{"id":4323,"date":"2012-05-03T10:30:41","date_gmt":"2012-05-03T07:30:41","guid":{"rendered":"http:\/\/regrunreanimator.com\/research\/?p=4323"},"modified":"2012-05-03T10:30:41","modified_gmt":"2012-05-03T07:30:41","slug":"startup-defender-2","status":"publish","type":"post","link":"https:\/\/regrunreanimator.com\/research\/security-tools\/startup-defender\/startup-defender-2.htm","title":{"rendered":"Startup Defender"},"content":{"rendered":"<p><img class=\"aligncenter size-full wp-image-4324\" title=\"Startup Defender\" src=\"https:\/\/regrunreanimator.com\/research\/wp-content\/uploads\/2012\/05\/Startup-Defender.ico\" alt=\"\" \/><\/p>\n<h1 style=\"text-align: center;\">Startup Defender<\/h1>\n<p style=\"text-align: center;\"><a href=\"http:\/\/www.zardssoftware.com\/startup\/startup.html\">http:\/\/www.zardssoftware.com\/startup\/startup.html<\/a><\/p>\n<p>Startup Defender is a small Windows startup manager program that sits in your Windows tray and constantly monitors in real time the startup locations on your PC to help prevent programs from auto starting up behind your back. If a program tries to write itself into any startup location Startup Defender will pop up a windows and ask if the program is allowed to place itself to start automatically with Windows. Also you can disable\/enable any programs that are currently installed to startup automatically. If there is an entry you are not sure what it is then you can Google it to see if it is needed or even harmful and choose if you want it to load it at startup or not. For the annoying programs that try to repeatedly place themselves in the autorun for Windows you can click the auto block so that Startup Defender stops them without you having to bother with them anymore. Also you can now view all processes and services then selectively start\/stop each one.<\/p>\n<p style=\"text-align: center;\"><strong>This software does not change the Windows boot time.<\/strong><\/p>\n<p><a href=\"https:\/\/regrunreanimator.com\/research\/wp-content\/uploads\/2012\/05\/Startup-Defender.png\"><img loading=\"lazy\" class=\"aligncenter size-medium wp-image-4325\" title=\"Startup Defender\" src=\"https:\/\/regrunreanimator.com\/research\/wp-content\/uploads\/2012\/05\/Startup-Defender-300x213.png\" alt=\"\" width=\"300\" height=\"213\" srcset=\"https:\/\/regrunreanimator.com\/research\/wp-content\/uploads\/2012\/05\/Startup-Defender-300x213.png 300w, https:\/\/regrunreanimator.com\/research\/wp-content\/uploads\/2012\/05\/Startup-Defender.png 718w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<div id=\"blist\"><strong>STARTUPDEFENDER.EXE<\/strong><br \/>\nDescription: <strong>Startup Defender Zards Software Startup Defender 3.9.1.0<\/strong><br \/>\nMD5= <strong>F12D9DAD9F8906F7B3767D5D5498B5F5<\/strong><br \/>\nFile is <strong>not signed<\/strong>.<br \/>\nFile size= <strong>1562624<\/strong><br \/>\n<strong>Related registry changes:<\/strong><br \/>\nHKLM\\SOFTWARE\\MICROSOFT\\WINDOWS\\CURRENTVERSION\\RUN\\STARTUP DEFENDER: &#8220;C:\\WINDOWS\\<strong>STARTUPDEFENDER.EXE<\/strong> -SILENT&#8221;<br \/>\nHKLM\\SOFTWARE\\MICROSOFT\\WINDOWS\\CURRENTVERSION\\UNINSTALL\\{43127A2A-C2FB-4D12-BD8A-17A2F7A67BC8}_IS1\\DISPLAYICON: &#8220;C:\\WINDOWS\\<strong>STARTUPDEFENDER.EXE<\/strong>&#8220;<\/div>\n<div id=\"alist\"><strong>BABYLONTOOLBAR.DLL<\/strong><br \/>\nDescription: <strong>Babylon BHO Babylon Toolbar 1.4.35.0<\/strong><br \/>\nMD5= <strong>C471B1EEF9DF1C55B5261006CE04E11F<\/strong><br \/>\nFile is <strong>signed<\/strong> and the <strong>signature was verified<\/strong>.