Top 10 Alerts
Latest 10 Malware Files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkigesys=rundll32.exe "khgdcb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstutrsys=rundll32.exe "khgdcb.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssronkaudio=rundll32.exe "hgdayy.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnnmlsys=rundll32.exe "khgdcb.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssronkaudio=rundll32.exe "hgdayy.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmnnmlsys=rundll32.exe "khgdcb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lxapovotuketo=rundll32.exe "[%WINDOWS%]\omcmsE.dll",Startup
- HKEY_USERS\S-1-5-21-1060284298-329068152-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lxapovotuketo=rundll32.exe "[%WINDOWS%]\omcmsE.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winugy32.rom,BMZXJSHQcwT
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mduguzubizebuf=rundll32.exe "[%WINDOWS%]\ezevozujit.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kpajaned=rundll32.exe "[%WINDOWS%]\dfcleg.dll",Startup
- HKEY_USERS\S-1-5-21-459401176-2798812695-4279474606-15695\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kpajaned=rundll32.exe "[%WINDOWS%]\dfcleg.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwes32.rom,TWmCzhFjnzCW
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwutqdrv=rundll32.exe "ljihgh.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopnmldrv=rundll32.exe "ljihgh.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifdbadrv=rundll32.exe "ljihgh.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wmunatanab=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\ihotikapaw.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yrijeqovuzit=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\clecrc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvfe32.rom,ujkIOvc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbrv32.rom,eonLdA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttrpmaudio=rundll32.exe "ursroo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkifgaudio=rundll32.exe "ursroo.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awttuvaudio=rundll32.exe "ursroo.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awttuvaudio=rundll32.exe "ursroo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pfadiwita=rundll32.exe "[%WINDOWS%]\wrsnplu.dll",Startup
- HKEY_USERS\S-1-5-21-2707063869-3300816373-2783891446-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pfadiwita=rundll32.exe "[%WINDOWS%]\wrsnplu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnkp32.rom,fOkCVnEE
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttturaudio=rundll32.exe "qonkii.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmllkjsys=rundll32.exe "yababx.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gebcyaaudio=rundll32.exe "qonkii.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyvspsys=rundll32.exe "yababx.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrommaudio=rundll32.exe "qonkii.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyvspsys=rundll32.exe "yababx.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrommaudio=rundll32.exe "qonkii.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dleqiqoref=rundll32.exe "[%LOCAL_APPDATA%]\wexfial.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\tuVomKDW.dll,#1
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyxxwaudio=rundll32.exe "pmnnki.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyxxwaudio=rundll32.exe "pmnnki.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lfega=rundll32.exe "[%WINDOWS%]\papxSDOG.dll",Startup
- HKEY_USERS\S-1-5-21-3416330673-3783517216-2495140351-1139\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lfega=rundll32.exe "[%WINDOWS%]\papxSDOG.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winscb32.rom,bGtMKVIYvQ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windju32.rom,ODgSQaAhKry
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Epupodegex=rundll32.exe "[%WINDOWS%]\kbarerou.dll",Startup
- HKEY_USERS\S-1-5-21-854245398-362288127-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Epupodegex=rundll32.exe "[%WINDOWS%]\kbarerou.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sdihidimenip=rundll32.exe "[%WINDOWS%]\uyosunuf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Htepuzojazijuluc=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\ohafisequp.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mvolud=rundll32.exe "[%WINDOWS%]\ajugumam.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yxanejaqapejucoh=rundll32.exe "[%WINDOWS%]\inayotevokomas.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qpalicericoxepo=rundll32.exe "[%LOCAL_APPDATA%]\ocobikeh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvfe32.rom,CCTHjWqKfNe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dwupowemowemow=rundll32.exe "[%WINDOWS%]\ugadanapiqifep.dll",Startup
- HKEY_USERS\S-1-5-21-1465643607-4287726430-2285093250-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sbuciran=rundll32.exe "[%WINDOWS%]\mpsewi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sbuciran=rundll32.exe "[%WINDOWS%]\mpsewi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ijanorunifusi=rundll32.exe "[%LOCAL_APPDATA%]\eyanawifukine.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sgokohe=rundll32.exe "[%LOCAL_APPDATA%]\KBDUQSW0.dll",Startup
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jujebotuba=Rundll32.exe "[%SYSTEM%]\geratuna.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jujebotuba=Rundll32.exe "[%SYSTEM%]\geratuna.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddbaxaudio=rundll32.exe "rqrono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtutrpsys=rundll32.exe "hgdcby.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgggdeaudio=rundll32.exe "rqrono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywuutsys=rundll32.exe "hgdcby.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywuutsys=rundll32.exe "hgdcby.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fcapomopa=rundll32.exe "[%WINDOWS%]\utoneravasamoqix.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nwimoducexu=rundll32.exe "[%WINDOWS%]\dcCECM14.dll",Startup
