Top 10 Alerts
Latest 10 Malware Files
Testimonials
In recent weeks, my computer has been infected with malware and adware that just would not quit. A*G G*****t failed to remove them. S****t just froze up. Another anti-virus program just sat there and looked at me. So I purchased Exterminate It! This was the only anti-virus program I could find that would recognize and remove particularly pesky viruses from my computer. But even more impressive, they allow subscribers to send in descriptions of new viruses they encounter, and they will design a way to remove the virus and send out to you an update. I submitted the description of a virus to them, and a couple of days later they sent to me an update that cleanly removed it. If you run into viruses that just won't quit, give this anti-virus program a try. It's cheap and removes the viruses that the other anti-virus programs can't touch for some reason.
Brother Mel
NetSky Registry Values
Scan your Windows registry for NetSky
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={C4467C8F-8A29-4359-BE46-DDB163617285}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={58D9172A-E87F-4025-B523-8E3724E5CD38}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={BDADFE90-C503-4A91-9560-F727DA674006}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF19F.exe=[%SYSTEM%]\YURF19F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUREE92.exe=[%SYSTEM%]\YUREE92.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURE9DE.exe=[%SYSTEM%]\YURE9DE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURE848.exe=[%SYSTEM%]\YURE848.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={898A1061-3DA6-44C0-BCB1-CB833073A66C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={50D26E7B-8960-4AB3-8FE3-606C3CD1AEE9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={42163A04-AF82-48B7-94E3-465BB1AD1716}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DrvPrx={e05621e9-e415-43ea-b75f-92d69951112c}
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General, Wallpaper=%SystemRoot%\Web\def.htm
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={7D019261-3E16-4278-BAC6-744448A82D69}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={EF7466C6-BB1A-4C54-9FBD-88F80D6A5383}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={6F7971E4-34B8-4225-862F-246D842845C5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7856AADE-0DD2-4F8D-9B1D-DABF8DB27565}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, G9zVrBlaif=[%COMMON_APPDATA%]\kfqxibev\ktwlkfcp.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, cfgact={596969F4-4929-4274-525E-07714CDF44C4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={336F34AA-9111-4370-B7D2-F2FE14A30457}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={2B245B4D-A03E-4062-A47B-BA317C4F72E4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {8BA91D58-FBDC-47C6-BAA8-11A0F48C5D27}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={B9FD0E68-C8B1-4E72-972D-B97B3D3E34DE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A2727B35-4F7E-4704-A511-866727BBC9ED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={44284096-F5C3-4E4D-867E-142E197CC67F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F13F81A7-F858-46A9-AF4F-CFCC535FAD5B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={484067F8-3517-4B15-8F31-43F8E2B5A5E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={927DFC03-D65D-469A-B031-A394981E6202}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={0EBCD7FE-81DE-4844-A840-BA882EF31B17}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={0ED3083B-A9A1-4011-B6C0-1EE4795288D9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {CA5DF1DA-5181-4190-B40B-E3FD8FB1EAED}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ApiAct={07717C17-CEFC-78C8-78D6-063E512FFEBA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E8892522-E283-4012-9F60-D852B02C180C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={FDBAD5C1-B42B-4FD5-8EB3-74B64AC7561C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={086B0038-518C-4A7E-9625-CF19A66D61E9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={9A72A972-8F1E-421C-B549-625184253EE6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={2DF5F4C3-AA9D-4BDB-9936-E8FCDFD5415D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={E77EAF3D-339D-4070-B532-F8204108E103}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={9C00950A-4035-41ED-9744-D98342AACD99}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={B77BD5B2-176A-4C60-84DD-79381B947BF2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {32678B97-2C98-4D22-A8F6-55C35572E946}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E5F85D38-EB22-4258-B335-6F63F0969A43}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={AF951F3C-F29E-446D-A478-F55FB3242EDB}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR7ECF.exe=[%SYSTEM%]\YUR7ECF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR5E54.exe=[%SYSTEM%]\YUR5E54.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR5A4F.exe=[%SYSTEM%]\YUR5A4F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR584C.exe=[%SYSTEM%]\YUR584C.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, lTWMB7xHgJ=[%COMMON_APPDATA%]\qbetopsr\slojufgr.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={F8BD976A-9714-4E63-999A-68CB909558FA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={185C6FBC-1676-49ED-944D-69A2A3B47E1F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {5D3BF66A-D62D-4D77-A209-8C8317054B1A}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={072E6C23-31FD-4F0E-BEB5-628987B74F44}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={0F708686-BE99-4CBA-8BBC-4A0499FFEF2E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Y3ZRxhiXOF=[%COMMON_APPDATA%]\dutkdgzc\dwlyzcvo.