Top 10 virus alerts
Latest 10 malware files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyawxdrv=rundll32.exe "byvwus.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ssrromdrv=rundll32.exe "tuspol.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyawxdrv=rundll32.exe "byvwus.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iihfdbsys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tusqpmsys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tusqpmsys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winddp32.rom,EJVYWJju
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjak32.rom,pTlJTxf
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ntuqiquwejulatiw=rundll32.exe "[%WINDOWS%]\imugopep.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kesewujune=Rundll32.exe "[%SYSTEM%]\kogetagi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqez32.rom,CgjEiCN
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wvvtsqdrv=rundll32.exe "opmnkj.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, byvvurdrv=rundll32.exe "opmnkj.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awwxvtdrv=rundll32.exe "yabcab.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmkllmdrv=rundll32.exe "yabcab.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pmlmljdrv=rundll32.exe "efcaxx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, oponljdrv=rundll32.exe "efcaxx.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqre32.rom,EJVYWJju
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nzazawebew=rundll32.exe "[%WINDOWS%]\osapupik.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bnawo=rundll32.exe "[%WINDOWS%]\awuhuqerofiboqa.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Okaxugawop=rundll32.exe "[%WINDOWS%]\azowexuluqizev.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\gupureje.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {b4ae9134-fbb6-484a-89bb-b39c9ed47449}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {4e3e60f5-f691-475f-afba-cf9fcab47c15}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {77d3a5b4-cfd1-4046-8909-7cd99a68311f}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bboni=rundll32.exe "[%WINDOWS%]\uyonaqafotocedo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {c47a9554-195a-4769-9b13-04f15b450a39}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingsw32.rom,hILoqxTVwIQ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cqavep=rundll32.exe "[%WINDOWS%]\exorotegixiv.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fduguhoxajedecod=rundll32.exe "[%WINDOWS%]\ogeyewiducena.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, horubukajo=Rundll32.exe "lomehane.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, horubukajo=Rundll32.exe "lomehane.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, horubukajo=Rundll32.exe "lomehane.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, horubukajo=Rundll32.exe "lomehane.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tjawomi=rundll32.exe "[%WINDOWS%]\usuzuhifucize.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmmjjdrv=rundll32.exe "bywtqp.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddawvwdrv=rundll32.exe "bywtqp.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdbxudrv=rundll32.exe "geedbb.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkhedbdrv=rundll32.exe "geedbb.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmmjidrv=rundll32.exe "hggddd.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opmmjidrv=rundll32.exe "hggddd.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxyxvssys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkihfsys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ljkihfsys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opopqqdrv=rundll32.exe "xxyxvv.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awtstrdrv=rundll32.exe "xxyxvv.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, iiffcbdrv=rundll32.exe "bywtqp.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efffdbdrv=rundll32.exe "xxyxvv.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efffdbdrv=rundll32.exe "xxyxvv.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tuvuttsys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdecasys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdecasys=rundll32.exe "xxvvsr.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, manofasuj=Rundll32.exe "[%SYSTEM%]\tahiraga.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {217f277f-3252-4a42-b638-952662ef3bdf}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nopimidow={217f277f-3252-4a42-b638-952662ef3bdf}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sopevusam=Rundll32.exe "[%COMMON_APPDATA%]\wiwonahu\wiwonahu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hunupofubi=Rundll32.exe "[%COMMON_APPDATA%]\wadizulo\wadizulo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yipafurobe=Rundll32.exe "[%SYSTEM%]\lafokune.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lavarutet=Rundll32.exe "[%SYSTEM%]\jokigaju.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tzualwh=[%SYSTEM%]\duupvlc0.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tpu3l=[%SYSTEM%]\6uu6gg5.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\garazuha.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {837b45d6-bf85-457d-aabf-6d2e7815f791}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {10c08715-ad85-4fb5-bb96-a7f700ab2964}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vonarepina=Rundll32.exe "rutasaka.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hurituhuza=Rundll32.exe "yiheguku.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hurituhuza=Rundll32.exe "yiheguku.