<?xml version="1.0" encoding="Windows-1252"?>

<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="StartupList">
<title>Recent 10 StartupList Entries</title>
<link>http://www.castlecops.com/StartupList.html</link>
<description>CastleCops - Paul Collins StartupList</description>
<dc:language>en-us</dc:language>
<dc:creator>Paul Laudanski (mailto:paul@computercops.biz)</dc:creator>
<dc:rights>Copyright &#169; 2002-2005 CastleCops&amp;reg;</dc:rights>
<dc:date>2008-08-21T02:09:00-05:00</dc:date>
<sy:updatePeriod>daily</sy:updatePeriod>
<sy:updateFrequency>24</sy:updateFrequency>
<sy:updateBase>2003-01-01T12:00-05:00</sy:updateBase>
<admin:generatorAgent rdf:resource="http://www.castlecops.com/" />

<item>
<name>Windows UDP Control Center</name>
<status>X</status>
<command>winudpmsgr.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17492.html</infourl>
<list>http://www.castlecops.com/startuplist-17492.html</list>
</item>
<item>
<name>WinDLL (asdfsa.exe)</name>
<status>X</status>
<command>asdfsa.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17491.html</infourl>
<list>http://www.castlecops.com/startuplist-17491.html</list>
</item>
<item>
<name>SVGA Adapter</name>
<status>X</status>
<command>svghost.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17490.html</infourl>
<list>http://www.castlecops.com/startuplist-17490.html</list>
</item>
<item>
<name>Security System</name>
<status>X</status>
<command>securesys.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17489.html</infourl>
<list>http://www.castlecops.com/startuplist-17489.html</list>
</item>
<item>
<name>MSN Security Agent</name>
<status>X</status>
<command>msnsecure.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17488.html</infourl>
<list>http://www.castlecops.com/startuplist-17488.html</list>
</item>
<item>
<name>Msn Message Acount Helper 7.7</name>
<status>X</status>
<command>msnmessage7.7.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17487.html</infourl>
<list>http://www.castlecops.com/startuplist-17487.html</list>
</item>
<item>
<name>MbarInstall</name>
<status>X</status>
<command>mirar_distro_876260.exe</command>
<description>Identified as a variant of the Adware.Mirar, http://www.bleepingcomputer.com/startups/MbarInstall-23651.html malware. [red]Note:[/red] located in \%WINDIR%\ [red]Note:[/red] Use SDFix under supervision. [red]Note: [/red] Filename and location of the file could different.</description>
<infourl>http://www.castlecops.com/startuplist-17486.html</infourl>
<list>http://www.castlecops.com/startuplist-17486.html</list>
</item>
<item>
<name>SpywareSweeper</name>
<status>X</status>
<command>SpywareSweeper.exe</command>
<description>Added by the SpywareSweeper, http://www.bleepingcomputer.com/startups/SpywareSweeper.exe-19618.html security risk. SpywareSweeper is a misleading application that may give exaggerated reports about potential risks on the computer. [red]Note:[/red] Located in \%Program Files%\SpywareSweeper\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17485.html</infourl>
<list>http://www.castlecops.com/startuplist-17485.html</list>
</item>
<item>
<name>LCASS</name>
<status>X</status>
<command>lcass.exe</command>
<description>Added by the W32/SillyFDC-W, http://www.sophos.com/security/analyses/viruses-and-spyware/w32sillyfdcw.html Worm for the Windows platform that spreads via removeable shared drives. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17484.html</infourl>
<list>http://www.castlecops.com/startuplist-17484.html</list>
</item>
<item>
<name>ctfnnon</name>
<status>X</status>
<command>ctfmon.exe</command>
<description>Identified as a variant of the Backdoor.Win32.Turkojan.ake, http://www.bleepingcomputer.com/startups/ctfmon.exe-23650.html malware. [red]Note:[/red] located in \%WINDIR%\ [red]Note:[/red] Use SDFix under supervision. [red]Please note[/red] that C:\Windows\System32\ctfmon.exe is legitimate and should not be deleted.</description>
<infourl>http://www.castlecops.com/startuplist-17483.html</infourl>
<list>http://www.castlecops.com/startuplist-17483.html</list>
</item>
</channel>

</rdf:RDF>

