Exterminate It! Antimalware

malpedia

Known threats:700,085 Last Update:March 01, 12:55

Testimonials

In recent weeks, my computer has been infected with malware and adware that just would not quit. A*G G*****t failed to remove them. S****t just froze up. Another anti-virus program just sat there and looked at me. So I purchased Exterminate It! This was the only anti-virus program I could find that would recognize and remove particularly pesky viruses from my computer. But even more impressive, they allow subscribers to send in descriptions of new viruses they encounter, and they will design a way to remove the virus and send out to you an update. I submitted the description of a virus to them, and a couple of days later they sent to me an update that cleanly removed it. If you run into viruses that just won't quit, give this anti-virus program a try. It's cheap and removes the viruses that the other anti-virus programs can't touch for some reason.

Source

Brother Mel

ZenoSearch- Registry Values List

This is a complete list of ZenoSearch registry values collected by Exterminate It!. If you find any of these registry values on your PC, your computer is very likely to be infected with the ZenoSearch - adware.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]sysstart=[%COMMON_APPDATA%]\SSA\monitor.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]sysstart=[%COMMON_APPDATA%]\SSA\envtask.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\swinopem.exe ELT001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3B-BA-A4-40-ZN}=[%SYSTEM%]\ondsregk.exe ELT001
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rwinoldm.exe SKY009
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{09-9D-DD-D7-ZN}=[%SYSTEM%]\kndsregj.exe SKY009
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mwinlndt.exe SKY009
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mwintndt.exe CHD003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\twinpldi.exe CHA001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{16-61-1B-B5-ZN}=[%SYSTEM%]\kodsrngj.exe CHA001
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\twinpldi.exe CHA001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CD-DB-B8-8D-ZN}=[%SYSTEM%]\dwdsrngt.exe CHD003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\owinpqdi.exe GID003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{25-58-80-01-ZN}=[%SYSTEM%]\podsregq.exe GID003
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\owinpqdi.exe GID003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rwinrsdi.exe CHD003
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rwinrsdi.exe CHD003
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]sysstart=[%SYSTEM_DRIVE%]\syswin.exe 1
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntrtdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntrsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntmsdi.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntmsdi.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qwinomdt.exe CHD003
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntrsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qwinlped.exe GID002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched="[%SYSTEM%]\tcntttdm.exe" DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D7-71-1A-AC-DW}="[%SYSTEM%]\rwwnw64d.exe" DWram
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched="[%SYSTEM%]\tcntttdm.exe" DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3C-C0-01-1F-ZN}=[%SYSTEM%]\pjdsregs.exe GID002
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\swintldq.exe CHD001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A8-8F-FC-CE-DW}=[%SYSTEM%]\pinz1\cegmgr76.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntksdh.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2C-CD-D2-25-DW}=[%SYSTEM%]\rqwnw64k.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8A-AD-D1-1D-DW}=[%SYSTEM%]\rkwnw64s.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{AA-A6-60-0B-ZN}=[%SYSTEM%]\dwdsregt.exe CORN001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{73-3A-A2-20-DW}=[%SYSTEM%]\rqwnw64k.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{94-42-2B-B6-DW}=[%SYSTEM%]\jmwnw64n.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntktdi.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F2-24-41-14-DW}=[%SYSTEM%]\rkwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntktdi.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{37-71-1E-E1-DW}=[%SYSTEM%]\rqwnw64o.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntntdi.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntntdi.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntnsdi.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{9C-C5-57-76-DW}=[%SYSTEM%]\rqwnw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntnsdi.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8B-BA-A9-9F-DW}=[%SYSTEM%]\rwwnw64d.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{55-5B-B6-6E-DW}=[%SYSTEM%]\rqwnw64n.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntqtdi.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{85-51-1C-C8-DW}=[%SYSTEM%]\rmwnw64l.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2B-B5-58-8F-DW}=[%SYSTEM%]\rlwnw64s.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcnttsdi.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1C-C1-18-85-DW}=[%SYSTEM%]\rswnw64p.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcnttsdi.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\swinkldi.exe MSM002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{BE-E0-0E-EA-ZN}=[%SYSTEM%]\kjdsrngq.exe MSM002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntqtdj.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A7-70-0F-F4-DW}=[%SYSTEM%]\rlwnw64p.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\swinkldi.exe MSM002