- HKEY_USERS\S-1-5-21-1417001333-57989841-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nwimoducexu=rundll32.exe "[%WINDOWS%]\dcCECM14.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winszd32.rom,TvOZrDMx
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winipx32.rom,OmiKGFNWg
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tpafifa=rundll32.exe "[%LOCAL_APPDATA%]\KBDWMR1.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qwekufero=rundll32.exe "[%LOCAL_APPDATA%]\ufudokake.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrps32.rom,XcMBGRyme
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,VTjNrwiiYcwD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbgo32.rom,NGnjUvieQ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urpnljdrv=rundll32.exe "qommnn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggggfdrv=rundll32.exe "qommnn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggggfdrv=rundll32.exe "qommnn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmjjhsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kheffdsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kheffdsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlifdcdrv=rundll32.exe "vturst.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khifggdrv=rundll32.exe "vturst.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaayxydrv=rundll32.exe "efcbyw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiifgfdrv=rundll32.exe "efcbyw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiifgfdrv=rundll32.exe "efcbyw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddefgsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khebyysys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khebyysys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopomndrv=rundll32.exe "cbyvtq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtqrqdrv=rundll32.exe "cbyvtq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomnndrv=rundll32.exe "vturst.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifcyvdrv=rundll32.exe "vturst.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssqnlldrv=rundll32.exe "vturst.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssqnlldrv=rundll32.exe "vturst.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutsrpsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddawtsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddawtsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtqondrv=rundll32.exe "qommnn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwuvwdrv=rundll32.exe "ssqpnk.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjdi32.rom,TGZXiVlIdCv
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, MSSMSGS=rundll32.exe winqzb32.rom,OmiKGFNWg
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qludedomigivaj=rundll32.exe "[%WINDOWS%]\arezogerutewotev.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qqivisuzoger=rundll32.exe "[%WINDOWS%]\wprent.dll",Startup
- HKEY_USERS\S-1-5-21-232049420-2715605573-1663702737-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qqivisuzoger=rundll32.exe "[%WINDOWS%]\wprent.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hxeqevatepinu=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\nswotwcn.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Frahaborovomasi=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\ulegefimifet.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhlt32.rom,rhmZbKGpvYZK
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, givojelozo=Rundll32.exe "[%SYSTEM%]\wabodezi.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, givojelozo=Rundll32.exe "[%SYSTEM%]\wabodezi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kwuvodowurafox=rundll32.exe "[%WINDOWS%]\mlgnet.dll",Startup
- HKEY_USERS\S-1-5-21-1757981266-725345543-1637202325-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kwuvodowurafox=rundll32.exe "[%WINDOWS%]\mlgnet.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hjosen=rundll32.exe "[%LOCAL_APPDATA%]\KBDHLe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nowukadopi=Rundll32.exe "ledanozo.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nowukadopi=Rundll32.exe "ledanozo.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nowukadopi=Rundll32.exe "ledanozo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bfatovuviyakid=rundll32.exe "[%LOCAL_APPDATA%]\irusitef.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwss32.rom,xlOQsejvywjJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoej32.rom,ZKHgpHAOGX
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoej32.rom,yCrirmIsp
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfibaxacumiru=rundll32.exe "[%WINDOWS%]\aqojiliquweju.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cmiyoxulodi=rundll32.exe "[%WINDOWS%]\kacrias.dll",Startup
- HKEY_USERS\S-1-5-21-3087532821-3387410904-378839110-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cmiyoxulodi=rundll32.exe "[%WINDOWS%]\kacrias.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ktiwaqaw=rundll32.exe "[%WINDOWS%]\ojirihesogol.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kqexiq=rundll32.exe "[%WINDOWS%]\sesfx2.dll",Startup
- HKEY_USERS\S-1-5-21-3448109982-3972192288-339976334-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kqexiq=rundll32.exe "[%WINDOWS%]\sesfx2.dll",Startup
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs=[%SYSTEM%]\nijufagi.dll [%SYSTEM%]\duweweba.dll [%SYSTEM%]\laroriwa.dll [%SYSTEM%]\rumerubo.dll [%SYSTEM%]\benugame.dll [%SYSTEM%]\bajibuli.dll [%SYSTEM%]\kumiberu.dll [%SYSTEM%]\vufeguja.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dimadavigi=Rundll32.exe "[%SYSTEM%]\hohazevu.dll",s
