Top 10 virus alerts
Latest 10 malware files
Testimonials
You guys are freakin' awesome, love the program, love the personalized service, and my pc loves it too :D
Justin S.
Vundo (Virtumondo) Registry Values
Scan your Windows registry for Vundo (Virtumondo)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mcibiwon=rundll32.exe "[%WINDOWS%]\Rruhujuze.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wahivinake=Rundll32.exe "[%SYSTEM%]\domemaha.dll",s
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, noyeduliki=Rundll32.exe "[%SYSTEM%]\yetevato.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, noyeduliki=Rundll32.exe "[%SYSTEM%]\yetevato.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mihipamus=Rundll32.exe "[%SYSTEM%]\lumuheze.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7cb681a3-a812-41aa-ac58-a6b5b75023ed}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kiwupumiy={7cb681a3-a812-41aa-ac58-a6b5b75023ed}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, boyemedes=Rundll32.exe "[%SYSTEM%]\todolaze.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\gobewowi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bda89cc1-efbe-42ad-a66c-0340dab4f856}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ripejogil={bda89cc1-efbe-42ad-a66c-0340dab4f856}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, avd32=[%SYSTEM%]\avd32.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 20399511=rundll32.exe "[%PROFILE_TEMP%]\ancuaigs.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM230aa68d=Rundll32.exe "[%PROFILE_TEMP%]\jynlxfin.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {1764af3f-400c-415e-9a92-67a7d55c2c71}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Olububitu=rundll32.exe "[%WINDOWS%]\izupijovapu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zefebozoz=Rundll32.exe "[%SYSTEM%]\tuledagi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bb4c798c-8786-4241-9c64-2deec945ba08}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, beropoley={bb4c798c-8786-4241-9c64-2deec945ba08}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {35921f66-2bf8-43b3-9a76-723b10833c73}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vuyenofoj={35921f66-2bf8-43b3-9a76-723b10833c73}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b401a2c1-f24a-4aea-a02d-ccc9348612c5}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mukaniyuk={b401a2c1-f24a-4aea-a02d-ccc9348612c5}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kimiwuduf=Rundll32.exe "[%SYSTEM%]\dobayovu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2037a1cb-9aa8-456a-8fa4-41ddb37ed088}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, namotepaj={2037a1cb-9aa8-456a-8fa4-41ddb37ed088}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, 643046dd=rundll32.exe "[%PROFILE_TEMP%]\domlhgsq.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fulugajig=Rundll32.exe "[%SYSTEM%]\fotuvoyi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4b3d267d-f69b-4fad-a865-ab547c5a6553}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rapemubes={4b3d267d-f69b-4fad-a865-ab547c5a6553}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zulogagad=Rundll32.exe "[%SYSTEM%]\nafiwezu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\midegida.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {57fd75de-8c5c-4534-bbf4-36c096e4608a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yokurotej={57fd75de-8c5c-4534-bbf4-36c096e4608a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\nigokeyo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {40781337-e56c-4041-9a31-5359c7464769}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bilonihuf={40781337-e56c-4041-9a31-5359c7464769}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, donisozay=Rundll32.exe "[%SYSTEM%]\wimavapa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {68bc18c0-2a6d-4780-a9b5-fab76b59b71a}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, migoyiyum={68bc18c0-2a6d-4780-a9b5-fab76b59b71a}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yupofukane=Rundll32.exe "[%SYSTEM%]\nelezuga.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yupofukane=Rundll32.exe "[%SYSTEM%]\nelezuga.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lipufohuk=Rundll32.exe "[%SYSTEM%]\fabeluva.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d7268612-1254-4e83-8df5-82cfa076df0a}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wiruyutoz={d7268612-1254-4e83-8df5-82cfa076df0a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Regedit32=[%SYSTEM%]\regedit.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Calc32=[%SYSTEM%]\regedit.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, judejerej=Rundll32.exe "[%SYSTEM%]\yejedotu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jayaseyohu=Rundll32.exe "vajetezo.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cdfd2cf0-622f-4204-bd3e-235fe92c2b2d}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sitokodey={cdfd2cf0-622f-4204-bd3e-235fe92c2b2d}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yuzikifey=Rundll32.exe "[%SYSTEM%]\vedilune.dll",a
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tunobejoko=Rundll32.exe "[%SYSTEM%]\wisepale.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tunobejoko=Rundll32.exe "[%SYSTEM%]\wisepale.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\biheseya.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {178ef7a7-8a9c-468b-b753-9402d651df40}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, numolewif={178ef7a7-8a9c-468b-b753-9402d651df40}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winfbc32.rom,qALpmKtOl
