Exterminate It! Antimalware

malpedia

Known threats:700,086 Last Update:March 16, 12:51

Testimonials

Having wasted better part of a day on a Vundo infection, which none of the antivirus/antispyware solutions I normally use came even close to handling (one of them actually compounded the problem due to a partial fix, causing all browsers to seemingly lose connectivity after a few seconds), Exterminate It! fixed it in a single pass and one restart.

Nothing short of perfect. A few dollars very well spent. Thanks again!

Laura G.

Mumuboy- Registry Values List

This is a complete list of Mumuboy registry values collected by Exterminate It!. If you find any of these registry values on your PC, your computer is very likely to be infected with the Mumuboy - trojan,spyware.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Explorer=[%WINDOWS%]\system\explorer.exe RO
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Explorer=[%SYSTEM%]\explorer.exe RO
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #0=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-client-side-phishing-detection --profile-info --enable-npapi --enable-tablo2 --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\explorer.exe RU
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #0=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --enable-cousteau --disable-client-side-phishing-detection --profile-info --disable-field-trial-config --disable-finish-rendering-on-resize --enable-mse-h264-support --enable-proprietary-video-hw-decoding --enable-dx11-for-proprietary-video-hw-decoding --enable-degradation-mode --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]94a40d183a1e5b33be1cb7d99b0c9e16="[%COMMON_APPDATA%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]94a40d183a1e5b33be1cb7d99b0c9e16="[%COMMON_APPDATA%]\explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Explorer=[%RESOURCES%]\themes\explorer.exe RO
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%WINDOWS%]\system\explorer.exe RU
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]44120498896beea9e5e0ac2561e6b80c="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]44120498896beea9e5e0ac2561e6b80c="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]08f4dc96bbb7af09d1a37fe35c75a42f="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\Borderlands GOTY\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%RESOURCES%]\themes\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer.exe=[%APPDATA%]\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer.exe=[%APPDATA%]\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\OWZCEN323F\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\Mozilla\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #1=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-client-side-phishing-detection --google-profile-info --enable-npapi --enable-tablo2 --external-app-path="[%WINDOWS%]\explorer.exe" --external-app-data=1c0-a04f8 --restore-last-session
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\alFSVWJB\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #2=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-cousteau --disable-client-side-phishing-detection --profile-info --disable-field-trial-config --enable-tab-discarding --enable-mse-h264-support --enable-proprietary-video-hw-decoding --enable-dx11-for-proprietary-video-hw-decoding --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\BitTorrent\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]RtHDVC="[%APPDATA%]\microsoft\windows\mmc\explorer.exe" c: system
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #0=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-client-side-phishing-detection --google-profile-info --enable-npapi --enable-tablo2 --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session -- http://fikrov.ru/?utm_source=uoua03&utm_content=9903289f54c7d1f1be065d5e64b0c701
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]c14d17b846af002d1bd7ffddb4d165ae="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #3=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-cousteau --disable-client-side-phishing-detection --profile-info --disable-field-trial-config --enable-mse-h264-support --enable-proprietary-video-hw-decoding --enable-dx11-for-proprietary-video-hw-decoding --external-app-path="[%WINDOWS%]\explorer.exe" --external-app-data=d58-503f0 --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]a4730ef33f5b0eb2b1ff7c9a9bba765c="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]93f19dda2412c86ad7520ba4198f39a0="[%APPDATA%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]93f19dda2412c86ad7520ba4198f39a0="[%APPDATA%]\explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]182ad509a458aba422eced4bc62ea36f="[%PROFILE%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]182ad509a458aba422eced4bc62ea36f="[%PROFILE%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #0=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --enable-cousteau --disable-client-side-phishing-detection --profile-info --disable-field-trial-config --enable-tab-discarding --enable-mse-h264-support --enable-proprietary-video-hw-decoding --enable-dx11-for-proprietary-video-hw-decoding --simple-blur --external-app-path="[%WINDOWS%]\explorer.exe" --external-app-data=67c-80316 --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\vlc\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #1=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-client-side-phishing-detection --google-profile-info --enable-npapi --enable-tablo2 --external-app-path="[%WINDOWS%]\explorer.exe" --external-app-data=109c-170f30 --restore-last-session --
