Windows Startup Entries, Symbol: [r]

! | ' | $ | % | ( | * | , | - | . | / | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | \ | space | ? | @ | A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | ^ | _ | {

RunServices

File Name: runsvc32.exe
Description:
Added by the External: AGOBOT.QJ WORM!
Bad startup (0) | Good startup (0) | (0)

runservices

File Name: services.exe
Description:
Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate External: services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Bad startup (0) | Good startup (0) | (0)

RunServices

File Name: service.exe
Description:
Added by the External: VEBISP VIRUS!
Bad startup (0) | Good startup (0) | (0)

runsql

File Name: runsql.exe
Description:
Added by the External: DELF.ZWK TROJAN!
Bad startup (0) | Good startup (0) | (0)

runSubvalues

File Name: [path to file]
Description:
Added by the External: DLOADER-QY TROJAN!
Bad startup (0) | Good startup (0) | (0)

runsvc

File Name: runsvc.exe
Description:
Added by the External: SMALL-CF TROJAN!
Bad startup (0) | Good startup (0) | (0)

RunSysd32

File Name: RunSysd32.exe
Description:
DesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
Bad startup (0) | Good startup (0) | (0)

Runtime Process

File Name: Csrss.exe
Description:
Added by the External: CIADOOR-J BACKDOOR! Note - this is not the legitimate External: csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Bad startup (0) | Good startup (0) | (0)

Runtime Server Subsystem

File Name: csrss.exe
Description:
Added by the External: IRCBOT-XV WORM!
Bad startup (0) | Good startup (0) | (0)

runtime.exe

File Name: runtime.exe
Description:
Added by a variant of the Tibs malware
Bad startup (0) | Good startup (0) | (0)
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63 | 64 | 65 | 66 | 67 | 68 | 69 | 70 | 71 | 72 | 73 | 74 | 75 | 76 | 77 | 78 | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | 90 | 91 | 92 | 93 | 94 | 95 | 96