Top 10 virus alerts
Latest 10 malware files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e3ca95fd-3f4d-4e7b-9a89-fce0e4b92e69}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zazuvowen={e3ca95fd-3f4d-4e7b-9a89-fce0e4b92e69}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {f7f6584c-864b-411d-a410-bb2de0d33ca1}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {f53bafe5-ce7a-4e95-95ac-a3912efd3739}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {d7fd6c15-4927-4aae-bf12-fbdabd287eb1}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {3F9D0C61-737D-44D1-BD80-91AF857061CC}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wintvo32.rom,opgcQN
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, odqlmj=RUNDLL32.EXE [%SYSTEM%]\msfplkqs.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winzfx32.rom,lINFiCCYZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pubizetar=Rundll32.exe "[%COMMON_APPDATA%]\firowazo\firowazo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, walanufad=Rundll32.exe "[%SYSTEM%]\fupikoti.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, liyuwuviho=Rundll32.exe "tomipojo.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {28df8e7f-ae64-45ba-aeec-a4ab2a9fc0b6}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, niripuyuy={28df8e7f-ae64-45ba-aeec-a4ab2a9fc0b6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1d278bcf-eca2-43a0-9761-9cdc6461f7d7}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pozofibos={1d278bcf-eca2-43a0-9761-9cdc6461f7d7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {09708d7d-58e0-4914-b80e-663a82f0cd57}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tudezapit={09708d7d-58e0-4914-b80e-663a82f0cd57}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4e5d60f5-fb79-4345-833d-3f39efd4b729}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tayajanuz={4e5d60f5-fb79-4345-833d-3f39efd4b729}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ca46731c-4618-43d2-a0bb-ee2a4c9f5eea}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, banamugey={ca46731c-4618-43d2-a0bb-ee2a4c9f5eea}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winhmp32.rom,wQUIZlKZ
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winguc32.rom,vAmXjLAcsgvU
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kizalihod=Rundll32.exe "[%SYSTEM%]\dodedeva.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6b33d4a9-b181-469a-83a6-249fbd8bad8b}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tebozazaz={6b33d4a9-b181-469a-83a6-249fbd8bad8b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM4feeb940=Rundll32.exe "[%SYSTEM%]\kawepibo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 4cdd8adc=rundll32.exe "[%SYSTEM%]\vutanoko.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rowevojolo=Rundll32.exe "[%SYSTEM%]\dijanumo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tahafanir=Rundll32.exe "[%SYSTEM%]\pofegohu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {88235fb3-1457-4acd-afe8-0cc5bec78884}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, garuyahoz={88235fb3-1457-4acd-afe8-0cc5bec78884}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ajudelewizuteroy=rundll32.exe "[%WINDOWS%]\ulamigobabamisa.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fataniyez=Rundll32.exe "[%SYSTEM%]\sikiruyu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4fb8517b-3a8c-4843-b193-6553f429464c}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ketinigap={4fb8517b-3a8c-4843-b193-6553f429464c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mekivefef=Rundll32.exe "[%SYSTEM%]\vohikesu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {be816ec2-15d1-48f0-9301-f700236875e7}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, desakakuk={be816ec2-15d1-48f0-9301-f700236875e7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfetesiyovup=rundll32.exe "[%WINDOWS%]\opiluheq.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ikigoqeziwakeco=rundll32.exe "[%WINDOWS%]\ikatanabonata.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winxfp32.rom,HTyVqvYuuLD
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F3E437.exe=[%PROFILE_TEMP%]\_A00F3E437.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F6ADD6.exe=[%PROFILE_TEMP%]\_A00F6ADD6.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F35A75.exe=[%PROFILE_TEMP%]\_A00F35A75.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F2AF4141.exe=[%PROFILE_TEMP%]\_A00F2AF4141.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F4AD63.exe=[%PROFILE_TEMP%]\_A00F4AD63.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F45754.exe=[%PROFILE_TEMP%]\_A00F45754.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dowibesuv=Rundll32.exe "[%SYSTEM%]\jojekode.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zijizisul=Rundll32.exe "[%SYSTEM%]\gururalu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Swejudenenorix=rundll32.exe "[%WINDOWS%]\adetufum.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mulemabam=Rundll32.exe "[%SYSTEM%]\yakituro.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9f8e6434-615a-45a0-99d7-0ee84cdc6ac3}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, leporiduj={9f8e6434-615a-45a0-99d7-0ee84cdc6ac3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Inazegopep=rundll32.exe "[%WINDOWS%]\ayonufuqoseje.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mupugaponi=Rundll32.exe "[%SYSTEM%]\fofufenu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ajosepaz=rundll32.exe "[%WINDOWS%]\areliyojoqoziyi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 443bb754=rundll32.exe "[%SYSTEM%]\hfyitple.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Csafiqamabimon=rundll32.exe "[%WINDOWS%]\axegesagubinago.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, helatadaz=Rundll32.exe "[%SYSTEM%]\luhuwuji.