Top 10 virus alerts
Testimonials
Hi Jean,
all done. I presume it went smoothly as the computer has not disintegrated into a pile of twinkling dust.
Very many thanks for you help and patience at Exterminate-it. When I contacted Exterminate-it and loaded down your software I was on to my third antispyware company to solve a problem. Two companies had refunded subscription fees to my credit card rather than persevere to fix the problem.
Your team has guided me through the problem. My system has continued to operate through the whole procedure and you have been endearing patient with an old computer geek.
Keep up the excellent work,D.
NetSky Registry Values
Scan your Windows registry for NetSky
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wdpoefan={B525B489-BFB0-409E-B2F9-E83E6C48A457}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vadokmxt={ED9827CA-98E3-46B2-994A-A521487E4171}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={5CD2BD59-E7F5-4103-8050-348276DE099E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={3FF1BE67-E912-46D1-B304-8C06FB138C6C}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, nTZJoa66Qo=[%COMMON_APPDATA%]\ihujstun\yvwtijyt.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={2530CB9A-B025-42D1-83FB-1FAC9AD37AD4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={42BA0D58-AAD5-4E1F-A9A2-B4F04A083702}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, sjPJ0Oe5g8=[%COMMON_APPDATA%]\tyzmpode\hyfmlijc.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={6CBDF760-EEF7-4C03-9FEB-3D07FA8036FE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={0CF365A9-D4FE-4AF2-A6A1-BD1A3C4E2015}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A3C23EB4-498D-4005-AA26-C988B1D2073A}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={E91B4B39-AED9-4B32-8EC3-6F4CAB65D561}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={A9361C57-2DE7-4C18-B7D3-2C4C61268E3B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={9E173CFA-D51E-4633-965B-E8B37E0B987E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {4D80831C-F0AC-4793-B3B5-A4DAB9F869EB}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ChkWinUtil={63397320-E2E5-2180-D571-01E9F87169CF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 6AdR2FheW6=[%COMMON_APPDATA%]\psxgfmrq\hmbstkxg.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={DF6290A5-F244-4501-8FE5-9339790A2B80}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={D158A40E-55D6-477B-9E9B-DA9FEAEE8B15}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={F60D16CB-976E-434A-A274-36F40C9C56E7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={B5E278CD-356F-4F6A-B210-9EA758E14C70}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={70EA6E51-AECF-4A8E-9729-A429B11C0F91}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={E4507ACF-93EB-459A-A558-81531446E948}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={317245A6-0969-48B4-A7C9-5CA9A14E7E6B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={F5E2B936-79CD-41D2-91EC-29C7007D2811}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={53886F08-05C6-43EF-ABC1-64E6BEE58328}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={6068A7B9-746F-430C-A7FA-8A5FEC862CCB}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, vOLODE8jwb=[%COMMON_APPDATA%]\ydidwxqh\ilijinmf.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={29BC1BF3-4AFD-45C7-B95E-4BAA2D294153}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={BA691BC1-498D-4DBA-B408-10E747C596F0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={21AAD242-3A64-44E7-A57B-83A1AF8AA2E9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {63BB2189-05DB-4E6B-9542-82C9A1C53C0B}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {0FA15166-39DA-4DAB-9B1A-0DDDBACA8BD5}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={8E268C2F-B3F9-4FDF-9088-CA1B527C090C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={6F92654E-47B4-4881-BFE2-1A5676EEC0BD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={A3D6D313-D730-4E4F-82F2-ED034EAB4C64}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7D8DAFFA-16AB-49F4-B0B3-ECF9F06997BF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {DC51F59F-D0BA-4CE7-8CDB-15ABF290546E}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={A66227C7-D52B-40A5-B7F5-5251A4379125}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={2A9A6BB0-EB0B-4581-9086-7A1009A3ECDE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={D14A255D-1CFA-4000-8EB9-77CBA94F5D6B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={A60E9582-0695-4404-8BF4-AA9442BD9286}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={9E277DDF-352E-4E95-BD1F-17DD2CA0E033}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={43E9598B-8F73-475F-B420-A7EE51E56DB4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={93D6DA82-8F9B-4F42-9F1C-321145066818}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={06FF139B-4550-4D6F-8AA9-FD5145D16411}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={21346BA5-A424-480C-BF73-79A766760E6D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={2F815D5B-25EF-4970-B58F-71D90DF38591}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={BA30707C-F836-4C53-B7A1-587189495587}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tQneCJnnfJ={7859649E-D2F3-CE34-6EB1-C59C85C2B521}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kbdctrl={E263F018-B767-4D17-8EBF-A151620A0493}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E6C938B3-5DC8-4994-91B7-F04A8A1ACD77}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={DD28AF8C-B384-47F0-8BA9-9244D48DE336}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {C01D990F-AB58-4AB5-B617-C2E4E7961434}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {BF53502D-3BEF-4273-9925-89D7526A5F87}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={5610323E-F4C9-486B-9CFC-E7A5593BDCC4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={0EA2F997-A6FC-4CAE-BFC4-B0A3F73271E0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fQjMfPZMs={DC39DC17-7693-76BD-9FA8-B8DEB7B2F0DD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={6E32A8AE-C712-4E89-9833-0880677BA244}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={BA52E894-BECD-4DF7-96FF-221C221BC122}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={94506773-10C2-4198-8091-A2787E645904}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={C9D3A474-8F82-4A97-BD1A-8CD4FA925E89}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={C97C7C61-0F96-42CD-88DA-5EC5888F710D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={63C481A6-73F4-4E53-90CE-FEDC1A991CB3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pxgdslro={D02AFF8C-D202-4E09-804D-15D07E2486C5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gnowmebk={F0DBF579-28EF-437A-A088-5F04D635702F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bokpkov={55597AAD-43E9-484C-872A-14E69044A353}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Hz2wGym6tm=[%COMMON_APPDATA%]\opizuriv\svgtwhah.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={9F70D936-9CCD-47F5-9762-60C8058937FA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={A7651C26-4649-419D-A482-1FFFA85EC950}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={58A907D2-8319-425F-9FE9-5CDAAD848B4B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F60E370A-71ED-4918-9F6C-A1ADA0FC5C30}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pmsoarbf={8F234BBA-FC28-479F-8139-07122154CA53}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, omlbpkaw={E2D053B3-4B8E-4FC1-B761-CB9EE8A6CA37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={62A27A7B-4E97-4203-B29E-A3A180CEE13C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={91EF41C6-CEE9-4CC8-837B-7933D58D663F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={8E2757F8-8573-4A23-9040-93A0FED9B1C7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {26C0A108-AAE6-4C3D-8910-D80521DF00B3}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={6B225DDA-DDBD-4981-B290-A0BAD2A479BB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={926C9BFB-7D9E-459C-A7B5-486F66BBB1BF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={7415613B-1023-4614-BD67-329DBE990BCC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={15CB5D94-ADA9-406D-8B2F-06A15CC9E092}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={DE45602C-98D0-4F88-B7C3-935B6B90F058}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, apimsgsrv={5B795D70-0442-17E4-1224-0755C2A3B2B3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CYJLBhs={68C049DA-C26A-E370-DE0C-48D47DF627BF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={03758BF5-E4FA-43A2-A484-C0A224B0F0D6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={5FA5FF15-25BA-4997-8B72-E292E29A683F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {326E1D30-5343-4B85-8BD5-DF6852DAA6F3}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={316D1581-97CE-45EF-9516-0745825EC3E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={D6C52A5F-FAE6-4E49-9186-27234A2CF9E9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={A0EBF9FF-BFE9-44A0-BA7C-E915E44F07BE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={AAA19D8C-F122-46FC-8515-0DC90767DB3F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={8034D176-2D9A-4D2B-9C47-85E299AFD3D6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, NDYMRkAqS={320D180F-98A7-B2A5-88B7-DA4E629C8ED9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={7E3E2F65-BB35-4DE9-8D5D-104BC4D8D787}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A24286D9-B33F-4BA1-A512-4DC7CEDA5B08}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={CCCDB22B-4177-47E4-B35B-4F565E06BA91}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tdomgafw={8C33FE70-95EA-478A-8FD5-6B6B7DB8D759}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {9BBD1381-809E-4207-B9CC-949B471878AD}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={5C3BB847-AF1B-4ED3-B3D4-5C9B48DEA518}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, MsgStr={1C2AB994-3CF2-5BF3-24FE-04F843ABF5F7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={501D20E9-D3F6-4D3B-8901-13C0B735DCB4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, neksolda={4EA9D5DA-2250-482A-BDD1-929A0A6C0276}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xgpsarbm={CD1D6001-6B21-4584-8F13-6132704EBF51}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={126963C7-24BC-458E-93C2-0CA6F2036272}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={DF6BD1B0-1A53-4B63-A3B7-E39173F0B669}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {EB6ABD3D-F2E7-4807-B9B6-F62AE3021A17}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {6BB63D88-1867-4FA4-ACDC-0510AE4956E4}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {BD48101F-198F-431B-9DDB-F5CCD0AB4027}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {1E54E389-923C-4DA3-B476-AFC5DB6EA302}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={19B8D460-01F0-4611-A0BD-B0439E00873B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={02E41A14-67C4-4F25-BE79-4756AC23488F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={36995B7C-8E41-4D55-9743-38546091446F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={E3949A81-B553-4B6F-AC29-01AF1363FBF6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={8792B919-27DA-4FB0-99C3-8F951C07BE29}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={39655DBA-D8D8-4D06-B33E-5881D19ACC2A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E4E37F2C-443E-4DC7-89AC-4BAB40222E3C}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {10BE6795-633E-4CC7-BE84-605669ECB604}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, xG0zsmYKYY=[%COMMON_APPDATA%]\lyvitebk\jcvkdolw.