Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

153 results found for Z

Startup Item or Name Status Command or Data Description Tested
7f8eXz****.exe 9idfDetected by Eset's NOD32 antivirus as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folderNo
647c21069130d325f036ca21984e0414Xz.exeDetected by Dr.Web as Trojan.DownLoader8.21159 and by Malwarebytes Anti-Malware as Trojan.FakeMediaNo
winuiXz.exeAdded by the KONDELI TROJAN!No
zaber0Xzaberg.exeDetected by Sophos as Troj/VB-FOV and Malwarebytes Anti-Malware as Backdoor.IRCBotNo
ZackerXZacker.exeAdded by the GEMEL WORM!No
Solutions Diagnostic Launcher UsermodeXzajlcqvvvg.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SDL. The file is located in %System%No
king_zaXzaking.exeAdded by the TATERF-AY WORM!No
jqehXzamnifrj.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %AppData%\Microsoft\ZamnifrjNo
!1_ProcessGuard_StartupXzamnifrj.exe /c procguard.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this is not the legitimate DiamondCS ProcessGuard which loads directly from %ProgramFiles%\ProcessGuard - this one copies "zamnifrj.exe" from %AppData%\Microsoft\Zamnifrj as %ProgramFiles%\ProcessGuard\procguard.exe and then runs itNo
Windows ConfigXZANBOR.EXEAdded by the SPYBOT-MH WORM!No
zangoXzango.exe180solutions adwareNo
ZangoSAXZangoSA.exeZango Search Assistant adwareNo
Zango SiteFinderXZangoSiteFinder.exeZangoSearch adware variantNo
Zango TvTimesXZangoTVTimes.exeZangoSearch adwareNo
Zango TvTimesXZANGOT~1.EXEZangoSearch adwareNo
[various names]Xzantu.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
zanuXzanu.exeZangoSearch adwareNo
SystemXZap.exeAdded by the MSNVB-D WORM!No
ZoneAlarm PlusYzaplus.exeOlder enhanced version of the ZoneAlarm firewall which was superseded by ZoneAlarm Pro and ZoneAlarm Internet Security SuiteNo
ZaproYzapro.exeOlder version of the ZoneAlarm Pro firewallNo
ZoneAlarm ProYzapro.exeOlder version of the ZoneAlarm Pro firewallNo
Win32Xzaq.exeAdded by the RBOT-GCE WORM!No
zatrayYZatray.exeSystem Tray access to and notifications for ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall. If this entry is disabled, the core product functions will work properly but the user will lose quick access to the main window and may miss notifications of potential problems and updatesYes
ZoneAlarmYZatray.exeSystem Tray access to and notifications for ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall. If this entry is disabled, the core product functions will work properly but the user will lose quick access to the main window and may miss notifications of potential problems and updatesYes
zaueradXzauerad.exeAdded by the VBKRYPT.AKRJ TROJAN!No
fe32e6b321a15a20570ae15a1efc1f36Xzaza.exeDetected by Dr.Web as Trojan.DownLoader7.21667 and by Malwarebytes Anti-Malware as Trojan.MSILNo
ZboardUZboard.exeSteelSeries (was Ideazon) Zboard gaming software - allows you to customise keyboard functionsNo
ZboardTrayUZboardTray.exeSteelSeries (was Ideazon) Zboard gaming software - allows you to customise keyboard functionsNo
zcb?zcb.exe??No
IntelZeroConfigUZCfgSvc.exeZero Config MFC Application, part of Intel's ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing "Not Responding" or "End this Program" shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have WinXP/2003, try setting the "Wireless Zero Configuration" service to disabledNo
ZcfgsvcUZCfgSvc.exeZero Config MFC Application, part of Intel's ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing "Not Responding" or "End this Program" shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have WinXP/2003, try setting the "Wireless Zero Configuration" service to disabledNo
ZCfgSvc.exeUZCfgSvc.exeZero Config MFC Application, part of Intel's ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing "Not Responding" or "End this Program" shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have WinXP/2003, try setting the "Wireless Zero Configuration" service to disabledNo
ZcxaxzXZcxaxz.exeDetected by Kaspersky as Worm.Win32.Ngrbot.dpl and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
ZDConfig?ZDConfig.exeRelated to various brands of Wireless USB LAN Adapter - what does it do and is it required?No
