Monday, January 19, 2009

Pigeon.ENC Trojan

Pigeon.ENC malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Pigeon.ENC:

An up-to-date copy of ExterminateIt should detect and prevent infection from Pigeon.ENC.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Pigeon.ENC manually.

To completely manually remove Pigeon.ENC malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Pigeon.ENC.

  1. Use Task Manager to terminate the Pigeon.ENC process.
  2. Delete the original Pigeon.ENC file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Pigeon.ENC from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Pigeon.ENC!


Also Be Aware of the Following Threats:
Remove Bancos.FWW Trojan
SharaQQ Trojan Removal instruction
WDonn Trojan Cleaner
SillyDl.AOY Trojan Cleaner

Pigeon.EPM Trojan

Pigeon.EPM malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Pigeon.EPM:

An up-to-date copy of ExterminateIt should detect and prevent infection from Pigeon.EPM.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Pigeon.EPM manually.

To completely manually remove Pigeon.EPM malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Pigeon.EPM.

  1. Use Task Manager to terminate the Pigeon.EPM process.
  2. Delete the original Pigeon.EPM file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Pigeon.EPM from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Pigeon.EPM!


Also Be Aware of the Following Threats:
RedHanded Spyware Removal
Win32.ChiracDance!Trojan Backdoor Symptoms

