Exterminate It! Antimalware

malpedia

Known threats:700,085 Last Update:March 01, 12:55

Testimonials

Dear Matt and Exterminate it,

Thank you so much. This seems to have fixed the problem. Wow. That virus was in there pretty deep. A*G didn't even identify it. S****t would just freeze up when I tried to run it. But the update from Exterminate It, removed it.

Again, thanks.

Kind Regards,
Rev. Mel C. Montgomery

Brother Mel

Ghokswa- Registry Keys List

This is a complete list of Ghokswa registry keys collected by Exterminate It!. If you find any of these registry keys on your PC, your computer is very likely to be infected with the Ghokswa - pua.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\vreXjvXBrowserUpdateCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\vreXjvXBrowserUpdateUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\vreXjvXCheckTask
  • HKEY_CURRENT_USER\SOFTWARE\vreXjvX
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\vreXjvX
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C70FF49-64D8-41A7-B61E-B1131DC2D68D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EE1B5B7-D1D0-4701-BD8A-725BC967891F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6421B85-D8A6-4795-A0AD-474472F26958}
  • HKEY_CURRENT_USER\SOFTWARE\Jamlarry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Jamlarry
  • HKEY_CURRENT_USER\SOFTWARE\Hotcine
  • HKEY_CURRENT_USER\SOFTWARE\Dayglad
  • HKEY_CURRENT_USER\SOFTWARE\birdjob
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hotcine
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Birdjob
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Dayglad
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jIxmRfRBrowserUpdateCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jIxmRfRBrowserUpdateUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jIxmRfRCheckTask
  • HKEY_CURRENT_USER\SOFTWARE\jIxmRfR
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\jIxmRfR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77CFD7A2-2CE1-40E8-97C4-A631C36307FA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15E319A6-7EB5-433B-A7DE-70EE270F8CE3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB9337D7-3F11-4653-A367-8B64ADD72EBA}
  • HKEY_CURRENT_USER\SOFTWARE\Antanna
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Antanna
  • HKEY_CURRENT_USER\SOFTWARE\Bangtony
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Everness
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bangtony
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LefttoeUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LefttoeUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ToolrainUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CupblueUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CupblueUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BirdeyeUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BirdeyeUpdateTaskMachineCore
  • HKEY_CURRENT_USER\SOFTWARE\Zoohair
  • HKEY_CURRENT_USER\SOFTWARE\Hiprain
  • HKEY_CURRENT_USER\SOFTWARE\Toolrain
  • HKEY_CURRENT_USER\SOFTWARE\Lefttoe
  • HKEY_CURRENT_USER\SOFTWARE\nobean
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Lefttoe
  • HKEY_CURRENT_USER\SOFTWARE\Birdeye
  • HKEY_CURRENT_USER\SOFTWARE\Cupblue
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Birdeye
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cupblue
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hiprain
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Toolrain
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\nobean
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B2FD7CB-C2E0-476D-9BFB-6BEA91743658}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17CF726B-A6C5-4DDD-879B-94DB7DFE6B2E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D85DF939-619D-4273-A968-C9DE70CD837D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{560311F9-77F8-4659-9974-85445FF774FF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83BA73B5-9821-4D5F-B1EB-BF95575CB1D3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D567793-B02D-494B-961F-81EBF18878C7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E57C088A-1A1A-428B-B7CE-0700AAC0FF0F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Zoohair
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BookfatUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BookfatUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Dopig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{749E23CF-BAFC-4786-8DCF-A19376BF9C35}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21EB4879-001B-4F13-B441-AFFC432911D5}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FirefoxU
  • HKEY_CURRENT_USER\SOFTWARE\Setleaf
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Setleaf
  • HKEY_CURRENT_USER\SOFTWARE\Easthas
  • HKEY_CURRENT_USER\SOFTWARE\legness
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Easthas
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\legness
  • HKEY_CURRENT_USER\SOFTWARE\ghokswa