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={9EFA9749-2CB6-48E5-BDBB-23CD15C5E350}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={86F71A7B-4431-484C-A63A-7F3E5FE1E07B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={BE42C1BD-2935-464D-8CA0-C86BE2AF586B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={944B71F2-33BC-48B3-8F27-82ACC0574652}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={049E448D-22F9-4D57-AFDC-EB13AC47618E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={12B1A070-F659-4A9F-8A27-4F9FDD36EF31}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={98903D7E-7530-42AE-B90E-21316A2163BE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F5DBBBE5-527D-441D-BEDB-E92A32205FA7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={79E1CF65-A4EF-4CE8-892F-107FFA5B71D6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={0DB005CE-2D3B-48B7-91D3-76225F5F18FB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={690C496B-D9E2-46ED-8D05-4F408E2D7B4F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A2EBCDEA-A5A4-4537-95C1-EF1A8F0069DB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, LkqdBjsGPA={58F7B2D4-F25D-187E-26CE-59E87611DC3C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={C4E6F051-636E-4D24-9A05-821ABCC36C6A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={A4EE1E24-94FE-463B-AEAA-48F3E67EC15D}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR25.exe=[%SYSTEM%]\YUR25.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A91B590B-67E6-4CB4-8741-423AD91E8C1A}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={92D7AE66-CB22-4ED8-B848-66070D783441}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={11BBB97A-EA96-4FA3-AAE4-43F4F39CA323}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={6A50760E-71B0-44F4-9FA3-966586E01BE8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={1CB96CA9-3E2E-4A4F-A68A-2ACB55120B93}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2B.exe=[%SYSTEM%]\YUR2B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR2A.exe=[%SYSTEM%]\YUR2A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR29.exe=[%SYSTEM%]\YUR29.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR28.exe=[%SYSTEM%]\YUR28.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={9CE815B8-1F41-4D1D-BBEB-C8A9E3DF630F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={EFEDD859-85F9-4ECB-A404-018A4485851C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={4337B175-F3FF-476A-BCD6-917EE04D7BDF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {28944906-7047-4C8E-9639-E6075B73C96D}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFC.exe=[%SYSTEM%]\YURFC.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFB.exe=[%SYSTEM%]\YURFB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFA.exe=[%SYSTEM%]\YURFA.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF9.exe=[%SYSTEM%]\YURF9.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={DF430EB0-EF90-4478-A540-38660E0FEC2C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={53D79A18-4F34-4C76-A849-7DABFAA2E132}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={AF0577CD-D91E-4C73-AA42-AD34FF522F7A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={2EAA6D6A-200D-4397-AE4C-9CFB658F93B8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={07D42B64-8F64-4D86-B7C3-F3B506CE17A1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F7BD98BD-B660-4395-8CEC-3F856329D3D3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={DD1ACC8F-9DA5-4377-A593-C27F4A6A001C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={91869350-DCA2-4F2D-8A77-B2D35E445CBF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xvorfwbd={9A49DA90-9B19-48C6-B723-9F8EBF846D52}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wpvmqosg={B6D48B96-62CD-4BC9-A0D2-80D8197E83AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={7FF0BF59-29C9-456B-98E1-AA25931999E6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F8284C0A-6B71-46BB-B134-831CAC7AF90C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={49B56E58-AD9B-44D3-8822-A5024A370B04}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={533361A8-AA72-406D-A194-69727E9282FE}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17F.exe=[%SYSTEM%]\YUR17F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17E.exe=[%SYSTEM%]\YUR17E.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17C.exe=[%SYSTEM%]\YUR17C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR178.exe=[%SYSTEM%]\YUR178.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={244CFADE-44A3-466A-B663-D03261A2BB55}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={B2373385-3907-42B4-8AA4-63D1BBEFB5AE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={4712B782-349C-4850-A7AE-847ECD4DA8A9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {BECDB70D-AE92-4B86-A8D5-0790D704B299}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={ACA43D9E-79B3-47F6-840E-E92575A92CE8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={BDBB06AC-8895-40A5-8638-7CFEDF17AC4B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={ECA2A9F6-02DA-44F2-9253-BCD3D1C08C6F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={008AAED0-981E-48CD-8AFC-2F138F6CB618}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={36CF9192-9B75-4825-90A4-4E9B37497954}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7E90843A-02EC-4852-B2D1-59E3FA0CB765}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jYUBhoy={0CBB229D-A611-8837-F4C5-9ECA4FF39420}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={BF6D2574-F039-4A4F-B70C-6EA35A0A3CFF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={693E4171-B147-4BC3-897A-F3BA90E4DD42}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={208311EA-D49E-47EF-85AA-841596601C6A}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR18.exe=[%SYSTEM%]\YUR18.