | N | YouCam.exe | System Tray access to YouCam from CyberLink - effects software for webcams | Yes |
| CyberLink YouCam Tray | N | YouCamTray.exe | System Tray access to YouCam from CyberLink - effects software for webcams | Yes |
| YouCam Mirror Tray icon | N | YouCamTray.exe | System Tray access to YouCam from CyberLink - effects software for webcams | Yes |
| YouCamTray | N | YouCamTray.exe | System Tray access to YouCam from CyberLink - effects software for webcams | Yes |
| YouPin | X | YouPin.exe | Detected by McAfee as RDN/Downloader.a!g and by Malwarebytes Anti-Malware as Trojan.Downloader.YP | No |
| Kris | X | YouPin2.exe | Detected by Sophos as Troj/Agent-AAPG and by Malwarebytes Anti-Malware as Trojan.Agent.YPN | No |
| System | X | YPager.exe | Added by the JUNTADOR.K TROJAN! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger | No |
| Yahoo Messenger | X | YPager.exe | Added by the RBOT-QO BACKDOOR! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger. This one is found in %System% | No |
| Yahoo! Messenger | N | ypager.exe | System tray access to an older version of the Yahoo! Messenger instant messenger | Yes |
| Yahoo! Pager | N | ypager.exe | System tray access to an older version of the Yahoo! Messenger instant messenger | Yes |
| ypager | N | ypager.exe | System tray access to an older version of the Yahoo! Messenger instant messenger | Yes |
| Ypager.exe | N | ypager.exe | System tray access to an older version of the Yahoo! Messenger instant messenger | Yes |
| ypager | X | ypagerr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %Windir%\system3232 | No |
| yahoo inc. | X | ypages.exe | Added by a variant of the SDBOT.62235D21 WORM! | No |
| YPC | U | ypc.exe | Yahoo Parental controls - "Let you decide what type of sites and Yahoo! services your kids can access" | No |
| 222qo3j | X | ypgz2y.exe | Added by the AGENT-RFJ TROJAN! | No |
| YPOPs | U | YPOPs | YPOPs! - an application that provides POP3 access to Yahoo! Mail. Yahoo! Mail disabled free access to its POP3 service in 2002. This application emulates a POP3 server and enables popular email clients like Outlook, Netscape, Eudora, Mozilla, etc., to download email from Yahoo! account | No |
| YPOPs | U | YPOPs.exe | YPOPs! - an application that provides POP3 access to Yahoo! Mail. Yahoo! Mail disabled free access to its POP3 service in 2002. This application emulates a POP3 server and enables popular email clients like Outlook, Netscape, Eudora, Mozilla, etc., to download email from Yahoo! account | No |
| yqbcfolmuryzdhbzilzi | X | yqbcfolmuryzdhbzilzi.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\yqbcfolmuryzdhbzilzi | No |
| yqClQMLyEMRydSo | X | yqClQMLyEMRydSo.exe | Added by the FAKEAV-DVB TROJAN! | No |
| Yahoo HP Reminder 1.1 | ? | yr.exe | ?? | No |
| YaAutoRepair | ? | yrepair.dll | Appears to be related to software from Yahoo China. What does it do and is it required? | No |
| zzx2m | X | yriryc5.exe | Detected by McAfee as W32/Virut.n.gen and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| Y!TunnelBasic | U | YTBasic.exe | Y!TunnelBasic add-on for Yahoo! Messenger - now replaced by Y!TunnelPro, which is now free | No |
| Rabipykuo | X | yten.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ransom. The file is located in %AppData%\Yqecc | No |
| ytewcxzsw | X | ytewcxzsw.exe | Added by the ONLINEG.YCL TROJAN! | No |
| Y!TunnelPro | U | YTPro.exe | Y!TunnelPro add-on for Yahoo! Messenger from Digital Asphyxia and Chet Simpson - adds features such as enhanced privacy, custom filtering and extensive visual improvements | No |
| YTrayMagic Lite 1 | Y | YTRAYMAGIC.EXE | YTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored | No |
| Y!TunnelPro | U | YTunnelPro.exe | Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia | No |
