Windows Startup Entries, Symbol: [f]

! | ' | $ | % | ( | * | , | - | . | / | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | \ | space | ? | @ | A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | ^ | _ | {

Firewall

File Name: ctfmon.exe
Description:
Added by a variant of the External: IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%
Bad startup (0) | Good startup (0) | (0)

firewall

File Name: spoolsv.exe
Description:
Added by the External: DIZAN.F VIRUS!
Bad startup (0) | Good startup (0) | (0)

firewall

File Name: firewall.exe
Description:
Added by the External: SURO-A TROJAN!
Bad startup (0) | Good startup (0) | (0)

firewall 2008

File Name: logoneui.exe
Description:
Added by the External: SILLYFDC WORM!
Bad startup (0) | Good startup (0) | (0)

Firewall Admin

File Name: infocard.exe
Description:
Added by the External: VBPIT-A MALWARE! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft which is normally found in %Windir%\Microsoft.NET%\Framework%\v3.0%\Windows Communication Foundation. This one is located in %Windir%
Bad startup (0) | Good startup (0) | (0)

Firewall Administrating

File Name: infocard.exe
Description:
Added by the External: AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename
Bad startup (0) | Good startup (0) | (0)

Firewall auto setup

File Name: winlogon.exe
Description:
Added by the External: AGENT-EDB TROJAN! Note - this is not the legitimate External: winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%
Bad startup (0) | Good startup (0) | (0)

Firewall auto setup

File Name: [path to trojan]
Description:
Added by the External: AGENT-GLY TROJAN!
Bad startup (0) | Good startup (0) | (0)

Firewall config

File Name: ReadMe.exe
Description:
Added by the External: SILLYFDC.BBT WORM!
Bad startup (0) | Good startup (0) | (0)

Firewall Controls

File Name: sys32.exe
Description:
Added by the External: SDBOT-DGI WORM!
Bad startup (0) | Good startup (0) | (0)
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44