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rcntqtdj.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)]ExploreUpdSched=[%SYSTEM%]\qwinmndt.exe SKY009
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)]{35-56-6E-EF-ZN}=[%SYSTEM%]\mldsregr.exe SKY009
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntpkdj.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{AA-A9-93-3F-DW}=[%SYSTEM%]\jownw64j.exe DWram
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntpkdj.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4D-D6-66-6A-DW}=[%SYSTEM%]\rmwnw64s.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntmtdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B3-32-24-4E-DW}=[%SYSTEM%]\rjwnw64o.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mwinrpdm.exe CHA001
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mwinrpdm.exe CHA001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E9-99-94-41-DW}=[%SYSTEM%]\rpwnw64k.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rwinkpdm.exe GID002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{60-09-93-37-ZN}=[%SYSTEM%]\dwdsregt.exe GID002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntnsdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DD-D2-29-9A-DW}=[%SYSTEM%]\rqwnw64k.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntnsdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2F-FA-AC-CF-DW}=[%SYSTEM%]\rnwnw64q.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rwinlldm.exe GAMES001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntqtdm.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{00-01-11-10-DW}=[%SYSTEM%]\rswnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{00-00-00-04-DW}=[%SYSTEM%]\rswnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{00-00-00-00-DW}=[%SYSTEM%]\rswnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntqtdm.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntaxdm.exe DWram1
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{FE-E7-7F-F4-DW}=[%SYSTEM%]\rqwnw64p.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntlldm.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]g]eeV\mWhjlnspB=[%SYSTEM%]\qcntlldn.exe DWram
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntlldm.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kwinkpdt.exe GID002
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kwinkpdt.exe GID002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntnsdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntnsdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntqsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{EC-C2-29-93-DW}=[%SYSTEM%]\rmwnw64m.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F6-64-40-09-DW}=[%SYSTEM%]\rqwnw64k.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntotdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntotdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntosdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8F-FD-DF-FF-DW}=[%SYSTEM%]\rqwnw64n.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntlsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntlsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntosdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{95-5B-BA-A6-DW}=[%SYSTEM%]\rqwnw64o.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C6-63-35-5D-DW}=[%SYSTEM%]\rqwnw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntosdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A5-53-30-02-DW}=[%SYSTEM%]\dwwnw64r.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntosdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntqkdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{08-86-62-21-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntqkdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{5F-FA-AA-A0-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntpsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{5F-F1-1B-B2-DW}=[%SYSTEM%]\rswnw64p.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntpsdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1E-EC-C6-6E-DW}=[%SYSTEM%]\rqwnw64k.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{21-18-8D-DE-DW}=[%SYSTEM%]\jownw64q.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntpsdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DE-EB-B7-7A-DW}=[%SYSTEM%]\rownw64j.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-Disabled]{DB-B5-51-1D-DW}=[%SYSTEM%]\rjwnw64n.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DB-B5-51-1D-DW}=[%SYSTEM%]\rjwnw64n.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{28-87-7D-DB-DW}=[%SYSTEM%]\rmwnw64k.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntpkdm.exe DWram