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={BD9E21D5-EBA1-46A7-BAEA-B5F5838DA47A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={86AB6CD9-89A7-40D9-917F-74B18A41CF50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E5D6010B-C375-4565-8C45-4E05CA068AD0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={00A600A8-88BC-447A-BE78-59792111B214}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={B5966F59-9146-4752-ABED-D9ED1D8C2A0F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, nh8Kgj6GxY=[%COMMON_APPDATA%]\erujwpit\azstkxin.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, AppSrvCfg={3CCFE94B-6D3F-BB13-E192-0A8920FD01A0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, evgratsm={32011AE2-79D0-4214-845E-22FCEDF55F26}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={EFBA8C45-CC8C-4BF2-8B97-DCFA76BA889C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={877ADEF5-AA3B-4DE8-B64D-3BC213BA7F01}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {FB63658B-C7BB-4E34-B2DA-6C25BB2BCDE6}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={843451C7-9731-4748-AFE0-67E78BA1F297}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={44DDECA2-216D-4E51-8449-C9F5A12401DF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CmdDbHlp={25F82964-8B9A-E723-9BA5-0B739CEC8A00}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E78A2822-3172-4F3D-95A4-865D41A495AF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {BAB8F6DC-41B1-440F-A066-AAC224906880}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E7ECD02B-5C19-4AC1-B702-7CADD47E1EA3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={15F342E5-0D7A-471F-B711-2C12E2E51948}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={CD83B617-6312-4701-8C28-F68CEE7DFA4F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fsrpknov={6C34E62C-9762-4672-BC2B-4620C89EC515}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={61B60079-5529-4791-90F8-38E37746F292}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={D81F01AA-6A71-4C77-AABA-F0D838A693E7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={A84F24BB-9393-43E1-BEF0-2D3A686E5877}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F18D214D-A009-43ED-B6FA-EAC3DD797C7C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hlpinfo={40570F90-8204-3B90-177E-0A82520DE1B9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={A547FFC5-ED19-48AD-BFA0-AC010F390F42}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E813010B-1231-41DC-9599-AE6677794D50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={C88D1D77-4820-479C-9861-D29127F982BA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={BF3F91E0-6F9D-4FBF-A23E-5E2D769E8F52}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 62Nt817MRO=[%COMMON_APPDATA%]\wnsrunkf\aboloxqv.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, InfoAppWeb={0BF78E20-F952-DA10-A777-0234D2541496}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={CF51B00D-0B01-4473-A7CB-31B42519BC48}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={C4467C8F-8A29-4359-BE46-DDB163617285}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={58D9172A-E87F-4025-B523-8E3724E5CD38}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={BDADFE90-C503-4A91-9560-F727DA674006}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF19F.exe=[%SYSTEM%]\YURF19F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUREE92.exe=[%SYSTEM%]\YUREE92.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURE9DE.exe=[%SYSTEM%]\YURE9DE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURE848.exe=[%SYSTEM%]\YURE848.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={898A1061-3DA6-44C0-BCB1-CB833073A66C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={50D26E7B-8960-4AB3-8FE3-606C3CD1AEE9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={42163A04-AF82-48B7-94E3-465BB1AD1716}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DrvPrx={e05621e9-e415-43ea-b75f-92d69951112c}
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General, Wallpaper=%SystemRoot%\Web\def.htm
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={7D019261-3E16-4278-BAC6-744448A82D69}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={EF7466C6-BB1A-4C54-9FBD-88F80D6A5383}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={6F7971E4-34B8-4225-862F-246D842845C5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7856AADE-0DD2-4F8D-9B1D-DABF8DB27565}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, G9zVrBlaif=[%COMMON_APPDATA%]\kfqxibev\ktwlkfcp.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, cfgact={596969F4-4929-4274-525E-07714CDF44C4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={336F34AA-9111-4370-B7D2-F2FE14A30457}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={2B245B4D-A03E-4062-A47B-BA317C4F72E4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {8BA91D58-FBDC-47C6-BAA8-11A0F48C5D27}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={B9FD0E68-C8B1-4E72-972D-B97B3D3E34DE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A2727B35-4F7E-4704-A511-866727BBC9ED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={44284096-F5C3-4E4D-867E-142E197CC67F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F13F81A7-F858-46A9-AF4F-CFCC535FAD5B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={484067F8-3517-4B15-8F31-43F8E2B5A5E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={927DFC03-D65D-469A-B031-A394981E6202}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={0EBCD7FE-81DE-4844-A840-BA882EF31B17}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={0ED3083B-A9A1-4011-B6C0-1EE4795288D9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {CA5DF1DA-5181-4190-B40B-E3FD8FB1EAED}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ApiAct={07717C17-CEFC-78C8-78D6-063E512FFEBA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E8892522-E283-4012-9F60-D852B02C180C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={FDBAD5C1-B42B-4FD5-8EB3-74B64AC7561C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={086B0038-518C-4A7E-9625-CF19A66D61E9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={9A72A972-8F1E-421C-B549-625184253EE6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={2DF5F4C3-AA9D-4BDB-9936-E8FCDFD5415D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E77EAF3D-339D-4070-B532-F8204108E103}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={9C00950A-4035-41ED-9744-D98342AACD99}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={B77BD5B2-176A-4C60-84DD-79381B947BF2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {32678B97-2C98-4D22-A8F6-55C35572E946}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E5F85D38-EB22-4258-B335-6F63F0969A43}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={AF951F3C-F29E-446D-A478-F55FB3242EDB}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR7ECF.exe=[%SYSTEM%]\YUR7ECF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR5E54.exe=[%SYSTEM%]\YUR5E54.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR5A4F.exe=[%SYSTEM%]\YUR5A4F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR584C.exe=[%SYSTEM%]\YUR584C.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, lTWMB7xHgJ=[%COMMON_APPDATA%]\qbetopsr\slojufgr.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={F8BD976A-9714-4E63-999A-68CB909558FA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={185C6FBC-1676-49ED-944D-69A2A3B47E1F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {5D3BF66A-D62D-4D77-A209-8C8317054B1A}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={072E6C23-31FD-4F0E-BEB5-628987B74F44}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={0F708686-BE99-4CBA-8BBC-4A0499FFEF2E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Y3ZRxhiXOF=[%COMMON_APPDATA%]\dutkdgzc\dwlyzcvo.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={9EFA9749-2CB6-48E5-BDBB-23CD15C5E350}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={86F71A7B-4431-484C-A63A-7F3E5FE1E07B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={BE42C1BD-2935-464D-8CA0-C86BE2AF586B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={944B71F2-33BC-48B3-8F27-82ACC0574652}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={049E448D-22F9-4D57-AFDC-EB13AC47618E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={12B1A070-F659-4A9F-8A27-4F9FDD36EF31}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={98903D7E-7530-42AE-B90E-21316A2163BE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F5DBBBE5-527D-441D-BEDB-E92A32205FA7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={79E1CF65-A4EF-4CE8-892F-107FFA5B71D6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={0DB005CE-2D3B-48B7-91D3-76225F5F18FB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={690C496B-D9E2-46ED-8D05-4F408E2D7B4F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A2EBCDEA-A5A4-4537-95C1-EF1A8F0069DB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, LkqdBjsGPA={58F7B2D4-F25D-187E-26CE-59E87611DC3C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={C4E6F051-636E-4D24-9A05-821ABCC36C6A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A4EE1E24-94FE-463B-AEAA-48F3E67EC15D}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR25.exe=[%SYSTEM%]\YUR25.