Exterminate It! Antimalware

malpedia

Known threats:699,443 Last Update:August 10, 12:54

Testimonials

Wow,

I really can't believe you got back to me. I had bought and paid for 2 other Malware programs in the last 5 days, X********E & P*********c Anti-Spyware, and sent them the same message. I paid for yours and got 2 others from friends that where cracked copies N****n & S*******r but no one has got back to me. I have not heard a peep out of them but You have got back to me.

Well done.

Your faithfully ( a customer forever)

Richard D. P.

DealPly- Registry Values List

This is a complete list of DealPly registry values collected by Exterminate It!. If you find any of these registry values on your PC, your computer is very likely to be infected with the DealPly - adware.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cusokikadec=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bipon"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Halodop=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Carerafaroh"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Ramaba=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Releloso"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Lesolulas=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mekelafed"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Datiratibap=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kodasubem"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Foced=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sadekoh"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Dilosagutu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\HALERE~1\Tamad.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Nilehoteceri=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lelam"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Bokinehokas=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{619B5~1\Gebigebod.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce]Mepofimepefa=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Capasopa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nomacegepe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cegetopic"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kefih=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cocah"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Behenebi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\29FD60~1\Sehedepu.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Segop=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\MIMOCI~1\Gasenuced.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Leceki=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fililelose"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Mosopaba=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\brick\Dekogorum.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lasus=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\46D5F8~1\Metiligibo.dat"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cagacoh=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Haromesimic"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pogakipan=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Ronemakahisa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Daretodote=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dadeholopeh"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Firuru=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pinarodalun"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hetab=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dadisesic"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fekono=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mupicib"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fasor=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Futahetom"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cafopori=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nosad"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gonilenecehe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mocegalusab"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Boguneho=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mupadogican"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tinomahamaco=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lefufopenugo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Patesata=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Raneluco"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nilep=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{FEBEC~1\Fenipereken.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Mogipudike=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Metan"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Napot=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mehot"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Geranorelom=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cehoso"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gakigumegoba=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Podomus"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Narucumosa=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Masenidabeha"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gekodog=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Biroli\Sulocobugupi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fatogotame=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\583C12~1\Podelipegar.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Redifikeho=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dabobirupese"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gupife=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gakafo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Palom=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Salopahigih"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cocamigifahe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lalere"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lomof=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Facake"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hipadopata=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rehedo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lodemigoneg=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\TEMUFE~1\Megunigakic.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lodalelef=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Copetehedade"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lator=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\7FBF3F~1\Nehohop.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tolagegorato=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\CUTECE~1\Kehisekofo.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Senomene=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\wincy\Tegus.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sudikug=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nakic\Leronegar.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hanamam=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lesosasolobe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kidotu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rifunurona"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lagora=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\HEGELE~1\Gocopi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fokag=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cefulagid"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Taheho=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\wincy\Dekesag.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gofatobuco=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mupeler"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kecehitotif=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Simogefona"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Belur=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fubelabof"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lahanohirena=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bitifofelimo"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hatinobalef=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Besefodepa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hatinobalef=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Besefodepa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lalinab=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Ronasafakere"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Silopenubu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\LAHACA~1\Lefemagu.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Genutom=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Didog"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Goraf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Begibe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lohicaga=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mikeb"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Magus=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Teratonesom"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bakigomel=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kegilepa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kalakarehule=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\bodor\Manoferubabu.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tadul=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Difacelogi"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pafilatop=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\16A9F2~1\Ralegamito.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Molufuroc=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gorat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Laretacobomi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Motenehenenu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nigis=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\CROWMI~1\Hirekekoc.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kamodaneget=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sutahora"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gegehab=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\hodor\Supidapepah.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nonani=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\1A7BB9~1\Petasumogi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Ratecagubela=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Midobe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dedomahepe=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Besipufefogo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Resediso=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Repucirob"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Feboparafir=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nulonife"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Capokom=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Putesedafabe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hotesul=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Homecaku"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Topet=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\519F5E~1\Ratepofogule.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Becagigipud=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Botepinosum"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cocabubumake=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tokas"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sobasinihaba=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Hemoheco\Fofohagehon.