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR16.exe=[%SYSTEM%]\YUR16.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR15.exe=[%SYSTEM%]\YUR15.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR14.exe=[%SYSTEM%]\YUR14.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={3508ECFD-4328-48CD-B9C1-5E0A69282C8A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={5E32E7B5-61A2-4622-AB9D-161575293B10}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, uvozgfel={417ffc4d-9e4d-4a79-9874-29c013867ae9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={41BA9396-3CF7-4392-99AE-649A0F0AEE96}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={44832247-E194-4FDB-B532-486AE453E273}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {1C67BD5F-A9EA-4FD0-A1D8-0AD71E86D48A}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4901.exe=[%SYSTEM%]\YUR4901.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4587.exe=[%SYSTEM%]\YUR4587.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4105.exe=[%SYSTEM%]\YUR4105.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3CC1.exe=[%SYSTEM%]\YUR3CC1.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={36EAC5F9-4EAE-4501-B7A1-903E730D2FB3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C3327420-297D-4028-A3B4-40BEDBE7169F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={8C6E7650-AC38-45C7-B01F-B1A308081564}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={C09D646B-3724-4F54-8DFE-E95D7D6EB70B}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1A.exe=[%SYSTEM%]\YUR1A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR19.exe=[%SYSTEM%]\YUR19.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR17.exe=[%SYSTEM%]\YUR17.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, AQEli={48E53AEA-E24F-9040-D59C-27F46E08A047}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xbrxWT={0C49BB6D-A6E3-11C7-8ED0-996A4FBAE088}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={61962A3A-464D-49C9-8C2C-686428081EB7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tdomgafw={0077CD8B-F7D3-4CE8-B4DB-659647E4130B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={F735FAE6-2D9E-4818-8705-EB3CCAF9331D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={51275C01-3F2F-4D1D-B98E-34271CDC9292}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={A013FFDD-CFCD-4588-80F2-6382F4A4E687}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CltfiTN={847D8932-2ED7-2398-4F58-EF048BD4C76B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={616C1A3B-9670-44AB-8DA1-F659ECE1CF37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={24AEF888-26C2-4244-B746-A99414A93989}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vregfwlx={8EAA5B7F-C5BF-4E1C-9253-289C82E1984B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, ERAG0Uzw2G=[%COMMON_APPDATA%]\ubcnqtih\idyninyj.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pmsoarbf={51CA5294-BA0C-4F93-B0E7-76E6C7FB48AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, omlbpkaw={B9B02A38-F5FA-4218-9EAF-D520BDA30723}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ohejidof={eda56d51-83dc-4f4e-94ec-ac1b97a3159c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, oNyBzVwQnLcC={54ECD006-FE46-7AAC-1D66-B0EC740C6AD5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={223D2FB4-6780-4B29-A286-5452BAFE29FD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F045CEE1-3A82-4955-9410-9CE139FA2798}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1B95C29D-16B2-4497-83D4-0E1BF67B48E3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={FCE5E131-AECD-4C65-BFD2-7BA631F8AE22}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={AB864F2E-A06C-4F9B-A0BB-19274D48223E}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rcKpYUF1gr=[%COMMON_APPDATA%]\tizapepi\zmvojibg.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={CEA9FD84-F2FB-4B42-9544-B6D89D33E5BA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={4D211F57-1EAB-4FFA-AF55-CC6512962D8D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {DFEAE9D3-90B8-4F9E-8AC2-8317693C94BA}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR926.exe=[%SYSTEM%]\YUR926.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={E6678262-A19A-4EDD-B0A6-975667D5BD61}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rwlfsdmk={7B5A32E6-BE6C-4F4C-9BA2-22298241C7F1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {E5ACC10D-16BD-42DB-9AAB-283DF9B3A4EA}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURFE22.exe=[%SYSTEM%]\YURFE22.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF9A0.exe=[%SYSTEM%]\YURF9A0.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF59A.exe=[%SYSTEM%]\YURF59A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURF202.exe=[%SYSTEM%]\YURF202.