Top 10 virus alerts
Latest 10 malware files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jiwisinih={ad73e4c9-a128-4c1e-bb3e-a6cf12abe323}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkcz32.rom,MCrtruxmug
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumazimif=Rundll32.exe "[%SYSTEM%]\fivajubu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9ab52173-0f37-44c1-8740-9761b68a6999}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wekamakat={9ab52173-0f37-44c1-8740-9761b68a6999}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tiyofawiv=Rundll32.exe "[%SYSTEM%]\dinahobu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vmemesiyovupomu=rundll32.exe "[%WINDOWS%]\ahuweciqusoletun.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhlt32.rom,ZLhdLPzIesK
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rxecesuxid=rundll32.exe "[%WINDOWS%]\asiboyorad.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jkkiihdrv=rundll32.exe "[%PROFILE_TEMP%]\fcbbby.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vttqonsys=rundll32.exe "[%PROFILE_TEMP%]\cbbyyv.dll",DllRegisterServer
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ddaayasys=rundll32.exe "[%PROFILE_TEMP%]\cbbyyv.dll",DllRegisterServer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vfosagurina=rundll32.exe "[%WINDOWS%]\okagacuticabaq.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ruyojutow=Rundll32.exe "[%SYSTEM%]\hodajupi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7b117d35-6cdb-4e48-bfeb-7e085d29ad8f}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dikopiyar={7b117d35-6cdb-4e48-bfeb-7e085d29ad8f}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a97c41dc-3fd0-4b3b-80e9-8b61855e3df0}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yadeboseb={a97c41dc-3fd0-4b3b-80e9-8b61855e3df0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {58f4eb39-a5a7-4d2c-af0a-23c41ef6dbdf}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gajazijew={58f4eb39-a5a7-4d2c-af0a-23c41ef6dbdf}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ruyojutow=Rundll32.exe "[%SYSTEM%]\resevine.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ovociga=rundll32.exe "[%WINDOWS%]\ibotegigusobo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, davonuful=Rundll32.exe "[%SYSTEM%]\huzaweli.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2dc815e5-4f7a-4845-abce-8a839c002b38}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, topeperod={2dc815e5-4f7a-4845-abce-8a839c002b38}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrtt32.rom,qCmgzh
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,vzMFdPbSO
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxfp32.rom,fomVjRJMtsze
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pokazibah=Rundll32.exe "[%SYSTEM%]\kusitozo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {002e970b-690d-4cf6-b55e-ad76740c337c}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dozebezaf={002e970b-690d-4cf6-b55e-ad76740c337c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {40e1734c-8b66-4a40-bd9c-4838282317a6}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vefotapuk={40e1734c-8b66-4a40-bd9c-4838282317a6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6ab32687-1f88-408e-ac8c-b6ee56b8c485}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pofupofaw={6ab32687-1f88-408e-ac8c-b6ee56b8c485}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yibanuwulu=Rundll32.exe "lejivaya.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {24e9519b-3f70-429b-99bc-4b2b49b96f66}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {ADCD30FF-0119-4906-8A8B-D52D1EED044B}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uhuguxoxotumud=rundll32.exe "[%WINDOWS%]\iyonigowe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\byXQGwXR.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jdami=rundll32.exe "[%WINDOWS%]\otabababababa.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bdibit=rundll32.exe "[%WINDOWS%]\ohazevuqanalepe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ehukegifopaniya=rundll32.exe "[%WINDOWS%]\otalihocimaf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, soteyosuk=Rundll32.exe "[%SYSTEM%]\holiditu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ae0ae78a-110b-4e88-90df-bdeadea76b10}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kuwiyehed={ae0ae78a-110b-4e88-90df-bdeadea76b10}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pigenomeze="Rundll32.exe" "[%COMMON_APPDATA%]\buzalevu\buzalevu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gafowumes=Rundll32.exe "[%SYSTEM%]\jidesoti.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {401b6a08-cb14-49e3-9add-26dfc7b04299}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gakosivid={401b6a08-cb14-49e3-9add-26dfc7b04299}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ruyojutow=Rundll32.exe "[%SYSTEM%]\logapoyi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0242b18a-417e-4f98-af19-3c172b6083ac}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, suzasobef={0242b18a-417e-4f98-af19-3c172b6083ac}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winwiz32.rom,mBOaxPtfoS
