You can use System Configuration Utility [Start > Run> 'msconfig'] and look under the 'Startup' tab. That will tell you all of the process that load at startup. In the 'command' column, you can find the location of these startup processes, and in turn find any suspect applications that are running on startup. The directory of the suspect application will usually give it away. Anything in 'c:/documents and settings/allusers/application data' could be suspect