Trojan.startup.1

Overview

Trojan.startup.1 is the detection name for a group of trojans.

Trojan.startup.1 run at startup and is mentioned at some of the security forums, where their removal is recommended. You can find more information how to disable Trojan.startup.1 from running on your computer in the removal instructions.

Trojan.startup.1 can be identified by 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service' located in the registry at the following locations:

'HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run',
'HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices'
'HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnce'
'HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
'HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices'
'HKCU \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnce'

Classification

Trojan

Files

winupdate.exe, deinst_qfe002.exe, winupdate.exe, MsMovies.exe, msresearch.exe, sp2update00.exe, hidn2.exe, winocx.exe, myupdates.exe, rundIl.exe, OSAV32.exe, SysExec.exe, MSExecCfg.exe, MSAVCfg.exe, SysDllServ.exe, WinExec.exe, OSAVCfg.exe, DBDllCom.exe, DBDllServ.exe, DBExecCom.exe, MSExecCom.exe, WinOCX32.exe, OSOCX32.exe, WinOCX.exe

If you have any of the files related to Trojan.startup.1 on your system, please send them for additional analysis. Generally, I have only analysed a few versions for each software component listed at this web site. With your help I will be able to look at both old and more recent versions of the Trojan.startup.1 software. Thank you very much for your time!

Log references



Vendor

Unknown

Privacy policy

No privacy policy available.

Detection

Bazooka Adware and Spyware Scanner detects Trojan.startup.1. Bazooka is freeware and detects spyware, adware, foistware, trojan horses, viruses, worms and other potentially unwanted applications. Read more »

Uninstall Trojan.startup.1 with FreeFixer

I'm working on a general purpose tool for removing unwanted software. The tool is called FreeFixer and can help you remove unwanted Browser Helper Objects, Internet Explorer toolbars and software that starts automatically when you reboot your computer, so it can offer some assistance while uninstalling Trojan.startup.1. The manual removal instructions listed below will help you to identify what to delete with FreeFixer.

Read more about FreeFixer.

Manual removal

Please follow the instructions below if you would like to remove Trojan.startup.1 manually. Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If Trojan.startup.1 remains on your system after stepping through the removal instructions, please double-check by stepping through them again.

  1. Start your computer in safe mode.
  2. Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
  3. Browse to the key:
    'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
  4. In the right pane, delete the values called 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service', if they exists. Remember the name of the file (**) it points to. (Deleting this value prevents Trojan.startup.1 from running next time you reboot your machine.)
  5. Browse to the key:
    'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices'
  6. In the right pane, delete the values called 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service', if they exists. Remember the name of the file (**) it points to. (Deleting this value prevents Trojan.startup.1 from running next time you reboot your machine.)
  7. Browse to the key:
    'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnce'
  8. In the right pane, delete the values called 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service', if they exists. Remember the name of the file (**) it points to. (Deleting this value prevents Trojan.startup.1 from running next time you reboot your machine.)
  9. Browse to the key:
    'HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
  10. In the right pane, delete the values called 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service', if they exists. Remember the name of the file (**) it points to. (Deleting this value prevents Trojan.startup.1 from running next time you reboot your machine.)
  11. Browse to the key:
    'HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices'
  12. In the right pane, delete the values called 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service', if they exists. Remember the name of the file (**) it points to. (Deleting this value prevents Trojan.startup.1 from running next time you reboot your machine.)
  13. Browse to the key:
    'HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnce'
  14. In the right pane, delete the values called 'Windows Update', 'Windows Update Checker', 'winupdate', 'MsMovies', 'msresearch', 'sp2update', 'drv_st_key', 'Windows Ocx Service', 'myupdates', 'System Management' 'Antivirus 32 Manager', 'System Verification Application', 'Secure Server 32', 'System Verification Manager', 'Firewall Socket Device', 'Win Verification Application', 'Microsoft 32 Manager', 'Windows Validation Client', 'Current Service Validation', 'MS Server 32', 'Secure Server 32', 'Root Update Verification', 'Secure Server Device', 'Root Service Validation', 'Remote Update Verification', 'Root Service Verification', 'Remote Update Client', 'Current Manager Validation', 'XP Manager Socket', 'MS Manager Socket', 'Microsoft Device Service', 'Current Manager Update', 'NT Application Server', 'Registry Client Manager', 'Admin Manager Update', 'MS Manager 32', and 'Driver Device Service', if they exists. Remember the name of the file (**) it points to. (Deleting this value prevents Trojan.startup.1 from running next time you reboot your machine.)
  15. Exit the registry editor.
  16. Start Windows Explorer and delete:
    The file (**) mentioned above

Problems uninstalling? Click here.

I'm looking for your help!

Thank you for using my site, I hope you find it useful. I'm looking for help from all users, please read more.

Contact information for Trojan.startup.1's vendor

In order to provide correct, accurate and updated information about Trojan.startup.1 I encourage the vendor to contact me if any part of this write-up needs a revision.

How do you rate the information provided about Trojan.startup.1?


Related links

Bazooka - Free scan for spyware, adware, trojan horses, keyloggers, etc. Detects more than 500 potentially unwanted applications. Freeware!

The File Database - Search the file database for more information. Free!

PopUp Blocker Test - Find out if your pop-up killer can handle all pop-ups. Free!

Kephyr Labs - Find out what is going on at Kephyr. Try products in an early stage of development.



FreeFixer
Read more about FreeFixer, Kephyr's latest spyware removal tool.
Home & Products |  Legal |  Privacy |  Search

© Kephyr, 2003-2012. HtmlTidy, HTML 4.01, CSS andy@kephyr.com