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00FBF4881.exe=[%PROFILE_TEMP%]\_A00FBF4881.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 2842758d=rundll32.exe "[%SYSTEM%]\cnqsnymb.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, safatabaye=Rundll32.exe "kuvoduze.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mhokeso=rundll32.exe "[%WINDOWS%]\ogisejadaza.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8c57cb69-ec1f-4ff3-916f-52151aabc187}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, CPM8f0e206d=Rundll32.exe "[%SYSTEM%]\hukubuhu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winffq32.rom,jdKZEZ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lohiyubin=Rundll32.exe "[%SYSTEM%]\yofolufe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c1cda5d5-9ed9-44bc-996f-1090f6529eae}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jukomomuj={c1cda5d5-9ed9-44bc-996f-1090f6529eae}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fobomumoy=Rundll32.exe "[%SYSTEM%]\lijuhidi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b90f6862-e2bd-4bba-b02e-a41093cfb6e4}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kuvohoyan={b90f6862-e2bd-4bba-b02e-a41093cfb6e4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loguyowoz=Rundll32.exe "[%SYSTEM%]\rarayuna.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c05f5847-7159-4a5d-9611-715f99dcf46e}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, guruhemag={c05f5847-7159-4a5d-9611-715f99dcf46e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kodomimut=Rundll32.exe "[%SYSTEM%]\wekenopo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {20c69a17-5c55-4ba5-a058-2fca039138ea}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, womewasun={20c69a17-5c55-4ba5-a058-2fca039138ea}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F105E6.exe=[%PROFILE_TEMP%]\_A00F105E6.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yorohuvan=Rundll32.exe "[%SYSTEM%]\yuniyuzi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c4f5be22-ddf8-4f90-b438-df7260f3aac4}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wumidukas={c4f5be22-ddf8-4f90-b438-df7260f3aac4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lohiyubin=Rundll32.exe "[%SYSTEM%]\ruhefife.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7ccdc44d-bc94-4f1d-b448-d2ed5c0c7e77}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lisobediw={7ccdc44d-bc94-4f1d-b448-d2ed5c0c7e77}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbwh32.rom,xIkgKC
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfusaqomi=rundll32.exe "[%WINDOWS%]\ekabatidedug.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zifebojis=Rundll32.exe "[%COMMON_APPDATA%]\yotapudo\yotapudo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ziripodej=Rundll32.exe "[%SYSTEM%]\nakonaze.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9c2938ef-b604-4d62-86fd-96254355475a}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tanikohir={9c2938ef-b604-4d62-86fd-96254355475a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d0453c42-f3b0-4f9c-9b3a-42177b3f95d3}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fosasupon={d0453c42-f3b0-4f9c-9b3a-42177b3f95d3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fnarubixaxayugu=rundll32.exe "[%WINDOWS%]\edobarax.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, walanufad=Rundll32.exe "[%SYSTEM%]\delidubu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {acf902f8-1468-4d9d-a52f-2bc84fda7bdc}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zubupagev={acf902f8-1468-4d9d-a52f-2bc84fda7bdc}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {602a8d65-c9d9-4d29-858f-6b1767619dd9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gahomaveb={602a8d65-c9d9-4d29-858f-6b1767619dd9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {82eed284-a0aa-42f9-8221-c2c46e5a74de}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, newigiliw={82eed284-a0aa-42f9-8221-c2c46e5a74de}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2c115c84-4409-4dcb-abcc-965cb5965cc9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wapolurim={2c115c84-4409-4dcb-abcc-965cb5965cc9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0fd361be-a167-4b0e-a7bc-3cb7b28870ce}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, buporadej={0fd361be-a167-4b0e-a7bc-3cb7b28870ce}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ab156ac0-d679-47d7-9100-9b5a589b046a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hokitemaf={ab156ac0-d679-47d7-9100-9b5a589b046a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {38c04f30-25f8-46c8-9bd2-d40bdf3e6028}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hirifutiw={38c04f30-25f8-46c8-9bd2-d40bdf3e6028}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dqeje=rundll32.exe "[%WINDOWS%]\amajecazuwipiqow.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lizeyujed=Rundll32.exe "[%SYSTEM%]\mebozihi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pahahakunu=Rundll32.exe "zabunego.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {33a010ae-d3fc-4277-b43b-3f23f29aaf56}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lobosemom={33a010ae-d3fc-4277-b43b-3f23f29aaf56}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fmawubalikoq=rundll32.exe "[%WINDOWS%]\ufegogagimogoyi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fobomumoy=Rundll32.exe "[%SYSTEM%]\hozekopo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {41fc3b77-91e9-4ea2-80a6-c8183c36daa4}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hadatobiy={41fc3b77-91e9-4ea2-80a6-c8183c36daa4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nesurukeb=Rundll32.exe "[%SYSTEM%]\hamobaku.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {061e4a73-2711-4189-9df8-3a536c679127}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, butajezoz={061e4a73-2711-4189-9df8-3a536c679127}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ytpdor=RUNDLL32.EXE [%SYSTEM%]\mslawejk.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, futizutif=Rundll32.exe "[%SYSTEM%]\vuvimuwe.dll",a
