Top 10 Alerts
Latest 10 Malware Files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win136.exe=[%SYSTEM%]\Win136.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win12B.exe=[%SYSTEM%]\Win12B.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win125.exe=[%SYSTEM%]\Win125.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win136.exe=[%SYSTEM%]\Win136.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win133.exe=[%SYSTEM%]\Win133.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win12B.exe=[%SYSTEM%]\Win12B.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win125.exe=[%SYSTEM%]\Win125.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \Win124.exe=[%SYSTEM%]\Win124.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winioa32.rom,MmjAAonbQj
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6588B41B-D14A-4B61-BA0B-B6F70F054292}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tdelem=rundll32.exe "[%WINDOWS%]\udasuket.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cpm272920d0=Rundll32.exe "[%SYSTEM%]\wotuzapi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 241a134c=rundll32.exe "[%SYSTEM%]\fihiyota.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, givakibahu=Rundll32.exe "[%SYSTEM%]\pihuwali.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cpinivumejabi=rundll32.exe "[%WINDOWS%]\MFPTP560.dll",Startup
- HKEY_USERS\S-1-5-21-684273676-1154595708-3659964400-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cpinivumejabi=rundll32.exe "[%WINDOWS%]\MFPTP560.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nhazaxesa=rundll32.exe "[%WINDOWS%]\ajuqufuna.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lqunilecolayizaj=rundll32.exe "[%WINDOWS%]\ikuhogev.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qbonulaqoc=rundll32.exe "[%WINDOWS%]\kpdesy.dll",Startup
- HKEY_USERS\S-1-5-21-1229272821-1532298954-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qbonulaqoc=rundll32.exe "[%WINDOWS%]\kpdesy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Eqocivehamir=rundll32.exe "[%LOCAL_APPDATA%]\eyipokid.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yvihuv=rundll32.exe "[%LOCAL_APPDATA%]\mstudnst.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winioa32.rom,LSdIutKC
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhw32.rom,ZlwSZSPM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winojr32.rom,jYTxlgiGv
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,VFHHmOl
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\urqOGVOe.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rluto=rundll32.exe "[%WINDOWS%]\wptrst.dll",Startup
- HKEY_USERS\S-1-5-21-2237637083-1072571693-1448886253-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rluto=rundll32.exe "[%WINDOWS%]\wptrst.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winulo32.rom,RXwAwspnMK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winofw32.rom,QBYqihSQPV
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled, Tmifucamo=rundll32.exe "[%WINDOWS%]\urokamod.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tmifucamo=rundll32.exe "[%WINDOWS%]\olaxocacirisoh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled, Qgolerezuqa=rundll32.exe "[%WINDOWS%]\necamf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qgolerezuqa=rundll32.exe "[%WINDOWS%]\necamf.dll",Startup
- HKEY_USERS\S-1-5-21-299502267-1177238915-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled, Qgolerezuqa=rundll32.exe "[%WINDOWS%]\necamf.dll",Startup
- HKEY_USERS\S-1-5-21-299502267-1177238915-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qgolerezuqa=rundll32.exe "[%WINDOWS%]\necamf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjdi32.rom,hNIjqlDW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awtsstsys=rundll32.exe "ddaxvu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjigdsys=rundll32.exe "ddaxvu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjigdsys=rundll32.exe "ddaxvu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddddbxsys=rundll32.exe "awuspq.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbcdadrv=rundll32.exe "ssqpmm.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlijklsys=rundll32.exe "awuspq.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlijklsys=rundll32.exe "awuspq.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxru32.rom,wdPJIRJxr
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonkhfsys=rundll32.exe "[%PROFILE_TEMP%]\qonnli.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbyvuaudio=rundll32.exe "[%PROFILE_TEMP%]\qonlkl.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxxyaaudio=rundll32.exe "[%PROFILE_TEMP%]\qonlkl.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmlihsys=rundll32.exe "[%PROFILE_TEMP%]\qonnli.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpbm32.rom,ODsgrafwUdHA
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cvefeposuce=rundll32.exe "[%WINDOWS%]\onivolov.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ddisuqeboq=rundll32.exe "[%WINDOWS%]\axobebagu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pdugepodatode=rundll32.exe "[%LOCAL_APPDATA%]\owoguvim.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqcc32.rom,rWKnku
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrv32.rom,wmPvQhSBceI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqcc32.rom,NBPyjyARkjix
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wrosuli=rundll32.exe "[%WINDOWS%]\inoxijumafu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rmusesabe=rundll32.exe "[%WINDOWS%]\herusg.dll",Startup
