Top 10 Alerts
Latest 10 Malware Files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tussqpsys=rundll32.exe "khijif.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxxxvsys=rundll32.exe "nnkkii.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifgfesys=rundll32.exe "nnkkii.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifgfesys=rundll32.exe "nnkkii.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gyicihagonama=rundll32.exe "[%LOCAL_APPDATA%]\omawifapo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bfasoze=rundll32.exe "[%LOCAL_APPDATA%]\icantz.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hudawabuj=Rundll32.exe "[%SYSTEM%]\zuragiwu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {364a83ed-948f-4599-8899-32ff50a4b6f9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dapuhufiw={364a83ed-948f-4599-8899-32ff50a4b6f9}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winifz32.rom,iGJEFyvd
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vpewo=rundll32.exe "[%WINDOWS%]\azayolax.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Msovicakih=rundll32.exe "[%WINDOWS%]\odoquqisef.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gpiloweqohar=rundll32.exe "[%WINDOWS%]\mrmgnhfs.dll",Startup
- HKEY_USERS\S-1-5-21-3802400216-1371315241-3233852318-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gpiloweqohar=rundll32.exe "[%WINDOWS%]\mrmgnhfs.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Skenevocogir=rundll32.exe "[%WINDOWS%]\ixafopawuqe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxulupoqox=rundll32.exe "[%WINDOWS%]\wsawif.dll",Startup
- HKEY_USERS\S-1-5-21-3705231157-2831351310-1404658679-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxulupoqox=rundll32.exe "[%WINDOWS%]\wsawif.dll",Startup
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, segoliripi=Rundll32.exe "[%SYSTEM%]\hohejupo.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, segoliripi=Rundll32.exe "[%SYSTEM%]\hohejupo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ovegicomeposuc=rundll32.exe "[%WINDOWS%]\osamocinexilah.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nvohocigezorijeg=rundll32.exe "[%WINDOWS%]\nryepn.dll",Startup
- HKEY_USERS\S-1-5-21-4019083953-2954773332-3430814185-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nvohocigezorijeg=rundll32.exe "[%WINDOWS%]\nryepn.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURCFDB.exe=[%SYSTEM%]\YURCFDB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURECAE.exe=[%SYSTEM%]\YURECAE.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD98C.exe=[%SYSTEM%]\YURD98C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD519.exe=[%SYSTEM%]\YURD519.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD1CF.exe=[%SYSTEM%]\YURD1CF.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qcekesi=rundll32.exe "[%WINDOWS%]\esuyusikuno.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fquzalogu=rundll32.exe "[%WINDOWS%]\jmplag.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursqnnsys=rundll32.exe "hgfdeb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnooopsys=rundll32.exe "hgfdeb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaaxvvsys=rundll32.exe "urronl.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttusqsys=rundll32.exe "hgfdeb.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttusqsys=rundll32.exe "hgfdeb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjrj32.rom,QrFyaCDlc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkml32.rom,ADVFfEfziGfn
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrps32.rom,VRFejTjLhp
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sliwosiholuhuziq=rundll32.exe "[%WINDOWS%]\imufifiz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Alivapeqik=rundll32.exe "[%WINDOWS%]\roalbthd.dll",Startup
- HKEY_USERS\S-1-5-21-2104812841-3475023466-443580600-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Alivapeqik=rundll32.exe "[%WINDOWS%]\roalbthd.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhlt32.rom,FjZorhhhD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xdomilesolas=rundll32.exe "[%LOCAL_APPDATA%]\edatokes.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gyadocifalutih=rundll32.exe "[%LOCAL_APPDATA%]\finvevfs.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lyokakamikagox=rundll32.exe "[%LOCAL_APPDATA%]\m3utpch.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\geBrrRkl.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhwn32.rom,rBfJmcGot
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suhajakohu=Rundll32.exe "[%COMMON_APPDATA%]\mazihihe\mazihihe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suhajakohu=Rundll32.exe "[%COMMON_APPDATA%]\mazihihe\mazihihe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ptinup=rundll32.exe "[%WINDOWS%]\dvms2plt.dll",Startup
- HKEY_USERS\S-1-5-21-1220945662-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ptinup=rundll32.exe "[%WINDOWS%]\dvms2plt.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqrq32.rom,YBCMTsig
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpdc32.rom,KCtOBpyaY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpan32.rom,BzxiMRec
