Top 10 virus alerts
Latest 10 malware files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sokigiyuk=Rundll32.exe "[%SYSTEM%]\saliyono.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hapiwolari=Rundll32.exe "nasanuko.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, riferizik=Rundll32.exe "[%SYSTEM%]\gokehama.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Htuziyawe=rundll32.exe "[%WINDOWS%]\epeleluf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nuhotovog=Rundll32.exe "[%SYSTEM%]\lewadiye.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nxuwapowi=rundll32.exe "[%WINDOWS%]\ajuxofipujilil.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {fc99bb0b-3a73-4304-a32a-851b72cc9f06}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {db80ff64-932a-4c4b-a502-66d1f2e9b0be}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6aa3809c-6261-456f-8fca-43fe39adc5e9}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, tepikisiy=Rundll32.exe "[%SYSTEM%]\zuvutaru.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3554e1ee-2d9f-4315-a7b7-f9fb8933eb8f}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kiporozed={3554e1ee-2d9f-4315-a7b7-f9fb8933eb8f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werigiwaz=Rundll32.exe "[%SYSTEM%]\higudivo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d27c8240-1a1a-40da-9bd3-556ccafbbb54}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zobafozih={d27c8240-1a1a-40da-9bd3-556ccafbbb54}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hugokebuf=Rundll32.exe "[%SYSTEM%]\nawowami.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {08abb407-6c30-4940-a87c-2f45adfa34ad}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mowivamum={08abb407-6c30-4940-a87c-2f45adfa34ad}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\hovolile.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bolitobif=Rundll32.exe "[%SYSTEM%]\jisaleyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {403908f4-2663-434e-b63d-9b7d2dcf3351}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tavanasag={403908f4-2663-434e-b63d-9b7d2dcf3351}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vayubejob=Rundll32.exe "[%SYSTEM%]\nazehogi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c74dd340-9bdf-4ca9-87a5-71b60eb91acd}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sipezikez={c74dd340-9bdf-4ca9-87a5-71b60eb91acd}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\cbXNeDur.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rokuviyan=Rundll32.exe "[%SYSTEM%]\nehozipa.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rokuviyan=Rundll32.exe "[%SYSTEM%]\nehozipa.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MS Juan=rundll32 "[%PROFILE_TEMP%]\twuayq.dll",run
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c7d4e8fc-e183-4d6d-8231-e9fb5c5406b5}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wigihapab={c7d4e8fc-e183-4d6d-8231-e9fb5c5406b5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fc22b980-a0df-4b0f-947e-569bd7161e50}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, favobeyup={fc22b980-a0df-4b0f-947e-569bd7161e50}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {95ecd833-fcd9-4eb2-a694-962d3cb84a8d}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rehaledeg={95ecd833-fcd9-4eb2-a694-962d3cb84a8d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ac190acf-c2a0-4ef6-a42a-092e62b6bcad}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, simibomim={ac190acf-c2a0-4ef6-a42a-092e62b6bcad}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b3ddfa3b-67b2-441f-a2f5-9026611e239e}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zaberabes={b3ddfa3b-67b2-441f-a2f5-9026611e239e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b8aeb3b7-30d9-4958-b71d-952f4088b54c}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, feyalayen={b8aeb3b7-30d9-4958-b71d-952f4088b54c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8fe5b9e0-1943-4ed6-bd84-fa81dff962a3}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, soyajukob={8fe5b9e0-1943-4ed6-bd84-fa81dff962a3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mapufinev=Rundll32.exe "[%SYSTEM%]\kosagiti.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e4668351-8dcc-4705-8293-f91789b3e9b1}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, begomawag={e4668351-8dcc-4705-8293-f91789b3e9b1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ufewawixorigegop=rundll32.exe "[%WINDOWS%]\azageqeluwenuqa.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zesavogip=Rundll32.exe "[%SYSTEM%]\yuzohiku.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tiyefotudi=Rundll32.exe "wafofozu.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73a6b95c-45a7-4646-9dcb-289e9bdd652f}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wilefewev={73a6b95c-45a7-4646-9dcb-289e9bdd652f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikavu=rundll32.exe "[%WINDOWS%]\ulibelis.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zumojavoy=Rundll32.exe "[%SYSTEM%]\gopapodu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2d8f460b-8b58-44f4-ba07-2ea0444b0724}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gahevaluw={2d8f460b-8b58-44f4-ba07-2ea0444b0724}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jivulepem=Rundll32.exe "[%SYSTEM%]\vanageke.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {92b36b8a-4ad5-4687-8f7a-c67ee827f38b}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kaletetur={92b36b8a-4ad5-4687-8f7a-c67ee827f38b}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, MSServer=rundll32.exe [%PROFILE_TEMP%]\efcARkji.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\vehuyafa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bcb1628b-e4e8-4166-b72e-a502dbc30149}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fatipuwij={bcb1628b-e4e8-4166-b72e-a502dbc30149}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jabugejoju=Rundll32.exe "[%SYSTEM%]\vejasoso.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kedolifuhe=Rundll32.exe "[%SYSTEM%]\wikakaru.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kedolifuhe=Rundll32.exe "[%SYSTEM%]\wikakaru.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ffahokezezocoh=rundll32.exe "[%WINDOWS%]\Nvovi.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mqolosamavab=rundll32.exe "[%WINDOWS%]\Ghuzofezipahalaf.dat",e