- HKEY_USERS\S-1-5-21-477163660-3524467549-1980530831-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rmusesabe=rundll32.exe "[%WINDOWS%]\herusg.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpdj32.rom,puJmbbYitT
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hovakufuse=Rundll32.exe "[%SYSTEM%]\wiwisoho.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hovakufuse=Rundll32.exe "[%SYSTEM%]\wiwisoho.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkxs32.rom,ZJxzmFWtLNI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyyq32.rom,ljWDYftBiCaN
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ygigibuzixuqotol=rundll32.exe "[%WINDOWS%]\abimawixorigeg.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wjocabobituyih=rundll32.exe "[%WINDOWS%]\tolsev.dll",Startup
- HKEY_USERS\S-1-5-21-606747145-2077806209-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wjocabobituyih=rundll32.exe "[%WINDOWS%]\tolsev.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, veguzal=Rundll32.exe "[%SYSTEM%]\kizevat.dll" s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winguc32.rom,PIAgdiiW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hfusimogudora=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\olosunogewu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Msigudafawinaqaf=rundll32.exe "[%LOCAL_APPDATA%]\arekanug.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\byXOfefF.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\rqRKCtSj.dll,c
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM13b6c5fb=Rundll32.exe "[%SYSTEM%]\tugufapi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 1085f667=rundll32.exe "[%SYSTEM%]\gokutoba.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, limiwiwafi=Rundll32.exe "[%SYSTEM%]\jihakera.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xfebajiyuhax=rundll32.exe "[%LOCAL_APPDATA%]\ovotagacuticab.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wgejamoxobuzog=rundll32.exe "[%LOCAL_APPDATA%]\comeras.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyrd32.rom,dbdKpCnWt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmxr32.rom,aVtrdt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fvikekaw=rundll32.exe "[%LOCAL_APPDATA%]\onaretoz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lbafuy=rundll32.exe "[%LOCAL_APPDATA%]\Ketdmser.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ixuqerecomexe=rundll32.exe "[%LOCAL_APPDATA%]\ajesiquy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bvukozuvovepur=rundll32.exe "[%LOCAL_APPDATA%]\ayuxusum.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,OnXMTSUDfuG
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cbefusadiyuregad=rundll32.exe "[%LOCAL_APPDATA%]\ushnsp.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {066a2cdc-319e-4460-ba45-c24562cd51aa}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {58aa2aab-e945-49e7-b7a2-672ac85367e7}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincba32.rom,dYNKOhrZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,eBejxWdXz
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-, A00FB46507.exe=[%PROFILE_TEMP%]\_A00FB46507.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgn32.rom,HnjhbzlM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lnefoja=rundll32.exe "[%WINDOWS%]\upanatanabona.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmkjksys=rundll32.exe "opqqpm.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvwwudrv=rundll32.exe "xxvurs.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnoppodrv=rundll32.exe "xxvwwt.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvwwudrv=rundll32.exe "xxvurs.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnoppodrv=rundll32.exe "xxvwwt.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urppnlsys=rundll32.exe "opqqpm.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urppnlsys=rundll32.exe "opqqpm.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rsupelaguzeyaweb=rundll32.exe "[%WINDOWS%]\izapiguyorukem.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,ODsgrafwUdHA
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6cfb7b83-b3e4-4ccc-a962-99189a800636}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fizuferob={6cfb7b83-b3e4-4ccc-a962-99189a800636}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcbbyaudio=rundll32.exe "[%PROFILE_TEMP%]\hggggg.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvttussys=rundll32.exe "[%PROFILE_TEMP%]\xxxutt.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Efica=rundll32.exe "[%LOCAL_APPDATA%]\ivimamajuxuges.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,bmQCjw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqxv32.rom,qtRKapPJcJkt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbyxusaudio=rundll32.exe "pmkjkl.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, effdbbaudio=rundll32.exe "pmkjkl.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbbywsys=rundll32.exe "byvust.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlklkaudio=rundll32.exe "yabxwu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdaxvsys=rundll32.exe "byvust.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlklkaudio=rundll32.exe "yabxwu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdaxvsys=rundll32.exe "byvust.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nhudapupiy=rundll32.exe "[%WINDOWS%]\isumilap.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ftaxagayusaqitih=rundll32.exe "[%WINDOWS%]\pioshk.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhsx32.rom,QknXRsTuNcrr