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rofosufodem=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cesabocareku"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Besacoc=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\77B7A2~1\Bifocipi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fekagesuseto=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Taticudemabi"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Botubi=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Legododicer"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Godomumo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Melohumapoha"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lapasufeluk=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\7F5539~1\Pilak.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Deherako=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\wincy\Nitacepado.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tefofocu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tokod"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hotepah=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lokaloc"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Febibeforap=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Homedotulore"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lagolasaso=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\758018~1\Foholahegi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cudutemak=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Haguraba"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gotuf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mimepe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Mepani=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\22EE27~1\Gaboragum.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hotego=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mababo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rodopidac=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\096EEE7E-9C37-1270-6A60-2008A05CFB85\Gogan.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Selutad=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\4BC3E2~1\Cefidilo.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Telemusef=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sakeg"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Larure=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mopeboba"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fohotamulok=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cebimefadeta"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nocero=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kacobitid"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kugum=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nalalaged"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fipasagonenu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kefap"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gadal=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\hodor\Macep.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nolil=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Marenesot"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Paligosoleb=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Botibosinoda"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cecenepegi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\4CE23C~1\Nabacol.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hesasus=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nadaforetono"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dagideferal=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fasopanap"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nepag=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Babukeb"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sudiga=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mogacutotafo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lebosu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Babepahacef"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nahuhip=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fitufomed"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sanifimedo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kagade"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kofuf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fohakobuhob"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lerolanod=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bodel"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pucenunehunu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fafures"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Neledohe=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fapupafid"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nupodura=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\7FF469~1\Hebotabut.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Mohaban=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\bodor\Foceboru.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fakehelesel=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Benetiluhe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Suhat=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Carob"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nadadapur=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fagepem"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cetateri=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\brick\Fomoti.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gohete=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kahec"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Memasatakoge=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bokapilumame"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nocerola=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\7C17DE~1\Gesac.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nitefes=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tefamak"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fisacarefah=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sohanarefa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pokoremariha=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Forarohoku"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bihefeba=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bokacefol"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gokebimaro=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Honate"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Foreba=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Napocapobu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Defolosahu=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kodobig"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sadupuhegoc=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tilocame"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cubulegatu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sirocuban"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Falepil=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\brick\Gupogofaho.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nedurofenebe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Benagoru"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Geneter=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\hodor\Temilo.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gegasulebo=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sesuc"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Codekapamof=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bahokasegeg"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Putategare=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pagaked"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Datidacagas=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\DOSELO~1\Dubep.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hucarufepi=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\304490~1\Somagemeg.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pehomuboraf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\58D379~1\Haliban.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Linusah=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\4A9680~1\Cafer.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cemabed=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kameleceka"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Garofodo=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cabifa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Benemegugo=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Renakugal"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Doseco=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Huhilugatemo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rulerecukoc=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Guletec"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Popofiro=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\11394B~1\Kabonede.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dunolu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gadanacel"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kolebobo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Konehonu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Faceridadehe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kisilogugetu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nusenob=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Deheheteho"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hagoralaboge=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\62234E~1\Fositadikoha.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lopero=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\5DBF61~1\Fotoba.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Redahit=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mehebor"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bocale=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Calepelatigo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Depacecah=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\wincbee\Secacagunehi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bimof=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nomanobagof"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Monosotocolo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rasiluraku"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fihanag=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lanisi\Renenerod.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sutafihoh=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\261145~1\Pabamukiketo.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bokelucodup=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Culidotekat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Furapi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cogifebubula"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nebedireben=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fatukihusero"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sagike=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bihitoneh"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fapanenigibe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\bodor\Bacipemel.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cacogotada=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Taforakidag"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sufuteg=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kodofopatu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Basare=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bisalog"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bobosepehul=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nakeropapa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bodute=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mukub"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Badocafaba=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\FAGUBI~1\Nitop.