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, onfwbsak={9C6DAD15-92A7-454D-8314-3EF4779DF089}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={DE356CEB-5951-4568-9587-36AEC5C2DC24}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={97BEF441-D6D1-49A0-AA02-A6384292BF2B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={BB451B73-2F9C-4261-8870-43B854D9A355}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ADD7524F-35F7-4CBB-92BB-E3D9E36DFEA2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={9F59D18F-80AB-4296-9432-A67F9B8DB0AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F2A6A4F9-82A2-4376-AFCB-7923901ABBEA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D1357694-D243-408B-AD7D-9A60F1341892}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3C37D805-A9CE-40BB-A403-C227D11C347C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={BF41A424-7CA7-42B3-8B40-6D18E6A76B79}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={B2F88D40-9006-440E-A7B7-9E616F60C0DF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6048865C-4BB5-4F36-AD7D-7B29D367C3D4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2809F3ED-73B7-4420-8AF7-EDDF0CC38871}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EBEF2595-431C-4F44-BA12-4FFBB3A03BAA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msgsh={11D27D17-014C-6C6E-BE75-02ECD1109574}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, InfoSh={4A0CFEA9-3FAA-4875-B4F6-0778DBF243BD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgsvflkw={3DA90683-BD3D-4C66-BC5A-B32FB7DE2E07}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={78769DC4-14A5-4777-A16D-CAE58A58B4C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={622C3AEA-BE88-4217-924F-C5B79427EB8E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A5C24FC0-CAAD-4F2C-B82E-BB1ABF62F2FF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5C8E6A98-ED78-494D-B4F0-368AF534EBDE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E8797073-C230-43DA-B1C6-815EA16E9462}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {5371FF76-9602-4029-9626-BE8CD757EB36}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vbksrofa={A097B6F8-B2E1-4794-A15A-F9FA7C2FC86E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pmsoarbf={ACA03255-B158-48A0-A484-3A680A7E7C09}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mpfanvqg={6CCDB726-E260-428B-8459-2AB0CCC3B09F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={352D3218-18ED-4946-BC0C-FB6050BADA2B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C0EBB4CF-59A3-466E-8950-216943AC14C8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bdkpfxqw={A1FE1A5E-312E-4DA6-B327-82B01670D01E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={84116BAC-EF2F-4555-A941-CFB8EB67840C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FC4B1021-E761-4060-B4C8-BBDDD8E60470}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A3F085DC-BA33-4546-8DB0-70DDA1AA7707}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3C66E15A-808C-49F5-84D7-2FA3E23D305E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={74889A48-921A-4FA5-ACC9-159BE2A6498E}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR174.exe=[%SYSTEM%]\YUR174.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR173.exe=[%SYSTEM%]\YUR173.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR172.exe=[%SYSTEM%]\YUR172.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR171.exe=[%SYSTEM%]\YUR171.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, winmon={37C3DC82-EB3D-3DD9-F48E-09C9EFDFEB42}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={2C7B769A-F905-41A0-9A02-7B2116AC5AA6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={81427609-BD52-43B1-9BF1-D1DAA5BFE2DD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {7A435241-0F51-4BBC-8E64-D2B613E7AA46}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={D476B659-917C-43EB-BA1D-1ECA4BA43FBC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={924AB76B-18E0-468D-B9A1-47EC5BE903C7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={4352CED4-D978-4FEF-AA46-E9708403750E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wbqxfpgl={47864F82-EA2E-4FD9-B567-530C98C64CFD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1E05117E-82E4-4D17-9003-4BD58E8D2DF5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9B41B7ED-7267-4F4E-8127-A758CC18385C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={61E02284-699B-4AC3-85C9-106CE533E1B7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={A3B9D6E6-3F62-4D72-8B0A-E1F6252A2DEF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={88A532A7-0E7B-41D9-9E9A-7D5743D08A2E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2053032F-51EC-403B-878C-66EBEFEA67D5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9B2.exe=[%SYSTEM%]\YUR9B2.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9B1.exe=[%SYSTEM%]\YUR9B1.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9B0.exe=[%SYSTEM%]\YUR9B0.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9AF.exe=[%SYSTEM%]\YUR9AF.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E2D450B3-2F6B-4071-954B-0D43B5FF6420}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1EFF883D-38DD-4708-B0EE-403FAF36E360}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={8981BFFB-1BDB-4876-9CFC-EDE5BD2F2B08}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {89F51B26-A3FB-487C-B4E8-334CC35795A1}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={DB82B9C9-CF8D-4ECF-BF2D-CAA5A0FE735D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={DED4B1C8-BEB4-4089-AF71-57D4C29AA3DC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={7D210C37-F882-4E79-BD85-2A3AA3B4EBDB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C12E1949-1BE2-442F-B86F-6A37734181C8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bokpkov={45CF7CCC-9813-403B-B686-502124CE5B36}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, altvxvm={9320153D-E801-43DA-AA26-B4D2FAE46BBD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={42584033-B7B2-42A1-937C-D4EBB7D8F0DD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FA04F3A1-284D-4937-B85E-15DD444CA1CF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CED92C57-1E6E-4D24-9AF5-B150399D11D9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={83833C8C-DD6E-4C76-93E3-73EAA4004534}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={5B73C627-F0B8-448D-BCC2-CF766B2CD9CE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={0536FDEA-8CF3-4597-89F1-67BABDB9C74F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={D570C370-B73A-4B91-9C7B-DAAACBD2CC44}