Zinio DLMNZDLM.EXEZinio - used to read magazines in digital rather than paper formatNo
802.11b+g USB Wireless LAN UtilityUZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Qualcomm Atheros) based chipsetsNo
Acer WLAN 11g USB DongleUZDWlan.exeWireless LAN configuration utility for an Acer wireless USB dongle based upon a ZyDAS (now acquired by Qualcomm Atheros) chipsetNo
ICIDU Wireless UtilityUZDWlan.exeWireless LAN configuration utility for an ICIDU wireless USB dongle based upon a ZyDAS (now acquired by Qualcomm Atheros) chipsetNo
Wireless 802.11g USB AdapterUZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Qualcomm Atheros) based chipsetsNo
Wireless Adapter ManagerUZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Qualcomm Atheros) based chipsetsNo
Wireless LAN USB DongleUZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Qualcomm Atheros) based chipsetsNo
XPC 802.11b+g Wireless UtilityUZDWlan.exeWireless LAN configuration utility for a Shuttle XPC Wireless LAN Kit - which is based upon ZyDAS (now acquired by Qualcomm Atheros) chipsetsNo
ZDWlanUZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Qualcomm Atheros) based chipsetsNo
ZDWLan UtilityUZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Qualcomm Atheros) based chipsetsNo
ZyAIR G-220 UtilityUZDWlan.exeZyXEL ZyAIR G-220 wireless LAN configuration utility - which is based upon ZyDAS (now acquired by Qualcomm Atheros) chipsetsNo
yahooXzebi.exeDetected by Malwarebytes Anti-Malware as Backdoor.Turkojan. The file is located in %Windir%No
zeluzXzeluz.exeAdded by the SILLYFDC-N MALWARE!No
Remote Management AgentUzenrc32.exePart of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstationNo
ZENRCYzenrc32.exeThe main component of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Leave well aloneNo
Zentimo xStorage ManagerUZentimo.exeZentimo xStorage Manager by Crystal Rich Ltd - "offers you an innovative approach to manage your USB & eSATA drives. While it solves many external drive related problems in Windows, it also gives more control on your devices and just makes working with external drives fun & pleasure"No
ZENRC Tray IconYzentray.exePart of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Best left aloneNo
zepmypvomohyXzepmypvomohy.exeDetected by McAfee as RDN/Generic BackDoor!dk and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
ZeroAdsUZeroads.exeZeroAds by FBM Software, Inc - culls ads, cookies and pop-ups. No longer availableNo
ZeroBoanXZeroBoan.exeZeroBoan rogue security software - not recommended, removal instructions hereNo
ZeroCleanXzerocup.exeZeroClean rogue security software - not recommended, removal instructions hereNo
ZeroSpywareUZeroSpyware.exeFBM Software ZeroSpyware 2004 spyware detector and removerNo
ZeroVaccineMainXZeroVaccine.exeZeroVaccine rogue security software - not recommended, removal instructions hereNo
ZipGenius CleanNzg.exeZipGenius file compression utilityNo
*zggjmydXzggjmyd.exeAdded by the AFCORE.O BACKDOOR!No
zggjmydXzggjmyd.exeAdded by the AFCORE.O BACKDOOR!No
ZGNUBI?ZGNUBI.exe??No
CHotKeyUzHotkey.exeEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended featuresNo
ϵͳע�ï½ï¿½ï¿½Xzhuruqi.exeAdded by the QHOST.V TROJAN!No
ziedXzied.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%No
zigwomzodupdXzigwomzodupd.exeDetected by Trend Micro as TROJ_JORIK.DMV and by Malwarebytes Anti-Malware as Trojan.Phex.THAGen6No
Zinaps7XZinaps7.exeZinaps Anti-Spyware 2008 rogue security software - not recommended, removal instructions hereNo
ZingSpoolerUZingSpooler.exeWas used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albumsNo
Zinio DLMNZinioDeliveryManager.exeRelated to Zinio used to read magazines in digital rather than paper formatNo
Agent5XZip01.exeDetected by Trend Micro as WORM_MYPICS.C and by Malwarebytes Anti-Malware as Worm.MyPicsNo
ziphelpXziphelp.exeCoolWebSearch parasite variantNo
Zip Driver LoaderXZipLoad32.exeDetected by Kaspersky as Backdoor.Win32.Oblivion.01.aNo
ZipLoader32.exeXZipLoader32.exeDetected by Trend Micro as BKDR_OBLIVION.ANo
ppsXziqidong.exeDetected by Dr.Web as Trojan.StartPage.45465 and by Malwarebytes Anti-Malware as Trojan.Agent.CNNo
testXzistro.exeAdded by the KIMAT-C TROJAN!No
ZENworks Imaging ServiceYZISWin.exeImaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management"No