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\npm\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\alFSVWJB\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce_Hidden]Explorer=[%SYSTEM%]\explorer.exe RO
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]95163d28f16a6e8f833446500f393ac1="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\IDM\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]8b5be15817333777446bd30b4cb4a3b7="[%APPDATA%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]8b5be15817333777446bd30b4cb4a3b7="[%APPDATA%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer Manager=[%APPDATA%]\Update\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]7d31449cc24545e5baf7b7e98c5e61d9="[%APPDATA%]\Explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]7d31449cc24545e5baf7b7e98c5e61d9="[%APPDATA%]\Explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\Roaming\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\runonce]Application Restart #0=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --user-agent-info=beta --flag-switches-begin --flag-switches-end --enable-cousteau --disable-client-side-phishing-detection --profile-info --disable-field-trial-config --enable-tab-discarding --enable-mse-h264-support --enable-proprietary-video-hw-decoding --enable-dx11-for-proprietary-video-hw-decoding --external-app-path="[%WINDOWS%]\explorer.exe" --external-app-data=844-40388 --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\runonce]Application Restart #2=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --user-agent-info=beta --flag-switches-begin --enable-cousteau --flag-switches-end --disable-client-side-phishing-detection --profile-info --disable-permissions-bubbles --disable-field-trial-config --enable-tab-discarding --enable-mse-h264-support --enable-proprietary-video-hw-decoding --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe="[%APPDATA%]\Microsoft\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #1=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --disable-cousteau --flag-switches-end --disable-client-side-phishing-detection --profile-info --disable-permissions-bubbles --disable-field-trial-config --enable-tab-discarding --enable-mse-h264-support --enable-proprietary-video-hw-decoding --enable-dx11-for-proprietary-video-hw-decoding --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]System=[%APPDATA%]\Microsoft\explorer.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]aea033eb207bc1e9a0c224d352888d97="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]aea033eb207bc1e9a0c224d352888d97="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{T5TBB77L-4678-0MKC-421Q-14416031DYU6}=[%SYSTEM%]\system32\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{T5TBB77L-4678-0MKC-421Q-14416031DYU6}=[%SYSTEM%]\system32\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]Application Restart #2=[%LOCAL_APPDATA%]\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-client-side-phishing-detection --google-profile-info --enable-npapi --enable-tablo2 --external-app-path="[%WINDOWS%]\explorer.exe" --restore-last-session
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\VFFiWwxx\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\Windows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Hosting Service Login=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Hosting Service Login=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\amVTUWJZYw==\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]0491ef6fa4e77398dab8882ead4fb5f7="[%PROFILE%]\explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]9de4fa9f7789ee7a6f3769efe2ebdf36="[%APPDATA%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]9de4fa9f7789ee7a6f3769efe2ebdf36="[%APPDATA%]\explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]microsoft=[%SYSTEM_DRIVE%]\directory\Microsoft\Pluguin\Microsoft\explorer.EXE
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=[%SYSTEM_DRIVE%]\directory\Microsoft\Pluguin\Microsoft\explorer.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]08f4dc96bbb7af09d1a37fe35c75a42f="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows=[%APPDATA%]\Microsoft\HTML Help\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\4MPMMXI-NIF\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\4MPMMXI-NIF\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Exolorer=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]8349386d0bbb11234c80528b83858a66="[%APPDATA%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]JavaUpdater=[%APPDATA%]\Java\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\PC-PC\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]8537e93ae4599cba4ed84a6ce932049c="[%PROFILE%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]System32=[%APPDATA%]\system32\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\install\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]win32=[%WINDOWS%]\win32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]win32=[%WINDOWS%]\win32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\winfile\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\install\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\Windows Explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]6209bb4f15c8adf10ef9b5b60f2325e4="[%PROFILE_TEMP%]\Explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]6209bb4f15c8adf10ef9b5b60f2325e4="[%PROFILE_TEMP%]\Explorer.exe" ..