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Njube=rundll32.exe "[%WINDOWS%]\eyaxomod.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\zowepaba.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {11863fad-4b4f-48e9-8d9d-0c158372fbe4}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jowigudam={11863fad-4b4f-48e9-8d9d-0c158372fbe4}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vopunikot=Rundll32.exe "[%SYSTEM%]\finobefe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {286fc8d6-42a7-49f0-a63c-1c65b1c1f238}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vazayesez={286fc8d6-42a7-49f0-a63c-1c65b1c1f238}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F1013E6E.exe=[%PROFILE_TEMP%]\_A00F1013E6E.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tateyalus=Rundll32.exe "[%SYSTEM%]\zehigipu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d0ead469-5569-4b54-a617-29e3ee033534}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dapenadof={d0ead469-5569-4b54-a617-29e3ee033534}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qcekesi=rundll32.exe "[%WINDOWS%]\otiviyifani.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\sazusuye.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {edd95e1a-1181-423d-a315-17437c368268}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lizimosiy={edd95e1a-1181-423d-a315-17437c368268}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, dumivasoz=Rundll32.exe "[%SYSTEM%]\sujejawo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f05fa1fb-636e-4395-a0b8-62bc572a4c86}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dogopiroh={f05fa1fb-636e-4395-a0b8-62bc572a4c86}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F45CD2.exe=[%PROFILE_TEMP%]\_A00F45CD2.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sinamiguf=Rundll32.exe "[%SYSTEM%]\pimenuda.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {dfb61d00-4808-4ae8-8815-d282bd85f2ce}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dojutayoj={dfb61d00-4808-4ae8-8815-d282bd85f2ce}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, didetavop=Rundll32.exe "[%SYSTEM%]\hagiyobi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {356f3c9d-453e-465c-9b5b-e20c7e6b721e}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gesonuhup={356f3c9d-453e-465c-9b5b-e20c7e6b721e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM2b873904=Rundll32.exe "[%SYSTEM%]\jesafijo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 28b40a98=rundll32.exe "[%SYSTEM%]\ripubato.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Tcizenoyiv=rundll32.exe "[%WINDOWS%]\edacoyucegaq.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Nholoxufapifovav=rundll32.exe "[%WINDOWS%]\Mdibebufebosuy.dat",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sebihihire=Rundll32.exe "[%SYSTEM%]\vegozadi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fmawubalikoq=rundll32.exe "[%WINDOWS%]\eheruculihiwe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Lgebuhelico=rundll32.exe "[%WINDOWS%]\uputaciwimanites.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\wepejapu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6d0b589b-e81a-4839-9e9e-d3bedc19ac69}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vejepelel={6d0b589b-e81a-4839-9e9e-d3bedc19ac69}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\mitihuho.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {26d6c9f3-d45d-48c6-9253-f71f1c8a5674}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lawofuvat={26d6c9f3-d45d-48c6-9253-f71f1c8a5674}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winvhi32.rom,faQesvrJZqSk
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bpuperokow=rundll32.exe "[%WINDOWS%]\igejafab.dll",e
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jusotabok=Rundll32.exe "[%SYSTEM%]\litunude.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {88fbf50b-3066-456b-a0e3-8418d78cc8eb}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pawogozab={88fbf50b-3066-456b-a0e3-8418d78cc8eb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zoyiwutus=Rundll32.exe "[%SYSTEM%]\hakolike.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bemubolan=Rundll32.exe "[%SYSTEM%]\govegomu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0df16bd6-f9d8-4cfa-9d7e-0e0ea17823bb}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tekatoket={0df16bd6-f9d8-4cfa-9d7e-0e0ea17823bb}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pipifivaz=Rundll32.exe "[%SYSTEM%]\vetuyija.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, johirezit=Rundll32.exe "[%SYSTEM%]\buyivalo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f53b9e77-a668-44f3-a086-cf90e01d7269}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, laramizet={f53b9e77-a668-44f3-a086-cf90e01d7269}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sofihohab=Rundll32.exe "[%SYSTEM%]\duyagawe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d6bf2b08-62e7-42e4-b4f3-6ed9eac41700}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fufenuwon={d6bf2b08-62e7-42e4-b4f3-6ed9eac41700}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {aae51deb-7851-4bf6-96b1-8ee682aab297}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, farireruj={aae51deb-7851-4bf6-96b1-8ee682aab297}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7ab12627-c32d-493e-a4f4-9b986f8f4fa6}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sekunivuw={7ab12627-c32d-493e-a4f4-9b986f8f4fa6}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {e47dc560-ce66-4ace-aa2b-82d5a8a0fe52}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jikegelin={e47dc560-ce66-4ace-aa2b-82d5a8a0fe52}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {18586bf5-542c-4b58-b0fc-0a7844ea96fd}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, turofegol={18586bf5-542c-4b58-b0fc-0a7844ea96fd}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {daf09e5a-ded4-4bcc-be7b-438064975e30}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zurumunod={daf09e5a-ded4-4bcc-be7b-438064975e30}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {eaca8299-969a-433c-9011-4623a625c0a5}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fezefayab={eaca8299-969a-433c-9011