Startup Entries

! | ' | $ | % | ( | * | , | - | . | / | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | \ | space | ? | @ | A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | ^ | _ | {
*WindowsAudio
File Name: systemupd.exe
Description:
Added by the External: AGENT-TH WORM!
(0) | (0) | (0)
*WinLogon
File Name: [trojan path] ren time:[random number]
Description:
Added by the External: VUNDO TROJAN!
(0) | (0) | (0)
*winsocks
File Name: msnmess.exe
Description:
Added by the External: PWS-ABU TROJAN!
(0) | (0) | (0)
*winstats
File Name: winstats.exe
Description:
Added by the External: GARGAFX TROJAN!
(0) | (0) | (0)
*wmstu
File Name: wmstu.exe
Description:
Added by the External: RBOT-TV WORM!
(0) | (0) | (0)
*wuauclt.exe
File Name: w****.exe [* = random char]
Description:
Added by a variant of the External: RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
(0) | (0) | (0)
*zggjmyd
File Name: zggjmyd.exe
Description:
Added by the External: AFCORE.O BACKDOOR!
(0) | (0) | (0)
1 | 2 | 3 | 4