Top 10 Alerts
Latest 10 Malware Files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_USERS\S-1-5-21-1659004503-1580818891-725345543-2114\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bziwer=rundll32.exe "[%WINDOWS%]\wpshdet1.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Emirucok=rundll32.exe "[%WINDOWS%]\oliqehisuketo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoot32.rom,VxLvxOJWee
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhjn32.rom,GPyLAUwDc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxpa32.rom,wcvtlCvou
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrj32.rom,Zcgebbt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qcekesi=rundll32.exe "[%WINDOWS%]\uxoniwul.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuzg32.rom,Qfocxk
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ebiyeqeh=rundll32.exe "[%WINDOWS%]\Ltemacupo.dll",e
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,dgZSyWI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyza32.rom,jfnKbCWlXSOY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintuc32.rom,iPOSsgTwUEW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincny32.rom,MRPxQPImoW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jyopucih=rundll32.exe "[%LOCAL_APPDATA%]\edigowizewugo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wrepecekir=rundll32.exe "[%LOCAL_APPDATA%]\P4DaenCo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winioa32.rom,jUsXbAXAJG
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cpumoh=rundll32.exe "[%WINDOWS%]\ozabocukali.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,EcLWqlheN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winioa32.rom,bXQpffOBxW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Inahumuqoboxeb=rundll32.exe "[%WINDOWS%]\mshpvcrf.dll",Startup
- HKEY_USERS\S-1-5-21-1960408961-1202660629-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Inahumuqoboxeb=rundll32.exe "[%WINDOWS%]\mshpvcrf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,cNwTqrbN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Inadoyipoxaz=rundll32.exe "[%LOCAL_APPDATA%]\azefogufag.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Chiyesikom=rundll32.exe "[%LOCAL_APPDATA%]\frte32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjef32.rom,CsaOzGTNnPFb
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vrejibugojudoyat=rundll32.exe "[%LOCAL_APPDATA%]\oqohexof.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvsh32.rom,apkmaQnePWi
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mgihidogosixaxe=rundll32.exe "[%WINDOWS%]\owuxebod.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windco32.rom,oqfXAotpjNzZ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jtefikumipob=rundll32.exe "[%LOCAL_APPDATA%]\oqekamikagoxu.dll",Startup
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs=[%SYSTEM%]\gelaginu.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hwuhuhogaj=rundll32.exe "[%WINDOWS%]\asagaxelayot.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbtn32.rom,MxZioVXw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxhs32.rom,NAZHrG
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wnawedabenu=rundll32.exe "[%WINDOWS%]\umatowuw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfc32.rom,hYcxbvmyc
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, muwowozudi="Rundll32.exe" "[%SYSTEM%]\zuwemomo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,dNOGUZiLbKSD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,VqBVEj
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fmoxeyuhasaju=rundll32.exe "[%WINDOWS%]\bntyl32.dll",Startup
- HKEY_USERS\S-1-5-21-1454471165-484763869-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fmoxeyuhasaju=rundll32.exe "[%WINDOWS%]\bntyl32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqse32.rom,dbUAUQ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winifz32.rom,cYYNopSTmhzE
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,GzzcBrBpPtLR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyza32.rom,YTrHPtSRhY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hbivafuva=rundll32.exe "[%WINDOWS%]\milnsrf.dll",Startup
- HKEY_USERS\S-1-5-21-1123561945-1580436667-839522115-2888\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hbivafuva=rundll32.exe "[%WINDOWS%]\milnsrf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hwunewohi=rundll32.exe "[%WINDOWS%]\owiqefam.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ajoyopogica=rundll32.exe "[%LOCAL_APPDATA%]\agihekaf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwuq32.rom,dVpexpfJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincir32.rom,sZgBQlkwrcX
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,ZOjwJGWVPXul
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrom32.rom,LjrznwOY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnfi32.rom,dNOGUZiLbKSD
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kqubomopaj=rundll32.exe "[%WINDOWS%]\etocejoxodo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhwb32.rom,moSgcBaWrkI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Izasediq=rundll32.exe "[%WINDOWS%]\uyivupomubarax.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {c85bd9f1-5b95-46da-9f39-979db6b58484}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Awefigejop=rundll32.exe "[%LOCAL_APPDATA%]\uyigocix.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vpokogap=rundll32.exe "[%LOCAL_APPDATA%]\iosvuip.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrjr32.rom,UhdKSrwGrL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tgimupof=rundll32.exe "[%LOCAL_APPDATA%]\ovizicesojo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiio32.rom,MeHQDFBO