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntssdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D1-18-80-0E-ZN}=[%SYSTEM%]\rqdsrngo.exe P2D002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D1-18-80-0E-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntpkdm.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C7-7B-B1-14-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntqsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{02-2E-E8-8A-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcnttsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{53-3B-BE-EF-DW}=[%SYSTEM%]\rqwnw64m.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C7-7B-B1-14-DW}=[%SYSTEM%]\rrwnw64s.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B7-75-56-69-DW}=[%SYSTEM%]\rqwnw64o.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcnttsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{02-2E-E8-8A-DW}=[%SYSTEM%]\rswnw64j.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntqsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntrsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C8-83-35-50-DW}=[%SYSTEM%]\rkwnw64l.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntqsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{9B-B3-3E-E4-DW}=[%SYSTEM%]\rrwnw64m.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcnttsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C2-28-8C-CC-DW}=[%SYSTEM%]\rqwnw64l.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntrsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcnttsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntssdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{BE-E8-8F-F4-DW}=[%SYSTEM%]\rqwnw64o.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntttdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D1-18-80-0E-DW}=[%SYSTEM%]\rrwnw64o.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A6-68-8B-B5-DW}=[%SYSTEM%]\rrwnw64l.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntosdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntssdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4A-A7-77-7A-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntksdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{33-3F-FD-D2-DW}=[%SYSTEM%]\rrwnw64j.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A2-2A-A9-9E-DW}=[%SYSTEM%]\rlwnw64k.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntksdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntqtdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{15-55-50-0C-DW}=[%SYSTEM%]\rkwnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntptdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{50-0C-C2-2B-DW}=[%SYSTEM%]\rkwnw64q.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{34-4F-FA-A9-DW}=[%SYSTEM%]\rqwnw64q.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CB-B9-94-43-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntlsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1A-AE-E3-3F-DW}=[%SYSTEM%]\rrwnw64n.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntqtdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntptdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4F-F4-4F-F0-DW}=[%SYSTEM%]\rrwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntmsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{26-6E-ED-D0-DW}=[%SYSTEM%]\rswnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntstdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched="[%SYSTEM%]\tcntosdl.exe" DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{24-49-93-3C-DW}="[%SYSTEM%]\rswnw64l.exe" DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3C-CA-A2-2A-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2D-D5-5C-CE-DW}=[%SYSTEM%]\rqwnw64n.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntnsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntstdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched="[%SYSTEM%]\tcntosdl.exe" DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntmsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D5-56-6C-C3-DW}=[%SYSTEM%]\rrwnw64s.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{FD-D3-3A-A7-DW}=[%SYSTEM%]\rrwnw64n.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntqkdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{AD-D0-01-1B-DW}=[%SYSTEM%]\jpwnw64o.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C9-9A-AC-CA-DW}=[%SYSTEM%]\rrwnw64n.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8E-E4-4D-DB-DW}=[%SYSTEM%]\rownw64s.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntmsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntlsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{15-5B-B7-70-DW}=[%SYSTEM%]\rrwnw64o.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{88-88-84-47-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntmsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{88-88-84-47-DW}=[%SYSTEM%]\rrwnw64k.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntqkdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntlsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntmsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntqsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{74-4C-CE-E7-DW}=[%SYSTEM%]\rrwnw64j.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntmkdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntssdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CB-B0-0D-D1-DW}=[%PROFILE_TEMP%]\eco98IV.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{58-8F-FF-F3-DW}=[%SYSTEM%]\rrwnw64o.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntmkdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{FE-EA-A8-81-DW}=[%SYSTEM%]\rkwnw64s.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntqsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{10-09-9F-F2-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntrsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1D-DF-FB-BE-DW}=[%SYSTEM%]\rrwnw64j.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E6-69-90-08-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntmtdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{60-07-7B-B5-DW}=[%SYSTEM%]\rswnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntmtdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntptdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{46-6E-E6-65-DW}=[%SYSTEM%]\rswnw64l.