|
|
Startup Name
| Process Name
| Details |
| X | | regedit.exe /s appboost.reg | "Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
|
| X | Ccao | regedit.exe | "Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This version resides in a ""mduu"" subfolder |
| X | Data789 | Regedit.exe ....data789.tmp | Homepage hijacker
|
| X | Internal | regedit.exe /s c[month number] | "Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir% |
| X | Microsoft Regestry Edit Manager | regedit.exe | "Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
|
| X | NeroCheck | regedit.exe | "Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD/DVD burning program. Also |
| X | OPQFile | regedit.exe /s ...rad03FA6.tmp | Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
|
| ? | PowerSet | Regedit.exe /s ...PowerSet_8100_CU.REG | "Appears to be Toshiba power management related"
|
| X | regedit | regedit.exe | "Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in %Windir$ and will not figure in Msconfig/Startup! This version resides in %System%"
|
| X | regedit | regedit.exe | "Added by the GANBATE.A WORM! Note that the legitimate Windows registry editor (regedit.exe) is located %Windir% and will not figure in Msconfig/Startup! This one is located in %Windir%\security\Database"
|
| X | Regedit32 | regedit.exe | Added by an unidentified WORM or TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%
|
| X | setupuser | regedit.exe setupuser.log | "Regfile in disguise - another CoolWebSearch parasite variant"
|
| X | Symantec Antivirus professional | regedit.exe | "Added by a variant of the FORBOT WORM! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
|
| X | SysSearch | Regedit.exe -s pcsearch.reg | "Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""pcsearch.reg"" file is located in %Windir%"
|
| X | SysSearch | Regedit.exe -s sysreg.reg | "Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""sysreg.reg"" file is located in %Windir%"
|
| X | SystemSearch | regedit.exe -s ie.reg | "Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""ie.reg"" is located in the root folder (ie |
| X | SystemSearch | regedit.exe -s sys.reg | "Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
|
| X | WinSP | [path] REGEDIT.EXE -s [path] sysreg.reg | "Added by the STARTPA-ME TROJAN!"
|
| X | [random name] | regedit.exe | "PurityScan adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup!"
|
DISCLAIMER: It is assumed that users are familiar with the operating
system they are using and comfortable with making the suggested changes. I will
not be held responsible if changes you make cause a system failure.
This is
NOT a list of tasks/processes taken from
Task Manager or the
Close Program window (
CTRL+ALT+DEL) but a list of startup
applications, although you will find some of them listed via this method.
Pressing CTRL+ALT+DEL identifies programs that are currently running - not
necessarily at startup. For a list of tasks/processes you should try
WinTasks 5 Standard/Professional from LIUtilities or the list at
AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL
just because it has an "X" recommendation, please check whether it's in MSCONFIG
or the registry first. An example would be "svchost.exe" - which doesn't appear
in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't
do anything.