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dimadavigi=Rundll32.exe "[%SYSTEM%]\hohazevu.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dimadavigi=Rundll32.exe "[%SYSTEM%]\hohazevu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dwujoqan=rundll32.exe "[%LOCAL_APPDATA%]\evoxitig.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rzagus=rundll32.exe "[%LOCAL_APPDATA%]\WMidp2g.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\tuvSjGAp.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\nnnnKcCu.dll,c
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvct32.rom,pJFbnFpfmqO
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiigdbsys=rundll32.exe "pmklih.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxvvvsaudio=rundll32.exe "awwuts.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvtuvvsys=rundll32.exe "pmklih.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddddedaudio=rundll32.exe "awwuts.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khebbasys=rundll32.exe "rqomjh.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopmljsys=rundll32.exe "pmklih.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxwxxaudio=rundll32.exe "awwuts.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopmljsys=rundll32.exe "pmklih.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxwxxaudio=rundll32.exe "awwuts.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pfafaxovab=rundll32.exe "[%WINDOWS%]\ibacedul.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gzelimayobiquyep=rundll32.exe "[%WINDOWS%]\cdhexc.dll",Startup
- HKEY_USERS\S-1-5-21-1063470676-1961264711-1616861783-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gzelimayobiquyep=rundll32.exe "[%WINDOWS%]\cdhexc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrta32.rom,TKhidFRteSI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tbawasuxom=rundll32.exe "[%LOCAL_APPDATA%]\ucixodemadav.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tfakecahexofipuj=rundll32.exe "[%LOCAL_APPDATA%]\W71095.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxfp32.rom,kiLwzwxl
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrnp32.rom,UXhkJP
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winiot32.rom,KLcKAM
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winckn32.rom,nalzjHoJm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdedcdrv=rundll32.exe "qommnn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opolmjdrv=rundll32.exe "opqono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutttrdrv=rundll32.exe "opqono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkkkkdrv=rundll32.exe "qommnn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssroondrv=rundll32.exe "qommnn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awuvvvdrv=rundll32.exe "qommnn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awuvvvdrv=rundll32.exe "qommnn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstrpnsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdawvsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdawvsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifdccdrv=rundll32.exe "dddded.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmkjjkdrv=rundll32.exe "dddded.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaxxusdrv=rundll32.exe "opqono.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgddawdrv=rundll32.exe "opqono.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgddawdrv=rundll32.exe "opqono.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttspnsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgedbsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khgedbsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxuvtdrv=rundll32.exe "rqrpop.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkijgdrv=rundll32.exe "rqrpop.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbyvvdrv=rundll32.exe "dddded.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuspoldrv=rundll32.exe "dddded.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuspoldrv=rundll32.exe "dddded.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwwussys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geebbxsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, geebbxsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopqrodrv=rundll32.exe "efcbyw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlmmkdrv=rundll32.exe "efcbyw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwwvvdrv=rundll32.exe "rqrpop.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcbbydrv=rundll32.exe "efcbyw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedcyvdrv=rundll32.exe "rqrpop.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcbbydrv=rundll32.exe "efcbyw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedcyvdrv=rundll32.exe "rqrpop.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvwttrsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqrspqsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqrspqsys=rundll32.exe "cbbbbb.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkheeaudio=rundll32.exe "geefcb.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljggedsys=rundll32.exe "ssqqqq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dddedbaudio=rundll32.exe "geefcb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlmkjaudio=rundll32.exe "khgddc.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssqnnnsys=rundll32.exe "ssqqqq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutusraudio=rundll32.exe "geefcb.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssqnnnsys=rundll32.exe "ssqqqq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutusraudio=rundll32.exe "geefcb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqre32.rom,BwQzDA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpan32.rom,JMjNcdkb
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winydu32.rom,rzPRhtDKc