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\ghokswa
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ghokswaBrowserUpdateUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ghokswaCheckTask
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clients\StartMenuInternet\ghokswa
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ghokswa
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F5CD2E3-E571-480C-8231-B1BAB0C60472}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B33BC6E9-61E4-4DFA-9765-79314442C144}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bangtony
  • HKEY_CURRENT_USER\SOFTWARE\Eastness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Eastness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Antanna
  • HKEY_LOCAL_MACHINE\SOFTWARE\Boxfat
  • HKEY_CURRENT_USER\SOFTWARE\Boxfat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Gofat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Footeat
  • HKEY_CURRENT_USER\SOFTWARE\Bookness
  • HKEY_CURRENT_USER\SOFTWARE\Everness
  • HKEY_CURRENT_USER\SOFTWARE\Applefat
  • HKEY_CURRENT_USER\SOFTWARE\Baghair
  • HKEY_CURRENT_USER\SOFTWARE\Yeahship
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Birdmay
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bookness
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Gunbean
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Redjane
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Yeahship
  • HKEY_CURRENT_USER\SOFTWARE\Gofat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Gofat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A08621E-1124-4778-8DB9-E84F4D3D1DCC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0554D857-8D80-493C-8751-8B47D7F5890B}
  • HKEY_CURRENT_USER\SOFTWARE\Standuck
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Standuck
  • HKEY_CURRENT_USER\SOFTWARE\Bagsarah
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bagsarah
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ceQeekgBrowserUpdateCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ceQeekgBrowserUpdateUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ceQeekgCheckTask
  • HKEY_CURRENT_USER\SOFTWARE\Dopig
  • HKEY_CURRENT_USER\SOFTWARE\Fanlook
  • HKEY_CURRENT_USER\SOFTWARE\Tooltony
  • HKEY_CURRENT_USER\SOFTWARE\Moncar
  • HKEY_CURRENT_USER\SOFTWARE\ceQeekg
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Fanlook
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Moncar
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ceQeekg
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82ADA12E-81D6-4E2A-9684-120772FCCB0F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38726B10-A607-45D0-AEA4-919A062733FE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E4048CE6-610D-4552-8F08-FAD8BF9E1809}
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tooltony
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Eastness
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Doeye
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bepat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Boxbob
  • HKEY_CURRENT_USER\SOFTWARE\Footjane
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Footjane
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\iedvutils
  • HKEY_CURRENT_USER\SOFTWARE\Bepat
  • HKEY_CURRENT_USER\SOFTWARE\Cuppat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cuppat
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iedvutils
  • HKEY_CURRENT_USER\SOFTWARE\Fishjane
  • HKEY_CURRENT_USER\SOFTWARE\Doeye
  • HKEY_CURRENT_USER\SOFTWARE\Antper
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Antper
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Fishjane
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\fishhas
  • HKEY_CURRENT_USER\SOFTWARE\Hippig
  • HKEY_CURRENT_USER\SOFTWARE\dohat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Boxfat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hippig
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\dohat
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BirdjobSU
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FishjaneSU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hotcine
  • HKEY_LOCAL_MACHINE\SOFTWARE\Boxbob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Setleaf
  • HKEY_LOCAL_MACHINE\SOFTWARE\Fanlook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Alltie
  • HKEY_LOCAL_MACHINE\SOFTWARE\Pearness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Coldmay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Standuck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Toolhair
  • HKEY_LOCAL_MACHINE\SOFTWARE\legass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Footper
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MonoldCheckTask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MonoldBrowserUpdateUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MonoldBrowserUpdateCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bookness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hotleaf