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\geBtUkiI.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BMc318a94c=Rundll32.exe "[%PROFILE_TEMP%]\hgbfnqod.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmljkaudio=rundll32.exe "xxvvts.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdecdsys=rundll32.exe "ssropp.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabxyvaudio=rundll32.exe "xxvvts.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khebxvsys=rundll32.exe "fcyvvs.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbawusys=rundll32.exe "tutroo.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlihhisys=rundll32.exe "ssropp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fccdbcaudio=rundll32.exe "xxvvts.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlihhisys=rundll32.exe "ssropp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fccdbcaudio=rundll32.exe "xxvvts.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiwq32.rom,cuHmhkJj
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kodasujoy=Rundll32.exe "[%SYSTEM%]\yigekote.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnsy32.rom,vAmXjLAcsgvU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dyorun=rundll32.exe "[%WINDOWS%]\ocudacir.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpbm32.rom,ImRHgFay
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Flexeciko=rundll32.exe "[%WINDOWS%]\axehosoz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ggamiroquqofoli=rundll32.exe "[%WINDOWS%]\wzcxpo.dll",Startup
- HKEY_USERS\S-1-5-21-1644491937-1343024091-1708537768-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ggamiroquqofoli=rundll32.exe "[%WINDOWS%]\wzcxpo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrv32.rom,rbiHPRmgeRm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winobp32.rom,xQEKMSFjn
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjrj32.rom,utRobUD
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rsupelaguzeyaweb=rundll32.exe "[%WINDOWS%]\afolecugofu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintuq32.rom,vIQQeSY
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wbiqax=rundll32.exe "[%WINDOWS%]\asuduliporerewer.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fzafaca=rundll32.exe "[%WINDOWS%]\agimoyesic.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bvukozuvovepur=rundll32.exe "[%LOCAL_APPDATA%]\uhocodeneq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrzy32.rom,oiliRiWfWi
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windyi32.rom,JegFJS
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, luwagiviko=Rundll32.exe "[%SYSTEM%]\tinasuva.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, luwagiviko=Rundll32.exe "[%SYSTEM%]\tinasuva.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hqefudivosogike=rundll32.exe "[%WINDOWS%]\enigogaj.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkmh32.rom,CKjCNyuH
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfi32.rom,ODsgrafwUdHA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyza32.rom,sQxnjv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM7b3becb5=Rundll32.exe "[%SYSTEM%]\popujubi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wenifikir=Rundll32.exe "[%SYSTEM%]\lolanayo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 7808df29=rundll32.exe "[%SYSTEM%]\yaruvofo.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nagipijira=Rundll32.exe "[%SYSTEM%]\wavowibi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Aqiracuqepiconih=rundll32.exe "[%LOCAL_APPDATA%]\ezovonej.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mgudasusevih=rundll32.exe "[%WINDOWS%]\ubebeditexete.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ljofeyitegigus=rundll32.exe "[%WINDOWS%]\asrerip.dll",Startup
- HKEY_USERS\S-1-5-21-606747145-1844823847-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ljofeyitegigus=rundll32.exe "[%WINDOWS%]\asrerip.dll",Startup
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kedolifuhe=Rundll32.exe "[%SYSTEM%]\wikakaru.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kedolifuhe=Rundll32.exe "[%SYSTEM%]\wikakaru.dll",s
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dobesuyelu=Rundll32.exe "[%SYSTEM%]\wenihubi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mxohi=rundll32.exe "[%LOCAL_APPDATA%]\uhijocetuwe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qfitusucamunuma=rundll32.exe "[%LOCAL_APPDATA%]\aracsc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winddp32.rom,bxzlny
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Amifelu=rundll32.exe "[%WINDOWS%]\afazuyufomorabul.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiqk32.rom,QXedXbL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,fWnJaGcLekG
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Twefoyatupek=rundll32.exe "[%WINDOWS%]\ugodusiboqu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Twogizuta=rundll32.exe "[%WINDOWS%]\axayekiten.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Evehapeqikoda=rundll32.exe "[%LOCAL_APPDATA%]\NLextsm.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,KmbwJWT
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cyofugo=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\ugutehihehate.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhdk32.rom,ONMgTIZszT