-4623a625c0a5}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {95551a6b-4656-4aa2-bd87-d995de1352a1}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yetorirup={95551a6b-4656-4aa2-bd87-d995de1352a1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d33c020d-3978-4318-a3fa-d1b70bf5f43c}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kapetipub={d33c020d-3978-4318-a3fa-d1b70bf5f43c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {88632ba2-ecaf-444f-9849-001e4a213d58}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zarunupap={88632ba2-ecaf-444f-9849-001e4a213d58}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {27c7dfea-7302-49c1-bb19-c776956fb6bb}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, devewizem={27c7dfea-7302-49c1-bb19-c776956fb6bb}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {57693b0f-f2bd-46c9-9148-6204ec3fda51}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, biwihekon={57693b0f-f2bd-46c9-9148-6204ec3fda51}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a3b75f0a-4e7a-42b3-84ee-cb6e32cbc0be}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tujozuway={a3b75f0a-4e7a-42b3-84ee-cb6e32cbc0be}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bmune=rundll32.exe "[%WINDOWS%]\ekodadotibuxer.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Upunupeyeguwiviy=rundll32.exe "[%WINDOWS%]\urunulamolim.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RUN-, 000000af=rundll32.exe "[%SYSTEM%]\nykgfgna.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zoletawor=Rundll32.exe "[%SYSTEM%]\fomasopi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b276eb76-acc0-40f9-a676-4f66bd54777f}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rolasonup={b276eb76-acc0-40f9-a676-4f66bd54777f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\kabetunu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b8c71b43-fe56-4faf-bfe3-cd44113342a2}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nusamodir={b8c71b43-fe56-4faf-bfe3-cd44113342a2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Azuhecaguhimuhab=rundll32.exe "[%WINDOWS%]\ipobajoganisap.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, duwenifuv=Rundll32.exe "[%SYSTEM%]\hesudipi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f0ca5b44-ef32-42bc-9d34-c46f80290f5a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pofipinur={f0ca5b44-ef32-42bc-9d34-c46f80290f5a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tetobafeh=Rundll32.exe "[%SYSTEM%]\barihuye.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {97320203-54b9-4ef4-9f8c-998df11dbd9b}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, payahinen={97320203-54b9-4ef4-9f8c-998df11dbd9b}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tudidujos=Rundll32.exe "[%SYSTEM%]\nunayeta.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8f18c5b9-1ed1-42c2-96fe-d63957dd4da1}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vibawejes={8f18c5b9-1ed1-42c2-96fe-d63957dd4da1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b9b40294-c9ca-4a49-bf4e-f5b9c7665476}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, runudupat={b9b40294-c9ca-4a49-bf4e-f5b9c7665476}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {44971e22-65c7-4af6-a7f8-c132f0295db0}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vemelikib={44971e22-65c7-4af6-a7f8-c132f0295db0}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {1ea55601-e64c-4ddb-a3d8-fabd80024578}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kohimapud={1ea55601-e64c-4ddb-a3d8-fabd80024578}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4dd7eb8d-926e-4b18-82dd-008ff5ed916c}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gimopaleh={4dd7eb8d-926e-4b18-82dd-008ff5ed916c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tifamipidu=Rundll32.exe "[%SYSTEM%]\fatodogi.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbiy32.rom,aGJUCMOiGumH
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sinamiguf=Rundll32.exe "[%SYSTEM%]\jowuhese.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {b2085166-aeb7-4567-bb0e-43fd74a6d8f7}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zuyusinar={b2085166-aeb7-4567-bb0e-43fd74a6d8f7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\sunimuju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9836b53c-a14d-464c-b787-682c7721ed1e}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lurofozib={9836b53c-a14d-464c-b787-682c7721ed1e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\fehijagu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {723a6a44-652f-4846-ae0d-bcf6fbd60554}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rofimamip={723a6a44-652f-4846-ae0d-bcf6fbd60554}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumurugid=Rundll32.exe "[%SYSTEM%]\fofedafe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {16d2e301-a4a5-4ca3-9031-7feaa5f9d3b7}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, diyuladop={16d2e301-a4a5-4ca3-9031-7feaa5f9d3b7}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2af4ecb6-597d-41c3-9918-e06ecff412cb}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yarewawas={2af4ecb6-597d-41c3-9918-e06ecff412cb}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loduzufan=Rundll32.exe "[%COMMON_APPDATA%]\mulumobu\mulumobu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gupaziduga=Rundll32.exe "jejesahe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gupaziduga=Rundll32.exe "jejesahe.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pipifivaz=Rundll32.exe "[%SYSTEM%]\huhukuge.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Uyoparaqesac=rundll32.exe "[%SYSTEM%]\config\systemprofile\AppData\Local\mg2rs09.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM4300fdc4=Rundll32.exe "[%SYSTEM%]\zomutaho.dll",a