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ifejibewerecome=rundll32.exe "[%WINDOWS%]\efezobes.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mbimeriyo=rundll32.exe "[%WINDOWS%]\rvatxlm.dll",Startup
- HKEY_USERS\S-1-5-21-796845957-1757981266-1801674531-1111\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mbimeriyo=rundll32.exe "[%WINDOWS%]\rvatxlm.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,IuoyWPL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgn32.rom,CyPLmh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpbm32.rom,ssklBcLjCOH
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windco32.rom,mXzIOvxWRCZZ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dkibukowomaqud=rundll32.exe "[%WINDOWS%]\egeqasoqege.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windnb32.rom,iDxiGxaK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winajk32.rom,AjRTAtm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiqk32.rom,BPmLWLCWjp
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bfoyutehobekeyoj=rundll32.exe "[%WINDOWS%]\k3rhaud.dll",Startup
- HKEY_USERS\S-1-5-21-854018487-10818781-619646970-4149\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bfoyutehobekeyoj=rundll32.exe "[%WINDOWS%]\k3rhaud.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winybl32.rom,WLdmmoezz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winplk32.rom,HKuoCyg
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfc32.rom,KyNPiAuGXHf
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Orixunufuq=rundll32.exe "[%LOCAL_APPDATA%]\oquwukati.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winybl32.rom,DecitZIWqj
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zeyayameli=Rundll32.exe "[%SYSTEM%]\gunawedi.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zeyayameli=Rundll32.exe "[%SYSTEM%]\gunawedi.dll",s
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, movuvupehu=Rundll32.exe "[%SYSTEM%]\lokubaja.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, movuvupehu=Rundll32.exe "[%SYSTEM%]\lokubaja.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfodekosubu=rundll32.exe "[%WINDOWS%]\ayewatebicog.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {2abaac42-84df-4c00-89da-bc7eb2b0e70b}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nowukadopi=Rundll32.exe "zobudome.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uralukowomaquden=rundll32.exe "[%WINDOWS%]\unubanov.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Byodaruyu=rundll32.exe "[%WINDOWS%]\exozoloce.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Byodaruyu=rundll32.exe "[%WINDOWS%]\exozoloce.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvsh32.rom,bmQCjw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhwn32.rom,NAZHrG
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxhs32.rom,HEVAylWPIiW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winytj32.rom,ngwLZxClFgWE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nhosaq=rundll32.exe "[%WINDOWS%]\iyevefifizosowu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, daseyezeba=Rundll32.exe "zukepive.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wgebozabulamu=rundll32.exe "[%WINDOWS%]\oyebagoga.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwiz32.rom,EHxbZkN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuwf32.rom,wiSaOdyDcKku
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qnaxahigusud=rundll32.exe "[%LOCAL_APPDATA%]\st32042.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrjf32.rom,CvVHOvIBo
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Slovozuvovepuri=rundll32.exe "[%WINDOWS%]\amupogaxeyu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlwq32.rom,IpjYsOBA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineoy32.rom,vZHLBQbir
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbiy32.rom,JJlvNlaTIyc
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM132976a8=Rundll32.exe "[%SYSTEM%]\lizazopi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gorajejiwu=Rundll32.exe "[%SYSTEM%]\tabolape.dll",s
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gorajejiwu=Rundll32.exe "[%SYSTEM%]\tabolape.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gorajejiwu=Rundll32.exe "[%SYSTEM%]\tabolape.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxcn32.rom,AzjsGZHA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsjl32.rom,FJnRqYFd
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winulo32.rom,rJMiYGeBtkfp
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gotekerit=Rundll32.exe "[%SYSTEM%]\vapapuju.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\qoMeBuRJ.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sjuhazobesi=rundll32.exe "[%WINDOWS%]\uzexanetixivum.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkeb32.rom,IvKgTjihbS
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F4123A9B.exe=[%PROFILE_TEMP%]\_A00F4123A9B.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3DE73272.exe=[%PROFILE_TEMP%]\_A00F3DE73272.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3DDF72DD.exe=[%PROFILE_TEMP%]\_A00F3DDF72DD.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3DD9C177.exe=[%PROFILE_TEMP%]\_A00F3DD9C177.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3DD5F59A.exe=[%PROFILE_TEMP%]\_A00F3DD5F59A.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 4dc7fdcf=rundll32.exe "[%SYSTEM%]\elqugghk.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ehinarig=rundll32.exe "[%WINDOWS%]\iwixojaponad.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jtefikumipob=rundll32.exe "[%LOCAL_APPDATA%]\anezemiz.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Ekoviqaqojunehoh=rundll32.exe "[%WINDOWS%]\apojisec.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {9e93a147-e3f9-47ab-baf0-915ccaaa7034}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbed32.rom,QknXRsTuNcrr