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURD98C.exe=[%SYSTEM%]\YURD98C.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURDD91.exe=[%SYSTEM%]\YURDD91.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURE262.exe=[%SYSTEM%]\YURE262.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YURCDC9.exe=[%SYSTEM%]\YURCDC9.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjef32.rom,FjZorhhhD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nbatig=rundll32.exe "[%LOCAL_APPDATA%]\imataqun.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Smitogom=rundll32.exe "[%LOCAL_APPDATA%]\MFusmcag.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nmukac=rundll32.exe "[%WINDOWS%]\APSAXpt.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {f6725edc-93ff-479b-a98b-c5b9e3c44864}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiiffesys=rundll32.exe "opqrsr.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmkheaudio=rundll32.exe "opqopo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dnheds=RUNDLL32.EXE [%SYSTEM%]\msdaozls.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyxusaudio=rundll32.exe "byvwvw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutqpmaudio=rundll32.exe "byvwvw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbyawtsys=rundll32.exe "dddaay.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkiifaudio=rundll32.exe "ddbcbx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opolklaudio=rundll32.exe "ddbcbx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtqqnsys=rundll32.exe "dddaay.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtqqnsys=rundll32.exe "dddaay.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Usoyacuqepicon=rundll32.exe "[%WINDOWS%]\ekibezud.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vjirikixezib=rundll32.exe "[%WINDOWS%]\mudngat.dll",Startup
- HKEY_USERS\S-1-5-21-1292428093-1637723038-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vjirikixezib=rundll32.exe "[%WINDOWS%]\mudngat.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbgo32.rom,uNepIqJpyKaK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ndotikijirazo=rundll32.exe "[%LOCAL_APPDATA%]\dierAug4.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfqj32.rom,NuiOyTuoH
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlmj32.rom,iKqIzDbAGXbH
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winuji32.rom,kdJOZCCUmz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhi32.rom,YdYpRPzitjfn
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstqnlsys=rundll32.exe "vtttrp.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomkhsys=rundll32.exe "vtttrp.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomkhsys=rundll32.exe "vtttrp.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincqh32.rom,EsfkEH
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnolkisys=rundll32.exe "opoolj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbcbxsys=rundll32.exe "opoolj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddbcbxsys=rundll32.exe "opoolj.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lfofufoqiwuhurop=rundll32.exe "[%LOCAL_APPDATA%]\udugohewat.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vcilef=rundll32.exe "[%LOCAL_APPDATA%]\moyn32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winopc32.rom,olAsdWux
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfpw32.rom,QyiBHrPs
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnwo32.rom,oGLKRgdMFts
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dsazaquzacuf=rundll32.exe "[%LOCAL_APPDATA%]\ihugoxut.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Amadiqohuw=rundll32.exe "[%LOCAL_APPDATA%]\ra04030.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pcokijudulig=rundll32.exe "[%WINDOWS%]\rceylufv.dll",Startup
- HKEY_USERS\S-1-5-21-1390067357-861567501-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pcokijudulig=rundll32.exe "[%WINDOWS%]\rceylufv.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winplk32.rom,VruXzGljF
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,MEDxVWqzgF
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yekayuses=Rundll32.exe "[%SYSTEM%]\yuworowe.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {c47a9554-195a-4769-9b13-04f15b450a39}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxumazubijaxes=rundll32.exe "[%LOCAL_APPDATA%]\ASTSGFri.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windco32.rom,QXedXbL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrso32.rom,jMWRCt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpdc32.rom,LOQTKXBhpW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiqk32.rom,McZcQym
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqez32.rom,BSpELgDp
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdb32.rom,ROBxHZwOP
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopnlkdrv=rundll32.exe "khigdc.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, effdaxdrv=rundll32.exe "khigdc.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, effdaxdrv=rundll32.exe "khigdc.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmmjksys=rundll32.exe "pmlmll.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmmjksys=rundll32.exe "pmlmll.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzyt32.rom,FxuMGwOSkOCB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,eonLdA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Urequl=rundll32.exe "[%LOCAL_APPDATA%]\ulegunep.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Phitiquyepiy=rundll32.exe "[%LOCAL_APPDATA%]\KBDEGR1.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windnb32.rom,FEQPKNnsT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sjiwugitixezo=rundll32.exe "[%LOCAL_APPDATA%]\egirukemomopuduy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ofijigejimijigo=rundll32.exe "[%LOCAL_APPDATA%]\msvdu3.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gzihi=rundll32.exe "[%LOCAL_APPDATA%]\KBDMIn.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ffugoxotum=rundll32.exe "[%WINDOWS%]\ufaxazexowalifip.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fdirizaz=rundll32.exe "[%LOCAL_APPDATA%]\akavujepope.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Anerozil=rundll32.exe "[%WINDOWS%]\oyiqajet.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddddecsys=rundll32.exe "dddcdc.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khihhfsys=rundll32.exe "dddcdc.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khihhfsys=rundll32.exe "dddcdc.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pzuquhuwonezonu=rundll32.exe "[%WINDOWS%]\ewilohoq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ghife=rundll32.exe "[%WINDOWS%]\ntht31.dll",Startup