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ritadasara=Rundll32.exe "[%SYSTEM%]\karowene.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ritadasara=Rundll32.exe "[%SYSTEM%]\karowene.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR39.exe=[%SYSTEM%]\YUR39.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR39.exe=[%SYSTEM%]\YUR39.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3C.exe=[%SYSTEM%]\YUR3C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3B.exe=[%SYSTEM%]\YUR3B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR3A.exe=[%SYSTEM%]\YUR3A.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 0cc82ee0=rundll32.exe "[%SYSTEM%]\wrcnvyqy.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {c2d425b2-3452-427a-96be-b3cd66620205}=
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F133A3D.exe=[%PROFILE_TEMP%]\_A00F133A3D.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, folotamij=Rundll32.exe "[%SYSTEM%]\wuwuhimu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {471d0caa-1266-402b-95da-05d415f05710}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nobomirit={471d0caa-1266-402b-95da-05d415f05710}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\vinomisu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, susatajaz=Rundll32.exe "[%SYSTEM%]\paselilu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgz32.rom,JcwttqEDD
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ferufuvap=Rundll32.exe "[%SYSTEM%]\repidihi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a539c6c5-fa9f-4db7-a002-412d6e09d6e8}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bojinusis={a539c6c5-fa9f-4db7-a002-412d6e09d6e8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b7ab9b12-7a2b-48d5-a4f8-ce5282e4e860}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wuzurebev={b7ab9b12-7a2b-48d5-a4f8-ce5282e4e860}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ferufuvap=Rundll32.exe "[%SYSTEM%]\laviyigo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6a591162-7c43-4e76-9346-8fab8ca79374}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kipehuset={6a591162-7c43-4e76-9346-8fab8ca79374}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, torejatefi=Rundll32.exe "[%SYSTEM%]\donojawi.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, torejatefi=Rundll32.exe "[%SYSTEM%]\donojawi.dll",s
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F424F76.exe=[%PROFILE_TEMP%]\_A00F424F76.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ybimomewomewome=rundll32.exe "[%WINDOWS%]\arufevor.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ajafe=rundll32.exe "[%WINDOWS%]\Skomanedevacuq.dll",e
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ybimomewomewome=rundll32.exe "[%WINDOWS%]\uvilufuj.dll",e
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ajafe=rundll32.exe "[%WINDOWS%]\Skomanedevacuq.dll",e
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0b3b5cf5-4389-464d-a595-bb990de83ca1}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zujebiyev={0b3b5cf5-4389-464d-a595-bb990de83ca1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled, jemegikep=Rundll32.exe "[%SYSTEM%]\kotefupu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled, bujopidiju=Rundll32.exe "[%SYSTEM%]\bihomimo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,KBCUROure
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rodogavut=Rundll32.exe "[%SYSTEM%]\zokohito.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b3dcf9b1-ee20-4e44-9216-e5067767aad2}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rivosimop={b3dcf9b1-ee20-4e44-9216-e5067767aad2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jivulepem=Rundll32.exe "[%SYSTEM%]\zejidipe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73460c84-9252-4e8e-b809-4d1f98b4a0ed}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sehuneweh={73460c84-9252-4e8e-b809-4d1f98b4a0ed}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bemubolan=Rundll32.exe "[%SYSTEM%]\lehebofi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1c84cab6-9994-4729-aaf4-94a50ace69eb}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zegeyokaj={1c84cab6-9994-4729-aaf4-94a50ace69eb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bolitobif=Rundll32.exe "[%SYSTEM%]\wuyamoba.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {85c505f0-37a4-4fa0-98b0-1a942ae6a447}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bulutojig={85c505f0-37a4-4fa0-98b0-1a942ae6a447}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rohodokug=Rundll32.exe "[%SYSTEM%]\fubeyahi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bfc055ba-527a-4371-ab8d-714da95d2b8c}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kafofezer={bfc055ba-527a-4371-ab8d-714da95d2b8c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zujonibek=Rundll32.exe "[%SYSTEM%]\harizepu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9f4fad94-22cc-435a-8ee7-2998fb69e18e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lelihoper={9f4fad94-22cc-435a-8ee7-2998fb69e18e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kevewalir=Rundll32.exe "[%SYSTEM%]\jupabone.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kuhupotum=Rundll32.exe "[%SYSTEM%]\giwasora.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2c00d1cd-6f1f-45c5-a377-9e030843611d}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sepokoyob={2c00d1cd-6f1f-45c5-a377-9e030843611d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3c65e32a-b805-42a3-b7b9-4003e9357165}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lebavuraz={3c65e32a-b805-42a3-b7b9-4003e9357165}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {83c7fe32-334b-43a7-993f-f1682231be43}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nirujukot={83c7fe32-334b-43a7-993f-f1682231be43}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {45d06dd4-7b73-4ce0-bf56-b3b2142e93fa}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bmumuqaz=rundll32.exe "[%WINDOWS%]\Yyaqozaniju.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ozapufutuf=rundll32.exe "[%WINDOWS%]\isicadotexaqakoy.dll",e
