Startup Entries

! | ' | $ | % | ( | * | , | - | . | / | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | \ | space | ? | @ | A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | ^ | _ | {
.NET.
File Name: msnmgnr.exe
Description:
Added by the External: DELF.AYF WORM!
(0) | (0) | (0)
.norton
File Name: rchost.exe
Description:
Added by the External: BOXED-H TROJAN!
(0) | (0) | (0)
.nvsvc
File Name: smss.exe
Description:
Added by the External: IRCBOT-FP TROJAN! Note - this is not the legitimate External: smss.exe process which should not normally figure in Msconfig/Startup!
(0) | (0) | (0)
.nvsvcb
File Name: smssb.exe
Description:
Added by the External: BOXED.CG TROJAN!
(0) | (0) | (0)
.Prog
File Name: services.exe
Description:
Added by the External: NEVEG.B or External: NEVEG.C WORMS! Note - this is not the legitimate External: services.exe process, which should not appear in Msconfig/Startup!
(0) | (0) | (0)
.Prog
File Name: winlogon.exe
Description:
Added by the External: NEVEG.A WORM! Note - this is not the legitimate External: winlogon.exe process, which should not appear in Msconfig/Startup!
(0) | (0) | (0)
.protected
File Name: N/A
Description:
External: Smitfraud variant
(0) | (0) | (0)
.service
File Name: winlgon.exe
Description:
Added by the External: BDOOR-BX BACKDOOR!
(0) | (0) | (0)
.svchost
File Name: CSRSS.EXE
Description:
Added by the External: WEBUS.F TROJAN! Note - this worm replaces the legitimate External: csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
(0) | (0) | (1)
.TEXTCONV
File Name: csrss.exe
Description:
Added by the External: WEBUS TROJAN! Note - this is not the legitimate External: csrss.exe process which should not normally figure in Msconfig/Startup!
(0) | (0) | (1)
1 | 2 | 3