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A91B590B-67E6-4CB4-8741-423AD91E8C1A}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F63CB648-B3AB-4001-A96B-324CE8B2F52C}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={92D7AE66-CB22-4ED8-B848-66070D783441}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={11BBB97A-EA96-4FA3-AAE4-43F4F39CA323}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={6A50760E-71B0-44F4-9FA3-966586E01BE8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={1CB96CA9-3E2E-4A4F-A68A-2ACB55120B93}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2B.exe=[%SYSTEM%]\YUR2B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2A.exe=[%SYSTEM%]\YUR2A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR29.exe=[%SYSTEM%]\YUR29.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR28.exe=[%SYSTEM%]\YUR28.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={9CE815B8-1F41-4D1D-BBEB-C8A9E3DF630F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={EFEDD859-85F9-4ECB-A404-018A4485851C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={4337B175-F3FF-476A-BCD6-917EE04D7BDF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {28944906-7047-4C8E-9639-E6075B73C96D}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFC.exe=[%SYSTEM%]\YURFC.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFB.exe=[%SYSTEM%]\YURFB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFA.exe=[%SYSTEM%]\YURFA.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF9.exe=[%SYSTEM%]\YURF9.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={DF430EB0-EF90-4478-A540-38660E0FEC2C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={53D79A18-4F34-4C76-A849-7DABFAA2E132}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={AF0577CD-D91E-4C73-AA42-AD34FF522F7A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={2EAA6D6A-200D-4397-AE4C-9CFB658F93B8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={07D42B64-8F64-4D86-B7C3-F3B506CE17A1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F7BD98BD-B660-4395-8CEC-3F856329D3D3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={DD1ACC8F-9DA5-4377-A593-C27F4A6A001C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={91869350-DCA2-4F2D-8A77-B2D35E445CBF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xvorfwbd={9A49DA90-9B19-48C6-B723-9F8EBF846D52}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wpvmqosg={B6D48B96-62CD-4BC9-A0D2-80D8197E83AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={7FF0BF59-29C9-456B-98E1-AA25931999E6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F8284C0A-6B71-46BB-B134-831CAC7AF90C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={49B56E58-AD9B-44D3-8822-A5024A370B04}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={533361A8-AA72-406D-A194-69727E9282FE}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17F.exe=[%SYSTEM%]\YUR17F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17E.exe=[%SYSTEM%]\YUR17E.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17C.exe=[%SYSTEM%]\YUR17C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR178.exe=[%SYSTEM%]\YUR178.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={244CFADE-44A3-466A-B663-D03261A2BB55}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={B2373385-3907-42B4-8AA4-63D1BBEFB5AE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={4712B782-349C-4850-A7AE-847ECD4DA8A9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {BECDB70D-AE92-4B86-A8D5-0790D704B299}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={ACA43D9E-79B3-47F6-840E-E92575A92CE8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={BDBB06AC-8895-40A5-8638-7CFEDF17AC4B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={ECA2A9F6-02DA-44F2-9253-BCD3D1C08C6F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={008AAED0-981E-48CD-8AFC-2F138F6CB618}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={36CF9192-9B75-4825-90A4-4E9B37497954}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7E90843A-02EC-4852-B2D1-59E3FA0CB765}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jYUBhoy={0CBB229D-A611-8837-F4C5-9ECA4FF39420}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={BF6D2574-F039-4A4F-B70C-6EA35A0A3CFF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={693E4171-B147-4BC3-897A-F3BA90E4DD42}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={208311EA-D49E-47EF-85AA-841596601C6A}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR18.exe=[%SYSTEM%]\YUR18.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR16.exe=[%SYSTEM%]\YUR16.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR15.exe=[%SYSTEM%]\YUR15.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR14.exe=[%SYSTEM%]\YUR14.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={3B9B67C6-9175-4B60-BC0E-97B7C96B07EE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tdomgafw={3CCC5A8D-27E0-4CAC-A444-BD45E4442C37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={3508ECFD-4328-48CD-B9C1-5E0A69282C8A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={5E32E7B5-61A2-4622-AB9D-161575293B10}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, uvozgfel={417ffc4d-9e4d-4a79-9874-29c013867ae9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={41BA9396-3CF7-4392-99AE-649A0F0AEE96}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={44832247-E194-4FDB-B532-486AE453E273}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {1C67BD5F-A9EA-4FD0-A1D8-0AD71E86D48A}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4901.exe=[%SYSTEM%]\YUR4901.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4587.exe=[%SYSTEM%]\YUR4587.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4105.exe=[%SYSTEM%]\YUR4105.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3CC1.exe=[%SYSTEM%]\YUR3CC1.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={36EAC5F9-4EAE-4501-B7A1-903E730D2FB3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C3327420-297D-4028-A3B4-40BEDBE7169F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={8C6E7650-AC38-45C7-B01F-B1A308081564}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={C09D646B-3724-4F54-8DFE-E95D7D6EB70B}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1A.exe=[%SYSTEM%]\YUR1A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR19.exe=[%SYSTEM%]\YUR19.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17.exe=[%SYSTEM%]\YUR17.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, AQEli={48E53AEA-E24F-9040-D59C-27F46E08A047}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xbrxWT={0C49BB6D-A6E3-11C7-8ED0-996A4FBAE088}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={61962A3A-464D-49C9-8C2C-686428081EB7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tdomgafw={0077CD8B-F7D3-4CE8-B4DB-659647E4130B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F735FAE6-2D9E-4818-8705-EB3CCAF9331D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={51275C01-3F2F-4D1D-B98E-34271CDC9292}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={A013FFDD-CFCD-4588-80F2-6382F4A4E687}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CltfiTN={847D8932-2ED7-2398-4F58-EF048BD4C76B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={616C1A3B-9670-44AB-8DA1-F659ECE1CF37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={24AEF888-26C2-4244-B746-A99414A93989}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vregfwlx={8EAA5B7F-C5BF-4E1C-9253-289C82E1984B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, ERAG0Uzw2G=[%COMMON_APPDATA%]\ubcnqtih\idyninyj.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pmsoarbf={51CA5294-BA0C-4F93-B0E7-76E6C7FB48AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, omlbpkaw={B9B02A38-F5FA-4218-9EAF-D520BDA30723}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ohejidof={eda56d51-83dc-4f4e-94ec-ac1b97a3159c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, oNyBzVwQnLcC={54ECD006-FE46-7AAC-1D66-B0EC740C6AD5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={223D2FB4-6780-4B29-A286-5452BAFE29FD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F045CEE1-3A82-4955-9410-9CE139FA2798}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1B95C29D-16B2-4497-83D4-0E1BF67B48E3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={FCE5E131-AECD-4C65-BFD2-7BA631F8AE22}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={AB864F2E-A06C-4F9B-A0BB-19274D48223E}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rcKpYUF1gr=[%COMMON_APPDATA%]\tizapepi\zmvojibg.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={CEA9FD84-F2FB-4B42-9544-B6D89D33E5BA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={4D211F57-1EAB-4FFA-AF55-CC6512962D8D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {DFEAE9D3-90B8-4F9E-8AC2-8317693C94BA}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR926.exe=[%SYSTEM%]\YUR926.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E6678262-A19A-4EDD-B0A6-975667D5BD61}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7B5A32E6-BE6C-4F4C-9BA2-22298241C7F1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {E5ACC10D-16BD-42DB-9AAB-283DF9B3A4EA}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFE22.exe=[%SYSTEM%]\YURFE22.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF9A0.exe=[%SYSTEM%]\YURF9A0.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF59A.exe=[%SYSTEM%]\YURF59A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF202.exe=[%SYSTEM%]\YURF202.