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sujulelepu=Rundll32.exe "dogejuhu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lirekusik=Rundll32.exe "[%SYSTEM%]\nugamibe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a18ecc02-ade6-48ea-810a-b42647163bfb}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yukaganuy={a18ecc02-ade6-48ea-810a-b42647163bfb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lafuredob=Rundll32.exe "[%SYSTEM%]\sawayuju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8f79a755-bc02-48d9-a5b1-3ef53ce11dbc}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rabojezer={8f79a755-bc02-48d9-a5b1-3ef53ce11dbc}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, larugojiwa=Rundll32.exe "[%SYSTEM%]\lugozeji.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, larugojiwa=Rundll32.exe "[%SYSTEM%]\lugozeji.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bonukavos=Rundll32.exe "[%SYSTEM%]\gitiraru.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jewodimiz=Rundll32.exe "[%SYSTEM%]\hoyobuva.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {07bac9e5-3ed1-4dcf-a7d2-13327aa4ecf1}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, silolatah={07bac9e5-3ed1-4dcf-a7d2-13327aa4ecf1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, befotafef=Rundll32.exe "[%SYSTEM%]\lehelojo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8535aacf-6239-401f-9eaa-114bcaaf9d6c}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nudunofet={8535aacf-6239-401f-9eaa-114bcaaf9d6c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\ganotida.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {72c80cff-01da-422d-985f-28ba80229963}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jidumerew={72c80cff-01da-422d-985f-28ba80229963}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lugevefasa=Rundll32.exe "[%SYSTEM%]\zapovafa.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lugevefasa=Rundll32.exe "[%SYSTEM%]\zapovafa.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gazuyihus=Rundll32.exe "[%SYSTEM%]\zumihade.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {dcbb3304-b1ba-4e06-b553-280075de1fa5}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mefuzebok={dcbb3304-b1ba-4e06-b553-280075de1fa5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3503628e-b90f-456f-984a-62db8d4d6091}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yenawujus={3503628e-b90f-456f-984a-62db8d4d6091}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c2d1229c-daf9-455b-8519-fddd127a3b9e}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dihedutot={c2d1229c-daf9-455b-8519-fddd127a3b9e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {943c9def-2c2a-4e48-bc9d-70a952261b9a}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fidalorey={943c9def-2c2a-4e48-bc9d-70a952261b9a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fa410e2f-7f5a-4349-b8ff-70cc727193cf}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, libodakig={fa410e2f-7f5a-4349-b8ff-70cc727193cf}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {78edfd09-ef35-4456-8e1b-54c609ce4d17}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wawuhodaz={78edfd09-ef35-4456-8e1b-54c609ce4d17}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM6920f984=Rundll32.exe "[%COMMON_APPDATA%]\viwafinu\viwafinu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 6a13ca18=rundll32.exe "[%COMMON_APPDATA%]\virinida\virinida.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pudezazado=Rundll32.exe "[%COMMON_APPDATA%]\gidogudi\gidogudi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jefugibak=Rundll32.exe "[%SYSTEM%]\rahobofo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, jagetukip=Rundll32.exe "[%SYSTEM%]\mewotuwu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0c94f531-8e17-4264-8626-83b4a725082b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yitijejah={0c94f531-8e17-4264-8626-83b4a725082b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bopayojuf=Rundll32.exe "[%SYSTEM%]\lisepeyo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sozugasul=Rundll32.exe "[%SYSTEM%]\kazerevi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c5c101af-d222-4a27-b9b7-ce0070203ad9}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, domogitel={c5c101af-d222-4a27-b9b7-ce0070203ad9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kirikehoz=Rundll32.exe "[%SYSTEM%]\sebodawe.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\junetike.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, susatajaz=Rundll32.exe "[%SYSTEM%]\juserolu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {82251dcf-b17e-45d1-b910-d8b4b3387538}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jiranedev={82251dcf-b17e-45d1-b910-d8b4b3387538}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lafuredob=Rundll32.exe "[%SYSTEM%]\kozezupo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {68e1e539-4c3f-4287-ab64-3383f246ad13}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dagezifam={68e1e539-4c3f-4287-ab64-3383f246ad13}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, feboyosof=Rundll32.exe "[%SYSTEM%]\jogihuju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {762773aa-f989-4522-8c47-f627d9cfd97f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lawawafid={762773aa-f989-4522-8c47-f627d9cfd97f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\tijojepe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b3a8f1b2-eaf4-4997-8bdc-c4243a9f3798}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dudowanal={b3a8f1b2-eaf4-4997-8bdc-c4243a9f3798}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sezemedoli=Rundll32.exe "[%SYSTEM%]\begakipu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sezemedoli=Rundll32.exe "[%SYSTEM%]\begakipu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ffufi=rundll32.exe "[%WINDOWS%]\etameyud.