List Information

Started by: Paul Collins

Maintained by: random/random, nasdaq, Vino Rosso
Startup List

The Startup List catalogues startup applications - not running processes.
For information on the difference, please see here.

These are entries for programs that can start automatically with your computer.

Status Key:
Y = Normally leave to run at start-up
N = Not required - often infrequently used tasks that can be started manually, if necessary
U = User's choice - depends whether a user deems it necessary
X = Malware, spyware, adware, or other potentially unwanted items
? = Currently unknown status
Search Results
(displaying 69 results)

Name Filename Description Status
Windows Serviceswinlogon.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.X
winlogon.exewinlogon.exeAdded by a variant of the SDBBOT Note: Located in \%WINDIR%\System32\drivers\ Note: Do not remove the legitimate file in \%WINDIR%\System32\ Note: Use SDFix under supervision.X
xp_systemwinlogon.exeAdded by the Troj/Krepper-G TROJAN! Note: Located in \%WINDIR%\inetndata\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
WMAudiowinlogon.exeAdded by the W32.Neveg.A@mm WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
WinlogonWINLOGON.EXEAdded by the W32/Punya-B WORM! Note: Located in \%AppData%\Windows\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
WINLOGONWINLOGON.vbsAdded by the VBS.Ypsan.F@mm WORM! Note: Located in \%WINDIR%\System\ Note: Do not remove the legitimate program file \%WINDIR%\System32\WScript.exeX
winlogonwinlogon.exeAdded by the Backdoor.Trodal TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
winlogonwinlogon.exeHijacker or adult content dialler. Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
winlogonwinlogon.exeWindows Logon Process - handles user logons described here Note: Located in \%WINDIR%\System32\ Note: Is malware if located in any other folder.Y
Windows Logon Applicationedcwinlogon.exeAdded by the Troj/DwnLdr-HGR TROJAN! Note: Located in \%UserProfile%\ Note: Use SDFix under supervision.X
Windows NT Update ManagerWinlogon.exeAdded by the W32/Agobot-NU WORM! Note: Located in \%WINDIR%\system\ Note: that those are zeroes in the filename and not capital "o" Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Windows NT Logon Applicationwinlogon.scrAdded by the W32/Rbot-ALP WORM! Note: Located in \%WINDIR%\system\X
Windows Messanger Control Centerwinlogon.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.X
Windows Logon Servicewinlogon.pifAdded by the W32/Rbot-AOU WORM! Note: Located in \%WINDIR%\system\X
Windows Logon Applicationwinlogon.exeAdded by the W32/Poebot-KW WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
Windows Log Agentwinlogon.exeAdded by the TR/Keylogger.avk - Trojan TROJAN! Note: Located in \%Program Files%\Common Files\ Note: Read the link, Keylogger steals information Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
Windows ARP Detectioncxwinlogon.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.X
Windows Login Serverwinlogon.exeIdentified by Kaspersky as Worm.Win32.AutoRun.atvs. Information at Threat Expert Note: Located in %ProgramFiles%\Common Files\System Note: This entry is loaded through one of the "Policies" startup keys. X
Servicewinlogon.exeUnidentified malware. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe program. Note: Located in \%Temp%\ Note: Do not remove the legitimate (winlogon.exe) file which is always found in \%Windir%\%System%\X
Windows SafeAssistwinlogon.exeAdded by the Troj/VB-FGB Trojan! Note: Located in \%AppData%\ Note: Do not remove the legitimate (winlogon.exe) file which is always found in \%Windir%\%System%\X
Windows Live Guardswinlogon.exeAdded by the Virus.Win32.Parite.b VIRUS! Note: Located in \%Program Files%\[note]Modifies the hosts file[/b]X
Windows SafeAssistwinlogon.exeAdded by an unidentified (Trojan.Agent) Note: Located in \%Documents and Settings%\User name\Application Data\ Note: Do not remove the legitimate winlogon.exe file which is always found in \%WINDIR%\%System%\X
Windows Security Centerwinlogon.exeAdded by the W32/Autorun-BEX WORM! Note: Located in \%AppData%\ Note: Spreads via removable media.X
SysManagerGoldwinlogon.eXeAdded by the W32.SillyDC Note: Located in \%AppData%\SysManager\X
UserLogonwinlogon.exeAdded by the Worm.Win32.AutoRun.acq Note: Located in \%UserProfile%\X
NVIDIA Media Center Librarywinlogon.exeAdded by W32/AutoRun-AZK WORM! Note: Located in \%WINDIR%\ Note: Spreads via removable media.X
Windows ARP Detectioncwinlogon.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.X
Windows Login Assistancewinlogon.exeIdentified by Sophos as Troj/Agent-LGL Note: Located in %AppData%\S05-3636-T34636-7574-BLAZEBOT-ASGET-UEIAASHX
networkswinlogon.exeAdded by the Worm.Win32.AutoRun.ctz Note: Located in \%WINDIR%\ Note: Do not remove the legitimate winlogon.exe file which is always found in \%WINDIR%\%System%\X
MSMSGSWINLOGON.EXEAdded by the W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible drives on the compromised computer. Note: Located in \%Documents and Settings%\Administrator\Local Settings\Application Data\WINDOWS\ Note: Do not remove the legitimate WINLOGON.EXE file which is always found in \%WINDIR%\%System%\X