-FreedomNeedsRebootYZkRunOnceR.exePart of internet security suites sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online. The exact purpose is unknown at this time and it shows no ill effects if disabled, but as the purpose is unknown and it's security related it should be left enabledYes
ZkRunOnceRYZkRunOnceR.exePart of internet security suites sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online. The exact purpose is unknown at this time and it shows no ill effects if disabled, but as the purpose is unknown and it's security related it should be left enabledYes
zlclientXzlclient.exeDetected by Symantec as Trojan.Syginre. Note - this is not the legitimate file used by older versions of the ZoneAlarm security products by Check Point Software Technologies Ltd and is located in %Root%No
zlclientYzlclient.exeSystem Tray access to and notifications for older versions of ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall. If this entry is disabled, the core product functions will work properly but the user will lose quick access to the main window and may miss notifications of potential problems and updatesYes
Zone Labs ClientYzlclient.exeSystem Tray access to and notifications for older versions of ZoneAlarm security products - including Internet Security Suite and Firewall. If this entry is disabled, the core product functions will work properly but the user will lose quick access to the main window and may miss notifications of potential problems and updatesYes
ZoneAlarm ClientYzlclient.exeSystem Tray access to and notifications for older versions of ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall. If this entry is disabled, the core product functions will work properly but the user will lose quick access to the main window and may miss notifications of potential problems and updatesYes
zone alarm securityXzlclint.exeAdded by the NIRBOT WORM!No
Norman ZANDAUZLH.EXESystem Tray icon for Norman AntivirusNo
ZLHUZLH.EXESystem Tray icon for Norman AntivirusNo
zli1lidy80Xzli1lidy80.exeAdded by the DWNLDR-JMW TROJAN!No
topatXzlip.exeAdded by the FLOOD-IG TROJAN!No
ZipMagicNzm32.exeZip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them firstNo
ZXzmon.exeAdded by the DELBOT-AO WORM!No
ZmoverUZMover.exeZmover by Basta Computing, Inc - "helps you manage your desktop layout by enabling you to set the size, position and layering of application windows. Instead of wasting time rearranging windows across your single or multiple monitor display, you can configure ZMover to do the job for you"No
Zekio StartupsXznksvc32.exeAdded by the AGOBOT-AGI WORM!No
ZNNXznnsvc.exeAdded by the SDBOT-DAA WORM!No
Zolero TranslatorXZoleroTranslator.exeZolero Translator - added by Clickspring, the makers of Purityscan, products and are bundled with the Outer Info Network Client, or OIN clientNo
Microsoft Update MachineXzonealarm.exeAdded by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!No
Winsock2 driverXZONEALARM.EXEAdded by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall programNo
ZoneAlarmYzonealarm.exeOlder version of the ZoneAlarm Free firewallNo
Winsock32driverXZoneAlarmPr0.exeAdded by the HACKARMY-B TROJAN!No
Winsock32driverXZoneLockup.exeAdded by the HACARMY.D TROJAN!No
ZoomUzoom.exeZoom - speeds up Windows startup and manages startup applicationsNo
ZoomingUZoomingHook.exeToshiba Zooming Utility - found on Toshiba laptops and Tablet PCs. It allows users to zoom in (or magnify) textNo
ZoomingHookUZoomingHook.exeToshiba Zooming Utility - found on Toshiba laptops and Tablet PCs. It allows users to zoom in (or magnify) textNo
zoorfatXzoorfat.exeAdded by the INHOO TROJAN!No
ZPLEDYZPKBDLED.exeDriver for the Advent ADE-AD2 Wireless KeyboardNo
Zero PoPup Killer XPUzpk_xp.exeIntelligent anti-pop-up software product by Ax-SoftNo
ZPOINT32YZPOINT32.exeUSB graphics/writing tablet driverNo
SystemSecurityXzprot32.exeAdded by the AGENT-FK TROJAN!No
Terminate PopupXZPU.exeFree Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see hereNo
Intel Common User InterfaceXzpyemhvct.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.ICU. The file is located in %CommonAppData%\Intel0No
star4XZred2.exeDetected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.BankerNo