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gerafebaneb=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Notigolefec"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tebor=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\palikan\Fonodosegu.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tagarelok=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Camegusen"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kegopeda=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kofosifa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lohofofekef=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cosopemegop"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rogafu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Poporolilona"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kikodalefar=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\0CE62D~1\Fedehidupe.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sofohem=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Hepotuhupene"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Feceg=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kosocefabo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Marari=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kuhahac"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lebetopesi=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\60F372~1\Hadifatonife.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pahutise=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\477539~1\Rucirabomoto.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Repalilik=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kehosotolako"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Radumol=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sepefis"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lekice=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cucihe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Halacohec=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kinedarahel"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Peruret=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\7CAB93~1\Dopuk.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cikefecet=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dutonetob"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bahomec=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Funerohona"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lagupupubi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\759EC7~1\Lofaceluge.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nakofokuk=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\43DB32~1\Tanuraturohe.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Baloroh=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rosenisas"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Torokurapem=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{133C2~1\Sosafagutuh.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fesum=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fihok"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nukemes=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{C0CDF~1\Bitotipe.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nicotelusaha=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mecalec"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hupapa=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sosedibotori"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kicafekineke=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rofunocunelo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Napolanacep=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mihiror"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Heboguhupih=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Firifihat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fodeducusok=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dekal"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Roratomikoc=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rihegoheg"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bilafel=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\4D9F7F~1\Pemukag.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Redosopeta=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tucega"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bomipefihupo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pakigep"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cenahafo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nefiluc"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dategifurir=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{ADA59~1\Momedosuhi.dat"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]PriceFountain=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\PriceFountain\UpdateProc\bkup.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]PriceFountain=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\PriceFountain\UpdateProc\bkup.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fogadimaf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tugagecace"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Foceledusep=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gorebocomute"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fanafos=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\06D1EE~1\Bebagos.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sogocasib=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cisoporodo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Giranelokepo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pubukerosumu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Risecotapob=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Facipacu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bilaruhoreb=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\1B48A4~1\Panido.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Momahokaciti=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\GATABA~1\Tuhakac.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pedunipake=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dukokakubus"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dokehaluse=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kicesi"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lofotepa=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nupap"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kopadefa=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fanufateceta"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kenesoto=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tipapeloc"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gasunoha=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bipoca"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Foboteceb=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fogudoparap"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tefefosope=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Hakoladopog"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Seroke=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lonak"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Ciloro=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{C314F5AF-E646-98D9-8D70-BF0B51A24235}\Pekocogika.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fahegaf=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lesadenosu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kogecupilu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tunerohepefa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dulofafelase=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\hodor\Parenekapa.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dibumeda=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Himasagod"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Terutafodo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mehapu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pocofehucoko=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Botubolotic"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kepakumaro=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\753CFA~1\Muped.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Madem=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\156D46~1\Kaceti.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kahopag=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pacotagunoho"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lomalehakok=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Casepo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Damirer=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\176676~1\Pesobohoper.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gafase=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nusekabamu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fotegirehi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\palikan\Fosopoceruf.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Mucogilebaco=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Terenebahik"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cihohamape=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nolatoniga"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dabul=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nusahobaca"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nisoca=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Doholodo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bopudofupo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tadeponifu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pemenike=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dekasa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rohogomogeni=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mokupareb"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tepibiribade=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Logilesapap"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fosebed=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\smith\Haconofumo.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sufira=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tegegicefih"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cisamena=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\356B20~1\Kopupupem.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Daluf=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\053D3F~1\Camesegenel.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gofotageguba=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%LOCAL_APPDATA%]\UPDATE~1\Segurenacege.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Momahokaciti=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nehofa\Tuhakac.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fumacan=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fosopetila"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Focopof=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Resitipa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sarafakitag=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lekecafuhu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Moderitek=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Turip"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Belehac=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fekotoga"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Binkiland=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Binkiland\UpdateProc\bkup.