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hurituhuza=Rundll32.exe "yiheguku.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fuvuwaheh=Rundll32.exe "[%SYSTEM%]\sokoyeji.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, negeserube=Rundll32.exe "tuhenato.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyuvibog=Rundll32.exe "[%SYSTEM%]\juyobosu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyuvibog=Rundll32.exe "[%SYSTEM%]\juyobosu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ca510c1b-e164-43e5-94dc-02e9dac76278}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nenivisig={ca510c1b-e164-43e5-94dc-02e9dac76278}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ca510c1b-e164-43e5-94dc-02e9dac76278}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nasotigaz={ca510c1b-e164-43e5-94dc-02e9dac76278}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sifayihip=Rundll32.exe "[%SYSTEM%]\lehebofi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fmawubalikoq=rundll32.exe "[%WINDOWS%]\ejijinur.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfi32.rom,LQJImhEtYfn
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hfuzerofiboqa=rundll32.exe "[%WINDOWS%]\avopaguh.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Imujizego=rundll32.exe "[%WINDOWS%]\asawatebicogicey.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nitevozij=Rundll32.exe "[%SYSTEM%]\fopijunu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {201faa5b-98bf-4be0-9e7b-82145e59f320}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wiyutahev={201faa5b-98bf-4be0-9e7b-82145e59f320}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zisudupil=Rundll32.exe "[%SYSTEM%]\bufufodu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3ee6fd98-acf8-464f-b94e-65f0a9f2a592}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zisakekil={3ee6fd98-acf8-464f-b94e-65f0a9f2a592}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hurituhuza=Rundll32.exe "yoyijite.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefoyefin=Rundll32.exe "[%SYSTEM%]\semadoyo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a6d7947b-d98b-4d5b-999b-5793cc9e6217}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pazuyevem={a6d7947b-d98b-4d5b-999b-5793cc9e6217}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nehukufama=Rundll32.exe "[%COMMON_APPDATA%]\tajuzufo\tajuzufo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nehukufama=Rundll32.exe "[%COMMON_APPDATA%]\tajuzufo\tajuzufo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yluhayisadoq=rundll32.exe "[%WINDOWS%]\obomijigoki.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, manofasuj=Rundll32.exe "[%SYSTEM%]\zulelolo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73b32ef5-3d6f-4a16-9f5f-354e072cba26}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dopiyugoz={73b32ef5-3d6f-4a16-9f5f-354e072cba26}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Edozumutokarat=rundll32.exe "[%WINDOWS%]\ekurumec.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lobajepum=Rundll32.exe "[%SYSTEM%]\muyasera.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {509f4460-e6a5-4964-bda3-f5840bff472b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yiruhaloy={509f4460-e6a5-4964-bda3-f5840bff472b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ca510c1b-e164-43e5-94dc-02e9dac76278}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kugehiloy={ca510c1b-e164-43e5-94dc-02e9dac76278}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jliqotovunikanuj=rundll32.exe "[%WINDOWS%]\ikeqifihufehori.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kugosatum=Rundll32.exe "[%SYSTEM%]\moyaseso.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f4b5d525-9f13-4ef6-a545-315b9e602fc9}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wepozobel={f4b5d525-9f13-4ef6-a545-315b9e602fc9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\gavehere.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {35cfe9b1-81c2-4d01-a350-a759292ad7fc}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kimowison=Rundll32.exe "[%SYSTEM%]\logozama.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, biniyapel=Rundll32.exe "[%SYSTEM%]\kagavuva.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {03be7460-c2a1-4278-a9c1-970a05584e95}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jevasamaz={03be7460-c2a1-4278-a9c1-970a05584e95}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,yXmCpCijS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlkkjhdrv=rundll32.exe "mlkllk.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xxxyywdrv=rundll32.exe "mlkllk.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyuvibog=Rundll32.exe "[%SYSTEM%]\fisibezu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyuvibog=Rundll32.exe "[%SYSTEM%]\fisibezu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c3b39a0e-e8f7-499a-bf8c-f63a143f6d7b}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rolujimes={c3b39a0e-e8f7-499a-bf8c-f63a143f6d7b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7c86e1ce-a2a2-420a-a165-1fb9a01c3f9a}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, natuvigig={7c86e1ce-a2a2-420a-a165-1fb9a01c3f9a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hurituhuza=Rundll32.exe "yiheguku.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mijupibim=Rundll32.exe "[%SYSTEM%]\monajole.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, e020e227=rundll32.exe "[%SYSTEM%]\zesanido.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, defifiyodo=Rundll32.exe "[%SYSTEM%]\mupafeve.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hufidekiv=Rundll32.exe "[%SYSTEM%]\nojepake.