|
Startup Name
| Process Name
| Details |
X | .Prog | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | Administrator | winlogon.exe | "Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process |
X | BuildLab | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | ccApps | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | CueX44_stil_here | WINLOGON.EXE | "Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process |
X | Firewall auto setup | winlogon.exe | "Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
X | FriendlyTypeName | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | Generic Host Process for Win32 Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
X | ICQ Net | winlogon.exe | "Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
|
X | ICQNet | winlogon.exe | "Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Microsoft Visual SourceSafe | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | Microsoft Windows Logon Process | winlogon.exe | "Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | MSMSGS | winlogon.exe | "Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
|
X | msn | winlogon.exe | "Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
|
X | MSWinlogon | winlogon.exe | "Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
X | nvchost | winlogon.exe | "Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | NVIDIA Media Center Library | winlogon.exe | "Added by the AUTORUN-AZK WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | PaRaY_VM | winlogon.exe | "Added by the AUTORUN-DV WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
|
X | RealTimeProtector | winlogon.exe | "Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
|
X | RegDone | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | ROOT_Machine | winlogon.exe | "Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
|
X | RPCserr32g | winlogon.exe | "Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | RPCserv32g | WINLOGON.EXE | "Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | runwinlogon | winlogon.exe | "Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process |
X | SmansaApp | winlogon.exe | "Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | srv | winlogon.exe | "Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data"
|
X | System Update2 | winlogon.exe | "Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process |
X | TEXTCONV | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | Torjan Program | WINLOGON.EXE | "Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | urudjeffni | winlogon.exe | "Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | userinit | winlogon.exe | "Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | WinAuth | winlogon.exe | "Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Window UDP Control Servic | winlogon.exe | "Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Windows ARP Detectionc | winlogon.exe | "Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
X | Windows ARP Detectioncx | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
X | Windows Log Agent | winlogon.exe | "Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
|
X | Windows Logon | winlogon.exe | "Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
|
X | Windows Logon Application | winlogon.exe | "Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process |
X | Windows Logon Applicationedc | winlogon.exe | "Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
|
X | Windows Logon Applicatonedc | winlogon.exe | "Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
|
X | Windows Messanger Control Center | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Windows Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | winlogon | winlogon.exe | "Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Winlogon | WINLOGON.EXE | "Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process |
X | Winlogon.exe | N/A | "CoolWebSearch parasite variant - resets home page to an adult content site"
|
X | winlogon.exe | helper.exe | "Added by the FAKESPY-A TROJAN!"
|
X | winlogon.exe | msole32.exe | "Adware |
X | WMAudio | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | xp_system | winlogon.exe | "Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe |
DISCLAIMER: It is assumed that users are familiar with the operating
system they are using and comfortable with making the suggested changes. I will
not be held responsible if changes you make cause a system failure.
This is
NOT a list of tasks/processes taken from
Task Manager or the
Close Program window (
CTRL+ALT+DEL) but a list of startup
applications, although you will find some of them listed via this method.
Pressing CTRL+ALT+DEL identifies programs that are currently running - not
necessarily at startup. For a list of tasks/processes you should try
WinTasks 5 Standard/Professional from LIUtilities or the list at
AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL
just because it has an "X" recommendation, please check whether it's in MSCONFIG
or the registry first. An example would be "svchost.exe" - which doesn't appear
in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't
do anything.