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {eb5eda22-6c5e-4111-a66e-d09bddce4e81}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hamikuwiy={eb5eda22-6c5e-4111-a66e-d09bddce4e81}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nodijukot=Rundll32.exe "[%SYSTEM%]\kegovahe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9bcd7af2-2670-4da5-ab6d-622b0f17bccb}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jefisulak={9bcd7af2-2670-4da5-ab6d-622b0f17bccb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yavukudud=Rundll32.exe "[%SYSTEM%]\ruketifu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a61a6d0f-0efa-4c45-9a65-2ed8c66981ea}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yovuzimub={a61a6d0f-0efa-4c45-9a65-2ed8c66981ea}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Olububitu=rundll32.exe "[%WINDOWS%]\eyotokesikomeje.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kwimaw=rundll32.exe "[%WINDOWS%]\ilamerihes.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dumivasoz=Rundll32.exe "[%SYSTEM%]\pihuwali.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {af460e1c-834b-49fa-95dc-83415122ca36}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pegaliyim={af460e1c-834b-49fa-95dc-83415122ca36}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {453f51e8-fef5-4c54-b136-944bf434360c}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dilobihol=Rundll32.exe "[%SYSTEM%]\bihomimo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rebadufimi=Rundll32.exe "[%SYSTEM%]\vivopiye.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM73c50bc7=Rundll32.exe "[%SYSTEM%]\huhugafe.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wutugehafi=Rundll32.exe "[%SYSTEM%]\fuyisajo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lurinozol=Rundll32.exe "[%SYSTEM%]\vuvijora.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2c80bb70-d1b7-4fd1-853d-d0746bb80f22}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, likohudow={2c80bb70-d1b7-4fd1-853d-d0746bb80f22}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yusasehab=Rundll32.exe "[%SYSTEM%]\tidahahi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4b48bb70-d075-4b1f-a0a3-e3ec87bcf819}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gusihekuk={4b48bb70-d075-4b1f-a0a3-e3ec87bcf819}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, damifebef=Rundll32.exe "[%SYSTEM%]\giwohide.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6865e6d1-3332-4009-8fab-f844358f4ecd}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pehibinog={6865e6d1-3332-4009-8fab-f844358f4ecd}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yavukudud=Rundll32.exe "[%SYSTEM%]\ripubato.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {08b2d443-8601-4d4b-97ab-f46189ceeeff}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, govimibey={08b2d443-8601-4d4b-97ab-f46189ceeeff}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jawutisoli=Rundll32.exe "bulopazo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rdafebiwel=rundll32.exe "[%WINDOWS%]\ucocixaf.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\khfETnnN.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, e024d77a=rundll32.exe "[%PROFILE_TEMP%]\nwokgsdt.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjfr32.rom,LkECcWGMLWCQ
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, habasewun=Rundll32.exe "[%SYSTEM%]\kinahoke.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, habasewun=Rundll32.exe "[%SYSTEM%]\kinahoke.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 37c52f9d=rundll32.exe "[%SYSTEM%]\yumuyofu.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Phitiquyepiy=rundll32.exe "[%WINDOWS%]\dsl3dp.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pesunuvuna=Rundll32.exe "[%SYSTEM%]\yavafike.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pesunuvuna=Rundll32.exe "[%COMMON_APPDATA%]\luparepu\luparepu.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f3fc4421-b75e-463f-ba15-97a3b761826f}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rerakaway={f3fc4421-b75e-463f-ba15-97a3b761826f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM8f66e2f6=Rundll32.exe "[%SYSTEM%]\lobekata.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 8c55d16a=rundll32.exe "[%SYSTEM%]\dsateahg.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hahikohimi=Rundll32.exe "[%SYSTEM%]\rulisofo.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrso32.rom,BLobfVOR
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Abibuneh=rundll32.exe "[%WINDOWS%]\Yqexiger.dat",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {81ea3f36-357a-435a-8741-52c27ccc9f21}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {d85530e8-d39d-49d0-9f36-300d594556d2}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tyoyigowelijosi=rundll32.exe "[%WINDOWS%]\uquwaceh.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lurinozol=Rundll32.exe "[%SYSTEM%]\warihagi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3f6882bf-31d3-4dff-8e18-86a2103d7204}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zayelemed={3f6882bf-31d3-4dff-8e18-86a2103d7204}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yolenuwuy=Rundll32.exe "[%SYSTEM%]\halojoge.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sukugavuy=Rundll32.exe "[%SYSTEM%]\nojutoko.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8c715394-b1b0-48b7-b558-931a6cb24063}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fiturigah={8c715394-b1b0-48b7-b558-931a6cb24063}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wavozonus=Rundll32.exe "[%SYSTEM%]\yidusaze.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjes32.rom,lcibJKdV