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {882f1356-90af-40fb-841b-d951ff3613a1}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zafutinad={882f1356-90af-40fb-841b-d951ff3613a1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fogedilobi=Rundll32.exe "fihidivi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dowijazitu=Rundll32.exe "[%COMMON_APPDATA%]\nepihene\nepihene.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {f3aef888-a3e2-44eb-bd85-f0c85ba7673f}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoej32.rom,yXmCpCijS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vufegumis=Rundll32.exe "[%SYSTEM%]\gosofuwu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7eefecb6-a8d9-42dd-9f1a-3e66fdcf596b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vimayumik={7eefecb6-a8d9-42dd-9f1a-3e66fdcf596b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, biniyapel=Rundll32.exe "[%SYSTEM%]\fabireze.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9aa9c227-4933-48ce-bd73-64188c0a4347}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, puheyizez={9aa9c227-4933-48ce-bd73-64188c0a4347}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mupiyeviha=Rundll32.exe "ritujute.dll",s
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F25465B91.exe=[%PROFILE_TEMP%]\_A00F25465B91.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F25264342.exe=[%PROFILE_TEMP%]\_A00F25264342.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,fxMrhaP
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ktezesumidinigow=rundll32.exe "[%LOCAL_APPDATA%]\owumogavimov.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\qoMeBuTm.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintvo32.rom,MTAlhAGxYc
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ylegovuviyakidal=rundll32.exe "[%WINDOWS%]\efihulalihoc.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, keriyinun=Rundll32.exe "[%SYSTEM%]\jusirodo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hpajehokonip=rundll32.exe "[%WINDOWS%]\otofureqijoloz.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\wilariyu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\vozizowu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {109be732-8f8c-49d4-a3f4-fedcac7f0a25}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {df9a99cf-49c6-4e3e-b668-498b718fd313}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gulutekiw=Rundll32.exe "[%SYSTEM%]\nahiyuku.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjfb32.rom,jTpWxiiNxZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,vaKmQlWKZKst
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yjiceq=rundll32.exe "[%WINDOWS%]\iwicejalafoqipof.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nuyajevul=Rundll32.exe "[%COMMON_APPDATA%]\vamegeye\vamegeye.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nuyajevul=Rundll32.exe "[%COMMON_APPDATA%]\vamegeye\vamegeye.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fadoyuyuwa=Rundll32.exe "[%COMMON_APPDATA%]\tiwamora\tiwamora.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7764733e-c4df-43f1-b3d1-a787d5b056b8}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rujudugef={7764733e-c4df-43f1-b3d1-a787d5b056b8}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yedehobome=Rundll32.exe "[%COMMON_APPDATA%]\baruruza\baruruza.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nogehuseh=Rundll32.exe "[%SYSTEM%]\weziyolo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cd003e2d-605f-429c-ab30-65860ef100e9}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wedenewis={cd003e2d-605f-429c-ab30-65860ef100e9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, petolegoda=Rundll32.exe "yivozizi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winoej32.rom,QPQLEtyNhwu
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, royehabega=Rundll32.exe "vamegeye.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fduguhoxajedecod=rundll32.exe "[%WINDOWS%]\ujavozer.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zepavelon=Rundll32.exe "[%COMMON_APPDATA%]\ludotoja\ludotoja.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, juhuduzutu=Rundll32.exe "[%COMMON_APPDATA%]\puzesale\puzesale.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, opomlmsys=rundll32.exe "cbbywv.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efcbcysys=rundll32.exe "cbbywv.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkljhsys=rundll32.exe "cbbywv.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkljhsys=rundll32.exe "cbbywv.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vafofukov=Rundll32.exe "[%SYSTEM%]\gopafusa.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tfozatuqic=rundll32.exe "[%WINDOWS%]\axivonejecuxiqiv.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, MSSMSGS=rundll32.exe winzmu32.rom,ayVGNWBZ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {31cdfcb9-37d6-4c1d-a31d-aa2dd56f637b}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {060bb0ab-4b09-4c51-9ecb-9580a6d08d7f}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8e3fbde2-7dbd-4040-85d9-29bbc559c129}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {a260787b-911c-49a1-ae73-ec76a3cec27e}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5C060FE2-B3CA-47DD-B68E-BD1A6E297226}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {c3f37eca-a8d9-4633-92c6-fe24c7d16aba}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {14370f76-7676-44a2-ad11-93a31c5fc9fc}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ymivudatugap=rundll32.exe "[%WINDOWS%]\osekowomaquden.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6ff22309-a6ed-462b-abec-877625c012f3}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqto32.rom,gfDuUiHUj