Autorun Malware Malware

Autorun Malware malware description and removal detail
Categories:Malware
Visible Symptoms:
Files in system folders:
[%APPDATA%]\ASKS~1\svchost.exe
[%APPDATA%]\DOBE~1\logonui.exe
[%APPDATA%]\FNTS~1\netdde.exe
[%APPDATA%]\PPATCH~1\chkdsk.exe
[%APPDATA%]\SSEMBL~1\winspool.exe
[%APPDATA%]\YSTEM~1\winword.exe
[%COMMON_APPDATA%]\msw\BMan1.exe
[%COMMON_STARTUP%]\Uninstall64578.exe
[%FONTS%]\svchost.exe
[%PROFILE%]\gOhgkog.exe
[%PROFILE%]\mssvmdll.dll
[%PROFILE%]\scvhost.exe
[%PROFILE%]\WINDOWS\svchost.exe
[%PROFILE%]\winmain.exe
[%PROFILE%]\zbecczmv.exe
[%PROFILE_TEMP%]\II22.exe
[%PROFILE_TEMP%]\NpcNMdohh
[%PROFILE_TEMP%]\svchost.exe
[%PROFILE_TEMP%]\tmp6.tmp.exe
[%PROFILE_TEMP%]\update.exe
[%PROFILE_TEMP%]\x2000.exe
[%PROGRAM_FILES%]\180solutions\ncase\msbb155\msbb.exe
[%PROGRAM_FILES%]\3BSOFT~1\WINDOW~2\Windows Clean-Up Pro.exe
[%PROGRAM_FILES%]\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[%PROGRAM_FILES%]\AdTools Service\AdTools.exe
[%PROGRAM_FILES%]\AGSeydsApp\AGSeyApp.exe
[%PROGRAM_FILES%]\altnet\points manager\Points Manager.exe
[%PROGRAM_FILES%]\AltPayments\AltPayments.exe
[%PROGRAM_FILES%]\AOL\Active Virus Shield\avp.exe
[%PROGRAM_FILES%]\AQUATI~1\AQ3Helper.exe
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%PROGRAM_FILES%]\Aveo\Attune\bin\attune_ce.exe
[%PROGRAM_FILES%]\Aveo\Attune\Bin\Attune_ST.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\Bargain Buddy\bin\bargains.exe
[%PROGRAM_FILES%]\Block Checker\block-checker.exe
[%PROGRAM_FILES%]\Breakpoint Computers\WinTimer\wintimerc.exe
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~2\SCANMSG.EXE
[%PROGRAM_FILES%]\COMETS~1\DM\bin\dmserver.exe
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES%]\COMMON~2\TOOLBAR\winnet.exe
[%PROGRAM_FILES%]\Cosmi\HelpExpress\HXDL.EXE
[%PROGRAM_FILES%]\Cosmi\HelpExpress\Mr Mrs English\HXIUL.EXE
[%PROGRAM_FILES%]\CROSOF~1\services.exe
[%PROGRAM_FILES%]\CURITY~1\winlogon.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\Search.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\whse.exe
[%PROGRAM_FILES%]\DelFin\PromulGate\PgMonitr.exe
[%PROGRAM_FILES%]\DeluxeCommunications\Dxc.exe
[%PROGRAM_FILES%]\divx\divx pro codec\gain_trickler_3202a.exe
[%PROGRAM_FILES%]\Dpoint\bin\update.exe
[%PROGRAM_FILES%]\DreamGroup\No-Spy\No-Spy.exe
[%PROGRAM_FILES%]\DropSpam\oesrv.exe
[%PROGRAM_FILES%]\dslifestyle\dslifestyle.exe
[%PROGRAM_FILES%]\Error Safe Free\ERS.exe
[%PROGRAM_FILES%]\FNTS~1\dvdplay.exe
[%PROGRAM_FILES%]\Globe Software\StatBar\StatBar.exe
[%PROGRAM_FILES%]\GogoTools\Gogoware\LaunchAdware.exe
[%PROGRAM_FILES%]\GOTSMI~1\GSYUpdater.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HooTech\NetMeter\HooNetMeter.exe
[%PROGRAM_FILES%]\HP\HP Software Update\hpwuSchd2.exe
[%PROGRAM_FILES%]\Instant Buzz\IBDaemon.exe
[%PROGRAM_FILES%]\Internet Explorer\IEXPLORE.EXE
[%PROGRAM_FILES%]\Internet Explorer\Setup\svchost.exe
[%PROGRAM_FILES%]\Internet Optimizer\optimize.exe
[%PROGRAM_FILES%]\INTERNET WASHER PRO\IW.EXE
[%PROGRAM_FILES%]\INTERN~2\iw.exe
[%PROGRAM_FILES%]\Ipwindows\ipwins.exe
[%PROGRAM_FILES%]\ipwins\ipwins.exe
[%PROGRAM_FILES%]\ISTsvc\istsvc.exe
[%PROGRAM_FILES%]\iTunes\iTunes.exe
[%PROGRAM_FILES%]\iWatchNow, Inc\iWatchNow Media Center\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
[%PROGRAM_FILES%]\License_Manager\license_manager.exe
[%PROGRAM_FILES%]\LimeWire\LimeWire.exe
[%PROGRAM_FILES%]\Linksys EasyLink Advisor\LinksysAgent.exe
[%PROGRAM_FILES%]\Logitech input devices\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\KEM.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\mailskinner\MailSkinner.exe
[%PROGRAM_FILES%]\MCROSO~1.NET\ping.exe
[%PROGRAM_FILES%]\Media Access\MediaAccK.exe
[%PROGRAM_FILES%]\Messaging Names\msgrsvr.exe
[%PROGRAM_FILES%]\Microsoft IntelliType Pro\type32.exe
[%PROGRAM_FILES%]\MYWEBS~1\bar\1.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\MYWEBS~1\bar\2.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\NavExcel\NavHelper\v2.0.4d\navapp.exe
[%PROGRAM_FILES%]\NaviSearch\bin\nls.exe
[%PROGRAM_FILES%]\Netcom3 Cleaner\SpyClean.exe
[%PROGRAM_FILES%]\NetPumper\NetPumperIEProxy.exe
[%PROGRAM_FILES%]\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
[%PROGRAM_FILES%]\Notify\notify.exe
[%PROGRAM_FILES%]\Open Site\opensite.exe
[%PROGRAM_FILES%]\Optimum Online\Netsurf.exe
[%PROGRAM_FILES%]\Outerinfo\OuterinfoUpdate.exe
[%PROGRAM_FILES%]\outlook\outlook.exe
[%PROGRAM_FILES%]\p2pnetworks\mpp2pl.exe
[%PROGRAM_FILES%]\PCSecurityShield\The Shield Deluxe 2008\avp.exe
[%PROGRAM_FILES%]\PCSecurityShield\TheShieldDeluxe\avp.exe
[%PROGRAM_FILES%]\PestTrap\PestTrap.exe
[%PROGRAM_FILES%]\Power Manager\PM.exe
[%PROGRAM_FILES%]\Protocom\SecureLogin\slproto.exe
[%PROGRAM_FILES%]\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\QuickTime\qttask.exe
[%PROGRAM_FILES%]\RACLE~1\ping.exe
[%PROGRAM_FILES%]\RACLE~1\wucrtupd.exe
[%PROGRAM_FILES%]\RSSoft\RSEDNClient.exe
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\Save\Save.exe
[%PROGRAM_FILES%]\SCURIT~1\csrss.exe
[%PROGRAM_FILES%]\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
[%PROGRAM_FILES%]\seekmo\seekmo.exe
[%PROGRAM_FILES%]\Silicon Integrated Systems\SiSRaidPackage\Hot_Plug.exe
[%PROGRAM_FILES%]\Smart Keystroke Recorder\LogService.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.0.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.6.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\461~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\480~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\484~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\486~1.0\SBInst.exe
[%PROGRAM_FILES%]\Support.com\bin\tgkill.exe
[%PROGRAM_FILES%]\support.com\client\bin\tgcmd.exe
[%PROGRAM_FILES%]\support.com\client\lserver\Server.vbs
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%PROGRAM_FILES%]\SYSTEM~1\soap.exe
[%PROGRAM_FILES%]\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Timer\Timer.exe
[%PROGRAM_FILES%]\Toolbar\TBPS.exe
[%PROGRAM_FILES%]\TopSearch\TopSearch.exe
[%PROGRAM_FILES%]\V3\SYSMONNT.EXE
[%PROGRAM_FILES%]\VVSN\VVSN.exe
[%PROGRAM_FILES%]\webHancer\Programs\whagent.exe
[%PROGRAM_FILES%]\webHancer\Programs\whSurvey.exe
[%PROGRAM_FILES%]\Web_Rebates\WebRebates0.exe
[%PROGRAM_FILES%]\WhenUSearch\Search.exe
[%PROGRAM_FILES%]\WhenUSearch\whse.exe
[%PROGRAM_FILES%]\WildTangent\DDC\DDCManager\DDCMan.exe
[%PROGRAM_FILES%]\Winamp\winampa.exe
[%PROGRAM_FILES%]\WINCLE~1\SCANMSG.EXE
[%PROGRAM_FILES%]\Windows Media Player\csrss.exe
[%PROGRAM_FILES%]\Windows Media Player\wmplayer.exe
[%PROGRAM_FILES%]\WindowsSA\omniscient.exe
[%PROGRAM_FILES%]\WindowsUpdate\wupdate.exe
[%PROGRAM_FILES%]\WinFixer\wfxcwr.exe
[%PROGRAM_FILES%]\winupdates\winupdates.exe
[%PROGRAM_FILES%]\WinUpdate\WinUpdate.exe
[%PROGRAM_FILES%]\WNSXS~1\msdtc.exe
[%PROGRAM_FILES%]\zango\zango.exe
[%PROGRAM_FILES%]\Zcodec\ZUpdate\ZUpdate.exe
[%PROGRAM_FILES_COMMON%]\CMEII\CMESys.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\smss.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\winword.exe
[%PROGRAM_FILES_COMMON%]\ECURIT~1\cmd.exe
[%PROGRAM_FILES_COMMON%]\MBOLS~1\wuauclt.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\msnfo32.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\TaskUpdate.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\web server extensions\40\bots\vinavbar\svchost.exe
[%PROGRAM_FILES_COMMON%]\SCURIT~1\nslookup.exe
[%PROGRAM_FILES_COMMON%]\SSEMBL~1\winword.exe
[%PROGRAM_FILES_COMMON%]\Stone Shared\winCheck.exe
[%PROGRAM_FILES_COMMON%]\SYSTEM\MOSEARCH\BIN\mosearch.exe
[%PROGRAM_FILES_COMMON%]\system\ms2src.exe
[%PROGRAM_FILES_COMMON%]\System\Update.exe
[%PROGRAM_FILES_COMMON%]\System\WinService32.exe
[%PROGRAM_FILES_COMMON%]\YSTEM~1\logonui.exe
[%STARTUP%]\svchost.exe
[%SYSTEM%]\
[%SYSTEM%]\a.exe
[%SYSTEM%]\addins\svchost.exe
[%SYSTEM%]\adprot.exe
[%SYSTEM%]\aim.exe
[%SYSTEM%]\aqesyg.exe
[%SYSTEM%]\ASKS~1\winword.exe
[%SYSTEM%]\avgss.exe
[%SYSTEM%]\bootcfg1.exe
[%SYSTEM%]\bpsveyyu.exe
[%SYSTEM%]\byyskv.exe
[%SYSTEM%]\c.exe
[%SYSTEM%]\cd_load.exe
[%SYSTEM%]\cgheuj.exe
[%SYSTEM%]\cmd.exe
[%SYSTEM%]\cme.exe
[%SYSTEM%]\cmeupd.exe
[%SYSTEM%]\crdwsys\smss.exe
[%SYSTEM%]\CROSOF~1.NET\notepad.exe
[%SYSTEM%]\csrs.exe
[%SYSTEM%]\ctfmon.exe
[%SYSTEM%]\dllhost32.exe
[%SYSTEM%]\DRIVERS\services.exe
[%SYSTEM%]\drivers\sysdrv.exe
[%SYSTEM%]\drivers\system.exe
[%SYSTEM%]\EXECUSER.EXE
[%SYSTEM%]\exploer.exe
[%SYSTEM%]\explore.exe
[%SYSTEM%]\EXPLORER.EXE
[%SYSTEM%]\firewall.exe
[%SYSTEM%]\fx.exe
[%SYSTEM%]\guarnset.exe
[%SYSTEM%]\gycrzc.exe
[%SYSTEM%]\gylxto.exe
[%SYSTEM%]\hbcyjpsdsc.exe
[%SYSTEM%]\illusion1.exe
[%SYSTEM%]\infwin.exe
[%SYSTEM%]\iovyrn.exe
[%SYSTEM%]\isass.exe
[%SYSTEM%]\javaw.exe
[%SYSTEM%]\kernel32.exe
[%SYSTEM%]\kernels1118.exe
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\kmbnac.exe
[%SYSTEM%]\Kmr.exe
[%SYSTEM%]\lelel.EXE
[%SYSTEM%]\lich.exe
[%SYSTEM%]\linkprd.exe
[%SYSTEM%]\links.exe
[%SYSTEM%]\lnaccess.exe
[%SYSTEM%]\lockx.exe
[%SYSTEM%]\m4n70s.exe
[%SYSTEM%]\mcafee32.exe
[%SYSTEM%]\MccTrayApp.exe
[%SYSTEM%]\mmf32.exe
[%SYSTEM%]\mmsvc32.exe
[%SYSTEM%]\mose.bat
[%SYSTEM%]\MSDATLST.exe
[%SYSTEM%]\msdmxm.exe
[%SYSTEM%]\mshelp32.com
[%SYSTEM%]\msiexec16.exe
[%SYSTEM%]\msnmger.exe
[%SYSTEM%]\msnmsg.exe
[%SYSTEM%]\MSPRCSS32.exe
[%SYSTEM%]\Msrtmon.exe
[%SYSTEM%]\mswinup.exe
[%SYSTEM%]\mwsrvacc.exe
[%SYSTEM%]\mxcrtp.dll
[%SYSTEM%]\ncgeca.exe
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\ntos.exe
[%SYSTEM%]\ocglia.exe
[%SYSTEM%]\omryog.exe