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, woguwewiv=Rundll32.exe "[%SYSTEM%]\vupodawa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0c16103b-0e5d-4f8d-9be6-c9c5fa42d170}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fizudehud={0c16103b-0e5d-4f8d-9be6-c9c5fa42d170}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werigiwaz=Rundll32.exe "[%SYSTEM%]\fimamile.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {030ada61-d523-4ced-942e-dc62a1f83918}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, divetalif={030ada61-d523-4ced-942e-dc62a1f83918}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ragediriyi=Rundll32.exe "[%SYSTEM%]\yosutihe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lafuredob=Rundll32.exe "[%SYSTEM%]\werigila.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {29d20356-05c5-47cd-9dc7-89d792ebd711}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vehezopik={29d20356-05c5-47cd-9dc7-89d792ebd711}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kebodowas=Rundll32.exe "[%SYSTEM%]\yitefuko.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5ddb1830-96cf-4227-b0e9-02757db80c85}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tiwuzuteb={5ddb1830-96cf-4227-b0e9-02757db80c85}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kazozedub=Rundll32.exe "[%SYSTEM%]\zifutoro.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {01087ae5-6f0f-4518-a8b4-8fc921ce96ee}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, teluzusuh={01087ae5-6f0f-4518-a8b4-8fc921ce96ee}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bhucosul=rundll32.exe "[%WINDOWS%]\owoxujes.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hipufugas=Rundll32.exe "[%SYSTEM%]\fujinaho.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e98b1e25-e14f-455a-bd53-292e3c6c6a8a}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, weduzukaj={e98b1e25-e14f-455a-bd53-292e3c6c6a8a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hokisebar=Rundll32.exe "[%SYSTEM%]\rutasaka.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {71dd6d3e-6a75-443c-a8ba-110562ca0a5a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gosimarag={71dd6d3e-6a75-443c-a8ba-110562ca0a5a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, notefuwuv=Rundll32.exe "[%SYSTEM%]\beyobusu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d631bb97-43c1-4a83-81e6-f476ef9016e8}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dugiwusay={d631bb97-43c1-4a83-81e6-f476ef9016e8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jivulepem=Rundll32.exe "[%SYSTEM%]\dugavulu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {18dd7df3-02bd-43d8-ab10-ece6e5d3d7e4}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nadetakug={18dd7df3-02bd-43d8-ab10-ece6e5d3d7e4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zirisekol=Rundll32.exe "[%SYSTEM%]\mibewoja.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d310a452-e8f8-4ae1-aec9-50036495e23f}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, likepayuj={d310a452-e8f8-4ae1-aec9-50036495e23f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zewoladed=Rundll32.exe "[%SYSTEM%]\vokafifu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7d6f9fe0-b6cb-491b-a415-b2abf97b964d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rukahobuy={7d6f9fe0-b6cb-491b-a415-b2abf97b964d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {55d98557-9358-4b61-9318-097ec04fea97}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hinenabul={55d98557-9358-4b61-9318-097ec04fea97}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\beyofaji.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c367f572-db6c-447c-89fb-9503749b9e94}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wonesirul={c367f572-db6c-447c-89fb-9503749b9e94}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\yeneriho.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f4d6b65f-7849-496d-8aa6-38685ab39466}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yuzodahiw={f4d6b65f-7849-496d-8aa6-38685ab39466}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lafuredob=Rundll32.exe "[%SYSTEM%]\sizulase.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c91c1d09-3206-4fa4-adb6-7534fcc3261e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kewopogud={c91c1d09-3206-4fa4-adb6-7534fcc3261e}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kabadilel=Rundll32.exe "[%COMMON_APPDATA%]\kekasika\kekasika.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pihabaweyi=Rundll32.exe "[%COMMON_APPDATA%]\ruzomivu\ruzomivu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bolitobif=Rundll32.exe "[%SYSTEM%]\riguhoyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9dd698ab-dcea-4643-a68f-a196b4337a94}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nefojugab={9dd698ab-dcea-4643-a68f-a196b4337a94}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, jagetukip=Rundll32.exe "[%SYSTEM%]\putevama.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c94a1d56-03da-45f0-b4d3-eff35741534e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pepahubay={c94a1d56-03da-45f0-b4d3-eff35741534e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {03d4067d-f483-4d48-a7ff-e216c4c7420d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wutimimar={03d4067d-f483-4d48-a7ff-e216c4c7420d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0629ee6a-3321-41af-812b-9261557d06de}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, betusulel={0629ee6a-3321-41af-812b-9261557d06de}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zevebavof=Rundll32.exe "[%SYSTEM%]\binosino.