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\winfile\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\winfile\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]anti-virus 2007=[%ANY_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]msn=[%PROGRAM_FILES%]\Movie Maker\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Mp3 player=[%COMMON_FAVORITES%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]internet_explorer=[%PROGRAM_FILES%]\Movie Maker\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Avgnt=[%WINDOWS%]\Microsoft\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Avirnt=[%WINDOWS%]\Microsoft\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Tumay=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%SYSTEM%]\sysdll32\explorer.exe -start
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]regdiit=[%SYSTEM%]\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]~backup~=[%PERSONAL%]\Application Data\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%LOCAL_APPDATA%]\Microsoft\Windows\explorer.exe Set
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run](default)=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled by Starter)]08f4dc96bbb7af09d1a37fe35c75a42f="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled by Starter)]08f4dc96bbb7af09d1a37fe35c75a42f="[%PROFILE_TEMP%]\explorer.exe" ..
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{17677031-3D9B-264E-1172-1431536824BD}=[%APPDATA%]\java\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]taskbar.exe=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]taskbar.exe=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe="[%STARTUP%]\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%STARTUP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]process.exe=[%PROFILE_TEMP%]\system\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Keyboard Inf.=[%APPDATA%]\gBurner\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%SYSTEM%]\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\system32\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Hidden]HKLM=[%APPDATA%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Hidden]HKCU=[%APPDATA%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]Sys=[%PROGRAM_FILES%]\Outlook Express\data\bin\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=[%PERSONAL%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=[%PERSONAL%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Profile Manager=[%PROFILE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WinDir=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]userini=[%WINDOWS%]\explorer.exe:userini.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorador de Windows=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]userini=[%WINDOWS%]\explorer.exe:userini.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Video Driver=[%APPDATA%]\config\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreM=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\Windows Explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe="[%APPDATA%]\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe="[%APPDATA%]\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]dfgdhdfhhf="[%APPDATA%]\explorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\Windows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\InstallDir\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\InstallDir\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Malwarebytes' Anti-Malware (reboot)="[%PROGRAM_FILES%]\Malwarebytes' Anti-Malware\explorer.exe" /runcleanupscript
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows=[%APPDATA%]\win32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\Microsoft\System\Services\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\Microsoft\System\Services\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\System\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\System\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\iExplore32\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\iExplore32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run](default)=[%COMMON_APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer32=[%APPDATA%]\system\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Defender=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Defender=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]msnmsgr=[%SYSTEM%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]msnmsgr=[%SYSTEM%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]Sys=[%PROGRAM_FILES%]\Outlook Express\data\bin\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]khasfdasdf="[%APPDATA%]\explorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]nVIDIA=[%SYSTEM%]\31337\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Sistem=[%APPDATA%]\Program Files\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WinZip=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Realtek=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]MS Essentials=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]XjymhuxYff="[%PROFILE_TEMP%]\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\Systems\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKEY_CURRENT_USER=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKEY_CURRENT_USER=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%WINDOWS%]\Debug\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]System32="[%APPDATA%]\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]Internet Explorer=[%APPDATA%]\Internet Explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\system32\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\Windows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\Windows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]Explorer=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]system=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]winupdater=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\Microsoft\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled]explorer.exe=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WindowsUpdate=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WindowsUpdate=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]windows=[%APPDATA%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Kernel Driver=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Kernel Driver=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\explorer.exe\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\explorer.exe\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]userini=[%WINDOWS%]\explorer.exe:userini.