|
|
Startup Name
| Process Name
| Details |
| X | WinXPService | lsass.exe | "Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
|
| X | WinXPService | taksmgr.exe | Identified as a variant of the IRC/Flood.tool malware
|
| X | WinXPService | Tskdbg.exe | "Added by the MDROP-BPQ TROJAN!"
|
| X | WinXPService | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""ctf"" sub-folder"
|
| X | WinXPService | mirc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | WinXPService | nero.exe | "Added by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%"
|
| X | WinXPService | taksmgr.exe | "Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
|
| X | WinXPService | taksmgr.exe | "Added by the KIRSUN.A BACKDOOR! The file is located in the root directory |
| X | WinXPService | wacult.exe | "Added by the KIRSUN.A BACKDOOR! The file is located in %Windir%\Fonts"
|
| X | WinXPService | wacult.exe | "Added by the KIRSUN.A BACKDOOR! The file is located in %System%\mnut"
|
DISCLAIMER: It is assumed that users are familiar with the operating
system they are using and comfortable with making the suggested changes. I will
not be held responsible if changes you make cause a system failure.
This is
NOT a list of tasks/processes taken from
Task Manager or the
Close Program window (
CTRL+ALT+DEL) but a list of startup
applications, although you will find some of them listed via this method.
Pressing CTRL+ALT+DEL identifies programs that are currently running - not
necessarily at startup. For a list of tasks/processes you should try
WinTasks 5 Standard/Professional from LIUtilities or the list at
AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL
just because it has an "X" recommendation, please check whether it's in MSCONFIG
or the registry first. An example would be "svchost.exe" - which doesn't appear
in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't
do anything.