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a9b7b639-b273-4dc7-a4e0-d20624c236f2}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sewosozob={a9b7b639-b273-4dc7-a4e0-d20624c236f2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ruzeboyiw=Rundll32.exe "[%SYSTEM%]\wuyojogi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yurowonavu=Rundll32.exe "yugobuku.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1bc28e64-cdc2-4550-ac89-59f9d7da52e5}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gutozahuy={1bc28e64-cdc2-4550-ac89-59f9d7da52e5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yurowonavu=Rundll32.exe "yugobuku.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jigebeheh=Rundll32.exe "[%SYSTEM%]\suwezosu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lobamemok=Rundll32.exe "[%SYSTEM%]\sasagasu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1faf130e-796e-48d1-84d0-2a214490678c}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sitahuziw={1faf130e-796e-48d1-84d0-2a214490678c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {afaf8314-45c9-4ec5-9317-a9c24e01d0ac}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {636e0f34-6a8f-4a4c-99b9-5da16de3d3d1}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vojomufiz={636e0f34-6a8f-4a4c-99b9-5da16de3d3d1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jabimazin=Rundll32.exe "[%SYSTEM%]\nisawoyi.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mstu="[%PROGRAM_FILES_COMMON%]\ICROSO~1\dvdplay.exe" -vt yazb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mstu="[%PROGRAM_FILES_COMMON%]\ICROSO~1\dvdplay.exe" -vt ndrv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kazozedub=Rundll32.exe "[%SYSTEM%]\wevetora.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0060cb67-39ae-4421-b4d3-434794db38e2}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pizuyukaw={0060cb67-39ae-4421-b4d3-434794db38e2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kmite=rundll32.exe "[%WINDOWS%]\awuvalanahifur.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yafihazoj=Rundll32.exe "[%SYSTEM%]\subareno.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\rqrsRLed.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, giyokugaj=Rundll32.exe "[%SYSTEM%]\duhavevo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {476efdb9-aff0-42e2-8da7-4c2c82a6c0b1}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kozufaran={476efdb9-aff0-42e2-8da7-4c2c82a6c0b1}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vipubigisu=Rundll32.exe "[%SYSTEM%]\yifeleka.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vipubigisu=Rundll32.exe "[%SYSTEM%]\yifeleka.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bibododes=Rundll32.exe "[%SYSTEM%]\zumupobi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {617e2ae6-c134-4d0e-ad1b-abd01d6db90a}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gihogatip={617e2ae6-c134-4d0e-ad1b-abd01d6db90a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1f0887ea-61e6-4874-9f82-6caa2c51ad90}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, binifepak={1f0887ea-61e6-4874-9f82-6caa2c51ad90}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nufoyozez=Rundll32.exe "[%SYSTEM%]\fotikaze.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6b8113c4-f3b3-452d-8812-555d0638d192}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bihifudip={6b8113c4-f3b3-452d-8812-555d0638d192}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hokisebar=Rundll32.exe "[%SYSTEM%]\kuhesaku.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {dd54b2c0-9795-408c-a67a-2c008b338dce}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gevibuhub={dd54b2c0-9795-408c-a67a-2c008b338dce}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, beyarujuf=Rundll32.exe "[%SYSTEM%]\fuyayeka.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9a5e9b14-9b72-4d66-a392-d94f4af5752d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dumugorak={9a5e9b14-9b72-4d66-a392-d94f4af5752d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b2f22d16-274d-4686-b586-15d125b81305}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tavawames={b2f22d16-274d-4686-b586-15d125b81305}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {aeb14d00-4316-42ee-91d0-b78c083828ee}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bigobihin={aeb14d00-4316-42ee-91d0-b78c083828ee}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f481a5fd-3809-4a99-9bc4-7b72efb4158a}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fepowuvad={f481a5fd-3809-4a99-9bc4-7b72efb4158a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, beyarujuf=Rundll32.exe "[%SYSTEM%]\kabehize.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {819f1b1f-191a-42c4-8241-c5f1d1c2552f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wakiyuyob={819f1b1f-191a-42c4-8241-c5f1d1c2552f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lafuredob=Rundll32.exe "[%SYSTEM%]\tulowifi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7123e3e2-0013-4f05-8974-c4cb837bca75}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yimazibag={7123e3e2-0013-4f05-8974-c4cb837bca75}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zelipesoy=Rundll32.exe "[%COMMON_APPDATA%]\sarapoga\sarapoga.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b00fc312-76b6-467e-9e5b-41d4723a700f}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hisamabot={b00fc312-76b6-467e-9e5b-41d4723a700f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hokisebar=Rundll32.exe "[%SYSTEM%]\kanelewu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7952093c-01d8-453a-9422-4c9c6f210e27}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bonozumaz={7952093c-01d8-453a-9422-4c9c6f210e27}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, venazuter=Rundll32.exe "[%SYSTEM%]\diyisoye.