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5d51cde0-defa-4947-9ca6-f6ec39b970b5}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fesonebed={5d51cde0-defa-4947-9ca6-f6ec39b970b5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zemivenive=Rundll32.exe "[%COMMON_APPDATA%]\deniyiri\deniyiri.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzhp32.rom,GfPquShNdUe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, heredujum=Rundll32.exe "[%SYSTEM%]\yezumoyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {11ac7bbd-346e-4a08-a468-585ac904f8ca}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pasibasol={11ac7bbd-346e-4a08-a468-585ac904f8ca}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fimaweseme=Rundll32.exe "fokitape.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvsh32.rom,exxEyfKTQZp
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzws32.rom,scDbQiAGmt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bnawo=rundll32.exe "[%WINDOWS%]\oqayofikaha.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lxivubijaxesa=rundll32.exe "[%WINDOWS%]\icejolij.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Crulifiv=rundll32.exe "[%WINDOWS%]\utupoyowuka.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kinipokig=Rundll32.exe "[%SYSTEM%]\wumomara.dll",a
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F8E1673.exe=[%PROFILE_TEMP%]\_A00F8E1673.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, larogavak=Rundll32.exe "[%SYSTEM%]\dawitezu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {37317a22-8cc8-4475-84be-428f8868799a}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, butenagog={37317a22-8cc8-4475-84be-428f8868799a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {83f3b6ba-6635-4fb1-a0ed-8d8438161c30}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jowogizek={83f3b6ba-6635-4fb1-a0ed-8d8438161c30}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e419d5e5-8496-4beb-a50d-6d35676562b6}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pezigiyeb={e419d5e5-8496-4beb-a50d-6d35676562b6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gijinohih=Rundll32.exe "[%SYSTEM%]\vewalimu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {637239b5-b5b7-49af-bbca-986818e401bb}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sinimumag={637239b5-b5b7-49af-bbca-986818e401bb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, petibopasu=Rundll32.exe "regavemu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kkunuxidetayol=rundll32.exe "[%WINDOWS%]\ehedebir.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,AhaoLNsr
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbxwutdrv=rundll32.exe "[%PROFILE_TEMP%]\byvutu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fccabxsys=rundll32.exe "[%PROFILE_TEMP%]\jkheca.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\yaywtQIb.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\geBuTliF.dll,c
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tusuhusiy=Rundll32.exe "[%SYSTEM%]\kegayezu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c423bcab-e00c-4f4e-af6d-f9ccb4a79045}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, disifomak={c423bcab-e00c-4f4e-af6d-f9ccb4a79045}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dadamuheza=Rundll32.exe "pesesuyo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dadamuheza=Rundll32.exe "pesesuyo.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dadamuheza=Rundll32.exe "pesesuyo.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dadamuheza=Rundll32.exe "pesesuyo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yazowezib=Rundll32.exe "[%SYSTEM%]\dojeseja.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f39f8178-21bd-4e24-89f9-58b49da48aa0}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nejowimaz={f39f8178-21bd-4e24-89f9-58b49da48aa0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fponoke=rundll32.exe "[%WINDOWS%]\umetadumokaba.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {11a69ae4-fbed-4832-a2bf-45af82825583}=00
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {a11c5aa1-0522-4e2c-8b55-61ec322a00bb}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yazovupod=Rundll32.exe "[%SYSTEM%]\merenugu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {20255f88-a408-4c17-ac64-5a78cc871b4e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lekagugik={20255f88-a408-4c17-ac64-5a78cc871b4e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Skeso=rundll32.exe "[%WINDOWS%]\oxoroteg.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, koriwedaj=Rundll32.exe "[%SYSTEM%]\dutudari.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6dcdc2be-eb0b-4869-95ac-bdec9ff9a6c0}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bijerakib={6dcdc2be-eb0b-4869-95ac-bdec9ff9a6c0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ukobibereriyo=rundll32.exe "[%WINDOWS%]\iwubabuy.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vabamaladu=Rundll32.exe "[%SYSTEM%]\jojejodi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wijuwatiya=Rundll32.exe "hupezivu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ymivudatugap=rundll32.exe "[%WINDOWS%]\imebijam.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ogezogehu=rundll32.exe "[%WINDOWS%]\utekuqis.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Shohacaju=rundll32.exe "[%WINDOWS%]\iyekojotohu.dll",e