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2CEFB58E-4859-43CF-B2B4-0DCAE2FEDB39}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={451376F4-38FD-4EAA-A19F-3FBF78832B9E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={45528941-1650-43C6-A26B-8936617B8D14}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6F0D15D3-BED6-48A4-B928-12F6BA7E8E61}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1BD9E285-ADD4-4734-94A6-A8068B5A0B50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C921936E-58E3-43D1-B606-FA032B5F81D0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={452988F7-AA58-4F24-8EA8-D76B2B988BD8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={39427AED-1471-4690-9243-65BC2FAE08A1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={61BBC309-4C90-4C8A-BCB6-3ED56C2D1593}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={66A7D078-C473-4CA9-B8F6-C42F893C15A1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, 0CHnHLYo4z=[%COMMON_APPDATA%]\qrqfuvqd\sledyryf.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fsrpknov={124159FD-D1C1-4C3C-AB6D-28D5248353EC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {28FE3E9C-E177-4D1D-93B2-14CD61F4ADD3}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {206DDC12-B015-499C-9981-BC5863B027CA}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E773C87A-DA1D-4638-AAD1-7C1E9154CA37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5A7C1563-1ACD-4812-AC4B-64AC096EF7E1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2BA05FEC-0676-48C6-9FDB-811C5B15F95C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E52F3AEE-1EE7-4D57-B1B3-0BACAC5B181A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={DFBF7B95-77BB-4757-9F76-03164A3F8514}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F8D248FD-E148-46AD-BF55-DA33CA1D541D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={B690078C-5D58-4C07-B4FA-86B2FF3EFB97}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D6.exe=[%SYSTEM%]\YUR1D6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D5.exe=[%SYSTEM%]\YUR1D5.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D4.exe=[%SYSTEM%]\YUR1D4.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1D3.exe=[%SYSTEM%]\YUR1D3.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3D208066-75BE-4962-92FF-2FE444BEAF56}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={5B7FECDC-9702-40C0-846F-0A5FFB3E81F2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={EB6337B4-51A3-4125-93BD-8C848A67D30F}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC5DE.exe=[%SYSTEM%]\YURC5DE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC39D.exe=[%SYSTEM%]\YURC39D.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURBFA7.exe=[%SYSTEM%]\YURBFA7.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURBE40.exe=[%SYSTEM%]\YURBE40.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={BEFB3339-75D7-4F29-A9FF-14D1633BA068}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3D56F15E-6227-4896-B604-284C387E823A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={36D4701D-61EE-4405-8ADA-870AC3A5171C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C577F8A0-91CB-412A-85A8-3F9C3E8DD37C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fsrpknov={E5B820F4-F3CD-4B97-8297-F8072EAC3D86}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3D9EE25E-26C3-4941-8CA5-6733DA38150E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F93E2DDD-58DD-4EEF-BFB7-7B48CAFA5DAB}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AF.exe=[%SYSTEM%]\YUR1AF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AE.exe=[%SYSTEM%]\YUR1AE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AB.exe=[%SYSTEM%]\YUR1AB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AA.exe=[%SYSTEM%]\YUR1AA.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2391D513-EFBD-4AC3-B7A3-05A3F02BCE16}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F43A6D20-CF03-4ED4-BE34-D5F4F2A92BC5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={170E661B-CCFE-45C5-B380-6B46780AABC7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wetkadmr={D0D34414-75F8-46C5-8929-7E84E93A21E5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E7FF9CD6-965C-498E-8A51-C04AC8332A0C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F1E1734D-DB1E-44DB-951C-10DC09FFAB25}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={609E02BB-FB3E-46D1-A203-2514DB00465F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {E92E9D54-85D0-4B31-AB61-16253EE625B6}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12E.exe=[%SYSTEM%]\YUR12E.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12D.exe=[%SYSTEM%]\YUR12D.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12C.exe=[%SYSTEM%]\YUR12C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR12B.exe=[%SYSTEM%]\YUR12B.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ADD22D56-3505-4FEC-B69B-F37DA412559E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {30ACFAA9-78D6-4C11-845C-804AF8AAC89F}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1E4F85C9-3767-4EBF-9625-1709859B2CC8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E9977779-D099-4F19-8BD6-4DC8CBF9D3AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1099178A-F7A2-46CE-AB76-BCA722236425}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={052AB6D1-82D1-47FF-8659-B2C036C971E8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EEC124D7-CF39-40E8-B191-4D24C74148EE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={C6EA1694-CB74-40C6-8E21-811E14F5F06E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B6CAD3B3-52DF-461E-9553-7A27EC963733}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gnowmebk={F38C5A70-7A98-4E67-82C4-050A959E2E05}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {C9A66198-D585-4160-A963-A889176926B0}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={4ABF4CAF-69D9-4714-AC25-A74428605B6A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={05715F60-00CB-4313-A5AB-D4EF9277D87E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B85519D8-FAF7-4DD1-AC28-E35DA3A2BD60}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={5A440159-B98A-49DE-8307-9698CF2B2B58}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={829FC829-5152-4BC7-9EBB-2F1058D1FE37}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={7939E25E-F1DF-4DBD-B752-FEF645901A78}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={591304CF-167C-4AFC-B263-6D28F3A01074}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={25823B0E-E345-464B-B269-B86E79BEBFCA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7DE7DA20-80E3-4506-8970-508A24931DA6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2DCA93F3-C25E-4192-944C-2B172BF1DE0C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={21D38B0C-23C4-40D0-8EB0-1FFE95D522CE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2827859F-7BA4-4134-BB87-A72E63CD7FBC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={B4B06B61-B206-4C0E-BFE4-E3552484BF46}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, evgratsm={6177D367-7F6E-411D-A2B2-9A150D5E5564}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D555FCF4-C7B3-482D-A382-D6F7178B0A71}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={11475C8A-4BE9-4CDB-B991-FB033E21CFAC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A3AC6E80-6FAE-4B5C-9901-488A75685383}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F54B5C35-6050-47FD-9040-92418918CF50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B5BB4C4D-C958-4566-A9CA-403EE3E04E2D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={3A48F694-4687-4FA4-8F29-7DBA5783478B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={544A050D-A342-4B7C-94A3-B79800977B6A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={A481A7FE-790A-48B6-8DF5-AB03967D380C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={4F034BA8-8D2F-499B-9E26-57F90A098BB1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={6840ED43-7BAB-467B-851B-55CEBE2F1BE1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, evgratsm={D73D5CD6-F809-40A0-A8F1-52F69C7B3966}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DbProcChk={4A0CFEA9-3FAA-4875-B4F6-0778DBF243BD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1C6338F4-C3B9-432A-98CC-A2451E4ACC9F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={808FBE7E-CC31-4C7C-9E89-22213F3A4363}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={2FB05857-388E-4DC4-BF59-92627B76FF77}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={67B22818-6A63-4094-A083-DE46F091EDCB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={FFB33CD3-57B9-4464-9C75-FD614045B4B3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9990113C-DCF8-4BF9-A7AD-1188B044D2C3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={A85810B0-6D8B-47B1-9E3D-876C49AA5E9D}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURDA37.exe=[%SYSTEM%]\YURDA37.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD62F.exe=[%SYSTEM%]\YURD62F.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD0A1.exe=[%SYSTEM%]\YURD0A1.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURCBBF.exe=[%SYSTEM%]\YURCBBF.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, NXwbwSN7sg=[%COMMON_APPDATA%]\hgnihajk\jkdwrwzw.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={A31A0513-D9DB-4A3F-83DC-2CA1632085AE}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={7BDA2F51-C110-4017-B675-AB7B58D88667}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2EAF0201-2623-4936-B209-37DB5A51B010}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={FCF5400F-0A0E-4523-96F9-8A33C353B2A5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={670BADAB-CB0F-45C9-A308-2205F72749AF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={84E4655A-164E-48D8-8D85-DD6D84A61DFC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F27873A3-AE07-4302-8440-E5CB352E72C6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1635F596-FE51-4DAD-9CD9-0718F7C14DC8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, btrklfr={9C84D3E9-017F-4858-A755-2ABC6E96E829}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, apdqnxp={AF8D0308-68D1-4AB7-98C6-FCA35EADD88B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={38D5C9E1-7739-4B05-BC81-6AD17040B38A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EAA06D31-2732-4D39-8809-2A4C1471228F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CA8E83FD-3E82-43E2-A978-4309283B4226}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E55B6DC4-1DEE-4BE0-BC92-2C0A695D5289}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A1BB3A1E-F35E-4FAE-A8EF-87C6B9683FC4}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA8E3.exe=[%SYSTEM%]\YURA8E3.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA6FF.exe=[%SYSTEM%]\YURA6FF.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURA27B.exe=[%SYSTEM%]\YURA27B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9F9C.exe=[%SYSTEM%]\YUR9F9C.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={848A4B4D-1301-4CB5-B667-17B6F2FEBAC9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F66184D4-B47B-4E5A-AA58-AF4D678E7990}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={8262B0BB-C3D6-40D3-BE47-C34BB39DF5A7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, G9zVrBlaif=[%COMMON_APPDATA%]\fknsbuha\ncrkdybq.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={CE7A5900-4065-494D-A0D3-CD3462C090AA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E7B21765-2825-4397-888F-0ECBCB41C1D0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, lOZQwlLksA=[%COMMON_APPDATA%]\jgfubybo\dkxqrqzq.