CLSID List Results
BHOs, Toolbars, SHs, Explorer Bars
BHOs, Toolbars, SHs, Explorer Bars
CLSID | Name | Filename | Description | Status |
{E3DB85B5-C559-4894-B474-42E89FAA1EFD} | Windows ToyClass, Microsoft Solo Browser Helper Ob | wuauclt.dll, winmsd.dll, wlbs.dll, tscupgrd.dll | Malware - detected by DrWeb antivirus as Trojan.Sinox - also see here | X BHO |
Startup List Results
Startup Entry
Startup Entry
Name | Filename | Description | Status |
Microsoft | wuauclt.exe | Added by a variant of the Win32.Delf downloader TROJAN! | X |
Microsoft (R) Windows Update Service | wuauclt.exe | Added by an unidentified Backdoor.Ranky TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\update\ | X |
Microsoft Update Device Drivers | wuauclt.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\drivers\ (Win9x/Me), C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) | X |
Microsoft ® Windows Update Service | wuauclt.exe | Added by the HackerDefender SDBot TROJAN! Note: ROOTKIT INFECTION Note:This is not the legitimate Windows Process located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) This worm\trojan is located in C:\WINDOWS\update\ | X |
Microsoft auto update | wuauclt.exe | Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! | X |
O23 List Results
Windows Services
Windows Services
Name | Filename | Description | Status |
automatic updates for Microsoft Windows | wuauclt.exe | Added by the W32/Sdbot-DFD Note: Located in \%WINDIR%\ Note: Allows remote access. Makes multiple system changes. Read link for additional information. | X |
Windows Update Service (UpdateSvc) | wuauclt.exe | Added by an unknown variant of a (backdoor raanky) TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate program file in \%WINDIR%\%System%\ | X |
Active Setup List Results
Active Setup - Installed Component
Active Setup - Installed Component
CLSID | Name | Filename | Description | Status |
{R3VQKX88-WIV1-50PB-GSY8-U41W8SK66WF0} | (no name) | wuauclt.exe | Infostealer trojan, detected by Microsoft as Backdoor:Win32/Hupigon.cn - also see here | X |
{ERYJ1103-540S-3204-8Y64-4C5X8VG6V04O} | (no name) | wuauclt.exe | Infostealer trojan, detected by Microsoft as VirTool:Win32/VBInject.gen!IY - also see here | X |
{V6FUDFW5-662B-D4E1-VGL7-780N6O8R3X4M} | (no name) | wuauclt.exe | Infostealer trojan, detected by Microsoft as Backdoor:Win32/Xtrat.A - also see here | X |