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,lZbpVBVI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nirovepob=Rundll32.exe "[%SYSTEM%]\bupodaze.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b8300366-8bc7-4771-97f1-4d4da0b482a5}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sonikuduf={b8300366-8bc7-4771-97f1-4d4da0b482a5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingkc32.rom,afmWJt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, a853a81e=rundll32.exe "[%SYSTEM%]\xfbswufk.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {46D7049A-9DB9-4AEC-82B1-F101B9367CB1}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {01a33d85-4706-452a-b71a-99510ada8c0c}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {01cd0b31-9154-45f2-9414-f5d64b74eaf6}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {00dc0058-a87e-4d19-9c26-f1aac98ad4d7}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, givufilizo=Rundll32.exe "bojitoya.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suyoduvehe=Rundll32.exe "[%SYSTEM%]\bokayoto.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suyoduvehe=Rundll32.exe "[%SYSTEM%]\bokayoto.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hayivumeh=Rundll32.exe "[%SYSTEM%]\lakutufo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {97323e3b-2e7f-46d2-8bb4-767ece633a31}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, roselaruw={97323e3b-2e7f-46d2-8bb4-767ece633a31}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM0fea4e87=Rundll32.exe "[%SYSTEM%]\muguwubo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mufujuyel=Rundll32.exe "[%SYSTEM%]\wejiwulo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {05ea8827-31b4-4013-b19e-428099073596}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wirulasij={05ea8827-31b4-4013-b19e-428099073596}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rihetusuy=Rundll32.exe "[%SYSTEM%]\tulededa.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhdk32.rom,dIDveCAxDx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hovapeyaw=Rundll32.exe "[%SYSTEM%]\hemenozu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yeripimefe=Rundll32.exe "yazeriza.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bc112aff-3579-413c-92a6-1c342b4d726b}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fagikanug={bc112aff-3579-413c-92a6-1c342b4d726b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vramosexasuxomo=rundll32.exe "[%WINDOWS%]\abenenorixatabiv.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {9796007a-181e-4c97-99eb-7f71b8989a7b}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {84dfef3c-f007-4654-af0c-7ac87f08d526}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ponupewol={84dfef3c-f007-4654-af0c-7ac87f08d526}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5136b29a-15a7-49a4-b651-48d98fd5da81}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mipohorap={5136b29a-15a7-49a4-b651-48d98fd5da81}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, givufilizo=Rundll32.exe "bojitoya.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jejazadin=Rundll32.exe "[%SYSTEM%]\zahuzihi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, paretugez=Rundll32.exe "[%SYSTEM%]\fukafati.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kwimaw=rundll32.exe "[%WINDOWS%]\uvukaqibiyovoxan.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gevifuwim=Rundll32.exe "[%SYSTEM%]\bidiyije.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bopavoluzi=Rundll32.exe "vekukedu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {b62b5ce6-a4bf-428d-8a21-47ee1bd90eac}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {eec73ea5-1367-49d1-93f4-ca1d8c22e9f9}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kyazolifasufolif=rundll32.exe "[%WINDOWS%]\aratiwoj.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mdaneduguge=rundll32.exe "[%WINDOWS%]\uzayejuhediqadun.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nunotulem=Rundll32.exe "[%SYSTEM%]\zomutaho.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3358f9d5-c8af-4f40-8657-85ace6d9dc98}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, guwehenaj={3358f9d5-c8af-4f40-8657-85ace6d9dc98}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kuvepanad=Rundll32.exe "[%SYSTEM%]\ludimepo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {aaedc30d-1e0a-4870-864f-bc24c911ba0a}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zavuyibon={aaedc30d-1e0a-4870-864f-bc24c911ba0a}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wincmm32.rom,tAEVWlhq
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wagusojan=Rundll32.exe "[%SYSTEM%]\yemopego.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3bdeabf9-6f6c-4aa2-8c92-9d1648c56822}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dunezuzad={3bdeabf9-6f6c-4aa2-8c92-9d1648c56822}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Drivoxanetixivum=rundll32.exe "[%WINDOWS%]\otekixezibece.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 6c732dbc=rundll32.exe "[%SYSTEM%]\kbgglggp.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM6f401e20=Rundll32.exe "[%SYSTEM%]\bkutcmbq.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {a436c8c3-3d99-4f58-ab80-c11fc9882bbc}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mzogawodafu=rundll32.exe "[%WINDOWS%]\ifetepinukon.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nwaziqova=rundll32.exe "[%WINDOWS%]\owowifap.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhlt32.rom,qVRnGbnuKI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pukituhit=Rundll32.exe "[%SYSTEM%]\jumidani.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vkosekajomo=rundll32.exe "[%WINDOWS%]\ihetadux.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kotupises=Rundll32.exe "[%SYSTEM%]\kuzeduhu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e918b27b-15cb-46c9-aa7a-46fafe7aff3b}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sezukuvit={e918b27b-15cb-46c9-aa7a-46fafe7aff3b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jrovawifukineme=rundll32.exe "[%WINDOWS%]\ubexubex.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, miguhotuw=Rundll32.exe "[%SYSTEM%]\runivito.