Top 10 Alerts
Latest 10 Malware Files
Testimonials
It seems that the problem with UACd.sys virus has been solved by this program. So many thanks for creating this amazingly useful program.
Eva S.
KoobFace Registry Values
Scan your Windows registry for KoobFace
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, captcha=
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, start=2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, WinError=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, mmas=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ccow=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp11.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ppdrv=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, tapisrvs=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ssed=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, fioo32=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, netsvc6=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, termisvc=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, rpcSsc=
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\captcha, type=288
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\jjp154.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ppoi=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill104.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ttgi=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy142.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp06.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy41.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill113.exe
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, failureactions=00000000000000000000000003000000140000000100000060EA00000100000060EA00000100000060EA0000
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, displayname=VMware Monitor CD ACPI Terminal List
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, errorcontrol=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, imagepath=[%SYSTEM%]\svchost.exe -k meetsvc
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, objectname=LocalSystem
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr, type=32
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr\enum, 0=Root\LEGACY_FLTOKOMGR\0000
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr\enum, count=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr\enum, nextinstance=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr\security, security=01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, npii=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\mc152.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rb=[%WINDOWS%]\rb.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, zzup=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, emusvc=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, termsv=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, termsvcr=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, meetsvc=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, okogrp=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill107.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy62.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy42.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre18.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, termsvc=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy128.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp12.exe
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld14.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy70.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, twr=[%PROFILE_TEMP%]\twr10.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre19.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy46.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\mike150.exe
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld08.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, trmsvcs=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill114.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp10.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, hhny=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, sswe=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy75.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Captcha7=rundll "[%PROGRAM_FILES%]\captcha.dll",captcha
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill103.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp14.exe
- HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run, sys32dll=SYS32DLL
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre22.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\mike148.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy145.exe
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld10.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy57.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre20.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\jjp153.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy58.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, sshi=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ttar=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\hjky159.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\dsvn160.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill112.exe
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld09.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy130.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy148.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\jjp155.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, netwisvc=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy147.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill110.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, zdll=
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\captcha, type=32
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\mike151.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dfg49df=[%WINDOWS%]\mike149.exe
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld15.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy69.exe
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, errorcontrol=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, group=PNP_TDI
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, imagepath=[%SYSTEM%]\drivers\klifoko.sys
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, start=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, type=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, displayname=Target VSSShellExt DocProp BandProxy PostgreSQL
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko\security, security=01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy72.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy143.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill122.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, uudh=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy147.___
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, hhrm=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre24.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy144.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy129.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy127.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd="[%WINDOWS%]\andy143.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, dobi=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy141.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill105.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, vmapisvc=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre26.exe
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko, nextinstance=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko\0000, class=LegacyDriver
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko\0000, classguid={8ECC055D-047F-11D1-A537-0000F8753ED1}
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko\0000, configflags=0
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko\0000, devicedesc=Internet Connections NetBIOS
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko\0000, legacy=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ftdisoko\0000, service=Ftdisoko
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld12.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy73.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy134.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy135.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy133.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy131.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%WINDOWS%]\andy132.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill106.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, nndrv=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd=[%SYSTEM_DRIVE%]\windows\andy128.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre21.exe
- HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, sysldtray=[%WINDOWS%]\ld16.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=c:\windows\freddy58.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xuri49tkd="[%WINDOWS%]\andy128.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy71.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre23.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill126.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=C:\windows\bill126.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill125.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill121.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, ssuf=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, syspptray=[%WINDOWS%]\pp15.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill124.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill123.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy74.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill119.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill120.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre25.exe
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fltokomgr\parameters, servicedll=[%SYSTEM%]\btw_oko.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill117.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy101.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill115.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy45.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill108.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo15.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%SYSTEM_DRIVE%]\windows\bill111.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill111.exe
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko, displayname=Internet Connections NetBIOS
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko\enum, 0=Root\LEGACY_FTDISOKO\0000
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko\enum, count=1
- HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ftdisoko\enum, nextinstance=1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray="[%WINDOWS%]\bill110.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy44.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ppx=[%COMMON_DOCUMENTS%]\My Music\ppx1.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysbetray2=[%WINDOWS%]\sber20.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\bill109.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy64.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Captcha7=rundll "[%PROGRAM_FILES%]\captcha7.dll",captcha
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=[%WINDOWS%]\tag16.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy61.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy82.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysbetray2=[%WINDOWS%]\sber18.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy84.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy81.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy79.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=[%WINDOWS%]\tag14.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy66.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp13.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Captcha5=rundll "[%PROGRAM_FILES%]\captcha5.dll",captcha
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy63.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systwtray=[%WINDOWS%]\twitty07.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy49.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy43.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy50.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy68.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy65.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy67.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy47.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy59.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy60.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo16.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy55.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy54.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy53.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre15.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy48.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=[%WINDOWS%]\tag07.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo14.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo12.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=C:\windows\tag12.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp04.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=[%WINDOWS%]\tag12.exe
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