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hxesohayeridasib=rundll32.exe "[%WINDOWS%]\evegofud.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yavukudud=Rundll32.exe "[%SYSTEM%]\rutirawi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4f4a817c-23a6-4cf3-8cc8-ac06441b5100}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gawetosum={4f4a817c-23a6-4cf3-8cc8-ac06441b5100}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfcb32.rom,FCXtlWaB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\xxyyvWMd.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ccc6d73c=rundll32.exe "[%SYSTEM%]\swqjsrgw.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bobehuheb=Rundll32.exe "[%SYSTEM%]\mosowisi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6010243b-d45e-4b03-8999-260141b28be0}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mewuzomow={6010243b-d45e-4b03-8999-260141b28be0}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wivovewej=Rundll32.exe "[%COMMON_APPDATA%]\jajulaze\jajulaze.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wotosisim=Rundll32.exe "[%SYSTEM%]\lehebofi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {078f507c-6c63-432a-9b1a-b897d2e92b26}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yuyedugap={078f507c-6c63-432a-9b1a-b897d2e92b26}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nuvebanubo=Rundll32.exe "firupifo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dovubenib=Rundll32.exe "[%SYSTEM%]\jogejase.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {12b06159-8fcb-423c-bfcb-2cfa4aa46a10}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nobabotid={12b06159-8fcb-423c-bfcb-2cfa4aa46a10}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {e9bd0828-1fd9-410c-a50f-43ebe65d310f}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {ebf1652d-fc54-4654-8738-55a21a0b520b}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dhnsog=RUNDLL32.EXE [%SYSTEM%]\msrtmzzk.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuyuvibog=Rundll32.exe "[%COMMON_APPDATA%]\hitivora\hitivora.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, misamikafi=Rundll32.exe "[%COMMON_APPDATA%]\gutodayo\gutodayo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMb75c8184=Rundll32.exe "[%SYSTEM%]\bopinati.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lowasarezu=Rundll32.exe "[%SYSTEM%]\bapugoki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yesavalav=Rundll32.exe "[%SYSTEM%]\jefaduku.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {03ab482b-e286-4474-9a6b-57c9ff315da6}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bimigomek={03ab482b-e286-4474-9a6b-57c9ff315da6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {585cf776-b14e-45f4-be8d-d5f1adf0873d}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fihegudef={585cf776-b14e-45f4-be8d-d5f1adf0873d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yusasehab=Rundll32.exe "[%SYSTEM%]\tizomahu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cf03c1a1-c22a-47d1-a5d5-a6b0e2395a9f}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tejugehuk={cf03c1a1-c22a-47d1-a5d5-a6b0e2395a9f}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hafekafahi=Rundll32.exe "[%SYSTEM%]\rofenima.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hafekafahi=Rundll32.exe "[%SYSTEM%]\rofenima.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gabebegim=Rundll32.exe "[%SYSTEM%]\bikojoki.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM9f51616c=Rundll32.exe "[%SYSTEM%]\wewidilu.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rujezimiv=Rundll32.exe "[%COMMON_APPDATA%]\yuguvine\yuguvine.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dahanorika=Rundll32.exe "[%COMMON_APPDATA%]\gopeyuye\gopeyuye.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zaguyotil=Rundll32.exe "[%SYSTEM%]\hatasefa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {039566a0-5d6a-416b-97d0-37a99fe012c6}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zebugehid={039566a0-5d6a-416b-97d0-37a99fe012c6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Abofudik=rundll32.exe "[%WINDOWS%]\opevigulusefub.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bemubolan=Rundll32.exe "[%SYSTEM%]\wisepale.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b7f3065e-1036-4807-aca7-f02c17101d1c}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dakisuguz={b7f3065e-1036-4807-aca7-f02c17101d1c}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pubizetar=Rundll32.exe "[%COMMON_APPDATA%]\yadihoni\yadihoni.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM0b0493c6=Rundll32.exe "[%SYSTEM%]\hadezabi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 0837a05a=rundll32.exe "[%SYSTEM%]\selekide.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, johiwifufi=Rundll32.exe "[%SYSTEM%]\zepepewa.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winldd32.rom,zAaMXsfedI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Ndiwuguxavi=rundll32.exe "[%WINDOWS%]\eseyafupe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Swejudenenorix=rundll32.exe "[%WINDOWS%]\ewidamuj.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, donisozay=Rundll32.exe "[%SYSTEM%]\fanifito.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8741062e-9a24-4337-bf65-0f9d239b087d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wunonekiz={8741062e-9a24-4337-bf65-0f9d239b087d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dumivasoz=Rundll32.exe "[%SYSTEM%]\rilihoki.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c12d3aa3-b835-41fa-9834-5a5b744a656f}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lusazerod={c12d3aa3-b835-41fa-9834-5a5b744a656f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, makiwoped=Rundll32.exe "[%SYSTEM%]\jemukuwo.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfpw32.rom,YLIQbGZHlHSD
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfi32.rom,gXexdz
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wineez32.rom,ZIlWuHLkOB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {fff29be4-24ac-4e31-b99b-45238b764111}=