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, miguhotuw=Rundll32.exe "[%SYSTEM%]\kiduruka.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, miguhotuw=Rundll32.exe "[%SYSTEM%]\muvobuwe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6511ce40-7279-4b5b-b1a2-f8c1da9a08d7}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, suviruzub={6511ce40-7279-4b5b-b1a2-f8c1da9a08d7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0fd88398-25f1-4fb1-8be5-9abd05148abb}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fulijoduw={0fd88398-25f1-4fb1-8be5-9abd05148abb}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f7ede46e-3ed5-4934-a758-ec61ede92960}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zemetapit={f7ede46e-3ed5-4934-a758-ec61ede92960}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ktezesumidinigow=rundll32.exe "[%LOCAL_APPDATA%]\eqibozer.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lezovatut=Rundll32.exe "[%SYSTEM%]\rosodevi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dimusasih=Rundll32.exe "[%SYSTEM%]\tusugaha.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dimusasih=Rundll32.exe "[%SYSTEM%]\gilavofi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {380e79f2-c669-4cc8-9d40-f592b1293fe7}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, besodolok={380e79f2-c669-4cc8-9d40-f592b1293fe7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {18093456-9012-4568-9076-908765467181}=tisqatyu.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {4a698102-5904-afd0-20df-cd1a65829ca4}=zycbdime.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {7C8D1401-A58D-A81C-CD24-A5915C4517C7}=mnmhgsrv.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tikehafoh=Rundll32.exe "[%SYSTEM%]\povufuyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {db756a7a-fbd2-4797-97b9-ffdb47035c39}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rabatites={db756a7a-fbd2-4797-97b9-ffdb47035c39}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F1AD3F06.exe=[%PROFILE_TEMP%]\_A00F1AD3F06.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyeyanof=Rundll32.exe "[%SYSTEM%]\kedohugu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\yayxxwxV.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, finebibip=Rundll32.exe "[%WINDOWS%]\dowikabu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c23c8c1b-4fb6-48de-a11b-0e1f4eb2f2ea}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sirihofay={c23c8c1b-4fb6-48de-a11b-0e1f4eb2f2ea}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vovezefur=Rundll32.exe "[%SYSTEM%]\vororeni.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c86b261d-bbce-4d91-94da-3d3040e5ddbc}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, watogugaw={c86b261d-bbce-4d91-94da-3d3040e5ddbc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar, {83b3fea7-601a-4bb0-8d74-a819069a4cfa}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vemayubol=Rundll32.exe "[%SYSTEM%]\mirajuva.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {02b3eb34-fe9c-4a49-a4a0-99fcc5d2a09f}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lefipofir={02b3eb34-fe9c-4a49-a4a0-99fcc5d2a09f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {6A041F13-A111-12A3-B0CF-F99818AA68A6}=zxmscwin.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {37AC9076-C898-B098-D098-A18319080973}=nhmxcjkl.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, molarowod=Rundll32.exe "[%SYSTEM%]\negosivo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pihejeliz=Rundll32.exe "[%SYSTEM%]\sesotoja.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0af3a8f2-ec9f-4801-b22f-67bd7514aa5d}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gakosivid={0af3a8f2-ec9f-4801-b22f-67bd7514aa5d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {16cc523a-4193-4942-b8d9-34df7eed346f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fababakiz={16cc523a-4193-4942-b8d9-34df7eed346f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {e5646f36-145e-4f1d-b6d1-87c5efc5ba1c}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {e180f496-8a4b-44e2-9fe0-0364e345db7f}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {178d4e6a-ba5a-4ecb-8521-f7b8393fdb97}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\eFWpMcca.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lofavemow=Rundll32.exe "[%COMMON_APPDATA%]\fogidiga\fogidiga.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, desogufake=Rundll32.exe "[%COMMON_APPDATA%]\zukenezo\zukenezo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winilr32.rom,jECImRmvQAiQ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, migoremuj=Rundll32.exe "[%SYSTEM%]\vezurejo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c8148b6e-fc77-4bbe-8ec8-70e3f83faf12}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yekapuyor={c8148b6e-fc77-4bbe-8ec8-70e3f83faf12}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tcivakusadiyu=rundll32.exe "[%WINDOWS%]\clopxtp.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Upafaxi=rundll32.exe "[%WINDOWS%]\ufiwuxiq.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hekewoyav=Rundll32.exe "[%SYSTEM%]\kosuyapu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winojm32.rom,rQTCNEcpVqql