<br \/>\nFile size= <strong>270960<\/strong><br \/>\n<strong>Related registry changes:<\/strong><br \/>\nHKLM\\SOFTWARE\\CLASSES\\CLSID\\{2EECD738-5844-4A99-B4B6-146BF802613B}\\INPROCSERVER32\\: &#8220;C:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\BH\\<strong>BABYLONTOOLBAR.DLL<\/strong>&#8221;<br \/>\nHKLM\\SOFTWARE\\CLASSES\\CLSID\\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}\\INPROCSERVER32\\: &#8220;C:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\BH\\<strong>BABYLONTOOLBAR.DLL<\/strong>&#8221;<br \/>\nHKLM\\SOFTWARE\\CLASSES\\CLSID\\{E46C8196-B634-44A1-AF6E-957C64278AB1}\\INPROCSERVER32\\: &#8220;C:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\BH\\<strong>BABYLONTOOLBAR.DLL<\/strong>&#8220;<\/div>\n<div id=\"blist\"><strong>BABYLONTOOLBARTLBR.DLL<\/strong><br \/>\nDescription: <strong>Babylon Ltd. Babylon Toolbar 1.4.35.0<\/strong><br \/>\nMD5= <strong>034C197E79D7233BD04BFAC1710CB988<\/strong><br \/>\nFile is <strong>signed<\/strong> and the <strong>signature was verified<\/strong>.<br \/>\nFile size= <strong>237680<\/strong><br \/>\n<strong>Related registry changes:<\/strong><br \/>\nHKLM\\SOFTWARE\\CLASSES\\CLSID\\{98889811-442D-49DD-99D7-DC866BE87DBC}\\INPROCSERVER32\\: &#8220;C:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBARTLBR.DLL<\/strong>&#8221;<br \/>\nHKLM\\SOFTWARE\\CLASSES\\TYPELIB\\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\\1.0\\0\\WIN32\\: &#8220;C:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBARTLBR.DLL<\/strong>&#8220;<\/div>\n<p><!--more--><\/p>\n<div class=\"date\"><strong>Modified during installation:<\/strong><\/div>\n<p>~+ [INTERNET EXPLORER] [CURRENT HOME PAGE] :HKCU START PAGE=HTTP:\/\/SEARCH.BABYLON.COM\/?AFFID=112542&amp;BABSRC=HP_SS&amp;MNTRID=0F1467FE000000000000000C2982064B<br \/>\n~- [INTERNET EXPLORER] [CURRENT HOME PAGE] :HKCU START PAGE=HTTP:\/\/WWW.GOOGLE.COM\/<\/p>\n<div class=\"date\"><\/div>\n<p><strong>FILES ADDED:51<\/strong><\/p>\n<div id=\"clist\">C:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\APPLICATION DATA\\BABYLON\\LOG_FILE.TXT<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\BAB033.TBINST.DAT<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\BAB091.NORECOVERICON.DAT<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\BABYLON.DAT<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\<strong>BEXTERNAL.DLL<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\BLUESTAR.PNG<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\EULA.HTML<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\GLOBE.PNG<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\OPTIONS.JS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE0.HTML<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE2.CSS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE2.HTML<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE2LRG.CSS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE3.CSS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE3.HTML<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PAGE3LRG.CSS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PBAR.GIF<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\PROGRESS.PNG<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\SETUP.JS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\TITLE.PNG<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS\\TOOLBAR.JPG<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\<strong>IECOOKIELOW.DLL<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\SETUP-LATEST-30B.ZPB<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\SETUP-TBMNTR903.ZPB<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\<strong>SETUP.EXE<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\SETUPSTRINGS.DAT<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\SIGN<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\<strong>SQLITE3.DLL<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBAR4FFX.EXE<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBAR4IE.EXE<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\USER.JS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\<strong>MYBABYLONTB.EXE<\/strong><br \/>\nC:\\DOCUMENTS AND SETTINGS\\ALL USERS\\START MENU\\PROGRAMS\\STARTUP DEFENDER\\STARTUP DEFENDER