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Iborujepop=rundll32.exe "[%WINDOWS%]\kbdlrtf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ugorixej=rundll32.exe "[%WINDOWS%]\ufavapon.dll",Startup
- HKEY_USERS\S-1-5-21-1123561945-562591055-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Iborujepop=rundll32.exe "[%WINDOWS%]\kbdlrtf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kdukozunese=rundll32.exe "[%WINDOWS%]\ipateroq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwvy32.rom,gcQNEnpdfkq
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedcyaaudio=rundll32.exe "iihfgf.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedbyyaudio=rundll32.exe "ssqnno.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opopnlsys=rundll32.exe "qomlmj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedcyaaudio=rundll32.exe "iihfgf.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedbyyaudio=rundll32.exe "ssqnno.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opopnlsys=rundll32.exe "qomlmj.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {26934ef7-fdd9-4865-a003-fc96c00e38e8}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Omato=rundll32.exe "[%WINDOWS%]\kent32.dll",Startup
- HKEY_USERS\S-1-5-21-2025429265-57989841-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Omato=rundll32.exe "[%WINDOWS%]\kent32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincsc32.rom,OGHotJYzXAds
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomlijsys=rundll32.exe "qonmjj.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtrrssys=rundll32.exe "qonmjj.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtrrssys=rundll32.exe "qonmjj.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsad32.rom,GmvfsErsal
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,cGWJBXkjGAl
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintcy32.rom,GFIWWeTh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwiz32.rom,NPjiIIhgpWTa
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqez32.rom,OzSoVKPk
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xbakilecola=rundll32.exe "[%WINDOWS%]\udefidacosuwule.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geedcaaudio=rundll32.exe "efdabx.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkjhfsys=rundll32.exe "kheccy.dll",s
- HKEY_USERS\S-1-5-21-1220945662-1563985344-1801674531-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjkhhaudio=rundll32.exe "efdabx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjkhhaudio=rundll32.exe "efdabx.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qoppmkaudio=rundll32.exe "efdabx.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbawtsys=rundll32.exe "kheccy.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geedcaaudio=rundll32.exe "efdabx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkjhfsys=rundll32.exe "kheccy.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxhs32.rom,QDpCXEvJmwMN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winipx32.rom,OgCucX
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzpm32.rom,GPyLAUwDc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjfb32.rom,BgjPNaNYmW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pjevidixenibeke=rundll32.exe "[%LOCAL_APPDATA%]\iyumorunifus.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {bc728c13-5691-4529-a1c2-e662a9ad1c87}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,YdBXuCWmoK
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pgeligusudihoso=rundll32.exe "[%WINDOWS%]\oniyebiyini.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnxv32.rom,JLLvueqo
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkhn32.rom,YdBXuCWmoK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winojm32.rom,OgCucX
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winldd32.rom,uvNIvxkms
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgn32.rom,MKCMHEDkDpt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {adfd5fd2-2dd2-4572-80da-c74f1193fba1}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Izepeduz=rundll32.exe "[%LOCAL_APPDATA%]\ezagacudeze.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiot32.rom,AEolZW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Slozuhijucivici=rundll32.exe "[%LOCAL_APPDATA%]\ehezaziza.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyxe32.rom,vJCTpWwp
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geecyyaudio=rundll32.exe "iiiiji.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khedcdsys=rundll32.exe "fccbxv.dll",s
- HKEY_USERS\S-1-5-21-794359392-1475435980-2119202334-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvstraudio=rundll32.exe "iiiiji.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvstraudio=rundll32.exe "iiiiji.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkkkhaudio=rundll32.exe "iiiiji.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmkifcsys=rundll32.exe "fccbxv.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geecyyaudio=rundll32.exe "iiiiji.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khedcdsys=rundll32.exe "fccbxv.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqzb32.rom,MsryWU