[%SYSTEM%]\P2P Networking\P2P Networking2.exe
[%SYSTEM%]\prodsrvs.exe
[%SYSTEM%]\prosvsys.exe
[%SYSTEM%]\PSHWR.EXE
[%SYSTEM%]\rant.exe
[%SYSTEM%]\regedit.exe
[%SYSTEM%]\regscan.exe
[%SYSTEM%]\REGSVR32.EXE
[%SYSTEM%]\rizg.exe
[%SYSTEM%]\rk.exe
[%SYSTEM%]\rundll32.exe
[%SYSTEM%]\schost.exe
[%SYSTEM%]\scvhost.exe
[%SYSTEM%]\scyxdaaa.exe
[%SYSTEM%]\sdoitjjwx.exe
[%SYSTEM%]\security.exe
[%SYSTEM%]\server.exe
[%SYSTEM%]\service.exe
[%SYSTEM%]\service1.exe
[%SYSTEM%]\servicess.exe
[%SYSTEM%]\setup.dll
[%SYSTEM%]\SKS~1\lsass.exe
[%SYSTEM%]\slk8x2peu.exesmss.exe
[%SYSTEM%]\sountaskmgr
[%SYSTEM%]\sp2ctr.exe
[%SYSTEM%]\spoolsv32.exe
[%SYSTEM%]\spoolsvc.exe
[%SYSTEM%]\spoolsvv.exe
[%SYSTEM%]\spoolvs.exe
[%SYSTEM%]\srshost.exe
[%SYSTEM%]\SSEMBL~1\dllhost.exe
[%SYSTEM%]\SSTEM3~1\dexplore.exe
[%SYSTEM%]\SVCHOST32.EXE
[%SYSTEM%]\svdhost.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\svhcost.exe
[%SYSTEM%]\svhost.exe
[%SYSTEM%]\svhosts.exe
[%SYSTEM%]\svshost.exe
[%SYSTEM%]\sys32dll.exe
[%SYSTEM%]\Sysctrls.exe
[%SYSTEM%]\sysfrcx.exe
[%SYSTEM%]\sysinfo.exe
[%SYSTEM%]\systembackup.exe
[%SYSTEM%]\systray.exe
[%SYSTEM%]\sysup.exe
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskmgr32.exe
[%SYSTEM%]\taskmgrs.com
[%SYSTEM%]\taskmngr.exe
[%SYSTEM%]\tibs3.exe
[%SYSTEM%]\timoty.exe
[%SYSTEM%]\unbsjd.exe
[%SYSTEM%]\Update32.exe
[%SYSTEM%]\uvovha.exe
[%SYSTEM%]\v6.exe
[%SYSTEM%]\vcxubk.exe
[%SYSTEM%]\vidmon\vidmon.exe
[%SYSTEM%]\wapisvsu.exe
[%SYSTEM%]\wbem\csrss.exe
[%SYSTEM%]\win32.exe
[%SYSTEM%]\windll.exe
[%SYSTEM%]\windowsupdats.exe
[%SYSTEM%]\winExplore.exe
[%SYSTEM%]\winipsec.exe
[%SYSTEM%]\winlog.exe
[%SYSTEM%]\winn32.exe
[%SYSTEM%]\winspoof.exe
[%SYSTEM%]\winsystem.exe
[%SYSTEM%]\wintems.exe
[%SYSTEM%]\winupdate.exe
[%SYSTEM%]\WINWORD.EXE
[%SYSTEM%]\wjview.exe
[%SYSTEM%]\wmiprvse.exe
[%SYSTEM%]\wplayer.exe
[%SYSTEM%]\ws2_32s.exe
[%SYSTEM%]\ypudutmnsl.exe
[%SYSTEM%]\zlip.exe
[%SYSTEM%]\zzb2.exe
[%WINDOWS%]\%A0svchost.exe
[%WINDOWS%]\.exe
[%WINDOWS%]\1903cr.exe
[%WINDOWS%]\aqadcup.exe
[%WINDOWS%]\avp.exe
[%WINDOWS%]\b.exe
[%WINDOWS%]\bbstore\dss\dssagent.exe
[%WINDOWS%]\cfg32.exe
[%WINDOWS%]\csrss.exe
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\directx.dll.vbs
[%WINDOWS%]\DirectX3D.exe
[%WINDOWS%]\dll32\csrss.exe
[%WINDOWS%]\DLLServAPI.exe
[%WINDOWS%]\dnscleaner.exe
[%WINDOWS%]\Duce6.exe
[%WINDOWS%]\EditorNetDos.exe
[%WINDOWS%]\emsw.exe
[%WINDOWS%]\enhupdt.exe
[%WINDOWS%]\explorer.exe
[%WINDOWS%]\FONTS\A46F2.com
[%WINDOWS%]\IEcheck.exe
[%WINDOWS%]\iexplorer.exe
[%WINDOWS%]\igator\trickler3103_pic_fs_dmpt_3103.exe
[%WINDOWS%]\inet20126\winlogon.exe
[%WINDOWS%]\jawa32.exe
[%WINDOWS%]\jusched.exe
[%WINDOWS%]\krn3.exe
[%WINDOWS%]\lsass.exe
[%WINDOWS%]\lssas1.exe
[%WINDOWS%]\MDM.EXE
[%WINDOWS%]\mservice1.exe
[%WINDOWS%]\msnmsgs.exe
[%WINDOWS%]\msqdevl1.exe
[%WINDOWS%]\msresearch.exe
[%WINDOWS%]\Navnet.exe
[%WINDOWS%]\nerocheck.exe
[%WINDOWS%]\NetMSConfig.exe
[%WINDOWS%]\OCXSMTPDos.exe
[%WINDOWS%]\PixArt\PAC207\Monitor.exe
[%WINDOWS%]\PixArt\PAC7311\Monitor.exe
[%WINDOWS%]\regedit.exe
[%WINDOWS%]\reload.vbs
[%WINDOWS%]\Remove_spyware.exe
[%WINDOWS%]\RUNDLL.EXE
[%WINDOWS%]\RUNDLL32.EXE
[%WINDOWS%]\satmat.exe
[%WINDOWS%]\scvhost.exe
[%WINDOWS%]\SEMBLY~1\javaw.exe
[%WINDOWS%]\Sentry.exe
[%WINDOWS%]\Servces32.exe
[%WINDOWS%]\service.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\services.exe
[%WINDOWS%]\ShellNew\RakyatKelaparan.exe
[%WINDOWS%]\ShowWnd.exe
[%WINDOWS%]\smss.exe
[%WINDOWS%]\snchost.exe
[%WINDOWS%]\SOUNDMAN.EXE
[%WINDOWS%]\sp2update00.exe
[%WINDOWS%]\sqldata1.exe
[%WINDOWS%]\STEM~1\notepad.exe
[%WINDOWS%]\stisvsq1.exe
[%WINDOWS%]\surfmonkey\SMProxy.exe
[%WINDOWS%]\sv.exe
[%WINDOWS%]\svchost.exe
[%WINDOWS%]\svhost.exe
[%WINDOWS%]\svhost32.exe
[%WINDOWS%]\SvrWizardVBX32.exe
[%WINDOWS%]\svshost1.exe
[%WINDOWS%]\sysfade.exe
[%WINDOWS%]\System\csrss.exe
[%WINDOWS%]\SYSTEM\EXPLORER.SCR
[%WINDOWS%]\system\fsg_3202.exe
[%WINDOWS%]\System\loader.exe
[%WINDOWS%]\system\rundll32.exe
[%WINDOWS%]\system\smss.exe
[%WINDOWS%]\system\svchost.exe
[%WINDOWS%]\system\svchost32.exe
[%WINDOWS%]\system\svhost.exe
[%WINDOWS%]\system\winstart001.exe
[%WINDOWS%]\SysWow64\timoty.exe
[%WINDOWS%]\taskmon.exe
[%WINDOWS%]\TEMP\win28B8.tmp.exe
[%WINDOWS%]\TEMP\win7C0D.tmp.exe
[%WINDOWS%]\TEMP\win??.tmp.exe
[%WINDOWS%]\TEMP\winC02.tmp.exe
[%WINDOWS%]\trest.exe
[%WINDOWS%]\twainxp.exe
[%WINDOWS%]\uninstall\rundl132.exe
[%WINDOWS%]\WindowsSecurityUpdate.exe
[%WINDOWS%]\WindowsUpdates.exe
[%WINDOWS%]\WINDOWS\svhost.exe
[%WINDOWS%]\winnetdos32.exe
[%WINDOWS%]\winnows.exe
[%WINDOWS%]\WinOCXDos32.exe
[%WINDOWS%]\WinOCXPOP32.exe
[%WINDOWS%]\winoscnfg.exe
[%WINDOWS%]\wintcpmod.exe
[%WINDOWS%]\wnad.exe
[%WINDOWS%]\WNSXS~1\rundll.exe
[%WINDOWS%]\wuauclt.exe
[%WINDOWS%]\Xhrmy.exe
[%WINDOWS%]\xpupdate.exe
[%WINDOWS%]\\\etb\\pokapoka79.exe
[%APPDATA%]\ASKS~1\svchost.exe
[%APPDATA%]\DOBE~1\logonui.exe
[%APPDATA%]\FNTS~1\netdde.exe
[%APPDATA%]\PPATCH~1\chkdsk.exe
[%APPDATA%]\SSEMBL~1\winspool.exe
[%APPDATA%]\YSTEM~1\winword.exe
[%COMMON_APPDATA%]\msw\BMan1.exe
[%COMMON_STARTUP%]\Uninstall64578.exe
[%FONTS%]\svchost.exe
[%PROFILE%]\gOhgkog.exe
[%PROFILE%]\mssvmdll.dll
[%PROFILE%]\scvhost.exe
[%PROFILE%]\WINDOWS\svchost.exe
[%PROFILE%]\winmain.exe
[%PROFILE%]\zbecczmv.exe
[%PROFILE_TEMP%]\II22.exe
[%PROFILE_TEMP%]\NpcNMdohh
[%PROFILE_TEMP%]\svchost.exe
[%PROFILE_TEMP%]\tmp6.tmp.exe
[%PROFILE_TEMP%]\update.exe
[%PROFILE_TEMP%]\x2000.exe
[%PROGRAM_FILES%]\180solutions\ncase\msbb155\msbb.exe
[%PROGRAM_FILES%]\3BSOFT~1\WINDOW~2\Windows Clean-Up Pro.exe
[%PROGRAM_FILES%]\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[%PROGRAM_FILES%]\AdTools Service\AdTools.exe
[%PROGRAM_FILES%]\AGSeydsApp\AGSeyApp.exe
[%PROGRAM_FILES%]\altnet\points manager\Points Manager.exe
[%PROGRAM_FILES%]\AltPayments\AltPayments.exe
[%PROGRAM_FILES%]\AOL\Active Virus Shield\avp.exe
[%PROGRAM_FILES%]\AQUATI~1\AQ3Helper.exe
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%PROGRAM_FILES%]\Aveo\Attune\bin\attune_ce.exe
[%PROGRAM_FILES%]\Aveo\Attune\Bin\Attune_ST.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\Bargain Buddy\bin\bargains.exe
[%PROGRAM_FILES%]\Block Checker\block-checker.exe
[%PROGRAM_FILES%]\Breakpoint Computers\WinTimer\wintimerc.exe
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~2\SCANMSG.EXE
[%PROGRAM_FILES%]\COMETS~1\DM\bin\dmserver.exe
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES%]\COMMON~2\TOOLBAR\winnet.exe
[%PROGRAM_FILES%]\Cosmi\HelpExpress\HXDL.EXE
[%PROGRAM_FILES%]\Cosmi\HelpExpress\Mr Mrs English\HXIUL.EXE
[%PROGRAM_FILES%]\CROSOF~1\services.exe
[%PROGRAM_FILES%]\CURITY~1\winlogon.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\Search.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\whse.exe
[%PROGRAM_FILES%]\DelFin\PromulGate\PgMonitr.exe
[%PROGRAM_FILES%]\DeluxeCommunications\Dxc.exe
[%PROGRAM_FILES%]\divx\divx pro codec\gain_trickler_3202a.exe
[%PROGRAM_FILES%]\Dpoint\bin\update.exe
[%PROGRAM_FILES%]\DreamGroup\No-Spy\No-Spy.exe
[%PROGRAM_FILES%]\DropSpam\oesrv.exe
[%PROGRAM_FILES%]\dslifestyle\dslifestyle.exe
[%PROGRAM_FILES%]\Error Safe Free\ERS.exe
[%PROGRAM_FILES%]\FNTS~1\dvdplay.exe
[%PROGRAM_FILES%]\Globe Software\StatBar\StatBar.exe
[%PROGRAM_FILES%]\GogoTools\Gogoware\LaunchAdware.exe
[%PROGRAM_FILES%]\GOTSMI~1\GSYUpdater.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HooTech\NetMeter\HooNetMeter.exe
[%PROGRAM_FILES%]\HP\HP Software Update\hpwuSchd2.exe
[%PROGRAM_FILES%]\Instant Buzz\IBDaemon.exe
[%PROGRAM_FILES%]\Internet Explorer\IEXPLORE.EXE
[%PROGRAM_FILES%]\Internet Explorer\Setup\svchost.exe
[%PROGRAM_FILES%]\Internet Optimizer\optimize.exe
[%PROGRAM_FILES%]\INTERNET WASHER PRO\IW.EXE
[%PROGRAM_FILES%]\INTERN~2\iw.exe
[%PROGRAM_FILES%]\Ipwindows\ipwins.exe
[%PROGRAM_FILES%]\ipwins\ipwins.exe
[%PROGRAM_FILES%]\ISTsvc\istsvc.exe
[%PROGRAM_FILES%]\iTunes\iTunes.exe
[%PROGRAM_FILES%]\iWatchNow, Inc\iWatchNow Media Center\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
[%PROGRAM_FILES%]\License_Manager\license_manager.exe
[%PROGRAM_FILES%]\LimeWire\LimeWire.exe
[%PROGRAM_FILES%]\Linksys EasyLink Advisor\LinksysAgent.exe
[%PROGRAM_FILES%]\Logitech input devices\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\KEM.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\mailskinner\MailSkinner.exe
[%PROGRAM_FILES%]\MCROSO~1.NET\ping.exe
[%PROGRAM_FILES%]\Media Access\MediaAccK.exe
[%PROGRAM_FILES%]\Messaging Names\msgrsvr.exe
[%PROGRAM_FILES%]\Microsoft IntelliType Pro\type32.exe
[%PROGRAM_FILES%]\MYWEBS~1\bar\1.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\MYWEBS~1\bar\2.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\NavExcel\NavHelper\v2.0.4d\navapp.exe
[%PROGRAM_FILES%]\NaviSearch\bin\nls.exe
[%PROGRAM_FILES%]\Netcom3 Cleaner\SpyClean.exe
[%PROGRAM_FILES%]\NetPumper\NetPumperIEProxy.exe
[%PROGRAM_FILES%]\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
[%PROGRAM_FILES%]\Notify\notify.exe
[%PROGRAM_FILES%]\Open Site\opensite.exe
[%PROGRAM_FILES%]\Optimum Online\Netsurf.exe
[%PROGRAM_FILES%]\Outerinfo\OuterinfoUpdate.exe
[%PROGRAM_FILES%]\outlook\outlook.exe
[%PROGRAM_FILES%]\p2pnetworks\mpp2pl.exe
[%PROGRAM_FILES%]\PCSecurityShield\The Shield Deluxe 2008\avp.exe
[%PROGRAM_FILES%]\PCSecurityShield\TheShieldDeluxe\avp.exe
[%PROGRAM_FILES%]\PestTrap\PestTrap.exe
[%PROGRAM_FILES%]\Power Manager\PM.exe
[%PROGRAM_FILES%]\Protocom\SecureLogin\slproto.exe
[%PROGRAM_FILES%]\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\QuickTime\qttask.exe