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kirikehoz=Rundll32.exe "[%SYSTEM%]\kuhirelu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8ae77a7f-4aee-4c8d-882f-3a46b29092b9}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yipesudon={8ae77a7f-4aee-4c8d-882f-3a46b29092b9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\kuwotevi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a3b3a2f1-3e8e-4ae5-bb3c-33dad52b02e8}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wiwiteder={a3b3a2f1-3e8e-4ae5-bb3c-33dad52b02e8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hekawutok=Rundll32.exe "[%SYSTEM%]\vawirofa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {941b60a2-2def-4cf5-a36f-e38282b1f365}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mimisizoy={941b60a2-2def-4cf5-a36f-e38282b1f365}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fokajekoy=Rundll32.exe "[%SYSTEM%]\duhazilu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1d1266c2-ec46-4a7d-b791-07ca71318908}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jilokepun={1d1266c2-ec46-4a7d-b791-07ca71318908}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wvubifivufepo=rundll32.exe "[%WINDOWS%]\acekigatekudat.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pitinared=Rundll32.exe "[%SYSTEM%]\fahodawi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6d912266-924c-492e-9d85-c3467a9b4af7}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sogufupif={6d912266-924c-492e-9d85-c3467a9b4af7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM0a6725ef=Rundll32.exe "[%SYSTEM%]\umskihtb.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, notefuwuv=Rundll32.exe "[%SYSTEM%]\bofofevu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {658c22e5-a8fc-4b20-95c3-d1348847d546}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zekevowog={658c22e5-a8fc-4b20-95c3-d1348847d546}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, potawuyade=Rundll32.exe "[%SYSTEM%]\kodesalo.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, potawuyade=Rundll32.exe "[%SYSTEM%]\kodesalo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, jajiweheb=Rundll32.exe "[%SYSTEM%]\kidowavi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jajiweheb=Rundll32.exe "[%SYSTEM%]\kidowavi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4493aaaa-451b-4f89-8da3-de644d3adda8}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pazomahuv={4493aaaa-451b-4f89-8da3-de644d3adda8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rbomi=rundll32.exe "[%WINDOWS%]\abocuzojazi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lirekusik=Rundll32.exe "[%SYSTEM%]\hiyovutu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {44d06603-96d2-4aa6-a30e-c4f64aa11791}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zekumiyor={44d06603-96d2-4aa6-a30e-c4f64aa11791}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, tepikisiy=Rundll32.exe "[%SYSTEM%]\barusaya.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8bb63f59-152d-46f3-b2d9-42b4e6cb175c}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fenokekay={8bb63f59-152d-46f3-b2d9-42b4e6cb175c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, duhavimil=Rundll32.exe "[%SYSTEM%]\vawirofa.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yukudewem=Rundll32.exe "[%COMMON_APPDATA%]\movoyari\movoyari.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gowijadej=Rundll32.exe "[%SYSTEM%]\mizenode.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {585ecfee-0b6e-428e-8d18-6be437b633c2}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, satisages={585ecfee-0b6e-428e-8d18-6be437b633c2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bolitobif=Rundll32.exe "[%SYSTEM%]\muyipigu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {67de06fd-1508-482e-a435-6b474ceed473}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wipiruzos={67de06fd-1508-482e-a435-6b474ceed473}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vayisasij=Rundll32.exe "[%SYSTEM%]\lujetifi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {af5ef82e-1559-4e06-80fa-6e485ea05c9f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dazuhilaz={af5ef82e-1559-4e06-80fa-6e485ea05c9f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pitinared=Rundll32.exe "[%SYSTEM%]\gifezuza.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {46156510-4c01-4a8d-a779-0278b7da7eca}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rimopakah={46156510-4c01-4a8d-a779-0278b7da7eca}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, woguwewiv=Rundll32.exe "[%SYSTEM%]\koposuya.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ba0145ac-77ea-4915-9082-ddd27d25726b}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kojelojim={ba0145ac-77ea-4915-9082-ddd27d25726b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, woguwewiv=Rundll32.exe "[%SYSTEM%]\neyelida.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {C004A8DA-623A-4409-B6ED-F3E3DA367792}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6dc2d282-d414-435e-8a26-ff3c23ac36ef}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {aced1c9f-2718-4512-9f69-f4e28c1f484f}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gijidejoga=Rundll32.exe "kulokuha.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kulapigij=Rundll32.exe "[%SYSTEM%]\jaduzumi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f9b8ce38-b934-40a8-817a-53133a65a864}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jugujerub={f9b8ce38-b934-40a8-817a-53133a65a864}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuzoregip=Rundll32.exe "[%SYSTEM%]\vorosuka.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {839bba89-b082-44ef-a222-65393a1906f3}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, valeravur={839bba89-b082-44ef-a222-65393a1906f3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, d077a242=rundll32.exe "[%SYSTEM%]\voledpsp.