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F20A15DE.exe=[%PROFILE_TEMP%]\_A00F20A15DE.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F69472.exe=[%PROFILE_TEMP%]\_A00F69472.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F34334.exe=[%PROFILE_TEMP%]\_A00F34334.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gotekerit=Rundll32.exe "[%SYSTEM%]\tugufapi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {011bdb6b-772f-4800-aa66-b3a719c8149f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mawepozeh={011bdb6b-772f-4800-aa66-b3a719c8149f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loguyowoz=Rundll32.exe "[%SYSTEM%]\begimepo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3ce53523-ecd3-457a-8a9c-5468a9423270}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, meyowunet={3ce53523-ecd3-457a-8a9c-5468a9423270}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Ypubol=rundll32.exe "[%WINDOWS%]\ajezuxawodafuv.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, zipivohun=Rundll32.exe "[%SYSTEM%]\wobowedi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zipivohun=Rundll32.exe "[%SYSTEM%]\gitoribo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3993d819-0006-484d-afb8-97dea49a15b7}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, behuvitun={3993d819-0006-484d-afb8-97dea49a15b7}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F968860.exe=[%PROFILE_TEMP%]\_A00F968860.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F7E912F.exe=[%PROFILE_TEMP%]\_A00F7E912F.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00FB36C9.exe=[%PROFILE_TEMP%]\_A00FB36C9.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F658CD3.exe=[%PROFILE_TEMP%]\_A00F658CD3.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F472538F.exe=[%PROFILE_TEMP%]\_A00F472538F.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00FA6F34.exe=[%PROFILE_TEMP%]\_A00FA6F34.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F9F63B.exe=[%PROFILE_TEMP%]\_A00F9F63B.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F31E83E.exe=[%PROFILE_TEMP%]\_A00F31E83E.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F11A035.exe=[%PROFILE_TEMP%]\_A00F11A035.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F1B6DCA.exe=[%PROFILE_TEMP%]\_A00F1B6DCA.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F643B2.exe=[%PROFILE_TEMP%]\_A00F643B2.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F9036F.exe=[%PROFILE_TEMP%]\_A00F9036F.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F447803.exe=[%PROFILE_TEMP%]\_A00F447803.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F55240A2.exe=[%PROFILE_TEMP%]\_A00F55240A2.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F27326C.exe=[%PROFILE_TEMP%]\_A00F27326C.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F5638C5E.exe=[%PROFILE_TEMP%]\_A00F5638C5E.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F365D0D.exe=[%PROFILE_TEMP%]\_A00F365D0D.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F47BC4.exe=[%PROFILE_TEMP%]\_A00F47BC4.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F948935.exe=[%PROFILE_TEMP%]\_A00F948935.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F610A182.exe=[%PROFILE_TEMP%]\_A00F610A182.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F93792C.exe=[%PROFILE_TEMP%]\_A00F93792C.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F441858A.exe=[%PROFILE_TEMP%]\_A00F441858A.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F5998080.exe=[%PROFILE_TEMP%]\_A00F5998080.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F16883F.exe=[%PROFILE_TEMP%]\_A00F16883F.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F43489.exe=[%PROFILE_TEMP%]\_A00F43489.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F221E02.exe=[%PROFILE_TEMP%]\_A00F221E02.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F1E25C21.exe=[%PROFILE_TEMP%]\_A00F1E25C21.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F6E31F.exe=[%PROFILE_TEMP%]\_A00F6E31F.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xjopulamolima=rundll32.exe "[%WINDOWS%]\olibuxeyakiwiki.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gibofawef=Rundll32.exe "[%SYSTEM%]\tuduriro.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {dd20edcd-ef3d-4c95-836c-7861d5065875}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lezuvekij={dd20edcd-ef3d-4c95-836c-7861d5065875}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lusakilotu=Rundll32.exe "mawaboga.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Runonce=[%SYSTEM%]\runouce.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {487C9905-26A8-42C8-8033-C58AD3D2AEC3}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {3CCDF8CE-C339-4DD6-AD4F-CA7230C7E2F2}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B0B3393C-62D1-44D8-ABF5-08E0F067F29E}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, qolvmm=RUNDLL32.EXE [%SYSTEM%]\msjcfilp.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,MEDxVWqzgF
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gyunelapelepi=rundll32.exe "[%WINDOWS%]\uwukogikewejo.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Amifelu=rundll32.exe "[%WINDOWS%]\iranatana.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nasedafin=Rundll32.exe "[%SYSTEM%]\vanabesa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {888a3978-34b9-4c69-97fa-b7194b0dfcb4}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yegayozor={888a3978-34b9-4c69-97fa-b7194b0dfcb4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fobomumoy=Rundll32.exe "[%SYSTEM%]\miyowepa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ce935202-37a6-4401-9be0-f908297079be}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, miwonusey={ce935202-37a6-4401-9be0-f908297079be}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Runonce=[%SYSTEM%]\runouce.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, titerutal=Rundll32.exe "[%SYSTEM%]\vebufewo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9808038b-606b-4cc2-af6b-7c7a2cedb0c5}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hehozulal={9808038b-606b-4cc2-af6b-7c7a2cedb0c5}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winqre32.rom,lpOYRGq
