|
| [.mscsbl] | "Added by the CMQ TROJAN!"
| b |
| [HKLMRun] | "Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
| b |
| [Load Service] | "Added by the PESIN-D WORM!"
| b |
| [Microsoft AutoUpdater] | "Added by the RBOT.QG WORM!"
| b |
| [Microsoft Host Protocol] | "Added by a variant of the RBOT WORM!"
| b |
| [Microsoft System NT] | "Added by the SDBOT.COU WORM!"
| b |
| [net32] | Added by a variant of the Trojan.Clicker family
| b |
| [Opera addon] | "Added by the AGENT-IBD WORM!"
| b |
| [S] | "Added by the AGOBOT-LN WORM!"
| b |
| [Security Service Process] | "Added by the AGOBOT-LC WORM!"
| b |
| [Servicio Local] | "Added by the SPYBOT.BGX WORM!"
| b |
| [Svchost Windows Remote Services] | "Added by the IRCBOT-IV WORM!"
| b |
| [SVHOST] | "Added by the MYDOOM.I WORM! The file is located in %System%"
| b |
| [svhost updates] | "Added by a variant of the RBOT WORM!"
| b |
| [SymantecFilterCheck] | "Added by the BANKER-EEO TROJAN!"
| b |
| [UPDATEMSN] | Added by an unidentified WORM or TROJAN!
| b |
| [Windows update config] | "Added by the SDBOT-PF WORM!"
| b |
| [WSVCHO] | "Added by the SPYBOT-OQ WORM!"
| b |