- HKEY_USERS\S-1-5-21-854245398-630328440-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ghife=rundll32.exe "[%WINDOWS%]\ntht31.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yjowogumaja=rundll32.exe "[%LOCAL_APPDATA%]\inujifoha.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Olero=rundll32.exe "[%LOCAL_APPDATA%]\DSyubAcS.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winigi32.rom,HuBOKzCa
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrj32.rom,CPPgUwjD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlihfdaudio=rundll32.exe "qonkki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuspqpaudio=rundll32.exe "qonkki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvuussys=rundll32.exe "ddbcbx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtqrqaudio=rundll32.exe "qonkki.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvvvvsys=rundll32.exe "ddbcbx.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtqrqaudio=rundll32.exe "qonkki.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvvvvsys=rundll32.exe "ddbcbx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, oponmkdrv=rundll32.exe "opooom.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geecccdrv=rundll32.exe "opooom.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkigedrv=rundll32.exe "opooom.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkigedrv=rundll32.exe "opooom.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddawwusys=rundll32.exe "jkjkkl.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvtuusys=rundll32.exe "jkjkkl.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvtuusys=rundll32.exe "jkjkkl.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ihudub=rundll32.exe "[%LOCAL_APPDATA%]\ahuyomeb.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pbadowucafojufan=rundll32.exe "[%LOCAL_APPDATA%]\ahulesolas.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Itowir=rundll32.exe "[%LOCAL_APPDATA%]\KBDSDa.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrps32.rom,lFCDkDkJPY
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qsuwa=rundll32.exe "[%WINDOWS%]\udifowasilarefo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uyipami=rundll32.exe "[%WINDOWS%]\lumouil.dll",Startup
- HKEY_USERS\S-1-5-21-58362785-1927153374-101290001-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uyipami=rundll32.exe "[%WINDOWS%]\lumouil.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hsajegada=rundll32.exe "[%WINDOWS%]\umiruwok.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Grufumerujom=rundll32.exe "[%WINDOWS%]\froduo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jgebivo=rundll32.exe "[%WINDOWS%]\etlost.dll",Startup
- HKEY_USERS\S-1-5-21-527237240-1229272821-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jgebivo=rundll32.exe "[%WINDOWS%]\etlost.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,QknXRsTuNcrr
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mtuhaduxo=rundll32.exe "[%LOCAL_APPDATA%]\ajocinexil.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyms32.rom,SWiaEyv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mxopugerudan=rundll32.exe "[%WINDOWS%]\unicogira.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qmimeguyoy=rundll32.exe "[%WINDOWS%]\kbdmst.dll",Startup
- HKEY_USERS\S-1-5-21-3577963067-3891133691-3700566796-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qmimeguyoy=rundll32.exe "[%WINDOWS%]\kbdmst.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfcb32.rom,YBCMTsig
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxywvvdrv=rundll32.exe "ssqpon.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttrqrdrv=rundll32.exe "dddeed.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbcbysys=rundll32.exe "rqrqoo.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbxursys=rundll32.exe "rqrqoo.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbxursys=rundll32.exe "rqrqoo.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxnz32.rom,wIQxQHHbq
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,KGyUdCnoN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winurk32.rom,UGEbPYVi
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, waragikosa=Rundll32.exe "[%SYSTEM%]\wipoveku.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, waragikosa=Rundll32.exe "[%SYSTEM%]\wipoveku.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgz32.rom,xeUpuhksb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jtihekajo=rundll32.exe "[%LOCAL_APPDATA%]\uqokebeg.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fduvono=rundll32.exe "[%WINDOWS%]\afahiciq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fjorofulohoqu=rundll32.exe "[%WINDOWS%]\oactxc.dll",Startup
- HKEY_USERS\S-1-5-21-1275210071-484763869-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fjorofulohoqu=rundll32.exe "[%WINDOWS%]\oactxc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxtq32.rom,KGyUdCnoN
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,apkmaQnePWi
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwpr32.rom,mZWrCZYx
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winggf32.rom,NoWVegrmCM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cmaya=rundll32.exe "[%WINDOWS%]\ofaqasunufuqo.dll",Startup
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqppnmsys=rundll32.exe "bywuvw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqppnmsys=rundll32.exe "bywuvw.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbrv32.rom,xyKKMsCFvd
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Phicehokofatahix=rundll32.exe "[%WINDOWS%]\iebse2r.dll",Startup