Microsoft Windows logon processwinlogon.exeAdded by the Troj/FakeAV-IJ Note: Located in \%User%\Owner\AppData\Roaming\Microsoft\Windows\ Note: Do not remove the legitimate program file in \%WINDIR%\%System%\X
CTEMON.EXEwinlogon.exeAdded by the Troj/FakeAv-FU TROJAN! Note: Located in \%Documents and Settings%\All Users\Application Data\ Note: This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe fileX
Window UDP Control Servicwinlogon.exeAdded by the W32/Rbot-GXN WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\%System%\X
screwswinlogon.exeIdentified by Sophos as Worm W32/VB-DWN Note: Located in \%WINDIR%\X
ICQ Netwinlogon.exeAdded by the W32.Netsky.C@mm or W32.Netsky.D@mm or W32.Netsky.E@mm or W32.Netsky.K@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
RegDonewinlogon.exeAdded by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
nvchostwinlogon.exeAdded by the Troj/Klone-J TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
MSWinlogonwinlogon.exeAdded by the Troj/Agent-FZM TROJAN! Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
MSMSGSwinlogon.exeAdded by the W32.Rahiwi.A WORM! Note: Located in \%Documents and Settings%\Administrator\Local Settings\Application Data\WINDOWS\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft Windows Logon Processwinlogon.exeAdded by the Troj/Proxyser-R TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Microsoft Visual SourceSafewinlogon.exeAdded by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
ICQNetwinlogon.exeAdded by the W32/NETSKY-C WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!X
ICQ Netwinlogon.exeAdded by the W32.Netsky.D@mm WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
ROOT_Machinewinlogon.exeAdded by the Troj/Banker-FI TROJAN! Note: Located in \%WINDIR%\inf\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Generic Host Process for Win32 Serviceswinlogon.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System\ Note: Use SDFix under supervision. Not to be confused by the original file in \%WINDIR%\System32\ folder.X
FriendlyTypeNamewinlogon.exeAdded by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Flash Driverwinlogon.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%Temp%\ Note: Use SDFix under supervision.X
Firewall auto setupwinlogon.exeIdentified by Norman as W32/Downloader Note: This worm\trojan is located in C:\%WINDIR%\Temp\ folder. Note: NoteThe filename spchost.exe has also been identified with this Keystroke Logger infection.X
CueX44_stil_hereWINLOGON.EXEAdded by the W32/Punya-A Worm Note: Read the link, alters file associationsX
ccAppswinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe processX
BuildLabwinlogon.exeAdded by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
Administratorwinlogon.exeAdded by the W32/Rubble-C WormX
Streams Driverswinlogon.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%Temp%\ Note: Use SDFix under supervision.X
WinAuthwinlogon.exeAdded by the TROJ_STRTPAGE.BE TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
W1N32.DLLWINLOGON .exeAdded by the TROJ_DROPPERFL.A TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
Userinitwinlogon.exeAdded by a variant of the Troj/Dloader-TP TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
userinitwinlogon.exeAdded by the Troj/Dloader-TP TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
urudjeffniwinlogon.exeAdded by the W32/Romario-A WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
Torjan ProgramWINLOGON.EXEAdded by Infostealer.Wowcraft.D TROJAN! horse that attempts to steal sensitive information related to online games and send it to a remote attacker. Note: This is not the legitimate Windows process WINLOGON.EXE (Which is always found in the System32 folder.) This trojan file (WINLOGON.EXE) is found in the Windows or Winnt folder.X
TEXTCONVwinlogon.exeAdded by the W32.Neveg.A@mm WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate file which is always found in \%WINDIR%\System32\X
System Update2winlogon.exeAdded by the Troj/Autotroj-C WORM! Note: Located in \%WINDIR%\system\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
.Progwinlogon.exeAdded by the W32.Neveg.A@mm Note: Located in \%WINDIR%\system Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
SmansaAppwinlogon.exeAdded by the W32/Romario-A WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
SkynetRevengewinlogon.scrAdded by the W32.Netsky.AA@mm WORM! Note: Located in \%WINDIR%\X
runwinlogonwinlogon.exeIdentified as a variant of the SpamTool.Win32.Agent.gj malware. Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\ Note: Use SDFix under supervision.X
run=winlogon.exeCoolWebSearch parasite related. Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
RPCserv32gWINLOGON.EXEAdded by the WORM_BOBAX.AD WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
RPCserr32gwinlogon.exeAdded by the W32/Ritdoor-B WORM! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X
xp_systemservices.exe or winlogon.exeAdded by the Trojan.Bookmarker.J TROJAN! Note: Located in \%WINDIR%\inet20004\ Note: Do not remove the legitimate program file in \%WINDIR%\System32\X


Powered by SystemLookup Engine. © 2008-2018 BrightFort. All Rights Reserved. | Privacy Policy | Terms of Use