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rirawapola=Rundll32.exe "[%SYSTEM%]\liseruka.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rirawapola=Rundll32.exe "[%SYSTEM%]\liseruka.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Klujeviwecedulo=rundll32.exe "[%WINDOWS%]\okewiduc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfpw32.rom,XcMBGRyme
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winugy32.rom,eMFiNhw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winytj32.rom,ufAAbR
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dogosuwad=Rundll32.exe "[%SYSTEM%]\lofuwogi.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvvwutaudio=rundll32.exe "pmnnli.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrqqpaudio=rundll32.exe "khecde.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlihebaudio=rundll32.exe "pmnnli.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvwvtdrv=rundll32.exe "byvsqo.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbawxdrv=rundll32.exe "khgded.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbawxdrv=rundll32.exe "khgded.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opqpmjsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddawvsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddawvsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssropnaudio=rundll32.exe "pmnnli.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkhhaudio=rundll32.exe "pmnnli.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkhhaudio=rundll32.exe "pmnnli.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyxxysys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvsrpsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvsrpsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedawusys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbbxvsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbbxvsys=rundll32.exe "iiffed.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingaw32.rom,xQfpbgTnBz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqhx32.rom,omoZpxs
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsxu32.rom,sLOtAjUltRo
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windgj32.rom,lFCDkDkJPY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winckn32.rom,jDobUwjaT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhgddaudio=rundll32.exe "ursqpp.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmjhiaudio=rundll32.exe "ursqpp.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbaxusys=rundll32.exe "mlkjkj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtustssys=rundll32.exe "mlkjkj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtustssys=rundll32.exe "mlkjkj.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,QYFFJulGSJwR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winajk32.rom,OnXMTSUDfuG
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,jDobUwjaT
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hkukebebaguwim=rundll32.exe "[%WINDOWS%]\iyeleyoc.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Clepovugiy=rundll32.exe "[%WINDOWS%]\edibiloba.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxevagaw=rundll32.exe "[%WINDOWS%]\mondims.dll",Startup
- HKEY_USERS\S-1-5-21-4204921945-2981611746-2263166876-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxevagaw=rundll32.exe "[%WINDOWS%]\mondims.dll",Startup
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rijinipaka=Rundll32.exe "[%SYSTEM%]\yufiweru.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rijinipaka=Rundll32.exe "[%SYSTEM%]\yufiweru.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxuttsys=rundll32.exe "[%PROFILE_TEMP%]\wvwvsr.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxmn32.rom,sKqbXB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhsx32.rom,uavWgnkOakA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,rKiKbKZvM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiqk32.rom,aVtrdt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,tJjhzPmhFw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhi32.rom,VqBVEj
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyrd32.rom,XkwebtVrHJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,euoVQZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winybl32.rom,jsYZytpucU
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,TferTBprDabB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwes32.rom,aVtrdt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmkijaudio=rundll32.exe "nnomnn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnonmlaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxyawaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomnnnaudio=rundll32.exe "nnomnn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opqnnlsys=rundll32.exe "yaabaa.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdcyysys=rundll32.exe "yaabaa.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkkiiaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awussrsys=rundll32.exe "yaabaa.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifdcyaudio=rundll32.exe "nnomnn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkkiiaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awussrsys=rundll32.exe "yaabaa.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifdcyaudio=rundll32.exe "nnomnn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljgfghaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtspmaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtspmaudio=rundll32.exe "fcbyvw.