- HKEY_USERS\S-1-5-21-789336058-1682526488-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Phicehokofatahix=rundll32.exe "[%WINDOWS%]\iebse2r.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hpiwibikixezib=rundll32.exe "[%WINDOWS%]\ifopizulufuj.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Avejobeditexeted=rundll32.exe "[%WINDOWS%]\SRDAVODF.dll",Startup
- HKEY_USERS\S-1-5-21-1372052820-3660714712-3685400738-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Avejobeditexeted=rundll32.exe "[%WINDOWS%]\SRDAVODF.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lwijifi=rundll32.exe "[%LOCAL_APPDATA%]\akenanerul.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lcihafabipere=rundll32.exe "[%LOCAL_APPDATA%]\DTPNlt.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Awunar=rundll32.exe "[%WINDOWS%]\amatihum.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bvamahuyuruw=rundll32.exe "[%WINDOWS%]\lbdbdxti.dll",Startup
- HKEY_USERS\S-1-5-21-1220945662-1993962763-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bvamahuyuruw=rundll32.exe "[%WINDOWS%]\lbdbdxti.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlmj32.rom,ROureUJP
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {9a50b2af-3b2b-47dd-aecd-5d80a886f504}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,EQdZjNNpi
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jsitop=rundll32.exe "[%WINDOWS%]\iqoyotik.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dcoduzozecahexof=rundll32.exe "[%WINDOWS%]\rvcwip.dll",Startup
- HKEY_USERS\S-1-5-21-1644491937-920026266-299502267-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dcoduzozecahexof=rundll32.exe "[%WINDOWS%]\rvcwip.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rwemu=rundll32.exe "[%LOCAL_APPDATA%]\ibd32560.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxmt32.rom,VtNbVRjZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkeb32.rom,OGHotJYzXAds
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Onahaponam=rundll32.exe "[%LOCAL_APPDATA%]\ikayixus.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pbonipip=rundll32.exe "[%LOCAL_APPDATA%]\clcols08.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjfb32.rom,daEGKqYT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,twxqrMbofmBt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrta32.rom,VBVojUPTS
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikeralebi=rundll32.exe "[%WINDOWS%]\lvceagde.dll",Startup
- HKEY_USERS\S-1-5-21-1229272821-1060284298-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikeralebi=rundll32.exe "[%WINDOWS%]\lvceagde.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,qrbtmn
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\ssqPHxUN.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlkjjsys=rundll32.exe "iiiiji.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwwxwsys=rundll32.exe "iiiiji.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwwxwsys=rundll32.exe "iiiiji.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ltisakihevatep=rundll32.exe "[%LOCAL_APPDATA%]\NTYSRURE.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sbetuzuhovehula=rundll32.exe "[%WINDOWS%]\iradotib.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jdeqezorijego=rundll32.exe "[%WINDOWS%]\ntpcuce.dll",Startup
- HKEY_USERS\S-1-5-21-1614895754-776561741-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jdeqezorijego=rundll32.exe "[%WINDOWS%]\ntpcuce.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wfaca=rundll32.exe "[%WINDOWS%]\idedarexow.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rsakijo=rundll32.exe "[%WINDOWS%]\qc4056.dll",Startup
- HKEY_USERS\S-1-5-21-1078081533-1284227242-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rsakijo=rundll32.exe "[%WINDOWS%]\qc4056.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsad32.rom,iFYcMqbt
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nsilevo=rundll32.exe "[%WINDOWS%]\pmeticl.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyoo32.rom,aLcKVxOIDvJR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,CjZANnmjcPD
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vladuwa=rundll32.exe "[%WINDOWS%]\atevefifizo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ocimucuyajasu=rundll32.exe "[%WINDOWS%]\ervsrg.dll",Startup
- HKEY_USERS\S-1-5-21-3638723732-4213920237-875907564-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ocimucuyajasu=rundll32.exe "[%WINDOWS%]\ervsrg.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Axezeneq=rundll32.exe "[%WINDOWS%]\edacikot.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttuvwdrv=rundll32.exe "opqqpp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlklmndrv=rundll32.exe "opqqpp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlklmndrv=rundll32.exe "opqqpp.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnonnsys=rundll32.exe "awwvtt.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xkeyaranawifu=rundll32.exe "[%WINDOWS%]\odavinasowo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\pmnkKbCV.dll,c
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingnr32.rom,QrFyaCDlc
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yponaqo=rundll32.exe "[%WINDOWS%]\epipevub.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sweri=rundll32.exe "[%WINDOWS%]\kbjtsv.dll",Startup
- HKEY_USERS\S-1-5-21-1708537768-1284227242-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sweri=rundll32.exe "[%WINDOWS%]\kbjtsv.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, edcsjh=RUNDLL32.EXE [%SYSTEM%]\msgvbtjn.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gxelew=rundll32.exe "[%WINDOWS%]\atfamgsp.dll",Startup
- HKEY_USERS\S-1-5-21-527237240-606747145-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gxelew=rundll32.exe "[%WINDOWS%]\atfamgsp.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhpa32.rom,ONMgTIZszT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxru32.rom,eMFiNhw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvfe32.rom,lFCDkDkJPY