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpbm32.rom,VFimFLGUzF
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xperehap=rundll32.exe "[%WINDOWS%]\aruhateh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lyowob=rundll32.exe "[%WINDOWS%]\avodieth.dll",Startup
- HKEY_USERS\S-1-5-21-1338366378-3709785567-2748637376-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lyowob=rundll32.exe "[%WINDOWS%]\avodieth.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrstuaudio=rundll32.exe "ursqqn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwvstaudio=rundll32.exe "ursqqn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sstsrrsys=rundll32.exe "pmljhg.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrrpoaudio=rundll32.exe "ursqqn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxxxusys=rundll32.exe "pmljhg.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrrpoaudio=rundll32.exe "ursqqn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxxxusys=rundll32.exe "pmljhg.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjdi32.rom,jCBOuCoHVJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpzc32.rom,KqshFUVAv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sdihidimenip=rundll32.exe "[%WINDOWS%]\iveqeviw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winckn32.rom,XtAoYJS
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfcb32.rom,UdEbeKDequx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxoyudocay=rundll32.exe "[%LOCAL_APPDATA%]\iyohacafofoceqoz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xvovedidakip=rundll32.exe "[%LOCAL_APPDATA%]\cpscmi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qronasevegu=rundll32.exe "[%LOCAL_APPDATA%]\KBDasif.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fbijufaveler=rundll32.exe "[%LOCAL_APPDATA%]\otaritul.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlik32.rom,bGtMKVIYvQ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnfi32.rom,YxweBJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqre32.rom,peVeZvfcRDz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpan32.rom,AJTcPsaHAOl
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kgoyiyawev=rundll32.exe "[%WINDOWS%]\edaruvup.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Acosusuyanamisun=rundll32.exe "[%WINDOWS%]\ducthe.dll",Startup
- HKEY_USERS\S-1-5-21-448539723-1500820517-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Acosusuyanamisun=rundll32.exe "[%WINDOWS%]\ducthe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mjequbixaxa=rundll32.exe "[%LOCAL_APPDATA%]\ihilayiz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wkutuvuho=rundll32.exe "[%LOCAL_APPDATA%]\SnTosgc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqxv32.rom,lVoueC
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mcinekiqaqo=rundll32.exe "[%WINDOWS%]\ovejonafazeqeq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fvagu=rundll32.exe "[%WINDOWS%]\mfisar.dll",Startup
- HKEY_USERS\S-1-5-21-1409082233-602162358-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fvagu=rundll32.exe "[%WINDOWS%]\mfisar.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hlejeg=rundll32.exe "[%WINDOWS%]\ojewowohon.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Akovogoyineb=rundll32.exe "[%WINDOWS%]\wrdxmtsh.dll",Startup
- HKEY_USERS\S-1-5-21-2938437012-3181124353-3250006542-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Akovogoyineb=rundll32.exe "[%WINDOWS%]\wrdxmtsh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fxemuxiqivoqu=rundll32.exe "[%LOCAL_APPDATA%]\hfsedins.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrrrqdrv=rundll32.exe "jkhhef.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byyvttdrv=rundll32.exe "jkhhef.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggdawdrv=rundll32.exe "jkhhef.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggdawdrv=rundll32.exe "jkhhef.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrolmsys=rundll32.exe "jkhhii.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcyvssys=rundll32.exe "jkhhii.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcyvssys=rundll32.exe "jkhhii.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxtq32.rom,mvRfxc
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wvabotib=rundll32.exe "[%WINDOWS%]\ibimesawegume.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xxuloviqohuwu=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\uyazogaz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xxuloviqohuwu=rundll32.exe "[%LOCAL_APPDATA%]\oculakizaxifivuf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Txihepijovapupi=rundll32.exe "[%LOCAL_APPDATA%]\dmsrols.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xcuwurowovoxa=rundll32.exe "[%LOCAL_APPDATA%]\WMTRONDU.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwes32.rom,JYKXJS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Frajavucuya=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\irubetog.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwss32.rom,ObSuZVC
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbiy32.rom,KqshFUVAv
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fxaqetofiwupucu=rundll32.exe "[%WINDOWS%]\sche32rx.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uzefafewoqan=rundll32.exe "[%WINDOWS%]\dmesva.dll",Startup
- HKEY_USERS\S-1-5-21-1482476501-1177238915-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uzefafewoqan=rundll32.exe "[%WINDOWS%]\dmesva.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqdd32.rom,WyouufIruxGe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhmp32.rom,dOwCDj
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Aduzohe=rundll32.exe "[%WINDOWS%]\exokuwupomukimu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xyajuvili=rundll32.exe "[%WINDOWS%]\dsioens.dll",Startup