[%PROGRAM_FILES%]\RACLE~1\ping.exe
[%PROGRAM_FILES%]\RACLE~1\wucrtupd.exe
[%PROGRAM_FILES%]\RSSoft\RSEDNClient.exe
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\Save\Save.exe
[%PROGRAM_FILES%]\SCURIT~1\csrss.exe
[%PROGRAM_FILES%]\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
[%PROGRAM_FILES%]\seekmo\seekmo.exe
[%PROGRAM_FILES%]\Silicon Integrated Systems\SiSRaidPackage\Hot_Plug.exe
[%PROGRAM_FILES%]\Smart Keystroke Recorder\LogService.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.0.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.6.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\461~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\480~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\484~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\486~1.0\SBInst.exe
[%PROGRAM_FILES%]\Support.com\bin\tgkill.exe
[%PROGRAM_FILES%]\support.com\client\bin\tgcmd.exe
[%PROGRAM_FILES%]\support.com\client\lserver\Server.vbs
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%PROGRAM_FILES%]\SYSTEM~1\soap.exe
[%PROGRAM_FILES%]\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Timer\Timer.exe
[%PROGRAM_FILES%]\Toolbar\TBPS.exe
[%PROGRAM_FILES%]\TopSearch\TopSearch.exe
[%PROGRAM_FILES%]\V3\SYSMONNT.EXE
[%PROGRAM_FILES%]\VVSN\VVSN.exe
[%PROGRAM_FILES%]\webHancer\Programs\whagent.exe
[%PROGRAM_FILES%]\webHancer\Programs\whSurvey.exe
[%PROGRAM_FILES%]\Web_Rebates\WebRebates0.exe
[%PROGRAM_FILES%]\WhenUSearch\Search.exe
[%PROGRAM_FILES%]\WhenUSearch\whse.exe
[%PROGRAM_FILES%]\WildTangent\DDC\DDCManager\DDCMan.exe
[%PROGRAM_FILES%]\Winamp\winampa.exe
[%PROGRAM_FILES%]\WINCLE~1\SCANMSG.EXE
[%PROGRAM_FILES%]\Windows Media Player\csrss.exe
[%PROGRAM_FILES%]\Windows Media Player\wmplayer.exe
[%PROGRAM_FILES%]\WindowsSA\omniscient.exe
[%PROGRAM_FILES%]\WindowsUpdate\wupdate.exe
[%PROGRAM_FILES%]\WinFixer\wfxcwr.exe
[%PROGRAM_FILES%]\winupdates\winupdates.exe
[%PROGRAM_FILES%]\WinUpdate\WinUpdate.exe
[%PROGRAM_FILES%]\WNSXS~1\msdtc.exe
[%PROGRAM_FILES%]\zango\zango.exe
[%PROGRAM_FILES%]\Zcodec\ZUpdate\ZUpdate.exe
[%PROGRAM_FILES_COMMON%]\CMEII\CMESys.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\smss.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\winword.exe
[%PROGRAM_FILES_COMMON%]\ECURIT~1\cmd.exe
[%PROGRAM_FILES_COMMON%]\MBOLS~1\wuauclt.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\msnfo32.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\TaskUpdate.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\web server extensions\40\bots\vinavbar\svchost.exe
[%PROGRAM_FILES_COMMON%]\SCURIT~1\nslookup.exe
[%PROGRAM_FILES_COMMON%]\SSEMBL~1\winword.exe
[%PROGRAM_FILES_COMMON%]\Stone Shared\winCheck.exe
[%PROGRAM_FILES_COMMON%]\SYSTEM\MOSEARCH\BIN\mosearch.exe
[%PROGRAM_FILES_COMMON%]\system\ms2src.exe
[%PROGRAM_FILES_COMMON%]\System\Update.exe
[%PROGRAM_FILES_COMMON%]\System\WinService32.exe
[%PROGRAM_FILES_COMMON%]\YSTEM~1\logonui.exe
[%STARTUP%]\svchost.exe
[%SYSTEM%]\
[%SYSTEM%]\a.exe
[%SYSTEM%]\addins\svchost.exe
[%SYSTEM%]\adprot.exe
[%SYSTEM%]\aim.exe
[%SYSTEM%]\aqesyg.exe
[%SYSTEM%]\ASKS~1\winword.exe
[%SYSTEM%]\avgss.exe
[%SYSTEM%]\bootcfg1.exe
[%SYSTEM%]\bpsveyyu.exe
[%SYSTEM%]\byyskv.exe
[%SYSTEM%]\c.exe
[%SYSTEM%]\cd_load.exe
[%SYSTEM%]\cgheuj.exe
[%SYSTEM%]\cmd.exe
[%SYSTEM%]\cme.exe
[%SYSTEM%]\cmeupd.exe
[%SYSTEM%]\crdwsys\smss.exe
[%SYSTEM%]\CROSOF~1.NET\notepad.exe
[%SYSTEM%]\csrs.exe
[%SYSTEM%]\ctfmon.exe
[%SYSTEM%]\dllhost32.exe
[%SYSTEM%]\DRIVERS\services.exe
[%SYSTEM%]\drivers\sysdrv.exe
[%SYSTEM%]\drivers\system.exe
[%SYSTEM%]\EXECUSER.EXE
[%SYSTEM%]\exploer.exe
[%SYSTEM%]\explore.exe
[%SYSTEM%]\EXPLORER.EXE
[%SYSTEM%]\firewall.exe
[%SYSTEM%]\fx.exe
[%SYSTEM%]\guarnset.exe
[%SYSTEM%]\gycrzc.exe
[%SYSTEM%]\gylxto.exe
[%SYSTEM%]\hbcyjpsdsc.exe
[%SYSTEM%]\illusion1.exe
[%SYSTEM%]\infwin.exe
[%SYSTEM%]\iovyrn.exe
[%SYSTEM%]\isass.exe
[%SYSTEM%]\javaw.exe
[%SYSTEM%]\kernel32.exe
[%SYSTEM%]\kernels1118.exe
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\kmbnac.exe
[%SYSTEM%]\Kmr.exe
[%SYSTEM%]\lelel.EXE
[%SYSTEM%]\lich.exe
[%SYSTEM%]\linkprd.exe
[%SYSTEM%]\links.exe
[%SYSTEM%]\lnaccess.exe
[%SYSTEM%]\lockx.exe
[%SYSTEM%]\m4n70s.exe
[%SYSTEM%]\mcafee32.exe
[%SYSTEM%]\MccTrayApp.exe
[%SYSTEM%]\mmf32.exe
[%SYSTEM%]\mmsvc32.exe
[%SYSTEM%]\mose.bat
[%SYSTEM%]\MSDATLST.exe
[%SYSTEM%]\msdmxm.exe
[%SYSTEM%]\mshelp32.com
[%SYSTEM%]\msiexec16.exe
[%SYSTEM%]\msnmger.exe
[%SYSTEM%]\msnmsg.exe
[%SYSTEM%]\MSPRCSS32.exe
[%SYSTEM%]\Msrtmon.exe
[%SYSTEM%]\mswinup.exe
[%SYSTEM%]\mwsrvacc.exe
[%SYSTEM%]\mxcrtp.dll
[%SYSTEM%]\ncgeca.exe
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\ntos.exe
[%SYSTEM%]\ocglia.exe
[%SYSTEM%]\omryog.exe
[%SYSTEM%]\P2P Networking\P2P Networking2.exe
[%SYSTEM%]\prodsrvs.exe
[%SYSTEM%]\prosvsys.exe
[%SYSTEM%]\PSHWR.EXE
[%SYSTEM%]\rant.exe
[%SYSTEM%]\regedit.exe
[%SYSTEM%]\regscan.exe
[%SYSTEM%]\REGSVR32.EXE
[%SYSTEM%]\rizg.exe
[%SYSTEM%]\rk.exe
[%SYSTEM%]\rundll32.exe
[%SYSTEM%]\schost.exe
[%SYSTEM%]\scvhost.exe
[%SYSTEM%]\scyxdaaa.exe
[%SYSTEM%]\sdoitjjwx.exe
[%SYSTEM%]\security.exe
[%SYSTEM%]\server.exe
[%SYSTEM%]\service.exe
[%SYSTEM%]\service1.exe
[%SYSTEM%]\servicess.exe
[%SYSTEM%]\setup.dll
[%SYSTEM%]\SKS~1\lsass.exe
[%SYSTEM%]\slk8x2peu.exesmss.exe
[%SYSTEM%]\sountaskmgr
[%SYSTEM%]\sp2ctr.exe
[%SYSTEM%]\spoolsv32.exe
[%SYSTEM%]\spoolsvc.exe
[%SYSTEM%]\spoolsvv.exe
[%SYSTEM%]\spoolvs.exe
[%SYSTEM%]\srshost.exe
[%SYSTEM%]\SSEMBL~1\dllhost.exe
[%SYSTEM%]\SSTEM3~1\dexplore.exe
[%SYSTEM%]\SVCHOST32.EXE
[%SYSTEM%]\svdhost.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\svhcost.exe
[%SYSTEM%]\svhost.exe
[%SYSTEM%]\svhosts.exe
[%SYSTEM%]\svshost.exe
[%SYSTEM%]\sys32dll.exe
[%SYSTEM%]\Sysctrls.exe
[%SYSTEM%]\sysfrcx.exe
[%SYSTEM%]\sysinfo.exe
[%SYSTEM%]\systembackup.exe
[%SYSTEM%]\systray.exe
[%SYSTEM%]\sysup.exe
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskmgr32.exe
[%SYSTEM%]\taskmgrs.com
[%SYSTEM%]\taskmngr.exe
[%SYSTEM%]\tibs3.exe
[%SYSTEM%]\timoty.exe
[%SYSTEM%]\unbsjd.exe
[%SYSTEM%]\Update32.exe
[%SYSTEM%]\uvovha.exe
[%SYSTEM%]\v6.exe
[%SYSTEM%]\vcxubk.exe
[%SYSTEM%]\vidmon\vidmon.exe
[%SYSTEM%]\wapisvsu.exe
[%SYSTEM%]\wbem\csrss.exe
[%SYSTEM%]\win32.exe
[%SYSTEM%]\windll.exe
[%SYSTEM%]\windowsupdats.exe
[%SYSTEM%]\winExplore.exe
[%SYSTEM%]\winipsec.exe
[%SYSTEM%]\winlog.exe
[%SYSTEM%]\winn32.exe
[%SYSTEM%]\winspoof.exe
[%SYSTEM%]\winsystem.exe
[%SYSTEM%]\wintems.exe
[%SYSTEM%]\winupdate.exe
[%SYSTEM%]\WINWORD.EXE
[%SYSTEM%]\wjview.exe
[%SYSTEM%]\wmiprvse.exe
[%SYSTEM%]\wplayer.exe
[%SYSTEM%]\ws2_32s.exe
[%SYSTEM%]\ypudutmnsl.exe
[%SYSTEM%]\zlip.exe
[%SYSTEM%]\zzb2.exe
[%WINDOWS%]\%A0svchost.exe
[%WINDOWS%]\.exe
[%WINDOWS%]\1903cr.exe
[%WINDOWS%]\aqadcup.exe
[%WINDOWS%]\avp.exe
[%WINDOWS%]\b.exe
[%WINDOWS%]\bbstore\dss\dssagent.exe
[%WINDOWS%]\cfg32.exe
[%WINDOWS%]\csrss.exe
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\directx.dll.vbs
[%WINDOWS%]\DirectX3D.exe
[%WINDOWS%]\dll32\csrss.exe
[%WINDOWS%]\DLLServAPI.exe
[%WINDOWS%]\dnscleaner.exe
[%WINDOWS%]\Duce6.exe
[%WINDOWS%]\EditorNetDos.exe
[%WINDOWS%]\emsw.exe
[%WINDOWS%]\enhupdt.exe
[%WINDOWS%]\explorer.exe
[%WINDOWS%]\FONTS\A46F2.com
[%WINDOWS%]\IEcheck.exe
[%WINDOWS%]\iexplorer.exe
[%WINDOWS%]\igator\trickler3103_pic_fs_dmpt_3103.exe
[%WINDOWS%]\inet20126\winlogon.exe
[%WINDOWS%]\jawa32.exe
[%WINDOWS%]\jusched.exe
[%WINDOWS%]\krn3.exe
[%WINDOWS%]\lsass.exe
[%WINDOWS%]\lssas1.exe
[%WINDOWS%]\MDM.EXE
[%WINDOWS%]\mservice1.exe
[%WINDOWS%]\msnmsgs.exe
[%WINDOWS%]\msqdevl1.exe
[%WINDOWS%]\msresearch.exe
[%WINDOWS%]\Navnet.exe
[%WINDOWS%]\nerocheck.exe
[%WINDOWS%]\NetMSConfig.exe
[%WINDOWS%]\OCXSMTPDos.exe
[%WINDOWS%]\PixArt\PAC207\Monitor.exe
[%WINDOWS%]\PixArt\PAC7311\Monitor.exe
[%WINDOWS%]\regedit.exe
[%WINDOWS%]\reload.vbs
[%WINDOWS%]\Remove_spyware.exe
[%WINDOWS%]\RUNDLL.EXE
[%WINDOWS%]\RUNDLL32.EXE
[%WINDOWS%]\satmat.exe
[%WINDOWS%]\scvhost.exe
[%WINDOWS%]\SEMBLY~1\javaw.exe
[%WINDOWS%]\Sentry.exe
[%WINDOWS%]\Servces32.exe
[%WINDOWS%]\service.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\services.exe
[%WINDOWS%]\ShellNew\RakyatKelaparan.exe
[%WINDOWS%]\ShowWnd.exe
[%WINDOWS%]\smss.exe
[%WINDOWS%]\snchost.exe
[%WINDOWS%]\SOUNDMAN.EXE
[%WINDOWS%]\sp2update00.exe
[%WINDOWS%]\sqldata1.exe
[%WINDOWS%]\STEM~1\notepad.exe
[%WINDOWS%]\stisvsq1.exe
[%WINDOWS%]\surfmonkey\SMProxy.exe
[%WINDOWS%]\sv.exe
[%WINDOWS%]\svchost.exe
[%WINDOWS%]\svhost.exe
[%WINDOWS%]\svhost32.exe
[%WINDOWS%]\SvrWizardVBX32.exe
[%WINDOWS%]\svshost1.exe
[%WINDOWS%]\sysfade.exe
[%WINDOWS%]\System\csrss.exe
[%WINDOWS%]\SYSTEM\EXPLORER.SCR
[%WINDOWS%]\system\fsg_3202.exe
[%WINDOWS%]\System\loader.exe
[%WINDOWS%]\system\rundll32.exe
[%WINDOWS%]\system\smss.exe
[%WINDOWS%]\system\svchost.exe
[%WINDOWS%]\system\svchost32.exe
[%WINDOWS%]\system\svhost.exe
[%WINDOWS%]\system\winstart001.exe
[%WINDOWS%]\SysWow64\timoty.exe
[%WINDOWS%]\taskmon.exe
[%WINDOWS%]\TEMP\win28B8.tmp.exe
[%WINDOWS%]\TEMP\win7C0D.tmp.exe
[%WINDOWS%]\TEMP\win??.tmp.exe
[%WINDOWS%]\TEMP\winC02.tmp.exe
[%WINDOWS%]\trest.exe
[%WINDOWS%]\twainxp.exe
[%WINDOWS%]\uninstall\rundl132.exe
[%WINDOWS%]\WindowsSecurityUpdate.exe
[%WINDOWS%]\WindowsUpdates.exe
[%WINDOWS%]\WINDOWS\svhost.exe
[%WINDOWS%]\winnetdos32.exe
[%WINDOWS%]\winnows.exe
[%WINDOWS%]\WinOCXDos32.exe
[%WINDOWS%]\WinOCXPOP32.exe
[%WINDOWS%]\winoscnfg.exe
[%WINDOWS%]\wintcpmod.exe
[%WINDOWS%]\wnad.exe
[%WINDOWS%]\WNSXS~1\rundll.exe
[%WINDOWS%]\wuauclt.exe
[%WINDOWS%]\Xhrmy.exe
[%WINDOWS%]\xpupdate.exe
[%WINDOWS%]\\\etb\\pokapoka79.exe