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\awtuvUMD.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumazimif=Rundll32.exe "[%SYSTEM%]\nigokeyo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumazimif=Rundll32.exe "[%SYSTEM%]\povukide.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f9240105-3316-4999-a9f7-3443e4d0a924}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yuteyubod={f9240105-3316-4999-a9f7-3443e4d0a924}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fvatucobu=rundll32.exe "[%WINDOWS%]\obubulezelag.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uruzeni=rundll32.exe "[%WINDOWS%]\oqexuzay.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumazimif=Rundll32.exe "[%SYSTEM%]\gibokiho.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zukazaros=Rundll32.exe "[%SYSTEM%]\yuhoraki.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nerusasaz=Rundll32.exe "[%SYSTEM%]\dihatobi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fusakeyuy=Rundll32.exe "[%SYSTEM%]\manujusa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a4ba372a-13ac-4903-ad38-36d0d67c4b9e}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yiheneron={a4ba372a-13ac-4903-ad38-36d0d67c4b9e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\ligijowe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8d140d66-654a-46e1-a67b-2a1971819ac6}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, davakugib={8d140d66-654a-46e1-a67b-2a1971819ac6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bvavovuv=rundll32.exe "[%WINDOWS%]\azovugiyarikom.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fudazoned=Rundll32.exe "[%SYSTEM%]\talefake.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4bb0224f-afc7-4a0c-8f3e-54a540f3d327}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, diworigun={4bb0224f-afc7-4a0c-8f3e-54a540f3d327}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wjowumafu=rundll32.exe "[%WINDOWS%]\uyiqaxuw.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Wxiyuyeve=rundll32.exe "[%WINDOWS%]\utucijez.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hayunasew=Rundll32.exe "[%SYSTEM%]\newuhawe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {38854704-1c70-4b7d-b53b-7fa0a5a964cd}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yopukuyaw={38854704-1c70-4b7d-b53b-7fa0a5a964cd}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zuzilajen=Rundll32.exe "[%SYSTEM%]\lofogoru.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c2aba724-2b20-4ba1-bc1b-0008701fc89c}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, horeledot={c2aba724-2b20-4ba1-bc1b-0008701fc89c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, davonuful=Rundll32.exe "[%SYSTEM%]\biwiluga.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {03a03f8a-9967-4892-b271-95202a759605}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yopikupef={03a03f8a-9967-4892-b271-95202a759605}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gotekerit=Rundll32.exe "[%SYSTEM%]\zosapoho.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f1e285c7-6f85-474a-a796-788fa8f1110d}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kowatehig={f1e285c7-6f85-474a-a796-788fa8f1110d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loguyowoz=Rundll32.exe "[%SYSTEM%]\senukare.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {67fa497f-9913-4b9e-a0d1-b7a4abbcee04}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jigojepey={67fa497f-9913-4b9e-a0d1-b7a4abbcee04}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nerusasaz=Rundll32.exe "[%SYSTEM%]\zewobihu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ca1bcdd7-e599-442e-97bc-66a4824bdf10}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zikokumij={ca1bcdd7-e599-442e-97bc-66a4824bdf10}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vowakuruy=Rundll32.exe "[%SYSTEM%]\logapoyi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e19c9ab2-af2a-4b8a-aa52-493b8ba2eaa6}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yodamonul={e19c9ab2-af2a-4b8a-aa52-493b8ba2eaa6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lugonehaz=Rundll32.exe "[%SYSTEM%]\yujukumi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lugonehaz=Rundll32.exe "[%SYSTEM%]\yesigoju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4b74a78f-3780-4ad4-b117-8a124fa17c26}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yujilopih={4b74a78f-3780-4ad4-b117-8a124fa17c26}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7442d4b1-4e3d-466a-962b-00dcaa439abc}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wenomosif={7442d4b1-4e3d-466a-962b-00dcaa439abc}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {254d05ef-db7e-4592-9c5d-c2ac5ac451d7}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, namasebeb={254d05ef-db7e-4592-9c5d-c2ac5ac451d7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {11b31885-6c14-40e6-9f12-27424fa07540}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hagabeyol={11b31885-6c14-40e6-9f12-27424fa07540}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9c44a098-798e-47d6-9ad5-1a927be6e04b}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, verebased={9c44a098-798e-47d6-9ad5-1a927be6e04b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1d4c591a-947b-4adc-bf9a-ed661cd00a36}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jekolajot={1d4c591a-947b-4adc-bf9a-ed661cd00a36}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b72dbbb1-aef0-4779-b192-f160d217653e}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gadamumub={b72dbbb1-aef0-4779-b192-f160d217653e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lugonehaz=Rundll32.exe "[%SYSTEM%]\ninegozu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hzekovehulat=rundll32.exe "[%WINDOWS%]\ologuqutoqihoj.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, Ywikuculihi=rundll32.exe "[%WINDOWS%]\ejihusucamunum.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loguyowoz=Rundll32.exe "[%SYSTEM%]\yitifuvu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2fba79ce-2fd4-4fa6-ae2b-b34b1246fb2f}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, buvofaluf={2fba79ce-2fd4-4fa6-ae2b-b34b1246fb2f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 08f37a09=rundll32.exe "[%SYSTEM%]\btlhhkme.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, folayedur=Rundll32.exe "[%SYSTEM%]\hajajepo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumumakah=Rundll32.exe "[%SYSTEM%]\welemige.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dakopihow=Rundll32.exe "[%SYSTEM%]\rojisabo.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winldd32.rom,pPZLxFoueiuY