StreamZap RemoteUzremote.exeStreamZap PC Remote - control Windows Media Player, iTunes, RealPlayer, Winamp, PowerPoint, MusicMatch Jukebox, and many other multimedia applicationsNo
Flash MediaXzrpk��'�'%''msn'�%'fix''.exeAdded by a variant of the IRCBOT BACKDOOR!No
OpenApizsXzrscbm.exeAdded by the AGENT.RLH TROJAN!No
MoveSearchXzsearch.exeDetected by Symantec as Adware.PigSearch and by Malwarebytes Anti-Malware as Adware.PigSearch. The file is located in %ProgramFiles%\HuaCi\huaciNo
WindowsXZser.exeAdded by the CULLER-D WORM!No
Andware DefenceXZsoft32.exeAdded by the GAOBOT.OO WORM!No
ZSSchedulerUzsscheduler.dllZeroSpyware from FBM SoftwareNo
ZSSnp211NZSSnp211.exeVimicro based webcam driver - as used by both internal (laptop) and external webcams from Vimicro themselves, A4tech, Canon and othersNo
zSearchXZstb.exeTotalVelocity zSearch parasiteNo
AdobeXzteam.exeAdded by an unidentified TROJAN!No
Jun LozadaXztescd32.exeDetected by Sophos as W32/AutoRun-XUNo
Microsoft Autorun14Xztinetzt.exeDetected by Symantec as W32.Ogleon.ANo
zts2.exeXzts2.exeDetected by Trend Micro as TSPY_ONLINEGA.ZP and by Malwarebytes Anti-Malware as PasswordStealer.LmirNo
Zune LauncherNZuneLauncher.exeAutomatically launches the Zune software for Microsoft's Zune media players when they're connected to your PC. The software can be used to manage media, rip and burn CDs/DVDs, create playlists, sync your player to your computer, etcYes
Zune®NZuneLauncher.exeAutomatically launches the Zune software for Microsoft's Zune media players when they're connected to your PC. The software can be used to manage media, rip and burn CDs/DVDs, create playlists, sync your player to your computer, etcYes
ZuneLauncherNZuneLauncher.exeAutomatically launches the Zune software for Microsoft's Zune media players when they're connected to your PC. The software can be used to manage media, rip and burn CDs/DVDs, create playlists, sync your player to your computer, etcYes
zunzudwekagyXzunzudwekagy.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
zupacha.exeXzupacha.exeAdded by the DROPPER-QL TROJAN!No
b3dUpdateXZupdate.exeAssociated with B3d Projector foistware - see hereNo
UpdateXZupdate.exeAssociated with B3d Projector foistware - see hereNo
ZupdateXZupdate.exeAssociated with B3d Projector foistware - see hereNo
OvisLink WL-5430USBUZUtility.exeWireless LAN configuration utility for the OvisLink WL-5430USB 802.11g Pen-Size WLAN USB AdapterNo
zuuijuqXzuuijuq.exeAdded by the SILLYFDC-T MALWARE!No
MSConfigXzvgzlwvo.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
Zvmtiezxgpnpyxnw.exeXZvmtiezxgpnpyxnw.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
icrosoft Visual InterDevcXzvslmqb.exeAdded by the RBOT-AYP WORM!No
chromeXzVZYJlTnrl.exeDetected by Dr.Web as Trojan.DownLoader4.23314. Note - this is not a legitimate Google Chrome browser fileNo
Windows Recylinder CheckXzwdomsgemw.exeAdded by the RBOT-EGJ WORM!No
ksrlnhmXzxatgso.exeAdded by the DLOADER-LI TROJAN!No
[various names]Xzxc.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
win_drivr32Xzxhstn.exeDetected by Trend Micro as TROJ_SMALL.CXONo
cdca408e3cbf7b0daaa425b5705221a4Xzxvbnmasfhjlqertyuiop.exeDetected by McAfee as RDN/Generic.dx!bb3 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
VasddwDgXzxXZwd.exeAdded by the SDBOT-SN WORM!No
ZyAIR B-122 UtilityUZyAIR.exeZyXEL ZyAIR B-122 wireless LAN configuration utilityNo
ZyAIR PCcard UtilityUZyAIR.exeZyXEL ZyAIR PCcard wireless LAN configuration utilityNo
ZyAIR USB UtilityUZyAIR.exeZyXEL ZyAIR wireless LAN configuration utilityNo
zyblasqumwanXzyblasqumwan.exeDetected by McAfee as RDN/Generic.tfr!a and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
ZynExploreXZynExplore.exeDetected by Malwarebytes Anti-Malware as Adware.Agent. The file is located in %UserTemp%No
zytyzykquldyXzytyzykquldy.exeDetected by McAfee as RDN/Downloader.a!g and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
dsdXzz.exeAdded by the RBOT-FOX WORM!No
zzbXzzb.exeIAGold adwareNo
zzb2Xzzb2.exeIAGold adwareNo
MSMSGNERXzzgf.exeAdded by the PWS-CCB TROJAN!No
gshpXzzgshp.vbsHomepage hi-jackerNo
Microsoft Security PanagersXzzoboony.exeAdded by the RBOT-AOI WORM!No

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home