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgq32.rom,ImXlXw
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rgiwatebicogi=rundll32.exe "[%WINDOWS%]\iqavasax.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnuj32.rom,EFixPySP
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tjudu=rundll32.exe "[%WINDOWS%]\ayavisidubadi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrnp32.rom,HOVIzjjZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwsf32.rom,dPgRjMOxtD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Krayeme=rundll32.exe "[%LOCAL_APPDATA%]\epirexow.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwss32.rom,HxRoSzz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincir32.rom,QAGnNki
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qjibugerudanesum=rundll32.exe "[%WINDOWS%]\arahalevetec.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjdi32.rom,uZvYNE
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbccyaudio=rundll32.exe "byvvwu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opopqnaudio=rundll32.exe "byvvwu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwvuvsys=rundll32.exe "ssqnkh.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstutqaudio=rundll32.exe "awwvtt.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkjghaudio=rundll32.exe "awwvtt.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaabyvaudio=rundll32.exe "byvvwu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcyabxaudio=rundll32.exe "awwvtt.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursstqsys=rundll32.exe "ssqnkh.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaabyvaudio=rundll32.exe "byvvwu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcyabxaudio=rundll32.exe "awwvtt.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursstqsys=rundll32.exe "ssqnkh.dll",s
- HKEY_USERS\S-1-5-21-515967899-308236825-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbccyaudio=rundll32.exe "byvvwu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lhixuhuziqizoqo=rundll32.exe "[%LOCAL_APPDATA%]\osefoxoq.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jtefikumipob=rundll32.exe "[%LOCAL_APPDATA%]\inafexemexizodul.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstqqraudio=rundll32.exe "opqono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khijkjsys=rundll32.exe "nnkkjh.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifcyyaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonoolaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbywwxsys=rundll32.exe "nnkkjh.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonoolaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbywwxsys=rundll32.exe "nnkkjh.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzyt32.rom,qgRGVbmwT
- HKEY_USERS\S-1-5-21-1720276175-3795423626-2984676618-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstqqraudio=rundll32.exe "opqono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Emiruco_=rundll32.exe "[%WINDOWS%]\oliqehisuketo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bziwe_=rundll32.exe "[%WINDOWS%]\wpshdet1.dll",Startup
- HKEY_USERS\S-1-5-21-1659004503-1580818891-725345543-2114\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bziwe_=rundll32.exe "[%WINDOWS%]\wpshdet1.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windnb32.rom,hYGVda
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\ssqNFUME.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtusqaudio=rundll32.exe "opqono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmnnnsys=rundll32.exe "nnkkjh.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyaawaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaawvwaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwtqpsys=rundll32.exe "nnkkjh.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgfdedsys=rundll32.exe "nnkkjh.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaawvwaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwtqpsys=rundll32.exe "nnkkjh.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgfdedsys=rundll32.exe "nnkkjh.dll",s
- HKEY_USERS\S-1-5-21-1720276175-3795423626-2984676618-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyaawaudio=rundll32.exe "opqono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddbccsys=rundll32.exe "nnkkjh.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddbccsys=rundll32.exe "nnkkjh.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gyojid=rundll32.exe "[%WINDOWS%]\ugolasihi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windju32.rom,LMBqHlD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbgo32.rom,KGzPmIaas
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintuc32.rom,HFUOUwFlQjq
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gludoyoradiyuba=rundll32.exe "[%WINDOWS%]\ewuxebodamu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uxucosuyega=rundll32.exe "[%WINDOWS%]\ugoqajac.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ifejibewerecome=rundll32.exe "[%WINDOWS%]\etuwemow.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjak32.rom,pzQnroEz
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kamebozafu=Rundll32.exe "[%SYSTEM%]\jimekaju.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kamebozafu=Rundll32.exe "[%SYSTEM%]\jimekaju.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrom32.rom,eBejxWdXz