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Internet Explorer=[%APPDATA%]\Windows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM:Run=[%WINDOWS%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU:Run=[%WINDOWS%]\install\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]Explorer.exe=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\main\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\main\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\system32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\system32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run](default)=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreWindows=[%APPDATA%]\WindowsExplorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WindowsUpdaterzz=[%APPDATA%]\WindowsExplorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WindowsUpdaterzz=[%APPDATA%]\WindowsExplorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%WINDOWS%]\BackUp\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%PROGRAM_FILES%]\WinRAR\fonts\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%PROGRAM_FILES%]\WinRAR\fonts\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\explorer.exe\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\explorer.exe\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled]explorer.exe=[%APPDATA%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]sdfkj=[%SYSTEM_DRIVE%]\drivers\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cerberus=[%SYSTEM%]\System32\explorer.exe.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cerberus=[%SYSTEM%]\System32\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]svchost=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Core Process=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Core Process=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\explorer32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\explorer32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]userini=[%WINDOWS%]\explorer.exe:userini.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]mssngers=[%COMMON_STARTUP%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Shell=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]windefender=[%APPDATA%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Startup=[%APPDATA%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Core Services=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]explorer=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\TEMP\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows RegGuard=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%WINDOWS%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Services=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Services=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\System32\explorer.exe.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\System32\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\svchost\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\svchost\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%SYSTEM%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%SYSTEM%]\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\drivers\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\drivers\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]msgrmsn=[%SYSTEM_DRIVE%]\drivers\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\main\explorer.exe\install\iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Policyes=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Policyes=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\explorer32\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%APPDATA%]\explorer32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Exp=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM_DRIVE%]\install\nwwia\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM_DRIVE%]\install\nwwia\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Defender Firewall 102.1=[%APPDATA%]\Microsoft\Installer\msupdates\v.1.2.4\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\Winbooter\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%WINDOWS%]\Winbooter\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]IEXPLORER=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]windows=[%SYSTEM%]\system32\Explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer=[%WINDOWS%]\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A150DFD5-757E-441E-F19A-80CF0CE5EAC2}=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1F27AD17-97DC-38DD-0D75-6AA767C3722E}=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Protector=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Protector=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\System\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%WINDOWS%]\main\explorer.exe\install\iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HP Start=[%PROGRAM_FILES_COMMON%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]HKLM=[%SYSTEM_DRIVE%]\install\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM_DRIVE%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]HKCU=[%SYSTEM_DRIVE%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM_DRIVE%]\install\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{194A1160-949B-FC9F-F4CE-D1A0F17EFC74}=[%APPDATA%]\system32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explore=[%PROFILE%]\System Files\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=[%SYSTEM_DRIVE%]\Svchost\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=[%SYSTEM_DRIVE%]\Svchost\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Update=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Hidden]userini=[%WINDOWS%]\explorer.exe:userini.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Hidden]userini=[%WINDOWS%]\explorer.exe:userini.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=[%SYSTEM_DRIVE%]\Microsoft\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=[%SYSTEM_DRIVE%]\Microsoft\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F016E3F2E25\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F01200168E7\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCUc=[%APPDATA%]\security\Database\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SystemExplorer=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\window\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\window\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F013D7B42AD\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled]explorer=[%WINDOWS%]\BackUp\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F011445189A\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F013AB1565E\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F01296731DD\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F010DDC405E\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]explorer.exe=[%APPDATA%]\system32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{9D71D88C-C598-4935-C5D1-43AA4DB90836}=[%APPDATA%]\iexplorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Updater=[%SYSTEM%]\updater\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\Win32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\Win32\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F010CB24ECF\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F0153175AEB\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F016D8C48C5\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Defender