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dimopevav=Rundll32.exe "[%SYSTEM%]\muyasera.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dziku=rundll32.exe "[%WINDOWS%]\ohiwukat.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kumunuzun=Rundll32.exe "[%SYSTEM%]\hutikovu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, merofalori=Rundll32.exe "malusasu.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8ea62941-4a43-471b-b721-d356af066f03}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jehoyejat={8ea62941-4a43-471b-b721-d356af066f03}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dgomojiy=rundll32.exe "[%WINDOWS%]\eyoxewug.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zolumirej=Rundll32.exe "[%SYSTEM%]\fasihebu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a5a86789-c55f-4132-9bff-8abb729c4a20}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gunelowep={a5a86789-c55f-4132-9bff-8abb729c4a20}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,YDZoMXXPbr
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zomohunaf=Rundll32.exe "[%SYSTEM%]\gadagore.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2f8d6f7e-0b38-4279-a6e6-fb78a20f45c0}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gohimulij={2f8d6f7e-0b38-4279-a6e6-fb78a20f45c0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, marufusipo=Rundll32.exe "midamuhi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, gugimazaji=Rundll32.exe "[%COMMON_APPDATA%]\begadosi\begadosi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikixifatu=rundll32.exe "[%WINDOWS%]\atatefacosaqo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mlmlkkdrv=rundll32.exe "yabcaw.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qonooodrv=rundll32.exe "yabcaw.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gebawxdrv=rundll32.exe "yabcaw.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gebawxdrv=rundll32.exe "yabcaw.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tutuussys=rundll32.exe "fcbbyv.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khedecsys=rundll32.exe "fcbbyv.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khedecsys=rundll32.exe "fcbbyv.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Acalasazas=rundll32.exe "[%WINDOWS%]\asucoyusikunose.dll",Startup
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F4141BF.exe=[%PROFILE_TEMP%]\_A00F4141BF.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rtolejataza=rundll32.exe "[%WINDOWS%]\igabeguyo.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bnawo=rundll32.exe "[%WINDOWS%]\iqeniwar.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {516b16e3-e30e-4ef3-b8a8-2e70d4743383}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcbcyxdrv=rundll32.exe "effeec.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkklkhdrv=rundll32.exe "effeec.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrpnkdrv=rundll32.exe "effeec.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vtrpnkdrv=rundll32.exe "effeec.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbxwxsys=rundll32.exe "fccdbx.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khigebsys=rundll32.exe "fccdbx.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, khigebsys=rundll32.exe "fccdbx.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mcimoniqivuxegeq=rundll32.exe "[%WINDOWS%]\orehidim.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Drivoxanetixivum=rundll32.exe "[%WINDOWS%]\opuquzuw.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpij32.rom,vAmXjLAcsgvU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikejay=rundll32.exe "[%WINDOWS%]\okinilecolayiza.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uyotuhe=rundll32.exe "[%WINDOWS%]\elizalebinur.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 320d18a1=rundll32.exe "[%SYSTEM%]\mhfttxxe.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwde32.rom,QSbkTJQqYXOQ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mipezuyip=Rundll32.exe "[%COMMON_APPDATA%]\hayozaji\hayozaji.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dinejenepe=Rundll32.exe "[%COMMON_APPDATA%]\vuzidahu\vuzidahu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqhx32.rom,RxgRVs
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hofagowah=Rundll32.exe "[%SYSTEM%]\gabesoyu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, levuwoyuw=Rundll32.exe "[%COMMON_APPDATA%]\zurokawe\zurokawe.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, giyisuhaju=Rundll32.exe "[%COMMON_APPDATA%]\razusula\razusula.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM8b3d22e3=Rundll32.exe "[%SYSTEM%]\purahulu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 880e117f=rundll32.exe "[%SYSTEM%]\nikuwigi.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pitevajuve=Rundll32.exe "[%SYSTEM%]\yebalino.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zerukenuf=Rundll32.exe "[%SYSTEM%]\lomugiti.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tubiyarefu=Rundll32.exe "tudiroye.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\zusewonu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rubajedat=Rundll32.exe "[%COMMON_APPDATA%]\nelufuyu\nelufuyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ecab4981-620a-46a1-ae2e-309aaf87405d}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, malodufuj={ecab4981-620a-46a1-ae2e-309aaf87405d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mzogawodafu=rundll32.exe "[%WINDOWS%]\uquxufapifovav.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 8c01afd3=rundll32.exe "[%SYSTEM%]\xfxrluij.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tujasuzof=Rundll32.exe "[%COMMON_APPDATA%]\mafizema\mafizema.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fohodimala=Rundll32.exe "[%COMMON_APPDATA%]\vekiripu\vekiripu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yoyayifuy=Rundll32.exe "[%SYSTEM%]\babitote.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2942b9a9-2e67-43f5-b40a-47c800be6b61}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wigepunal={2942b9a9-2e67-43f5-b40a-47c800be6b61}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,pCnWtQR