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pihofikene=Rundll32.exe "[%COMMON_APPDATA%]\nilimuvo\nilimuvo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sylonz=RUNDLL32.EXE [%SYSTEM%]\msdmgvzq.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yjiceq=rundll32.exe "[%WINDOWS%]\upoyogomu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, b0b4b3b6=rundll32.exe "[%SYSTEM%]\pokitiwi.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pamiliviwa=Rundll32.exe "[%SYSTEM%]\diyobela.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uvuqigegopepub=rundll32.exe "[%WINDOWS%]\erufoqipofevinuy.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jatigoren=Rundll32.exe "[%SYSTEM%]\wevoyira.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8a09dabb-4630-46e2-b321-912bcf8d5afc}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jotamidoj={8a09dabb-4630-46e2-b321-912bcf8d5afc}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pubizetar=Rundll32.exe "[%COMMON_APPDATA%]\bigitita\bigitita.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, feboboken=Rundll32.exe "[%SYSTEM%]\nesasawe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {05ac1f39-e83b-4a9d-b320-466907cfaf67}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dusitefiw={05ac1f39-e83b-4a9d-b320-466907cfaf67}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gerevenas=Rundll32.exe "[%SYSTEM%]\hisozopa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fe016694-9e0a-4259-8fa7-98cd8136dae4}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nonazabiv={fe016694-9e0a-4259-8fa7-98cd8136dae4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hovobejar=Rundll32.exe "[%SYSTEM%]\makatizi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, degejibaf=Rundll32.exe "[%SYSTEM%]\makatizi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c7ca316b-ace3-4c56-9b66-2dcbd67efd6b}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fagavehet={c7ca316b-ace3-4c56-9b66-2dcbd67efd6b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f65447d2-cfc8-4362-84c2-d3a490c772f1}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, golahezih={f65447d2-cfc8-4362-84c2-d3a490c772f1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7904f16f-7549-4119-8619-ee00f2ddb313}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sikazejew={7904f16f-7549-4119-8619-ee00f2ddb313}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2d0c2b99-73b5-4351-bb45-46180b47aed6}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fowuyetos={2d0c2b99-73b5-4351-bb45-46180b47aed6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {dc758e03-7a32-4464-b45a-5858c91c9b23}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yenitateh={dc758e03-7a32-4464-b45a-5858c91c9b23}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3d14bb14-9aa1-4a9d-aa1d-5dbaa94dc548}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wumeyekuh={3d14bb14-9aa1-4a9d-aa1d-5dbaa94dc548}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ac001096-f68a-47fe-b798-3c4437eb5abb}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dugatiriv={ac001096-f68a-47fe-b798-3c4437eb5abb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dizumazul=Rundll32.exe "[%SYSTEM%]\muzurimo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1faece0d-522a-422f-8055-a4662ee89f78}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nagewirog={1faece0d-522a-422f-8055-a4662ee89f78}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yusasehab=Rundll32.exe "[%SYSTEM%]\wowinule.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a4269e42-15e7-4b2e-8c03-af0a452a11ae}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hofedediy={a4269e42-15e7-4b2e-8c03-af0a452a11ae}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, luvejugov=Rundll32.exe "[%SYSTEM%]\najeduni.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5a5dfa11-aa11-423c-be30-5a83331d564d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rukobakuv={5a5dfa11-aa11-423c-be30-5a83331d564d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3c4906ce-7cb5-48fd-acc3-4d0da7814f6d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dularibad={3c4906ce-7cb5-48fd-acc3-4d0da7814f6d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bcd18212-4031-4bb0-b142-a558d154852e}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nizofihid={bcd18212-4031-4bb0-b142-a558d154852e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c4651c94-b332-4a6c-b79d-00a471b101e2}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yolodiwan={c4651c94-b332-4a6c-b79d-00a471b101e2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pokilomek=Rundll32.exe "[%SYSTEM%]\diyohobe.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fniron=B:\RUNDLL32.EXE [%SYSTEM%]\mskluuku.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, akycos=B:\RUNDLL32.EXE [%SYSTEM%]\msybexig.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dhnsog=B:\RUNDLL32.EXE [%SYSTEM%]\msrtmzzk.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, himukujaw=Rundll32.exe "[%SYSTEM%]\bamukitu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hovobejar=Rundll32.exe "[%SYSTEM%]\yugovuji.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {dc1dc4cb-b386-4de9-bcbc-e6e79668d74d}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hapalibel={dc1dc4cb-b386-4de9-bcbc-e6e79668d74d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yavukudud=Rundll32.exe "[%SYSTEM%]\terobila.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fe36bb61-16ec-4657-a074-191e49b0e97c}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, filigohal={fe36bb61-16ec-4657-a074-191e49b0e97c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jawuzobeg=Rundll32.exe "[%SYSTEM%]\davafuhu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {45e74309-7ed0-4581-9caf-705389b32033}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rarukimig={45e74309-7ed0-4581-9caf-705389b32033}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zapedonofe=Rundll32.exe "rilihoki.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zapedonofe=Rundll32.exe "rilihoki.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Acuzogoloputuye=rundll32.exe "[%WINDOWS%]\okavokit.