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winybl32.rom,jMWRCt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winaho32.rom,keaDMDrekI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtusssys=rundll32.exe "[%PROFILE_TEMP%]\gedbya.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifedbaudio=rundll32.exe "opqnno.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmmklaudio=rundll32.exe "gebxvs.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljifgdaudio=rundll32.exe "opqnno.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifcdaudio=rundll32.exe "gebxvs.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awtqqnsys=rundll32.exe "mlkjkj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvtstaudio=rundll32.exe "gebxvs.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonooosys=rundll32.exe "mlkjkj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvtstaudio=rundll32.exe "gebxvs.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonooosys=rundll32.exe "mlkjkj.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjdi32.rom,QmwHuRrnehzr
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jbadelukiga=rundll32.exe "[%LOCAL_APPDATA%]\alacoqafar.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kyuge=rundll32.exe "[%WINDOWS%]\ezamojokesiyovup.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gtuqutibofe=rundll32.exe "[%WINDOWS%]\i3dmsr.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmjiiaudio=rundll32.exe "[%PROFILE_TEMP%]\opqomj.dll",s
- HKEY_USERS\S-1-5-21-2106437253-2158421917-2115271889-1012\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Slopaduqiruha=rundll32.exe "[%WINDOWS%]\msapi32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomljhaudio=rundll32.exe "cbyyxw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iihgebaudio=rundll32.exe "cbyyxw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabawtsys=rundll32.exe "efcbxv.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opopqosys=rundll32.exe "efcbxv.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddddcaaudio=rundll32.exe "cbyyxw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opopqosys=rundll32.exe "efcbxv.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddddcaaudio=rundll32.exe "cbyyxw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Twezor=rundll32.exe "[%WINDOWS%]\uloxotumudivos.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kvapanisapamote=rundll32.exe "[%WINDOWS%]\akudacirojikehad.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmyb32.rom,VxLvxOJWee
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjak32.rom,aVtrdt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwtrqaudio=rundll32.exe "pmkkij.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmmnlaudio=rundll32.exe "pmkkij.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddddbcsys=rundll32.exe "jkkhfg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwxwuaudio=rundll32.exe "cbywvu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyayvaudio=rundll32.exe "cbywvu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efffebaudio=rundll32.exe "cbywvu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssqomlsys=rundll32.exe "jkkhfg.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efffebaudio=rundll32.exe "cbywvu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssqomlsys=rundll32.exe "jkkhfg.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiqk32.rom,bUvdrpKrDhNJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Stamocacezafiteq=rundll32.exe "[%WINDOWS%]\idviewms.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Stamocacezafiteq=rundll32.exe "[%WINDOWS%]\idviewms.dll",Startup
- HKEY_USERS\S-1-5-21-3016678523-3895043386-4032527683-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Stamocacezafiteq=rundll32.exe "[%WINDOWS%]\idviewms.dll",Startup
- HKEY_USERS\S-1-5-21-3016678523-3895043386-4032527683-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Stamocacezafiteq=rundll32.exe "[%WINDOWS%]\idviewms.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hudawabuj=Rundll32.exe "[%SYSTEM%]\dewezuwa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {10e7579d-ec5a-4cd8-a39f-881c0d3385a0}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fasugigol={10e7579d-ec5a-4cd8-a39f-881c0d3385a0}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Dgofegepaz=rundll32.exe "[%LOCAL_APPDATA%]\udubivep.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dgofegepaz=rundll32.exe "[%LOCAL_APPDATA%]\udubivep.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hpefe=rundll32.exe "[%WINDOWS%]\umutatux.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hmotapu=rundll32.exe "[%WINDOWS%]\dluack32.dll",Startup
- HKEY_USERS\S-1-5-21-725345543-413027322-2147260053-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hmotapu=rundll32.exe "[%WINDOWS%]\dluack32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,dJupNdEhxA
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rudawifumo=Rundll32.exe "[%SYSTEM%]\juzeziwi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiot32.rom,mADfeNQbU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kxufuqicacepe=rundll32.exe "[%WINDOWS%]\ikotamag.dll",e
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wtohayizajovan=rundll32.exe "[%LOCAL_APPDATA%]\uhomejes.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gsejovaru=rundll32.exe "[%WINDOWS%]\opejunehohiceki.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pmopu=rundll32.exe "[%WINDOWS%]\ozelogiwabaf.dll",Startup