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={9C6DAD15-92A7-454D-8314-3EF4779DF089}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={DE356CEB-5951-4568-9587-36AEC5C2DC24}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={97BEF441-D6D1-49A0-AA02-A6384292BF2B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={BB451B73-2F9C-4261-8870-43B854D9A355}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ADD7524F-35F7-4CBB-92BB-E3D9E36DFEA2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={9F59D18F-80AB-4296-9432-A67F9B8DB0AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F2A6A4F9-82A2-4376-AFCB-7923901ABBEA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D1357694-D243-408B-AD7D-9A60F1341892}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3C37D805-A9CE-40BB-A403-C227D11C347C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={BF41A424-7CA7-42B3-8B40-6D18E6A76B79}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={B2F88D40-9006-440E-A7B7-9E616F60C0DF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6048865C-4BB5-4F36-AD7D-7B29D367C3D4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2809F3ED-73B7-4420-8AF7-EDDF0CC38871}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EBEF2595-431C-4F44-BA12-4FFBB3A03BAA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msgsh={11D27D17-014C-6C6E-BE75-02ECD1109574}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, InfoSh={4A0CFEA9-3FAA-4875-B4F6-0778DBF243BD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgsvflkw={3DA90683-BD3D-4C66-BC5A-B32FB7DE2E07}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={78769DC4-14A5-4777-A16D-CAE58A58B4C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={622C3AEA-BE88-4217-924F-C5B79427EB8E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A5C24FC0-CAAD-4F2C-B82E-BB1ABF62F2FF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5C8E6A98-ED78-494D-B4F0-368AF534EBDE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E8797073-C230-43DA-B1C6-815EA16E9462}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {5371FF76-9602-4029-9626-BE8CD757EB36}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vbksrofa={A097B6F8-B2E1-4794-A15A-F9FA7C2FC86E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pmsoarbf={ACA03255-B158-48A0-A484-3A680A7E7C09}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mpfanvqg={6CCDB726-E260-428B-8459-2AB0CCC3B09F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {953D575D-6A6D-4E5A-BB87-CF5C3C1A9A36}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={352D3218-18ED-4946-BC0C-FB6050BADA2B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C0EBB4CF-59A3-466E-8950-216943AC14C8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bdkpfxqw={A1FE1A5E-312E-4DA6-B327-82B01670D01E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={84116BAC-EF2F-4555-A941-CFB8EB67840C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FC4B1021-E761-4060-B4C8-BBDDD8E60470}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A3F085DC-BA33-4546-8DB0-70DDA1AA7707}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3C66E15A-808C-49F5-84D7-2FA3E23D305E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={74889A48-921A-4FA5-ACC9-159BE2A6498E}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR174.exe=[%SYSTEM%]\YUR174.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR173.exe=[%SYSTEM%]\YUR173.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR172.exe=[%SYSTEM%]\YUR172.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR171.exe=[%SYSTEM%]\YUR171.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, winmon={37C3DC82-EB3D-3DD9-F48E-09C9EFDFEB42}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={2C7B769A-F905-41A0-9A02-7B2116AC5AA6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={81427609-BD52-43B1-9BF1-D1DAA5BFE2DD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {7A435241-0F51-4BBC-8E64-D2B613E7AA46}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={D476B659-917C-43EB-BA1D-1ECA4BA43FBC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={924AB76B-18E0-468D-B9A1-47EC5BE903C7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={4352CED4-D978-4FEF-AA46-E9708403750E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wbqxfpgl={47864F82-EA2E-4FD9-B567-530C98C64CFD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1E05117E-82E4-4D17-9003-4BD58E8D2DF5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9B41B7ED-7267-4F4E-8127-A758CC18385C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={61E02284-699B-4AC3-85C9-106CE533E1B7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={A3B9D6E6-3F62-4D72-8B0A-E1F6252A2DEF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={88A532A7-0E7B-41D9-9E9A-7D5743D08A2E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2053032F-51EC-403B-878C-66EBEFEA67D5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9B2.exe=[%SYSTEM%]\YUR9B2.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9B1.exe=[%SYSTEM%]\YUR9B1.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9B0.exe=[%SYSTEM%]\YUR9B0.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9AF.exe=[%SYSTEM%]\YUR9AF.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E2D450B3-2F6B-4071-954B-0D43B5FF6420}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1EFF883D-38DD-4708-B0EE-403FAF36E360}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={8981BFFB-1BDB-4876-9CFC-EDE5BD2F2B08}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {89F51B26-A3FB-487C-B4E8-334CC35795A1}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={DB82B9C9-CF8D-4ECF-BF2D-CAA5A0FE735D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={DED4B1C8-BEB4-4089-AF71-57D4C29AA3DC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={7D210C37-F882-4E79-BD85-2A3AA3B4EBDB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C12E1949-1BE2-442F-B86F-6A37734181C8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bokpkov={45CF7CCC-9813-403B-B686-502124CE5B36}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, altvxvm={9320153D-E801-43DA-AA26-B4D2FAE46BBD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={42584033-B7B2-42A1-937C-D4EBB7D8F0DD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FA04F3A1-284D-4937-B85E-15DD444CA1CF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CED92C57-1E6E-4D24-9AF5-B150399D11D9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={83833C8C-DD6E-4C76-93E3-73EAA4004534}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={5B73C627-F0B8-448D-BCC2-CF766B2CD9CE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={0536FDEA-8CF3-4597-89F1-67BABDB9C74F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={D570C370-B73A-4B91-9C7B-DAAACBD2CC44}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2CEFB58E-4859-43CF-B2B4-0DCAE2FEDB39}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={451376F4-38FD-4EAA-A19F-3FBF78832B9E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={45528941-1650-43C6-A26B-8936617B8D14}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6F0D15D3-BED6-48A4-B928-12F6BA7E8E61}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1BD9E285-ADD4-4734-94A6-A8068B5A0B50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C921936E-58E3-43D1-B606-FA032B5F81D0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={452988F7-AA58-4F24-8EA8-D76B2B988BD8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={39427AED-1471-4690-9243-65BC2FAE08A1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={61BBC309-4C90-4C8A-BCB6-3ED56C2D1593}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={66A7D078-C473-4CA9-B8F6-C42F893C15A1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 0CHnHLYo4z=[%COMMON_APPDATA%]\qrqfuvqd\sledyryf.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fsrpknov={124159FD-D1C1-4C3C-AB6D-28D5248353EC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {28FE3E9C-E177-4D1D-93B2-14CD61F4ADD3}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {206DDC12-B015-499C-9981-BC5863B027CA}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E773C87A-DA1D-4638-AAD1-7C1E9154CA37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5A7C1563-1ACD-4812-AC4B-64AC096EF7E1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2BA05FEC-0676-48C6-9FDB-811C5B15F95C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E52F3AEE-1EE7-4D57-B1B3-0BACAC5B181A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={DFBF7B95-77BB-4757-9F76-03164A3F8514}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F8D248FD-E148-46AD-BF55-DA33CA1D541D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={B690078C-5D58-4C07-B4FA-86B2FF3EFB97}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D6.exe=[%SYSTEM%]\YUR1D6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D5.exe=[%SYSTEM%]\YUR1D5.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D4.exe=[%SYSTEM%]\YUR1D4.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D3.exe=[%SYSTEM%]\YUR1D3.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3D208066-75BE-4962-92FF-2FE444BEAF56}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={5B7FECDC-9702-40C0-846F-0A5FFB3E81F2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={EB6337B4-51A3-4125-93BD-8C848A67D30F}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC5DE.exe=[%SYSTEM%]\YURC5DE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC39D.exe=[%SYSTEM%]\YURC39D.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURBFA7.exe=[%SYSTEM%]\YURBFA7.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURBE40.exe=[%SYSTEM%]\YURBE40.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={BEFB3339-75D7-4F29-A9FF-14D1633BA068}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3D56F15E-6227-4896-B604-284C387E823A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={36D4701D-61EE-4405-8ADA-870AC3A5171C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C577F8A0-91CB-412A-85A8-3F9C3E8DD37C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fsrpknov={E5B820F4-F3CD-4B97-8297-F8072EAC3D86}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3D9EE25E-26C3-4941-8CA5-6733DA38150E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F93E2DDD-58DD-4EEF-BFB7-7B48CAFA5DAB}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AF.exe=[%SYSTEM%]\YUR1AF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AE.exe=[%SYSTEM%]\YUR1AE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AB.exe=[%SYSTEM%]\YUR1AB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AA.exe=[%SYSTEM%]\YUR1AA.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2391D513-EFBD-4AC3-B7A3-05A3F02BCE16}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F43A6D20-CF03-4ED4-BE34-D5F4F2A92BC5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={170E661B-CCFE-45C5-B380-6B46780AABC7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={D0D34414-75F8-46C5-8929-7E84E93A21E5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E7FF9CD6-965C-498E-8A51-C04AC8332A0C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F1E1734D-DB1E-44DB-951C-10DC09FFAB25}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={609E02BB-FB3E-46D1-A203-2514DB00465F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {E92E9D54-85D0-4B31-AB61-16253EE625B6}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12E.exe=[%SYSTEM%]\YUR12E.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12D.exe=[%SYSTEM%]\YUR12D.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12C.exe=[%SYSTEM%]\YUR12C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12B.exe=[%SYSTEM%]\YUR12B.