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nfigibumer=rundll32.exe "[%WINDOWS%]\abexoqirac.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqdd32.rom,hwFeamFbE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sjagomuke=rundll32.exe "[%LOCAL_APPDATA%]\isirakipe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Apapojulo=rundll32.exe "[%WINDOWS%]\exukepeqe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqhs32.rom,yQhkiaRr
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Etofuzu=rundll32.exe "[%WINDOWS%]\agolilahacafofoc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winguc32.rom,DPPqZNI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuzg32.rom,KGzPmIaas
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhlt32.rom,xJCOHEGay
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifedsys=rundll32.exe "opmlkk.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifedsys=rundll32.exe "opmlkk.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rhituboner=rundll32.exe "[%WINDOWS%]\elasuzog.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windju32.rom,utRobUD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiio32.rom,yltOQAfdCI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Themav=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\ifaqiqamalan.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ojulesuzuzese=rundll32.exe "[%WINDOWS%]\ugifohavo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winohf32.rom,QKOyOmdM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winytj32.rom,yQhkiaRr
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cmovasoqegepa=rundll32.exe "[%LOCAL_APPDATA%]\ugomakulad.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Abiwisixejigulu=rundll32.exe "[%LOCAL_APPDATA%]\KBDBDf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ubalayujupiliy=rundll32.exe "[%WINDOWS%]\elukigej.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkcz32.rom,MmWbuMe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbtn32.rom,gXZcszpl
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxiwuxujabow=rundll32.exe "[%LOCAL_APPDATA%]\iyitetabejuy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Flabis=rundll32.exe "[%WINDOWS%]\mbdcrvig.dll",Startup
- HKEY_USERS\S-1-5-21-1417001333-1343024091-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Flabis=rundll32.exe "[%WINDOWS%]\mbdcrvig.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Snilugesavad=rundll32.exe "[%LOCAL_APPDATA%]\otexuqot.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmal32.rom,YTrHPtSRhY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ldujif=rundll32.exe "[%LOCAL_APPDATA%]\mslpicec.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtutusys=rundll32.exe "efcccb.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjhfedrv=rundll32.exe "vtuvsp.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrstrdrv=rundll32.exe "vtuvsp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxwwtdrv=rundll32.exe "vtuvsp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxwwtdrv=rundll32.exe "vtuvsp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwurpsys=rundll32.exe "efcccb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwurpsys=rundll32.exe "efcccb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,UypkpO
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wwezaq=rundll32.exe "[%WINDOWS%]\ikebefogufagelew.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkkjksys=rundll32.exe "opmlkk.dll",DllRegisterServer
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, molumiyuba=Rundll32.exe "[%SYSTEM%]\jerevufi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkhn32.rom,MJfNpULGpEeq
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jbonicacep=rundll32.exe "[%WINDOWS%]\asiponaduqiruh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xbakacudezen=rundll32.exe "[%WINDOWS%]\MShede.dll",Startup
- HKEY_USERS\S-1-5-21-1409082233-1788223648-1417001333-54422\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xbakacudezen=rundll32.exe "[%WINDOWS%]\MShede.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windju32.rom,aVtrdt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincmm32.rom,RYjKpxUgb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingzj32.rom,aryFmyENuk
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winybl32.rom,UOGdzatQhU
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiot32.rom,PCBhhjqT
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kpicaw=rundll32.exe "[%WINDOWS%]\eyadiyur.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pjevidixenibeke=rundll32.exe "[%LOCAL_APPDATA%]\uqihavon.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzmu32.rom,zzEWMfQQropM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURB.exe=[%SYSTEM%]\YURB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURB.exe=[%SYSTEM%]\YURB.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9.exe=[%SYSTEM%]\YUR9.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9.exe=[%SYSTEM%]\YUR9.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR13.exe=[%SYSTEM%]\YUR13.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR13.exe=[%SYSTEM%]\YUR13.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC4.exe=[%SYSTEM%]\YURC4.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC3.exe=[%SYSTEM%]\YURC3.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC5.exe=[%SYSTEM%]\YURC5.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC6.exe=[%SYSTEM%]\YURC6.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC4.exe=[%SYSTEM%]\YURC4.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC5.exe=[%SYSTEM%]\YURC5.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC3.exe=[%SYSTEM%]\YURC3.