  • HKEY_LOCAL_MACHINE\SOFTWARE\Eggper
  • HKEY_LOCAL_MACHINE\SOFTWARE\Doeye
  • HKEY_CURRENT_USER\SOFTWARE\Monold
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Monold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F104885D-C7F5-43A3-9DC3-82297D40E1E8}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57D3C11C-2C61-4669-B8D4-FE48DB8AF2B6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FE94E18-A877-49D1-8E5F-FC400B53EF22}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MustangU
  • HKEY_CURRENT_USER\SOFTWARE\Alltie
  • HKEY_CURRENT_USER\SOFTWARE\Mapbob
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Alltie
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Applefat
  • HKEY_CURRENT_USER\SOFTWARE\Hotjob
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hotjob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DocineUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DocineUpdateTaskMachineCore
  • HKEY_CURRENT_USER\SOFTWARE\Docine
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Docine
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{96EB2644-F8F3-4577-A1E1-970F70CB6BBC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4764C83E-479C-42C2-BE24-7742082D8A9A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Stanper
  • HKEY_CURRENT_USER\SOFTWARE\Yeshat
  • HKEY_CURRENT_USER\SOFTWARE\Bossseed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bossseed
  • HKEY_CURRENT_USER\SOFTWARE\Jarhair
  • HKEY_LOCAL_MACHINE\SOFTWARE\Jarhair
  • HKEY_CURRENT_USER\SOFTWARE\Alltoe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Alltoe
  • HKEY_CURRENT_USER\SOFTWARE\Cupduck
  • HKEY_CURRENT_USER\SOFTWARE\Baglook
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Canrain
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Applemy
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Baglook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EastmyUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EastmyUpdateTaskMachineCore
  • HKEY_CURRENT_USER\SOFTWARE\Eastmy
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Eastmy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A2EED45-E136-4C07-B828-4A11043534A5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2368E354-B7CF-41ED-9ADE-310444F398DD}
  • HKEY_CURRENT_USER\SOFTWARE\Shutness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Shutness
  • HKEY_CURRENT_USER\SOFTWARE\Gotoe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Gotoe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SeablueBrowserUpdateCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SeablueBrowserUpdateUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SeablueCheckTask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C281CE83-2C21-4C51-8824-0BA52C7E3C7F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15946902-D02B-4B4F-944D-789757C3551E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B90E0852-0582-444F-A208-A326B73C168B}
  • HKEY_CURRENT_USER\SOFTWARE\Hothair
  • HKEY_CURRENT_USER\SOFTWARE\Birdsarah
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Birdsarah
  • HKEY_CURRENT_USER\SOFTWARE\Fishlose
  • HKEY_CURRENT_USER\SOFTWARE\Nosejane
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cupduck
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Fishlose
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hothair
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Nosejane
  • HKEY_CURRENT_USER\SOFTWARE\Jamper
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\eeaUDOiyy
  • HKEY_CURRENT_USER\SOFTWARE\Footper
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Footper
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PearnessSU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bagsarah
  • HKEY_LOCAL_MACHINE\SOFTWARE\Yeshat
  • HKEY_CURRENT_USER\SOFTWARE\Everbean
  • HKEY_CURRENT_USER\SOFTWARE\Ineat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ineat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Everbean
  • HKEY_CURRENT_USER\SOFTWARE\Legpat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Legpat
  • HKEY_CURRENT_USER\SOFTWARE\Hotleaf
  • HKEY_CURRENT_USER\SOFTWARE\Canrain
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hotleaf
  • HKEY_CURRENT_USER\SOFTWARE\Junemike
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Junemike
  • HKEY_CURRENT_USER\SOFTWARE\noflat
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\noflat
  • HKEY_CURRENT_USER\SOFTWARE\Hipmy
  • HKEY_CURRENT_USER\SOFTWARE\Pearhas
  • HKEY_CURRENT_USER\SOFTWARE\Coldone
  • HKEY_CURRENT_USER\SOFTWARE\Jamsarah
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JamsarahUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JamsarahUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\browserServer_2015.11.10.13.42.02
  • HKEY_CURRENT_USER\SOFTWARE\Footeat
  • HKEY_CURRENT_USER\SOFTWARE\Bangcar
  • HKEY_CURRENT_USER\SOFTWARE\Eggper
  • HKEY_CURRENT_USER\SOFTWARE\legass
  • HKEY_CURRENT_USER\SOFTWARE\Boxbob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bepat
