Windows Startup Entries, Symbol: [h]
Powered by: sysinfo.org (Archived @ web.archive.org)
HKLM
File Name: wininit.exe
Description:
Added by the External: MDROP-CY MALWARE! Note - this is not the legitimate External: wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" sub-folder
Added by the External: MDROP-CY MALWARE! Note - this is not the legitimate External: wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" sub-folder
HKLM\\Run
File Name: svhost.exe
Description:
Added by the External: FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!
Added by the External: FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!
HKLM\Run
File Name: windowsupdate.exe
Description:
Added by the External: FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!
Added by the External: FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!