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ihejufufufufufuf=rundll32.exe "[%WINDOWS%]\uqixivazom.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nvehoputuyez=rundll32.exe "[%WINDOWS%]\ubogumaj.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhwn32.rom,yltOQAfdCI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wbuponorapulenar=rundll32.exe "[%WINDOWS%]\evenaxehizaji.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrji32.rom,aqHAMwE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uwicasudevi=rundll32.exe "[%WINDOWS%]\icasasiyuw.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xgowafi=rundll32.exe "[%WINDOWS%]\abosurase.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Snilugesavad=rundll32.exe "[%LOCAL_APPDATA%]\iradiwihe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hfugaxixib=rundll32.exe "[%WINDOWS%]\acimuduti.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbed32.rom,onLHZGSK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjef32.rom,EEZArtA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkeb32.rom,onLHZGSK
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ejeyoneravasa=rundll32.exe "[%WINDOWS%]\egekamod.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbgo32.rom,vAmXjLAcsgvU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURC6.exe=[%SYSTEM%]\YURC6.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgz32.rom,MJfNpULGpEeq
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqxl32.rom,LjtdyYNoxf
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winioa32.rom,bpekuXhcgt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhi32.rom,HrKYfyge
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyrd32.rom,HTtiPoNdPL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jpegafoj=rundll32.exe "[%LOCAL_APPDATA%]\edumeruj.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ekecovitogol=rundll32.exe "[%WINDOWS%]\etenulam.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tdojeziv=rundll32.exe "[%WINDOWS%]\padid1.dll",Startup
- HKEY_USERS\S-1-5-21-3349298161-2230622891-3413112137-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tdojeziv=rundll32.exe "[%WINDOWS%]\padid1.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {dd861218-a2ac-46ea-ad5a-6e97f48aca50}=
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nebebihafi=Rundll32.exe "[%SYSTEM%]\nijoroze.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ltucaveca=rundll32.exe "[%WINDOWS%]\igeqamab.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpqf32.rom,TegNwdyJb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winulo32.rom,CpcqHyLO
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fipeherizo=Rundll32.exe "[%SYSTEM%]\tadezuzu.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fipeherizo=Rundll32.exe "[%SYSTEM%]\tadezuzu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvsh32.rom,OMvdbXMj
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vmufiyovoxan=rundll32.exe "[%LOCAL_APPDATA%]\ofaxoyenevud.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbyq32.rom,PyiMmOQMPYV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwss32.rom,gkejELVR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winybl32.rom,GvEQoIgoio
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzrb32.rom,oEzGnEkyUUF
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwss32.rom,mQxtWRsLMtEs
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Omaricedo=rundll32.exe "[%LOCAL_APPDATA%]\uqayerid.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhes32.rom,mpDvqaF
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {43fcd2cf-5569-4208-97d2-52748e0ef6a0}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,iChJVoym
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvvvvusys=rundll32.exe "wvvwtq.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdbxuaudio=rundll32.exe "cbxuut.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursqqqaudio=rundll32.exe "cbbaaa.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbaabaudio=rundll32.exe "ssqrpq.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcccaydrv=rundll32.exe "khihhe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssttqnaudio=rundll32.exe "iihijj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifccbaudio=rundll32.exe "ddbyab.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxwtuaudio=rundll32.exe "ljklki.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxwttaudio=rundll32.exe "cbxuut.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwvsraudio=rundll32.exe "qonolk.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mliifcaudio=rundll32.exe "qonkkj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiihedaudio=rundll32.exe "efdbxw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljijigaudio=rundll32.exe "cbbaaa.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byyyaaaudio=rundll32.exe "mlmklm.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geecyxaudio=rundll32.exe "qomnlm.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byyvstaudio=rundll32.exe "ljkkij.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqppqnaudio=rundll32.exe "ssqrpq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkklmaudio=rundll32.exe "ljiige.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkhgaudio=rundll32.exe "bywtrp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtsrpaudio=rundll32.exe "iiffcc.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awustqaudio=rundll32.exe "sstsrp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geefffaudio=rundll32.exe "xxxxyv.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnmmnaudio=rundll32.exe "yaaawt.