In order to ensure that the Autorun Malware is launched automatically each time the system is booted, the Autorun Malware adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%APPDATA%]\ASKS~1\svchost.exe
[%APPDATA%]\DOBE~1\logonui.exe
[%APPDATA%]\FNTS~1\netdde.exe
[%APPDATA%]\PPATCH~1\chkdsk.exe
[%APPDATA%]\SSEMBL~1\winspool.exe
[%APPDATA%]\YSTEM~1\winword.exe
[%COMMON_APPDATA%]\msw\BMan1.exe
[%COMMON_STARTUP%]\Uninstall64578.exe
[%FONTS%]\svchost.exe
[%PROFILE%]\gOhgkog.exe
[%PROFILE%]\scvhost.exe
[%PROFILE%]\WINDOWS\svchost.exe
[%PROFILE%]\winmain.exe
[%PROFILE%]\zbecczmv.exe
[%PROFILE_TEMP%]\II22.exe
[%PROFILE_TEMP%]\svchost.exe
[%PROFILE_TEMP%]\tmp6.tmp.exe
[%PROFILE_TEMP%]\update.exe
[%PROFILE_TEMP%]\x2000.exe
[%PROGRAM_FILES%]\180solutions\ncase\msbb155\msbb.exe
[%PROGRAM_FILES%]\3BSOFT~1\WINDOW~2\Windows Clean-Up Pro.exe
[%PROGRAM_FILES%]\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[%PROGRAM_FILES%]\AdTools Service\AdTools.exe
[%PROGRAM_FILES%]\AGSeydsApp\AGSeyApp.exe
[%PROGRAM_FILES%]\altnet\points manager\Points Manager.exe
[%PROGRAM_FILES%]\AltPayments\AltPayments.exe
[%PROGRAM_FILES%]\AOL\Active Virus Shield\avp.exe
[%PROGRAM_FILES%]\AQUATI~1\AQ3Helper.exe
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%PROGRAM_FILES%]\Aveo\Attune\bin\attune_ce.exe
[%PROGRAM_FILES%]\Aveo\Attune\Bin\Attune_ST.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\Bargain Buddy\bin\bargains.exe
[%PROGRAM_FILES%]\Block Checker\block-checker.exe
[%PROGRAM_FILES%]\Breakpoint Computers\WinTimer\wintimerc.exe
[%PROGRAM_FILES%]\COMETS~1\DM\bin\dmserver.exe
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES%]\COMMON~2\TOOLBAR\winnet.exe
[%PROGRAM_FILES%]\CROSOF~1\services.exe
[%PROGRAM_FILES%]\CURITY~1\winlogon.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\Search.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\whse.exe
[%PROGRAM_FILES%]\DelFin\PromulGate\PgMonitr.exe
[%PROGRAM_FILES%]\DeluxeCommunications\Dxc.exe
[%PROGRAM_FILES%]\divx\divx pro codec\gain_trickler_3202a.exe
[%PROGRAM_FILES%]\Dpoint\bin\update.exe
[%PROGRAM_FILES%]\DreamGroup\No-Spy\No-Spy.exe
[%PROGRAM_FILES%]\DropSpam\oesrv.exe
[%PROGRAM_FILES%]\dslifestyle\dslifestyle.exe
[%PROGRAM_FILES%]\Error Safe Free\ERS.exe
[%PROGRAM_FILES%]\FNTS~1\dvdplay.exe
[%PROGRAM_FILES%]\Globe Software\StatBar\StatBar.exe
[%PROGRAM_FILES%]\GogoTools\Gogoware\LaunchAdware.exe
[%PROGRAM_FILES%]\GOTSMI~1\GSYUpdater.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HooTech\NetMeter\HooNetMeter.exe
[%PROGRAM_FILES%]\HP\HP Software Update\hpwuSchd2.exe
[%PROGRAM_FILES%]\Instant Buzz\IBDaemon.exe
[%PROGRAM_FILES%]\Internet Explorer\Setup\svchost.exe
[%PROGRAM_FILES%]\Internet Optimizer\optimize.exe
[%PROGRAM_FILES%]\INTERN~2\iw.exe
[%PROGRAM_FILES%]\Ipwindows\ipwins.exe
[%PROGRAM_FILES%]\ipwins\ipwins.exe
[%PROGRAM_FILES%]\ISTsvc\istsvc.exe
[%PROGRAM_FILES%]\iTunes\iTunes.exe
[%PROGRAM_FILES%]\iWatchNow, Inc\iWatchNow Media Center\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
[%PROGRAM_FILES%]\License_Manager\license_manager.exe
[%PROGRAM_FILES%]\LimeWire\LimeWire.exe
[%PROGRAM_FILES%]\Linksys EasyLink Advisor\LinksysAgent.exe
[%PROGRAM_FILES%]\Logitech input devices\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\KEM.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\mailskinner\MailSkinner.exe
[%PROGRAM_FILES%]\MCROSO~1.NET\ping.exe
[%PROGRAM_FILES%]\Media Access\MediaAccK.exe
[%PROGRAM_FILES%]\Messaging Names\msgrsvr.exe
[%PROGRAM_FILES%]\Microsoft IntelliType Pro\type32.exe
[%PROGRAM_FILES%]\NavExcel\NavHelper\v2.0.4d\navapp.exe
[%PROGRAM_FILES%]\NaviSearch\bin\nls.exe
[%PROGRAM_FILES%]\Netcom3 Cleaner\SpyClean.exe
[%PROGRAM_FILES%]\NetPumper\NetPumperIEProxy.exe
[%PROGRAM_FILES%]\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
[%PROGRAM_FILES%]\Notify\notify.exe
[%PROGRAM_FILES%]\Open Site\opensite.exe
[%PROGRAM_FILES%]\Optimum Online\Netsurf.exe
[%PROGRAM_FILES%]\Outerinfo\OuterinfoUpdate.exe
[%PROGRAM_FILES%]\outlook\outlook.exe
[%PROGRAM_FILES%]\p2pnetworks\mpp2pl.exe
[%PROGRAM_FILES%]\PCSecurityShield\The Shield Deluxe 2008\avp.exe
[%PROGRAM_FILES%]\PCSecurityShield\TheShieldDeluxe\avp.exe
[%PROGRAM_FILES%]\PestTrap\PestTrap.exe
[%PROGRAM_FILES%]\Power Manager\PM.exe
[%PROGRAM_FILES%]\Protocom\SecureLogin\slproto.exe
[%PROGRAM_FILES%]\QuickTime\qttask.exe
[%PROGRAM_FILES%]\RACLE~1\ping.exe
[%PROGRAM_FILES%]\RACLE~1\wucrtupd.exe
[%PROGRAM_FILES%]\RSSoft\RSEDNClient.exe
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\Save\Save.exe
[%PROGRAM_FILES%]\SCURIT~1\csrss.exe
[%PROGRAM_FILES%]\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
[%PROGRAM_FILES%]\seekmo\seekmo.exe
[%PROGRAM_FILES%]\Silicon Integrated Systems\SiSRaidPackage\Hot_Plug.exe
[%PROGRAM_FILES%]\Smart Keystroke Recorder\LogService.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.0.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.6.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\461~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\480~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\484~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\486~1.0\SBInst.exe
[%PROGRAM_FILES%]\Support.com\bin\tgkill.exe
[%PROGRAM_FILES%]\support.com\client\bin\tgcmd.exe
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%PROGRAM_FILES%]\SYSTEM~1\soap.exe
[%PROGRAM_FILES%]\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Timer\Timer.exe
[%PROGRAM_FILES%]\Toolbar\TBPS.exe
[%PROGRAM_FILES%]\TopSearch\TopSearch.exe
[%PROGRAM_FILES%]\VVSN\VVSN.exe
[%PROGRAM_FILES%]\webHancer\Programs\whagent.exe
[%PROGRAM_FILES%]\webHancer\Programs\whSurvey.exe
[%PROGRAM_FILES%]\Web_Rebates\WebRebates0.exe
[%PROGRAM_FILES%]\WhenUSearch\Search.exe
[%PROGRAM_FILES%]\WhenUSearch\whse.exe
[%PROGRAM_FILES%]\WildTangent\DDC\DDCManager\DDCMan.exe
[%PROGRAM_FILES%]\Winamp\winampa.exe
[%PROGRAM_FILES%]\Windows Media Player\csrss.exe
[%PROGRAM_FILES%]\Windows Media Player\wmplayer.exe
[%PROGRAM_FILES%]\WindowsSA\omniscient.exe
[%PROGRAM_FILES%]\WindowsUpdate\wupdate.exe
[%PROGRAM_FILES%]\WinFixer\wfxcwr.exe
[%PROGRAM_FILES%]\winupdates\winupdates.exe
[%PROGRAM_FILES%]\WinUpdate\WinUpdate.exe
[%PROGRAM_FILES%]\WNSXS~1\msdtc.exe
[%PROGRAM_FILES%]\zango\zango.exe
[%PROGRAM_FILES%]\Zcodec\ZUpdate\ZUpdate.exe
[%PROGRAM_FILES_COMMON%]\CMEII\CMESys.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\smss.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\winword.exe
[%PROGRAM_FILES_COMMON%]\ECURIT~1\cmd.exe
[%PROGRAM_FILES_COMMON%]\MBOLS~1\wuauclt.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\msnfo32.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\TaskUpdate.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\web server extensions\40\bots\vinavbar\svchost.exe
[%PROGRAM_FILES_COMMON%]\SCURIT~1\nslookup.exe
[%PROGRAM_FILES_COMMON%]\SSEMBL~1\winword.exe
[%PROGRAM_FILES_COMMON%]\Stone Shared\winCheck.exe
[%PROGRAM_FILES_COMMON%]\SYSTEM\MOSEARCH\BIN\mosearch.exe
[%PROGRAM_FILES_COMMON%]\system\ms2src.exe
[%PROGRAM_FILES_COMMON%]\System\Update.exe
[%PROGRAM_FILES_COMMON%]\System\WinService32.exe
[%PROGRAM_FILES_COMMON%]\YSTEM~1\logonui.exe
[%STARTUP%]\svchost.exe
[%SYSTEM%]\a.exe
[%SYSTEM%]\addins\svchost.exe
[%SYSTEM%]\adprot.exe
[%SYSTEM%]\aim.exe
[%SYSTEM%]\aqesyg.exe
[%SYSTEM%]\ASKS~1\winword.exe
[%SYSTEM%]\avgss.exe
[%SYSTEM%]\bootcfg1.exe
[%SYSTEM%]\bpsveyyu.exe
[%SYSTEM%]\byyskv.exe
[%SYSTEM%]\c.exe
[%SYSTEM%]\cd_load.exe
[%SYSTEM%]\cgheuj.exe
[%SYSTEM%]\cmd.exe
[%SYSTEM%]\cme.exe
[%SYSTEM%]\cmeupd.exe
[%SYSTEM%]\crdwsys\smss.exe
[%SYSTEM%]\CROSOF~1.NET\notepad.exe
[%SYSTEM%]\csrs.exe
[%SYSTEM%]\ctfmon.exe
[%SYSTEM%]\dllhost32.exe
[%SYSTEM%]\DRIVERS\services.exe
[%SYSTEM%]\drivers\sysdrv.exe
[%SYSTEM%]\drivers\system.exe
[%SYSTEM%]\exploer.exe
[%SYSTEM%]\explore.exe
[%SYSTEM%]\firewall.exe
[%SYSTEM%]\fx.exe
[%SYSTEM%]\guarnset.exe
[%SYSTEM%]\gycrzc.exe
[%SYSTEM%]\gylxto.exe
[%SYSTEM%]\hbcyjpsdsc.exe
[%SYSTEM%]\illusion1.exe
[%SYSTEM%]\infwin.exe
[%SYSTEM%]\iovyrn.exe
[%SYSTEM%]\isass.exe
[%SYSTEM%]\javaw.exe
[%SYSTEM%]\kernel32.exe
[%SYSTEM%]\kernels1118.exe
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\kmbnac.exe
[%SYSTEM%]\Kmr.exe
[%SYSTEM%]\lich.exe
[%SYSTEM%]\linkprd.exe
[%SYSTEM%]\links.exe
[%SYSTEM%]\lnaccess.exe
[%SYSTEM%]\lockx.exe
[%SYSTEM%]\m4n70s.exe
[%SYSTEM%]\mcafee32.exe
[%SYSTEM%]\MccTrayApp.exe
[%SYSTEM%]\mmf32.exe
[%SYSTEM%]\mmsvc32.exe
[%SYSTEM%]\MSDATLST.exe
[%SYSTEM%]\msdmxm.exe
[%SYSTEM%]\msiexec16.exe
[%SYSTEM%]\msnmger.exe
[%SYSTEM%]\msnmsg.exe
[%SYSTEM%]\MSPRCSS32.exe
[%SYSTEM%]\Msrtmon.exe
[%SYSTEM%]\mswinup.exe
[%SYSTEM%]\mwsrvacc.exe
[%SYSTEM%]\ncgeca.exe
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\ntos.exe
[%SYSTEM%]\ocglia.exe
[%SYSTEM%]\omryog.exe
[%SYSTEM%]\P2P Networking\P2P Networking2.exe
[%SYSTEM%]\prodsrvs.exe
[%SYSTEM%]\prosvsys.exe
[%SYSTEM%]\rant.exe
[%SYSTEM%]\regedit.exe
[%SYSTEM%]\regscan.exe
[%SYSTEM%]\rizg.exe
[%SYSTEM%]\rk.exe
[%SYSTEM%]\rundll32.exe
[%SYSTEM%]\schost.exe
[%SYSTEM%]\scvhost.exe
[%SYSTEM%]\scyxdaaa.exe
[%SYSTEM%]\sdoitjjwx.exe
[%SYSTEM%]\security.exe
[%SYSTEM%]\server.exe
[%SYSTEM%]\service.exe
[%SYSTEM%]\service1.exe
[%SYSTEM%]\servicess.exe
[%SYSTEM%]\SKS~1\lsass.exe
[%SYSTEM%]\slk8x2peu.exesmss.exe
[%SYSTEM%]\sp2ctr.exe
[%SYSTEM%]\spoolsv32.exe
[%SYSTEM%]\spoolsvc.exe
[%SYSTEM%]\spoolsvv.exe
[%SYSTEM%]\spoolvs.exe
[%SYSTEM%]\srshost.exe
[%SYSTEM%]\SSEMBL~1\dllhost.exe
[%SYSTEM%]\SSTEM3~1\dexplore.exe
[%SYSTEM%]\svdhost.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\svhcost.exe
[%SYSTEM%]\svhost.exe
[%SYSTEM%]\svhosts.exe
[%SYSTEM%]\svshost.exe
[%SYSTEM%]\sys32dll.exe
[%SYSTEM%]\Sysctrls.exe
[%SYSTEM%]\sysfrcx.exe
[%SYSTEM%]\sysinfo.exe
[%SYSTEM%]\systembackup.exe
[%SYSTEM%]\systray.exe
[%SYSTEM%]\sysup.exe
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskmgr32.exe
[%SYSTEM%]\taskmngr.exe
[%SYSTEM%]\tibs3.exe
[%SYSTEM%]\timoty.exe
[%SYSTEM%]\unbsjd.exe
[%SYSTEM%]\Update32.exe
[%SYSTEM%]\uvovha.exe
[%SYSTEM%]\v6.exe
[%SYSTEM%]\vcxubk.exe
[%SYSTEM%]\vidmon\vidmon.exe
[%SYSTEM%]\wapisvsu.exe
[%SYSTEM%]\wbem\csrss.exe
[%SYSTEM%]\win32.exe
[%SYSTEM%]\windll.exe
[%SYSTEM%]\windowsupdats.exe
[%SYSTEM%]\winExplore.exe
[%SYSTEM%]\winipsec.exe
[%SYSTEM%]\winlog.exe
[%SYSTEM%]\winn32.exe
[%SYSTEM%]\winspoof.exe
[%SYSTEM%]\winsystem.exe
[%SYSTEM%]\wintems.exe
[%SYSTEM%]\winupdate.exe
[%SYSTEM%]\wjview.exe
[%SYSTEM%]\wmiprvse.exe
[%SYSTEM%]\wplayer.exe
[%SYSTEM%]\ws2_32s.exe
[%SYSTEM%]\ypudutmnsl.exe
[%SYSTEM%]\zlip.exe
[%SYSTEM%]\zzb2.exe
[%WINDOWS%]\%A0svchost.exe
[%WINDOWS%]\.exe
[%WINDOWS%]\1903cr.exe
[%WINDOWS%]\aqadcup.exe
[%WINDOWS%]\avp.exe
[%WINDOWS%]\b.exe
[%WINDOWS%]\bbstore\dss\dssagent.exe
[%WINDOWS%]\cfg32.exe
[%WINDOWS%]\csrss.exe
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\DirectX3D.exe
[%WINDOWS%]\dll32\csrss.exe
[%WINDOWS%]\DLLServAPI.exe
[%WINDOWS%]\dnscleaner.exe
[%WINDOWS%]\Duce6.exe
[%WINDOWS%]\EditorNetDos.exe
[%WINDOWS%]\emsw.exe
[%WINDOWS%]\enhupdt.exe
[%WINDOWS%]\explorer.exe
[%WINDOWS%]\IEcheck.exe
[%WINDOWS%]\iexplorer.exe
[%WINDOWS%]\igator\trickler3103_pic_fs_dmpt_3103.exe
[%WINDOWS%]\inet20126\winlogon.exe
[%WINDOWS%]\jawa32.exe
[%WINDOWS%]\jusched.exe
[%WINDOWS%]\krn3.exe
[%WINDOWS%]\lsass.exe
[%WINDOWS%]\lssas1.exe
[%WINDOWS%]\mservice1.exe
[%WINDOWS%]\msnmsgs.exe
[%WINDOWS%]\msqdevl1.exe
[%WINDOWS%]\msresearch.exe
[%WINDOWS%]\Navnet.exe
[%WINDOWS%]\nerocheck.exe
[%WINDOWS%]\NetMSConfig.exe
[%WINDOWS%]\OCXSMTPDos.exe
[%WINDOWS%]\PixArt\PAC207\Monitor.exe
[%WINDOWS%]\PixArt\PAC7311\Monitor.exe
[%WINDOWS%]\regedit.exe
[%WINDOWS%]\Remove_spyware.exe
[%WINDOWS%]\satmat.exe
[%WINDOWS%]\scvhost.exe
[%WINDOWS%]\SEMBLY~1\javaw.exe
[%WINDOWS%]\Sentry.exe
[%WINDOWS%]\Servces32.exe
[%WINDOWS%]\service.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\services.exe
[%WINDOWS%]\ShellNew\RakyatKelaparan.exe
[%WINDOWS%]\ShowWnd.exe
[%WINDOWS%]\smss.exe
[%WINDOWS%]\snchost.exe
[%WINDOWS%]\sp2update00.exe
[%WINDOWS%]\sqldata1.exe
[%WINDOWS%]\STEM~1\notepad.exe
[%WINDOWS%]\stisvsq1.exe
[%WINDOWS%]\surfmonkey\SMProxy.exe
[%WINDOWS%]\sv.exe
[%WINDOWS%]\svchost.exe
[%WINDOWS%]\svhost.exe
[%WINDOWS%]\svhost32.exe
[%WINDOWS%]\SvrWizardVBX32.exe
[%WINDOWS%]\svshost1.exe
[%WINDOWS%]\sysfade.exe
[%WINDOWS%]\System\csrss.exe
[%WINDOWS%]\system\fsg_3202.exe
[%WINDOWS%]\System\loader.exe
[%WINDOWS%]\system\rundll32.exe
[%WINDOWS%]\system\smss.exe
[%WINDOWS%]\system\svchost.exe
[%WINDOWS%]\system\svchost32.exe
[%WINDOWS%]\system\svhost.exe
[%WINDOWS%]\system\winstart001.exe
[%WINDOWS%]\SysWow64\timoty.exe
[%WINDOWS%]\taskmon.exe
[%WINDOWS%]\TEMP\win28B8.tmp.exe
[%WINDOWS%]\TEMP\win7C0D.tmp.exe
[%WINDOWS%]\TEMP\win??.tmp.exe
[%WINDOWS%]\TEMP\winC02.tmp.exe
[%WINDOWS%]\trest.exe
[%WINDOWS%]\twainxp.exe
[%WINDOWS%]\uninstall\rundl132.exe
[%WINDOWS%]\WindowsSecurityUpdate.exe
[%WINDOWS%]\WindowsUpdates.exe
[%WINDOWS%]\WINDOWS\svhost.exe
[%WINDOWS%]\winnetdos32.exe
[%WINDOWS%]\winnows.exe
[%WINDOWS%]\WinOCXDos32.exe
[%WINDOWS%]\WinOCXPOP32.exe
[%WINDOWS%]\winoscnfg.exe
[%WINDOWS%]\wintcpmod.exe
[%WINDOWS%]\wnad.exe
[%WINDOWS%]\WNSXS~1\rundll.exe
[%WINDOWS%]\wuauclt.exe
[%WINDOWS%]\Xhrmy.exe
[%WINDOWS%]\xpupdate.exe
[%WINDOWS%]\\\etb\\pokapoka79.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Autorun Malware:

Files:
[%APPDATA%]\ASKS~1\svchost.exe
[%APPDATA%]\DOBE~1\logonui.exe
[%APPDATA%]\FNTS~1\netdde.exe
[%APPDATA%]\PPATCH~1\chkdsk.exe
[%APPDATA%]\SSEMBL~1\winspool.exe
[%APPDATA%]\YSTEM~1\winword.exe
[%COMMON_APPDATA%]\msw\BMan1.exe
[%COMMON_STARTUP%]\Uninstall64578.exe
[%FONTS%]\svchost.exe
[%PROFILE%]\gOhgkog.exe
[%PROFILE%]\mssvmdll.dll
[%PROFILE%]\scvhost.exe
[%PROFILE%]\WINDOWS\svchost.exe
[%PROFILE%]\winmain.exe
[%PROFILE%]\zbecczmv.exe
[%PROFILE_TEMP%]\II22.exe
[%PROFILE_TEMP%]\NpcNMdohh
[%PROFILE_TEMP%]\svchost.exe
[%PROFILE_TEMP%]\tmp6.tmp.exe
[%PROFILE_TEMP%]\update.exe
[%PROFILE_TEMP%]\x2000.exe
[%PROGRAM_FILES%]\180solutions\ncase\msbb155\msbb.exe
[%PROGRAM_FILES%]\3BSOFT~1\WINDOW~2\Windows Clean-Up Pro.exe
[%PROGRAM_FILES%]\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[%PROGRAM_FILES%]\AdTools Service\AdTools.exe
[%PROGRAM_FILES%]\AGSeydsApp\AGSeyApp.exe
[%PROGRAM_FILES%]\altnet\points manager\Points Manager.exe
[%PROGRAM_FILES%]\AltPayments\AltPayments.exe
[%PROGRAM_FILES%]\AOL\Active Virus Shield\avp.exe
[%PROGRAM_FILES%]\AQUATI~1\AQ3Helper.exe
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%PROGRAM_FILES%]\Aveo\Attune\bin\attune_ce.exe
[%PROGRAM_FILES%]\Aveo\Attune\Bin\Attune_ST.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\Bargain Buddy\bin\bargains.exe
[%PROGRAM_FILES%]\Block Checker\block-checker.exe
[%PROGRAM_FILES%]\Breakpoint Computers\WinTimer\wintimerc.exe
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~2\SCANMSG.EXE
[%PROGRAM_FILES%]\COMETS~1\DM\bin\dmserver.exe
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES%]\COMMON~2\TOOLBAR\winnet.exe
[%PROGRAM_FILES%]\Cosmi\HelpExpress\HXDL.EXE
[%PROGRAM_FILES%]\Cosmi\HelpExpress\Mr Mrs English\HXIUL.EXE
[%PROGRAM_FILES%]\CROSOF~1\services.exe
[%PROGRAM_FILES%]\CURITY~1\winlogon.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\Search.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\whse.exe
[%PROGRAM_FILES%]\DelFin\PromulGate\PgMonitr.exe
[%PROGRAM_FILES%]\DeluxeCommunications\Dxc.exe
[%PROGRAM_FILES%]\divx\divx pro codec\gain_trickler_3202a.exe
[%PROGRAM_FILES%]\Dpoint\bin\update.exe
[%PROGRAM_FILES%]\DreamGroup\No-Spy\No-Spy.exe
[%PROGRAM_FILES%]\DropSpam\oesrv.exe
[%PROGRAM_FILES%]\dslifestyle\dslifestyle.exe
[%PROGRAM_FILES%]\Error Safe Free\ERS.exe
[%PROGRAM_FILES%]\FNTS~1\dvdplay.exe
[%PROGRAM_FILES%]\Globe Software\StatBar\StatBar.exe
[%PROGRAM_FILES%]\GogoTools\Gogoware\LaunchAdware.exe
[%PROGRAM_FILES%]\GOTSMI~1\GSYUpdater.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HooTech\NetMeter\HooNetMeter.exe
[%PROGRAM_FILES%]\HP\HP Software Update\hpwuSchd2.exe
[%PROGRAM_FILES%]\Instant Buzz\IBDaemon.exe
[%PROGRAM_FILES%]\Internet Explorer\IEXPLORE.EXE
[%PROGRAM_FILES%]\Internet Explorer\Setup\svchost.exe
[%PROGRAM_FILES%]\Internet Optimizer\optimize.exe
[%PROGRAM_FILES%]\INTERNET WASHER PRO\IW.EXE
[%PROGRAM_FILES%]\INTERN~2\iw.exe
[%PROGRAM_FILES%]\Ipwindows\ipwins.exe
[%PROGRAM_FILES%]\ipwins\ipwins.exe
[%PROGRAM_FILES%]\ISTsvc\istsvc.exe
[%PROGRAM_FILES%]\iTunes\iTunes.exe
[%PROGRAM_FILES%]\iWatchNow, Inc\iWatchNow Media Center\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
[%PROGRAM_FILES%]\License_Manager\license_manager.exe
[%PROGRAM_FILES%]\LimeWire\LimeWire.exe
[%PROGRAM_FILES%]\Linksys EasyLink Advisor\LinksysAgent.exe
[%PROGRAM_FILES%]\Logitech input devices\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\KEM.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\mailskinner\MailSkinner.exe
[%PROGRAM_FILES%]\MCROSO~1.NET\ping.exe
[%PROGRAM_FILES%]\Media Access\MediaAccK.exe
[%PROGRAM_FILES%]\Messaging Names\msgrsvr.exe
[%PROGRAM_FILES%]\Microsoft IntelliType Pro\type32.exe
[%PROGRAM_FILES%]\MYWEBS~1\bar\1.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\MYWEBS~1\bar\2.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\NavExcel\NavHelper\v2.0.4d\navapp.exe
[%PROGRAM_FILES%]\NaviSearch\bin\nls.exe
[%PROGRAM_FILES%]\Netcom3 Cleaner\SpyClean.exe
[%PROGRAM_FILES%]\NetPumper\NetPumperIEProxy.exe
[%PROGRAM_FILES%]\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
[%PROGRAM_FILES%]\Notify\notify.exe
[%PROGRAM_FILES%]\Open Site\opensite.exe
[%PROGRAM_FILES%]\Optimum Online\Netsurf.exe
[%PROGRAM_FILES%]\Outerinfo\OuterinfoUpdate.exe
[%PROGRAM_FILES%]\outlook\outlook.exe
[%PROGRAM_FILES%]\p2pnetworks\mpp2pl.exe
[%PROGRAM_FILES%]\PCSecurityShield\The Shield Deluxe 2008\avp.exe
[%PROGRAM_FILES%]\PCSecurityShield\TheShieldDeluxe\avp.exe
[%PROGRAM_FILES%]\PestTrap\PestTrap.exe
[%PROGRAM_FILES%]\Power Manager\PM.exe
[%PROGRAM_FILES%]\Protocom\SecureLogin\slproto.exe
[%PROGRAM_FILES%]\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\QuickTime\qttask.exe
[%PROGRAM_FILES%]\RACLE~1\ping.exe
[%PROGRAM_FILES%]\RACLE~1\wucrtupd.exe
[%PROGRAM_FILES%]\RSSoft\RSEDNClient.exe
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\Save\Save.exe
[%PROGRAM_FILES%]\SCURIT~1\csrss.exe
[%PROGRAM_FILES%]\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
[%PROGRAM_FILES%]\seekmo\seekmo.exe
[%PROGRAM_FILES%]\Silicon Integrated Systems\SiSRaidPackage\Hot_Plug.exe
[%PROGRAM_FILES%]\Smart Keystroke Recorder\LogService.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.0.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.6.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\461~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\480~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\484~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\486~1.0\SBInst.exe
[%PROGRAM_FILES%]\Support.com\bin\tgkill.exe
[%PROGRAM_FILES%]\support.com\client\bin\tgcmd.exe
[%PROGRAM_FILES%]\support.com\client\lserver\Server.vbs
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%PROGRAM_FILES%]\SYSTEM~1\soap.exe
[%PROGRAM_FILES%]\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Timer\Timer.exe
[%PROGRAM_FILES%]\Toolbar\TBPS.exe
[%PROGRAM_FILES%]\TopSearch\TopSearch.exe
[%PROGRAM_FILES%]\V3\SYSMONNT.EXE
[%PROGRAM_FILES%]\VVSN\VVSN.exe
[%PROGRAM_FILES%]\webHancer\Programs\whagent.exe
[%PROGRAM_FILES%]\webHancer\Programs\whSurvey.exe
[%PROGRAM_FILES%]\Web_Rebates\WebRebates0.exe
[%PROGRAM_FILES%]\WhenUSearch\Search.exe
[%PROGRAM_FILES%]\WhenUSearch\whse.exe
[%PROGRAM_FILES%]\WildTangent\DDC\DDCManager\DDCMan.exe
[%PROGRAM_FILES%]\Winamp\winampa.exe
[%PROGRAM_FILES%]\WINCLE~1\SCANMSG.EXE
[%PROGRAM_FILES%]\Windows Media Player\csrss.exe
[%PROGRAM_FILES%]\Windows Media Player\wmplayer.exe
[%PROGRAM_FILES%]\WindowsSA\omniscient.exe
[%PROGRAM_FILES%]\WindowsUpdate\wupdate.exe
[%PROGRAM_FILES%]\WinFixer\wfxcwr.exe
[%PROGRAM_FILES%]\winupdates\winupdates.exe
[%PROGRAM_FILES%]\WinUpdate\WinUpdate.exe
[%PROGRAM_FILES%]\WNSXS~1\msdtc.exe
[%PROGRAM_FILES%]\zango\zango.exe
[%PROGRAM_FILES%]\Zcodec\ZUpdate\ZUpdate.exe
[%PROGRAM_FILES_COMMON%]\CMEII\CMESys.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\smss.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\winword.exe
[%PROGRAM_FILES_COMMON%]\ECURIT~1\cmd.exe
[%PROGRAM_FILES_COMMON%]\MBOLS~1\wuauclt.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\msnfo32.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\TaskUpdate.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\web server extensions\40\bots\vinavbar\svchost.exe
[%PROGRAM_FILES_COMMON%]\SCURIT~1\nslookup.exe
[%PROGRAM_FILES_COMMON%]\SSEMBL~1\winword.exe
[%PROGRAM_FILES_COMMON%]\Stone Shared\winCheck.exe
[%PROGRAM_FILES_COMMON%]\SYSTEM\MOSEARCH\BIN\mosearch.exe
[%PROGRAM_FILES_COMMON%]\system\ms2src.exe
[%PROGRAM_FILES_COMMON%]\System\Update.exe
[%PROGRAM_FILES_COMMON%]\System\WinService32.exe
[%PROGRAM_FILES_COMMON%]\YSTEM~1\logonui.exe
[%STARTUP%]\svchost.exe
[%SYSTEM%]\
[%SYSTEM%]\a.exe
[%SYSTEM%]\addins\svchost.exe
[%SYSTEM%]\adprot.exe
[%SYSTEM%]\aim.exe
[%SYSTEM%]\aqesyg.exe
[%SYSTEM%]\ASKS~1\winword.exe
[%SYSTEM%]\avgss.exe
[%SYSTEM%]\bootcfg1.exe
[%SYSTEM%]\bpsveyyu.exe
[%SYSTEM%]\byyskv.exe
[%SYSTEM%]\c.exe
[%SYSTEM%]\cd_load.exe
[%SYSTEM%]\cgheuj.exe
[%SYSTEM%]\cmd.exe
[%SYSTEM%]\cme.exe
[%SYSTEM%]\cmeupd.exe
[%SYSTEM%]\crdwsys\smss.exe
[%SYSTEM%]\CROSOF~1.NET\notepad.exe
[%SYSTEM%]\csrs.exe
[%SYSTEM%]\ctfmon.exe
[%SYSTEM%]\dllhost32.exe
[%SYSTEM%]\DRIVERS\services.exe
[%SYSTEM%]\drivers\sysdrv.exe
[%SYSTEM%]\drivers\system.exe
[%SYSTEM%]\EXECUSER.EXE
[%SYSTEM%]\exploer.exe
[%SYSTEM%]\explore.exe
[%SYSTEM%]\EXPLORER.EXE
[%SYSTEM%]\firewall.exe
[%SYSTEM%]\fx.exe
[%SYSTEM%]\guarnset.exe
[%SYSTEM%]\gycrzc.exe
[%SYSTEM%]\gylxto.exe
[%SYSTEM%]\hbcyjpsdsc.exe
[%SYSTEM%]\illusion1.exe
[%SYSTEM%]\infwin.exe
[%SYSTEM%]\iovyrn.exe
[%SYSTEM%]\isass.exe
[%SYSTEM%]\javaw.exe
[%SYSTEM%]\kernel32.exe
[%SYSTEM%]\kernels1118.exe
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\kmbnac.exe
[%SYSTEM%]\Kmr.exe
[%SYSTEM%]\lelel.EXE
[%SYSTEM%]\lich.exe
[%SYSTEM%]\linkprd.exe
[%SYSTEM%]\links.exe
[%SYSTEM%]\lnaccess.exe
[%SYSTEM%]\lockx.exe
[%SYSTEM%]\m4n70s.exe
[%SYSTEM%]\mcafee32.exe
[%SYSTEM%]\MccTrayApp.exe
[%SYSTEM%]\mmf32.exe
[%SYSTEM%]\mmsvc32.exe
[%SYSTEM%]\mose.bat
[%SYSTEM%]\MSDATLST.exe
[%SYSTEM%]\msdmxm.exe
[%SYSTEM%]\mshelp32.com
[%SYSTEM%]\msiexec16.exe
[%SYSTEM%]\msnmger.exe
[%SYSTEM%]\msnmsg.exe
[%SYSTEM%]\MSPRCSS32.exe
[%SYSTEM%]\Msrtmon.exe
[%SYSTEM%]\mswinup.exe
[%SYSTEM%]\mwsrvacc.exe
[%SYSTEM%]\mxcrtp.dll
[%SYSTEM%]\ncgeca.exe
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\ntos.exe
[%SYSTEM%]\ocglia.exe
[%SYSTEM%]\omryog.exe
[%SYSTEM%]\P2P Networking\P2P Networking2.exe
[%SYSTEM%]\prodsrvs.exe
[%SYSTEM%]\prosvsys.exe
[%SYSTEM%]\PSHWR.EXE
[%SYSTEM%]\rant.exe
[%SYSTEM%]\regedit.exe
[%SYSTEM%]\regscan.exe
[%SYSTEM%]\REGSVR32.EXE
[%SYSTEM%]\rizg.exe
[%SYSTEM%]\rk.exe
[%SYSTEM%]\rundll32.exe
[%SYSTEM%]\schost.exe
[%SYSTEM%]\scvhost.exe
[%SYSTEM%]\scyxdaaa.exe
[%SYSTEM%]\sdoitjjwx.exe
[%SYSTEM%]\security.exe
[%SYSTEM%]\server.exe
[%SYSTEM%]\service.exe
[%SYSTEM%]\service1.exe
[%SYSTEM%]\servicess.exe
[%SYSTEM%]\setup.dll
[%SYSTEM%]\SKS~1\lsass.exe