Firewall 1.1=[%APPDATA%]\Microsoft\Installer\msupdates\v.1.2.3\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]System=[%SYSTEM%]\System\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]System=[%SYSTEM%]\System\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]uTorrent=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]uTorrent=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]uTorrent=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{41A18321-3982-D05C-F309-205C45A3B55C}=[%APPDATA%]\System32\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]HKCU=[%COMMON_PROFILE%]\explorer.exe\Windows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%COMMON_PROFILE%]\explorer.exe\Windows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer System Files=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROFILE%]\explorer.exe=[%PROFILE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROFILE_TEMP%]\explorer.exe=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%APPDATA%]\explorer.exe=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]Explorer=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]Explorer=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\mswindows\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%LOCAL_APPDATA%]\explorer.exe=[%LOCAL_APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%PROFILE%]\explorer.exe=[%PROFILE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%COMMON_APPDATA%]\explorer.exe=[%COMMON_APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%PROFILE_TEMP%]\explorer.exe=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%APPDATA%]\explorer.exe=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%LOCAL_APPDATA%]\explorer.exe=[%LOCAL_APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%COMMON_APPDATA%]\explorer.exe=[%COMMON_APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]iwindows=[%APPDATA%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]winupdate=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]xwp=[%SYSTEM%]\F01538F6644\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows File Explorer=[%APPDATA%]\Explorer.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROFILE%]\explorer.exe=[%PROFILE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROGRAM_FILES_COMMON%]\explorer.exe=[%PROGRAM_FILES_COMMON%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROFILE_TEMP%]\explorer.exe=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%SYSTEM_DRIVE%]\explorer.exe=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%APPDATA%]\explorer.exe=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROGRAM_FILES_COMMON%]\explorer.exe=[%PROGRAM_FILES_COMMON%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%SYSTEM_DRIVE%]\explorer.exe=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%PROFILE%]\explorer.exe=[%PROFILE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%PROGRAM_FILES_COMMON%]\explorer.exe=[%PROGRAM_FILES_COMMON%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%PROFILE_TEMP%]\explorer.exe=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%SYSTEM_DRIVE%]\explorer.exe=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce][%APPDATA%]\explorer.exe=[%APPDATA%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]klp=[%SYSTEM%]\PAL\CSS\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]systemfile=[%SYSTEM_DRIVE%]\Temp\System\Explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows File Explorer=[%APPDATA%]\Explorer.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Services Entry=[%SYSTEM_DRIVE%]\Temp\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Services Entry=[%SYSTEM_DRIVE%]\Temp\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cerberus=[%WINDOWS%]\explorer\explorer.exe.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cerberus=[%WINDOWS%]\explorer\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Hosting Service=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Windows Hosting Service=[%PROFILE_TEMP%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Hidden]Explorer=[%SYSTEM%]\Microsoft\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]winupdate="[%PROFILE_TEMP%]\explorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\system\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\system\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorador de Windows=[%PERSONAL%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\nvdse\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\nvdse\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cerberus=[%SYSTEM%]\explorer\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cerberus=[%SYSTEM%]\explorer\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM_DRIVE%]\Directory\System32\Cookies\explorer\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM_DRIVE%]\Directory\System32\Cookies\explorer\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]CSM=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Loader=[%PROGRAM_FILES%]\Internet Explorer\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Loader=[%PROGRAM_FILES%]\Internet Explorer\Explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Mozilla=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Mozilla=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]mdm=[%SYSTEM%]\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]aawservice=[%SYSTEM%]\explorer.exe.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]taskmgr=[%SYSTEM%]\explorer.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%ANY_FOLDER%]\snet\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%ANY_FOLDER%]\snet\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]incognito=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer.exe=[%SYSTEM%]\Explorer.exe\windows.exe.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer.exe=[%SYSTEM%]\Explorer.exe\windows.exe.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKLM=[%SYSTEM%]\spynet\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%SYSTEM%]\spynet\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]HKCU=[%APPDATA%]\spynet\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled by Starter)]HKLM=[%SYSTEM%]\spynet\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled by Starter)]HKCU=[%SYSTEM%]\spynet\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Malwarebytes Anti-Malware (reboot)="[%PROGRAM_FILES%]\Malwarebytes' Anti-Malware\explorer.exe.exe" /runcleanupscript
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]fe3r4rf=[%SYSTEM_DRIVE%]\rooty\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]hhh=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]WinXPService=[%WINDOWS%]\Installer\{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2E}\r2c\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]EXPLORER.EXE=EXPLORER.EXE