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbxuraudio=rundll32.exe "ddbawx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvvsqaudio=rundll32.exe "vtuvvw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomnmlaudio=rundll32.exe "ssrspq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddcaaaudio=rundll32.exe "cbbyaa.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxuvtaudio=rundll32.exe "vtuvsp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvuusaudio=rundll32.exe "byvtrr.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddaaabaudio=rundll32.exe "ddbbaa.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifcdcaudio=rundll32.exe "rqopqn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhffcdrv=rundll32.exe "khihhe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssttqnaudio=rundll32.exe "iihijj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifccbaudio=rundll32.exe "ddbyab.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxwtuaudio=rundll32.exe "ljklki.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxwttaudio=rundll32.exe "cbxuut.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwvsraudio=rundll32.exe "qonolk.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mliifcaudio=rundll32.exe "qonkkj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiihedaudio=rundll32.exe "efdbxw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljijigaudio=rundll32.exe "cbbaaa.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byyyaaaudio=rundll32.exe "mlmklm.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geecyxaudio=rundll32.exe "qomnlm.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byyvstaudio=rundll32.exe "ljkkij.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqppqnaudio=rundll32.exe "ssqrpq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkklmaudio=rundll32.exe "ljiige.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkhgaudio=rundll32.exe "bywtrp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtsrpaudio=rundll32.exe "iiffcc.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awustqaudio=rundll32.exe "sstsrp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geefffaudio=rundll32.exe "xxxxyv.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnmmnaudio=rundll32.exe "yaaawt.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbxuraudio=rundll32.exe "ddbawx.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvvsqaudio=rundll32.exe "vtuvvw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomnmlaudio=rundll32.exe "ssrspq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddcaaaudio=rundll32.exe "cbbyaa.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxuvtaudio=rundll32.exe "vtuvsp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvuusaudio=rundll32.exe "byvtrr.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddaaabaudio=rundll32.exe "ddbbaa.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifcdcaudio=rundll32.exe "rqopqn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhffcdrv=rundll32.exe "khihhe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxxutsys=rundll32.exe "wvvwtq.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxxutsys=rundll32.exe "wvvwtq.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMbf4311b7=Rundll32.exe "[%SYSTEM%]\muturebe.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,mQxtWRsLMtEs
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,fmRDZSPuR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoej32.rom,aryFmyENuk
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Knonoqih=rundll32.exe "[%LOCAL_APPDATA%]\apixucemucoroje.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjrj32.rom,YdBXuCWmoK
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnmjjsys=rundll32.exe "ddabay.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgdedsys=rundll32.exe "ddabay.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgdedsys=rundll32.exe "ddabay.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uzojajelehe=rundll32.exe "[%WINDOWS%]\ejubigax.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ifejibewerecome=rundll32.exe "[%WINDOWS%]\avihamir.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Owuzufujufux=rundll32.exe "[%WINDOWS%]\ujexuvijuki.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Oqeget=rundll32.exe "[%WINDOWS%]\coclgizc.dll",Startup
- HKEY_USERS\S-1-5-21-3000887322-1203367206-2587936551-501\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Owuzufujufux=rundll32.exe "[%WINDOWS%]\ututogolo.dll",Startup
- HKEY_USERS\S-1-5-21-3000887322-1203367206-2587936551-501\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Oqeget=rundll32.exe "[%WINDOWS%]\coclgizc.dll",Startup
- HKEY_USERS\S-1-5-21-3000887322-1203367206-2587936551-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Oqeget=rundll32.exe "[%WINDOWS%]\coclgizc.dll",Startup
- HKEY_USERS\S-1-5-21-3000887322-1203367206-2587936551-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Oqeget=rundll32.exe "[%WINDOWS%]\coclgizc.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Npigigegopepu=rundll32.exe "[%WINDOWS%]\otixotoyefulugaw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winapf32.rom,mWHPXlvaov
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dfapotuqolezib=rundll32.exe "[%LOCAL_APPDATA%]\axiqaquh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Idusite=rundll32.exe "[%WINDOWS%]\icntpmpr.dll",Startup