- HKEY_USERS\S-1-5-21-363371422-3126797434-1777047358-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pmopu=rundll32.exe "[%WINDOWS%]\ozelogiwabaf.dll",Startup
- HKEY_USERS\S-1-5-21-363371422-3126797434-1777047358-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pmopu=rundll32.exe "[%WINDOWS%]\ozelogiwabaf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingnr32.rom,uavWgnkOakA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzyt32.rom,Pjvyby
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqyu32.rom,FJnRqYFd
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxhs32.rom,nWTipqOqNW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wtihub=rundll32.exe "[%WINDOWS%]\ihevupoq.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pctfrb=RUNDLL32.EXE [%SYSTEM%]\msmlalfu.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hudawabuj=Rundll32.exe "[%SYSTEM%]\yagerumu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1209f2a6-2ab9-4faa-ac5c-6749aecb60d9}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dipisobiz={1209f2a6-2ab9-4faa-ac5c-6749aecb60d9}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\efcCurQK.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winddp32.rom,LQxwbHdsDcL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmkjijsys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywtssaudio=rundll32.exe "urpnki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifddaudio=rundll32.exe "urpnki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifcysys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khedaaaudio=rundll32.exe "urpnki.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvtrpsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khedaaaudio=rundll32.exe "urpnki.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvtrpsys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmnlmsys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opoppmaudio=rundll32.exe "urpnki.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkiijaudio=rundll32.exe "urpnki.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddeedsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqonoosys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqonoosys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byyvspaudio=rundll32.exe "urpnki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gebabcsys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvwxvaudio=rundll32.exe "urpnki.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khijkhsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urspnksys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urspnksys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbyvvaudio=rundll32.exe "urpnki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgfedsys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabawvaudio=rundll32.exe "urpnki.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaayawsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fccbcbsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fccbcbsys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjfb32.rom,iGJEFyvd
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlta32.rom,DNPzkMOKuf
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,DLrNgV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winith32.rom,mADfeNQbU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Slizaradewi=rundll32.exe "[%WINDOWS%]\ozowirozil.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pkukeqeluwe=rundll32.exe "[%WINDOWS%]\kbuptle.dll",Startup
- HKEY_USERS\S-1-5-21-2000478354-706699826-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pkukeqeluwe=rundll32.exe "[%WINDOWS%]\kbuptle.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Stavejifigocix=rundll32.exe "[%LOCAL_APPDATA%]\ucasafuz.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uvale=rundll32.exe "[%WINDOWS%]\isrhtr.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wjexiyonox=rundll32.exe "[%LOCAL_APPDATA%]\ahoninoz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkml32.rom,rEtvWD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnoliaudio=rundll32.exe "[%PROFILE_TEMP%]\ssqpmm.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mliigesys=rundll32.exe "[%PROFILE_TEMP%]\khefgd.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lqirovonegif=rundll32.exe "[%WINDOWS%]\atolepixox.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmbz32.rom,UcjxzVpkt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintuc32.rom,yXmCpCijS
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrta32.rom,LQxwbHdsDcL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mcequ=rundll32.exe "[%WINDOWS%]\taynbocf.dll",Startup
- HKEY_USERS\S-1-5-21-790525478-854245398-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mcequ=rundll32.exe "[%WINDOWS%]\taynbocf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlrl32.rom,hVXgZerUP
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rohuvizopa=Rundll32.exe "[%SYSTEM%]\lekupeyi.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rohuvizopa=Rundll32.exe "[%SYSTEM%]\lekupeyi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpqt32.rom,NuiOyTuoH
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyoo32.rom,QhOyeZLIFwj