[%SYSTEM%]\slk8x2peu.exesmss.exe
[%SYSTEM%]\sountaskmgr
[%SYSTEM%]\sp2ctr.exe
[%SYSTEM%]\spoolsv32.exe
[%SYSTEM%]\spoolsvc.exe
[%SYSTEM%]\spoolsvv.exe
[%SYSTEM%]\spoolvs.exe
[%SYSTEM%]\srshost.exe
[%SYSTEM%]\SSEMBL~1\dllhost.exe
[%SYSTEM%]\SSTEM3~1\dexplore.exe
[%SYSTEM%]\SVCHOST32.EXE
[%SYSTEM%]\svdhost.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\svhcost.exe
[%SYSTEM%]\svhost.exe
[%SYSTEM%]\svhosts.exe
[%SYSTEM%]\svshost.exe
[%SYSTEM%]\sys32dll.exe
[%SYSTEM%]\Sysctrls.exe
[%SYSTEM%]\sysfrcx.exe
[%SYSTEM%]\sysinfo.exe
[%SYSTEM%]\systembackup.exe
[%SYSTEM%]\systray.exe
[%SYSTEM%]\sysup.exe
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskmgr32.exe
[%SYSTEM%]\taskmgrs.com
[%SYSTEM%]\taskmngr.exe
[%SYSTEM%]\tibs3.exe
[%SYSTEM%]\timoty.exe
[%SYSTEM%]\unbsjd.exe
[%SYSTEM%]\Update32.exe
[%SYSTEM%]\uvovha.exe
[%SYSTEM%]\v6.exe
[%SYSTEM%]\vcxubk.exe
[%SYSTEM%]\vidmon\vidmon.exe
[%SYSTEM%]\wapisvsu.exe
[%SYSTEM%]\wbem\csrss.exe
[%SYSTEM%]\win32.exe
[%SYSTEM%]\windll.exe
[%SYSTEM%]\windowsupdats.exe
[%SYSTEM%]\winExplore.exe
[%SYSTEM%]\winipsec.exe
[%SYSTEM%]\winlog.exe
[%SYSTEM%]\winn32.exe
[%SYSTEM%]\winspoof.exe
[%SYSTEM%]\winsystem.exe
[%SYSTEM%]\wintems.exe
[%SYSTEM%]\winupdate.exe
[%SYSTEM%]\WINWORD.EXE
[%SYSTEM%]\wjview.exe
[%SYSTEM%]\wmiprvse.exe
[%SYSTEM%]\wplayer.exe
[%SYSTEM%]\ws2_32s.exe
[%SYSTEM%]\ypudutmnsl.exe
[%SYSTEM%]\zlip.exe
[%SYSTEM%]\zzb2.exe
[%WINDOWS%]\%A0svchost.exe
[%WINDOWS%]\.exe
[%WINDOWS%]\1903cr.exe
[%WINDOWS%]\aqadcup.exe
[%WINDOWS%]\avp.exe
[%WINDOWS%]\b.exe
[%WINDOWS%]\bbstore\dss\dssagent.exe
[%WINDOWS%]\cfg32.exe
[%WINDOWS%]\csrss.exe
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\directx.dll.vbs
[%WINDOWS%]\DirectX3D.exe
[%WINDOWS%]\dll32\csrss.exe
[%WINDOWS%]\DLLServAPI.exe
[%WINDOWS%]\dnscleaner.exe
[%WINDOWS%]\Duce6.exe
[%WINDOWS%]\EditorNetDos.exe
[%WINDOWS%]\emsw.exe
[%WINDOWS%]\enhupdt.exe
[%WINDOWS%]\explorer.exe
[%WINDOWS%]\FONTS\A46F2.com
[%WINDOWS%]\IEcheck.exe
[%WINDOWS%]\iexplorer.exe
[%WINDOWS%]\igator\trickler3103_pic_fs_dmpt_3103.exe
[%WINDOWS%]\inet20126\winlogon.exe
[%WINDOWS%]\jawa32.exe
[%WINDOWS%]\jusched.exe
[%WINDOWS%]\krn3.exe
[%WINDOWS%]\lsass.exe
[%WINDOWS%]\lssas1.exe
[%WINDOWS%]\MDM.EXE
[%WINDOWS%]\mservice1.exe
[%WINDOWS%]\msnmsgs.exe
[%WINDOWS%]\msqdevl1.exe
[%WINDOWS%]\msresearch.exe
[%WINDOWS%]\Navnet.exe
[%WINDOWS%]\nerocheck.exe
[%WINDOWS%]\NetMSConfig.exe
[%WINDOWS%]\OCXSMTPDos.exe
[%WINDOWS%]\PixArt\PAC207\Monitor.exe
[%WINDOWS%]\PixArt\PAC7311\Monitor.exe
[%WINDOWS%]\regedit.exe
[%WINDOWS%]\reload.vbs
[%WINDOWS%]\Remove_spyware.exe
[%WINDOWS%]\RUNDLL.EXE
[%WINDOWS%]\RUNDLL32.EXE
[%WINDOWS%]\satmat.exe
[%WINDOWS%]\scvhost.exe
[%WINDOWS%]\SEMBLY~1\javaw.exe
[%WINDOWS%]\Sentry.exe
[%WINDOWS%]\Servces32.exe
[%WINDOWS%]\service.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\services.exe
[%WINDOWS%]\ShellNew\RakyatKelaparan.exe
[%WINDOWS%]\ShowWnd.exe
[%WINDOWS%]\smss.exe
[%WINDOWS%]\snchost.exe
[%WINDOWS%]\SOUNDMAN.EXE
[%WINDOWS%]\sp2update00.exe
[%WINDOWS%]\sqldata1.exe
[%WINDOWS%]\STEM~1\notepad.exe
[%WINDOWS%]\stisvsq1.exe
[%WINDOWS%]\surfmonkey\SMProxy.exe
[%WINDOWS%]\sv.exe
[%WINDOWS%]\svchost.exe
[%WINDOWS%]\svhost.exe
[%WINDOWS%]\svhost32.exe
[%WINDOWS%]\SvrWizardVBX32.exe
[%WINDOWS%]\svshost1.exe
[%WINDOWS%]\sysfade.exe
[%WINDOWS%]\System\csrss.exe
[%WINDOWS%]\SYSTEM\EXPLORER.SCR
[%WINDOWS%]\system\fsg_3202.exe
[%WINDOWS%]\System\loader.exe
[%WINDOWS%]\system\rundll32.exe
[%WINDOWS%]\system\smss.exe
[%WINDOWS%]\system\svchost.exe
[%WINDOWS%]\system\svchost32.exe
[%WINDOWS%]\system\svhost.exe
[%WINDOWS%]\system\winstart001.exe
[%WINDOWS%]\SysWow64\timoty.exe
[%WINDOWS%]\taskmon.exe
[%WINDOWS%]\TEMP\win28B8.tmp.exe
[%WINDOWS%]\TEMP\win7C0D.tmp.exe
[%WINDOWS%]\TEMP\win??.tmp.exe
[%WINDOWS%]\TEMP\winC02.tmp.exe
[%WINDOWS%]\trest.exe
[%WINDOWS%]\twainxp.exe
[%WINDOWS%]\uninstall\rundl132.exe
[%WINDOWS%]\WindowsSecurityUpdate.exe
[%WINDOWS%]\WindowsUpdates.exe
[%WINDOWS%]\WINDOWS\svhost.exe
[%WINDOWS%]\winnetdos32.exe
[%WINDOWS%]\winnows.exe
[%WINDOWS%]\WinOCXDos32.exe
[%WINDOWS%]\WinOCXPOP32.exe
[%WINDOWS%]\winoscnfg.exe
[%WINDOWS%]\wintcpmod.exe
[%WINDOWS%]\wnad.exe
[%WINDOWS%]\WNSXS~1\rundll.exe
[%WINDOWS%]\wuauclt.exe
[%WINDOWS%]\Xhrmy.exe
[%WINDOWS%]\xpupdate.exe
[%WINDOWS%]\\\etb\\pokapoka79.exe
[%APPDATA%]\ASKS~1\svchost.exe
[%APPDATA%]\DOBE~1\logonui.exe
[%APPDATA%]\FNTS~1\netdde.exe
[%APPDATA%]\PPATCH~1\chkdsk.exe
[%APPDATA%]\SSEMBL~1\winspool.exe
[%APPDATA%]\YSTEM~1\winword.exe
[%COMMON_APPDATA%]\msw\BMan1.exe
[%COMMON_STARTUP%]\Uninstall64578.exe
[%FONTS%]\svchost.exe
[%PROFILE%]\gOhgkog.exe
[%PROFILE%]\mssvmdll.dll
[%PROFILE%]\scvhost.exe
[%PROFILE%]\WINDOWS\svchost.exe
[%PROFILE%]\winmain.exe
[%PROFILE%]\zbecczmv.exe
[%PROFILE_TEMP%]\II22.exe
[%PROFILE_TEMP%]\NpcNMdohh
[%PROFILE_TEMP%]\svchost.exe
[%PROFILE_TEMP%]\tmp6.tmp.exe
[%PROFILE_TEMP%]\update.exe
[%PROFILE_TEMP%]\x2000.exe
[%PROGRAM_FILES%]\180solutions\ncase\msbb155\msbb.exe
[%PROGRAM_FILES%]\3BSOFT~1\WINDOW~2\Windows Clean-Up Pro.exe
[%PROGRAM_FILES%]\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[%PROGRAM_FILES%]\AdTools Service\AdTools.exe
[%PROGRAM_FILES%]\AGSeydsApp\AGSeyApp.exe
[%PROGRAM_FILES%]\altnet\points manager\Points Manager.exe
[%PROGRAM_FILES%]\AltPayments\AltPayments.exe
[%PROGRAM_FILES%]\AOL\Active Virus Shield\avp.exe
[%PROGRAM_FILES%]\AQUATI~1\AQ3Helper.exe
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%PROGRAM_FILES%]\Aveo\Attune\bin\attune_ce.exe
[%PROGRAM_FILES%]\Aveo\Attune\Bin\Attune_ST.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\Bargain Buddy\bin\bargains.exe
[%PROGRAM_FILES%]\Block Checker\block-checker.exe
[%PROGRAM_FILES%]\Breakpoint Computers\WinTimer\wintimerc.exe
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\CATCOM~1\QUICKH~2\SCANMSG.EXE
[%PROGRAM_FILES%]\COMETS~1\DM\bin\dmserver.exe
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES%]\COMMON~2\TOOLBAR\winnet.exe
[%PROGRAM_FILES%]\Cosmi\HelpExpress\HXDL.EXE
[%PROGRAM_FILES%]\Cosmi\HelpExpress\Mr Mrs English\HXIUL.EXE
[%PROGRAM_FILES%]\CROSOF~1\services.exe
[%PROGRAM_FILES%]\CURITY~1\winlogon.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\Search.exe
[%PROGRAM_FILES%]\DAEMON Tools SearchBar\whse.exe
[%PROGRAM_FILES%]\DelFin\PromulGate\PgMonitr.exe
[%PROGRAM_FILES%]\DeluxeCommunications\Dxc.exe
[%PROGRAM_FILES%]\divx\divx pro codec\gain_trickler_3202a.exe
[%PROGRAM_FILES%]\Dpoint\bin\update.exe
[%PROGRAM_FILES%]\DreamGroup\No-Spy\No-Spy.exe
[%PROGRAM_FILES%]\DropSpam\oesrv.exe
[%PROGRAM_FILES%]\dslifestyle\dslifestyle.exe
[%PROGRAM_FILES%]\Error Safe Free\ERS.exe
[%PROGRAM_FILES%]\FNTS~1\dvdplay.exe
[%PROGRAM_FILES%]\Globe Software\StatBar\StatBar.exe
[%PROGRAM_FILES%]\GogoTools\Gogoware\LaunchAdware.exe
[%PROGRAM_FILES%]\GOTSMI~1\GSYUpdater.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.2.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe
[%PROGRAM_FILES%]\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe
[%PROGRAM_FILES%]\HooTech\NetMeter\HooNetMeter.exe
[%PROGRAM_FILES%]\HP\HP Software Update\hpwuSchd2.exe
[%PROGRAM_FILES%]\Instant Buzz\IBDaemon.exe
[%PROGRAM_FILES%]\Internet Explorer\IEXPLORE.EXE
[%PROGRAM_FILES%]\Internet Explorer\Setup\svchost.exe
[%PROGRAM_FILES%]\Internet Optimizer\optimize.exe
[%PROGRAM_FILES%]\INTERNET WASHER PRO\IW.EXE
[%PROGRAM_FILES%]\INTERN~2\iw.exe
[%PROGRAM_FILES%]\Ipwindows\ipwins.exe
[%PROGRAM_FILES%]\ipwins\ipwins.exe
[%PROGRAM_FILES%]\ISTsvc\istsvc.exe
[%PROGRAM_FILES%]\iTunes\iTunes.exe
[%PROGRAM_FILES%]\iWatchNow, Inc\iWatchNow Media Center\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[%PROGRAM_FILES%]\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
[%PROGRAM_FILES%]\License_Manager\license_manager.exe
[%PROGRAM_FILES%]\LimeWire\LimeWire.exe
[%PROGRAM_FILES%]\Linksys EasyLink Advisor\LinksysAgent.exe
[%PROGRAM_FILES%]\Logitech input devices\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\KEM.exe
[%PROGRAM_FILES%]\Logitech\SetPoint\SetPoint.exe
[%PROGRAM_FILES%]\mailskinner\MailSkinner.exe
[%PROGRAM_FILES%]\MCROSO~1.NET\ping.exe
[%PROGRAM_FILES%]\Media Access\MediaAccK.exe
[%PROGRAM_FILES%]\Messaging Names\msgrsvr.exe
[%PROGRAM_FILES%]\Microsoft IntelliType Pro\type32.exe
[%PROGRAM_FILES%]\MYWEBS~1\bar\1.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\MYWEBS~1\bar\2.bin\MWSOEMON.EXE
[%PROGRAM_FILES%]\NavExcel\NavHelper\v2.0.4d\navapp.exe
[%PROGRAM_FILES%]\NaviSearch\bin\nls.exe
[%PROGRAM_FILES%]\Netcom3 Cleaner\SpyClean.exe
[%PROGRAM_FILES%]\NetPumper\NetPumperIEProxy.exe
[%PROGRAM_FILES%]\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
[%PROGRAM_FILES%]\Notify\notify.exe
[%PROGRAM_FILES%]\Open Site\opensite.exe
[%PROGRAM_FILES%]\Optimum Online\Netsurf.exe
[%PROGRAM_FILES%]\Outerinfo\OuterinfoUpdate.exe
[%PROGRAM_FILES%]\outlook\outlook.exe
[%PROGRAM_FILES%]\p2pnetworks\mpp2pl.exe
[%PROGRAM_FILES%]\PCSecurityShield\The Shield Deluxe 2008\avp.exe
[%PROGRAM_FILES%]\PCSecurityShield\TheShieldDeluxe\avp.exe
[%PROGRAM_FILES%]\PestTrap\PestTrap.exe
[%PROGRAM_FILES%]\Power Manager\PM.exe
[%PROGRAM_FILES%]\Protocom\SecureLogin\slproto.exe
[%PROGRAM_FILES%]\QUICKH~1\SCANMSG.EXE
[%PROGRAM_FILES%]\QuickTime\qttask.exe
[%PROGRAM_FILES%]\RACLE~1\ping.exe
[%PROGRAM_FILES%]\RACLE~1\wucrtupd.exe
[%PROGRAM_FILES%]\RSSoft\RSEDNClient.exe
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\Save\Save.exe
[%PROGRAM_FILES%]\SCURIT~1\csrss.exe
[%PROGRAM_FILES%]\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
[%PROGRAM_FILES%]\seekmo\seekmo.exe
[%PROGRAM_FILES%]\Silicon Integrated Systems\SiSRaidPackage\Hot_Plug.exe
[%PROGRAM_FILES%]\Smart Keystroke Recorder\LogService.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.0.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
[%PROGRAM_FILES%]\SpamBlockerUtility\Bin\4.8.6.0\SbOEAddOn.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\461~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\480~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\484~1.0\SBInst.exe