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, serisejeh=Rundll32.exe "[%SYSTEM%]\sebajuyo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0bde4f89-7910-4d7e-a8aa-8f5fd675ba98}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, siwiweyey={0bde4f89-7910-4d7e-a8aa-8f5fd675ba98}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lurinozol=Rundll32.exe "[%SYSTEM%]\yupujufo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {545b9c7f-a796-4975-83d6-cb673769a041}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nopilutoj={545b9c7f-a796-4975-83d6-cb673769a041}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rkuhelaguzeya=rundll32.exe "[%WINDOWS%]\otukumibol.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Hidden, Gwawoqihojis=rundll32.exe "[%WINDOWS%]\uvoratiqefamete.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Gwawoqihojis=rundll32.exe "[%WINDOWS%]\uvoratiqefamete.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hagiyevaj=Rundll32.exe "[%SYSTEM%]\vozaposo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f53d99c0-02a4-4c9a-8a2d-4605e51defc0}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pubutawek={f53d99c0-02a4-4c9a-8a2d-4605e51defc0}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F499AD5.exe=[%PROFILE_TEMP%]\_A00F499AD5.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, papazuler=Rundll32.exe "[%SYSTEM%]\gobirahu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {57161bbb-60e3-4d41-9d8c-0c24f6421a2c}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, baweninut={57161bbb-60e3-4d41-9d8c-0c24f6421a2c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jawuzobeg=Rundll32.exe "[%SYSTEM%]\fesisone.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7e13f3e5-6485-4e1f-8af8-e5424558c4a2}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wohemitij={7e13f3e5-6485-4e1f-8af8-e5424558c4a2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, feboboken=Rundll32.exe "[%SYSTEM%]\vuvimuwe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fee28bf3-9968-4f50-b2ae-f9ea90cc5f0a}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, witupibis={fee28bf3-9968-4f50-b2ae-f9ea90cc5f0a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hidavivum=Rundll32.exe "[%SYSTEM%]\jodunufe.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, goliripif=Rundll32.exe "[%SYSTEM%]\mebapiro.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ece67162-115a-4d9c-af65-d173f05f8fd3}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lazewoluv={ece67162-115a-4d9c-af65-d173f05f8fd3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vpefo=rundll32.exe "[%WINDOWS%]\ozovedecotezi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zudomesag=Rundll32.exe "[%SYSTEM%]\yuwefayi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hakegolos=Rundll32.exe "[%SYSTEM%]\migunugo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {51238295-1a6a-44d0-8b1d-c98b86c6759c}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dosogotud={51238295-1a6a-44d0-8b1d-c98b86c6759c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gimanitos=Rundll32.exe "[%SYSTEM%]\yajafewa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f6f2f14b-64e7-460d-a217-6e39fc6f86f9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pakiwegap={f6f2f14b-64e7-460d-a217-6e39fc6f86f9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, duwehuvuw=Rundll32.exe "[%SYSTEM%]\rinokulo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, robehiruv=Rundll32.exe "[%SYSTEM%]\pakiguwu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {ba6c6cb6-676c-4dea-9bda-3bc4ab075f7c}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9.exe=[%SYSTEM%]\YUR9.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR8.exe=[%SYSTEM%]\YUR8.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR9.exe=[%SYSTEM%]\YUR9.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR8.exe=[%SYSTEM%]\YUR8.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR7.exe=[%SYSTEM%]\YUR7.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, \YUR7.exe=[%SYSTEM%]\YUR7.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {91223de9-f8e6-4ffd-8889-be6784c18696}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pipifivaz=Rundll32.exe "[%SYSTEM%]\gulobimu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM9f145990=Rundll32.exe "[%SYSTEM%]\rotapote.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 9c276a0c=rundll32.exe "[%SYSTEM%]\bihofiye.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hanudivole=Rundll32.exe "[%SYSTEM%]\hisozopa.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pubizetar=Rundll32.exe "[%COMMON_APPDATA%]\luhuwuji\luhuwuji.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled by Starter), dhnsog=RUNDLL32.EXE [%SYSTEM%]\msrtmzzk.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nsokozuxe=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\akbrynd.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suyuselas=Rundll32.exe "[%SYSTEM%]\femawiko.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suyuselas=Rundll32.exe "[%SYSTEM%]\femawiko.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {695ccc5a-e1ee-4c7c-9b6d-85a0b10b224a}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kalumowuy={695ccc5a-e1ee-4c7c-9b6d-85a0b10b224a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yesavalav=Rundll32.exe "[%SYSTEM%]\zevitedu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM5f613092=Rundll32.exe "[%SYSTEM%]\sigolaja.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hejusawori=Rundll32.exe "[%SYSTEM%]\kawamuvo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ginihezad=Rundll32.exe "[%SYSTEM%]\najejifo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e97e6136-ec17-47e0-b595-972c8e317bbe}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kewigirut={e97e6136-ec17-47e0-b595-972c8e317bbe}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yesavalav=Rundll32.exe "[%SYSTEM%]\huyahife.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yusasehab=Rundll32.exe "[%SYSTEM%]\lotonene.