Startup List Results
Startup Entry
Startup Entry
Name | Filename | Description | Status |
Microsoft Update | svghost.exe | Added by a variant of the WIN32.RBOT WORM! | X |
SVGA Adapter | svghost.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. | X |
windows update configurator | svghost.exe | Added by a variant of the W32.SPYBOT WORM! | X |
Genius Mose Driver | svghost.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. | X |
{2C0BE568-4431-11DB-8C92-806D6172696F} | svghost.exe | Identified as "Ransomlock" trojan variant, detected by Nod32 as Trojan:Win32/LockScreen.BO Note: Located in %AppData%\Microsoft | X |
Active Setup List Results
Active Setup - Installed Component
Active Setup - Installed Component
CLSID | Name | Filename | Description | Status |
{4C55E6E8-044E-11DF-8031-806D6172696F} | (no name) | svghost.exe, torrent.exe, lsmass.exe, other filenames | Infostealer trojan, detected by Sophos antivirus as Troj/Agent-VAH | X |
{2c0be568-4431-11db-8c92-806d6172696f} | (no name) | wscntfy.exe, dllhsts.exe, torrent.exe, hostrun.exe, svhcost.exe, svghost.exe, aletoc.exe, loadhst.exe, newsrdr.exe, other filenames | "Ransomlock" trojan variant, detected by Nod32 as Trojan:Win32/LockScreen.BO - also see this ThreatExpert Report | X |