- HKEY_USERS\S-1-5-21-742135367-2609228642-3039254828-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xyajuvili=rundll32.exe "[%WINDOWS%]\dsioens.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoye32.rom,pDdQcrV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhjn32.rom,feNKQf
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, sstsqpsys=rundll32.exe "mlkhfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, pmkkijaudio=rundll32.exe "pmnmnn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, jkkkigaudio=rundll32.exe "khggge.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, oponlmaudio=rundll32.exe "khijjj.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, gebcyxsys=rundll32.exe "mlkhfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, nnmllmaudio=rundll32.exe "pmnmnn.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, rqpponaudio=rundll32.exe "khggge.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkiifsys=rundll32.exe "mlkhfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqolkiaudio=rundll32.exe "khijjj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxyyvaudio=rundll32.exe "khijjj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomlllaudio=rundll32.exe "khggge.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpnkjsys=rundll32.exe "mlkhfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxyyvaudio=rundll32.exe "khijjj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomlllaudio=rundll32.exe "khggge.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpnkjsys=rundll32.exe "mlkhfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpopoaudio=rundll32.exe "khijjj.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdecysys=rundll32.exe "mlkhfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmkkhisys=rundll32.exe "mlkhfe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqrppmaudio=rundll32.exe "khijjj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byywwxaudio=rundll32.exe "khijjj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutrrqsys=rundll32.exe "mlkhfe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byywwxaudio=rundll32.exe "khijjj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutrrqsys=rundll32.exe "mlkhfe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tgalego=rundll32.exe "[%WINDOWS%]\nvcrdsg.dll",Startup
- HKEY_USERS\S-1-5-21-1644491937-1292428093-682003330-1135\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tgalego=rundll32.exe "[%WINDOWS%]\nvcrdsg.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhi32.rom,HYQgtU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Plamehavaq=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\esiqujar.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnomljaudio=rundll32.exe "nnmjjg.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggfghsys=rundll32.exe "ljklkl.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tusrqnaudio=rundll32.exe "nnmjjg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedaaasys=rundll32.exe "ljklkl.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrrrpsys=rundll32.exe "ljklkl.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjgheaudio=rundll32.exe "nnmjjg.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrrrpsys=rundll32.exe "ljklkl.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkjgheaudio=rundll32.exe "nnmjjg.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincir32.rom,YRlamUtCp
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, Windows Printing Driver=WinSpooler.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run, WinUpdating=WinUpdating.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, a899bf4a=rundll32.exe "[%SYSTEM%]\qfedgnhk.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BMabaa8cd6=Rundll32.exe "[%SYSTEM%]\itfxpxyd.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, MSSMSGS=rundll32.exe winbtn32.rom,KRkQmMEI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrzy32.rom,ujaIGGigbqQj
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fccccaaudio=rundll32.exe "qonmjj.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabyaxaudio=rundll32.exe "qonmjj.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iifdayaudio=rundll32.exe "hgfgec.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bywvvwaudio=rundll32.exe "hgfgec.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssturoaudio=rundll32.exe "qonmjj.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomnnnaudio=rundll32.exe "hgfgec.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssturoaudio=rundll32.exe "qonmjj.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomnnnaudio=rundll32.exe "hgfgec.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpqf32.rom,KRkQmMEI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kvaxakamodetako=rundll32.exe "[%LOCAL_APPDATA%]\winwior.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mxokekawepa=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\etibajog.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yhefu=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\wiclcp.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ugagigokidonot=rundll32.exe "[%LOCAL_APPDATA%]\anekipipa.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vkirujuqodih=rundll32.exe "[%LOCAL_APPDATA%]\sDHatal.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnuj32.rom,otJDPjbOnYFp
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nvorejivul=rundll32.exe "[%WINDOWS%]\qui3ap7.dll",Startup
- HKEY_USERS\S-1-5-21-3968456070-2797407979-577682692-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nvorejivul=rundll32.exe "[%WINDOWS%]\qui3ap7.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yjuxatariveham=rundll32.exe "[%WINDOWS%]\iwipavuro.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dheyomusigeg=rundll32.exe "[%WINDOWS%]\dvwimsi.dll",Startup