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suwemosule=Rundll32.exe "[%SYSTEM%]\reviyifu.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, suwemosule=Rundll32.exe "[%SYSTEM%]\reviyifu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\khfCssQG.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 255a1bc5=rundll32.exe "[%SYSTEM%]\ndefncpn.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\zegofadu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {77a2108d-a0e4-4ea6-9f6c-606e3905fde0}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wajumuhas={77a2108d-a0e4-4ea6-9f6c-606e3905fde0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\pedisasa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {a6ef13dc-3147-4b85-a669-2f91ae534723}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, natakajoy={a6ef13dc-3147-4b85-a669-2f91ae534723}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fkuhomixefen=rundll32.exe "[%WINDOWS%]\olacuhay.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lisabiwam=Rundll32.exe "[%SYSTEM%]\yokelase.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {39859530-bbe4-4ea5-bf6d-ef069548ff80}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, degugonij={39859530-bbe4-4ea5-bf6d-ef069548ff80}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F19A16180.exe=[%PROFILE_TEMP%]\_A00F19A16180.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {1c218bc1-b339-40df-8346-792d2dbaffb5}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E271F4E9-D46E-4C7A-8608-AFDD4A87E582}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wshost32=[%SYSTEM%]\wshost32.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Rrujunumatoya=rundll32.exe "[%WINDOWS%]\ucomarigafeyuzub.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, birunusib=Rundll32.exe "[%SYSTEM%]\monajole.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ae373f06-6c7c-4681-9223-1df8324fb5e9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fahowikez={ae373f06-6c7c-4681-9223-1df8324fb5e9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tagokayuz=Rundll32.exe "[%SYSTEM%]\tunirufa.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {4152e46b-2e04-4eba-ba23-b834785dcb01}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zonedinaj={4152e46b-2e04-4eba-ba23-b834785dcb01}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\puzominu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9297e44c-2fe9-45eb-9162-7520ad454a0c}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nohesaneg={9297e44c-2fe9-45eb-9162-7520ad454a0c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pufebahon=Rundll32.exe "[%SYSTEM%]\notabage.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0107e9b5-2ce1-4969-bed3-4c931903fa01}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, melefikug={0107e9b5-2ce1-4969-bed3-4c931903fa01}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Bbexuyaf=rundll32.exe "[%WINDOWS%]\okabepaguheyek.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yalavides=Rundll32.exe "[%SYSTEM%]\reyosite.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {17cbcd9c-ad64-4290-9c35-bc961da4303c}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gejejofej={17cbcd9c-ad64-4290-9c35-bc961da4303c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\jefosodi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d8ebfec1-ade5-4fb7-87e4-58f3df0f712a}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yumizajit={d8ebfec1-ade5-4fb7-87e4-58f3df0f712a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\kuzeyogi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {77bc8d43-c443-48d7-93b2-928ee4f7f7ab}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jenodawaz={77bc8d43-c443-48d7-93b2-928ee4f7f7ab}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ladivemos=Rundll32.exe "[%SYSTEM%]\dovinabu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, siwepepis=Rundll32.exe "[%SYSTEM%]\nagewati.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {47eb607b-4dd1-4ed7-8344-b9afd9b7d898}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vafotowev={47eb607b-4dd1-4ed7-8344-b9afd9b7d898}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zilelurov=Rundll32.exe "[%SYSTEM%]\jijejeju.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0e2ca730-453c-4855-a38c-365fd5ace1bd}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pisayoroh={0e2ca730-453c-4855-a38c-365fd5ace1bd}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {823ea984-f2a0-470b-928d-77dc39059087}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vakuseguy={823ea984-f2a0-470b-928d-77dc39059087}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0c5c7c98-5b5e-4993-9fbb-b92099b52a55}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sirawuvoy={0c5c7c98-5b5e-4993-9fbb-b92099b52a55}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73870a4e-2212-4d18-b9f8-b5455dea816a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nokitijet={73870a4e-2212-4d18-b9f8-b5455dea816a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6900fd6c-636c-47eb-8a91-f910587039d5}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wipepisow={6900fd6c-636c-47eb-8a91-f910587039d5}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kjopesojolo=rundll32.exe "[%WINDOWS%]\ozaxozoquqisef.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM8b20bfaf=Rundll32.exe "[%SYSTEM%]\vopuvemi.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 88138c33=rundll32.exe "[%SYSTEM%]\yagepodo.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tohenehaba=Rundll32.exe "[%SYSTEM%]\limowuyu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\efcAQJcy.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\monelare.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d0784e0e-45fb-4555-88f8-22b7d86ce04f}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yayayanod={d0784e0e-45fb-4555-88f8-22b7d86ce04f}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Qjinufica=rundll32.exe "[%WINDOWS%]\aletedabexobe.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, larujomah=Rundll32.exe "[%SYSTEM%]\dobojobe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {89235a7a-3be8-4baf-9c88-fe6136a8e373}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kukaviluj={89235a7a-3be8-4baf-9c88-fe6136a8e373}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {C5E84927-CFF0-4CA3-A068-02E7C01C1E7C}=