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kazozedub=Rundll32.exe "[%SYSTEM%]\jiyayuda.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM0ade429f=Rundll32.exe "[%SYSTEM%]\uidbjlxm.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fokajekoy=Rundll32.exe "[%SYSTEM%]\piyuniha.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {96368323-0183-4134-9bb7-fb62b9e9e2dc}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, loyajatal={96368323-0183-4134-9bb7-fb62b9e9e2dc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bonukavos=Rundll32.exe "[%SYSTEM%]\yihazuso.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rigivijuva=Rundll32.exe "mozuzuwo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hiharulef=Rundll32.exe "[%SYSTEM%]\bepaleju.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hasariliza=Rundll32.exe "nurugapu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wpavaqogunewu=rundll32.exe "[%WINDOWS%]\umuvoridozoxazex.dll",Startup
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jiziyonube=Rundll32.exe "[%SYSTEM%]\pitepako.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jiziyonube=Rundll32.exe "[%SYSTEM%]\pitepako.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kulapigij=Rundll32.exe "[%SYSTEM%]\mogeviga.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {88e75cc9-44f9-4680-94bf-3acb83b3de7f}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sewiluyoh={88e75cc9-44f9-4680-94bf-3acb83b3de7f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gazidivig=Rundll32.exe "[%SYSTEM%]\faviloze.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, konufedes=Rundll32.exe "[%SYSTEM%]\womayovi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lirekusik=Rundll32.exe "[%SYSTEM%]\wuboyiki.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f4762f3d-13aa-4694-90f9-41bc156dc4a3}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jebomepav={f4762f3d-13aa-4694-90f9-41bc156dc4a3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, tepikisiy=Rundll32.exe "[%SYSTEM%]\dadeyisi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1e3485b8-c53a-449c-a908-ffac0d4acd83}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mavamekoy={1e3485b8-c53a-449c-a908-ffac0d4acd83}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, budebutik=Rundll32.exe "[%SYSTEM%]\wekupijo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tayavesuy=Rundll32.exe "[%SYSTEM%]\hevuzame.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tayavesuy=Rundll32.exe "[%SYSTEM%]\vugopifu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {28412d60-0012-46f8-8c1b-5b734dec7c62}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, feriyuzeb={28412d60-0012-46f8-8c1b-5b734dec7c62}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {29f736c6-451b-4ec8-ba95-20012e56f8f3}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, juvanogak={29f736c6-451b-4ec8-ba95-20012e56f8f3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rodogavut=Rundll32.exe "[%SYSTEM%]\feyajute.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d1e046a6-cd14-40b2-b89f-353e7c9acc73}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, parunuvik={d1e046a6-cd14-40b2-b89f-353e7c9acc73}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rodogavut=Rundll32.exe "[%SYSTEM%]\ludoyuja.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f685e700-deac-4319-b7b1-6b8558adcce8}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, safuhofoy={f685e700-deac-4319-b7b1-6b8558adcce8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, honuwukim=Rundll32.exe "[%SYSTEM%]\yoharoyi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yosagiyeg=Rundll32.exe "[%SYSTEM%]\remowoka.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fokajekoy=Rundll32.exe "[%SYSTEM%]\legiyaye.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3124a1d8-6d79-4f83-ae6d-aa27de91bffc}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lumiriwih={3124a1d8-6d79-4f83-ae6d-aa27de91bffc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, luvituzam=Rundll32.exe "[%SYSTEM%]\mepediki.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {57a42c40-d228-47e2-a119-aafeb301c790}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vezumipek={57a42c40-d228-47e2-a119-aafeb301c790}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3D6C9C.exe=[%PROFILE_TEMP%]\_A00F3D6C9C.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pitinared=Rundll32.exe "[%SYSTEM%]\jilehobe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4608a055-4ca4-49cb-b37a-165c6933aba7}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vemebekow={4608a055-4ca4-49cb-b37a-165c6933aba7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kopajuwem=Rundll32.exe "[%SYSTEM%]\rotatopu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {408235e5-1338-4d33-9176-46fa13f06df8}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sajusarer={408235e5-1338-4d33-9176-46fa13f06df8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sedewagid=Rundll32.exe "[%SYSTEM%]\dowikabu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {7C24493F-3D23-4258-9426-42C5FC3B8211}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ybaxowiloji=rundll32.exe "[%WINDOWS%]\agutahix.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yoligalem=Rundll32.exe "[%SYSTEM%]\rahobofo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zuduvuvul=Rundll32.exe "[%SYSTEM%]\sebaruja.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f0372e3c-11d7-4bc4-8f02-78ec3b21e0fd}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yasakotod={f0372e3c-11d7-4bc4-8f02-78ec3b21e0fd}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kazozedub=Rundll32.exe "[%SYSTEM%]\bidifetu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cf2a16e3-4646-4954-8146-4df0e82a8b47}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dokopopiv={cf2a16e3-4646-4954-8146-4df0e82a8b47}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 9ced9a95=rundll32.exe "[%SYSTEM%]\gtqrvpid.