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fwutonamevede=rundll32.exe "[%WINDOWS%]\iperapa.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fkiqixusoyaqo=rundll32.exe "[%WINDOWS%]\itipisozoqocefuw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqxv32.rom,hckSdB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhvr32.rom,LQxwbHdsDcL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlfo32.rom,GFIWWeTh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iihhhiaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqopolsys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedbaaaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssroolsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywvwxaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqopmmsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywvwxaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqopmmsys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgghgeaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urssqpsys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmlmkaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljifcbsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtsqosys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtsqosys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgfdbcaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhhfesys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkigfsys=rundll32.exe "ljigfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhiihaudio=rundll32.exe "xxxwvu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgdccsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgdccsys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wbiqax=rundll32.exe "[%WINDOWS%]\iwijebuqagetey.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mxisoxaxedak=rundll32.exe "[%WINDOWS%]\ltinbd.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Njufe=rundll32.exe "[%LOCAL_APPDATA%]\amasiyuwamoxobuz.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Abuwukaqibiyovo=rundll32.exe "[%WINDOWS%]\iveqidefa.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jwopunehohicek=rundll32.exe "[%LOCAL_APPDATA%]\ibupijov.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifghfaudio=rundll32.exe "urpnki.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomnosys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursspnaudio=rundll32.exe "urpnki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursspmsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggfedsys=rundll32.exe "ljigfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggfedsys=rundll32.exe "ljigfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mdamesubasebiw=rundll32.exe "[%WINDOWS%]\emayahejo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xzavocal=rundll32.exe "[%WINDOWS%]\apinde.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xzavocal=rundll32.exe "[%WINDOWS%]\apinde.dll",Startup
- HKEY_USERS\S-1-5-21-765794409-2066034309-1939501292-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xzavocal=rundll32.exe "[%WINDOWS%]\apinde.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwss32.rom,CxWMkiG
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqcc32.rom,GFIWWeTh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincir32.rom,IuoyWPL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbrv32.rom,JFIWsBifuFV
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Omefoqe=rundll32.exe "[%WINDOWS%]\olokuwafonutuliv.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dhawigu=rundll32.exe "[%LOCAL_APPDATA%]\awalequfir.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxhs32.rom,RArmPiBoO
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vdabiqu=rundll32.exe "[%WINDOWS%]\ujizukohoma.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmdb32.rom,GFIWWeTh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqse32.rom,GUgLxLmClJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exevirus winqse32.rom,GUgLxLmClJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpfi32.rom,IjqlDWC
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,aVtrdt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pxayerokowucafoj=rundll32.exe "[%WINDOWS%]\oxujuhiq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winugy32.rom,fIqRlJzT
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Utupadisayikovuv=rundll32.exe "[%WINDOWS%]\ojositad.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlrl32.rom,vIQQeSY
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kokusevimo=Rundll32.exe "[%SYSTEM%]\jehavomu.dll",s
- HKEY_USERS\S-1-5-21-2608422716-4151189271-1679842236-1007_Classes\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kokusevimo=Rundll32.exe "[%SYSTEM%]\jehavomu.dll",s
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kokusevimo=Rundll32.exe "[%SYSTEM%]\lidewiti.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kokusevimo=Rundll32.exe "[%SYSTEM%]\lidewiti.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kokusevimo=Rundll32.exe "[%SYSTEM%]\jehavomu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhiifsys=rundll32.exe "ljgheb.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabaaasys=rundll32.exe "ljgheb.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabaaasys=rundll32.exe "ljgheb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrj32.rom,FxuMGwOSkOCB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,HniJQLdwcFi
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, e2bc5b97=rundll32.exe "[%PROFILE_TEMP%]\gviubaxg.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,KteDqsmYKnlv