- HKEY_USERS\S-1-5-21-1927313440-2451444065-965443739-1110\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dheyomusigeg=rundll32.exe "[%WINDOWS%]\dvwimsi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gmoyi=rundll32.exe "[%LOCAL_APPDATA%]\epowoziqipuzim.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uxepalamuti=rundll32.exe "[%LOCAL_APPDATA%]\KBDKBDR.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gtecekamosar=rundll32.exe "[%LOCAL_APPDATA%]\ikicutic.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gtecekamosar=rundll32.exe "[%LOCAL_APPDATA%]\ikicutic.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rkoqahazuyoseg=rundll32.exe "[%LOCAL_APPDATA%]\KBDapc.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xjuzuzojazij=rundll32.exe "[%WINDOWS%]\eluhokonipuc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hvixez=rundll32.exe "[%WINDOWS%]\shipicl6.dll",Startup
- HKEY_USERS\S-1-5-21-2584030144-1363760427-4016519328-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hvixez=rundll32.exe "[%WINDOWS%]\shipicl6.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winssh32.rom,fzsgzc
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Pvagi=rundll32.exe "[%WINDOWS%]\ogenasowo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bwujewigame=rundll32.exe "[%WINDOWS%]\csplthe.dll",Startup
- HKEY_USERS\S-1-5-21-448539723-1580818891-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bwujewigame=rundll32.exe "[%WINDOWS%]\csplthe.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,nDemmm
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tkekatehihehateh=rundll32.exe "[%LOCAL_APPDATA%]\umibewahaz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qlenequkivegoh=rundll32.exe "[%LOCAL_APPDATA%]\ic320101.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Stejofiv=rundll32.exe "[%WINDOWS%]\wintaums.dll",Startup
- HKEY_USERS\S-1-5-21-1060284298-602162358-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Stejofiv=rundll32.exe "[%WINDOWS%]\wintaums.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjst32.rom,bUvdrpKrDhNJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kmasibebax=rundll32.exe "[%LOCAL_APPDATA%]\ijayubader.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nbasevuq=rundll32.exe "[%LOCAL_APPDATA%]\icujatazalebinur.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hpanigihagonama=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\nd3201.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hpanigihagonama=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\nd3201.dll",Startup
- HKEY_USERS\S-1-5-21-1146402402-45027732-3669579969-1109\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hpanigihagonama=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\nd3201.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nrewekoco=rundll32.exe "[%LOCAL_APPDATA%]\osoxidet.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xlejire=rundll32.exe "[%LOCAL_APPDATA%]\hcodimpt.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,pAmcCBTNsHsV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winlrl32.rom,DpwZyRyCbQt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kbowapifovavo=rundll32.exe "[%WINDOWS%]\drpcfx.dll",Startup
- HKEY_USERS\S-1-5-21-1962901425-3920665240-435226128-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kbowapifovavo=rundll32.exe "[%WINDOWS%]\drpcfx.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Aziyeniqedukicuh=rundll32.exe "[%WINDOWS%]\ufudamujumu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ywiyij=rundll32.exe "[%WINDOWS%]\WMVXES.dll",Startup
- HKEY_USERS\S-1-5-21-585493820-4219992952-1779951637-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ywiyij=rundll32.exe "[%WINDOWS%]\WMVXES.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkklkjsys=rundll32.exe "ssrsqn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, effcdbaudio=rundll32.exe "[%PROFILE_TEMP%]\mliigd.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpqpqsys=rundll32.exe "ssrsqn.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkjgfsys=rundll32.exe "ssrsqn.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkjgfsys=rundll32.exe "ssrsqn.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jlewazayujupili=rundll32.exe "[%LOCAL_APPDATA%]\zerpetca.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qqawizewugowi=rundll32.exe "[%LOCAL_APPDATA%]\igusuyeg.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Htepuzojazijuluc=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\elibafid.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fpelibumer=rundll32.exe "[%WINDOWS%]\apawubixaxayug.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fred4=rundll32.exe "urstst.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awututsys=rundll32.exe "opomjg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonnnkaudio=rundll32.exe "urstst.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonmjisys=rundll32.exe "opomjg.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonmjisys=rundll32.exe "opomjg.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8710fc9f-0816-49d7-ae14-4ba5269e838c}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winddp32.rom,iAGSIR
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Txovimesumi=rundll32.exe "[%WINDOWS%]\hposns.dll",Startup
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaaaxydrv=rundll32.exe "fcyxut.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaaaxydrv=rundll32.exe "fcyxut.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iihiiisys=rundll32.exe "urpqqo.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iihiiisys=rundll32.exe "urpqqo.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwgk32.rom,QjKFuizgVnJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Obilar=rundll32.exe "[%LOCAL_APPDATA%]\avefuzaw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Oniliriyijik=rundll32.exe "[%LOCAL_APPDATA%]\KBDizr.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkeb32.rom,JMjNcdkb