  • HKEY_LOCAL_MACHINE\SOFTWARE\eeaUDOiyy
  • HKEY_CURRENT_USER\SOFTWARE\eeaUDOiyy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Baghair
  • HKEY_LOCAL_MACHINE\SOFTWARE\birdjob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bigold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Inbob
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\YestonyU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Applemy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Yestony
  • HKEY_CURRENT_USER\SOFTWARE\Yestony
  • HKEY_LOCAL_MACHINE\SOFTWARE\Yeahship
  • HKEY_LOCAL_MACHINE\SOFTWARE\fishhas
  • HKEY_CURRENT_USER\SOFTWARE\fishhas
  • HKEY_CURRENT_USER\SOFTWARE\Goldass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Goldass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DNSVINCENTOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85B7335D-8161-4A42-B475-10C3A930A25E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFEEB7E1-BABB-4B4E-8134-C7D3E636281F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21C0A53B-D286-4E9B-A5A8-C50CB7A45870}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E15829A-8C6C-43D2-A992-5154EC3FF4E4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Mapbob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hippig
  • HKEY_LOCAL_MACHINE\SOFTWARE\nobean
  • HKEY_LOCAL_MACHINE\SOFTWARE\Zooface
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JamjobP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JamjobU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Easthas
  • HKEY_LOCAL_MACHINE\SOFTWARE\Cuppat
  • HKEY_LOCAL_MACHINE\SOFTWARE\legness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Anerres Configuration
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66A92A18-9854-4D8A-9BFB-442E17D6E222}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Applefat
  • HKEY_CURRENT_USER\SOFTWARE\Hotdear
  • HKEY_CURRENT_USER\SOFTWARE\Bagbin
  • HKEY_LOCAL_MACHINE\SOFTWARE\dohat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Gunbean
  • HKEY_LOCAL_MACHINE\SOFTWARE\Zoohair
  • HKEY_LOCAL_MACHINE\SOFTWARE\Everness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Dayglad
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LegassSU
  • HKEY_CURRENT_USER\SOFTWARE\Pearness
  • HKEY_CURRENT_USER\SOFTWARE\Jarness
  • HKEY_LOCAL_MACHINE\SOFTWARE\Jarness
  • HKEY_CURRENT_USER\SOFTWARE\Applemy
  • HKEY_CURRENT_USER\SOFTWARE\Nolarry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Nolarry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Footjane
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hipmy
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FirefoxDL
  • HKEY_LOCAL_MACHINE\SOFTWARE\ghokswa
  • HKEY_LOCAL_MACHINE\SOFTWARE\Cuptony
  • HKEY_CURRENT_USER\SOFTWARE\Cuptony
  • HKEY_LOCAL_MACHINE\SOFTWARE\Junemike
  • HKEY_CURRENT_USER\SOFTWARE\IHEEAWA
  • HKEY_LOCAL_MACHINE\SOFTWARE\IHEEAWA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Baglook
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\StanduckSU
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BallduckSU
  • HKEY_CURRENT_USER\SOFTWARE\Junedoor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Junedoor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Docine
  • HKEY_CURRENT_USER\SOFTWARE\Bigjane
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bigjane
  • HKEY_CURRENT_USER\SOFTWARE\Zooarm
  • HKEY_LOCAL_MACHINE\SOFTWARE\Zooarm
  • HKEY_CURRENT_USER\SOFTWARE\Stanper
  • HKEY_CURRENT_USER\SOFTWARE\Hipbear
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hipbear
  • HKEY_LOCAL_MACHINE\SOFTWARE\ceQeekg
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoldlarryUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoldlarryUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EastmyU
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZootonyU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ZootonyUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ZootonyUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Fishjane
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JamsarahSU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Eastmy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Goldlarry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{811CEA1A-0079-46AF-A437-B04579B782CC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0A6DB66E-FB7E-4AA9-8FD3-614117FA0E60}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0C75156-DC3E-4144-894B-8DF2BBA35660}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89144BC6-B964-4DC6-AD15-716C6580E17F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EastnessUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EastnessUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FC70508-41BA-4DD1-845B-25678103817A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52956DED-9365-4EE1-A6B8-2AB8490EDE88}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5891BAB4-0FD3-4C38-92E9-0AE5E24A354C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F6E2B51-2AEF-4046-BFD1-2099C134118D}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EastnessU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Zootony