ON THE WEB.URL<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ALL USERS\\START MENU\\PROGRAMS\\STARTUP DEFENDER\\STARTUP DEFENDER.LNK<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ALL USERS\\START MENU\\PROGRAMS\\STARTUP DEFENDER\\UNINSTALL STARTUP DEFENDER.LNK<br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBARAPP.DLL<\/strong><br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBARENG.DLL<\/strong><br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBARSRV.EXE<\/strong><br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>BABYLONTOOLBARTLBR.DLL<\/strong><br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\BH\\<strong>BABYLONTOOLBAR.DLL<\/strong><br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\<strong>UNINSTALL.EXE<\/strong><br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\BABYLONTB.XPI<br \/>\nC:\\PROGRAM FILES\\STARTUP DEFENDER\\UNINS000.DAT<br \/>\nC:\\PROGRAM FILES\\STARTUP DEFENDER\\<strong>UNINS000.EXE<\/strong><br \/>\nC:\\WINDOWS\\BANPRC.DAT<br \/>\nC:\\WINDOWS\\<strong>INTEROP.IWSHRUNTIMELIBRARY.DLL<\/strong><br \/>\nC:\\WINDOWS\\<strong>INTEROP.SHELL32.DLL<\/strong><br \/>\nC:\\WINDOWS\\START.ICO<br \/>\nC:\\WINDOWS\\<strong>STARTUPDEFENDER.EXE<\/strong><br \/>\nC:\\WINDOWS\\STOP.ICO<br \/>\nC:\\USER.JS<\/div>\n<div class=\"date\"><\/div>\n<p><strong>FILES[ATTR]MODIFIED:2<\/strong><\/p>\n<div id=\"dlist\">C:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\GDIPFONTCACHEV1.DAT<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\CE4CF87733651BF1F44DD1E02FC1A8E8<\/div>\n<div class=\"date\"><\/div>\n<p><strong>FOLDERS ADDED:14<\/strong><\/p>\n<div id=\"clist\">C:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\APPLICATION DATA\\BABYLON<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\APPLICATION DATA\\BABYLON\\SETUP\\HTMLSCREENS<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\BABYLONTOOLBAR<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\BABYLONTOOLBAR\\BABYLONTOOLBAR<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ADMINISTRATOR\\LOCAL SETTINGS\\TEMP\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ALL USERS\\APPLICATION DATA\\BABYLON<br \/>\nC:\\DOCUMENTS AND SETTINGS\\ALL USERS\\START MENU\\PROGRAMS\\STARTUP DEFENDER<br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR<br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR<br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17<br \/>\nC:\\PROGRAM FILES\\BABYLONTOOLBAR\\BABYLONTOOLBAR\\1.5.3.17\\BH<br \/>\nC:\\PROGRAM FILES\\STARTUP DEFENDER<\/div>\n<div class=\"wpInsert wpInsertInPostAd wpInsertBelow\" style=\"padding: 0px;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Startup Defender http:\/\/www.zardssoftware.com\/startup\/startup.html Startup Defender is a small Windows startup manager program that sits in your Windows tray and constantly monitors in real time the startup locations on your PC to help prevent programs from auto starting up behind your back. If a program tries to write itself into any startup location Startup Defender will [&hellip;]<br \/><a style=\"color: #42A2CE\" href=\"https:\/\/regrunreanimator.com\/research\/security-tools\/startup-defender\/startup-defender-2.htm\"><u>More&#8230;<\/u><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[333],"tags":[],"_links":{"self":[{"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/posts\/4323"}],"collection":[{"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/comments?post=4323"}],"version-history":[{"count":0,"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/posts\/4323\/revisions"}],"wp:attachment":[{"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/media?parent=4323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/categories?post=4323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regrunreanimator.com\/research\/wp-json\/wp\/v2\/tags?post=4323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}