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ADD22D56-3505-4FEC-B69B-F37DA412559E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {30ACFAA9-78D6-4C11-845C-804AF8AAC89F}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1E4F85C9-3767-4EBF-9625-1709859B2CC8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E9977779-D099-4F19-8BD6-4DC8CBF9D3AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1099178A-F7A2-46CE-AB76-BCA722236425}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={052AB6D1-82D1-47FF-8659-B2C036C971E8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EEC124D7-CF39-40E8-B191-4D24C74148EE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={C6EA1694-CB74-40C6-8E21-811E14F5F06E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B6CAD3B3-52DF-461E-9553-7A27EC963733}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gnowmebk={F38C5A70-7A98-4E67-82C4-050A959E2E05}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {C9A66198-D585-4160-A963-A889176926B0}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={4ABF4CAF-69D9-4714-AC25-A74428605B6A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={05715F60-00CB-4313-A5AB-D4EF9277D87E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B85519D8-FAF7-4DD1-AC28-E35DA3A2BD60}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={5A440159-B98A-49DE-8307-9698CF2B2B58}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={829FC829-5152-4BC7-9EBB-2F1058D1FE37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={7939E25E-F1DF-4DBD-B752-FEF645901A78}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={591304CF-167C-4AFC-B263-6D28F3A01074}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={25823B0E-E345-464B-B269-B86E79BEBFCA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7DE7DA20-80E3-4506-8970-508A24931DA6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2DCA93F3-C25E-4192-944C-2B172BF1DE0C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={21D38B0C-23C4-40D0-8EB0-1FFE95D522CE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2827859F-7BA4-4134-BB87-A72E63CD7FBC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={B4B06B61-B206-4C0E-BFE4-E3552484BF46}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, evgratsm={6177D367-7F6E-411D-A2B2-9A150D5E5564}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D555FCF4-C7B3-482D-A382-D6F7178B0A71}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={11475C8A-4BE9-4CDB-B991-FB033E21CFAC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A3AC6E80-6FAE-4B5C-9901-488A75685383}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F54B5C35-6050-47FD-9040-92418918CF50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B5BB4C4D-C958-4566-A9CA-403EE3E04E2D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3A48F694-4687-4FA4-8F29-7DBA5783478B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={544A050D-A342-4B7C-94A3-B79800977B6A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={A481A7FE-790A-48B6-8DF5-AB03967D380C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={4F034BA8-8D2F-499B-9E26-57F90A098BB1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={6840ED43-7BAB-467B-851B-55CEBE2F1BE1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, evgratsm={D73D5CD6-F809-40A0-A8F1-52F69C7B3966}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DbProcChk={4A0CFEA9-3FAA-4875-B4F6-0778DBF243BD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1C6338F4-C3B9-432A-98CC-A2451E4ACC9F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={808FBE7E-CC31-4C7C-9E89-22213F3A4363}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2FB05857-388E-4DC4-BF59-92627B76FF77}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={67B22818-6A63-4094-A083-DE46F091EDCB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={FFB33CD3-57B9-4464-9C75-FD614045B4B3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9990113C-DCF8-4BF9-A7AD-1188B044D2C3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={A85810B0-6D8B-47B1-9E3D-876C49AA5E9D}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURDA37.exe=[%SYSTEM%]\YURDA37.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD62F.exe=[%SYSTEM%]\YURD62F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD0A1.exe=[%SYSTEM%]\YURD0A1.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURCBBF.exe=[%SYSTEM%]\YURCBBF.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, NXwbwSN7sg=[%COMMON_APPDATA%]\hgnihajk\jkdwrwzw.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A31A0513-D9DB-4A3F-83DC-2CA1632085AE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={7BDA2F51-C110-4017-B675-AB7B58D88667}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2EAF0201-2623-4936-B209-37DB5A51B010}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={FCF5400F-0A0E-4523-96F9-8A33C353B2A5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={670BADAB-CB0F-45C9-A308-2205F72749AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={84E4655A-164E-48D8-8D85-DD6D84A61DFC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F27873A3-AE07-4302-8440-E5CB352E72C6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1635F596-FE51-4DAD-9CD9-0718F7C14DC8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, btrklfr={9C84D3E9-017F-4858-A755-2ABC6E96E829}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, apdqnxp={AF8D0308-68D1-4AB7-98C6-FCA35EADD88B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={38D5C9E1-7739-4B05-BC81-6AD17040B38A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EAA06D31-2732-4D39-8809-2A4C1471228F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CA8E83FD-3E82-43E2-A978-4309283B4226}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E55B6DC4-1DEE-4BE0-BC92-2C0A695D5289}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A1BB3A1E-F35E-4FAE-A8EF-87C6B9683FC4}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA8E3.exe=[%SYSTEM%]\YURA8E3.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA6FF.exe=[%SYSTEM%]\YURA6FF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA27B.exe=[%SYSTEM%]\YURA27B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9F9C.exe=[%SYSTEM%]\YUR9F9C.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={848A4B4D-1301-4CB5-B667-17B6F2FEBAC9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F66184D4-B47B-4E5A-AA58-AF4D678E7990}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={8262B0BB-C3D6-40D3-BE47-C34BB39DF5A7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, G9zVrBlaif=[%COMMON_APPDATA%]\fknsbuha\ncrkdybq.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CE7A5900-4065-494D-A0D3-CD3462C090AA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E7B21765-2825-4397-888F-0ECBCB41C1D0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, lOZQwlLksA=[%COMMON_APPDATA%]\jgfubybo\dkxqrqzq.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bklgvsf={DD76AD19-7AF3-4ECF-A31B-4B3731377C81}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ampkfst={989CC160-5D46-4C9E-993F-0E1838D3C9E0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={ABE4593A-5974-4048-94DC-8186D6306421}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={52E991FB-C208-467A-84D2-CBA9530C70E4}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4C6B.exe=[%SYSTEM%]\YUR4C6B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4AF4.exe=[%SYSTEM%]\YUR4AF4.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR470E.exe=[%SYSTEM%]\YUR470E.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR45D6.exe=[%SYSTEM%]\YUR45D6.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={AD186A5F-3629-4884-B3D5-D62CDBEEEA40}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1C66F552-8229-49BA-9BEF-78F87B49D151}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1CA6.exe=[%SYSTEM%]\YUR1CA6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AC3.exe=[%SYSTEM%]\YUR1AC3.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR16FC.exe=[%SYSTEM%]\YUR16FC.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR15A4.exe=[%SYSTEM%]\YUR15A4.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F03F4F28-C020-4910-ABE6-888919CB784D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={CF202593-A5D7-4296-B1BF-821CF296D8C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E9968F93-C98B-49F2-A40D-E176DF2BC307}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={62D1BB0A-0CF8-439D-9F19-2EC0E8C9CEF8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {D355A751-C166-4351-8112-0EB0775E1B16}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={CCAF41CA-AD7B-4A2D-8B0C-E2FC7AF4A4E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={681FF80A-F748-4988-B6B6-81D329196288}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9488CD49-5466-4FD5-A637-0AC70BD401DC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={906E9433-F984-464B-9275-0F5C14AB9356}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={42880B02-56E7-495B-B25D-0EEC9CD4A227}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={548DE7F9-468B-4C17-82F2-F82B424D0E73}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7D108250-DCB6-4F6C-B6D7-E8AFD51DF3C5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3C.exe=[%SYSTEM%]\YUR3C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3B.exe=[%SYSTEM%]\YUR3B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3A.exe=[%SYSTEM%]\YUR3A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR39.exe=[%SYSTEM%]\YUR39.