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bklgvsf={DD76AD19-7AF3-4ECF-A31B-4B3731377C81}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ampkfst={989CC160-5D46-4C9E-993F-0E1838D3C9E0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={ABE4593A-5974-4048-94DC-8186D6306421}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={52E991FB-C208-467A-84D2-CBA9530C70E4}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4C6B.exe=[%SYSTEM%]\YUR4C6B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR4AF4.exe=[%SYSTEM%]\YUR4AF4.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR470E.exe=[%SYSTEM%]\YUR470E.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR45D6.exe=[%SYSTEM%]\YUR45D6.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={AD186A5F-3629-4884-B3D5-D62CDBEEEA40}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={1C66F552-8229-49BA-9BEF-78F87B49D151}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1CA6.exe=[%SYSTEM%]\YUR1CA6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR1AC3.exe=[%SYSTEM%]\YUR1AC3.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR16FC.exe=[%SYSTEM%]\YUR16FC.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR15A4.exe=[%SYSTEM%]\YUR15A4.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F03F4F28-C020-4910-ABE6-888919CB784D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={CF202593-A5D7-4296-B1BF-821CF296D8C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E9968F93-C98B-49F2-A40D-E176DF2BC307}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={62D1BB0A-0CF8-439D-9F19-2EC0E8C9CEF8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {D355A751-C166-4351-8112-0EB0775E1B16}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={CCAF41CA-AD7B-4A2D-8B0C-E2FC7AF4A4E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={681FF80A-F748-4988-B6B6-81D329196288}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={9488CD49-5466-4FD5-A637-0AC70BD401DC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={906E9433-F984-464B-9275-0F5C14AB9356}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={42880B02-56E7-495B-B25D-0EEC9CD4A227}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={548DE7F9-468B-4C17-82F2-F82B424D0E73}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7D108250-DCB6-4F6C-B6D7-E8AFD51DF3C5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3C.exe=[%SYSTEM%]\YUR3C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3B.exe=[%SYSTEM%]\YUR3B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3A.exe=[%SYSTEM%]\YUR3A.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR39.exe=[%SYSTEM%]\YUR39.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msmhost={5D64F95C-3E02-429E-BD9E-3057977AB589}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, msmdev={BB628EFC-86E1-426E-AAA2-39236CBFD6D8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={2CA1CE1E-DF12-41E4-A52F-01C1877DA0A4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={DDE9F340-CAB4-4C8A-8443-A00266430E87}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E3BD65DB-6A6A-4811-93CD-676F66F80FA5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FF173CFD-130D-427B-95EE-D9D0EA178B33}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bxlrvps={0AA01F01-D9AA-47BA-BCC3-CC12F12494F4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, alofkmn={53637B2C-7682-4BF6-ABD9-799AA0FA417E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5F36E835-FF52-4E93-8AF7-70619D3F31C0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={70F5FE77-BB5F-4262-ADE2-F8FDFDB9884D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={AC589E37-C2BF-47D4-99B4-F7D450E1A978}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F137EF73-D32C-4B14-A04E-1C6C1E6AAD61}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7F9BD5F0-3CC3-4D0A-9F72-6DD0C0E2FBF3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pdoskegl={FBA31B17-FF5A-4EB5-8D2F-55226875AC99}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rqbmvpso={E6933515-3A2A-4A83-AE11-E361CD0A0A0C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={0F17909F-736D-4945-8478-A88C76D7500D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2BF8FB90-413F-4FC2-B243-AB86E3937FE4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {CF83D74E-ED31-490D-B8EA-DA20D79F79EB}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kvxqmtre={CDFFDA73-874B-42A8-8D71-E4C12A7524AC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5EF47D96-3BEA-48E0-99AF-AFF971DF81DD}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={18F884EB-D124-42C3-A80B-3DA4C7C8A8B4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={6FCDDDEF-1519-4472-BD32-BF7BD789E7CC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={6B13DADD-8574-4B3D-AD2B-7CC2222187ED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={38553345-130C-4997-B620-EB52A4D30D94}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={E6BD1D63-FD35-4D6B-90FF-E22E072B6B95}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E186EB92-7E46-44AC-96CD-CCB804EE0C32}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={09BC086C-42C9-414B-A58F-50543C318999}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, qdnkewfa={438EA28A-A0F6-4683-AA89-95F5E893903E}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgsvflkw={496E6BD5-16FD-4604-888A-85BF20DC4A2B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {7976222E-DC29-45CD-87EA-9D2397B52D0E}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={582E670D-E578-4F08-B6B0-43DF57D73106}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ABABF7A5-F385-46C0-B2AD-CDAA6E110AF8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={61F42D6F-C1F3-4D4A-8511-EA0AB7DED9ED}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={09735BA8-B566-4015-BCE1-0F7AF2A20A31}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5CD1C326-2FCA-4394-ABD6-F0CCDE376ADF}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={D9215A25-40E6-4FB0-9D55-5DBB151E6EC6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Qq2z7muloc=[%COMMON_APPDATA%]\hopshopu\hsncluja.