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, nukuvahoji=Rundll32.exe "lapomefe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, makowokas=Rundll32.exe "[%SYSTEM%]\falojoho.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7cbbfe94-6d15-482c-97cf-746d0722125a}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tuhanajep={7cbbfe94-6d15-482c-97cf-746d0722125a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kodomimut=Rundll32.exe "[%SYSTEM%]\lofuwogi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0cdf252b-b1b9-4313-9f50-3f82a651c7ea}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dusumakuz={0cdf252b-b1b9-4313-9f50-3f82a651c7ea}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, puhajodov=Rundll32.exe "[%SYSTEM%]\fafaropu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cfa13d77-af43-4eb8-a8d9-1fab2974ec34}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bayuranov={cfa13d77-af43-4eb8-a8d9-1fab2974ec34}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {595bdcd7-2368-422e-b44a-b04c476c79a0}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, getegewag={595bdcd7-2368-422e-b44a-b04c476c79a0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a111d09a-0882-46ea-a8de-81c3cfd63581}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yisofalih={a111d09a-0882-46ea-a8de-81c3cfd63581}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {29326bc7-d306-4d1d-8fe2-b9779091dbc9}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dogetusey={29326bc7-d306-4d1d-8fe2-b9779091dbc9}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1a439fa8-a5b4-4f8e-ade7-ded5e420bb1e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kenafavom={1a439fa8-a5b4-4f8e-ade7-ded5e420bb1e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {eacfe6c5-a638-4df2-a095-a32573dd2d70}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hupipidih={eacfe6c5-a638-4df2-a095-a32573dd2d70}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f79195e8-e193-4a9f-b3a2-d47e81459b1b}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dofobobas={f79195e8-e193-4a9f-b3a2-d47e81459b1b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a4d09cbf-f4cb-4ba0-b863-4523c9009048}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dezirisof={a4d09cbf-f4cb-4ba0-b863-4523c9009048}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a3017954-4fd4-407d-9e7f-96026d7ea59a}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rerimitow={a3017954-4fd4-407d-9e7f-96026d7ea59a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Abohawepewapafi=rundll32.exe "[%WINDOWS%]\edonecekiriyi.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rewalasazi=Rundll32.exe "juvuselu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, semesubuz=Rundll32.exe "[%SYSTEM%]\wigimogo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {226def97-ce5e-49cf-bea2-db3148a72f79}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yozinoson={226def97-ce5e-49cf-bea2-db3148a72f79}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Eteruzuhoveh=rundll32.exe "[%WINDOWS%]\uzuvebuq.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfcb32.rom,LhxQoNyzAuR
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didizazug=Rundll32.exe "[%SYSTEM%]\vevesojo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {28790db1-ca97-4f99-801f-a71cc0e3c90c}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, puzemohay={28790db1-ca97-4f99-801f-a71cc0e3c90c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rebuninat=Rundll32.exe "[%SYSTEM%]\jesonowe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cb460d89-2d18-4fa6-b656-26d6fa9fde03}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, retofaheh={cb460d89-2d18-4fa6-b656-26d6fa9fde03}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyuvibog=Rundll32.exe "[%COMMON_APPDATA%]\jifibiti\jifibiti.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, misamikafi=Rundll32.exe "[%COMMON_APPDATA%]\raniyiyi\raniyiyi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\fozehuka.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3a79b78a-cdee-4383-96e9-a070d740089d}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zonaropib={3a79b78a-cdee-4383-96e9-a070d740089d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\viyiyini.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1ce92b50-18db-4a8f-ad6c-dc8610556e97}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, depihigof={1ce92b50-18db-4a8f-ad6c-dc8610556e97}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, viweromem=Rundll32.exe "[%SYSTEM%]\gadagore.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {619fb94c-755a-45f9-9357-fae992d0a16e}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gozayuwon={619fb94c-755a-45f9-9357-fae992d0a16e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMb7bdb247=Rundll32.exe "[%SYSTEM%]\fokipize.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, b48e81db=rundll32.exe "[%SYSTEM%]\nazehogi.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hiyelisovi=Rundll32.exe "[%SYSTEM%]\jepafuzi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fobomumoy=Rundll32.exe "[%SYSTEM%]\vamodimu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ba95f70f-9a88-4779-bb6e-1c20d9ced01e}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sababidej={ba95f70f-9a88-4779-bb6e-1c20d9ced01e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jiwiyodov=Rundll32.exe "[%SYSTEM%]\newoyiju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0dc29710-d19c-4d1c-87ab-933d58fa68ed}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lebisutoj={0dc29710-d19c-4d1c-87ab-933d58fa68ed}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jiwiyodov=Rundll32.exe "[%SYSTEM%]\natulevo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {27141a26-332d-4913-9016-009e50af9377}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dumasobug={27141a26-332d-4913-9016-009e50af9377}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nbinajijoh=rundll32.exe "[%WINDOWS%]\ikolacihir.