Description: Added by the THROD.A TROJAN! The filename is a random combination the following: ms, svc, win, 16, 32, 64, mes, prn, reg - "ms16prn.exe", for example - and is located in %System%
Windows Messanger Control Center
(0) | (0) | (0)
File Name: svchosl.exe
Description: Added by a variant of the IRCBOT BACKDOOR! See here
Windows Messanger Control Center
(0) | (0) | (0)
File Name: svhost.exe
Description: Added by a variant of the IRCBOT BACKDOOR! See here
Windows Messanger Control Center
(0) | (0) | (0)
File Name: winlogin.exe
Description: Added by a variant of the IRCBOT BACKDOOR! See here
Windows Messanger Control Center
(0) | (0) | (0)
File Name: winlogon.exe
Description: Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows Messanger Control Center
(0) | (0) | (0)
File Name: winsys.exe
Description: Added by a variant of the IRCBOT BACKDOOR! See here