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {40db2588-913a-4073-997e-b89ab1075bf1}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bimetelay={40db2588-913a-4073-997e-b89ab1075bf1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kadatazeb=Rundll32.exe "[%SYSTEM%]\waziroto.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7eea029c-91f5-4934-a74a-af3e4d89a11c}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vavujuzuz={7eea029c-91f5-4934-a74a-af3e4d89a11c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loyomuvog=Rundll32.exe "[%SYSTEM%]\bodalene.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c366e577-5d62-40bb-8664-d1ae839e2dbb}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, duduvates={c366e577-5d62-40bb-8664-d1ae839e2dbb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hubavagok=Rundll32.exe "[%SYSTEM%]\forobevo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {50eb9507-e122-4018-85eb-b62c65949335}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tidedojot={50eb9507-e122-4018-85eb-b62c65949335}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yavukudud=Rundll32.exe "[%SYSTEM%]\hatakuvu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3de63968-db57-4aa6-9b5d-5a7e500cad11}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sukapugut={3de63968-db57-4aa6-9b5d-5a7e500cad11}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rubameday=Rundll32.exe "[%SYSTEM%]\viwafinu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1c1c70e9-9c68-4749-82ff-a9c2e6085efe}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jokudokup={1c1c70e9-9c68-4749-82ff-a9c2e6085efe}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tqeravowiyeluk=rundll32.exe "[%WINDOWS%]\alufusizebazobif.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winakd32.rom,EmPLZoRKxV
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bemubolan=Rundll32.exe "[%SYSTEM%]\mebokero.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {abf3d139-6981-498b-9f74-64e57191ceff}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, temufekoh={abf3d139-6981-498b-9f74-64e57191ceff}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {92801950-7a41-40e8-a475-28e2caa782c1}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hewuvovuf={92801950-7a41-40e8-a475-28e2caa782c1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7c2e2ef3-e56f-4e6b-832a-23b38c9c1ee3}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, siburutuh={7c2e2ef3-e56f-4e6b-832a-23b38c9c1ee3}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e1a12431-a2c8-4791-897e-2a091ba0dd94}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sezurujib={e1a12431-a2c8-4791-897e-2a091ba0dd94}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bemubolan=Rundll32.exe "[%SYSTEM%]\pekedado.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8a24b29c-71f4-4117-b5b1-3105c8b18bf6}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kubohoyim={8a24b29c-71f4-4117-b5b1-3105c8b18bf6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM87fe04ee=Rundll32.exe "[%SYSTEM%]\ciqxduve.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Oyarenuwiqinoq=rundll32.exe "[%WINDOWS%]\iwicebez.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Oyarenuwiqinoq=rundll32.exe "[%WINDOWS%]\iwicebez.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhi32.rom,tsUPsqE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pozenunoh=Rundll32.exe "[%SYSTEM%]\tiwamora.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {eab6aeb2-f19d-4866-9e7e-6855e2db428b}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yeketozed={eab6aeb2-f19d-4866-9e7e-6855e2db428b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rdafebiwel=rundll32.exe "[%WINDOWS%]\izejivul.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hakegolos=Rundll32.exe "[%SYSTEM%]\kelaworu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0e46a1c1-a8e2-41b6-86f1-f483857946dc}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nuzejijon={0e46a1c1-a8e2-41b6-86f1-f483857946dc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hakegolos=Rundll32.exe "[%SYSTEM%]\huzomopo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ef43055f-a80c-4892-972f-46a47931a8fe}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pajepunuz={ef43055f-a80c-4892-972f-46a47931a8fe}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tyuhazomopajebo=rundll32.exe "[%WINDOWS%]\uhiyosam.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dumivasoz=Rundll32.exe "[%SYSTEM%]\roheteje.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, muwavogan=Rundll32.exe "[%COMMON_APPDATA%]\hupebogi\hupebogi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vovinuyig=Rundll32.exe "[%SYSTEM%]\bunefife.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8cde4611-c375-4d72-9b2c-e0ca10fea739}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, teyulusak={8cde4611-c375-4d72-9b2c-e0ca10fea739}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {9a50b2af-3b2b-47dd-aecd-5d80a886f504}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {d6aeeadc-7733-4aa6-9cc3-2a0415f73416}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5A041F13-A111-12A4-B0CF-F99818AA68A5}=ar12A40098dll.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {1ffb1a32-1d58-46cf-be8b-237586af7f2f}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, howizozub=Rundll32.exe "[%SYSTEM%]\fenufebo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gugetetavi=Rundll32.exe "deporare.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9c41af2e-46f4-4dac-8026-017c2cdd1759}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bugavotif={9c41af2e-46f4-4dac-8026-017c2cdd1759}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pebifewur=Rundll32.exe "[%SYSTEM%]\fetabeke.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suboturema=Rundll32.exe "nobajanu.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pubizetar=Rundll32.exe "[%COMMON_APPDATA%]\sejuvoma\sejuvoma.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, feboboken=Rundll32.exe "[%SYSTEM%]\podewolu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e3e126cf-0e55-40ff-b9cd-4c1144750cbc}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gekomulov={e3e126cf-0e55-40ff-b9cd-4c1144750cbc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\wvUlifGW.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zulogagad=Rundll32.exe "[%SYSTEM%]\kayufegi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f6fbf4b0-3fd3-40d6-86e4-c0803fbffd29}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jijayokit={f6fbf4b0-3fd3-40d6-86e4-c0803fbffd29}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Emetosulizeg=rundll32.exe "[%WINDOWS%]\oxihazuyosegefim.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yesavalav=Rundll32.exe "[%SYSTEM%]\kivereza.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7faba548-612c-4235-9e64-1af0ebd0a9dc}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dutiyidom={7faba548-612c-4235-9e64-1af0ebd0a9dc}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rfoyuboneravasa=rundll32.exe "[%WINDOWS%]\asugezorijegozu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nibozuwow=Rundll32.exe "[%SYSTEM%]\tizuluke.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nibozuwow=Rundll32.exe "[%SYSTEM%]\hayemave.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {18615e45-241d-462e-b8fc-fc2b906a1872}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, havejerah={18615e45-241d-462e-b8fc-fc2b906a1872}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ziniguyen=Rundll32.exe "[%SYSTEM%]\bulopazo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pirenulup=Rundll32.exe "[%SYSTEM%]\sojerire.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {37233754-535c-4f84-b390-ebcc7dc7a03d}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mabadaser={37233754-535c-4f84-b390-ebcc7dc7a03d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, efoelq=RUNDLL32.EXE [%SYSTEM%]\msmxiodm.dll,w
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrso32.rom,XRmlRstWetAE
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F36EA5F.exe=[%PROFILE_TEMP%]\_A00F36EA5F.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wuyibagib=Rundll32.exe "[%SYSTEM%]\dobazusi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {34e7c060-463c-4da5-8f82-bc1e3b615886}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gahogebej={34e7c060-463c-4da5-8f82-bc1e3b615886}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yiwuyahik=Rundll32.exe "[%SYSTEM%]\wohobiye.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {eec7bdad-c197-494f-9ed6-05162b338eba}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zijubowiw={eec7bdad-c197-494f-9ed6-05162b338eba}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dbopegu=rundll32.exe "[%WINDOWS%]\isaciduwato.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dugipuzel=Rundll32.exe "[%SYSTEM%]\rogavove.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kwimaw=rundll32.exe "[%WINDOWS%]\aqerabat.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rwejatumoyesi=rundll32.exe "[%WINDOWS%]\iqabupiceric.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {C84D8A0A-E708-42B6-90CA-9C30956A87C6}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5A041F13-A111-12A4-B0CF-F99818AA68A5}=ar12A40097dll.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tqammy=RUNDLL32.EXE [%SYSTEM%]\msaouahn.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, telosipiyi=Rundll32.exe "wofihalo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, doniriwimi=Rundll32.exe "[%SYSTEM%]\verarozu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hisorirat=Rundll32.exe "[%SYSTEM%]\lewabenu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Twopepopeg=rundll32.exe "[%WINDOWS%]\opemizuf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pebifewur=Rundll32.exe "[%SYSTEM%]\nabojaga.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suboturema=Rundll32.exe "getuyiza.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yusasehab=Rundll32.exe "[%SYSTEM%]\jihakera.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e8c06371-1ced-4635-bfde-8540c5f44d87}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, birayafok={e8c06371-1ced-4635-bfde-8540c5f44d87}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pubizetar=Rundll32.exe "[%COMMON_APPDATA%]\rikojine\rikojine.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pihofikene=Rundll32.exe "[%COMMON_APPDATA%]\fugafizu\fugafizu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lebilazit=Rundll32.exe "[%SYSTEM%]\kokufara.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kasahanogi=Rundll32.exe "palifomu.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {63c666ee-d53a-4c0d-8eb9-b7573bad1cf1}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kejojihoj={63c666ee-d53a-4c0d-8eb9-b7573bad1cf1}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, telosipiyi=Rundll32.exe "wofihalo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hakegolos=Rundll32.exe "[%SYSTEM%]\gopubeme.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\povukide.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a604bd8b-4ff8-4f94-be55-d95cf65f541b}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yakedosof={a604bd8b-4ff8-4f94-be55-d95cf65f541b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dumivasoz=Rundll32.exe "[%SYSTEM%]\zijotijo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e8d8b864-7c25-41a2-bc42-2b7da57430be}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pomonizuf={e8d8b864-7c25-41a2-bc42-2b7da57430be}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zulogagad=Rundll32.exe "[%SYSTEM%]\yapipije.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c518f5a1-9aec-4c94-a7e9-b8a1bea7a633}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ligakavuh={c518f5a1-9aec-4c94-a7e9-b8a1bea7a633}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tqammy=RUNDLL32.EXE [%PROFILE_TEMP%]\msaouahn.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tregehejo=rundll32.exe "[%WINDOWS%]\axifusizebazobif.