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, talokover=Rundll32.exe "[%SYSTEM%]\gekuhiri.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loguyowoz=Rundll32.exe "[%SYSTEM%]\lamisefi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7a01279b-e669-4080-9e77-c32303715091}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vuwayevog={7a01279b-e669-4080-9e77-c32303715091}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, taziwetoj=Rundll32.exe "[%SYSTEM%]\kiwasuge.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMcfca230f=Rundll32.exe "[%SYSTEM%]\bozoyipo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ccf91093=rundll32.exe "[%SYSTEM%]\muwevola.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rotatigov=Rundll32.exe "[%SYSTEM%]\muyinepa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {602a741e-1ba8-4b7f-929b-5821b4269c1a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dodudogeh={602a741e-1ba8-4b7f-929b-5821b4269c1a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kqihudiwo=rundll32.exe "[%WINDOWS%]\ihabacaxoza.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kodomimut=Rundll32.exe "[%SYSTEM%]\gekujoni.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {62e6a7ef-e2f6-4e66-8b4e-5fe41c40ffdc}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, futobeyod={62e6a7ef-e2f6-4e66-8b4e-5fe41c40ffdc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Epefawegumesaw=rundll32.exe "[%WINDOWS%]\usefozujecazuwip.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bnawo=rundll32.exe "[%WINDOWS%]\uhedesuv.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bjudukaqibiyov=rundll32.exe "[%WINDOWS%]\uzoxaboko.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tazazatem=Rundll32.exe "[%SYSTEM%]\pedisasa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6863f0ee-12fb-4ade-9996-12403ac37d51}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rurowules={6863f0ee-12fb-4ade-9996-12403ac37d51}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kavowibabu=Rundll32.exe "fezovezi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zalopiniz=Rundll32.exe "[%SYSTEM%]\tanetezo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {085cc590-9684-4ac3-9447-33384f345885}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wohususej={085cc590-9684-4ac3-9447-33384f345885}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E4EEFFED-93CD-4CF0-A0F3-50D139121FEE}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8ea86503-476f-476a-a55a-7225082df3eb}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {be7e4ce1-8cba-44a6-956f-462a667d3286}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rupurovak=Rundll32.exe "[%SYSTEM%]\porevujo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bad05b46-76fe-4b2d-b04d-2e376ed64410}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lubizotum={bad05b46-76fe-4b2d-b04d-2e376ed64410}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, luvawokam=Rundll32.exe "[%SYSTEM%]\sofigeda.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rxecesuxid=rundll32.exe "[%WINDOWS%]\alokumip.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\juvuselu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ce5d8819-9b5a-41d3-a60e-6afcd2fa521b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hipivipug={ce5d8819-9b5a-41d3-a60e-6afcd2fa521b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didizazug=Rundll32.exe "[%SYSTEM%]\yofolufe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b121b839-1bc0-4b0c-80c1-f173c3987752}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vitokopaj={b121b839-1bc0-4b0c-80c1-f173c3987752}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zejojugaz=Rundll32.exe "[%SYSTEM%]\nigokeyo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pozahelah=Rundll32.exe "[%SYSTEM%]\zulahigu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d14ccbfb-3f7d-4cb5-8925-1b2239327593}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zovotafiw={d14ccbfb-3f7d-4cb5-8925-1b2239327593}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winkcz32.rom,IspeQMjducr
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zetuliwud=Rundll32.exe "[%SYSTEM%]\gokehama.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8f29ca1e-9209-4550-993c-6aa9146ecfca}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lesoruwim={8f29ca1e-9209-4550-993c-6aa9146ecfca}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sojujawoh=Rundll32.exe "[%SYSTEM%]\vamegeye.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c8b96d5d-c42c-484e-8acc-c727c8527b38}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gevedozoz={c8b96d5d-c42c-484e-8acc-c727c8527b38}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bugegilis=Rundll32.exe "[%SYSTEM%]\torazovi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fuvujefivu=Rundll32.exe "yolobohi.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {97e84bb5-b74f-46fd-8855-403bba900d9a}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gasebotum={97e84bb5-b74f-46fd-8855-403bba900d9a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {75b35a0f-59b4-4247-b703-7b3ebe03fbca}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rajonigod={75b35a0f-59b4-4247-b703-7b3ebe03fbca}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9629550b-1a15-47f6-b006-004887b7b919}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hewolimon={9629550b-1a15-47f6-b006-004887b7b919}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, 8a9f381d=rundll32.exe "[%SYSTEM%]\lbfteals.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, faviwebuv=Rundll32.exe "[%SYSTEM%]\bizijeju.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\geBtQkJy.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\iifefGwU.dll,c