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntotdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B4-42-28-85-DW}=[%SYSTEM%]\rmwnw64o.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntrsdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8D-D4-49-9F-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntptdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntotdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{79-9D-DF-F5-DW}=[%SYSTEM%]\rpwnw64o.exe DWbrk01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntssdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{76-69-93-3D-DW}=[%SYSTEM%]\rrwnw64l.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{99-9D-D3-3E-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{EF-FE-E9-90-DW}=[%SYSTEM%]\rkwnw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntmtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E2-24-46-66-DW}=[%SYSTEM%]\rjwnw64n.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntmtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2C-C2-2B-BE-DW}=[%SYSTEM%]\rswnw64o.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{7A-A0-04-40-DW}=[%SYSTEM%]\rswnw64s.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CC-C8-8C-CF-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntosdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntmsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{34-49-95-59-DW}=[%SYSTEM%]\rswnw64j.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntosdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{65-58-82-2A-DW}=[%SYSTEM%]\rswnw64p.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntosdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D0-00-01-1F-DW}=[%SYSTEM%]\rswnw64p.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntqkdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{31-1D-DD-D3-DW}=[%SYSTEM%]\jpwnw64p.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{80-05-57-7C-DW}=[%SYSTEM%]\rswnw64l.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntosdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E7-7C-CC-C2-DW}=[%SYSTEM%]\rswnw64k.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntpkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{43-3A-A5-55-DW}="[%SYSTEM%]\rswnw64k.exe" DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntpkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched="[%SYSTEM%]\rcntqsdl.exe" DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{5A-AF-F3-3E-DW}="[%SYSTEM%]\rswnw64l.exe" DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntlkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E9-9E-EE-EC-DW}=[%SYSTEM%]\jkwnw64o.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D3-3B-BC-C1-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcnttsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched="[%SYSTEM%]\rcntqsdl.exe" DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntlkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcnttsdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F0-07-7D-DA-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8E-E7-71-1E-DW}=[%SYSTEM%]\rswnw64k.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntrtdl.exe DWAM01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F1-16-6F-FC-DW}=[%SYSTEM%]\rownw64l.exe DWAM01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntrtdl.exe DWAM01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntptdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntptdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntltdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{13-36-62-20-DW}=[%SYSTEM%]\rkwnw64s.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{43-33-31-12-DW}=[%SYSTEM%]\rlwnw64n.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DE-E7-7D-DF-DW}=[%SYSTEM%]\rkwnw64o.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F4-44-4B-B6-DW}=[%SYSTEM%]\rkwnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6B-BF-F6-67-DW}=[%SYSTEM%]\rjwnw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntltdl.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntltdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntltdl.exe DWmmm01XX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mwinmldm.exe CHD003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2E-EE-E7-76-ZN}=[%SYSTEM%]\kldsrngk.exe CHD003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{31-19-98-82-DW}=[%SYSTEM%]\rkwnw64n.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B3-36-6E-E1-DW}=[%SYSTEM%]\rlwnw64m.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntntdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{97-74-49-97-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntntdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntokdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{74-4A-A1-14-DW}=[%SYSTEM%]\jnwnw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{FF-F2-2F-F2-DW}=[%SYSTEM%]\rlwnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{38-8F-FD-D9-DW}=[%SYSTEM%]\rjwnw64l.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntokdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntrtdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{25-50-0A-AA-DW}=[%SYSTEM%]\rjwnw64j.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntttdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8B-B7-78-84-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntptdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{55-50-0B-BA-DW}=[%SYSTEM%]\rjwnw64q.