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f0ca5b44-ef32-42bc-9d34-c46f80290f5a}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vepejotet={f0ca5b44-ef32-42bc-9d34-c46f80290f5a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\nefuwipi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6a41f8f8-186f-4759-bfc0-4118ab4c9fe7}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hodikipuj={6a41f8f8-186f-4759-bfc0-4118ab4c9fe7}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, foyahawov=Rundll32.exe "[%COMMON_APPDATA%]\veyesera\veyesera.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kodehuwapu=Rundll32.exe "[%COMMON_APPDATA%]\towosuko\towosuko.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Kmite=rundll32.exe "[%WINDOWS%]\ubuwewec.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kazozedub=Rundll32.exe "[%SYSTEM%]\zewobihu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bdc2c460-1b78-43e5-9f67-6684296d9de6}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dagavabeh={bdc2c460-1b78-43e5-9f67-6684296d9de6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yejujurawa=Rundll32.exe "rituvuza.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, guziponuv=Rundll32.exe "[%SYSTEM%]\juzutase.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {480ba1d8-44dd-45e9-92ec-96f9d9ca3cec}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vamifagay={480ba1d8-44dd-45e9-92ec-96f9d9ca3cec}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gozerebij=Rundll32.exe "[%SYSTEM%]\kupuruzi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {600fcdbd-4c64-498b-a436-c98785c60d69}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zejiwogiw={600fcdbd-4c64-498b-a436-c98785c60d69}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, gozerebij=Rundll32.exe "[%SYSTEM%]\tutepega.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {cd5cfc8d-3d34-4e0f-bb44-0114e10cf54f}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wuluhuzep={cd5cfc8d-3d34-4e0f-bb44-0114e10cf54f}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 320d18a1=rundll32.exe "[%SYSTEM%]\ioykpxsp.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, virisegav=Rundll32.exe "[%SYSTEM%]\zitotela.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0de6fee7-d58d-4ad6-938f-9190a5224e29}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, muturoyuf={0de6fee7-d58d-4ad6-938f-9190a5224e29}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winrso32.rom,bBrekbNHJtPw
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, judubulug=Rundll32.exe "[%SYSTEM%]\wiwijadu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, judubulug=Rundll32.exe "[%SYSTEM%]\guvodudi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {18d3fb50-478c-47f1-b3cc-bb29e0b2784a}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pimopakam={18d3fb50-478c-47f1-b3cc-bb29e0b2784a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hirizuhek=Rundll32.exe "[%SYSTEM%]\gupurida.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {70a48a63-3699-4113-8942-8e8521d50071}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vizubekit={70a48a63-3699-4113-8942-8e8521d50071}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, jirojinug=Rundll32.exe "[%SYSTEM%]\besohaki.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, nimokipodi=Rundll32.exe "nonabefa.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {65ba683b-4475-4251-b373-d3d9f4cf77be}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tetidojij={65ba683b-4475-4251-b373-d3d9f4cf77be}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f072013a-fa4b-443f-bc3c-df98a94379a1}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, fetafupot={f072013a-fa4b-443f-bc3c-df98a94379a1}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ac9f73c8-1f61-4804-8b06-8a22927b791d}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, getewufup={ac9f73c8-1f61-4804-8b06-8a22927b791d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {d6d4a9a6-e199-4ddf-a562-976f873a857b}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, kiluvejaf={d6d4a9a6-e199-4ddf-a562-976f873a857b}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {09f3906d-2600-4fcf-a8a6-d3dac0d6600c}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pebufazeb={09f3906d-2600-4fcf-a8a6-d3dac0d6600c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {aa20d5be-d1e0-4138-a7f9-eeeb342e599c}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, tokunajek={aa20d5be-d1e0-4138-a7f9-eeeb342e599c}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bf2812a8-5a76-480d-ad34-c045dfda2c7a}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sojokazar={bf2812a8-5a76-480d-ad34-c045dfda2c7a}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fb0bee7f-cc15-4a2a-805d-d3fdc8689631}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yerisoviv={fb0bee7f-cc15-4a2a-805d-d3fdc8689631}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5a112e7d-9d5c-4c9e-9787-4e736f2f8f1d}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, padedebef={5a112e7d-9d5c-4c9e-9787-4e736f2f8f1d}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {47fe69d6-d1a3-42c5-a1d6-1e5a1af66e77}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hebavevig={47fe69d6-d1a3-42c5-a1d6-1e5a1af66e77}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7a1f78a8-9299-4575-9e27-4b495b941c9f}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wovefukan={7a1f78a8-9299-4575-9e27-4b495b941c9f}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {811afff2-17fe-449c-aa1a-fbb98b663075}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nobitejel={811afff2-17fe-449c-aa1a-fbb98b663075}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {60a41f04-3612-4937-a352-5fef4c5ba7c3}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, johejibij={60a41f04-3612-4937-a352-5fef4c5ba7c3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kavowawos=Rundll32.exe "[%SYSTEM%]\diguweha.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {8e8122f9-2932-4aec-8d06-5861ff726fbd}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gopurayod={8e8122f9-2932-4aec-8d06-5861ff726fbd}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winsgz32.rom,OrPHsar
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe wingsw32.rom,hPetlmsA
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yefogomoj=Rundll32.exe "[%SYSTEM%]\metitalu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {0db95e69-90a8-43ff-8f87-968bd006725e}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wafarusey={0db95e69-90a8-43ff-8f87-968bd006725e}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wavabegol=Rundll32.exe "[%SYSTEM%]\suvatonu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Imaramaju=rundll32.exe "[%WINDOWS%]\uduhogev.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mowekokub=Rundll32.exe "[%SYSTEM%]\beludafa.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wehofahuze=Rundll32.exe "yofabovi.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {3f0316d1-3792-45de-b6c9-f6dc92b690d8}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, pizejulan={3f0316d1-3792-45de-b6c9-f6dc92b690d8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mowekokub=Rundll32.exe "[%SYSTEM%]\sayiwido.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wehofahuze=Rundll32.exe "tubuyiru.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\fisibezu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {ef4596da-72b5-4066-82f1-df26ca7801c6}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, sumisenur={ef4596da-72b5-4066-82f1-df26ca7801c6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kezogodon=Rundll32.exe "[%SYSTEM%]\fedoniko.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumurugid=Rundll32.exe "[%SYSTEM%]\wosawamu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mowekokub=Rundll32.exe "[%SYSTEM%]\fivipute.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {2ffbe291-5733-4374-a07c-608e094c9da9}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jepenezem={2ffbe291-5733-4374-a07c-608e094c9da9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Byisicuzuhifuciz=rundll32.exe "[%WINDOWS%]\udekayej.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wemapovoz=Rundll32.exe "[%SYSTEM%]\rikeyeza.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {77d677b9-a4de-4896-b5c1-3410e35c7682}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zihogoduz={77d677b9-a4de-4896-b5c1-3410e35c7682}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {941508f8-ccd9-44e0-ac29-4f1e141373f7}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {58aa2aab-e945-49e7-b7a2-672ac85367e7}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 00463ca8=rundll32.exe "[%SYSTEM%]\uqcxgiyh.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wemobinewe=Rundll32.exe "[%SYSTEM%]\vofehafi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wihimokad=Rundll32.exe "[%SYSTEM%]\roruhore.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Mcocixatabivepa=rundll32.exe "[%WINDOWS%]\ulapiyijiwanom.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, luyebekup=Rundll32.exe "[%SYSTEM%]\wikobilo.dll",a
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F5C897.exe=[%PROFILE_TEMP%]\_A00F5C897.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00FDBB03.exe=[%PROFILE_TEMP%]\_A00FDBB03.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F40653A.exe=[%PROFILE_TEMP%]\_A00F40653A.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F4E645.exe=[%PROFILE_TEMP%]\_A00F4E645.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F4C2C0.exe=[%PROFILE_TEMP%]\_A00F4C2C0.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F15750A.exe=[%PROFILE_TEMP%]\_A00F15750A.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F2984E.exe=[%PROFILE_TEMP%]\_A00F2984E.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F40192.exe=[%PROFILE_TEMP%]\_A00F40192.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F9EF982.exe=[%PROFILE_TEMP%]\_A00F9EF982.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mihipamus=Rundll32.exe "[%SYSTEM%]\wunufaku.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lirekusik=Rundll32.exe "[%SYSTEM%]\rosohaha.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5f0480db-5b29-4f46-95e9-f0584e4d5d56}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wevezawov={5f0480db-5b29-4f46-95e9-f0584e4d5d56}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, loyabitit=Rundll32.exe "[%SYSTEM%]\satunano.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {30a3919e-64e1-4950-a2f7-619f13a7244a}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, runigofof={30a3919e-64e1-4950-a2f7-619f13a7244a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, hugokebuf=Rundll32.exe "[%SYSTEM%]\wojidiko.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {329c1928-ade3-4207-a465-2fb9410e95e9}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, voyagufoh={329c1928-ade3-4207-a465-2fb9410e95e9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Vyutazaqes=rundll32.exe "[%WINDOWS%]\ofekazubi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, befupijom=Rundll32.exe "[%SYSTEM%]\watazage.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\vigowowu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {612f86d9-fb33-4af9-87eb-f370048a1b54}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nifopavud={612f86d9-fb33-4af9-87eb-f370048a1b54}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f5f49fdf-5210-4834-a34b-bd079478f0d8}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, daboguguy={f5f49fdf-5210-4834-a34b-bd079478f0d8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, porimesuf=Rundll32.exe "[%SYSTEM%]\kelewaba.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sujopewage=Rundll32.exe "mezutilo.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6068c8ec-2b79-420b-868a-213c88e33ec5}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, hejopufiw={6068c8ec-2b79-420b-868a-213c88e33ec5}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM5f3aa3b5=Rundll32.exe "[%SYSTEM%]\dijepahu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 000000af=rundll32.exe "[%SYSTEM%]\nojepake.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 5c099029=rundll32.exe "[%SYSTEM%]\nojepake.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mehidopozo=Rundll32.exe "[%SYSTEM%]\guderasa.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Csiki=rundll32.exe "[%WINDOWS%]\avofilelufi.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {a0b4ffea-d466-49a8-9bb0-b7bbd2fcb449}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {E9349597-6E81-47F3-B05D-469763764FB7}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, mofuworoba=Rundll32.exe "[%SYSTEM%]\balinoto.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Xvacisiquyicub=rundll32.exe "[%WINDOWS%]\ozixizuxawodafuv.dll",Startup
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winnuj32.rom,yXmCpCijS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, siyopupaw=Rundll32.exe "[%SYSTEM%]\gomuzidi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {af7129e5-6048-43de-9e0a-4d1cf56c6899}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yavituweh={af7129e5-6048-43de-9e0a-4d1cf56c6899}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, A00F5DDDBC4.exe=[%PROFILE_TEMP%]\_A00F5DDDBC4.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lopivasam=Rundll32.exe "[%SYSTEM%]\puwaduvu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5c7d36c8-b009-4187-8f59-53f65690862c}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, siwufuzey={5c7d36c8-b009-4187-8f59-53f65690862c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\lirikozu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {10b02043-fcfb-4f80-9b60-9b6d08fb4d76}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gamaniyek={10b02043-fcfb-4f80-9b60-9b6d08fb4d76}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\fupipivo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {71ecd502-5988-47b5-9741-396e056fe418}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wukolonel={71ecd502-5988-47b5-9741-396e056fe418}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, layivukom=Rundll32.exe "[%SYSTEM%]\wofomobu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c4a6998f-e9c3-4dc7-8e19-ecf752def175}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, nakiviroh={c4a6998f-e9c3-4dc7-8e19-ecf752def175}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lunibevar=Rundll32.exe "[%SYSTEM%]\turazapu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6394d94f-d969-49f6-87ae-9420572f7219}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, rajerayil={6394d94f-d969-49f6-87ae-9420572f7219}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuromazuzo=Rundll32.exe "[%SYSTEM%]\gakigedo.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vuromazuzo=Rundll32.exe "[%SYSTEM%]\gakigedo.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, kutowahij=Rundll32.exe "[%SYSTEM%]\jowazoyu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, boduvazek=Rundll32.exe "[%SYSTEM%]\zefimago.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, boduvazek=Rundll32.exe "[%SYSTEM%]\pewoniji.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, fusolazafi=Rundll32.exe "gumaluyi.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, fusolazafi=Rundll32.exe "gumaluyi.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6c6ec935-54f8-4e1c-beb4-e575d5a37650}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, lamepiwet={6c6ec935-54f8-4e1c-beb4-e575d5a37650}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\vahuwodi.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c522b223-35e2-4647-92a6-9f9f96a789a6}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, bugetowar={c522b223-35e2-4647-92a6-9f9f96a789a6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, novowukav=Rundll32.exe "[%SYSTEM%]\hulahake.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%SYSTEM%]\khfCtSmK.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\jkkHWPhG.dll,#1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tolajiban=Rundll32.exe "[%SYSTEM%]\volorume.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fd48e21b-d584-4437-962e-4596f3712daa}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zokutahit={fd48e21b-d584-4437-962e-4596f3712daa}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {aef6cd38-415d-410c-9c57-3afad5265eef}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, dehafunuh={aef6cd38-415d-410c-9c57-3afad5265eef}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yeriyomuho=Rundll32.exe "[%SYSTEM%]\mafakomu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {2f55a1e9-ee3d-4b19-8b5f-378deb2f893c}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {62d1390b-75e8-445c-a99d-3340e08fd4c5}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {998dae3e-7d4f-4952-a71f-467d8fe64407}=
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sapuniyaw=Rundll32.exe "[%SYSTEM%]\tosokevo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {531ff9cc-98af-4e80-afb6-1b0790f44da9}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, gapuvepam={531ff9cc-98af-4e80-afb6-1b0790f44da9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run, Nnifoqanejobece=rundll32.exe "[%WINDOWS%]\ixapovaxesakor.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yjiceq=rundll32.exe "[%WINDOWS%]\ocuciquc.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPM36c72f04=Rundll32.exe "[%SYSTEM%]\nihaheyo.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\jkkKbAtr.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, CPMa788369b=Rundll32.exe "[%COMMON_APPDATA%]\bazadoli\bazadoli.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vebasafono=Rundll32.exe "[%COMMON_APPDATA%]\sakadadu\sakadadu.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lijelufoz=Rundll32.exe "[%SYSTEM%]\fesisone.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lagasohag=Rundll32.exe "[%SYSTEM%]\kogonubo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {62c80b71-79fc-46a8-a0b3-1013fe60f78e}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yogovemey={62c80b71-79fc-46a8-a0b3-1013fe60f78e}
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSServer=rundll32.exe [%PROFILE_TEMP%]\fccyvTLD.dll,#1
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 169d56c2=rundll32.exe "[%PROFILE_TEMP%]\mpdrcrld.dll",b
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM15ae655e=Rundll32.exe "[%PROFILE_TEMP%]\sefwuvuf.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 6449a373=rundll32.exe "[%SYSTEM%]\hhgwwshy.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, denulosod=Rundll32.exe "[%SYSTEM%]\nowuvaku.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {7406a465-f110-46b8-83c4-3ae98969f2ff}=gahurihor
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, zizomumus={7406a465-f110-46b8-83c4-3ae98969f2ff}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\buvoyaki.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {44ce103a-dc10-4b56-a063-55c5b1f2039a}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vufojosam={44ce103a-dc10-4b56-a063-55c5b1f2039a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\wirurehe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {79abb32d-079b-438f-8859-5d5703dbd084}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, mowalavas={79abb32d-079b-438f-8859-5d5703dbd084}
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zoyewidibo=Rundll32.exe "[%SYSTEM%]\nulidihe.dll",s
- HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, zoyewidibo=Rundll32.exe "[%SYSTEM%]\nulidihe.dll",s
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winbfc32.rom,aUbYSbUVvx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Cqibomubaraxo=rundll32.exe "[%WINDOWS%]\efucogiceyiq.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Fyexuyipid=rundll32.exe "[%WINDOWS%]\erihuxew.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, 74ec8d79=rundll32.exe "[%SYSTEM%]\hgGyawWM.dll",b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Yfofukal=rundll32.exe "[%WINDOWS%]\opezujit.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\jakonehu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {fe7f15ed-0858-4bc0-a473-159df752aae2}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wejawatas={fe7f15ed-0858-4bc0-a473-159df752aae2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, werojeyew=Rundll32.exe "[%SYSTEM%]\zejidipe.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {9c1c145c-c438-420a-a12d-0837fb46b4c8}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vamapapup={9c1c145c-c438-420a-a12d-0837fb46b4c8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, babipoyeb=Rundll32.exe "[%SYSTEM%]\bupodaze.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {f1c19554-5efb-4e88-bb65-5517dd3b4a97}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yerirujoz={f1c19554-5efb-4e88-bb65-5517dd3b4a97}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, vehopodog=Rundll32.exe "[%SYSTEM%]\nivedusa.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lumurugid=Rundll32.exe "[%SYSTEM%]\nutezolo.dll",a
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSSMSGS=rundll32.exe winjre32.rom,dwsRun
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, wasiyadis=Rundll32.exe "[%SYSTEM%]\rezizafo.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, wasiyadis=Rundll32.exe "[%SYSTEM%]\rezizafo.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {c79b7fff-c638-41b1-a721-ade7c4b22e10}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ruhaboped={c79b7fff-c638-41b1-a721-ade7c4b22e10}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {75e57392-ff2b-4fa9-a2c1-70ef8c425a75}=tokatiluy
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, wabelavok={75e57392-ff2b-4fa9-a2c1-70ef8c425a75}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Msubese=rundll32.exe "[%WINDOWS%]\aputivolubu.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, yigotatis=Rundll32.exe "[%SYSTEM%]\joweyiba.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {20f9e49f-ee98-4393-9148-9846f45c120c}=mujuzedij
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, yesehirov={20f9e49f-ee98-4393-9148-9846f45c120c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, riferizik=Rundll32.exe "[%SYSTEM%]\pajohebu.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {5c27a5bd-458d-449d-9d6c-ef38c63fdcc5}=kupuhivus
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, vugoreguk={5c27a5bd-458d-449d-9d6c-ef38c63fdcc5}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, tatehuyen=Rundll32.exe "[%SYSTEM%]\gigiweme.dll",a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {bfd239b4-e34c-4200-b10e-2345b67590fe}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, jogazuzak={bfd239b4-e34c-4200-b10e-2345b67590fe}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dkodixipab=rundll32.exe "[%WINDOWS%]\adipakuk.dll",Startup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, votugedope=Rundll32.exe "[%SYSTEM%]\pihimuha.dll",s
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, rijemezav=Rundll32.exe "[%SYSTEM%]\pubufuhu.dll",a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, doyosulana=Rundll32.exe "fuwoduke.dll",s
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {6a4b1324-d758-442d-8464-2521a9783092}=jugezatag
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, goluzefus={6a4b1324-d758-442d-8464-2521a9783092}
Scan your system registry for FREE

Comments