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ewixuqeruzonahuk=rundll32.exe "[%LOCAL_APPDATA%]\KBDPng2.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiym32.rom,YRlamUtCp
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fdobiwogi=rundll32.exe "[%LOCAL_APPDATA%]\lpiglhz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrv32.rom,JTtYnwLmFSF
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Psumumenesanuzeh=rundll32.exe "[%LOCAL_APPDATA%]\snrotoxi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssrppndrv=rundll32.exe "jkjijg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbyyawdrv=rundll32.exe "jkjijg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttsqrsys=rundll32.exe "fcyawx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awtrqosys=rundll32.exe "fcyawx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geddefdrv=rundll32.exe "jkjijg.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awtrqosys=rundll32.exe "fcyawx.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geddefdrv=rundll32.exe "jkjijg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khggfdsys=rundll32.exe "effgfg.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgfgdcdrv=rundll32.exe "ljiiii.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmmlidrv=rundll32.exe "ljiiii.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opqolmdrv=rundll32.exe "ssrrsq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttqqqdrv=rundll32.exe "ssrrsq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttqqqdrv=rundll32.exe "ssrrsq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljgdaasys=rundll32.exe "gebyab.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstuussys=rundll32.exe "gebyab.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstuussys=rundll32.exe "gebyab.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfqj32.rom,wEjYrjm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lyekoyi=rundll32.exe "[%LOCAL_APPDATA%]\theapi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dnixegozavo=rundll32.exe "[%LOCAL_APPDATA%]\ezofadufodiz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gbiyinebagoga=rundll32.exe "[%LOCAL_APPDATA%]\KBDadm.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfcb32.rom,HXqOnYZaUrW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxuv32.rom,KDEDbAvHDPi
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fhelihocimafe=rundll32.exe "[%LOCAL_APPDATA%]\upalenarohilo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ocazerevafi=rundll32.exe "[%LOCAL_APPDATA%]\ASnsms.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnfi32.rom,qGTPJyx
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqrq32.rom,piemnVac
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cxeyu=rundll32.exe "[%LOCAL_APPDATA%]\arelexexe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wzipacihirewapa=rundll32.exe "[%LOCAL_APPDATA%]\mStPOb.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmdb32.rom,Xehwxu
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pukajiveju=Rundll32.exe "[%SYSTEM%]\juyadewi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhsx32.rom,RWdRWO
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qqunoka=rundll32.exe "[%WINDOWS%]\ozayogovi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dseha=rundll32.exe "[%WINDOWS%]\rtioft50.dll",Startup
- HKEY_USERS\S-1-5-21-3428043183-2211055249-1831991071-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dseha=rundll32.exe "[%WINDOWS%]\rtioft50.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winllf32.rom,wmPPbFKJkUg
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sweqevoz=rundll32.exe "[%WINDOWS%]\sacaftua.dll",Startup
- HKEY_USERS\S-1-5-21-1844237615-261478967-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sweqevoz=rundll32.exe "[%WINDOWS%]\sacaftua.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfpw32.rom,OCLIVZMDSVc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tjunofezi=rundll32.exe "[%WINDOWS%]\anshchoe.dll",Startup
- HKEY_USERS\S-1-5-21-1614895754-1979792683-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tjunofezi=rundll32.exe "[%WINDOWS%]\anshchoe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Showiwanom=rundll32.exe "[%LOCAL_APPDATA%]\fdPeHTE.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vjadepasu=rundll32.exe "[%WINDOWS%]\ixitesuzupijafer.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gvefegumesa=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\apuvazij.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fzefo=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\wldpspl.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Onoraraxonugi=rundll32.exe "[%LOCAL_APPDATA%]\udakanujuq.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ljizisubac=rundll32.exe "[%WINDOWS%]\opizcpA.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Szitucam=rundll32.exe "[%LOCAL_APPDATA%]\amovilitaciw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Evopuwezan=rundll32.exe "[%LOCAL_APPDATA%]\mexpt32.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfc32.rom,pJFbnFpfmqO
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {03657894-7c44-4ef3-a162-e70d19564373}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rdllvz=RUNDLL32.EXE [%SYSTEM%]\mslaejjs.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qaqmyc=RUNDLL32.EXE [%SYSTEM%]\mskdlpso.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wdvcnx=RUNDLL32.EXE [%SYSTEM%]\msmrxgok.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vwikayusaqitih=rundll32.exe "[%WINDOWS%]\enexigot.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ucayerafiqej=rundll32.exe "[%WINDOWS%]\hcusapv.dll",Startup
- HKEY_USERS\S-1-5-21-4120639718-1920170257-3011144544-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ucayerafiqej=rundll32.exe "[%WINDOWS%]\hcusapv.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windnb32.rom,YQQVpbnM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winyms32.rom,IdyIuADfc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpqt32.rom,XkQEMEP