  • HKEY_CURRENT_USER\SOFTWARE\Gunbean
  • HKEY_CURRENT_USER\SOFTWARE\eahpenhiuj
  • HKEY_LOCAL_MACHINE\SOFTWARE\eahpenhiuj
  • HKEY_CURRENT_USER\SOFTWARE\Goldlarry
  • HKEY_LOCAL_MACHINE\SOFTWARE\Lefttoe
  • HKEY_CURRENT_USER\SOFTWARE\Outboat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Outboat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Dopig
  • HKEY_CURRENT_USER\SOFTWARE\Toolhair
  • HKEY_CURRENT_USER\SOFTWARE\Hipeat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hipeat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Cupduck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Tooltony
  • HKEY_CURRENT_USER\SOFTWARE\Standoor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Standoor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Stanper
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hotjob
  • HKEY_CURRENT_USER\SOFTWARE\Bigold
  • HKEY_CURRENT_USER\SOFTWARE\Junetoe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Junetoe
  • HKEY_CURRENT_USER\SOFTWARE\Birdmay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Birdmay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ghokswaBrowserUpdateCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A3462D3-1B7D-4DD5-A61D-86251AF85C90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F59600C-EBE7-41C0-8D0A-CD371768FE81}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C61E8D50-B7C9-45D4-BAAB-121F5EC0F7A9}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LegpatP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LegpatU
  • HKEY_LOCAL_MACHINE\SOFTWARE\infun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hotdear
  • HKEY_CURRENT_USER\SOFTWARE\Yesdear
  • HKEY_LOCAL_MACHINE\SOFTWARE\Yesdear
  • HKEY_CURRENT_USER\SOFTWARE\Zootony
  • HKEY_LOCAL_MACHINE\SOFTWARE\Toolrain
  • HKEY_CURRENT_USER\SOFTWARE\Outlose
  • HKEY_LOCAL_MACHINE\SOFTWARE\Outlose
  • HKEY_CURRENT_USER\SOFTWARE\Nosekiss
  • HKEY_LOCAL_MACHINE\SOFTWARE\Nosekiss
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{388A09F1-B479-4600-903C-AD8698EEBFA1}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F7A9D28-6943-4C23-AB62-CBA75DC28C9F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9861B754-0EBB-4A8F-9766-962D0D220FFB}
  • HKEY_CURRENT_USER\SOFTWARE\infun
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OutboatU
  • HKEY_CURRENT_USER\SOFTWARE\Ballduck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Ballduck
  • HKEY_CURRENT_USER\SOFTWARE\Banglamp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Banglamp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Moncar
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FootperSU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bangcar
  • HKEY_CURRENT_USER\SOFTWARE\Ontoe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Ontoe
  • HKEY_CURRENT_USER\SOFTWARE\Bossship
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bossship
  • HKEY_LOCAL_MACHINE\SOFTWARE\Pearhas
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PearhasSU
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSModules
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BagbinP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BagbinU
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EastmyP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BagbinUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BagbinUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Footblue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bagbin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9240251-A158-4689-9B7F-373F42256706}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B3D18E3-81BA-4523-BDD8-ACC41E7B0D56}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B46392C0-5F7C-49CB-9E69-396C8D178461}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F2E1234-2EF5-42E7-8D6F-FE4A4BE365B0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EAF2A2E3-D770-4760-9640-16F9EE645E86}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BAE3DDBB-5DFF-4C79-869F-1AD46F99EFFA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B4734B6-A8B8-4CC0-A08E-E9FB63939242}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\browserServer_2015.11.10.09.29.16
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZootonyP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NewjobP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NewjobU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NewjobUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NewjobUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Gunone