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={83DCEE07-A88E-4B37-8E35-A9494274223F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={DBEAC386-D528-482F-8343-C8266A9AA639}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7D7B1536-9065-420E-9671-01CE6C10D98D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {B02C10A6-38D7-4CBB-988A-D511F9B114F7}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={C7CFEECB-3BEE-4924-B4E8-C374031ED250}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dgksvbpn={015D077C-0A4C-4BC0-B2A1-93337F7963D0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={4D5A007A-1BB2-4092-A8D8-CC4FB24C34AC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={70E29C25-457D-4543-B4AA-DF9CDF377AD4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {4BB9EDD1-CE63-4ABF-8B79-8D5CAB9BBAEA}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={51333B54-5E61-4A18-BEB0-EACA6C67F526}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3C4A72CA-B302-4D98-A912-405D172E3526}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rnopbfgt={DF80DAD3-239A-4411-98F5-811295C8335F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F83D77A1-0491-4B24-B0CA-D0E8D5B25EEC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={573D7F0A-D708-4D02-B9E6-36412E58304F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={EF6C53F9-A396-414A-AA88-6436DA1F1A82}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={58404AB1-5900-471A-A75A-8169701A8A23}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E34EABFC-DDD5-4849-B741-4B0F4BE0BE4A}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={FB168FB8-4D5A-4A9B-8D9C-06A504E17032}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={B84DE707-F56F-462C-A981-1E95135E671C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={ED95960A-0C58-43DB-A86F-AAFDEF97928C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E447CB5D-9C69-4D5B-8B1B-DF109DB04CD9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F016D54B-6B00-47B8-882D-296D2B2D9579}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1DE3AB69-D38A-4252-881F-D30E72C38ADA}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={75C5B586-E359-4EAF-A3CE-66AD80A5384F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C5AFC39F-32D7-402B-A04E-A5B21878C36D}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DscInfoSys={3473E3A6-CE7B-4F23-F5CE-08A00AA7515B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={5E1AA605-9E0C-4E96-97C1-E77CF84F1483}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={C79BA1D3-E741-48B8-A20D-F191CDB51D9F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={79CDA69A-509B-45C7-A7CF-2B8C41262087}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={AA93392D-D074-43DF-BC10-0AA3F892179B}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, HlpProcMon={5B85C1EC-5B55-AF6F-11A5-08A108CED0AC}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={F901B9BA-04ED-40B0-9B7B-EB714BB51DD6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={2B33960D-3794-440A-90F6-6EA96E5EB007}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {A00C7A68-87B7-4CAE-9470-6B7CD75E4F23}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={4B70FBCF-A8AF-48EA-9CAB-EAE74A508D87}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={3D974367-324C-4941-B3C7-B96ADE2223A2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D2376858-44B0-4836-BD76-8CAE0D6D8C5C}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={E5F801C1-75DB-4190-A73E-504E153FEC0F}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9.exe=[%SYSTEM%]\YUR9.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR8.exe=[%SYSTEM%]\YUR8.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR6.exe=[%SYSTEM%]\YUR6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR5.exe=[%SYSTEM%]\YUR5.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, btrklfr={7F441FBB-1088-479E-B982-E801761D3A19}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bdmanager={43246AFA-F3C5-4200-9DC9-49DB76B41054}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, apdqnxp={F22D388D-E65A-438C-852B-52C001154B54}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, admgcx={D4EA2B86-20AD-4FC3-A1D9-C97E011A27E2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={970C277A-49FD-44B9-B5A8-2B3BAB22E0EB}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={7EBA8C48-944C-4243-8575-44DFE4C1F84F}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={D9EFA498-38AF-4F38-BD9B-F87ED87D8238}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={911CF70C-071E-4484-8D26-F4671FA790D9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={284FABC3-94BC-401C-9E56-F1F930141F51}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={863C0071-C39F-402E-8F12-94F36ECF27C4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dtseqrxk={1FF52BE9-7727-4219-8D11-434DA15BB332}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={23D5CE64-6F0B-489D-AEF5-9882F97248D6}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURBF.exe=[%SYSTEM%]\YURBF.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mgxfebsq={F49E4C08-5679-4BC1-8860-4F1F21CAD9B4}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, xrdwbfgn={1DAE5E24-AFDA-48FB-8116-2E53DD29D8F0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {F661BA6B-FAF4-4165-A701-F65A7585AC91}=
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