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CE-EE-E9-92-DW}=[%SYSTEM%]\rlwnw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntptdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntotdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{12-2A-AD-D2-DW}=[%SYSTEM%]\rkwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pwinpmdt.exe CHD003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntptdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{50-0C-C2-2B-DW}=[%SYSTEM%]\rkwnw64q.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{9C-C7-7B-B2-DW}=[%SYSTEM%]\rjwnw64l.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{FA-A4-4C-C0-DW}=[%SYSTEM%]\rlwnw64m.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntltdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{0D-D2-29-9B-DW}=[%SYSTEM%]\rswnw64l.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntrtdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntttdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B0-0A-AC-CE-DW}=[%SYSTEM%]\rjwnw64q.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{EE-E0-02-2D-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntqtdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{5D-DA-A9-92-DW}=[%SYSTEM%]\rjwnw64j.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntotdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntptdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntltdm.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntttdl.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rcntqtdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{36-69-9F-FD-DW}=[%SYSTEM%]\rkwnw64r.exe DWrvgYB
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntmtdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{ED-DB-BD-D8-DW}=[%SYSTEM%]\rkwnw64p.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6D-D4-47-7B-DW}=[%SYSTEM%]\rkwnw64q.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D4-40-0C-C7-DW}=[%SYSTEM%]\rjwnw64j.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D3-35-54-49-DW}=[%SYSTEM%]\rjwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D4-40-0C-C7-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntmtdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntnkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6F-F3-3B-B6-DW}=[%SYSTEM%]\jmwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntlkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{75-5F-F1-13-DW}=[%SYSTEM%]\jkwnw64m.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A3-3F-F8-83-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{04-4E-E2-29-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6F-F5-53-3E-DW}=[%SYSTEM%]\jpwnw64o.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntntdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{86-6B-B4-48-DW}=[%SYSTEM%]\rkwnw64s.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{98-8D-DD-DA-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntlkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4E-E8-84-41-DW}=[%SYSTEM%]\rkwnw64s.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntqtdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntqtdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{5A-A3-31-18-DW}=[%SYSTEM%]\rkwnw64o.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4B-BF-F0-0A-DW}=[%SYSTEM%]\rkwnw64j.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8E-EF-FE-EC-DW}=[%SYSTEM%]\rmwnw64j.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntpkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{ED-D6-69-9B-DW}=[%SYSTEM%]\jownw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{02-28-84-43-DW}=[%SYSTEM%]\rkwnw64n.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntotdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DC-CC-CA-AD-DW}=[%SYSTEM%]\rkwnw64j.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DB-B1-17-70-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntltdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{75-50-00-03-DW}=[%SYSTEM%]\rpwnw64p.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]{88-81-17-78-DW}=[%SYSTEM%]\rkwnw64p.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1D-DF-FD-D1-DW}=[%SYSTEM%]\rlwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DB-B1-13-35-DW}=[%SYSTEM%]\rlwnw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{71-16-69-96-DW}=[%SYSTEM%]\rkwnw64p.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{69-90-0C-C2-DW}=[%SYSTEM%]\rlwnw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntltdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntotdl.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{BB-B6-61-1F-DW}=[%SYSTEM%]\rkwnw64r.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{28-8C-C0-01-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{96-68-89-95-DW}=[%SYSTEM%]\rlwnw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qwinpldm.exe P2D002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E4-4A-AD-D9-ZN}=[%SYSTEM%]\kodsrngr.exe P2D002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kwinlndm.exe SKY009
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{AC-CD-DC-CE-ZN}=[%SYSTEM%]\mkdsregq.exe SKY009