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hiprain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Jamjob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAA67F99-F82D-4C03-AFDD-74A2E935FD93}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D55E2D8-9CC5-4190-A921-444568732439}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9F822D2-B36F-4FD9-966C-DF85D684BF0F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4EA82BA-95CD-4023-BCD4-65F811703CBF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1AF8CA7-67C4-4635-9166-43740E6D6D43}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1B84E9E-F796-4B13-9981-937326F86613}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HiprainUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HiprainUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50AD63D5-DB60-4E48-A440-67081F7F8B7A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DFD78B4-6BD2-4BAB-B972-0E93B0D218C1}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F556839F-CF77-4E58-8D02-2DBE791B48F5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFC13D28-0D87-4B55-A547-322553EA78A9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{538F74ED-736D-4E76-98EF-468ADD1AA686}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DAB4591-D8FE-4149-B14B-CBD4CAE439AF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A981E225-C530-43AE-82FE-62452A3AE632}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BirdmayP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BirdmayU
  • HKEY_CURRENT_USER\SOFTWARE\Coldmay
  • HKEY_CURRENT_USER\SOFTWARE\Seablue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Seablue
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SetleafSU
  • HKEY_CURRENT_USER\SOFTWARE\Ballcine
  • HKEY_LOCAL_MACHINE\SOFTWARE\Ballcine
  • HKEY_LOCAL_MACHINE\SOFTWARE\Legpat
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LefttoeU
  • HKEY_CURRENT_USER\SOFTWARE\Bigflat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Bigflat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Yeahfire
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LegpatUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LegpatUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDA5BF12-4C30-4075-8B97-C57B569DD655}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D05D81B-3317-4659-99DA-AB9B8EE0C8CA}
  • HKEY_CURRENT_USER\SOFTWARE\Stancine
  • HKEY_LOCAL_MACHINE\SOFTWARE\Stancine
  • HKEY_LOCAL_MACHINE\SOFTWARE\jIxmRfR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Ineat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Birdsarah
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SetmikeU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SetmikeUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SetmikeUpdateTaskMachineCore
  • HKEY_CURRENT_USER\SOFTWARE\Setmike
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D56CE6E-0068-4968-9708-809F276CAC64}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24AA4CCC-4A9E-446B-8CA9-B6A219C05DDF}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LefttoeP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85FE7611-1097-4923-B842-FEB7C40AF6ED}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{179D2EFE-497A-41DD-AF69-258C6FBE67EA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\vreXjvX
  • HKEY_LOCAL_MACHINE\SOFTWARE\Jamsarah
  • HKEY_LOCAL_MACHINE\SOFTWARE\Footeat
  • HKEY_CURRENT_USER\SOFTWARE\Gunone
  • HKEY_CURRENT_USER\SOFTWARE\Footlook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Footlook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CCEBFE5-7280-445D-937A-FA3B53E1A1E1}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D82D65F-3A72-4B89-9044-D8CD4DB36F4C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD7645CA-46EC-4BB9-A329-ADFCAD3482ED}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Setmike
  • HKEY_CURRENT_USER\SOFTWARE\Toolduck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Toolduck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Canrain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Coldone
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA8153DC-BD6C-41DB-92B6-ED63EA420BAF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2E03214-3F34-4542-85D1-05869FFD92AA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{746587A9-C76D-4564-989E-0C1586321BB1}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GunshipUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GunshipUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC24F30C-9BED-41E4-AC61-156B7C687833}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{100A9D75-3F48-4312-8DE7-F5A1860B8780}
  • HKEY_CURRENT_USER\SOFTWARE\Redjane
  • HKEY_LOCAL_MACHINE\SOFTWARE\Redjane
  • HKEY_CURRENT_USER\SOFTWARE\Yeahfire
  • HKEY_LOCAL_MACHINE\SOFTWARE\Hothair
  • HKEY_LOCAL_MACHINE\SOFTWARE\Monrice
  • HKEY_LOCAL_MACHINE\SOFTWARE\Herhat
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BookfatP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BookfatU
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BossseedP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BossseedU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BossseedUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BossseedUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43A3A499-6ED0-4F97-B7D8-F44A5888B869}