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Diparedeh=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Demepeh"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cosala=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pacegotaron"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Didan=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lehutale"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fefominu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\3E194B~1\Comodobe.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bafacidek=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sucotadul"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Torebadug=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mobalanuler"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rudeso=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nogumeta\Nofire.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tadenedepeno=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fukamotiter"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dobusorum=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Ligedok"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tihuno=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\wincy\Medok.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tarekom=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Begunatuge"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bepaseto=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Misof"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cipilefor=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sehata"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sekihehega=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Maginopu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dadoca=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pesapokupunu"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Manegobe=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mefedakit"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kadomegulo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Marumetisofa"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pokocago=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Marebenere"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nasibobobi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\3DE20C~1\Dopomotolo.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pecameko=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Cigiradi"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nafogeco=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gigebokup"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lamibonad=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{1CA52~1\Hugomafapine.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lonemelig=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lepic\Noletakoheso.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Ludakeb=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dumuned"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nefigefar=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dukunakido"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fatepedole=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{DAA2E~1\Sohamacosif.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Segarugidedo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tedef"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Ditonu=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{60CD5~1\Dosogenaseha.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dumofopubug=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\38C0DD~1\Lurag.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fodananula=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\33B6DF~1\Betodoreh.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lahadi=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\67D068~1\Capohomepa.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gumefer=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Daker"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dubogeki=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\UPDATE~1\Safabe.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nelarupe=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Momebalefep"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Podop=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nidipeborobo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bodehotimo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\25CDA6~1\Lasugedu.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Losenatomo=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dodokopo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Logetom=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kefecenen"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pababehoru=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\UPDATE~1\Renag.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tecalenimi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{E66ED~1\Rupek.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lelifed=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pohadibeboda"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Salacem=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Mebobobapege"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kapanadag=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gecehutasufo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Raralemogu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Ponupod"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kihoditaligu=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Hetugapaga"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Luhipumanaso=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gamopeb"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dodamekohi=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lomesamebe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Butebi=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Babed"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Habem=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{D7D7E~1\Tokube.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cemup=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{8F57B~1\Letekahegos.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Loseges=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lopaheb"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Kibekun=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tinuhatasipi"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Ponagebofap=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Datehi"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rikes=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{F7E0C~1\Fesetarodino.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rehehokar=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fosomekopoh"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Hofetefet=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{69955~1\Cabanace.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tabatit=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Lakonuna"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Birekarubaro=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gosudan"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bagorotape=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dilidomo"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Modalafe=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dodeseg"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Torolecu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Fofub"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Fafadum=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Tafilulahul"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Garotec=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Faboruhanak"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Molecotaduci=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Panusogapem"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Pagibanoro=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\02D5EE~1\Sifoli.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cumesubut=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bagamuk"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nehil=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Berog\Setodab.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lifola=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Hamiceledeko"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Bahukam=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\54A35A~1\Gociceged.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Sehedaripodo=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\24841C~1\Nohafusi.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gucak=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\225772~1\Hagoguratak.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Lomenoliho=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Numaga"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Norebotob=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Gesah"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tupog=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Kidufofiro"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nikohemaf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Bahos"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Cofofol=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Dosim"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Tofefosobu=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Pehataho"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Narebakac=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Sefecena"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Nomop=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\5C909D~1\Bamomucafahu.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Mebotonihado=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Rupeletof"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gacemomeb=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nekamepirife"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Gagadafofo=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Nahalasucene"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Naherol=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{9E05A~1\Mogolotoh.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Henahena=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\Ratolit"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Dikemeraf=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\5ea500898ba8e5b69c4f78bf866fa926\Lopig.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Netucodir=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\{8C1EBAA5-A94C-D7D3-C27A-F0011EA80D3F}\Dahesuhoce.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Katamekic=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%PROGRAM_FILES_COMMON%]\Nusika\Gocimemot.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rosedorise=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\711502~1\Cobufagam.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Totug=[%SYSTEM%]\wscript.exe /E:vbscript /B "[%LOCAL_APPDATA%]\{92ECA~1\Namidareketa.dat"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Rodobolob=[%SYSTEMX86%]\wscript.exe /E:vbscript /B "[%APPDATA%]\6BA9D6~1\Fanebena.dat"