<?xml version="1.0" encoding="Windows-1252"?>

<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="StartupList">
<title>Recent 10 StartupList Entries</title>
<link>http://www.castlecops.com/StartupList.html</link>
<description>CastleCops - Paul Collins StartupList</description>
<dc:language>en-us</dc:language>
<dc:creator>Paul Laudanski (mailto:paul@computercops.biz)</dc:creator>
<dc:rights>Copyright &#169; 2002-2005 CastleCops&amp;reg;</dc:rights>
<dc:date>2008-12-05T14:12:49-05:00</dc:date>
<sy:updatePeriod>daily</sy:updatePeriod>
<sy:updateFrequency>24</sy:updateFrequency>
<sy:updateBase>2003-01-01T12:00-05:00</sy:updateBase>
<admin:generatorAgent rdf:resource="http://www.castlecops.com/" />

<item>
<name>ISPSERVICE</name>
<status>X</status>
<command>wintmp.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%Program Files%\Common Files\System\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17537.html</infourl>
<list>http://www.castlecops.com/startuplist-17537.html</list>
</item>
<item>
<name>WinXPService</name>
<status>X</status>
<command>taksmgr.exe</command>
<description>Identified as a variant of the IRC/Flood.tool, http://www.bleepingcomputer.com/startups/taksmgr.exe-23732.html malware. [red]Note:[/red] Located in \%WINDIR%\fonts\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17536.html</infourl>
<list>http://www.castlecops.com/startuplist-17536.html</list>
</item>
<item>
<name>WinDLL (tmp.exe)</name>
<status>X</status>
<command>tmp.exe</command>
<description>Identified as a variant of the Net-Worm.Win32.Kolab.l malware. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17535.html</infourl>
<list>http://www.castlecops.com/startuplist-17535.html</list>
</item>
<item>
<name>Power-Antivirus-2009</name>
<status>X</status>
<command>Power-Antivirus-2009.exe</command>
<description>Added by the Power_Antivirus_2009, http://www.bleepingcomputer.com/malware-removal/remove-power-antivirus-2009 rogue antivirus program. [red]Note:[/red] Located in \%Program Files%\Power-Antivirus-2009\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17534.html</infourl>
<list>http://www.castlecops.com/startuplist-17534.html</list>
</item>
<item>
<name>Help</name>
<status>X</status>
<command>lshost.exe</command>
<description>Identified as a variant of the Trojan-Clicker.Win32.Delf.aro, http://www.bleepingcomputer.com/startups/lshost.exe-23730.html malware. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17533.html</infourl>
<list>http://www.castlecops.com/startuplist-17533.html</list>
</item>
<item>
<name>Antivir64</name>
<status>X</status>
<command>Antivir64.exe</command>
<description>Added by the Antivir64, http://www.bleepingcomputer.com/malware-removal/remove-antivir64 rogue anti-spyware program. [red]Note:[/red] Located in \%Program Files%\Antivir64\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17532.html</infourl>
<list>http://www.castlecops.com/startuplist-17532.html</list>
</item>
<item>
<name>Nod32 Service</name>
<status>X</status>
<command>nod6.exe</command>
<description>Added by a variant of the RBOT, http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=39437 family of IRC Backdoor trojan. [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17531.html</infourl>
<list>http://www.castlecops.com/startuplist-17531.html</list>
</item>
<item>
<name>Windows Update</name>
<status>X</status>
<command>McAfee.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%Program Files%\Common Files\System\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17530.html</infourl>
<list>http://www.castlecops.com/startuplist-17530.html</list>
</item>
<item>
<name>Windows Update</name>
<status>X</status>
<command>winsc.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%Program Files%\Common Files\System\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17529.html</infourl>
<list>http://www.castlecops.com/startuplist-17529.html</list>
</item>
<item>
<name>System Presets</name>
<status>X</status>
<command>systempre.exe</command>
<description>Added by a variant of the IRCBOT, http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99 [red]Note:[/red] Located in \%WINDIR%\System32\ [red]Note:[/red] Use SDFix under supervision.</description>
<infourl>http://www.castlecops.com/startuplist-17528.html</infourl>
<list>http://www.castlecops.com/startuplist-17528.html</list>
</item>
</channel>

</rdf:RDF>