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM9fdea909=Rundll32.exe "[%SYSTEM%]\cbfffbnd.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mapemavim=Rundll32.exe "[%SYSTEM%]\bogerijo.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mapemavim=Rundll32.exe "[%SYSTEM%]\bogerijo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a3d63909-9527-47b9-ad9a-86d26aeac8f9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ganurubez={a3d63909-9527-47b9-ad9a-86d26aeac8f9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mefidolut=Rundll32.exe "[%SYSTEM%]\vozanije.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ffff700b-6e1f-437a-8bdc-ef29ea1f95d4}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dapanipuv={ffff700b-6e1f-437a-8bdc-ef29ea1f95d4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuhigotuw=Rundll32.exe "[%SYSTEM%]\pofutuva.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9a3764c3-1541-48be-9ea3-fe00bc75e406}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yukorizen={9a3764c3-1541-48be-9ea3-fe00bc75e406}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yimizodol=Rundll32.exe "[%SYSTEM%]\votojoye.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pitinared=Rundll32.exe "[%SYSTEM%]\zoripuzo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6f8b6ebc-f979-4ee2-8ba2-9c84fe7fcb0b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, piyebiraf={6f8b6ebc-f979-4ee2-8ba2-9c84fe7fcb0b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nufoyozez=Rundll32.exe "[%SYSTEM%]\gaperofe.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, huwohuvoz=Rundll32.exe "[%SYSTEM%]\vegozadi.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gakobudowa=Rundll32.exe "nimiwoga.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fokajekoy=Rundll32.exe "[%SYSTEM%]\jevayeyi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {19bc4494-b94e-4bd3-9bb4-43ef6958c3ee}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lakifukug={19bc4494-b94e-4bd3-9bb4-43ef6958c3ee}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yumeboron=Rundll32.exe "[%SYSTEM%]\heyehupi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yumeboron=Rundll32.exe "[%SYSTEM%]\kipiheba.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d563228f-a91a-4415-984d-f5794bbc7f2b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wiloyayom={d563228f-a91a-4415-984d-f5794bbc7f2b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {238d22e8-1d7a-4601-bf81-c9e1997b4e64}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bayoyorup={238d22e8-1d7a-4601-bf81-c9e1997b4e64}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\yAtrQhFY.dll,c
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pahibeyubi=Rundll32.exe "[%SYSTEM%]\dezudesu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pahibeyubi=Rundll32.exe "[%SYSTEM%]\dezudesu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suhagasezo=Rundll32.exe "[%SYSTEM%]\mepawadi.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suhagasezo=Rundll32.exe "[%SYSTEM%]\mepawadi.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vigiyegeba=Rundll32.exe "[%SYSTEM%]\tuvafuye.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vigiyegeba=Rundll32.exe "[%SYSTEM%]\tuvafuye.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sukejupadi=Rundll32.exe "buyaneju.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {24c61c09-62c0-42ed-b640-53f7fec9098a}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kifozetoku=Rundll32.exe "[%SYSTEM%]\manuhavi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiwq32.rom,gmlwcqkoEE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kazozedub=Rundll32.exe "[%SYSTEM%]\molugivu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {433c10bf-250b-4f4f-becf-bb3bf26afeb5}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hivogewoz={433c10bf-250b-4f4f-becf-bb3bf26afeb5}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {d2eeb637-a4a5-4bbb-8c0c-96af821110c2}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sugisilus=Rundll32.exe "[%SYSTEM%]\habebesi.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sugisilus=Rundll32.exe "[%SYSTEM%]\habebesi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1793b311-2598-4c56-932c-81fbcbbaeba9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nazejehan={1793b311-2598-4c56-932c-81fbcbbaeba9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kowuwiyay=Rundll32.exe "[%SYSTEM%]\fuwobozu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {07ad7e55-56cf-4725-b23b-f731390d300d}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, meyolubiy={07ad7e55-56cf-4725-b23b-f731390d300d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yoligalem=Rundll32.exe "[%SYSTEM%]\minimogo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fb674a81-f189-434a-a28a-6d885f46ff64}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, watoyukey={fb674a81-f189-434a-a28a-6d885f46ff64}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {17d2cb8e-c228-4141-acd9-e39e76683f7f}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, robikejij={17d2cb8e-c228-4141-acd9-e39e76683f7f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nabegilud=Rundll32.exe "[%SYSTEM%]\fogiguzu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jozogasiw=Rundll32.exe "[%SYSTEM%]\jadikure.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {483727b2-2843-4b15-b4e7-98d4a725fbcc}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nohuluguj={483727b2-2843-4b15-b4e7-98d4a725fbcc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kufuzifod=Rundll32.exe "[%SYSTEM%]\gidogudi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {473ed28e-7919-4287-b59c-119511eb3357}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ligakehej={473ed28e-7919-4287-b59c-119511eb3357}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rohodokug=Rundll32.exe "[%SYSTEM%]\mesegahe.dll",a
Scan your system registry for FREE

Comments