| userinit | X | ytvpoh.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| yuiabct | X | yuiabct.exe | Added by the ONLINEG.VPL TROJAN! | No |
| Duweculey | X | yujixit.exe | Added by the SDBOT.BRP WORM! | No |
| icifati | X | yujixit.exe | Added by the SDBOT.ZZH WORM! | No |
| iyelejiv | X | yujixit.exe | Added by the SDBOT.BJK WORM! | No |
| jete | X | yujixit.exe | Added by the SDBOT.BRT WORM! | No |
| lify | X | yujixit.exe | Added by a variant of W32/Sdbot.worm | No |
| sayimici | X | yujixit.exe | Added by a variant of W32/Sdbot.worm | No |
| uneri | X | yujixit.exe | Added by the SDBOT.BOO WORM! | No |
| upyxo | X | yujixit.exe | Added by the SDBOT.BIX WORM! | No |
| uwyw.exe | X | yujixit.exe | Added by the SDBOT.BGB WORM! | No |
| Windows Live Messenger | X | yUKTNyKxCNAAyIg.exe | Detected by Dr.Web as Trojan.AVKill.24470 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Yumgo's Homepage Protector V1 | U | YumgoHomepageProtector.exe | Yumgo's Homepage Protector | No |
| iexplorer | X | yupdater.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\yahoo!\messenger but this it not the legitimate automatic updater for older versions of Yahoo! Messenger which has the same filename and location and it loads via the HKLM\Run, HKLM\RunOnce & HKLM\RunOnceEx keys | No |
| \YUR##.exe | X | YUR##.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent - where # represents a number and the file is located in %System% | No |
| \YUR#.exe | X | YUR#.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent - where # represents a number and the file is located in %System% | No |
| userinit | X | ywcugnt.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Microsoft Driver Setup | X | ywdrive32.exe | Detected by Malwarebytes Anti-Malware as Worm.Palevo. The file is located in %Windir% | No |
| Windows Service Agent | X | ywgma.exe | Added by the RBOT.DZT BACKDOOR! | No |
| YWjcrFuitUsqdav | X | YWjcrFuitUsqdav.exe | Added by the FAKEAV-LI MALWARE! | No |
| ywwvc.exe | X | ywwvc.exe | Added by the STARTPA-HR TROJAN! | No |
| ywzizdon | X | ywzizdon.exe | Free_Scratch_Cards foistware | No |
| yz.exe | X | yz.exe | Detected by McAfee as PWS-LegMir.dll and by Malwarebytes Anti-Malware as PasswordStealer.Lmir | No |
| Y'z Dock | U | YzDock.exe | Y'z Dock by M.Yamaguchi - "is a program launcher like the dock in MacOS X. This was the first ever dock launcher made for Windows" | No |
| YzDock | U | YzDock.exe | Y'z Dock by M.Yamaguchi - "is a program launcher like the dock in MacOS X. This was the first ever dock launcher made for Windows" | No |
| YZH | X | YZH.exe | Added by the LEGMIR-BM VIRUS! | No |
| YZH.SYS | X | YZH.exe | Added by the PHILIS.C VIRUS! | No |
| Session TPM Control Compatibility Performance | X | yzhzapafx.exe | Detected by McAfee as Generic.bfr!ei | No |
| Y'z Shadow | U | YzShadow.exe | Y'z Shadow by M.Yamaguchi - 'adds a shadow effect to the windows in pursuit of the "beauty of a shadow". It also allows the user the option of making menus transparent' | No |
| YzShadow | U | YzShadow.exe | Y'z Shadow by M.Yamaguchi - 'adds a shadow effect to the windows in pursuit of the "beauty of a shadow". It also allows the user the option of making menus transparent' | No |
| Y'z Toolbar | U | YzToolBar.exe | Y'z Toolbar by M.Yamaguchi - "allows the user to change the toolbar icons in Explorer and Internet Explorer. The user can also create and add their own themes" | No |
| YzToolBar | U | YzToolBar.exe | Y'z Toolbar by M.Yamaguchi - "allows the user to change the toolbar icons in Explorer and Internet Explorer. The user can also create and add their own themes" | No |
| y_updater | X | y_updater.exe | Added by the WORSMEP.A TROJAN! | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |