Top 10 Alerts
Latest 10 Malware Files
Testimonials
I managed to get my main PC infected by the Koobface virus. I put up with it's constant interruptions as it presented me with the fake virus screens offering to correct the problems for me. This continued for a couple of days. I ran both SUPERAntiSpyware and Malwarebyte's Anti-Malware several times and neither of them cleaned my PC of this irritating virus. Then I found your Exterminate It! product and decided to give it a chance to succeed where my other attempts had failed.
I was blown away by the speed your scan runs, and once it identified the virus, I would have been crazy not to buy the product and let it really exterminate my pc of this virus.
I'm very pleased with your software and I'm so thankful I found it. You've saved me hours of time, effort and frustation.
There are so many companies offering software that promises to clean viruses, but I'm thrilled to find one that actually keeps it's promise.
Thank you!
Sheila M.
Win32.ExpDwnldr Registry Values
Scan your Windows registry for Win32.ExpDwnldr
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {3c9a4dd3-d64d-fd25-2f2b-f53bd9faabda}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\{8e811b4b-ad0d-338a-6d57-f0193c4bbbd9}.dll" DllStart
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcg7qj0en9t=[%SYSTEM%]\lphcg7qj0en9t.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphca26j0er4n=[%SYSTEM%]\lphca26j0er4n.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video88.cfg.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhc1dqj0eefc=[%WINDOWS%]\Temp\.tt8.tmp.exe /CR=633FFE3B56F063E8210B3949396C29ACB235E312877D858795F46B21303653D30DFB159C29B2B4904547E26EAA2C5FE0EBDA38F09AA14F275431C241839E46DA324C92CB74E0249B8E9A341735CC643B3E
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1048.cfg.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcprsj0e993=[%PROGRAM_FILES%]\rhcprsj0e993\rhcprsj0e993.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphctrsj0e993=[%SYSTEM%]\lphctrsj0e993.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhc7fbj0ev2c=[%WINDOWS%]\TEMP\.tt10.tmp.exe /CR=7DACC85701BBBAAD35501769EF08A0A0A2E7D29BC825590428FDC9E5CCBB35C8FD57B7E6274AEC3584EB5CBAAE1DA8A3E55CCE31D3F75322B5BA9C74656D343E9995BEA0A3546998F6A9E06329D52CB044
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphct4jj0en1n=[%SYSTEM%]\lphct4jj0en1n.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhc349j0egfe=[%PROFILE_TEMP%]\.ttCD.tmp.exe /CR=5F8C0875B49BA02BB503A8EC828A17BC739F28DC8B70F547845201FF033D2C13BD34D96C045CE38FA91BBAA3AE7FBA959CBB6235E89CC39390FE2288A5A887D88F39A362922C92F05E1CC45969D3CC1579
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc749j0egfe=[%SYSTEM%]\lphc749j0egfe.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcv6wj0ev38=[%SYSTEM%]\lphcv6wj0ev38.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcehqj0e5e5=[%PROGRAM_FILES%]\rhcehqj0e5e5\rhcehqj0e5e5.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphccsgj0eaov=[%SYSTEM%]\lphccsgj0eaov.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcp8rj0ej7g=[%WINDOWS%]\SysWow64\lphcp8rj0ej7g.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcp3lj0epf9=[%SYSTEM%]\lphcp3lj0epf9.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMshc5t9j0ej1l=[%PROGRAM_FILES%]\shc5t9j0ej1l\shc5t9j0ej1l.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc11wj0epcn=[%SYSTEM%]\lphc11wj0epcn.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcj9kj0ecal=[%PROGRAM_FILES%]\rhcj9kj0ecal\rhcj9kj0ecal.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcn9kj0ecal=[%SYSTEM%]\lphcn9kj0ecal.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc1jnj0egrw=[%SYSTEM%]\lphc1jnj0egrw.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhce1nj0e191=[%PROGRAM_FILES%]\rhce1nj0e191\rhce1nj0e191.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc3noj0elfa=[%SYSTEM%]\lphc3noj0elfa.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcat9j0e905=[%SYSTEM%]\lphcat9j0e905.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhccafj0ev1p=[%PROGRAM_FILES%]\rhccafj0ev1p\rhccafj0ev1p.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc9afj0ev1p=[%SYSTEM%]\lphc9afj0ev1p.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhcra9j0e387=[%WINDOWS%]\Temp\.tt24.tmp.exe /CR=992C90B7888DE011127362A0A4389A2DB3462D2A93282513587BB6E896BBA7084F73D0097F9DA67A1F2F24C249C6CD4DBEB880C6BD5A39ADED776008CCC3AB441009ED32EEF14F7985100759A50A14CDA6955A
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhcj82j0e31p=[%PROFILE_TEMP%]\.tt23.tmp.exe /CR=120A94E60B356F7498BDC1DBA12263B82EFAF54D2F67F2B41585B38BB2924AB067E26EF747AC708E89C67C0E4C56DE58C5FDC3A8632098AE16A7B5F1415EB9AF20D9187602412163C70192324AB641CC77
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcn82j0e31p=[%SYSTEM%]\lphcn82j0e31p.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcnu9j0eea5=[%SYSTEM%]\lphcnu9j0eea5.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc721j0ejc9=[%SYSTEM%]\lphc721j0ejc9.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc97ej0eg75=[%SYSTEM%]\lphc97ej0eg75.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcjh8j0e12l=[%PROGRAM_FILES%]\rhcjh8j0e12l\rhcjh8j0e12l.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc3fbj0ev2c=[%SYSTEM%]\lphc3fbj0ev2c.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc1v6j0en1g=[%SYSTEM%]\lphc1v6j0en1g.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhcr1aj0ea6c=[%PROFILE_TEMP%]\.tt168.tmp.exe /CR=7DACC85701BBBAAD35501769EF08A0A0D578DDAE032B0F2555809C64903515B7FFEF6DF9F246F488E9D9E726B5ADD8D9EAC0D74AA7AD68AD8FB3AA8B6C3E8EE2654EEA35813E617F29425BD48103112188
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcv1aj0ea6c=[%SYSTEM%]\lphcv1aj0ea6c.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%WINDOWS%]\TEMP\a.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhctdoj0e5dr=[%WINDOWS%]\Temp\.tt4F.tmp.exe /CR=68DEB7C597303033839BA975741E35C7C918529F7B841B4B1F8AF0349D46E08E1E83CF5FDF3EA0D88B680ACF8E3CEC15D135F74D7A9865A1C73C68EFA86C4B38642D16D5E2AEED848D44FA06C2D150EFC2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhc1lrj0en2t=[%PROFILE_TEMP%]\.tt2B1.tmp.exe /CR=5F8C0875B49BA02BB503A8EC828A17BCF30F213A82CCED723D9F5299E771F8CBFB22B689CB3C5EAD3D21AFA135EFD798D3EEA754E2D1A87B8E184F53678D97E9B190CB586FEEC1D28376453A30D66DDFCE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc5lrj0en2t=[%SYSTEM%]\lphc5lrj0en2t.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc7hnj0e9cn=[%SYSTEM%]\lphc7hnj0e9cn.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhc5wmj0en7j=[%PROGRAM_FILES%]\rhc5wmj0en7j\rhc5wmj0en7j.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc1wmj0en7j=[%SYSTEM%]\lphc1wmj0en7j.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcpglj0el4e=[%SYSTEM%]\lphcpglj0el4e.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhcg8lj0elw3=[%PROFILE_TEMP%]\.tt34F.tmp.exe /CR=0B9EF0ACFB8FBFDD4B2DD86928DB01F7DEC4BC8CB8AF3A5D2E003E92B3A09B545D194D1EB47CA23AE5EF8E291B604850ACC731AB4C2644A4AADEA013A379E9F757A077FB28085A5DD7E1CFE78F617E21FC
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcl8lj0elw3=[%SYSTEM%]\lphcl8lj0elw3.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc9a1j0e7b1=[%SYSTEM%]\lphc9a1j0e7b1.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhc9mpj0elfr=[%PROFILE_TEMP%]\.tt761.tmp.exe /CR=5718ABDCC536512F731413C41EB45C62D193BBCC447BDA71E74098E505990D6A85E7647393062A42944DF93B93B57E6BA59F5601C76E2D9E43384B8D077D515367C25BB5C4BE3ED2FC71DFC057470281BBAF8B
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphccmpj0elfr=[%SYSTEM%]\lphccmpj0elfr.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcj3qj0ea2l=[%PROGRAM_FILES%]\rhcj3qj0ea2l\rhcj3qj0ea2l.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcn3qj0ea2l=[%SYSTEM%]\lphcn3qj0ea2l.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcg61j0en19=[%PROGRAM_FILES%]\rhcg61j0en19\rhcg61j0en19.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcl61j0en19=[%SYSTEM%]\lphcl61j0en19.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcrfbj0ev7f=[%SYSTEM%]\lphcrfbj0ev7f.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc9tej0en1c=[%SYSTEM%]\lphc9tej0en1c.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhctkhj0egec=[%WINDOWS%]\temp\.tt15.tmp.exe /CR=88CAAC34A93683E032FD72ACCB1321286679F5E8C0FB6499DCBD86CCCFA6E18BA966F11C64E791A7580A0E2659A34BB55863BB9C9AB07CBE79CEE386C9FAAED18F4A2E1689780E6B54CBACED1DDA324F2A
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcpkhj0egec=[%SYSTEM%]\lphcpkhj0egec.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhcltej0ev0g=[%PROFILE_TEMP%]\.tt6A.tmp.exe /CR=09502FFA8BDF757D6F816904DDEAE1C0835B5D64D6A41B5025989075671724BD3AB16F715ECC1CD450035418C81E36841E08CA1C5598ADCA9475C71AA7654A92E05F037CAA3B899FA08797056627D69F82CC43
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc5oej0eg1n=[%SYSTEM%]\lphc5oej0eg1n.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhc539j0e9bc=[%PROGRAM_FILES%]\rhc539j0e9bc\rhc539j0e9bc.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, inrhcvcgj0eeqv=[%PROFILE_TEMP%]\.tt7F.tmp.exe /CR=5F8C0875B49BA02BB503A8EC828A17BC2140D975B6D75905F1553FC068339397AC6B7A372F1E699732C58563F76E9651E2F301E189B32F319E83A4F5B50183456C5CFBCF5940454B22BC9A5C489869ACBC
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcrcgj0eeqv=[%SYSTEM%]\lphcrcgj0eeqv.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {67adec97-867f-7394-a7c9-f1ee1d23ef9d}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\{a98891a8-52de-be91-191a-3c66fc018f73}.dll" DllStart
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc5djj0en9v=[%SYSTEM%]\lphc5djj0en9v.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhc9swj0e5b9=[%PROGRAM_FILES%]\rhc9swj0e5b9\rhc9swj0e5b9.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc1ghj0e521=[%SYSTEM%]\lphc1ghj0e521.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhc9v6j0e7g7=[%PROGRAM_FILES%]\rhc9v6j0e7g7\rhc9v6j0e7g7.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcpovj0e5d3=[%SYSTEM%]\lphcpovj0e5d3.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphcrnuj0ej57=[%SYSTEM%]\lphcrnuj0ej57.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphclroj0ec4e=[%SYSTEM%]\lphclroj0ec4e.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMrhcp9qj0e7ea=[%PROGRAM_FILES%]\rhcp9qj0e7ea\rhcp9qj0e7ea.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lphc1k5j0er83=[%SYSTEM%]\lphc1k5j0er83.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1162.cfg.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {37276a75-bf50-ef03-e61e-5d10230da88f}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\ucytbpdyyjbb.dll" DllStart
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1114.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1161.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE%]\LOCALS~1\Temp\video1054.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\A147.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\26.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video0.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\162.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1018.cfg.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {9a3084c0-9aff-a289-289c-5c2c4460dc38}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\{b36675a9-e535-eb09-671b-39deb3971ecd}.dll" DllStart
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1004.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\16.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1038.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PERSONAL%]\video92.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\174.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video199.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\D328.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1039.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1A5.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video41.cfg.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {da9f38d0-3069-4c43-32e0-f8ccbf5e9589}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\cpdxrweleakebywtk.dll" DllStart
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\AF54.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video198.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video217.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1138.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1020.cfg.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {986f714f-5503-86bd-5c97-9ab800d14621}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\rsgeuaniuz.dll" DllStart