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yvuxisunogewusu=rundll32.exe "[%WINDOWS%]\MShgmi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Stavejifigocix=rundll32.exe "[%LOCAL_APPDATA%]\eworisoh.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Slotoxagijobakez=rundll32.exe "[%LOCAL_APPDATA%]\netLeodl.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Etete=rundll32.exe "[%WINDOWS%]\adazuwip.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Evayirakipejoxi=rundll32.exe "[%WINDOWS%]\wribcl32.dll",Startup
- HKEY_USERS\S-1-5-21-1292428093-1085031214-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Evayirakipejoxi=rundll32.exe "[%WINDOWS%]\wribcl32.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 00000e5f=rundll32.exe "[%SYSTEM%]\pftqiuhf.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jpuje=rundll32.exe "[%WINDOWS%]\cz1tolnd.dll",Startup
- HKEY_USERS\S-1-5-21-790525478-1004336348-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jpuje=rundll32.exe "[%WINDOWS%]\cz1tolnd.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Pfiqeme=rundll32.exe "[%WINDOWS%]\olesolet.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxtq32.rom,RwQzXlLuTHfj
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gkilukukubub=rundll32.exe "[%WINDOWS%]\adigumajapim.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rwuzah=rundll32.exe "[%WINDOWS%]\msetrcas.dll",Startup
- HKEY_USERS\S-1-5-21-286864404-2726782864-5992633-1501\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rwuzah=rundll32.exe "[%WINDOWS%]\msetrcas.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cjewowayewecigit=rundll32.exe "[%WINDOWS%]\isemehig.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikiweqehexo=rundll32.exe "[%WINDOWS%]\solsaps.dll",Startup
- HKEY_USERS\S-1-5-21-1482079830-2570139838-1662533616-2817\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikiweqehexo=rundll32.exe "[%WINDOWS%]\solsaps.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wducicabaq=rundll32.exe "[%WINDOWS%]\ojovabowinewunoz.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Imoguresiqaquzuw=rundll32.exe "[%WINDOWS%]\st46gc.dll",Startup
- HKEY_USERS\S-1-5-21-2641315184-692297851-2266503997-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Imoguresiqaquzuw=rundll32.exe "[%WINDOWS%]\st46gc.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxwf32.rom,WeyTuIsZhDt
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Mzabitefesufiya=rundll32.exe "[%LOCAL_APPDATA%]\KBtletU.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vcipecah=rundll32.exe "[%WINDOWS%]\mshear.dll",Startup
- HKEY_USERS\S-1-5-21-2025429265-1645522239-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vcipecah=rundll32.exe "[%WINDOWS%]\mshear.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vbagitemeko=rundll32.exe "[%WINDOWS%]\amexerux.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kyavodizi=rundll32.exe "[%WINDOWS%]\robshec.dll",Startup
- HKEY_USERS\S-1-5-21-590485390-207161868-1971066577-109229\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kyavodizi=rundll32.exe "[%WINDOWS%]\robshec.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 188525e0=rundll32.exe "[%SYSTEM%]\ctmlvwas.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rmipejaqape=rundll32.exe "[%LOCAL_APPDATA%]\efamujumuqobo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qdafunajazeti=rundll32.exe "[%LOCAL_APPDATA%]\kbhirog.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rmipejaqape=rundll32.exe "[%LOCAL_APPDATA%]\efamujumuqobo.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,uskhqxjS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunAdvanced Uninstaller, sppobv=RUNDLL32.EXE [%SYSTEM%]\mskpwvmx.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbiy32.rom,pGeELWSNYh
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qopppqsys=rundll32.exe "vturpq.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gedbxxsys=rundll32.exe "vturpq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpmjisys=rundll32.exe "vturpq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rqpmjisys=rundll32.exe "vturpq.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xfebajiyuhax=rundll32.exe "[%LOCAL_APPDATA%]\awemeroko.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wgejamoxobuzog=rundll32.exe "[%LOCAL_APPDATA%]\mserai.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhhfddrv=rundll32.exe "tusron.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efdebcdrv=rundll32.exe "tusron.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincba32.rom,oZyhvPu
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jsigafugaho=rundll32.exe "[%WINDOWS%]\sacowsw.dll",Startup
- HKEY_USERS\S-1-5-21-507921405-448539723-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jsigafugaho=rundll32.exe "[%WINDOWS%]\sacowsw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbiy32.rom,bGtMKVIYvQ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsdk32.rom,deeyYhjykxjs
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sppobv=RUNDLL32.EXE [%SYSTEM%]\mskpwvmx.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winckn32.rom,hXiFouKxGz
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ucagiqurejada=rundll32.exe "[%LOCAL_APPDATA%]\osobigaxel.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ibasoletunuxafu=rundll32.exe "[%LOCAL_APPDATA%]\uits46.dll",Startup
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ihimagovag=rundll32.exe "[%WINDOWS%]\swuiench.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Iqidiqohuwud=rundll32.exe "[%WINDOWS%]\unedo6gr.dll",Startup
- HKEY_USERS\S-1-5-21-2603378715-54182933-2587047097-3727\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Iqidiqohuwud=rundll32.exe "[%WINDOWS%]\unedo6gr.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpan32.rom,KRkQmMEI
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,WJdxSARcbsHD
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Npoxu=rundll32.exe "[%WINDOWS%]\uwarazoh.dll",Startup