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qwinpldm.exe P2D002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{25-54-46-60-DW}=[%SYSTEM%]\rlwnw64p.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E7-74-44-42-DW}=[%SYSTEM%]\rkwnw64o.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{FE-ED-DF-FB-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{0D-D8-86-64-DW}=[%SYSTEM%]\rkwnw64l.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A7-78-86-65-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{38-8D-DB-B8-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F0-0F-FD-D3-DW}=[%SYSTEM%]\rkwnw64q.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D1-18-80-0E-DW}=[%SYSTEM%]\rkwnw64m.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4C-CB-BB-B3-DW}=[%SYSTEM%]\rlwnw64s.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D6-65-5C-C1-DW}=[%SYSTEM%]\rkwnw64j.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6A-A0-0F-FB-DW}=[%SYSTEM%]\rpwnw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{41-16-60-04-DW}=[%WINDOWS%]\qggu58826.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{00-08-8D-D9-DW}=[%SYSTEM%]\rlwnw64s.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{67-77-7B-BB-DW}=[%SYSTEM%]\rkwnw64j.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{84-43-3B-BC-DW}=[%SYSTEM%]\rlwnw64j.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CA-A2-22-29-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntstdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6C-CC-CD-D1-DW}=[%SYSTEM%]\rkwnw64j.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D1-18-80-0E-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{76-6D-DE-E3-DW}=[%SYSTEM%]\rmwnw64p.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntktdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F3-37-78-8B-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]g]eeV\mWhjlnspB=[%SYSTEM%]\rcntnndn.exe DWram
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntktdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntltdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{87-7D-D8-84-DW}=[%SYSTEM%]\rlwnw64o.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{7B-B9-94-4C-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D8-8A-AE-E9-DW}=[%SYSTEM%]\jkwnw64o.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{38-85-55-59-DW}=[%SYSTEM%]\rmwnw64m.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{64-4D-DF-FB-DW}=[%SYSTEM%]\rlwnw64q.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntttdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E6-68-8E-EE-DW}=[%SYSTEM%]\rlwnw64o.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntttdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntpkdm.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{32-2C-CC-C0-DW}=[%SYSTEM%]\rlwnw64s.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntqtdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntqtdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F9-93-3F-FB-DW}=[%SYSTEM%]\dwwnw64r.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{81-13-3F-FD-DW}=[%SYSTEM%]\jownw64m.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntqtdl.exe DWmmm01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{43-3A-A9-94-DW}=[%SYSTEM%]\rpwnw64o.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntstdl.exe DWbrk02FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{71-1F-FA-AF-DW}=[%SYSTEM%]\rlwnw64j.exe DWbrk02FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntntdl.exe DWbrk02FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3F-FB-BC-CD-DW}=[%SYSTEM%]\rownw64k.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rcntstdl.exe DWbrk02FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E1-16-6F-FF-DW}=[%SYSTEM%]\JMWNW64O.EXE DWram
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\OCNTNKDM.EXE DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntktdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntptdm.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{8B-B9-96-65-DW}=[%SYSTEM%]\rmwnw64s.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B4-4E-EF-FB-ZN}=[%SYSTEM%]\nkdsregl.exe CHA001
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CD-D0-04-45-DW}=[%SYSTEM%]\rownw64l.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rcntptdm.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{ED-DA-A6-63-DW}=[%SYSTEM%]\rnwnw64n.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{39-92-23-31-DW}=[%SYSTEM%]\rownw64j.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\nwinkoeb.exe GID002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2F-F8-82-26-DW}=[%SYSTEM%]\rmwnw64p.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\nwinkoeb.exe GID002
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntrtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{80-07-70-0B-DW}=[%SYSTEM%]\rmwnw64s.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rcntrtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{35-5A-AE-E0-DW}=[%SYSTEM%]\rmwnw64l.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{EA-A3-39-91-DW}=[%SYSTEM%]\rmwnw64l.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3B-B4-48-80-DW}=[%SYSTEM%]\rmwnw64o.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntktdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{33-38-8C-CA-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{07-7D-D2-23-DW}=[%SYSTEM%]\rmwnw64q.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntqkdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{AF-FB-B4-4E-DW}=[%SYSTEM%]\jpwnw64o.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{1C-C6-6F-FE-DW}=[%SYSTEM%]\rpwnw64o.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntqkdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{37-7E-EF-FD-DW}=[%SYSTEM%]\rownw64r.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{37-7E-EF-FD-DW}=[%SYSTEM%]\dwwnw64r.