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dyoboc=rundll32.exe "[%WINDOWS%]\wsini2t.dll",Startup
- HKEY_USERS\S-1-5-21-1177238915-1450960922-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dyoboc=rundll32.exe "[%WINDOWS%]\wsini2t.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintuc32.rom,SiIKeL
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcbcdsys=rundll32.exe "fccyvs.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiihhesys=rundll32.exe "fccyvs.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiihhesys=rundll32.exe "fccyvs.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mpocaqawicoziqow=rundll32.exe "[%WINDOWS%]\ifucehezusuqikuw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkml32.rom,vOfozT
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pbibacaj=rundll32.exe "[%WINDOWS%]\ayaqabezaxeqe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hjuzik=rundll32.exe "[%WINDOWS%]\ridmbshe.dll",Startup
- HKEY_USERS\S-1-5-21-301695669-2834429868-4039847928-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hjuzik=rundll32.exe "[%WINDOWS%]\ridmbshe.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Syikafe=rundll32.exe "[%WINDOWS%]\msufxy.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tpamanapi=rundll32.exe "[%WINDOWS%]\utiramiyaparo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Syikafe=rundll32.exe "[%WINDOWS%]\msufxy.dll",Startup
- HKEY_USERS\S-1-5-21-1935655697-790525478-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Syikafe=rundll32.exe "[%WINDOWS%]\msufxy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xxinexejiva=rundll32.exe "[%WINDOWS%]\sntbdhA.dll",Startup
- HKEY_USERS\S-1-5-21-2025429265-515967899-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xxinexejiva=rundll32.exe "[%WINDOWS%]\sntbdhA.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,gFayVlc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpnklaudio=rundll32.exe "efcayx.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxwwwsys=rundll32.exe "hgddbb.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvtsqaudio=rundll32.exe "efcayx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khefgdsys=rundll32.exe "hgddbb.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabxvwaudio=rundll32.exe "efcayx.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khefgdsys=rundll32.exe "hgddbb.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabxvwaudio=rundll32.exe "efcayx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ynujivebaxit=rundll32.exe "[%WINDOWS%]\mcdmsfu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhdk32.rom,GCLDiy
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winguc32.rom,KtOlskHTiDs
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Anelepa=rundll32.exe "[%WINDOWS%]\inolijosifa.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ovunohawurovi=rundll32.exe "[%WINDOWS%]\ut3diap.dll",Startup
- HKEY_USERS\S-1-5-21-2052111302-838170752-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ovunohawurovi=rundll32.exe "[%WINDOWS%]\ut3diap.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljigdeaudio=rundll32.exe "ssrpqp.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrollaudio=rundll32.exe "ssrpqp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdawxaudio=rundll32.exe "ssrpqp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdawxaudio=rundll32.exe "ssrpqp.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nconovuni=rundll32.exe "[%WINDOWS%]\dshaclgr.dll",Startup
- HKEY_USERS\S-1-5-21-507921405-963894560-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nconovuni=rundll32.exe "[%WINDOWS%]\dshaclgr.dll",Startup
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fekozajado=Rundll32.exe "[%SYSTEM%]\pukufaje.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fekozajado=Rundll32.exe "[%SYSTEM%]\pukufaje.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnxv32.rom,VFXHhKmfDU
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjak32.rom,TKhidFRteSI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxnz32.rom,ROBxHZwOP
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vqekiqeniw=rundll32.exe "[%WINDOWS%]\nvibexl.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gvoyuloruzi=rundll32.exe "[%WINDOWS%]\eqokicuhuhoneni.dll",Startup
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnopqraudio=rundll32.exe "ssrpqp.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnopqraudio=rundll32.exe "ssrpqp.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rcukowilojihume=rundll32.exe "[%WINDOWS%]\ixotucig.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywwwwaudio=rundll32.exe "rqpnnm.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxvtusys=rundll32.exe "awwvwu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmkigaudio=rundll32.exe "rqpnnm.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opolljsys=rundll32.exe "awwvwu.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywvvuaudio=rundll32.exe "rqpnnm.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opolljsys=rundll32.exe "awwvwu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywvvuaudio=rundll32.exe "rqpnnm.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,ROBxHZwOP
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {634bbab7-3f60-4426-944f-a62b9007f67f}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sxuxene=rundll32.exe "[%LOCAL_APPDATA%]\umeqiqam.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winckn32.rom,JYuFKL
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingkc32.rom,bqBRhjECn
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlvh32.rom,LybqLExWHm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,TuYpnAIiAWk