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cc369b12=rundll32.exe "[%PROFILE_TEMP%]\rginuphv.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, cmds=rundll32.exe [%PROFILE_TEMP%]\jkkJcCrr.dll,c
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\toborebu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, boyanakak=Rundll32.exe "[%SYSTEM%]\sovowuyi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cfdddf55-e734-4f2f-91b6-97cfd89a3de0}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mekimomiz={cfdddf55-e734-4f2f-91b6-97cfd89a3de0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nipatepaj=Rundll32.exe "[%SYSTEM%]\jatereya.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {654d1e97-93d0-48ab-984b-cc34e8028247}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pufijonim={654d1e97-93d0-48ab-984b-cc34e8028247}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nulewezew=Rundll32.exe "[%SYSTEM%]\nukatojo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {83316e8f-483f-4a4c-9c15-8ee5047c6bed}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vejatihob={83316e8f-483f-4a4c-9c15-8ee5047c6bed}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fputecik=rundll32.exe "[%WINDOWS%]\eretigok.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didizazug=Rundll32.exe "[%SYSTEM%]\rezubeza.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {42feb8ac-03b9-479e-81ba-a43d481d8f4e}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bipupojes={42feb8ac-03b9-479e-81ba-a43d481d8f4e}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F79F3C9.exe=[%PROFILE_TEMP%]\_A00F79F3C9.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hibesesob=Rundll32.exe "[%SYSTEM%]\yetevato.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jiwiyodov=Rundll32.exe "[%SYSTEM%]\seruyone.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2f030ebf-6b8b-4874-81e2-fb67c5991118}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, munuloruz={2f030ebf-6b8b-4874-81e2-fb67c5991118}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winpdc32.rom,nSgngyW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM83d86f9f=Rundll32.exe "[%SYSTEM%]\lasofesu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 80eb5c03=rundll32.exe "[%SYSTEM%]\fatenuva.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, voditaguj=Rundll32.exe "[%SYSTEM%]\keyutova.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {91717354-624a-4637-8864-2d2fdae76c39}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jatowivib={91717354-624a-4637-8864-2d2fdae76c39}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nukuvahoji=Rundll32.exe "lapomefe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nukuvahoji=Rundll32.exe "lapomefe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winilr32.rom,tbRosDg
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nfufa=rundll32.exe "[%WINDOWS%]\uwefuqoqiwogijan.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uyixaneyulexahe=rundll32.exe "[%WINDOWS%]\Fdozul.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, talokover=Rundll32.exe "[%SYSTEM%]\zititohu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a54c9588-4e63-402d-9a0d-1842d431758a}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, buhafulot={a54c9588-4e63-402d-9a0d-1842d431758a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loguyowoz=Rundll32.exe "[%SYSTEM%]\vadawife.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8930887e-0db7-46bd-a9d8-57753da57535}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vadonosog={8930887e-0db7-46bd-a9d8-57753da57535}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, faviwebuv=Rundll32.exe "[%SYSTEM%]\rutihuku.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fedb80c0-2798-4b27-bb70-7f266bfbd71b}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hopekilod={fedb80c0-2798-4b27-bb70-7f266bfbd71b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Jtowazaq=rundll32.exe "[%WINDOWS%]\exebupic.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sedewagid=Rundll32.exe "[%SYSTEM%]\vuyugije.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {09c72999-5c10-41a3-a524-24661d942003}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {8A61098D-612B-4EF2-943D-64E920684061}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {7f3ea905-de65-4d00-bc1f-ff3a77f8ca30}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {10b5e5c2-8901-4e3c-bf61-ac6e11039292}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {d2376fb3-3d0d-414d-83aa-3ad6ad6b111f}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,hqhmFqWgapW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumazimif=Rundll32.exe "[%SYSTEM%]\detezada.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {25134772-932d-42a7-8c61-67ffee944045}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hedineteh={25134772-932d-42a7-8c61-67ffee944045}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, koharuvud=Rundll32.exe "[%SYSTEM%]\nebiteda.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rhifugowizew=rundll32.exe "[%WINDOWS%]\ivipitucigenog.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gusujodip=Rundll32.exe "[%SYSTEM%]\wolohuse.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gusujodip=Rundll32.exe "[%SYSTEM%]\jolemovu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a02dba5a-16dd-4a0b-8a2c-a9852167d659}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gunulisij={a02dba5a-16dd-4a0b-8a2c-a9852167d659}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c86f6bf4-d017-45bf-94a5-035038882058}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dawuyafuk={c86f6bf4-d017-45bf-94a5-035038882058}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gusujodip=Rundll32.exe "[%SYSTEM%]\kusewovi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fofusokima=Rundll32.exe "[%SYSTEM%]\piragobo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yepinusek=Rundll32.exe "[%SYSTEM%]\saperiho.