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video119.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video1062.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\26BF.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\118.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\D.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1C.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\58.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\159.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1A.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%WINDOWS%]\Temp\54.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\DD82.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\152.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\6474.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\79.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1054.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\2F.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\EB3B.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\2B1E.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\A41C.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\D76B.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\869D.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\856.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run, Somefox=[%PROFILE_TEMP%]\2D.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1D5.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\E8.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\76.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\6B.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\EE07.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\6EC.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1AAA.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\EE84.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\1223.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\847.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\2FC9.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\A156.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\125.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\6330.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\13E.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\340A.tmp.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {912b5ae6-dbe0-d4de-ee92-d161964653dd}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\{c99c1e49-003f-f31b-3d74-7d65f600f107}.dll" DllStart
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\33B2.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\3929.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\A.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\84CE.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\814.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\4D6.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\107C.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video143.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\190.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\8621.tmp.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, {2a1facd1-9203-2b96-a674-50d3426ce0dc}=[%SYSTEM%]\Rundll32.exe "[%SYSTEM%]\{0896f053-518a-3151-90de-c9522a3b045b}.dll" DllStart
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\E4.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\B6.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\9.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\5F8.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\AF1C.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\BD.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\13.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\CF.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\9503.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\video170.cfg.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\F528.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\59.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-, Somefox=[%PROFILE_TEMP%]\139.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\139.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\291.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\71D.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\F.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\9BD.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup41.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\51.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1018.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\3093.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\39.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\FC59.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\248.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\685.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%LOCAL_APPDATA%]\Temp\78DB.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\2824.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\168C.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\311.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\131.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\2CD.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\C7EB.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1050.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\947.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\63EE.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1073.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1066.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE%]\Temp\3.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%WINDOWS%]\TEMP\7FA.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1067.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\7281.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup1065.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\21.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\A87F.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup53.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\c..exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\BA03.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup40.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\A799.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\C.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\849.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup119.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\2C09.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\669E.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\CE2B.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\6AC.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\26D.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\CE.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\227.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\36.tmp.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup145.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Somefox=[%PROFILE_TEMP%]\setup85.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Windows Installer Configuration=msiconf.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msiconf.exe=msiconf.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, bal=[%PROGRAM_FILES%]\WinMsg\SYSMONMS.EXE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Personal Security Center Monitor=[%SYSTEM%]\psc_mon.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sclick=[%PROGRAM_FILES%]\WinMsg\sclick.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, StUnInst=[%PROGRAM_FILES%]\WinMsg\uinst.exe
Scan your system registry for FREE


CURIOLAB S.M.B.A., Amagertorv 15, 2, 1160 Copenhagen K, Denmark, +45.36965533