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tboxuc=rundll32.exe "[%WINDOWS%]\onoxelayotevok.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fjasuwus=rundll32.exe "[%WINDOWS%]\kcavcan.dll",Startup
- HKEY_USERS\S-1-5-21-3939154532-148459787-1506545217-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fjasuwus=rundll32.exe "[%WINDOWS%]\kcavcan.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlmj32.rom,XkQEMEP
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tguhabocukalibik=rundll32.exe "[%LOCAL_APPDATA%]\oweganid.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cgalukur=rundll32.exe "[%WINDOWS%]\exoqaguvimupa.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Svoluzifulo=rundll32.exe "[%WINDOWS%]\ofodamujumuqobo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ekapezenocopo=rundll32.exe "[%WINDOWS%]\MPoineD.dll",Startup
- HKEY_USERS\S-1-5-21-2936693403-1194930031-223751899-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ekapezenocopo=rundll32.exe "[%WINDOWS%]\MPoineD.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winggf32.rom,XMzVpFdK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMdf0a8fdf=Rundll32.exe "[%COMMON_APPDATA%]\jolefayu\jolefayu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dc39bc43=rundll32.exe "[%COMMON_APPDATA%]\zolekare\zolekare.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bovivibeva=Rundll32.exe "[%COMMON_APPDATA%]\tajelavo\tajelavo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MS Juan=rundll32 "[%PROFILE_TEMP%]\sqjzqb.dll",run
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,xeUpuhksb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhdk32.rom,QLJgYUsMa
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, negezamod=Rundll32.exe "[%SYSTEM%]\yubihimo.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjak32.rom,qdeuvlAooG
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ycowagi=rundll32.exe "[%LOCAL_APPDATA%]\NMSplp35.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Eyurovesebeva=rundll32.exe "[%LOCAL_APPDATA%]\iboquyicub.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dqubi=rundll32.exe "[%WINDOWS%]\wcoxtwmt.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windco32.rom,troZjvb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tmuki=rundll32.exe "[%WINDOWS%]\esclepi.dll",Startup
- HKEY_USERS\S-1-5-21-2221179514-1974565712-2106517767-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tmuki=rundll32.exe "[%WINDOWS%]\esclepi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,EQdZjNNpi
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windgj32.rom,daEGKqYT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winggf32.rom,YmWcazLpq
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineoy32.rom,RmBOFMbT
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,ORiYTWCfcM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnxv32.rom,LybqLExWHm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjef32.rom,uDLCUfabUaMA
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jnelide=rundll32.exe "[%LOCAL_APPDATA%]\otibesid.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bmoyu=rundll32.exe "[%LOCAL_APPDATA%]\pintexyn.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {c7bbc1fa-e415-4926-9a47-9ab58d0b3bc8}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vozuduwor=Rundll32.exe "[%SYSTEM%]\wejeduwa.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrj32.rom,qsBKtjqQy
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qquqeciyozoxujes=rundll32.exe "[%WINDOWS%]\p32cenp.dll",Startup
- HKEY_USERS\S-1-5-21-1644491937-789336058-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qquqeciyozoxujes=rundll32.exe "[%WINDOWS%]\p32cenp.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhww32.rom,xnPKjui
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lzusidohugili=rundll32.exe "[%WINDOWS%]\owapuwido.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rqoladi=rundll32.exe "[%WINDOWS%]\semcar.dll",Startup
- HKEY_USERS\S-1-5-21-1078081533-1979792683-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rqoladi=rundll32.exe "[%WINDOWS%]\semcar.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vmufiyovoxan=rundll32.exe "[%LOCAL_APPDATA%]\icemebop.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,ZDjJFAq
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F12DCEB.exe=[%PROFILE_TEMP%]\_A00F12DCEB.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winojm32.rom,hRCUWgKmBan
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjrj32.rom,QdJRcQGhQdw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgz32.rom,EqkAIB
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,JMjNcdkb
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hdopafuzawosafu=rundll32.exe "[%WINDOWS%]\abumenipavu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uxagimiba=rundll32.exe "[%WINDOWS%]\hkbjgt.dll",Startup
- HKEY_USERS\S-1-5-21-839522115-287218729-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uxagimiba=rundll32.exe "[%WINDOWS%]\hkbjgt.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxnz32.rom,sLAgfHC
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnfi32.rom,kGSoMcpFtc
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3BE4D3.exe=[%PROFILE_TEMP%]\_A00F3BE4D3.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F8A3374.exe=[%PROFILE_TEMP%]\_A00F8A3374.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxtq32.rom,QLJgYUsMa
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbxuvdrv=rundll32.exe "ssrrsq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkihidrv=rundll32.exe "ssrrsq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkhiidrv=rundll32.exe "tusqrs.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomkldrv=rundll32.exe "ssrrsq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifeffdrv=rundll32.exe "tusqrs.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomkldrv=rundll32.exe "ssrrsq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifeffdrv=rundll32.exe "tusqrs.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxuvtsys=rundll32.exe "gebyab.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgfeesys=rundll32.exe "gebyab.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgfeesys=rundll32.exe "gebyab.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, edcsjh=RUNDLL32.EXE [%PROFILE_TEMP%]\msgvbtjn.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiqk32.rom,pJFbnFpfmqO