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qpavubalikoqatu=rundll32.exe "[%WINDOWS%]\edikelikufev.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, popoyeyeh=Rundll32.exe "[%SYSTEM%]\fesuwugo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0a4d581a-bb7b-4e6b-9620-f00f23a72578}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, soduwakal={0a4d581a-bb7b-4e6b-9620-f00f23a72578}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cf949617-9aa0-44a2-a625-eecab56cd357}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, defolemey={cf949617-9aa0-44a2-a625-eecab56cd357}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didizazug=Rundll32.exe "[%SYSTEM%]\gigopero.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b7bc8b6c-1cc5-426e-88ff-053422b6eb3c}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kihedorug={b7bc8b6c-1cc5-426e-88ff-053422b6eb3c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didizazug=Rundll32.exe "[%SYSTEM%]\doriyubi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ad8f9217-31fd-4644-b96d-a8324d6d0675}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yuheyorit={ad8f9217-31fd-4644-b96d-a8324d6d0675}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didizazug=Rundll32.exe "[%SYSTEM%]\wobezozu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6eb35ff2-c91d-4727-b3fa-a8b3f48da068}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, goyazifiy={6eb35ff2-c91d-4727-b3fa-a8b3f48da068}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, muzohomeb=Rundll32.exe "[%SYSTEM%]\fosifopu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, ruhayajij=Rundll32.exe "[%SYSTEM%]\miyowepa.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rejahawen=Rundll32.exe "[%SYSTEM%]\sokoyeji.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Etuyixezib=rundll32.exe "[%WINDOWS%]\odukumipobe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gotinowef=Rundll32.exe "[%SYSTEM%]\worajiju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9848afdd-87e0-4f33-80e0-b8c4ddcbc024}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, buvibafey={9848afdd-87e0-4f33-80e0-b8c4ddcbc024}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pebivozod=Rundll32.exe "[%SYSTEM%]\juwefisi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e677953a-440d-4b78-aa79-7cb026cf6f82}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, morazobuf={e677953a-440d-4b78-aa79-7cb026cf6f82}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gosunowip=Rundll32.exe "[%SYSTEM%]\fidezeta.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, henewonara=Rundll32.exe "rulisofo.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {844a66c8-bee0-4be1-b1ad-b22feb9c54ab}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yilabaviy={844a66c8-bee0-4be1-b1ad-b22feb9c54ab}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vramosexasuxomo=rundll32.exe "[%WINDOWS%]\elufatah.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Elesixor=rundll32.exe "[%WINDOWS%]\uwiruwokuqis.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wududamam=Rundll32.exe "[%SYSTEM%]\rilalelu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ef81fb80-dd53-4a84-98e6-1d4930317a39}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sulekoziw={ef81fb80-dd53-4a84-98e6-1d4930317a39}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, miramobum=Rundll32.exe "[%SYSTEM%]\zomumuzo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f17fa9f1-cf81-4c79-81ee-f8702735cf3c}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lowiwafef={f17fa9f1-cf81-4c79-81ee-f8702735cf3c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tujizafir=Rundll32.exe "[%SYSTEM%]\toyutabo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lulikeven=Rundll32.exe "[%SYSTEM%]\jekatuji.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fe7f6905-7cd1-4d60-b5e5-9f024420ee6f}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tejiwudek={fe7f6905-7cd1-4d60-b5e5-9f024420ee6f}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f1072ba8-d585-4904-aacb-34224cacb870}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jedemutaz={f1072ba8-d585-4904-aacb-34224cacb870}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hujehapok=Rundll32.exe "[%SYSTEM%]\garizugo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vikudotezi=Rundll32.exe "himepuka.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {96edce64-70a7-4221-85e0-1baf5706a5ca}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mehamedif={96edce64-70a7-4221-85e0-1baf5706a5ca}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fobomumoy=Rundll32.exe "[%SYSTEM%]\vepuhuje.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {32c0bfd6-dbb0-44dc-aa63-2d8df40d22e0}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zudifovuz={32c0bfd6-dbb0-44dc-aa63-2d8df40d22e0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMbb67e5ac=Rundll32.exe "[%SYSTEM%]\wiwifezi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, b854d630=rundll32.exe "[%SYSTEM%]\lutovute.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sugidahafi=Rundll32.exe "[%SYSTEM%]\sevikuji.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\jkkHWNDw.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zetuliwud=Rundll32.exe "[%SYSTEM%]\gepesiso.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {010083aa-7dd4-4851-8c73-485fadd7f50c}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vanupisus={010083aa-7dd4-4851-8c73-485fadd7f50c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, MSServer=rundll32.exe [%SYSTEM%]\ssqRJccA.dll,#1
Scan your system registry for FREE

Comments