- HKEY_USERS\S-1-5-21-1855329561-874992332-184960113-4761\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nkusaduqiru=rundll32.exe "[%WINDOWS%]\iashtdl.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Utebunazilekoc=rundll32.exe "[%WINDOWS%]\wpsravj.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tkiwepasule=rundll32.exe "[%LOCAL_APPDATA%]\NlalsE2E.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winina32.rom,IQvrNgB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cjewowayewecigit=rundll32.exe "[%WINDOWS%]\asuxeqay.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxuv32.rom,lGcIEFJ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {27a82d47-9a2a-4b39-b4ec-792bbdfd03fa}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlijkaudio=rundll32.exe "[%PROFILE_TEMP%]\khebyy.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxywxusys=rundll32.exe "[%PROFILE_TEMP%]\gebxwx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winboy32.rom,EQpIfJhJQV
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxpa32.rom,GtcHjbdk
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, femokuhebo=Rundll32.exe "[%SYSTEM%]\begimepo.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, femokuhebo=Rundll32.exe "[%SYSTEM%]\begimepo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhgffaudio=rundll32.exe "cbxusq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmmnlaudio=rundll32.exe "cbxusq.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urppnksys=rundll32.exe "jkhhed.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmmmkaudio=rundll32.exe "cbxusq.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urppnksys=rundll32.exe "jkhhed.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnmmmkaudio=rundll32.exe "cbxusq.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qomkjgaudio=rundll32.exe "cbxusq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hggghiaudio=rundll32.exe "cbxusq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddawtrsys=rundll32.exe "jkhhed.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe windco32.rom,psddYlqzA
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Xtelu=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\dbshta.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ayoliyimevoc=rundll32.exe "[%WINDOWS%]\icesejad.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Aferusigeg=rundll32.exe "[%WINDOWS%]\mdbc32.dll",Startup
- HKEY_USERS\S-1-5-21-1756457629-3316092617-963565094-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Aferusigeg=rundll32.exe "[%WINDOWS%]\mdbc32.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ldulogocelozugec=rundll32.exe "[%WINDOWS%]\urajimonobap.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bkilagedey=rundll32.exe "[%WINDOWS%]\moli21Eq.dll",Startup
- HKEY_USERS\S-1-5-21-1715567821-113007714-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bkilagedey=rundll32.exe "[%WINDOWS%]\moli21Eq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwiz32.rom,XVdzyJ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbtn32.rom,NjHzIuqYIbhR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Dhuwubemojo=rundll32.exe "[%LOCAL_APPDATA%]\ozuqibiy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Sxoxepova=rundll32.exe "[%LOCAL_APPDATA%]\RAMUGUIR.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dhuwubemojo=rundll32.exe "[%LOCAL_APPDATA%]\ozuqibiy.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sxoxepova=rundll32.exe "[%LOCAL_APPDATA%]\RAMUGUIR.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincmm32.rom,psddYlqzA
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbyxxyaudio=rundll32.exe "[%PROFILE_TEMP%]\fcbbaw.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxtq32.rom,rxTqgw
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Usagelukigateku=rundll32.exe "[%WINDOWS%]\eceyulid.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ozejeririfejel=rundll32.exe "[%WINDOWS%]\ojegumaj.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xwehihutafuzacan=rundll32.exe "[%WINDOWS%]\wmonseT.dll",Startup
- HKEY_USERS\S-1-5-21-1275210071-484763869-1957994488-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xwehihutafuzacan=rundll32.exe "[%WINDOWS%]\wmonseT.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwrv32.rom,FMRUHu
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjak32.rom,QgEzWkRDE
- HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, welebewiyi=Rundll32.exe "[%SYSTEM%]\hilozepi.dll",s
- HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, welebewiyi=Rundll32.exe "[%SYSTEM%]\hilozepi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ocexefubem=rundll32.exe "[%WINDOWS%]\odajugaborovom.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fcafotezivanomo=rundll32.exe "[%LOCAL_APPDATA%]\ogifehoriqowaqi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lcigamewi=rundll32.exe "[%LOCAL_APPDATA%]\NTSNltpi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winulo32.rom,dzOmxxpBRrOb
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rpiqoludosayero=rundll32.exe "[%LOCAL_APPDATA%]\alamibol.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Awumuyaja=rundll32.exe "[%LOCAL_APPDATA%]\cstetal.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vzejudoca=rundll32.exe "[%WINDOWS%]\abegiqinicim.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uradol=rundll32.exe "[%LOCAL_APPDATA%]\urojuhiqijo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vqafuh=rundll32.exe "[%LOCAL_APPDATA%]\exaxebodamujumu.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jcewazeq=rundll32.exe "[%LOCAL_APPDATA%]\mstst9.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qyisediwihep=rundll32.exe "[%WINDOWS%]\lExtuin.dll",Startup
- HKEY_USERS\S-1-5-21-3969355068-488989653-2669547036-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qyisediwihep=rundll32.exe "[%WINDOWS%]\lExtuin.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkxs32.rom,hUrlyshpWHh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwvy32.rom,zNltaCCJHbhw
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhxc32.rom,NzFhMnF
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