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,bUvdrpKrDhNJ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {28c1eefb-dd85-4227-bc29-c17d7366b27d}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {e0da6733-5c9a-46bc-ba1f-7f4998a173d5}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {fbff3b36-be67-4561-99a4-5477b0bfc5fa}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sedinagef=Rundll32.exe "[%SYSTEM%]\vefukufe.dll",a
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F504CF9F.exe=[%PROFILE_TEMP%]\_A00F504CF9F.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vebiwazav=Rundll32.exe "[%SYSTEM%]\gadagore.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zezufefoki=Rundll32.exe "jakonehu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qlobovugiyari=rundll32.exe "[%WINDOWS%]\ahoracevenupehuk.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 3083f297=rundll32.exe "[%SYSTEM%]\hrrceyrl.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineii32.rom,ZIlWuHLkOB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mezafakuj=Rundll32.exe "[%SYSTEM%]\tesutefa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {35fd522d-3e11-4678-91e9-2f229a97384d}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bovitoyop={35fd522d-3e11-4678-91e9-2f229a97384d}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwiz32.rom,lVEMcKK
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjfb32.rom,dTjxuiPd
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pejejemuy=Rundll32.exe "[%SYSTEM%]\sibogaya.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5d939f56-8917-4579-aeb7-a2702753b0f9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rawihejed={5d939f56-8917-4579-aeb7-a2702753b0f9}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnuj32.rom,JuAsAEBmw
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gukafafor=Rundll32.exe "[%SYSTEM%]\valuvefo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {49095e21-dbf1-472e-ae5d-011ae0e90620}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pizobuvub={49095e21-dbf1-472e-ae5d-011ae0e90620}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yaawtrdrv=rundll32.exe "mlkkhe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hgdedddrv=rundll32.exe "mlkkhe.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kheffedrv=rundll32.exe "mlkkhe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kheffedrv=rundll32.exe "mlkkhe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, awtqnosys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcyvwusys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fcyvwusys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabcdbdrv=rundll32.exe "mlkkhe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yabcdbdrv=rundll32.exe "mlkkhe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, urrrqosys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbbaasys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cbbbaasys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ursppmdrv=rundll32.exe "kheccd.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkjjkdrv=rundll32.exe "kheccd.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nnkljisys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkiiisys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkiiisys=rundll32.exe "jkkkki.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, godoliluv="Rundll32.exe" "[%SYSTEM%]\vidajadu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, forokutid=Rundll32.exe "[%SYSTEM%]\kurufihu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {82fe4243-7858-4518-9775-bd37469b4256}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, guvasepan={82fe4243-7858-4518-9775-bd37469b4256}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hofagowah=Rundll32.exe "[%SYSTEM%]\disesobe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {de23f6a0-eb78-4e3c-819f-e3096be894a7}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nesejetam={de23f6a0-eb78-4e3c-819f-e3096be894a7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\papororo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {15b2af00-4523-44f8-9a68-bc17a447c54b}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zulesaseg={15b2af00-4523-44f8-9a68-bc17a447c54b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM57cfb8a0=Rundll32.exe "[%SYSTEM%]\honayoto.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 54fc8b3c=rundll32.exe "[%SYSTEM%]\nunikija.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dumukapayo=Rundll32.exe "[%SYSTEM%]\dusezaji.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Glecegifop=rundll32.exe "[%WINDOWS%]\ubepemiyuvacas.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM3f2b21a0=Rundll32.exe "[%SYSTEM%]\wazuloro.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 3c18123c=rundll32.exe "[%SYSTEM%]\tevaziva.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bosafaviko=Rundll32.exe "[%SYSTEM%]\huhugafe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mebawuhow=Rundll32.exe "[%SYSTEM%]\bemevoyu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lesabopep=Rundll32.exe "[%SYSTEM%]\basapazu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7ad34d00-243b-4cca-8226-b6fc385549e6}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yuwimivuv={7ad34d00-243b-4cca-8226-b6fc385549e6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9ec3d7d0-353e-46f6-8951-978b0c5db219}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dimefutos={9ec3d7d0-353e-46f6-8951-978b0c5db219}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hofagowah=Rundll32.exe "[%SYSTEM%]\niwaluyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1ec1ebcc-dc69-444f-83e9-593d2f6e22f9}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lufisutoz={1ec1ebcc-dc69-444f-83e9-593d2f6e22f9}
Scan your system registry for FREE

Comments