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winmdb32.rom,enNOHslWFR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxru32.rom,VkqqZemsC
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfit32.rom,LkGvafylW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dcaguhasaj=rundll32.exe "[%WINDOWS%]\ovubiduk.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrdz32.rom,mHGiVw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winplk32.rom,WFGiQPH
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vkesafiqema=rundll32.exe "[%LOCAL_APPDATA%]\agoxevuq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiot32.rom,EQpIfJhJQV
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Ndajijokiq=rundll32.exe "[%WINDOWS%]\etolobomagifinos.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, f4114a8f=rundll32.exe "[%PROFILE_TEMP%]\aunmqbop.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\ddcYpNEv.dll,c
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Atuzacanuveruqap=rundll32.exe "[%WINDOWS%]\picexbch.dll",Startup
- HKEY_USERS\S-1-5-21-1039474938-394416222-939856875-3221\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Atuzacanuveruqap=rundll32.exe "[%WINDOWS%]\picexbch.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Iyoxizodu=rundll32.exe "[%WINDOWS%]\ofalulin.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tsasefifizosowu=rundll32.exe "[%LOCAL_APPDATA%]\ehiqiyalo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tsasefifizosowu=rundll32.exe "[%LOCAL_APPDATA%]\ehiqiyalo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8e509ef7-6209-4a5c-a145-22f514f51c4f}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nowukadopi=Rundll32.exe "ledanozo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fnakamep=rundll32.exe "[%WINDOWS%]\iwixeyaki.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wgoqabafojocetu=rundll32.exe "[%WINDOWS%]\ufodohaqitej.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qaqmyc=RUNDLL32.EXE [%PROFILE_TEMP%]\mskdlpso.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ojisulene=rundll32.exe "[%WINDOWS%]\uyenilec.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fyirilapeyamole=rundll32.exe "[%WINDOWS%]\msrfin.dll",Startup
- HKEY_USERS\S-1-5-21-3039274163-1768848045-4065000510-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fyirilapeyamole=rundll32.exe "[%WINDOWS%]\msrfin.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrps32.rom,waQGfjbA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpgg32.rom,jfaQJIG
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhdk32.rom,EqkAIB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hudawabuj=Rundll32.exe "[%SYSTEM%]\sisazibo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c9813f79-5b8c-4f84-a866-da6d87ab257e}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kifujetan={c9813f79-5b8c-4f84-a866-da6d87ab257e}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Udupu=rundll32.exe "[%WINDOWS%]\ntrpsja.dll",Startup
- HKEY_USERS\S-1-5-21-1085031214-507921405-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Udupu=rundll32.exe "[%WINDOWS%]\ntrpsja.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iwjpqr=RUNDLL32.EXE [%PROFILE_TEMP%]\msreaayl.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Obareneq=rundll32.exe "[%LOCAL_APPDATA%]\ocexacodeneq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wfexifinohazoz=rundll32.exe "[%LOCAL_APPDATA%]\odasLedg.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqez32.rom,uUebwhP
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnxv32.rom,eQMOsGCbA
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rirawapola=Rundll32.exe "[%SYSTEM%]\vetahadu.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rirawapola=Rundll32.exe "[%SYSTEM%]\vetahadu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cxibizagova=rundll32.exe "[%WINDOWS%]\ewahediq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfazi=rundll32.exe "[%WINDOWS%]\msp9401.dll",Startup
- HKEY_USERS\S-1-5-21-3469138192-473331470-559204528-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfazi=rundll32.exe "[%WINDOWS%]\msp9401.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,VBVojUPTS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {b62b5ce6-a4bf-428d-8a21-47ee1bd90eac}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Egelocuka=rundll32.exe "[%WINDOWS%]\senedmag.dll",Startup
- HKEY_USERS\S-1-5-21-1409082233-796845957-1614895754-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Egelocuka=rundll32.exe "[%WINDOWS%]\senedmag.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, munikizay=Rundll32.exe "[%SYSTEM%]\mekawiba.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mijusirozu=Rundll32.exe "mikolobe.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c99e5562-6075-48a1-b85c-c483c4fe975b}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sazibakiv={c99e5562-6075-48a1-b85c-c483c4fe975b}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrjf32.rom,PsFrwdvxVmn
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhwb32.rom,wJqEXIspK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nbupupijaferoc=rundll32.exe "[%WINDOWS%]\ksprlbdp.dll",Startup
- HKEY_USERS\S-1-5-21-1123561945-179605362-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nbupupijaferoc=rundll32.exe "[%WINDOWS%]\ksprlbdp.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khihiiaudio=rundll32.exe "opoopn.dll",s
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