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yesavalav=Rundll32.exe "[%SYSTEM%]\nefilepu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, riguhowom=Rundll32.exe "[%SYSTEM%]\pihuwali.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ec9aaae3-6d75-45af-b3e5-51b6aa43c9aa}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zoyefodon={ec9aaae3-6d75-45af-b3e5-51b6aa43c9aa}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Hvowuco=rundll32.exe "[%WINDOWS%]\etagifobawut.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vujevuvan=Rundll32.exe "[%SYSTEM%]\sisifeme.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3b9dd8e3-b2d9-4255-9fed-56c5393d666e}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wudofofuz={3b9dd8e3-b2d9-4255-9fed-56c5393d666e}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mtevusadiyurega=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\KBDeOG2.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pikusukor=Rundll32.exe "[%SYSTEM%]\jimikesu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {1d531771-1ad5-4f27-87a2-6980501f9703}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zafofovom=Rundll32.exe "[%SYSTEM%]\gayihiga.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7dbf9b8d-1110-4996-9ffd-2b78ee1ac56d}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zibigayur={7dbf9b8d-1110-4996-9ffd-2b78ee1ac56d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {299b5fac-2168-4a5d-a67d-aa4c8f8055da}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, eopwag=RUNDLL32.EXE [%SYSTEM%]\msgmegdj.dll,w
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tguyafiqemaqa=rundll32.exe "[%WINDOWS%]\uwerecom.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\hutijezu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7ab8e4b7-e005-40f9-b894-c0630bc0430e}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gobuvasor={7ab8e4b7-e005-40f9-b894-c0630bc0430e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yusasehab=Rundll32.exe "[%SYSTEM%]\detukimi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c3198f2e-26ed-4c47-b50f-74df2c8ca2bf}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, geroruret={c3198f2e-26ed-4c47-b50f-74df2c8ca2bf}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mayitumop=Rundll32.exe "[%SYSTEM%]\dasobave.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMe7500b7c=Rundll32.exe "[%SYSTEM%]\bapenuge.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bokituyak=Rundll32.exe "[%COMMON_APPDATA%]\vuwafaji\vuwafaji.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bokituyak=Rundll32.exe "[%COMMON_APPDATA%]\vuwafaji\vuwafaji.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {33ab9c60-e0b6-4208-bec8-139f5f4a698e}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wodamotey={33ab9c60-e0b6-4208-bec8-139f5f4a698e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hakegolos=Rundll32.exe "[%SYSTEM%]\dojiralo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0ef65830-757e-4aa0-b89d-877252033785}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hupizonug={0ef65830-757e-4aa0-b89d-877252033785}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\vawopijo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3de08940-21e4-4be9-bac6-b98035de8a07}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, werunuliw={3de08940-21e4-4be9-bac6-b98035de8a07}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Srugopaniyaw=rundll32.exe "[%WINDOWS%]\iqorucatofokeyi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xsuyoqutunagec=rundll32.exe "[%WINDOWS%]\Wpehoq.dat",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zafofovom=Rundll32.exe "[%SYSTEM%]\togehupe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {13f1d182-755b-4da4-b940-c1c68ba9c53d}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, luvibalub={13f1d182-755b-4da4-b940-c1c68ba9c53d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zafofovom=Rundll32.exe "[%SYSTEM%]\takavere.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cfc90ab3-6ea2-4d38-95b7-6e9ce3e261af}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ganafebek={cfc90ab3-6ea2-4d38-95b7-6e9ce3e261af}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {04ebc576-e4d6-484d-874b-dd3120631380}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jatevusiy={04ebc576-e4d6-484d-874b-dd3120631380}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {69adeca7-6b0a-47e2-84ed-9e0bc393558f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, najewebij={69adeca7-6b0a-47e2-84ed-9e0bc393558f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\laluhowo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Twopepopeg=rundll32.exe "[%WINDOWS%]\opemizuf.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, muwakifot=Rundll32.exe "[%SYSTEM%]\samorasa.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, newuzihad=Rundll32.exe "[%SYSTEM%]\wutorame.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f85cc9d4-1296-4b18-9a7d-bd1b2d6a3f7e}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zarimanil={f85cc9d4-1296-4b18-9a7d-bd1b2d6a3f7e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ddac6fa2-5e93-4916-8a0e-df03d2dd413e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mejagawiz={ddac6fa2-5e93-4916-8a0e-df03d2dd413e}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fe9f1255-9c0a-4c4e-852f-2d53ee74015b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gijusoreb={fe9f1255-9c0a-4c4e-852f-2d53ee74015b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\tenugizu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e853a66d-a92c-4b84-af26-45435e73c599}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, joyimubiy={e853a66d-a92c-4b84-af26-45435e73c599}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zafofovom=Rundll32.exe "[%SYSTEM%]\wudokaha.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {66a6c455-31c0-4367-bab4-81628fd83d21}=jugezatag
Scan your system registry for FREE

Comments