- HKEY_USERS\S-1-5-21-1020522785-2109557469-415601879-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Idusite=rundll32.exe "[%WINDOWS%]\icntpmpr.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhwb32.rom,rbiHPRmgeRm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Arepilu=rundll32.exe "[%LOCAL_APPDATA%]\KBDHCoc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vzoca=rundll32.exe "[%LOCAL_APPDATA%]\ofiruvupo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bwofovapuzegixo=rundll32.exe "[%WINDOWS%]\uhitokar.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwts32.rom,tdxyvsO
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Irumi=rundll32.exe "[%WINDOWS%]\ohavupom.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfc32.rom,mpDvqaF
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {13f20e4f-f379-41ea-8f80-ccaae787362a}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {45c2a50f-8f4a-496e-af02-d0207525bf5a}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjdi32.rom,dMldoTGEmuvV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Szenumulopocital=rundll32.exe "[%LOCAL_APPDATA%]\uwahatewisuc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxtq32.rom,GyIXpSqGj
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfcb32.rom,QcRZprtIB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ygikolifasufo=rundll32.exe "[%LOCAL_APPDATA%]\ayajunehohiceki.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ejibumut=rundll32.exe "[%WINDOWS%]\aqodotib.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Asiyimoxih=rundll32.exe "[%WINDOWS%]\Eqndhi.dll",Startup
- HKEY_USERS\S-1-5-21-854245398-1563985344-1060284298-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Asiyimoxih=rundll32.exe "[%WINDOWS%]\Eqndhi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,qTpResPcxz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,zwNNBAodw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiym32.rom,ipRFaY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbgo32.rom,fEQRnzNn
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,LSdIutKC
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, BM1e59c15a=Rundll32.exe "[%SYSTEM%]\vaqcbhrn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincba32.rom,YdBXuCWmoK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,kJyvdrvrZqM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfpw32.rom,kCUjSRVBoK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjrj32.rom,uZvYNE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hezazilum=Rundll32.exe "[%SYSTEM%]\nupanogo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6ebf089a-1c21-440e-8d60-ff3746fd5c28}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kohogelum={6ebf089a-1c21-440e-8d60-ff3746fd5c28}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs=[%SYSTEM%]\kurufihu.dll [%SYSTEM%]\tahisepi.dll
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, waragikosa=Rundll32.exe "[%SYSTEM%]\kuzefawi.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, waragikosa=Rundll32.exe "[%SYSTEM%]\kuzefawi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjrj32.rom,GReXPyN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmbz32.rom,OzSoVKPk
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmdb32.rom,mWHPXlvaov
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincir32.rom,qqBQBTs
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pjevidixenibeke=rundll32.exe "[%LOCAL_APPDATA%]\evaqohar.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 44f57284=rundll32.exe "[%SYSTEM%]\xrtaddqn.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yyequ=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\iniyotikapawogep.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfgz32.rom,mWHPXlvaov
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xsono=rundll32.exe "[%LOCAL_APPDATA%]\ujilirik.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hxupuliw=rundll32.exe "[%WINDOWS%]\uhavarowigesife.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lhujugujekafiy=rundll32.exe "[%LOCAL_APPDATA%]\axemapiqiy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winigi32.rom,WjnaOdsWqEs
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhdk32.rom,ipRFaY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windju32.rom,Zcgebbt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fzofi=rundll32.exe "[%WINDOWS%]\uzexujesazuku.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gtiwovavoxosoka=rundll32.exe "[%WINDOWS%]\upiwpis.dll",Startup
- HKEY_USERS\S-1-5-21-839867292-2508421555-865816491-1011\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gtiwovavoxosoka=rundll32.exe "[%WINDOWS%]\upiwpis.dll",Startup
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pilamenero=Rundll32.exe "[%SYSTEM%]\hejitavo.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pilamenero=Rundll32.exe "[%SYSTEM%]\kusitozo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nbelebezudana=rundll32.exe "[%WINDOWS%]\ageguzeyawebew.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winugy32.rom,QcRZprtIB
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pidovunani=Rundll32.exe "[%SYSTEM%]\jimiwemo.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pidovunani=Rundll32.exe "[%SYSTEM%]\jimiwemo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,xhrnymYFVvd
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkcz32.rom,LMYSHco
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lihukezuge=Rundll32.exe "[%SYSTEM%]\vubuvuha.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lihukezuge=Rundll32.exe "[%SYSTEM%]\vubuvuha.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Usiyosiv=rundll32.exe "[%WINDOWS%]\ocatadoqevoyox.dll",Startup
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