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkhn32.rom,FuTMxZioVXw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbrv32.rom,ECnWOBFbDCDy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jvatikeki=rundll32.exe "[%WINDOWS%]\amokazaqawico.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winugx32.rom,pQjKFui
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqyu32.rom,bTAlCkvX
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbiy32.rom,QHXYlzXaRAV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,DmRyhkiWXfjq
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qtetiqiyonoxuxa=rundll32.exe "[%WINDOWS%]\oyugigus.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxfp32.rom,rWKnku
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ngazaja=rundll32.exe "[%WINDOWS%]\iricohof.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ojecuhayat=rundll32.exe "[%LOCAL_APPDATA%]\ugovebuq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbgo32.rom,IzoemnRmllch
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnuj32.rom,vIQQeSY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvsh32.rom,xfZrqazMSOt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windco32.rom,FEQPKNnsT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,SGpfbL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxmn32.rom,wHpzBVthZueD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vrowoxo=rundll32.exe "[%LOCAL_APPDATA%]\obuqolezibahaqe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tcukutaze=rundll32.exe "[%LOCAL_APPDATA%]\mlspls.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wmerorucatofok=rundll32.exe "[%WINDOWS%]\iyevegohe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mlakikod=rundll32.exe "[%WINDOWS%]\tmapap.dll",Startup
- HKEY_USERS\S-1-5-21-1993962763-162531612-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mlakikod=rundll32.exe "[%WINDOWS%]\tmapap.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dsegopib=rundll32.exe "[%WINDOWS%]\ikidigib.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvwvsaudio=rundll32.exe "nnopqn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkjkjsys=rundll32.exe "ljiifc.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwuvtaudio=rundll32.exe "nnopqn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkihaudio=rundll32.exe "nnopqn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutuuraudio=rundll32.exe "tuvvts.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmmmmsys=rundll32.exe "ljiifc.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkihaudio=rundll32.exe "nnopqn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutuuraudio=rundll32.exe "tuvvts.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmmmmsys=rundll32.exe "ljiifc.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmws32.rom,QjuIhPuqyFxp
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ycelufevorid=rundll32.exe "[%WINDOWS%]\onuzozec.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vzuguqikuwafon=rundll32.exe "[%WINDOWS%]\wrpiet.dll",Startup
- HKEY_USERS\S-1-5-21-3122838510-1374153179-708785583-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vzuguqikuwafon=rundll32.exe "[%WINDOWS%]\wrpiet.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxpa32.rom,rWKnku
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifcbsys=rundll32.exe "xxvstu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yababasys=rundll32.exe "xxvstu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yababasys=rundll32.exe "xxvstu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintvo32.rom,RArmPiBoO
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhvr32.rom,wIQxQHHbq
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwes32.rom,TGZXiVlIdCv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\qoMfdbcy.dll,#1
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vunakewuli=Rundll32.exe "[%SYSTEM%]\segudedu.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vunakewuli=Rundll32.exe "[%SYSTEM%]\segudedu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tteholequfirawa=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\udedicuvuh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winurk32.rom,ccAonP
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Irujimo=rundll32.exe "[%WINDOWS%]\utdtPlg.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Pxererofiboqax=rundll32.exe "[%WINDOWS%]\arevinuyozewahat.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gminejul=rundll32.exe "[%WINDOWS%]\emepiqowaliyunol.dll",Startup
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F76231C5.exe=[%PROFILE_TEMP%]\_A00F76231C5.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrjf32.rom,GFIWWeTh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqrq32.rom,uavWgnkOakA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqez32.rom,uavWgnkOakA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winckn32.rom,kCUjSRVBoK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windju32.rom,oIgUMhRqxPN
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, piviyikove=Rundll32.exe "[%SYSTEM%]\yamapaso.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, piviyikove=Rundll32.exe "[%SYSTEM%]\yamapaso.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Uzojajelehe=rundll32.exe "[%WINDOWS%]\ucawodafuvelikol.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uzojajelehe=rundll32.exe "[%WINDOWS%]\ucawodafuvelikol.dll",Startup
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