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msmhost={5D64F95C-3E02-429E-BD9E-3057977AB589}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msmdev={BB628EFC-86E1-426E-AAA2-39236CBFD6D8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={2CA1CE1E-DF12-41E4-A52F-01C1877DA0A4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={DDE9F340-CAB4-4C8A-8443-A00266430E87}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E3BD65DB-6A6A-4811-93CD-676F66F80FA5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FF173CFD-130D-427B-95EE-D9D0EA178B33}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bxlrvps={0AA01F01-D9AA-47BA-BCC3-CC12F12494F4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, alofkmn={53637B2C-7682-4BF6-ABD9-799AA0FA417E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5F36E835-FF52-4E93-8AF7-70619D3F31C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={70F5FE77-BB5F-4262-ADE2-F8FDFDB9884D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={AC589E37-C2BF-47D4-99B4-F7D450E1A978}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F137EF73-D32C-4B14-A04E-1C6C1E6AAD61}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7F9BD5F0-3CC3-4D0A-9F72-6DD0C0E2FBF3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={FBA31B17-FF5A-4EB5-8D2F-55226875AC99}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={E6933515-3A2A-4A83-AE11-E361CD0A0A0C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={0F17909F-736D-4945-8478-A88C76D7500D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2BF8FB90-413F-4FC2-B243-AB86E3937FE4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {CF83D74E-ED31-490D-B8EA-DA20D79F79EB}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={CDFFDA73-874B-42A8-8D71-E4C12A7524AC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5EF47D96-3BEA-48E0-99AF-AFF971DF81DD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={18F884EB-D124-42C3-A80B-3DA4C7C8A8B4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={6FCDDDEF-1519-4472-BD32-BF7BD789E7CC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6B13DADD-8574-4B3D-AD2B-7CC2222187ED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={38553345-130C-4997-B620-EB52A4D30D94}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E6BD1D63-FD35-4D6B-90FF-E22E072B6B95}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E186EB92-7E46-44AC-96CD-CCB804EE0C32}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={09BC086C-42C9-414B-A58F-50543C318999}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, qdnkewfa={438EA28A-A0F6-4683-AA89-95F5E893903E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgsvflkw={496E6BD5-16FD-4604-888A-85BF20DC4A2B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {7976222E-DC29-45CD-87EA-9D2397B52D0E}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={582E670D-E578-4F08-B6B0-43DF57D73106}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ABABF7A5-F385-46C0-B2AD-CDAA6E110AF8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={61F42D6F-C1F3-4D4A-8511-EA0AB7DED9ED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={09735BA8-B566-4015-BCE1-0F7AF2A20A31}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5CD1C326-2FCA-4394-ABD6-F0CCDE376ADF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={D9215A25-40E6-4FB0-9D55-5DBB151E6EC6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Qq2z7muloc=[%COMMON_APPDATA%]\hopshopu\hsncluja.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={83DCEE07-A88E-4B37-8E35-A9494274223F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={DBEAC386-D528-482F-8343-C8266A9AA639}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7D7B1536-9065-420E-9671-01CE6C10D98D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {B02C10A6-38D7-4CBB-988A-D511F9B114F7}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={C7CFEECB-3BEE-4924-B4E8-C374031ED250}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={015D077C-0A4C-4BC0-B2A1-93337F7963D0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={4D5A007A-1BB2-4092-A8D8-CC4FB24C34AC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={70E29C25-457D-4543-B4AA-DF9CDF377AD4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {4BB9EDD1-CE63-4ABF-8B79-8D5CAB9BBAEA}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={51333B54-5E61-4A18-BEB0-EACA6C67F526}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3C4A72CA-B302-4D98-A912-405D172E3526}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rnopbfgt={DF80DAD3-239A-4411-98F5-811295C8335F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F83D77A1-0491-4B24-B0CA-D0E8D5B25EEC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={573D7F0A-D708-4D02-B9E6-36412E58304F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EF6C53F9-A396-414A-AA88-6436DA1F1A82}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={58404AB1-5900-471A-A75A-8169701A8A23}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E34EABFC-DDD5-4849-B741-4B0F4BE0BE4A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FB168FB8-4D5A-4A9B-8D9C-06A504E17032}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B84DE707-F56F-462C-A981-1E95135E671C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ED95960A-0C58-43DB-A86F-AAFDEF97928C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E447CB5D-9C69-4D5B-8B1B-DF109DB04CD9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F016D54B-6B00-47B8-882D-296D2B2D9579}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1DE3AB69-D38A-4252-881F-D30E72C38ADA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={75C5B586-E359-4EAF-A3CE-66AD80A5384F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {2D8F572A-0382-4212-B2DD-F4D95B508189}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C5AFC39F-32D7-402B-A04E-A5B21878C36D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DscInfoSys={3473E3A6-CE7B-4F23-F5CE-08A00AA7515B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5E1AA605-9E0C-4E96-97C1-E77CF84F1483}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C79BA1D3-E741-48B8-A20D-F191CDB51D9F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={79CDA69A-509B-45C7-A7CF-2B8C41262087}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={AA93392D-D074-43DF-BC10-0AA3F892179B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vltdfabw={690B69F5-9C79-441B-B7B4-F781CEF82D77}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, HlpProcMon={5B85C1EC-5B55-AF6F-11A5-08A108CED0AC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F901B9BA-04ED-40B0-9B7B-EB714BB51DD6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2B33960D-3794-440A-90F6-6EA96E5EB007}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A00C7A68-87B7-4CAE-9470-6B7CD75E4F23}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={4B70FBCF-A8AF-48EA-9CAB-EAE74A508D87}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3D974367-324C-4941-B3C7-B96ADE2223A2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {94E952A4-FAE1-40E5-BBE1-8199D8CF7FD0}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D2376858-44B0-4836-BD76-8CAE0D6D8C5C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E5F801C1-75DB-4190-A73E-504E153FEC0F}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9.exe=[%SYSTEM%]\YUR9.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR8.exe=[%SYSTEM%]\YUR8.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR6.exe=[%SYSTEM%]\YUR6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR5.exe=[%SYSTEM%]\YUR5.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, btrklfr={7F441FBB-1088-479E-B982-E801761D3A19}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bdmanager={43246AFA-F3C5-4200-9DC9-49DB76B41054}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, apdqnxp={F22D388D-E65A-438C-852B-52C001154B54}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, admgcx={D4EA2B86-20AD-4FC3-A1D9-C97E011A27E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={970C277A-49FD-44B9-B5A8-2B3BAB22E0EB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7EBA8C48-944C-4243-8575-44DFE4C1F84F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D9EFA498-38AF-4F38-BD9B-F87ED87D8238}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={911CF70C-071E-4484-8D26-F4671FA790D9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={284FABC3-94BC-401C-9E56-F1F930141F51}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={863C0071-C39F-402E-8F12-94F36ECF27C4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1FF52BE9-7727-4219-8D11-434DA15BB332}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={23D5CE64-6F0B-489D-AEF5-9882F97248D6}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURBF.exe=[%SYSTEM%]\YURBF.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F49E4C08-5679-4BC1-8860-4F1F21CAD9B4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={1DAE5E24-AFDA-48FB-8116-2E53DD29D8F0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {ABA69CF4-20FB-42CE-BB6D-B6171D64B8EC}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F661BA6B-FAF4-4165-A701-F65A7585AC91}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={BAE0C5AA-71A3-47C4-B1C5-EF77282A8ADB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={0379121B-C5FD-4FEF-B7EB-77064311A422}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={BF1C4A3F-940D-461B-A4B6-FDBC1C8D2C05}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {CF876BE1-CCD4-493C-ACAC-C6DC7E5615EB}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vtqnxfko={65535A84-765F-4DC0-B045-CD02AE2671D2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tsxngabr={ED5590E0-6965-4DDD-8258-0B9DFE1BB3AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2EECCF8D-C3B2-435A-B94E-61E2453105AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9A097075-19FB-4333-AE60-EE59611CC599}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={71F6316D-2549-4300-BC4D-506807B4264D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A42E4C52-8D2E-4F10-BF7D-0E5CD09EA2A2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {9F342F63-3E27-4BB6-8A01-D7C2C6FEB055}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6B9A3929-EBFB-4E77-A8A1-A50097E4389D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={83A9F555-B7E4-4757-A92F-4416A256EB72}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={59B84BC2-89A6-4F1D-934A-D19B9E5BFFA6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={5AE69121-B7C2-40A0-A3CE-F5A8D538D028}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={41A27D41-B35C-4B33-9533-E0B1FEC7F556}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={56920BA8-DD59-4D7C-9CBD-218F0F5FF5AB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, comcmd={6C9BFDF8-97B9-349F-120C-0B1B33BEF07F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={81F54C6E-F780-4EE9-8F0B-94CD2A4C2BED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wbqxfpgl={6469C827-FB4C-4B72-8EDB-284967FA6D6E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tpabfelq={CB3F4F8C-F10B-40E1-9280-5EC50CC9C6AD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={78872E2E-374D-402A-AC1E-DC3D411E89BD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={241071A7-EE56-40A5-B5AD-1B396DA0B0FB}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Qgd1WPdg18=[%COMMON_APPDATA%]\vgvytuni\nsbinola.