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]fe3r4rf=[%SYSTEM_DRIVE%]\rooty\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]anti-virus 2007=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]internet_explorer=[%SYSTEM_DRIVE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]project_einstein=[%SYSTEM_DRIVE%]\system_info\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]Microsoft Driver Setup=[%SYSTEM%]\drivers\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Driver Setup=[%SYSTEM%]\drivers\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Help=[%RECYCLE_BIN%]\Explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=[%SYSTEM_DRIVE%]\hyd\Tools\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Avira=[%SYSTEM_DRIVE%]\hyd\Tools\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]internet_explorer=[%ANY_DRIVE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Updater=[%APPDATA%]\updater\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SystemExplorer="[%PROGRAM_FILES%]\System Explorer\SystemExplorer.exe" /TRAY
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]protection=[%SYSTEM%]\config\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]protection 2=[%SYSTEM%]\config\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Audiocodec=[%SYSTEM%]\winsyds\iexplorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]videocodecs=[%SYSTEM%]\winsyds\iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]klp=[%SYSTEM%]\PAL\KLP\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled by Starter)]Updater=[%SYSTEM%]\updater\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SService=[%WINDOWS%]\TEMP\EXPLORER.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]System Restore=[%WINDOWS%]\TEMP\EXPLORER.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer Key=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]klp=[%ANY_FOLDER%]\KLP\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run][%PROGRAM_FILES%]\KidPix\explorer.exe=[%PROGRAM_FILES%]\KidPix\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft Intranet Patcher=[%APPDATA%]\intranetexplorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{27D5ED5F-8092-7FE3-A9F2-9B4D0455C49B}=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]system32.exe=[%APPDATA%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]eMuleAutoStart=[%SYSTEM%]\drivers\disdn\eMule0.48a-ScarAngel_v2.5-bin\explorer.exe -AutoStart
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled]explorer=[%SYSTEM%]\Explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]Updater="[%SYSTEM%]\updater\explorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]Updater=[%SYSTEM%]\updater\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Update=[%PROGRAM_FILES_COMMON%]\System\iexplorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\iexplorer.exe en
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]iexplorer=[%WINDOWS%]\tmpie\iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]iexplorer=[%WINDOWS%]\tmpie\iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\Sys\Explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Hamachi=[%SYSTEM%]\cexplorer.exe -run
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SystemExplorer="[%ANY_FOLDER%]\SystemExplorer\SystemExplorer.exe" /TRAY
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]Windows Taskmanager=iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Taskmanager=iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]QuicktimerTask32=[%WINDOWS%]\aroot\msexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%SYSTEM%]\iexplorer.exe en
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices-]Microsoft=explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]Microsoft=explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]Microsoft=explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer=[%APPDATA%]\iexplorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]IEXPLORER=[%SYSTEM%]\iexplorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]winxp=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer 2238=[%PROFILE_TEMP%]\24334\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]explorer=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]SystemExplorer="[%DESKTOP%]\software\SystemExplorer\SystemExplorer.exe" /TRAY
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]SpybotDeletingC9824=cmd /c del "[%WINDOWS%]\iexplorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]SpybotDeletingC1229=cmd /c del "[%WINDOWS%]\iexplorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]SpybotDeletingC3494=cmd /c del "[%WINDOWS%]\iexplorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]SpybotDeletingD2488=cmd /c del "[%WINDOWS%]\iexplorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]SpybotDeletingD2632=cmd /c del "[%WINDOWS%]\iexplorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]SpybotDeletingD8140=cmd /c del "[%WINDOWS%]\iexplorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Explorer="[%APPDATA%]\explorer.exe"
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Scbu="[%SYSTEM%]\RACLE~1\explorer.exe" -vt yazb
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]VondleExplorer="[%PROGRAM_FILES%]\Bricsys\VondleExplorer\VondleExplorer.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]DRam prosessor=explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]DRam prosessor=explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Cpue="[%SYSTEM%]\CROSOF~1.NET\explorer.exe" -vt yazb
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Sen="[%PERSONAL%]\SSEMBL~1\explorer.exe" -vt ndrv
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]startkey=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]startkey=[%SYSTEM%]\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Windows Explorer=explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] cleaner7=[%PROGRAM_FILES%]\thread22\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] MsExplorer=[%PROGRAM_FILES%]\Internet Explorer\PLUGINS\explorer.exe
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Windows Update=[%SYSTEM%]\Explorer.EXE
  • [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] *Windows Update=[%SYSTEM%]\Explorer.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] crtfmon=[%PROFILE%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Explorer=[%SYSTEM%]\Sys\Explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Explorer=[%WINDOWS%]\$NtServicePackUninstall$\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Explorer Shell=[%WINDOWS%]\ServicePackFiles\i386\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] IExplorer=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] MsExplorer=[%PROGRAM_FILES%]\Internet Explorer\PLUGINS\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Svcs: Dnscache=[%PROFILE_TEMP%]\17226\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Windows Explorer=explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Windows Explorer Key=[%SYSTEM%]\explorer.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Windows Update=[%SYSTEM%]\Explorer.EXE
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] *Windows Update=[%SYSTEM%]\Explorer.EXE