Filename: MSASCuiL.exe (I'm in autoruns and I have a trailing 'L' before the extension.
Registry Value Name: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Command: (no clue)
File Location: %ProgramFiles%\Windows Defender\MSASCuiL.exe
== or ==
c:\program files\windows defender\msascuil.exe
Description: Windows Defender notification icon
Status: Y - Yes, this program is necessary to run in order for the computer or a program to operate correctly.
Please verify tho!
Windows10's big Update occurred exactly when my cable modem slowly died. I thought I was looking at malware at first, not hardware. I got a little delete-happy and figured I horked up my install, so did a Windows Settings refresh while saving my data. Yet now my login is 'Administrator' and I can't change it, yet I have to provide administrator privilages to move files to different folders. Flat out can't save in other folders, and am prompted for every move I make. Program defaults aren't 'sticking' either. Which smells like fish to me.
autoruns64.exe has a "TotalVrus" check feature, and this entry with a lingering 'L' is missing in the Startup Database (as if it were just a typo, extra character). It scored a 0/62 for being a threat, if their source is legit:
Edited by hamluis, 06 September 2017 - 07:53 PM.
Moved from Windows Startup DB to Am I Infected - Hamluis.