Exterminate It! Antimalware

malpedia

Known threats:699,742 Last Update:October 27, 11:19

Testimonials

Over the past six months I had a lot of trouble surfing the Internet and working on my PC. I tried different free and pay antivirus software, but they were all of little help. I scanned with Exterminate It! It turned out that my computer was infected by five different viruses and Trojans, and your tool found them all! Now my PC is perfectly fine. I am really impressed.

Exterminate It is also very simple to use, which is essential for computer novices like me. I like it so much that I recommend it to my family and friends.

Vale R.

AutoIT- Registry Values List

This is a complete list of AutoIT registry values collected by Exterminate It!. If you find any of these registry values on your PC, your computer is very likely to be infected with the AutoIT - trojan.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AntiWormUpdate=[%SYSTEM_DRIVE%]\Google\AutoIt3.exe /AutoIt3ExecuteScript
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AntiWormUpdate=[%SYSTEM_DRIVE%]\Google\AutoIt3.exe /AutoIt3ExecuteScript [%SYSTEM_DRIVE%]\Google\googleupdate.a3x
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]run32=[%SYSTEM_DRIVE%]\Win\lsass.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]Window Title=Internet Exploiter
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]taskman=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Xplorer="[%WINDOWS%]\Xplorer.exe" /Windows
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]G_Host="[%WINDOWS%]\System\gHost.exe" /Reproduce
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Xplorer=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Xplorer=[%WINDOWS%]\Xplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Yemensoft AutoBackup=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]TkBellExe=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]configuration=[%WINDOWS%]\configuration\configuration.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Avira SystrayStartTrigger=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]GrooveMonitor=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]run32=[%ANY_DRIVE%]\Win\lsass.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]IMJPMIG8.1=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WinampAgent=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Persistence=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]NUSB3MON=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]USB Security=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]BCSSync=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Wondershare Helper Compact.exe=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]mobilegeni daemon=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]1=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]vProt=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Clinck v3=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ASUSGamerOSD=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HotKeysCmds=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]run32=(EMPTY)
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SkyTel=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]G_Host="[%SYSTEM%]\gHost.exe" /Reproduce
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]RTHDCPL=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Xplorer=/Windows
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]APSDaemon=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]igfxtray=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Adobe ARM=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]USB Antivirus=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]MSC=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]KernelFaultCheck=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]DRIVESYS1=[%SYSTEM%]\bycool1\windo.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]igfxhkcmd=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]GhostStartTrayApp=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HP Simple Trax=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]fun=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ISUSScheduler=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]NeroFilterCheck=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run](default)=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]MSConfig=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SunJavaUpdateSched=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Mouse Suite 98 Daemon=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WHITNEY_S2P=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AzMixerSel=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ShutdownEventCheck=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]VMware hqtray=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SWd=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Alcmtr=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ePower_DMC=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]PromptService=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]RemoteControl=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]QuickTime Task=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]PTHOSTTR=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ShStatEXE=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]PDA 5 Autoupdater=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]BitDefender Antiphishing Helper=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Yahoo Messenger=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Defender=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SoundMan=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]BluetoothAuthenticationAgent=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Quick Heal Core UI=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]googletalk=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]nerocheck=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]LanguageShortcut=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]eScan Updater=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]FilmFanatic Browser Plugin Loader=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ApnUpdater=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]NBKeyScan=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft(R) System Manager=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]BigDogPath=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WSVCHO=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]UnlockerAssistant=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]USBScan.exe=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AutorunRemover.exe=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]YSearchProtection=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]egui=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HDAudDeck=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]DATAMNGR=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Adobe Reader Speed Launcher=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]DrvLsnr=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]svchost Agent=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]avast5=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Sony Ericsson PC Suite=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SiSPower=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]snp2uvc=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]PMX Daemon=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]EzButton=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]VTTimer=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SigmatelSysTrayApp=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Everything=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]avgnt=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Eraser=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]InCD=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]PRONoMgrWired=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]BDMCon=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HP Software Update=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]StormCodec_Helper=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]CarboniteSetupLite=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]NvMediaCenter=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]LManager=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]CanonMyPrinter=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]MyWebSearch Email Plugin=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cmaudio=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]K7TSStart=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]VMC PPPoE=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Internet Explorer Sys32=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]JobHisInit=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]DSLSTATEXE=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AudioDeck=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]CanonSolutionMenu=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]FlashGuard=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]S3Trayp=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]nwiz=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Antiphishing Domain Advisor=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]NortonOnlineBackupReminder=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SMSERIAL=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]netxpert=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]MDS_Menu=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]hpWirelessAssistant=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]hpqSRMon=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]BMMLREF=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]C-Media Mixer=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AdobeCS5ServiceManager=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]AdobeCS4ServiceManager=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Aide=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]XP-28A023CF=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]UpdatePSTShortCut=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]High Definition Audio Property Page Shortcut=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]igfxpers=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]G_Host=0
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]G_Host=1
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]MMTray=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]NWEReboot=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ESB=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]iTunesHelper=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]hpbdfawep=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]IntelWireless=[%SYSTEM%]\KHATRA.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]RtHDVCpl=[%SYSTEM%]\KHATRA.exe