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{53-32-23-3C-DW}=[%SYSTEM%]\rmwnw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntqkdm.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{7E-E3-33-34-DW}=[%SYSTEM%]\jpwnw64l.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{D5-51-1E-E6-DW}=[%SYSTEM%]\rownw64l.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntqkdm.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntotdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3B-B8-81-13-DW}=[%SYSTEM%]\rmwnw64n.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntotdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntotdl.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\lcntntdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6D-D0-05-5E-DW}=[%SYSTEM%]\rmwnw64m.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DE-E0-08-8F-DW}=[%SYSTEM%]\rmwnw64q.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\lcntntdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{04-4C-C4-49-DW}=[%SYSTEM%]\rmwnw64j.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntntdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{B1-12-2B-B7-DW}=[%SYSTEM%]\rmwnw64s.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ncntntdl.exe DWbrk01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{18-80-0C-C0-DW}=[%SYSTEM%]\dwwnw64r.exe DWbrk01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntqtdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{EF-F3-3F-F7-DW}=[%SYSTEM%]\rmwnw64s.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ncntntdl.exe DWbrk01
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntqtdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{5C-CE-E3-37-DW}=[%SYSTEM%]\rownw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{DB-B8-80-04-DW}=[%SYSTEM%]\rmwnw64l.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{68-88-80-05-DW}=[%SYSTEM%]\rnwnw64k.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntotdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CD-D9-9A-A5-DW}=[%SYSTEM%]\rmwnw64l.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{EE-EC-C8-82-DW}=[%SYSTEM%]\rownw64r.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{2B-B5-54-4D-ZN}=[%SYSTEM%]\lodsrngl.exe CHD003
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{9B-BE-EE-E0-DW}=[%SYSTEM%]\rnwnw64m.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{F9-91-14-49-DW}=[%SYSTEM%]\rmwnw64k.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{24-45-53-35-DW}=[%SYSTEM%]\dwwnw64r.exe DWram03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\kcntttdm.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{23-38-85-5C-DW}=[%SYSTEM%]\rrwnw64o.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\kcntttdm.exe DWrvgFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C1-1C-C8-85-DW}=[%SYSTEM%]\jpwnw64q.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntqtdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{E4-42-23-34-DW}=[%SYSTEM%]\rmwnw64s.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\rcntqtdl.exe DWbrk03FF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntqtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{77-7B-B0-00-DW}=[%SYSTEM%]\rmwnw64l.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{34-4C-C3-34-DW}=[%SYSTEM%]\dwwnw64r.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\tcntltdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{84-4B-B2-2B-DW}=[%SYSTEM%]\rnwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\tcntltdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{75-52-2D-D9-DW}=[%SYSTEM%]\rownw64k.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\mcntqtdl.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\rcntttdl.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntqtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntqtdl.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\scntkkdm.exe DWbrk01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{07-79-9E-EF-DW}=[%SYSTEM%]\jjwnw64q.exe DWbrk01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{6E-ED-D6-61-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\scntkkdm.exe DWbrk01
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{C4-49-99-9B-DW}=[%SYSTEM%]\dwwnw64r.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{4F-FB-B0-0B-DW}=[%SYSTEM%]\rmwnw64o.exe DWrvg
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{CE-EE-EF-F8-DW}=[%SYSTEM%]\rnwnw64o.exe DWbrk03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{3D-DD-D8-8A-DW}=[%SYSTEM%]\wTMP\idevdpll.exe DWram
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{23-35-53-36-DW}=[%SYSTEM%]\rownw64n.exe dwbrk03ffffFF
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\ocntttdl.exe dwbrk03ffffFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntmkdm.exe DWrvg
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntttdl.exe dwbrk03ffffFF
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\ocntltdm.exe DWrvgXX
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\pcntltdl.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A8-81-19-9F-DW}=[%SYSTEM%]\rnwnw64q.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]{A8-81-19-9F-DW}=[%SYSTEM%]\dwwnw64r.exe DWram03
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\qcntstdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\pcntltdl.exe DWram03
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]exploreupdsched=[%SYSTEM%]\qcntstdl.exe DWbrk02
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]ExploreUpdSched=[%SYSTEM%]\mcntotdl.exe DWram03FF
12