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, PreBootCheck={c856e18b-14e3-4c26-90da-b625d9cb251a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={ED46EECC-EEF4-45CB-B72B-57D5E532A084}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={2059D3B8-E148-4601-8D48-0C1F379D0718}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {3CC64413-8D34-4336-A176-4DA5F7C147F1}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={6005AB06-B0C5-4B45-8CAD-5F3DBF509012}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {E7B781BF-C1BE-41AB-BE83-ECA71A575F97}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, qadovnel={86C7762F-B33A-4D25-BC21-56376D80F669}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={E5030823-33F2-4604-853D-223613799B23}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {480473F2-2C60-4CBE-812C-C09F4C7AE483}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CF663CEC-AA7C-4BFB-8046-32A7ED6FE0F4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={14231DBE-A894-4B3B-BE6D-A34CBE513BF9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, HlpSh={4A0CFEA9-3FAA-4875-B4F6-0778DBF243BD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, XVXLfqhcBD=[%COMMON_APPDATA%]\nwlexyby\tmhuhyfy.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E5C9FA79-5E3C-4686-9FCD-AD55A9D8C614}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2507B5FC-2D6C-45AC-8A00-4A211FB35CD1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={CD0EF9C6-AF85-4D47-A087-9C9DB1B6774E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={DB0E7965-A751-418A-8FFB-DFB0671B6476}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={48B099F9-CF7C-4E5F-B17C-794F4B145465}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5A477133-AE0F-4CBA-AB91-F319D62EBA55}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7FA73391-3A26-4430-9D8D-0C1DD7943364}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={196E1BC3-CD6D-42A6-AB7C-4C226A714227}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={0373BE29-12C2-449D-A390-D6BC58FFF768}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {64D115E0-EF9F-4980-AAF3-F1BC78E0AF05}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {DA708AB1-837F-4230-B4E9-92E98A2CEB06}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={16C7400F-5F47-4F2A-8E9E-1C7256E04C6B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={44FA564B-B552-4AD5-B26E-F501C2DAE108}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {75745753-36ED-47BC-B54B-CFCA6403B379}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={73DA20E5-C756-469D-8C40-8600F9244762}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3A13B7F6-3618-4BBC-9ACC-4DD34EC65E29}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={674CE53C-A9CD-4AD9-82E9-5070ADA9BC28}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5AA9FD91-4429-4EF8-8F77-E00C4845D6D3}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, uKG2v24KsF=[%COMMON_APPDATA%]\yxcdcteh\sxivwdwb.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={8E94EDC7-EEF6-4AEF-9B1B-21B94596A34E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={63B8E8B1-122C-4866-A7BB-2AEA405DA959}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={8BFA6F5B-ADF2-46D3-A9C5-BB86B2F5934E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={64F2DC19-DD59-4E66-B463-527DDED1E31E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={8090A859-6EE7-4FF1-A74F-7FEE8E44FF49}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={5287AE5D-4CFC-4F00-B319-CF0C3D52AC14}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={EFC5B3C1-1C1A-4965-B42D-D91C0D7F4F04}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={87A8284B-A93C-4AA2-83BB-F56377EDBD28}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, actsys={1BFF2A7A-B2A7-4029-4874-01984DD7F341}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={169A47DB-6CDF-4BF9-8F26-39E3B0361EC0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F87E9BE8-5B1E-48F0-BDCB-5FB552CB55F0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {FC907671-A480-49CF-8953-F5E5CA145228}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={B0A8274F-B19B-4351-9AEB-D54A3E2ADAD4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={5FCC70C2-4169-4EEA-AFB7-BF6F8500C0B9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={583A7C16-134E-40E6-A623-5D83CFF0471C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msmhost={AF443167-291A-48AC-8952-585D137C58DC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msmdev={7297BDC7-6C2C-467E-A63D-D1E3AE78868F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {9638003E-5BE9-4A57-98BA-CA691478858A}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Y0VNh6hzSJ=[%COMMON_APPDATA%]\zelkrqxq\dmzulyds.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={EA6DE3AB-6CAC-4B12-A28C-9CC7656A77B9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E39566ED-520B-4D17-A9B0-979C0EE5CC74}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={398C4803-6C66-43C7-8929-DE805E7B6377}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={17E3346F-34D7-408B-878F-CC02C17E283D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={B9131182-64DC-467E-B2FB-7D9B901BCF90}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={7E6D52F4-33E2-4A06-AB94-1C2CC0AD5A5C}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F71B2A6B-F337-4737-B282-F7F721E527AC}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={6B5F3D32-840F-4263-B64D-1B25EC6BCB32}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={B3180820-16EB-4A28-AEC7-164DBE3FDF49}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={C10F0BEB-647F-475A-879C-A6FC2ADE595F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={6E7785AA-2257-4524-87B1-F6DA227FAE7F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={F08AF86D-BE28-4CDF-A267-5211F8DF641F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={A9466824-43F7-4CBC-AB06-2C0BF5DB75E6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {B766F1CE-A1FD-448E-A03D-5C68DB7F1EC3}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 3hc3KZOvJi=[%COMMON_APPDATA%]\gxojcluv\stufqpad.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={6E6C73F6-F498-40B8-8F5B-1BC0FDE6F7BA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={A087624A-90E5-4F2C-A3A4-8C864A6D8212}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={2064950C-FC9E-4C52-B3E4-731647CE3736}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={E92A11EA-BA39-4AEA-966A-EFBF68B94F77}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={C4FF72F7-B788-4CC5-9961-0DF70C5F0868}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={FC4D05C4-C274-43D5-AA0F-15A4851D68FC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={9851436C-CD93-4E68-983F-49AA65D3621D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={0A9641C4-1C19-4DE3-A760-1B42B842292A}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR459.exe=[%SYSTEM%]\YUR459.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR455.exe=[%SYSTEM%]\YUR455.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR454.exe=[%SYSTEM%]\YUR454.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR453.exe=[%SYSTEM%]\YUR453.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={7E39A5D3-6536-41C7-BAE9-0C44884FDB9E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={1FE5C08E-FFF2-4BB8-A0B0-BBC7E3666B88}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={52D9342A-E336-45F6-952A-F3F5509CD245}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={98183DA4-C6CF-4A8D-8752-FC25ABDEE95E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={69517F3B-64DB-4A2C-AF36-540D0F0A2A89}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={E7ECE794-9BCF-46D1-AB88-C054D48AB541}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {4564780C-A9CF-47BF-A268-BB081BB8EE9A}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={FC952AB0-E920-4B7A-86E7-E792276D02C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={5657B306-2C24-4072-BB16-F5BB468956CB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={43011EFE-84E7-469D-8900-592CAC83FD10}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={D739A43B-5CDD-4F26-8D71-FB06AF9EA330}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {FF61FEF9-D771-4BB1-81E7-C55B3AED213E}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={41BD1A1C-731A-482D-AA8C-CBC5090E7D5D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tdomgafw={3EF8E976-2AFE-485F-8A54-33DD22076B00}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {BB324F49-82D8-4778-9E25-267724F65061}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 2fclOCxLAe=[%COMMON_APPDATA%]\qzexuxgz\uxyzszuj.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={EE93AB9E-3B9C-4525-91C0-C82F469E4BE0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={4216FF8F-D058-42FB-8F88-5EAC5F625169}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {7C74C1B1-81FB-4105-B304-80A12EC6E73D}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={0D6E3547-06DD-4008-A6C2-864B735965AE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={1EC8DAD6-A811-453D-88FF-2C32D12B50E6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={903DC57C-6F91-43AB-8D3F-3AD11B806647}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={7B1E1892-E0F3-41ED-AB27-AA0E0F284D4D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={933866B8-AECC-4C31-9926-6FD4759BCC77}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {C1C6A660-ED01-4C3E-A0DE-D14F31008087}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={BC8150FE-7DA4-48A0-9617-307D59AC6DC8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={9E5B2773-18FE-472C-88F0-127E3E468AF0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F9387F02-A5A7-4C48-B4FC-7FE81C4EAD52}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={2B4CEAB8-EF1C-4276-89B1-38E709A776C1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={D57A4D88-B014-44A4-A60C-BD3F560E67E8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {6134A39A-C1EA-4E6F-B6D2-9ED5D9CC03B5}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={99FC9D55-4B14-482A-8D77-E62BF8542CC0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={A928F9E5-8AF7-487D-A1DA-C597D3C38FC2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={B4D71062-AD94-4D94-90EE-ACCA37144631}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={05FA1DC0-B4CE-40DB-A558-6BC1A831B1A7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={8AD06678-E8D2-41A8-B697-4CB7A51AE2E7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={1EFA9F1F-81C5-499F-B3AA-F4C3ED0D5140}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2A78.exe=[%SYSTEM%]\YUR2A78.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2A76.exe=[%SYSTEM%]\YUR2A76.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2A75.exe=[%SYSTEM%]\YUR2A75.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2A74.exe=[%SYSTEM%]\YUR2A74.