[%PROGRAM_FILES%]\SPAMBL~1\Bin\486~1.0\SBInst.exe
[%PROGRAM_FILES%]\Support.com\bin\tgkill.exe
[%PROGRAM_FILES%]\support.com\client\bin\tgcmd.exe
[%PROGRAM_FILES%]\support.com\client\lserver\Server.vbs
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%PROGRAM_FILES%]\SYSTEM~1\soap.exe
[%PROGRAM_FILES%]\TBONBin\tbon.exe
[%PROGRAM_FILES%]\Timer\Timer.exe
[%PROGRAM_FILES%]\Toolbar\TBPS.exe
[%PROGRAM_FILES%]\TopSearch\TopSearch.exe
[%PROGRAM_FILES%]\V3\SYSMONNT.EXE
[%PROGRAM_FILES%]\VVSN\VVSN.exe
[%PROGRAM_FILES%]\webHancer\Programs\whagent.exe
[%PROGRAM_FILES%]\webHancer\Programs\whSurvey.exe
[%PROGRAM_FILES%]\Web_Rebates\WebRebates0.exe
[%PROGRAM_FILES%]\WhenUSearch\Search.exe
[%PROGRAM_FILES%]\WhenUSearch\whse.exe
[%PROGRAM_FILES%]\WildTangent\DDC\DDCManager\DDCMan.exe
[%PROGRAM_FILES%]\Winamp\winampa.exe
[%PROGRAM_FILES%]\WINCLE~1\SCANMSG.EXE
[%PROGRAM_FILES%]\Windows Media Player\csrss.exe
[%PROGRAM_FILES%]\Windows Media Player\wmplayer.exe
[%PROGRAM_FILES%]\WindowsSA\omniscient.exe
[%PROGRAM_FILES%]\WindowsUpdate\wupdate.exe
[%PROGRAM_FILES%]\WinFixer\wfxcwr.exe
[%PROGRAM_FILES%]\winupdates\winupdates.exe
[%PROGRAM_FILES%]\WinUpdate\WinUpdate.exe
[%PROGRAM_FILES%]\WNSXS~1\msdtc.exe
[%PROGRAM_FILES%]\zango\zango.exe
[%PROGRAM_FILES%]\Zcodec\ZUpdate\ZUpdate.exe
[%PROGRAM_FILES_COMMON%]\CMEII\CMESys.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\smss.exe
[%PROGRAM_FILES_COMMON%]\DOBE~1\winword.exe
[%PROGRAM_FILES_COMMON%]\ECURIT~1\cmd.exe
[%PROGRAM_FILES_COMMON%]\MBOLS~1\wuauclt.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\msnfo32.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\MSInfo\TaskUpdate.exe
[%PROGRAM_FILES_COMMON%]\Microsoft Shared\web server extensions\40\bots\vinavbar\svchost.exe
[%PROGRAM_FILES_COMMON%]\SCURIT~1\nslookup.exe
[%PROGRAM_FILES_COMMON%]\SSEMBL~1\winword.exe
[%PROGRAM_FILES_COMMON%]\Stone Shared\winCheck.exe
[%PROGRAM_FILES_COMMON%]\SYSTEM\MOSEARCH\BIN\mosearch.exe
[%PROGRAM_FILES_COMMON%]\system\ms2src.exe
[%PROGRAM_FILES_COMMON%]\System\Update.exe
[%PROGRAM_FILES_COMMON%]\System\WinService32.exe
[%PROGRAM_FILES_COMMON%]\YSTEM~1\logonui.exe
[%STARTUP%]\svchost.exe
[%SYSTEM%]\
[%SYSTEM%]\a.exe
[%SYSTEM%]\addins\svchost.exe
[%SYSTEM%]\adprot.exe
[%SYSTEM%]\aim.exe
[%SYSTEM%]\aqesyg.exe
[%SYSTEM%]\ASKS~1\winword.exe
[%SYSTEM%]\avgss.exe
[%SYSTEM%]\bootcfg1.exe
[%SYSTEM%]\bpsveyyu.exe
[%SYSTEM%]\byyskv.exe
[%SYSTEM%]\c.exe
[%SYSTEM%]\cd_load.exe
[%SYSTEM%]\cgheuj.exe
[%SYSTEM%]\cmd.exe
[%SYSTEM%]\cme.exe
[%SYSTEM%]\cmeupd.exe
[%SYSTEM%]\crdwsys\smss.exe
[%SYSTEM%]\CROSOF~1.NET\notepad.exe
[%SYSTEM%]\csrs.exe
[%SYSTEM%]\ctfmon.exe
[%SYSTEM%]\dllhost32.exe
[%SYSTEM%]\DRIVERS\services.exe
[%SYSTEM%]\drivers\sysdrv.exe
[%SYSTEM%]\drivers\system.exe
[%SYSTEM%]\EXECUSER.EXE
[%SYSTEM%]\exploer.exe
[%SYSTEM%]\explore.exe
[%SYSTEM%]\EXPLORER.EXE
[%SYSTEM%]\firewall.exe
[%SYSTEM%]\fx.exe
[%SYSTEM%]\guarnset.exe
[%SYSTEM%]\gycrzc.exe
[%SYSTEM%]\gylxto.exe
[%SYSTEM%]\hbcyjpsdsc.exe
[%SYSTEM%]\illusion1.exe
[%SYSTEM%]\infwin.exe
[%SYSTEM%]\iovyrn.exe
[%SYSTEM%]\isass.exe
[%SYSTEM%]\javaw.exe
[%SYSTEM%]\kernel32.exe
[%SYSTEM%]\kernels1118.exe
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\kmbnac.exe
[%SYSTEM%]\Kmr.exe
[%SYSTEM%]\lelel.EXE
[%SYSTEM%]\lich.exe
[%SYSTEM%]\linkprd.exe
[%SYSTEM%]\links.exe
[%SYSTEM%]\lnaccess.exe
[%SYSTEM%]\lockx.exe
[%SYSTEM%]\m4n70s.exe
[%SYSTEM%]\mcafee32.exe
[%SYSTEM%]\MccTrayApp.exe
[%SYSTEM%]\mmf32.exe
[%SYSTEM%]\mmsvc32.exe
[%SYSTEM%]\mose.bat
[%SYSTEM%]\MSDATLST.exe
[%SYSTEM%]\msdmxm.exe
[%SYSTEM%]\mshelp32.com
[%SYSTEM%]\msiexec16.exe
[%SYSTEM%]\msnmger.exe
[%SYSTEM%]\msnmsg.exe
[%SYSTEM%]\MSPRCSS32.exe
[%SYSTEM%]\Msrtmon.exe
[%SYSTEM%]\mswinup.exe
[%SYSTEM%]\mwsrvacc.exe
[%SYSTEM%]\mxcrtp.dll
[%SYSTEM%]\ncgeca.exe
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\ntos.exe
[%SYSTEM%]\ocglia.exe
[%SYSTEM%]\omryog.exe
[%SYSTEM%]\P2P Networking\P2P Networking2.exe
[%SYSTEM%]\prodsrvs.exe
[%SYSTEM%]\prosvsys.exe
[%SYSTEM%]\PSHWR.EXE
[%SYSTEM%]\rant.exe
[%SYSTEM%]\regedit.exe
[%SYSTEM%]\regscan.exe
[%SYSTEM%]\REGSVR32.EXE
[%SYSTEM%]\rizg.exe
[%SYSTEM%]\rk.exe
[%SYSTEM%]\rundll32.exe
[%SYSTEM%]\schost.exe
[%SYSTEM%]\scvhost.exe
[%SYSTEM%]\scyxdaaa.exe
[%SYSTEM%]\sdoitjjwx.exe
[%SYSTEM%]\security.exe
[%SYSTEM%]\server.exe
[%SYSTEM%]\service.exe
[%SYSTEM%]\service1.exe
[%SYSTEM%]\servicess.exe
[%SYSTEM%]\setup.dll
[%SYSTEM%]\SKS~1\lsass.exe
[%SYSTEM%]\slk8x2peu.exesmss.exe
[%SYSTEM%]\sountaskmgr
[%SYSTEM%]\sp2ctr.exe
[%SYSTEM%]\spoolsv32.exe
[%SYSTEM%]\spoolsvc.exe
[%SYSTEM%]\spoolsvv.exe
[%SYSTEM%]\spoolvs.exe
[%SYSTEM%]\srshost.exe
[%SYSTEM%]\SSEMBL~1\dllhost.exe
[%SYSTEM%]\SSTEM3~1\dexplore.exe
[%SYSTEM%]\SVCHOST32.EXE
[%SYSTEM%]\svdhost.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\svhcost.exe
[%SYSTEM%]\svhost.exe
[%SYSTEM%]\svhosts.exe
[%SYSTEM%]\svshost.exe
[%SYSTEM%]\sys32dll.exe
[%SYSTEM%]\Sysctrls.exe
[%SYSTEM%]\sysfrcx.exe
[%SYSTEM%]\sysinfo.exe
[%SYSTEM%]\systembackup.exe
[%SYSTEM%]\systray.exe
[%SYSTEM%]\sysup.exe
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskmgr32.exe
[%SYSTEM%]\taskmgrs.com
[%SYSTEM%]\taskmngr.exe
[%SYSTEM%]\tibs3.exe
[%SYSTEM%]\timoty.exe
[%SYSTEM%]\unbsjd.exe
[%SYSTEM%]\Update32.exe
[%SYSTEM%]\uvovha.exe
[%SYSTEM%]\v6.exe
[%SYSTEM%]\vcxubk.exe
[%SYSTEM%]\vidmon\vidmon.exe
[%SYSTEM%]\wapisvsu.exe
[%SYSTEM%]\wbem\csrss.exe
[%SYSTEM%]\win32.exe
[%SYSTEM%]\windll.exe
[%SYSTEM%]\windowsupdats.exe
[%SYSTEM%]\winExplore.exe
[%SYSTEM%]\winipsec.exe
[%SYSTEM%]\winlog.exe
[%SYSTEM%]\winn32.exe
[%SYSTEM%]\winspoof.exe
[%SYSTEM%]\winsystem.exe
[%SYSTEM%]\wintems.exe
[%SYSTEM%]\winupdate.exe
[%SYSTEM%]\WINWORD.EXE
[%SYSTEM%]\wjview.exe
[%SYSTEM%]\wmiprvse.exe
[%SYSTEM%]\wplayer.exe
[%SYSTEM%]\ws2_32s.exe
[%SYSTEM%]\ypudutmnsl.exe
[%SYSTEM%]\zlip.exe
[%SYSTEM%]\zzb2.exe
[%WINDOWS%]\%A0svchost.exe
[%WINDOWS%]\.exe
[%WINDOWS%]\1903cr.exe
[%WINDOWS%]\aqadcup.exe
[%WINDOWS%]\avp.exe
[%WINDOWS%]\b.exe
[%WINDOWS%]\bbstore\dss\dssagent.exe
[%WINDOWS%]\cfg32.exe
[%WINDOWS%]\csrss.exe
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\directx.dll.vbs
[%WINDOWS%]\DirectX3D.exe
[%WINDOWS%]\dll32\csrss.exe
[%WINDOWS%]\DLLServAPI.exe
[%WINDOWS%]\dnscleaner.exe
[%WINDOWS%]\Duce6.exe
[%WINDOWS%]\EditorNetDos.exe
[%WINDOWS%]\emsw.exe
[%WINDOWS%]\enhupdt.exe
[%WINDOWS%]\explorer.exe
[%WINDOWS%]\FONTS\A46F2.com
[%WINDOWS%]\IEcheck.exe
[%WINDOWS%]\iexplorer.exe
[%WINDOWS%]\igator\trickler3103_pic_fs_dmpt_3103.exe
[%WINDOWS%]\inet20126\winlogon.exe
[%WINDOWS%]\jawa32.exe
[%WINDOWS%]\jusched.exe
[%WINDOWS%]\krn3.exe
[%WINDOWS%]\lsass.exe
[%WINDOWS%]\lssas1.exe
[%WINDOWS%]\MDM.EXE
[%WINDOWS%]\mservice1.exe
[%WINDOWS%]\msnmsgs.exe
[%WINDOWS%]\msqdevl1.exe
[%WINDOWS%]\msresearch.exe
[%WINDOWS%]\Navnet.exe
[%WINDOWS%]\nerocheck.exe
[%WINDOWS%]\NetMSConfig.exe
[%WINDOWS%]\OCXSMTPDos.exe
[%WINDOWS%]\PixArt\PAC207\Monitor.exe
[%WINDOWS%]\PixArt\PAC7311\Monitor.exe
[%WINDOWS%]\regedit.exe
[%WINDOWS%]\reload.vbs
[%WINDOWS%]\Remove_spyware.exe
[%WINDOWS%]\RUNDLL.EXE
[%WINDOWS%]\RUNDLL32.EXE
[%WINDOWS%]\satmat.exe
[%WINDOWS%]\scvhost.exe
[%WINDOWS%]\SEMBLY~1\javaw.exe
[%WINDOWS%]\Sentry.exe
[%WINDOWS%]\Servces32.exe
[%WINDOWS%]\service.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\services.exe
[%WINDOWS%]\ShellNew\RakyatKelaparan.exe
[%WINDOWS%]\ShowWnd.exe
[%WINDOWS%]\smss.exe
[%WINDOWS%]\snchost.exe
[%WINDOWS%]\SOUNDMAN.EXE
[%WINDOWS%]\sp2update00.exe
[%WINDOWS%]\sqldata1.exe
[%WINDOWS%]\STEM~1\notepad.exe
[%WINDOWS%]\stisvsq1.exe
[%WINDOWS%]\surfmonkey\SMProxy.exe
[%WINDOWS%]\sv.exe
[%WINDOWS%]\svchost.exe
[%WINDOWS%]\svhost.exe
[%WINDOWS%]\svhost32.exe
[%WINDOWS%]\SvrWizardVBX32.exe
[%WINDOWS%]\svshost1.exe
[%WINDOWS%]\sysfade.exe
[%WINDOWS%]\System\csrss.exe
[%WINDOWS%]\SYSTEM\EXPLORER.SCR
[%WINDOWS%]\system\fsg_3202.exe
[%WINDOWS%]\System\loader.exe
[%WINDOWS%]\system\rundll32.exe
[%WINDOWS%]\system\smss.exe
[%WINDOWS%]\system\svchost.exe
[%WINDOWS%]\system\svchost32.exe
[%WINDOWS%]\system\svhost.exe
[%WINDOWS%]\system\winstart001.exe
[%WINDOWS%]\SysWow64\timoty.exe
[%WINDOWS%]\taskmon.exe
[%WINDOWS%]\TEMP\win28B8.tmp.exe
[%WINDOWS%]\TEMP\win7C0D.tmp.exe
[%WINDOWS%]\TEMP\win??.tmp.exe
[%WINDOWS%]\TEMP\winC02.tmp.exe
[%WINDOWS%]\trest.exe
[%WINDOWS%]\twainxp.exe
[%WINDOWS%]\uninstall\rundl132.exe
[%WINDOWS%]\WindowsSecurityUpdate.exe
[%WINDOWS%]\WindowsUpdates.exe
[%WINDOWS%]\WINDOWS\svhost.exe
[%WINDOWS%]\winnetdos32.exe
[%WINDOWS%]\winnows.exe
[%WINDOWS%]\WinOCXDos32.exe
[%WINDOWS%]\WinOCXPOP32.exe
[%WINDOWS%]\winoscnfg.exe
[%WINDOWS%]\wintcpmod.exe
[%WINDOWS%]\wnad.exe
[%WINDOWS%]\WNSXS~1\rundll.exe
[%WINDOWS%]\wuauclt.exe
[%WINDOWS%]\Xhrmy.exe
[%WINDOWS%]\xpupdate.exe
[%WINDOWS%]\\\etb\\pokapoka79.exe

Registry Values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\runservices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\runservicesonce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Disabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Disabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Disabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run_Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Disabled)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Removing Autorun Malware:

An up-to-date copy of ExterminateIt should detect and prevent infection from Autorun Malware.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Autorun Malware manually.

To completely manually remove Autorun Malware malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Autorun Malware.

  1. Use Task Manager to terminate the Autorun Malware process.
  2. Delete the original Autorun Malware file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Autorun Malware from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Autorun Malware!


Also Be Aware of the Following Threats:
Removing All.in.One Spyware
Hauntpc Trojan Symptoms