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={2082B548-0244-46AC-B7B9-4959D65D9D31}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={07173F1A-7BD9-43DD-98AE-0F701F3B795C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={ADF445AF-16B2-49EC-9D53-985D5EF0A9E3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={215EA116-E5B5-45EE-B85E-80AEFD9B0F8D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {EB95B22A-E37E-4EFF-9A9D-4E3D3BADD9E6}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={DC5A9B8A-6455-4260-A2BA-43CD21CCC8AE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={AF5976AA-8D9F-41A2-85AE-6A5A38649397}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, xJFdlmDPJL=[%COMMON_APPDATA%]\pexsnwle\zorqjmjw.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={D52320BA-234A-4748-BCF1-03D9CB3073CD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={4B8CA7F1-61FE-43DF-BF7B-822DA65B973F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={5E5DE27F-9886-44A8-BA30-8A9005FF4034}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURB9BF.exe=[%SYSTEM%]\YURB9BF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURB414.exe=[%SYSTEM%]\YURB414.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURB07C.exe=[%SYSTEM%]\YURB07C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURACB5.exe=[%SYSTEM%]\YURACB5.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={6B619229-9780-4241-A442-21B58D3B7001}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={CEC97FFF-C078-4FF5-95A5-92DB12212C53}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={B3B9A810-495E-487E-9E9B-07A4DBEC5D02}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={D1D6B52D-FC26-416D-8964-294C335C8D50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={1FC64156-0524-4396-8C2A-83F27D88BD65}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={791E3C99-3992-4DD4-AE13-E357DE91DA54}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={1C9CFCDA-3105-4706-B91B-4382CEDF8727}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={EDCA2054-54AE-4C23-A778-E81876FBFF03}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {CCF8082F-2A1A-4460-B3FF-E2D826259ADD}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={6B5287D9-4F95-404F-8A10-EC35F30BF79A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={C07507C6-9DE7-4B9E-B7E0-C84A14BA1C7F}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA7B.exe=[%SYSTEM%]\YURA7B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA77.exe=[%SYSTEM%]\YURA77.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA76.exe=[%SYSTEM%]\YURA76.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA74.exe=[%SYSTEM%]\YURA74.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={B42AB227-5ABD-4DE3-9038-8B4B495B6CB8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={059E22F0-DFE8-4B50-8960-3B5078DF3181}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, qadovnel={9589F245-243F-4B58-BE5E-E6F1698F8298}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bdkpfxqw={2444E60B-80A2-4E53-A219-A4F466C45C86}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {0CAA216D-B1AF-4C4A-8EDC-FB2D822570CB}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={3F168C2C-23BA-421D-837A-CAF25E256FA4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={F99BF270-0D2A-496C-971A-81BEF1A9ADDB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={87626AC5-3163-427E-A466-D6BE21B45135}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={38544107-D0E9-40F8-958D-FCF552C2811D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hstsys={46D43C72-4275-44C9-89B2-9C8BF5EEEF10}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 7QE1WUa8ke=[%COMMON_APPDATA%]\jofilqvc\lsjmlgdm.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={58F2BA73-E304-4D1D-9D89-FA537B949CE3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={615A5181-35C7-407D-BE85-DBB1B38D3398}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={F6EEC43A-0D98-4C35-8472-383C7CCF33B0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={D1B486E7-5891-462C-91D8-DEB208E57C89}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={340D70A1-A17E-4A52-89D6-7751A4EE406F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={864F881C-F5AD-434A-A43A-7C184588C4BF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={D93D7EC6-772F-462F-A568-578DED70958B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={A6152DF6-5D68-4191-B436-B252E2CF3566}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={88ED6475-F7B4-4760-8F68-DF041F5A9845}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {D3D9261A-22F3-4D6A-9A1E-850416C9B357}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={896AFD99-987B-415C-AB7F-1725AF50DE82}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={545B6982-1145-4932-B39D-E33C56F26335}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={BE515E3B-CAA2-45CD-9610-54A4A6D55A7A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vbgtorfd={768A9198-3590-419A-BC18-DD33BD5A0B7A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dwnrpofk={D6FD33DB-2D73-476C-AF93-3120FD085CA8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {521A5897-9EA7-43B4-A51D-B4C11D67BEEF}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={75BA896F-FAAC-4DC3-B7EA-AB4C2D598B8A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={4B7AF6B2-5CFD-4A49-A837-077D8DEF34DB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={CC9DBF9E-1171-4295-9D4A-8B5EFF263A0F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={92B9A56E-367D-485A-BB30-9FAE51E41BBF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={8B75E735-6109-4CD1-BA2C-19281BB75894}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={F4F19F52-648E-4936-96BD-64646F47684E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {8255476E-97F9-470F-9190-031DD1941B74}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={3F399ACB-2B0F-4C77-9C97-253437CCC99D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={04F78F68-00E4-4C4F-96B2-7391D89D75F3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={8E14D864-73DC-45AF-B7B2-C1CC05DE2A2C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={11575C64-A2A0-4389-98DC-766178CDBCF1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={6E3330AA-A94C-4E40-ACCB-72818BF70D14}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={9A7BBCD9-FBF7-432A-9A7A-86F7F4D347F4}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIE798D.exe=[%SYSTEM%]\VIE798D.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIE7827.exe=[%SYSTEM%]\VIE7827.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIE74FB.exe=[%SYSTEM%]\VIE74FB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIE7450.exe=[%SYSTEM%]\VIE7450.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={ABD36AD1-EFE6-409E-99D8-58C690083B85}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={1FB2C4D8-B78F-48F8-848A-C16074D2EBBC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={1367BEE4-4466-4EA5-A9FB-73EBE527AD87}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {D6D8B176-DEBB-40C9-AC5E-2BCF9C06735C}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={AF85EB3E-096B-47E5-A78C-36C233FC4A30}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={164808BA-2056-4D7B-85F1-6D46F39B2AFA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={0ACD1104-2823-410E-B5F8-C05DC4301BED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={0174DE07-488C-454A-913C-E1404AE83BC9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={E3F14F69-DA7C-4AA9-87D1-4C412E81E63F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={25B3B4E6-E135-4151-9BC4-BA9544F9978D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={E3F91C0B-F7D5-4BCA-9AFA-6D5CD66EE470}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={19DFBDAC-88E2-4B63-ABF0-35C9B6489B43}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={F445321F-0211-4DD6-9FF6-4049586B3751}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={AE6CA69D-BA48-47DA-8F4C-6094ADE396B9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={782AFF40-C57B-4BE4-9F3C-209758BC36AB}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {B36B25DB-E0B4-4058-BEBF-DB0C12B38C89}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={C7C5B021-270D-4E50-81D3-EB18C17ECE68}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={170365B7-799B-45BF-932E-4A95BB42EBCC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={0AC748F6-ABD4-4EA9-90F5-52CDBE37409A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={8D487BC5-1250-461D-B9BA-F57FDF5CCAEA}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIE861.exe=[%SYSTEM%]\VIE861.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIE860.exe=[%SYSTEM%]\VIE860.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, start=[%PROGRAM_FILES%]\Applications\iebtm.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, smile=[%PROGRAM_FILES%]\Applications\wcs.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, BYA6SUgkYK=[%COMMON_APPDATA%]\enafghcx\ebuzmjsf.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={0673FFC2-3838-4D75-8A6F-2DD8AB4651A4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={3B6207B7-36E0-411B-90D0-57D753D986D7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={737DF60E-94F7-48CA-A1F6-EBFD93B309F5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={E2547CD8-3A26-41DB-A9D6-63C6FCBF86B7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {FD195BE8-3E2E-448E-8D9D-EA3E1624CB98}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {2F398AF7-F1A1-4D9E-92E9-36A94898D559}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={923EC67B-A461-4E98-9059-DB92EC3C9070}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={CD0BE6C9-8D44-44BD-B053-512E123BBA2E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {68A5923E-76A7-44CE-9B04-1F6C33F2DEBC}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={E638A067-BFE5-4278-AF2F-6C12387E05F4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={D6C23AC2-9FAF-42A3-9BE2-D91148B0D922}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIECE.exe=[%SYSTEM%]\VIECE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIECA.exe=[%SYSTEM%]\VIECA.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIEC9.exe=[%SYSTEM%]\VIEC9.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \VIEC8.exe=[%SYSTEM%]\VIEC8.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={BCCFDB65-C167-4151-A3FE-BBB70198AC3F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={E1207BD7-4652-40CF-BF93-B847A461EE17}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wind
